cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ ZHPCleaner v2017.3.26.53 by Nicolas Coolman (2017/03/26)
~ Run by J.P Meusureux (Administrator) (27/03/2017 15:40:44)
~ Web: https://www.nicolascoolman.com
~ Blog: https://nicolascoolman.eu/
~ Facebook : https://www.facebook.com/nicolascoolman1
~ State version : Version OK
~ Type : Nettoyer
~ Report : C:\Users\J.P Meusureux\Desktop\ZHPCleaner.txt
~ Quarantine : C:\Users\J.P Meusureux\AppData\Roaming\ZHP\ZHPCleaner_Reg.txt
~ UAC : Activate
~ Boot Mode : Normal (Normal boot)
Windows 10 Home, 64-bit (Build 14393)


---\\ Service. (2)
ARRETÉ : ByteFenceService =>.Superfluous.ByteFence
ARRETÉ : rtop =>.Superfluous.ByteFence


---\\ Navigateur internet. (0)


---\\ Fichier hôte. (0)
~ Aucun élément malicieux ou superflu trouvé.


---\\ Tâche planifiée. (2)
SUPPRIMÉ tâche: [AutoKMS] [C:\Windows\AutoKMS\AutoKMS.exe (Not File) ] =>HackTool.AutoKMS
SUPPRIMÉ tâche: [Yahoo! Powered matem] [C:\WINDOWS\Tasks\Yahoo! Powered matem.job (Not File) ] =>Adware.YahooPowered


---\\ Explorateur ( Dossiers, Fichiers ). (19)
DEPLACÉ fichier: C:\Users\J.P Meusureux\AppData\Roaming\Mozilla\Firefox\Profiles\4mra65cs.default\searchplugins\yahoo! powered.xml =>Adware.YahooPowered
DEPLACÉ fichier: C:\Users\J.P Meusureux\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_nahhmpbckpgdidfnmfkfgiflpjijilce_0.localstorage =>.Superfluous.SearchManager
DEPLACÉ fichier: C:\Windows\AutoKMS\AutoKMS.exe [CODYQX4 & Bosh - AutoKMS] =>HackTool.AutoKMS
DEPLACÉ fichier: C:\Windows\Tasks\AutoKMS.job =>HackTool.AutoKMS
DEPLACÉ fichier: C:\Windows\Tasks\Yahoo! Powered matem.job =>Adware.YahooPowered
DEPLACÉ fichier: C:\Users\J.P Meusureux\AppData\Local\Temp\wctCC5D.tmp =>.Superfluous.Temporary.Various
DEPLACÉ fichier: C:\Users\J.P Meusureux\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_cdncache-a.akamaihd.net_0.localstorage =>.Superfluous.AkamaiHD
DEPLACÉ fichier: C:\Users\J.P Meusureux\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_cdncache-a.akamaihd.net_0.localstorage-journal =>.Superfluous.AkamaiHD
DEPLACÉ fichier: C:\Users\J.P Meusureux\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.audienceinsights.net_0.localstorage =>.Superfluous.AudienceInsights
DEPLACÉ fichier: C:\Users\J.P Meusureux\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.audienceinsights.net_0.localstorage-journal =>.Superfluous.AudienceInsights
DEPLACÉ fichier: C:\Windows\AutoKMS\AutoKMS.log =>HackTool.AutoKMS
DEPLACÉ dossier: C:\Users\J.P Meusureux\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce =>.Superfluous.SearchManager
DEPLACÉ dossier^: C:\Program Files\ByteFence =>.Superfluous.ByteFence
DEPLACÉ dossier^: C:\ProgramData\ByteFence =>.Superfluous.ByteFence
DEPLACÉ dossier: C:\ProgramData\Microleaves =>.Superfluous.Microleaves
DEPLACÉ dossier: C:\WINDOWS\AutoKMS =>HackTool.AutoKMS
DEPLACÉ dossier: C:\Users\J.P Meusureux\AppData\Roaming\Microleaves =>.Superfluous.Microleaves
DEPLACÉ dossier: C:\Users\J.P Meusureux\AppData\Local\Programs\GEN =>.Superfluous.Funfeedr
DEPLACÉ dossier: C:\WINDOWS\Installer\MSIEE9F.tmp- =>.Superfluous.Empty


