~ ZHPCleaner v2017.3.15.46 by Nicolas Coolman (2017/03/15) ~ Run by Husen (Administrator) (15/03/2017 19:41:28) ~ Web: https://www.nicolascoolman.com ~ Blog: https://nicolascoolman.eu/ ~ Facebook : https://www.facebook.com/nicolascoolman1 ~ State version : Version OK ~ Type : Repair ~ Report : C:\Users\Husen\Desktop\ZHPCleaner.txt ~ Quarantine : C:\Users\Husen\AppData\Roaming\ZHP\ZHPCleaner_Quarantine.txt ~ UAC : Deactivate ~ Boot Mode : Normal (Normal boot) Windows 7 Ultimate, 32-bit Service Pack 1 (Build 7601) ---\\ Services (0) ~ No malicious or unnecessary items found. ---\\ Browser internet (0) ~ No malicious or unnecessary items found. ---\\ Hosts file (1) ~ The hosts file is legitimate (21) ---\\ Scheduled automatic tasks. (0) ~ No malicious or unnecessary items found. ---\\ Explorer ( File, Folder) (35) MOVED file: C:\Windows\Installer\wix{5CFFD58D-A8EB-439C-B3FD-A8862C886C55}.SchedServiceConfig.rmi =>.Superfluous.Empty MOVED file: C:\Windows\Installer\wix{E1DB0812-2D60-43DB-AE09-6C7027D93B28}.SchedServiceConfig.rmi =>.Superfluous.Empty MOVED file: C:\Users\Husen\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_ciuvo.com_0.localstorage =>PUP.Optional.Ciuvo MOVED file: C:\Users\Husen\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_ciuvo.com_0.localstorage-journal =>PUP.Optional.Ciuvo MOVED file: C:\Windows\Installer\{5245414C-392D-4700-76A7-A758B70C2806}\ToolbarIcon.exe =>PUP.Optional.BrowserTabSearch MOVED folder: C:\Users\Husen\AppData\Roaming\HMYGSetting =>Adware.Suspect MOVED folder: C:\Users\Husen\AppData\Local\Temp\scoped_dir_3492_3803 =>.Superfluous.Temporary.Steam MOVED folder: C:\Users\Husen\AppData\Local\Temp\scoped_dir_3560_21959 =>.Superfluous.Temporary.Steam MOVED folder: C:\Windows\Installer\MSI11FA.tmp- =>.Superfluous.Empty MOVED folder: C:\Windows\Installer\MSI2BA4.tmp- =>.Superfluous.Empty MOVED folder: C:\Windows\Installer\MSI33EA.tmp- =>.Superfluous.Empty MOVED folder: C:\Windows\Installer\MSI36CC.tmp- =>.Superfluous.Empty MOVED folder: C:\Windows\Installer\MSI3AD8.tmp- =>.Superfluous.Empty MOVED folder: C:\Windows\Installer\MSI3D6.tmp- =>.Superfluous.Empty MOVED folder: C:\Windows\Installer\MSI49E5.tmp- =>.Superfluous.Empty MOVED folder: C:\Windows\Installer\MSI5108.tmp- =>.Superfluous.Empty MOVED folder: C:\Windows\Installer\MSI530A.tmp- =>.Superfluous.Empty MOVED folder: C:\Windows\Installer\MSI55E9.tmp- =>.Superfluous.Empty MOVED folder: C:\Windows\Installer\MSI5990.tmp- =>.Superfluous.Empty MOVED folder: C:\Windows\Installer\MSI5F9A.tmp- =>.Superfluous.Empty MOVED folder: C:\Windows\Installer\MSI6531.tmp- =>.Superfluous.Empty MOVED folder: C:\Windows\Installer\MSI723.tmp- =>.Superfluous.Empty MOVED folder: C:\Windows\Installer\MSI7627.tmp- =>.Superfluous.Empty MOVED folder: C:\Windows\Installer\MSI78C7.tmp- =>.Superfluous.Empty MOVED folder: C:\Windows\Installer\MSIBC5.tmp- =>.Superfluous.Empty MOVED folder: C:\Windows\Installer\MSIBFCD.tmp- =>.Superfluous.Empty