~ ZHPCleaner v2017.2.27.37 by Nicolas Coolman (2017/02/27)
~ Run by MSI CR-460 (Administrator) (01/03/2017 03:17:18)
~ Web: https://www.nicolascoolman.com
~ Blog: https://nicolascoolman.eu/
~ Facebook : ZHP
~ State version : Version OK
~ Type : Repair
~ Report : C:\Users\MSI CR-460\Desktop\ZHPCleaner.txt
~ Quarantine : C:\Users\MSI CR-460\AppData\Roaming\ZHP\ZHPCleaner_Quarantine.txt
~ UAC : Activate
~ Boot Mode : Normal (Normal boot)
Windows 7 Starter, 32-bit Service Pack 1 (Build 7601)
~ Run by MSI CR-460 (Administrator) (01/03/2017 03:17:18)
~ Web: https://www.nicolascoolman.com
~ Blog: https://nicolascoolman.eu/
~ Facebook : ZHP
~ State version : Version OK
~ Type : Repair
~ Report : C:\Users\MSI CR-460\Desktop\ZHPCleaner.txt
~ Quarantine : C:\Users\MSI CR-460\AppData\Roaming\ZHP\ZHPCleaner_Quarantine.txt
~ UAC : Activate
~ Boot Mode : Normal (Normal boot)
Windows 7 Starter, 32-bit Service Pack 1 (Build 7601)
~ No malicious or unnecessary items found.
—\ Browser internet (2)
DELETED data: HKEY_USERS.DEFAULT\Software\Microsoft\Windows\Curr entVersion\Internet Settings\Connections\SavedLegacySettings [Bad : Port=52737 <-Loopback>] =>Hijacker.Proxy
DELETED data: HKEY_USERS.DEFAULT\Software\Microsoft\Windows\Curr entVersion\Internet Settings\Connections\DefaultConnectionSettings [Bad : Port=52737 <-Loopback>] =>Hijacker.Proxy
—\ Hosts file (1)
~ The hosts file is legitimate (1)
—\ Scheduled automatic tasks. (0)
~ No malicious or unnecessary items found.
—\ Explorer ( File, Folder) (22)
MOVED file: C:\Users\MSI CR-460\AppData\Roaming\Mozilla\Firefox\Profiles\n6sg4 hyy.default\searchplugins\WebSearch.xml =>PUP.Optional.SimpleSearches
MOVED file: C:\Windows\Installer\wix{0592EF96-69D8-4E4B-9CC9-88F58EA86F01}.SchedServiceConfig.rmi =>.Superfluous.Empty
MOVED file: C:\Windows\Installer\wix{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}.SchedServiceConfig.rmi =>.Superfluous.Empty
MOVED file: C:\Windows\Installer\wix{6EE644CD-FC7F-424C-83EA-9C0285C4FB7F}.SchedServiceConfig.rmi =>.Superfluous.Empty
MOVED file: C:\Windows\Installer\wix{8F1ADE4D-EFAC-4F5A-B346-23C2687FAF50}.SchedServiceConfig.rmi =>.Superfluous.Empty
MOVED file: C:\Windows\Installer\wix{CCA1EEA3-555E-4D05-AC46-4B49C6C5D887}.SchedServiceConfig.rmi =>.Superfluous.Empty
MOVED file: C:\Windows\Installer\wix{F53D678E-238F-4A71-9742-08BB6774E9DC}.SchedServiceConfig.rmi =>.Superfluous.Empty
MOVED file: C:\Windows\AutoKMS\AutoKMS.log =>HackTool.AutoKMS
MOVED folder: C:\Users\MSI CR-460\AppData\Local\Google\Chrome\User Data\Default\Extensions\dnligehkhogpcngalffdoomehj cbecna =>.Superfluous.Linkury
MOVED folder: C:\Users\MSI CR-460\AppData\Local\Google\Chrome\User Data\Default\Extensions\gehmndecgbcffhmfjkenpamdge chcgpe =>.Superfluous.Linkury
MOVED folder: C:\Users\MSI CR-460\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccm gmieda =>Hijacker.Browser [ https://epicunitscan.info/00service/update2/crx ]
MOVED folder: C:\Users\MSI CR-460\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi =>PUP.Optional.CrossRider
MOVED folder: C:\Program Files\Ashampoo =>.Superfluous.Empty
