voici le rapport avec ZHPFix apres le nettoyage
Rapport de ZHPFix 1.12.3345 par Nicolas Coolman, Update du 29/07/2011
Fichier d'export Registre :
Run by JChristian at 09-08-2011 15:57:14
Windows 7 Ultimate Edition, 64-bit (Build 7600)
Web site :
http://www.premiumorange.com/zeb-help-process/zhpfix.html
========== Memory Process ==========
DELETE on Reboot Memory Process: C:\Windows\system32\Tasks\Scheduled Update for Ask Toolbar
========== Registry Key ==========
NOT FOUND Key: CLSID BHO: {D4027C7F-154A-4066-A1AD-4243D8127440}
DELETED Key: HKCU\Software\AppDataLow\Software\AskToolbar
DELETED Key: HKCU\Software\Ask.com
DELETED Key: HKLM\Software\Classes\AppID\GenericAskToolbar.DLL
NOT FOUND Key: HKLM\Software\Wow6432Node\Classes\AppID\GenericAskToolbar.DLL
DELETED Key: HKLM\Software\Classes\GenericAskToolbar.ToolbarWnd
NOT FOUND Key: HKLM\Software\Wow6432Node\Classes\GenericAskToolbar.ToolbarWnd
DELETED Key: HKLM\Software\Classes\GenericAskToolbar.ToolbarWnd.1
NOT FOUND Key: HKLM\Software\Wow6432Node\Classes\GenericAskToolbar.ToolbarWnd.1
DELETED Key: HKLM\Software\Classes\Wow6432Node\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
NOT FOUND Key: HKLM\Software\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
DELETED Key: HKLM\Software\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
NOT FOUND Key: HKLM\Software\Wow6432Node\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
DELETED Key: HKLM\Software\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
DELETED Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
DELETED Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
DELETED Key: HKLM\Software\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF
DELETED Key: HKLM\Software\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
DELETED Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF
========== Registry Value ==========
DELETED RunValue: ApnUpdater
DELETED RunValue: QuickTime Task
DELETED RunValue: WinampAgent
NOT FOUND RunValue: TkBellExe
DELETED [HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]:{D4027C7F-154A-4066-A1AD-4243D8127440}
No Value in Standard Profile Register Key FirewallRaz :
No Value in Domain Profile Register Key FirewallRaz :
DELETED FirewallRaz (None) : {9F4274D1-D9F0-4A0A-BAC3-0A72A3BF7966}
DELETED FirewallRaz (Private) : TCP Query User{87BEB385-65DE-44AC-9697-0D951564E0E2}C:\users\jchristian\desktop\shoutcast-interface\console\sc_serv.exe
DELETED FirewallRaz (Private) : UDP Query User{06E7055B-1AAF-4BEA-A392-914765BCA89B}C:\users\jchristian\desktop\shoutcast-interface\console\sc_serv.exe
========== Registry Data Items ==========
REPLACED Value AntiVirusDisableNotify : Good (0) - Bad (1)
REPLACED Value FirewallDisableNotify : Good (0) - Bad (1)
REPLACED Value UpdatesDisableNotify : Good (0) - Bad (1)
========== Repertory ==========
DELETED Folder*: C:\Program Files\System
DELETED Folder: C:\Users\JChristian\AppData\Roaming\OpenCandy
DELETED Folder: C:\Users\JChristian\AppData\Local\OpenCandy
NOT FOUND C:\Program Files (x86)\Ask.com
DELETED Folder: c:\users\jchristian\appdata\roaming\mozilla\firefox\profiles\d7jt735u.default\extensions\dttoolbar@toolbarnet.com
DELETED Flash Cookies: 180
DELETED Window Temporary: : 906
========== File ==========
DELETED c:\program files (x86)\ask.com
NOT FOUND File: c:\program files (x86)\ask.com
NOT FOUND Folder/File: c:\users\jchristian\appdata\roaming\opencandy
NOT FOUND Folder/File: c:\users\jchristian\appdata\local\opencandy
NOT FOUND Folder/File: c:\program files (x86)\ask.com
DELETED Flash Cookies: 62
DELETED Window Temporary: : 2445
========== Hosts file ==========
Hosts File not cleaned
========== Restoration ==========
Restore System Point created succefully
========== Summary ==========
1 : Memory Process
19 : Registry Key
10 : Registry Value
3 : Registry Data Items
7 : Repertory
7 : File
1 : Hosts file
1 : Restoration
========== Report File ==========
C:\ZHP\ZHPFixReport.txt
End of the scan in 01mn 00s
voici le rapport Ad-remover
======= REPORT FROM AD-REMOVER 2.0.0.2,G | ONLY XP/VISTA/7 =======
Updated by TeamXscript on 12/04/11
Contact: AdRemover[DOT]contact[AT]gmail[DOT]com
website:
http://www.teamxscript.org
C:\Program Files (x86)\Ad-Remover\main.exe (CLEAN [1]) -> Launched at 16:11:55 on 09/08/2011, Normal boot
Microsoft Windows 7 Ultimate (X64)
JChristian@JCHRISTIAN ( )
============== ACTION(S) ==============
Folder deleted: C:\Users\JChristian\AppData\Roaming\Mozilla\FireFox\Profiles\d7jt735u.default\extensions\toolbar@ask.com
File deleted: C:\Users\JChristian\AppData\Roaming\Mozilla\FireFox\Profiles\d7jt735u.default\searchplugins\askcom.xml
Folder deleted: C:\Users\JChristian\AppData\LocalLow\AskToolbar
(!) -- Temporary files deleted.
