cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

Rapport de ZHPFix 2015.2.17.3 par Nicolas Coolman, Update du 17/02/2015
Fichier d'export Registre :
Run by ll at 14/03/2015 13:34:45
High Elevated Privileges : OK
Windows 7 Ultimate Edition, 32-bit Service Pack 1 (Build 7601)

Recycle Bin emptied (00mn 06s)

========== Process memory ==========
REMOVES: Memory Process: C:\Windows\AutoKMS\AutoKMS.exe
ABSENT Memory Process: O34 - HKLM BootExecute: (autocheck autochk /p \??\F:) - File not found
ABSENT Memory Process: O34 - HKLM BootExecute: (autocheck autochk /p \??\G:) - File not found
ABSENT Memory Process: O34 - HKLM BootExecute: (autocheck autochk *) - File not found
ABSENT Memory Process: O34 - HKLM BootExecute: (PCloudBroom.exe \systemroot\system32\BroomData.bit) - File not found

========== Registry keys ==========
REMOVES: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Registry Reviver
REMOVES: HKLM\Software\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
REMOVES: HKLM\Software\7f91a117-e484-4378-ac02-78b69dbf1cf9
REMOVES: HKLM\Software\RegistryReviver
REMOVES: HKLM\Software\StrongSignal
REMOVES: Mozilla Plugin: @haihaisoft/HPReader_Plugin
REMOVES: Mozilla Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.2
REMOVES: Mozilla Plugin: @real.com/nprndlhtml5videoshim;version=1.3.2
REMOVES: Mozilla Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.2
REMOVES: Mozilla Plugin: @realnetworks.com/npdlplugin;version=1
REMOVES: Mozilla Plugin: Adobe Reader
REMOVES: Service: SparkSvc
REMOVES CLSID MPSK: {11f9ee9e-a549-11e2-a3c6-e981dcdd70e7}
REMOVES CLSID MPSK: {11f9eec0-a549-11e2-a3c6-001e101f7f74}
REMOVES CLSID MPSK: {4cadc160-a4f3-11e2-bf3d-c45d5fefedfb}
REMOVES CLSID MPSK: {5de9beec-a70c-11e4-9723-d2ecdce15c73}
REMOVES CLSID MPSK: {5de9bf8b-a70c-11e4-9723-d2ecdce15c73}
REMOVES CLSID MPSK: {5de9c3c9-a70c-11e4-9723-d2ecdce15c73}
REMOVES CLSID MPSK: {5de9c461-a70c-11e4-9723-d2ecdce15c73}
REMOVES CLSID MPSK: {60cdd0be-3434-11e4-9bf2-0207450e1be0}
REMOVES CLSID MPSK: {743459aa-a421-11e2-86e9-002264554f19}
REMOVES CLSID MPSK: {743459b7-a421-11e2-86e9-002264554f19}
REMOVES CLSID MPSK: {871c7bb5-a994-11e4-971f-e4e1ab749c82}
REMOVES CLSID MPSK: {a38c18df-9eab-11e2-bebb-002264554f19}
REMOVES CLSID MPSK: {a38c191b-9eab-11e2-bebb-002264554f19}
REMOVES CLSID MPSK: {a38c1936-9eab-11e2-bebb-002264554f19}
REMOVES CLSID MPSK: {e0d0beb7-ac90-11e4-8888-af02681663fd}
REMOVES CLSID MPSK: {e5bbb80f-6509-11e2-934a-806e6f6e6963}
REMOVES: StartupReg: APSDaemon
REMOVES: StartupReg: BlueStacks Agent
REMOVES: StartupReg: CanonQuickMenu
REMOVES: StartupReg: iTunesHelper
REMOVES: StartupReg: msnmsgr
REMOVES: StartupReg: Skype
REMOVES: SearchScopes :{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}
REMOVES: SearchScopes :{E733165D-CBCF-4FDA-883E-ADEF965B476C}

========== Registry values ==========
REMOVES: URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497}
ABSENT value Standard Profile: FirewallRaz :
ABSENT value Domain Profile: FirewallRaz :
ProxyFix : Proxy configuration successfully removed
REMOVES ProxyServer Value
REMOVES ProxyEnable Value
REMOVES EnableHttp1_1 Value
REMOVES ProxyHttp1.1 Value
REMOVES ProxyOverride Value

========== Elements of the registry data ==========
REMOVES: R1 Search Page = res://ieframe.dll/tabswelcome.htm
REMOVES TCPIP: NameServer = 8.8.8.8,4.4.8.8
REMOVES TCPIP: NameServer = 62.251.230.241 212.217.1.1
REMOVES TCPIP: NameServer = 212.217.0.1,212.217.0.40
REMOVES TCPIP: NameServer = 212.217.0.12 212.217.1.12
REMOVES TCPIP: DhcpNameServer = 192.168.1.1
REMOVES: StartMenuInternet: C:\Program Files\baidu\Spark\Spark.exe

