Rapport de ZHPFix 2013.6.12.3 par Nicolas Coolman, Update du 12/06/2013 Fichier d'export Registre : Run by Henri Rigo at 27/06/2013 07:10:12 High Elevated Privileges : OK Windows XP Professional Service Pack 3 (Build 2600) Corbeille vidée ========== Logiciel(s) ========== ABSENT Software Key: Ad-Aware ABSENT Software Key: {DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF} SUPPRIME Java(TM) 7 Update 4 SUPPRIME J2SE Runtime Environment 5.0 Update 10 ========== Processus mémoire ========== SUPPRIME Reboot Memory Process: C:\Program Files\Alwil Software\Avast5\afwServ.exe ABSENT Memory Process: O34 - HKLM BootExecute: (autocheck autochk *) - File not found ABSENT Memory Process: O34 - HKLM BootExecute: (lsdelete) - File not found SUPPRIME Reboot Memory Process: C:\Program Files\Alwil Software\Avast5\AvastEmUpdate.exe ========== Clé(s) du Registre ========== SUPPRIME [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{26A24AE4-039D-4CA4-87B4-2F83217004FF}] SUPPRIME [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0150100}] SUPPRIME Key: CLSID BHO: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} SUPPRIME Key: CLSID: [HKLM\SOFTWARE\Classes\CLSID\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}] SUPPRIME Key: CLSID Extra Buttons: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} SUPPRIME Key: CLSID: [HKLM\SOFTWARE\Classes\CLSID\{08B0E5C0-4FCB-11CF-AAA5-00401C608501}] SUPPRIME Key: CLSID Extra Buttons: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} SUPPRIME Key: CLSID Extra Buttons: {53F6FCCD-9E22-4d71-86EA-6E43136192AB} SUPPRIME Key: CLSID DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} SUPPRIME Key: CLSID: [HKLM\SOFTWARE\Classes\CLSID\{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}] SUPPRIME Key: CLSID DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} ERREUR Key****: Service: avast! Antivirus ERREUR Key****: Service: avast! Firewall ABSENT Key: Service: Lavasoft Ad-Aware Service SUPPRIME Driver Key: PCLEPCI SUPPRIME O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vgasave.sys . (...) -- C:\WINDOWS\system32\Drivers\vgasave.sys (.not file.) SUPPRIME O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpdd.sys . (...) -- C:\WINDOWS\system32\Drivers\rdpdd.sys (.not file.) SUPPRIME O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vgasave.sys . (...) -- C:\WINDOWS\system32\Drivers\vgasave.sys (.not file.) SUPPRIME Key: Service Legacy: LEGACY_AVAST!_ANTIVIRUS SUPPRIME Key: Service Legacy: LEGACY_AVAST!_FIREWALL ABSENT Key: Service Legacy: LEGACY_LAVASOFT_AD-AWARE_SERVICE SUPPRIME Key: SearchScopes :{0633EE93-D776-472f-A0FF-E1416B8B2E3A} SUPPRIME Key: SearchScopes :{50EF0F12-5084-49C7-AFF6-99FA5C3C4E45} SUPPRIME Key: SearchScopes :{513185D9-D3EF-47F0-BE8E-DBDBA5D945C7} SUPPRIME Key: SearchScopes :{6A1806CD-94D4-4689-BA73-E35EA1EA9990} SUPPRIME Key: SearchScopes :{8E09C979-A4D0-4819-ABDF-8FAF04ADD8BF} SUPPRIME Key: SearchScopes :{9D5BD211-422C-4164-9298-BB4186A30F31} SUPPRIME Key: SearchScopes :{9E55402B-B6DF-4188-B561-3EC4C7A09216} SUPPRIME Key: SearchScopes :{C9646295-CF81-49BB-B403-80F6C78C6F30} SUPPRIME Key*: SearchScopes :{0633EE93-D776-472f-A0FF-E1416B8B2E3A} ABSENT SearchScopes :{0633EE93-D776-472f-A0FF-E1416B8B2E3A} SUPPRIME Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0F6E720A-1A6B-40E1-A294-1D4D19F156C8} SUPPRIME Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0F6E720A-1A6B-40E1-A294-1D4D19F156C8} SUPPRIME