-- File opened: C:\Users\JChristian\AppData\Roaming\Mozilla\FireFox\Profiles\d7jt735u.default\Prefs.js --
Line deleted: user_pref("browser.search.defaultengine", "Ask.com");
Line deleted: user_pref("browser.search.defaultenginename", "Ask.com");
Line deleted: user_pref("browser.search.order.1", "Ask.com");
Line deleted: user_pref("browser.search.selectedEngine", "Ask.com");
Line deleted: user_pref("extensions.asktb.abar-war-timeout", "4000");
Line deleted: user_pref("extensions.asktb.cbid", "RX");
Line deleted: user_pref("extensions.asktb.config-updated", true);
Line deleted: user_pref("extensions.asktb.crumb", "2011.07.08+00.06.52-toolbar007iad-IN-QmFuZ2Fsb3JlLEluZGlh");
Line deleted: user_pref("extensions.asktb.default-channel-url-mask", "hxxp://www.ask.com/web?q={query}&o={o}&l={l}...
Line deleted: user_pref("extensions.asktb.dtid", "YYYYYYYYIN");
Line deleted: user_pref("extensions.asktb.dyn-weather-do-locid-lookup-weatherWidget", true);
Line deleted: user_pref("extensions.asktb.ff-original-keyword-url", "hxxp://websearch.ask.com/redirect?client=ff&s...
Line deleted: user_pref("extensions.asktb.fresh-install", false);
Line deleted: user_pref("extensions.asktb.hxxp-header-whitelist-hosts", "[\"static-dev.en.dev.ask.com\", \"ask.com...
Line deleted: user_pref("extensions.asktb.l", "dis");
Line deleted: user_pref("extensions.asktb.last-config-req", "1312835520563");
Line deleted: user_pref("extensions.asktb.locale", "en_US");
Line deleted: user_pref("extensions.asktb.o", "15180");
Line deleted: user_pref("extensions.asktb.overlay-reloaded-using-restart", true);
Line deleted: user_pref("extensions.asktb.qsrc", "2871");
Line deleted: user_pref("extensions.asktb.r", "3");
Line deleted: user_pref("extensions.asktb.search-plugin-suggestions-url", "hxxp://ss.websearch.ask.com/query?qsrc=...
Line deleted: user_pref("extensions.asktb.search-suggestions-enabled", true);
Line deleted: user_pref("extensions.asktb.silent-upgrade", true);
Line deleted: user_pref("extensions.asktb.silent-upgrade-from-pre-newtabs-build", true);
Line deleted: user_pref("extensions.asktb.socialmini-first", true);
Line deleted: user_pref("extensions.asktb.socialmini-interval", "1200000");
Line deleted: user_pref("extensions.asktb.socialmini-max-char-ticker", "33");
Line deleted: user_pref("extensions.asktb.socialmini-max-items", "30");
Line deleted: user_pref("extensions.asktb.socialmini-native-on", true);
Line deleted: user_pref("extensions.asktb.socialmini-speed", "5000");
Line deleted: user_pref("extensions.asktb.socialmini-transition-first-open", false);
Line deleted: user_pref("extensions.asktb.v", "3.12.2.100006");
Line deleted: user_pref("extensions.enabledAddons", "{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20,{CAFEEFAC-0016-...
Line deleted: user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"{23fcfd51-4958-...
Line deleted: user_pref("keyword.URL", "hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=PF&o=15180&locale=en...
Line deleted: user_pref("sweetim.toolbar.previous.keyword.URL", "hxxp://websearch.ask.com/redirect?client=ff&src=k...
