cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ ZHPCleaner v2015.6.27.283 by Nicolas Coolman (2015\06\27)
~ Run by toshiba (Administrator) (29/06/2015 16:31:48)
~ Site : http://www.nicolascoolman.fr
~ Facebook : https://www.facebook.com/nicolascoolman1
~ State version : Version KO
~ Type : Repair
~ Report : C:\Users\toshiba\Desktop\ZHPCleaner.txt
~ Quarantine : C:\Users\toshiba\AppData\Roaming\ZHP\ZHPCleaner_Quarantine.txt
~ UAC : Activate
~ Boot Mode : Normal (Normal boot)
~ Windows 8, 64-bit (Build 9200)


---\\ Services (0)
~ No malicious items found.


---\\ Browser internet (4)
DELETED: [q0i2kbcr.default] - user_pref("extensions.toolbar.mindspark._9tMembers_.lastActivePing", "1404881171579"); (Adware.Bandoo)
DELETED: [q0i2kbcr.default] - user_pref("extensions.toolbar.mindspark.hp.enabled", false); (Adware.Bandoo)
DELETED: [q0i2kbcr.default] - user_pref("extensions.toolbar.mindspark.hp.enabled.guid", ""); (Adware.Bandoo)
DELETED: [q0i2kbcr.default] - user_pref("extensions.toolbar.mindspark.lastInstalled", "internetspeedtracker@mindspark.com"); (Adware.Bandoo)


---\\ Hosts file (1)
~ The hosts file is legitimate (21)


---\\ Scheduled automatic tasks. (0)
~ No malicious items found.


---\\ Explorer ( File, Folder) (13)
MOVED file: C:\Users\toshiba\AppData\Local\Temp\Softonic_France_FF\nsb833B.tbSof2.dll [ClientConnect Ltd. - Toolbar] (PUP.ClientConnect)
MOVED file: C:\Users\toshiba\AppData\Local\Temp\Softonic_France_FF\nsg4C8D.tbSof0.dll [ClientConnect Ltd. - Toolbar] (PUP.ClientConnect)
MOVED file: C:\Users\toshiba\AppData\Local\Temp\Softonic_France_FF\nsiF67.tbSof0.dll [ClientConnect Ltd. - Toolbar] (PUP.ClientConnect)
MOVED file: C:\Users\toshiba\AppData\Local\Temp\FFSetupSoftonic270.exe (PUP.Softonic)
MOVED file: C:\Users\toshiba\AppData\Local\Temp\softonic_france_ff.exe [Conduit - Softonic_France_FF Toolbar] (PUP.Softonic)
MOVED folder: C:\Program Files (x86)\FilmFanaticEI (PUP.MindSpark)
MOVED folder: C:\Program Files (x86)\Softonic_France_FF (PUP.Softonic)
MOVED folder: C:\windows\AutoKMS (HackTool.AutoKMS)
MOVED folder: C:\Users\toshiba\AppData\LocalLow\PriceGong (Adware.PriceGong)
MOVED folder: C:\Users\toshiba\AppData\LocalLow\Softonic_France_FF (PUP.Softonic)
MOVED folder: C:\Users\toshiba\AppData\Local\iLivid (Adware.Bandoo)
MOVED folder: C:\Users\toshiba\AppData\Local\Temp\Softonic_France_FF (PUP.Softonic)
MOVED folder: C:\Users\toshiba\AppData\LocalLow\Conduit (PUP.Conduit)


