start::
closeprocesses:
createrestorepoint:
CustomCLSID: HKU\S-1-5-21-661168172-397195425-1930316338-1001_Classes\CLSID\{18f916ae-15c7-1d5e-0bfe-6ce3a17cd20d}\localserver32 -> "C:\Users\Janick\AppData\Local\OneLaunch\5.32.1\onelaunch.exe" -ToastActivated => Pas de fichier
CustomCLSID: HKU\S-1-5-21-661168172-397195425-1930316338-1001_Classes\CLSID\{227C9E8F-71A1-4B23-9076-682A1A8EAAED}\localserver32 -> "c:\program files\macrium\common\reflectmonitor.exe" -ToastActivated => Pas de fichier
CustomCLSID: HKU\S-1-5-21-661168172-397195425-1930316338-1001_Classes\CLSID\{97eb3dff-2dfc-5915-ba64-f671beb022e2}\localserver32 -> "C:\Users\Janick\AppData\Local\OneLaunch\5.31.2\OneLaunch.exe" -ToastActivated => Pas de fichier
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Pas de fichier
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - Pas de fichier
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
HKLM\Software\Policies\...\system: [EnableSmartScreen] 0
HKLM\Software\...\Authentication\Credential Providers: [{503739d0-4c5e-4cfd-b3ba-d881334f0df2}] ->
Task: {07751B22-6F78-42AC-9DC8-D004803E5150} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Pas de fichier <==== ATTENTION
Task: {171ECD58-52AF-41D7-98C9-7628CF9D8C8D} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Pas de fichier <==== ATTENTION
Task: {191EE20B-D25D-4C9A-8379-0450C81FBF8F} - \SidebarExecute -> Pas de fichier <==== ATTENTION
Task: {2C4108E0-246A-48BC-B88A-11D67F42A24A} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Pas de fichier <==== ATTENTION
Task: {3C72ABEB-664B-41D5-8369-CA45656B7A0A} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Pas de fichier <==== ATTENTION
Task: {892A4BF5-F73E-4B18-931F-51EED7AE188E} - \1ad381bba1f612867c86b4abc6d2528a -> Pas de fichier <==== ATTENTION
Task: {8B35062D-6245-4788-AF12-42708761336D} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Pas de fichier <==== ATTENTION
Task: {8CBA8176-6887-42D4-BDD8-0CE64B8C3DA8} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Pas de fichier <==== ATTENTION
Task: {A6A41C8E-D5F4-48C3-AAF5-D25E2630CA08} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> Pas de fichier <==== ATTENTION
Task: {BA2FE0B6-0BC3-4552-8E87-5A5DADCBA086} - \Microsoft\Windows\UNP\RunCampaignManager -> Pas de fichier <==== ATTENTION
Task: {C40B4EDD-9FF7-41E2-946A-60124FBDAE9D} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Pas de fichier <==== ATTENTION
Task: {C8431B75-F702-4A36-BEE6-1D92EABB15C6} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> Pas de fichier <==== ATTENTION
Task: {DDF4077D-A850-4184-B5CB-3AC07DB8C8FF} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Pas de fichier <==== ATTENTION
Task: {DE739162-DD51-4565-9DD8-321E48E370C8} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Pas de fichier <==== ATTENTION
Task: {E0980FA8-0EA6-403D-B0FB-9F442DDE49DB} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Pas de fichier <==== ATTENTION
Task: {82CFA00E-24FB-47A6-8365-1F57FD09D718} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [1790184 2021-04-29] (Avast Software s.r.o. -> Avast Software)
C:\Program Files\Common Files\Avast Software
Task: {1895DBF2-2F31-44FC-A96A-192351039740} - System32\Tasks\baattracted frushattracted frush => C:\Program Files (x86)\Enchilada\crimp.exe (Pas de fichier)
Task: {6C28405A-4C24-4833-8783-A76B7BE93DF5} - System32\Tasks\bacoring_saturatingcoring_saturating => C:\Users\Janick\AppData\Local\crimp.exe (Pas de fichier)
Task: {E8E32731-D222-4C4B-B0D7-BCE27FE242FF} - System32\Tasks\badecayingdecaying => C:\Program Files (x86)\Mana\fischler.exe (Pas de fichier)
Task: {96ED6286-854F-4C0F-8965-9AFF5ADAD213} - System32\Tasks\bagroepgroep => C:\Program Files (x86)\canas\canas.exe (Pas de fichier)
Task: {6CD4A1CC-DFAE-4E07-B185-425F0AE73476} - System32\Tasks\bakriss gelbart hermosakriss gelbart hermosa => C:\Users\Janick\AppData\Local\fischler.exe (Pas de fichier)
Task: {B9431EA5-F958-48F1-8519-E3A8A85724F8} - System32\Tasks\baquestioners-retracedquestioners-retraced => C:\Program Files (x86)\teufel\crimp.exe (Pas de fichier)
Task: {6216F405-4BA4-478C-8828-AB5422C827AF} - System32\Tasks\basandel_cypriotsandel_cypriot => C:\Program Files (x86)\Enchilada\fischler.exe (Pas de fichier)
Task: {D7AE9037-19E3-4AE2-8651-85AF7BEFC11B} - System32\Tasks\McAfee\McAfee Auto Maintenance Task Agent => {ABCECA3B-EA5A-496B-A021-5C6BAB365E5C} C:\Program Files\Common Files\McAfee\Platform\McAMTaskAgent.exe [908816 2016-07-07] (McAfee, Inc. -> McAfee, Inc.)
