~ ZHPCleaner v2016.12.30.225 by Nicolas Coolman (2016/12/30) ~ Run by USER (Administrator) (30/12/2016 22:23:43) ~ Web: https://www.nicolascoolman.com ~ Blog: https://www.anti-malware.top ~ Facebook : https://www.facebook.com/nicolascoolman1 ~ State version : ~ Type : Nettoyer ~ Report : C:\Users\USER\Desktop\ZHPCleaner.txt ~ Quarantine : C:\Users\USER\AppData\Roaming\ZHP\ZHPCleaner_Quarantine.txt ~ UAC : Activate ~ Boot Mode : Normal (Normal boot) Windows 7 Professional, 64-bit (Build 7600) ---\\ Service. (0) ~ Aucun élément malicieux ou superflu trouvé. ---\\ Navigateur internet. (1) REMPLACÉ Google Chrome Preferences: "https://fb-s-d-a.akamaihd.net/" =>.Superfluous.AkamaiHD ---\\ Fichier hôte. (1) ~ Le fichier hôte est légitime. (25) ---\\ Tâche planifiée. (0) ~ Aucun élément malicieux ou superflu trouvé. ---\\ Explorateur ( Dossiers, Fichiers ). (11) DEPLACÉ fichier: C:\Users\USER\AppData\Roaming\ApplicationHosting.dat =>PUP.Optional.ApplicationHosting DEPLACÉ fichier: C:\Users\USER\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_cdncache-a.akamaihd.net_0.localstorage =>.Superfluous.AkamaiHD DEPLACÉ fichier: C:\Users\USER\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_cdncache-a.akamaihd.net_0.localstorage-journal =>.Superfluous.AkamaiHD DEPLACÉ fichier: C:\Users\USER\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_d10lpsik1i8c69.cloudfront.net_0.localstorage =>.Superfluous.CloudfrontNet DEPLACÉ fichier: C:\Users\USER\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_d10lpsik1i8c69.cloudfront.net_0.localstorage-journal =>.Superfluous.CloudfrontNet DEPLACÉ fichier: C:\Users\USER\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_s0ft4pc.com_0.localstorage =>.Superfluous.EORezo DEPLACÉ fichier: C:\Users\USER\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_s0ft4pc.com_0.localstorage-journal =>.Superfluous.EORezo DEPLACÉ fichier: C:\Users\USER\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.coupontime00.coupontime.co_0.localstorage =>PUP.Optional.CouponTime DEPLACÉ fichier: C:\Users\USER\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.coupontime00.coupontime.co_0.localstorage-journal =>PUP.Optional.CouponTime DEPLACÉ fichier^: C:\Users\USER\AppData\Local\app =>PUP.Optional.CrossRider DEPLACÉ dossier: C:\Users\USER\AppData\Local\Google\Chrome\User Data\Default\File System\008 =>PUP.Optional.DomaIQ ---\\ Base de Registres ( Clés, Valeurs, Données ). (21) SUPPRIMÉ clé: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{ielnksrch} [http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sN[...]] [Search the web] =>PUP.Optional.IMBooster SUPPRIMÉ clé: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\ielnksrch [http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sN[...]] [Search the web] =>PUP.Optional.IMBooster SUPPRIMÉ donnée: [X64] HKLM\SOFTWARE\Classes\BaiduSparkHTML\Shell\Open\Command\\Default [Bad : [html] "C:\Program Files (x86)\baidu\Baidu Browser\Spark.exe" -- "%1"] =>Broken.OpenCommand SUPPRIMÉ clé: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{ielnksrch} [http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoH2TlPbfGRogFok1dGdSxtSSRDeTxYkRgQEsutSwCJhN_UyMGRQBJC5aolADhufcigHczPOZDjZ9hUMjx9xX9F87pBrcuELYRJFoqMmpNL6aHsULFVAoQpwykajgmblZUFWjbPbFBxgaOImz88Hp7vOVh9CvXyiWRMxe4aA,&q={searchTerms}] =>PUP.Optional.IMBooster SUPPRIMÉ clé: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\ielnksrch [http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoH2TlPbfGRogFok1dGdSxtSSRDeTxYkRgQEsutSwCJhN_UyMGRQBJC5aolADhufcigHczPOZDjZ9hUMjx9xX9F87pBrcuELYRJFoqMmpNL6aHsULFVAoQpwykajgmblZUFWjbPbFBxgaOImz88Hp7vOVh9CvXyiWRMxe4aA,&q={searchTerms}] =>PUP.Optional.IMBooster SUPPRIMÉ clé*: