Rapport de ZHPFix 1.3.15 par Nicolas Coolman, Update du 14/02/2013 Fichier d'export Registre : Run by Christine at 15/02/2013 12:45:04 Windows 7 Home Premium Edition, 64-bit (Build 7600) ========== Logiciel(s) ========== SUPPRIME Advanced System Protector SUPPRIME Iminent ========== Processus mémoire ========== SUPPRIME Memory Process: C:\Program Files (x86)\Common Files\Umbrella\Umbrella.exe SUPPRIME Memory Process: C:\Users\Christine\AppData\Local\Temp\ins7A62.tmp.exe SUPPRIME Memory Process: C:\Users\Christine\AppData\Local\Temp\ins9EB4.tmp.exe SUPPRIME Memory Process: C:\Users\Christine\AppData\Local\Temp\insD71E.tmp.exe SUPPRIME Memory Process: C:\Users\Christine\AppData\Local\Temp\OB.exe SUPPRIME Memory Process: C:\Users\Christine\AppData\Local\Temp\uninst1.exe ========== Clé(s) du Registre ========== SUPPRIME [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{58BC9E49-2867-4153-A23F-6D62A3572599}] SUPPRIME Key: Service: SProtection SUPPRIME Key: HKCU\Software\Iminent SUPPRIME Key: HKLM\Software\Wow6432Node\Umbrella SUPPRIME Key*: HKLM\Software\Classes\Interface\{1B730ACF-26A3-447B-9994-14AEE0EB72CC} ABSENT Key: HKLM\Software\Wow6432Node\Classes\Interface\{1B730ACF-26A3-447B-9994-14AEE0EB72CC} SUPPRIME Key*: HKLM\Software\Classes\Interface\{44B619BC-3D2B-4990-AA4F-9AA366921792} ABSENT Key: HKLM\Software\Wow6432Node\Classes\Interface\{44B619BC-3D2B-4990-AA4F-9AA366921792} SUPPRIME Key: HKLM\Software\Classes\AppID\{4CE516A7-F7AC-4628-B411-8F886DC5733E} ABSENT Key: HKLM\Software\Wow6432Node\Classes\AppID\{4CE516A7-F7AC-4628-B411-8F886DC5733E} SUPPRIME Key: HKLM\Software\Classes\AppID\{AC662AF2-4601-4A68-84DF-A3FE83F1A5F9} ABSENT Key: HKLM\Software\Wow6432Node\Classes\AppID\{AC662AF2-4601-4A68-84DF-A3FE83F1A5F9} SUPPRIME Key: HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{BFFED5CA-8BDF-47CC-AED0-23F4E6D77732} SUPPRIME Key: HKLM\Software\Classes\AppID\{D97A8234-F2A2-4AD4-91D5-FECDB2C553AF} ABSENT Key: HKLM\Software\Wow6432Node\Classes\AppID\{D97A8234-F2A2-4AD4-91D5-FECDB2C553AF} SUPPRIME Key: HKLM\Software\Classes\AppID\BrowserConnection.dll SUPPRIME Key: HKLM\Software\Classes\AppID\DNSBHO.dll SUPPRIME Key: HKLM\Software\Classes\BrowserConnection.Loader SUPPRIME Key: HKLM\Software\Classes\DnsBHO.BHO SUPPRIME Key*: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\482AA67AD25E6E74E9F48BD5FBE8533C SUPPRIME Key: HKLM\Software\Wow6432Node\Microsoft\Tracing\MyBabylontb_RASAPI32 SUPPRIME Key: HKLM\Software\Wow6432Node\Microsoft\Tracing\MyBabylontb_RASMANCS SUPPRIME Key: HKLM\Software\Wow6432Node\Microsoft\Tracing\offerbox_RASAPI32 SUPPRIME Key: HKLM\Software\Wow6432Node\Microsoft\Tracing\offerbox_RASMANCS SUPPRIME Key: HKLM\Software\Wow6432Node\Microsoft\Tracing\OfferBoxHTTPProxy_RASAPI32 SUPPRIME Key: HKLM\Software\Wow6432Node\Microsoft\Tracing\OfferBoxHTTPProxy_RASMANCS SUPPRIME Key: HKLM\Software\Classes\Iminent.Mediator.Communication.DataContracts.TestContentCommand ABSENT Key: HKLM\Software\Wow6432Node\Classes\Iminent.Mediator.Communication.DataContracts.TestContentCommand SUPPRIME Key: \Software\Classes\Installer\Products\\94E9CB85768235142AF3D6263A755299 SUPPRIME Key: \Software\Classes\Installer\Features\94E9CB85768235142AF3D6263A755299 ABSENT Key: Service: SProtection ========== Valeur(s) du Registre ========== SUPPRIME {EE95E576-0A5B-4028-81C9-0806488DC699} SUPPRIME {8F5334E5-E7FB-4D18-8423-E94D782EE2FB} SUPPRIME {B7150C82-E531-4A6F-858A-A2FA9F097D6E} SUPPRIME {3AADF268-EEF2-4E10-A953-C38FEF6F51C2} ========== Elément(s) de donnée du Registre ========== SUPPRIME R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride SUPPRIME AppInit: \Program Files (x86)\SEARCH~1\Datamngr\x64\datamngr.dll ========== Dossier(s) ========== ABSENT C:\Program Files (x86)\Advanced System Protector SUPPRIME Folder: C:\Program Files (x86)\Common Files\Umbrella SUPPRIME Reboot Folder**: c:\programdata\microsoft\windows\start menu\programs\iminent SUPPRIME Folder: c:\users\christine\appdata\local\temp\installer ========== Fichier(s) ========== ABSENT Folder/File: c:\program files (x86)\advanced system protector\advancedsystemprotector.exe SUPPRIME File: c:\program files (x86)\common files\umbrella\umbrella.exe ABSENT File: \program files (x86)\search~1\datamngr\x64\datamngr.dll ABSENT File: c:\program files (x86)\common files\umbrella\umbrella.exe SUPPRIME File*: c:\users\christine\appdata\local\temp\ins7a62.tmp.exe SUPPRIME File*: c:\users\christine\appdata\local\temp\ins9eb4.tmp.exe SUPPRIME File*: c:\users\christine\appdata\local\temp\insd71e.tmp.exe SUPPRIME File: c:\users\christine\appdata\local\temp\ob.exe SUPPRIME File: c:\users\christine\appdata\local\temp\uninst1.exe SUPPRIME File: C:\Users\Christine\AppData\Local\Temp\bar_babylon.bmp SUPPRIME File*: c:\users\christine\appdata\local\temp\bar_babylon.bmp ABSENT Folder/File: c:\users\christine\appdata\local\temp\ob.exe ABSENT Folder/File: c:\users\christine\appdata\local\temp\uninst1.exe ========== Tache planifiée ========== ABSENT Task: Advanced System Protector_startup ABSENT Task: DealPlyUpdate ========== Autre ========== NON TRAITE Malware (55) ========== Récapitulatif ========== 6 : Processus mémoire 31 : Clé(s) du Registre 4 : Valeur(s) du Registre 2 : Elément(s) de donnée du Registre 4 : Dossier(s) 13 : Fichier(s) 2 : Logiciel(s) 2 : Tache planifiée 1 : Autre End of clean in 00mn 32s ========== Chemin de fichier rapport ========== C:\ZHP\ZHPFix[R1].txt - 15/02/2013 12:45:05 [5601]