Rapport de ZHPFix 2015.10.19.9 par Nicolas Coolman, Update du 19/10/2015 Fichier d'export Registre : Run by Evil Yukito at 10/02/2016 16:52:59 High Elevated Privileges : OK Windows 8 Home Premium Edition, 64-bit Service Pack 1 (10240) Recycle Bin emptied (01mn 39s) Prefetcher emptied ========== Software ========== REMOVES: Itibiti RTC ABSENT Uninstall Process: c:\users\evil yukito\appdata\roaming\enigma software group\sh_installer.exe ========== Registry keys ========== REMOVES Logiciel Key: [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SpyHunter] REMOVES: HKCU\SOFTWARE\winfixpro REMOVES:* StartupReg: cacaoweb REMOVES:* StartupReg: Facebook Update REMOVES:* StartupReg: Orange Installer ========== Registry values ========== ABSENT value Standard Profile: FirewallRaz : ABSENT value Domain Profile: FirewallRaz : REMOVES: FirewallRaz (None) : MCX-Prov-Out-TCP REMOVES: FirewallRaz (None) : MCX-McrMgr-Out-TCP REMOVES: FirewallRaz (None) : WCF-NetTcpActivator-In-TCP-64bit REMOVES: FirewallRaz (Public) : {2691E6AC-E16F-4CD2-B821-39E2F1C607BC} REMOVES: FirewallRaz (Public) : {B1DBB3FA-A04C-40E3-8CB3-423DE110632C} REMOVES: FirewallRaz (Public) : UDP Query User{E2CD2BD4-B425-4FED-8FBB-28CCB39A4431}C:\program files (x86)\heroes of the storm\versions\base37351\heroesofthestorm_x64.exe REMOVES: FirewallRaz (Public) : TCP Query User{3D5B9501-ABF9-4486-AA0C-D02679210DAA}C:\program files (x86)\heroes of the storm\versions\base37351\heroesofthestorm_x64.exe REMOVES: FirewallRaz (Private) : {E2C2AB48-A1BB-4293-B5ED-4EB93BC1E04B} REMOVES: FirewallRaz (Private) : {EE029E78-3367-4035-A23A-E3FD0A01C372} REMOVES: FirewallRaz (Private) : UDP Query User{4FE55064-1DE8-4266-B960-7903A2B61EC7}C:\program files (x86)\cabal2 (us)\c2launcher.exe REMOVES: FirewallRaz (Private) : TCP Query User{453C7ED8-F2D5-4D52-94AE-89900AB70F4F}C:\program files (x86)\cabal2 (us)\c2launcher.exe REMOVES: FirewallRaz (Private) : UDP Query User{24EF87A0-A122-4663-B280-D6F72395B84E}C:\users\evil yukito\appdata\local\temp\i1434760600\windows\resource\jre\bin\javaw.exe REMOVES: FirewallRaz (Private) : TCP Query User{D92A142C-ED53-4D45-A1C9-07064705CDB7}C:\users\evil yukito\appdata\local\temp\i1434760600\windows\resource\jre\bin\javaw.exe REMOVES: FirewallRaz (Private) : UDP Query User{C221271F-B9A3-4E85-9C20-F93465513AF3}C:\program files (x86)\heroes of the storm\versions\base34846\heroesofthestorm_x64.exe REMOVES: FirewallRaz (Private) : TCP Query User{1AB7FDC1-9B2A-49B4-B56A-B76DD3CA950B}C:\program files (x86)\heroes of the storm\versions\base34846\heroesofthestorm_x64.exe REMOVES: FirewallRaz (Private) : UDP Query User{E532B5B7-E174-4538-BD91-68CDC3932639}C:\program files (x86)\heroes of the storm\versions\base34659\heroesofthestorm_x64.exe REMOVES: FirewallRaz (Private) : TCP Query User{ACC13D7A-067A-432B-896C-0B91FB1E10C2}C:\program files (x86)\heroes of the