start::
CreateRestorePoint:
CloseProcesses:
Hosts:
RemoveProxy:
GroupPolicy: Restriction ? <==== ATTENTION
Task: {8A7A5574-8E30-4058-BD4A-0292604F5310} - System32\Tasks\{161BB3AD-7682-4386-854D-A11036DE1EEF} => C:\Windows\system32\pcalua.exe -a "C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BP1YZXZC\MP71[1].exe" -d C:\Users\user\Desktop
BHO: Protection IE Trend Micro -> {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} -> Pas de fichier
BHO-x32: Protection IE Trend Micro -> {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} -> Pas de fichier
CHR HKLM-x32\...\Chrome\Extension: [dflinnddekagfkncpgojoppgnppfkbkj] - <pas de Path/update_url>
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ohhcpmplhhiiaoiddkfboafbhiknefdf] - hxxps://clients2.google.com/service/update2/crx
S4 LMIRfsClientNP; pas de ImagePath
S3 TBPanel; pas de ImagePath
S3 SANDRA; \??\C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2014.SP1a\WNt500x64\Sandra.sys [X]
AlternateDataStreams: C:\Users\user\Desktop\sacha s'avance.jpg:com.dropbox.attributes [318]
IE trusted site: HKU\S-1-5-21-2880688410-515900543-6404032-1000\...\alta.be -> hxxp://bureau.alta.be
MSCONFIG\startupreg: SyncService => "C:\Program Files (x86)\SYNCING.NET Technologies\SYNCING.NET\bin\SyncService.exe" /silent
EmptyTemp:
cmd: ipconfig /flushdns
end::