start::
closeprocesses:
createrestorepoint:
CustomCLSID: HKU\S-1-5-21-3849337051-40948182-4080137746-1001_Classes\CLSID\{23B3E3D8-C162-4A8B-AB0C-0905DCB1DF19}\InprocServer32 -> C:\Users\raphi\AppData\Local\Packages\Microsoft.PowerAutomateDesktop_8wekyb3d8bbwe\TempState\RDP\DVCPlugin\x64\Microsoft.Flow.RPA.Desktop.UIAutomation.RDP.DVC.Plugin.dll => Pas de fichier
AlternateDataStreams: C:\WINDOWS\system32\9EarsSurroundSound.dll:97D88723C8 [3434]
AlternateDataStreams: C:\ProgramData\mntemp:8EAD8B3507 [3434]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini:B1DA6C571C [3434]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\4K Video Downloader.lnk:CCF539F03F [3434]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk:B026C77744 [3434]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks 5 Multi-Instance Manager.lnk:35C0D57199 [3434]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks 5.lnk:088221F38A [3434]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini:41964AA945 [3434]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCUE.lnk:36398BE0BF [3434]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCUE.lnk:97831153DE [3434]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn.lnk:CF0BC1546B [3434]
HKU\S-1-5-21-3849337051-40948182-4080137746-1001\Software\Classes\regfile: <==== ATTENTION
HKU\S-1-5-21-3849337051-40948182-4080137746-1001\Software\Classes\.reg: => <==== ATTENTION
HKU\S-1-5-21-3849337051-40948182-4080137746-1001\Software\Classes\.bat: => <==== ATTENTION
HKU\S-1-5-21-3849337051-40948182-4080137746-1001\Software\Classes\.cmd: => <==== ATTENTION
HKLM\...\StartupApproved\Run32: => "Wondershare Helper Compact.exe"
FirewallRules: [{7AD173C1-46B0-44FC-A31D-C45E62F1160C}] => (Allow) C:\Program Files (x86)\Overwolf\0.212.0.10\OverwolfBrowser.exe => Pas de fichier
FirewallRules: [{C9AE5E81-ECAD-4C26-BE4E-1A1809F0697C}] => (Allow) C:\Program Files (x86)\Overwolf\0.212.0.10\OverwolfBrowser.exe => Pas de fichier
FirewallRules: [{0E4A35AE-0D5B-4414-8A94-8BFCFC48A491}] => (Block) C:\Program Files (x86)\Overwolf\0.212.0.10\OverwolfBrowser.exe => Pas de fichier
FirewallRules: [{19641318-3C1C-4FF1-94E4-367D307C0684}] => (Block) C:\Program Files (x86)\Overwolf\0.212.0.10\OverwolfBrowser.exe => Pas de fichier
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2133728 2017-09-12] (Wondershare Technology Co.,Ltd -> Wondershare)
C:\Program Files (x86)\Common Files\Wondershare
HKU\S-1-5-21-3849337051-40948182-4080137746-1001\...\Run: [Power2GoExpress8] => [X]
Task: {3536F146-7BBA-48FF-A2E6-387CFA5810AC} - System32\Tasks\MicrosoftEdgeShadowStackRollbackTask => C:\Program Files (x86)\Microsoft\Edge\Application\105.0.1343.50\Installer\setup.exe --handle-crash="$(ProcessPath)" (Pas de fichier)
Task: {E0F10DCF-44AD-40E8-9370-FB5DA59F93FB} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => C:\WINDOWS\system32\MusNotification.exe (Pas de fichier)
CHR DefaultSearchURL: Profile 2 -> hxxps://fr.search.yahoo.com/search?fr=mcafee&type=E210FR91082G0&p={searchTerms}
CHR DefaultSearchKeyword: Profile 2 -> mcafee
CHR DefaultSuggestURL: Profile 2 -> hxxps://fr.search.yahoo.com/sugg/gossip/gossip-fr-partner?output=fxjson&appid=mca&source=yahoo_mcafee_searchassist&command={searchTerms}
S3 GSDriver; \SystemRoot\System32\drivers\GSDriver64.sys [X]
emptytemp:
end::