start::
closeprocesses:
createrestorepoint:
ShortcutWithArgument: C:\Users\Romain\Desktop\Logiciels\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC) -> --google-base-url=hxxps://yoursearchbar.me --extensions-on-chrome-urls --load-extension=C:\Windows\InternalKernelGrid4
AlternateDataStreams: C:\WINDOWS\system32\9EarsSurroundSound.dll:97D88723C8 [3442]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini:B1DA6C571C [3442]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk:A1B76439FE [3442]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini:41964AA945 [3442]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Epic Games Launcher.lnk:BE32D07BC5 [3442]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk:B96E9B8455 [3442]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NZXT CAM.lnk:AB04221C49 [3442]
AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [6008]
AlternateDataStreams: C:\Users\Romain\Application Data:00e481b5e22dbe1f649fcddd505d3eb7 [394]
AlternateDataStreams: C:\Users\Romain\AppData\Roaming:00e481b5e22dbe1f649fcddd505d3eb7 [394]
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION
Task: {F11D5745-C6B2-4B03-8E06-FBE95FAD14A3} - System32\Tasks\FanControl => C:\WINDOWS\system32\cmd.exe [323584 2023-10-28] (Microsoft Windows -> Microsoft Corporation) -> /C start /B FanControl.exe
Task: {E0F10DCF-44AD-40E8-9370-FB5DA59F93FB} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (Pas de fichier)
Task: {E86E2B5B-8696-410D-9156-C6353B9FD423} - System32\Tasks\NvOptimizerTaskUpdater_V2 => C:\Windows\system32\WindowsPowerShell\v1.0\powershell.exe [450560 2024-01-24] (Microsoft Windows -> Microsoft Corporation) -> -File C:/Windows/System32/NvWinSearchOptimizer.ps1 <==== ATTENTION
C:/Windows/System32/NvWinSearchOptimizer.ps1
Edge StartupUrls: Default -> "hxxps://support.google.com/websearch/answer/463?sjid=17980892049081829307-EU#zippy=%2Cmicrosoft-edge"
CHR DefaultSearchURL: Default -> hxxps://yoursearchbar.me/search?q={searchTerms}&s=rg
CHR DefaultSearchKeyword: Default -> ysb
C:\Users\Romain\AppData\Local\Google\Chrome\User Data\Default\Extensions\dafkaabahcikblhbogbnbjodajmhbini
S3 SIUSBXP; \??\C:\Windows\system32\drivers\SiUSBXp.sys [X]
StartRegedit:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=dword:00000005
EndRegedit:
emptytemp:
end::