~ ZHPCleaner v2017.2.16.28 by Nicolas Coolman (2017/02/16)
~ Run by CRJ (Administrator) (18/02/2017 09:47:57)
~ Web:
https://www.nicolascoolman.com
~ Blog:
https://nicolascoolman.eu/
~ Facebook :
https://www.facebook.com/nicolascoolman1
~ State version : Version OK
~ Type : Repair
~ Report : C:\Users\CRJ\Desktop\ZHPCleaner.txt
~ Quarantine : C:\Users\CRJ\AppData\Roaming\ZHP\ZHPCleaner_Quarantine.txt
~ UAC : Activate
~ Boot Mode : Normal (Normal boot)
Windows 10 Home, 64-bit (Build 10586)
---\\ Services (1)
CLOSED : EasyTuneEngineService =>Heuristic.Pirrit
---\\ Browser internet (0)
~ No malicious or unnecessary items found.
---\\ Hosts file (1)
~ The hosts file is legitimate (1)
---\\ Scheduled automatic tasks. (0)
~ No malicious or unnecessary items found.
---\\ Explorer ( File, Folder) (30)
MOVED file: C:\Windows\Installer\wix{2E4AF2A6-50EA-4260-9BA4-5E582D11879A}.SchedServiceConfig.rmi =>.Superfluous.Empty
MOVED file: C:\Windows\Installer\wix{3540181E-340A-4E7A-B409-31663472B2F7}.SchedServiceConfig.rmi =>.Superfluous.Empty
MOVED file: C:\Windows\Installer\wix{55BB2110-FB43-49B3-93F4-945A0CFB0A6C}.SchedServiceConfig.rmi =>.Superfluous.Empty
MOVED file: C:\Windows\Installer\wix{CDB60A91-DA13-41AA-A827-7967BEC75AF8}.SchedServiceConfig.rmi =>.Superfluous.Empty
MOVED file: C:\Windows\Installer\wix{D4D86CB2-2370-4691-8272-3869EDED6C64}.SchedServiceConfig.rmi =>.Superfluous.Empty
MOVED file: C:\Users\CRJ\AppData\Local\Temp\wct880C.tmp =>.Superfluous.Temporary.Various
MOVED file: C:\Users\CRJ\AppData\Local\Temp\wct8F76.tmp =>.Superfluous.Temporary.Various
MOVED folder^: C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService =>Heuristic.Pirrit
MOVED folder: C:\Program Files (x86)\QuickTime =>Riskware.QuickTime
MOVED folder: C:\Users\CRJ\AppData\Local\Google\Chrome\User Data\Default\File System\008 =>PUP.Optional.DomaIQ
MOVED folder: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime =>Riskware.QuickTime
MOVED folder: C:\Windows\Installer\MSI1EDB.tmp- =>.Superfluous.Empty
MOVED folder: C:\Windows\Installer\MSI1F69.tmp- =>.Superfluous.Empty
MOVED folder: C:\Windows\Installer\MSI1FB8.tmp- =>.Superfluous.Empty
MOVED folder: C:\Windows\Installer\MSI28F7.tmp- =>.Superfluous.Empty
MOVED folder: C:\Windows\Installer\MSI307A.tmp- =>.Superfluous.Empty
MOVED folder: C:\Windows\Installer\MSI30E9.tmp- =>.Superfluous.Empty
MOVED folder: C:\Windows\Installer\MSI3138.tmp- =>.Superfluous.Empty
MOVED folder: C:\Windows\Installer\MSI7C30.tmp- =>.Superfluous.Empty
MOVED folder: C:\Windows\Installer\MSI7CEC.tmp- =>.Superfluous.Empty
MOVED folder: C:\Windows\Installer\MSI7DB9.tmp- =>.Superfluous.Empty
MOVED folder: C:\Windows\Installer\MSI8346.tmp- =>.Superfluous.Empty
MOVED folder: C:\Windows\Installer\MSI83A5.tmp- =>.Superfluous.Empty
MOVED folder: C:\Windows\Installer\MSI8413.tmp- =>.Superfluous.Empty
MOVED folder: C:\Windows\Installer\MSI980A.tmp- =>.Superfluous.Empty
MOVED folder: C:\Windows\Installer\MSI9916.tmp- =>.Superfluous.Empty
MOVED folder: C:\Windows\Installer\MSICFD6.tmp- =>.Superfluous.Empty
MOVED folder: C:\Windows\Installer\MSID1BE.tmp- =>.Superfluous.Empty
MOVED folder: C:\Windows\Installer\MSID733.tmp- =>.Superfluous.Empty
MOVED folder: C:\Windows\Installer\MSIDE0B.tmp- =>.Superfluous.Empty
---\\ Registry ( Key, Value, Data) (5)
DELETED key*: HKLM\SYSTEM\CurrentControlSet\Services\EasyTuneEngineService [C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\EasyTuneEngineService.exe] =>Heuristic.Pirrit
DELETED key*: HKLM\SYSTEM\CurrentControlSet\Services\OcButtonService [C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\OcButtonService.exe (Not File)] =>Heuristic.Pirrit
DELETED key*: [X64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\018DB0496FC46614CBED2103F75B7262 [C:\?Program Files (x86)\GIGABYTE\EasyTuneEngineService\acpimof_ocpanel.dll (Not File)] =>Heuristic.Pirrit
DELETED key*: [X64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E5B51D5DDC32D34390DD1AF91EF7BA2 [C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\Languages\ARA\ (Not File)] =>Heuristic.Pirrit
DELETED key*: [X64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E779259750044C565F4587810BED609 [C:\?Program Files (x86)\GIGABYTE\EasyTuneEngineService\ICCProxy.exe (Not File)] =>Heuristic.Pirrit
---\\ Summary of the elements found (5)
https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>Heuristic.Pirrit
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.Superfluous.Empty
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.Superfluous.Temporary.Various
https://nicolascoolman.eu/2017/01/15/riskware-quicktime/ =>Riskware.QuickTime
https://www.nicolascoolman.com/fr/adware-domaiq/ =>PUP.Optional.DomaIQ
---\\ Other deletions. (20)
~ Registry Keys Tracing deleted (20)
~ Remove the old reports ZHPCleaner. (0)
---\\ Result of repair
~ Repair carried out successfully
~ Browser not found (Mozilla Firefox)
~ Browser not found (Opera Software)
~ The system has been restarted.
---\\ Statistics
~ Items scanned : 315
~ Items found : 0
~ Items cancelled : 0
~ Items repaired : 37
~ End of clean in 00h00mn15s
~====================
ZHPCleaner-[R]-18022017-09_48_12.txt
ZHPCleaner-
-18022017-09_43_57.txt