Task: {4AD910C6-717E-4649-B61F-EB2B358F3767} - System32\Tasks\McAfee\McAfee Idle Detection Task => {ABCDCA3B-DE6B-5A7C-B132-6D7CBA63E5C5} C:\Program Files\Common Files\McAfee\Platform\McAMTaskAgent.exe [908816 2016-07-07] (McAfee, Inc. -> McAfee, Inc.)
Task: {38955295-132A-42FF-B9FF-D447AB57BA8E} - System32\Tasks\McAfeeLogon => C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe [949480 2016-09-20] (McAfee, Inc. -> McAfee, Inc.)
C:\Program Files\Common Files\McAfee
Task: {2984B5A3-A531-4885-A032-181E2F9DA816} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => %SystemRoot%\ehome\ehPrivJob.exe /DoActivateWindowsSearch (Pas de fichier)
Task: {69B8C3D7-3DEB-4B34-99B5-51F85A17C88F} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => %SystemRoot%\ehome\ehPrivJob.exe /DoConfigureInternetTimeService (Pas de fichier)
Task: {4B2B8C6C-70F0-422C-9C55-EF0021517887} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => %SystemRoot%\ehome\ehPrivJob.exe /DoRecoveryTasks $(Arg0) (Pas de fichier)
Task: {FCDCA8CB-C213-46A3-8167-E95E74653E52} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => %SystemRoot%\ehome\ehPrivJob.exe /DRMInit (Pas de fichier)
Task: {B39E4759-5960-4A0F-AE66-0B744FF8B635} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => %SystemRoot%\ehome\ehPrivJob.exe /InstallPlayReady $(Arg0) (Pas de fichier)
Task: {DEA69668-1D59-4CD2-B2F2-0779F04C530A} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => %SystemRoot%\ehome\mcupdate $(Arg0) (Pas de fichier)
Task: {2F08AF35-2367-4F87-A8BB-7141AFBD622F} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => %SystemRoot%\ehome\mcupdate -crl -hms -pscn 15 (Pas de fichier)
Task: {AEAAA4B4-309D-4729-AF42-AF0E50A7EF19} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => %SystemRoot%\ehome\mcupdate.exe -MediaCenterRecoveryTask (Pas de fichier)
Task: {6BA58DC5-E2C2-42C0-9C09-BC02ABABDFBD} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => %SystemRoot%\ehome\mcupdate.exe -ObjectStoreRecoveryTask (Pas de fichier)
Task: {74CCD70B-CC56-425B-98A4-8DD19CE0DA5A} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => %SystemRoot%\ehome\ehPrivJob.exe /OCURActivate (Pas de fichier)
Task: {57035A3B-728F-4667-9242-E2FECD74FEFD} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => %SystemRoot%\ehome\ehPrivJob.exe /OCURDiscovery $(Arg0) (Pas de fichier)
Task: {79A4644A-1526-4649-8219-97B1D0C3D67A} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => %SystemRoot%\ehome\ehPrivJob.exe /PBDADiscovery (Pas de fichier)
Task: {C3615217-E575-4B6A-8C7A-F31B471649BC} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => %SystemRoot%\ehome\ehPrivJob.exe /wait:7 /PBDADiscovery (Pas de fichier)
Task: {DE3C6976-B2D9-40BF-A860-261A4949D086} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => %SystemRoot%\ehome\ehPrivJob.exe /wait:90 /PBDADiscovery (Pas de fichier)
Task: {DACA6FB9-2C2A-40C7-A059-F83759A50CF6} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => %windir%\ehome\MCUpdate.exe -pscn 0 (Pas de fichier)
Task: {115CFC27-8D06-403E-83B4-C0F874EFEA4D} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => %SystemRoot%\ehome\mcupdate.exe -PvrRecoveryTask (Pas de fichier)
Task: {82EEF27C-9D27-4137-AD55-7BCF9CB8F72C} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => %SystemRoot%\ehome\mcupdate.exe -PvrSchedule (Pas de fichier)
Task: {CF64BBB2-39BC-4FBC-A170-D0192946121A} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => %SystemRoot%\ehome\ehrec /RestartRecording (Pas de fichier)
Task: {24280FD3-582A-411C-ABCC-2B60FE7F4C88} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => %SystemRoot%\ehome\ehPrivJob.exe /DoRegisterSearch $(Arg0) (Pas de fichier)
