Rapport de ZHPFix 2013.5.24.2 par Nicolas Coolman, Update du 24/05/2013 Fichier d'export Registre : Run by modesta at 25/05/2013 15:02:45 High Elevated Privileges : OK Windows 7 Home Premium Edition, 64-bit Service Pack 1 (Build 7601) Corbeille vidée ========== Logiciel(s) ========== ABSENT Software Key: GKL2 ABSENT Software Key: {BCD55450-77AC-4347-B24F-654B1189F8D4} ABSENT Uninstall Process: c:\program files (x86)\vshare.tv plugin\uninst.exe ========== Processus mémoire ========== SUPPRIME Memory Process: C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\FreeDrumKits.net - Over 1500 Loops and Samples Kit\Noise Kit 5\Crackle 1.wav SUPPRIME Memory Process: C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\FreeDrumKits.net - Over 1500 Loops and Samples Kit\Noise Kit 5\Crackle 2.wav SUPPRIME Memory Process: C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\KeyGen RECYCLE\air.nfo SUPPRIME Memory Process: C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\KeyGen RECYCLE\file_id.diz SUPPRIME Memory Process: C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\KeyGen RECYCLE\Keygen.exe SUPPRIME Memory Process: C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\KeyGen RECYCLE\lien recycle hotfile.url SUPPRIME Memory Process: C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\KeyGen RECYCLE\Setup.exe SUPPRIME Memory Process: C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\REASON 5.0\REASON_5_KEYGEN.EXE SUPPRIME Memory Process: C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\recycle2.1.2\Keygen.exe SUPPRIME Memory Process: C:\Users\modesta\Desktop\Propellerheads.Reason.v5.0.HYBRID.DVDR-AiRISO\air-reason5kgn\REASON_5_KEYGEN.EXE SUPPRIME Memory Process: C:\Users\modesta\AppData\Local\Temp\SHSetup.exe ========== Clé(s) du Registre ========== SUPPRIME [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\vShare.tv plugin] SUPPRIME Key: HKCU\Software\vShare.tv SUPPRIME Key: HKLM\Software\Wow6432Node\FE42DAC9 SUPPRIME CLSID MPSK: {0a62c182-b49b-11e1-bf69-c80aa92458ab} SUPPRIME CLSID MPSK: {18d4ce97-8840-11df-ab00-c80aa92458ab} SUPPRIME CLSID MPSK: {22a9dfaa-7101-11e2-9aa7-c80aa92458ab} SUPPRIME CLSID MPSK: {22a9dfb1-7101-11e2-9aa7-c80aa92458ab} SUPPRIME CLSID MPSK: {3f79c2a8-a39e-11df-8561-c80aa92458ab} SUPPRIME CLSID MPSK: {5131fc1b-546b-11e2-90a6-c80aa92458ab} SUPPRIME CLSID MPSK: {5131fc22-546b-11e2-90a6-c80aa92458ab} SUPPRIME CLSID MPSK: {557efeed-b66a-11e1-96c7-c80aa92458ab} SUPPRIME CLSID MPSK: {557efeff-b66a-11e1-96c7-c80aa92458ab} SUPPRIME CLSID MPSK: {5c099320-7258-11df-b08d-c80aa92458ab} SUPPRIME CLSID MPSK: {ab18219d-eab1-11df-93bb-c80aa92458ab} SUPPRIME CLSID MPSK: {ab1821cc-eab1-11df-93bb-c80aa92458ab} SUPPRIME CLSID MPSK: {f2e3cc01-9609-11e0-b73e-c80aa92458ab} SUPPRIME CLSID MPSK: {f3131c0a-6d67-11e1-b911-c80aa92458ab} ERREUR Key: Service Legacy: LEGACY_X6VA005 ERREUR Key: Service Legacy: LEGACY_X6VA006 ERREUR Key: Service Legacy: LEGACY_X6VA007 SUPPRIME Key: HKLM\Software\Wow6432Node\Google\Chrome\Extensions\kpionmjnkbpcdpcflammlgllecmejgjj SUPPRIME Key: HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5} SUPPRIME Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} SUPPRIME Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} SUPPRIME Key: HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} SUPPRIME Key: HKLM\Software\Wow6432Node\Google\Chrome\Extensions\paoponfhfdfnjgddpnpjkambkcgdaaib SUPPRIME Key*: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375 SUPPRIME Key*: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5 SUPPRIME Key*: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\00E944CB89111313EAF35A0553F547F9 SUPPRIME Key*: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\53F55AF3F4049ED3FA6EA6F88E414E24 SUPPRIME Key*: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\68E4BF4B11615E03C97732FD581AB607 SUPPRIME Key*: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8CE3DDAB2D152683FBCEB4866BCD2B0F SUPPRIME Key*: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AF6CE16AFEA5C9A39B766468A8B35C21 SUPPRIME Key*: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FB1E44269B58F433A8C8E671E37CFDCF SUPPRIME Key: Service: X6va005 SUPPRIME Key: Service: X6va006 SUPPRIME Key: Service: X6va007 ========== Valeur(s) du Registre ========== SUPPRIME URLSearchHook: {05eeb91a-aef7-4f8a-978f-fb83e7b03f8e} SUPPRIME RunValue: Performance Center SUPPRIME RunValue: Spyware Striker Pro SUPPRIME RunValue: WLAN Optimizer SUPPRIME RunValue: Akamai NetSession Interface SUPPRIME RunValue: Mobile Partner SUPPRIME {0226B77E-02C4-462F-B9BE-88F9B26DFCA7} SUPPRIME {F4BE2A9C-91EF-452C-A61F-2521FA435541} ABSENT TCP Query User{76C319FE-1CEA-4314-B24A-4F5D1399A055}C:/program files (x86)/limewire/limewire.exe ABSENT UDP Query User{45428802-E481-4C75-A775-09BA377198AB}C:/program files (x86)/limewire/limewire.exe ABSENT TCP Query User{7B482AA8-B297-4C4F-B187-0604ECA0E033}C:/program files (x86)/pokertracker 3/camfrog video chat/camfrog video chat.exe ABSENT UDP Query User{719CB486-32B5-42AD-9406-655BCDB3BBB2}C:/program files (x86)/pokertracker 3/camfrog video chat/camfrog video chat.exe ABSENT TCP Query User{68CD20F0-A418-4091-8D3B-942082827D33}C:/users/modesta/appdata/local/akamai/netsession_win.exe ABSENT UDP Query User{241E7CA5-23E6-413D-A264-8ABE3AF5D38B}C:/users/modesta/appdata/local/akamai/netsession_win.exe ABSENT TCP Query User{C41DD321-49FE-444F-8B80-2AF28468B511}C:/aeriagames/wolfteam-fr/wolfteam.bin ABSENT UDP Query User{569F16D5-F427-423B-A01C-21E0F5DE8946}C:/aeriagames/wolfteam-fr/wolfteam.bin ABSENT TCP Query User{BEF5B89E-78B2-4482-9394-064C898762AA}C:/users/modesta/appdata/local/akamai/netsession_win.exe ABSENT UDP Query User{BA92A843-B0E1-4332-A996-EA9C6FB455E0}C:/users/modesta/appdata/local/akamai/netsession_win.exe SUPPRIME {C9AAED7F-8283-4248-94D3-98B888D6C83F} SUPPRIME {A87A0A41-13BD-4C78-A054-650F532B56A7} ABSENT TCP Query User{9E32F00F-4B2E-483F-BE86-D0ED90911155}C:/program files (x86)/soulseekqt/soulseekqt.exe ABSENT UDP Query User{4AA9D3FA-6190-4F9E-984F-F63374B9FA8F}C:/program files (x86)/soulseekqt/soulseekqt.exe ABSENT TCP Query User{5FF97416-28F4-4C85-A46E-368F8FDF25B8}C:/program files/xfire2/xfire.exe ABSENT UDP Query User{86A9269F-AA4E-4EAB-9C10-8D63851E0217}C:/program files/xfire2/xfire.exe SUPPRIME {99938C8C-758A-4BA0-B920-21CFE3081C3C} SUPPRIME {2F42313D-3F66-4DB5-B4C6-63A945484031} SUPPRIME {1DDC509B-AE2B-4F1B-BD3D-898F79BCEE7B} SUPPRIME {78FC0A18-B7B5-44DC-9C60-253B79708360} ========== Elément(s) de donnée du Registre ========== SUPPRIME Explorer Association Data Application: http://www.filefacts.net/redirect.php?ext=%s SUPPRIME R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page ========== Dossier(s) ========== SUPPRIME Reboot Folder**: g:\setup.exe SUPPRIME Reboot Folder**: g:\directx\dxsetup.exe SUPPRIME Folder: C:\Users\modesta\AppData\Roaming\WinDir SUPPRIME Folder: C:\Users\modesta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter SUPPRIME Temporaires Windows SUPPRIME Flash Cookies ========== Fichier(s) ========== ABSENT File: c:\program files (x86)\ascentive\performance center\apcmain.exe ABSENT File: c:\users\modesta\desktop\wlan optimizer.exe ABSENT File: c:\users\modesta\appdata\local\akamai\netsession_win.exe ABSENT File: c:\users\modesta\desktop\asio4all v2 instruction manual.lnk ABSENT File: c:\users\modesta\desktop\cool audio video converter.lnk ABSENT File: c:\users\modesta\desktop\installation de pmu poker.lnk ABSENT File: c:\users\modesta\desktop\installeur de world of warcraft.lnk ABSENT File: c:\users\modesta\desktop\limewire 5.5.10.lnk ABSENT File: c:\users\modesta\desktop\pmu poker.lnk ABSENT File: c:\programs\pmu\pmu.exe SUPPRIME File: c:\users\modesta\appdata\roaming\microsoft\internet explorer\quick launch\chat-land site de chat et de rencontre gratuit.url ABSENT File: c:\users\modesta\appdata\roaming\microsoft\internet explorer\quick launch\chat-land site de chat SUPPRIME File: c:\users\modesta\appdata\roaming\microsoft\internet explorer\quick launch\jouer à hp games.lnk SUPPRIME File: c:\users\modesta\desktop\spyhunter.lnk SUPPRIME File: c:\windows\tasks\smartpcfix task.job ABSENT Folder/File: c:\program files (x86)\smartpcfix\smartpcfix.exe ABSENT Folder/File: c:\users\modesta\downloads\rkfree_setup.exe ABSENT Folder/File: c:\users\modesta\downloads\rk_uninstall.exe SUPPRIME File: c:\windows\prefetch\spyhunter-installer.exe-d087a74e.pf SUPPRIME File: c:\windows\prefetch\wisecustomcalla32.exe-d6a47d72.pf SUPPRIME File: c:\windows\prefetch\wisecustomcalla31.exe-c34ec2ed.pf SUPPRIME File: c:\windows\prefetch\wisecustomcalla33.exe-e9fa37f7.pf SUPPRIME File: c:\windows\prefetch\wisecustomcalla34.exe-fd4ff27c.pf SUPPRIME File: c:\windows\prefetch\wisecustomcalla37.exe-3751220b.pf SUPPRIME File: c:\windows\prefetch\spyhunter4.exe-7bd5e907.pf ABSENT File: k:\setup.exe ABSENT File: g:\launcher.exe ABSENT File: k:\autorun.exe ABSENT File: h:\autorun.exe ABSENT File: h:\launcher.exe ABSENT File: i:\setup.exe ABSENT File: j:\kodak_software_downloader.exe ABSENT File: j:\setup.exe SUPPRIME File: c:\users\modesta\downloads\spyhunter-installer.exe SUPPRIME File: c:\users\modesta\desktop\hiphopisdream\00000.nico.com c le taf tupepatest\freedrumkits.net - over 1500 loops and samples kit\noise kit 5\crackle 1.wav SUPPRIME File: c:\users\modesta\desktop\hiphopisdream\00000.nico.com c le taf tupepatest\freedrumkits.net - over 1500 loops and samples kit\noise kit 5\crackle 2.wav SUPPRIME File***: c:\users\modesta\desktop\hiphopisdream\00000.nico.com c le taf tupepatest\utilitaire\keygen recycle\air.nfo SUPPRIME File***: c:\users\modesta\desktop\hiphopisdream\00000.nico.com c le taf tupepatest\utilitaire\keygen recycle\file_id.diz SUPPRIME File***: c:\users\modesta\desktop\hiphopisdream\00000.nico.com c le taf tupepatest\utilitaire\keygen recycle\keygen.exe SUPPRIME File: c:\users\modesta\desktop\hiphopisdream\00000.nico.com c le taf tupepatest\utilitaire\keygen recycle\lien recycle hotfile.url SUPPRIME File: c:\users\modesta\desktop\hiphopisdream\00000.nico.com c le taf tupepatest\utilitaire\keygen recycle\setup.exe SUPPRIME File***: c:\users\modesta\desktop\hiphopisdream\00000.nico.com c le taf tupepatest\utilitaire\reason 5.0\reason_5_keygen.exe SUPPRIME File***: c:\users\modesta\desktop\hiphopisdream\00000.nico.com c le taf tupepatest\utilitaire\recycle2.1.2\keygen.exe ABSENT Folder/File: c:\users\modesta\desktop\hiphopisdream\00000.nico.com c le taf tupepatest\utilitaire\steinberg wavelab 6.1.1.353 (cracked by team air) erg wavelab 6.1.1.353 (cracked by team air)\img1_wavelab.jpg ABSENT Folder/File: c:\users\modesta\desktop\hiphopisdream\00000.nico.com c le taf tupepatest\utilitaire\steinberg wavelab 6.1.1.353 (cracked by team air) erg wavelab 6.1.1.353 (cracked by team air)\wavelab 6.1.1_setup\extra\wavpack plugin\readm ABSENT Folder/File: c:\users\modesta\desktop\hiphopisdream\00000.nico.com c le taf tupepatest\utilitaire\steinberg wavelab 6.1.1.353 (cracked by team air) erg wavelab 6.1.1.353 (cracked by team air)\wavelab 6.1.1_setup\extra\wavpack plugin\wavpa ABSENT Folder/File: c:\users\modesta\desktop\hiphopisdream\00000.nico.com c le taf tupepatest\utilitaire\steinberg wavelab 6.1.1.353 (cracked by team air) erg wavelab 6.1.1.353 (cracked by team air)\wavelab 6.1.1_setup\install\data\help\deutsch\ ABSENT Folder/File: c:\users\modesta\desktop\hiphopisdream\00000.nico.com c le taf tupepatest\utilitaire\steinberg wavelab 6.1.1.353 (cracked by team air) erg wavelab 6.1.1.353 (cracked by team air)\wavelab 6.1.1_setup\install\data\help\english\ ABSENT Folder/File: c:\users\modesta\desktop\hiphopisdream\00000.nico.com c le taf tupepatest\utilitaire\steinberg wavelab 6.1.1.353 (cracked