~ Rapport de ZHPDiag v2013.12.6.12 - Nicolas Coolman  (06/12/2013) 
~ Lancé par Chateaudun (16/12/2013 18:05:14) 
~ Adresse du Site Web  http://nicolascoolman.webs.com 
~ Forums gratuits d'Assistance à la désinfection : http://nicolascoolman.webs.com/apps/links/ 
~ Traduit par Nicolas Coolman 
~ Etat de la version :  
~ Liste blanche : Activée par le programme 
~ Elévation des Privilèges : OK 
~ User Account Control (UAC): Activate by user 
  
  
---\\ Navigateurs Internet 
MSIE: Internet Explorer v11.0.9431.224 
GCIE: Google Chrome v31.0.1650.63 (Defaut) 
  
---\\ Informations sur les produits Windows 
~ Langage: Français 
Windows 8 Business Edition, 32-bit Service Pack 1 (9431) 
Windows Server License Manager Script : OK 
~ ion : Windows® Operating System, RETAIL channel 
Windows ID Activation : OK 
~ Windows Partial Key : VCBQH 
Windows License : OK 
~ Windows Remaining Initializations Number : 1000 
Software Protection Service (Protection logicielle) : OK 
Windows Automatic Updates : OK 
Windows Activation Technologies : OK 
  
---\\ Logiciels de protection du système 
Malwarebytes' Anti-Malware 
Windows Defender W8 
  
---\\ Logiciels d'optimisation du système 
CCleaner v4.02 =>Piriform Ltd 
  
---\\ Logiciels de partage PeerToPeer 
  
---\\ Surveillance de Logiciels 
Adobe Flash Player 11 Plugin 
  
---\\ Informations sur le système 
~ Processor: x86 Family 16 Model 4 Stepping 2, AuthenticAMD 
~ Operating System: 32 Bits 
Boot mode: Normal (Normal boot) 
Total RAM: 2047 MB (69% free) 
System Restore: Activé (Enable) 
System drive C: has 113 GB (75%) free of 149 GB 
  
---\\ Mode de connexion au système 
~ Computer Name: DOMICILE 
~ User Name: Chateaudun 
~ All Users Names: HomeGroupUser$, Chateaudun, Administrateur,  
~ Unselected Option: O45,O61,O62,O65,O66,O80,O82,O89 
Logged in as Administrator 
  
---\\ Variables d'environnement 
~ System Unit : C:\ 
~ %AppZHP% : C:\Users\Chateaudun\AppData\Roaming\ZHP\ 
~ %AppData% : C:\Users\Chateaudun\AppData\Roaming\ 
~ %Desktop% : C:\Users\Chateaudun\Desktop\ 
~ %Favorites% : C:\Users\Chateaudun\Favorites\ 
~ %LocalAppData% : C:\Users\Chateaudun\AppData\Local\ 
~ %StartMenu% : C:\Users\Chateaudun\AppData\Roaming\Microsoft\Windows\Start Menu\ 
~ %Windir% : C:\Windows\ 
~ %System% : C:\Windows\System32\ 
  
---\\ Enumération des unités disques 
C: Hard drive, Flash drive, Thumb drive (Free 113 Go of 149 Go) 
D: Hard drive, Flash drive, Thumb drive (Free 60 Go of 298 Go) 
  
  
  
---\\ Etat du Centre de Sécurité Windows 
~ Security Center: 38 Legitimates Filtered in 00mn 00s 
  
  
  
