~ ZHPCleaner v2017.8.15.140 by Nicolas Coolman (2017/08/15) ~ Run by Maison (Administrator) (19/08/2017 13:01:36) ~ Web: https://www.nicolascoolman.com ~ Blog: https://nicolascoolman.eu/ ~ Facebook : https://www.facebook.com/nicolascoolman1 ~ State version : Version OK ~ Certificate ZHPCleaner: Illegal ~ Type : Nettoyer ~ Report : C:\Users\Maison\Desktop\ZHPCleaner.txt ~ Quarantine : C:\Users\Maison\AppData\Roaming\ZHP\ZHPCleaner_Reg.txt ~ UAC : Activate ~ Boot Mode : Normal (Normal boot) Windows 7 Home Premium, 64-bit Service Pack 1 (Build 7601) ---\\ Service. (2) ARRETÉ : ByteFenceService =>.SUP.ByteFence ARRETÉ : rtop =>.SUP.ByteFence ---\\ Navigateur internet. (0) ---\\ Fichier hôte. (1) ~ Le fichier hôte est légitime. (60) ---\\ Tâche planifiée. (2) SUPPRIMÉ tâche: [ByteFence] [C:\Program Files\ByteFence\ByteFence.exe] =>.SUP.ByteFence SUPPRIMÉ tâche: [Yahoo! Powered faser] [C:\Windows\Tasks\Yahoo! Powered faser.job (Not File) ] =>Adware.YahooPowered ---\\ Explorateur ( Dossiers, Fichiers ). (22) DEPLACÉ fichier: C:\Users\Maison\AppData\Roaming\Mozilla\Firefox\Profiles\tjxobm0f.default\searchplugins\yahoo! powered.xml =>Adware.YahooPowered DEPLACÉ fichier: C:\Users\Maison\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_nahhmpbckpgdidfnmfkfgiflpjijilce_0.localstorage =>.SUP.SearchManager DEPLACÉ fichier: C:\Users\Maison\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pilplloabdedfmialnfchjomjmpjcoej_0.localstorage =>.SUP.SearchManager DEPLACÉ fichier: C:\Windows\Tasks\Yahoo! Powered faser.job =>Adware.YahooPowered DEPLACÉ fichier: C:\Windows\Prefetch\BYTEFENCESCAN.EXE-210ADD1C.pf =>.SUP.ByteFence DEPLACÉ fichier: C:\Users\Maison\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_d22j4fzzszoii2.cloudfront.net_0.localstorage =>.SUP.CloudfrontNet DEPLACÉ fichier: C:\Users\Maison\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.audienceinsights.net_0.localstorage =>.SUP.AudienceInsights DEPLACÉ dossier: C:\Users\Maison\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce =>.SUP.SearchManager DEPLACÉ dossier: C:\Users\Maison\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej =>.SUP.SearchManager DEPLACÉ dossier^: C:\Program Files\ByteFence =>.SUP.ByteFence DEPLACÉ dossier^: C:\Program Files\WebBarMedia =>PUP.Optional.WebBar DEPLACÉ dossier^: C:\ProgramData\ByteFence =>.SUP.ByteFence DEPLACÉ dossier: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ByteFence Anti-Malware =>.SUP.ByteFence DEPLACÉ dossier: C:\Users\Maison\Documents\PROPCCleaner =>.SUP.DoctorPC DEPLACÉ dossier: C:\Users\Maison\AppData\Local\PRO_PC_Cleaner =>.SUP.PCCleaner DEPLACÉ dossier^: C:\Users\Maison\AppData\Local\WebBar =>PUP.Optional.WebBar DEPLACÉ dossier: C:\Program Files (x86)\Common Files\IObit\Advanced SystemCare =>.SUP.AdvancedSystemCare DEPLACÉ dossier: C:\ProgramData\Application Data\IObit\ASCDownloader =>.SUP.AdvancedSystemCare DEPLACÉ dossier: C:\ProgramData\IObit\ASCDownloader =>.SUP.AdvancedSystemCare DEPLACÉ dossier: C:\Users\Maison\AppData\Local\Google\Chrome\User Data\Default\File System\008 =>PUP.Optional.DomaIQ DEPLACÉ dossier: C:\Users\Maison\AppData\Roaming\IObit\Advanced SystemCare =>.SUP.AdvancedSystemCare DEPLACÉ dossier: C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\IObit\Advanced SystemCare =>.SUP.AdvancedSystemCare ---\\ Base de Registres ( Clés, Valeurs, Données ). (60) SUPPRIMÉ clé: [X64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [https://fr.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_popjar_17_33_ss[...]] [Yahoo! Powered] =>Adware.YahooPowered SUPPRIMÉ clé: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [https://fr.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_popjar_17_33_ss[...]] [Yahoo! Powered] =>Adware.YahooPowered SUPPRIMÉ clé*: HKCU\SOFTWARE\Google\Chrome\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce [] =>.SUP.SearchManager SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Google\Chrome\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce [] =>.SUP.SearchManager SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce [] =>.SUP.SearchManager SUPPRIMÉ clé*: HKCU\SOFTWARE\Google\Chrome\Extensions\pilplloabdedfmialnfchjomjmpjcoej [] =>.SUP.SearchManager SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Google\Chrome\Extensions\pilplloabdedfmialnfchjomjmpjcoej [] =>.SUP.SearchManager SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\pilplloabdedfmialnfchjomjmpjcoej [] =>.SUP.SearchManager SUPPRIMÉ clé: [X64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [https://fr.