Format du document : text/plain
Prévisualisation
start
CloseProcesses:
Hosts:
CreateRestorePoint:
HKLM-x32\...\Run: [] => [X]
() C:\Windows\Temp\gBA39.tmp.exe
() C:\Windows\Temp\g3361.tmp.exe
(53H8WWIEJ) C:\Program Files (x86)\2gbr4nmwfoc\DJ3B7.exe
(53H8WWIEJ) C:\Program Files\5NAX994AL2\5NAX994AL.exe
(53H8WWIEJ) C:\Program Files\02IEBCQXKY\02IEBCQXK.exe
HKLM\ DisallowedCertificates: 0F684EC1163281085C6AF20528878103ACEFCAAB (F-Secure Corporation) <==== ATTENTION
HKLM\ DisallowedCertificates: 18DEA4EFA93B06AE997D234411F3FD72A677EECE (Bitdefender SRL) <==== ATTENTION
HKLM\ DisallowedCertificates: 249BDA38A611CD746A132FA2AF995A2D3C941264 (Malwarebytes Corporation) <==== ATTENTION
HKLM\ DisallowedCertificates: 331E2046A1CCA7BFEF766724394BE6112B4CA3F7 (Trend Micro) <==== ATTENTION
HKLM\ DisallowedCertificates: 3850EDD77CC74EC9F4829AE406BBF9C21E0DA87F (Kaspersky Lab) <==== ATTENTION
HKLM\ DisallowedCertificates: 42727E052C0C2E1B35AB53E1005FD9EDC9DE8F01 (K7 Computing Pvt Ltd) <==== ATTENTION
HKLM\ DisallowedCertificates: 5DD3D41810F28B2A13E9A004E6412061E28FA48D (Emsisoft Ltd) <==== ATTENTION
HKLM\ DisallowedCertificates: 76A9295EF4343E12DFC5FE05DC57227C1AB00D29 (BullGuard Ltd) <==== ATTENTION
HKLM\ DisallowedCertificates: 88AD5DFE24126872B33175D1778687B642323ACF (McAfee) <==== ATTENTION
HKLM\ DisallowedCertificates: 982D98951CF3C0CA2A02814D474A976CBFF6BDB1 (Safer Networking Ltd.) <==== ATTENTION
HKLM\ DisallowedCertificates: 9C43F665E690AB4D486D4717B456C5554D4BCEB5 (ThreatTrack Security) <==== ATTENTION
HKLM\ DisallowedCertificates: 9E3F95577B37C74CA2F70C1E1859E798B7FC6B13 (CURIOLAB S.M.B.A.) <==== ATTENTION
HKLM\ DisallowedCertificates: A5341949ABE1407DD7BF7DFE75460D9608FBC309 (BullGuard Ltd) <==== ATTENTION
HKLM\ DisallowedCertificates: AB7E760DA2485EA9EF5A6EEE7647748D4BA6B947 (AVG Technologies CZ) <==== ATTENTION
HKLM\ DisallowedCertificates: AD96BB64BA36379D2E354660780C2067B81DA2E0 (Symantec Corporation) <==== ATTENTION
HKLM\ DisallowedCertificates: DB303C9B61282DE525DC754A535CA2D6A9BD3D87 (ThreatTrack Security) <==== ATTENTION
HKLM\ DisallowedCertificates: E22240E837B52E691C71DF248F12D27F96441C00 (Total Defense, Inc.) <==== ATTENTION
HKLM\ DisallowedCertificates: ED841A61C0F76025598421BC1B00E24189E68D54 (Bitdefender SRL) <==== ATTENTION
HKLM\ DisallowedCertificates: FFFA650F2CB2ABC0D80527B524DD3F9FC172C138 (Doctor Web Ltd.) <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-3875425450-4177650351-1418416325-1000\...\Run: [LMUEP214NMP7BTE] => "C:\Program Files\5DI842ZKX8\5DI842ZKX.exe"
HKU\S-1-5-21-3875425450-4177650351-1418416325-1000\...\Run: [WDA8R6QSBTSHE50] => C:\Program Files (x86)\2gbr4nmwfoc\DJ3B7.exe [1040384 2017-07-04] (53H8WWIEJ)
HKU\S-1-5-21-3875425450-4177650351-1418416325-1000\...\Run: [L8D5MIZ9RSL2ED0] => C:\Program Files\5NAX994AL2\5NAX994AL.exe [1040384 2017-07-04] (53H8WWIEJ)
HKU\S-1-5-21-3875425450-4177650351-1418416325-1000\...\Run: [SYJGJE6A0J2VCXE] => C:\Program Files\02IEBCQXKY\02IEBCQXK.exe [1040384 2017-07-04] (53H8WWIEJ)
Toolbar: HKU\S-1-5-21-3875425450-4177650351-1418416325-1000 -> Pas de nom - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Pas de fichier
CHR Profile: C:\Users\hp\AppData\Local\Google\Chrome\User Data\ChromeDefaultData [2017-07-07] <==== ATTENTION
2017-07-04 22:48 - 2017-07-04 15:19 - 02005504 ___SH (Micrasaft Carparation) C:\windows\C_02iu47.dat
ContextMenuHandlers01: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => -> Pas de fichier
Task: {0F1D1983-42FE-4EE6-ADA8-F1C6B9E76939} - System32\Tasks\26c3dbc9295dc2ec1ed06010a6f5790d => sc start 26c3dbc9295dc2ec1ed06010a6f5790d <==== ATTENTION
Task: {757B8D9A-075B-4663-A15C-D35EBCFAABFF} - System32\Tasks\My Watermark => Rundll32.exe "C:\Program Files\My Watermark\My Watermark.dll",QCJipYTpamr <==== ATTENTION
2017-07-06 21:12 - 2017-07-07 01:41 - 00478720 _____ () C:\windows\TEMP\gBA39.tmp.exe
2017-07-05 12:39 - 2017-07-07 01:41 - 00558592 _____ () C:\windows\TEMP\g3361.tmp.exe
HKU\S-1-5-21-3875425450-4177650351-1418416325-1000\Software\Classes\regfile: regedit.exe "%1" <==== ATTENTION
EmptyTemp:
end