---\\ Recherche particulière de fichiers génériques 
[MD5.253252BBC9E61728986CB54261F8AECD] - (.Microsoft Corporation - Explorateur Windows.) (.16/06/2013 - 02:33:13.) -- C:\Windows\Explorer.exe [2009104] 
[MD5.7EC2DCAA1BA0CF2B1207F03325131E89] - (.Microsoft Corporation - Application de démarrage de Windows.) (.15/06/2013 - 23:09:14.) -- C:\Windows\System32\Wininit.exe [113152] 
[MD5.7993622CF9407CA51DAEB2E965ED94F4] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.15/12/2013 - 19:03:49.) -- C:\Windows\System32\wininet.dll [1788928] 
[MD5.29A02ACCC5A9FC862FD2EE8E459A7499] - (.Microsoft Corporation - Application d’ouverture de session Windows.) (.15/06/2013 - 23:07:58.) -- C:\Windows\System32\Winlogon.exe [456704] 
[MD5.F0EE9627460DD09A16C2032B86C6B40F] - (.Microsoft Corporation - Bibliothèque de licences.) (.15/06/2013 - 23:38:49.) -- C:\Windows\System32\sppcomapi.dll [438784] 
[MD5.2E738F26946DB2D81623C5DC4512EFE6] - (.Microsoft Corporation - Pilote de fonction connexe pour WinSock.) (.16/06/2013 - 03:19:44.) -- C:\Windows\system32\Drivers\AFD.sys [454144] 
[MD5.471129F85C6A5F6A015FA0B0B667BB35] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.16/06/2013 - 02:43:41.) -- C:\Windows\system32\Drivers\atapi.sys [23304] 
[MD5.B8E122FA0399D3F4ABDA11C502DED530] - (.Microsoft Corporation - CD-ROM File System Driver.) (.16/06/2013 - 00:28:41.) -- C:\Windows\system32\Drivers\Cdfs.sys [73728] 
[MD5.57F897474528E1545927B758AB477CA0] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.15/06/2013 - 22:27:19.) -- C:\Windows\system32\Drivers\Cdrom.sys [124928] 
[MD5.D7343BB50B926B5E3D244E97002C8CC5] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.16/06/2013 - 00:26:43.) -- C:\Windows\system32\Drivers\DfsC.sys [100864] 
[MD5.0C840206C7717B668C1E87DAE8089255] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.16/06/2013 - 00:27:05.) -- C:\Windows\system32\Drivers\HDAudBus.sys [70144] 
[MD5.CE945A0B0E44D6ECDED1D9D5847B11D6] - (.Microsoft Corporation - Pilote de port i8042.) (.16/06/2013 - 00:27:44.) -- C:\Windows\system32\Drivers\i8042prt.sys [82944] 
[MD5.7DC6AF75FAC033A3426D1D7D7E3BBB0E] - (.Microsoft Corporation - IP Network Address Translator.) (.16/06/2013 - 00:24:43.) -- C:\Windows\system32\Drivers\IpNat.sys [126464] 
[MD5.909FC8A42CFA5F9A9781148C08D797FC] - (.Microsoft Corporation - Minirdr SMB Windows NT.) (.16/06/2013 - 00:25:17.) -- C:\Windows\system32\Drivers\MRxSmb.sys [331776] 
[MD5.12EBA25B38A1A0F8B4933026496B2C1E] - (.Microsoft Corporation - MBT Transport driver.) (.16/06/2013 - 00:25:35.) -- C:\Windows\system32\Drivers\netBT.sys [218112] 
[MD5.C573C02D83097766EF52E3177A17CABF] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.16/06/2013 - 03:19:43.) -- C:\Windows\system32\Drivers\ntfs.sys [1672456] 
[MD5.3DF319156740EAFB3344E6F74D094CE9] - (.Microsoft Corporation - Pilote de port parallèle.) (.16/06/2013 - 00:28:36.) -- C:\Windows\system32\Drivers\Parport.sys [82432] 
[MD5.7D4559EAC6F71C2B378D11212ACDC923] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.16/06/2013 - 00:24:53.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [81920] 
[MD5.99294446C36E4636F96EF5D3A94A67D7] - (.Microsoft Corporation - Redirecteur de périphérique de Microsoft RDP.) (.16/06/2013 - 10:25:52.) -- C:\Windows\system32\Drivers\rdpdr.sys [143360] 
[MD5.8D054D65C42F2C3C0199FA0318B06C8D] - (.Microsoft Corporation - TDI Translation Driver.) (.16/06/2013 - 03:19:44.) -- C:\Windows\system32\Drivers\tdx.sys [86016] 
[MD5.0013DF4B81C450AB1AD40CC7FBC8F163] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.16/06/2013 - 02:35:26.) -- C:\Windows\system32\Drivers\volsnap.sys [264968] 
~ Generic Processes:  Scanned in 00mn 00s 
  
