~ ZHPCleaner v2018.1.31.21 by Nicolas Coolman (2018/01/31) ~ Run by Marie (Administrator) (01/02/2018 00:35:52) ~ Web: https://www.nicolascoolman.com ~ Blog: https://nicolascoolman.eu/ ~ Facebook : https://www.facebook.com/nicolascoolman1 ~ State version : Version OK ~ Certificate ZHPCleaner: Legal ~ Type : Nettoyer ~ Report : C:\Users\Marie\Desktop\ZHPCleaner.txt ~ Quarantine : C:\Users\Marie\AppData\Roaming\ZHP\ZHPCleaner_Reg.txt ~ UAC : Activate ~ Boot Mode : Normal (Normal boot) Windows 10 Home, 64-bit (Build 16299) ---\\ Alternate Data Stream (ADS). (0) ~ Aucun élément malicieux ou superflu trouvé. ---\\ Service. (1) ARRETÉ : KMSEmulator =>HackTool.AutoKMS ---\\ Navigateur internet. (2) SUPPRIMÉ: [qotobehb.default] - user_pref("extensions.enabledAddons", "uploader%40adblockfilters.mozdev.org:2.1,%7Ba0d7ccb3-214d-498[...] =>.SUP.CacaoWeb SUPPRIMÉ: [qotobehb.default] - user_pref("extensions.installCache", "[{\"name\":\"app-global\",\"addons\":{\"{972ce4c6-7e08-4474-a2[...] =>.SUP.CacaoWeb ---\\ Fichier Hosts. (1) ~ Le fichier hôte est légitime. (1) ---\\ Tâche planifiée. (0) ~ Aucun élément malicieux ou superflu trouvé. ---\\ Explorateur ( Dossiers, Fichiers ). (27) DEPLACÉ fichier: C:\Users\Marie\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\cacaoweb (1).lnk [Bad : C:\Users\Marie\Downloads\cacaoweb (1).exe](..) =>.SUP.CacaoWeb DEPLACÉ fichier: C:\ProgramData\KMSAuto\bin\KMSSS.exe [MDL Forum, mod by Ratiborus - KMS Server Emulator Service (XP)] =>HackTool.AutoKMS DEPLACÉ fichier**: C:\Windows\Prefetch\CACAOWEB (1).EXE-4CC2C82C.pf =>.SUP.CacaoWeb DEPLACÉ fichier**: C:\Windows\Prefetch\CACAOWEB.EXE-E618903C.pf =>.SUP.CacaoWeb DEPLACÉ fichier**: C:\ProgramData\KMSAuto\KMSAuto Net.exe [MSFree Inc. - KMSAuto Net] =>HackTool.WinActivator DEPLACÉ fichier^: C:\ProgramData\InstallMate\{66BF0329-358B-44F4-A61F-7DA9BD5C21DF}\Setup.exe [Tarma Software Research Pty Ltd - InstallMate® Setup] =>Adware.Tarma DEPLACÉ fichier^: C:\ProgramData\InstallMate\{66BF0329-358B-44F4-A61F-7DA9BD5C21DF}\TsuDll.dll [Tarma Software Research Pty Ltd - InstallMate® Setup Library] =>Adware.Tarma DEPLACÉ fichier**: C:\Users\Marie\Downloads\cacaoweb (2).exe =>.SUP.CacaoWeb DEPLACÉ fichier**: C:\Users\Marie\Downloads\cacaoweb (3).exe =>.SUP.CacaoWeb DEPLACÉ fichier**: C:\Users\Marie\Downloads\cacaoweb nat diagnostics.json =>.SUP.CacaoWeb DEPLACÉ dossier*: C:\Program Files (x86)\CoolSalECoaupOn =>PUP.Optional.CoolSaleCoupon DEPLACÉ dossier*: C:\Program Files (x86)\dOWnloAAditkeep =>PUP.Optional.DownloadItKeep DEPLACÉ dossier*: C:\Program Files (x86)\FlexibleShopper =>PUP.Optional.FlexibleShoper DEPLACÉ dossier*: C:\ProgramData\Babylon =>Adware.Babylon DEPLACÉ dossier*: C:\ProgramData\CoolSalECoaupOn =>PUP.Optional.CoolSaleCoupon DEPLACÉ dossier*: C:\ProgramData\CoolSaleeCCoaupon =>PUP.Optional.CoolSaleCoupon DEPLACÉ dossier*: C:\ProgramData\dOWnloAAditkeep =>PUP.Optional.DownloadItKeep DEPLACÉ dossier*: C:\ProgramData\FlexibleShopper =>PUP.Optional.FlexibleShoper DEPLACÉ dossier*: C:\ProgramData\InstallMate =>Adware.Tarma DEPLACÉ dossier*: C:\ProgramData\KMSAuto =>HackTool.WinActivator DEPLACÉ dossier*: C:\ProgramData\SaverAdddon =>PUP.Optional.SaverOn DEPLACÉ dossier*: C:\ProgramData\tperfaECtCoupon =>PUP.Optional.TPerfectCoupon DEPLACÉ dossier*: C:\Users\Marie\AppData\Roaming\Babylon =>Adware.Babylon DEPLACÉ dossier*: C:\Users\Marie\AppData\Local\MSfree Inc =>HackTool.WinActivator DEPLACÉ dossier*: C:\Program Files (x86)\Software =>PUP.Optional.Boxore DEPLACÉ dossier*: C:\ProgramData\Software =>PUP.Optional.Boxore DEPLACÉ dossier*: C:\Users\Marie\AppData\Local\Software =>PUP.Optional.Boxore ---\\ Base de Registres ( Clés, Valeurs, Données ). (64) SUPPRIMÉ clé*: HKLM\SYSTEM\CurrentControlSet\Services\KMSEmulator [C:\ProgramData\KMSAuto\bin\KMSSS.exe (Not File)] =>HackTool.AutoKMS SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\..9 [topdeal] =>PUP.Optional.Generic SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\Prod.cap [] =>PUP.Optional.ClaroSearch SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\FlexibleShopper.FlexibleShopper [FlexibleShopper] =>PUP.Optional.FlexibleShopper SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\FlexibleShopper.FlexibleShopper.9 [FlexibleShopper] =>PUP.Optional.FlexibleShopper SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\CLSID\{12c5747a-fb68-4c78-a2e1-dfc744ba51c5} [CoolSalECoaupOn] =>PUP.Optional.CoolSaleCoupon SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\CLSID\{45FC6FE3-B09F-AAA0-CFE3-F40D34AC3AC9} [dOWnloAAditkeep] =>PUP.Optional.DownloadItKeep SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\CLSID\{72424cc6-f912-4ff5-a5df-a2b561db284f} [daeal2dealIt] =>PUP.Optional.Deal2Dealit SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\CLSID\{759bf2e3-b0cb-4f5e-91b2-e9b4858d4fa6} [PrroShopapeR] =>PUP.Optional.ProShopper SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\CLSID\{9452a53f-023a-4aac-9959-73b5efb809c9} [topbuyer] =>PUP.Optional.TopBuyer SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\CLSID\{96a53b61-8240-463a-b31c-07b5a4dbee75} [FlexibleShopper] =>PUP.Optional.FlexibleShoper SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\CLSID\{b5f8512f-daec-43f0-9aa3-cb5f89386685} [savernet] =>PUP.Optional.SaveNet SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\CLSID\{dcb2adf5-e428-4ee0-8ced-5feb83467301} [FFineDeAAlSoft] =>PUP.Optional.FineDealSoft SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\CLSID\{e1520979-1a68-4e22-a713-b527f6be8bde} [dealpeak] =>PUP.Optional.DealPeak SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\CLSID\{e65a2f0d-1760-4772-be83-04bc657ab86e} [ssaVernet] =>PUP.Optional.SaveNet SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\CLSID\{f152697e-a20c-4340-be3a-ee4dbe7b1566} [WowCOupoun] =>PUP.Optional.WOwCoupon SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{237FDFDB-3722-470E-8BA8-90196DABE967} [ISetup] =>PUP.Optional.GetNow SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA} [IStatedContract] =>PUP.Optional.IMBooster SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49} [_LogoutCommand] =>PUP.Optional.IMBooster SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460} [_LoginCommand] =>PUP.Optional.IMBooster SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920} [_LightUri] =>PUP.Optional.RewardsArcade SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3} [_PlayContentCommand] =>PUP.Optional.RewardsArcade SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861} [_VariableChangedCallback] =>PUP.Optional.RewardsArcade SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065} [ITinyfyingArgs] =>PUP.Optional.RewardsArcade SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA} [_AddToUserContentCommand] =>PUP.Optional.RewardsArcade SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000} [IServerResult] =>PUP.Optional.RewardsArcade SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4} [_TinyUrlArgs] =>PUP.Optional.RewardsArcade SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D} [_RawDataArgs] =>PUP.Optional.RewardsArcade SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0} [_ShowPluginWindowCommand] =>PUP.Optional.RewardsArcade SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C} [_LightContent] =>PUP.Optional.RewardsArcade SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9} [_WarmUpCommand] =>PUP.Optional.RewardsArcade SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08} [_CheckLoginStatusCommand] =>PUP.Optional.RewardsArcade SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4} [_WelcomeCommand] =>PUP.Optional.RewardsArcade SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C} [_ShowBrowserWindowCommand] =>PUP.Optional.RewardsArcade SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37} [IMediatorClient] =>PUP.Optional.RewardsArcade SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0} [_ShowControlCenterCommand] =>PUP.Optional.RewardsArcade SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003} [IServerCommand] =>PUP.Optional.RewardsArcade SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4} [ICoordCommand] =>PUP.Optional.RewardsArcade SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D} [_GetVariableResult] =>PUP.Optional.RewardsArcade SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5} [_GetLoginStatusResult] =>PUP.Optional.RewardsArcade SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A} [_DownloadArgs] =>PUP.Optional.RewardsArcade SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D} [_GameOverCallback] =>PUP.Optional.RewardsArcade SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA} [IMediatorServiceProxy] =>PUP.Optional.RewardsArcade SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75} [_InstallationContextResult] =>PUP.Optional.RewardsArcade SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556} [IContractBase] =>PUP.Optional.RewardsArcade SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C} [_CleanCacheCommand] =>PUP.Optional.RewardsArcade SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500} [_GetInstallationContextCommand] =>PUP.Optional.RewardsArcade SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205} [_LoginStatusChangedCallback] =>PUP.Optional.RewardsArcade SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED} [_MergeIdentityCommand] =>PUP.Optional.RewardsArcade SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25} [_SetVariableCommand] =>PUP.Optional.RewardsArcade SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D} [_MyAccountCommand] =>PUP.Optional.RewardsArcade SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3} [IHWndContract] =>PUP.Optional.RewardsArcade SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7} [_PostContentCallback] =>PUP.Optional.RewardsArcade SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01} [_RecycleViewsCommand] =>PUP.Optional.RewardsArcade SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2} [_UserContentChangedCallback] =>PUP.Optional.RewardsArcade SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587} [_GetCreditCommand] =>PUP.Optional.RewardsArcade SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4} [_LinkToPromoteArgs] =>PUP.Optional.RewardsArcade SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B} [_LoadContentCommandResult] =>PUP.Optional.RewardsArcade SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7} [_ViralLinkArgs] =>PUP.Optional.RewardsArcade SUPPRIMÉ clé: [X64] HKLM\SOFTWARE\Classes\CLSID\{e1520979-1a68-4e22-a713-b527f6be8bde}\InprocServer32 [C:\ProgramData\dealpeak\pzmPrRyY8w4jsi.x64.dll (Not File)] =>PUP.Optional.DealPeak SUPPRIMÉ valeur: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\GoogleChromeAutoLaunch_D555174A98A2F0684F8075DBE0BF0C0E ["C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window] =>PUP.Optional.MyBrowser SUPPRIMÉ valeur: HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files (x86)\Iminent\inst\Bootstrapper\ [No Folder] =>PUP.Optional.IMBooster SUPPRIMÉ valeur: HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files (x86)\Iminent\inst\ [No Folder] =>PUP.Optional.IMBooster SUPPRIMÉ valeur: HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files (x86)\Iminent\ [No Folder] =>PUP.Optional.IMBooster ---\\ Récapitulatif des éléments trouvés sur votre station. (25) https://nicolascoolman.eu/2017/02/02/hacktool-autokms/ =>HackTool.AutoKMS https://nicolascoolman.eu/2017/01/15/superfluous-cacaoweb/ =>.SUP.CacaoWeb https://nicolascoolman.eu/2017/01/13/hacktool-winactivator/ =>HackTool.WinActivator https://nicolascoolman.eu/2017/09/09/adware-tarma/ =>Adware.Tarma https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>PUP.Optional.CoolSaleCoupon https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>PUP.Optional.DownloadItKeep https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>PUP.Optional.FlexibleShoper https://nicolascoolman.eu/2017/03/03/adware-babylon/ =>Adware.Babylon https://www.nicolascoolman.com/fr/pup-saveron/ =>PUP.Optional.SaverOn https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>PUP.Optional.TPerfectCoupon https://nicolascoolman.eu/2017/03/14/pup-optional-boxore/ =>PUP.Optional.Boxore https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>PUP.Optional.Generic https://www.nicolascoolman.com/fr/pup-clarosearch/ =>PUP.Optional.ClaroSearch https://www.nicolascoolman.com/fr/pup-flexibleshoper/ =>PUP.Optional.FlexibleShopper https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>PUP.Optional.Deal2Dealit https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>PUP.Optional.ProShopper https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>PUP.Optional.TopBuyer https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>PUP.Optional.SaveNet https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>PUP.Optional.FineDealSoft https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>PUP.Optional.DealPeak https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>PUP.Optional.WOwCoupon https://www.nicolascoolman.com/fr/pup-getnow/ =>PUP.Optional.GetNow https://nicolascoolman.eu/2017/09/08/adware-imbooster/ =>PUP.Optional.IMBooster https://www.nicolascoolman.com/fr/pup-rewardsarcade/ =>PUP.Optional.RewardsArcade https://nicolascoolman.eu/2017/11/01/adware-mybrowser/ =>PUP.Optional.MyBrowser ---\\ Nettoyage Additionnel. (6) ~ Suppression des Clés de registre Tracing. (6) ~ Suppression des anciens rapports ZHPCleaner. (0) ---\\ Bilan de la réparation ~ Réparation réalisée avec succès. ~ Ce navigateur est absent (Opera Software) ~ Le système a été redémarré. ---\\ Statistiques ~ Items scannés : 661 ~ Items trouvés : 0 ~ Items annulés : 0 ~ Items options : 0/7 ~ Gain de place (Octets) : 0 ~ End of clean in 00h02mn29s ~==================== ZHPCleaner-[S]-01022018-00_34_31.txt ZHPCleaner-[R]-01022018-00_38_21.txt