start:: SystemRestore: On CreateRestorePoint: CloseProcesses: Hosts: RemoveProxy: HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION HKLM\Software\...\Authentication\Credential Providers: [{503739d0-4c5e-4cfd-b3ba-d881334f0df2}] -> BootExecute: autocheck autochk * sdnclean64.exe FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe Handler: WSISAllmytubechrome - {4724F5AF-4E6D-41CA - Pas de fichier FF HKU\S-1-5-21-3397517708-3417149383-1571176189-1000\...\Firefox\Extensions: [ISAllmytube@iSkysoft.com] - C:\Program Files (x86)\Aimersoft\Aimersoft iTube Studio\BrowserPlugin\isallmytube@iskysoft.com_xpi => non trouvé(e) CHR HKLM\...\Chrome\Extension: [bkfajajhmehapdgmgjejilcbjmhmebkl] - hxxps://clients2.google.com/service/update2/crx CHR HKU\S-1-5-21-3397517708-3417149383-1571176189-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bkfajajhmehapdgmgjejilcbjmhmebkl] - hxxps://clients2.google.com/service/update2/crx CHR HKU\S-1-5-21-3397517708-3417149383-1571176189-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [dhdgffkkebhmkfjojejmpbldmpobfkfo] - hxxp://clients2.google.com/service/update2/crx U3 idsvc; pas de ImagePath S4 IUFileFilter; \??\C:\Program Files (x86)\IObit\IObit Uninstaller\drivers\win10_amd64\IUFileFilter.sys [X] 2019-08-15 16:42 - 2018-08-22 16:10 - 000000000 ____D C:\Users\PLAISANCE\AppData\Local\AVAST Software 2019-08-15 16:42 - 2016-12-01 13:22 - 000000000 ____D C:\ProgramData\AVAST Software 2018-01-06 11:44 - 2018-01-06 11:44 - 000000052 _____ () C:\Users\PLAISANCE\AppData\Local\fdb94zxvtr ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Pas de fichier ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Pas de fichier ContextMenuHandlers1: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => -> Pas de fichier ContextMenuHandlers4: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => -> Pas de fichier ContextMenuHandlers6: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => -> Pas de fichier WMI:subscription\__FilterToConsumerBinding->CommandLineEventConsumer.Name=\"BVTConsumer\"",Filter="__EventFilter.Name=\"BVTFilter\":: WMI:subscription\__EventFilter->BVTFilter::[Query => SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99] WMI:subscription\CommandLineEventConsumer->BVTConsumer::[CommandLineTemplate => cscript KernCap.vbs][WorkingDirectory => C:\\tools\\kernrate] AlternateDataStreams: C:\ProgramData\TEMP:FCA8C9CD [266] HKLM\...\StartupApproved\Run32: => "IObit Malware Fighter" HKLM\...\StartupApproved\Run32: => "Aimersoft Helper Compact.exe" EmptyTemp: cmd: ipconfig /flushdns end::