HKEY_USERS\S-1-5-21-506902913-3260032894-634671402-1000\SOFTWARE\InstallMonster [] =>Adware.InstallMonster SUPPRIMÉ clé: HKCU\Software\InstallMonster [] =>Adware.InstallMonster SUPPRIMÉ clé*: HKCU\Software\Mozilla\Extends [] =>PUP.Optional.FastStart SUPPRIMÉ clé*: HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WdsManPro [] =>PUP.Optional.WdsManPro SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Microsoft\Tracing\ByteFence_RASAPI32 [] =>.Superfluous.ByteFence SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Microsoft\Tracing\ByteFence_RASMANCS [] =>.Superfluous.ByteFence SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\4723_cor_istartsurf_RASAPI32 [] =>PUP.Optional.IsStart SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\4723_cor_istartsurf_RASMANCS [] =>PUP.Optional.IsStart SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\CloudPrinter_RASAPI32 [] =>.Superfluous.Linkury SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\CloudPrinter_RASMANCS [] =>.Superfluous.Linkury SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\InstallMonster_Download_Manager_RASAPI32 [] =>Adware.InstallMonster SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\InstallMonster_Download_Manager_RASMANCS [] =>Adware.InstallMonster SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\WdsManPro_RASAPI32 [] =>PUP.Optional.WdsManPro SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\WdsManPro_RASMANCS [] =>PUP.Optional.WdsManPro SUPPRIMÉ valeur: HKLM64\SOFTWARE\Wow6432Node\Mozilla\Firefox\Extensions\\defsearchp@gmail.com [C:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\ngfh75x1.default\extensions\defsearchp@gmail.com] =>PUP.Optional.PriceFountain SUPPRIMÉ valeur: HKLM64\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\\SMΔRT-Protection [C:\Program Files (x86)\SMADAV\SMΔRTP.exe] =>Heuristic.Salus ---\\ Récapitulatif des éléments trouvés sur votre station. (17) https://www.nicolascoolman.com/fr/logiciels-superflus =>.Superfluous.AkamaiHD https://www.nicolascoolman.com/fr/repaquetage-et_infections/ =>PUP.Optional.ApplicationHosting https://www.anti-malware.top/2016/08/31/cloudfront-net/ =>.Superfluous.CloudfrontNet https://www.nicolascoolman.com/fr/pup-eorezo/ =>.Superfluous.EORezo https://www.nicolascoolman.com/fr/repaquetage-et_infections/ =>PUP.Optional.CouponTime https://www.anti-malware.top/2016/04/30/pup-optional-crossrider/ =>PUP.Optional.CrossRider https://www.nicolascoolman.com/fr/adware-domaiq/ =>PUP.Optional.DomaIQ https://www.nicolascoolman.com/fr/adware-imbooster/ =>PUP.Optional.IMBooster https://www.nicolascoolman.com/fr/repaquetage-et_infections/ =>Broken.OpenCommand https://www.nicolascoolman.com/fr/repaquetage-et_infections/ =>Adware.InstallMonster https://www.nicolascoolman.com/fr/repaquetage-et_infections/ =>PUP.Optional.FastStart https://www.anti-malware.top/2016/05/20/pup-optional-wdsmanpro/ =>PUP.Optional.WdsManPro https://www.anti-malware.top/2016/04/29/superfluous-bytefence/ =>.Superfluous.ByteFence https://www.nicolascoolman.com/fr/pup-isstart/ =>PUP.Optional.IsStart https://www.anti-malware.top/2016/08/02/superfluous-linkury/ =>.Superfluous.Linkury https://www.nicolascoolman.com/fr/repaquetage-et_infections/ =>PUP.Optional.PriceFountain https://www.nicolascoolman.com/fr/repaquetage-et_infections/ =>Heuristic.Salus ---\\ Nettoyage Additionnel. (185) ~ Suppression des Clés de registre Tracing. (185) ~ Suppression des anciens rapports ZHPCleaner. (0) ---\\ Bilan de la réparation ~ Réparation réalisée avec succès. ~ Le système a été redémarré. ---\\ Statistiques ~ Items scannés : 3525 ~ Items trouvés : 0 ~ Items annulés : 0 ~ Items réparés : 33 ~ End of clean in 00h01mn07s ~==================== ZHPCleaner-[R]-30122016-22_24_50.txt ZHPCleaner-[S]-30122016-22_23_22.txt