start:: CreateRestorePoint: cmd: Net stop wuauserv cmd: Rd /s /q %windir%\SoftwareDistribution\. CloseProcesses: EmptyTemp: EmptyEventLogs: Hosts: RemoveProxy: C:\Windows\Temp\*.* C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\* C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\* C:\Users\CurrentUserName\Appdata\Local\Temp\*.* C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service\*.* DeleteValue: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|AtlasVPN DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\\Software\Microsoft\Windows\CurrentVersion\Run|AtlasVPN] C:\Users\UTILIS~1\AppData\Local\Temp\tmp-p2v.xpi C:\Users\UTILIS~1\AppData\Local\Temp\tmp-xx5.xpi C:\Users\UTILIS~1\AppData\Local\Temp\mat-debug-10108.log C:\Users\UTILIS~1\AppData\Local\Temp\mat-debug-11376.log C:\Users\UTILIS~1\AppData\Local\Temp\mat-debug-11640.log C:\Users\UTILIS~1\AppData\Local\Temp\mat-debug-11820.log C:\Users\UTILIS~1\AppData\Local\Temp\mat-debug-12264.log C:\Users\UTILIS~1\AppData\Local\Temp\mat-debug-12528.log C:\Users\UTILIS~1\AppData\Local\Temp\mat-debug-13568.log C:\Users\UTILIS~1\AppData\Local\Temp\mat-debug-14264.log C:\Users\UTILIS~1\AppData\Local\Temp\mat-debug-14392.log C:\Users\UTILIS~1\AppData\Local\Temp\mat-debug-15508.log C:\Users\UTILIS~1\AppData\Local\Temp\mat-debug-1864.log C:\Users\UTILIS~1\AppData\Local\Temp\mat-debug-3792.log C:\Users\UTILIS~1\AppData\Local\Temp\mat-debug-4144.log C:\Users\UTILIS~1\AppData\Local\Temp\mat-debug-4588.log C:\Users\UTILIS~1\AppData\Local\Temp\mat-debug-4704.log C:\Users\UTILIS~1\AppData\Local\Temp\mat-debug-4908.log C:\Users\UTILIS~1\AppData\Local\Temp\mat-debug-5300.log C:\Users\UTILIS~1\AppData\Local\Temp\mat-debug-5472.log C:\Users\UTILIS~1\AppData\Local\Temp\mat-debug-8116.log C:\Users\UTILIS~1\AppData\Local\Temp\mat-debug-8212.log DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\AppData\Local\Temp\qa7LXJuw\RelKSetup.exe.FriendlyAppName DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\AppData\Local\Temp\qa7LXJuw\RelKSetup.exe.ApplicationCompany DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\AppData\Local\Programs\Opera\Launcher.exe.FriendlyAppName DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\AppData\Local\Programs\Opera\Launcher.exe.ApplicationCompany DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\program files (x86)\relevantknowledge\rlvknlg.exe.FriendlyAppName DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\program files (x86)\relevantknowledge\rlvknlg.exe.ApplicationCompany DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\games\world_of_tanks_eu\win64\worldoftanks.exe.FriendlyAppName DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\games\world_of_tanks_eu\win64\worldoftanks.exe.ApplicationCompany DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|Q:\140066.fra\Office14\MSTORE.EXE DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|Q:\%systemDrive%\oasys\shared\ClrTestHost.exe DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|Q:\%systemDrive%\oasys\shared\ClrTestHost_x86.exe DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|Q:\%windir%\system32\Control.exe DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|Q:\140066.fra\Office14\EXCELC.EXE DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|Q:\140066.fra\Office14\MSOUC.EXE DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|Q:\140066.fra\Office14\OIS.EXE DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|Q:\140066.fra\Office14\MOMM.EXE DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|Q:\140066.fra\Office14\WINWORDC.EXE DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|Q:\%SFT_MNT%\140066.fra\Office14\MSOSYNC.EXE DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|Q:\%commonprogramfiles%\microsoft shared\virtualization handler\OfficeVirt.exe DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|Q:\%SFT_MNT%\140066.fra\Office14\ONENOTEM.EXE DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|Q:\%commonprogramfiles%\microsoft shared\virtualization handler\MapiServer.exe DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|Q:\%windir%\system32\cmd.exe DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|Q:\%commonprogramfiles%\microsoft shared\virtualization handler\VirtualOWSSuppManager.exe DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|Q:\%commonprogramfiles%\microsoft shared\virtualization handler\VirtualSearchHost.exe DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|Q:\%systemroot%\system32\rundll32.exe DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\program files (x86)\bluestacks\hd-plus-service.exe.FriendlyAppName DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\program files (x86)\bluestacks\hd-plus-service.exe.ApplicationCompany DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|D:\Autorun.exe.FriendlyAppName DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\OneDrive\Bureau\Photos S\DiskInfoA64.exe.FriendlyAppName DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\OneDrive\Bureau\Photos S\DiskInfoA64.exe.ApplicationCompany DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\OneDrive\Bureau\Photos S\DiskInfoA32.exe.FriendlyAppName DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\OneDrive\Bureau\Photos S\DiskInfoA32.exe.ApplicationCompany DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\OneDrive\Bureau\Photos S\DiskInfo64.exe.FriendlyAppName DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\OneDrive\Bureau\Photos S\DiskInfo64.exe.ApplicationCompany DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\OneDrive\Bureau\Photos S\DiskInfo32.exe.FriendlyAppName DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\OneDrive\Bureau\Photos S\DiskInfo32.exe.ApplicationCompany DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\OneDrive\Bureau\SYLVIANE\Photos S\DiskInfoA64.exe.FriendlyAppName DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\OneDrive\Bureau\SYLVIANE\Photos S\DiskInfoA64.exe.ApplicationCompany DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\OneDrive\Bureau\SYLVIANE\Photos S\DiskInfoA32.exe.FriendlyAppName DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\OneDrive\Bureau\SYLVIANE\Photos S\DiskInfoA32.exe.ApplicationCompany DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\OneDrive\Bureau\SYLVIANE\Photos S\DiskInfo64.exe.FriendlyAppName DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\OneDrive\Bureau\SYLVIANE\Photos S\DiskInfo64.exe.ApplicationCompany DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\OneDrive\Bureau\SYLVIANE\Photos S\DiskInfo32.exe.FriendlyAppName DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\OneDrive\Bureau\SYLVIANE\Photos S\DiskInfo32.exe.ApplicationCompany DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Program Files (x86)\Mozilla Firefox\firefox.exe.FriendlyAppName DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\program files\kodi\kodi.exe.FriendlyAppName DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\program files\kodi\kodi.exe.ApplicationCompany DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Program Files\AtlasVPN\Bin\AtlasVPN.exe.FriendlyAppName DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Program Files\AtlasVPN\Bin\AtlasVPN.exe.ApplicationCompany DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\AppData\Local\PlariumPlay\9.5.0-0.0.0\PlariumPlay.exe.FriendlyAppName DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\AppData\Local\PlariumPlay\9.5.0-0.0.0\PlariumPlay.exe.ApplicationCompany DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\AppData\Local\PlariumPlay\9.6.0-0.0.3\PlariumPlay.exe.FriendlyAppName DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\AppData\Local\PlariumPlay\9.6.0-0.0.3\PlariumPlay.exe.ApplicationCompany DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\AppData\Local\PlariumPlay\StandAloneApps\raid-shadow-legends\114795\Raid.exe.FriendlyAppName DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\AppData\Local\PlariumPlay\StandAloneApps\raid-shadow-legends\114795\Raid.exe.ApplicationCompany DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\AppData\Local\PlariumPlay\StandAloneApps\raid-shadow-legends\115158\Raid.exe.FriendlyAppName DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\AppData\Local\PlariumPlay\StandAloneApps\raid-shadow-legends\115158\Raid.exe.ApplicationCompany DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\AppData\Local\PlariumPlay\9.8.0-0.0.0\PlariumPlay.exe.FriendlyAppName DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\AppData\Local\PlariumPlay\9.8.0-0.0.0\PlariumPlay.exe.ApplicationCompany DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\AppData\Local\PlariumPlay\StandAloneApps\raid-shadow-legends\127309\Raid.exe.FriendlyAppName DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\AppData\Local\PlariumPlay\StandAloneApps\raid-shadow-legends\127309\Raid.exe.ApplicationCompany DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\AppData\Local\PlariumPlay\9.9.0-0.0.0\PlariumPlay.exe.FriendlyAppName DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\AppData\Local\PlariumPlay\9.9.0-0.0.0\PlariumPlay.exe.ApplicationCompany DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\AppData\Local\Temp\qa7LXJuw\RelKSetup.exe.FriendlyAppName DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\AppData\Local\Temp\qa7LXJuw\RelKSetup.exe.ApplicationCompany DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\AppData\Local\Programs\Opera\Launcher.exe.FriendlyAppName DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\AppData\Local\Programs\Opera\Launcher.exe.ApplicationCompany DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\program files (x86)\relevantknowledge\rlvknlg.exe.FriendlyAppName DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\program files (x86)\relevantknowledge\rlvknlg.exe.ApplicationCompany DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\games\world_of_tanks_eu\win64\worldoftanks.exe.FriendlyAppName DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\games\world_of_tanks_eu\win64\worldoftanks.exe.ApplicationCompany DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|Q:\140066.fra\Office14\MSTORE.EXE DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|Q:\%systemDrive%\oasys\shared\ClrTestHost.exe DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|Q:\%systemDrive%\oasys\shared\ClrTestHost_x86.exe DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|Q:\%windir%\system32\Control.exe DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|Q:\140066.fra\Office14\EXCELC.EXE DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|Q:\140066.fra\Office14\MSOUC.EXE DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|Q:\140066.fra\Office14\OIS.EXE DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|Q:\140066.fra\Office14\MOMM.EXE DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|Q:\140066.fra\Office14\WINWORDC.EXE DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|Q:\%SFT_MNT%\140066.fra\Office14\MSOSYNC.EXE DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|Q:\%commonprogramfiles%\microsoft shared\virtualization handler\OfficeVirt.exe DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|Q:\%SFT_MNT%\140066.fra\Office14\ONENOTEM.EXE DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|Q:\%commonprogramfiles%\microsoft shared\virtualization handler\MapiServer.exe DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|Q:\%windir%\system32\cmd.exe DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|Q:\%commonprogramfiles%\microsoft shared\virtualization handler\VirtualOWSSuppManager.exe DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|Q:\%commonprogramfiles%\microsoft shared\virtualization handler\VirtualSearchHost.exe DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|Q:\%systemroot%\system32\rundll32.exe DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\program files (x86)\bluestacks\hd-plus-service.exe.FriendlyAppName DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\program files (x86)\bluestacks\hd-plus-service.exe.ApplicationCompany DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|D:\Autorun.exe.FriendlyAppName DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\OneDrive\Bureau\Photos S\DiskInfoA64.exe.FriendlyAppName DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\OneDrive\Bureau\Photos S\DiskInfoA64.exe.ApplicationCompany DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\OneDrive\Bureau\Photos S\DiskInfoA32.exe.FriendlyAppName DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\OneDrive\Bureau\Photos S\DiskInfoA32.exe.ApplicationCompany DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\OneDrive\Bureau\Photos S\DiskInfo64.exe.FriendlyAppName DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\OneDrive\Bureau\Photos S\DiskInfo64.exe.ApplicationCompany DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\OneDrive\Bureau\Photos S\DiskInfo32.exe.FriendlyAppName DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\OneDrive\Bureau\Photos S\DiskInfo32.exe.ApplicationCompany DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\OneDrive\Bureau\SYLVIANE\Photos S\DiskInfoA64.exe.FriendlyAppName DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\OneDrive\Bureau\SYLVIANE\Photos S\DiskInfoA64.exe.ApplicationCompany DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\OneDrive\Bureau\SYLVIANE\Photos S\DiskInfoA32.exe.FriendlyAppName DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\OneDrive\Bureau\SYLVIANE\Photos S\DiskInfoA32.exe.ApplicationCompany DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\OneDrive\Bureau\SYLVIANE\Photos S\DiskInfo64.exe.FriendlyAppName DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\OneDrive\Bureau\SYLVIANE\Photos S\DiskInfo64.exe.ApplicationCompany DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\OneDrive\Bureau\SYLVIANE\Photos S\DiskInfo32.exe.FriendlyAppName DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\OneDrive\Bureau\SYLVIANE\Photos S\DiskInfo32.exe.ApplicationCompany DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Program Files (x86)\Mozilla Firefox\firefox.exe.FriendlyAppName DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\program files\kodi\kodi.exe.FriendlyAppName DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\program files\kodi\kodi.exe.ApplicationCompany DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Program Files\AtlasVPN\Bin\AtlasVPN.exe.FriendlyAppName DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Program Files\AtlasVPN\Bin\AtlasVPN.exe.ApplicationCompany DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\AppData\Local\PlariumPlay\9.5.0-0.0.0\PlariumPlay.exe.FriendlyAppName DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\AppData\Local\PlariumPlay\9.5.0-0.0.0\PlariumPlay.exe.ApplicationCompany DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\AppData\Local\PlariumPlay\9.6.0-0.0.3\PlariumPlay.exe.FriendlyAppName DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\AppData\Local\PlariumPlay\9.6.0-0.0.3\PlariumPlay.exe.ApplicationCompany DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\AppData\Local\PlariumPlay\StandAloneApps\raid-shadow-legends\114795\Raid.exe.FriendlyAppName DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\AppData\Local\PlariumPlay\StandAloneApps\raid-shadow-legends\114795\Raid.exe.ApplicationCompany DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\AppData\Local\PlariumPlay\StandAloneApps\raid-shadow-legends\115158\Raid.exe.FriendlyAppName DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\AppData\Local\PlariumPlay\StandAloneApps\raid-shadow-legends\115158\Raid.exe.ApplicationCompany DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\AppData\Local\PlariumPlay\9.8.0-0.0.0\PlariumPlay.exe.FriendlyAppName DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\AppData\Local\PlariumPlay\9.8.0-0.0.0\PlariumPlay.exe.ApplicationCompany DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\AppData\Local\PlariumPlay\StandAloneApps\raid-shadow-legends\127309\Raid.exe.FriendlyAppName DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\AppData\Local\PlariumPlay\StandAloneApps\raid-shadow-legends\127309\Raid.exe.ApplicationCompany DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\AppData\Local\PlariumPlay\9.9.0-0.0.0\PlariumPlay.exe.FriendlyAppName DeleteValue: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Utilisateur\AppData\Local\PlariumPlay\9.9.0-0.0.0\PlariumPlay.exe.ApplicationCompany DeleteKey: HKCU\SOFTWARE\Software DeleteKey: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\SOFTWARE\Software C:\ProgramData\McAfee C:\Users\Utilisateur]\Desktop\facebook.lnk DeleteKey: HKCU\SOFTWARE\Opera Software DeleteKey: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\SOFTWARE\Opera Software C:\Users\Utilisateur\AppData\Roaming\Opera Software C:\Users\Utilisateur\AppData\Local\Opera Software C:\Users\Utilisateur\AppData\Local\Programs\Opera HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\...