~ ZHPCleaner v2017.2.24.35 by Nicolas Coolman (2017/02/24) ~ Run by llagu (Administrator) (25/04/2017 13:00:41) ~ Web: https://www.nicolascoolman.com ~ Blog: https://nicolascoolman.eu/ ~ Facebook : https://www.facebook.com/nicolascoolman1 ~ State version : Version OK ~ Type : Nettoyer ~ Report : C:\Users\llagu\Desktop\ZHPCleaner.txt ~ Quarantine : C:\Users\llagu\AppData\Roaming\ZHP\ZHPCleaner_Quarantine.txt ~ UAC : Activate ~ Boot Mode : Normal (Normal boot) Windows 10 Home, 64-bit (Build 14393) ---\\ Service. (0) ~ Aucun élément malicieux ou superflu trouvé. ---\\ Navigateur internet. (0) ---\\ Fichier hôte. (2) REMPLACÉ: 0.0.0.1 mssplus.mcafee.com ~ Nombre de redirections trouvées 1/29 ---\\ Tâche planifiée. (0) ~ Aucun élément malicieux ou superflu trouvé. ---\\ Explorateur ( Dossiers, Fichiers ). (44) DEPLACÉ fichier: C:\Users\llagu\AppData\Roaming\Mozilla\Firefox\Profiles\yj9d8ca5.default\searchplugins\yahoo! powered.xml =>Adware.YahooPowered DEPLACÉ fichier: C:\Windows\Prefetch\BYTEFENCE.EXE-FAC31F78.pf =>.Superfluous.ByteFence DEPLACÉ fichier: C:\Windows\Prefetch\BYTEFENCESERVICE.EXE-4186E33D.pf =>.Superfluous.ByteFence DEPLACÉ fichier: C:\Windows\Installer\wix{7D84E343-A23D-451C-B123-0195B2D903A6}.SchedServiceConfig.rmi =>.Superfluous.Empty DEPLACÉ fichier: C:\Users\llagu\AppData\Local\Temp\wct101D.tmp =>.Superfluous.Temporary.Various DEPLACÉ fichier: C:\Users\llagu\AppData\Local\Temp\wct1782.tmp =>.Superfluous.Temporary.Various DEPLACÉ fichier: C:\Users\llagu\AppData\Local\Temp\wct1B6F.tmp =>.Superfluous.Temporary.Various DEPLACÉ fichier: C:\Users\llagu\AppData\Local\Temp\wct314D.tmp =>.Superfluous.Temporary.Various DEPLACÉ fichier: C:\Users\llagu\AppData\Local\Temp\wct31E5.tmp =>.Superfluous.Temporary.Various DEPLACÉ fichier: C:\Users\llagu\AppData\Local\Temp\wct55B3.tmp =>.Superfluous.Temporary.Various DEPLACÉ fichier: C:\Users\llagu\AppData\Local\Temp\wct65FA.tmp =>.Superfluous.Temporary.Various DEPLACÉ fichier: C:\Users\llagu\AppData\Local\Temp\wct7325.tmp =>.Superfluous.Temporary.Various DEPLACÉ fichier: C:\Users\llagu\AppData\Local\Temp\wct7BC8.tmp =>.Superfluous.Temporary.Various DEPLACÉ fichier: C:\Users\llagu\AppData\Local\Temp\wct8508.tmp =>.Superfluous.Temporary.Various DEPLACÉ fichier: C:\Users\llagu\AppData\Local\Temp\wct9308.tmp =>.Superfluous.Temporary.Various DEPLACÉ fichier: C:\Users\llagu\AppData\Local\Temp\wctAB47.tmp =>.Superfluous.Temporary.Various DEPLACÉ fichier: C:\Users\llagu\AppData\Local\Temp\wctB6BB.tmp =>.Superfluous.Temporary.Various DEPLACÉ fichier: C:\Users\llagu\AppData\Local\Temp\wctB6FC.tmp =>.Superfluous.Temporary.Various DEPLACÉ fichier: C:\Users\llagu\AppData\Local\Temp\wctD384.tmp =>.Superfluous.Temporary.Various DEPLACÉ fichier: C:\Users\llagu\AppData\Local\Temp\wctDF74.tmp =>.Superfluous.Temporary.Various DEPLACÉ fichier: C:\Users\llagu\AppData\Local\Temp\wctEB27.tmp =>.Superfluous.Temporary.Various DEPLACÉ fichier: C:\Users\llagu\AppData\Local\Temp\wctEEC4.tmp =>.Superfluous.Temporary.Various DEPLACÉ fichier: C:\Users\llagu\AppData\Local\Temp\wctF82C.tmp =>.Superfluous.Temporary.Various DEPLACÉ fichier: C:\WINDOWS\System32\log\iSafeKrnlCall.log =>.Superfluous.YetAnotherCleaner DEPLACÉ fichier: C:\WINDOWS\System32\Drivers\iSafeNetFilter.sys [Elex do Brasil Participações Ltda - iSafeNetFilter SDK WFP Driver (WPP)] =>.Superfluous.YetAnotherCleaner DEPLACÉ fichier: C:\WINDOWS\System32\Drivers\iSafeKrnlBoot.sys [Elex do Brasil Participações Ltda - iSafe