cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ ZHPFix v2019.3.28.40 by Nicolas Coolman (2019/03/28)
~ Run by Patrick (Administrator) (02/04/2019 18:52:09)
~ Web: https://www.nicolascoolman.com
~ Blog: https://nicolascoolman.eu/
~ Certificate ZHPFix: Legal
~ State version : Version OK
~ Report : C:\Users\Patrick\Desktop\ZHPFix.txt
~ Quarantine : HKCU\SOFTWARE\ZHP\ZHPFix\Quarantine\
~ UAC : Activate
~ Boot Mode : Normal (Normal boot)
Windows 7 Professional, 64-bit Service Pack 1 (Build 7601)



---\\ SCRIPT DE L'UTILISATEUR. (65)
Script ZHPFix
EmptyCLSID
Emptytemp
EmptyFlash
UnMaskSoftware: O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} =>.Google Inc. (Hidden)
UnMaskSoftware: O42 - Logiciel: Google Update Helper - (.Google LLC.) [HKLM][64Bits] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA} (Hidden)
FilesInDirectory: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GLPCCamera\*.exe;*.dll
Folder: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GLPCCamera
HKEY_USERS\S-1-5-21-3193970907-298708633-41943527-1000\Software\csastats
HKCU\Software\csastats
HKCU\Software\ProductSetup
HKU\S-1-5-21-3193970907-298708633-41943527-1000\SOFTWARE\csastats
HKU\S-1-5-21-3193970907-298708633-41943527-1000\SOFTWARE\ProductSetup
HKEY_USERS\S-1-5-21-3193970907-298708633-41943527-1000\Software\csastats
HKCU\Software\csastats
HKCU\Software\ProductSetup
HKLM\SOFTWARE\Wow6432Node\drpsu
HKU\S-1-5-21-3193970907-298708633-41943527-1000\SOFTWARE\drpsu
HKU\S-1-5-21-3193970907-298708633-41943527-1000\SOFTWARE\undefined
O43 - CFD: 23/03/2019 - [] D -- C:\ProgramData\ByteFence
O43 - CFD: 25/02/2019 - [] D -- C:\Users\Patrick\AppData\Roaming\DRPSu
O108 - CMH1: EPPShellEx [64Bits] - {509FE1AF-ADD5-49EC-BC55-7CF81FD16E78} . (.Orphan.)
HKLM\SOFTWARE\Microsoft\Tracing\ByteFenceService_RASAPI32
HKLM\SOFTWARE\Microsoft\Tracing\ByteFenceService_RASMANCS
HKLM\SOFTWARE\Microsoft\Tracing\ByteFence_RASAPI32
HKLM\SOFTWARE\Microsoft\Tracing\ByteFence_RASMANCS
C:\ProgramData\ByteFence
C:\Users\Patrick\AppData\Roaming\DRPSu
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\EPPShellEx
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ByteFenceService_RASAPI32
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ByteFenceService_RASMANCS
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ByteFence_RASAPI32
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ByteFence_RASMANCS
C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\File System\000
C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\File System\001
C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\File System\002
C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\File System\003
HKU\S-1-5-21-3193970907-298708633-41943527-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\drp.su
HKCU\Software\drpsu
HKCU\Software\undefined
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\drp.su
HKLM\SOFTWARE\Wow6432Node\drpsu
O4 - HKCU\..\Run: [Chromium] . (.The Chromium Authors - Chromium.) -- c:\Users\Patrick\AppData\Local\chromium\application\chrome.exe
O4 - HKUS\S-1-5-21-3193970907-298708633-41943527-1000\..\Run: [Chromium] . (.The Chromium Authors - Chromium.) -- c:\Users\Patrick\AppData\Local\chromium\application\chrome.exe
O4 - GS\Quicklaunch [Administrateur]: Chromium.lnk . (.The Chromium Authors - Chromium.) C:\Users\Patrick\AppData\Local\chromium\Application\chrome.exe
O4 - GS\Quicklaunch [Patrick]: Chromium.lnk . (.The Chromium Authors - Chromium.) C:\Users\Patrick\AppData\Local\chromium\Application\chrome.exe
HKCU\SOFTWARE\Chromium
HKU\S-1-5-21-3193970907-298708633-41943527-1000\SOFTWARE\Chromium
O43 - CFD: 23/03/2019 - [] D -- C:\Users\Patrick\AppData\Local\chromium
O87 - FAEL: "{32086154-2EDB-4F7A-924A-12E17D776D3F}" [In-None-P17-TRUE] .(.The Chromium Authors - Chromium.) -- C:\Users\Patrick\AppData\Local\Chromium\Application\chrome.exe
O38 - TASK: {AE7ABF38-CF01-413D-969D-61904592456A} [64Bits][\Avast Software\Overseer] - (.AVAST Software - Avast Overseer.) -- C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [2371784]
C:\Windows\System32\Tasks\Avast Software\Overseer - (.AVAST Software.) -- C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [/from_scheduler:1]
HKLM\SOFTWARE\AVAST Software
HKLM\SOFTWARE\WOW6432Node\AVAST Software
HKCU\SOFTWARE\AvastAdSDK
HKCU\SOFTWARE\Browser Cleanup
HKU\S-1-5-21-3193970907-298708633-41943527-1000\SOFTWARE\AvastAdSDK
HKU\S-1-5-21-3193970907-298708633-41943527-1000\SOFTWARE\Browser Cleanup
O43 - CFD: 25/02/2019 - [] D -- C:\ProgramData\AVAST Software
HKLM\SOFTWARE\McAfee
O43 - CFD: 23/03/2019 - [] D -- C:\ProgramData\McAfee
cmd: ipconfig /flushdns
cmd: netsh winsock reset
cmd: netsh advfirewall reset
cmd: Netsh advfirewall set allprofiles state on