by team air) erg wavelab 6.1.1.353 (cracked by team air)\wavelab 6.1.1_setup\install\data\help\french\w ABSENT Folder/File: c:\users\modesta\desktop\hiphopisdream\00000.nico.com c le taf tupepatest\utilitaire\steinberg wavelab 6.1.1.353 (cracked by team air) erg wavelab 6.1.1.353 (cracked by team air)\wavelab 6.1.1_setup\install\data\help\helpmap. ABSENT Folder/File: c:\users\modesta\desktop\hiphopisdream\00000.nico.com c le taf tupepatest\utilitaire\steinberg wavelab 6.1.1.353 (cracked by team air) erg wavelab 6.1.1.353 (cracked by team air)\wavelab 6.1.1_setup\install\data\help\japanese ABSENT Folder/File: c:\users\modesta\desktop\hiphopisdream\00000.nico.com c le taf tupepatest\utilitaire\steinberg wavelab 6.1.1.353 (cracked by team air) erg wavelab 6.1.1.353 (cracked by team air)\wavelab 6.1.1_setup\install\readme.htm ABSENT Folder/File: c:\users\modesta\desktop\hiphopisdream\00000.nico.com c le taf tupepatest\utilitaire\steinberg wavelab 6.1.1.353 (cracked by team air) erg wavelab 6.1.1.353 (cracked by team air)\wavelab 6.1.1_setup\install\setup.exe ABSENT Folder/File: c:\users\modesta\desktop\hiphopisdream\00000.nico.com c le taf tupepatest\utilitaire\steinberg wavelab 6.1.1.353 (cracked by team air) erg wavelab 6.1.1.353 (cracked by team air)\wavelab 6.1.1_setup\install\wl6emu.exe ABSENT Folder/File: c:\users\modesta\desktop\hiphopisdream\00000.nico.com c le taf tupepatest\utilitaire\steinberg wavelab 6.1.1.353 (cracked by team air) erg wavelab 6.1.1.353 (cracked by team air)\wavelab 6.1.1_setup\install notes!.txt SUPPRIME File*: c:\users\modesta\desktop\propellerheads.reason.v5.0.hybrid.dvdr-airiso\air-reason5kgn\reason_5_keygen.exe SUPPRIME File: C:\Users\modesta\AppData\Local\Temp\sh4plist.dat SUPPRIME File*: c:\users\modesta\appdata\local\temp\shsetup.exe ABSENT Folder/File: c:\users\modesta\desktop\spyhunter.lnk ABSENT File: c:\users\modesta\appdata\local\temp\00513bd.tmp ABSENT File: c:\users\modesta\appdata\local\temp\006b932.tmp ABSENT File: c:\users\modesta\appdata\local\temp\0072523.tmp SUPPRIME Temporaires Windows SUPPRIME Flash Cookies ========== Tache planifiée ========== SUPPRIME Task: SmartPCFix Task SUPPRIME Task: {00B6A442-52CD-4A5A-9332-55523E2F4088} SUPPRIME Task: {0ED07BB4-7D3F-477D-9A3C-C1B13FCDCA84} SUPPRIME Task: {5CB4C33B-D517-4CB0-A65A-83A47A6E0F65} SUPPRIME Task: {CA7F1355-2B46-409D-BAC0-1231A4DDD877} SUPPRIME Task: {CBD660F3-E00D-47C2-801F-0B931D991A7E} SUPPRIME Task: {DC981EEA-92B1-4BE8-A9FC-188EF765D676} ========== Récapitulatif ========== 11 : Processus mémoire 37 : Clé(s) du Registre 28 : Valeur(s) du Registre 2 : Elément(s) de donnée du Registre 6 : Dossier(s) 64 : Fichier(s) 3 : Logiciel(s) 7 : Tache planifiée End of clean in 00mn 24s ========== Chemin de fichier rapport ========== C:\ZHP\ZHPFix[R1].txt - 25/05/2013 08:41:23 [1918] C:\ZHP\ZHPFix[R2].txt - 25/05/2013 08:48:45 [1920] C:\ZHP\ZHPFix[R3].txt - 25/05/2013 15:02:45 [15636]