---\\ Base de Registres ( Clés, Valeurs, Données ). (38)
SUPPRIMÉ clé: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [https://fr.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_frmr_17_12¶[...]] [Yahoo! Powered] =>Adware.YahooPowered
SUPPRIMÉ clé: [X64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [https://fr.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_frmr_17_12¶[...]] [Yahoo! Powered] =>Adware.YahooPowered
SUPPRIMÉ clé: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [https://fr.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_frmr_17_12¶[...]] [Yahoo! Powered] =>Adware.YahooPowered
SUPPRIMÉ clé*: HKCU\SOFTWARE\Google\Chrome\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce [] =>.Superfluous.SearchManager
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Google\Chrome\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce [] =>.Superfluous.SearchManager
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce [] =>.Superfluous.SearchManager
SUPPRIMÉ clé: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [https://fr.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_frmr_17_12¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dfr%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1QzuyCtDyC0D0CyBtAyCtByE0D0A0E0D0AyCtN0D0Tzu0StCzytCtCtN1L2XzutAtFtByBtFyEtFyCtBtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyEyCzy0BtDyCzyyBtGtByCtCtAtGzzzztC0BtGyCyEtDtBtG0AyDzz0CyCyD0DtC0E0F0CtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2Szz0F0C0ByC0Azy0BtGtD0AyEzztGyEtDyDzytGzy0FtA0DtG0BtCyDyEtCzyyDzytDtCyBzy2QtN0A0LzuyE%26cr%3D1754789830%26a%3Dwbf_frmr_17_12%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms}] =>Adware.YahooPowered
SUPPRIMÉ clé: [X64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [https://fr.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_frmr_17_12¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dfr%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1QzuyCtDyC0D0CyBtAyCtByE0D0A0E0D0AyCtN0D0Tzu0StCzytCtCtN1L2XzutAtFtByBtFyEtFyCtBtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyEyCzy0BtDyCzyyBtGtByCtCtAtGzzzztC0BtGyCyEtDtBtG0AyDzz0CyCyD0DtC0E0F0CtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2Szz0F0C0ByC0Azy0BtGtD0AyEzztGyEtDyDzytGzy0FtA0DtG0BtCyDyEtCzyyDzytDtCyBzy2QtN0A0LzuyE%26cr%3D1754789830%26a%3Dwbf_frmr_17_12%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms}] =>Adware.YahooPowered
SUPPRIMÉ clé: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [https://fr.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_frmr_17_12¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dfr%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1QzuyCtDyC0D0CyBtAyCtByE0D0A0E0D0AyCtN0D0Tzu0StCzytCtCtN1L2XzutAtFtByBtFyEtFyCtBtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyEyCzy0BtDyCzyyBtGtByCtCtAtGzzzztC0BtGyCyEtDtBtG0AyDzz0CyCyD0DtC0E0F0CtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2Szz0F0C0ByC0Azy0BtGtD0AyEzztGyEtDyDzytGzy0FtA0DtG0BtCyDyEtCzyyDzytDtCyBzy2QtN0A0LzuyE%26cr%3D1754789830%26a%3Dwbf_frmr_17_12%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms}] =>Adware.YahooPowered
SUPPRIMÉ clé*: HKLM\SYSTEM\CurrentControlSet\Services\ByteFenceService [C:\Program Files\ByteFence\ByteFenceService.exe] =>.Superfluous.ByteFence
SUPPRIMÉ clé*: HKLM\SYSTEM\CurrentControlSet\Services\rtop [C:\Program Files\ByteFence\rtop\bin\rtop_svc.exe] =>.Superfluous.ByteFence
SUPPRIMÉ clé*: HKEY_USERS\S-1-5-21-4140145555-2342484209-1620211677-1000\SOFTWARE\ByteFence [] =>.Superfluous.ByteFence
SUPPRIMÉ clé: HKCU\Software\ByteFence [] =>.Superfluous.ByteFence
SUPPRIMÉ clé*: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\abbyy-finereader.fr.softonic.com [] =>.Superfluous.Softonic
SUPPRIMÉ clé*: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\atwola.com [] =>.Superfluous.Atwola
SUPPRIMÉ clé*: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\ol.uk.at.atwola.com [] =>.Superfluous.Atwola
SUPPRIMÉ clé*: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\softonic.com [] =>.Superfluous.Softonic
SUPPRIMÉ clé*: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\abbyy-finereader.fr.softonic.com [] =>.Superfluous.Softonic
SUPPRIMÉ clé*: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\atwola.com [] =>.Superfluous.Atwola
SUPPRIMÉ clé*: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\ol.uk.at.atwola.com [] =>.Superfluous.Atwola
SUPPRIMÉ clé*: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\softonic.com [] =>.Superfluous.Softonic
SUPPRIMÉ clé*: HKCU\Software\Hotspot [] =>Adware.Eszjuxuan
SUPPRIMÉ clé*: HKCU\Software\csastats [] =>Adware.InstallCore
SUPPRIMÉ clé*: HKCU\Software\ProductSetup [] =>Adware.InstallCore
SUPPRIMÉ clé*: HKLM\SOFTWARE\Hotspot [] =>Adware.Eszjuxuan
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5} [ITool] =>Toolbar.Ask
SUPPRIMÉ clé*: HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\ByteFenceService [] =>.Superfluous.ByteFence
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\ByteFence [] =>.Superfluous.ByteFence
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Conduit [] =>.Superfluous.Conduit
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Microsoft\Tracing\ByteFence_RASAPI32 [] =>.Superfluous.ByteFence
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Microsoft\Tracing\ByteFence_RASMANCS [] =>.Superfluous.ByteFence
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\029AB1D033707234FAD100A0EAB4A227 [C:\Program Files (x86)\Microleaves\Traffic Exchange\Traffic Exchange Updater.exe (Not File)] =>.Superfluous.Microleaves
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E61F5183882B6F45A67D57C3AFF28E1 [C:\Program Files (x86)\Microleaves\Online.io Application\OnlineGuardian-v2.exe (Not File)] =>.Superfluous.Microleaves
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\ByteFence [] =>.Superfluous.ByteFence
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\SlimWare Utilities Inc [] =>.Superfluous.SlimWareUtilities
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ByteFence [Byte Technologies LLC] =>.Superfluous.ByteFence
SUPPRIMÉ clé*: HKCU\SOFTWARE\899E44DF08BDA8B6EB4D8416469D8C11 [] =>Hijacker.Browser
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\899E44DF08BDA8B6EB4D8416469D8C11 [] =>Hijacker.Browser


