~ ZHPCleaner v2017.9.13.156 by Nicolas Coolman (2017/09/13)
~ Run by Laurence (Administrator) (07/10/2017 21:14:20)
~ Web: https://www.nicolascoolman.com
~ Blog: https://nicolascoolman.eu/
~ Facebook : https://www.facebook.com/nicolascoolman1
~ State version : Version OK
~ Certificate ZHPCleaner: Illegal
~ Type : Nettoyer
~ Report : C:\Users\Laurence\Desktop\ZHPCleaner.txt
~ Quarantine : C:\Users\Laurence\AppData\Roaming\ZHP\ZHPCleaner_Reg.txt
~ UAC : Activate
~ Boot Mode : Normal (Normal boot)
Windows 7 Home Premium, 64-bit Service Pack 1 (Build 7601)


---\\ Service. (0)
~ Aucun élément malicieux ou superflu trouvé.


---\\ Navigateur internet. (1)
REMPLACÉ Google Chrome Preferences: "https://api-fr.igraal.com/" =>Toolbar.Graal


---\\ Fichier hôte. (1)
~ Le fichier hôte est légitime. (1)


---\\ Tâche planifiée. (0)
~ Aucun élément malicieux ou superflu trouvé.


---\\ Explorateur ( Dossiers, Fichiers ). (24)
DEPLACÉ fichier: C:\Users\Laurence\Downloads\antimalwaresetup.exe [Plumbytes Software - Plumbytes Anti-Malware] =>.SUP.Plumbytes
DEPLACÉ fichier: C:\Users\Laurence\Downloads\FlashPlayerPro.exe [AirInstaller - Flash Player Pro] =>PUP.Optional.AirInstaller
DEPLACÉ fichier: C:\Users\Laurence\Downloads\SoftonicDownloader_pour_utorrent.exe [Softonic - Softonic Downloader] =>.SUP.Softonic
DEPLACÉ fichier: C:\Users\Laurence\Downloads\SoftonicDownloader_pour_video-to-video-converter.exe [Softonic - Softonic Downloader] =>.SUP.Softonic
DEPLACÉ fichier: C:\Users\Laurence\Downloads\TradeInterceptorCharting.jnlp =>.SUP.Torch
DEPLACÉ fichier: C:\Users\Laurence\Downloads\[www.Cpasbien.pe] Microsoft Office Professional Plus 2013 VL Edition x86 x64 FR\MicrosoftToolkit.exe [CODYQX4 - Microsoft Toolkit] =>HackTool.WinActivator
DEPLACÉ fichier: C:\Documents and Settings\Les souris\Local Settings\Application Data\Google\Chrome\User Data\Default\Local Storage\https_d22j4fzzszoii2.cloudfront.net_0.localstorage =>.SUP.CloudfrontNet
DEPLACÉ fichier: C:\Documents and Settings\Les souris\Local Settings\Application Data\Google\Chrome\User Data\Default\Local Storage\https_d22j4fzzszoii2.cloudfront.net_0.localstorage-journal =>.SUP.CloudfrontNet
DEPLACÉ fichier: C:\Documents and Settings\Les souris\Local Settings\Application Data\Google\Chrome\User Data\Default\Local Storage\https_dsms0mj1bbhn4.cloudfront.net_0.localstorage =>.SUP.CloudfrontNet
DEPLACÉ fichier: C:\Documents and Settings\Les souris\Local Settings\Application Data\Google\Chrome\User Data\Default\Local Storage\https_dsms0mj1bbhn4.cloudfront.net_0.localstorage-journal =>.SUP.CloudfrontNet
DEPLACÉ fichier: C:\Documents and Settings\Les souris\Local Settings\Application Data\Google\Chrome\User Data\Default\Local Storage\https_ol.uk.at.atwola.com_0.localstorage =>.SUP.Atwola
DEPLACÉ fichier: C:\Documents and Settings\Les souris\Local Settings\Application Data\Google\Chrome\User Data\Default\Local Storage\https_ol.uk.at.atwola.com_0.localstorage-journal =>.SUP.Atwola
DEPLACÉ fichier: C:\Documents and Settings\Les souris\Local Settings\Application Data\Google\Chrome\User Data\Default\Local Storage\http_laurensinwonderland.blogspot.fr_0.localstorage =>PUP.Optional.LaurensCustomized
DEPLACÉ fichier: C:\Documents and Settings\Les souris\Local Settings\Application Data\Google\Chrome\User Data\Default\Local Storage\http_laurensinwonderland.blogspot.fr_0.localstorage-journal =>PUP.Optional.LaurensCustomized
DEPLACÉ fichier: C:\Documents and Settings\Les souris\Local Settings\Application Data\Google\Chrome\User Data\Default\Local Storage\http_st.chatango.com_0.localstorage =>.SUP.Chatango
DEPLACÉ fichier: C:\Documents and Settings\Les souris\Local Settings\Application Data\Google\Chrome\User Data\Default\Local Storage\http_st.chatango.com_0.localstorage-journal =>.SUP.Chatango
DEPLACÉ fichier: C:\Documents and Settings\Les souris\Local Settings\Application Data\Google\Chrome\User Data\Default\Local Storage\http_static.audienceinsights.net_0.localstorage =>.SUP.AudienceInsights
DEPLACÉ fichier: C:\Documents and Settings\Les souris\Local Settings\Application Data\Google\Chrome\User Data\Default\Local Storage\http_static.audienceinsights.net_0.localstorage-journal =>.SUP.AudienceInsights
DEPLACÉ dossier*: C:\Users\Laurence\AppData\Local\Google\Chrome\User Data\Default\Extensions\kmhkepipobnjllejbafajoemahjejdcm =>Toolbar.Graal
DEPLACÉ dossier*: C:\Users\Laurence\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kmhkepipobnjllejbafajoemahjejdcm =>Toolbar.Graal
DEPLACÉ dossier*: C:\ProgramData\Microsoft Toolkit =>HackTool.AutoKMS
DEPLACÉ dossier*: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IMBooster =>PUP.Optional.IMBooster
DEPLACÉ dossier*: C:\Program Files (x86)\QuickTime =>Riskware.QuickTime
DEPLACÉ dossier*: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime =>Riskware.QuickTime