---\\ Registry ( Key, Value, Data) (45)
DELETED key: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{96D2A946-E257-44F7-AE55-11DF69638783} [http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2207610] [Softonic France FF Customized Web Search] (PUP.Softonic)
DELETED data: HKCR\AutoCADScriptFile\Shell\Open\Command\\Default [Bad : [scr] C:\windows\system32\notepad.exe "%1"] (Broken.OpenCommand)
DELETED key*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6d6b212b-2245-4898-8b16-9a11b81ff9e1} [Softonic France FF] (PUP.Softonic)
DELETED key*: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6d6b212b-2245-4898-8b16-9a11b81ff9e1} [] (PUP.Softonic)
DELETED key*: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6d6b212b-2245-4898-8b16-9a11b81ff9e1} [] (PUP.Softonic)
DELETED key*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{6d6b212b-2245-4898-8b16-9a11b81ff9e1} [Softonic France FF Toolbar] (PUP.Softonic)
DELETED key: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{96D2A946-E257-44F7-AE55-11DF69638783} [http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2207610] (PUP.Softonic)
DELETED key*: HKEY_USERS\S-1-5-21-949968091-1234346035-2361368954-1001\Software\Conduit [] (PUP.Conduit)
DELETED key*: HKEY_USERS\S-1-5-21-949968091-1234346035-2361368954-1001\Software\Softonic_France_FF [] (PUP.Softonic)
DELETED key*: HKEY_USERS\S-1-5-21-949968091-1234346035-2361368954-1001\Software\Tbccint_HKLM [] (PUP.Conduit)
DELETED key: HKCU\Software\Conduit [] (PUP.Conduit)
DELETED key: HKCU\Software\Softonic_France_FF [] (PUP.Softonic)
DELETED key: HKCU\Software\Tbccint_HKLM [] (PUP.Conduit)
DELETED key*: HKCU\Software\AppDataLow\Software\Conduit [] (PUP.Conduit)
DELETED key*: HKCU\Software\AppDataLow\Software\ConduitSearchScopes [] (PUP.Conduit)
DELETED key*: HKCU\Software\AppDataLow\Software\PriceGong [] (Adware.PriceGong)
DELETED key*: HKCU\Software\AppDataLow\Software\Smartbar [] (PUP.QuickShare)
DELETED key*: HKCU\Software\AppDataLow\Software\Softonic_France_FF [] (PUP.Softonic)
DELETED key*: HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{31745E4B-C216-4E82-BAA2-CF2DD57E5CB6} [C:\Users\toshiba\AppData\Local\Conduit\CT2207610] (PUP.Conduit)
DELETED key*: HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CACCFB8A-E56F-4883-80ED-4D64179AF81B} [C:\Users\toshiba\AppData\Local\Conduit\CT2207610] (PUP.Conduit)
DELETED key*: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\ask.com [688] (Toolbar.Ask)
DELETED key*: [X64] HKLM\SOFTWARE\Classes\esri3DAnalystUI.DeltaXYZSketch3DMenuItem [esri3DAnalystUI.DeltaXYZSketch3DMenuItem] (Toolbar.DeltaSearch)
DELETED key*: [X64] HKLM\SOFTWARE\Classes\esri3DAnalystUI.DeltaXYZSketch3DMenuItem.1 [esri3DAnalystUI.DeltaXYZSketch3DMenuItem] (Toolbar.DeltaSearch)
DELETED key*: [X64] HKLM\SOFTWARE\Classes\esriArcScan.RasterShapeRecognitionTool [esriArcScan.RasterShapeRecognitionTool] (Adware.CrossRider)
DELETED key*: [X64] HKLM\SOFTWARE\Classes\esriArcScan.RasterShapeRecognitionTool.1 [esriArcScan.RasterShapeRecognitionTool] (Adware.CrossRider)
DELETED key*: [X64] HKLM\SOFTWARE\Classes\esriCadastralUI.DeltaXYConstructionMenuItem [esriCadastralUI.DeltaXYConstructionMenuItem] (Toolbar.DeltaSearch)
DELETED key*: [X64] HKLM\SOFTWARE\Classes\esriCadastralUI.DeltaXYConstructionMenuItem.1 [esriCadastralUI.DeltaXYConstructionMenuItem] (Toolbar.DeltaSearch)
DELETED key*: [X64] HKLM\SOFTWARE\Classes\esriControls.ControlsEditingSketchDeltaXYCommand [esriControls.ControlsEditingSketchDeltaXYCommand] (Toolbar.DeltaSearch)
DELETED key*: [X64] HKLM\SOFTWARE\Classes\esriControls.ControlsEditingSketchDeltaXYCommand.1 [esriControls.ControlsEditingSketchDeltaXYCommand] (Toolbar.DeltaSearch)
DELETED key*: [X64] HKLM\SOFTWARE\Classes\esriGeoDatabaseDistributed.DeltaDataChanges [esriGeoDatabaseDistributed.DeltaDataChanges] (Toolbar.DeltaSearch)
DELETED key*: [X64] HKLM\SOFTWARE\Classes\esriGeoDatabaseDistributed.DeltaDataChanges.1 [esriGeoDatabaseDistributed.DeltaDataChanges] (Toolbar.DeltaSearch)
DELETED key*: [X64] HKLM\SOFTWARE\Classes\esriGeoprocessing.GPCheckInDeltaDatabase [esriGeoprocessing.GPCheckInDeltaDatabase] (Toolbar.DeltaSearch)
DELETED key*: [X64] HKLM\SOFTWARE\Classes\esriGeoprocessing.GPCheckInDeltaDatabase.1 [esriGeoprocessing.GPCheckInDeltaDatabase] (Toolbar.DeltaSearch)
DELETED key*: [X64] HKLM\SOFTWARE\Classes\esriGeoprocessing.GPExportDeltaDatabase [esriGeoprocessing.GPExportDeltaDatabase] (Toolbar.DeltaSearch)
DELETED key*: [X64] HKLM\SOFTWARE\Classes\esriGeoprocessing.GPExportDeltaDatabase.1 [esriGeoprocessing.GPExportDeltaDatabase] (Toolbar.DeltaSearch)
DELETED key*: [X64] HKLM\SOFTWARE\Classes\Toolbar.CT2207610 [] (PUP.Conduit)
DELETED key*: [X64] HKLM\SOFTWARE\Classes\Applications\iLividSetup-r701-n-bf.exe [] (Adware.Bandoo)
DELETED key*: [X64] HKLM\SOFTWARE\Wow6432Node\Conduit [] (PUP.Conduit)
DELETED key*: [X64] HKLM\SOFTWARE\Wow6432Node\FilmFanaticEI [] (Toolbar.Agent)
DELETED key*: [X64] HKLM\SOFTWARE\Wow6432Node\Softonic_France_FF [] (PUP.Softonic)
DELETED key*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5} [ITool] (Toolbar.Ask)
DELETED key*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Softonic France FF Toolbar [] (Adware.FFToolBar)
DELETED key*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Softonic_France_FF Toolbar [Softonic France FF] (Adware.FFToolBar)
DELETED key*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{31745E4B-C216-4E82-BAA2-CF2DD57E5CB6} [C:\Program Files (x86)\Softonic_France_FF (Not File)] (PUP.Softonic)
DELETED key*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CACCFB8A-E56F-4883-80ED-4D64179AF81B} [C:\Users\toshiba\AppData\Local\Conduit\CT2207610] (PUP.Conduit)


---\\ Result of repair
~ Repair carried out successfully
~ Browser not found (Google Chrome)
~ Browser not found (Opera Software)


---\\ Statistics
~ Items scanned : 1101
~ Items found : 0
~ Items cancelled : 0
~ Items repaired : 62


End of clean at 16:33:48
===================
ZHPCleaner-[R]-29062015-16_33_48.txt
ZHPCleaner-[S]-27062015-17_50_09.txt
ZHPCleaner-[S]-29062015-16_31_08.txt

Publicité


Signaler le contenu de ce document

Publicité