~ ZHPCleaner v2017.8.15.140 by Nicolas Coolman (2017/08/15) ~ Run by BS (Administrator) (19/08/2017 20:34:36) ~ Web: https://www.nicolascoolman.com ~ Blog: https://nicolascoolman.eu/ ~ Facebook : https://www.facebook.com/nicolascoolman1 ~ State version : ~ Certificate ZHPCleaner: Legal ~ Type : Nettoyer ~ Report : C:\Users\BS\Desktop\ZHPCleaner.txt ~ Quarantine : C:\Users\BS\AppData\Roaming\ZHP\ZHPCleaner_Reg.txt ~ UAC : Activate ~ Boot Mode : Normal (Normal boot) Windows 10 Home, 64-bit (Build 15063) ---\\ Service. (1) ARRETÉ : rtop =>.SUP.ByteFence ---\\ Navigateur internet. (0) ---\\ Fichier hôte. (1) ~ Le fichier hôte est légitime. (60) ---\\ Tâche planifiée. (2) SUPPRIMÉ tâche: [App Explorer] [C:\Users\BS\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe (Not File) ] =>.SUP.SweetLabs SUPPRIMÉ tâche: [Yahoo! Powered resaf] [C:\WINDOWS\Tasks\Yahoo! Powered resaf.job (Not File) ] =>Adware.YahooPowered ---\\ Explorateur ( Dossiers, Fichiers ). (25) DEPLACÉ fichier: C:\Users\BS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo App Explorer.lnk [Bad : C:\Users\BS\AppData\Local\Host App Service\Engine\HostAppService.exe](.SweetLabs, Inc.) =>.SUP.SweetLabs DEPLACÉ fichier: C:\Users\BS\AppData\Roaming\Mozilla\Firefox\Profiles\5m9zp55x.default\searchplugins\bing-lavasoft.xml =>PUP.Optional.LavasoftWebCompanion DEPLACÉ fichier^: C:\Users\BS\AppData\Roaming\Mozilla\Firefox\Profiles\5m9zp55x.default\Extensions\{a00bef25-f21a-4539-adbb-b179b29e2b92}\chrome =>.SUP.VidAdBlock DEPLACÉ fichier: C:\Users\BS\AppData\Roaming\Mozilla\Firefox\Profiles\5m9zp55x.default\Extensions\{a00bef25-f21a-4539-adbb-b179b29e2b92}\chrome.manifest =>.SUP.VidAdBlock DEPLACÉ fichier: C:\Users\BS\AppData\Roaming\Mozilla\Firefox\Profiles\5m9zp55x.default\Extensions\{a00bef25-f21a-4539-adbb-b179b29e2b92}\install.rdf =>.SUP.VidAdBlock DEPLACÉ fichier^: C:\Users\BS\AppData\Roaming\Mozilla\Firefox\Profiles\5m9zp55x.default\Extensions\{a00bef25-f21a-4539-adbb-b179b29e2b92}\modules =>.SUP.VidAdBlock DEPLACÉ fichier: C:\Users\BS\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe [SweetLabs, Inc - Host App Service Updater] =>.SUP.SweetLabs DEPLACÉ fichier**: C:\Windows\Tasks\Yahoo! Powered resaf.job =>Adware.YahooPowered DEPLACÉ fichier^: C:\Program Files (x86)\Lavasoft\web companion =>PUP.Optional.LavasoftWebCompanion DEPLACÉ fichier^: C:\Users\BS\AppData\Roaming\Lavasoft\web companion =>PUP.Optional.LavasoftWebCompanion DEPLACÉ fichier^: C:\ProgramData\Lavasoft\web companion =>PUP.Optional.LavasoftWebCompanion DEPLACÉ dossier*: C:\Users\BS\AppData\Roaming\Mozilla\Firefox\Profiles\5m9zp55x.default\Extensions\{a00bef25-f21a-4539-adbb-b179b29e2b92} =>.SUP.VidAdBlock DEPLACÉ dossier^: C:\Program Files\ByteFence =>.SUP.ByteFence DEPLACÉ dossier^: C:\ProgramData\ByteFence =>.SUP.ByteFence DEPLACÉ dossier*: C:\ProgramData\Host App Service =>.SUP.SweetLabs DEPLACÉ dossier*: C:\Users\BS\AppData\Roaming\Microsoft\Windows\Start Menu\ByteFence =>.SUP.ByteFence DEPLACÉ dossier^: C:\Users\BS\AppData\Local\Host App Service =>.SUP.SweetLabs DEPLACÉ dossier*: C:\Users\Default\AppData\Local\Host App Service =>.SUP.SweetLabs DEPLACÉ dossier: C:\Users\Default User\AppData\Local\Host App Service =>.SUP.SweetLabs DEPLACÉ dossier*: C:\Users\defaultuser0\AppData\Local\Host App Service =>.SUP.SweetLabs DEPLACÉ dossier*: C:\Program Files (x86)\Common Files\IObit\Advanced SystemCare =>.SUP.AdvancedSystemCare DEPLACÉ dossier*: C:\ProgramData\Application Data\IObit\ASCDownloader =>.SUP.AdvancedSystemCare DEPLACÉ dossier: C:\ProgramData\IObit\ASCDownloader =>.SUP.AdvancedSystemCare DEPLACÉ dossier*: C:\Users\BS\AppData\Roaming\IObit\Advanced SystemCare =>.SUP.AdvancedSystemCare DEPLACÉ dossier*: C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Roaming\IObit\Advanced SystemCare =>.SUP.AdvancedSystemCare ---\\ Base de Registres ( Clés, Valeurs, Données ). (30) SUPPRIMÉ donnée: HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{60fe6215-4518-4d5d-846f-ff1a4cd4275c}\\DhcpNameServer [Bad : 150.203.1.2] =>Hijacker.Browser SUPPRIMÉ clé*: HKLM\SYSTEM\CurrentControlSet\Services\ByteFenceService [C:\Program Files\ByteFence\ByteFenceService.exe (Not File)] =>.SUP.ByteFence SUPPRIMÉ clé*: HKLM\SYSTEM\CurrentControlSet\Services\rtop [C:\Program Files\ByteFence\rtop\bin\rtop_svc.exe] =>.SUP.ByteFence SUPPRIMÉ clé*: HKEY_USERS\S-1-5-21-3795497416-2115614967-1374131030-1001\SOFTWARE\ByteFence [] =>.SUP.ByteFence SUPPRIMÉ clé*: HKEY_USERS\S-1-5-21-3795497416-2115614967-1374131030-1001\SOFTWARE\Conduit [] =>.SUP.Conduit SUPPRIMÉ clé*: HKEY_USERS\S-1-5-21-3795497416-2115614967-1374131030-1001\SOFTWARE\Host App Service [] =>.SUP.SweetLabs SUPPRIMÉ clé*: HKEY_USERS\.DEFAULT\Software\ByteFence [] =>.SUP.ByteFence SUPPRIMÉ clé: HKCU\Software\ByteFence [] =>.SUP.ByteFence SUPPRIMÉ clé: HKCU\Software\Conduit [] =>.SUP.Conduit SUPPRIMÉ clé: HKCU\Software\Host App Service [] =>.SUP.SweetLabs SUPPRIMÉ clé*: HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Host App Service [SweetLabs for Lenovo] =>.SUP.SweetLabs SUPPRIMÉ clé*: HKCU\Software\csastats [] =>Adware.InstallCore SUPPRIMÉ clé*: HKCU\Software\undefined [] =>.SUP.Downloader SUPPRIMÉ clé*: HKCU\Software\ProductSetup [] =>Adware.InstallCore SUPPRIMÉ clé*: HKLM\SOFTWARE\Iobit\ASC [] =>.SUP.AdvancedSystemCare SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\AppID\NCTAudioCompress3.DLL [] =>PUP.Optional.BearShare SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\AppID\NCTAudioFile3.DLL [] =>PUP.Optional.BearShare SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\AppID\NCTAudioFileWMA3.DLL [] =>PUP.Optional.BearShare SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\AppID\NCTAudioFormatSettings3.DLL [] =>PUP.Optional.BearShare SUPPRIMÉ clé*: HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\ByteFenceService [] =>.SUP.ByteFence SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\ByteFence [] =>.SUP.ByteFence SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Microsoft\Tracing\ByteFence_RASAPI32 [] =>.SUP.ByteFence SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Microsoft\Tracing\ByteFence_RASMANCS [] =>.SUP.ByteFence SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\ByteFence [] =>.SUP.ByteFence SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Conduit [] =>.SUP.Conduit SUPPRIMÉ clé: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\AppID\NCTAudioCompress3.DLL [] =>PUP.Optional.BearShare SUPPRIMÉ clé: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\AppID\NCTAudioFile3.DLL [] =>PUP.Optional.BearShare SUPPRIMÉ clé: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\AppID\NCTAudioFileWMA3.DLL [] =>PUP.Optional.BearShare SUPPRIMÉ clé: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\AppID\NCTAudioFormatSettings3.DLL [] =>PUP.Optional.BearShare SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ByteFence [Byte Technologies LLC] =>.SUP.ByteFence ---\\ Récapitulatif des éléments trouvés sur votre station. (11) https://nicolascoolman.eu/2017/03/13/superfluous-bytefence/ =>.SUP.ByteFence https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.SUP.SweetLabs https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>Adware.YahooPowered https://nicolascoolman.eu/2017/03/12/superfluous-lavasoftwebcompanion/ =>PUP.Optional.LavasoftWebCompanion https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.SUP.VidAdBlock https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.SUP.AdvancedSystemCare https://nicolascoolman.eu/2017/02/02/hijacker-browser-2/ =>Hijacker.Browser https://nicolascoolman.eu/2017/02/06/superfluous-conduit/ =>.SUP.Conduit https://nicolascoolman.eu/2017/03/12/adware-installcore-2/ =>Adware.InstallCore https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.SUP.Downloader https://www.nicolascoolman.com/fr/pup-bearshare/ =>PUP.Optional.BearShare ---\\ Nettoyage Additionnel. (28) ~ Suppression des Clés de registre Tracing. (28) ~ Suppression des anciens rapports ZHPCleaner. (0) ---\\ Bilan de la réparation ~ Réparation réalisée avec succès. ~ Ce navigateur est absent (Google Chrome) ~ Ce navigateur est absent (Opera Software) ~ Le système a été redémarré. ---\\ Statistiques ~ Items scannés : 2082 ~ Items trouvés : 0 ~ Items annulés : 0 ~ Items réparés : 59 ~ End of clean in 00h02mn56s ~==================== ZHPCleaner-[R]-19082017-20_37_32.txt ZHPCleaner-[S]-19082017-20_12_51.txt ZHPCleaner-[S]-19082017-20_34_16.txt