cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ ZHPCleaner v2015.5.18.244 by Nicolas Coolman (2015\05\18)
~ Run by jimmy (Administrator) (18/05/2015 17:50:17)
~ Forum : http://forum.nicolascoolman.fr
~ Facebook : https://www.facebook.com/nicolascoolman1
~ State version : Version OK
~ Type : Netttoyer
~ Report : C:\Users\jimmy\Desktop\ZHPCleaner.txt
~ Quarantine : C:\Users\jimmy\AppData\Roaming\ZHP\ZHPCleaner_Quarantine.txt
~ UAC : Activate
~ Boot Mode : Normal (Normal boot)
~ Windows 81, 64-bit (Build 9600)


---\\ Service. (4)
SUPPRIM� : {713f4525-9b38-40c8-81c7-6dd3bd0d9646}w64 (PUP.LinkiDoo)
SUPPRIM� : {9a9157bb-003e-4fef-8bd1-c09bc4586a28}w64 (PUP.LinkiDoo)
SUPPRIM� : {9edd0ea8-2819-47c2-8320-b007d5996f8a}w64 (PUP.LinkiDoo)
SUPPRIM� : esgiguard (Crapware.SpyHunter)


---\\ Navigateur internet. (20)
SUPPRIM�: [fvrjgm3x.default] - user_pref("extensions.DigiHelp.is", "isgiwhFR"); (PUP.DigiHelp)
SUPPRIM�: [fvrjgm3x.default] - user_pref("extensions.DigiHelp.ug", "F4AA3937-383D-4B93-A0BA-4E5F925B32AC"); (PUP.DigiHelp)
SUPPRIM�: [fvrjgm3x.default] - user_pref("extensions.xpiState", "{\"app-profile\":{\"cacaoweb@cacaoweb.org\":{\"d\":\"C:\\\\Users\\[...] (PUP.CacaoWeb)
DEPLAC� fichier: C:\Users\jimmy\AppData\Roaming\Mozilla\Firefox\Profiles\fvrjgm3x.default\Extensions\cacaoweb@cacaoweb.org\chrome (PUP.CacaoWeb) []
DEPLAC� fichier: C:\Users\jimmy\AppData\Roaming\Mozilla\Firefox\Profiles\fvrjgm3x.default\Extensions\cacaoweb@cacaoweb.org\chrome.manifest (PUP.CacaoWeb) [3AB2922972335BD726B64157924800A1]
DEPLAC� fichier: C:\Users\jimmy\AppData\Roaming\Mozilla\Firefox\Profiles\fvrjgm3x.default\Extensions\cacaoweb@cacaoweb.org\defaults (PUP.CacaoWeb) []
DEPLAC� fichier: C:\Users\jimmy\AppData\Roaming\Mozilla\Firefox\Profiles\fvrjgm3x.default\Extensions\cacaoweb@cacaoweb.org\install.rdf (PUP.CacaoWeb) [F3C86BC9A40A2FD6CB09D7F67BD1808E]
REMPLAC� IE Params: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Page_URL [hxxp://istart.webssearches.com/?type=hp&ts=1395790288&from=tugs&uid=WDCXWD10JPVX[...]] (Hijacker.WebsSearches)
REMPLAC� IE Params: HKLM64\SOFTWARE\Microsoft\Internet Explorer\MAIN\\Default_Page_URL [hxxp://istart.webssearches.com/?type=hp&ts=1395790288&from=tugs&uid=WDCXWD10JPVX[...]] (Hijacker.WebsSearches)
REMPLAC� IE Params: HKLM64\SOFTWARE\Microsoft\Internet Explorer\MAIN\\Default_Search_URL [hxxp://istart.webssearches.com/web/?type=ds&ts=1395790288&from=tugs&uid=WDCXWD10[...]] (Hijacker.WebsSearches)
REMPLAC� IE Params: HKLM64\SOFTWARE\Microsoft\Internet Explorer\MAIN\\Start Page [hxxp://istart.webssearches.com/?type=hp&ts=1395790288&from=tugs&uid=WDCXWD10JPVX[...]] (Hijacker.WebsSearches)
REMPLAC� IE Params: HKLM64\SOFTWARE\Microsoft\Internet Explorer\MAIN\\Search Page [hxxp://istart.webssearches.com/web/?type=ds&ts=1395790288&from=tugs&uid=WDCXWD10[...]] (Hijacker.WebsSearches)
REMPLAC� IE Params: HKLM64\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\\Default_Page_URL [hxxp://istart.webssearches.com/?type=hp&ts=1395790288&from=tugs&uid=WDCXWD10JPVX[...]] (Hijacker.WebsSearches)
REMPLAC� IE Params: HKLM64\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\\Default_Search_URL [hxxp://istart.webssearches.com/web/?type=ds&ts=1395790288&from=tugs&uid=WDCXWD10[...]] (Hijacker.WebsSearches)
REMPLAC� IE Params: HKLM64\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\\Start Page [hxxp://istart.webssearches.com/?type=hp&ts=1395790288&from=tugs&uid=WDCXWD10JPVX[...]] (Hijacker.WebsSearches)
REMPLAC� IE Params: HKLM64\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\\Search Page [hxxp://istart.webssearches.com/web/?type=ds&ts=1395790288&from=tugs&uid=WDCXWD10[...]] (Hijacker.WebsSearches)
SUPPRIM� donn�e: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride [Bad : <-loopback>] (Hijacker.Proxy)
REMPLAC� Quicklaunch: C:\Users\jimmy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk [Bad : http://istart.webssearches.com/?type=sc&ts=1395790288&from=tugs&uid=WDCXWD10JPVX-80JC3T0_WD-WX11E83CJV35CJV35] (Hijacker.Browser)
REMPLAC� TaskBar: C:\Users\jimmy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk [Bad : http://istart.webssearches.com/?type=sc&ts=1395790288&from=tugs&uid=WDCXWD10JPVX-80JC3T0_WD-WX11E83CJV35CJV35] (Hijacker.Browser)
REMPLAC� Startup\Programs: C:\Users\jimmy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk [Bad : http://istart.webssearches.com/?type=sc&ts=1395790288&from=tugs&uid=WDCXWD10JPVX-80JC3T0_WD-WX11E83CJV35CJV35] (Hijacker.Browser)