---\\ Base de Registres ( Clés, Valeurs, Données ). (50)
REMPLACÉ donnée: HKLM\...\Opera.exe\Shell\open\Command\\"C:\Program Files (x86)\Opera\Opera.exe" http://www.nationzoom.com/?type=sc&ts=1388595745&from=tugs&uid=WDCXWD1001FALS-55J7B0_WD-WMATV570448604486 =>PUP.Optional.NationZoom
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\1916A2AF346D399F50313C393200F14140456616 [Avast Software] =>PUM.Misplaced.Certificate
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\2A83E9020591A55FC6DDAD3FB102794C52B24E70 [Avast Software] =>PUM.Misplaced.Certificate
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\2B84BFBB34EE2EF949FE1CBE30AA026416EB2216 [Avast Software] =>PUM.Misplaced.Certificate
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\305F8BD17AA2CBC483A4C41B19A39A0C75DA39D6 [Avast Software] =>PUM.Misplaced.Certificate
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\367D4B3B4FCBBC0B767B2EC0CDB2A36EAB71A4EB [Avast Software] =>PUM.Misplaced.Certificate
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\3A850044D8A195CD401A680C012CB0A3B5F8DC08 [Avast Software] =>PUM.Misplaced.Certificate
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\40AA38731BD189F9CDB5B9DC35E2136F38777AF4 [Avast Software] =>PUM.Misplaced.Certificate
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\43D9BCB568E039D073A74A71D8511F7476089CC3 [Avast Software] =>PUM.Misplaced.Certificate
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\471C949A8143DB5AD5CDF1C972864A2504FA23C9 [Avast Software] =>PUM.Misplaced.Certificate
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\51C3247D60F356C7CA3BAF4C3F429DAC93EE7B74 [Avast Software] =>PUM.Misplaced.Certificate
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\5DE83EE82AC5090AEA9D6AC4E7A6E213F946E179 [Avast Software] =>PUM.Misplaced.Certificate
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\61793FCBFA4F9008309BBA5FF12D2CB29CD4151A [Avast Software] =>PUM.Misplaced.Certificate
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\637162CC59A3A1E25956FA5FA8F60D2E1C52EAC6 [Avast Software] =>PUM.Misplaced.Certificate
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\63FEAE960BAA91E343CE2BD8B71798C76BDB77D0 [Avast Software] =>PUM.Misplaced.Certificate
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\6431723036FD26DEA502792FA595922493030F97 [Avast Software] =>PUM.Misplaced.Certificate
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\7D7F4414CCEF168ADF6BF40753B5BECD78375931 [Avast Software] =>PUM.Misplaced.Certificate
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\80962AE4D6C5B442894E95A13E4A699E07D694CF [Avast Software] =>PUM.Misplaced.Certificate
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\86E817C81A5CA672FE000F36F878C19518D6F844 [Avast Software] =>PUM.Misplaced.Certificate
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\8E5BD50D6AE686D65252F843A9D4B96D197730AB [Avast Software] =>PUM.Misplaced.Certificate
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\9845A431D51959CAF225322B4A4FE9F223CE6D15 [Avast Software] =>PUM.Misplaced.Certificate
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\B533345D06F64516403C00DA03187D3BFEF59156 [Avast Software] =>PUM.Misplaced.Certificate
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\B86E791620F759F17B8D25E38CA8BE32E7D5EAC2 [Avast Software] =>PUM.Misplaced.Certificate
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\C060ED44CBD881BD0EF86C0BA287DDCF8167478C [Avast Software] =>PUM.Misplaced.Certificate
