start::
closeprocesses:
createrestorepoint:
CustomCLSID: HKU\S-1-5-21-92845616-3661918259-1759182592-1001_Classes\CLSID\{14100442-9664-1407-2647-000000000000}\localserver32 -> "C:\Users\alexy\AppData\Local\Wondershare\Wondershare NativePush\WsToastNotification.exe" -ToastActivated => Pas de fichier
CustomCLSID: HKU\S-1-5-21-92845616-3661918259-1759182592-1001_Classes\CLSID\{2F81B25E-7507-4844-BFF2-77D2CC24CED4}\localserver32 -> "C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" -ToastActivated => Pas de fichier
AV: BullGuard Antivirus (Disabled - Out of date) {0C5A09FB-657F-B94D-DF1B-BB843C6EE0E4}
FW: BullGuard Firewall (Enabled) {346188DE-2F10-B815-F444-12B1C2BDA79F}
AlternateDataStreams: C:\Users\alexy\Application Data:00e481b5e22dbe1f649fcddd505d3eb7 [394]
AlternateDataStreams: C:\Users\alexy\AppData\Roaming:00e481b5e22dbe1f649fcddd505d3eb7 [394]
SearchScopes: HKU\S-1-5-21-92845616-3661918259-1759182592-1001 -> DefaultScope {097C1C62-B6C5-4298-8AD7-15708B4D01E0} URL =
HKLM\...\StartupApproved\Run32: => "Wondershare Helper Compact.exe"
C:\Users\alexy\OneDrive\Bureau\Project Zomboid (v41.78.16) By STG GEGE
HKLM-x32\...\Run: [Backup] => C:\Program Files (x86)\Wondershare\drfone\Addins\Backup\DrFoneBackup.exe /hide (Pas de fichier)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKU\S-1-5-21-92845616-3661918259-1759182592-1001\...\Run: [QMxNetworkSync] => C:\Program Files\Common Files\MAGIX Services\Update Notifier\QMxNetworkSync.exe (Pas de fichier)
HKLM\Software\...\Authentication\Credential Providers: [{C885AA15-1764-4293-B82A-0586ADD46B35}] ->
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WSAndroidAppHelper.lnk [2023-02-02]
ShortcutTarget: WSAndroidAppHelper.lnk -> C:\Program Files (x86)\Wondershare\drfone\Addins\SocialApps\WSAndroidAppHelper.exe (Pas de fichier)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WSAppHelper.lnk [2023-02-02]
ShortcutTarget: WSAppHelper.lnk -> C:\Program Files (x86)\Wondershare\drfone\Addins\SocialApps\WSAppHelper.exe (Pas de fichier)
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION
Task: {7B2840F3-0022-4191-BD7B-72A773BC99E8} - System32\Tasks\ChromsteraUpdater => C:\Program Files (x86)\Chromstera Browser\ChromsteraUpdater.exe [1204192 2023-09-11] (Dragon Boss Solutions LLC -> Chromstera Browser Solutions) <==== ATTENTION
C:\Program Files (x86)\Chromstera Browser
Task: {CCDFC0B8-01A3-4E74-A820-4F13F51D269E} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => %SystemRoot%\System32\MbaeParserTask.exe (Pas de fichier)
Task: {331B9606-2F66-4228-ABE7-ADFD00457DFD} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\MusUx_LogonUpdateResults => %systemroot%\system32\MusNotification.exe LogonUpdateResults (Pas de fichier)
Task: {0B27949A-FC60-4EC8-8CD8-3CDDAEEC1199} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\MusUx_UpdateInterval => %systemroot%\system32\MusNotification.exe Display (Pas de fichier)
