~ ZHPCleaner v2017.7.17.123 by Nicolas Coolman (2017/07/17) ~ Run by Eric (Administrator) (21/07/2017 17:34:30) ~ Web: https://www.nicolascoolman.com ~ Blog: https://nicolascoolman.eu/ ~ Facebook : https://www.facebook.com/nicolascoolman1 ~ State version : Version OK ~ Certificate ZHPCleaner: Illegal ~ Type : Nettoyer ~ Report : C:\Users\Eric\Desktop\ZHPCleaner.txt ~ Quarantine : C:\Users\Eric\AppData\Roaming\ZHP\ZHPCleaner_Reg.txt ~ UAC : Activate ~ Boot Mode : Normal (Normal boot) Windows VISTA, 32-bit Service Pack 2 (Build 6002) ---\\ Service. (0) ~ Aucun élément malicieux ou superflu trouvé. ---\\ Navigateur internet. (2) SUPPRIMÉ: [g81k9ty4.default] - user_pref("extensions.cacaoweb.firstRun", 0); =>.Superfluous.CacaoWeb REMPLACÉ Google Chrome Preferences: "http://d36s9hlc2vimc.cloudfront.net/" =>.Superfluous.CloudfrontNet ---\\ Fichier hôte. (1) ~ Le fichier hôte est légitime. (20) ---\\ Tâche planifiée. (0) ~ Aucun élément malicieux ou superflu trouvé. ---\\ Explorateur ( Dossiers, Fichiers ). (25) DEPLACÉ fichier^: C:\Users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\g81k9ty4.default\Extensions\cacaoweb@cacaoweb.org\chrome =>.Superfluous.CacaoWeb DEPLACÉ fichier: C:\Users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\g81k9ty4.default\Extensions\cacaoweb@cacaoweb.org\chrome.manifest =>.Superfluous.CacaoWeb DEPLACÉ fichier^: C:\Users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\g81k9ty4.default\Extensions\cacaoweb@cacaoweb.org\defaults =>.Superfluous.CacaoWeb DEPLACÉ fichier: C:\Users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\g81k9ty4.default\Extensions\cacaoweb@cacaoweb.org\install.rdf =>.Superfluous.CacaoWeb DEPLACÉ fichier**: C:\Users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\g81k9ty4.default\extensions\cacaoweb@cacaoweb.org\defaults\preferences\prefs.js =>.Superfluous.CacaoWeb DEPLACÉ fichier**: C:\Users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\g81k9ty4.default\extensions\cacaoweb@cacaoweb.org\chrome\skin\cacaoweb-64.png =>.Superfluous.CacaoWeb DEPLACÉ fichier**: C:\Users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\g81k9ty4.default\extensions\cacaoweb@cacaoweb.org\chrome\skin\cacaoweb.css =>.Superfluous.CacaoWeb DEPLACÉ fichier**: C:\Users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\g81k9ty4.default\extensions\cacaoweb@cacaoweb.org\chrome\skin\cacaoweb.png =>.Superfluous.CacaoWeb DEPLACÉ fichier**: C:\Users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\g81k9ty4.default\extensions\cacaoweb@cacaoweb.org\chrome\locale\fr-FR\cacaoweb.properties =>.Superfluous.CacaoWeb DEPLACÉ fichier**: C:\Users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\g81k9ty4.default\extensions\cacaoweb@cacaoweb.org\chrome\locale\es-ES\cacaoweb.properties =>.Superfluous.CacaoWeb DEPLACÉ fichier**: C:\Users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\g81k9ty4.default\extensions\cacaoweb@cacaoweb.org\chrome\locale\en-US\cacaoweb.properties =>.Superfluous.CacaoWeb DEPLACÉ fichier**: C:\Users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\g81k9ty4.default\extensions\cacaoweb@cacaoweb.org\chrome\locale\de-DE\cacaoweb.properties =>.Superfluous.CacaoWeb DEPLACÉ fichier**: C:\Users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\g81k9ty4.default\extensions\cacaoweb@cacaoweb.org\chrome\content\cacaoweb.js =>.Superfluous.CacaoWeb DEPLACÉ fichier**: C:\Users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\g81k9ty4.default\extensions\cacaoweb@cacaoweb.org\chrome\content\cacaoweb.xul =>.Superfluous.CacaoWeb DEPLACÉ fichier**: C:\Users\Eric\Desktop\cacaoweb.exe =>.Superfluous.CacaoWeb