~ ZHPFix v2019.3.28.40 by Nicolas Coolman (2019/03/28) ~ Run by HP (Administrator) (05/04/2019 18:04:07) ~ Web: https://www.nicolascoolman.com ~ Blog: https://nicolascoolman.eu/ ~ Certificate ZHPFix: Legal ~ State version : Version OK ~ Report : C:\Users\HP\Desktop\ZHPFix.txt ~ Quarantine : HKCU\SOFTWARE\ZHP\ZHPFix\Quarantine\ ~ UAC : Activate ~ Boot Mode : Normal (Normal boot) Windows 10 Pro, 64-bit (Build 17134) ---\\ SCRIPT DE L'UTILISATEUR. (65) Script Zhpfix O4 - HKCU\..\RunOnce: [Delete Cached Update Binary] . (. - .) -- /q /c del /q "C:\Users\HP\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe (.Not File.) O4 - HKCU\..\RunOnce: [Delete Cached Standalone Update Binary] . (. - .) -- /q /c del /q "C:\Users\HP\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe (.Not File.) O4 - HKUS\S-1-5-19\..\StartupApproved\Run: [OneDriveSetup] . (. - .) -- 0x020000000000000000000000 O4 - HKUS\S-1-5-20\..\StartupApproved\Run: [OneDriveSetup] . (. - .) -- 0x020000000000000000000000 O4 - HKLM\..\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe =>.Apple Inc.® O4 - HKCU\..\Run: [OneDrive] . (.Microsoft Corporation - Microsoft OneDrive.) -- C:\Users\HP\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation® O4 - HKCU\..\Run: [CCleaner Smart Cleaning] . (.Piriform Software Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe =>.Piriform Software Ltd® O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\SysWOW64\OneDriveSetup.exe =>.Microsoft Windows® O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\SysWOW64\OneDriveSetup.exe =>.Microsoft Windows® O4 - HKUS\S-1-5-19\..\StartupApproved\Run: [OneDriveSetup] . (. - .) -- 0x020000000000000000000000 =>.SUP.Orphan O4 - HKUS\S-1-5-20\..\StartupApproved\Run: [OneDriveSetup] . (. - .) -- 0x020000000000000000000000 =>.SUP.Orphan O4 - HKUS\S-1-5-21-2708689705-2006787418-4275935011-1001\..\Run: [OneDrive] . (.Microsoft Corporation - Microsoft OneDrive.) -- C:\Users\HP\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation® O4 - HKUS\S-1-5-21-2708689705-2006787418-4275935011-1001\..\Run: [CCleaner Smart Cleaning] . (.Piriform Software Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe =>.Piriform Software Ltd® O4 - HKUS\S-1-5-21-2708689705-2006787418-4275935011-1001\..\RunOnce: [Delete Cached Update Binary] . (. - .) -- /q /c del /q "C:\Users\HP\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe (.Not File.) O4 - HKUS\S-1-5-21-2708689705-2006787418-4275935011-1001\..\RunOnce: [Delete Cached Standalone Update Binary] . (. - .) -- /q /c del /q "C:\Users\HP\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe (.Not File.) [MD5.D92E8F1A06C588678F2F6CE5B1AC25E2] - (.McAfee, Inc. - McAfee Security Scanner Scheduler.) -- C:\Program Files\McAfee Security Scan\3.11.968\SSScheduler.exe [536912] [PID.8212] =>.McAfee, Inc.®HKCU\SOFTWARE\69846732-891f-563b-a7f3-958f57d206ec HKU\S-1-5-21-2708689705-2006787418-4275935011-1001\SOFTWARE\69846732-891f-563b-a7f3-958f57d206ec O42 - Logiciel: McAfee Security Scan Plus - (.McAfee, Inc..) [HKLM][64Bits] -- McAfee Security Scan =>.McAfee, Inc.