Task: {43B3D2CF-D53A-44A4-BDF9-299B928A5DC9} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_AC => %systemroot%\system32\MusNotification.exe /RunOnAC ReadyToReboot (Pas de fichier)
Task: {21F9C5F8-70A0-4AB7-93A4-752DBC8C30D5} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery => %systemroot%\system32\MusNotification.exe /RunOnBattery ReadyToReboot (Pas de fichier)
Task: {E0F10DCF-44AD-40E8-9370-FB5DA59F93FB} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (Pas de fichier)
Task: {0BC78A35-15DA-49AA-A14C-99FA94CD2B2C} - System32\Tasks\Opera scheduled Autoupdate 1627028320 => C:\Users\alexy\AppData\Local\Programs\Opera\launcher.exe --scheduledautoupdate $(Arg0) (Pas de fichier)
Task: {A4CBC0B1-FD02-4BFB-A9F4-99FF5339B33E} - System32\Tasks\Opera scheduled Autoupdate 1629318105 => C:\Users\alexy\AppData\Local\Programs\Opera\launcher.exe --scheduledautoupdate $(Arg0) (Pas de fichier)
Task: {61E3C83C-0350-4C43-9E4B-426DF39156EC} - System32\Tasks\Opera scheduled Autoupdate 1657201685 => C:\Users\alexy\AppData\Local\Programs\Opera\launcher.exe --scheduledautoupdate $(Arg0) (Pas de fichier)
Task: {2C2559EB-169B-405B-816E-B46A98D45D14} - System32\Tasks\Opera scheduled Autoupdate 1668087603 => C:\Users\alexy\AppData\Local\Programs\Opera\launcher.exe --scheduledautoupdate $(Arg0) (Pas de fichier)
Task: {DC6EB578-7052-46A5-8847-F8C3F432AB53} - System32\Tasks\PC HelpSoft Driver Updater automatic scan and new device notifications => "C:\Program Files (x86)\PC HelpSoft Driver Updater\PCHelpSoftDriverUpdater.exe" /TRAY (Pas de fichier) <==== ATTENTION
C:\Program Files (x86)\PC HelpSoft Driver Updater
C:\Users\alexy\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\kgpincabapnpelfophhngnaegimbbipf
C:\apps-helper
C:\Users\alexy\AppData\Local\Google\Chrome\User Data\Default\Extensions\kgpincabapnpelfophhngnaegimbbipf
CHR HKLM-x32\...\Chrome\Extension: [aegnopegbbhjeeiganiajffnalhlkkjb]
CHR HKLM-x32\...\Chrome\Extension: [kgpincabapnpelfophhngnaegimbbipf] - C:\\Users\\alexy\\AppData\\Local\\apps.crx [2023-09-11]
CHR HKLM-x32\...\Chrome\Extension: [mfhcmdonhekjhfbjmeacdjbhlfgpjabp]
S2 DFWSIDService; C:\ProgramData\Wondershare\wsServices\WsidService.exe [X]
S2 WirelessBackupService; C:\Program Files (x86)\Wondershare\drfone\Addins\Backup\WirelessBackupService.exe [X]
S2 Wondershare InstallAssist; C:\ProgramData\Wondershare\Service\InstallAssistService.exe [X]
S3 WsDrvInst; "C:\Program Files (x86)\Wondershare\drfone\Addins\Repair\DriverInstall.exe" [X]
2023-09-22 18:35 - 2023-09-22 18:35 - 000000000 ____D C:\ProgramData\Chromstera Browser Solutions
2023-09-11 18:02 - 2023-09-11 18:02 - 000000000 ____D C:\Users\alexy\AppData\Local\Chromstera
2023-09-11 18:00 - 2023-09-11 18:02 - 000000000 ____D C:\Program Files (x86)\Chromstera Browser
2023-09-11 18:00 - 2023-09-11 18:00 - 000012135 _____ C:\Users\alexy\AppData\Local\apps.crx
2023-09-11 18:00 - 2023-09-11 18:00 - 000004342 _____ C:\WINDOWS\system32\Tasks\ChromsteraUpdater
2023-09-11 18:00 - 2023-09-11 18:00 - 000000000 ____D C:\apps-helper
cmd: netsh advfirewall reset
emptytemp:
end::