~ ZHPCleaner v2014.12.9.251 by Nicolas Coolman (09/12/2014) ~ Run by Dominique PORTMANN (Administrator) (10/12/2014 23:47:01) ~ Forum : http://forum.nicolascoolman.fr ~ Facebook : https://www.facebook.com/nicolascoolman1 ~ State version : Version OK ~ Type : Réparer ~ Report : H:\Documents and Settings\Dominique PORTMANN\Bureau\ZHPCleaner.txt ~ Quarantine : H:\Documents and Settings\Dominique PORTMANN\Application Data\ZHP\ZHPCleaner_Quarantine.txt ~ UAC : Deactivate ~ Windows XP, 32-bit Service Pack 3 (Build 2600) ---\\ Service. (0) ~ Aucun élément malicieux trouvé. ---\\ Navigateur internet. (7) REMPLACÉ Proxy: ProxyHttp1.1 ( 1 ) REMPLACÉ Proxy: ProxyOverride ( ) REMPLACÉ Proxy: ProxyHttp1.1 ( 1 ) REMPLACÉ IE Params: Tabs ( about:newtab ) REMPLACÉ Firefox: [34ptqylg.default-1395091837240] URL HomePage : hxxp://www.google.fr REMPLACÉ: [34ptqylg.default-1395091837240] - user_pref("browser.search.order.1", "Microsoft (Bing)"); (PUP.Babylon) REMPLACÉ: [34ptqylg.default-1395091837240] - user_pref("extensions.crossrider.bic", "14a309fb250d2da8622005ba22696667"); (PUP.CrossRider) ---\\ Fichier hôte. (1) ~ Le fichier hôte est légitime. (20) ---\\ Tâche planifiée. (0) ~ Aucun élément malicieux trouvé. ---\\ Explorateur ( Dossiers, Fichiers ). (21) DEPLACÉ dossier: H:\Program Files\ca6fecac-b5fc-4455-a064-6f984cfd8f95 (PUP.CrossRider) DEPLACÉ: H:\Program Files\RocketPDF (PUP.RockTurner) DEPLACÉ: H:\Program Files\RocketPDF\RocketPDF.exe [ - ] (PUP.RockTurner) DEPLACÉ: H:\Documents and Settings\All Users\Application Data\InstaShare (PUP.InstaShare) DEPLACÉ: H:\Documents and Settings\All Users\Application Data\InstaShare\InstaShare.ico [ - ] (PUP.InstaShare) DEPLACÉ: H:\Documents and Settings\All Users\Application Data\InstaShare\uninstall.exe.config [ - ] (PUP.InstaShare) DEPLACÉ: H:\Documents and Settings\All Users\Application Data\InstaShare\up [ - ] (PUP.InstaShare) DEPLACÉ: H:\Documents and Settings\All Users\Documents\ShopperPro (PUP.ShopperPro) DEPLACÉ: H:\Documents and Settings\All Users\Documents\ShopperPro\JsDriver [ - ] (PUP.ShopperPro) DEPLACÉ: H:\Documents and Settings\Dominique PORTMANN\Application Data\RocketPDF (PUP.RockTurner) DEPLACÉ: H:\Documents and Settings\Dominique PORTMANN\Application Data\RocketPDF\sumatrapdfcache [ - ] (PUP.RockTurner) DEPLACÉ: H:\Documents and Settings\Dominique PORTMANN\Application Data\RocketPDF\sumatrapdfprefs.dat [ - ] (PUP.RockTurner) DEPLACÉ: H:\DOCUME~1\DOMINI~1\LOCALS~1\Temp\comh.149666\goopdate.dll [globalUpdate] (PUP.GlobalUpdate) DEPLACÉ: H:\DOCUME~1\DOMINI~1\LOCALS~1\Temp\comh.149666\goopdateres_en.dll [globalUpdate] (PUP.GlobalUpdate) DEPLACÉ: H:\DOCUME~1\DOMINI~1\LOCALS~1\Temp\comh.149666\npGoogleUpdate4.dll [globalUpdate] (PUP.GlobalUpdate) DEPLACÉ: H:\DOCUME~1\DOMINI~1\LOCALS~1\Temp\comh.149666\psmachine.dll [globalUpdate] (PUP.GlobalUpdate) DEPLACÉ: H:\DOCUME~1\DOMINI~1\LOCALS~1\Temp\comh.149666\psuser.dll [globalUpdate] (PUP.GlobalUpdate) DEPLACÉ: H:\DOCUME~1\DOMINI~1\LOCALS~1\Temp\comh.149666\GoogleCrashHandler.exe [globalUpdate] (PUP.GlobalUpdate) DEPLACÉ: H:\DOCUME~1\DOMINI~1\LOCALS~1\Temp\comh.149666\GoogleUpdate.exe [globalUpdate] (PUP.GlobalUpdate) DEPLACÉ: H:\DOCUME~1\DOMINI~1\LOCALS~1\Temp\comh.149666\GoogleUpdateBroker.exe [globalUpdate] (PUP.GlobalUpdate) DEPLACÉ: H:\DOCUME~1\DOMINI~1\LOCALS~1\Temp\comh.149666\GoogleUpdateOnDemand.exe [globalUpdate] (PUP.GlobalUpdate) ---\\ Base de Registres ( Clés, Valeurs, Données ). (13) SUPPRIMÉ: HKEY_CLASSES_ROOT\JSFile\Shell\Open\Command\JSFile\Shell\Open\Command\\JSFile [Bad : %SystemRoot%\System32\WScript.exe "%1" %*] (Broken.OpenCommand) SUPPRIMÉ: HKCU\SOFTWARE\SearchProtectWS (PUP.SearchProtect) SUPPRIMÉ: HKLM\SOFTWARE\f4929f7e-f998-4bff-9481-312016fa5e98 (PUP.CrossRider) SUPPRIMÉ: HKCR\TypeLib\{1A1BD1A4-DE07-441E-8EAF-880C7FDF7683} [glindorusIEClientLib] (PUP.Glindorus) SUPPRIMÉ: HKCU\Software\Ge-Force-nv (PUP.CrossRider) SUPPRIMÉ: HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Update glindorus (PUP.Glindorus) SUPPRIMÉ: HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Update Mega Browse (PUP.MegaBrowse) SUPPRIMÉ: HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Util Mega Browse (PUP.MegaBrowse) SUPPRIMÉ: HKLM\SOFTWARE\Ge-Force (PUP.CrossRider) SUPPRIMÉ: HKLM\SOFTWARE\Ge-Force-nv (PUP.CrossRider) SUPPRIMÉ: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Ge-Force (PUP.CrossRider) SUPPRIMÉ: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\bearsharemusicboxtoolbar181FF (PUP.BearShare) SUPPRIMÉ: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ilividmoviestoolbar20IE (Adware.Bandoo) ---\\ Bilan de la réparation ~ Réparation réalisée avec succès. ~ Ce navigateur est absent (Opera Software) End of clean at 23:59:00