Rapport de ZHPFix 2015.10.19.9 par Nicolas Coolman, Update du 19/10/2015 Fichier d'export Registre : Run by corinne at 23/06/2016 15:16:44 High Elevated Privileges : OK Windows 8 Home Premium Edition, 64-bit Service Pack 1 (10586) Corbeille vidée (00mn 05s) Dossier Prefetcher vidé Réparation des raccourcis navigateur ========== Logiciels ========== SUPPRIMÉ: DriverUpdate ========== Processus mémoire ========== SUPPRIMÉ: Memory Process: C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe SUPPRIMÉ: Memory Process: C:\Users\corinne\Downloads\ReimageRepair (1).exe SUPPRIMÉ: Memory Process: C:\Users\corinne\Downloads\ReimageRepair.exe SUPPRIMÉ: Memory Process: C:\Users\corinne\AppData\Local\Microsoft\Windows\INetCache\IE\W5KR3P3J\ProtectorPackage2010x64a[1].exe SUPPRIMÉ: Memory Process: C:\Users\corinne\AppData\Local\Microsoft\Windows\INetCache\IE\W5KR3P3J\ReimagePackage1838x64[1].exe ========== Clés du Registre ========== SUPPRIMÉ: [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{0894C096-1F06-4D2E-A53E-5E28F13DDEE6}] SUPPRIMÉ: [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\DriverUpdate] SUPPRIMÉ: HKCU\SOFTWARE\Security Cleaner llc SUPPRIMÉ: Service: SlimService SUPPRIMÉ: HKLM\SOFTWARE\Wow6432Node\SlimWare Utilities, Inc. SUPPRIMÉ: HKCU\SOFTWARE\Reimage SUPPRIMÉ: HKCU\SOFTWARE\Security Cleaner Branche de Base de Registres IFEO non infectée ! ========== Valeurs du Registre ========== Aucune Valeur Standard Profile: FirewallRaz : Aucune Valeur Domain Profile: FirewallRaz : SUPPRIMÉ: FirewallRaz (None) : MCX-Prov-Out-TCP SUPPRIMÉ: FirewallRaz (None) : MCX-McrMgr-Out-TCP ProxyFix : Configuration proxy supprimée avec succès SUPPRIMÉ ProxyServer Value SUPPRIMÉ ProxyEnable Value SUPPRIMÉ EnableHttp1_1 Value SUPPRIMÉ ProxyHttp1.1 Value SUPPRIMÉ ProxyOverride Value ========== Eléments de donnée du Registre ========== SUPPRIMÉ TCPIP: DhcpNameServer = 40.33.1.55 ========== Préférences navigateur ========== PRESENT Chrome File: C:\Users\corinne\AppData\Local\Google\Chrome\User Data\Default\Preferences ABSENT Chrome Site: http://i_skyntjs_info.tlscdn.com PRESENT Chrome File: C:\Users\corinne\AppData\Local\Google\Chrome\User Data\Default\Preferences SUPPRIMÉ Chrome Site: http://onlinemegax.com SUPPRIMÉ Chrome Site: http://onlinemegax.com SUPPRIMÉ Chrome Site: http://onlinemegax.com SUPPRIMÉ Chrome Site: http://onlinemegax.com SUPPRIMÉ Chrome Site: http://onlinemegax.com SUPPRIMÉ Chrome Site: http://onlinemegax.com PRESENT Chrome File: C:\Users\corinne\AppData\Local\Google\Chrome\User Data\Default\Preferences SUPPRIMÉ Chrome Site: http://serve.adsvmedia.com SUPPRIMÉ Chrome Site: http://serve.adsvmedia.com SUPPRIMÉ Folder Chrome: C:\Users\corinne\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbhfhidkikgajkbdljplcmihkhhjghil SUPPRIMÉ Mozilla Pref: https://homepage-web.com/?s=acer&m=start SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._e5Members_.BUTTON_STRUCTURE", "[{\"b\":224233618,\"c\":\"mindspark.magnify\",\"p\":\"L.0\[...] SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._e5Members_.browser.startup.homepage.savedPrev", "true"); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._e5Members_.browser.startup.homepage.tb", "http://hp.myway.com/productivityboss/ttab02/ind[...] SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._e5Members_.browser.startup.page.savedPrev", 1); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._e5Members_.browser.startup.page.tb", 1); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._e5Members_.browser.version.last", "38.0"); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._e5Members_.coId", "198a57c474804422932fa6988028205c"); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._e5Members_.firstKnownVersion", "7.70.9.27869"); ABSENT Mozilla Pref: user_pref("extensions.toolbar.mindspark._e5Members_.homepage", "http://hp.myway.com/productivityboss/ttab02/index.html?coId=198a57[...] SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._e5Members_.hp.enabled", true); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._e5Members_.hp.guardType", "HPR"); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._e5Members_.hp.user.defined", false); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._e5Members_.initialized", true); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._e5Members_.installType", "XPI"); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._e5Members_.installation.dlpCountryCode", "FR"); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._e5Members_.installation.installDate", "2016042809"); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._e5Members_.installation.partnerId", "^BYM^xdm009^TTAB02^fr"); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._e5Members_.installation.pixelUrl", "http://www.productivityboss.com/install_pixels.jhtml?