re Tinou
Lance Farbar
Copies les lignes suivantes dans le cadre rouge
start::
CloseProcesses:
CreateRestorePoint:
(SweetLabs Inc. -> SweetLabs, Inc) C:\Users\edema\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe
C:\Users\edema\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe
HKU\S-1-5-21-3655374664-1735676624-2911693723-1001\...\Run: [Chromium] => c:\users\edema\appdata\local\chromium\application\chrome.exe [828416 2017-01-21] (The Chromium Authors) [Fichier non signé]
HKU\S-1-5-21-3655374664-1735676624-2911693723-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09142019142300142\...\Run: [Chromium] => c:\users\edema\appdata\local\chromium\application\chrome.exe [828416 2017-01-21] (The Chromium Authors) [Fichier non signé]
HKU\S-1-5-21-3655374664-1735676624-2911693723-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09142019142301396\...\Run: [Chromium] => c:\users\edema\appdata\local\chromium\application\chrome.exe [828416 2017-01-21] (The Chromium Authors) [Fichier non signé]
HKU\S-1-5-21-3655374664-1735676624-2911693723-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-09152019123953841\...\Run: [Chromium] => c:\users\edema\appdata\local\chromium\application\chrome.exe [828416 2017-01-21] (The Chromium Authors) [Fichier non signé]
Task: {B832FA77-4DC8-49A3-8AE0-D6B44723D9A0} - System32\Tasks\App Explorer => C:\Users\edema\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe [7399080 2019-06-04] (SweetLabs Inc. -> SweetLabs, Inc) <==== ATTENTION
SearchScopes: HKLM -> DefaultScope {88C25964-E496-45D5-BE0E-EA12B873EBA8} URL =
SearchScopes: HKLM-x32 -> DefaultScope {88C25964-E496-45D5-BE0E-EA12B873EBA8} URL =
SearchScopes: HKU\S-1-5-21-3655374664-1735676624-2911693723-1001 -> DefaultScope {2f23ab71-4ac6-41f2-a955-ea576e553146} URL =
U4 AppMgmt; pas de ImagePath
U4 CscService; pas de ImagePath
U4 napagent; pas de ImagePath
U4 PeerDistSvc; pas de ImagePath
2019-09-10 19:55 - 2019-09-10 19:55 - 000002983 _____ C:\Users\edema\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search Powered by Yahoo!.lnk
C:\Users\edema\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search Powered by Yahoo!.lnk
AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxlctlfudivq`qsp`28hfm [0]
AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`27hfm [0]
AlternateDataStreams: C:\Users\Public\AppData:CSM [220]
AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [478]
FirewallRules: [UDP Query User{810FFE38-A177-46F9-85EF-AD9173492646}C:\program files (x86)\common files\oracle\java\javapath_target_3853031\java.exe] => (Allow) C:\program files (x86)\common files\oracle\java\javapath_target_3853031\java.exe Pas de fichier
FirewallRules: [TCP Query User{FB83223C-8462-488A-9524-47A2CAE53AB5}C:\program files (x86)\common files\oracle\java\javapath_target_3853031\java.exe] => (Allow) C:\program files (x86)\common files\oracle\java\javapath_target_3853031\java.exe Pas de fichier
FirewallRules: [UDP Query User{8F70A247-258C-433A-9183-FB0C05E64E60}C:\program files (x86)\common files\oracle\java\javapath_target_3853031\java.exe] => (Allow) C:\program files (x86)\common files\oracle\java\javapath_target_3853031\java.exe Pas de fichier
FirewallRules: [TCP Query User{60AA183B-0051-45D7-B85F-E55A82F519C6}C:\program files (x86)\common files\oracle\java\javapath_target_3853031\java.exe] => (Allow) C:\program files (x86)\common files\oracle\java\javapath_target_3853031\java.exe Pas de fichier
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B832FA77-4DC8-49A3-8AE0-D6B44723D9A0
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{B832FA77-4DC8-49A3-8AE0-D6B44723D9A0
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B832FA77-4DC8-49A3-8AE0-D6B44723D9A0
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Maintenance\{B832FA77-4DC8-49A3-8AE0-D6B44723D9A0
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{B832FA77-4DC8-49A3-8AE0-D6B44723D9A0
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{B832FA77-4DC8-49A3-8AE0-D6B44723D9A0
C:\Windows\System32\Tasks\App Explorer
C:\Users\edema\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe
C:\Users\defaultuser0\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo App Explorer.lnk
C:\Users\edema\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo App Explorer.lnk
C:\Users\Public\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo App Explorer.lnk
DeleteKey: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Host App Service
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Segurazo
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ViewpointMediaPlayer
DeleteKey: HKU\.DEFAULT\Software\ByteFence
DeleteKey: HKU\S-1-5-18\Software\ByteFence
DeleteKey: HKCU\Software\pctonics.com
DeleteKey: HKCU\Software\ProductSetup
DeleteKey: HKLM\System\CurrentControlSet\Services\EventLog\Reason\ReasonByteFence
DeleteKey: HKLM\SOFTWARE\pctonics.com
DeleteKey: HKLM\SOFTWARE\WOW6432Node\MetaStream
DeleteKey: HKLM\SOFTWARE\WOW6432Node\Viewpoint
DeleteKey: HKCU\SOFTWARE\App Host Service
C:\Program Files (x86)\Viewpoint
C:\WINDOWS\Prefetch\SEGURAZOUNINSTALLER.EXE-23769AFB.pf
DeleteValue: HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION|ByteFence.exe
DeleteKey: HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Segurazo
DeleteKey: HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ViewpointMediaPlayer
EmptyTemp:
end::
Corrige et heberge le rapport fixlog
@+