first line (icacls C:\Users\Kaique-Vidal\AppData\Local\Temp /save "%userprofile%\temp" /t /c)
result: 165 files successfully processed; failed to process 0 files
second line(takeown /f C:\Users\Kaique-Vidal\AppData\Local\Temp /r)
result:C:\Windows\System32>icacls C: \Users\Kaique-Vidal\AppData\Local\Temp /grant administrators:F /t /c
Invalid parameter "\Users\Kaique-Vidal\AppData\Local\Temp"
third line (icacls C: \Users\Kaique-Vidal\AppData\Local\Temp /grant administrators:F /t /c)
result: C:\Windows\System32>icacls C: \Users\Kaique-Vidal\AppData\Local\Temp /grant administrators:F /t /c
Invalid parameter "\Users\Kaique-Vidal\AppData\Local\Temp"
fourth line (del C:\Users\Kaique-Vidal\AppData\Local\Temp)
result: The file is already being used by another process.
fifth line: C:\Windows\System32>icacls C:\ Users\Kaique-Vidal\AppData\Local /restore "%userprofile%\temp"
Invalid parameter "Users\Kaique-Vidal\AppData\Local"
When restarting, it is no longer opening any browser at first. several files appear at first.. when you locate them they are named: chrome_url_fetcher_2652_(random number) and within them is a crx file with the name extension_1_0_64. in addition to those that always appear. there is also a file called: SquirrelSetup. it looks like this:
023-09-14 23:52:02> Program: Starting Squirrel Updater: --uninstall --msiUninstall --source=default
2023-09-14 23:52:02> Program: Starting uninstall for app:
2023-09-14 23:52:02> Program: CheckAndTryDeleteInstallSource msiUninstall: True
2023-09-14 23:52:02> RegistryService: TryGetRegKey: HKEY_CURRENT_USER\Software\Microsoft\Office\Teams\InstallSource does not exist
2023-09-14 23:52:02> Program: CheckAndTryDeleteInstallSource isInstallSourceExpected: False
2023-09-14 23:52:02> Program: CheckAndTryDeleteInstallSource: MSI uninstall initiated, but no MSI-installed Teams found. Quitting
2023-09-14 23:52:02> Program: Uninstall: checkAndTryDeleteInstallSource? False
Finally, there is:__PSScriptPolicyTest_0acgf2dy.sgn.ps1. it says that the PowerShell test file to determine AppLocker lockdown mode.
just that.