Rapport de ZHPFix 2015.4.9.5 par Nicolas Coolman, Update du 18/03/2015 Fichier d'export Registre : Run by bouhassoun at 15/06/2015 01:23:06 High Elevated Privileges : OK Windows 8 Home Premium Edition, 64-bit Service Pack 1 (9600) Recycle Bin emptied (00mn 03s) ========== Software ========== ABSENT Uninstall Process: c:\program files (x86)\baidu\baidu browser\uninst.exe ========== Registry keys ========== REMOVES Logiciel Key: [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Spark] REMOVES: Service: mglupdate REMOVES: Service: mglupdatem REMOVES: HKLM\Software\Wow6432Node\Baidu REMOVES: HKCU\Software\Baidu ========== Registry values ========== REMOVES RunValue: MaxigetMasterUpdate REMOVES RunValue: Viber REMOVES RunValue: AdobeAAMUpdater-1.0 REMOVES RunValue: gpuminer REMOVES RunValue: cpuminer REMOVES RunValue: EagleGet REMOVES RunValue: Facebook Update REMOVES RunValue: جدنف افاختبارات ABSENT value Standard Profile: FirewallRaz : ABSENT value Domain Profile: FirewallRaz : REMOVES: FirewallRaz (Domain) : {9E3D57FC-7C37-4424-9352-4831E97D029D} REMOVES: FirewallRaz (Domain) : {548DCF8C-BFF2-4BA4-AA88-FBAF9AC8BCC6} REMOVES: FirewallRaz (Domain) : NetPres-In-TCP-NoScope REMOVES: FirewallRaz (Domain) : NetPres-Out-TCP-NoScope REMOVES: FirewallRaz (None) : NetPres-WSD-In-UDP REMOVES: FirewallRaz (None) : NetPres-WSD-Out-UDP REMOVES: FirewallRaz (Public) : NetPres-In-TCP REMOVES: FirewallRaz (Public) : NetPres-Out-TCP REMOVES: FirewallRaz (None) : MCX-Prov-Out-TCP REMOVES: FirewallRaz (None) : MCX-McrMgr-Out-TCP REMOVES: FirewallRaz (Public) : UDP Query User{0EAF2315-631F-456C-B1B4-38F236A8CD12}C:\program files\active webcam\webcam.exe REMOVES: FirewallRaz (Public) : TCP Query User{C9AEA8F7-2BCF-4C2E-A186-B58C9B7F121E}C:\program files\active webcam\webcam.exe REMOVES: FirewallRaz (Public) : UDP Query User{99FCCC12-6F38-4384-A90B-722EF1FFF023}C:\users\bouhassoun\appdata\roaming\utorrent\utorrent.exe REMOVES: FirewallRaz (Public) : TCP Query User{3ED9BBD7-06BC-4B40-A1EC-F835B279E5D6}C:\users\bouhassoun\appdata\roaming\utorrent\utorrent.exe REMOVES: FirewallRaz (Private) : UDP Query User{094A6336-7347-4051-9E5E-F4B8A1BC7643}C:\users\bouhassoun\appdata\local\temp\ir_ext_temp_2\autoplay\docs\rtmpgw.exe REMOVES: FirewallRaz (Private) : TCP Query User{0753023E-F3D5-4DF3-BDD2-1988334A539C}C:\users\bouhassoun\appdata\local\temp\ir_ext_temp_2\autoplay\docs\rtmpgw.exe REMOVES: FirewallRaz (Private) : UDP Query User{294A8B86-342C-4C51-87B7-0A214EF24436}C:\program files (x86)\top tv\rtmpgw.exe REMOVES: FirewallRaz (Private) : TCP Query User{92C0E10B-C898-4D26-BE5F-73B05B0263DB}C:\program files (x86)\top tv\rtmpgw.exe REMOVES: FirewallRaz (Private) : UDP Query User{746D69FC-E806-4252-89F8-56A30DBD8067}C:\users\bouhassoun\appdata\roaming\utorrent\utorrent.exe REMOVES: FirewallRaz (Private) : TCP Query User{D49A7ED2-57B3-47F5-85F9-C295F0C795A7}C:\users\bouhassoun\appdata\roaming\utorrent\utorrent.exe REMOVES: FirewallRaz (Domain) : {E7985E1D-C36F-4787-80A8-6350D07E9266} REMOVES: FirewallRaz (None) : {808F1451-4108-46FD-ADBB-F17324B5F0BD} REMOVES: FirewallRaz (Public) : TCP Query User{BF1CDB15-ADE7-4100-87D8-9234B22F29D3}C:\program files (x86)\tv 3l pc\tv3lpcex.exe REMOVES: FirewallRaz (Public) : UDP Query User{9C290ABA-16DA-49D4-8C17-F92689A19F21}C:\program files (x86)\tv 3l pc\tv3lpcex.exe REMOVES: FirewallRaz (Public) : TCP Query User{448E6FCD-ABAC-400D-AFC7-A744F3829B26}C:\program files (x86)\symantec\norton online backup\nobuclient.exe REMOVES: FirewallRaz (Public) : UDP Query User{7C6905BF-7B0E-41BE-B2F8-3D9D74320215}C:\program files (x86)\symantec\norton online backup\nobuclient.exe REMOVES: FirewallRaz (Private) : {B845F5DD-48D3-4297-8810-182CE95373FF} REMOVES: FirewallRaz (Private) : {A19C8425-41CF-4681-8F76-FB2BC14E97E7} REMOVES: FirewallRaz (Private) : {03BE36BF-8D99-4890-B705-C668B8050E00} REMOVES: FirewallRaz (Private) : {EDCC1525-8FA7-428B-80DC-6076C8C2053C} REMOVES: FirewallRaz (Private) : {5B7F7AB5-16CA-4097-95A3-5F8520FC5812} REMOVES: FirewallRaz (Public) : {CAD98579-25DC-4471-9650-D046D60D510E} REMOVES: FirewallRaz (Public) : {24F9DCFE-971D-47CC-90F1-642E2081F09A} REMOVES: FirewallRaz (Public) : {1E53AC66-4EF4-41BA-AAFE-DD6DF69E363D} REMOVES: FirewallRaz (Public) : {E06A1A62-516E-47FB-BA87-E12EAA507B3D} REMOVES: FirewallRaz (Domain) : {97E8F858-CC04-49B3-AFA8-D4FA0E2DEF9E} REMOVES: FirewallRaz (Domain) : {D7B2C831-DC8A-4AD6-A521-17A96299A823} REMOVES: FirewallRaz (Private) : {9664B43B-CB06-4C4E-BAF7-9AD79E096FA5} REMOVES: FirewallRaz (Private) : {132177CA-1F2E-46AE-A7E2-C597DB00A5A6} ProxyFix : Proxy configuration successfully removed REMOVES ProxyServer Value REMOVES ProxyEnable Value REMOVES EnableHttp1_1 Value REMOVES ProxyHttp1.1 Value REMOVES ProxyOverride Value ========== Elements of the registry data ========== REMOVES Explorer Association Data Application: http://www.fileextensionpro.com/redir.aspx?s=obrdc1_0_0_0_0,854430f4-84ee-4a79-ade6-3e36cf370628,&LangID=%04x&Ext=%s ========== Folders ========== REMOVES: c:\program files (x86)\maxiget software manager REMOVES: c:\programdata\microsoft\windows\start menu\programs\maxiget software manager REMOVES: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Baidu Browser Deletes temporary Windows (25) REMOVES Flash Cookies (0) ========== Files ========== REMOVES: C:\Windows\Tasks\MaxigetUpdaterTaskMachineCore.job REMOVES: C:\Windows\System32\Tasks\MaxigetUpdaterTaskMachineCore REMOVES: C:\Windows\Tasks\MaxigetUpdaterTaskMachineUA.job REMOVES: C:\Windows\System32\Tasks\MaxigetUpdaterTaskMachineUA REMOVES Reboot: c:\windows\system32\config\systemprofile\appdata\roaming\maxiget\master\updater\masterupdater.exe REMOVES: c:\windows\prefetch\amt_oursurfing.exe-1f4ad0ee.pf REMOVES: c:\windows\prefetch\desktopicontoy.exe-0c950dab.pf REMOVES: c:\windows\prefetch\desktopicontoyx64.exe-7bf317be.pf REMOVES: c:\windows\prefetch\desktopicontoyx64.tmp-9c04c715.pf REMOVES: c:\windows\prefetch\desktopicontoyx64.tmp-9c16878a.pf REMOVES: c:\windows\prefetch\globalupdate.exe-a3071c5b.pf REMOVES: c:\windows\prefetch\globalupdatecrashhandler.exe-dffdc96b.pf REMOVES: c:\windows\prefetch\ins_shopperpro.exe-85f1dd4e.pf REMOVES: c:\windows\prefetch\maxigetcrashhandler.exe-3624a6d7.pf REMOVES: c:\windows\prefetch\maxigetupdater.exe-2d5bff64.pf REMOVES: c:\windows\prefetch\olbpre.exe-2ca25d00.pf REMOVES: c:\windows\prefetch\reimage.exe-7b15761e.pf REMOVES: c:\windows\prefetch\reimageexpresssetup.exe-c314c9ee.pf REMOVES: c:\windows\prefetch\reimagepackage.exe-9486a61b.pf REMOVES: c:\windows\prefetch\reimagerepair.exe-2883561a.pf REMOVES: c:\windows\prefetch\shopperpro.exe-123d782c.pf REMOVES: c:\windows\prefetch\utorrent.exe-0a08c655.pf REMOVES: c:\windows\prefetch\webplayer.exe-9f7e9fe8.pf REMOVES: c:\windows\prefetch\wpm_v20.0.0.2289.exe-6385fe2f.pf REMOVES: c:\windows\prefetch\ytdownloader.exe-3fac45e0.pf REMOVES: c:\program files (x86)\common files\adobe\oobe\pdapp\uwa\updaterstartuputility.exe REMOVES: c:\users\bouhassoun\appdata\local\facebook\update\facebookupdate.exe REMOVES: c:\users\public\desktop\google.lnk Deletes temporary Windows (165) (9 276 196 octets) REMOVES Flash Cookies (0) (0 octets) ========== Scheduled task ========== REMOVES: IYZWF REMOVES: IYZWF REMOVES: MaxigetUpdaterTaskMachineCore REMOVES: MaxigetUpdaterTaskMachineCore REMOVES: MaxigetUpdaterTaskMachineUA ========== System restore ========== The system successfully created restore point ========== Summary ========== 5 : Registry keys 55 : Registry values 1 : Elements of the registry data 5 : Folders 30 : Files 1 : Software 5 : Scheduled task 1 : System restore End of clean in 00mn 52s ========== Path to file report ========== C:\Users\bouhassoun\AppData\Roaming\ZHP\ZHPFix[R1].txt - 15/06/2015 01:23:09 [7849]