========== Folders ==========
REMOVES: c:\users\ll\appdata\roaming\mozilla\firefox\profiles\t66gteiu.default\retrogamer_4w
Deletes temporary Windows (48)
REMOVES Flash Cookies (0)

========== Files ==========
REMOVES: c:\users\ll\appdata\roaming\mozilla\firefox\profiles\t66gteiu.default\extensions\{e6c1199f-e687-42da-8c24-e7770cc3ae66}.xpi
REMOVES: c:\users\public\desktop\mozilla firefox.lnk (http://www.omniboxes.com)
CREATES: C:\Users\Public\Desktop\Mozilla Firefox.lnk
REMOVES: c:\users\ll\appdata\roaming\microsoft\internet explorer\quick launch\google chrome.lnk (http://www.omniboxes.com)
CREATES: C:\Users\ll\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
REMOVES: c:\users\ll\appdata\roaming\microsoft\internet explorer\quick launch\launch internet explorer browser.lnk (http://www.omniboxes.com)
CREATES: C:\Users\ll\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
REMOVES: c:\users\ll\appdata\roaming\microsoft\internet explorer\quick launch\user pinned\taskbar\google chrome.lnk (http://www.omniboxes.com)
CREATES: C:\Users\ll\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk
REMOVES: c:\users\ll\appdata\roaming\microsoft\internet explorer\quick launch\user pinned\taskbar\opera.lnk (http://www.omniboxes.com)
REMOVES: c:\program files\opera\launcher.exe
REMOVES: c:\users\ll\appdata\roaming\microsoft\windows\start menu\programs\convertisseur de fichiers en ligne.lnk
REMOVES: c:\users\ll\appdata\roaming\microsoft\windows\start menu\programs\internet explorer.lnk (http://www.omniboxes.com)
CREATES: C:\Users\ll\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
REMOVES: c:\users\ll\appdata\roaming\microsoft\windows\start menu\programs\accessories\system tools\internet explorer (no add-ons).lnk (http://www.omniboxes.com)
CREATES: C:\Users\ll\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
REMOVES: c:\users\ll\desktop\google chrome.lnk (http://www.omniboxes.com)
CREATES: C:\Users\ll\Desktop\Google Chrome.lnk
REMOVES: c:\users\ll\desktop\internet explorer.lnk (http://www.omniboxes.com)
CREATES: C:\Users\ll\Desktop\Internet Explorer.lnk
REMOVES: c:\users\ll\desktop\opera.lnk (http://www.omniboxes.com)
REMOVES: c:\windows\tasks\facebookupdatetaskusers-1-5-21-2329119762-1733588567-290054825-1000core.job
REMOVES: c:\windows\system32\tasks\facebookupdatetaskusers-1-5-21-2329119762-1733588567-290054825-1000core
REMOVES: c:\windows\tasks\facebookupdatetaskusers-1-5-21-2329119762-1733588567-290054825-1000ua.job
REMOVES: c:\windows\system32\tasks\facebookupdatetaskusers-1-5-21-2329119762-1733588567-290054825-1000ua
REMOVES: c:\windows\prefetch\isafe.exe-534ce13e.pf
REMOVES: c:\windows\prefetch\isafesvc.exe-8d0d11aa.pf
REMOVES: c:\windows\prefetch\isafethlp.exe-88bbb3d6.pf
REMOVES: c:\windows\prefetch\istart.exe-37ac45d9.pf
REMOVES: c:\users\ll\appdata\local\temp\tempfolder.aaa\iml32.dll
REMOVES: c:\users\ll\appdata\local\temp\tempfolder.aaa\proj.dll
REMOVES: c:\users\ll\appdata\local\temp\tempfolder.aaa\msvcrt.dll
Deletes temporary Windows (1533) (499�644�102 octets)
REMOVES Flash Cookies (0) (0 octets)

========== Scheduled task ==========
REMOVES: {6C8E528F-77D8-4E9E-AC2F-0C1831D9D54C}
REMOVES: AutoKMS
REMOVES: AutoKMS
REMOVES: {D18707CC-F728-4F57-866F-4FD9A2B3B5C8}

========== System restore ==========
The system successfully created restore point


========== Summary ==========
5 : Process memory
36 : Registry keys
9 : Registry values
7 : Elements of the registry data
3 : Folders
34 : Files
4 : Scheduled task
1 : System restore


End of clean in 01mn 04s

========== Path to file report ==========
C:\Users\ll\AppData\Roaming\ZHP\ZHPFix[R1].txt - 14/03/2015 13:34:51 [7460]

Publicité


Signaler le contenu de ce document

Publicité