---\\ Récapitulatif des éléments trouvés sur votre station. (18)
https://nicolascoolman.eu/2017/03/13/superfluous-bytefence/ =>.Superfluous.ByteFence
https://nicolascoolman.eu/2017/02/02/hacktool-autokms/ =>HackTool.AutoKMS
https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>Adware.YahooPowered
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.Superfluous.SearchManager
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.Superfluous.Temporary.Various
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.Superfluous.AkamaiHD
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.Superfluous.AudienceInsights
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.Superfluous.Microleaves
https://www.anti-malware.top/2016/05/05/superfluous-funfeedr/ =>.Superfluous.Funfeedr
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.Superfluous.Empty
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.Superfluous.Softonic
https://nicolascoolman.eu/2017/02/04/superfluous-atwola/ =>.Superfluous.Atwola
https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>Adware.Eszjuxuan
https://nicolascoolman.eu/2017/03/12/adware-installcore-2/ =>Adware.InstallCore
https://nicolascoolman.eu/2017/02/28/toolbar-ask/ =>Toolbar.Ask
https://nicolascoolman.eu/2017/02/06/superfluous-conduit/ =>.Superfluous.Conduit
https://nicolascoolman.eu/2017/03/03/superfluous-slimwareutilities/ =>.Superfluous.SlimWareUtilities
https://nicolascoolman.eu/2017/02/02/hijacker-browser-2/ =>Hijacker.Browser


---\\ Nettoyage Additionnel. (23)
~ Suppression des Clés de registre Tracing. (23)
~ Suppression des anciens rapports ZHPCleaner. (0)


---\\ Bilan de la réparation
~ Réparation réalisée avec succès.
~ Le système a été redémarré.


---\\ Statistiques
~ Items scannés : 835
~ Items trouvés : 0
~ Items annulés : 0
~ Items réparés : 61


~ End of clean in 00h01mn21s
~====================
ZHPCleaner-[R]-27032017-15_42_05.txt
ZHPCleaner-[S]-27032017-15_40_16.txt

Publicité


Signaler le contenu de ce document

Publicité