~ ZHPCleaner v2017.5.14.81 by Nicolas Coolman (2017/05/14) ~ Run by joseph (Administrator) (18/05/2017 16:49:23) ~ Web: https://www.nicolascoolman.com ~ Blog: https://nicolascoolman.eu/ ~ Facebook : https://www.facebook.com/nicolascoolman1 ~ State version : Version OK ~ Type : Nettoyer ~ Report : C:\Users\joseph\Desktop\ZHPCleaner.txt ~ Quarantine : C:\Users\joseph\AppData\Roaming\ZHP\ZHPCleaner_Reg.txt ~ UAC : Activate ~ Boot Mode : Normal (Normal boot) Windows 10 Home, 64-bit (Build 14393) ---\\ Service. (0) ~ Aucun élément malicieux ou superflu trouvé. ---\\ Navigateur internet. (36) SUPPRIMÉ: [9qx4uz5s.default] - user_pref("extensions.DigiHelp.asul", "1418114972913"); =>PUP.Optional.DigiHelp SUPPRIMÉ: [9qx4uz5s.default] - user_pref("extensions.DigiHelp.aul", "1418026900392"); =>PUP.Optional.DigiHelp SUPPRIMÉ: [9qx4uz5s.default] - user_pref("extensions.DigiHelp.irl", true); =>PUP.Optional.DigiHelp SUPPRIMÉ: [9qx4uz5s.default] - user_pref("extensions.DigiHelp.is", "isgiwhFR"); =>PUP.Optional.DigiHelp SUPPRIMÉ: [9qx4uz5s.default] - user_pref("extensions.DigiHelp.ug", "0EA9166E-5868-4C9E-A29F-F84291B4A569"); =>PUP.Optional.DigiHelp SUPPRIMÉ: [9qx4uz5s.default] - user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.72893.internaldb.moneti[...] =>PUP.Optional.Monetization SUPPRIMÉ: [9qx4uz5s.default] - user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.72893.name", "CinemaPlu[...] =>Adware.CrossRider SUPPRIMÉ: [9qx4uz5s.default] - user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.72893.publisher", "Cine[...] =>Adware.CrossRider SUPPRIMÉ: [9qx4uz5s.default] - user_pref("extensions.srchvstrn.AL", 2); =>PUP.Optional.Vosteran SUPPRIMÉ: [9qx4uz5s.default] - user_pref("extensions.srchvstrn.aflt", "vst_ir_14_51_other"); =>PUP.Optional.Vosteran SUPPRIMÉ: [9qx4uz5s.default] - user_pref("extensions.srchvstrn.appId", "{4CB3598A-82E8-4D1F-983F-061238AE696E}"); =>PUP.Optional.Vosteran SUPPRIMÉ: [9qx4uz5s.default] - user_pref("extensions.srchvstrn.cd", "2XzuyEtN2Y1L1Qzu0Bzz0E0EyCyD0CtCyC0F0AyEyDtBtAzytN0D0Tzu0StCtD[...] =>PUP.Optional.Vosteran SUPPRIMÉ: [9qx4uz5s.default] - user_pref("extensions.srchvstrn.cr", "348316094"); =>PUP.Optional.Vosteran SUPPRIMÉ: [9qx4uz5s.default] - user_pref("extensions.srchvstrn.data.1475e97c0146bfb1c490339546d9e72ee", "1"); =>PUP.Optional.Vosteran SUPPRIMÉ: [9qx4uz5s.default] - user_pref("extensions.srchvstrn.data._dy", "20141118"); =>PUP.Optional.Vosteran SUPPRIMÉ: [9qx4uz5s.default] - user_pref("extensions.srchvstrn.data.a._dy", "20141118"); =>PUP.Optional.Vosteran SUPPRIMÉ: [9qx4uz5s.default] - user_pref("extensions.srchvstrn.data.a.aliveDate", "20141118"); =>PUP.Optional.Vosteran SUPPRIMÉ: [9qx4uz5s.default] - user_pref("extensions.srchvstrn.data.a.instlDate", "20141118"); =>PUP.Optional.Vosteran SUPPRIMÉ: [9qx4uz5s.default] - user_pref("extensions.srchvstrn.data.cc", "fr"); =>PUP.Optional.Vosteran