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\CEA586B2CE593EC7D939898337C57814708AB2BE [Avast Software] =>PUM.Misplaced.Certificate
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\D018B62DC518907247DF50925BB09ACF4A5CB3AD [Avast Software] =>PUM.Misplaced.Certificate
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\F8A54E03AADC5692B850496A4C4630FFEAA29D83 [Avast Software] =>PUM.Misplaced.Certificate
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\SystemCertificates\Disallowed\Certificates\FA6660A94AB45F6A88C0D7874D89A863D74DEE97 [Avast Software] =>PUM.Misplaced.Certificate
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\TypeLib\{2C6674DB-EFB5-464A-A715-3E770B9C8A94}\1.0 [IminentWinCoreAimPlugin 1.0 Type Library] =>PUP.Optional.IMBooster
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\TypeLib\{2C6674DB-EFB5-464A-A715-3E770B9C8A94} [IminentWinCoreAimPlugin 1.0 Type Library] =>PUP.Optional.IMBooster
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\fst_fr_35 [] =>PUP.Optional.FreeSoftToday
SUPPRIMÉ clé*: HKEY_USERS\S-1-5-21-473937144-2440636609-1579235599-1001\SOFTWARE\TBSB01620 [] =>.SUP.Conduit
SUPPRIMÉ clé*: HKEY_USERS\.DEFAULT\Software\AppDataLow\Software\Feven 1.7 [] =>Adware.CrossRider
SUPPRIMÉ clé: HKCU\Software\TBSB01620 [] =>.SUP.Conduit
SUPPRIMÉ clé*: HKCU\Software\WEBAPP [] =>.SUP.Downloader
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\protector_dll.Protector [Protector Class] =>Adware.BProtector
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\protector_dll.Protector.1 [Protector Class] =>Adware.BProtector
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\protector_dll.ProtectorLib [ProtectorLib Class] =>Adware.BProtector
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\protector_dll.ProtectorLib.1 [ProtectorLib Class] =>Adware.BProtector
SUPPRIMÉ clé*: [X64] HKLM\Software\Classes\Installer\Products\2DAC3F70948BD1B48A00FDD9B0A3EA89 [IMBooster] =>PUP.Optional.IMBooster
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Microsoft\Tracing\Plumbytes_RASAPI32 [] =>.SUP.Plumbytes
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Microsoft\Tracing\Plumbytes_RASMANCS [] =>.SUP.Plumbytes
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-473937144-2440636609-1579235599-1001\Products\0C68E85F2E5704D45A7F417D2B77D27C [SearchTheWeb] =>PUP.Optional.IMBooster
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\058A75F0530072D4E859C70AA2818117 [C:\Program Files (x86)\Iminent\IMBooster\msvcm90.dll (Not File)] =>PUP.Optional.IMBooster
SUPPRIMÉ clé: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\TypeLib\{2C6674DB-EFB5-464A-A715-3E770B9C8A94} [IminentWinCoreAimPlugin 1.0 Type Library] =>PUP.Optional.IMBooster
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{07F3CAD2-B849-4B1D-A800-DF9D0B3AAE98} [Iminent] =>PUP.Optional.IMBooster
SUPPRIMÉ clé*: HKCU\Software\Microsoft\Installer\Products\0C68E85F2E5704D45A7F417D2B77D27C [SearchTheWeb] =>PUP.Optional.IMBooster
SUPPRIMÉ clé*: HKCU\Software\Microsoft\Installer\Features\0C68E85F2E5704D45A7F417D2B77D27C [] =>PUP.Optional.IMBooster
SUPPRIMÉ clé: HKU\S-1-5-21-473937144-2440636609-1579235599-1001\Software\Microsoft\Installer\Products\0C68E85F2E5704D45A7F417D2B77D27C [SearchTheWeb] =>PUP.Optional.IMBooster
SUPPRIMÉ clé: HKU\S-1-5-21-473937144-2440636609-1579235599-1001\Software\Microsoft\Installer\Features\0C68E85F2E5704D45A7F417D2B77D27C [] =>PUP.Optional.IMBooster


