~ ZHPCleaner v2016.12.13.215 by Nicolas Coolman (2016/12/13)
~ Run by Jason (Administrator) (14/12/2016 12:38:06)
~ Web:
https://www.nicolascoolman.com
~ Blog:
https://www.anti-malware.top
~ Facebook :
https://www.facebook.com/nicolascoolman1
~ State version : Version OK
~ Type : Repair
~ Report : C:\Users\Jason\Desktop\ZHPCleaner.txt
~ Quarantine : C:\Users\Jason\AppData\Roaming\ZHP\ZHPCleaner_Quarantine.txt
~ UAC : Activate
~ Boot Mode : Normal (Normal boot)
Windows 10 Pro, 64-bit (Build 14393)
---\\ Services (0)
~ No malicious or unnecessary items found.
---\\ Browser internet (0)
~ No malicious or unnecessary items found.
---\\ Hosts file (1)
~ The hosts file is legitimate (14)
---\\ Scheduled automatic tasks. (0)
~ No malicious or unnecessary items found.
---\\ Explorer ( File, Folder) (49)
MOVED file: C:\Windows\Installer\wix{159AA592-31AA-4EAC-A6CB-B47AB2CB1476}.SchedServiceConfig.rmi =>.Superfluous.Empty
MOVED file: C:\Windows\Installer\wix{2D7D85DF-8BBA-427F-8E85-055CD22F2D2A}.SchedServiceConfig.rmi =>.Superfluous.Empty
MOVED file: C:\Windows\Installer\wix{2E4AF2A6-50EA-4260-9BA4-5E582D11879A}.SchedServiceConfig.rmi =>.Superfluous.Empty
MOVED file: C:\Windows\Installer\wix{2E9C0CF2-6FD1-417E-A5A1-5AE93C0032DF}.SchedServiceConfig.rmi =>.Superfluous.Empty
MOVED file: C:\Windows\Installer\wix{3540181E-340A-4E7A-B409-31663472B2F7}.SchedServiceConfig.rmi =>.Superfluous.Empty
MOVED file: C:\Windows\Installer\wix{5032D869-5D74-46FD-8C52-7F15420589B0}.SchedServiceConfig.rmi =>.Superfluous.Empty
MOVED file: C:\Windows\Installer\wix{55BB2110-FB43-49B3-93F4-945A0CFB0A6C}.SchedServiceConfig.rmi =>.Superfluous.Empty
MOVED file: C:\Windows\Installer\wix{5D61F006-168C-4B8B-B7FD-F113C10AE0E4}.SchedServiceConfig.rmi =>.Superfluous.Empty
MOVED file: C:\Windows\Installer\wix{61F565EB-B101-4EBE-89BB-EF0AA3F2FFB8}.SchedServiceConfig.rmi =>.Superfluous.Empty
MOVED file: C:\Windows\Installer\wix{6FC79C95-F54F-4515-8012-01F33D894492}.SchedServiceConfig.rmi =>.Superfluous.Empty
MOVED file: C:\Windows\Installer\wix{7446FE8D-C1F9-4D42-AAAE-5DBCE58605A6}.SchedServiceConfig.rmi =>.Superfluous.Empty
MOVED file: C:\Windows\Installer\wix{7D2C319D-3907-472D-9B55-EC1F240962FC}.SchedServiceConfig.rmi =>.Superfluous.Empty
MOVED file: C:\Windows\Installer\wix{8432E4EF-ABFB-48C8-B77B-24728E71D3DD}.SchedServiceConfig.rmi =>.Superfluous.Empty
MOVED file: C:\Windows\Installer\wix{912422D4-0A22-4F70-BF8D-802B4BCD0999}.SchedServiceConfig.rmi =>.Superfluous.Empty
MOVED file: C:\Windows\Installer\wix{95EB2FCC-AE0B-40E9-B804-347C6358923B}.SchedServiceConfig.rmi =>.Superfluous.Empty
MOVED file: C:\Windows\Installer\wix{A1A724F3-F1A6-479C-AE98-208946717E2B}.SchedServiceConfig.rmi =>.Superfluous.Empty
MOVED file: C:\Windows\Installer\wix{A6B6501F-A987-437B-BFAC-319AE1F990ED}.SchedServiceConfig.rmi =>.Superfluous.Empty
MOVED file: C:\Windows\Installer\wix{C230A275-D2A0-446B-ACE5-06BF067D50F2}.SchedServiceConfig.rmi =>.Superfluous.Empty
MOVED file: C:\Windows\Installer\wix{C9F8858E-B6F9-4E56-B155-2A5CE7FC74B9}.SchedServiceConfig.rmi =>.Superfluous.Empty
MOVED file: C:\Windows\Installer\wix{CDF9E1C8-4B97-4F8B-A848-7DD0E8BEB89F}.SchedServiceConfig.rmi =>.Superfluous.Empty
MOVED file: C:\Windows\Installer\wix{D4D86CB2-2370-4691-8272-3869EDED6C64}.SchedServiceConfig.rmi =>.Superfluous.Empty
