Rapport de ZHPFix 2015.10.19.9 par Nicolas Coolman, Update du 19/10/2015 Fichier d'export Registre : Run by DELL at 2015-10-23 1:20:35 AM High Elevated Privileges : OK Windows 8 Home Premium Edition, 64-bit Service Pack 1 (10240) Recycle Bin emptied (34mn AMs) Prefetcher emptied ========== Process memory ========== REMOVES Reboot: Memory Process: C:\Users\DELL\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\TempState\TileCache_100_0_Header.bin [14632] ========== Registry keys ========== REMOVES: CLSID BHO: {B4F3A835-0E21-4959-BA22-42B3008E02FF} REMOVES: [HKLM\SOFTWARE\Classes\CLSID\{B4F3A835-0E21-4959-BA22-42B3008E02FF}] REMOVES: [HKLM\SOFTWARE\Classes\CLSID\{3507FA00-ADA2-4A02-99B9-51AD26CA9120}] REMOVES: HKCU\SOFTWARE\2aOHlaja REMOVES: HKCU\SOFTWARE\Haali REMOVES: HKCU\SOFTWARE\WTjNtlo REMOVES: HKCU\SOFTWARE\Ye7qrQDxd6tcqgch9P4 REMOVES: HKCU\SOFTWARE\ZprUG609 REMOVES: SearchScopes :${searchCLSID} REMOVES: SearchScopes :{0633EE93-D776-472f-A0FF-E1416B8B2E3A} REMOVES: HKLM\SYSTEM\CurrentControlSet\Services\KMService ========== Registry values ========== ABSENT value Standard Profile: FirewallRaz : ABSENT value Domain Profile: FirewallRaz : REMOVES: FirewallRaz (None) : MCX-Prov-Out-TCP REMOVES: FirewallRaz (None) : MCX-McrMgr-Out-TCP REMOVES: FirewallRaz (None) : {A59D28BD-D81B-42D3-B512-52A214AA8812} REMOVES: FirewallRaz (Public) : {9D0E8097-C566-456D-8814-C4F4FE046092} REMOVES: FirewallRaz (Public) : {36083B94-D3B3-443A-8BF4-F0063825C392} REMOVES: FirewallRaz (None) : {EB667F66-2C29-4587-960A-E199FB3B757D} REMOVES: FirewallRaz (Domain) : {E7985E1D-C36F-4787-80A8-6350D07E9266} REMOVES: FirewallRaz (None) : {808F1451-4108-46FD-ADBB-F17324B5F0BD} REMOVES: FirewallRaz (Private) : {12ACC0D9-FAF3-43E3-9524-68271CEEC0DB} REMOVES: FirewallRaz (Private) : {22C9D884-F7C1-4912-B647-B5BF28E5E3CA} REMOVES: URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} REMOVES: Toolbar: {3507FA00-ADA2-4A02-99B9-51AD26CA9120} REMOVES RunValue: QuickSet REMOVES RunValue: IntelTBRunOnce REMOVES RunValue: iTunesHelper REMOVES RunValue: OneDrive REMOVES RunValue: BingSvc REMOVES RunValue: IDMan REMOVES RunValue: Google Update REMOVES RunValue: IAStorIcon REMOVES RunValue: RemoteControl10 REMOVES RunValue: BCSSync REMOVES RunValue: SunJavaUpdateSched REMOVES RunValue: OneDriveSetup ========== Preferences browser ========== NOW Chrome File: C:\Users\DELL\AppData\Local\Google\Chrome\User Data\Default\Preferences REMOVES Chrome Site: http://home.searchpile.com REMOVES Chrome Site: http://home.searchpile.com NOW Chrome File: C:\Users\DELL\AppData\Local\Google\Chrome\User Data\Default\Preferences REMOVES Chrome Site: http://searchinterneat-a.akamaihd.net NOW Chrome File: C:\Users\DELL\AppData\Local\Google\Chrome\User Data\Default\Preferences ABSENT Chrome Site: http://www.linkszb.com NOW Chrome File: C:\Users\DELL\AppData\Local\Google\Chrome\User Data\Default\Preferences ABSENT Chrome Site: http://clients1.google.com NOW Chrome File: C:\Users\DELL\AppData\Local\Google\Chrome\User Data\Default\Preferences ABSENT Chrome Site: http://ssl.gstatic.com NOW Chrome File: C:\Users\DELL\AppData\Local\Google\Chrome\User Data\Default\Preferences ABSENT Chrome Site: http://www.google.com.bh ========== Folders ========== Deletes temporary Windows (89) REMOVES Flash Cookies (0) ========== Files ========== Deletes temporary Windows (722) (397,112,138 octets) REMOVES Flash Cookies (0) (0 octets) REMOVES: c:\program files (x86)\microsoft office\office14\urlredir.dll REMOVES: c:\program files\dell\quickset\quickset.exe REMOVES: c:\windows\system32\wscript.exe REMOVES: c:\program files\itunes\ituneshelper.exe REMOVES: c:\users\dell\appdata\local\microsoft\onedrive\onedrive.exe REMOVES: c:\users\dell\appdata\local\microsoft\bingsvc\bingsvc.exe REMOVES: c:\users\dell\appdata\local\google\update\googleupdate.exe REMOVES: c:\windows\syswow64\onedrivesetup.exe REMOVES Reboot: c:\windows\syswow64\onedrivesetup.exe REMOVES Reboot: c:\users\dell\appdata\local\microsoft\onedrive\onedrive.exe REMOVES Reboot: c:\users\dell\appdata\local\microsoft\bingsvc\bingsvc.exe REMOVES Reboot: c:\program files (x86)\internet download manager\idman.exe REMOVES: c:\windows\prefetch\globalupdate.exe-c50783d1.pf REMOVES: c:\users\dell\downloads\programs\avira_internet_security_en.exe REMOVES: c:\users\dell\downloads\programs\dj2540_188.exe REMOVES: c:\users\dell\appdata\local\packages\microsoft.microsoftedge_8wekyb3d8bbwe\ac\microsoftedge\urlblock\urlblock_635806931140836907.bin REMOVES: c:\users\dell\appdata\local\microsoft\windows\inetcache\ie\lvzjj2e6\installer[1].exe REMOVES: c:\users\dell\appdata\local\microsoft\windows\inetcache\ie\lvzjj2e6\setup[2].exe REMOVES: c:\users\dell\appdata\local\microsoft\windows\inetcache\ie\lvzjj2e6\vopackage[1].exe REMOVES: c:\users\dell\appdata\local\microsoft\windows\inetcache\ie\lvzjj2e6\vuupc_vo2_8907[1].exe REMOVES: c:\users\dell\appdata\local\microsoft\windows\inetcache\ie\iy050298\runasu[1].exe REMOVES: c:\users\dell\appdata\local\microsoft\windows\inetcache\ie\iy050298\searchupdater[1].exe REMOVES: c:\users\dell\appdata\local\microsoft\windows\inetcache\ie\iy050298\setup[1].exe REMOVES: c:\users\dell\appdata\local\microsoft\windows\inetcache\ie\eudgxo99\4bbda52393b575e64d530bd478a6717b[1].exe REMOVES: c:\users\dell\appdata\local\microsoft\windows\inetcache\ie\eudgxo99\cmmdwriter[2].exe REMOVES: c:\users\dell\appdata\local\microsoft\windows\inetcache\ie\eudgxo99\jfw3w[1].exe REMOVES: c:\users\dell\appdata\local\microsoft\windows\inetcache\ie\eudgxo99\rcpsetup_17970[1].exe REMOVES: c:\users\dell\appdata\local\microsoft\windows\inetcache\ie\bcus1cd8\installer[1].exe REMOVES: c:\users\dell\appdata\local\microsoft\windows\inetcache\ie\bcus1cd8\josrv[1].exe REMOVES: c:\users\dell\appdata\local\microsoft\windows\inetcache\ie\bcus1cd8\setup[1].exe REMOVES: c:\users\dell\appdata\local\microsoft\windows\inetcache\ie\bcus1cd8\setup_362[1].exe ========== Scheduled task ========== REMOVES: 2aOHlaja REMOVES: 2aOHlaja REMOVES: WTjNtlo REMOVES: WTjNtlo REMOVES: Ye7qrQDxd6tcqgch9P4 REMOVES: Ye7qrQDxd6tcqgch9P4 REMOVES: ZprUG609 REMOVES: ZprUG609 ========== Summary ========== 1 : Process memory 11 : Registry keys 26 : Registry values 2 : Folders 33 : Files 13 : Preferences browser 8 : Scheduled task End of clean in 36mn AMs ========== Path to file report ========== C:\Users\DELL\AppData\Roaming\ZHP\ZHPFix[R1].txt - 2015-10-23 1:22:10 AM [6508]