~ ZHPCleaner v2018.6.28.142 by Nicolas Coolman (2018/06/28)
~ Run by Usuario (Administrator) (01/07/2018 03:12:01)
~ Web:
https://www.nicolascoolman.com
~ Blog:
https://nicolascoolman.eu/
~ Facebook :
https://www.facebook.com/nicolascoolman1
~ State version : Version OK
~ Certificate ZHPCleaner: Legal
~ Type : Repair
~ Report : C:\Users\Usuario\Desktop\ZHPCleaner.txt
~ Quarantine : C:\Users\Usuario\AppData\Roaming\ZHP\ZHPCleaner_Reg.txt
~ UAC : Activate
~ Boot Mode : Normal (Normal boot)
Windows 10 Pro, 64-bit (Build 17134)
---\\ Alternate Data Stream (ADS). (0)
~ No malicious or unnecessary items found.
---\\ Services (0)
~ No malicious or unnecessary items found.
---\\ Browser internet (0)
~ No malicious or unnecessary items found.
---\\ Hosts file (1)
~ The hosts file is legitimate (1)
---\\ Scheduled automatic tasks. (0)
~ No malicious or unnecessary items found.
---\\ Explorer ( File, Folder) (13)
MOVED file: C:\Users\Usuario\Desktop\Popcorn-Time.lnk [Bad : C:\Users\Usuario\AppData\Local\Popcorn-Time\Popcorn-Time.exe](.The NWJS Community.) =>.SUP.PopcornTime
MOVED file: C:\Users\Usuario\Desktop\µTorrent.lnk [Bad : C:\Users\Usuario\AppData\Roaming\uTorrent\uTorrent.exe](.BitTorrent Inc..) =>BitTorrent (P2P)
MOVED file: C:\Users\Usuario\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk [Bad : C:\Users\Usuario\AppData\Roaming\uTorrent\uTorrent.exe](.BitTorrent Inc..) =>BitTorrent (P2P)
MOVED file: C:\WINDOWS\System32\DRIVERS\SWDUMon.sys [SlimWare Utilities, Inc. - Driver Update Installer Monitor] =>.SUP.SlimWareUtilities
MOVED file: C:\Users\Usuario\Downloads\MHO_Setup_2.0.11.535_QQVIPDL_speeded_signed.exe =>.SUP.Tencent
MOVED file: C:\Windows\SECOH-QAD.exe =>HackTool.KMSpico
MOVED folder: C:\Program Files (x86)\Skillbrains =>.SUP.Skillbrains
MOVED folder: C:\Program Files\KMSpico =>HackTool.KMSpico
MOVED folder: C:\ProgramData\SlimWare Utilities, Inc =>.SUP.SlimWareUtilities
MOVED folder: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KMSpico =>HackTool.KMSpico
MOVED folder: C:\Users\Usuario\AppData\Roaming\Tencent =>.SUP.Tencent
MOVED folder: C:\Users\Usuario\AppData\Local\Popcorn-Time =>.SUP.PopcornTime
MOVED folder: C:\Users\Usuario\AppData\Local\SlimWare Utilities Inc =>.SUP.SlimWareUtilities
---\\ Registry ( Key, Value, Data) (15)
DELETED key*: HKLM\SYSTEM\CurrentControlSet\Services\SWDUMon [C:\WINDOWS\System32\DRIVERS\SWDUMon.sys (Not File)] =>.SUP.SlimWareUtilities
DELETED key*: HKEY_USERS\S-1-5-21-1200185014-1064253907-2239933727-1001\SOFTWARE\QQVipDownloader [] =>.SUP.Tencent
DELETED key*: HKEY_USERS\S-1-5-21-1200185014-1064253907-2239933727-1001\SOFTWARE\SkillBrains [] =>.SUP.Skillbrains
DELETED key*: HKEY_USERS\S-1-5-21-1200185014-1064253907-2239933727-1001\SOFTWARE\SlimWare Utilities Inc [] =>.SUP.SlimWareUtilities
DELETED key: HKCU\Software\QQVipDownloader [] =>.SUP.Tencent
DELETED key: HKCU\Software\SkillBrains [] =>.SUP.Skillbrains
DELETED key: HKCU\Software\SlimWare Utilities Inc [] =>.SUP.SlimWareUtilities
DELETED key*: HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Popcorn-Time [Popcorn Time] =>.SUP.PopcornTime
DELETED key*: HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent [BitTorrent Inc.] =>BitTorrent (P2P)
DELETED key*: HKLM\SYSTEM\CurrentControlSet\Services\RZSURROUNDVADService [] =>Trojan.AdService
DELETED key*: [X64] HKLM\SOFTWARE\Wow6432Node\Skillbrains [] =>.SUP.Skillbrains
DELETED key*: [X64] HKLM\SOFTWARE\Wow6432Node\SlimWare Utilities Inc [] =>.SUP.SlimWareUtilities
DELETED key*: [X64] HKLM\SOFTWARE\Wow6432Node\SlimWare Utilities, Inc. [] =>.SUP.SlimWareUtilities
DELETED value: HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules\\{7C2C5807-74F4-471C-8453-453CBE762CDF} [C:\Program Files\KMSpico\AutoPico.exe] =>HackTool.KMSpico
DELETED value: HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules\\{C2ADB24E-7C3D-4690-8F7A-273B5B99EE1E} [C:\Program Files\KMSpico\AutoPico.exe] =>HackTool.KMSpico
---\\ Summary of the elements found (7)
https://nicolascoolman.eu/2017/02/26/superfluous-popcorntime/ =>.SUP.PopcornTime
https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>BitTorrent (P2P)
https://nicolascoolman.eu/2017/03/03/superfluous-slimwareutilities/ =>.SUP.SlimWareUtilities
https://nicolascoolman.eu/2017/02/23/tencentadressbar/ =>.SUP.Tencent
https://nicolascoolman.eu/2017/02/16/hacktool-kmspico/ =>HackTool.KMSpico
https://www.anti-malware.top/2016/04/30/superfluous-skillbrains/ =>.SUP.Skillbrains
https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>Trojan.AdService
---\\ Other deletions. (11)
~ Registry Keys Tracing deleted (11)
~ Remove the old reports ZHPCleaner. (0)
---\\ Result of repair
~ Repair carried out successfully
~ Browser not found (Mozilla Firefox)
~ Browser not found (Opera Software)
---\\ Statistics
~ Items scanned : 528
~ Items found : 0
~ Items cancelled : 0
~ Items options : 0/7
~ Space saving (bytes) : 0
~ End of clean in 00h01mn26s
---\\ Reports (2)
ZHPCleaner-[S]-01072018-03_11_11.txt
ZHPCleaner-[R]-01072018-03_13_27.txt
[/S]