Rapport de ZHPFix 2015.4.9.5 par Nicolas Coolman, Update du 18/03/2015 Fichier d'export Registre : Run by Jeremy at 01/07/2015 22:25:32 High Elevated Privileges : OK Windows 7 Ultimate Edition, 64-bit Service Pack 1 (Build 7601) Corbeille vidée (00mn 34s) ========== Clés du Registre ========== SUPPRIMÉ: HKCU\SOFTWARE\Win SUPPRIMÉ: HKCU\SOFTWARE\AppDataLow\Software\Smartbar Branche de Base de Registres IFEO non infectée ! ========== Valeurs du Registre ========== SUPPRIMÉ RunValue: start SUPPRIMÉ RunValue: systray Aucune Valeur Standard Profile: FirewallRaz : Aucune Valeur Domain Profile: FirewallRaz : SUPPRIMÉ: FirewallRaz (Public) : TCP Query User{4B690DFD-F4A3-45D4-94F4-D67B231750DB}D:\jeux\ncsoft\lineage ii clean tauti\system\l2.bin SUPPRIMÉ: FirewallRaz (Public) : UDP Query User{748F22E5-350C-49D4-8168-DE0A0C6005AA}D:\jeux\ncsoft\lineage ii clean tauti\system\l2.bin SUPPRIMÉ: FirewallRaz (Public) : TCP Query User{AF45F355-072B-4FDE-8F61-4A240925A6BE}D:\jeux\ncsoft\lineage ii high five\l2 tower\l2tower.exe SUPPRIMÉ: FirewallRaz (Public) : UDP Query User{26C2D776-7AEC-46E7-B4D1-B09197D2A3DD}D:\jeux\ncsoft\lineage ii high five\l2 tower\l2tower.exe SUPPRIMÉ: FirewallRaz (Private) : TCP Query User{858CF3E3-FBDE-4825-9147-4DEDD7A4A1A2}C:\users\jeremy\appdata\roaming\cacaoweb\cacaoweb.exe SUPPRIMÉ: FirewallRaz (Private) : UDP Query User{219A1CCD-C732-40DB-899E-98D9FA0AF9BE}C:\users\jeremy\appdata\roaming\cacaoweb\cacaoweb.exe SUPPRIMÉ: FirewallRaz (Private) : TCP Query User{2DCEF95B-9526-4BB6-86D2-5DBD42BFE833}D:\jeux\ncsoft\lineage ii freya\l2 tower\l2tower.exe SUPPRIMÉ: FirewallRaz (Private) : UDP Query User{31990318-8CDC-4434-9DA4-74E71500073C}D:\jeux\ncsoft\lineage ii freya\l2 tower\l2tower.exe SUPPRIMÉ: FirewallRaz (Private) : TCP Query User{3D311F00-8DE3-4AC3-87F4-572BD74E6145}D:\jeux\ncsoft\bot\l2tower.exe SUPPRIMÉ: FirewallRaz (Private) : UDP Query User{E039B258-1480-4D04-A9CE-076A96A67D39}D:\jeux\ncsoft\bot\l2tower.exe SUPPRIMÉ: FirewallRaz (Public) : TCP Query User{EE96FF74-94DC-448F-A124-F87A0474F7D5}C:\users\jeremy\appdata\roaming\cacaoweb\cacaoweb.exe SUPPRIMÉ: FirewallRaz (Public) : UDP Query User{9177E9F5-4DF8-47CD-B418-CE2493D136A3}C:\users\jeremy\appdata\roaming\cacaoweb\cacaoweb.exe SUPPRIMÉ: FirewallRaz (Public) : {E4B2136C-5AFE-4497-B03B-356916CD0FB3} SUPPRIMÉ: FirewallRaz (Public) : {87819549-D5FC-449F-AE78-778F327EA851} SUPPRIMÉ: FirewallRaz (Public) : {4767C50B-30D2-416F-8E4C-55C126A6B85D} SUPPRIMÉ: FirewallRaz (Public) : {E5BEE126-5A3F-4C58-8426-BB2798898086} SUPPRIMÉ: FirewallRaz (Private) : {D6EBDB41-0982-4660-B4DC-B05762578A56} SUPPRIMÉ: FirewallRaz (Private) : {9CEEF786-3CA9-4354-AB09-59D7A4F3C8B6} SUPPRIMÉ: FirewallRaz (Private) : {784B6542-726D-4EE5-B50B-CE4F57574D08} SUPPRIMÉ: FirewallRaz (Private) : {94A91792-7BED-4629-BD12-0D391F02F5D5} SUPPRIMÉ: FirewallRaz (Private) : {FA00C352-3CB8-4E75-B4C7-24E6DFDA5365} SUPPRIMÉ: FirewallRaz (Private) : {48F1DEC8-E3FD-49F7-BD85-6F402E8A83CA} SUPPRIMÉ: FirewallRaz (Public) : TCP Query User{4D81B908-B6BB-4EB3-9906-46AAEDAC99AA}D:\multimedia\jeux\lol\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcher.exe SUPPRIMÉ: FirewallRaz (Public) : UDP Query User{9E9AEB8A-1954-4308-9274-4072AC7E553A}D:\multimedia\jeux\lol\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcher.exe SUPPRIMÉ: FirewallRaz (Public) : TCP Query User{4EC3B8DA-D952-440C-B2F9-9BC11139B0A0}D:\multimedia\jeux\lol\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcherux.exe SUPPRIMÉ: FirewallRaz (Public) : UDP Query User{174CFD8F-C3EB-4FB2-A7FD-269B7568C098}D:\multimedia\jeux\lol\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcherux.exe ProxyFix : Configuration proxy supprimée avec succès SUPPRIMÉ ProxyServer Value SUPPRIMÉ ProxyEnable Value SUPPRIMÉ EnableHttp1_1 Value SUPPRIMÉ ProxyHttp1.1 Value SUPPRIMÉ ProxyOverride Value ========== Préférences navigateur ========== ABSENT Mozilla Pref: user_pref("smartbar.searchAddressUrlList", "http://search.conduit.com/ResultsExt.aspx?ctid=CT3205709&octid=CT3205709&CUI=UN7189471[...] SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B+7E+x305.storedInFile", true); SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B+7E,x305.storedInFile", true); SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B+7E-x305.storedInFile", true); SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B+7E.:2z527.storedInFile", true); SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B+7E.x305.storedInFile", true); SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B+7E/x305.storedInFile", true); SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B+7E06CG5EL8:", "6E6C716F6F6F6F6F7771"); SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B+7E06CG5EL8:.storedInFile", false); SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B+7E06CG5EL;8I:K", "247E2D2F226A74727775757575757D77242F4B49474F42357D5D5C3D"); SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B+7E06CG5EL;8I:K.storedInFile", false); SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B+7E0x305.storedInFile", true); SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B+7E1x305.storedInFile", true); SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B+7E2x305.storedInFile", true); SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B+7E31;CJI8A K@C.storedInFile", true); SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B+7E3x305.storedInFile", true); SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B+7E4x305.storedInFile", true); SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B+7E5x305.storedInFile", true); SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B+7E6x305.storedInFile", true); SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B+7E7x305.storedInFile", true); SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B+7E8x305.storedInFile", true); SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B+7E9x305.storedInFile", true); SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B+7E:x305.storedInFile", true); SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B+7E;x305.storedInFile", true); SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B+7Ex305.storedInFile", true); SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B+7E?x305.storedInFile", true); SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B+7E@x305.storedInFile", true); SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B+7EAx305.storedInFile", true); SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B+7EBE3G=;D9N9=D", "372C2D326975762E3A3C7B3A39434A494841434B265146492965504656496571734D334B57"); SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B+7EBE3G=;D9N9=D.storedInFile", false); SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B+7EBx305.storedInFile", true); SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B+7ECx305.storedInFile", true); SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B+7EDx305.storedInFile", true); SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B+7Etx305.storedInFile", true); SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B-0?3G>D", "6A6E6C6C6B3F71427A42484876207B7A7E7B254E2325212A2654292A2924572F2E305F5C"); SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B-0?3G>D.storedInFile", false); SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B-0?3G@6:5;", ""); SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B-0?3G@6:5;.storedInFile", false); SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B-0?3GFA7EF", "2B2E2C3D"); SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B-0?3GFA7EF.storedInFile", false); ABSENT Mozilla Pref: user_pref("valueApps.CT3205709./9B-3=3ECCJA=F>", "247E333D2C452F4135276F292A212C393D44307832332A354448584C3A23282E2E3132333435363B[...] SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B-3=3ECCJA=F>.storedInFile", false); SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B/>01=9A6K601=9A6K6F;P;ANR@P", "6E6C716F6F6F6F6F7771707779"); SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B6B11G4C56B>F;P;ANR@P.storedInFile", false); SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B90E@.3C;7B=?OFB>>RHIQS", "393F352F3E"); SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B90E@.3C;7B=?OFB>>RHIQS.storedInFile", false); SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B9643G3/9E", "6A"); SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B9643G3/9E.storedInFile", false); SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B;45>:BI9I7IE", "2B2E2C3D"); SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B;45>:BI9I7IE.storedInFile", false); SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B<:222H64<", "393F352F3E"); SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B<:222H64<.storedInFile", false); SUPPRIMÉ Mozilla Pref: user_pref("valueApps.CT3205709./9B<:222H64