® HKLM\SOFTWARE\McAfee =>.McAfee Inc. HKLM\SOFTWARE\mcafeeupdater =>.McAfee Inc. HKLM\SOFTWARE\WOW6432Node\McAfee.com =>.McAfee Inc. HKLM\SOFTWARE\WOW6432Node\mcafeeupdater =>.McAfee Inc. HKCU\SOFTWARE\69846732-891f-563b-a7f3-958f57d206ec =>Adware.CrossRider O43 - CFD: 06/03/2019 - [] D -- C:\Program Files\McAfee Security Scan =>.McAfee O43 - CFD: 04/04/2019 - [] D -- C:\ProgramData\McAfee Security Scan =>.McAfee C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\File System\016 C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\File System\017 C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\File System\022 C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\File System\023 EmptyPrefetch Emptytemp EmptyClsidScript Zhpfix O4 - HKCU\..\RunOnce: [Delete Cached Update Binary] . (. - .) -- /q /c del /q "C:\Users\HP\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe (.Not File.) O4 - HKCU\..\RunOnce: [Delete Cached Standalone Update Binary] . (. - .) -- /q /c del /q "C:\Users\HP\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe (.Not File.) O4 - HKUS\S-1-5-19\..\StartupApproved\Run: [OneDriveSetup] . (. - .) -- 0x020000000000000000000000 O4 - HKUS\S-1-5-20\..\StartupApproved\Run: [OneDriveSetup] . (. - .) -- 0x020000000000000000000000 O4 - HKLM\..\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe =>.Apple Inc.® O4 - HKCU\..\Run: [OneDrive] . (.Microsoft Corporation - Microsoft OneDrive.) -- C:\Users\HP\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation® O4 - HKCU\..\Run: [CCleaner Smart Cleaning] . (.Piriform Software Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe =>.Piriform Software Ltd® O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\SysWOW64\OneDriveSetup.exe =>.Microsoft Windows® O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\SysWOW64\OneDriveSetup.exe =>.Microsoft Windows® O4 - HKUS\S-1-5-19\..\StartupApproved\Run: [OneDriveSetup] . (. - .) -- 0x020000000000000000000000 =>.SUP.Orphan O4 - HKUS\S-1-5-20\..\StartupApproved\Run: [OneDriveSetup] . (. - .) -- 0x020000000000000000000000 =>.SUP.Orphan O4 - HKUS\S-1-5-21-2708689705-2006787418-4275935011-1001\..\Run: [OneDrive] . (.Microsoft Corporation - Microsoft OneDrive.) -- C:\Users\HP\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation® O4 - HKUS\S-1-5-21-2708689705-2006787418-4275935011-1001\..\Run: [CCleaner Smart Cleaning] . (.Piriform Software Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe =>.Piriform Software Ltd® O4 - HKUS\S-1-5-21-2708689705-2006787418-4275935011-1001\..\RunOnce: [Delete Cached Update Binary] . (. - .) -- /q /c del /q "C:\Users\HP\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe (.Not File.) O4 - HKUS\S-1-5-21-2708689705-2006787418-4275935011-1001\..\RunOnce: [Delete Cached Standalone Update Binary] . (. - .) -- /q /c del /q "C:\Users\HP\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe (.Not File.) [MD5.D92E8F1A06C588678F2F6CE5B1AC25E2] - (.McAfee, Inc. - McAfee Security Scanner Scheduler.) -- C:\Program Files\McAfee Security Scan\3.11.968\SSScheduler.exe [536912] [PID.8212] =>.McAfee, Inc.®HKCU\SOFTWARE\69846732-891f-563b-a7f3-958f57d206ec HKU\S-1-5-21-2708689705-2006787418-4275935011-1001\SOFTWARE\69846732-891f-563b-a7f3-958f57d206ec O42 - Logiciel: McAfee Security Scan Plus - (.McAfee, Inc..) [HKLM][64Bits] -- McAfee Security Scan =>.McAfee, Inc.