DEPLACÉ fichier**: C:\Users\Eric\Downloads\cacaoweb.exe =>.Superfluous.CacaoWeb DEPLACÉ fichier**: C:\Users\Eric\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_fr.igraal.com_0.localstorage =>Toolbar.Graal DEPLACÉ fichier**: C:\Users\Eric\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_fr.igraal.com_0.localstorage-journal =>Toolbar.Graal DEPLACÉ fichier**: C:\Windows\AutoKMS\AutoKMS.exe [CODYQX4 & Bosh - AutoKMS] =>HackTool.AutoKMS DEPLACÉ fichier**: C:\Windows\AutoKMS\AutoKMS.log =>HackTool.AutoKMS DEPLACÉ fichier**: C:\Users\Eric\AppData\Roaming\cacaoweb\cacaoweb.exe =>.Superfluous.CacaoWeb DEPLACÉ dossier*: C:\Users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\g81k9ty4.default\Extensions\cacaoweb@cacaoweb.org =>.Superfluous.CacaoWeb DEPLACÉ dossier: C:\Program Files\cfFncEnabler.exe =>Heuristic.Salus DEPLACÉ dossier*: C:\Windows\AutoKMS =>HackTool.AutoKMS DEPLACÉ dossier*: C:\Users\Eric\AppData\Roaming\cacaoweb =>.Superfluous.CacaoWeb ---\\ Base de Registres ( Clés, Valeurs, Données ). (42) SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\1916A2AF346D399F50313C393200F14140456616 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\2A83E9020591A55FC6DDAD3FB102794C52B24E70 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\2B84BFBB34EE2EF949FE1CBE30AA026416EB2216 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\305F8BD17AA2CBC483A4C41B19A39A0C75DA39D6 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\367D4B3B4FCBBC0B767B2EC0CDB2A36EAB71A4EB [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\3A850044D8A195CD401A680C012CB0A3B5F8DC08 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\40AA38731BD189F9CDB5B9DC35E2136F38777AF4 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\43D9BCB568E039D073A74A71D8511F7476089CC3 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\471C949A8143DB5AD5CDF1C972864A2504FA23C9 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\51C3247D60F356C7CA3BAF4C3F429DAC93EE7B74 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\5DE83EE82AC5090AEA9D6AC4E7A6E213F946E179 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\61793FCBFA4F9008309BBA5FF12D2CB29CD4151A [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\637162CC59A3A1E25956FA5FA8F60D2E1C52EAC6 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\63FEAE960BAA91E343CE2BD8B71798C76BDB77D0 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\6431723036FD26DEA502792FA595922493030F97 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\7D7F4414CCEF168ADF6BF40753B5BECD78375931 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\80962AE4D6C5B442894E95A13E4A699E07D694CF [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\86E817C81A5CA672FE000F36F878C19518D6F844 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\8E5BD50D6AE686D65252F843A9D4B96D197730AB [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\9845A431D51959CAF225322B4A4FE9F223CE6D15 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\B533345D06F64516403C00DA03187D3BFEF59156 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\B86E791620F759F17B8D25E38CA8BE32E7D5EAC2 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\C060ED44CBD881BD0EF86C0BA287DDCF8167478C [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\CEA586B2CE593EC7D939898337C57814708AB2BE [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\D018B62DC518907247DF50925BB09ACF4A5CB3AD [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\F8A54E03AADC5692B850496A4C4630FFEAA29D83 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\FA6660A94AB45F6A88C0D7874D89A863D74DEE97 