~ ZHPDiag v2015.8.20.122 Par Nicolas Coolman (2015/08/20) ~ Démarré par sedik (Administrator) (2015/08/23 03:22:04) ~ Site: http://www.nicolascoolman.fr ~ Facebook: https://www.facebook.com/nicolascoolman1 ~ Etat de la version: Version OK ~ Mode: Scanner ~ Rapport: C:\Users\sedik\Desktop\ZHPDiag.txt ~ Rapport: C:\Users\sedik\AppData\Roaming\ZHP\ZHPDiag.txt ~ UAC: Deactivate ~ Démarrage du système: Normal (Normal boot) Windows Se7en Titan, 32-bit (Build 7600) ---\\ Navigateurs Internet (3) - 0s GCIE: Google Chrome v44.0.2403.157 MFIE: Mozilla Firefox 39.0 (x86 fr) v39.0 MSIE: Internet Explorer v8.0.7600.16385 ---\\ Informations sur les produits Windows (4) - 12s ~ Windows Server License Manager Script : OK ~ Licence Script File Génération : OK Windows Automatic Updates : OK (Auto) Windows Activation Technologies : OK ---\\ Logiciels de protection (3) - 0s Kaspersky Internet Security v15.0.2.361 Malwarebytes Anti-Malware version 2.1.8.1057 Windows Defender W7 (Activate) ---\\ Logiciels d'optimisation (1) - 0s CCleaner v5.06 ---\\ Surveillance de Logiciels (2) - 0s Adobe Flash Player 18 NPAPI Adobe Acrobat Reader DC - Français ---\\ Informations sur le système (6) - 0s ~ Operating System: x86 Family 6 Model 23 Stepping 10, GenuineIntel ~ Operating System: 32-bit ~ Boot mode: Normal (Normal boot) Total RAM: 2087.16 MB (18% free) ~ System Restore: Activé (Enable) ~ System drive C: has 60 GB free of 80 GB ---\\ Mode de connexion au système (3) - 0s ~ Computer Name: SEDIK-PC ~ User Name: sedik ~ Logged in as Administrator ---\\ Enumération des unités disques (3) - 6s ~ Drive C: has 60 GB free of 80 GB (System) ~ Drive D: has 0 GB free of 80 GB ~ Drive E: has 12 GB free of 78 GB ---\\ Etat du Centre de Sécurité Windows (12) - 0s [HKLM\SOFTWARE\Microsoft\Security Center] UacDisableNotify: Modified [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoResolveSearch: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK [HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] Load: OK [HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK ---\\ Recherche particulière de fichiers génériques (24) - 0s [MD5.9BA1F2C5A3F98D85921456295A3C4A20] - (.Microsoft Corporation - Explorateur Windows.) () -- C:\Windows\Explorer.exe [2614272] [MD5.51138BEEA3E2C21EC44D0932C71762A8] - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) () -- C:\Windows\System32\rundll32.exe [44544] [MD5.B5C5DCAD3899512020D135600129D665] - (.Microsoft Corporation - Application de démarrage de Windows.) () -- C:\Windows\System32\Wininit.exe [96256] [MD5.A7360A3B20B38F1D6A09402FB6E9E2C3] - (.Microsoft Corporation - Extensions Internet pour Win32.) () -- C:\Windows\System32\wininet.dll [978944] [MD5.37CDB7E72EB66BA85A87CBE37E7F03FD] - (.Microsoft Corporation - Application d’ouverture de session Windows.) () -- C:\Windows\System32\Winlogon.exe [285696] [MD5.58C94EAE54BF0C5E2B80B2E5E7744D4C] - (.Microsoft Corporation - Bibliothèque de licences.) () -- C:\Windows\System32\sppcomapi.dll [193024] [MD5.D8714A5FB3141F8226D16861F20C5AC4] - (.Microsoft Corporation - DLL client de l’API uilisateur de Windows m.) () -- C:\Windows\System32\fr-FR\user32.dll.mui [19968] [MD5.DDC040FDB01EF1712A6B13E52AFB104C] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) () -- C:\Windows\System32\drivers\AFD.sys [338944] [MD5.338C86357871C167A96AB976519BF59E] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) () -- C:\Windows\System32\drivers\atapi.sys [21584] [MD5.77EA11B065E0A8AB902D78145CA51E10] - (.Microsoft Corporation - CD-ROM File System Driver.) () -- C:\Windows\System32\drivers\Cdfs.sys [70656] [MD5.BA6E70AA0E6091BC39DE29477D866A77] - (.Microsoft Corporation - SCSI CD-ROM Driver.) () -- C:\Windows\System32\drivers\Cdrom.sys [108544] [MD5.8E09E52EE2E3CEB199EF3DD99CF9E3FB] - (.Microsoft Corporation - DFS Namespace