re
Lance Farbar
Copies les lignes suivantes dans le cadre rouge
start::
CloseProcesses:
CreateRestorePoint:
cmd: Net stop wuauserv
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
GroupPolicy: Restriction - Edge <==== ATTENTION
GroupPolicy-Firefox: Restriction <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3: <==== ATTENTION (Restriction - Zones)
S2 ElevationService; C:\Program Files (x86)\Wondershare\drfone\Addins\Transfer\ElevationService.exe [X]
S3 netprotection_network_filter2; System32\drivers\netprotection_network_filter2.sys [X]
CustomCLSID: HKU\S-1-5-21-2778292364-3399344871-1874558377-1005_Classes\CLSID\{CB965DF1-B8EA-49C7-BDAD-5457FDC1BF92}\InprocServer32 -> C:\Users\Alice\AppData\Local\Microsoft\TeamsMeetingAddin\1.0.20244.4\x64\Microsoft.Teams.AddinLoader.dll => Pas de fichier
CustomCLSID: HKU\S-1-5-21-2778292364-3399344871-1874558377-1005_Classes\CLSID\{d1b22d3d-8585-53a6-acb3-0e803c7e8d2a}\localserver32 -> "C:\Users\Alice\AppData\Local\Microsoft\Teams\current\Teams.exe" --toast => Pas de fichier
FirewallRules: [UDP Query User{E251C16A-93E6-46F7-B5B1-CFA5586D13A9}C:\users\alice\appdata\local\microsoft\teams\current\teams.exe] => (Block) C:\users\alice\appdata\local\microsoft\teams\current\teams.exe => Pas de fichier
FirewallRules: [TCP Query User{9DC94226-80B8-490B-A0D7-2DAFD46F1266}C:\users\alice\appdata\local\microsoft\teams\current\teams.exe] => (Block) C:\users\alice\appdata\local\microsoft\teams\current\teams.exe => Pas de fichier
FirewallRules: [UDP Query User{D0CAF3C6-72D6-4E6A-8FE8-A4DF0104F7B6}C:\users\alice\appdata\local\microsoft\teams\current\teams.exe] => (Allow) C:\users\alice\appdata\local\microsoft\teams\current\teams.exe => Pas de fichier
FirewallRules: [TCP Query User{5A6CA960-4131-4373-9C9E-B595EE4909FF}C:\users\alice\appdata\local\microsoft\teams\current\teams.exe] => (Allow) C:\users\alice\appdata\local\microsoft\teams\current\teams.exe => Pas de fichier
FirewallRules: [{2A35B47C-3E35-43F0-B43D-BA701177FC81}] => (Block) C:\Program Files (x86)\Avira\SoftwareUpdater\avirasoftwareupdatertoastnotificationsbridge.exe => Pas de fichier
FirewallRules: [{0F9BE82C-1249-46D0-8FE0-2DBB2A9FCB01}] => (Allow) C:\Program Files (x86)\Avira\SoftwareUpdater\avirasoftwareupdatertoastnotificationsbridge.exe => Pas de fichier
FirewallRules: [{33A86E2D-6502-4923-8894-3BB2D98D81DA}] => (Allow) C:\Program Files (x86)\Avira\SoftwareUpdater\avirasoftwareupdatertoastnotificationsbridge.exe => Pas de fichier
StartRegedit:
Windows Registry Editor Version 5.00
[-HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains]
@=""
[-HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains]
[-HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P]
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains]
@=""
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains]
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P]
EndRegedit:
C:\Windows\Temp\ *.*
C:\Users\CurrentUserName\Appdata\Local\Temp\ *.*
C:\Windows\SoftwareDistribution\Download\ *
EmptyTemp:
cmd: dism.exe /online /cleanup-image /restorehealth
cmd: sfc /scannow
cmd: Net start wuauserv
Reboot:
end::
Corrige et heberge le rapport fixlog
@+