start CreateRestorePoint: closeProcesses: ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Pas de fichier ContextMenuHandlers1-x32: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => -> Pas de fichier ContextMenuHandlers3: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} => -> Pas de fichier ContextMenuHandlers4-x32: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files (x86)\7-Zip\7-zip.dll -> Pas de fichier ContextMenuHandlers6-x32: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files (x86)\7-Zip\7-zip.dll -> Pas de fichier ContextMenuHandlers4-x32: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> Pas de fichier ContextMenuHandlers6-x32: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> Pas de fichier Task: {1025F6D6-21A2-43C1-9022-0A794F98490C} - System32\Tasks\ByteFence => C:\Program Files\ByteFence\ByteFence.exe [2017-10-03] (Byte Technologies LLC) <==== ATTENTION Task: {AFBBB1B2-E466-4F04-AEEA-36EE9CABA4BD} - System32\Tasks\ReimageUpdater => C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe <==== ATTENTION 2017-10-26 22:26 - 2017-10-26 22:27 - 000302920 _____ () C:\Program Files\ByteFence\rtop\bin\rtop_svc.exe 2017-03-07 19:18 - 2017-03-07 19:18 - 000582936 _____ () C:\Program Files\ByteFence\rsLggr.exe 2017-10-26 22:26 - 2017-10-26 22:27 - 000620872 _____ () C:\Program Files\ByteFence\rtop\bin\rtop_bg.exe 2016-05-25 13:38 - 2016-05-25 13:38 - 000129304 _____ () C:\Program Files\ByteFence\x64\lz4_x64.dll AlternateDataStreams: C:\ProgramData\Temp:1CE11B51 [190] SearchScopes: HKLM -> {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://fr.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms} SearchScopes: HKLM-x32 -> {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://fr.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms} SearchScopes: HKU\S-1-5-21-1459901259-3685812830-3045488267-1001 -> DefaultScope {A352AC5F-6DAA-49BB-BFB5-4D9267A5D087} URL = SearchScopes: HKU\S-1-5-21-1459901259-3685812830-3045488267-1001 -> {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://fr.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms} BHO: True Key Helper -> {0F4B8786-5502-4803-8EBC-F652A1153BB6} -> C:\Program Files\Intel Security\True Key\MSIE\truekey_ie64.dll => Pas de fichier BHO-x32: True Key Helper -> {0F4B8786-5502-4803-8EBC-F652A1153BB6} -> C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll => Pas de fichier Toolbar: HKLM-x32 - True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll Pas de fichier FF DefaultSearchEngine: Mozilla\Firefox\Profiles\h0qr3jbw.default -> Web Search FF SelectedSearchEngine: Mozilla\Firefox\Profiles\h0qr3jbw.default -> Web Search R2 ByteFenceService; C:\Program Files\ByteFence\ByteFenceService.exe [156640 2017-10-03] (Byte Technologies LLC) R2 rtop; C:\Program Files\ByteFence\rtop\bin\rtop_svc.exe [302920 2017-10-26] () 2017-10-27 01:58 - 2017-10-27 01:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ByteFence Anti-Malware 2017-10-26 22:26 - 2017-10-26 22:26 - 000000000 ____D C:\ProgramData\ByteFence 2017-10-26 22:15 - 2017-10-26 22:39 - 000000000 ____D C:\ProgramData\AVAST Software 2017-10-26 22:15 - 2017-10-26 22:34 - 000000000 ____D C:\Program Files (x86)\Booking 2017-10-26 22:15 - 2017-10-26 22:23 - 000000000 ____D C:\Program Files\WebDiscoverBrowser 2017-10-26 22:15 - 2017-10-26 22:15 - 000003454 _____ C:\WINDOWS\System32\Tasks\ByteFence 2017-10-26 22:15 - 2017-10-26 22:15 - 000000000 ____D C:\Users\jazzn\AppData\Roaming\WOW 2017-10-26 22:14 - 2017-10-26 22:45 - 000000000 ____D C:\Program Files\ByteFence 2017-10-25 23:10 - 2017-10-26 22:39 - 000000000 ____D C:\Program Files\Plumbytes Software 2017-10-25 23:10 - 2017-10-25 23:10 - 000000000 ____D C:\Users\jazzn\AppData\Local\{12A8CCFE-3C33-4995-BAD8-074E4C5B22FD} 2017-10-25 22:26 - 2017-10-25 22:28 - 000000000 ____D C:\rei C:\Program Files\Intel Security C:\Program Files (x86)\7-Zip virustotal: C:\autoexec.bat hosts: emptytemp: end