[...] SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._e5Members_.installation.success", true); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._e5Members_.installation.toolbarId", "B0B04906-17EA-4E15-A547-B9688F158FD0"); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._e5Members_.lastActivePing", "1464105906004"); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._e5Members_.lastKnownVersion", "7.70.9.27869"); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._e5Members_.lssState", "{\"previousLocales\":[\"fr\",\"fr-FR\",\"en-US\",\"en\"],\"support[...] SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._e5Members_.options.defaultSearch", false); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._e5Members_.options.homePageEnabled", true); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._e5Members_.options.keywordEnabled", false); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._e5Members_.options.tabEnabled", true); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._e5Members_.partnerPixelFired", true); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._e5Members_.productDeliveryOption.language", "en"); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._e5Members_.productDeliveryOption.newTabURL", "http://hp.myway.com/productivityboss/ttab02[...] SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._e5Members_.productDeliveryOption.type", "ToolTab"); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._e5Members_.successUrl", "http://www.productivityboss.com/installComplete.jhtml"); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._e5Members_.toolbarCollapsed", false); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._e5Members_.uninstallSurveyUrl", "http://www.research.net/r/HYSCVNM?CBID=&[...] SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._e5Members_.uninstallTasks", "{\"prefBranchesToDelete\":[\"extensions.toolbar.mindspark._e[...] SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._exMembers_.BUTTON_STRUCTURE", "[{\"b\":224324440,\"c\":\"mindspark.magnify\",\"p\":\"L.0\[...] SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._exMembers_.browser.startup.homepage.prev", "http://hp.myway.com/productivityboss/ttab02/i[...] SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._exMembers_.browser.startup.homepage.savedPrev", "true"); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._exMembers_.browser.startup.homepage.tb", "http://hp.myway.com/easydocmerge/ttab02/index.h[...] SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._exMembers_.browser.startup.page.savedPrev", 1); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._exMembers_.browser.startup.page.tb", 1); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._exMembers_.browser.version.last", "38.0"); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._exMembers_.coId", "2df2eb36151e4eb98f3524b21466765f"); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._exMembers_.firstKnownVersion", "7.70.9.27615"); ABSENT Mozilla Pref: user_pref("extensions.toolbar.mindspark._exMembers_.homepage", "http://hp.myway.com/easydocmerge/ttab02/index.html?coId=2df2eb3615[...] SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._exMembers_.hp.enabled", true); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._exMembers_.hp.guardType", "HPR"); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._exMembers_.hp.user.defined", false); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._exMembers_.initialized", true); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._exMembers_.installType", "XPI"); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._exMembers_.installation.dlpCountryCode", "FR"); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._exMembers_.installation.installDate", "2016042809"); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._exMembers_.installation.partnerId", "^BYU^xdm116^TTAB02^fr"); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._exMembers_.installation.partnerSubId", "22930442001"); ABSENT Mozilla Pref: user_pref("extensions.toolbar.mindspark._exMembers_.installation.pixelUrl", "http://www.easydocmerge.com/install_pixels.jhtml?part[...] SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._exMembers_.installation.success", true); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._exMembers_.installation.toolbarId", "657D6AB8-4F43-4D27-9C17-1A79F1471DCD"); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._exMembers_.lastActivePing", "1464105906032"); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._exMembers_.lastKnownVersion", "7.70.9.27615"); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._exMembers_.lssState", "{\"previousLocales\":[\"fr\",\"fr-FR\",\"en-US\",\"en\"],\"support[...] SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._exMembers_.options.defaultSearch", false); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._exMembers_.options.homePageEnabled", true); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._exMembers_.options.keywordEnabled", false); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._exMembers_.options.tabEnabled", true); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._exMembers_.partnerPixelFired", true); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._exMembers_.productDeliveryOption.language", "en"); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._exMembers_.productDeliveryOption.newTabURL", "http://hp.myway.com/easydocmerge/ttab02/ind[...] SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._exMembers_.productDeliveryOption.type", "ToolTab"); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._exMembers_.successUrl", "http://www.easydocmerge.com/installComplete.jhtml"); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._exMembers_.toolbarCollapsed", false); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._exMembers_.uninstallSurveyUrl", "http://www.research.net/r/HYSCVNM?CBID=&[...] SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark._exMembers_.uninstallTasks", "{\"prefBranchesToDelete\":[\"extensions.toolbar.mindspark._e[...] SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark.hp.enabled", true); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark.hp.enabled.guid", "productivityboss@mindspark.com"); SUPPRIMÉ Mozilla Pref: user_pref("extensions.toolbar.mindspark.lastInstalled", "easydocmerge@mindspark.com"); ========== Dossiers ========== SUPPRIMÉ: C:\Users\corinne\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbhfhidkikgajkbdljplcmihkhhjghil SUPPRIMÉ: C:\Program Files\SlimCleaner Plus SUPPRIMÉ: C:\Program Files\SlimService SUPPRIMÉ: c:\program files\reimage SUPPRIMÉ: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Security Cleaner llc SUPPRIMÉ: c:\program files (x86)\security cleaner llc SUPPRIMÉS Temporaires Windows (38) SUPPRIMÉS Flash Cookies (0) ========== Fichiers ========== SUPPRIMÉ: c:\program files\slimservice\slimservicefactory.exe SUPPRIMÉ: c:\windows\prefetch\printcreations_softonic_tbyb_-50fc5bac.pf SUPPRIMÉ: c:\windows\prefetch\reimage.exe-02b30964.pf SUPPRIMÉ: c:\windows\prefetch\reimagepackage.exe-9ed2b7e2.pf SUPPRIMÉ: c:\windows\prefetch\reimagerepair (1).exe-ecb4d5d2.pf SUPPRIMÉ: c:\windows\prefetch\reimagerepair.exe-a4ab23f0.pf SUPPRIMÉS Temporaires Windows (809) (77 241 491 octets) SUPPRIMÉS Flash Cookies (0) (0 octets) ========== Fichier HOSTS ========== Le fichier Hosts est sain ========== Tache planifiée ========== SUPPRIMÉ: DriverUpdate Scan SUPPRIMÉ: DriverUpdate Startup ========== Restauration Système ========== Point de restauration du système créé avec succès ========== Autre ========== NON TRAITÉ O4 - GS\CommonDesktop [Public]: Booking.com.lnk . (...) C:\Program Files (x86)\Booking.COM\StartURL.exe NON TRAITÉ O4 - GS\CommonDesktop [Public]: DriverUpdate.lnk . (...) C:\WINDOWS\Installer\{0894C096-1F06-4D2E-A53E-5E28F13DDEE6}\Icon.exe NON TRAITÉ O4 - GS\CommonDesktop [Public]: eBay.lnk . (...) c:\Windows\Installer\{3DC26EA7-03E3-4353-9424-EEB7A34A7504}\_697C8F93ABDF89FB4ABDD9.exe NON TRAITÉ O4 - GS\CommonDesktop [Public]: Indispensables.lnk . (.Security Cleaner llc - Logiciels indispensables.) C:\Users\corinne\Logiciel.exe {6DA7EB4D0BD23D6371F00F71EB9A5581} NON TRAITÉ O4 - GS\CommonDesktop [Public]: SlimCleaner Plus.lnk . (...) C:\Windows\Installer\{393BB488-92C4-4F25-92D9-599C21A19D89}\Icon.exe NON TRAITÉ O4 - GS\CommonDesktop [Public]: PC Scan & Repair by Reimage.lnk . (.Reimage - Reimage Downloader.) C:\Program Files\Reimage\Reimage Repair\ReimageRepair.exe {4320101ADF7A07C7405BC4433AE31FFD} NON TRAITÉ [HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Reimage Protector] NON TRAITÉ [HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Reimage Repair] NON TRAITÉ [HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{393BB488-92C4-4F25-92D9-599C21A19D89}] NON TRAITÉ O4 - GS\CommonDesktop [Public]: Browser Cleaner.lnk . (.Security Cleaner llc - Browser Cleaner Application.) C:\Program Files (x86)\Security Cleaner llc\Browser Cleaner\BrowserCleaner.exe {6DA7EB4D0BD23D6371F00F71EB9A5581} NON TRAITÉ O4 - GS\CommonDesktop [Public]: System Optimizer.lnk . (.Security Cleaner - SystemOptimizer 2016.) C:\Program Files (x86)\Security Cleaner llc\System Optimizer\SystemOptimizer.exe {6DA7EB4D0BD23D6371F00F71EB9A5581} NON TRAITÉ [HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Security Cleaner llc System Optimizer] ========== Récapitulatif ========== 5 : Processus mémoire 8 : Clés du Registre 10 : Valeurs du Registre 1 : Eléments de donnée du Registre 8 : Dossiers 8 : Fichiers 1 : Logiciels 89 : Préférences navigateur 1 : Fichier HOSTS 2 : Tache planifiée 1 : Restauration Système 12 : Autre End of clean in 04mn 16s ========== Chemin de fichier rapport ========== C:\Users\corinne\AppData\Roaming\ZHP\ZHPFix[R1].txt - 23/06/2016 15:16:51 [15586]