~ ZHPCleaner v2022.7.25.50 by Nicolas Coolman (2022/07/25)
~ Run by Ramon Fiaux (Administrator) (27/07/2022 10:22:44)
~ Web: https://www.nicolascoolman.com
~ Blog: https://nicolascoolman.eu/
~ Facebook : https://www.facebook.com/nicolascoolman1
~ State version : Version OK
~ Type : Repair
~ Report : C:\Users\Ramon Fiaux\OneDrive\Área de Trabalho\ZHPCleaner (R).txt
~ Quarantine : C:\Users\Ramon Fiaux\AppData\Roaming\ZHP\ZHPCleaner_Reg.txt
~ System Restore Point : OK
~ UAC : Activate
~ Boot Mode : Normal (Normal boot)
Windows 10 Home Single Language, 64-bit (Build 22000)


---\\ Alternate Data Stream (ADS). (0)
~ No malicious or unnecessary items found.


---\\ Services (0)
~ No malicious or unnecessary items found.


---\\ Browser internet (0)
~ No malicious or unnecessary items found.


---\\ Hosts file (2)
REPLACED: 177.54.149.114 ip-177-54-149-114.lazerpenguin.com
Number of found redirections 1/4


---\\ Scheduled automatic tasks. (0)
~ No malicious or unnecessary items found.


---\\ Explorer ( File, Folder) (4)
MOVED file: C:\Users\Ramon Fiaux\AppData\Local\Google\Chrome\User Data\Default\Preferences =>Préférences Chromium
MOVED file: C:\Users\Ramon Fiaux\AppData\Local\Microsoft\Edge\User Data\Default\Preferences =>Préférences Chromium
MOVED file: C:\Users\Ramon Fiaux\Downloads\0x80090010-outbyte-pc-repair.exe [Outbyte - Outbyte PC Repair Installation File] =>SUP.Optional.Outbyte
MOVED folder: C:\Program Files (x86)\DummyDir =>.SUP.Empty


---\\ Registry ( Key, Value, Data) (5)
DELETED data: HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{41be297c-b4de-40e5-a3f5-50db9288b5ce}\\DhcpNameServer [Bad : 172.18.15.1] =>Hijacker.Browser
DELETED data: HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{75dfd2ad-e776-49d9-9a45-634cc02b0ffa}\\DhcpNameServer [Bad : 186.223.160.75 186.223.160.80] =>Hijacker.Browser
DELETED data: HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\\DhcpNameServer [Bad : 186.223.160.75 186.223.160.80] =>Hijacker.Browser
DELETED key*: HKEY_USERS\S-1-5-21-4192884717-58469100-4038748977-1001\SOFTWARE\Classes\AppXq0pwa73vfcn2qdexp8cexcc6qk87xh1r [] =>Adware.Navipromo
DELETED value: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\GoogleChromeAutoLaunch_7ACC9AA893EE72F153EE68F147E9E20F ["C:\Program Files\Google\Chrome\Application\chrome] =>PUP.Optional.MyBrowser


---\\ Summary of the elements found (6)
https://nicolascoolman.eu/forum/Topic/repaquetage-et-infection/ =>Préférences Chromium
https://nicolascoolman.eu/forum/Topic/-logiciel-potentiellement-superflu-lps/ =>SUP.Optional.Outbyte
https://nicolascoolman.eu/forum/Topic/logiciels-potentiellement-superflus-lps/ =>.SUP.Empty
https://nicolascoolman.eu/2017/11/10/hijacker-browser-3/ =>Hijacker.Browser
https://nicolascoolman.eu/forum/Topic/repaquetage-et-infection/ =>Adware.Navipromo
https://nicolascoolman.eu/2017/11/01/adware-mybrowser/ =>PUP.Optional.MyBrowser


---\\ Other deletions. (13)
~ Registry Keys Tracing deleted (13)
~ Remove the old reports ZHPCleaner. (0)


---\\ Result of repair
~ Repair carried out successfully
~ Google Chrome OK
~ Internet Explorer OK


---\\ Statistics
~ Items scanned : 1264
~ Items found : 0
~ Items cancelled : 0
~ Space saving (bytes) : 0
~ Items options : 9/17


---\\ OPTIONS NOT ACTIVES
~ Temporary file analysis
~ Temporary folder analysis
~ Empty Folder CLSID Analysis
~ Empty Other Folder Analysis
~ Empty LocalLow Folder Analysis
~ Empty Local Folder Analysis
~ Obsolete Installer File Analysis
~ Start browsers with extensions removed





~ End of clean in 00h00mn17s

---\\ Reports (3)
ZHPCleaner-[S]-27072022-07_58_05.txt
ZHPCleaner-[S]-27072022-10_18_38.txt
ZHPCleaner-[R]-27072022-10_23_01.txt