® HKLM\SOFTWARE\McAfee =>.McAfee Inc. HKLM\SOFTWARE\mcafeeupdater =>.McAfee Inc. HKLM\SOFTWARE\WOW6432Node\McAfee.com =>.McAfee Inc. HKLM\SOFTWARE\WOW6432Node\mcafeeupdater =>.McAfee Inc. HKCU\SOFTWARE\69846732-891f-563b-a7f3-958f57d206ec =>Adware.CrossRider O43 - CFD: 06/03/2019 - [] D -- C:\Program Files\McAfee Security Scan =>.McAfee O43 - CFD: 04/04/2019 - [] D -- C:\ProgramData\McAfee Security Scan =>.McAfee C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\File System\016 C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\File System\017 C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\File System\022 C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\File System\023 EmptyPrefetch Emptytemp EmptyClsid ---\\ LOGICIEL. (1) DESINSTALLER : McAfee Security Scan ---\\ SERVICE. (0) ---\\ TÂCHE PLANIFIÉE. (0) ---\\ NAVIGATEUR INTERNET. (0) ---\\ EXPLORATEUR ( Dossiers, Fichiers ). (34) DEPLACÉ Fichier Run: C:\Program Files\iTunes\iTunesHelper.exe DEPLACÉ Fichier Run: C:\Users\HP\AppData\Local\Microsoft\OneDrive\OneDrive.exe DEPLACÉ Fichier Run: C:\Program Files\CCleaner\CCleaner64.exe DEPLACÉ Fichier Run: C:\Windows\SysWOW64\OneDriveSetup.exe SUPPRIMÉ Redémarrage Dossier ^: C:\Program Files\McAfee Security Scan SUPPRIMÉ Dossier : C:\ProgramData\McAfee Security Scan SUPPRIMÉ Dossier : C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\File System\016 SUPPRIMÉ Redémarrage Dossier ^: C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\File System\017 SUPPRIMÉ Dossier : C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\File System\022 SUPPRIMÉ Dossier : C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\File System\023 DEPLACÉ Fichier Temp: C:\Users\HP\AppData\Local\Temp\AdobeARM.log DEPLACÉ Fichier Temp: C:\Users\HP\AppData\Local\Temp\aria-debug-456.log SUPPRIMÉ Redémarrage Fichier Temp^: C:\Users\HP\AppData\Local\Temp\aria-debug-8324.log DEPLACÉ Fichier Temp: C:\Users\HP\AppData\Local\Temp\BITF56D.tmp DEPLACÉ Fichier Temp: C:\Users\HP\AppData\Local\Temp\tmpE275.tmp DEPLACÉ Fichier Temp: C:\Users\HP\AppData\Local\Temp\tmpFADE.tmp DEPLACÉ Fichier Temp: C:\Users\HP\AppData\Local\Temp\wct11A3.tmp DEPLACÉ Fichier Temp: C:\Users\HP\AppData\Local\Temp\wct1A93.tmp DEPLACÉ Fichier Temp: C:\Users\HP\AppData\Local\Temp\wct290.tmp DEPLACÉ Fichier Temp: C:\Users\HP\AppData\Local\Temp\wct3A7C.tmp DEPLACÉ Fichier Temp: C:\Users\HP\AppData\Local\Temp\wct3BE0.tmp DEPLACÉ Fichier Temp: C:\Users\HP\AppData\Local\Temp\wct6091.tmp DEPLACÉ Fichier Temp: C:\Users\HP\AppData\Local\Temp\wct72E6.tmp DEPLACÉ Fichier Temp: C:\Users\HP\AppData\Local\Temp\wct7998.tmp DEPLACÉ Fichier Temp: C:\Users\HP\AppData\Local\Temp\wct8EAC.tmp DEPLACÉ Fichier Temp: C:\Users\HP\AppData\Local\Temp\wct90E5.tmp DEPLACÉ Fichier Temp: C:\Users\HP\AppData\Local\Temp\wctA24E.tmp DEPLACÉ Fichier Temp: C:\Users\HP\AppData\Local\Temp\wctA3FA.tmp DEPLACÉ Fichier Temp: C:\Users\HP\AppData\Local\Temp\wctA650.tmp DEPLACÉ Fichier Temp: C:\Users\HP\AppData\Local\Temp\wctB3BE.tmp DEPLACÉ Fichier Temp: C:\Users\HP\AppData\Local\Temp\wctB484.tmp DEPLACÉ Fichier Temp: C:\Users\HP\AppData\Local\Temp\wctBC9.tmp DEPLACÉ Fichier Temp: C:\Users\HP\AppData\Local\Temp\wctC7B0.tmp DEPLACÉ Fichier Temp: C:\Users\HP\AppData\Local\Temp\wctF1DE.tmp ---\\ REGISTRE ( Clés, Valeurs, Données ). (32) ABSENT Valeur Run: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\ [/q /c del /q "C:\Users\HP\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe (.Not File.)] ABSENT Valeur Run: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\ [/q /c del /q "C:\Users\HP\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe (.Not File.)] SUPPRIMÉ Valeur Run: OneDriveSetup [HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\] SUPPRIMÉ Valeur Run: OneDriveSetup [HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\] ABSENT Valeur