~ ZHPDiag v2015.7.27.104 Par Nicolas Coolman (2015/07/27) ~ Démarré par JEAN Matthieu (Administrator) (2015/07/29 20:11:07) ~ Site: http://www.nicolascoolman.fr ~ Facebook: https://www.facebook.com/nicolascoolman1 ~ Etat de la version: Version OK ~ Mode: Scanner ~ Rapport: C:\Users\JEAN Matthieu\Desktop\ZHPDiag.txt ~ Rapport: C:\Users\JEAN Matthieu\AppData\Roaming\ZHP\ZHPDiag.txt ~ UAC: Activate ~ Démarrage du système: Normal (Normal boot) ~ Windows 7, 64-bit Service Pack 1 (Build 7601) ---\\ Navigateurs Internet (2) - 0s GCIE: Google Chrome v44.0.2403.107 MSIE: Internet Explorer v11.0.9600.17914 ---\\ Informations sur les produits Windows (4) - 1s ~ Windows Server License Manager Script : OK System - VBScript Engine not found Windows Automatic Updates : OK (Auto) Windows Activation Technologies : OK ---\\ Logiciels de protection (1) - 2s Malwarebytes Anti-Malware version 2.1.6.1022 ---\\ Logiciels de protection et autres (Superflus) (1) - 2s McAfee Security Scan Plus v3.8.150.1 ---\\ Surveillance de Logiciels (2) - 2s Adobe Flash Player 18 NPAPI Adobe Reader XI ---\\ Informations sur le système (8) - 0s ~ Operating System: Intel64 Family 6 Model 23 Stepping 10, GenuineIntel ~ Operating System: 64-bit ~ Boot mode: Normal (Normal boot) Total RAM: 6290.616 MB (70% free) ~ System Restore: Activé (Enable) ~ System drive C: has 742 GB free of 939 GB Total RAM: 6290.616 MB (69% free) Total RAM: 6290.616 MB (63% free) ---\\ Mode de connexion au système (3) - 0s ~ Computer Name: JEANMATTHIEU-PC ~ User Name: JEAN Matthieu ~ Logged in as Administrator ---\\ Enumération des unités disques (4) - 0s ~ Drive C: has 742 GB free of 939 GB (System) ~ Drive D: has 2 GB free of 14 GB ~ Drive F: has 0 GB free of 0 GB ~ Drive G: has 767 GB free of 953 GB ---\\ Etat du Centre de Sécurité Windows (12) - 1s [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] DisableTaskMgr: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK [HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK ---\\ Recherche particulière de fichiers génériques (23) - 0s [MD5.332FEAB1435662FC6C672E25BEB37BE3] - (.Microsoft Corporation - Explorateur Windows.) () -- C:\Windows\Explorer.exe [2871808] [MD5.DD81D91FF3B0763C392422865C9AC12E] - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) () -- C:\Windows\System32\rundll32.exe [45568] [MD5.94355C28C1970635A31B3FE52EB7CEBA] - (.Microsoft Corporation - Application de démarrage de Windows.) () -- C:\Windows\System32\Wininit.exe [129024] [MD5.E066FDC3A2074D926903B8C31EF3B347] - (.Microsoft Corporation - Extensions Internet pour Win32.) () -- C:\Windows\System32\wininet.dll [2427392] [MD5.8CEBD9D0A0A879CDE9F36F4383B7CAEA] - (.Microsoft Corporation - Application d’ouverture de session Windows.) () -- C:\Windows\System32\Winlogon.exe [455168] [MD5.067FA52BFB59A56110A12312EF9AF243] - (.Microsoft Corporation - Bibliothèque de licences.) () -- C:\Windows\System32\sppcomapi.dll [232448] [MD5.0D57D091E06BB1E58E72E5D08479FDDF] - (.Microsoft Corporation - DLL client de l’API uilisateur de Windows m.) () -- C:\Windows\System32\fr-FR\user32.dll.mui [20480] [MD5.FA886682CFC5D36718D3E436AACF10B9] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) () -- C:\Windows\System32\drivers\AFD.sys [497152] [MD5.02062C0B390B7729EDC9E69C680A6F3C] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) () -- C:\Windows\System32\drivers\atapi.sys [24128] [MD5.B8BD2BB284668C84865658C77574381A] - (.Microsoft Corporation - CD-ROM File System Driver.) () -- C:\Windows\System32\drivers\Cdfs.sys [92160] [MD5.F036CE71586E93D94DAB220D7BDF4416] - (.Microsoft Corporation - SCSI CD-ROM Driver.) () -- C:\Windows\System32\drivers\Cdrom.sys [147456] [MD5.9BB2EF44EAA163B29C4A4587887A0FE4] - (.Microsoft Corporation - DFS Namespace Client Driver.) () -- C:\Windows\System32\drivers\DfsC.sys [102400] [MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - (.Microsoft Corporation - High Definition Audio Bus Driver.) () -- C:\Windows\System32\drivers\HDAudBus.sys [122368] [MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - (.Microsoft