cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ ZHPCleaner v2017.10.10.179 by Nicolas Coolman (2017/10/10)
~ Run by Gingobel (Administrator) (22/10/2017 10:46:09)
~ Web: https://www.nicolascoolman.com
~ Blog: https://nicolascoolman.eu/
~ Facebook : https://www.facebook.com/nicolascoolman1
~ State version : Version OK
~ Certificate ZHPCleaner: Illegal
~ Type : Nettoyer
~ Report : C:\Users\Gingobel\Desktop\ZHPCleaner.txt
~ Quarantine : C:\Users\Gingobel\AppData\Roaming\ZHP\ZHPCleaner_Reg.txt
~ UAC : Activate
~ Boot Mode : Normal (Normal boot)
Windows 10 Home, 64-bit (Build 15063)


---\\ Service. (0)
~ Aucun élément malicieux ou superflu trouvé.


---\\ Navigateur internet. (0)
~ Aucun élément malicieux ou superflu trouvé.


---\\ Fichier hôte. (1)
~ Le fichier hôte est légitime. (21)


---\\ Tâche planifiée. (4)
SUPPRIMÉ tâche: [DropboxUpdateTaskMachineCore] [C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job (Not File) ] =>PUP.Optional.MySearch
SUPPRIMÉ tâche: [DropboxUpdateTaskMachineUA] [C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job (Not File) ] =>PUP.Optional.MySearch
SUPPRIMÉ tâche: [WpsNotifyTask_Administrator] [C:\Windows\Tasks\WpsNotifyTask_Administrator.job (Not File) ] =>PUP.Optional.MySearch
SUPPRIMÉ tâche: [WpsUpdateTask_Administrator] [C:\Windows\Tasks\WpsUpdateTask_Administrator.job (Not File) ] =>PUP.Optional.MySearch


---\\ Explorateur ( Dossiers, Fichiers ). (11)
DEPLACÉ fichier: C:\Users\Gingobel\AppData\Roaming\Mozilla\Firefox\Profiles\db7x5xyl.default\storage\default\https+++game286491.konggames.com\.metadata =>PUP.Optional.KongGames
DEPLACÉ fichier: C:\Users\Gingobel\AppData\Roaming\Mozilla\Firefox\Profiles\db7x5xyl.default\storage\default\https+++game286491.konggames.com\.metadata-v2 =>PUP.Optional.KongGames
DEPLACÉ fichier: C:\Users\Gingobel\AppData\Roaming\Mozilla\Firefox\Profiles\db7x5xyl.default\storage\default\https+++game286491.konggames.com\idb\3619119340leogcaarlof.sqlite =>PUP.Optional.KongGames
DEPLACÉ fichier: C:\Users\Gingobel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_nahhmpbckpgdidfnmfkfgiflpjijilce_0.localstorage =>.SUP.SearchManager
DEPLACÉ fichier: C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job =>PUP.Optional.MySearch
DEPLACÉ fichier: C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job =>PUP.Optional.MySearch
DEPLACÉ fichier: C:\Windows\Tasks\WpsNotifyTask_Administrator.job =>PUP.Optional.MySearch
DEPLACÉ fichier: C:\Windows\Tasks\WpsUpdateTask_Administrator.job =>PUP.Optional.MySearch
DEPLACÉ fichier: C:\Users\Gingobel\AppData\Local\Akamai\netsession_win.exe [Akamai Technologies, Inc. - Akamai NetSession Client] =>.SUP.AkamaiHD
DEPLACÉ dossier*: C:\Users\Gingobel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce =>.SUP.SearchManager
DEPLACÉ dossier^: C:\Users\Gingobel\AppData\Local\Akamai =>.SUP.AkamaiHD