Run: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ [C:\Program Files\iTunes\iTunesHelper.exe ] SUPPRIMÉ Valeur Run: OneDrive [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\] SUPPRIMÉ Valeur Run: CCleaner Smart Cleaning [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\] SUPPRIMÉ Valeur Run: OneDriveSetup [HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\] SUPPRIMÉ Valeur Run: OneDriveSetup [HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\] ABSENT Valeur Run: HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\ [0x020000000000000000000000 ] ABSENT Valeur Run: HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\ [0x020000000000000000000000 ] ABSENT Valeur Run: HKU\S-1-5-21-2708689705-2006787418-4275935011-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ [C:\Users\HP\AppData\Local\Microsoft\OneDrive\OneDrive.exe ] ABSENT Valeur Run: HKU\S-1-5-21-2708689705-2006787418-4275935011-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ [C:\Program Files\CCleaner\CCleaner64.exe ] ABSENT Valeur Run: HKU\S-1-5-21-2708689705-2006787418-4275935011-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\ [/q /c del /q "C:\Users\HP\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe (.Not File.)] ABSENT Valeur Run: HKU\S-1-5-21-2708689705-2006787418-4275935011-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\ [/q /c del /q "C:\Users\HP\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe (.Not File.)] SUPPRIMÉ Clé: HKU\S-1-5-21-2708689705-2006787418-4275935011-1001\SOFTWARE\69846732-891f-563b-a7f3-958f57d206ec [69846732-891f-563b-a7f3-958f57d206ec] SUPPRIMÉ Clé: HKLM\SOFTWARE\McAfee [McAfee ] SUPPRIMÉ Clé: HKLM\SOFTWARE\mcafeeupdater [mcafeeupdater ] SUPPRIMÉ Clé: HKLM\SOFTWARE\WOW6432Node\McAfee.com [McAfee.com ] SUPPRIMÉ Clé: HKLM\SOFTWARE\WOW6432Node\mcafeeupdater [mcafeeupdater ] ABSENT Clé: HKCU\SOFTWARE\69846732-891f-563b-a7f3-958f57d206ec ABSENT Valeur Run: HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\ [0x020000000000000000000000] ABSENT Valeur Run: HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\ [0x020000000000000000000000] ABSENT Valeur Run: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ [C:\Users\HP\AppData\Local\Microsoft\OneDrive\OneDrive.exe ] ABSENT Valeur Run: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ [C:\Program Files\CCleaner\CCleaner64.exe ] ABSENT Valeur Run: HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ [C:\Windows\SysWOW64\OneDriveSetup.exe ] ABSENT Valeur Run: HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ [C:\Windows\SysWOW64\OneDriveSetup.exe ] ABSENT Clé: HKU\S-1-5-21-2708689705-2006787418-4275935011-1001\SOFTWARE\69846732-891f-563b-a7f3-958f57d206ec ABSENT Clé: HKLM\SOFTWARE\McAfee ABSENT Clé: HKLM\SOFTWARE\mcafeeupdater ABSENT Clé: HKLM\SOFTWARE\WOW6432Node\McAfee.com ABSENT Clé: HKLM\SOFTWARE\WOW6432Node\mcafeeupdater ---\\ COMMANDE. (5) ~ EmptyPrefetch: Fichiers Prefetcher supprimés (461) ~ EmptyTemp: Dossier Local temp partiellement vidé (24) ~ EmptyPrefetch: Fichiers Prefetcher supprimés (2) ~ EmptyTemp: Dossier Local temp partiellement vidé (1) ~ EmptyCSID: Dossiers CLSID vides supprimés (0) ---\\ NON TRAITÉ. (1) [MD5.D92E8F1A06C588678F2F6CE5B1AC25E2] - (.McAfee, Inc. - McAfee Security Scanner Scheduler.) -- C:\Program Files\McAfee Security Scan\3.11.968\SSScheduler.exe [536912] [PID.8212] ~ Le système a été redémarré. ***** ~ Fin de rapport terminé en 00h00mn40s