Voici les rapports demandés... :
ZHPCleaner :
~ ZHPCleaner v2017.3.24.50 by Nicolas Coolman (2017/03/24)
~ Run by JP (Administrator) (24/03/2017 22:37:40)
~ Web:
https://www.nicolascoolman.com
~ Blog:
https://nicolascoolman.eu/
~ Facebook :
https://www.facebook.com/nicolascoolman1
~ State version :
~ Type : Scanner
~ Report : C:\Users\JP\Desktop\ZHPCleaner.txt
~ Quarantine : C:\Users\JP\AppData\Roaming\ZHP\ZHPCleaner_Quarantine.txt
~ UAC : Activate
~ Boot Mode : Normal (Normal boot)
Windows 10 Home, 64-bit (Build 14393)
---\\ Service. (0)
~ Aucun élément malicieux ou superflu trouvé.
---\\ Navigateur internet. (0)
~ Aucun élément malicieux ou superflu trouvé.
---\\ Fichier hôte. (1)
~ Le fichier hôte est légitime. (33)
---\\ Tâche planifiée. (2)
TROUVÉ tâche: [Start Simple Driver Updater Schedule] [C:\Program Files\Simple Driver Updater\SimpleDriverUpdater.exe] =>.Superfluous.SimpleStar
TROUVÉ tâche: [Start Simple Driver Updater for PCDRAILLARD@JP(logon)] [C:\WINDOWS\Tasks\Start Simple Driver Updater for PCDRAILLARD@JP(logon).job] =>.Superfluous.SimpleStar
---\\ Explorateur ( Dossiers, Fichiers ). (55)
TROUVÉ dossier: C:\Users\JP\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd =>.Superfluous.MindSpark
TROUVÉ dossier: C:\Users\JP\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabloidgodmbnmnhoenmhlcjkfelomgp =>PUP.Optional.MyWebSearch
TROUVÉ dossier: C:\Users\JP\AppData\Roaming\0A1Q1J1G1F2W1I1P1Q1N1P0P2Y1S\7zip Packages =>Adware.InstallCore
TROUVÉ dossier: C:\Users\JP\AppData\Roaming\0A1Q1J1G1F2W1I1P1Q1N1P0P2Y1S =>Adware.InstallCore
TROUVÉ fichier: C:\Program Files\Simple Driver Updater\SimpleDriverUpdater.exe [Copyright © 2016 SimpleStar. All Rights Reserved. - Simple Driver Updater] =>.Superfluous.SimpleStar
TROUVÉ fichier: C:\Windows\Tasks\Start Simple Driver Updater for PCDRAILLARD@JP(logon).job =>.Superfluous.SimpleStar
TROUVÉ fichier: C:\Windows\Installer\wix{2E4AF2A6-50EA-4260-9BA4-5E582D11879A}.SchedServiceConfig.rmi =>.Superfluous.Empty
TROUVÉ fichier: C:\Windows\Installer\wix{3540181E-340A-4E7A-B409-31663472B2F7}.SchedServiceConfig.rmi =>.Superfluous.Empty
TROUVÉ fichier: C:\Windows\Installer\wix{55BB2110-FB43-49B3-93F4-945A0CFB0A6C}.SchedServiceConfig.rmi =>.Superfluous.Empty
TROUVÉ fichier: C:\Windows\Installer\wix{5D61F006-168C-4B8B-B7FD-F113C10AE0E4}.SchedServiceConfig.rmi =>.Superfluous.Empty
TROUVÉ fichier: C:\Windows\Installer\wix{5ED7462B-EF58-4757-B609-53755021EC34}.SchedServiceConfig.rmi =>.Superfluous.Empty
TROUVÉ fichier: C:\Windows\Installer\wix{A37CDB58-AAE8-0000-8C13-E0F7BACB0D5F}.SchedServiceConfig.rmi =>.Superfluous.Empty
TROUVÉ fichier: C:\Windows\Installer\wix{B678797F-DF38-4556-8A31-8B818E261868}.SchedServiceConfig.rmi =>.Superfluous.Empty
TROUVÉ fichier: C:\Windows\Installer\wix{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}.SchedServiceConfig.rmi =>.Superfluous.Empty
TROUVÉ fichier: C:\Windows\Installer\wix{C4123106-B685-48E6-B9BD-E4F911841EB4}.SchedServiceConfig.rmi =>.Superfluous.Empty
TROUVÉ fichier: C:\Windows\Installer\wix{D4D86CB2-2370-4691-8272-3869EDED6C64}.SchedServiceConfig.rmi =>.Superfluous.Empty
TROUVÉ fichier: C:\Windows\Installer\wix{F4404AFD-2EF3-40C1-8C09-29E5F3B6972B}.SchedServiceConfig.rmi =>.Superfluous.Empty
