Script Zhpfix O4 - HKCU\..\Run: [CCleaner Smart Cleaning] . (. - .) -- C:\Program Files\CCleaner\CCleaner64.exe (.Not File.) O4 - HKCU\..\Run: [NTR1çWsPB_.exe] . (. - .) -- C:\Program Files\Windows Photo Viewer\5ORB6JJMR8SQFT2KG4354YQSM89\NTR1çWsPB_.exe (.Not File.) O4 - HKUS\S-1-5-21-519253191-2592713891-2785590042-1000\..\Run: [CCleaner Smart Cleaning] . (. - .) -- C:\Program Files\CCleaner\CCleaner64.exe (.Not File.) O4 - HKUS\S-1-5-21-519253191-2592713891-2785590042-1000\..\Run: [NTR1çWsPB_.exe] . (. - .) -- C:\Program Files\Windows Photo Viewer\5ORB6JJMR8SQFT2KG4354YQSM89\NTR1çWsPB_.exe (.Not File.) HKCU\SOFTWARE\be8b4d656922d1c582ed676196e87681 HKU\S-1-5-21-519253191-2592713891-2785590042-1000\SOFTWARE\be8b4d656922d1c582ed676196e87681 HKU\S-1-5-21-519253191-2592713891-2785590042-1000\SOFTWARE\AvastAdSDK =>.Avast Software s.r.o HKCU\SOFTWARE\AvastAdSDK =>.Avast Software s.r.o O108 - CMH1: WinRAR32 [64Bits] - {B41DB860-8EE4-11D2-9906-E49FADC173CA} . (.Orphan.) O108 - CMH3: Emsisoft Shell Extension [64Bits] - {AB77609F-2178-4E6F-9C4B-44AC179D937A} . (.Orphan.) O108 - CMH6: Emsisoft Shell Extension [64Bits] - {AB77609F-2178-4E6F-9C4B-44AC179D937A} . (.Orphan.) O108 - CMH6: WinRAR32 [64Bits] - {B41DB860-8EE4-11D2-9906-E49FADC173CA} . (.Orphan.) O108 - CMH7: Emsisoft Shell Extension [64Bits] - {AB77609F-2178-4E6F-9C4B-44AC179D937A} . (.Orphan.) O108 - CMH1: Baidu_Scan [64Bits] - {0A93904A-BB1E-4a0c-9753-B57B9AE272CB} . (...) -- C:\Program Files (x86)\Baidu Security\Baidu Antivirus\5.4.3.148966.0\BavShx64.dll (.not file.) C:\Program Files\Fix_Taskmgr.exe C:\Users\UTILISATEUR\AppData\Local\OneDrive HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\Baidu_Scan HKLM\Software\Classes\CLSID\{0A93904A-BB1E-4a0c-9753-B57B9AE272CB} HKLM\Software\Wow6432Node\Classes\CLSID\{0A93904A-BB1E-4a0c-9753-B57B9AE272CB} HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\WinRAR32 HKLM\Software\Classes\lnkfile\shellex\ContextMenuHandlers\Baidu_Scan HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\Emsisoft Shell Extension HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\Baidu_Scan HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\Emsisoft Shell Extension HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\WinRAR32 HKLM\Software\Classes\Drive\shellex\ContextMenuHandlers\Baidu_Scan HKLM\Software\Classes\Drive\shellex\ContextMenuHandlers\Emsisoft Shell Extension C:\WINDOWS\Installer\8f9b1aa5.msi C:\Users\UTILISATEUR\AppData\Roaming\rarcc.exe C:\Users\UTILIS~1\AppData\Local\Temp\tmp-xlv.xpi EmptyPrefetch Emptytemp EmptyClsid