Corporation - Pilote de port i8042.) () -- C:\Windows\System32\drivers\i8042prt.sys [105472] [MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - (.Microsoft Corporation - IP Network Address Translator.) () -- C:\Windows\System32\drivers\IpNat.sys [116224] [MD5.1877EB1495CFBDAB27D6A32F6DDF3818] - (.Microsoft Corporation - Windows NT SMB Minirdr.) () -- C:\Windows\System32\drivers\MRxSmb.sys [159232] [MD5.09594D1089C523423B32A4229263F068] - (.Microsoft Corporation - MBT Transport driver.) () -- C:\Windows\System32\drivers\netBT.sys [261632] [MD5.B98F8C6E31CD07B2E6F71F7F648E38C0] - (.Microsoft Corporation - Pilote du système de fichiers NT.) () -- C:\Windows\System32\drivers\ntfs.sys [1656680] [MD5.0086431C29C35BE1DBC43F52CC273887] - (.Microsoft Corporation - Pilote de port parallèle.) () -- C:\Windows\System32\drivers\Parport.sys [97280] [MD5.471815800AE33E6F1C32FB1B97C490CA] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) () -- C:\Windows\System32\drivers\Rasl2tp.sys [129536] [MD5.548260A7B8654E024DC30BF8A7C5BAA4] - (.Microsoft Corporation - SMB Transport driver.) () -- C:\Windows\System32\drivers\smb.sys [93184] [MD5.DDAD5A7AB24D8B65F8D724F5C20FD806] - (.Microsoft Corporation - TDI Translation Driver.) () -- C:\Windows\System32\drivers\tdx.sys [119296] [MD5.0D08D2F3B3FF84E433346669B5E0F639] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) () -- C:\Windows\System32\drivers\volsnap.sys [295808] ---\\ Processus lancés (10) - 0s [MD5.ACEC3397D7FE8DF37DAD3B175CA2E148] - (.Bitdefender - Bitdefender Security Service.) -- C:\Program Files\Bitdefender\Bitdefender\vsserv.exe [1538672] [PID.880] [MD5.B7AB7637262BC0FA3431DA5319C5A246] - (.FileOpen Systems Inc. - FileOpen Manager Service.) -- C:\Program Files\FileOpen\Services\FileOpenManager64.exe [341312] [PID.2268] [MD5.CD421DDB5C6E5458CE52EDC36DE7DC5B] - (...) -- C:\Windows\System32\PnkBstrA.exe [76152] [PID.2660] [MD5.3B43F4F67F3C539C3BBF40A552A12B5E] - (.TomTom - Windows Service for TomTom HOME.) -- C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe [93040] [PID.2720] [MD5.B239FDC885A77E4D5FB93AD1BA2A80EC] - (.Bitdefender - Bitdefender Update Service.) -- C:\Program Files\Bitdefender\Bitdefender\updatesrv.exe [67320] [PID.1128] [MD5.12213B47F83486ECA2F7529A673B1130] - (.Oodrive - WS.WindowsService.) -- C:\Program Files (x86)\Oodrive\WebSynchro\WS.WindowsService.exe [8192] [PID.1132] [MD5.D5F1ADEA6513A230E27A3ADAD2A3B160] - (.Bitdefender - Bitdefender Agent.) -- C:\Program Files\Bitdefender\Bitdefender\bdagent.exe [1757520] [PID.3676] [MD5.8FA2558967394D9133700EF03EED9574] - (.FileOpen Systems Inc. - FileOpen Broker.) -- C:\Program Files\FileOpen\Services\FileOpenBroker64.exe [1317184] [PID.3104] [MD5.0DFC21F95480B688E83C715A6C668095] - (.Bitdefender - Bitdefender Password Manager Agent.) -- C:\Program Files\BitDefender\Bitdefender\pmbxag.exe [568400] [PID.2376] [MD5.DB1919F34AB9CD5F43B0ED463D7E8D28] - (.Bitdefender - Bitdefender Application Password Manager Ag.) -- C:\Program Files\BitDefender\Bitdefender\antispam32\bdapppassmgr.exe [615256] [PID.236] ---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2) (6) - 0s G0 - GCSP: Secure Preferences [User Data\Default][HomePage] http://www.google.fr/ G0 - GCSP: Secure Preferences [User Data\Default][HomePage] http://www.youtube.com/ G2 - GCE: Preference [User Data\Default] [ccahoghmggldkcdjiebjkidpfongdfbl] Bitdefender Wallet G2 - GCE: Preference [User Data\Default] [cfhdojbkjhnklbpkdaibdccddilifddb] __MSG_name__ G2 - GCE: Preference [User Data\Default] [lccekmodgklaepjeofjdjpbminllajkg] Chrome Hotword Shared Module G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Chrome manifest =>.Google Inc. ---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3) (22) - 2s M0 - MFSP: prefs.js [JEAN Matthieu - wy4h48dz.default] http://r.orange.fr/r/Ohome_portail?ref=O_OI_defaultPage P2 - EXT: (...) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\nppdf32.FRA P2 - EXT FILE: (...) -- C:\Users\JEAN Matthieu\AppData\Roaming\Mozilla\Firefox\Profiles\wy4h48dz.default\searchplugins\orange.xml P2 - EXT: (.EA Digital Illusions CE AB - Battlefield Heroes Updater.) -- C:\Users\JEAN Matthieu\AppData\Roaming\Mozilla\Firefox\Profiles\wy4h48dz.default\extensions\battlefieldheroespatcher@ea.com P2 - EXT: (.EA Digital Illusions CE AB - Battlefield Play4Free.) -- C:\Users\JEAN Matthieu\AppData\Roaming\Mozilla\Firefox\Profiles\wy4h48dz.default\extensions\battlefieldplay4free@ea.com P2 - EXT: (.FranceTelecom-Orange Copyright 2008-2009 - Menu Contextuel Orange.) -- C:\Users\JEAN Matthieu\AppData\Roaming\Mozilla\Firefox\Profiles\wy4h48dz.default\extensions\menu_contextuel_orange@orange.fr P2 - EXT: (.Orange - Plugin Orange Installeur.) -- C:\Users\JEAN Matthieu\AppData\Roaming\Mozilla\Firefox\Profiles\wy4h48dz.default\extensions\{4D9AE42B-F4C0-40e6-AEDB-4EC6E42B77AF} P2 - FPN: [HKCU] [ubisoft.com/uplaypc] - (...) -- C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_209.dll P2 - FPN: [HKLM] [@Apple.com/iTunes,version=1.0] - (.Apple Inc..) -- C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll P2 - FPN: [HKLM] [@esn/esnlaunch,version=1.122.0] - (.ESN Social Software AB.) -- C:\Program Files (x86)\Battlelog Web Plugins\1.122.0\npesnlaunch.dll P2 - FPN: [HKLM] [@esn/esnlaunch,version=1.138.0] - (.ESN Social Software AB.) -- C:\Program Files (x86)\Battlelog Web Plugins\1.138.0\npesnlaunch.dll P2 - FPN: [HKLM] [@esn/esnlaunch,version=2.1.3] - (.ESN Social Software AB.) -- C:\Program Files (x86)\Battlelog Web Plugins\2.1.3\npesnlaunch.dll P2 - FPN: [HKLM] [@esn/esnlaunch,version=2.1.7] - (.ESN Social Software AB.) -- C:\Program Files (x86)\Battlelog Web Plugins\2.1.7\npesnlaunch.dll P2 - FPN: [HKLM] [@esn/npbattlelog,version=2.4.0] - (.EA Digital Illusions CE AB.) -- C:\Program Files (x86)\Battlelog Web Plugins\2.4.0\npbattlelog.dll P2 - FPN: [HKLM] [@java.com/DTPlugin,version=10.65.2] - (.Oracle Corporation.) -- C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll P2 - FPN: [HKLM] [@java.com/JavaPlugin,version=10.65.2] - (.Oracle Corporation.) -- C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll P2 - FPN: [HKLM] [@nokia.com/EnablerPlugin] - (.Nokia.) -- C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll P2 - FPN: [HKLM] [@pandonetworks.com/PandoWebPlugin] - (.Pando Networks Inc..) -- C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll P2 - FPN: [HKLM] [@videolan.org/vlc,version=2.1.3] - (.VideoLAN.) -- C:\Program Files (x86)\adslTV\VLC\npvlc.dll P2 - FPN: [HKLM] [@videolan.org/vlc,version=2.1.5] - (.VideoLAN.) -- C:\Program Files (x86)\adslTV\VLC\npvlc.dll P2 - FPN: [HKLM] [@WildTangent.com/GamesAppPresenceDetector,Version=1.0] - (.WildTangent.) -- C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll ---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4) (14) - 0s R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = preserve R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com R3 - URLSearchHook: (no name) - {c41be492-d9e6-4262-a0bd-e8cf6dc4208d} Orphean R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphean =>.Microsoft Internet Explorer ---\\ Internet Explorer, Proxy Management (R5) (4) - 0s R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll ---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs (3) - 0s F2 - REG:system.ini: UserInit=userinit.exe (.Microsoft Corporation.) F2 - REG:system.ini: Shell=C:\Windows\explorer.exe (.Microsoft Corporation.) F2 - REG:system.ini: VMApplet=C:\Windows\SysWOW64\SystemPropertiesPerformance.exe (.Microsoft Corporation.) ---\\ Hosts file redirection (O1) (3) - 0s ~ Le fichier hôte est sain (The hosts file is clean) (21) ~ Le fichier hôte est sain (The hosts file is clean) (21) ~ Nombre lignes détournées ~ Le fichier hôte est sain (The hosts file is clean) (21) 21 (Hosts file redirected) ---\\ Browser Helper Object de navigateur (BHO) (O2) (6) - 1s O2 - BHO: Bitdefender Wallet [64Bits] - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} . (.Bitdefender - Bitdefender Password Manager Internet Explo.) -- C:\Program Files\Bitdefender\Bitdefender\pmbxie.dll O2 - BHO: Increase performance and video formats for your HTML5