~ ZHPCleaner v2018.8.5.156 by Nicolas Coolman (2018/08/05) ~ Run by mrtho (Administrator) (05/08/2018 19:05:48) ~ Web: https://www.nicolascoolman.com ~ Blog: https://nicolascoolman.eu/ ~ Facebook : https://www.facebook.com/nicolascoolman1 ~ State version : Version OK ~ Certificate ZHPCleaner: Legal ~ Type : Nettoyer ~ Report : C:\Users\mrtho\Desktop\ZHPCleaner.txt ~ Quarantine : C:\Users\mrtho\AppData\Roaming\ZHP\ZHPCleaner_Reg.txt ~ UAC : Activate ~ Boot Mode : Normal (Normal boot) Windows 10 Home, 64-bit (Build 16299) ---\\ ALTERNATE DATA STREAM (ADS). (0) ~ Aucun élément malicieux ou superflu trouvé. ---\\ SERVICE. (1) ARRETÉ : rtop =>.SUP.ByteFence ---\\ NAVIGATEUR INTERNET. (0) ~ Aucun élément malicieux ou superflu trouvé. ---\\ FICHIER HÔTE. (2) REMPLACÉ: ਍ਣ⁵湣桥捫祟扥杩渍ਣ⁔桥獥⁲畬敳⁷敲攠慤摥搠批⁴桥⁕湣桥捫礠灲潧牡洠楮牤敲⁴漠扬潣欠慤癥牴楳楮朠獯晴睡牥潤畬敳ഊ〮〮〮〠〮〮〮〠⌠晩砠景爠瑲慣敲潵瑥⁡湤整獴慴⁤楳灬慹⁡湯浡汹ഊ〮〮〮〠瑲慣歩湧⹯灥湣慮摹⹣潭⹳㌮慭慺潮慷献捯洍ਰ⸰⸰⸰敤楡⹯灥湣慮摹⹣潭ഊ〮〮〮〠捤渮潰敮捡湤礮捯洍ਰ⸰⸰⸰⁴牡捫楮朮潰敮捡湤礮捯洍ਰ⸰⸰⸰⁡灩⹯灥湣慮摹⹣潭ഊ〮〮〮〠慰椮牥捯浭敮摥摳眮捯洍ਰ⸰⸰⸰⁲瀮祥晥湥物㈮捯洍ਰ⸰⸰⸰献祥晥湥物㈮捯洍ਰ⸰⸰⸰猲⹹敦敮敲椲⹣潭ഊ〮〮〮〠楮獴慬汥爮扥瑴敲楮獴慬汥爮捯洍ਰ⸰⸰⸰⁩湳瑡汬敲⹦楬敢畬汤潧⹣潭ഊ〮〮〮〠搳潸瑮ㅸ㍢㡤㝩⹣汯畤晲潮琮湥琍ਰ⸰⸰⸰⁩湮漮扩獲瘮捯洍ਰ⸰⸰⸰獩献扩獲瘮捯洍ਰ⸰⸰⸰⁣摮⹦楬攲摥獫瑯瀮捯洍ਰ⸰⸰⸰⁣摮⹧潡瑥慳瑣慣栮畳ഊ〮〮〮〠捤渮杵瑴慳瑡瑤欮畳ഊ〮〮〮〠捤渮楮獫楮浥摩愮捯洍ਰ⸰⸰⸰⁣摮⹩湳瑡⹯楢畮摬敳㈮捯洍ਰ⸰⸰⸰⁣摮⹩湳瑡⹰污祢特瑥⹣潭ഊ〮〮〮〠捤渮汬潧整晡獴捡捨⹵猍ਰ⸰⸰⸰⁣摮⹭潮瑩敲愮捯洍ਰ⸰⸰⸰⁣摮⹭獤睮汤⹣潭ഊ〮〮〮〠捤渮浹灣扡捫異⹣潭ഊ〮〮〮〠捤渮灰摯睮汯慤⹣潭ഊ〮〮〮〠捤渮物捥慴敡獴捡捨⹵猍ਰ⸰⸰⸰⁣摮⹳桹慰潴慴漮畳ഊ〮〮〮〠捤渮獯汩浢愮捯洍ਰ⸰⸰⸰⁣摮⹴畴漴灣⹣潭ഊ〮〮〮〠捤渮慰灲潵湤⹢楺ഊ〮〮〮〠捤渮扩杳灥敤灲漮捯洍ਰ⸰⸰⸰⁣摮⹢楳灤⹣潭ഊ〮〮〮〠捤渮扩獲瘮捯洍ਰ⸰⸰⸰⁣摮⹣摮摰⹣潭ഊ〮〮〮〠捤渮摯睮汯慤⹳睥整灡捫献捯洍ਰ⸰⸰⸰⁣摮⹤灤潷湬潡搮捯洍ਰ⸰⸰⸰⁣摮⹶楳畡汢敥⹮整ഊ⌠畮捨散歹彥湤ഊ ~ Nombre de redirections trouvées 1/3 ---\\ TÂCHE PLANIFIÉE. (1) SUPPRIMÉ tâche: [ByteFence] [C:\Program Files\ByteFence\ByteFence.exe (Not File) ] =>.SUP.ByteFence ---\\ EXPLORATEUR ( Dossiers, Fichiers ). (11) DEPLACÉ fichier: C:\Users\mrtho\AppData\Roaming\Mozilla\Firefox\Profiles\qo0etggc.default\searchplugins\yahoo! powered.xml =>Adware.YahooPowered DEPLACÉ fichier: C:\Program Files\ByteFence\ByteFenceService.exe [Byte Technologies LLC - ByteFence Anti-Malware] =>.SUP.ByteFence DEPLACÉ fichier: C:\Program Files\ByteFence\rtop\bin\rtop_svc.exe [Byte Technologies LLC. - ByteFence Real-time Protection Service] =>.SUP.ByteFence DEPLACÉ fichier: C:\Windows\Prefetch\BYTEFENCE.EXE-945F23E2.pf =>.SUP.ByteFence DEPLACÉ fichier: C:\ProgramData\KMSAutoS\KMSAuto Net.exe [MSFree Inc. - KMSAuto Net] =>HackTool.WinActivator DEPLACÉ fichier: C:\ProgramData\KMSAutoS\bin\KMSSS.exe [MDL Forum, mod by Ratiborus - KMS Server Emulator Service (XP)] =>HackTool.AutoKMS DEPLACÉ dossier: C:\Program Files\ByteFence =>.SUP.ByteFence DEPLACÉ dossier^: C:\ProgramData\ByteFence =>.SUP.ByteFence DEPLACÉ dossier: C:\ProgramData\KMSAutoS =>HackTool.WinActivator DEPLACÉ dossier: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ByteFence Anti-Malware =>.SUP.ByteFence DEPLACÉ dossier: C:\Users\mrtho\AppData\Local\MSfree Inc =>HackTool.WinActivator ---\\ BASE DE REGISTRES ( Clés, Valeurs, Données ). (28) SUPPRIMÉ clé: [X64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [https://us.