\Run: [AtlasVPN] => "C:\Program Files\AtlasVPN\Bin\AtlasVPN.exe" -h (Pas de fichier) S2 cfbackd; "E:\Disk Drill\cfbackd.w32.exe" [X] HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\133.0.6943.142\Installer\chrmstp.exe [2025-02-27] (Google LLC -> Google LLC) Task: {F5D026F2-BD49-49A3-8702-F12C43101FEB} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem135.0.7023.0{F2906513-FB8D-4627-9AEC-9958104F1B7B} => C:\Program Files (x86)\Google\GoogleUpdater\135.0.7023.0\updater.exe [5745760 2025-02-19] (Google LLC -> Google LLC) Task: {8E2B2CC8-D776-4E6D-B8F6-4E702E647792} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [682560 2025-03-06] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (l'élément de données a 6 caractères en plus). Task: {7E475F6B-C5C1-4CA5-AD53-266E9E3253CD} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-2699182137-3270908012-3895445023-1001 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [682560 2025-03-06] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (l'élément de données a 6 caractères en plus). Task: {287D7ED0-592F-46AC-8A70-B5B1B0F31AFA} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [34880 2025-03-06] (Mozilla Corporation -> Mozilla Foundation) Task: {6293B7B3-8EF2-4426-B42A-6C0E521027BA} - System32\Tasks\VS Revo Group\RevoHelperFreeStartup => C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUninHelper.exe [4053672 2024-12-10] (VS REVO GROUP OOD -> VS Revo Group Ltd.) Edge Extension: (Google Docs hors connexion) - C:\Users\Utilisateur\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-12-23]hxxps://clients2.google.com/service/update2/crx Edge Extension: (Edge relevant text changes) - C:\Users\Utilisateur\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-01-24]hxxps://edge.microsoft.com/extensionwebstorebase/v1/crx Edge HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\SOFTWARE\Microsoft\Edge\Extensions\...\Edge\Extension: [eiaeiblijfjekdanodkjadfinkhbfgcd] Edge HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\SOFTWARE\Microsoft\Edge\Extensions\...\Edge\Extension: [fjoaledfpmneenckfbpdfhkmimnjocfa] Edge HKLM-x32\...\Edge\Extension: [ihcjicgdanjaechkgeegckofjjedodee] FF Extension: (Malwarebytes Browser Guard) - C:\Users\Utilisateur\AppData\Roaming\Mozilla\Firefox\Profiles\uws7xqes.default\Extensions\{242af0bb-db11-4734-b7a0-61cb8a9b20fb}.xpi [2024-11-23] FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL [2011-04-05] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=3.0.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=3.0.7 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN) CHR HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [eiaeiblijfjekdanodkjadfinkhbfgcd] CHR HKU\S-1-5-21-2699182137-3270908012-3895445023-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fjoaledfpmneenckfbpdfhkmimnjocfa] CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee] 2024-08-14 09:18 - 2024-11-23 14:25 - 000027345 _____ () C:\Users\Utilisateur\AppData\Local\PlariumPlay.log CustomCLSID: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001_Classes\CLSID\{1668633d-bb0e-a3d4-3b7b-acfc671dc77e}\localserver32 -> "C:\Users\Utilisateur\AppData\Local\PlariumPlay\9.8.0-0.0.0\dotnet\info\PlariumPlayInfo.exe" -ToastActivated => Pas de fichier CustomCLSID: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001_Classes\CLSID\{220f6c23-bf82-cf74-6dc5-bd2664edfacd}\localserver32 -> "E:\Disk Drill\DD.exe" -ToastActivated => Pas de fichier CustomCLSID: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001_Classes\CLSID\{3e5dba08-7ec3-cc88-1f18-0cf79ce7ade4}\localserver32 -> "C:\Program Files\AtlasVPN\Bin\AtlasVPN.exe" -ToastActivated => Pas de fichier CustomCLSID: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001_Classes\CLSID\{a1387b99-1834-3fc7-4e13-e30645633ec4}\localserver32 -> "C:\Users\Utilisateur\AppData\Local\PlariumPlay\9.6.0-0.0.3\dotnet\info\PlariumPlayInfo.exe" -ToastActivated => Pas de fichier CustomCLSID: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001_Classes\CLSID\{b6a0f955-7068-7f36-7a7a-b7d71a394920}\localserver32 -> "C:\Users\Utilisateur\AppData\Local\PlariumPlay\9.7.0-0.0.0\dotnet\info\PlariumPlayInfo.exe" -ToastActivated => Pas de fichier CustomCLSID: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001_Classes\CLSID\{c51cd249-13d4-a313-de06-103f5463085c}\localserver32 -> "C:\Users\Utilisateur\AppData\Local\PlariumPlay\9.5.0-0.0.0\dotnet\info\PlariumPlayInfo.exe" -ToastActivated => Pas de fichier CustomCLSID: HKU\S-1-5-21-2699182137-3270908012-3895445023-1001_Classes\CLSID\{fe478704-568a-1f53-cb8e-7820c7c319d0}\localserver32 -> "C:\Users\Utilisateur\AppData\Local\PlariumPlay\9.9.0-0.0.0\dotnet\info\PlariumPlayInfo.exe" -ToastActivated => Pas de fichier FirewallRules: [TCP Query User{2C480F87-DD52-4D62-8E18-4E4F2594D1E2}C:\games\world_of_tanks_eu\win64\worldoftanks.exe] => (Allow) C:\games\world_of_tanks_eu\win64\worldoftanks.exe => Pas de fichier FirewallRules: [UDP Query User{1BC39DDE-BFFC-451E-A170-9BE7E631E77C}C:\games\world_of_tanks_eu\win64\worldoftanks.exe] => (Allow) C:\games\world_of_tanks_eu\win64\worldoftanks.exe => Pas de fichier FirewallRules: [TCP Query User{0DF45FB3-F372-40CE-830D-D7025A3233A6}C:\program files\kodi\kodi.exe] => (Allow) C:\program files\kodi\kodi.exe => Pas de fichier FirewallRules: [UDP Query User{0C7DA8BE-85C4-454A-81CA-1F9EE242A3C8}C:\program files\kodi\kodi.exe] => (Allow) C:\program files\kodi\kodi.exe => Pas de fichier FirewallRules: [{972A791F-9559-49E4-9DC7-748FB60BF4D4}] => (Block) C:\program files\kodi\kodi.exe => Pas de fichier FirewallRules: [{32A71F49-6B7B-437A-A519-2FF6F78F4017}] => (Block) C:\program files\kodi\kodi.exe => Pas de fichier FirewallRules: [{9B749974-5496-40C8-AB92-A276BCDFB48A}] => (Allow) C:\Program Files (x86)\BlueStacks X\Cloud Game.exe => Pas de fichier FirewallRules: [{58968C1D-A77A-4872-B111-143D6CEA408B}] => (Allow) C:\Users\Utilisateur\Downloads\4ddig-for-windows_11727678618314242001.exe => Pas de fichier FirewallRules: [{6360E39D-8D37-4851-931A-69D6BBC3AA95}] => (Allow) C:\Users\Utilisateur\Downloads\4ddig-for-windows_11727678618314242001.exe => Pas de fichier FirewallRules: [{55D51A7F-CD0C-4A86-AAD6-F12D8C6545F1}] => (Allow) C:\Program Files (x86)\Tenorshare\Tenorshare 4DDiG\NetFrameCheck.exe => Pas de fichier FirewallRules: [{611EC0B9-C91D-444F-BC08-208FB33781AE}] => (Allow) C:\Program Files (x86)\Tenorshare\Tenorshare 4DDiG\NetFrameCheck.exe => Pas de fichier HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CleverFiles Disk Drill (x64)\Disk Drill.lnk C:\Users\Public\Desktop\Disk Drill.lnk C:\Users\Utilisateur\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk StartBatch: del /s /q C:\Windows\prefetch\*.* del /s /q "%userprofile%\AppData\Local\Temp\*.*" del /s /q "%userprofile%\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\*.*" del /s /q "%userprofile%\AppData\LocalLow\Microsoft\CryptnetUrlCache\Metada\*.*" del /s /q "%userprofile%\AppData\Local\Microsoft\Windows\History\*.*" del /s /q "%userprofile%\AppData\Local\Microsoft\Windows\Temporary Internet Files\*.*" del /s /q "%userprofile%\AppData\Roaming\Microsoft\Windows\Recent\*.lnk" For /D %%d In ("%userprofile%\AppData\Local\Mozilla\Firefox\Profiles\*") Do (If Exist "%%d\Cache2" Del /s /q "%%d\Cache2\*.*") del /s /q "%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Code Cache\Js\." del /s /q "%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Cache\*.*" del /s /q "%userprofile%\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\Js\." del /s /q "%userprofile%\AppData\Local\Microsoft\Edge\User Data\Default\Cache\Cache_Data\." For /D %%d In ("%userprofile%\AppData\Local\Thunderbird\Profiles\*") Do (If Exist "%%d\Cache2" Del /s /q "%%d\Cache2\*.*") For /D %%d In ("%userprofile%\AppData\Roaming\Mozilla\Firefox\Profiles\*") Do (If Exist "%%d\cookies.sqlite" Del /s /q "%%d\cookies.sqlite") For /D %%d In ("%userprofile%\AppData\Roaming\Mozilla\Firefox\Profiles\*") Do (If Exist "%%d\Places.Sqlite" Del /s /q "%%d\Places.Sqlite") del /s /q "%userprofile%\AppData\Local\Google\Chrome\User Data\Default\History" del /s /q "%userprofile%\AppData\Local\Microsoft\Edge\User Data\Default\History" ipconfig /release ipconfig /renew ipconfig /flushdns ipconfig /registerdns netsh winsock reset netsh advfirewall reset netsh advfirewall set allprofiles state on netsh winhttp reset proxy bitsadmin /reset /allusers net start sdrsvc net start vss net start rpcss net start eventsystem net start winmgmt net start msiserver net start bfe net start trustedinstaller net start windefend net start mpssvc net start mpsdrv Winmgmt /salvagerepository Winmgmt /resetrepository Winmgmt /resyncperf Endbatch: cmd: Net start wuauserv Reboot: end::