Start::
CreateRestorePoint:
CloseProcesses:
CHR HKLM\SOFTWARE\Policies\Google: Restriction
ProxyEnable: [.DEFAULT] => Proxy est activé.
ProxyServer: [.DEFAULT] => http=127.0.0.1:50347;https=127.0.0.1:50347
ProxyServer: [S-1-5-21-1345798209-2535738462-2939399751-1001] => http=127.0.0.1:50219;https=127.0.0.1:50219
SearchScopes: HKLM -> DefaultScope {03380079-D14A-433C-8415-A268A1565347} URL =
SearchScopes: HKLM-x32 -> DefaultScope {03380079-D14A-433C-8415-A268A1565347} URL =
SearchScopes: HKU\S-1-5-21-1345798209-2535738462-2939399751-500 -> DefaultScope {03380079-D14A-433C-8415-A268A1565347} URL =
FF Extension: (cacaoweb) - C:\Users\philippe\AppData\Roaming\Mozilla\Firefox\Profiles\i78noznw.default\Extensions\cacaoweb@cacaoweb.org [2017-02-23] [non signé]
FF Extension: (Video Downloader professional) - C:\Users\philippe\AppData\Roaming\Mozilla\Firefox\Profiles\i78noznw.default\Extensions\ffext_basicvideoext@startpage24.xpi [2017-08-05]
FF Extension: (Safe Browsing Version 4 (temporary add-on)) - C:\Users\philippe\AppData\Roaming\Mozilla\Firefox\Profiles\i78noznw.default\Extensions\sbv4-gradual-rollout@mozilla.com.xpi [2017-10-26]
FF Extension: (mC+) - C:\Users\philippe\AppData\Roaming\Mozilla\Firefox\Profiles\i78noznw.default\Extensions\{8D8ABF0C-6469-48A0-8002-65FEF50A8463}.xpi [2017-09-20]
FF SearchPlugin: C:\Users\philippe\AppData\Roaming\Mozilla\Firefox\Profiles\i78noznw.default\searchplugins\google-lavasoft.xml [2016-05-12]
C:\Users\philippe\AppData\Local\Google\Chrome\User Data\Default\Extensions\elicpjhcidhpjomhibiffojpinpmmpil
CHR HKU\S-1-5-21-1345798209-2535738462-2939399751-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] -
hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [dbchoocfamphhbbimpbggjkaepfojpgb] -
hxxps://clients2.google.com/service/update2/crx 2017-10-27 13:37 - 2017-10-27 13:41 - 000000000 ____D C:\WINDOWS\System32\Tasks\TweakBit
2017-10-27 13:37 - 2017-10-27 13:41 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TweakBit
2017-10-27 13:37 - 2017-10-27 13:37 - 000000000 ____D C:\ProgramData\TweakBit
2017-10-26 17:50 - 2017-10-26 17:50 - 000000000 ____D C:\Users\philippe\AppData\Local\Chromium
2017-10-26 17:22 - 2017-10-26 17:22 - 000000000 ____D C:\Users\philippe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Popcorn-Time
2017-10-26 17:19 - 2017-10-26 17:50 - 000000000 ____D C:\Users\philippe\AppData\Local\Popcorn-Time
C:\Users\philippe\AppData\Local\Yandex
Task: {DD8E8B05-071A-4A72-8C16-7DF5AE0C0FF1} - System32\Tasks\TweakBit\Internet Optimizer\Start Internet Optimizer automatic scanning => C:\Program Files (x86)\TweakBit\Internet Optimizer\InternetOptimizer.exe
Task: {79C96FF5-11DE-4CE0-8057-DF8FCED28807} - System32\Tasks\Update for Yandex Browser => C:\Users\philippe\AppData\Local\Yandex\YandexBrowser\Application\browser.exe
Task: C:\WINDOWS\Tasks\Update for Yandex Browser.job => C:\Users\philippe\AppData\Local\Yandex\YandexBrowser\Application\browser.exe
AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`27hfm [0]
IE trusted site: HKU\S-1-5-21-1345798209-2535738462-2939399751-1001\...\webcompanion.com ->
hxxp://webcompanion.comRemoveProxy:
EmptyTemp:
End::