MOVED file: C:\Windows\Installer\wix{D669DC52-B1A4-4933-878D-CB80F660D95D}.SchedServiceConfig.rmi =>.Superfluous.Empty
MOVED file: C:\Windows\Installer\wix{EBFF2EA1-3944-4CA2-89FA-8B70C0058DD3}.SchedServiceConfig.rmi =>.Superfluous.Empty
MOVED file: C:\Windows\Installer\wix{FD244E19-6EFE-4A2D-948A-0D45D4C168BE}.SchedServiceConfig.rmi =>.Superfluous.Empty
MOVED file: C:\Windows\Installer\wix{FD6E648E-1378-467F-AD37-2B98B379B0DD}.SchedServiceConfig.rmi =>.Superfluous.Empty
MOVED file: C:\Users\Jason\Downloads\SecureDownloadManager.log =>PUP.Optional.SearchAssist
MOVED file: C:\Users\Jason\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.olark.com_0.localstorage =>PUP.Optional.Generic
MOVED file: C:\Users\Jason\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.olark.com_0.localstorage-journal =>PUP.Optional.Generic
MOVED file: C:\Users\Jason\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_ebookbrowsee.net_0.localstorage =>PUP.Optional.Multiplug
MOVED file: C:\Users\Jason\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_ebookbrowsee.net_0.localstorage-journal =>PUP.Optional.Multiplug
MOVED file: C:\Users\Jason\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_
www.ask.com_0.localstorage =>Toolbar.Ask
MOVED file: C:\Users\Jason\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_
www.ask.com_0.localstorage-journal =>Toolbar.Ask
MOVED file: C:\Users\Jason\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_
www.metrolyrics.com_0.localstorage =>PUP.Optional.AddLyrics
MOVED file: C:\Users\Jason\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_
www.metrolyrics.com_0.localstorage-journal =>PUP.Optional.AddLyrics
MOVED file: C:\Users\Jason\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_
www.putlocker.com_0.localstorage =>PUP.Optional.PutLocker
MOVED file: C:\Users\Jason\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_
www.putlocker.com_0.localstorage-journal =>PUP.Optional.PutLocker
MOVED folder: C:\Users\Jason\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd =>Hijacker.Browser [
https://lastpass.com/upgrade.php?binary=1]
MOVED folder: C:\Program Files (x86)\QuickTime =>Riskware.QuickTime
MOVED folder: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime =>Riskware.QuickTime
MOVED folder: C:\WINDOWS\Installer\MSI2039.tmp- =>.Superfluous.Empty
MOVED folder: C:\WINDOWS\Installer\MSI2144.tmp- =>.Superfluous.Empty
MOVED folder: C:\WINDOWS\Installer\MSI3BC1.tmp- =>.Superfluous.Empty
MOVED folder: C:\WINDOWS\Installer\MSI3C8D.tmp- =>.Superfluous.Empty
MOVED folder: C:\WINDOWS\Installer\MSI4664.tmp- =>.Superfluous.Empty
MOVED folder: C:\WINDOWS\Installer\MSI47CD.tmp- =>.Superfluous.Empty
MOVED folder: C:\WINDOWS\Installer\MSI6640.tmp- =>.Superfluous.Empty
MOVED folder: C:\WINDOWS\Installer\MSI678A.tmp- =>.Superfluous.Empty
MOVED folder: C:\WINDOWS\Installer\MSIE6DC.tmp- =>.Superfluous.Empty
MOVED folder: C:\WINDOWS\Installer\MSIEECD.tmp- =>.Superfluous.Empty
---\\ Registry ( Key, Value, Data) (9)
DELETED data: HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3dc0fc79-3933-4539-bd45-fe7cbfd0feaf}\\DhcpNameServer [Bad : 61.9.194.49 61.9.195.193] =>Hijacker.Browser
DELETED data: HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\\DhcpNameServer [Bad : 61.9.194.49 61.9.195.193] =>Hijacker.Browser