---\\ Fichier h�te. (1)
~ Le fichier h�te est l�gitime. (21)


---\\ T�che planifi�e. (5)
SUPPRIM� t�che: [APSnotifierPP1] [C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe (Not File) ] (PUP.AnyProtect)
SUPPRIM� t�che: [APSnotifierPP2] [C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe (Not File) ] (PUP.AnyProtect)
SUPPRIM� t�che: [APSnotifierPP3] [C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe (Not File) ] (PUP.AnyProtect)
SUPPRIM� t�che: [DoctorPC_Popup] [C:\Program Files (x86)\Doctor PC\Splash.exe (Not File) ] (PUP.DoctorPC)
SUPPRIM� t�che: [DoctorPC_Start] [C:\Program Files (x86)\Doctor PC\DoctorPC.exe (Not File) ] (PUP.DoctorPC)


---\\ Explorateur ( Dossiers, Fichiers ). (137)
DEPLAC� fichier*: C:\Users\jimmy\AppData\Roaming\Mozilla\Firefox\Profiles\fvrjgm3x.default\Extensions\cacaoweb@cacaoweb.org\chrome (PUP.CacaoWeb)
DEPLAC� fichier: C:\Users\jimmy\AppData\Roaming\Mozilla\Firefox\Profiles\fvrjgm3x.default\Extensions\cacaoweb@cacaoweb.org\chrome.manifest (PUP.CacaoWeb)
DEPLAC� fichier*: C:\Users\jimmy\AppData\Roaming\Mozilla\Firefox\Profiles\fvrjgm3x.default\Extensions\cacaoweb@cacaoweb.org\defaults (PUP.CacaoWeb)
DEPLAC� fichier: C:\Users\jimmy\AppData\Roaming\Mozilla\Firefox\Profiles\fvrjgm3x.default\Extensions\cacaoweb@cacaoweb.org\install.rdf (PUP.CacaoWeb)
DEPLAC� fichier: C:\WINDOWS\System32\drivers\{713f4525-9b38-40c8-81c7-6dd3bd0d9646}w64.sys [StdLib - StdLib] (PUP.LinkiDoo)
DEPLAC� fichier: C:\WINDOWS\System32\drivers\{9a9157bb-003e-4fef-8bd1-c09bc4586a28}w64.sys [StdLib - StdLib] (PUP.LinkiDoo)
DEPLAC� fichier: C:\WINDOWS\System32\drivers\{9edd0ea8-2819-47c2-8320-b007d5996f8a}w64.sys [StdLib - StdLib] (PUP.LinkiDoo)
DEPLAC� fichier: C:\WINDOWS\Tasks\APSnotifierPP1.job (PUP.AnyProtect)
DEPLAC� fichier: C:\WINDOWS\Tasks\APSnotifierPP2.job (PUP.AnyProtect)
DEPLAC� fichier: C:\WINDOWS\Tasks\APSnotifierPP3.job (PUP.AnyProtect)
DEPLAC� fichier: C:\WINDOWS\Prefetch\ANYPROTECT.EXE-53752276.pf (PUP.AnyProtect)
DEPLAC� fichier: C:\WINDOWS\Prefetch\BUBBLE DOCK.EXE-1741B4E4.pf (PUP.BubbleDock)
DEPLAC� fichier: C:\WINDOWS\Prefetch\FLVPLAYER.EXE-AB312A49.pf (PUP.FLVPlayer)
DEPLAC� fichier: C:\WINDOWS\Prefetch\PREDM.TMP-CA9F3D4D.pf (Adware.Downware)
DEPLAC� fichier: C:\WINDOWS\Prefetch\SELECTION TOOLS UNINSTALL.EXE-4C83B7B9.pf (PUP.Nosibay)
DEPLAC� fichier: C:\WINDOWS\Prefetch\SELECTION TOOLS UNINSTALL.EXE-C1D2CC74.pf (PUP.Nosibay)
DEPLAC� fichier: C:\WINDOWS\Prefetch\UNINSTALL BUBBLE DOCK.EXE-57FFAF39.pf (PUP.BubbleDock)
DEPLAC� fichier: C:\WINDOWS\Prefetch\UPFST_FR_134.EXE-8B90B552.pf (Adware.FreeSoftToday)
DEPLAC� fichier: C:\WINDOWS\System32\OptimizerMonitorOff.ini (Adware.OptimizerMonitor)
DEPLAC� fichier: C:\WINDOWS\SysWOW64\OptimizerMonitorOff.ini (Adware.OptimizerMonitor)
DEPLAC� fichier: C:\Users\jimmy\Desktop\cacaoweb.exe (PUP.CacaoWeb)
DEPLAC� fichier: C:\Users\jimmy\AppData\Roaming\Bubble Dock.boostrap.log (PUP.BubbleDock)
DEPLAC� fichier: C:\Users\jimmy\AppData\Roaming\Bubble Dock.installation.log (PUP.BubbleDock)
DEPLAC� fichier: C:\Users\jimmy\AppData\Roaming\Selection Tools.installation.log (PUP.Nosibay)
DEPLAC� fichier: C:\Users\jimmy\AppData\Roaming\WindApp.boostrap.log (PUP.Nosibay)
DEPLAC� fichier: C:\Users\jimmy\AppData\Roaming\WindApp.installation.log (PUP.Nosibay)
DEPLAC� fichier: C:\Users\jimmy\AppData\Local\Temp\fullpackage_temp1395790268\alilog.dll [Skytech Co., Ltd. - Skytech] (PUP.Skytech)
DEPLAC� fichier: C:\Users\jimmy\AppData\Local\Temp\comh.184556\goopdate.dll [globalUpdate - globalUpdate Update] (PUP.GlobalUpdate)
DEPLAC� fichier: C:\Users\jimmy\AppData\Local\Temp\comh.184556\goopdateres_en.dll [globalUpdate - globalUpdate Update Resource DLL] (PUP.GlobalUpdate)
DEPLAC� fichier: C:\Users\jimmy\AppData\Local\Temp\comh.184556\npGoogleUpdate4.dll [globalUpdate - globalUpdate Update] (PUP.GlobalUpdate)
DEPLAC� fichier: C:\Users\jimmy\AppData\Local\Temp\comh.184556\psmachine.dll [globalUpdate - globalUpdate Update] (PUP.GlobalUpdate)
DEPLAC� fichier: C:\Users\jimmy\AppData\Local\Temp\comh.184556\psuser.dll [globalUpdate - globalUpdate Update] (PUP.GlobalUpdate)
DEPLAC� fichier: C:\Users\jimmy\AppData\Local\Temp\AVBD.exe [Nosibay - Bubble Dock installer] (PUP.Nosibay)
DEPLAC� fichier: C:\Users\jimmy\AppData\Local\Temp\ReimagePackage.exe [Reimage� - Reimage Repair] (PUP.ReimageRepair)
DEPLAC� fichier: C:\Users\jimmy\AppData\Local\Temp\is-DFHRA.tmp\SpeedUpMyPC-standalone-setup.exe [Uniblue Systems Limited - SpeedUpMyPC Setup] (PUP.UniblueSystem)
