~ ZHPCleaner v2017.7.6.115 by Nicolas Coolman (2017/07/06) ~ Run by WELTINFO (Administrator) (08/07/2017 20:42:33) ~ Web: https://www.nicolascoolman.com ~ Blog: https://nicolascoolman.eu/ ~ Facebook : https://www.facebook.com/nicolascoolman1 ~ State version : Version KO ~ Certificate ZHPCleaner: Legal ~ Type : Nettoyer ~ Report : C:\Users\WELTINFO\Desktop\ZHPCleaner.txt ~ Quarantine : C:\Users\WELTINFO\AppData\Roaming\ZHP\ZHPCleaner_Reg.txt ~ UAC : Activate ~ Boot Mode : Normal (Normal boot) Windows 7 Home Premium, 64-bit Service Pack 1 (Build 7601) ---\\ Service. (0) ~ Aucun élément malicieux ou superflu trouvé. ---\\ Navigateur internet. (0) ~ Aucun élément malicieux ou superflu trouvé. ---\\ Fichier hôte. (0) ~ Aucun élément malicieux ou superflu trouvé. ---\\ Tâche planifiée. (0) ~ Aucun élément malicieux ou superflu trouvé. ---\\ Explorateur ( Dossiers, Fichiers ). (45) DEPLACÉ fichier: C:\Users\WELTINFO\AppData\Roaming\Mozilla\Firefox\Profiles\er3ymino.default-1461349838011\storage\temporary\http+++game256923.konggames.com\.metadata =>PUP.Optional.KongGames DEPLACÉ fichier: C:\Users\WELTINFO\AppData\Roaming\Mozilla\Firefox\Profiles\er3ymino.default-1461349838011\storage\temporary\http+++game256923.konggames.com\.metadata-v2 =>PUP.Optional.KongGames DEPLACÉ fichier: C:\Users\WELTINFO\AppData\Roaming\Mozilla\Firefox\Profiles\er3ymino.default-1461349838011\storage\temporary\http+++game256923.konggames.com\asmjs\metadata =>PUP.Optional.KongGames DEPLACÉ fichier: C:\Users\WELTINFO\AppData\Roaming\Mozilla\Firefox\Profiles\er3ymino.default-1461349838011\storage\temporary\http+++game256923.konggames.com\asmjs\module14 =>PUP.Optional.KongGames DEPLACÉ fichier: C:\Users\WELTINFO\AppData\Roaming\Mozilla\Firefox\Profiles\er3ymino.default-1461349838011\storage\temporary\http+++game256923.konggames.com\asmjs\module15 =>PUP.Optional.KongGames DEPLACÉ fichier: C:\Users\WELTINFO\AppData\Roaming\Mozilla\Firefox\Profiles\er3ymino.default-1461349838011\storage\default\http+++game256923.konggames.com\.metadata =>PUP.Optional.KongGames DEPLACÉ fichier: C:\Users\WELTINFO\AppData\Roaming\Mozilla\Firefox\Profiles\er3ymino.default-1461349838011\storage\default\http+++game256923.konggames.com\.metadata-v2 =>PUP.Optional.KongGames DEPLACÉ fichier: C:\Users\WELTINFO\AppData\Roaming\Mozilla\Firefox\Profiles\er3ymino.default-1461349838011\storage\default\http+++game256923.konggames.com\idb\2083995541%s2fFbid.sqlite =>PUP.Optional.KongGames DEPLACÉ fichier: C:\Users\WELTINFO\AppData\Roaming\Mozilla\Firefox\Profiles\er3ymino.default-1461349838011\storage\default\http+++game256923.konggames.com\idb\471098692%t2sFeitd-bsf.sqlite =>PUP.Optional.KongGames DEPLACÉ fichier: C:\Users\WELTINFO\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_jidkebcigjgheaahopdnlfaohgnocfai_0.localstorage =>PUP.Optional.SmartBar DEPLACÉ fichier: C:\Users\WELTINFO\AppData\Roaming\ZonSonlex.exe =>Adware.Pirrit DEPLACÉ fichier: C:\Windows\Temp\bbbripdx.exe =>Heuristic.Suspect DEPLACÉ fichier: C:\Users\WELTINFO\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_d16fk4ms6rqz1v.cloudfront.net_0.localstorage =>.Superfluous.CloudfrontNet DEPLACÉ fichier: C:\Users\WELTINFO\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_d16fk4ms6rqz1v.cloudfront.net_0.localstorage-journal =>.Superfluous.CloudfrontNet DEPLACÉ fichier: C:\Users\WELTINFO\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_d19tqk5t6qcjac.cloudfront.net_0.localstorage =>.Superfluous.CloudfrontNet DEPLACÉ fichier: C:\Users\WELTINFO\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_d19tqk5t6qcjac.cloudfront.net_0.localstorage-journal =>.Superfluous.CloudfrontNet DEPLACÉ fichier: C:\Users\WELTINFO\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_ol.uk.at.atwola.com_0.localstorage =>.Superfluous.Atwola DEPLACÉ fichier: C:\Users\WELTINFO\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_ol.uk.at.atwola.com_0.localstorage-journal =>.Superfluous.Atwola DEPLACÉ fichier: C:\Users\WELTINFO\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.audienceinsights.net_0.localstorage =>.Superfluous.AudienceInsights DEPLACÉ fichier: C:\Users\WELTINFO\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.audienceinsights.net_0.localstorage-journal =>.Superfluous.AudienceInsights DEPLACÉ fichier: C:\Users\WELTINFO\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_download.bringmesports.com_0.localstorage =>.Superfluous.MindSpark DEPLACÉ fichier: C:\Users\WELTINFO\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_download.bringmesports.com_0.localstorage-journal =>.Superfluous.MindSpark DEPLACÉ fichier: C:\Users\WELTINFO\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_funsafetab.com_0.localstorage =>PUP.Optional.SocialMediaNewTab DEPLACÉ fichier: C:\Users\WELTINFO\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_funsafetab.com_0.localstorage-journal =>PUP.Optional.SocialMediaNewTab DEPLACÉ fichier: C:\Users\WELTINFO\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_internetspeedtracker.dl.myway.com_0.localstorage =>.Superfluous.MindSpark DEPLACÉ fichier: C:\Users\WELTINFO\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_internetspeedtracker.dl.myway.com_0.localstorage-journal =>.Superfluous.MindSpark DEPLACÉ fichier: C:\Users\WELTINFO\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_internetspeedtracker.dl.tb.ask.com_0.localstorage =>.Superfluous.MindSpark DEPLACÉ fichier: C:\Users\WELTINFO\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_internetspeedtracker.dl.tb.ask.com_0.localstorage-journal =>.Superfluous.MindSpark DEPLACÉ fichier: C:\Users\WELTINFO\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_search.funmediatabsearch.com_0.localstorage =>.Superfluous.FunMediaTab DEPLACÉ fichier: C:\Users\WELTINFO\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_search.funmediatabsearch.com_0.localstorage-journal =>.Superfluous.FunMediaTab DEPLACÉ fichier: C:\Users\WELTINFO\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_search.funsafetabsearch.com_0.localstorage =>PUP.Optional.SocialMediaNewTab DEPLACÉ fichier: C:\Users\WELTINFO\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_search.funsafetabsearch.com_0.localstorage-journal =>PUP.Optional.SocialMediaNewTab DEPLACÉ fichier: C:\Users\WELTINFO\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_st.chatango.com_0.localstorage =>PUP.Optional.Chatango DEPLACÉ fichier: C:\Users\WELTINFO\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_st.chatango.com_0.localstorage-journal =>PUP.Optional.Chatango DEPLACÉ fichier: C:\Users\WELTINFO\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.audienceinsights.net_0.localstorage =>.Superfluous.AudienceInsights DEPLACÉ fichier: C:\Users\WELTINFO\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.audienceinsights.net_0.localstorage-journal =>.Superfluous.AudienceInsights DEPLACÉ fichier: C:\Users\WELTINFO\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_videodownloadconverter.dl.myway.com_0.localstorage =>PUP.Optional.VideoDownloadConverter DEPLACÉ fichier: C:\Users\WELTINFO\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_videodownloadconverter.dl.myway.com_0.localstorage-journal =>PUP.Optional.VideoDownloadConverter DEPLACÉ fichier: C:\Users\WELTINFO\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_videodownloadconverter.dl.tb.ask.com_0.localstorage =>PUP.Optional.VideoDownloadConverter DEPLACÉ fichier: C:\Users\WELTINFO\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_videodownloadconverter.dl.tb.ask.com_0.localstorage-journal =>PUP.Optional.VideoDownloadConverter DEPLACÉ fichier: C:\Users\WELTINFO\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.radiorage.com_0.localstorage =>.Superfluous.MindSpark DEPLACÉ fichier: C:\Users\WELTINFO\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.radiorage.com_0.localstorage-journal =>.Superfluous.MindSpark DEPLACÉ dossier: C:\Users\WELTINFO\AppData\Local\Google\Chrome\User Data\Default\Extensions\jidkebcigjgheaahopdnlfaohgnocfai =>PUP.Optional.SmartBar DEPLACÉ dossier: C:\ProgramData\Logic Handler =>PUP.Optional.LogicHandler DEPLACÉ dossier: C:\Users\WELTINFO\AppData\Local\Google\Chrome\User Data\Default\File System\008 =>PUP.Optional.DomaIQ ---\\ Base de Registres ( Clés, Valeurs, Données ). (34) SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\jidkebcigjgheaahopdnlfaohgnocfai [] =>PUP.Optional.SmartBar SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\1916A2AF346D399F50313C393200F14140456616 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\2B84BFBB34EE2EF949FE1CBE30AA026416EB2216 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\305F8BD17AA2CBC483A4C41B19A39A0C75DA39D6 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\367D4B3B4FCBBC0B767B2EC0CDB2A36EAB71A4EB [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\40AA38731BD189F9CDB5B9DC35E2136F38777AF4 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\43D9BCB568E039D073A74A71D8511F7476089CC3 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\471C949A8143DB5AD5CDF1C972864A2504FA23C9 