start::
CreateRestorePoint:
CloseProcesses:
Hosts:
RemoveProxy:
HKLM\...\Run: [AdobeGCInvoker-1.0] => "C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe" (Pas de fichier)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction
HKU\S-1-5-19\...\Run: [OneDriveSetup] => C:\Windows\SysWOW64\OneDriveSetup.exe [30870320 2019-12-07]
HKU\S-1-5-20\...\Run: [OneDriveSetup] => C:\Windows\SysWOW64\OneDriveSetup.exe [30870320 2019-12-07]
HKU\S-1-5-21-905969777-43035773-1705488793-1002\...\Run: [OneDrive] => C:\Users\renov\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2602424 2023-05-24]
HKU\S-1-5-21-905969777-43035773-1705488793-1002\...\Run: [AirBackupHelper] => C:\Program Files (x86)\iMobie\AnyTrans\AirBackupHelper.exe [2740920 2022-02-08]
HKU\S-1-5-21-905969777-43035773-1705488793-1002\...\Run: [AnyTransToolHelper] => C:\Program Files (x86)\iMobie\AnyTrans\AnyTransToolHelper.exe [576184 2022-02-08]
HKU\S-1-5-21-905969777-43035773-1705488793-1002\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [40454048 2023-05-12]
HKU\S-1-5-21-905969777-43035773-1705488793-1002\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\renov\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe" (Pas de fichier)
HKU\S-1-5-21-905969777-43035773-1705488793-1002\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\renov\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe" (Pas de fichier)
HKU\S-1-5-21-905969777-43035773-1705488793-1002\...\RunOnce: [Uninstall 23.086.0423.0001] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\renov\AppData\Local\Microsoft\OneDrive\23.086.0423.0001" (Pas de fichier)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{052EB454-9F19-CB42-7875-807F79F311C4}] -> C:\Program Files (x86)\CCleaner Browser\Application\113.0.21244.129\Installer\chrmstp.exe
Task: C:\WINDOWS\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
FF Extension: (Avast Online Security & Privacy) - C:\Users\renov\AppData\Roaming\Mozilla\Firefox\Profiles\vyjiah9d.default-release-1568016421349\Extensions\wrc@avast.com.xpi
S2 ccleaner; C:\Program Files (x86)\CCleaner Browser\Update\CCleanerBrowserUpdate.exe [208176 2022-12-14]
S3 CCleanerBrowserElevationService; C:\Program Files (x86)\CCleaner Browser\Application\113.0.21244.129\elevation_service.exe [2032688 2023-05-18]
S3 ccleanerm; C:\Program Files (x86)\CCleaner Browser\Update\CCleanerBrowserUpdate.exe [208176 2022-12-14]
S3 CCleanerPerformanceOptimizerService; C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe
2023-05-26 07:02 - 2023-05-26 07:02 - 000000000 ____D C:\WINDOWS\{8BFE99CA-A048-445D-8771-1A1BD952EA37}
2023-05-11 18:16 - 2023-05-11 18:16 - 005562976 _____ (Piriform Ltd) C:\Users\renov\Downloads\rcsetup153(1).exe
FCheck: C:\WINDOWS\system32\wowreg32.exe [2021-09-15]
AlternateDataStreams: C:\Users\renov\Desktop\FRST64.exe:MBAM.Zone.Identifier [193]
SearchScopes: HKU\S-1-5-21-905969777-43035773-1705488793-1002 -> DefaultScope {D1F15621-C383-442B-A8A1-4BEFBA92756F} URL =
SearchScopes: HKU\S-1-5-21-905969777-43035773-1705488793-1002 -> {D1F15621-C383-442B-A8A1-4BEFBA92756F} URL =
Handler: mso-minsb-roaming.16 - Pas de valeur CLSID
Handler: mso-minsb.16 - Pas de valeur CLSID
Handler: osf-roaming.16 - Pas de valeur CLSID
Handler: osf.16 - Pas de valeur CLSID
Filter: text/xml - Pas de valeur CLSID
EmptyTemp:
cmd: netsh advfirewall reset
cmd: ipconfig /flushdns
end::