-- File closed --
Key deleted: HKLM\Software\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}
Key deleted: HKLM\Software\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key deleted: HKLM\Software\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Key deleted: HKLM\Software\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Key deleted: HKLM\Software\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Key deleted: HKLM\Software\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Key deleted: HKLM\Software\AskToolbar
Key deleted: HKLM\Software\Conduit
Key deleted: HKCU\Software\Conduit
Key deleted: HKCU\Software\AppDataLow\AskToolbarInfo
Key deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}
Key deleted: HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key deleted: HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Value deleted: HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks|{00000000-6E41-4FD3-8538-502F5495E5FC}
Value deleted: HKLM\Software\Microsoft\Internet Explorer\Toolbar|{D4027C7F-154A-4066-A1AD-4243D8127440}
============== ADDITIONNAL SCAN ==============
**** Mozilla Firefox Version [5.0 (en-US)] ****
Plugins\npDivxPlayerPlugin.dll (DivX, Inc)
Plugins\npdnu.dll (AOL LLC)
Plugins\npdnupdater2.dll (AOL LLC)
Plugins\npFoxitReaderPlugin.dll (Foxit Software Company)
Plugins\npwachk.dll (Nullsoft, Inc.)
HKLM_MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 (x)
HKLM_MozillaPlugins\Adobe Reader (x)
HKLM_MozillaPlugins\NitroPDF (x)
Searchplugins\amazondotcom.xml (hxxp://www.amazon.com/exec/obidos/external-search/)
Searchplugins\bing.xml ( hxxp://www.bing.com/search)
Searchplugins\eBay.xml (hxxp://rover.ebay.com/rover/1/711-47294-18009-3/4)
Searchplugins\wikipedia.xml (hxxp://en.wikipedia.org/wiki/Special:Search)
Components\browsercomps.dll (Mozilla Foundation)
HKLM_Extensions|{23fcfd51-4958-4f00-80a3-ae97e717ed8b} - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
-- C:\Users\JChristian\AppData\Roaming\Mozilla\FireFox\Profiles\d7jt735u.default --
Extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f} (Winamp Toolbar)
Extensions\{12e4c684-c03e-4e4d-85bc-0c065e7a9489} (SHOUTcast Radio Toolbar)
Extensions\{37964A3C-4EE8-47b1-8321-34DE2C39BA4D} (??????? @Mail.Ru)
Extensions\{EEE6C361-6118-11DC-9C72-001320C79847} (SweetIM Toolbar for Firefox)
Searchplugins\aol-web-search.xml (?)
Searchplugins\mailru---.xml (?)
Searchplugins\sweetim.xml (?)
Prefs.js - browser.search.defaulturl, hxxp://search.winamp.com/search/search?query={searchTerms}&invocationType=tb50-ff-winamp-chro...
Prefs.js - browser.startup.homepage, hxxp://www.google.com
Prefs.js - browser.startup.homepage_override.buildID, 20110615151330
Prefs.js - browser.startup.homepage_override.mstone, rv:5.0
========================================
**** Google Chrome Version [12.0.742.122] ****
Extension\jfmjfhklogoienhpfnppmbcbjfjnkonk (C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Chrome\Ext\rphtml5video.crx) (?)
Extension\nneajnkjbffgblleaoojgaacokifdkhm (C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx) (?)
-- C:\Users\JChristian\AppData\Local\Google\Chrome\User Data\Default --
Preferences - default_search_provider: "Google" (Enabled: true) (?)
Preferences - homepage: hxxp://www.google.com/
Preferences - homepage_is_newtabpage: false
========================================
**** Internet Explorer Version [9.0.8112.16421] ****
HKCU_Main|Default_Page_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
HKCU_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU_Main|Search bar - hxxp://go.microsoft.com/fwlink/?linkid=54896
HKCU_Main|Start Page - hxxp://fr.msn.com/
HKLM_Main|Default_Page_URL - hxxp://go.microsoft.com/fwlink/?LinkId=54896
HKLM_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM_Main|Search bar - hxxp://search.msn.com/spbasic.htm
HKLM_Main|Search Page - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM_Main|Start Page - hxxp://fr.msn.com/
HKCU_URLSearchHooks|{14f0d511-36a2-41ca-ae01-ba4f87282c97} - "SHOUTcast Toolbar Search Class" (C:\Program Files (x86)\SHOUTcast Radio Toolbar\shoutcasttb.dll)
HKLM_URLSearchHooks|{14f0d511-36a2-41ca-ae01-ba4f87282c97} - "SHOUTcast Toolbar Search Class" (C:\Program Files (x86)\SHOUTcast Radio Toolbar\shoutcasttb.dll)
HKLM_URLSearchHooks|{57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - "Winamp Toolbar Search Class" (C:\Program Files (x86)\Winamp Toolbar\winamptb.dll)
HKCU_SearchScopes\{F87FC392-D7A4-480D-AAFA-F00E67E9016E} - "?" (?)
