Rapport de ZHPFix 2015.10.19.9 par Nicolas Coolman, Update du 19/10/2015 Fichier d'export Registre : Run by MUHANNAD at 30/10/2016 08:52:07 Õ High Elevated Privileges : OK Windows 8 Home Premium Edition, 64-bit Service Pack 1 (9600) Recycle Bin emptied (:0mn Õs) Prefetcher emptied ========== Registry keys ========== REMOVES: Service: IlS REMOVES: HKLM\SOFTWARE\Wow6432Node\BE4CF238B4FB758E41F819FA57386F21 ========== Registry values ========== ABSENT value Standard Profile: FirewallRaz : ABSENT value Domain Profile: FirewallRaz : REMOVES: FirewallRaz (Domain) : {9E3D57FC-7C37-4424-9352-4831E97D029D} REMOVES: FirewallRaz (Domain) : {548DCF8C-BFF2-4BA4-AA88-FBAF9AC8BCC6} REMOVES: FirewallRaz (Domain) : NetPres-In-TCP-NoScope REMOVES: FirewallRaz (Domain) : NetPres-Out-TCP-NoScope REMOVES: FirewallRaz (None) : NetPres-WSD-In-UDP REMOVES: FirewallRaz (None) : NetPres-WSD-Out-UDP REMOVES: FirewallRaz (Public) : NetPres-In-TCP REMOVES: FirewallRaz (Public) : NetPres-Out-TCP REMOVES: FirewallRaz (None) : MCX-Prov-Out-TCP REMOVES: FirewallRaz (None) : MCX-McrMgr-Out-TCP REMOVES: FirewallRaz (Public) : {7D44EFE4-0269-4ABA-938A-00F14A9332DF} REMOVES: FirewallRaz (Public) : {81B8E092-BA72-40A5-B58A-8632E9F9F764} REMOVES: FirewallRaz (Public) : {B94CDFAF-8495-4B3C-994C-DD719385BEBB} REMOVES: FirewallRaz (Public) : {B568A4B4-5DE7-4475-A4A3-C3689737538C} REMOVES: FirewallRaz (None) : {9B798E2A-0533-497B-BBA3-868CC4F3F5E1} REMOVES: FirewallRaz (Private) : {2D2303DE-0804-4CA7-AAEF-700B4B99DCED} REMOVES: FirewallRaz (Private) : {D3CB08A9-5D25-43CD-8185-C6122AE07D4D} REMOVES: FirewallRaz (Private) : {A375583B-4558-432D-A6E5-9462D41A1DB0} REMOVES: FirewallRaz (Private) : {395E8760-C729-4278-8DBC-DD8984E14B76} REMOVES: FirewallRaz (Public) : TCP Query User{F1DD4F04-CAFE-4C6B-BCA7-1AF23510E623}C:\program files (x86)\sopcast\sopcast.exe REMOVES: FirewallRaz (Public) : UDP Query User{C2B6507E-47C8-4C45-978A-3C4956205170}C:\program files (x86)\sopcast\sopcast.exe REMOVES: FirewallRaz (Public) : TCP Query User{E82D9738-7C9F-42E6-AC3D-F5AE99C0CC5D}C:\users\muhannad\desktop\utorrent pro v3.4.5 build 41202 stable multilingual\pro\utorrent.exe REMOVES: FirewallRaz (Public) : UDP Query User{648C93BD-26FC-4D6D-94EA-93888DBC632C}C:\users\muhannad\desktop\utorrent pro v3.4.5 build 41202 stable multilingual\pro\utorrent.exe REMOVES: FirewallRaz (Private) : {FC466006-9A70-41FF-AAA5-FC4F025B7453} REMOVES: FirewallRaz (Private) : {26BD11C1-95FE-4F8C-811A-7DAB5CD16472} REMOVES: FirewallRaz (Private) : {8C25D326-C75B-4226-A7BF-08D0ECDAC8FD} REMOVES: FirewallRaz (Private) : {BB8EA077-14CF-48E8-B2BE-3921DCA2E708} REMOVES: FirewallRaz (Domain) : {0C5F92AD-1BDB-4B50-BCC5-C90912449DCC} REMOVES: FirewallRaz (Domain) : {D325944C-0F04-4500-8A4F-0288AE164862} REMOVES: FirewallRaz (Domain) : {6862E17A-585D-4084-9AA7-AD63975CF0B5} REMOVES: FirewallRaz (Domain) : {5451F4F1-5970-42D4-87AB-E0B9C2F29C0B} REMOVES: FirewallRaz (Public) : TCP Query User{772ADEA2-AD8A-4332-83D3-9A0963DE9C8A}C:\program files (x86)\dearmob\5kplayer\5kplayer.exe