Rapport de ZHPFix 2017.06.13.1 par Nicolas Coolman, Update du 13/06/2017 Fichier d'export Registre : Run by ÑíÇÖ at 11/18/2017 10:47:26 ã High Elevated Privileges : OK Windows 7 Ultimate Edition, 32-bit Service Pack 1 (Build 7601) Recycle Bin emptied (:0mn Õs) Prefetcher emptied ========== Software ========== ABSENT Uninstall Process: c:\program files\baidu wifihotspot\wifiuninstall.exe ========== Registry keys ========== REMOVES: HKLM\SOFTWARE\Baidu_Drp_pos REMOVES: HKCU\SOFTWARE\Baidu Security REMOVES: HKCU\SOFTWARE\Baidu WiFiHotspot REMOVES: HKCU\SOFTWARE\Flux REMOVES: HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui REMOVES: HKLM\SOFTWARE\Software ========== Registry values ========== ABSENT value Standard Profile: FirewallRaz : ABSENT value Domain Profile: FirewallRaz : ========== Elements of the registry data ========== REMOVES TCPIP: NameServer = 77.88.8.7,77.88.8.3 REMOVES TCPIP: DhcpNameServer = 192.168.0.1 192.168.0.1 REMOVES: R0 - Main,Start Page = KCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page REMOVES: R0 - Main,Start Page = KLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page ========== Preferences browser ========== NOW Chrome File: C:\Users\ÑíÇÖ\AppData\Local\Google\Chrome\User Data\Default\Preferences REMOVES Chrome Site: http://me-cdn.effectivemeasure.net NOW Chrome File: C:\Users\ÑíÇÖ\AppData\Local\Google\Chrome\User Data\Default\Preferences REMOVES Chrome Site: http://s.effectivemeasure.net REMOVES Chrome Site: http://s.effectivemeasure.net REMOVES Chrome Site: http://s.effectivemeasure.net NOW Chrome File: C:\Users\ÑíÇÖ\AppData\Local\Google\Chrome\User Data\Default\Preferences REMOVES Chrome Site: http://www.google-analytics.com REMOVES Chrome Site: http://www.google-analytics.com REMOVES Chrome Site: http://www.google-analytics.com REMOVES Chrome Site: http://www.google-analytics.com REMOVES Chrome Site: http://www.google-analytics.com NOW Chrome File: C:\Users\ÑíÇÖ\AppData\Local\Google\Chrome\User Data\Default\Preferences REMOVES Chrome Site: http://www.startimes.com REMOVES Chrome Site: http://www.startimes.com REMOVES Chrome Site: http://www.startimes.com REMOVES Chrome Site: http://www.startimes.com NOW Chrome File: C:\Users\ÑíÇÖ\AppData\Local\Google\Chrome\User Data\Default\Preferences ABSENT Chrome Site: http://adservice.google.dz NOW Chrome File: C:\Users\ÑíÇÖ\AppData\Local\Google\Chrome\User Data\Default\Preferences ABSENT Chrome Site: http://apis.google.com NOW Chrome File: C:\Users\ÑíÇÖ\AppData\Local\Google\Chrome\User Data\Default\Preferences ABSENT Chrome Site: http://ssl.gstatic.com NOW Chrome File: C:\Users\ÑíÇÖ\AppData\Local\Google\Chrome\User Data\Default\Preferences ABSENT Chrome Site: http://stats.g.doubleclick.net REMOVES Folder Chrome: C:\Users\ÑíÇÖ\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo ========== Folders ========== Deletes temporary Windows (7) REMOVES: C:\Program Files\Baidu WiFiHotspot REMOVES: C:\Users\ÑíÇÖ\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo REMOVES: C:\ProgramData\AVG2015 REMOVES: C:\ProgramData\MFAData REMOVES: C:\Windows\System32\Config\systemprofile\AppData\Local\Avg2015 REMOVES: C:\Windows\System32\Config\systemprofile\AppData\Local\MFAData REMOVES: C:\Windows\System32\Config\systemprofile\AppData\Roaming\AVG2015 REMOVES: C:\ProgramData\AVAST Software REMOVES: C:\Program Files\Common Files\AV ========== Files ========== Deletes temporary Windows (33) (277,386 octets) REMOVES: c:\users\ÑíÇÖ\appdata\local\google\chrome\user data\default\preferences ========== Other ========== NON-TREATY O38 - TASK: {28E9EAE1-C2D4-45CD-9CFB-1180D5FA486F}[\Baidu