re
pas d'infection a priori
1/
https://support.mozilla.org/fr/kb/resta ... rque-pages
2/ Lance Farbar
Copies les lignes suivantes dans le cadre rouge
start::
CloseProcesses:
CreateRestorePoint:
cmd: Net stop wuauserv
HKU\S-1-5-21-3948649708-2309024466-3722208386-1000\...\Run: [electron.app.Loom] => C:\Users\Luc\AppData\Local\Programs\Loom\Loom.exe --process-start-args "--loomHidden" (Pas de fichier)
HKU\S-1-5-21-3948649708-2309024466-3722208386-1000\...\MountPoints2: {070bdfa6-aa2c-11ec-84d3-d8cb8a1aeac5} - "H:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-3948649708-2309024466-3722208386-1000\...\MountPoints2: {070bdfc9-aa2c-11ec-84d3-d8cb8a1aeac5} - "H:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-3948649708-2309024466-3722208386-1000\...\MountPoints2: {147a444f-8f88-11ed-84f3-d8cb8a1aeac5} - "H:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-3948649708-2309024466-3722208386-1000\...\MountPoints2: {147a4475-8f88-11ed-84f3-d8cb8a1aeac5} - "H:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-3948649708-2309024466-3722208386-1000\...\MountPoints2: {3caadaa2-9933-11eb-8492-d8cb8a1aeac5} - "H:\HiSuiteDownLoader.exe"
U3 TrueSight; \??\C:\Windows\System32\drivers\truesight.sys [X]
CustomCLSID: HKU\S-1-5-21-3948649708-2309024466-3722208386-1000_Classes\CLSID\{5D094BAA-E1E7-406A-9B33-7219A5CBC6D9}\InprocServer32 -> C:\Users\Luc\AppData\Local\BraveSoftware\Update\1.3.361.133\psuser_64.dll => Pas de fichier
FirewallRules: [TCP Query User{760CF221-9278-4951-A5D3-CBE39D4D67E1}C:\users\luc\appdata\local\programs\opera\70.0.3728.106\opera.exe] => (Allow) C:\users\luc\appdata\local\programs\opera\70.0.3728.106\opera.exe => Pas de fichier
FirewallRules: [UDP Query User{8CD7EAAF-F2DD-4A95-B18E-5123D0B980D6}C:\users\luc\appdata\local\programs\opera\70.0.3728.106\opera.exe] => (Allow) C:\users\luc\appdata\local\programs\opera\70.0.3728.106\opera.exe => Pas de fichier
FirewallRules: [{4BACCD9E-0878-460E-83BC-244C2DCFF471}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.63.76.0_x86__kzf8qxf38zg5c\Skype\Skype.exe => Pas de fichier
FirewallRules: [{473B35E6-C0C0-4487-9A4B-365DD93DD4E5}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.63.76.0_x86__kzf8qxf38zg5c\Skype\Skype.exe => Pas de fichier
FirewallRules: [{BECBB8C7-92B6-4705-8F1A-19B7519FB58C}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.63.76.0_x86__kzf8qxf38zg5c\Skype\Skype.exe => Pas de fichier
FirewallRules: [{C249A90C-D465-44DA-BE9C-3FA318E31DDB}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.63.76.0_x86__kzf8qxf38zg5c\Skype\Skype.exe => Pas de fichier
FirewallRules: [TCP Query User{7F84EED9-D71E-4E4C-9EC2-83B9831C7671}C:\users\luc\appdata\local\microsoft\teams\current\teams.exe] => (Allow) C:\users\luc\appdata\local\microsoft\teams\current\teams.exe => Pas de fichier
FirewallRules: [UDP Query User{EB2FAA6C-3933-4744-9DD0-26EE3E8E6577}C:\users\luc\appdata\local\microsoft\teams\current\teams.exe] => (Allow) C:\users\luc\appdata\local\microsoft\teams\current\teams.exe => Pas de fichier
FirewallRules: [{4E743556-B3B5-464F-98C1-11FF612729A0}] => (Allow) C:\Users\Luc\AppData\Local\Temp\7zS6277\Installer\hpbcsiInstaller.exe => Pas de fichier
FirewallRules: [{1AC72475-09D3-47C2-B6B5-AC661EBBC5A4}] => (Allow) C:\Users\Luc\AppData\Local\Temp\7zS6277\Installer\hpbcsiInstaller.exe => Pas de fichier
StartBatch:
For /D %%d In ("%userprofile%\AppData\Local\Mozilla\Firefox\Profiles\*") Do (If Exist "%%d\Cache2" Del /s /q "%%d\Cache2\*.*")
del /s /q "%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Cache\*.*"
del /s /q "%userprofile%\AppData\Local\Microsoft\Edge\User Data\Default\Cache\*.*"
del /s /q "%userprofile%\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Cache\*.*"
del /s /q "%userprofile%\AppData\Local\Opera Software\*"
Endbatch:
C:\Windows\Temp\ *.*
C:\Users\CurrentUserName\Appdata\Local\Temp\ *.*
C:\Windows\SoftwareDistribution\Download\ *
EmptyTemp:
cmd: dism.exe /online /cleanup-image /restorehealth
cmd: sfc /scannow
cmd: Net start wuauserv
Reboot:
end::
Corrige et heberge le rapport fixlog
@+