  
  
---\\ Etat des fichiers cachés (Caché/Total) 
~ Mes images (My Pictures) : 2/480 
~ Mes musiques (My Musics) : 2/269 
~ Mes Videos (My Videos) : 2/10 
~ Mes Favoris (My Favorites) : 1/5 
~ Mes Documents (My Documents) : 2/537 
~ Mon Bureau (My Desktop) : 2/1817 
~ Menu demarrer (Programs) : 1/38 
~ Hidden Files:  Scanned in 00mn 02s 
  
  
  
---\\ Processus lancés 
[MD5.17D4E929FEF1FD2B3FD0F4D3DA809EA6] - (.Microsoft Corporation - Processus hôte pour Tâches Windows.) -- C:\WINDOWS\system32\taskhostex.exe   [66000] [PID.1608] 
[MD5.06EBAA1B77724C1FC858AD49F2D5B88D] - (.Glarysoft Ltd - Glary Utilities 4.) -- C:\Program Files\Glary Utilities 4\Integrator.exe   [757536] [PID.360] 
[MD5.C1DB9BDF885C2F1ADC15264FBEA2788F] - (.Pas de propriétaire - HOSTS Anti-PUPs/Adwares.) -- C:\Program Files\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware_main.exe   [302961] [PID.2068] 
[MD5.1C5A81304F4B3A24914E10E339E3D51A] - (.BitTorrent Inc. - µTorrent.) -- C:\Users\Chateaudun\AppData\Roaming\uTorrent\uTorrent.exe   [900440] [PID.2084]  =>P2P.BitTorrent 
[MD5.A9C80B3425FF31210A005573480CE123] - (.Microsoft Corporation - Microsoft SkyDrive.) -- C:\Windows\System32\skydrive.exe   [515072] [PID.3528] 
[MD5.A80D2D9D8752B54FF96C4E953F886EEC] - (.Microsoft Corporation - Paramètres du PC.) -- C:\WINDOWS\ImmersiveControlPanel\SystemSettings.exe   [85672] [PID.3668] 
[MD5.650BC2E301E20C957C08798B1240E95F] - (.Microsoft Corporation - Host Process for Setting Synchronization.) -- C:\Windows\System32\SettingSyncHost.exe   [437760] [PID.2808] 
[MD5.34DA68CCDC56BF9409C72C43BA6B744F] - (.The Eraser Project - Eraser.) -- C:\Program Files\Eraser\Eraser.exe   [980920] [PID.2516] 
[MD5.CF48ADB5E601310A577F0D1BADD28ACB] - (.Microsoft Corporation - COM Surrogate.) -- C:\WINDOWS\system32\DllHost.exe   [17672] [PID.2484] 
[MD5.AADD0892A428B133ABEF5EBCCE5E1799] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe   [8281600] [PID.3584] 
~ Processes Running:  Scanned in 00mn 01s 
  
  
  