DEPLAC� fichier: C:\Users\jimmy\AppData\Local\Temp\dc00d6fe-c103-4595-b94c-75c831f6365a\software\speedupmypc.exe [Uniblue Systems Limited - SpeedUpMyPC Setup] (PUP.UniblueSystem)
DEPLAC� fichier: C:\Users\jimmy\AppData\Local\Temp\dc00d6fe-c103-4595-b94c-75c831f6365a\software\tugs_webssearches.exe [Skytech Co., Ltd. - Skytech] (PUP.Skytech)
DEPLAC� fichier: C:\Users\jimmy\AppData\Local\Temp\comh.184556\GoogleCrashHandler.exe [globalUpdate - globalUpdate Update] (PUP.GlobalUpdate)
DEPLAC� fichier: C:\Users\jimmy\AppData\Local\Temp\comh.184556\GoogleUpdate.exe [globalUpdate - globalUpdate Update] (PUP.GlobalUpdate)
DEPLAC� fichier: C:\Users\jimmy\AppData\Local\Temp\comh.184556\GoogleUpdateBroker.exe [globalUpdate - globalUpdate Update] (PUP.GlobalUpdate)
DEPLAC� fichier: C:\Users\jimmy\AppData\Local\Temp\comh.184556\GoogleUpdateOnDemand.exe [globalUpdate - globalUpdate Update] (PUP.GlobalUpdate)
DEPLAC� fichier: C:\Users\jimmy\AppData\Local\Temp\822015115953\Selection Tools Uninstall.exe [Nosibay - Selection Tools installer] (PUP.Nosibay)
DEPLAC� fichier: C:\Users\jimmy\AppData\Local\Temp\822015115854\WindApp Uninstall.exe [Nosibay - WindApp installer] (PUP.Nosibay)
DEPLAC� fichier: C:\Users\jimmy\AppData\Local\Temp\822015114157\Uninstall Bubble Dock.exe [Nosibay - Bubble Dock installer] (PUP.Nosibay)
DEPLAC� fichier*: C:\Users\jimmy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_api.togglemark.net_0.localstorage (Adware.Sambreel)
DEPLAC� fichier*: C:\Users\jimmy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_api.togglemark.net_0.localstorage-journal (Adware.Sambreel)
DEPLAC� fichier*: C:\Users\jimmy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_hdapp1008-a.akamaihd.net_0.localstorage (PUP.AkamaiHD)
DEPLAC� fichier*: C:\Users\jimmy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_hdapp1008-a.akamaihd.net_0.localstorage-journal (PUP.AkamaiHD)
DEPLAC� fichier*: C:\Users\jimmy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.olark.com_0.localstorage (PUP.Optional)
DEPLAC� fichier*: C:\Users\jimmy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.olark.com_0.localstorage-journal (PUP.Optional)
DEPLAC� fichier*: C:\Users\jimmy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage (PUP.SpecialSavings)
DEPLAC� fichier*: C:\Users\jimmy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage-journal (PUP.SpecialSavings)
DEPLAC� fichier*: C:\Users\jimmy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_binbox.io_0.localstorage (PUP.InboxEmail)
DEPLAC� fichier*: C:\Users\jimmy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_binbox.io_0.localstorage-journal (PUP.InboxEmail)
DEPLAC� fichier*: C:\Users\jimmy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_fr.reimageplus.com_0.localstorage (PUP.ReimageRepair)
DEPLAC� fichier*: C:\Users\jimmy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_fr.reimageplus.com_0.localstorage-journal (PUP.ReimageRepair)
DEPLAC� fichier*: C:\Users\jimmy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_fr.similarsites.com_0.localstorage (Adware.SimilarSites)
DEPLAC� fichier*: C:\Users\jimmy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_fr.similarsites.com_0.localstorage-journal (Adware.SimilarSites)
DEPLAC� fichier*: C:\Users\jimmy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_serviceama-a.akamaihd.net_0.localstorage (PUP.AkamaiHD)
DEPLAC� fichier*: C:\Users\jimmy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_serviceama-a.akamaihd.net_0.localstorage-journal (PUP.AkamaiHD)
DEPLAC� fichier*: C:\Users\jimmy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_startertv.fr_0.localstorage (Adware.StarterTV)
DEPLAC� fichier*: C:\Users\jimmy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_startertv.fr_0.localstorage-journal (Adware.StarterTV)
DEPLAC� fichier*: C:\Users\jimmy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.select-n-go00.select-n-go.com_0.localstorage (PUP.SelectNGo)
DEPLAC� fichier*: C:\Users\jimmy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.select-n-go00.select-n-go.com_0.localstorage-journal (PUP.SelectNGo)
DEPLAC� fichier*: C:\Users\jimmy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_traducteur.babylon.com_0.localstorage (PUP.Babylon)
DEPLAC� fichier*: C:\Users\jimmy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_traducteur.babylon.com_0.localstorage-journal (PUP.Babylon)