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\51C3247D60F356C7CA3BAF4C3F429DAC93EE7B74 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\5DE83EE82AC5090AEA9D6AC4E7A6E213F946E179 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\61793FCBFA4F9008309BBA5FF12D2CB29CD4151A [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\637162CC59A3A1E25956FA5FA8F60D2E1C52EAC6 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\63FEAE960BAA91E343CE2BD8B71798C76BDB77D0 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\6431723036FD26DEA502792FA595922493030F97 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\7D7F4414CCEF168ADF6BF40753B5BECD78375931 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\80962AE4D6C5B442894E95A13E4A699E07D694CF [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\86E817C81A5CA672FE000F36F878C19518D6F844 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\8E5BD50D6AE686D65252F843A9D4B96D197730AB [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\9845A431D51959CAF225322B4A4FE9F223CE6D15 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\B533345D06F64516403C00DA03187D3BFEF59156 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\B86E791620F759F17B8D25E38CA8BE32E7D5EAC2 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\C060ED44CBD881BD0EF86C0BA287DDCF8167478C [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\CEA586B2CE593EC7D939898337C57814708AB2BE [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\D018B62DC518907247DF50925BB09ACF4A5CB3AD [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\F8A54E03AADC5692B850496A4C4630FFEAA29D83 [Avast Software] =>PUM.Misplaced.Certificate SUPPRIMÉ clé*: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\safefinder.com [] =>PUP.Optional.Browser SUPPRIMÉ clé*: HKCU\Software\csastats [] =>Adware.InstallCore SUPPRIMÉ clé*: HKCU\Software\ProductSetup [] =>Adware.InstallCore SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Quotenamron.exe [] =>PUP.Optional.Salus SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\QuotenamronU [] =>PUP.Optional.Salus SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\mtQuotenamron [] =>PUP.Optional.Salus SUPPRIMÉ clé: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\QuotenamronU [] =>PUP.Optional.Salus SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Quotenamron_RASAPI32 [] =>PUP.Optional.Salus SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Quotenamron_RASMANCS [] =>PUP.Optional.Salus ---\\ Récapitulatif des éléments trouvés sur votre station. (18) https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>PUP.Optional.KongGames https://www.nicolascoolman.com/fr/hijacker-smartbar/ =>PUP.Optional.SmartBar https://nicolascoolman.eu/2017/02/25/adware-pirrit/ =>Adware.Pirrit https://nicolascoolman.eu/2017/01/28/heuristic-suspect/ =>Heuristic.Suspect https://nicolascoolman.eu/2017/02/02/superfluous-cloudfrontnet/ =>.Superfluous.CloudfrontNet https://nicolascoolman.eu/2017/02/04/superfluous-atwola/ =>.Superfluous.Atwola https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.Superfluous.AudienceInsights https://nicolascoolman.eu/2017/01/15/superfluous-mindspark/ =>.Superfluous.MindSpark https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>PUP.Optional.SocialMediaNewTab https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.Superfluous.FunMediaTab https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>PUP.Optional.Chatango https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>PUP.Optional.VideoDownloadConverter https://nicolascoolman.eu/2017/01/04/pup-optional-logichandler/ =>PUP.Optional.LogicHandler https://www.nicolascoolman.com/fr/adware-domaiq/ =>PUP.Optional.DomaIQ https://nicolascoolman.eu/2017/06/26/trojan-certlock/ =>PUM.Misplaced.Certificate https://nicolascoolman.eu/2017/01/26/hijacker-browser/ =>PUP.Optional.Browser https://nicolascoolman.eu/2017/03/12/adware-installcore-2/ =>Adware.InstallCore https://www.nicolascoolman.com/fr/pup-salus/ =>PUP.Optional.Salus ---\\ Nettoyage Additionnel. (31) ~ Suppression des Clés de registre Tracing. (31) ~ Suppression des anciens rapports ZHPCleaner. (0) ---\\ Bilan de la réparation ~ Réparation réalisée avec succès. ~ Ce navigateur est absent (Opera Software) ---\\ Statistiques ~ Items scannés : 780 ~ Items trouvés : 0 ~ Items annulés : 0 ~ Items réparés : 79 ~ End of clean in 00h00mn53s ~==================== ZHPCleaner-[R]-08072017-20_43_26.txt ZHPCleaner-[R]-14042016-21_28_46.txt ZHPCleaner-[S]-08072017-19_54_24.txt ZHPCleaner-[S]-08072017-20_42_08.txt ZHPCleaner-[S]-14042016-21_20_27.txt