cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ ZHPCleaner v2014.12.17.263 by Nicolas Coolman (17/12/2014)
~ Run by marc (Administrator) (18/12/2014 08:16:46)
~ Forum : http://forum.nicolascoolman.fr
~ Facebook : https://www.facebook.com/nicolascoolman1
~ State version : Version OK
~ Type : R�parer
~ Report : C:\Users\marc\Desktop\ZHPCleaner.txt
~ Quarantine : C:\Users\marc\AppData\Roaming\ZHP\ZHPCleaner_Quarantine.txt
~ UAC : Activate
~ Windows 81, 64-bit (Build 9600)


---\\ Service. (1)
SERVICE ARRET� : MgAssistService (PUP.Mobogenie)


---\\ Navigateur internet. (6)
REMPLAC� Proxy: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyHttp1.1 ( 1 )
REMPLAC� IE Params: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Search_URL ( hxxp://www.sweet-page.com/web/?type=ds&ts=1394716353&from=cor&uid=HGSTXHTS541010A9E680_J81000760DASE[...] )
REMPLAC� IE Params: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Page ( hxxp://www.sweet-page.com/web/?type=ds&ts=1394716353&from=cor&uid=HGSTXHTS541010A9E680_J81000760DASE[...] )
REMPLAC� IE Params: HKLM64\SOFTWARE\Microsoft\Internet Explorer\MAIN\\Default_Search_URL ( hxxp://www.sweet-page.com/web/?type=ds&ts=1394716353&from=cor&uid=HGSTXHTS541010A9E680_J81000760DASE[...] )
REMPLAC� IE Params: HKLM64\SOFTWARE\Microsoft\Internet Explorer\MAIN\\Search Page ( hxxp://www.sweet-page.com/web/?type=ds&ts=1394716353&from=cor&uid=HGSTXHTS541010A9E680_J81000760DASE[...] )
REMPLAC� Chrome URL: "hxxp://Vosteran.com/?f=7&a=vst_ggfc_14_51_ch&cd=2XzuyEtN2Y1L1QzuyByE0DtDtB0B0B0A0AtD0BtBzz0B0CtCtN0[...]


---\\ Fichier h�te. (0)
~ Aucun �l�ment malicieux trouv�.


---\\ T�che planifi�e. (2)
SUPPRIM� t�che: [Digital Sites] [Orphean] (Hijacker.DSite)
SUPPRIM� t�che: [WSE_Vosteran] (PUP.Vosteran)


---\\ Explorateur ( Dossiers, Fichiers ). (2)
DEPLAC� fichier: C:\Program Files (x86)\Mobogenie\MgAssist.exe (PUP.Mobogenie)
DEPLAC� fichier: C:\Program Files (x86)\Mobogenie\DaemonProcess.exe (PUP.Mobogenie)