LiveUpdate] - (.Baidu, Inc. - Baidu PC Faster LiveUpdate.) -- C:\Program Files\Baidu WiFiHotspot\liveupdate.exe [497632] NON-TREATY O38 - TASK: {BADD67F3-0CF0-4B7E-94C8-85776DC02456}[\{12D2E961-61E3-44C9-9F89-ACB4ECD23563}] - (.Baidu, Inc. - Baidu Wifi Sharing.) -- C:\Program Files\Baidu WiFiHotspot\WifiHotspot.exe [2033120] NON-TREATY O38 - TASK: {2C123E9E-3E46-48C9-A6B5-053A685CC2E4}[\UninstMiniWifi] - (...) -- C:\Users\99DA~1\AppData\Local\Temp\MU8A25.bat (.not file.) [0] (.Orphan.) NON-TREATY O38 - TASK: {424EFAC2-E2A3-43E4-AAD6-5E84888D0D88}[\{ABE190F5-B82D-4E0A-86E4-C7C8F7E8719A}] - (...) -- C:\Program Files\Nox\bin\Nox.exe (.not file.) [0] (.Orphan.) NON-TREATY O38 - TASK: {45892B24-0783-47FF-BE41-521099853EA8}[\Microsoft\Windows\Media Center\mcupdate] - (...) -- C:\Windows\ehome\mcupdate (.not file.) [0] (.Orphan.) NON-TREATY O38 - TASK: {50CAC92A-3AA9-459E-9201-3E9B64682094}[\{16F715E6-D8E5-42C9-9FF0-335C149C2F8C}] - (...) -- C:\Program Files\Nox\bin\Nox.exe (.not file.) [0] (.Orphan.) NON-TREATY O38 - TASK: {5733AF9A-5B67-49BD-9E7E-EBABCF2F9E1A}[\{633971A3-B0AB-4A9E-87D7-8C41E7BA7B83}] - (...) -- C:\Users\????\Desktop\Tech 4 All Wi-Fi Hack\2jumpstart.exe (.not file.) [0] (.Orphan.) NON-TREATY O38 - TASK: {597CFEF3-3957-437F-AD25-3580C6D77E02}[\Microsoft\Windows\Media Center\mcupdate_scheduled] - (...) -- C:\Windows\ehome\mcupdate (.not file.) [0] (.Orphan.) NON-TREATY O38 - TASK: {5B184694-64C3-4633-94C5-945B3FA561D6}[ NON-TREATY O38 - TASK: {5B2BAA8B-F86E-4001-A605-6D866FC62EE4}[\{659D5E10-10E2-4462-B254-B258EB876CF5}] - (...) -- C:\Program Files\Nox\bin\Nox_unload.exe (.not file.) [0] (.Orphan.) NON-TREATY O38 - TASK: {67094BA2-FECA-4F2B-A9C2-0EB45C849065}[\{6D782A5C-9D63-4AC6-BAC0-13D6D060679B}] - (...) -- C:\Users\????\Desktop\Waircut V1.4\wAirCut.exe (.not file.) [0] (.Orphan.) NON-TREATY O38 - TASK: {80F5CC05-8105-4E78-813E-C6C67E4D1D8F}[\Microsoft\Windows\Media Center\StartRecording] - (...) -- C:\Windows\ehome\ehrec (.not file.) [0] (.Orphan.) NON-TREATY O38 - TASK: {81AF2E46-1AAF-4B4F-B693-4D950B505C86}[\{0C2C8CD4-12CA-45B5-AD17-5838C1E65043}] - (...) -- C:\Users\????\Desktop\VGA Customized for QT10\IEGD_10_3_Windows\Utilities\Setup.exe (.not file.) [0] (.Orphan.) NON-TREATY O38 - TASK: {89C86EB4-E708-49ED-944F-A82221AEF84C}[\{AD245F7F-327B-4308-B637-3523FC182F92}] - (...) -- C:\Users\????\Desktop\airsnort-0.2.7e\bin\airsnort.exe (.not file.) [0] (.Orphan.) NON-TREATY O38 - TASK: {A74C8925-0585-47EE-A3C6-1F33DEE428BC}[\{606AEC81-1C21-46F2-8E01-DDC3A6F8CDBB}] - (...) -- C:\Users\????\Desktop\airsnort-0.2.7e\bin\airsnort.exe (.not file.) [0] (.Orphan.) NON-TREATY O38 - TASK: {BEE93C25-6F8D-4441-A021-2B3556BB1F37}[\{3395D4F3-55A2-4E54-B11D-AC96738BBF0E}] - (...) -- C:\Users\????\Downloads\Programs\DuOSInstaller.exe (.not file.) [0] (.Orphan.) NON-TREATY O38 - TASK: {FA6E8C84-C0A6-441C-B4BD-B23AA8295DC9}[\Microsoft\Windows\Media Center\RecordingRestart] - (...) -- C:\Windows\ehome\ehrec (.not file.) [0] (.Orphan.) NON-TREATY Read more at http://www.cjoint.com/c/GKsvGqodfPj#74PGh0ZLLdXy4DBX.99 ========== Summary ========== 6 : Registry keys 2 : Registry values 4 : Elements of the registry data 10 : Folders 2 : Files 1 : Software 26 : Preferences browser 18 : Other End of clean in :5mn Õs ========== Path to file report ========== C:\Users\ÑíÇÖ\AppData\Roaming\ZHP\ZHPFix[R1].txt - 07/04/2014 04:46:43 Õ [2212] C:\Users\ÑíÇÖ\AppData\Roaming\ZHP\ZHPFix[R2].txt - 11/16/2016 06:43:35 ã [10386] C:\Users\ÑíÇÖ\AppData\Roaming\ZHP\ZHPFix[R3].txt - 05/07/2017 05:22:18 ã [4468] C:\Users\ÑíÇÖ\AppData\Roaming\ZHP\ZHPFix[R4].txt - 11/18/2017 10:47:32 ã [7382]