DEPLAC� fichier*: C:\Users\jimmy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.mypcspeedmaximizer.com_0.localstorage (PUP.PCSpeedMaximizer)
DEPLAC� fichier*: C:\Users\jimmy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.mypcspeedmaximizer.com_0.localstorage-journal (PUP.PCSpeedMaximizer)
DEPLAC� fichier*: C:\Users\jimmy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.putlocker.com_0.localstorage (Spyware.PutLocker)
DEPLAC� fichier*: C:\Users\jimmy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.putlocker.com_0.localstorage-journal (Spyware.PutLocker)
DEPLAC� fichier*: C:\Users\jimmy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage (PUP.SpecialSavings)
DEPLAC� fichier*: C:\Users\jimmy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal (PUP.SpecialSavings)
DEPLAC� fichier: C:\Users\jimmy\AppData\Local\Temp\Bubble Dock.txt (PUP.BubbleDock)
DEPLAC� fichier: C:\Users\jimmy\AppData\Local\Temp\HQTotalSInstaller_1395790320.log (PUP.HQTotalS)
DEPLAC� fichier: C:\Users\jimmy\AppData\Local\Temp\HQTotalSUninstaller_1395791124.log (PUP.HQTotalS)
DEPLAC� fichier: C:\Users\jimmy\AppData\Local\Temp\LBubble Dock.txt (PUP.BubbleDock)
DEPLAC� fichier: C:\Users\jimmy\AppData\Local\Temp\nsm5F19.tmp [wincheck - wincheck] (PUP.Wincheck)
DEPLAC� fichier: C:\Users\jimmy\AppData\Local\Temp\OptimizerMonitorr.log (Adware.OptimizerMonitor)
DEPLAC� fichier: C:\Users\jimmy\AppData\Local\Temp\reimage.log (PUP.ReimageRepair)
DEPLAC� fichier: C:\Users\jimmy\AppData\Local\Temp\SecureAssistr.log (PUP.SupraSavings)
DEPLAC� fichier: C:\Users\jimmy\AppData\Local\Temp\vitruvian-installer-install-v0003 (PUP.Vitruvian)
DEPLAC� fichier: C:\Users\jimmy\AppData\Local\Temp\vitruvian-installer-processes-v0002 (PUP.Vitruvian)
DEPLAC� fichier: C:\Users\jimmy\AppData\Local\Temp\vitruvian-installer-scheduledtasks-v0001 (PUP.Vitruvian)
DEPLAC� fichier: C:\Users\jimmy\AppData\Local\Temp\vitruvian-installer-softwareregkeys-v0002 (PUP.Vitruvian)
DEPLAC� fichier: C:\Users\jimmy\AppData\Local\Temp\_@6D9D.tmp [Elex do Brasil Participa��es Ltda - uninstal] (PUP.Elex)
DEPLAC� fichier: C:\Users\jimmy\AppData\Local\Temp\_@6DAE.tmp [Elex do Brasil Participa��es Ltda - iCommu] (PUP.Elex)
DEPLAC� fichier: C:\Users\jimmy\AppData\Local\Temp\_@6DAF.tmp [Elex do Brasil Participa��es Ltda - Module Config] (PUP.Elex)
DEPLAC� fichier: C:\WINDOWS\Reimage.ini (PUP.ReimageRepair)
DEPLAC� fichier: C:\WINDOWS\System32\log\iSafeKrnlCall.log (PUP.YetAnotherCleaner)
DEPLAC� fichier: C:\Users\jimmy\AppData\Local\Temp\Uninstall.exe [Copyright 2013 - ] (PUP.Optional)
DEPLAC� fichier: C:\END (PUP.Conduit)
DEPLAC� dossier: C:\Users\jimmy\AppData\Roaming\Mozilla\Firefox\Profiles\fvrjgm3x.default\Extensions\cacaoweb@cacaoweb.org (PUP.CacaoWeb)
DEPLAC� dossier: C:\Users\jimmy\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg (PUP.DigitalMore)
DEPLAC� dossier: C:\Program Files (x86)\globalUpdate (PUP.GlobalUpdate)
DEPLAC� dossier: C:\Program Files (x86)\Iminent (Adware.IMBooster)
DEPLAC� dossier: C:\Program Files (x86)\K9-PC Protector (PUP.Systweak)
DEPLAC� dossier: C:\Program Files (x86)\K9-PCFixer (PUP.Systweak)
DEPLAC� dossier: C:\Program Files (x86)\MediaPlayerplus (Adware.CrossRider)
DEPLAC� dossier: C:\Program Files (x86)\Mega Browse (Adware.Sambreel)
DEPLAC� dossier: C:\Program Files (x86)\MyPC Backup (PUP.MyPCBackup)
DEPLAC� dossier: C:\Program Files (x86)\Nosibay (Adware.SPointer)
DEPLAC� dossier: C:\Program Files (x86)\PC Performer (PUP.PCPerformer)
DEPLAC� dossier: C:\Program Files (x86)\predm (Adware.Downware)
DEPLAC� dossier: C:\Program Files (x86)\PriceMeterLiveUpdate (PUP.PriceMeter)
DEPLAC� dossier: C:\Program Files (x86)\SupTab (Adware.SupTab)
DEPLAC� dossier: C:\Program Files\Enigma Software Group (PUP.EnigmaSoftware)
DEPLAC� dossier: C:\ProgramData\BitGuard (PUP.BitGuard)
DEPLAC� dossier: C:\ProgramData\Browser Manager (PUP.SpeedBrowser)
DEPLAC� dossier: C:\ProgramData\BrowserProtect (PUP.SpeedBrowser)
DEPLAC� dossier: C:\ProgramData\IePluginService (Trojan.SProtector)
DEPLAC� dossier: C:\ProgramData\IePluginServices (Trojan.SProtector)
DEPLAC� dossier: C:\ProgramData\K9Tools (PUP.Systweak)
DEPLAC� dossier: C:\ProgramData\WindowsMangerProtect (PUP.Fuyu)
DEPLAC� dossier: C:\ProgramData\WPM (PUP.WpManager)
DEPLAC� dossier: C:\ProgramData\PriceMeterLiveUpdate (PUP.PriceMeter)
DEPLAC� dossier: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\free_soft_to_day (Adware.Multiplug)
DEPLAC� dossier: C:\Users\jimmy\AppData\Roaming\AnyProtectEx (PUP.AnyProtect)
