start::
CreateRestorePoint:
CloseProcesses:
RemoveProxy:
HKLM\Software\...\Authentication\Credential Providers: [{C885AA15-1764-4293-B82A-0586ADD46B35}] ->
Edge Extension: (Safe Torrent Scanner) - C:\Users\paolo\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\aegnopegbbhjeeiganiajffnalhlkkjb
Edge HKU\S-1-5-21-1560103729-790777611-1156302081-1001\SOFTWARE\Microsoft\Edge\Extensions\...\Edge\Extension: [kagpabjoboikccfdghpdlaaopmgpgfdc]
CHR HKU\S-1-5-21-1560103729-790777611-1156302081-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [ljglajjnnkapghbckkcmodicjhacbfhk]
CHR HKU\S-1-5-21-1560103729-790777611-1156302081-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
2023-02-27 14:11 - 2023-02-27 14:21 - 000000000 ____D C:\Program Files\Wondershare
2023-02-27 14:11 - 2023-02-27 14:11 - 000000000 ____D C:\Users\paolo\AppData\Roaming\Wondershare
2023-02-27 14:11 - 2023-02-27 14:11 - 000000000 ____D C:\ProgramData\Wondershare
2023-02-27 14:11 - 2023-02-27 14:11 - 000000000 ____D C:\Program Files\Common Files\Wondershare
CustomCLSID: HKU\S-1-5-21-1560103729-790777611-1156302081-1001_Classes\CLSID\{23B3E3D8-C162-4A8B-AB0C-0905DCB1DF19}\InprocServer32 -> C:\Users\paolo\AppData\Local\Packages\Microsoft.PowerAutomateDesktop_8wekyb3d8bbwe\TempState\RDP\DVCPlugin\x64\Microsoft.Flow.RPA.Desktop.UIAutomation.RDP.DVC.Plugin.dll => Pas de fichier
ContextMenuHandlers1_.DEFAULT: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => -> Pas de fichier
ContextMenuHandlers4_.DEFAULT: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => -> Pas de fichier
ContextMenuHandlers5_.DEFAULT: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => -> Pas de fichier
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{5099944A-F6B9-4057-A056-8C550228544C} => "SafeBootDrivers"="1"
HKU\S-1-5-21-1560103729-790777611-1156302081-1001\Software\Classes\regfile: <==== ATTENTION
HKU\S-1-5-21-1560103729-790777611-1156302081-1001\Software\Classes\.reg: => <==== ATTENTION
HKU\S-1-5-21-1560103729-790777611-1156302081-1001\Software\Classes\.bat: => <==== ATTENTION
HKU\S-1-5-21-1560103729-790777611-1156302081-1001\Software\Classes\.cmd: => <==== ATTENTION
URLSearchHook: [S-1-5-21-1560103729-790777611-1156302081-1001] ATTENTION => URLSearchHook par défaut est absent
BHO: IEToEdge BHO -> {1FD49718-1D00-4B19-AF5F-070AF6D5D54C} -> C:\Program Files (x86)\Microsoft\Edge\Application\110.0.1587.57\BHO\ie_to_edge_bho_64.dll => Pas de fichier
IE trusted site: HKU\S-1-5-21-1560103729-790777611-1156302081-1001\...\sharepoint.com -> hxxps://ccinca-files.sharepoint.com
HKLM\...\StartupApproved\StartupFolder: => "Wondershare PEToolbox.lnk"
HKLM\...\StartupApproved\StartupFolder: => "Wondershare PEScreenshot.lnk"
HKU\S-1-5-21-1560103729-790777611-1156302081-1001\...\StartupApproved\StartupFolder: => "Wondershare PEToolbox.lnk"
HKU\S-1-5-21-1560103729-790777611-1156302081-1001\...\StartupApproved\StartupFolder: => "Wondershare PEScreenshot.lnk"
EmptyTemp:
cmd: sfc /scannow
cmd: DISM /Online /Cleanup-image /Restorehealth
end::