REMOVES: FirewallRaz (Public) : UDP Query User{495B4E0D-78F4-402C-AEB8-87C218A93E8C}C:\program files (x86)\dearmob\5kplayer\5kplayer.exe REMOVES: FirewallRaz (Private) : {49D4A19D-9B0A-4CF6-945A-E2EFF6812686} REMOVES: FirewallRaz (Private) : {81330FAD-2762-43A3-8A2D-4519BECF4D47} REMOVES: FirewallRaz (Public) : TCP Query User{0899A681-6BD2-41FF-AFD2-88B82A7EFA0E}C:\program files (x86)\embratoria\embratoriag1\embrastreamer.exe REMOVES: FirewallRaz (Public) : UDP Query User{27530B1B-57C2-4A88-94BD-0128EA51EC0E}C:\program files (x86)\embratoria\embratoriag1\embrastreamer.exe REMOVES: FirewallRaz (Private) : {C76F2859-38B6-4E09-AD03-B13D5C9D096E} REMOVES: FirewallRaz (Private) : {6186B990-DEED-4E0C-B8E1-0803563DCFA9} REMOVES: FirewallRaz (Public) : TCP Query User{0533C714-2A97-4C3D-9623-6E37D2687547}C:\program files (x86)\origin games\fifa 16\fifa16.exe REMOVES: FirewallRaz (Public) : UDP Query User{5A58A0B5-3224-4426-B39F-76B5E96E1897}C:\program files (x86)\origin games\fifa 16\fifa16.exe REMOVES: FirewallRaz (Public) : TCP Query User{696FB1B8-CA7A-4B81-8EF2-F6D9CE4DFAE0}C:\users\muhannad\appdata\local\temp\rar$exa0.942\embratoria_g3\es.exe REMOVES: FirewallRaz (Public) : UDP Query User{CB0194AD-160E-4804-A2BC-92E2B3ADFB8B}C:\users\muhannad\appdata\local\temp\rar$exa0.942\embratoria_g3\es.exe REMOVES: FirewallRaz (Public) : TCP Query User{BFF94AF4-D524-4393-8DE5-F6C1A40896BD}C:\users\muhannad\appdata\local\temp\rar$exa0.274\embratoria_g3\es.exe REMOVES: FirewallRaz (Public) : UDP Query User{58C45108-4C69-4A13-A1E7-83273C20C515}C:\users\muhannad\appdata\local\temp\rar$exa0.274\embratoria_g3\es.exe REMOVES: FirewallRaz (Public) : TCP Query User{F2CB11EB-814C-4722-B5AC-34BBA5B3A2F1}C:\users\muhannad\desktop\embratoria_g3\es.exe REMOVES: FirewallRaz (Public) : UDP Query User{6329B2CD-28A5-40B7-AE8A-D2CF950EF199}C:\users\muhannad\desktop\embratoria_g3\es.exe REMOVES: FirewallRaz (Public) : {F21BC326-30BF-40ED-B166-56E828EAFBA6} REMOVES: FirewallRaz (Public) : TCP Query User{2ECC852E-B9B9-48D1-9226-5B7E20129CD5}C:\users\muhannad\desktop\embratoria_g4\es.exe REMOVES: FirewallRaz (Public) : UDP Query User{F8C2A902-31EB-4C8B-BBF8-AF2A2542E4D7}C:\users\muhannad\desktop\embratoria_g4\es.exe REMOVES: FirewallRaz (Public) : TCP Query User{153A5EAD-006C-4159-99A2-F06FE0F34391}C:\users\muhannad\desktop\nba all-star weekend 2016 toronto\b593u-91_v100r001c00sp056_universal_05011uxc_asanfile.com\ver\b593_upgrade.exe REMOVES: FirewallRaz (Public) : UDP Query User{5052EA39-F902-4E2C-9162-0E9AAB36BAF4}C:\users\muhannad\desktop\nba all-star weekend 2016 toronto\b593u-91_v100r001c00sp056_universal_05011uxc_asanfile.com\ver\b593_upgrade.exe REMOVES: FirewallRaz (None) : {12D7AB40-B3B3-49EA-900A-D847E03919CD} REMOVES: FirewallRaz (Public) : TCP Query User{390829EA-6EF5-4F49-A0CC-480FAEB2B2F2}C:\games\saints row iv\saintsrowiv.exe REMOVES: FirewallRaz (Public) : UDP Query User{8F654F20-CFAA-4D09-B459-34935C90C546}C:\games\saints row iv\saintsrowiv.exe REMOVES: FirewallRaz (Public) : TCP Query