DEPLAC� dossier: C:\Users\jimmy\AppData\Roaming\cacaoweb (PUP.CacaoWeb)
DEPLAC� dossier: C:\Users\jimmy\AppData\Roaming\DriverTurbo (PUP.DriverTurbo)
DEPLAC� dossier: C:\Users\jimmy\AppData\Roaming\K9-PCFixer (PUP.Systweak)
DEPLAC� dossier: C:\Users\jimmy\AppData\Roaming\K9Tools (PUP.Systweak)
DEPLAC� dossier: C:\Users\jimmy\AppData\Roaming\mysearchdial (PUP.MySearchDial)
DEPLAC� dossier: C:\Users\jimmy\AppData\Roaming\Nosibay (Adware.SPointer)
DEPLAC� dossier: C:\Users\jimmy\AppData\Roaming\PerformerSoft (PUP.PerformerSoft)
DEPLAC� dossier: C:\Users\jimmy\AppData\Roaming\Store (PUP.Nosibay)
DEPLAC� dossier: C:\Users\jimmy\AppData\Roaming\webssearches (Hijacker.WebsSearches)
DEPLAC� dossier: C:\Users\jimmy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PriceMet�r (PUP.PriceMeter)
DEPLAC� dossier: C:\Users\jimmy\AppData\Local\Doctor_PC (PUP.DoctorPC)
DEPLAC� dossier: C:\Users\jimmy\AppData\Local\globalUpdate (PUP.GlobalUpdate)
DEPLAC� dossier: C:\Users\jimmy\AppData\Local\PriceMeter (PUP.PriceMeter)
DEPLAC� dossier: C:\Users\jimmy\AppData\Local\PriceMeterLiveUpdate (PUP.PriceMeter)
DEPLAC� dossier: C:\Users\jimmy\AppData\Local\Temp\DigiHelp (Adware.Sambreel)
DEPLAC� dossier: C:\Users\jimmy\AppData\Local\Temp\DriverTurbo (PUP.DriverTurbo)
DEPLAC� dossier: C:\Users\jimmy\AppData\Local\Temp\Iminent (Adware.IMBooster)
DEPLAC� dossier: C:\Users\jimmy\AppData\Local\Temp\iSafeRightKeyScan (PUP.Elex)
DEPLAC� dossier: C:\Users\jimmy\AppData\Local\Temp\webget (Adware.Sambreel)
DEPLAC� dossier: C:\Program Files (x86)\Software (Adware.Boxore)


---\\ Base de Registres ( Cl�s, Valeurs, Donn�es ). (128)
REMPLAC� donn�e: HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope \\\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} (Hijacker.SearchScopes)
SUPPRIM� cl�: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} [http://www.trovi.com/Results.aspx?gd=&ctid=CT3330124&octid=EB_ORIGINAL_CTID&ISID=M66ABAD13-6E2D-44E5[...]] [Trovi search] (Hijacker.Trovigo)
SUPPRIM� cl�: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [http://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=tele_14_12_ch&cd=2XzuyEtN2Y1L1Qzu0B0[...]] [Mysearchdial] (PUP.MySearchDial)
SUPPRIM� cl�: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} [http://istart.webssearches.com/web/?type=ds&ts=1395790288&from=tugs&uid=WDCXWD10JPVX-80JC3T0_WD-WX11[...]] [webssearches] (Hijacker.WebsSearches)
SUPPRIM� cl�: [X64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [http://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=tele_14_12_ch&cd=2XzuyEtN2Y1L1Qzu0B0[...]] [Mysearchdial] (PUP.MySearchDial)
SUPPRIM� cl�: [X64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} [http://istart.webssearches.com/web/?type=ds&ts=1395790288&from=tugs&uid=WDCXWD10JPVX-80JC3T0_WD-WX11[...]] [webssearches] (Hijacker.WebsSearches)
SUPPRIM� cl�: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} [http://istart.webssearches.com/web/?type=ds&ts=1395790288&from=tugs&uid=WDCXWD10JPVX-80JC3T0_WD-WX11[...]] [webssearches] (Hijacker.WebsSearches)
REMPLAC� donn�e: HKLM\...\IEXPLORE.EXE\Shell\open\Command\\C:\Program Files\Internet Explorer\iexplore.exe http://istart.webssearches.com/?type=sc&ts=1395790288&from=tugs&uid=WDCXWD10JPVX-80JC3T0_WD-WX11E83CJV35CJV35 (PUP.IsStart)
SUPPRIM� cl�: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} [http://www.trovi.com/Results.aspx?gd=&ctid=CT3330124&octid=EB_ORIGINAL_CTID&ISID=M66ABAD13-6E2D-44E5-8D7D-38AF4E1C1408&SearchSource=58&CUI=&UM=6&UP=SPAE7D52AD-229E-474D-A7E7-0FD4D633107A&q={searchTerms}&SSPV=] (Hijacker.Trovigo)
SUPPRIM� cl�: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [http://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=tele_14_12_ch&cd=2XzuyEtN2Y1L1Qzu0B0C0E0EyB0BtByC0AzzyByDyEyBtA0CtN0D0Tzu0SzztCtAtN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StDtA0AtDyEtAtD0CtGyC0AtAyBtGyEtBzz0BtGtAyCtAyEtGyDyB0BzyyC0FtD0AyEzzyBtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyBzy0DtD0DtBtCyDtGzy0CtB0EtGyEzy0DyEtG0E0Bzz0FtGtDzyzzyC0FyEtDtAtD0BtBzy2Q&cr=1576919464&ir=] (PUP.MySearchDial)
SUPPRIM� cl�: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} [http://istart.webssearches.com/web/?type=ds&ts=1395790288&from=tugs&uid=WDCXWD10JPVX-80JC3T0_WD-WX11E83CJV35CJV35&q={searchTerms}] (Hijacker.WebsSearches)
