~ Rapport de ZHPDiag v2013.12.6.12 - Nicolas Coolman (06/12/2013)
~ Lancé par Chateaudun (16/12/2013 18:05:14)
~ Adresse du Site Web http://nicolascoolman.webs.com
~ Forums gratuits d'Assistance à la désinfection : http://nicolascoolman.webs.com/apps/links/
~ Traduit par Nicolas Coolman
~ Etat de la version :
~ Liste blanche : Activée par le programme
~ Elévation des Privilèges : OK
~ User Account Control (UAC): Activate by user
---\\ Navigateurs Internet
MSIE: Internet Explorer v11.0.9431.224
GCIE: Google Chrome v31.0.1650.63 (Defaut)
---\\ Informations sur les produits Windows
~ Langage: Français
Windows 8 Business Edition, 32-bit Service Pack 1 (9431)
Windows Server License Manager Script : OK
~ ion : Windows® Operating System, RETAIL channel
Windows ID Activation : OK
~ Windows Partial Key : VCBQH
Windows License : OK
~ Windows Remaining Initializations Number : 1000
Software Protection Service (Protection logicielle) : OK
Windows Automatic Updates : OK
Windows Activation Technologies : OK
---\\ Logiciels de protection du système
Malwarebytes' Anti-Malware
Windows Defender W8
---\\ Logiciels d'optimisation du système
CCleaner v4.02 =>Piriform Ltd
---\\ Logiciels de partage PeerToPeer
---\\ Surveillance de Logiciels
Adobe Flash Player 11 Plugin
---\\ Informations sur le système
~ Processor: x86 Family 16 Model 4 Stepping 2, AuthenticAMD
~ Operating System: 32 Bits
Boot mode: Normal (Normal boot)
Total RAM: 2047 MB (69% free)
System Restore: Activé (Enable)
System drive C: has 113 GB (75%) free of 149 GB
---\\ Mode de connexion au système
~ Computer Name: DOMICILE
~ User Name: Chateaudun
~ All Users Names: HomeGroupUser$, Chateaudun, Administrateur,
~ Unselected Option: O45,O61,O62,O65,O66,O80,O82,O89
Logged in as Administrator
---\\ Variables d'environnement
~ System Unit : C:\
~ %AppZHP% : C:\Users\Chateaudun\AppData\Roaming\ZHP\
~ %AppData% : C:\Users\Chateaudun\AppData\Roaming\
~ %Desktop% : C:\Users\Chateaudun\Desktop\
~ %Favorites% : C:\Users\Chateaudun\Favorites\
~ %LocalAppData% : C:\Users\Chateaudun\AppData\Local\
~ %StartMenu% : C:\Users\Chateaudun\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\
---\\ Enumération des unités disques
C: Hard drive, Flash drive, Thumb drive (Free 113 Go of 149 Go)
D: Hard drive, Flash drive, Thumb drive (Free 60 Go of 298 Go)
---\\ Etat du Centre de Sécurité Windows
~ Security Center: 38 Legitimates Filtered in 00mn 00s
---\\ Recherche particulière de fichiers génériques
[MD5.253252BBC9E61728986CB54261F8AECD] - (.Microsoft Corporation - Explorateur Windows.) (.16/06/2013 - 02:33:13.) -- C:\Windows\Explorer.exe [2009104]
[MD5.7EC2DCAA1BA0CF2B1207F03325131E89] - (.Microsoft Corporation - Application de démarrage de Windows.) (.15/06/2013 - 23:09:14.) -- C:\Windows\System32\Wininit.exe [113152]
[MD5.7993622CF9407CA51DAEB2E965ED94F4] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.15/12/2013 - 19:03:49.) -- C:\Windows\System32\wininet.dll [1788928]
[MD5.29A02ACCC5A9FC862FD2EE8E459A7499] - (.Microsoft Corporation - Application d’ouverture de session Windows.) (.15/06/2013 - 23:07:58.) -- C:\Windows\System32\Winlogon.exe [456704]
[MD5.F0EE9627460DD09A16C2032B86C6B40F] - (.Microsoft Corporation - Bibliothèque de licences.) (.15/06/2013 - 23:38:49.) -- C:\Windows\System32\sppcomapi.dll [438784]
[MD5.2E738F26946DB2D81623C5DC4512EFE6] - (.Microsoft Corporation - Pilote de fonction connexe pour WinSock.) (.16/06/2013 - 03:19:44.) -- C:\Windows\system32\Drivers\AFD.sys [454144]
[MD5.471129F85C6A5F6A015FA0B0B667BB35] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.16/06/2013 - 02:43:41.) -- C:\Windows\system32\Drivers\atapi.sys [23304]