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_chtengin_18_01&[...]] [Yahoo! Powered] =>Adware.YahooPowered SUPPRIMÉ clé: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [https://us.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_chtengin_18_01&[...]] [Yahoo! Powered] =>Adware.YahooPowered SUPPRIMÉ clé: [X64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [https://us.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_chtengin_18_01¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1QzutC0CtC0BtD0D0EzzyByC0C0BtDyB0A0BtN0D0Tzu0StBtCzyyDtN1L2XzuyEtFtBtCtFtDtFyDtCtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2SyCyE0ByB0Ezy0B0BtGyByE0BzztGzytD0DtBtGyByB0A0DtGyE0F0B0FtAtCzztCzz0E0CtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyD1QyE1P1QyC1P1RtG1StByB1RtGyEtB1P1QtG1TtByCtDtGtAyB1QyEyB1P1RyBtC1OzyyB2QtN0A0LzuyEtN1B2Z1V1T1S1NzutN1Q2Z1B1P1RzutCyDtCyDtDzztCyDyByD%26cr%3D1102233743%26a%3Dwbf_chtengin_18_01%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms}] =>Adware.YahooPowered SUPPRIMÉ clé: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} [https://us.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_chtengin_18_01¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1QzutC0CtC0BtD0D0EzzyByC0C0BtDyB0A0BtN0D0Tzu0StBtCzyyDtN1L2XzuyEtFtBtCtFtDtFyDtCtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2SyCyE0ByB0Ezy0B0BtGyByE0BzztGzytD0DtBtGyByB0A0DtGyE0F0B0FtAtCzztCzz0E0CtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyD1QyE1P1QyC1P1RtG1StByB1RtGyEtB1P1QtG1TtByCtDtGtAyB1QyEyB1P1RyBtC1OzyyB2QtN0A0LzuyEtN1B2Z1V1T1S1NzutN1Q2Z1B1P1RzutCyDtCyDtDzztCyDyByD%26cr%3D1102233743%26a%3Dwbf_chtengin_18_01%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms}] =>Adware.YahooPowered SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\029c4619-0385-5543-9426-46f9987161d9 [] =>Adware.CrossRider SUPPRIMÉ clé*: HKLM\SYSTEM\CurrentControlSet\Services\ByteFenceService [C:\Program Files\ByteFence\ByteFenceService.exe (Not File)] =>.SUP.ByteFence SUPPRIMÉ clé*: HKLM\SYSTEM\CurrentControlSet\Services\rtop [C:\Program Files\ByteFence\rtop\bin\rtop_svc.exe (Not File)] =>.SUP.ByteFence SUPPRIMÉ clé*: HKEY_USERS\S-1-5-21-3728115668-3251098077-3353745527-1001\SOFTWARE\ByteFence [] =>.SUP.ByteFence SUPPRIMÉ clé*: HKEY_USERS\.DEFAULT\Software\ByteFence [] =>.SUP.ByteFence SUPPRIMÉ clé: HKCU\Software\ByteFence [] =>.SUP.ByteFence SUPPRIMÉ clé: HKU\.DEFAULT\Software\ByteFence [] =>.SUP.ByteFence SUPPRIMÉ clé: HKU\S-1-5-18\Software\ByteFence [] =>.SUP.ByteFence SUPPRIMÉ clé*: HKCU\Software\csastats [] =>Adware.InstallCore