User{71F38E39-A06E-433F-84F0-379193C48E7C}C:\users\muhannad\appdata\local\temp\hydda72.tmp.1462914091_permissionscopy\utorrent.exe REMOVES: FirewallRaz (Public) : UDP Query User{5F339CE6-CD72-4619-9826-19E768F8BEFA}C:\users\muhannad\appdata\local\temp\hydda72.tmp.1462914091_permissionscopy\utorrent.exe REMOVES: FirewallRaz (Private) : {E949955D-DCFD-47DB-A303-8FB0C7F40D11} REMOVES: FirewallRaz (Private) : {280889AA-E364-42CB-AA73-9819E9E89EC4} REMOVES: FirewallRaz (Private) : {8F6C6044-569D-43D6-B5AD-8DE0ECA90D52} REMOVES: FirewallRaz (Private) : {BD678AE8-119F-4D28-AA3A-FB4A4D0AD460} REMOVES: FirewallRaz (Private) : {CE796E62-FCD7-4887-8B04-266658779E0F} REMOVES: FirewallRaz (Private) : {DF403DE4-6877-43C9-B036-ABA97677EA4D} REMOVES: FirewallRaz (None) : {66A4F58A-39A1-4DE7-8E92-3EACB25A4E85} REMOVES: FirewallRaz (Private) : {7048D2AD-9A54-4CA3-90BE-7C7F52D7B58E} REMOVES: FirewallRaz (Private) : {1285A320-0EBD-41B2-A150-5AD995B478DE} REMOVES: FirewallRaz (Private) : {3D6B3E2A-BB55-402A-9902-82337DA76F38} REMOVES: FirewallRaz (Private) : {5419D98F-9B2E-4A3A-B55D-5717CFC3113E} REMOVES: FirewallRaz (Private) : {970E9F2F-7F2E-4A20-80FE-126B5725CFA9} REMOVES: FirewallRaz (Private) : {99356D53-10C2-416F-8803-40D700BE58F6} REMOVES: FirewallRaz (Private) : {109DA31A-D6F5-4DCB-B50D-8F4613E0E825} REMOVES: FirewallRaz (Private) : {AF2D50C1-8DF8-4E6A-BEFC-A0A8079DE978} REMOVES: FirewallRaz (Public) : {382B48B6-969B-469F-8E57-4B42A4509E08} REMOVES: FirewallRaz (Public) : {D9DB28ED-653D-42A7-9520-1CC2C39E8929} REMOVES: FirewallRaz (None) : {68AABAA2-2A47-4B54-94F2-DB8141F9D58B} REMOVES: URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} REMOVES RunValue: BTNetwork REMOVES RunValue: DivXMediaServer ========== Elements of the registry data ========== REMOVES TCPIP: DhcpNameServer = 192.168.1.1 192.168.1.1 ========== Folders ========== Deletes temporary Windows (658) REMOVES Flash Cookies (0) REMOVES: c:\users\muhannad\appdata\local\comodo\dragon\user data\default\extensions\cmaiofennmphjldldcpphcechfnnohja ========== Files ========== Deletes temporary Windows (3241) (809,036,005 octets) REMOVES Flash Cookies (0) (0 octets) REMOVES Reboot: c:\windows\system32\tasks\dolbyselectortask ========== Scheduled task ========== REMOVES: DivXUpdate REMOVES: Wakoshqiqa Helper REMOVES: Wakoshqiqa Helper REMOVES: Wakoshqiqa Helper REMOVES: Wakoshqiqa Helper REMOVES: Wakoshqiqa Helper REMOVES: Wakoshqiqa Helper ========== Other ========== NON-TREATY R1 - HKUS\S-1-5-21-207879651-921022964-1861920971-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar NON-TREATY C2 - CDE: Preference [User Data\Default] [cmaiofennmphjldldcpphcechfnnohja] [http://privdog.com/updates/1194/chromium/update.xm] PrivDog ========== Summary ========== 2 : Registry keys 80 : Registry values 1 : Elements of the registry data 3 : Folders 3 : Files 7 : Scheduled task 2 : Other End of clean in :2mn Õs ========== Path to file report ========== C:\Users\MUHANNAD\AppData\Roaming\ZHP\ZHPFix[R1].txt - 30/10/2016 08:52:13 Õ [9154]