[MD5.B8E122FA0399D3F4ABDA11C502DED530] - (.Microsoft Corporation - CD-ROM File System Driver.) (.16/06/2013 - 00:28:41.) -- C:\Windows\system32\Drivers\Cdfs.sys [73728]
[MD5.57F897474528E1545927B758AB477CA0] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.15/06/2013 - 22:27:19.) -- C:\Windows\system32\Drivers\Cdrom.sys [124928]
[MD5.D7343BB50B926B5E3D244E97002C8CC5] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.16/06/2013 - 00:26:43.) -- C:\Windows\system32\Drivers\DfsC.sys [100864]
[MD5.0C840206C7717B668C1E87DAE8089255] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.16/06/2013 - 00:27:05.) -- C:\Windows\system32\Drivers\HDAudBus.sys [70144]
[MD5.CE945A0B0E44D6ECDED1D9D5847B11D6] - (.Microsoft Corporation - Pilote de port i8042.) (.16/06/2013 - 00:27:44.) -- C:\Windows\system32\Drivers\i8042prt.sys [82944]
[MD5.7DC6AF75FAC033A3426D1D7D7E3BBB0E] - (.Microsoft Corporation - IP Network Address Translator.) (.16/06/2013 - 00:24:43.) -- C:\Windows\system32\Drivers\IpNat.sys [126464]
[MD5.909FC8A42CFA5F9A9781148C08D797FC] - (.Microsoft Corporation - Minirdr SMB Windows NT.) (.16/06/2013 - 00:25:17.) -- C:\Windows\system32\Drivers\MRxSmb.sys [331776]
[MD5.12EBA25B38A1A0F8B4933026496B2C1E] - (.Microsoft Corporation - MBT Transport driver.) (.16/06/2013 - 00:25:35.) -- C:\Windows\system32\Drivers\netBT.sys [218112]
[MD5.C573C02D83097766EF52E3177A17CABF] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.16/06/2013 - 03:19:43.) -- C:\Windows\system32\Drivers\ntfs.sys [1672456]
[MD5.3DF319156740EAFB3344E6F74D094CE9] - (.Microsoft Corporation - Pilote de port parallèle.) (.16/06/2013 - 00:28:36.) -- C:\Windows\system32\Drivers\Parport.sys [82432]
[MD5.7D4559EAC6F71C2B378D11212ACDC923] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.16/06/2013 - 00:24:53.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [81920]
[MD5.99294446C36E4636F96EF5D3A94A67D7] - (.Microsoft Corporation - Redirecteur de périphérique de Microsoft RDP.) (.16/06/2013 - 10:25:52.) -- C:\Windows\system32\Drivers\rdpdr.sys [143360]
[MD5.8D054D65C42F2C3C0199FA0318B06C8D] - (.Microsoft Corporation - TDI Translation Driver.) (.16/06/2013 - 03:19:44.) -- C:\Windows\system32\Drivers\tdx.sys [86016]
[MD5.0013DF4B81C450AB1AD40CC7FBC8F163] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.16/06/2013 - 02:35:26.) -- C:\Windows\system32\Drivers\volsnap.sys [264968]
~ Generic Processes: Scanned in 00mn 00s
---\\ Etat des fichiers cachés (Caché/Total)
~ Mes images (My Pictures) : 2/480
~ Mes musiques (My Musics) : 2/269
~ Mes Videos (My Videos) : 2/10
~ Mes Favoris (My Favorites) : 1/5
~ Mes Documents (My Documents) : 2/537
~ Mon Bureau (My Desktop) : 2/1817
~ Menu demarrer (Programs) : 1/38
~ Hidden Files: Scanned in 00mn 02s
---\\ Processus lancés
[MD5.17D4E929FEF1FD2B3FD0F4D3DA809EA6] - (.Microsoft Corporation - Processus hôte pour Tâches Windows.) -- C:\WINDOWS\system32\taskhostex.exe [66000] [PID.1608]
[MD5.06EBAA1B77724C1FC858AD49F2D5B88D] - (.Glarysoft Ltd - Glary Utilities 4.) -- C:\Program Files\Glary Utilities 4\Integrator.exe [757536] [PID.360]
[MD5.C1DB9BDF885C2F1ADC15264FBEA2788F] - (.Pas de propriétaire - HOSTS Anti-PUPs/Adwares.) -- C:\Program Files\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware_main.exe [302961] [PID.2068]
[MD5.1C5A81304F4B3A24914E10E339E3D51A] - (.BitTorrent Inc. - µTorrent.) -- C:\Users\Chateaudun\AppData\Roaming\uTorrent\uTorrent.exe [900440] [PID.2084] =>P2P.BitTorrent
[MD5.A9C80B3425FF31210A005573480CE123] - (.Microsoft Corporation - Microsoft SkyDrive.) -- C:\Windows\System32\skydrive.exe [515072] [PID.3528]
[MD5.A80D2D9D8752B54FF96C4E953F886EEC] - (.Microsoft Corporation - Paramètres du PC.) -- C:\WINDOWS\ImmersiveControlPanel\SystemSettings.exe [85672] [PID.3668]