---\\ Base de Registres ( Cl�s, Valeurs, Donn�es ). (46)
SUPPRIM� cl�: [X64] HKLM\SYSTEM\CurrentControlSet\Services\MgAssistService [C:\Program Files (x86)\Mobogenie\MgAssist.exe] (PUP.Mobogenie)
SUPPRIM�: HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9cf7f2d8-05d0-477d-bd80-49233e2ad7d9} [HypeNet] (PUP.HypeNet)
SUPPRIM�: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [http://Vosteran.com/results.php?f=4&q={searchTerms}&a=vst_ggfc_14_51_ch&cd=2XzuyEtN2Y1L1QzuyByE0DtDtB0B0B0A0AtD0BtBzz0B0CtCtN0D0Tzu0StCtDzztCtN1L2XzutAtFyCtFtCtDtFyBtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyCyEtD0C0A0D0EzytGzztBzztDtGtByB0EyEtGyBtAtDzztGyDyDtC0B0C0D0C0F0EyEyD0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StA0A0CyEyEyDzzzztGyCyB0E0FtGyE0DtB0AtGzyyCyEtCtGtDyE0AtAtB0EyC0AtD0EtCzz2Q&cr=1993567804&ir=] [Vosteran] (PUP.Vosteran)
SUPPRIM�: [X64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [http://Vosteran.com/results.php?f=4&q={searchTerms}&a=vst_ggfc_14_51_ch&cd=2XzuyEtN2Y1L1QzuyByE0DtDtB0B0B0A0AtD0BtBzz0B0CtCtN0D0Tzu0StCtDzztCtN1L2XzutAtFyCtFtCtDtFyBtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyCyEtD0C0A0D0EzytGzztBzztDtGtByB0EyEtGyBtAtDzztGyDyDtC0B0C0D0C0F0EyEyD0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StA0A0CyEyEyDzzzztGyCyB0E0FtGyE0DtB0AtGzyyCyEtCtGtDyE0AtAtB0EyC0AtD0EtCzz2Q&cr=1993567804&ir=] [Vosteran] (PUP.Vosteran)
SUPPRIM�: [X64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} [http://www.sweet-page.com/web/?type=ds&ts=1394716353&from=cor&uid=HGSTXHTS541010A9E680_J81000760DASEA0DASEAX&q={searchTerms}] [sweet-page] (PUP.SweetPage)
SUPPRIM�: [X64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{460C3D19-B3D4-4964-A550-77D263B0CCCB} [http://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=dsites0101&cd=2XzuyEtN2Y1L1QzuyByE0DtDtB0B0B0A0AtD0BtBzz0B0CtCtN0D0Tzu0SyByDtAtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R&cr=1210765641&ir=] [Mysearchdial] (Adware.MyWebSearch)
SUPPRIM�: HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} [http://www.sweet-page.com/web/?type=ds&ts=1394716353&from=cor&uid=HGSTXHTS541010A9E680_J81000760DASEA0DASEAX&q={searchTerms}] [sweet-page] (PUP.SweetPage)
SUPPRIM� RUN: HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\\mobilegeni daemon [C:\Program Files (x86)\Mobogenie\DaemonProcess.exe] (PUP.Mobogenie)
SUPPRIM� cl�: [X64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{100EB1FD-D03E-47FD-81F3-EE91287F9465} [ShopperReports.dll] (Adware.ShopperReports)
SUPPRIM� cl�: [X64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{258C9770-1713-4021-8D7E-1F184A2BD754} [ShoppingReport.dll] (Adware.ShoppingReport)
SUPPRIM� cl�: [X64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{2EECD738-5844-4A99-B4B6-146BF802613B} [BabylonToolbar.dll] (PUP.Babylon)
SUPPRIM� cl�: [X64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E} [BabylonToolbar.dll] (PUP.Babylon)
SUPPRIM� cl�: [X64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{98889811-442D-49DD-99D7-DC866BE87DBC} [BabylonToolbarTlbr.dll] (PUP.Babylon)
SUPPRIM� cl�: [X64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{BDEA95CF-F0E6-41E0-BD3D-B00F39A4E939} [ShoppingReport.dll] (Adware.ShoppingReport)
SUPPRIM� cl�: HKCU\SOFTWARE\HypeNet [] (PUP.HypeNet)
SUPPRIM� cl�: [X64] HKLM\SOFTWARE\Microsoft\Windows\Currentversion\Uninstall\HypeNet [] (PUP.HypeNet)
SUPPRIM� cl�: HKLM\SOFTWARE\Wow6432Node\HypeNet [] (PUP.HypeNet)
SUPPRIM� cl�: HKCR\Prod.cap [] (PUP.ClaroSearch)
SUPPRIM� cl�: HKCR\protector_dll.protectorbho [Google Toolbar Notifier BHO] (PUP.BProtector)
SUPPRIM� cl�: HKCR\protector_dll.protectorbho.1 [Google Toolbar Notifier BHO] (PUP.BProtector)
SUPPRIM� cl�: HKCR\Interface\{237FDFDB-3722-470E-8BA8-90196DABE967} [ISetup] (PUP.GetNow)
SUPPRIM� cl�: HKCR\AppID\esrv.EXE [] (PUP.Funmoods)
SUPPRIM� cl�: HKCR\Iminent [] (Adware.IMBooster)
SUPPRIM� cl�: HKCU\Software\BabSolution [] (Hijacker.BabSolution)
SUPPRIM� cl�: HKCU\Software\Doko-Toolbar [] (Hijacker.Doko)
SUPPRIM� cl�: HKCU\Software\DSiteProducts [] (Hijacker.DSite)
SUPPRIM� cl�: HKCU\Software\InstallCore [] (Adware.InstallCore)
SUPPRIM� cl�: HKCU\Software\Optimizer Pro [] (PUP.OptimizerPro)
SUPPRIM� cl�: HKCU\Software\Softonic [] (PUP.Softonic)
SUPPRIM� cl�: HKCU\Software\systweak [] (PUP.Systweak)
SUPPRIM� cl�: HKCU\Software\UpToDown [] (PUP.UpToDown)
SUPPRIM� cl�: HKCU\Software\Wajam [] (PUP.Wajam)
SUPPRIM� cl�: HKCU\Software\wse_vosteran [] (PUP.Vosteran)
SUPPRIM� cl�: HKCU\Software\AppDataLow\Software\Crossrider [] (PUP.CrossRider)
SUPPRIM� cl�: HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Zip Extractor Packages [Zip Extractor Packages] (Adware.InstallCore)
SUPPRIM� cl�: [X64] HKLM\SOFTWARE\Iminent [] (Adware.IMBooster)
SUPPRIM� cl�: HKLM\SOFTWARE\Wow6432Node\Doko-Toolbar [] (Hijacker.Doko)
SUPPRIM� cl�: HKLM\SOFTWARE\Wow6432Node\Iminent [] (Adware.IMBooster)
SUPPRIM� cl�: HKLM\SOFTWARE\Wow6432Node\InstallCore [] (Adware.InstallCore)
SUPPRIM� cl�: HKLM\SOFTWARE\Wow6432Node\Mobogenie3 [] (PUP.Mobogenie)
SUPPRIM� cl�: HKLM\SOFTWARE\Wow6432Node\supWPM [] (PUP.WpManager)
SUPPRIM� cl�: HKLM\SOFTWARE\Wow6432Node\sweet-pageSoftware [] (PUP.SweetPage)
SUPPRIM� cl�: HKLM\SOFTWARE\Wow6432Node\Systweak [] (PUP.Systweak)
SUPPRIM� cl�: HKLM\SOFTWARE\Wow6432Node\Trymedia Systems [] (Adware.Trymedia)
SUPPRIM� cl�: HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Mobogenie [Mobogenie.com] (PUP.Mobogenie)
SUPPRIM� cl�: HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\WSE_Vosteran [WSE_Vosteran] (PUP.Vosteran)



---\\ Bilan de la r�paration
~ R�paration r�alis�e avec succ�s.
~ Ce navigateur est absent (Mozilla Firefox)
~ Ce navigateur est absent (Opera Software)


---\\ Statistiques
~ Items scann�s : 75694
~ Items trouv�s : 34
~ Items r�par�s : 56


End of clean at 08:30:38

Publicité


Signaler le contenu de ce document

Publicité