SUPPRIMÉ: [9qx4uz5s.default] - user_pref("extensions.srchvstrn.data.ccfc1eb13092ea34473c169417eefd00", "1"); =>PUP.Optional.Vosteran SUPPRIMÉ: [9qx4uz5s.default] - user_pref("extensions.srchvstrn.dfltLng", ""); =>PUP.Optional.Vosteran SUPPRIMÉ: [9qx4uz5s.default] - user_pref("extensions.srchvstrn.dfltSrch", true); =>PUP.Optional.Vosteran SUPPRIMÉ: [9qx4uz5s.default] - user_pref("extensions.srchvstrn.dnsErr", true); =>PUP.Optional.Vosteran SUPPRIMÉ: [9qx4uz5s.default] - user_pref("extensions.srchvstrn.excTlbr", false); =>PUP.Optional.Vosteran SUPPRIMÉ: [9qx4uz5s.default] - user_pref("extensions.srchvstrn.general.guid", "d65851e2-8cf3-41c4-a00a-033964a5bb60"); =>PUP.Optional.Vosteran SUPPRIMÉ: [9qx4uz5s.default] - user_pref("extensions.srchvstrn.hmpg", true); =>PUP.Optional.Vosteran SUPPRIMÉ: [9qx4uz5s.default] - user_pref("extensions.srchvstrn.id", "B8EE65C16FA45239"); =>PUP.Optional.Vosteran SUPPRIMÉ: [9qx4uz5s.default] - user_pref("extensions.srchvstrn.instlDay", "16422"); =>PUP.Optional.Vosteran SUPPRIMÉ: [9qx4uz5s.default] - user_pref("extensions.srchvstrn.instlRef", "142905_s"); =>PUP.Optional.Vosteran SUPPRIMÉ: [9qx4uz5s.default] - user_pref("extensions.srchvstrn.prdct", "srchvstrn"); =>PUP.Optional.Vosteran SUPPRIMÉ: [9qx4uz5s.default] - user_pref("extensions.srchvstrn.tlbrId", ""); =>PUP.Optional.Vosteran SUPPRIMÉ: [9qx4uz5s.default] - user_pref("extensions.srchvstrn.vrsn", ""); =>PUP.Optional.Vosteran SUPPRIMÉ: [9qx4uz5s.default] - user_pref("extensions.srchvstrn.vrsni", ""); =>PUP.Optional.Vosteran SUPPRIMÉ: [9qx4uz5s.default] - user_pref("extensions.srchvstrn_i.newTab", true); =>PUP.Optional.Vosteran SUPPRIMÉ: [9qx4uz5s.default] - user_pref("extensions.srchvstrn_i.smplGrp", "none"); =>PUP.Optional.Vosteran SUPPRIMÉ: [9qx4uz5s.default] - user_pref("extensions.srchvstrn_i.vrsnTs", "19:37:59"); =>PUP.Optional.Vosteran ---\\ Fichier hôte. (1) ~ Le fichier hôte est légitime. (21) ---\\ Tâche planifiée. (0) ~ Aucun élément malicieux ou superflu trouvé. ---\\ Explorateur ( Dossiers, Fichiers ). (39) DEPLACÉ fichier: C:\Windows\Installer\wix{B5E06417-A4AC-4225-B36E-7E34C91616E7}.SchedServiceConfig.rmi =>.Superfluous.Empty DEPLACÉ fichier: C:\Windows\Installer\wix{C4123106-B685-48E6-B9BD-E4F911841EB4}.SchedServiceConfig.rmi =>.Superfluous.Empty DEPLACÉ fichier: C:\Users\joseph\AppData\Local\Temp\6280.tmp =>.Superfluous.Temporary.Empty DEPLACÉ fichier: C:\Users\joseph\AppData\Local\Temp\6484.tmp =>.Superfluous.Temporary.Empty DEPLACÉ fichier: C:\Users\joseph\AppData\Local\Temp\6522.tmp =>.Superfluous.Temporary.Empty DEPLACÉ fichier: C:\Users\joseph\AppData\Local\Temp\7AA0.tmp =>.Superfluous.Temporary.Empty DEPLACÉ fichier: C:\Users\joseph\AppData\Local\Temp\7BCA.tmp =>.Superfluous.Temporary.Empty DEPLACÉ fichier: C:\Users\joseph\AppData\Local\Temp\7C38.tmp =>.Superfluous.Temporary.Empty DEPLACÉ fichier: C:\Users\joseph\AppData\Local\Temp\CVR102C.tmp.cvr =>.Superfluous.Temporary.Empty DEPLACÉ fichier: C:\Users\joseph\AppData\Local\Temp\CVR18A5.tmp.cvr =>.Superfluous.Temporary.Empty DEPLACÉ fichier: C:\Users\joseph\AppData\Local\Temp\CVR18A6.tmp.cvr =>.Superfluous.Temporary.Empty DEPLACÉ fichier: C:\Users\joseph\AppData\Local\Temp\CVR1CFA.tmp.cvr =>.Superfluous.Temporary.Empty DEPLACÉ fichier: C:\Users\joseph\AppData\Local\Temp\CVR5A04.tmp.cvr =>.Superfluous.Temporary.Empty DEPLACÉ fichier: C:\Users\joseph\AppData\Local\Temp\CVR5D5E.tmp.cvr =>.Superfluous.Temporary.Empty DEPLACÉ fichier: C:\Users\joseph\AppData\Local\Temp\CVR70.tmp.cvr =>.Superfluous.Temporary.Empty DEPLACÉ fichier: C:\Users\joseph\AppData\Local\Temp\CVR7B67.tmp.cvr =>.Superfluous.Temporary.Empty DEPLACÉ fichier: C:\Users\joseph\AppData\Local\Temp\CVR85B7.tmp.cvr =>.Superfluous.Temporary.Empty DEPLACÉ fichier: C:\Users\joseph\AppData\Local\Temp\CVRA893.tmp.cvr =>.Superfluous.Temporary.Empty DEPLACÉ fichier: C:\Users\joseph\AppData\Local\Temp\CVRB998.tmp.cvr =>.Superfluous.Temporary.Empty DEPLACÉ fichier: C:\Users\joseph\AppData\Local\Temp\CVRBA34.tmp.cvr =>.Superfluous.Temporary.Empty DEPLACÉ fichier: C:\Users\joseph\AppData\Local\Temp\CVRDDFA.tmp.cvr =>.Superfluous.Temporary.Empty DEPLACÉ fichier: C:\Users\joseph\AppData\Local\Temp\CVRE5AD.tmp.cvr =>.Superfluous.Temporary.Empty DEPLACÉ fichier: C:\Users\joseph\AppData\Local\Temp\CVREB68.tmp.cvr =>.Superfluous.Temporary.Empty DEPLACÉ fichier: C:\Users\joseph\AppData\Local\Temp\CVRF434.tmp.cvr =>.Superfluous.Temporary.Empty DEPLACÉ fichier: C:\Users\joseph\AppData\Local\Temp\DeleteOnReboot.bat =>.Superfluous.Temporary.Empty DEPLACÉ fichier: C:\Users\joseph\AppData\Local\Temp\JavaDeployReg.log =>.Superfluous.Temporary.Empty DEPLACÉ fichier: C:\Users\joseph\AppData\Local\Temp\NitroOutlookAddin.ini =>.Superfluous.Temporary.Empty DEPLACÉ fichier: C:\Users\joseph\AppData\Local\Temp\sa.B7334264-6338-BD94-1884-4D4217C09133_5__.Public.AppUpdate.dat =>.Superfluous.Temporary DEPLACÉ fichier: C:\Users\joseph\AppData\Local\Temp\Setup Log 2017-05-17 #001.txt =>.Superfluous.Temporary.Empty DEPLACÉ fichier: C:\Users\joseph\AppData\Local\Temp\URL6D2A.tmp =>.Superfluous.Temporary.Empty DEPLACÉ fichier: C:\Users\joseph\AppData\Local\Temp\URL7187.tmp =>.Superfluous.Temporary.Empty DEPLACÉ fichier: C:\Users\joseph\AppData\Local\Temp\URLB739.tmp =>.Superfluous.Temporary.Empty DEPLACÉ fichier: C:\Users\joseph\AppData\Local\Temp\URLBA4F.tmp =>.Superfluous.Temporary.Empty DEPLACÉ fichier: C:\Users\joseph\AppData\Local\Temp\URLCD7E.tmp =>.Superfluous.Temporary.Empty DEPLACÉ fichier: C:\Users\joseph\AppData\Local\Temp\URLE7AD.tmp =>.Superfluous.Temporary.Empty DEPLACÉ fichier^: C:\Users\joseph\AppData\Local\Temp\{5D6C0964-79E6-49C1-804E-ABE9EF71346B}-DropboxClient_26.4.24.exe =>.Superfluous.Temporary.Empty DEPLACÉ fichier: C:\Users\joseph\AppData\Local\Temp\~DF247BC44D6DE1D4CD.TMP =>.Superfluous.Temporary.Empty DEPLACÉ dossier: C:\ProgramData\7c0535b143fc4671b6ebd202fbffe066 =>Adware.CrossRider DEPLACÉ dossier: C:\Users\joseph\AppData\Roaming\HMYGSetting =>Adware.Suspect ---\\ Base de Registres ( Clés, Valeurs, Données ). (8) SUPPRIMÉ clé*: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\chatango.com [] =>PUP.Optional.Chatango SUPPRIMÉ clé*: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\soundcloud.com [] =>PUP.Optional.SoundCloud SUPPRIMÉ clé*: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\chatango.com [] =>PUP.Optional.Chatango SUPPRIMÉ clé*: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\soundcloud.com [] =>PUP.Optional.SoundCloud SUPPRIMÉ clé*: HKCU\Software\WEBAPP [] =>.Superfluous.Downloader SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\f [f] =>PUP.Optional.Funmoods SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56} [secman] =>PUP.Optional.Camec SUPPRIMÉ clé: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56} [secman] =>PUP.Optional.Camec ---\\ Récapitulatif des éléments trouvés sur votre station. (13) https://www.anti-malware.top/2016/05/01/pup-optional-digihelp/ =>PUP.Optional.DigiHelp https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>PUP.Optional.Monetization https://nicolascoolman.eu/2017/03/11/pup-optional-crossrider/ =>Adware.CrossRider https://nicolascoolman.eu/2017/03/01/pup-optional-vosteran/ =>PUP.Optional.Vosteran https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.Superfluous.Empty https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.Superfluous.Temporary.Empty https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.Superfluous.Temporary https://nicolascoolman.eu/2017/03/02/adware-suspect/ =>Adware.Suspect https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>PUP.Optional.Chatango https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>PUP.Optional.SoundCloud https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.Superfluous.Downloader https://www.nicolascoolman.com/fr/pup-funmoods/ =>PUP.Optional.Funmoods https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>PUP.Optional.Camec ---\\ Nettoyage Additionnel. (25) ~ Suppression des Clés de registre Tracing. (25) ~ Suppression des anciens rapports ZHPCleaner. (0) ---\\ Bilan de la réparation ~ Réparation réalisée avec succès. ~ Ce navigateur est absent (Google Chrome) ~ Ce navigateur est absent (Opera Software) ~ Le système a été redémarré. ---\\ Statistiques ~ Items scannés : 1147 ~ Items trouvés : 0 ~ Items annulés : 0 ~ Items réparés : 89 ~ End of clean in 00h00mn29s ~==================== ZHPCleaner-[R]-18052017-16_49_52.txt ZHPCleaner-[S]-17052017-22_05_11.txt ZHPCleaner-[S]-18052017-16_49_08.txt