TROUVÉ fichier: C:\Windows\Installer\wix{FD244E19-6EFE-4A2D-948A-0D45D4C168BE}.SchedServiceConfig.rmi =>.Superfluous.Empty
TROUVÉ fichier: C:\Users\JP\AppData\Local\Temp\wct4BB1.tmp =>.Superfluous.Temporary.Various
TROUVÉ fichier: C:\Users\JP\AppData\Local\Temp\wct537C.tmp =>.Superfluous.Temporary.Various
TROUVÉ fichier: C:\Users\JP\AppData\Local\Temp\wct6D3E.tmp =>.Superfluous.Temporary.Various
TROUVÉ fichier: C:\Users\JP\AppData\Local\Temp\wct8042.tmp =>.Superfluous.Temporary.Various
TROUVÉ fichier: C:\Users\JP\AppData\Local\Temp\wct90AD.tmp =>.Superfluous.Temporary.Various
TROUVÉ fichier: C:\Users\JP\AppData\Local\Temp\wctAAAF.tmp =>.Superfluous.Temporary.Various
TROUVÉ fichier: C:\Users\JP\AppData\Local\Temp\wctCA77.tmp =>.Superfluous.Temporary.Various
TROUVÉ fichier: C:\Users\JP\AppData\Local\Temp\wctD2A4.tmp =>.Superfluous.Temporary.Various
TROUVÉ fichier: C:\Users\JP\AppData\Local\Temp\wctE7F.tmp =>.Superfluous.Temporary.Various
TROUVÉ fichier: C:\Users\JP\AppData\Local\Temp\wctECF2.tmp =>.Superfluous.Temporary.Various
TROUVÉ fichier: C:\Program Files\Simple Driver Updater\lci.lci =>.Superfluous.SimpleStar
TROUVÉ fichier: C:\Program Files\Simple Driver Updater\SimpleDriverUpdaterUpdater.exe [Copyright © 2016 SimpleStar. All Rights Reserved. - Simple Driver Updater Updater] =>.Superfluous.SimpleStar
TROUVÉ fichier: C:\Program Files\Simple Driver Updater\tray.exe [Copyright © 2016 SimpleStar. All Rights Reserved. - Simple Driver Updater] =>.Superfluous.SimpleStar
TROUVÉ dossier: C:\Program Files\Simple Driver Updater\defaults =>.Superfluous.SimpleStar
TROUVÉ dossier: C:\Program Files\Simple Driver Updater =>.Superfluous.SimpleStar
TROUVÉ fichier: C:\Users\JP\AppData\Roaming\SafetyBrowsing\mainservice_sb.exe [Copyright © 2015 - Service] =>.Superfluous.BalmainManagement
TROUVÉ fichier: C:\Users\JP\AppData\Roaming\SafetyBrowsing\mainservice_sb.exe.config =>.Superfluous.BalmainManagement
TROUVÉ fichier: C:\Users\JP\AppData\Roaming\SafetyBrowsing\MetroFramework.dll [Sven Walter - MetroFramework.dll] =>.Superfluous.BalmainManagement
TROUVÉ fichier: C:\Users\JP\AppData\Roaming\SafetyBrowsing\MetroFramework.Fonts.dll [Sven Walter - MetroFramework.Fonts.dll] =>.Superfluous.BalmainManagement
TROUVÉ fichier: C:\Users\JP\AppData\Roaming\SafetyBrowsing\netfilter.dll =>.Superfluous.BalmainManagement
TROUVÉ fichier: C:\Users\JP\AppData\Roaming\SafetyBrowsing\sb_core.exe [Balmain Management Ltd - Safety Browsing] =>.Superfluous.BalmainManagement
TROUVÉ fichier: C:\Users\JP\AppData\Roaming\SafetyBrowsing\sb_core.exe.config =>.Superfluous.BalmainManagement
TROUVÉ fichier: C:\Users\JP\AppData\Roaming\SafetyBrowsing\uninstaller.exe [Balmain Management Ltd - ] =>.Superfluous.BalmainManagement
TROUVÉ dossier: C:\Users\JP\AppData\Roaming\SafetyBrowsing\de-de =>.Superfluous.BalmainManagement
TROUVÉ dossier: C:\Users\JP\AppData\Roaming\SafetyBrowsing\es-es =>.Superfluous.BalmainManagement
TROUVÉ dossier: C:\Users\JP\AppData\Roaming\SafetyBrowsing\fr-fr =>.Superfluous.BalmainManagement
TROUVÉ dossier: C:\Users\JP\AppData\Roaming\SafetyBrowsing\it-it =>.Superfluous.BalmainManagement
TROUVÉ dossier: C:\Users\JP\AppData\Roaming\SafetyBrowsing =>.Superfluous.BalmainManagement
TROUVÉ dossier: C:\Program Files (x86)\QuickTime =>Riskware.QuickTime
TROUVÉ dossier: C:\Users\JP\AppData\Local\{B17C4C7B-98C5-4F77-B8C2-0673D8AC9A3D} =>.Superfluous.Empty
