start CloseProcesses: hosts: CreateRestorePoint: HKLM\...\Run: [IntelTBRunOnce] => wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" BootExecute: autocheck autochk * sdnclean64.exe GroupPolicy: Restriction - Chrome <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION Tcpip\..\Interfaces\{3B7F2F84-982A-49EA-9368-45FB5BC144D9}: [DhcpNameServer] 150.200.3.2 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.sweet-page.com/web/?type=ds&ts=1422900125&from=corfr&uid=WDCXWD6400BPVT-35HXZT1_WD-WXA1A91A9338A9338&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.sweet-page.com/web/?type=ds&ts=1422900125&from=corfr&uid=WDCXWD6400BPVT-35HXZT1_WD-WXA1A91A9338A9338&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.sweet-page.com/?type=hp&ts=1422900125&from=corfr&uid=WDCXWD6400BPVT-35HXZT1_WD-WXA1A91A9338A9338 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.sweet-page.com/?type=hp&ts=1422900125&from=corfr&uid=WDCXWD6400BPVT-35HXZT1_WD-WXA1A91A9338A9338 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.sweet-page.com/web/?type=ds&ts=1422900125&from=corfr&uid=WDCXWD6400BPVT-35HXZT1_WD-WXA1A91A9338A9338&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.sweet-page.com/web/?type=ds&ts=1422900125&from=corfr&uid=WDCXWD6400BPVT-35HXZT1_WD-WXA1A91A9338A9338&q={searchTerms} HKU\S-1-5-21-3767814352-3994908510-1756447976-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.sweet-page.com/?type=hp&ts=1422900125&from=corfr&uid=WDCXWD6400BPVT-35HXZT1_WD-WXA1A91A9338A9338 HKU\S-1-5-21-3767814352-3994908510-1756447976-1002\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.sweet-page.com/web/?type=ds&ts=1422900125&from=corfr&uid=WDCXWD6400BPVT-35HXZT1_WD-WXA1A91A9338A9338&q={searchTerms} HKU\S-1-5-21-3767814352-3994908510-1756447976-1002\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.sweet-page.com/web/?type=ds&ts=1422900125&from=corfr&uid=WDCXWD6400BPVT-35HXZT1_WD-WXA1A91A9338A9338&q={searchTerms} SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-3767814352-3994908510-1756447976-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = FF NewTab: hxxp://www.sweet-page.com/newtab/?type=nt&ts=1422900125&from=corfr&uid=WDCXWD6400BPVT-35HXZT1_WD-WXA1A91A9338A9338 FF SelectedSearchEngine: sweet-page FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\sweet-page.xml [2015-02-02] CHR dev: Chrome dev build détecté(e)! <======= ATTENTION 2016-03-29 18:10 - 2015-02-01 21:07 - 00000000 ____D C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7 2015-01-10 22:04 - 2015-01-10 22:04 - 0000004 _____ () C:\Users\CécileA\AppData\Roaming\appdataFr2.bin EmptyTemp: end