[MD5.650BC2E301E20C957C08798B1240E95F] - (.Microsoft Corporation - Host Process for Setting Synchronization.) -- C:\Windows\System32\SettingSyncHost.exe [437760] [PID.2808]
[MD5.34DA68CCDC56BF9409C72C43BA6B744F] - (.The Eraser Project - Eraser.) -- C:\Program Files\Eraser\Eraser.exe [980920] [PID.2516]
[MD5.CF48ADB5E601310A577F0D1BADD28ACB] - (.Microsoft Corporation - COM Surrogate.) -- C:\WINDOWS\system32\DllHost.exe [17672] [PID.2484]
[MD5.AADD0892A428B133ABEF5EBCCE5E1799] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [8281600] [PID.3584]
~ Processes Running: Scanned in 00mn 01s
---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
C:\Users\Chateaudun\AppData\Local\Google\Chrome\User Data\Default\Preferences
G2 - GCE: Preference [user Data\Default] [dgiecfacokilefjaaodhjlpdgdhdomgj] Adventure Golf v.1.0 (Activé)
G2 - GCE: Preference [user Data\Default] [edlgljkkoneggjmhhlbnkeohlaplokpj] Tennis de table HD v.1.0.0 (Désactivé)
G2 - GCE: Preference [user Data\Default] [enaaiocgfnhfddlooahdapieledmlhnc] Débloquer v.1.0.0 (Activé)
G2 - GCE: Preference [user Data\Default] [fmedapekkakaehidplfhmblngkelolaj] Voodoo Friends v.1.0 (Désactivé)
G2 - GCE: Preference [user Data\Default] [gabjgmfeekebnbifcagmpmobohmjheoe] Meilleurs Jeux Super Mario v.1.0.25.0 (Activé)
G2 - GCE: Preference [user Data\Default] [hfpeacgpdnhofhebmincihdelcemhagd] Creatures & Castles (Créatures & Ch\u00E2teaux) v.2.0 (Désactivé)
G2 - GCE: Preference [user Data\Default] [iogblfbfoldfgammcabomglfajocfpea] Fire Boy And Water Girl v.1.0.0 (Désactivé)
G2 - GCE: Preference [user Data\Default] [jomlahcelngebaebobkjhogcenmkafmn] Jeu de tennis 3D v.1.0.0 (Activé)
G2 - GCE: Preference [user Data\Default] [kpbhbohcdnlcediiopngchhnnofnhaec] Super Angelo v.1.0.25.0 (Activé)
G2 - GCE: Preference [user Data\Default] [lfgcmpnnailedfapmafbigfifabfamcl] Rider Fou v.1.0.4 (Activé)
G2 - GCE: Preference [user Data\Default] [ncgcikiganileglfgcpcplalmkmalhne] The Island - Castaway v.1.0.0.5 (Désactivé)
G2 - GCE: Preference [user Data\Default] [pfglnpdpgmecffbejlfgpnebopinlclj] SiteBlock v.0.2.3 (Désactivé)
~ Google Browser: 34 Legitimates Filtered in 00mn 12s
---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
C:\Users\Chateaudun\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\prefs.js
C:\Users\Chateaudun\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\user.js
~ Firefox Browser: 9 Legitimates Filtered in 00mn 00s
---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;<local>
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s
---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn 00s
---\\ Hosts file redirection (O1)
~ Le fichier hosts est sain (The hosts file is clean).
~ Hosts File: Scanned in 00mn 00s
~ Nombre de lignes (Lines number): 1837
---\\ Autres liens utilisateurs (O4)
O4 - GS\Desktop [Public]: Eraser.lnk . (.The Eraser Project - Eraser.) -- C:\Program Files\Eraser\Eraser.exe
O4 - GS\Desktop [Public]: MappyPlus.lnk . (...) -- C:\WINDOWS\Installer\{478F482D-C30B-4876-A080-BE3916268682}\app_icon.ico
O4 - GS\Desktop [Public]: PowerISO.lnk . (.PowerISO Computing, Inc. - PowerISO.) -- C:\Program Files\PowerISO\PowerISO.exe
O4 - GS\Desktop [Public]: WahOO.lnk . (...) -- C:\Users\Chateaudun\AppData\Local\WahOO\Wahoo.exe
O4 - GS\Program [Public]: Desktop.lnk - Clé orpheline
O4 - GS\Program [Public]: Eraser.lnk . (.The Eraser Project - Eraser.) -- C:\Program Files\Eraser\Eraser.exe
O4 - GS\QuickLaunch [Chateaudun]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O4 - GS\QuickLaunch [Chateaudun]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) -- C:\Users\Chateaudun\AppDa