TROUVÉ dossier: C:\WINDOWS\Installer\MSI2A4E.tmp- =>.Superfluous.Empty
TROUVÉ dossier: C:\WINDOWS\Installer\MSI2A7.tmp- =>.Superfluous.Empty
TROUVÉ dossier: C:\WINDOWS\Installer\MSI321F.tmp- =>.Superfluous.Empty
TROUVÉ dossier: C:\WINDOWS\Installer\MSI43E.tmp- =>.Superfluous.Empty
TROUVÉ dossier: C:\WINDOWS\Installer\MSI4CB.tmp- =>.Superfluous.Empty
TROUVÉ dossier: C:\WINDOWS\Installer\MSI53A.tmp- =>.Superfluous.Empty
TROUVÉ dossier: C:\WINDOWS\Installer\MSI5B8.tmp- =>.Superfluous.Empty
---\\ Base de Registres ( Clés, Valeurs, Données ). (0)
~ Aucun élément malicieux ou superflu trouvé.
---\\ Récapitulatif des éléments trouvés sur votre station. (8)
https://nicolascoolman.eu/2017/01/20/lo ... superflus/ =>.Superfluous.SimpleStar
https://nicolascoolman.eu/2017/01/15/su ... mindspark/ =>.Superfluous.MindSpark
https://www.nicolascoolman.com/fr/adware-mywebsearch/ =>PUP.Optional.MyWebSearch
https://nicolascoolman.eu/2017/03/12/ad ... allcore-2/ =>Adware.InstallCore
https://nicolascoolman.eu/2017/01/20/lo ... superflus/ =>.Superfluous.Empty
https://nicolascoolman.eu/2017/01/20/lo ... superflus/ =>.Superfluous.Temporary.Various
https://nicolascoolman.eu/2017/03/13/su ... ybrowsing/ =>.Superfluous.BalmainManagement
https://nicolascoolman.eu/2017/01/15/ri ... quicktime/ =>Riskware.QuickTime
---\\ Bilan de la réparation
~ Aucune réparation effectuée.
~ Ce navigateur est absent (Mozilla Firefox)
---\\ Statistiques
~ Items scannés : 97228
~ Items trouvés : 73
~ Items annulés : 0
~ Items réparés : 0
~ End of search in 00h04mn58s
~====================
ZHPCleaner-[R]-24032017-10_55_01.txt
ZHPCleaner-
-24032017-10_53_01.txt
ZHPCleaner--24032017-22_42_38.txt
....
# AdwCleaner v6.043 - Rapport créé le 24/03/2017 à 10:57:23
# Mis à jour le 27/01/2017 par Malwarebytes
# Base de données : 2017-03-23.2 [Serveur]
# Système d'exploitation : Windows 10 Home (X64)
# Nom d'utilisateur : JP - PC
# Exécuté depuis : C:\Users\JP\Desktop\adwcleaner_6.043.exe
# Mode: Scan
# Support : https://www.malwarebytes.com/support
***** [ Services ] *****
Service trouvé: YSearchUtilSvc
Service trouvé: sbnetsys
***** [ Dossiers ] *****
Dossier trouvé: C:\Users\JP\AppData\Local\Google\Chrome\User Data\Default\Extensions\hclpcakhmfeidfpdlmoompeikfiapikb
Dossier trouvé: C:\Users\JP\AppData\Local\Downloaded Installers
Dossier trouvé: C:\ProgramData\BSD
Dossier trouvé: C:\ProgramData\Application Data\BSD
Dossier trouvé: C:\Users\Public\Documents\Downloaded Installers
Dossier trouvé: C:\Program Files (x86)\Yahoo!\yset
Dossier trouvé: C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\YSearchUtil
Dossier trouvé: C:\Users\JP\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcfenmboojpjinhpgggodefccipikbpd
Dossier trouvé: C:\Users\JP\AppData\Local\Google\Chrome\User Data\Default\Extensions\npdicihegicnhaangkdmcgbjceoemeoo
Dossier trouvé: C:\Users\JP\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlincbpgbkpbjepghokdnhnnpphmegig
Dossier trouvé: C:\Users\JP\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jlincbpgbkpbjepghokdnhnnpphmegig
***** [ Fichiers ] *****
Fichier trouvé: C:\Users\JP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_fcfenmboojpjinhpgggodefccipikbpd_0.localstorage
***** [ DLL ] *****
Aucune DLL patchée trouvée.