HKCU_Toolbar\WebBrowser|{32099AAC-C132-4136-9E9A-4E364A424E17} (C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll)
HKCU_Toolbar\WebBrowser|{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} (C:\Program Files (x86)\Winamp Toolbar\winamptb.dll)
HKLM_Toolbar|{8dcb7100-df86-4384-8842-8fa844297b3f} (C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll)
HKLM_Toolbar|{32099AAC-C132-4136-9E9A-4E364A424E17} (C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll)
HKLM_Toolbar|{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} (C:\Program Files (x86)\Winamp Toolbar\winamptb.dll)
HKLM_Toolbar|{0457331d-8ca6-4f97-9c26-6a9ef2b2dba8} (C:\Program Files (x86)\SHOUTcast Radio Toolbar\shoutcasttb.dll)
HKLM_Toolbar|{EEE6C35B-6118-11DC-9C72-001320C79847} (C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll)
HKLM_ElevationPolicy\{07d873dc-b9b9-44f5-af0b-fb59fa54fb7a} - C:\Windows\SysWOW64\wpcer.exe (x)
HKLM_ElevationPolicy\{0a402d70-1f10-4ae7-bec9-286a98240695} - C:\Windows\SysWOW64\winfxdocobj.exe (x)
HKLM_ElevationPolicy\{5F17E524-3447-4c7d-8E5F-4EFF31CDE3B7} - C:\Program Files (x86)\Common Files\DivX Shared\DesktopService\DDMService.exe (DivX, LLC)
HKLM_ElevationPolicy\{64903E32-AE0B-408D-909C-09A08791F28D} - C:\Program Files (x86)\DivX\DivX Plus Web Player\dwpBroker.exe (?)
HKLM_ElevationPolicy\{70f641fd-9ffc-4d5b-a4dc-962af4ed7999} - C:\Program Files (x86)\Internet Explorer\iedw.exe (x)
HKLM_ElevationPolicy\{7BD9A644-9DC6-42be-8872-CBF5524276BD} - C:\Program Files (x86)\Common Files\Software Update Utility\dnu.exe (AOL LLC)
HKLM_ElevationPolicy\{a8c2644d-bf72-4a89-a88c-d85f565f2f46} - c:\program files (x86)\winamp toolbar\winamptbServer.exe (AOL Inc.)
HKLM_ElevationPolicy\{ADADAEE2-457A-4984-A57C-E01C3A2BA612} - c:\program files (x86)\shoutcast radio toolbar\SHOUTcastTbServer.exe (AOL LLC)
HKLM_ElevationPolicy\{B43A0C1E-B63F-4691-B68F-CD807A45DA01} - C:\Windows\system32\TSWbPrxy.exe (x)
HKLM_ElevationPolicy\{D802E3EF-2513-4661-972E-BAD737EFBA88} - C:\Program Files (x86)\DivX\DivX OVS Helper\OVSHelperBroker.exe (DivX, LLC.)
HKLM_ElevationPolicy\{EEE6C367-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgHelperApp.exe (SweetIM Technologies Ltd.)
HKLM_Extensions\{B205A35E-1FC4-4CE3-818B-899DBBB3388C} - "Barre de recherche Encarta" (?)
BHO\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - "Winamp Toolbar Loader" (C:\Program Files (x86)\Winamp Toolbar\winamptb.dll)
BHO\{326E768D-4182-46FD-9C16-1449A49795F4} - "DivX Plus Web Player HTML5 <video>" (C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll)
BHO\{5FF49FE8-B332-4CB9-B102-FB6951629E55} - "Virtual Storage Mount Notification" (C:\Windows\SysWOW64\CbFsMntNtf3.dll)
BHO\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - "Search Helper" (C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll)
BHO\{CC59E0F9-7E43-44FA-9FAA-8377850BF205} - "FDMIECookiesBHO Class" (C:\Program Files (x86)\Free Download Manager\iefdm2.dll)
BHO\{ccec60fc-2608-4e58-9659-3ffc159e8ea9} - "SHOUTcast Loader" (C:\Program Files (x86)\SHOUTcast Radio Toolbar\shoutcasttb.dll)
BHO\{EEE6C35C-6118-11DC-9C72-001320C79847} - "SweetIM Toolbar Helper" (C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll)
========================================
C:\Program Files (x86)\Ad-Remover\Quarantine: 220 File(s)
C:\Program Files (x86)\Ad-Remover\Backup: 14 File(s)
C:\Ad-Report-CLEAN[1].txt - 09/08/2011 16:12:20 (12546 Byte(s))
End at: 16:13:14, 09/08/2011
============== E.O.F ==============
merci de votre aide