MOVED folder: C:\ProgramData\Microsoft Toolkit =>HackTool.AutoKMS
MOVED folder: C:\ProgramData\AutoKMS =>HackTool.AutoKMS
MOVED folder: C:\windows\AutoKMS =>HackTool.AutoKMS
MOVED folder: C:\Users\MSI CR-460\AppData\LocalLow\DataMngr =>PUP.Optional.Datamngr
MOVED folder: C:\Program Files\QuickTime =>Riskware.QuickTime
MOVED folder: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime =>Riskware.QuickTime
MOVED folder: C:\windows\Installer\MSI6442.tmp- =>.Superfluous.Empty
MOVED folder: C:\windows\Installer\MSI687.tmp- =>.Superfluous.Empty
MOVED folder: C:\windows\Installer\MSI9C74.tmp- =>.Superfluous.Empty
—\ Registry ( Key, Value, Data) (7)
DELETED key*: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\d10lpsik1i8c69.clo udfront.net [3548] =>.Superfluous.CloudfrontNet
DELETED key*: HKLM\SOFTWARE\Classes\Interface{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5} [ITool] =>Toolbar.Ask
DELETED key*: HKLM\SOFTWARE\Classes\Allin1Convert_8h.ToolbarProt ector [ProtectorControl Class] =>.Superfluous.MindSpark
DELETED key*: HKLM\SOFTWARE\Classes\Allin1Convert_8h.ToolbarProt ector.1 [ProtectorControl Class] =>.Superfluous.MindSpark
DELETED key*: HKLM\SOFTWARE\Classes\PC2739C7E_FABD_4632_AAD0_F06 3DFE8F006_.PC2739C7E_FABD_4632_AAD0_F063DFE8F006_ [bestadblocker] =>PUP.Optional.BestADBlocker
DELETED key*: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uni nstall{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} [Google Inc.] =>Heuristic.Suspect
DELETED key*: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\PCBooster.exe [C:\Program Files\inKline Global\PC Booster\PCBooster.exe] =>.Superfluous.Energize
—\ Summary of the elements found (15)
Redirecting... =>Hijacker.Proxy
Le repaquetage ou l'empaquetage logiciel peut représenter un risque de sécurité - ZAM =>PUP.Optional.SimpleSearches
Logiciels Potentiellement Superflus (LPS). - ZAM =>.Superfluous.Empty
AutoKMS, Application Potentiellement Superflue. - ZAM =>HackTool.AutoKMS
Redirecting... =>.Superfluous.Linkury
Le repaquetage ou l'empaquetage logiciel peut représenter un risque de sécurité - ZAM =>Hijacker.Browser [ https://epicunitscan.info/00service/update2/crx ]
Redirecting... =>PUP.Optional.CrossRider
https://www.nicolascoolman.com/fr/pup-datamngr/ =>PUP.Optional.Datamngr
https://nicolascoolman.eu/2017/01/15...are-quicktime/ =>Riskware.QuickTime
CloudFront, Réseau de distribution d'Amazon. - ZAM =>.Superfluous.CloudfrontNet
Redirecting... =>Toolbar.Ask
MindSpark, Logiciel Potentiellement Superflu. - ZAM =>.Superfluous.MindSpark
Le repaquetage ou l'empaquetage logiciel peut représenter un risque de sécurité - ZAM =>PUP.Optional.BestADBlocker
Heuristic Suspect, 1 Logiciel Indésirable. - ZAM =>Heuristic.Suspect
Redirecting... =>.Superfluous.Energize
—\ Other deletions. (2)
~ Registry Keys Tracing deleted (1)
~ Remove the old reports ZHPCleaner. (1)
—\ Result of repair
~ Repair carried out successfully
—\ Statistics
~ Items scanned : 2257
~ Items found : 0
~ Items cancelled : 0
~ Items repaired : 31
~ End of clean in 00h00mn52s
~====================
ZHPCleaner-[R]-01032017-03_18_10.txt
ZHPCleaner--28022017-20_30_32.txt
Comment