***** [ WMI ] *****
Aucune clé malveillante trouvée.
***** [ Raccourcis ] *****
Aucun raccourci infecté trouvé.
***** [ Tâches planifiées ] *****
Aucune tâche malveillante trouvée.
***** [ Registre ] *****
Clé trouvée: HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\SCService
Clé trouvée: [x64] HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\SCService
Clé trouvée: HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\scservice
Clé trouvée: [x64] HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\scservice
Clé trouvée: HKCU\Software\Classes\CLSID\{9C4EFBD5-1ADF-41E6-BE26-AF44326E30E4}
Clé trouvée: HKLM\SOFTWARE\Classes\Interface\{A8F7D0A5-7074-40B8-9BDC-1174BDD0A132}
Clé trouvée: HKLM\SOFTWARE\Classes\Interface\{D14D64BC-A0E4-42E3-BB72-FB41EA43C198}
Clé trouvée: HKLM\SOFTWARE\Classes\Interface\{DD1F043F-ABC8-4643-8B95-D2C5B22BB019}
Clé trouvée: HKLM\SOFTWARE\Classes\Interface\{E3F3E8F9-F747-4DD6-BA6B-82A6CE1E0860}
Clé trouvée: HKLM\SOFTWARE\Classes\Interface\{ED0B64D4-BF27-4521-AD27-190F49BF5EA7}
Clé trouvée: HKLM\SOFTWARE\Classes\Interface\{023E9EC8-B147-40EB-B0B3-DF90618FB371}
Clé trouvée: HKLM\SOFTWARE\Classes\Interface\{0522D9A4-4D57-437D-978D-E5B3B6C9005D}
Clé trouvée: HKLM\SOFTWARE\Classes\Interface\{07F41522-AF7D-4F26-B394-094F059FDB8A}
Clé trouvée: HKLM\SOFTWARE\Classes\Interface\{0C40F472-7407-4467-8914-1DEA7C326972}
Clé trouvée: HKLM\SOFTWARE\Classes\Interface\{212E6D43-6062-492A-B8CC-144669FF11ED}
Clé trouvée: HKLM\SOFTWARE\Classes\Interface\{224FE662-1E6D-4BC0-AEBB-9E2FB4057BE9}
Clé trouvée: HKLM\SOFTWARE\Classes\Interface\{3A807417-B46D-4D37-8C9A-19AC6DE204F9}
Clé trouvée: HKLM\SOFTWARE\Classes\Interface\{3CC60715-D6C5-429D-830E-43FA3F86C61D}
Clé trouvée: HKLM\SOFTWARE\Classes\Interface\{4517D94C-19BA-46FA-BE66-2A30CEAC4A85}
Clé trouvée: HKLM\SOFTWARE\Classes\Interface\{555D7146-94A8-4C94-AE76-C39CDC7F7705}
Clé trouvée: HKLM\SOFTWARE\Classes\Interface\{59D188FA-757A-424E-8C93-F58FFD896BD7}
Clé trouvée: HKLM\SOFTWARE\Classes\Interface\{8120D9D6-785C-4413-9C0C-DF2028C56FAD}
Clé trouvée: HKLM\SOFTWARE\Classes\Interface\{823AE2EB-E62C-4847-B192-C99B91B92416}
Clé trouvée: HKLM\SOFTWARE\Classes\Interface\{9B4F7CFE-987D-410E-A8E4-20182E0B3C24}
Clé trouvée: HKLM\SOFTWARE\Classes\Interface\{9B9A45F4-18FC-484A-BACA-076D78273D8E}
Clé trouvée: HKLM\SOFTWARE\Classes\Interface\{A6D54287-7939-466A-8579-92546D946C8C}
Clé trouvée: HKLM\SOFTWARE\Classes\Interface\{A78EDAFB-926F-4D93-AB13-8232D7378EB1}
Clé trouvée: HKLM\SOFTWARE\Classes\Interface\{6C42038D-817A-472C-8C2A-EF46F1DA576D}
Clé trouvée: HKLM\SOFTWARE\Classes\Interface\{873C7DA8-195D-4D5A-B830-C5E2831901EA}
Clé trouvée: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3B96B5D3-4A8D-42DC-9CDE-E9B94B3CFE5D}
Clé trouvée: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Clé trouvée: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{ACCC747B-2A59-4F30-BA7C-D26333DE65F5}
Clé trouvée: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Clé trouvée: HKLM\SOFTWARE\MaxPower
Clé trouvée: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! SearchSet
Clé trouvée: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\developpement-dur
Clé trouvée: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\immo.trovit.fr
Clé trouvée: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\nicematin.com