Kernel Boot Driver] =>.Superfluous.YetAnotherCleaner DEPLACÉ dossier: C:\Users\llagu\AppData\Local\Temp\PremierOpinion =>Adware.PremierOpinion DEPLACÉ dossier: C:\WINDOWS\Installer\MSI307F.tmp- =>.Superfluous.Empty DEPLACÉ dossier: C:\WINDOWS\Installer\MSI341A.tmp- =>.Superfluous.Empty DEPLACÉ dossier: C:\WINDOWS\Installer\MSI34B7.tmp- =>.Superfluous.Empty DEPLACÉ dossier: C:\WINDOWS\Installer\MSI411.tmp- =>.Superfluous.Empty DEPLACÉ dossier: C:\WINDOWS\Installer\MSI48CE.tmp- =>.Superfluous.Empty DEPLACÉ dossier: C:\WINDOWS\Installer\MSI499B.tmp- =>.Superfluous.Empty DEPLACÉ dossier: C:\WINDOWS\Installer\MSI4A86.tmp- =>.Superfluous.Empty DEPLACÉ dossier: C:\WINDOWS\Installer\MSI66C7.tmp- =>.Superfluous.Empty DEPLACÉ dossier: C:\WINDOWS\Installer\MSI6C41.tmp- =>.Superfluous.Empty DEPLACÉ dossier: C:\WINDOWS\Installer\MSI7A91.tmp- =>.Superfluous.Empty DEPLACÉ dossier: C:\WINDOWS\Installer\MSIAA75.tmp- =>.Superfluous.Empty DEPLACÉ dossier: C:\WINDOWS\Installer\MSIC31.tmp- =>.Superfluous.Empty DEPLACÉ dossier: C:\WINDOWS\Installer\MSIC8C5.tmp- =>.Superfluous.Empty DEPLACÉ dossier: C:\WINDOWS\Installer\MSICC23.tmp- =>.Superfluous.Empty DEPLACÉ dossier: C:\WINDOWS\Installer\MSIF8D2.tmp- =>.Superfluous.Empty DEPLACÉ dossier: C:\WINDOWS\Installer\MSIF9AE.tmp- =>.Superfluous.Empty DEPLACÉ dossier: C:\WINDOWS\Installer\MSIFA4A.tmp- =>.Superfluous.Empty ---\\ Base de Registres ( Clés, Valeurs, Données ). (19) SUPPRIMÉ clé: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2211d4a5-48d0-47f5-a7cd-81e861470f7f} [https://fr.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_frmr_17_12¶[...]] [Yahoo! Powered] =>Adware.YahooPowered SUPPRIMÉ clé: [X64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [https://fr.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_frmr_17_12¶[...]] [Yahoo! Powered] =>Adware.YahooPowered SUPPRIMÉ clé: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [https://fr.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_frmr_17_12¶[...]] [Yahoo! Powered] =>Adware.YahooPowered SUPPRIMÉ clé: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2211d4a5-48d0-47f5-a7cd-81e861470f7f} [https://fr.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_frmr_17_12¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dfr%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1Qzu0AyEtB0B0BtD0B0Czy0EtByBtBtByByDtN0D0Tzu0StCzytCtDtN1L2XzutAtFtBzytFtAtFyDtBtN1L1Czu1StN1L1G1B1V1N2Y1L1Qzu2SyBtAyE0EyD0B0EtAtGtC0D0EyCtG0CtDyCyBtGtBtDtAzztGtAtCyCzzyC0D0D0BtC0BtD0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyDyD0B0BtA0F0AtBtGzztCyCyDtGyEzyyCyBtG0A0D0E0AtGzzzztDtByDzyyDtC0Bzy0F0F2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtByDtDzy%26cr%3D1041629909%26a%3Dwbf_frmr_17_12%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms}] =>Adware.YahooPowered SUPPRIMÉ clé: [X64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [https://fr.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_frmr_17_12¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dfr%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1Qzu0AyEtB0B0BtD0B0Czy0EtByBtBtByByDtN0D0Tzu0StCzytCtDtN1L2XzutAtFtBzytFtAtFyDtBtN1L1Czu1StN1L1G1B1V1N2Y1L1Qzu2SyBtAyE0EyD0B0EtAtGtC0D0EyCtG0CtDyCyBtGtBtDtAzztGtAtCyCzzyC0D0D0BtC0BtD0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyDyD0B0BtA0F0AtBtGzztCyCyDtGyEzyyCyBtG0A0D0E0AtGzzzztDtByDzyyDtC0Bzy0F0F2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtByDtDzy%26cr%3D1041629909%26a%3Dwbf_frmr_17_12%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms}] =>Adware.YahooPowered SUPPRIMÉ clé: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [https://fr.