DELETED key*: [X64] HKLM\SOFTWARE\Classes\S [] =>Toolbar.Agent
DELETED key*: [X64] HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56} [secman] =>PUP.Optional.Camec
DELETED key*: HKLM\SYSTEM\CurrentControlSet\Services\CscService [] =>.Superfluous.PCSpeedUp
DELETED key*: [X64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\014AA45914BC47A46AC4007B890B0404 [C:\Perl64\lib\ExtUtils\Command\] =>PUP.Optional.Manager
DELETED key: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56} [secman] =>PUP.Optional.Camec
DELETED key*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} [Google Inc.] =>Heuristic.Suspect
DELETED value: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\\MusicManager [0x0300000076DC1EB75D54CE01] =>.Superfluous.MusicManager
---\\ Summary of the elements found (16)
https://www.nicolascoolman.com/fr/logiciels-superflus =>.Superfluous.Empty
https://www.nicolascoolman.com/fr/repaquetage-et_infections/ =>PUP.Optional.SearchAssist
https://www.anti-malware.top/2016/05/01/definition-dun-logiciel-pup-lpi/ =>PUP.Optional.Generic
https://www.anti-malware.top/2016/04/28/pup-optional-multiplug/ =>PUP.Optional.Multiplug
https://www.anti-malware.top/2016/09/22/toolbar-ask/ =>Toolbar.Ask
https://www.nicolascoolman.com/fr/adware-addlyrics/ =>PUP.Optional.AddLyrics
https://www.nicolascoolman.com/fr/spyware-putlocker/ =>PUP.Optional.PutLocker
https://www.nicolascoolman.com/fr/repaquetage-et_infections/ =>Hijacker.Browser [
https://lastpass.com/upgrade.php?binary=1]
https://www.anti-malware.top/2016/04/21/riskware-quicktime/ =>Riskware.QuickTime
https://www.nicolascoolman.com/fr/hijacker-browser/ =>Hijacker.Browser
https://www.nicolascoolman.com/fr/?p=5143 =>Toolbar.Agent
https://www.nicolascoolman.com/fr/repaquetage-et_infections/ =>PUP.Optional.Camec
https://www.nicolascoolman.com/fr/superfluous-pcspeeduppro/ =>.Superfluous.PCSpeedUp
https://www.nicolascoolman.com/fr/pup-manager/ =>PUP.Optional.Manager
https://www.anti-malware.top/2016/04/22/heuristic-suspect/ =>Heuristic.Suspect
https://www.anti-malware.top/2016/05/21/superfluous-musicmanager/ =>.Superfluous.MusicManager
---\\ Other deletions. (17)
~ Registry Keys Tracing deleted (17)
~ Remove the old reports ZHPCleaner. (0)
---\\ Result of repair
~ Repair carried out successfully
~ Browser not found (Mozilla Firefox)
~ Browser not found (Opera Software)
---\\ Statistics
~ Items scanned : 929
~ Items found : 0
~ Items cancelled : 0
~ Items repaired : 58
~ End of clean in 00h00mn26s
~====================
ZHPCleaner-[R]-14122016-12_38_32.txt
ZHPCleaner-
-14122016-12_36_55.txt
SecurityCheck by glax24 & Severnyj v.1.4.0.46 [22.09.16]
WebSite: www.safezone.cc
DateLog: 14.12.2016 12:47:31
Path starting: C:\Users\Jason\AppData\Local\Temp\SecurityCheck\SecurityCheck.exe
Log directory: C:\SecurityCheck\
IsAdmin: True
User: Jason
VersionXML: 3.62is-13.12.2016
___________________________________________________________________________
Windows 10(6.3.14393) (x64) Professional Lang: English(0409)
Installation date OS: 23.09.2016 14:02:33
LicenseStatus: Office 16, Office16O365ProPlusR_Subscription1 edition Timebased activation will expire :56647 minutes
LicenseStatus: Windows(R), Professional edition The machine is permanently activated.