Clé trouvée: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\trovit.fr
Clé trouvée: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\www.developpement
Clé trouvée: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\www.nicematin.com
Clé trouvée: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\developpement-durabl
Clé trouvée: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\immo.trovit.fr
Clé trouvée: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\nicematin.com
Clé trouvée: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\trovit.fr
Clé trouvée: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\www.developpement-du
Clé trouvée: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\www.nicematin.com
Clé trouvée: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\developpement-d
Clé trouvée: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\immo.trovit.fr
Clé trouvée: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\nicematin.com
Clé trouvée: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\trovit.fr
Clé trouvée: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\www.developpeme
Clé trouvée: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\www.nicematin.c
Clé trouvée: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\developpement-dura
Clé trouvée: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\immo.trovit.fr
Clé trouvée: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\nicematin.com
Clé trouvée: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\trovit.fr
Clé trouvée: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\www.developpement-
Clé trouvée: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\www.nicematin.com
Valeur trouvée: HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION [StormWatchApp.exe]
Clé trouvée: HKCU\Software\Google\Chrome\Extensions\fcfenmboojpjinhpgggodefccipikbpd
Clé trouvée: [x64] HKCU\Software\Google\Chrome\Extensions\fcfenmboojpjinhpgggodefccipikbpd
Clé trouvée: HKLM\SOFTWARE\Google\Chrome\Extensions\npdicihegicnhaangkdmcgbjceoemeoo
***** [ Navigateurs web ] *****
Aucune préférence Firefox malveillante trouvée.
Chromium préf trouvée: [C:\Users\JP\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences ] - ceopoaldcnmhechacafgagdkklcogkgd
Chromium préf trouvée: [C:\Users\JP\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences ] - fcfenmboojpjinhpgggodefccipikbpd
Chromium préf trouvée: [C:\Users\JP\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences ] - jlincbpgbkpbjepghokdnhnnpphmegig
Chromium préf trouvée: [C:\Users\JP\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences ] - mabloidgodmbnmnhoenmhlcjkfelomgp
Chromium préf trouvée: [C:\Users\JP\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences ] - npdicihegicnhaangkdmcgbjceoemeoo
*************************
C:\AdwCleaner\AdwCleaner[C1].txt - [8205 octets] - [13/06/2016 09:28:04]
C:\AdwCleaner\AdwCleaner[C2].txt - [13048 octets] - [07/10/2016 09:40:29]
C:\AdwCleaner\AdwCleaner[S1].txt - [8017 octets] - [13/06/2016 09:26:04]
C:\AdwCleaner\AdwCleaner[S2].txt - [12209 octets] - [07/10/2016 09:39:24]
C:\AdwCleaner\AdwCleaner[S3].txt - [11798 octets] - [24/03/2017 10:57:23]
########## EOF - C:\AdwCleaner\AdwCleaner[S3].txt - [11873 octets] ##########
.....
