~ ZHPCleaner v2019.3.25.39 by Nicolas Coolman (2019/03/25) ~ Run by Jean-Marie (Administrator) (26/03/2019 21:19:17) ~ Web: https://www.nicolascoolman.com ~ Blog: https://nicolascoolman.eu/ ~ Facebook : https://www.facebook.com/nicolascoolman1 ~ State version : Version OK ~ Certificate ZHPCleaner: Legal ~ Type : Nettoyer ~ Report : C:\Users\Jean-Marie\Desktop\ZHPCleaner (R).txt ~ Quarantine : C:\Users\Jean-Marie\AppData\Roaming\ZHP\ZHPCleaner_Reg.txt ~ UAC : Activate ~ Boot Mode : Normal (Normal boot) Windows 8, 64-bit (Build 9200) ---\\ ALTERNATE DATA STREAM (ADS). (0) ~ Aucun élément malicieux ou superflu trouvé. ---\\ SERVICE. (0) ~ Aucun élément malicieux ou superflu trouvé. ---\\ NAVIGATEUR INTERNET. (0) ~ Aucun élément malicieux ou superflu trouvé. ---\\ FICHIER HÔTE (Hosts). (0) ~ Aucun élément malicieux ou superflu trouvé. ---\\ TÂCHE PLANIFIÉE. (0) ~ Aucun élément malicieux ou superflu trouvé. ---\\ EXPLORATEUR ( Dossiers, Fichiers ). (32) DEPLACÉ fichier: C:\Users\Jean-Marie\Desktop\ByteFence Anti-Malware.lnk [Bad : C:\Program Files (x86)\ByteFence\ByteFence.exe](.Byte Technologies LLC.) =>.SUP.ByteFence DEPLACÉ fichier: C:\Users\Public\Desktop\Anvi AD Blocker Ultimate.lnk [Bad : C:\OneSafe PC Cleaner\la théorie du complot\Anvi AD Blocker Ultimate\adblocker2.exe](.Anvisoft.) =>.SUP.OneSafePCCleaner DEPLACÉ fichier: C:\Users\Public\Desktop\Disk Analyzer Pro.lnk [Bad : C:\Program Files (x86)\Disk Analyzer Pro\DiskAnalyzerPro.exe](.Systweak.) =>.SUP.Systweak DEPLACÉ fichier: C:\Users\Public\Desktop\Duplicate Photos Fixer Pro.lnk [Bad : C:\Program Files (x86)\Duplicate Photos Fixer Pro\DuplicatePhotosFixerPro.exe](.Systweak.) =>.SUP.Systweak DEPLACÉ fichier: C:\Users\Public\Desktop\Restoro.lnk [Bad : C:\Program Files\Restoro\Restoro.exe](.Restoro.) =>.SUP.Restoro DEPLACÉ fichier: C:\Users\Public\Desktop\StartupBooster.lnk [Bad : K:\OneSafe PC Cleaner\Anvisoft\StartupBooster\StartupBooster.exe](.Anvisoft.) =>.SUP.OneSafePCCleaner DEPLACÉ fichier: C:\Windows\Prefetch\BYTEFENCE-INSTALLER-5.4.1.18.-13D1FA5B.pf =>.SUP.ByteFence DEPLACÉ fichier: C:\Windows\Prefetch\RESTORO.EXE-2600681C.pf =>.SUP.Restoro DEPLACÉ fichier: C:\Windows\Prefetch\RESTOROMAIN.EXE-1EC55EA5.pf =>.SUP.Restoro DEPLACÉ fichier: C:\Windows\Prefetch\RESTOROUI.EXE-7312489B.pf =>.SUP.Restoro DEPLACÉ fichier: C:\Windows\Installer\wix{DE24241A-7C94-4FCD-BAB6-23A18BAF331B}.SchedServiceConfig.rmi =>.SUP.Empty DEPLACÉ fichier: C:\Windows\Installer\MSI49CC.tmp =>.SUP.MSIInstaller DEPLACÉ fichier: C:\Windows\Installer\MSI99F5.tmp =>.SUP.MSIInstaller DEPLACÉ fichier^: C:\Users\Jean-Marie\AppData\Local\temp\~DFEDDF381C2E9FAE51.TMP =>.SUP.Temporary.Other DEPLACÉ dossier: C:\Users\Jean-Marie\AppData\Roaming\mxnitro => DEPLACÉ dossier^: C:\Users\Jean-Marie\AppData\Roaming\DRPSu =>.SUP.DriverPack DEPLACÉ dossier: C:\Users\Jean-Marie\AppData\Roaming\Fighters =>.SUP.SlowPCfighter DEPLACÉ dossier^: C:\Program Files (x86)\BabylonToolbar =>Adware.Babylon DEPLACÉ dossier: C:\OneSafe PC Cleaner =>.SUP.SafePCCleaner DEPLACÉ dossier^: C:\Program Files\ByteFence =>.SUP.ByteFence DEPLACÉ dossier^: C:\Program Files\Restoro =>.SUP.Restoro DEPLACÉ dossier^: C:\ProgramData\Restoro =>.SUP.Restoro DEPLACÉ dossier: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ByteFence