Boot Mode: Normal
Default Browser: Microsoft Edge (C:\WINDOWS\system32\LaunchWinApp.exe)
SystemDrive: C: FS: [NTFS] Capacity: [101 Gb] Used: [82.8 Gb] Free: [18.2 Gb]
------------------------------- [ Windows ] -------------------------------
Internet Explorer 11.447.14393.0
User Account Control enabled
Automatically download and schedule installation
Windows Update (wuauserv) - The service is running
Security Center (wscsvc) - The service is running
Remote Registry (RemoteRegistry) - The service has stopped
SSDP Discovery (SSDPSRV) - The service is running
Remote Desktop Services (TermService) - The service has stopped
Windows Remote Management (WS-Management) (WinRM) - The service has stopped
System Restore Disable
---------------------------- [ Antivirus_WMI ] ----------------------------
Windows Defender (enabled and up to date)
--------------------------- [ FirewallWindows ] ---------------------------
Windows Firewall (MpsSvc) - The service is running
--------------------------- [ AntiSpyware_WMI ] ---------------------------
Windows Defender (enabled and up to date)
--------------------------- [ OtherUtilities ] ----------------------------
WinRAR 4.20 (64-bit) v.4.20.0 Warning! Download Update
Microsoft Silverlight v.5.1.50901.0
DivX Setup v.2.7.0.64
VLC media player v.2.2.4
OpenOffice.org 3.4.1 v.3.41.9593 Warning! Download Update
--------------------------------- [ IM ] ----------------------------------
Skype™ 7.27 v.7.27.101 Warning! Download Update
^Optional update.^
---------------------------- [ ProxyAndVPNs ] -----------------------------
Spotflux v.2.9.11 Warning! This app can show ads.
--------------------------------- [ P2P ] ---------------------------------
qBittorrent 3.2.0 v.3.2.0 Warning! P2P-client.
-------------------------------- [ Java ] ---------------------------------
Java SE Development Kit 7 Update 7 (64-bit) v.1.7.0.70 Warning! This software is no longer supported. Please uninstall it and use Java SDK 8 (jdk-8u112-windows-x64.exe).
Java 8 Update 101 v.8.0.1010.13 Warning! Download Update
Uninstall old version and install new one (jre-8u112-windows-i586.exe).
Java SE Development Kit 7 Update 6 v.1.7.0.60 Warning! This software is no longer supported. Please uninstall it and use Java SDK 8 (jdk-8u112-windows-i586.exe).
Java SE Development Kit 7 Update 7 v.1.7.0.70 Warning! This software is no longer supported. Please uninstall it and use Java SDK 8 (jdk-8u112-windows-i586.exe).
--------------------------- [ AppleProduction ] ---------------------------
iTunes v.12.5.3.17
Bonjour v.3.1.0.1
QuickTime 7 v.7.76.80.95 Warning! This software is no longer supported. Please uninstall it and use another software.
Bonjour Service (Bonjour Service) - The service is running
--------------------------- [ AdobeProduction ] ---------------------------
Adobe AIR v.3.4.0.2540 Warning! Download Update
Adobe Flash Player 23 NPAPI v.23.0.0.207 Warning! Download Update
Adobe Shockwave Player 11.6 v.11.6.6.636 Warning! Download Update
Adobe Acrobat Reader DC v.15.020.20042
------------------------------- [ Browser ] -------------------------------
Google Chrome v.56.0.2924.21 [+]
----------------------------- [ EmailClient ] -----------------------------
Windows Live Mail v.16.4.3503.0728
--------------------------- [ RunningProcess ] ----------------------------
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe v.56.0.2924.21
------------------ [ AntivirusFirewallProcessServices ] -------------------
C:\Program Files\Windows Defender\MsMpEng.exe v.4.10.14393.0
C:\Program Files\Windows Defender\MpCmdRun.exe v.4.10.14393.0
C:\Program Files\Windows Defender\NisSrv.exe v.4.10.14393.0
Windows Defender Service (WinDefend) - The service is running
Windows Defender Network Inspection Service (WdNisSvc) - The service is running
---------------------------- [ UnwantedApps ] -----------------------------
Unity Web Player Warning! Application is distributed through the partnership programs and bundle assemblies. Uninstallation recommended. Possible you became a victim of fraud or social engineering.
----------------------------- [ End of Log ] ------------------------------