# AdwCleaner v6.043 - Rapport créé le 24/03/2017 à 10:58:11
# Mis à jour le 27/01/2017 par Malwarebytes
# Base de données : 2017-03-23.2 [Serveur]
# Système d'exploitation : Windows 10 Home (X64)
# Nom d'utilisateur : JP - PC
# Exécuté depuis : C:\Users\JP\Desktop\adwcleaner_6.043.exe
# Mode: Nettoyage
# Support : https://www.malwarebytes.com/support
***** [ Services ] *****
[-] Service supprimé: YSearchUtilSvc
[-] Service supprimé: sbnetsys
***** [ Dossiers ] *****
[-] Dossier supprimé: C:\Users\JP\AppData\Local\Google\Chrome\User Data\Default\Extensions\hclpcakhmfeidfpdlmoompeikfiapikb
[-] Dossier supprimé: C:\Users\JP\AppData\Local\Downloaded Installers
[-] Dossier supprimé: C:\ProgramData\BSD
[#] Dossier supprimé au redémarrage: C:\ProgramData\Application Data\BSD
[-] Dossier supprimé: C:\Users\Public\Documents\Downloaded Installers
[-] Dossier supprimé: C:\Program Files (x86)\Yahoo!\yset
[-] Dossier supprimé: C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\YSearchUtil
[-] Dossier supprimé: C:\Users\JP\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcfenmboojpjinhpgggodefccipikbpd
[-] Dossier supprimé: C:\Users\JP\AppData\Local\Google\Chrome\User Data\Default\Extensions\npdicihegicnhaangkdmcgbjceoemeoo
[-] Dossier supprimé: C:\Users\JP\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlincbpgbkpbjepghokdnhnnpphmegig
[-] Dossier supprimé: C:\Users\JP\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jlincbpgbkpbjepghokdnhnnpphmegig
***** [ Fichiers ] *****
[-] Fichier supprimé: C:\Users\JP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_fcfenmboojpjinhpgggodefccipikbpd_0.localstorage
***** [ DLL ] *****
***** [ WMI ] *****
***** [ Raccourcis ] *****
***** [ Tâches planifiées ] *****
***** [ Registre ] *****
[-] Clé supprimée: HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\SCService
[#] Clé supprimée au redémarrage: [x64] HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\SCService
[#] Clé supprimée au redémarrage: HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\scservice
[#] Clé supprimée au redémarrage: [x64] HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\scservice
[-] Clé supprimée: HKCU\Software\Classes\CLSID\{9C4EFBD5-1ADF-41E6-BE26-AF44326E30E4}
[-] Clé supprimée: HKLM\SOFTWARE\Classes\Interface\{A8F7D0A5-7074-40B8-9BDC-1174BDD0A132}
[-] Clé supprimée: HKLM\SOFTWARE\Classes\Interface\{D14D64BC-A0E4-42E3-BB72-FB41EA43C198}
[-] Clé supprimée: HKLM\SOFTWARE\Classes\Interface\{DD1F043F-ABC8-4643-8B95-D2C5B22BB019}
[-] Clé supprimée: HKLM\SOFTWARE\Classes\Interface\{E3F3E8F9-F747-4DD6-BA6B-82A6CE1E0860}
[-] Clé supprimée: HKLM\SOFTWARE\Classes\Interface\{ED0B64D4-BF27-4521-AD27-190F49BF5EA7}
[-] Clé supprimée: HKLM\SOFTWARE\Classes\Interface\{023E9EC8-B147-40EB-B0B3-DF90618FB371}
[-] Clé supprimée: HKLM\SOFTWARE\Classes\Interface\{0522D9A4-4D57-437D-978D-E5B3B6C9005D}
[-] Clé supprimée: HKLM\SOFTWARE\Classes\Interface\{07F41522-AF7D-4F26-B394-094F059FDB8A}
[-] Clé supprimée: HKLM\SOFTWARE\Classes\Interface\{0C40F472-7407-4467-8914-1DEA7C326972}
[-] Clé supprimée: HKLM\SOFTWARE\Classes\Interface\{212E6D43-6062-492A-B8CC-144669FF11ED}
[-] Clé supprimée: HKLM\SOFTWARE\Classes\Interface\{224FE662-1E6D-4BC0-AEBB-9E2FB4057BE9}
[-] Clé supprimée: HKLM\SOFTWARE\Classes\Interface\{3A807417-B46D-4D37-8C9A-19AC6DE204F9}
[-] Clé supprimée: HKLM\SOFTWARE\Classes\Interface\{3CC60715-D6C5-429D-830E-43FA3F86C61D}
[-] Clé supprimée: HKLM\SOFTWARE\Classes\Interface\{4517D94C-19BA-46FA-BE66-2A30CEAC4A85}
[-] Clé supprimée: HKLM\SOFTWARE\Classes\Interface\{555D7146-94A8-4C94-AE76-C39CDC7F7705}
[-] Clé supprimée: HKLM\SOFTWARE\Classes\Interface\{59D188FA-757A-424E-8C93-F58FFD896BD7}
[-] Clé supprimée: HKLM\SOFTWARE\Classes\Interface\{8120D9D6-785C-4413-9C0C-DF2028C56FAD}
[-] Clé supprimée: HKLM\SOFTWARE\Classes\Interface\{823AE2EB-E62C-4847-B192-C99B91B92416}
[-] Clé supprimée: HKLM\SOFTWARE\Classes\Interface\{9B4F7CFE-987D-410E-A8E4-20182E0B3C24}
[-] Clé supprimée: HKLM\SOFTWARE\Classes\Interface\{9B9A45F4-18FC-484A-BACA-076D78273D8E}
[-] Clé supprimée: HKLM\SOFTWARE\Classes\Interface\{A6D54287-7939-466A-8579-92546D946C8C}
[-] Clé supprimée: HKLM\SOFTWARE\Classes\Interface\{A78EDAFB-926F-4D93-AB13-8232D7378EB1}
[-] Clé supprimée: HKLM\SOFTWARE\Classes\Interface\{6C42038D-817A-472C-8C2A-EF46F1DA576D}
[-] Clé supprimée: HKLM\SOFTWARE\Classes\Interface\{873C7DA8-195D-4D5A-B830-C5E2831901EA}
[-] Clé supprimée: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3B96B5D3-4A8D-42DC-9CDE-E9B94B3CFE5D}
