Rapport de ZHPFix 2015.4.9.5 par Nicolas Coolman, Update du 18/03/2015 Fichier d'export Registre : Run by med at 25/06/2015 04:15:41 High Elevated Privileges : OK Windows 7 Business Edition, 64-bit (Build 7600) Recycle Bin emptied (00mn 03s) ========== Software ========== REMOVES: µTorrent ========== Process memory ========== ABSENT Memory Process: O34 - HKLM BootExecute: (autocheck autochk *) - File not found REMOVES: Memory Process: C:\Users\med\AppData\Local\Temp\Rar$EXb0.941\PdfGrabber.Pro.v7.0.0.8 STARTIMES\Cracked\PdfGrabber.exe REMOVES: Memory Process: C:\Users\med\Desktop\WL.v2.1.7.By.DAZ.ouez.MaZiKa2daY.CoM\Windows Loader\checksums.md5 REMOVES: Memory Process: C:\Users\med\Desktop\WL.v2.1.7.By.DAZ.ouez.MaZiKa2daY.CoM\Windows Loader\Keys.ini REMOVES: Memory Process: C:\Users\med\Desktop\WL.v2.1.7.By.DAZ.ouez.MaZiKa2daY.CoM\Windows Loader\Read me.txt REMOVES: Memory Process: C:\Users\med\Desktop\WL.v2.1.7.By.DAZ.ouez.MaZiKa2daY.CoM\Windows Loader\Windows Loader.exe REMOVES: Memory Process: C:\Users\med\AppData\Local\Temp\sp-downloader.exe ========== Registry keys ========== REMOVES:* Mozilla Plugin: @mcafee.com/MSC,version=10 REMOVES: Service: mfecore REMOVES: HKCU\Software\Baidu REMOVES: HKCU\Software\ParetoLogic REMOVES: HKCU\Software\oTweak REMOVES: HKLM\Software\Wow6432Node\ParetoLogic REMOVES: HKLM\Software\Wow6432Node\SmdmF REMOVES CLSID MPSK: {4ed793cb-c0fc-11e4-8375-806e6f6e6963} REMOVES CLSID MPSK: {c8b55049-c0ef-11e4-bb01-806e6f6e6963} REMOVES: SearchScopes :FCD7B04A0719377DEE63AA417463B6AC REMOVES: SearchScopes :{9BB47C17-9C68-4BB3-B188-DD9AF0FD2498} REMOVES: HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\uTorrent_RASAPI32 REMOVES: HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\uTorrent_RASMANCS REMOVES: HKLM\Software\Classes\Prod.cap REMOVES:* HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2498} ========== Registry values ========== REMOVES RunValue: SynTPEnh REMOVES CLSID SSODL: {E6FB5E20-DE35-11CF-9C87-00AA005127ED} ABSENT value Standard Profile: FirewallRaz : ABSENT value Domain Profile: FirewallRaz : REMOVES: FirewallRaz (Private) : TCP Query User{590383CD-6E7D-409A-8FAF-F41456B1AD1D}J:\snappy.driver.installer.r166.eng.2015.full.edition-nabil@batna\sdi_r166.exe REMOVES: FirewallRaz (Private) : UDP Query User{D903A565-EB5D-4550-9017-AA9D1E918927}J:\snappy.driver.installer.r166.eng.2015.full.edition-nabil@batna\sdi_r166.exe REMOVES: FirewallRaz (Public) : TCP Query User{38031D6D-B871-4F0E-B274-939BA43A69FB}J:\snappy.driver.installer.r166.eng.2015.full.edition-nabil@batna\sdi_r166.exe REMOVES: FirewallRaz (Public) : UDP Query User{7A1492C9-0EB0-4AC6-9AFB-A020A0A1DE26}J:\snappy.driver.installer.r166.eng.2015.full.edition-nabil@batna\sdi_r166.exe REMOVES: FirewallRaz (Public) : TCP Query User{69EE36A0-068D-462B-94CE-9561C5A8F0DA}H:\snappy.driver.installer.r166.eng.2015.full.edition-nabil@batna\sdi_r166.exe REMOVES: FirewallRaz (Public) : UDP Query User{709E3AEA-0EB5-487E-BCD8-FD475AE7704F}H:\snappy.driver.installer.r166.eng.2015.full.edition-nabil@batna\sdi_r166.exe ProxyFix : Proxy configuration successfully removed REMOVES ProxyServer Value REMOVES ProxyEnable Value REMOVES EnableHttp1_1 Value REMOVES ProxyHttp1.1 Value REMOVES ProxyOverride Value ========== Folders ========== REMOVES: C:\Program Files (x86)\baidu REMOVES: C:\Program Files (x86)\oTweak REMOVES: C:\ProgramData\Babylon REMOVES: C:\ProgramData\Baidu REMOVES: C:\Users\med\AppData\Roaming\Babylon REMOVES: C:\Users\med\AppData\Roaming\Baidu REMOVES: C:\Users\med\AppData\Roaming\RHEng REMOVES: C:\Users\med\AppData\Roaming\uTorrent REMOVES: C:\Users\med\AppData\Local\Babylon REMOVES: C:\Users\med\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\oTweak Software Deletes temporary Windows (660) REMOVES Flash Cookies (0) ========== Files ========== REMOVES: c:\program files (x86)\mozilla firefox\browser\searchplugins\default-search.xml REMOVES: C:\Users\med\Downloads\Compressed\Cracked.rar Deletes temporary Windows (2596) (1 519 871 415 octets) REMOVES Flash Cookies (0) (0 octets) ========== Scheduled task ========== REMOVES: Driver Booster SkipUAC (med) ========== System restore ========== The system successfully created restore point ========== Other ========== NON-TREATY Format du document : text/plain NON-TREATY Read more at http://www.cjoint.com/c/EFzcVtDCEdz#bWvoddhcAMHUfqHI.99 ========== Summary ========== 7 : Process memory 15 : Registry keys 16 : Registry values 12 : Folders 4 : Files 1 : Software 1 : Scheduled task 1 : System restore 2 : Other End of clean in 00mn 57s ========== Path to file report ========== C:\Users\med\AppData\Roaming\ZHP\ZHPFix[R1].txt - 25/06/2015 04:15:45 [4739]