~ ZHPCleaner v2015.6.24.282 by Nicolas Coolman (2015\06\24) ~ Run by flya (Administrator) (25/06/2015 12:14:05) ~ Site : http://www.nicolascoolman.fr ~ Facebook : https://www.facebook.com/nicolascoolman1 ~ State version : Version OK ~ Type : Reparar ~ Report : C:\Users\flya\Desktop\ZHPCleaner.txt ~ Quarantine : C:\Users\flya\AppData\Roaming\ZHP\ZHPCleaner_Quarantine.txt ~ UAC : Activate ~ Boot Mode : Normal (Normal boot) ~ Windows 8.1, 64-bit (Build 9600) ---\\ Servicios (0) ~ No malintencionados artículos encontrados. ---\\ Navegadores de Internet (1) BORRADOS: [b7uu5ms2.default] - user_pref("extensions.accf7276cd388480f88355b680025e1cagmailcom71387.71387.internaldb.monetization_p[...] (PUP.Monetization) ---\\ Archivo hosts (1) ~ El archivo hosts es legítimo (21) ---\\ Tareas automáticas programadas. (0) ~ No malintencionados artículos encontrados. ---\\ Explorador ( Archivos, Carpetas ) (60) MOVIDO carpeta: C:\Users\flya\AppData\Roaming\RKJ.exe [enter - videos_MediaPlayers_v1.1 exe] (Adware.Pirrit) MOVIDO carpeta: C:\Windows\Prefetch\GUPLAYER.EXE-62C71055.pf (PUP.GUPlayer) MOVIDO carpeta: C:\Windows\Prefetch\REIMAGE.EXE-BEE43FC1.pf (PUP.ReimageRepair) MOVIDO carpeta: C:\Windows\Prefetch\REIMAGEREPAIR.EXE-DACCD39B.pf (PUP.ReimageRepair) MOVIDO carpeta: C:\Windows\Prefetch\SHOPPERZ_2002--7CA7C95D.TMP-9275849B.pf (PUP.Shopperz) MOVIDO carpeta: C:\Windows\Prefetch\SMARTBAR.EXE-8B9ACAB1.pf (Hijacker.SmartBar) MOVIDO carpeta: C:\Windows\Prefetch\VOSTERAN.EXE-5D1507BD.pf (PUP.Vosteran) MOVIDO carpeta: C:\Windows\Installer\5b2f4d7.msi [APN, LLC - Ask.com ® - Install Builder] (Adware.Bandoo) MOVIDO carpeta: C:\Users\flya\Downloads\ReimageRepair.exe [Reimage® - Reimage Downloader] (PUP.ReimageRepair) MOVIDO carpeta: C:\Users\flya\Downloads\SoftonicDownloader_pour_painttool-sai (1).exe [Copyright (C) 2014 - Application Installer] (PUP.Softonic) MOVIDO carpeta: C:\Users\flya\Downloads\SoftonicDownloader_pour_painttool-sai.exe [Copyright (C) 2014 - Application Installer] (PUP.Softonic) MOVIDO carpeta: C:\Users\flya\AppData\Local\Temp\res.dll [Pay By Ads LTD - ] (PUP.PaybyAds) MOVIDO carpeta: C:\Users\flya\AppData\Local\Temp\comh.487886\goopdate.dll [globalUpdate - globalUpdate Update] (PUP.GlobalUpdate) MOVIDO carpeta: C:\Users\flya\AppData\Local\Temp\comh.487886\goopdateres_en.dll [globalUpdate - globalUpdate Update Resource DLL] (PUP.GlobalUpdate) MOVIDO carpeta: C:\Users\flya\AppData\Local\Temp\comh.487886\psmachine.dll [globalUpdate - globalUpdate Update] (PUP.GlobalUpdate) MOVIDO carpeta: C:\Users\flya\AppData\Local\Temp\comh.487886\psuser.dll [globalUpdate - globalUpdate Update] (PUP.GlobalUpdate) MOVIDO carpeta: C:\Users\flya\AppData\Local\Temp\dsrsetup.exe [Pay By Ads LTD - ] (PUP.PaybyAds) MOVIDO carpeta: C:\Users\flya\AppData\Local\Temp\ReimagePackage.exe [Reimage® - Reimage Package] (PUP.ReimageRepair) MOVIDO carpeta: C:\Users\flya\AppData\Local\Temp\ReiSysUpdate.exe [Reimage® - Reimage System Update] (PUP.ReimageRepair) MOVIDO carpeta: C:\Users\flya\AppData\Local\Temp\SettingsManagerSetup[2].exe [Aztec Media Inc - Settings Manager Install] (PUP.SystemK) MOVIDO carpeta: C:\Users\flya\AppData\Local\Temp\speedupmypc.exe [Uniblue Systems Limited - SpeedUpMyPC Setup] (PUP.UniblueSystem) MOVIDO carpeta: C:\Users\flya\AppData\Local\Temp\UE256.tmp\UNTE266.tmp.exe [Nosibay - Bubble Dock installer] (PUP.Nosibay) MOVIDO carpeta: C:\Users\flya\AppData\Local\Temp\U77CF.tmp\UNT77D0.tmp.exe [Nosibay - Bubble Dock installer] (PUP.Nosibay) MOVIDO carpeta: C:\Users\flya\AppData\Local\Temp\U2B75.tmp\UNT2B76.tmp.exe [Nosibay - Bubble Dock installer] (PUP.Nosibay) MOVIDO carpeta: C:\Users\flya\AppData\Local\Temp\is-QIO3P.tmp\SpeedUpMyPC-standalone-setup.exe [Uniblue Systems Limited - SpeedUpMyPC Setup] (PUP.UniblueSystem) MOVIDO carpeta: C:\Users\flya\AppData\Local\Temp\comh.487886\GoogleCrashHandler.exe [globalUpdate - globalUpdate Update] (PUP.GlobalUpdate) MOVIDO carpeta: C:\Users\flya\AppData\Local\Temp\comh.487886\GoogleUpdateBroker.exe [globalUpdate - globalUpdate Update] (PUP.GlobalUpdate) MOVIDO carpeta: C:\Users\flya\AppData\Local\Temp\comh.487886\GoogleUpdateOnDemand.exe [globalUpdate - globalUpdate Update] (PUP.GlobalUpdate) MOVIDO carpeta: C:\Users\flya\AppData\Local\Temp\17102014190921\WindApp Uninstall.exe [Nosibay - WindApp installer] (PUP.Nosibay) MOVIDO carpeta: C:\Users\flya\AppData\Local\Temp\17102014152519\Uninstall Bubble Dock.exe [Nosibay - Bubble Dock installer] (PUP.Nosibay) MOVIDO carpeta: C:\Users\flya\AppData\Local\Temp\Bubble Dock.txt (PUP.BubbleDock) MOVIDO carpeta: C:\Users\flya\AppData\Local\Temp\LBubble Dock.txt (PUP.BubbleDock) MOVIDO carpeta: C:\Users\flya\AppData\Local\Temp\MediaViewerTracing_PhotosApp.etl (PUP.MediaViewer) MOVIDO carpeta: C:\Users\flya\AppData\Local\Temp\MediaViewerTracing_PhotosApp.last.etl (PUP.MediaViewer) MOVIDO carpeta: C:\Users\flya\AppData\Local\Temp\reimage.log (PUP.ReimageRepair) MOVIDO carpeta: C:\Users\flya\AppData\Local\Temp\Softonic_FR_1-5-11_FR-Production_10_CleanRelease.exe (PUP.Softonic) MOVIDO carpeta: C:\Users\flya\AppData\Local\Temp\v-bates.exe [Wajamu - ] (Adware.IncrediBar) MOVIDO carpeta: C:\Users\flya\AppData\Local\Temp\vitruvian-installer-install-v0003 (PUP.Vitruvian) MOVIDO carpeta: C:\Users\flya\AppData\Local\Temp\vitruvian-installer-processes-v0002 (PUP.Vitruvian) MOVIDO carpeta: C:\Users\flya\AppData\Local\Temp\vitruvian-installer-scheduledtasks-v0001 (PUP.Vitruvian) MOVIDO carpeta: C:\Users\flya\AppData\Local\Temp\vitruvian-installer-softwareregkeys-v0002 (PUP.Vitruvian) MOVIDO carpeta: C:\Users\flya\AppData\Local\Temp\vitruvian-installer-uninstall-v0002 (PUP.Vitruvian) MOVIDO carpeta: C:\Windows\Installer\{4F524A2D-5350-4500-76A7-A758B70C1C01}\ToolbarIcon.exe (PUP.BrowserTabSearch) MOVIDO archivo: C:\Program Files (x86)\CinemaP-1.9cV16.03 (Adware.CrossRider) MOVIDO archivo: C:\ZombieNews (PUP.ZombieNews) MOVIDO archivo: C:\ProgramData\SaleItCoupon (Adware.Multiplug) MOVIDO archivo: C:\ProgramData\webSaveR (Adware.Multiplug) MOVIDO archivo: C:\Users\flya\AppData\LocalLow\DataMngr (PUP.Datamngr) MOVIDO archivo: C:\Users\flya\AppData\Local\BreakingNewsAlert (PUP.BreakingNewsAlert) MOVIDO archivo: C:\Users\flya\AppData\Local\CrashRpt (SUP.CrashReports) MOVIDO archivo: C:\Users\flya\AppData\Local\com (PUP.Optional) MOVIDO archivo: C:\windows\Installer\MSI1F93.tmp- (Empty) MOVIDO archivo: C:\windows\Installer\MSI3A0.tmp- (Empty) MOVIDO archivo: C:\windows\Installer\MSI49C2.tmp- (Empty) MOVIDO archivo: C:\windows\Installer\MSI7B93.tmp- (Empty) MOVIDO archivo: C:\windows\Installer\MSIBCD0.tmp- (Empty) MOVIDO archivo: C:\windows\Installer\MSID59.tmp- (Empty) MOVIDO archivo: C:\windows\Installer\MSID8E9.tmp- (Empty) MOVIDO archivo: C:\windows\Installer\MSIE503.tmp- (Empty) MOVIDO archivo: C:\windows\Installer\MSIE70D.tmp- (Empty) ---\\ Registro ( Claves, Valores, Datos) (57) BORRADOS clave*: HKCU\Software\CinemaP-1.9cV16.03-nv-ie [] (Adware.CrossRider) BORRADOS clave*: [X64] HKLM\SOFTWARE\Wow6432Node\CinemaP-1.9cV16.03-nv-ie [] (Adware.CrossRider) BORRADOS clave*: HKEY_USERS\S-1-5-21-3706412250-2803098473-82048792-1001\Software\CinemaP-1.9cV16.03 [] (Adware.CrossRider) BORRADOS clave: HKEY_USERS\S-1-5-21-3706412250-2803098473-82048792-1001\Software\CinemaP-1.9cV16.03-nv-ie [] (Adware.CrossRider) BORRADOS clave*: HKEY_USERS\S-1-5-21-3706412250-2803098473-82048792-1001\Software\Probit Software [] (PUP.ProbitSoftware) BORRADOS clave*: HKEY_USERS\S-1-5-21-3706412250-2803098473-82048792-1001\Software\Smartbar [] (PUP.QuickShare) BORRADOS clave: HKCU\Software\CinemaP-1.9cV16.03 [] (Adware.CrossRider) BORRADOS clave: HKCU\Software\Probit Software [] (PUP.ProbitSoftware) BORRADOS clave: HKCU\Software\Smartbar [] (PUP.QuickShare) BORRADOS clave*: HKCU\Software\AppDataLow\Software\SpeedCheck [] (PUP.SpeedCheck) BORRADOS clave*: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\bubbledock.es [] (PUP.BubbleDock) BORRADOS clave*: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\es.reimageplus.com [108] (PUP.ReimageRepair) BORRADOS clave*: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\fastplayerpro.com [] (PUP.FastPlayer) BORRADOS clave*: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\gettvwizard.com [] (PUP.TVWizard) BORRADOS clave*: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\iminent.com [] (Adware.IMBooster) BORRADOS clave*: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\inst.bubbledock.es [248] (PUP.BubbleDock) BORRADOS clave*: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\myhome.vi-view.com [108] (Hijacker.MyhomeViview) BORRADOS clave*: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\mystartsearch.com [] (PUP.StartSearch) BORRADOS clave*: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\openask.com [] (Toolbar.Ask) BORRADOS clave*: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\powerbundle.systweak.com [248] (PUP.SystSupportDock) BORRADOS clave*: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\re-markable.net [] (PUP.Re-Markable) BORRADOS clave*: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\reimageplus.com [] (PUP.ReimageRepair) BORRADOS clave*: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\searches.vi-view.com [207] (Hijacker.MyhomeViview) BORRADOS clave*: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\snapdo.com [] (Hijacker.SmartBar) BORRADOS clave*: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\softonic.fr [] (PUP.Softonic) BORRADOS clave*: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\start.iminent.com [349] (Adware.IMBooster) BORRADOS clave*: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\static.boostsaves.com [403] (PUP.BoostSaves) BORRADOS clave*: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\static.livelyrics00.live-lyrics.com [3383] (Adware.AddLyrics) BORRADOS clave*: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\static.re-markable00.re-markable.net [3275] (PUP.Re-Markable) BORRADOS clave*: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\systweak.com [21] (PUP.SystSupportDock) BORRADOS clave*: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\vi-view.com [] (Hijacker.MyhomeViview) BORRADOS clave*: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.gettvwizard.com [21] (PUP.TVWizard) BORRADOS clave*: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.mystartsearch.com [1088] (PUP.StartSearch) BORRADOS clave*: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.openask.com [55] (Toolbar.Ask) BORRADOS clave*: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.softonic.fr [256] (PUP.Softonic) BORRADOS clave*: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.systweak.com [1136] (PUP.SystSupportDock) BORRADOS clave*: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www1.fastplayerpro.com [198] (PUP.FastPlayer) BORRADOS clave*: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\zombienewsapp.com [] (PUP.ZombieNews) BORRADOS clave*: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\share2give.net [241] (Adware.Multiplug) BORRADOS clave*: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\static.boostsaves.com [194] (PUP.BoostSaves) BORRADOS clave*: [X64] HKLM\SOFTWARE\Classes\finedeal.finedeal [FineDealSoft] (PUP.FineDeal) BORRADOS clave*: [X64] HKLM\SOFTWARE\Classes\finedeal.finedeal.9 [FineDealSoft] (PUP.FineDeal) BORRADOS clave*: [X64] HKLM\Software\Classes\Installer\Products\D2A425F405350054677A7A857BC0C110 [Search App by Ask] (PUP.BrowserTabSearch) BORRADOS clave*: [X64] HKLM\SOFTWARE\Classes\Record\{181480C8-90AC-3430-B39A-CD121E034A1A} [IESmartBar.MSG] (Hijacker.SmartBar) BORRADOS clave*: [X64] HKLM\SOFTWARE\Classes\Record\{2009AF2F-5786-3067-8799-B97F7832FDD6} [IESmartBar.BandObjectStyle] (Hijacker.SmartBar) BORRADOS clave*: [X64] HKLM\SOFTWARE\Classes\Record\{425E7597-03A2-338D-B72A-0E51FFE77A7E} [IESmartBar.POINT] (Hijacker.SmartBar) BORRADOS clave*: [X64] HKLM\SOFTWARE\Classes\Record\{8F54FA54-1DF8-3B20-890C-CDD95364BC95} [IESmartBar.DBIM] (Hijacker.SmartBar) BORRADOS clave*: [X64] HKLM\SOFTWARE\Classes\Record\{915BB7D5-082E-3B91-B1E0-45B5FDE01F24} [IESmartBar.DESKBANDINFO] (Hijacker.SmartBar) BORRADOS clave*: [X64] HKLM\SOFTWARE\Classes\Record\{FB2E65F4-5687-33EF-9BBF-4E3C9C98D3B9} [IESmartBar.DBIMF] (Hijacker.SmartBar) BORRADOS clave*: [X64] HKLM\SOFTWARE\Wow6432Node\CinemaP-1.9cV16.03 [] (Adware.CrossRider) BORRADOS clave*: [X64] HKLM\SOFTWARE\Wow6432Node\ErrorLists-crcodedownloader [] (PUP.SoftwareEngine) BORRADOS clave*: [X64] HKLM\SOFTWARE\Wow6432Node\Infonaut_1.10.0.14 [] (PUP.Infonaut) BORRADOS clave*: [X64] HKLM\SOFTWARE\Wow6432Node\Smartbar [] (PUP.QuickShare) BORRADOS clave*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Premier Download Manager [Mindspark Interactive Network] (PUP.MindSpark) BORRADOS clave*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\RGMUpdater Monetization Controlcc56729e-9fc2-4c79-a5a8-77edc7087390 [ ] (PUP.RGMUpdater) BORRADOS clave*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\028BBEF6A9C7E514DBD346613B4DC0C8 [C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ (Not File)] (Toolbar.Ask) BORRADOS clave*: [X64] HKLM\Software\Classes\Installer\Features\D2A425F405350054677A7A857BC0C110 [] (PUP.BrowserTabSearch) ---\\ Resultado de la reparación. ~ Reparación llevada a cabo con éxito ~ falta este navegador! (Opera Software) ---\\ Statistiques ~ Items escaneado : 1077 ~ Items encontrado : 0 ~ artículos cancelados : 0 ~ Items reparado : 124 End of clean at 12:15:24 =================== ZHPCleaner-[R]-04062015-20_06_30.txt ZHPCleaner-[R]-04062015-21_08_11.txt ZHPCleaner-[R]-25062015-12_15_24.txt ZHPCleaner-[S]-04062015-19_42_15.txt ZHPCleaner-[S]-04062015-19_54_29.txt ZHPCleaner-[S]-04062015-21_05_52.txt ZHPCleaner-[S]-25062015-12_13_41.txt