start::
closeprocesses:
createrestorepoint:
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://search.yahoo.com/yhs/web?hspart=lvs&hsimp=yhs-awc&type=lvs__webcompa__1_0__ya__hp_WCYID10369_spdf_fre_g_fr_cdsk_a_creator_170906__ya[browser]
HKU\S-1-5-21-4075061478-3060132768-1520890907-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com/?pc=COSP&ptag=D090617-N0690A581E47B05C&form=CONMHP&conlogo=CT3335669
HKU\S-1-5-21-4075061478-3060132768-1520890907-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus13.msn.com/?pc=ASJB
SearchScopes: HKU\S-1-5-21-4075061478-3060132768-1520890907-1001 -> DefaultScope {CC865B26-C31D-4D23-B17B-96548EEF03F6} URL =
SearchScopes: HKU\S-1-5-21-4075061478-3060132768-1520890907-1001 -> {CC865B26-C31D-4D23-B17B-96548EEF03F6} URL =
Handler: tmtbim - {0B37915C-8B98-4B9E-80D4-464D2C830D10} - C:\Program Files\Trend Micro\Titanium\UIFramework\ProToolbarIMRatingActiveX.dll Pas de fichier
IE trusted site: HKU\.DEFAULT\...\webcompanion.com -> hxxp://webcompanion.com
C:\Program Files\Trend Micro
IE trusted site: HKU\S-1-5-21-4075061478-3060132768-1520890907-1001\...\webcompanion.com -> hxxp://webcompanion.com
FirewallRules: [{ECA85538-FACF-44E7-9889-1FE486AF3FFC}] => (Allow) C:\Program Files (x86)\Apowersoft\YouTube Music Converter\YouTube Music Converter.exe => Pas de fichier
FirewallRules: [{A62A3BE8-AC6B-4B77-9563-E56A86E700DA}] => (Allow) C:\Program Files (x86)\Apowersoft\YouTube Music Converter\YouTube Music Converter.exe => Pas de fichier
FirewallRules: [{5795D10F-44B2-4957-A6AE-EC999C655D3F}] => (Allow) C:\Users\Philippe\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe => Pas de fichier
FirewallRules: [{B9B805A2-510D-4B86-B3E0-A747560F00C9}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe => Pas de fichier
FirewallRules: [{7E55611F-E4FC-4CE6-9DC9-368F9F2A5B1B}] => (Allow) C:\Users\Philippe\AppData\Local\Temp\7zS0606\HPDiagnosticCoreUI.exe => Pas de fichier
FirewallRules: [{A545DD29-0AE4-448E-9F29-3E033A94708E}] => (Allow) C:\Users\Philippe\AppData\Local\Temp\7zS0606\HPDiagnosticCoreUI.exe => Pas de fichier
C:\Program Files (x86)\Lavasoft
HKU\S-1-5-21-4075061478-3060132768-1520890907-1001\...\Run: [Web Companion] => C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe [8442464 2021-01-14] (LAVASOFT SOFTWARE CANADA INC -> Lavasoft)
Task: {01FFD1E9-A6BF-47FE-A4D6-030C298AC3C1} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Pas de fichier <==== ATTENTION
Task: {11BB8C3C-7432-4028-AC42-FEBB7C083632} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> Pas de fichier <==== ATTENTION
Task: {25B67553-E01B-4002-9064-9348FE3EE83F} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Pas de fichier <==== ATTENTION
Task: {34C7AD98-167E-4BD7-98F9-E0525B686E0D} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Pas de fichier <==== ATTENTION
Task: {3657DFD2-112C-4536-9106-CC63512BE4B5} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Pas de fichier <==== ATTENTION
Task: {3F20DF04-978A-4529-B9C0-0D8EC06D1469} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Pas de fichier <==== ATTENTION
Task: {54119657-3240-4B21-B340-94AB65609B4A} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Pas de fichier <==== ATTENTION
Task: {54F8C1A2-BFE2-4C6B-8D21-94C10191B71A} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\BrowserChoice\browserchoice.exe
Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task => {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}
Task: {6FEB3A38-87A7-49A2-9782-E10D3D82331E} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2020-12-08] (Adobe Inc. -> Adobe)
Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task => {1B1F472E-3221-4826-97DB-2C2324D389AE}
Task: {94D4E205-5AD3-4D81-9E18-13F19EBC1144} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Pas de fichier <==== ATTENTION
Task: {9D7FEDDC-0AB3-472B-99F0-DCB0A2174393} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_465_Plugin.exe [1504312 2020-12-08] (Adobe Inc. -> Adobe)
Task: {A0D35A17-23BF-4B66-8F5F-ED1912BCC7DC} - \Microsoft\Windows\UNP\RunCampaignManager -> Pas de fichier <==== ATTENTION
Task: {BF6D07A5-E76F-422E-83CA-8487E2CF4E56} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Pas de fichier <==== ATTENTION
Task: {D4CE02B9-A55B-4D11-80A0-AD7E3A0CDA00} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Pas de fichier <==== ATTENTION
Task: {D59EACDD-C76D-4CF4-ACD5-37EE1FB6F234} - \WPD\SqmUpload_S-1-5-21-4075061478-3060132768-1520890907-1001 -> Pas de fichier <==== ATTENTION
Task: {E0A487A9-DE5B-489E-854A-8F6B7BEB6D46} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Pas de fichier <==== ATTENTION
FF Extension: (Pas de nom) - C:\Program Files (x86)\TomTom HOME 2\xul\extensions\MapShare-status@tomtom.com [non trouvé(e)]
FF Homepage: Mozilla\Firefox\Profiles\o5w8kwvx.default -> hxxps://mysearchengine.co/homepage?hp=1&bitmask=9996&pId=LU170101SODA_FN&iDate=2017-09-06 12:33:16&bName=
FF NewTab: Mozilla\Firefox\Profiles\o5w8kwvx.default -> hxxps://mysearchengine.co/homepage?hp=1&bitmask=9996&pId=LU170101SODA_FN&iDate=2017-09-06 12:33:16&bName=
FF SearchPlugin: C:\Users\Philippe\AppData\Roaming\Mozilla\Firefox\Profiles\o5w8kwvx.default\searchplugins\mysearchengine.xml [2020-11-24]
FF HKLM\...\Firefox\Extensions: [{c2056674-a37f-4b29-9300-2004759d74fe}] - C:\Program Files\Trend Micro\AMSP\module\20013\FxExt\firefoxextension => non trouvé(e)
FF HKLM-x32\...\Firefox\Extensions: [{c2056674-a37f-4b29-9300-2004759d74fe}] - C:\Program Files\Trend Micro\AMSP\module\20013\FxExt\firefoxextension => non trouvé(e)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_465.dll [2020-12-08] (Adobe Inc. -> )
S2 WCAssistantService; C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe [29280 2021-01-14] (LAVASOFT SOFTWARE CANADA INC -> )
S3 AdobeFlashPlayerUpdateSvc; C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2020-12-08] (Adobe Inc. -> Adobe)
cmd: sfc /scannow
emptytemp:
end::