---\\ Récapitulatif des éléments trouvés sur votre station. (21)
https://www.nicolascoolman.com/fr/toolbar-igraal/ =>Toolbar.Graal
https://nicolascoolman.eu/2017/09/09/sup-plumbytes/ =>.SUP.Plumbytes
https://www.nicolascoolman.com/fr/pup-optional-airinstaller =>PUP.Optional.AirInstaller
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.SUP.Softonic
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.SUP.Torch
https://nicolascoolman.eu/2017/01/13/hacktool-winactivator/ =>HackTool.WinActivator
https://nicolascoolman.eu/2017/02/02/superfluous-cloudfrontnet/ =>.SUP.CloudfrontNet
https://nicolascoolman.eu/2017/02/04/superfluous-atwola/ =>.SUP.Atwola
https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>PUP.Optional.LaurensCustomized
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.SUP.Chatango
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.SUP.AudienceInsights
https://nicolascoolman.eu/2017/02/02/hacktool-autokms/ =>HackTool.AutoKMS
https://nicolascoolman.eu/2017/09/08/adware-imbooster/ =>PUP.Optional.IMBooster
https://nicolascoolman.eu/2017/01/15/riskware-quicktime/ =>Riskware.QuickTime
https://www.nicolascoolman.com/fr/hijacker-nationzoom/ =>PUP.Optional.NationZoom
https://nicolascoolman.eu/2017/06/26/trojan-certlock/ =>PUM.Misplaced.Certificate
https://www.nicolascoolman.com/fr/adware-freesofttoday/ =>PUP.Optional.FreeSoftToday
https://nicolascoolman.eu/2017/02/06/superfluous-conduit/ =>.SUP.Conduit
https://nicolascoolman.eu/2017/03/11/pup-optional-crossrider/ =>Adware.CrossRider
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.SUP.Downloader
https://nicolascoolman.eu/2017/04/12/adware-bprotector/ =>Adware.BProtector


---\\ Nettoyage Additionnel. (52)
~ Suppression des Clés de registre Tracing. (52)
~ Suppression des anciens rapports ZHPCleaner. (0)


---\\ Bilan de la réparation
~ Réparation réalisée avec succès.


---\\ Statistiques
~ Items scannés : 1770
~ Items trouvés : 0
~ Items annulés : 0
~ Items réparés : 75


~ End of clean in 00h01mn15s
~====================
ZHPCleaner-[R]-07102017-21_15_35.txt
ZHPCleaner-[S]-07102017-21_09_17.txt