SUPPRIM� cl�: [X64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [http://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=tele_14_12_ch&cd=2XzuyEtN2Y1L1Qzu0B0C0E0EyB0BtByC0AzzyByDyEyBtA0CtN0D0Tzu0SzztCtAtN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StDtA0AtDyEtAtD0CtGyC0AtAyBtGyEtBzz0BtGtAyCtAyEtGyDyB0BzyyC0FtD0AyEzzyBtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyBzy0DtD0DtBtCyDtGzy0CtB0EtGyEzy0DyEtG0E0Bzz0FtGtDzyzzyC0FyEtDtAtD0BtBzy2Q&cr=1576919464&ir=] (PUP.MySearchDial)
SUPPRIM� cl�: [X64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} [http://istart.webssearches.com/web/?type=ds&ts=1395790288&from=tugs&uid=WDCXWD10JPVX-80JC3T0_WD-WX11E83CJV35CJV35&q={searchTerms}] (Hijacker.WebsSearches)
SUPPRIM� cl�: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} [http://istart.webssearches.com/web/?type=ds&ts=1395790288&from=tugs&uid=WDCXWD10JPVX-80JC3T0_WD-WX11E83CJV35CJV35&q={searchTerms}] (Hijacker.WebsSearches)
SUPPRIM� cl�*: HKCU\Software\TheHDvid-Codec C+-nv-ie [] (Adware.CrossRider)
SUPPRIM� cl�*: [X64] HKLM\SYSTEM\CurrentControlSet\Services\{713f4525-9b38-40c8-81c7-6dd3bd0d9646}w64 [C:\WINDOWS\System32\drivers\{713f4525-9b38-40c8-81c7-6dd3bd0d9646}w64.sys (Not File)] (PUP.LinkiDoo)
SUPPRIM� cl�*: [X64] HKLM\SYSTEM\CurrentControlSet\Services\{9a9157bb-003e-4fef-8bd1-c09bc4586a28}w64 [C:\WINDOWS\System32\drivers\{9a9157bb-003e-4fef-8bd1-c09bc4586a28}w64.sys (Not File)] (PUP.LinkiDoo)
SUPPRIM� cl�*: [X64] HKLM\SYSTEM\CurrentControlSet\Services\{9edd0ea8-2819-47c2-8320-b007d5996f8a}w64 [C:\WINDOWS\System32\drivers\{9edd0ea8-2819-47c2-8320-b007d5996f8a}w64.sys (Not File)] (PUP.LinkiDoo)
SUPPRIM� cl�*: [X64] HKLM\SYSTEM\CurrentControlSet\Services\esgiguard [C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys (Not File)] (Crapware.SpyHunter)
SUPPRIM� cl�*: [X64] HKLM\SYSTEM\CurrentControlSet\Services\Update DigiHelp ["C:\Program Files (x86)\DigiHelp\updateDigiHelp.exe" (Not File)] (PUP.DigiHelp)
SUPPRIM� cl�*: [X64] HKLM\SYSTEM\CurrentControlSet\Services\Update ToggleMark ["C:\Program Files (x86)\ToggleMark\updateToggleMark.exe" (Not File)] (Adware.Sambreel)
SUPPRIM� cl�*: [X64] HKLM\SYSTEM\CurrentControlSet\Services\Util ToggleMark ["C:\Program Files (x86)\ToggleMark\bin\utilToggleMark.exe" (Not File)] (Adware.Sambreel)
SUPPRIM� cl�*: HKEY_USERS\S-1-5-21-4187242678-1897555983-2689790938-1002\Software\1ClickDownload [] (PUP.1ClickDownloader)
SUPPRIM� cl�*: HKEY_USERS\S-1-5-21-4187242678-1897555983-2689790938-1002\Software\AnyProtect [] (PUP.AnyProtect)
SUPPRIM� cl�*: HKEY_USERS\S-1-5-21-4187242678-1897555983-2689790938-1002\Software\cacaoweb [C:\Users\jimmy\AppData\Roaming\cacaoweb\cacaoweb.exe (Not File)] (PUP.CacaoWeb)
SUPPRIM� cl�*: HKEY_USERS\S-1-5-21-4187242678-1897555983-2689790938-1002\Software\freesofttoday [] (Adware.Multiplug)
SUPPRIM� cl�*: HKEY_USERS\S-1-5-21-4187242678-1897555983-2689790938-1002\Software\globalUpdate [] (PUP.GlobalUpdate)
SUPPRIM� cl�*: HKEY_USERS\S-1-5-21-4187242678-1897555983-2689790938-1002\Software\InstallCore [] (Adware.InstallCore)
SUPPRIM� cl�*: HKEY_USERS\S-1-5-21-4187242678-1897555983-2689790938-1002\Software\Nosibay [] (Adware.SPointer)
SUPPRIM� cl�*: HKEY_USERS\S-1-5-21-4187242678-1897555983-2689790938-1002\Software\nuevos-programas.com [] (PUP.Optional)
SUPPRIM� cl�*: HKEY_USERS\S-1-5-21-4187242678-1897555983-2689790938-1002\Software\Reimage [] (PUP.ReimageRepair)
SUPPRIM� cl�*: HKEY_USERS\S-1-5-21-4187242678-1897555983-2689790938-1002\Software\SearchProtectIN4T [] (PUP.SearchProtect)
SUPPRIM� cl�*: HKEY_USERS\S-1-5-21-4187242678-1897555983-2689790938-1002\Software\StormWatchApp [] (PUP.StormWatch)
SUPPRIM� cl�: HKEY_USERS\S-1-5-21-4187242678-1897555983-2689790938-1002\Software\TheHDvid-Codec C+-nv-ie [] (Adware.CrossRider)
SUPPRIM� cl�*: HKEY_USERS\S-1-5-21-4187242678-1897555983-2689790938-1002\Software\TutoTag [] (PUP.AgenceExclusive)
SUPPRIM� cl�*: HKEY_USERS\S-1-5-21-4187242678-1897555983-2689790938-1002\Software\WeDlMngr [] (PUP.weDownloadManager)
SUPPRIM� cl�: HKCU\Software\1ClickDownload [] (PUP.1ClickDownloader)
SUPPRIM� cl�: HKCU\Software\AnyProtect [] (PUP.AnyProtect)
SUPPRIM� cl�: HKCU\Software\cacaoweb [C:\Users\jimmy\AppData\Roaming\cacaoweb\cacaoweb.exe (Not File)] (PUP.CacaoWeb)
SUPPRIM� cl�: HKCU\Software\freesofttoday [] (Adware.Multiplug)
SUPPRIM� cl�: HKCU\Software\globalUpdate [] (PUP.GlobalUpdate)
SUPPRIM� cl�: HKCU\Software\InstallCore [] (Adware.InstallCore)
SUPPRIM� cl�: HKCU\Software\Nosibay [] (Adware.SPointer)
SUPPRIM� cl�: HKCU\Software\nuevos-programas.com [] (PUP.Optional)
SUPPRIM� cl�: HKCU\Software\Reimage [] (PUP.ReimageRepair)
