Édité le 19 novembre 2022
Télécharger | Reposter | Largeur fixe

start::
CreateRestorePoint:
CloseProcesses:
Hosts:
RemoveProxy:
Task: {CD639208-9A0C-462D-9E34-F80C80D510E0} - \Microsoft\Windows\UNP\RunCampaignManager -> Pas de fichier
Task: {e7c24d1e-22bf-4adb-a949-56a5f528c42f} - pas de chemin du fichier
Task: C:\WINDOWS\Tasks\{364E1AEC-29A1-D2B5-128E-696B78EA3194}.job => C:\Users\xavie\AppData\Roaming\Lepigod\SYNHEL~1.EXE
CHR HKLM\...\Chrome\Extension: [afgeoapebnkefelmpoepnmjiflidjjce]
CHR HKLM\...\Chrome\Extension: [elmkjjfkkchohaaoljobaffjeedcoocj]
CHR HKLM\...\Chrome\Extension: [gboaiodgdajeapekadgejlbmabjganof]
CHR HKLM\...\Chrome\Extension: [iicdcmjmlnliniifciehlchmdepfndfn]
CHR HKLM\...\Chrome\Extension: [ocilpnnapnkmcdabaeoobbamlniheaep]
CHR HKLM\...\Chrome\Extension: [oonbcpdabjcggcklopgbdagbfnkhbgbe]
CHR HKU\S-1-5-21-3317908826-1146592389-1670111846-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [afgeoapebnkefelmpoepnmjiflidjjce]
CHR HKU\S-1-5-21-3317908826-1146592389-1670111846-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [elmkjjfkkchohaaoljobaffjeedcoocj]
CHR HKU\S-1-5-21-3317908826-1146592389-1670111846-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [gboaiodgdajeapekadgejlbmabjganof]
CHR HKU\S-1-5-21-3317908826-1146592389-1670111846-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [iicdcmjmlnliniifciehlchmdepfndfn]
CHR HKU\S-1-5-21-3317908826-1146592389-1670111846-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [ocilpnnapnkmcdabaeoobbamlniheaep]
CHR HKU\S-1-5-21-3317908826-1146592389-1670111846-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [oonbcpdabjcggcklopgbdagbfnkhbgbe]
CHR HKU\S-1-5-21-3317908826-1146592389-1670111846-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [pfnciekpafndamlomnebbfophenfehbc]
CHR HKLM-x32\...\Chrome\Extension: [afgeoapebnkefelmpoepnmjiflidjjce]
CHR HKLM-x32\...\Chrome\Extension: [elmkjjfkkchohaaoljobaffjeedcoocj]
CHR HKLM-x32\...\Chrome\Extension: [gboaiodgdajeapekadgejlbmabjganof]
CHR HKLM-x32\...\Chrome\Extension: [iicdcmjmlnliniifciehlchmdepfndfn]
CHR HKLM-x32\...\Chrome\Extension: [oonbcpdabjcggcklopgbdagbfnkhbgbe]
2020-06-10 10:24 - 2020-06-10 10:24 - 000000000 ____D () C:\ProgramData\DUNotifier.exe
2019-03-15 18:20 - 2019-03-15 18:20 - 000213983 _____ () C:\Users\xavie\AppData\Roaming\Datofopacot
2020-02-10 12:22 - 2020-02-10 12:22 - 000224098 _____ () C:\Users\xavie\AppData\Roaming\Fanugiteco
2019-03-24 10:20 - 2019-03-24 10:20 - 000313251 _____ () C:\Users\xavie\AppData\Roaming\Fecomu
2019-04-05 10:20 - 2019-04-05 10:20 - 000234176 _____ () C:\Users\xavie\AppData\Roaming\Holesuhesifa
2019-05-07 10:41 - 2019-05-07 10:41 - 000147257 _____ () C:\Users\xavie\AppData\Roaming\Meham
2020-01-30 11:22 - 2020-01-30 11:22 - 000279923 _____ () C:\Users\xavie\AppData\Roaming\Mepokofecaha
2019-04-29 08:20 - 2019-04-29 08:20 - 000176995 _____ () C:\Users\xavie\AppData\Roaming\Nesabelipo
2019-04-16 00:20 - 2019-04-16 00:20 - 000185662 _____ () C:\Users\xavie\AppData\Roaming\Rasebo
2020-01-16 10:28 - 2020-01-16 10:28 - 000326427 _____ () C:\Users\xavie\AppData\Local\lJbzX
2019-08-08 16:25 - 2020-01-16 10:17 - 000326427 _____ () C:\Users\xavie\AppData\Local\lJbzXp
2020-03-31 16:28 - 2020-03-31 16:28 - 000185073 _____ () C:\Users\xavie\AppData\Local\lJbzXpNf
2017-12-12 09:17 - 2018-01-03 18:28 - 000000052 _____ () C:\Users\xavie\AppData\Local\lJbzXpNfDV
2017-12-14 09:35 - 2017-12-14 09:35 - 000000052 _____ () C:\Users\xavie\AppData\Local\ntz58bhntz
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> Pas de fichier
SearchScopes: HKU\S-1-5-21-3317908826-1146592389-1670111846-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://fr.search.yahoo.com/yhs/search?hspart=
SearchScopes: HKU\S-1-5-21-3317908826-1146592389-1670111846-1001 -> {f7bb050c-e116-44da-89c2-6f2b68c54836} URL = hxxps://fr.search.yahoo.com/yhs/search?hspart=
HKU\S-1-5-21-3317908826-1146592389-1670111846-1001\...\StartupApproved\Run: => "Chromium"
EmptyTemp:
cmd: ipconfig /flushdns
cmd: netsh advfirewall reset
end::

x
Éditer le texte

Merci d'entrer le mot de passe que vous avez indiqué à la création du texte.

x
Télécharger le texte

Merci de choisir le format du fichier à télécharger.