storm\versions\base34659\heroesofthestorm_x64.exe REMOVES: FirewallRaz (Private) : {CB4E878A-D36D-445E-99D8-DB3E1DA91E32} REMOVES: FirewallRaz (Private) : {CBB6B6E7-3434-4CCF-B554-24D82A980412} REMOVES: FirewallRaz (Public) : {10741CF0-36F0-487F-82F9-DEE43532BC76} REMOVES: FirewallRaz (Public) : {1BA1EE3D-771F-4DF4-8F4B-343E3DD2413A} REMOVES: FirewallRaz (Private) : UDP Query User{A3E351C1-1E00-4F88-8713-F6E2D455297F}C:\users\evil yukito\appdata\local\temp\rarsfx0\hl.exe REMOVES: FirewallRaz (Private) : TCP Query User{33A228DC-C8F4-4E6D-9508-53CBEBEB3711}C:\users\evil yukito\appdata\local\temp\rarsfx0\hl.exe REMOVES: FirewallRaz (Private) : {0AC8AF15-5762-4782-93FF-14F620F6C640} REMOVES: FirewallRaz (Private) : {535B8282-1E35-4BDD-87E9-925E721FE532} REMOVES: FirewallRaz (Private) : {329047AA-0E1B-498B-BF3A-6B4D485C3142} REMOVES: FirewallRaz (Private) : {F19AC7D7-5038-42FC-8FF5-D5C548D21EA7} REMOVES: FirewallRaz (Private) : UDP Query User{A578BB09-FCC2-457A-9400-A6EB420A405F}C:\users\evil yukito\appdata\roaming\cacaoweb\cacaoweb.exe REMOVES: FirewallRaz (Private) : TCP Query User{4E746254-1AC4-4422-801D-F5462CC82ADC}C:\users\evil yukito\appdata\roaming\cacaoweb\cacaoweb.exe REMOVES: FirewallRaz (Private) : {2C25B336-2172-4BAE-8841-1E3B1DE34B4A} REMOVES: FirewallRaz (Private) : {5185F9B4-3536-43B6-8DA7-BBFB28B4EF99} REMOVES: FirewallRaz (Private) : {58E57749-C9C2-4A74-9922-A469B7343CF6} REMOVES: FirewallRaz (Private) : {32139A6E-6D79-4782-95C1-7DE9C050CACB} REMOVES: FirewallRaz (Public) : {075408F1-7085-4849-9D87-721717472189} REMOVES: FirewallRaz (Public) : {E7B991EC-791F-4FC6-8BE0-200F69BB429B} ========== Folders ========== Deletes temporary Windows (17822) REMOVES Flash Cookies (0) REMOVES: C:\Program Files (x86)\Software REMOVES: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus REMOVES: C:\ProgramData\InstallMate REMOVES: C:\ProgramData\McAfee REMOVES: c:\programdata\{3c5cbd7b-3d1d-411e-96c2-513ffca84d2d} REMOVES: C:\Users\Evil Yukito\AppData\Roaming\Enigma Software Group REMOVES: C:\Users\Evil Yukito\AppData\Local\CrashRpt REMOVES: C:\Users\Evil Yukito\AppData\Local\Installer REMOVES: C:\Users\Evil Yukito\AppData\Local\Software ========== Files ========== Deletes temporary Windows (5176) (702?759?492 octets) REMOVES Flash Cookies (0) (0 octets) REMOVES Reboot: c:\windows\system32\drivers\esgscanner.sys ========== Scheduled task ========== REMOVES: Reveil REMOVES: SidebarExecute ========== System restore ========== The system successfully created restore point ========== Summary ========== 5 : Registry keys 37 : Registry values 11 : Folders 3 : Files 2 : Software 2 : Scheduled task 1 : System restore End of clean in 03mn 53s ========== Path to file report ========== C:\Users\Evil Yukito\AppData\Roaming\ZHP\ZHPFix[R1].txt - 09/02/2016 20:55:28 [3102] C:\Users\Evil Yukito\AppData\Roaming\ZHP\ZHPFix[R2].txt - 10/02/2016 16:54:39 [5834]