Script ZHPFix FirewallRaz EmptyPrefetch EmptyTemp [HKLM\Software\WOW6432Node\Microsoft\Security Center\Svc] AntiSpywareOverride: OK [HKLM\Software\WOW6432Node\Microsoft\Security Center\Svc] AntiVirusOverride: OK [HKLM\Software\WOW6432Node\Microsoft\Security Center\Svc] FirewallOverride: OK [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK [HKLM64\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{8B29D47F-92E2-4C20-9EE0-F710991F5D7C}_is1 =>HackTool.KMSpico C:\Program Files\KMSpico =>HackTool.KMSpico HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\WinRAR32 =>.SUP.Orphan HKLM\Software\Classes\CLSID\{B41DB860-8EE4-11D2-9906-E49FADC173CA} =>.SUP.Orphan HKLM\Software\Classes\lnkfile\shellex\ContextMenuHandlers\WinRAR32 =>.SUP.Orphan HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\WinRAR32 =>.SUP.Orphan C:\Windows\Installer\235dade.msp =>.SUP.Obsolete.Adobe C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\File System\002 =>.SUP.Temporary.Chrome C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\File System\003 =>.SUP.Temporary.Chrome C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\File System\004 =>.SUP.Temporary.Chrome C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\File System\006 =>.SUP.Temporary.Chrome C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\File System\007 =>.SUP.Temporary.Chrome C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\File System\008 =>.SUP.Temporary.Chrome C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\File System\009 =>.SUP.Temporary.Chrome C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\File System\010 =>.SUP.Temporary.Chrome C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\File System\011 =>.SUP.Temporary.Chrome C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\File System\012 =>.SUP.Temporary.Chrome C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\File System\013 =>.SUP.Temporary.Chrome C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\File System\014 =>.SUP.Temporary.Chrome C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\File System\015 =>.SUP.Temporary.Chrome C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\File System\016 =>.SUP.Temporary.Chrome C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\File System\017 =>.SUP.Temporary.Chrome C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\File System\018 =>.SUP.Temporary.Chrome C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\File System\019 =>.SUP.Temporary.Chrome C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\File System\020 =>.SUP.Temporary.Chrome C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\File System\021 =>.SUP.Temporary.Chrome C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\File System\022 =>.SUP.Temporary.Chrome C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\File System\023 =>.SUP.Temporary.Chrome C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\File System\024 =>.SUP.Temporary.Chrome C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\File System\025 =>.SUP.Temporary.Chrome C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\File System\026 =>.SUP.Temporary.Chrome C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\File System\027 =>.SUP.Temporary.Chrome C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\File System\028 =>.SUP.Temporary.Chrome C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\File System\029 =>.SUP.Temporary.Chrome O4 - HKCU\..\RunOnce: [Adobe Speed Launcher] . (. - .) -- 1621418026 =>.SUP.Orphan O4 - HKUS\S-1-5-21-2678541173-3945003891-1277454714-1000\..\RunOnce: [Adobe Speed Launcher] . (. - .) -- 1621418026 =>.SUP.Orphan O108 - CMH1: WinRAR32 [64Bits] - {B41DB860-8EE4-11D2-9906-E49FADC173CA} . (.Orphan.) [Unsigned] O108 - CMH2: WinRAR32 [64Bits] - {B41DB860-8EE4-11D2-9906-E49FADC173CA} . (.Orphan.) [Unsigned] O108 - CMH6: WinRAR32 [64Bits] - {B41DB860-8EE4-11D2-9906-E49FADC173CA} . (.Orphan.) [Unsigned] R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com =>.Google Inc. R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ =>.Microsoft Corporation R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ =>.Microsoft Corporation R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ =>.Microsoft Corporation R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ =>.Microsoft Corporation R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ =>.Microsoft Corporation R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ =>.Microsoft Corporation R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation R3 - URLSearchHook: (no name)[HKCU] - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Navigateur Internet.) (11.00.9600.19400 (winblue_ltsb_escrow.190617-1730)) -- C:\Windows\System32\ieframe.dll =>.Microsoft Corporation O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = hichambouazza40 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 =>.Local IP Adress O17 - HKLM\System\CCS\Services\Tcpip\..\{273ACE38-5A12-4E79-A1B6-54681428707E}: DhcpNameServer = 192.168.0.1 =>.Local IP Adress O108 - CMH3: XXX Groove GFS Context Menu Handler XXX [64Bits] - {6C467336-8281-4E60-8204-430CED96822D} . (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL =>.Microsoft Corporation® O108 - CMH4: XXX Groove GFS Context Menu Handler XXX [64Bits] - {6C467336-8281-4E60-8204-430CED96822D} . (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL =>.Microsoft Corporation® O108 - CMH5: XXX Groove GFS Context Menu Handler XXX [64Bits] - {6C467336-8281-4E60-8204-430CED96822D} . (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL =>.Microsoft Corporation® O108 - CMH6: XXX Groove GFS Context Menu Handler XXX [64Bits] - {6C467336-8281-4E60-8204-430CED96822D} . (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL =>.Microsoft Corporation® O69 - SBI: SearchScopes [HKCU] [64Bits]{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com/ =>.Bing.com O69 - SBI: SearchScopes [HKLM] [64Bits]{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (@ieframe.dll,-12512) - http://www.bing.com/ =>.Bing.com O87 - FAEL: "{EA859887-E3BE-40BA-AC51-4EC43EE7C109}" [In-None-P17-TRUE] .(...) -- C:\Windows\system32\LMabcoms.exe [Unsigned] O87 - FAEL: "{BD623AE0-DEB9-465B-B45A-47EF7D87A64C}" [In-None-P17-TRUE] .(.Google LLC - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google LLC®