SUPPRIM� cl�: HKCU\Software\SearchProtectIN4T [] (PUP.SearchProtect)
SUPPRIM� cl�: HKCU\Software\StormWatchApp [] (PUP.StormWatch)
SUPPRIM� cl�: HKCU\Software\TutoTag [] (PUP.AgenceExclusive)
SUPPRIM� cl�: HKCU\Software\WeDlMngr [] (PUP.weDownloadManager)
SUPPRIM� cl�*: HKCU\Software\AppDataLow\Software\BlockAndSurf [] (PUP.BlockAndSurf)
SUPPRIM� cl�*: HKCU\Software\AppDataLow\Software\Crossrider [] (Adware.CrossRider)
SUPPRIM� cl�*: HKCU\Software\AppDataLow\Software\Re_markit [] (PUP.ReMarkIt)
SUPPRIM� cl�*: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\bubbledock.com [] (PUP.BubbleDock)
SUPPRIM� cl�*: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\s.bubbledock.com [45] (PUP.BubbleDock)
SUPPRIM� cl�*: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\istart.webssearches.com [4053] (PUP.IsStart)
SUPPRIM� cl�*: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\superfish.com [] (PUP.SpecialSavings)
SUPPRIM� cl�*: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\webssearches.com [] (Hijacker.WebsSearches)
SUPPRIM� cl�*: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.superfish.com [271] (PUP.SpecialSavings)
SUPPRIM� cl�*: HKCU\Software\Store [] (PUP.Optional)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Classes\AppID\esrv.EXE [] (PUP.Funmoods)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Classes\AppID\{C292AD0A-C11F-479B-B8DB-743E72D283B0} [esrv] (PUP.MySearchDial)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Classes\esrv.mysearchdialESrvc [] (PUP.MySearchDial)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Classes\esrv.mysearchdialESrvc.1 [] (PUP.MySearchDial)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Classes\REI_AxControl.ReiEngine [] (PUP.GetLiveSupport)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Classes\REI_AxControl.ReiEngine.1 [] (PUP.GetLiveSupport)
SUPPRIM� cl�*: [X64] HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Update DigiHelp [] (PUP.DigiHelp)
SUPPRIM� cl�*: [X64] HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Update ToggleMark [] (Adware.Sambreel)
SUPPRIM� cl�*: [X64] HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Util ToggleMark [] (Adware.Sambreel)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\EnigmaSoftwareGroup [] (PUP.EnigmaSoftware)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Reimage [] (PUP.ReimageRepair)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Microsoft\Tracing\StormWatch_RASAPI32 [] (PUP.StormWatch)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Microsoft\Tracing\StormWatch_RASMANCS [] (PUP.StormWatch)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsermngr.exe [] (PUP.Babylon)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe [] (Hijacker.Eazel)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe [] (PUP.SafeGuard)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bundlesweetimsetup.exe [] (PUP.SweetIM)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\delta babylon.exe [] (Toolbar.DeltaSearch)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\delta tb.exe [] (Toolbar.DeltaSearch)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\delta2.exe [] (Toolbar.DeltaSearch)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltainstaller.exe [] (Toolbar.DeltaSearch)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltasetup.exe [] (Toolbar.DeltaSearch)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltatb.exe [] (Toolbar.DeltaSearch)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltatb_2501-c733154b.exe [] (Toolbar.DeltaSearch)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iminentsetup.exe [] (Adware.IMBooster)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe [] (Spyware.ProtectedSearch)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe [] (PUP.SearchProtect)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe [] (PUP.SearchProtect)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe [] (Hijacker.SmartBar)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sweetimsetup.exe [] (PUP.SweetIM)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tbdelta.exetoolbar783881609.exe [] (Toolbar.DeltaSearch)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe [] (Adware.Sambreel)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Wow6432Node\FREESOFTTODAY [] (Adware.Multiplug)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Wow6432Node\free_soft_to_day [] (Adware.Multiplug)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Wow6432Node\GAMESDESKTOP [] (Adware.GamesDesktop)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Wow6432Node\GlobalUpdate [] (PUP.GlobalUpdate)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Wow6432Node\SafetyNut [] (PUP.MoviesToolbar)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Wow6432Node\Tutorials [] (PUP.AgenceExclusive)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Wow6432Node\webssearchesSoftware [] (Hijacker.WebsSearches)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Wow6432Node\WordProser_1.10.0.6 [] (PUP.WordProser)
