Start::
SystemRestore: on
CloseProcesses:
CreateRestorePoint:
Removeproxy:
Hosts:
ContextMenuHandlers1: [Gridinsoft Anti-Malware] -> {F77F27A6-89F3-471A-AFA8-3B280940A10C} => -> Pas de fichier
ContextMenuHandlers2: [Gridinsoft Anti-Malware] -> {F77F27A6-89F3-471A-AFA8-3B280940A10C} => -> Pas de fichier
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2022-07-15] (Igor Pavlov) [Fichier non signé]
ContextMenuHandlers4: [Gridinsoft Anti-Malware] -> {F77F27A6-89F3-471A-AFA8-3B280940A10C} => -> Pas de fichier
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
Task: {55F0FE31-F6E6-425D-8BB9-CDF4DE6267D0} - System32\Tasks\BDAntiCryptoWallTask => C:\Program Files\Bitdefender\Tools\AntiCryptoWall\BDAntiCryptoWall.exe [1216264 2015-08-17] (Bitdefender SRL -> )
Task: {1B55A245-E434-43FA-9D9A-EF5EF7F0DB21} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24030.9-0\MpCmdRun.exe -IdleTask -TaskName WdCleanup (Pas de fichier)
Task: {8FA7A5EA-22DC-4848-850F-E1224C071409} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24030.9-0\MpCmdRun.exe Scan -ScheduleJob -ScanTrigger 55 -IdleScheduledJob (Pas de fichier)
Task: {1875D096-B78E-4CE7-97D5-5F58AB9A6175} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24030.9-0\MpCmdRun.exe -IdleTask -TaskName WdVerification (Pas de fichier)
Task: {A77A5AA4-D8F7-47DD-9E37-304328DF072B} - System32\Tasks\GridinSoft Anti-Malware => "C:\Program Files\GridinSoft Anti-Malware\gsam.exe" -startupscan (Pas de fichier)
S2 MDCoreSvc; "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24030.9-0\MpDefenderCoreService.exe" [X]
S3 WdNisSvc; "%ProgramData%\Microsoft\Windows Defender\Platform\4.18.24030.9-0\NisSrv.exe" [X]
S2 WinDefend; "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24030.9-0\MsMpEng.exe" [X]
2024-04-08 15:23 - 2024-04-20 09:31 - 000000000 ____D C:\Users\touggourt\AppData\Roaming\Lavasoft
2024-04-08 11:48 - 2024-04-20 09:31 - 000000000 ____D C:\ProgramData\Lavasoft
cmd: powershell DISM /Online /Cleanup-image /Restorehealth
cmd: powershell sfc /scannow
cmd: ipconfig /flushdns
cmd: netsh advfirewall reset
cmd: netsh advfirewall set allprofiles state on
cmd: netsh winsock reset
Emptytemp:
End::