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_popjar_17_33_ssg08¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dfr%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1QzuyByE0DyEtAyDzzyEyE0EyD0A0CtB0FyBtN0D0Tzu0StBtDyDyCtN1L2XzutAtFtBzytFtCtDyEtFyDtCtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyByC0BtCtA0AyC0BtGtDtCtC0CtG0C0EtBzztGyCtCzyzztGyEtAtByDtAyB0C0DtBzy0CtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCyCyEzy0FyDyEzytG0ByCzz0FtGyEtB0BtDtGzztDzzzytG0EtByC0B0DtD0CzzyD0A0AtB2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtAzzyEyC%26cr%3D1786013215%26a%3Dwbf_popjar_17_33_ssg08%26os_ver%3D6.1%26os%3DWindows%2B7%2BHome%2BPremium&p={searchTerms}] =>Adware.YahooPowered SUPPRIMÉ clé: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [https://fr.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_popjar_17_33_ssg08¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dfr%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1QzuyByE0DyEtAyDzzyEyE0EyD0A0CtB0FyBtN0D0Tzu0StBtDyDyCtN1L2XzutAtFtBzytFtCtDyEtFyDtCtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyByC0BtCtA0AyC0BtGtDtCtC0CtG0C0EtBzztGyCtCzyzztGyEtAtByDtAyB0C0DtBzy0CtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCyCyEzy0FyDyEzytG0ByCzz0FtGyEtB0BtDtGzztDzzzytG0EtByC0B0DtD0CzzyD0A0AtB2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtAzzyEyC%26cr%3D1786013215%26a%3Dwbf_popjar_17_33_ssg08%26os_ver%3D6.1%26os%3DWindows%2B7%2BHome%2BPremium&p={searchTerms}] =>Adware.YahooPowered SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\1916A2AF346D399F50313C393200F14140456616 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\2A83E9020591A55FC6DDAD3FB102794C52B24E70 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\2B84BFBB34EE2EF949FE1CBE30AA026416EB2216 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\305F8BD17AA2CBC483A4C41B19A39A0C75DA39D6 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\367D4B3B4FCBBC0B767B2EC0CDB2A36EAB71A4EB [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\3A850044D8A195CD401A680C012CB0A3B5F8DC08 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\40AA38731BD189F9CDB5B9DC35E2136F38777AF4 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\43D9BCB568E039D073A74A71D8511F7476089CC3 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\471C949A8143DB5AD5CDF1C972864A2504FA23C9 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\51C3247D60F356C7CA3BAF4C3F429DAC93EE7B74 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\5DE83EE82AC5090AEA9D6AC4E7A6E213F946E179 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\61793FCBFA4F9008309BBA5FF12D2CB29CD4151A [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\637162CC59A3A1E25956FA5FA8F60D2E1C52EAC6 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\63FEAE960BAA91E343CE2BD8B71798C76BDB77D0 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\6431723036FD26DEA502792FA595922493030F97 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\7D7F4414CCEF168ADF6BF40753B5BECD78375931 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\80962AE4D6C5B442894E95A13E4A699E07D694CF [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\86E817C81A5CA672FE000F36F878C19518D6F844 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\8E5BD50D6AE686D65252F843A9D4B96D197730AB [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\9845A431D51959CAF225322B4A4FE9F223CE6D15 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\B533345D06F64516403C00DA03187D3BFEF59156 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\B86E791620F759F17B8D25E38CA8BE32E7D5EAC2 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\C060ED44CBD881BD0EF86C0BA287DDCF8167478C [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\CEA586B2CE593EC7D939898337C57814708AB2BE [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\D018B62DC518907247DF50925BB09ACF4A5CB3AD [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\F8A54E03AADC5692B850496A4C4630FFEAA29D83 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\FA6660A94AB45F6A88C0D7874D89A863D74DEE97 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\SYSTEM\CurrentControlSet\Services\ByteFenceService [C:\Program Files\ByteFence\ByteFenceService.exe] =>.SUP.ByteFence SUPPRIMÉ clé*: HKLM\SYSTEM\CurrentControlSet\Services\rtop [C:\Program Files\ByteFence\rtop\bin\rtop_svc.exe] =>.SUP.ByteFence SUPPRIMÉ clé*: HKEY_USERS\S-1-5-21-266285106-2113203036-1789988685-1000\SOFTWARE\ByteFence [] =>.SUP.ByteFence SUPPRIMÉ clé*: HKEY_USERS\S-1-5-21-266285106-2113203036-1789988685-1000\SOFTWARE\PROPCCleanerLanguage [] =>.SUP.DoctorPC SUPPRIMÉ clé: HKCU\Software\ByteFence [] =>.SUP.ByteFence SUPPRIMÉ clé: HKCU\Software\PROPCCleanerLanguage [] =>.SUP.DoctorPC SUPPRIMÉ clé*: HKCU\Software\csastats [] =>Adware.InstallCore SUPPRIMÉ clé*: HKCU\Software\undefined [] =>.SUP.Downloader SUPPRIMÉ clé*: HKCU\Software\ProductSetup [] =>Adware.InstallCore SUPPRIMÉ clé*: HKLM\SOFTWARE\Iobit\ASC [] =>.SUP.AdvancedSystemCare SUPPRIMÉ clé*: HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\ByteFenceService [] =>.SUP.ByteFence SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\ByteFence [] =>.SUP.ByteFence SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\WebBar [] =>PUP.Optional.WebBar SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Microsoft\Tracing\ByteFence_RASAPI32 [] =>.SUP.ByteFence SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Microsoft\Tracing\ByteFence_RASMANCS [] =>.SUP.ByteFence SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Microsoft\Tracing\PROPCCleaner_RASAPI32 [] =>.SUP.DoctorPC SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Microsoft\Tracing\PROPCCleaner_RASMANCS [] =>.SUP.DoctorPC SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0BCE8B0A-1E76-44E5-9909-3CF804D92E4D}_is1 [WebBar] =>PUP.Optional.WebBar SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\ByteFence [] =>.SUP.ByteFence SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ByteFence [Byte Technologies LLC] =>.SUP.ByteFence SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{28C8C008-7848-1188-C9C8-61081948B288} [Yahoo! Powered] =>Adware.YahooPowered SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ByteFenceScan_RASAPI32 [] =>.SUP.ByteFence SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ByteFenceScan_RASMANCS [] =>.SUP.ByteFence ---\\ Récapitulatif des éléments trouvés sur votre station. (13) https://nicolascoolman.eu/2017/03/13/superfluous-bytefence/ =>.SUP.ByteFence https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>Adware.YahooPowered https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.SUP.SearchManager https://nicolascoolman.eu/2017/02/02/superfluous-cloudfrontnet/ =>.SUP.CloudfrontNet https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.SUP.AudienceInsights https://www.anti-malware.top/2016/06/07/pup-optional-webbar/ =>PUP.Optional.WebBar https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.SUP.DoctorPC https://www.nicolascoolman.com/fr/usp-pccleaner/ =>.SUP.PCCleaner https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.SUP.AdvancedSystemCare https://www.nicolascoolman.com/fr/adware-domaiq/ =>PUP.Optional.DomaIQ https://nicolascoolman.eu/2017/06/26/trojan-certlock/ =>PUM.Misplaced.Certificate https://nicolascoolman.eu/2017/03/12/adware-installcore-2/ =>Adware.InstallCore https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.SUP.Downloader ---\\ Nettoyage Additionnel. (91) ~ Suppression des Clés de registre Tracing. (91) ~ Suppression des anciens rapports ZHPCleaner. (0) ---\\ Bilan de la réparation ~ Réparation réalisée avec succès. ~ Le système a été redémarré. ---\\ Statistiques ~ Items scannés : 1351 ~ Items trouvés : 0 ~ Items annulés : 0 ~ Items réparés : 86 ~ End of clean in 00h01mn34s ~==================== ZHPCleaner-[R]-19082017-13_03_10.txt ZHPCleaner-[S]-19082017-13_00_34.txt