Task: {1B80E348-B288-45A5-B1CE-297973582E6A} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => %SystemRoot%\ehome\ehPrivJob.exe /DoReindexSearchRoot (Pas de fichier)
Task: {48A54546-9FC9-4548-B929-3BE6723C1E62} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => %SystemRoot%\ehome\mcupdate.exe -SqlLiteRecoveryTask (Pas de fichier)
Task: {FC034A58-6234-4B05-8343-E16C22AAF689} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => %SystemRoot%\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0) (Pas de fichier)
Task: {1B0EFB37-044D-4B54-9D36-DA579F5AEDD8} - System32\Tasks\Microsoft\Windows\MobilePC\HotStart => {06DA0625-9701-43DA-BFD7-FBEEA2180A1E}
Task: {B0CBAB43-44FC-469B-A4CE-87426761FDCE} - System32\Tasks\Microsoft\Windows\PerfTrack\BackgroundConfigSurveyor => {EA9155A3-8A39-40B4-8963-D3C761B18371}
Task: {5B42DD9C-5A26-4F27-BB95-34603F0997E5} - System32\Tasks\Microsoft\Windows\Shell\WindowsParentalControls => {DFA14C43-F385-4170-99CC-1B7765FA0E4A}
Task: {486D715E-6AA2-44CF-BC48-B6990CBB53C6} - System32\Tasks\Microsoft\Windows\Shell\WindowsParentalControlsMigration => {343D770D-7788-47C2-B62A-B7C4CED925CB}
Task: {67586E27-7966-4388-B290-2FA0E6874F4E} - System32\Tasks\Microsoft\Windows\SideShow\AutoWake => {E51DFD48-AA36-4B45-BB52-E831F02E8316}
Task: {90FD736D-1072-45B1-A864-0AF2C2862392} - System32\Tasks\Microsoft\Windows\SideShow\GadgetManager => {FF87090D-4A9A-4F47-879B-29A80C355D61}
Task: {241B1957-164C-42FF-83CD-D2ECB252E705} - System32\Tasks\Microsoft\Windows\SideShow\SessionAgent => {45F26E9E-6199-477F-85DA-AF1EDFE067B1}
Task: {A91011EE-B027-4A61-8887-1655F17FABF2} - System32\Tasks\Microsoft\Windows\SideShow\SystemDataProviders => {7CCA6768-8373-4D28-8876-83E8B4E3A969}
HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3: <==== ATTENTION (Restriction - Zones)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [Pas de fichier]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk]
CHR HKLM\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk]
CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
S2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [596768 2016-07-07] (McAfee, Inc. -> McAfee, Inc.)
S2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [993824 2016-09-23] (McAfee, Inc. -> McAfee, Inc.)
S2 McBootDelayStartSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [596768 2016-07-07] (McAfee, Inc. -> McAfee, Inc.)
S2 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\1.9.829.0\McCSPServiceHost.exe [1910000 2016-05-31] (McAfee, Inc. -> McAfee, Inc.)
S4 McNaiAnn; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [596768 2016-07-07] (McAfee, Inc. -> McAfee, Inc.)
S3 McODS; C:\Program Files\McAfee\VirusScan\mcods.exe [816128 2016-06-21] (McAfee, Inc. -> McAfee, Inc.)
S2 McProxy; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [596768 2016-07-07] (McAfee, Inc. -> McAfee, Inc.)
R2 ModuleCoreService; C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe [1454216 2016-09-13] (McAfee, Inc. -> McAfee, Inc.)
S3 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [596768 2016-07-07] (McAfee, Inc. -> McAfee, Inc.)
S2 PEFService; C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe [1045336 2016-05-25] (McAfee, Inc. -> Intel Security, Inc.)
S3 HipShieldK; C:\WINDOWS\System32\drivers\HipShieldK.sys [216704 2016-08-02] (McAfee, Inc. -> McAfee, Inc.)
S3 mfeaack; C:\WINDOWS\System32\drivers\mfeaack.sys [419616 2016-04-27] (McAfee, Inc. -> McAfee, Inc.)
S3 mfencbdc; C:\WINDOWS\System32\DRIVERS\mfencbdc.sys [519456 2016-08-01] (McAfee, Inc. -> McAfee, Inc.)
S3 mfencrk; C:\WINDOWS\System32\DRIVERS\mfencrk.sys [100136 2016-08-01] (McAfee, Inc. -> McAfee, Inc.)
emptytemp:
end::