Rapport de ZHPFix 2013.5.24.2 par Nicolas Coolman, Update du 24/05/2013 Fichier d'export Registre : Run by Cuicui at 02/06/2013 23:43:19 High Elevated Privileges : OK Windows 7 Home Premium Edition, 64-bit Service Pack 1 (Build 7601) Corbeille vidée ========== Logiciel(s) ========== SUPPRIME Iminent ========== Processus mémoire ========== SUPPRIME Reboot Memory Process: C:\ProgramData\BrowserProtect\2.6.1249.132\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe SUPPRIME Reboot Memory Process: C:\Program Files (x86)\Yontoo\Y2Desktop.Updater.exe SUPPRIME Memory Process: C:\Windows\SysWOW64\msdtt.exe ========== Clé(s) du Registre ========== SUPPRIME Key: Service: BrowserProtect ABSENT Key: Service: SProtection SUPPRIME Key: HKCU\Software\5208a88b039ba49 SUPPRIME Key*: HKCU\Software\DataMngr_Toolbar ABSENT Key: HKCU\Software\Iminent SUPPRIME Key: HKLM\Software\Wow6432Node\5208a88b039ba49 ABSENT Key: HKLM\Software\Wow6432Node\Umbrella SUPPRIME Key: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ecdf796-c2dc-4d79-a620-cce0c0a66cc9} SUPPRIME Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A} SUPPRIME Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} SUPPRIME Key: HKLM\Software\Wow6432Node\Google\Chrome\Extensions\pgafcinpmmpklohkojmllohdhomoefph SUPPRIME Key*: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\482AA67AD25E6E74E9F48BD5FBE8533C SUPPRIME Key: HKCU\Software\1ClickDownload SUPPRIME Key: HKLM\Software\Wow6432Node\Microsoft\Tracing\MyBabylontb_RASAPI32 SUPPRIME Key: HKLM\Software\Wow6432Node\Microsoft\Tracing\MyBabylontb_RASMANCS SUPPRIME Key: HKLM\Software\Classes\Prod.cap SUPPRIME Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings SUPPRIME Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{82E1477C-B154-48D3-9891-33D83C26BCD3} SUPPRIME Key: HKLM\SYSTEM\CurrentControlSet\Services\Yontoo Desktop Updater ABSENT Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\F1057DD419AED0B468AD8888429E139A SUPPRIME Key: HKLM\Software\Classes\Iminent.Mediator.Communication.DataContracts.TestContentCommand ABSENT Key: HKLM\Software\Wow6432Node\Classes\Iminent.Mediator.Communication.DataContracts.TestContentCommand ABSENT Key: \Software\Classes\Installer\Products\\ACFD5B980E184AE4A8A0F404781ADD00 ABSENT Key: HKCU\Software\5208a88b039ba49 ABSENT Key: HKLM\Software\Wow6432Node\5208a88b039ba49 ABSENT Key: Service: BrowserProtect ABSENT Key: Service: Yontoo Desktop Updater SUPPRIME Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} SUPPRIME Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} SUPPRIME Key*: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375 SUPPRIME Key*: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5 SUPPRIME Key: HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{348C2DF3-1191-4C3E-92A6-B3A89A9D9C85} SUPPRIME Key: HKLM\Software\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3} ABSENT Key: HKLM\Software\Wow6432Node\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3} SUPPRIME Key: HKLM\Software\Classes\AppID\{39CB8175-E224-4446-8746-00566302DF8D} SUPPRIME Key: HKLM\Software\Classes\TypeLib\{39CB8175-E224-4446-8746-00566302DF8D} ABSENT Key: HKLM\Software\Wow6432Node\Classes\AppID\{39CB8175-E224-4446-8746-00566302DF8D} SUPPRIME Key: HKLM\Software\Classes\TypeLib\{4599D05A-D545-4069-BB42-5895B4EAE05B} ========== Valeur(s) du Registre ========== ABSENT [HKCU\Software\5208a88b039ba49\history\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}2.6.1125.80]:guid="{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}" ABSENT [HKCU\Software\5208a88b039ba49\history\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}2.6.1125.80]:version="2.6.1125.80" ABSENT [HKCU\Software\5208a88b039ba49]:GUID="{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}" ABSENT [HKCU\Software\5208a88b039ba49]:version="2.6.1249.132" ABSENT [HKLM\Software\Wow6432Node\5208a88b039ba49]:GUID="{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}" ABSENT [HKLM\Software\Wow6432Node\5208a88b039ba49]:version="2.6.1249.132" ABSENT Valeur Standard Profile: FirewallRaz : ABSENT Valeur Domain Profile: FirewallRaz : SUPPRIME FirewallRaz (None) : {376A3426-68AA-47C9-A891-FE81256B83C1} SUPPRIME FirewallRaz (None) : {E5CF2BD8-ACE3-4E2E-9F50-855488247964} SUPPRIME FirewallRaz (Public) : TCP Query User{40CEC527-A345-4624-804E-014DE11CC337}C:\program files (x86)\wizards of the coast llc\magic the gathering dotp 2012\magic_2012.exe SUPPRIME FirewallRaz (Public) : UDP Query User{AE19FB08-DBF6-4D09-8457-49F164B3D797}C:\program files (x86)\wizards of the coast llc\magic the gathering dotp 2012\magic_2012.exe ========== Dossier(s) ========== SUPPRIME Folder: C:\Program Files (x86)\Yontoo ABSENT C:\Program Files (x86)\Common Files\Umbrella SUPPRIME Reboot Folder**: C:\ProgramData\BrowserProtect SUPPRIME Folder: C:\Users\Cuicui\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BrowserProtect SUPPRIME Flash Cookies SUPPRIME Temporaires Windows ========== Fichier(s) ========== ABSENT Folder/File: c:\program files (x86)\common files\umbrella\umbrella.exe SUPPRIME Reboot c:\programdata\browserprotect\2.6.1249.132\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\browserprotect.exe ABSENT File: c:\program files (x86)\common files\umbrella\umbrella.exe SUPPRIME File: c:\windows\syswow64\msdtt.exe SUPPRIME File: c:\windows\prefetch\browserprotect.exe-3a1f4ed0.pf ABSENT File: c:\windows\tasks\at1.job SUPPRIME Flash Cookies SUPPRIME Temporaires Windows ========== Tache planifiée ========== SUPPRIME Task: At1 SUPPRIME Task: GoforFilesUpdate SUPPRIME Task: {B993B0A4-363F-489C-BD72-EB3391B6EE6A} ========== Restauration Système ========== Point de restauration du système créé avec succès ========== Récapitulatif ========== 3 : Processus mémoire 38 : Clé(s) du Registre 12 : Valeur(s) du Registre 6 : Dossier(s) 8 : Fichier(s) 1 : Logiciel(s) 3 : Tache planifiée 1 : Restauration Système End of clean in 01mn 14s ========== Chemin de fichier rapport ========== C:\ZHP\ZHPFix[R1].txt - 02/06/2013 23:43:19 [6441]