~ ZHPCleaner v2021.4.11.290 by Nicolas Coolman (2021/04/11) ~ Run by Jon Imaz (Administrator) (14/04/2021 16:36:34) ~ Web: https://www.nicolascoolman.com ~ Blog: https://nicolascoolman.eu/ ~ Facebook : https://www.facebook.com/nicolascoolman1 ~ State version : Version OK ~ Type : Repair ~ Report : D:\Jon Imaz\ÀREA DE TRABALHO\ZHPCleaner (R).txt ~ Quarantine : C:\Users\Jon Imaz\AppData\Roaming\ZHP\ZHPCleaner_Reg.txt ~ System Restore Point : OK ~ UAC : Activate ~ Boot Mode : Normal (Normal boot) Windows 8.1 Single Language, 64-bit (Build 9600) ---\\ Alternate Data Stream (ADS). (0) ~ No malicious or unnecessary items found. ---\\ Services (0) ~ No malicious or unnecessary items found. ---\\ Browser internet (0) ~ No malicious or unnecessary items found. ---\\ Hosts file (1) ~ The hosts file is legitimate (1) ---\\ Scheduled automatic tasks. (0) ~ No malicious or unnecessary items found. ---\\ Explorer ( File, Folder) (10) MOVED file: C:\Users\Jon Imaz\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\BS.Player FREE.lnk [Bad : C:\Program Files (x86)\Webteh\BSPlayer\bsplayer.exe](.AB Team.) =>.SUP.ABTeam MOVED file: C:\Users\Public\Desktop\BS.Player FREE.lnk [Bad : C:\Program Files (x86)\Webteh\BSPlayer\bsplayer.exe](.AB Team.) =>.SUP.ABTeam MOVED file: C:\Users\Jon Imaz\AppData\Roaming\Mozilla\Firefox\Profiles\w2eu3x0b.default-1495374066735-1554123762353\searchplugins\yahoo.xml =>PUP.Optional.BDYahoo MOVED file: C:\Users\Jon Imaz\AppData\Local\Google\Chrome\User Data\Default\Preferences =>Préférences Chromium MOVED file: C:\Users\Jon Imaz\AppData\Local\Microsoft\Edge\User Data\Default\Preferences =>Préférences Chromium MOVED file: D:\Jon Imaz\ÀREA DE TRABALHO\~$SAuto Net 2016 Portable by Ratiborus.docx =>HackTool.KMSpico MOVED folder: C:\Program Files (x86)\Webteh =>.SUP.ABTeam MOVED folder: C:\ProgramData\KMSAutoS =>HackTool.WinActivator MOVED folder: C:\Users\Jon Imaz\AppData\Roaming\DiskDefrag =>SUP.Optional.AuslogicsDiskDefrag MOVED folder: C:\Users\Jon Imaz\AppData\Local\MSfree Inc =>HackTool.WinActivator ---\\ Registry ( Key, Value, Data) (7) DELETED key*: [X64] HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5} [ITool] =>Toolbar.Ask DELETED key*: [X64] HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56} [secman] =>PUP.Optional.Camec DELETED key^: [X64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Flash Player PPAPI Notifier [] =>Riskware.FlashPlayer DELETED key^: [X64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Flash Player Updater [] =>Riskware.FlashPlayer DELETED key*: [X64] HKLM\SOFTWARE\Wow6432Node\Webteh [] =>.SUP.ABTeam DELETED key**: [X64] HKLM\SOFTWARE\Wow6432Node\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56} [secman] =>PUP.Optional.Camec DELETED key*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player PPAPI [Adobe] =>Riskware.FlashPlayer ---\\ Summary of the elements found (9) https://nicolascoolman.eu/forum/Topic/logiciels-potentiellement-superflus-lps/ =>.SUP.ABTeam https://nicolascoolman.eu/forum/Topic/repaquetage-et-infection/ =>PUP.Optional.BDYahoo https://nicolascoolman.eu/forum/Topic/repaquetage-et-infection/ =>Préférences Chromium https://nicolascoolman.eu/2017/02/16/hacktool-kmspico/ =>HackTool.KMSpico https://nicolascoolman.eu/2017/01/13/hacktool-winactivator/ =>HackTool.WinActivator https://nicolascoolman.eu/forum/Topic/repaquetage-et-infection/ =>SUP.Optional.AuslogicsDiskDefrag https://nicolascoolman.eu/2017/02/28/toolbar-ask/ =>Toolbar.Ask https://nicolascoolman.eu/forum/Topic/repaquetage-et-infection/ =>PUP.Optional.Camec https://nicolascoolman.eu/forum/Topic/flashplayer-logiciel-a-risque-riskware/ =>Riskware.FlashPlayer ---\\ Other deletions. (1) ~ Registry Keys Tracing deleted (1) ~ Remove the old reports ZHPCleaner. (0) ---\\ Result of repair ~ Repair carried out successfully ~ Google Chrome OK ~ Mozilla Firefox OK ~ Internet Explorer OK ~ Opera Stable OK ~ The system has been restarted. ---\\ Statistics ~ Items scanned : 3298 ~ Items found : 0 ~ Items cancelled : 0 ~ Space saving (bytes) : 0 ~ Items options : 9/17 ---\\ OPTIONS NOT ACTIVES ~ Temporary file analysis ~ Temporary folder analysis ~ Empty Folder CLSID Analysis ~ Empty Other Folder Analysis ~ Empty LocalLow Folder Analysis ~ Empty Local Folder Analysis ~ Obsolete Installer File Analysis ~ Start browsers with extensions removed ~ End of clean in 00h01mn03s ---\\ Reports (2) ZHPCleaner-[S]-14042021-16_32_16.txt ZHPCleaner-[R]-14042021-16_37_37.txt