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_frmr_17_12¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dfr%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1Qzu0AyEtB0B0BtD0B0Czy0EtByBtBtByByDtN0D0Tzu0StCzytCtDtN1L2XzutAtFtBzytFtAtFyDtBtN1L1Czu1StN1L1G1B1V1N2Y1L1Qzu2SyBtAyE0EyD0B0EtAtGtC0D0EyCtG0CtDyCyBtGtBtDtAzztGtAtCyCzzyC0D0D0BtC0BtD0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyDyD0B0BtA0F0AtBtGzztCyCyDtGyEzyyCyBtG0A0D0E0AtGzzzztDtByDzyyDtC0Bzy0F0F2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtByDtDzy%26cr%3D1041629909%26a%3Dwbf_frmr_17_12%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms}] =>Adware.YahooPowered SUPPRIMÉ clé*: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\atwola.com [] =>.Superfluous.Atwola SUPPRIMÉ clé*: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\ol.uk.at.atwola.com [] =>.Superfluous.Atwola SUPPRIMÉ clé*: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\atwola.com [] =>.Superfluous.Atwola SUPPRIMÉ clé*: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\ol.uk.at.atwola.com [123] =>.Superfluous.Atwola SUPPRIMÉ clé*: HKCU\Software\csastats [] =>Adware.InstallCore SUPPRIMÉ clé*: HKCU\Software\ProductSetup [] =>Adware.InstallCore SUPPRIMÉ clé*: HKLM\SOFTWARE\Wow6432Node\Firefox [] =>Adware.GhokswaBrowser SUPPRIMÉ clé: HKLM\SOFTWARE\Firefox [] =>Adware.GhokswaBrowser SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Microsoft\Tracing\ByteFence_RASAPI32 [] =>.Superfluous.ByteFence SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Microsoft\Tracing\ByteFence_RASMANCS [] =>.Superfluous.ByteFence SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} [Google Inc.] =>Heuristic.Suspect SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\bytefenceupdater-csb_RASAPI32 [] =>.Superfluous.ByteFence SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\bytefenceupdater-csb_RASMANCS [] =>.Superfluous.ByteFence ---\\ Récapitulatif des éléments trouvés sur votre station. (10) https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>Adware.YahooPowered https://www.anti-malware.top/2016/04/29/superfluous-bytefence/ =>.Superfluous.ByteFence https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.Superfluous.Empty https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.Superfluous.Temporary.Various https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.Superfluous.YetAnotherCleaner https://www.anti-malware.top/2016/06/13/adware-premieropinion/ =>Adware.PremierOpinion https://nicolascoolman.eu/2017/02/04/superfluous-atwola/ =>.Superfluous.Atwola https://www.anti-malware.top/2016/04/22/adware-installcore/ =>Adware.InstallCore https://nicolascoolman.eu/2017/02/19/adware-ghokswabrowser/ =>Adware.GhokswaBrowser https://nicolascoolman.eu/2017/01/28/heuristic-suspect/ =>Heuristic.Suspect ---\\ Nettoyage Additionnel. (32) ~ Suppression des Clés de registre Tracing. (32) ~ Suppression des anciens rapports ZHPCleaner. (0) ---\\ Bilan de la réparation ~ Réparation réalisée avec succès. ~ Ce navigateur est absent (Opera Software) ---\\ Statistiques ~ Items scannés : 735 ~ Items trouvés : 1 ~ Items annulés : 0 ~ Items réparés : 63 ~ End of clean in 00h00mn26s ~==================== ZHPCleaner-[R]-25042017-13_01_07.txt ZHPCleaner-[S]-25042017-12_59_17.txt