Anti-Malware =>.SUP.ByteFence DEPLACÉ dossier: C:\Users\Jean-Marie\AppData\Local\moo0clicdroitpro_restoro_powerdvd365_remo_x0ttoneiconpack_donation4keep_lfsu100%s_finalized setup =>.SUP.Restoro DEPLACÉ dossier^: C:\Program Files (x86)\Fighters =>.SUP.SlowPCfighter DEPLACÉ dossier: C:\ProgramData\Fighters =>.SUP.SlowPCfighter DEPLACÉ dossier: C:\ProgramData\Application Data\IObit\ASCDownloader =>.SUP.AdvancedSystemCare DEPLACÉ dossier: C:\ProgramData\IObit\ASCDownloader =>.SUP.AdvancedSystemCare DEPLACÉ dossier: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fighters =>.SUP.SlowPCfighter DEPLACÉ dossier^: C:\Users\Jean-Marie\AppData\Local\Babylon =>Adware.Babylon DEPLACÉ dossier: C:\Users\Jean-Marie\AppData\Roaming\IObit\Advanced SystemCare =>.SUP.AdvancedSystemCare DEPLACÉ dossier: C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Fighters =>.SUP.SlowPCfighter ---\\ BASE DE REGISTRES ( Clés, Valeurs, Données ). (56) SUPPRIMÉ clé: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{1F096B29-E9DA-4D64-8D63-936BE7762CC5} [http://search.babylon.com/?babsrc=SP_ss&q={searchTerms}&mntrId=763fe89200000000000000ff842e59ab&tlve[...]] [Search the web (Babylon)] =>PUP.Optional.IMBooster SUPPRIMÉ clé**: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{1F096B29-E9DA-4D64-8D63-936BE7762CC5} [http://search.babylon.com/?babsrc=SP_ss&q={searchTerms}&mntrId=763fe89200000000000000ff842e59ab&tlver=1.4.19.19&affID=16553] =>PUP.Optional.IMBooster SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}\1.0 [escortApp 1.0 Type Library] =>Adware.MySearchDial SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} [escortApp 1.0 Type Library] =>Adware.MySearchDial SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\Prod.cap [] =>PUP.Optional.ClaroSearch SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\Babylon.dskBnd [CDskBnd Object] =>Adware.Babylon SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\Babylon.dskBnd.1 [CDskBnd Object] =>Adware.Babylon SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\bbylnApp.appCore [appCore Object] =>Adware.Babylon SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\bbylnApp.appCore.1 [appCore Object] =>Adware.Babylon SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\escort.escortIEPane [escortIEPane Object] =>.SUP.DLLescort SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\escort.escortIEPane.1 [escortIEPane Object] =>.SUP.DLLescort SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\escort.escrtBtn.1 [escrtBtn Object] =>Adware.Babylon SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546} [_IReiEngineEvents] =>PUP.Optional.Legacy SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4} [IReiEngine] =>PUP.Optional.Legacy SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\AppID\esrv.EXE [] =>PUP.Optional.Funmoods SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\AppID\BabylonHelper.EXE [] =>Adware.Babylon SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\AppID\escort.dll [] =>Adware.Babylon SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr [CescrtHlpr Object] =>Adware.Babylon SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1 [CescrtHlpr Object] =>Adware.Babylon SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\bbylntlbr.xtrnl [escrtAx Object] =>Adware.Babylon SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\bbylntlbr.xtrnl.1 [escrtAx Object] =>Adware.Babylon SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\Restoro.Engine [Restoro Class] =>.SUP.Restoro SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\Restoro.Engine.1 [Restoro Class] =>.SUP.Restoro SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\CLSID\{25C88C47-EB26-40D1-BDC7-BBB30E0F752B} [SlimWare Services Session Server] =>.SUP.SlimWareUtilities SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\CLSID\{36137FA3-91C0-48EF-B1A8-27C1974708B8} [SlimWare Services Session] =>.SUP.SlimWareUtilities SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\CLSID\{BA827421-E282-479E-AE60-34796877B8AE} [Restoro Class] =>.SUP.Restoro SUPPRIMÉ clé*: HKCU\Software\drpsu [] =>.SUP.DriverPack SUPPRIMÉ clé*: HKCU\Software\Fighters [] =>.SUP.SlowPCfighter SUPPRIMÉ clé*: HKCU\Software\undefined [] =>.SUP.Downloader SUPPRIMÉ clé*: HKCU\Software\Local AppWizard-Generated Applications\Restoro [] =>.SUP.Restoro SUPPRIMÉ clé*: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Restoro [] =>.SUP.Restoro SUPPRIMÉ clé*: HKLM\SOFTWARE\Wow6432Node\drpsu [] =>.SUP.DriverPack SUPPRIMÉ clé*: HKLM\SOFTWARE\Wow6432Node\ByteFence [] =>.SUP.ByteFence SUPPRIMÉ clé*: HKLM\SOFTWARE\Wow6432Node\Fighters [] =>.SUP.SlowPCfighter SUPPRIMÉ clé*: HKLM\SOFTWARE\ByteFence [] =>.SUP.ByteFence SUPPRIMÉ clé*: HKLM\SOFTWARE\Restoro [] =>.SUP.Restoro SUPPRIMÉ clé*: HKLM\SOFTWARE\Classes\*\shell\ByteFence File Scan [Scanner avec Bytefence Anti- Malware...] =>.SUP.ByteFence SUPPRIMÉ clé*: HKLM\SOFTWARE\Classes\Directory\Shell\ByteFence Folder Scan [] =>.SUP.ByteFence SUPPRIMÉ clé*: HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} [] =>PUP.Optional.Legacy SUPPRIMÉ clé**: [X64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Restoro [Restoro] =>.SUP.Restoro SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{84A89263-AA96-41D0-8345-77A704A76B4C} [Slimware Utilities Holdings, Inc.] =>.SUP.SlimWareUtilities SUPPRIMÉ clé**: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\AppID\esrv.EXE [] =>PUP.Optional.Funmoods SUPPRIMÉ clé**: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\AppID\BabylonHelper.EXE [] =>Adware.Babylon SUPPRIMÉ clé**: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\AppID\escort.dll [] =>Adware.Babylon SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546} [_IReiEngineEvents] =>PUP.Optional.Legacy SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4} [IReiEngine] =>PUP.Optional.Legacy SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ByteFence [Byte Technologies LLC] =>.SUP.ByteTechnologies SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} [AVG Technologies] =>Heuristic.Suspect SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\CLSID\{AE198C69-7358-4856-9029-F4C0FAD524C1} [CompReg Class] =>.SUP.Restoro SUPPRIMÉ clé**: [X64] HKLM\SOFTWARE\Classes\CLSID\{AE198C69-7358-4856-9029-F4C0FAD524C1}\InprocServer32 [C:\Program Files\Restoro\ax.dll] =>.SUP.Restoro SUPPRIMÉ clé**: [X64] HKLM\SOFTWARE\Classes\CLSID\{BA827421-E282-479E-AE60-34796877B8AE}\InprocServer32 [C:\Program Files\Restoro\ax.dll] =>.SUP.Restoro SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\CLSID\{BDF76960-B341-4592-BDBA-DFC8C74165A9} [PSFactoryBuffer] =>.SUP.SlimWareUtilities SUPPRIMÉ clé**: [X64] HKLM\SOFTWARE\Classes\CLSID\{BDF76960-B341-4592-BDBA-DFC8C74165A9}\InprocServer32 [C:\Program Files\SlimWare Utilities\Services\SlimWare.Session.ProxyStub.dll (Not File)] =>.SUP.SlimWareUtilities SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\CLSID\{E58DA376-0D39-45ED-A6EE-A7B6DD10BED2} [PSFactoryBuffer] =>.SUP.SlimWareUtilities SUPPRIMÉ clé**: [X64] HKLM\SOFTWARE\Classes\CLSID\{E58DA376-0D39-45ED-A6EE-A7B6DD10BED2}\InprocServer32 [C:\Program Files\SlimWare Utilities\Services\SlimWare.Services.ProxyStub.dll (Not File)] =>.SUP.SlimWareUtilities SUPPRIMÉ valeur: HKLM64\SOFTWARE\Wow6432Node\Mozilla\Firefox\Extensions\\MoraeFirefoxExtension@techsmith.com [C:\Program Files (x86)\TechSmith\Morae\BrowserExtensions\Firefox\morae_firefox_extension-1.0-fx-windows.xpi] =>.SUP.BrowserExtension ---\\ RÉCAPITULATIF DES ÉLÉMENTS TROUVÉS SUR VOTRE STATION. (23) https://nicolascoolman.eu/2017/03/13/superfluous-bytefence/ =>.SUP.ByteFence https://www.anti-malware.top/2016/08/21/superfluous-onesafepccleaner/ =>.SUP.OneSafePCCleaner https://nicolascoolman.eu/2017/09/14/sup-systweak/ =>.SUP.Systweak https://nicolascoolman.eu/2018/08/17/sup-restoro/ =>.SUP.Restoro https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.SUP.Empty https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.SUP.MSIInstaller https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.SUP.Temporary.Other https://nicolascoolman.eu/2018/07/04/sup-driverpack/ =>.SUP.DriverPack https://nicolascoolman.eu/2017/09/26/sup-slowpcfighter/ =>.SUP.SlowPCfighter https://nicolascoolman.eu/2017/03/03/adware-babylon/ =>Adware.Babylon https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.SUP.SafePCCleaner https://nicolascoolman.eu/2017/12/26/sup-advancedsystemcare/ =>.SUP.AdvancedSystemCare https://nicolascoolman.eu/2017/09/08/adware-imbooster/ =>PUP.Optional.IMBooster https://nicolascoolman.eu/2017/12/23/adware-mysearchdial/ =>Adware.MySearchDial https://www.nicolascoolman.com/fr/pup-clarosearch/ =>PUP.Optional.ClaroSearch https://nicolascoolman.eu/2018/02/16/sup-dllescort/ =>.SUP.DLLescort https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>PUP.Optional.Legacy https://www.nicolascoolman.com/fr/pup-funmoods/ =>PUP.Optional.Funmoods https://nicolascoolman.eu/2017/03/03/superfluous-slimwareutilities/ =>.SUP.SlimWareUtilities https://nicolascoolman.eu/2017/12/22/sup-downloader/ =>.SUP.Downloader https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.SUP.ByteTechnologies https://nicolascoolman.eu/2017/01/28/heuristic-suspect/ =>Heuristic.Suspect https://nicolascoolman.eu/2017/10/05/sup-browserextension/ =>.SUP.BrowserExtension ---\\ NETTOYAGE ADDITIONNEL. (14) ~ Suppression des Clés de registre Tracing. (14) ~ Suppression des anciens rapports ZHPCleaner. (0) ---\\ BILAN DE LA REPARATION ~ Réparation réalisée avec succès. ~ Le système a été redémarré. ---\\ STATISTIQUES ~ Items scannés : 1208 ~ Items trouvés : 0 ~ Items annulés : 0 ~ Items options : 12/12 ~ Gain de place (Octets) : 16384 ~ End of clean in 00h10mn58s ---\\ LISTE DES RAPPORTS (2) ZHPCleaner-[S]-26032019-20_48_35.txt ZHPCleaner-[R]-26032019-21_30_15.txt