Key: HKLM\Software\Classes\CLSID\{0F6E720A-1A6B-40E1-A294-1D4D19F156C8} SUPPRIME Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0F6E720A-1A6B-40E1-A294-1D4D19F156C8} SUPPRIME Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\freeCompressor SUPPRIME Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\ItsLabel SUPPRIME Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\PCTuto SUPPRIME Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\RelevantKnowledge SUPPRIME Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\00E944CB89111313EAF35A0553F547F9 SUPPRIME Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\53F55AF3F4049ED3FA6EA6F88E414E24 SUPPRIME Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\68E4BF4B11615E03C97732FD581AB607 SUPPRIME Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8CE3DDAB2D152683FBCEB4866BCD2B0F SUPPRIME Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AF6CE16AFEA5C9A39B766468A8B35C21 SUPPRIME Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FB1E44269B58F433A8C8E671E37CFDCF SUPPRIME Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Companion SUPPRIME Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094 SUPPRIME Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536 SUPPRIME Key: \Software\Classes\Installer\Products\\68AB67CA7DA76301B744AA0100000010 SUPPRIME Key: \Software\Classes\Installer\Features\68AB67CA7DA76301B744AA0100000010 ========== Valeur(s) du Registre ========== SUPPRIME Toolbar: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} SUPPRIME RunValue: LaunchApp ERREUR RunValue: avast ABSENT RunValue: AutoLaunch SUPPRIME AAKE KeyValue: C:\Program Files\Zattoo\zattood.exe SUPPRIME AAKE KeyValue: C:\Program Files\Zattoo\Zattoo1.exe SUPPRIME AAKE KeyValue: C:\Program Files\POST-NET\Post-Net.exe SUPPRIME AAKE KeyValue: C:\Program Files\Download Guru\Download Guru.exe SUPPRIME FirewallRaz (SP) : %windir%\system32\sessmgr.exe SUPPRIME FirewallRaz (SP) : C:\Program Files\eMule\emule.exe SUPPRIME FirewallRaz (SP) : %windir%\Network Diagnostic\xpnetdiag.exe SUPPRIME FirewallRaz (SP) : C:\Program Files\IncrediMail\bin\ImApp.exe SUPPRIME FirewallRaz (SP) : C:\Program Files\IncrediMail\bin\IncMail.exe SUPPRIME FirewallRaz (SP) : C:\Program Files\IncrediMail\bin\ImpCnt.exe SUPPRIME FirewallRaz (SP) : C:\Program Files\Nero\Nero 7\Nero ShowTime\ShowTime.exe SUPPRIME FirewallRaz (SP) : C:\Program Files\Adobe\Photoshop Elements 7.0\AdobePhotoshopElementsMediaServer.exe SUPPRIME FirewallRaz (SP) : C:\Program Files\Skype\Phone\Skype.exe SUPPRIME FirewallRaz (SP) : C:\Program Files\Epson Software\Event Manager\EEventManager.exe SUPPRIME FirewallRaz (SP) : C:\Program Files\Nero\Nero 7\Nero Home\NeroHome.exe SUPPRIME FirewallRaz (SP) : C:\Program Files\Microsoft ActiveSync\rapimgr.exe SUPPRIME FirewallRaz (SP) : C:\Program Files\Microsoft ActiveSync\wcescomm.exe SUPPRIME FirewallRaz (SP) : C:\Program Files\Microsoft ActiveSync\WCESMgr.exe SUPPRIME FirewallRaz (SP) : C:\Program Files\adslTV\adsltv.exe SUPPRIME FirewallRaz (SP) : C:\Program Files\adslTV\VLC\vlc.exe SUPPRIME FirewallRaz (DP) : %windir%\system32\sessmgr.exe SUPPRIME FirewallRaz (DP) : %windir%\Network Diagnostic\xpnetdiag.exe SUPPRIME FirewallRaz (DP) : C:\Program Files\Microsoft