start::
closeprocesses:
createrestorepoint:
virustotal: C:\Windows\System32\SppExtComObj.Exe
CustomCLSID: HKU\S-1-5-21-2764081607-3401011857-487964011-1001_Classes\CLSID\{0D327DA6-B4DF-4842-B833-2CFF84F0948F}\localserver32 -> D:\Autodesk\AutoCAD 2017\acad.exe /Automation => Pas de fichier
CustomCLSID: HKU\S-1-5-21-2764081607-3401011857-487964011-1001_Classes\CLSID\{720DB9AF-D62C-4ED0-A377-429C22312852}\localserver32 -> D:\Autodesk\AutoCAD 2017\acad.exe => Pas de fichier
CustomCLSID: HKU\S-1-5-21-2764081607-3401011857-487964011-1001_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}\InprocServer32 -> D:\Autodesk\AutoCAD 2017\fr-FR\acadficn.dll => Pas de fichier
ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Pas de fichier
ContextMenuHandlers1: [DIALuxShellExtension] -> {F23E3460-D1B1-4F51-8C3D-E5D91E3C71C8} => C:\Program Files\DIAL GmbH\DIALux\Dial.ShellExtension.x64.dll -> Pas de fichier
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => -> Pas de fichier
BHO: True Key Helper -> {0F4B8786-5502-4803-8EBC-F652A1153BB6} -> C:\Program Files\McAfee\TrueKey\MSIE\truekey_ie64.dll => Pas de fichier
BHO-x32: True Key Helper -> {0F4B8786-5502-4803-8EBC-F652A1153BB6} -> C:\Program Files\McAfee\TrueKey\MSIE\truekey_ie.dll => Pas de fichier
Toolbar: HKLM - True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\McAfee\TrueKey\MSIE\truekey_ie64.dll Pas de fichier
Toolbar: HKLM-x32 - True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\McAfee\TrueKey\MSIE\truekey_ie.dll Pas de fichier
HKU\S-1-5-21-2764081607-3401011857-487964011-1001\...\StartupApproved\Run: => "Chromium"
C:\Windows\System32\SppExtComObj.Exe
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
HKU\S-1-5-21-2764081607-3401011857-487964011-1001\...\Run: [Chromium] => "c:\users\b-ami\appdata\local\chromium\application\chrome.exe" --auto-launch-at-startup --profile-directory="Default" --restore-last-session
HKU\S-1-5-21-2764081607-3401011857-487964011-1001\...\Policies\Explorer: []
Lsa: [Notification Packages] scecli C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter "C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter"
Startup: C:\Users\b-ami\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DS4Windows.lnk [2018-07-21]
ShortcutTarget: DS4Windows.lnk -> C:\Users\b-ami\Desktop\DS4Windows_1.4.123_x64\DS4Windows\DS4Windows.exe (Pas de fichier)
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
Task: {75F87FFA-014F-4691-B5CF-080ED613E76C} - System32\Tasks\Microsoft\Windows\Setup\EOSNotify => C:\WINDOWS\system32\EOSNotify.exe
Task: {E44440CA-5D54-4386-9662-7AD6F40D665F} - System32\Tasks\{E4AF9A02-5F10-4FE2-A799-57D89133D274} => C:\WINDOWS\system32\pcalua.exe -a C:\Users\b-ami\AppData\Local\{3356050A-17FE-69B2-7A66-4C5A5E0EB0C2}\uninst.exe -c -FN=""-P=/Uninstall /s /noun /DelSelfDir
CHR HKU\S-1-5-21-2764081607-3401011857-487964011-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
2017-12-12 20:11 - 2017-12-13 21:11 - 000000052 _____ () C:\Users\b-ami\AppData\Local\YdozKPUZep
cmd: netsh advfirewall reset
emptytemp:
end::