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKCU\SOFTWARE\BrowseMark [] =>PUP.Optional.BrowseMark SUPPRIMÉ clé: HKEY_USERS\S-1-5-21-722343333-1444958518-3134038162-1000\SOFTWARE\BrowseMark [] =>PUP.Optional.BrowseMark SUPPRIMÉ clé*: HKEY_USERS\S-1-5-21-722343333-1444958518-3134038162-1000\SOFTWARE\cacaoweb [C:\Users\Eric\AppData\Roaming\cacaoweb\cacaoweb.exe (Not File)] =>.Superfluous.CacaoWeb SUPPRIMÉ clé: HKCU\Software\cacaoweb [C:\Users\Eric\AppData\Roaming\cacaoweb\cacaoweb.exe (Not File)] =>.Superfluous.CacaoWeb SUPPRIMÉ clé*: HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\BrowseMark [] =>PUP.Optional.BrowseMark SUPPRIMÉ clé*: HKCU\Software\TeleCharger [] =>.Superfluous.Downloader SUPPRIMÉ clé*: HKCU\Software\Mozilla\Extends [] =>PUP.Optional.FastStart SUPPRIMÉ clé*: HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Update BrowseMark [] =>PUP.Optional.BrowseMark SUPPRIMÉ clé*: HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Util BrowseMark [] =>PUP.Optional.BrowseMark SUPPRIMÉ clé*: HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Wpm [] =>PUP.Optional.WpManager SUPPRIMÉ valeur: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\cfFncEnabler.exe [cfFncEnabler.exe] =>Heuristic.Salus SUPPRIMÉ valeur: HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules\\TCP Query User{7EDA5469-27F5-49B7-9E58-1E448A1F33BB}C:\users\eric\appdata\roaming\cacaoweb\cacaoweb.exe [C:\users\eric\appdata\roaming\cacaoweb\cacaoweb.exe] =>.Superfluous.CacaoWeb SUPPRIMÉ valeur: HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules\\UDP Query User{191C4FA0-2FB8-4C8C-8A30-1417773E1780}C:\users\eric\appdata\roaming\cacaoweb\cacaoweb.exe [C:\users\eric\appdata\roaming\cacaoweb\cacaoweb.exe] =>.Superfluous.CacaoWeb SUPPRIMÉ valeur: HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules\\TCP Query User{1DA7389E-2BC5-430E-BADE-7F65933CEE15}C:\users\eric\appdata\roaming\cacaoweb\cacaoweb.exe [C:\users\eric\appdata\roaming\cacaoweb\cacaoweb.exe] =>.Superfluous.CacaoWeb SUPPRIMÉ valeur: HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules\\UDP Query User{90C30E70-CD91-4089-9647-A014D65532B1}C:\users\eric\appdata\roaming\cacaoweb\cacaoweb.exe [C:\users\eric\appdata\roaming\cacaoweb\cacaoweb.exe] =>.Superfluous.CacaoWeb ---\\ Récapitulatif des éléments trouvés sur votre station. (10) https://nicolascoolman.eu/2017/01/15/superfluous-cacaoweb/ =>.Superfluous.CacaoWeb https://nicolascoolman.eu/2017/02/02/superfluous-cloudfrontnet/ =>.Superfluous.CloudfrontNet https://www.nicolascoolman.com/fr/toolbar-igraal/ =>Toolbar.Graal https://nicolascoolman.eu/2017/02/02/hacktool-autokms/ =>HackTool.AutoKMS https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>Heuristic.Salus https://nicolascoolman.eu/2017/06/26/trojan-certlock/ =>PUM.Misplaced.Certificate https://www.nicolascoolman.com/fr/pup-browsemark/ =>PUP.Optional.BrowseMark https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.Superfluous.Downloader https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>PUP.Optional.FastStart https://www.anti-malware.top/2016/06/18/superfluous-wpmanager/ =>PUP.Optional.WpManager ---\\ Nettoyage Additionnel. (12) ~ Suppression des Clés de registre Tracing. (12) ~ Suppression des anciens rapports ZHPCleaner. (0) ---\\ Bilan de la réparation ~ Réparation réalisée avec succès. ~ Ce navigateur est absent (Opera Software) ~ Le système a été redémarré. ---\\ Statistiques ~ Items scannés : 1164 ~ Items trouvés : 0 ~ Items annulés : 0 ~ Items réparés : 69 ~ End of clean in 00h06mn10s ~==================== ZHPCleaner-[R]-21072017-17_40_40.txt ZHPCleaner-[S]-21072017-17_34_12.txt