---\\ LOGICIEL. (0)


---\\ SERVICE. (0)


---\\ TÂCHE PLANIFIÉE. (2)
SUPPRIMÉ Redémarrage Clé Tasks^: HKLM64\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AE7ABF38-CF01-413D-969D-61904592456A}
SUPPRIMÉ Redémarrage Clé Tasks^: HKLM64\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{AE7ABF38-CF01-413D-969D-61904592456A}


---\\ NAVIGATEUR INTERNET. (0)


---\\ EXPLORATEUR ( Dossiers, Fichiers ). (17)
SUPPRIMÉ Redémarrage Fichier Temp^: C:\Users\Patrick\AppData\Local\Temp\isp63E7.tmp
DEPLACÉ Fichier Temp: C:\Users\Patrick\AppData\Local\Temp\Set5FFE.tmp
DEPLACÉ Fichier Temp: C:\Users\Patrick\AppData\Local\Temp\_iu14D2N.tmp
SUPPRIMÉ Redémarrage Fichier Temp^: C:\Users\Patrick\AppData\Local\Temp\~DFE394E51E5DDE6945.TMP
DEPLACÉ Fichier Temp: C:\Users\Patrick\AppData\Local\Temp\DoxillionCounts.txt
SUPPRIMÉ Redémarrage Fichier Temp^: C:\Users\Patrick\AppData\Local\Temp\FXSAPIDebugLogFile.txt
SUPPRIMÉ Dossier : C:\ProgramData\ByteFence
SUPPRIMÉ Dossier : C:\Users\Patrick\AppData\Roaming\DRPSu
SUPPRIMÉ Dossier : C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\File System\000
SUPPRIMÉ Dossier : C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\File System\001
SUPPRIMÉ Dossier : C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\File System\002
SUPPRIMÉ Dossier : C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\File System\003
DEPLACÉ Fichier Shortcut: C:\Users\Patrick\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Chromium.lnk
SUPPRIMÉ Dossier : C:\Users\Patrick\AppData\Local\chromium
DEPLACÉ Fichier Tasks: C:\Windows\System32\Tasks\Avast Software\Overseer
SUPPRIMÉ Dossier : C:\ProgramData\AVAST Software
SUPPRIMÉ Dossier : C:\ProgramData\McAfee