ActiveSync\rapimgr.exe SUPPRIME FirewallRaz (DP) : C:\Program Files\Microsoft ActiveSync\wcescomm.exe SUPPRIME FirewallRaz (DP) : C:\Program Files\Microsoft ActiveSync\WCESMgr.exe Aucune valeur présente dans la clé d'exception du registre (FirewallRaz) ========== Préférences navigateur ========== PRESENT Chrome File: C:\Documents and Settings\Henri Rigo\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences SUPPRIME Chrome Site: http://search.babylon.com ABSENT Folder Chrome: ahfgeienlihckogmohjhadlkjgocpleb ABSENT Folder Chrome: eemcgdkfndhakfknompkggombfjjjeno ABSENT Folder Chrome: ennkphjdgehloodpbhlhldgbnhmacadg ABSENT Folder Chrome: mfehgcgbbipciphmccgaenjidiccnmng ABSENT Folder Chrome: mgndgikekgjfcpckkfioiadnlibdjbkf ========== Dossier(s) ========== Aucun dossiers CLSID Local utilisateur vide SUPPRIME Temporaires Windows SUPPRIME Flash Cookies ========== Fichier(s) ========== ABSENT Folder/File: c:\program files\lavasoft\ad-aware\aawservice.exe ABSENT Folder/File: c:\program files\lavasoft\ad-aware\aawtray.exe ABSENT File: c:\documents and settings\henri rigo\application data\mozilla\firefox\profiles\zt0e7d6r.default\searchplugins\browserdefender.xml ERREUR Folder: c:\program files\alwil software\avast5\aswwebrepie.dll () ERREUR Folder: c:\program files\alwil software\avast5\avastui.exe () ABSENT File: c:\program files\lavasoft\ad-aware\autolaunch.exe ABSENT File: c:\dotnetfx\documents and settings\programmes\super ©.lnk ABSENT File: c:\program files\erightsoft\super\super.exe ABSENT File: c:\dotnetfx\documents and settings\programmes\objectif tarot.lnk ABSENT File: c:\program files\objective tarot\objectiftarot.exe SUPPRIME c:\program files\alwil software\avast5\avastsvc.exe ERREUR Folder: c:\program files\alwil software\avast5\afwserv.exe () ABSENT File: c:\program files\lavasoft\ad-aware\aawservice.exe SUPPRIME c:\windows\tasks\ad-aware update (daily 1).job SUPPRIME c:\windows\tasks\avast! emergency update.job SUPPRIME c:\windows\tasks\pcconfidential.job ABSENT Folder/File: c:\program files\lavasoft\ad-aware\ad-awareadmin.exe SUPPRIME c:\windows\prefetch\ad-aware.exe-02fdafae.pf SUPPRIME c:\windows\prefetch\ad-awareadmin.exe-08f79add.pf ABSENT File: c:\program files\zattoo\zattood.exe ABSENT File: c:\program files\zattoo\zattoo1.exe ABSENT File: c:\program files\post-net\post-net.exe ABSENT File: c:\program files\download guru\download guru.exe ABSENT File: c:\windows\system32\drivers\vgasave.sys ABSENT File: c:\windows\system32\drivers\rdpdd.sys ERREUR Folder: c:\program files\alwil software\avast5\avastsvc.exe () SUPPRIME Temporaires Windows SUPPRIME Flash Cookies ========== Tache planifiée ========== SUPPRIME Task: Ad-Aware Update (Daily 1) SUPPRIME Task: Ad-Aware Update (Daily 2) SUPPRIME Task: Ad-Aware Update (Daily 3) SUPPRIME Task: Ad-Aware Update (Daily 4) SUPPRIME Task: Ad-Aware Update (Weekly) SUPPRIME Task: avast! Emergency Update ========== Restauration Système ========== Point de restauration du système créé avec succès ========== Récapitulatif ========== 4 : Processus mémoire 50 : Clé(s) du Registre 30 : Valeur(s) du Registre 3 : Dossier(s) 28 : Fichier(s) 4 : Logiciel(s) 7 : Préférences navigateur 6 : Tache planifiée 1 : Restauration Système End of clean in 02mn 10s ========== Chemin de fichier rapport ========== C:\ZHP\ZHPFix[R1].txt - 27/06/2013 07:10:13 [10692]