[-] Clé supprimée: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
[-] Clé supprimée: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{ACCC747B-2A59-4F30-BA7C-D26333DE65F5}
[-] Clé supprimée: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
[-] Clé supprimée: HKLM\SOFTWARE\MaxPower
[-] Clé supprimée: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! SearchSet
[-] Clé supprimée: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\developpement-durable.gouv.fr
[-] Clé supprimée: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\immo.trovit.fr
[-] Clé supprimée: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\nicematin.com
[-] Clé supprimée: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\trovit.fr
[-] Clé supprimée: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\www.developpement-durable.gouv.fr
[-] Clé supprimée: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\www.nicematin.com
[-] Clé supprimée: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\developpement-durable.gouv.fr
[-] Clé supprimée: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\immo.trovit.fr
[-] Clé supprimée: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\nicematin.com
[-] Clé supprimée: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\trovit.fr
[-] Clé supprimée: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\www.developpement-durable.gouv.fr
[-] Clé supprimée: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\www.nicematin.com
[#] Clé supprimée au redémarrage: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\developpement-durable.gouv.fr
[#] Clé supprimée au redémarrage: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\immo.trovit.fr
[#] Clé supprimée au redémarrage: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\nicematin.com
[#] Clé supprimée au redémarrage: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\trovit.fr
[#] Clé supprimée au redémarrage: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\www.developpement-durable.gouv.fr
[#] Clé supprimée au redémarrage: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\www.nicematin.com
[#] Clé supprimée au redémarrage: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\developpement-durable.gouv.fr
[#] Clé supprimée au redémarrage: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\immo.trovit.fr
[#] Clé supprimée au redémarrage: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\nicematin.com
[#] Clé supprimée au redémarrage: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\trovit.fr
[#] Clé supprimée au redémarrage: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\www.developpement-durable.gouv.fr
[#] Clé supprimée au redémarrage: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\www.nicematin.com
[-] Valeur supprimée: HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION [StormWatchApp.exe]
[-] Clé supprimée: HKCU\Software\Google\Chrome\Extensions\fcfenmboojpjinhpgggodefccipikbpd
[#] Clé supprimée au redémarrage: [x64] HKCU\Software\Google\Chrome\Extensions\fcfenmboojpjinhpgggodefccipikbpd
[-] Clé supprimée: HKLM\SOFTWARE\Google\Chrome\Extensions\npdicihegicnhaangkdmcgbjceoemeoo
***** [ Navigateurs ] *****
[-] [C:\Users\JP\AppData\Local\Google\Chrome\User Data\Default] [extension] Supprimé: ceopoaldcnmhechacafgagdkklcogkgd
[-] [C:\Users\JP\AppData\Local\Google\Chrome\User Data\Default] [extension] Supprimé: fcfenmboojpjinhpgggodefccipikbpd
[-] [C:\Users\JP\AppData\Local\Google\Chrome\User Data\Default] [extension] Supprimé: jlincbpgbkpbjepghokdnhnnpphmegig
[-] [C:\Users\JP\AppData\Local\Google\Chrome\User Data\Default] [extension] Supprimé: mabloidgodmbnmnhoenmhlcjkfelomgp
[-] [C:\Users\JP\AppData\Local\Google\Chrome\User Data\Default] [extension] Supprimé: npdicihegicnhaangkdmcgbjceoemeoo
*************************
:: Clés "Tracing" supprimées
:: Paramètres Winsock réinitialisés
*************************
C:\AdwCleaner\AdwCleaner[C1].txt - [8205 octets] - [13/06/2016 09:28:04]
C:\AdwCleaner\AdwCleaner[C2].txt - [13048 octets] - [07/10/2016 09:40:29]
C:\AdwCleaner\AdwCleaner[C3].txt - [12225 octets] - [24/03/2017 10:58:11]
C:\AdwCleaner\AdwCleaner[S1].txt - [8017 octets] - [13/06/2016 09:26:04]
C:\AdwCleaner\AdwCleaner[S2].txt - [12209 octets] - [07/10/2016 09:39:24]
C:\AdwCleaner\AdwCleaner[S3].txt - [12014 octets] - [24/03/2017 10:57:23]
########## EOF - C:\AdwCleaner\AdwCleaner[C3].txt - [12524 octets] ##########
...