---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2) 
C:\Users\Chateaudun\AppData\Local\Google\Chrome\User Data\Default\Preferences 
G2 - GCE: Preference [user Data\Default] [dgiecfacokilefjaaodhjlpdgdhdomgj] Adventure Golf v.1.0 (Activé) 
G2 - GCE: Preference [user Data\Default] [edlgljkkoneggjmhhlbnkeohlaplokpj] Tennis de table HD v.1.0.0 (Désactivé) 
G2 - GCE: Preference [user Data\Default] [enaaiocgfnhfddlooahdapieledmlhnc] Débloquer v.1.0.0 (Activé) 
G2 - GCE: Preference [user Data\Default] [fmedapekkakaehidplfhmblngkelolaj] Voodoo Friends v.1.0 (Désactivé) 
G2 - GCE: Preference [user Data\Default] [gabjgmfeekebnbifcagmpmobohmjheoe] Meilleurs Jeux Super Mario v.1.0.25.0 (Activé) 
G2 - GCE: Preference [user Data\Default] [hfpeacgpdnhofhebmincihdelcemhagd] Creatures & Castles (Créatures & Ch\u00E2teaux) v.2.0 (Désactivé) 
G2 - GCE: Preference [user Data\Default] [iogblfbfoldfgammcabomglfajocfpea] Fire Boy And Water Girl v.1.0.0 (Désactivé) 
G2 - GCE: Preference [user Data\Default] [jomlahcelngebaebobkjhogcenmkafmn] Jeu de tennis 3D v.1.0.0 (Activé) 
G2 - GCE: Preference [user Data\Default] [kpbhbohcdnlcediiopngchhnnofnhaec] Super Angelo v.1.0.25.0 (Activé) 
G2 - GCE: Preference [user Data\Default] [lfgcmpnnailedfapmafbigfifabfamcl] Rider Fou v.1.0.4 (Activé) 
G2 - GCE: Preference [user Data\Default] [ncgcikiganileglfgcpcplalmkmalhne] The Island - Castaway v.1.0.0.5 (Désactivé) 
G2 - GCE: Preference [user Data\Default] [pfglnpdpgmecffbejlfgpnebopinlclj] SiteBlock v.0.2.3 (Désactivé) 
~ Google Browser: 34 Legitimates Filtered in 00mn 12s 
  
  
  
---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions  (P2,M0,M1,M2,M3) 
C:\Users\Chateaudun\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\prefs.js 
C:\Users\Chateaudun\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\user.js 
~ Firefox Browser: 9 Legitimates Filtered in 00mn 00s 
  
  
  
---\\ Internet Explorer, Proxy Management (R5) 
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;<local> 
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key 
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll 
~ Proxy management:  Scanned in 00mn 00s 
  
  
  
---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs 
F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe, 
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe 
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe 
~ Keys:  Scanned in 00mn 00s 
  
  
  
---\\ Hosts file redirection (O1) 
~ Le fichier hosts est sain (The hosts file is clean). 
~ Hosts File:  Scanned in 00mn 00s 
~ Nombre de lignes (Lines number): 1837 
  
  
  
---\\ Autres liens utilisateurs (O4) 
O4 - GS\Desktop [Public]: Eraser.lnk . (.The Eraser Project - Eraser.)  -- C:\Program Files\Eraser\Eraser.exe  
O4 - GS\Desktop [Public]: MappyPlus.lnk . (...)  -- C:\WINDOWS\Installer\{478F482D-C30B-4876-A080-BE3916268682}\app_icon.ico  
O4 - GS\Desktop [Public]: PowerISO.lnk . (.PowerISO Computing, Inc. - PowerISO.)  -- C:\Program Files\PowerISO\PowerISO.exe  
O4 - GS\Desktop [Public]: WahOO.lnk . (...)  -- C:\Users\Chateaudun\AppData\Local\WahOO\Wahoo.exe 
O4 - GS\Program [Public]: Desktop.lnk - Clé orpheline 
O4 - GS\Program [Public]: Eraser.lnk . (.The Eraser Project - Eraser.)  -- C:\Program Files\Eraser\Eraser.exe  
O4 - GS\QuickLaunch [Chateaudun]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.)  -- C:\Program Files\Internet Explorer\iexplore.exe  
O4 - GS\QuickLaunch [Chateaudun]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.)  -- C:\Users\Chateaudun\AppDa