start::
closeprocesses:
createrestorepoint:
URLSearchHook: HKU\S-1-5-21-3753595105-2811040318-3898745294-1003 - (Pas de nom) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - Pas de fichier
SearchScopes: HKLM-x32 -> {a5b9c0f5-5616-47cd-a95f-e43b488faccf} URL = hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?p2=^XP^xdm049^YY^be&si=38885&ptb=B8FA8D96-886F-4DDC-97C9-8C603252D397&psa=&ind=2013041916&st=sb&n=77fc94fc&searchfor={searchTerms}
Toolbar: HKU\S-1-5-21-3753595105-2811040318-3898745294-1001 -> Pas de nom - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Pas de fichier
Toolbar: HKU\S-1-5-21-3753595105-2811040318-3898745294-1001 -> Pas de nom - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - Pas de fichier
Toolbar: HKU\S-1-5-21-3753595105-2811040318-3898745294-1003 -> Pas de nom - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Pas de fichier
HKLM-x32\...\Run: [WSHelperSetup.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [1985824 2013-07-25] (Wondershare Software Co., Ltd. -> Wondershare)
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [1985824 2013-07-25] (Wondershare Software Co., Ltd. -> Wondershare)
HKU\S-1-5-21-3753595105-2811040318-3898745294-1001\...\Run: [WSHelperSetup.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [1985824 2013-07-25] (Wondershare Software Co., Ltd. -> Wondershare)
HKLM\Software\...\Authentication\Credential Providers: [{503739d0-4c5e-4cfd-b3ba-d881334f0df2}] ->
Task: {000C7BDF-6524-4FD0-A94E-AFBDF91E8B9A} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {01C29EE7-9EED-4DB8-B090-E1CAFDA59B05} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Pas de fichier <==== ATTENTION
Task: {1583FB17-694C-4C9E-BC7F-9616D5709D35} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Pas de fichier <==== ATTENTION
Task: {1B583AD9-ED4E-4BE2-BC51-E22CD4DFC4A7} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {2C5280BF-4558-4BF4-B39A-337AB416B520} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {2DA8F3F5-3F79-4333-8B28-0690010395AE} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe
Task: {338F43E4-51CC-419A-8263-650061161956} - \WPD\SqmUpload_S-1-5-21-3753595105-2811040318-3898745294-1001 -> Pas de fichier <==== ATTENTION
Task: {33A3942F-C59C-44AF-9642-E8B754716905} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Pas de fichier <==== ATTENTION
Task: {3F837336-CE7A-41CD-B6F2-B462C1A4C91E} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {41EC2B41-3548-4DED-A1F1-43B9B12533EA} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {45E3A231-0091-4530-8D7C-0CCB260A2650} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Pas de fichier <==== ATTENTION
Task: {46307A5B-0A17-4C1D-9FB7-1A0CD719EB16} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {48162D36-C930-47CC-9674-321100471E45} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Pas de fichier <==== ATTENTION
Task: {48E59401-E319-44A7-B757-F3298271BCEA} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {5356D920-1917-416C-A897-21F61039300F} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {562272B6-B9DD-4658-9F31-0274287A0448} - \Sony Corporation\VAIO Personalization Manager\VpmLM Task Music ISAAC -> Pas de fichier <==== ATTENTION
Task: {593A1B3A-B1F2-45DD-BC4F-29762365195E} - \Microsoft\Windows\UNP\RunCampaignManager -> Pas de fichier <==== ATTENTION
Task: {5E7AD256-649A-4575-B11C-A55A68D10245} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {6A570078-4AFC-403E-8615-2784C99FD166} - \Microsoft\Windows\Media Center\mcupdate_scheduled -> Pas de fichier <==== ATTENTION
Task: {759DD95C-F9EA-4005-9608-B93E774705FA} - \Sony Corporation\VAIO Personalization Manager\VpmLM Task Music CATHERINE -> Pas de fichier <==== ATTENTION
Task: {76CCD7BC-1DF3-490B-96DE-40A251C27AD6} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> Pas de fichier <==== ATTENTION
Task: {77939616-EC04-4C81-8BAE-CFC6469F05AC} - \User_Feed_Synchronization-{7CCDA5AE-1103-4A3D-B904-87498A0DB3C7} -> Pas de fichier <==== ATTENTION
Task: {78A32EE9-21BB-49A9-8C89-5353A11080EC} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Pas de fichier <==== ATTENTION
Task: {7996E079-D0BD-483D-B7C5-16D4039DB8FB} - \Microsoft\Windows\Media Center\StartRecording -> Pas de fichier <==== ATTENTION
Task: {7F6BBD77-8D7F-4855-9765-A2A28A483736} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Pas de fichier <==== ATTENTION
Task: {813661E2-2DFC-46F9-8186-2E2DA407DE75} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Pas de fichier <==== ATTENTION
Task: {832E3F53-1152-4D2C-9591-FE0F24AF81D0} - System32\Tasks\Microsoft\Windows\MobilePC\HotStart => {06DA0625-9701-43DA-BFD7-FBEEA2180A1E}
Task: {8E3D2D93-54D6-4542-8219-5033333417C0} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> Pas de fichier <==== ATTENTION
Task: {9F6E1D50-0894-47A9-9FEA-5BA32DD90C05} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {AEEB2F17-CD42-419E-8490-3CD172C84EBA} - System32\Tasks\Microsoft\Windows\SideShow\GadgetManager => {FF87090D-4A9A-4F47-879B-29A80C355D61}
Task: {B9313C4A-33C1-4644-BAB2-C77271B3DB29} - System32\Tasks\Microsoft\Windows\SideShow\SessionAgent => {45F26E9E-6199-477F-85DA-AF1EDFE067B1}
Task: {B9B6DC0E-C4CE-4FD1-8D56-BA90EA44377C} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {BE9B2A79-C8A3-45F7-BAD2-2B7440A1D553} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {D2D2552F-EFF4-472A-AD41-3BE5FE688751} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe
Task: {D3E0F8AE-92F6-49E8-BE90-661FE35CA2E9} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {D67CF821-6776-45FE-811D-FE4C8152FAFF} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {DA5D9F05-08BD-410C-8005-F1F6707169AE} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {E006BB50-F233-4849-B672-FFBB0D4A5C47} - \task36345066 -> Pas de fichier <==== ATTENTION
Task: {EC65C5AD-4F17-4592-8650-960E4858F226} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe
Task: {F240A93D-8756-4AFC-B744-C2A5C6C267FF} - \Skype -> Pas de fichier <==== ATTENTION
Task: {FE653A73-6EC5-4895-B19C-004FBA515F81} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {FF063EF8-8A90-4BFF-81E7-CBDEA9070438} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Pas de fichier <==== ATTENTION
Task: {FF365ACD-A779-43AC-A45B-3B8E747D8E92} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Pas de fichier <==== ATTENTION
CHR Notifications: Default -> hxxps://fdj-by.accengage.net; hxxps://fr.nd-bd.com; hxxps://ufancyme.com; hxxps://www.filmpornofrancais.fr; hxxps://www.thelotter.com; hxxps://www.youtube.com
cmd: sfc /scannow
cmd: netsh advfirewall reset
emptytemp:
end::