---\\ Base de Registres ( Clés, Valeurs, Données ). (17)
SUPPRIMÉ clé: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2211d4a5-48d0-47f5-a7cd-81e861470f7f} [https://fr.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_btrnt_17_40&pa[...]] [Yahoo! Powered] =>Adware.YahooPowered
SUPPRIMÉ clé: [X64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [https://fr.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_btrnt_17_40&pa[...]] [Yahoo! Powered] =>Adware.YahooPowered
SUPPRIMÉ clé: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [https://fr.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_btrnt_17_40&pa[...]] [Yahoo! Powered] =>Adware.YahooPowered
SUPPRIMÉ clé*: HKCU\SOFTWARE\Google\Chrome\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce [] =>.SUP.SearchManager
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Google\Chrome\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce [] =>.SUP.SearchManager
SUPPRIMÉ clé: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2211d4a5-48d0-47f5-a7cd-81e861470f7f} [https://fr.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_btrnt_17_40¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dfr%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1Qzu0Bzzzz0AyCtD0AtCyB0B0EyC0DtC0EyDtN0D0Tzu0StBtCtDyDtN1L2XzutAtFtBzytFyCtFyDtAtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2StA0BtB0AtAyD0CyCtGtD0DzzyCtGyB0C0FtAtGtByDtDtAtG0B0FtC0EtCyEzytByByDzyzz2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0A0FtD0AyCyBzyzztG0A0E0DyDtGyEtCyEyDtGzytD0C0AtGyC0A0FyC0E0DzyyCyD0F0Dzy2QtN0A0LzuyE%26cr%3D2099293900%26a%3Dwncy_btrnt_17_40%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms}] =>Adware.YahooPowered
SUPPRIMÉ clé: [X64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [https://fr.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_btrnt_17_40¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dfr%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1Qzu0Bzzzz0AyCtD0AtCyB0B0EyC0DtC0EyDtN0D0Tzu0StBtCtDyDtN1L2XzutAtFtBzytFyCtFyDtAtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2StA0BtB0AtAyD0CyCtGtD0DzzyCtGyB0C0FtAtGtByDtDtAtG0B0FtC0EtCyEzytByByDzyzz2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0A0FtD0AyCyBzyzztG0A0E0DyDtGyEtCyEyDtGzytD0C0AtGyC0A0FyC0E0DzyyCyD0F0Dzy2QtN0A0LzuyE%26cr%3D2099293900%26a%3Dwncy_btrnt_17_40%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms}] =>Adware.YahooPowered
SUPPRIMÉ clé: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [https://fr.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_btrnt_17_40¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dfr%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1Qzu0Bzzzz0AyCtD0AtCyB0B0EyC0DtC0EyDtN0D0Tzu0StBtCtDyDtN1L2XzutAtFtBzytFyCtFyDtAtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2StA0BtB0AtAyD0CyCtGtD0DzzyCtGyB0C0FtAtGtByDtDtAtG0B0FtC0EtCyEzytByByDzyzz2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0A0FtD0AyCyBzyzztG0A0E0DyDtGyEtCyEyDtGzytD0C0AtGyC0A0FyC0E0DzyyCyD0F0Dzy2QtN0A0LzuyE%26cr%3D2099293900%26a%3Dwncy_btrnt_17_40%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms}] =>Adware.YahooPowered
SUPPRIMÉ clé*: HKEY_USERS\S-1-5-21-1485702640-3372445448-1532171041-1001\SOFTWARE\Akamai [] =>.SUP.AkamaiHD
SUPPRIMÉ clé: HKCU\Software\Akamai [] =>.SUP.AkamaiHD
SUPPRIMÉ clé*: HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Akamai [Akamai Technologies, Inc] =>.SUP.AkamaiHD
SUPPRIMÉ valeur: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\Akamai NetSession Interface ["C:\Users\Gingobel\AppData\Local\Akamai\netsession_win.exe"] =>.SUP.AkamaiHD
SUPPRIMÉ valeur: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\\Akamai NetSession Interface [0x020000000000000000000000] =>.SUP.AkamaiHD
SUPPRIMÉ valeur: HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules\\TCP Query User{E7288054-C745-4E28-B731-A183A314637C}C:\users\gingobel\appdata\local\akamai\netsession_win.exe [C:\users\gingobel\appdata\local\akamai\netsession_win.exe] =>.SUP.AkamaiHD
SUPPRIMÉ valeur: HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules\\UDP Query User{B228C603-C203-4466-AA09-241DADC3D048}C:\users\gingobel\appdata\local\akamai\netsession_win.exe [C:\users\gingobel\appdata\local\akamai\netsession_win.exe] =>.SUP.AkamaiHD
SUPPRIMÉ valeur: HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules\\{1B314035-833D-43ED-ADBA-6BF5ADB2FBBD} [C:\users\gingobel\appdata\local\akamai\netsession_win.exe] =>.SUP.AkamaiHD
SUPPRIMÉ valeur: HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules\\{E7139650-7665-46E7-BFB1-AE2CF1585AB0} [C:\users\gingobel\appdata\local\akamai\netsession_win.exe] =>.SUP.AkamaiHD


---\\ Récapitulatif des éléments trouvés sur votre station. (5)
https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>PUP.Optional.MySearch
https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>PUP.Optional.KongGames
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.SUP.SearchManager
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.SUP.AkamaiHD
https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>Adware.YahooPowered


---\\ Nettoyage Additionnel. (28)
~ Suppression des Clés de registre Tracing. (28)
~ Suppression des anciens rapports ZHPCleaner. (0)


---\\ Bilan de la réparation
~ Réparation réalisée avec succès.
~ Ce navigateur est absent (Opera Software)
~ Le système a été redémarré.


---\\ Statistiques
~ Items scannés : 1019
~ Items trouvés : 0
~ Items annulés : 0
~ Items réparés : 32


~ End of clean in 00h00mn38s
~====================
ZHPCleaner-[R]-22102017-10_46_47.txt
ZHPCleaner-[S]-21102017-14_05_11.txt
ZHPCleaner-[S]-22102017-10_29_43.txt

Publicité


Signaler le contenu de ce document

Publicité