SUPPRIMÉ clé*: HKCU\Software\ProductSetup [] =>Adware.InstallCore SUPPRIMÉ clé*: HKLM\System\CurrentControlSet\Services\EventLog\Reason\ReasonByteFence [] =>.SUP.ByteFence SUPPRIMÉ clé*: HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\ByteFenceService [] =>.SUP.ByteFence SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\ByteFence [] =>.SUP.ByteFence SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Microsoft\Tracing\ByteFenceService_RASAPI32 [] =>.SUP.ByteFence SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Microsoft\Tracing\ByteFenceService_RASMANCS [] =>.SUP.ByteFence SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Microsoft\Tracing\ByteFence_RASAPI32 [] =>.SUP.ByteFence SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Microsoft\Tracing\ByteFence_RASMANCS [] =>.SUP.ByteFence SUPPRIMÉ clé^: [X64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ByteFence [] =>.SUP.ByteFence SUPPRIMÉ clé^: [X64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\KMSAutoNet [] =>HackTool.WinActivator SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\ByteFence [] =>.SUP.ByteFence SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Uniblue [] =>.SUP.Uniblue SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ByteFence [Byte Technologies LLC] =>.SUP.ByteTechnologies SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ByteFenceScan_RASAPI32 [] =>.SUP.ByteFence SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ByteFenceScan_RASMANCS [] =>.SUP.ByteFence ---\\ RÉCAPITULATIF DES ÉLÉMENTS TROUVÉS SUR VOTRE STATION. (8) https://nicolascoolman.eu/2017/03/13/superfluous-bytefence/ =>.SUP.ByteFence https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>Adware.YahooPowered https://nicolascoolman.eu/2017/01/13/hacktool-winactivator/ =>HackTool.WinActivator https://nicolascoolman.eu/2017/02/02/hacktool-autokms/ =>HackTool.AutoKMS https://nicolascoolman.eu/2017/03/11/pup-optional-crossrider/ =>Adware.CrossRider https://nicolascoolman.eu/2017/09/19/adware-installcore-3/ =>Adware.InstallCore https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.SUP.Uniblue https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.SUP.ByteTechnologies ---\\ NETTOYAGE ADDITIONNEL. (21) ~ Suppression des Clés de registre Tracing. (21) ~ Suppression des anciens rapports ZHPCleaner. (0) ---\\ BILAN DE LA REPARATION ~ Réparation réalisée avec succès. ~ Ce navigateur est absent (Opera Software) ~ Le système a été redémarré. ---\\ STATISTIQUES ~ Items scannés : 697 ~ Items trouvés : 0 ~ Items annulés : 0 ~ Items options : 0/7 ~ Gain de place (Octets) : 0 ~ End of clean in 00h06mn51s ---\\ LISTE DES RAPPORTS (2) ZHPCleaner-[S]-05082018-19_05_36.txt ZHPCleaner-[R]-05082018-19_12_39.txt