start::
SystemRestore: on
CreateRestorePoint:
CloseProcesses:
Hosts:
RemoveProxy:
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction
Task: {1B3BE398-AB02-4C08-88F7-0F7C03C8DDE8} - System32\Tasks\Microsoft\Windows\Maintenance\InstallWinSAT => Maintenance.vbs (Pas de fichier)
HKU\S-1-5-21-4025387563-2344523962-729458578-1001\...\Run: [AMDNoiseSuppression] => "C:\Windows\system32\AMD\ANR\AMDNoiseSuppression.exe" (Pas de fichier)
HKU\S-1-5-21-4025387563-2344523962-729458578-1001\...\Run: [Microsoft Store] => C:\Users\MARCO\Desktop\911\Update.exe (Pas de fichier)
Task: C:\Windows\Tasks\update-S-1-5-21-4025387563-2344523962-729458578-1001.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe
S3 dg_ssudbus; \SystemRoot\System32\drivers\ssudbus.sys [X]
CustomCLSID: HKU\S-1-5-21-4025387563-2344523962-729458578-1001_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\MARCO\AppData\Local\Microsoft\OneDrive\22.131.0619.0001\FileSyncShell64.dll => Pas de fichier
CustomCLSID: HKU\S-1-5-21-4025387563-2344523962-729458578-1001_Classes\CLSID\{20894375-46AE-46E2-BAFD-CB38975CDCE6}\InprocServer32 -> C:\Users\MARCO\AppData\Local\Microsoft\OneDrive\22.131.0619.0001\FileSyncShell64.dll => Pas de fichier
CustomCLSID: HKU\S-1-5-21-4025387563-2344523962-729458578-1001_Classes\CLSID\{47E6DCAF-41F8-441C-BD0E-A50D5FE6C4D1}\localserver32 -> "C:\Users\MARCO\AppData\Local\Microsoft\OneDrive\22.131.0619.0001\Microsoft.SharePoint.exe" => Pas de fichier
CustomCLSID: HKU\S-1-5-21-4025387563-2344523962-729458578-1001_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\MARCO\AppData\Local\Microsoft\OneDrive\22.131.0619.0001\FileSyncShell64.dll => Pas de fichier
CustomCLSID: HKU\S-1-5-21-4025387563-2344523962-729458578-1001_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\MARCO\AppData\Local\Microsoft\OneDrive\22.131.0619.0001\FileSyncShell64.dll => Pas de fichier
CustomCLSID: HKU\S-1-5-21-4025387563-2344523962-729458578-1001_Classes\CLSID\{917E8742-AA3B-7318-FA12-10485FB322A2}\localserver32 -> "C:\Users\MARCO\AppData\Local\Microsoft\OneDrive\22.131.0619.0001\Microsoft.SharePoint.exe" => Pas de fichier
CustomCLSID: HKU\S-1-5-21-4025387563-2344523962-729458578-1001_Classes\CLSID\{997809F3-33FD-4FD6-A2ED-CEF50F3263B1}\InprocServer32 -> C:\Users\MARCO\AppData\Local\Microsoft\EdgeUpdate\1.3.169.31\psuser_64.dll => Pas de fichier
CustomCLSID: HKU\S-1-5-21-4025387563-2344523962-729458578-1001_Classes\CLSID\{ABF66F82-B04C-4FE4-8272-661539463FE1}\InprocServer32 -> C:\Users\MARCO\AppData\Local\Microsoft\EdgeUpdate\1.3.171.37\psuser_64.dll => Pas de fichier
EmptyTemp:
cmd: ipconfig /flushdns
end::