Rapport de ZHPFix 2017.06.13.1 par Nicolas Coolman, Update du 13/06/2017 Fichier d'export Registre : Run by Admin at 01/07/2017 4:00:17 PM High Elevated Privileges : OK Windows 7 Business Edition, 64-bit Service Pack 1 (Build 7601) Recycle Bin emptied (02mn AMs) Prefetcher emptied ========== Process memory ========== REMOVES Reboot: Memory Process: C:\Windows\System32\drivers\0DFE3DA9.sys ========== Registry keys ========== REMOVES:³ StartupReg: CryptoMill Refresh REMOVES:³ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} REMOVES: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} REMOVES:³ StartupReg: APSDaemon REMOVES:³ StartupReg: CCleaner Monitoring REMOVES:³ StartupReg: Persistence ========== Registry values ========== ABSENT value Standard Profile: FirewallRaz : ABSENT value Domain Profile: FirewallRaz : No value present in the exception of registry key (FirewallRaz) ProxyFix : Proxy configuration successfully removed REMOVES ProxyServer Value REMOVES ProxyEnable Value REMOVES EnableHttp1_1 Value REMOVES ProxyHttp1.1 Value REMOVES ProxyOverride Value ========== Preferences browser ========== NOW Chrome File: C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Preferences REMOVES Chrome Site: http://static.criteo.net ========== Folders ========== No folders empty CLSID Local user REMOVES: C:\Users\Admin\AppData\Local\TempTaskUpdateDetection05B435EC-3201-4EF0-A5F6-4EC9E850BDCC REMOVES: C:\Users\Admin\AppData\Local\TempTaskUpdateDetection0666CB66-4738-496D-8350-95BB6685BD7A REMOVES: C:\Users\Admin\AppData\Local\TempTaskUpdateDetection27CA7537-368F-4BCC-A63B-BEFB7A887ECA REMOVES: C:\Users\Admin\AppData\Local\TempTaskUpdateDetection2CA22DC0-D0EC-4A4E-B0E7-7B97283AC97D REMOVES: C:\Users\Admin\AppData\Local\TempTaskUpdateDetection3605CEED-06D0-4249-8A74-BF237859BD83 REMOVES: C:\Users\Admin\AppData\Local\TempTaskUpdateDetection5283571E-ED2F-4406-8047-DBFA4870C404 REMOVES: C:\Users\Admin\AppData\Local\TempTaskUpdateDetection571E8C48-FFFC-4E86-BB54-C8D30FA70A17 REMOVES: C:\Users\Admin\AppData\Local\TempTaskUpdateDetectionB9C3ECA2-8538-4338-A694-9AEE7E0D6009 REMOVES: C:\Users\Admin\AppData\Local\TempTaskUpdateDetectionBB5F1862-85AE-4976-8D78-1D1200F949F4 REMOVES: C:\Users\Admin\AppData\Local\TempTaskUpdateDetectionC127E892-40EC-4F67-B4A4-E8FCB1CC0BD8 REMOVES: C:\Users\Admin\AppData\Local\TempTaskUpdateDetectionDBB06A58-FDAB-49FF-A832-37FC189731BF ========== Files ========== Deletes temporary Windows (72) (4,513,481 octets) REMOVES Flash Cookies (0) (0 octets) REMOVES Reboot: c:\windows\system32\drivers\0dfe3da9.sys ========== Scheduled task ========== REMOVES: {0E4387B4-FDE4-C872-2E47-0CC48D323479} ========== Summary ========== 1 : Process memory 6 : Registry keys 9 : Registry values 12 : Folders 3 : Files 2 : Preferences browser 1 : Scheduled task End of clean in 07mn AMs ========== Path to file report ========== C:\Users\Admin\AppData\Roaming\ZHP\ZHPFix[R1].txt - 01/07/2017 4:00:20 PM [3078]