RogueKiller V12.9.9.0 (x64) [Feb 27 2017] (Gratuit) par Adlice Software
email : http://www.adlice.com/contact/
Remontées : http://forum.adlice.com
Site web : https://www.sosvirus.net/telecharger/roguekiller-anti-malware/
Blog : http://www.adlice.com
Système d'exploitation : Windows 10 (10.0.14393) 64 bits version
Démarré en : Mode normal
Utilisateur : JP [Administrateur]
Démarré depuis : C:\Users\JP\Desktop\RogueKillerX64.exe
Mode : Scan -- Date : 03/24/2017 11:09:42 (Durée : 00:44:17)
¤¤¤ Processus : 0 ¤¤¤
¤¤¤ Registre : 3 ¤¤¤
[PUP.Gen0] (X64) HKEY_CLASSES_ROOT\CLSID\{9C4EFBD5-1ADF-41E6-BE26-AF44326E30E4} -> Trouvé(e)
[PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-3564986373-298261902-3817003692-1001\Software\IM -> Trouvé(e)
[PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-3564986373-298261902-3817003692-1001\Software\IM -> Trouvé(e)
¤¤¤ Tâches : 0 ¤¤¤
¤¤¤ Fichiers : 0 ¤¤¤
¤¤¤ WMI : 0 ¤¤¤
¤¤¤ Fichier Hosts : 0 ¤¤¤
¤¤¤ Antirootkit : 0 (Driver: Chargé) ¤¤¤
¤¤¤ Navigateurs web : 0 ¤¤¤
¤¤¤ Vérification MBR : ¤¤¤
+++++ PhysicalDrive0: ST2000DM001-1CH164 +++++
--- User ---
[MBR] eb6baeb17bdf31346393177c57f1d3cf
[BSP] 93549d5f0aaf33075dad7ad97e96096c : Unknown MBR Code
Partition table:
0 - [SYSTEM][MAN-MOUNT] Basic data partition | Offset (sectors): 2048 | Size: 1023 MB
1 - [MAN-MOUNT] EFI system partition | Offset (sectors): 2097152 | Size: 360 MB
2 - [MAN-MOUNT] Microsoft reserved partition | Offset (sectors): 2834432 | Size: 128 MB
3 - Basic data partition | Offset (sectors): 3096576 | Size: 1887457 MB
4 - [SYSTEM][MAN-MOUNT] | Offset (sectors): 3868610560 | Size: 498 MB
5 - [SYSTEM][MAN-MOUNT] | Offset (sectors): 3869630464 | Size: 350 MB
6 - [SYSTEM] Basic data partition | Offset (sectors): 3870347264 | Size: 17906 MB
User = LL1 ... OK
User = LL2 ... OK
+++++ PhysicalDrive1: SanDisk SDSA5GK-016G-1006 +++++
--- User ---
[MBR] 6fd9dcdc88ac8d9638277d2e61486d44
[BSP] 2cbc2f133ad1ebc059e63a41af978254 : Windows Vista/7/8 MBR Code
Partition table:
0 - [XXXXXX] UNKNOWN (0x73) [VISIBLE] Offset (sectors): 2048 | Size: 15270 MB
User = LL1 ... OK
User = LL2 ... OK
+++++ PhysicalDrive2: TOSHIBA TransMemory USB Device +++++
--- User ---
[MBR] d5ec2c2b24b33618b587609fec128ed3
[BSP] df4f83c1f72e36823a12b0dfc7617313 : Empty MBR Code
Partition table:
0 - Microsoft Basic Data | Offset (sectors): 2048 | Size: 29542 MB
User = LL1 ... OK
Error reading LL2 MBR! ([32] Cette demande n?est pas prise en charge.