start::
closeprocesses:
createrestorepoint:
IE trusted site: HKU\.DEFAULT\...\webcompanion.com -> hxxp://webcompanion.com
IE trusted site: HKU\S-1-5-21-2980599220-2505403589-2136101026-1001\...\webcompanion.com -> hxxp://webcompanion.com
C:\ProgramData\Freemake
HKU\S-1-5-18\...\Run: [Bomgar_Cleanup_ZD545498424025] => cmd.exe /C rd /S /Q "C:\ProgramData\bomgar-scc-0x617e5817" & reg.exe delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Bomgar_Cleanup_ZD545498424025 /f (Pas de fichier) <==== ATTENTION
GroupPolicy-Firefox: Restriction <==== ATTENTION
Task: {684D29C5-AE7B-4FCA-BCED-75CE6A0E42FF} - System32\Tasks\Avast Software\Overseer => C:\Windows\OEM\CustomizationFiles\Overseer.exe [2135448 2023-04-13] (Avast Software s.r.o. -> Avast Software)
HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3: <==== ATTENTION (Restriction - Zones)
Edge HKLM-x32\...\Edge\Extension: [caiblelclndcckfafdaggpephhgfpoip]
Edge HKLM-x32\...\Edge\Extension: [emgfgdclgfeldebanedpihppahgngnle]
FF Homepage: Mozilla\Firefox\Profiles\t64yxgdk.default -> hxxps://mysearchengine.co/homepage?hp=1&bitmask=9996&pId=BT170603&iDate=2021-07-21 05:42:09&bName=
FF NewTab: Mozilla\Firefox\Profiles\t64yxgdk.default -> hxxps://mysearchengine.co/homepage?hp=1&bitmask=9996&pId=BT170603&iDate=2021-07-21 05:42:09&bName=
CHR HKLM-x32\...\Chrome\Extension: [aegnopegbbhjeeiganiajffnalhlkkjb]
CHR HKLM-x32\...\Chrome\Extension: [caljgklbbfbcjjanaijlacgncafpegll]
CHR HKLM-x32\...\Chrome\Extension: [ccbpbkebodcjkknkfkpmfeciinhidaeh]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk]
cmd: netsh advfirewall reset
emptytemp:
end::