MOVED folder: C:\Windows\Installer\MSICB72.tmp- =>.Superfluous.Empty MOVED folder: C:\Windows\Installer\MSICC0C.tmp- =>.Superfluous.Empty MOVED folder: C:\Windows\Installer\MSICD00.tmp- =>.Superfluous.Empty MOVED folder: C:\Windows\Installer\MSID428.tmp- =>.Superfluous.Empty MOVED folder: C:\Windows\Installer\MSID4DD.tmp- =>.Superfluous.Empty MOVED folder: C:\Windows\Installer\MSIDB03.tmp- =>.Superfluous.Empty MOVED folder: C:\Windows\Installer\MSIF8D.tmp- =>.Superfluous.Empty MOVED folder: C:\Windows\Installer\MSIFC0B.tmp- =>.Superfluous.Empty MOVED folder: C:\Windows\Installer\MSIFF96.tmp- =>.Superfluous.Empty ---\\ Registry ( Key, Value, Data) (8) DELETED key*: HKLM\SOFTWARE\Classes\esrv.escrtSrvc [escrtSrvc Object] =>PUP.Optional.Facemoods DELETED key*: HKLM\SOFTWARE\Classes\esrv.escrtSrvc.1 [escrtSrvc Object] =>PUP.Optional.Facemoods DELETED key*: HKLM\Software\Classes\Installer\Products\C4145425D2930074677A7A857BC08260 [Search App by Ask] =>PUP.Optional.BrowserTabSearch DELETED key*: HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6978F29A-3493-40B2-8CDC-9C13A02F85A4} [C:\Program Files\AskPartnerNetwork\Toolbar\ (Not File)] =>PUP.Optional.APNToolBar DELETED key*: HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D7949A66-D936-4028-9552-14F7DC50F38D} [C:\Program Files\AskPartnerNetwork\Toolbar\ (Not File)] =>PUP.Optional.APNToolBar DELETED key*: HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FFDF9EF3-3C3A-4f05-9A6E-5D3B778EC567} [C:\Program Files\facemoods.com\facemoods\1.4.17.10 (Not File)] =>PUP.Optional.Facemoods DELETED key*: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\189F6D048E923EA48B11D15B30CDAC81 [C:\Program Files\AskPartnerNetwork\Toolbar\ServiceLocator.exe (Not File)] =>PUP.Optional.APNToolBar DELETED key*: HKLM\Software\Classes\Installer\Features\C4145425D2930074677A7A857BC08260 [] =>PUP.Optional.BrowserTabSearch ---\\ Summary of the elements found (7) https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.Superfluous.Empty https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>PUP.Optional.Ciuvo https://www.nicolascoolman.com/fr/pup-browsertabsearch/ =>PUP.Optional.BrowserTabSearch https://nicolascoolman.eu/2017/03/02/adware-suspect/ =>Adware.Suspect https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.Superfluous.Temporary.Steam https://www.nicolascoolman.com/fr/adware-facemoods/ =>PUP.Optional.Facemoods https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>PUP.Optional.APNToolBar ---\\ Other deletions. (8) ~ Registry Keys Tracing deleted (8) ~ Remove the old reports ZHPCleaner. (0) ---\\ Result of repair ~ Repair carried out successfully ~ Browser not found (Mozilla Firefox) ~ Browser not found (Opera Software) ---\\ Statistics ~ Items scanned : 349 ~ Items found : 0 ~ Items cancelled : 0 ~ Items repaired : 43 ~ End of clean in 00h00mn23s ~==================== ZHPCleaner-[R]-15032017-19_41_51.txt ZHPCleaner-[S]-15032017-19_39_55.txt