---\\ REGISTRE ( Clés, Valeurs, Données ). (40)
REMPLACÉ Donnée Software: 1 [HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}\\SystemComponent]
ABSENT Donnée Software: 1 [HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA} (Hidden)\\SystemComponent]
SUPPRIMÉ Clé: HKEY_USERS\S-1-5-21-3193970907-298708633-41943527-1000\Software\csastats [csastats]
ABSENT Clé: HKCU\Software\csastats
SUPPRIMÉ Clé: HKCU\Software\ProductSetup [ProductSetup]
ABSENT Clé: HKU\S-1-5-21-3193970907-298708633-41943527-1000\SOFTWARE\csastats
ABSENT Clé: HKU\S-1-5-21-3193970907-298708633-41943527-1000\SOFTWARE\ProductSetup
ABSENT Clé: HKEY_USERS\S-1-5-21-3193970907-298708633-41943527-1000\Software\csastats
ABSENT Clé: HKCU\Software\ProductSetup
SUPPRIMÉ Clé: HKLM\SOFTWARE\Wow6432Node\drpsu [drpsu]
SUPPRIMÉ Clé: HKU\S-1-5-21-3193970907-298708633-41943527-1000\SOFTWARE\drpsu [drpsu]
SUPPRIMÉ Clé: HKU\S-1-5-21-3193970907-298708633-41943527-1000\SOFTWARE\undefined [undefined]
SUPPRIMÉ Clé CMH: HKLM64\Software\Classes\*\ShellEx\ContextMenuHandlers\EPPShellEx [EPPShellEx1]
ABSENT Clé CMH: HKLM64\SOFTWARE\Classes\CLSID\509FE1AF-ADD5-49EC-BC55-7CF81FD16E78}
SUPPRIMÉ Clé Tracing: HKLM\SOFTWARE\Microsoft\Tracing\ByteFenceService_RASAPI32 [ByteFenceService_RASAPI32]
SUPPRIMÉ Clé Tracing: HKLM\SOFTWARE\Microsoft\Tracing\ByteFenceService_RASMANCS [ByteFenceService_RASMANCS]
SUPPRIMÉ Clé Tracing: HKLM\SOFTWARE\Microsoft\Tracing\ByteFence_RASAPI32 [ByteFence_RASAPI32]
SUPPRIMÉ Clé Tracing: HKLM\SOFTWARE\Microsoft\Tracing\ByteFence_RASMANCS [ByteFence_RASMANCS]
ABSENT Clé: HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\EPPShellEx
ABSENT Clé Tracing: HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ByteFenceService_RASAPI32
ABSENT Clé Tracing: HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ByteFenceService_RASMANCS
ABSENT Clé Tracing: HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ByteFence_RASAPI32
ABSENT Clé Tracing: HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ByteFence_RASMANCS
SUPPRIMÉ Clé: HKU\S-1-5-21-3193970907-298708633-41943527-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\drp.su [drp.su]
ABSENT Clé: HKCU\Software\drpsu
ABSENT Clé: HKCU\Software\undefined
ABSENT Clé: HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\drp.su
ABSENT Clé: HKLM\SOFTWARE\Wow6432Node\drpsu
SUPPRIMÉ Valeur Run: Chromium [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\]
ABSENT Valeur Run: HKU\S-1-5-21-3193970907-298708633-41943527-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ [c:\Users\Patrick\AppData\Local\chromium\application\chrome.exe]
SUPPRIMÉ Clé: HKCU\SOFTWARE\Chromium [Chromium]
ABSENT Clé: HKU\S-1-5-21-3193970907-298708633-41943527-1000\SOFTWARE\Chromium
SUPPRIMÉ Valeur FirewallRules: {32086154-2EDB-4F7A-924A-12E17D776D3F} [HKLM\SYSTEM\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules]
SUPPRIMÉ Clé: HKLM\SOFTWARE\AVAST Software [AVAST Software]
ABSENT Clé: HKLM\SOFTWARE\WOW6432Node\AVAST Software
SUPPRIMÉ Clé: HKCU\SOFTWARE\AvastAdSDK [AvastAdSDK]
SUPPRIMÉ Clé: HKCU\SOFTWARE\Browser Cleanup [Browser Cleanup]
ABSENT Clé: HKU\S-1-5-21-3193970907-298708633-41943527-1000\SOFTWARE\AvastAdSDK
ABSENT Clé: HKU\S-1-5-21-3193970907-298708633-41943527-1000\SOFTWARE\Browser Cleanup
SUPPRIMÉ Clé: HKLM\SOFTWARE\McAfee [McAfee]


---\\ COMMANDE. (7)
~ EmptyCSID: Dossiers CLSID vides supprimés (0)
~ EmptyTemp: Dossier Local temp partiellement vidé (6)
~ EmptyFlash: Dossier FlashPlayer vide.
~ Command spéciale exécutée avec succès: ipconfig /flushdns
~ Command spéciale exécutée avec succès: netsh winsock reset
~ Command spéciale exécutée avec succès: netsh advfirewall reset
~ Command spéciale exécutée avec succès: Netsh advfirewall set allprofiles state on


---\\ NON TRAITÉ. (2)
FilesInDirectory: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GLPCCamera\*.exe;*.dll
Folder: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GLPCCamera

~ Le système a été redémarré.

***** ~ Fin de rapport terminé en 00h00mn44s

Publicité


Signaler le contenu de ce document

Publicité