SUPPRIM� cl�: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\AppID\esrv.EXE [] (PUP.Funmoods)
SUPPRIM� cl�: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\AppID\{C292AD0A-C11F-479B-B8DB-743E72D283B0} [esrv] (PUP.MySearchDial)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ToggleMark_RASAPI32 [] (Adware.Sambreel)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ToggleMark_RASMANCS [] (Adware.Sambreel)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\updateDigiHelp_RASAPI32 [] (PUP.DigiHelp)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\updateDigiHelp_RASMANCS [] (PUP.DigiHelp)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\updateScanTack_RASAPI32 [] (Adware.Sambreel)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\updateScanTack_RASMANCS [] (Adware.Sambreel)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\updateToggleMark_RASAPI32 [] (Adware.Sambreel)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\updateToggleMark_RASMANCS [] (Adware.Sambreel)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\updatewebget_RASAPI32 [] (Adware.Sambreel)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\updatewebget_RASMANCS [] (Adware.Sambreel)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\utilToggleMark_RASAPI32 [] (Adware.Sambreel)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\utilToggleMark_RASMANCS [] (Adware.Sambreel)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\utilwebget_RASAPI32 [] (Adware.Sambreel)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\utilwebget_RASMANCS [] (Adware.Sambreel)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\webget_RASAPI32 [] (Adware.Sambreel)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\webget_RASMANCS [] (Adware.Sambreel)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Classes\CLSID\{10ECCE17-29B5-4880-A8F5-EAD298611484} [ReiEngine Class] (PUP.ReimageRepair)
SUPPRIM� cl�: [X64] HKLM\SOFTWARE\Classes\CLSID\{10ECCE17-29B5-4880-A8F5-EAD298611484}\InprocServer32 [C:\Program Files\Reimage\Reimage Repair\REI_Axcontrol.dll (Not File)] (PUP.ReimageRepair)
SUPPRIM� cl�*: [X64] HKLM\SOFTWARE\Classes\CLSID\{801B440B-1EE3-49B0-B05D-2AB076D4E8CB} [CompReg Class] (PUP.ReimageRepair)
SUPPRIM� cl�: [X64] HKLM\SOFTWARE\Classes\CLSID\{801B440B-1EE3-49B0-B05D-2AB076D4E8CB}\InprocServer32 [C:\Program Files\Reimage\Reimage Repair\REI_Axcontrol.dll (Not File)] (PUP.ReimageRepair)
SUPPRIM� valeur: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\DriverTurbo [C:\Program Files (x86)\DriverTurbo\DriverTurbo.exe] (PUP.DriverTurbo)
SUPPRIM� valeur: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\cacaoweb ["C:\Users\jimmy\AppData\Roaming\cacaoweb\cacaoweb.exe" -noplayer] (PUP.CacaoWeb)
SUPPRIM� valeur: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\WindApp ["C:\Users\jimmy\AppData\Roaming\Store\WindApp\WindApp.exe" /winstartup] (PUP.Nosibay)
SUPPRIM� valeur: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\Selection Tools ["C:\Users\jimmy\AppData\Roaming\WTools\Selection Tools\Selection Tools.exe" /winstartup] (PUP.Nosibay)
SUPPRIM� valeur: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\\fst_fr_134 ["C:\Program Files (x86)\fst_fr_134\fst_fr_134.exe"] (Adware.FreeSoftToday)
SUPPRIM� valeur: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\\fst_fr_384 ["C:\Program Files (x86)\fst_fr_384\fst_fr_384.exe"] (Adware.FreeSoftToday)
SUPPRIM� valeur: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_fr_189 [] (Adware.CrossRider)


---\\ Bilan de la r�paration
~ R�paration r�alis�e avec succ�s.
~ Ce navigateur est absent (Opera Software)


---\\ Statistiques
~ Items scann�s : 7227
~ Items trouv�s : 0
~ Items annul�s : 0
~ Items r�par�s : 297


End of clean at 17:51:33
===================
ZHPCleaner-[R]-18052015-17_51_33.txt
ZHPCleaner-[S]-18052015-17_49_57.txt

Publicité


Signaler le contenu de ce document

Publicité