Client Driver.) () -- C:\Windows\System32\drivers\DfsC.sys [78336] [MD5.717A2207FD6F13AD3E664C7D5A43C7BF] - (.Microsoft Corporation - High Definition Audio Bus Driver.) () -- C:\Windows\System32\drivers\HDAudBus.sys [108544] [MD5.F151F0BDC47F4A28B1B20A0818EA36D6] - (.Microsoft Corporation - Pilote de port i8042.) () -- C:\Windows\System32\drivers\i8042prt.sys [80896] [MD5.A5FA468D67ABCDAA36264E463A7BB0CD] - (.Microsoft Corporation - IP Network Address Translator.) () -- C:\Windows\System32\drivers\IpNat.sys [101888] [MD5.F1B6AA08497EA86CA6EF6F7A08B0BFB8] - (.Microsoft Corporation - Windows NT SMB Minirdr.) () -- C:\Windows\System32\drivers\MRxSmb.sys [123392] [MD5.DD52A733BF4CA5AF84562A5E2F963B91] - (.Microsoft Corporation - MBT Transport driver.) () -- C:\Windows\System32\drivers\netBT.sys [187904] [MD5.3795DCD21F740EE799FB7223234215AF] - (.Microsoft Corporation - Pilote du système de fichiers NT.) () -- C:\Windows\System32\drivers\ntfs.sys [1210432] [MD5.2EA877ED5DD9713C5AC74E8EA7348D14] - (.Microsoft Corporation - Pilote de port parallèle.) () -- C:\Windows\System32\drivers\Parport.sys [79360] [MD5.D9F91EAFEC2815365CBE6D167E4E332A] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) () -- C:\Windows\System32\drivers\Rasl2tp.sys [78848] [MD5.C5FF95883FFEF704D50C40D21CFB3AB5] - (.Microsoft Corporation - Microsoft RDP Device redirector.) () -- C:\Windows\System32\drivers\rdpdr.sys [133120] [MD5.3E21C083B8A01CB70BA1F09303010FCE] - (.Microsoft Corporation - SMB Transport driver.) () -- C:\Windows\System32\drivers\smb.sys [71168] [MD5.CB39E896A2A83702D1737BFD402B3542] - (.Microsoft Corporation - TDI Translation Driver.) () -- C:\Windows\System32\drivers\tdx.sys [74240] [MD5.58DF9D2481A56EDDE167E51B334D44FD] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) () -- C:\Windows\System32\drivers\volsnap.sys [245328] ---\\ Processus lancés (15) - 2s [MD5.579FD11E112542A0D5D43838CCA08309] - (.DTools LIMITED - DTools.) -- C:\ProgramData\tWinManProt\ProtectWindowsManager.exe [708264] [PID.1372] [MD5.9C7C876ACB9B707ECD08BD434C46A4D3] - (.Kaspersky Lab ZAO - Kaspersky Anti-Virus.) -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.2\avp.exe [194000] [PID.1592] [MD5.70AF0E844C9A684236B96E582D2B2E61] - (.Kaspersky Lab ZAO - Kaspersky Anti-Virus.) -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.2\avpui.exe [192768] [PID.2100] [MD5.EE526B0428581B57FFC571FF57309E28] - (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner.exe [6369048] [PID.2416] [MD5.547E975DC8F8EDEBE832009EC04A37B9] - (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files\Internet Download Manager\IDMan.exe [3907152] [PID.2688] [MD5.E9C6EF9437ECB30911488F9313AD821A] - (.Tonec Inc. - Internet Download Manager agent for click m.) -- C:\Program Files\Internet Download Manager\IEMonitor.exe [269848] [PID.2732] [MD5.013697369EAFFA675D0671607F036020] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [82128] [PID.1188] [MD5.16C5FDC8A77E9A442B929FF92A59CF7F] - (.Sysinternals - www.sysinternals.com - Sysinternals Process Explorer.) -- C:\Users\sedik\Desktop\procexp.exe [3412856] [PID.2856] [MD5.AB9990DB80EA3DAC0EAE50C906EF7ECA] - (.BitTorrent Inc. - µTorrent.) -- C:\Users\sedik\AppData\Roaming\uTorrent\uTorrent.exe [1693024] [PID.3224] [MD5.ABFF2B3A80AA5348BE5E43EFD6B415D1] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files\Malwarebytes Anti-Malware\mbam.exe [6554424] [PID.3324] [MD5.1CE7982AA6A983F4C49A32C8D624237B] - (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe [377000] [PID.5692] [MD5.2B145A50EE1EF53989887A711A9F2981] - (.Mozilla Corporation - Plugin Container for Firefox.) -- C:\Program Files\Mozilla Firefox\plugin-container.exe [271016] [PID.4560] [MD5.2B145A50EE1EF53989887A711A9F2981] - (.Mozilla Corporation - Plugin Container for Firefox.) -- C:\Program Files\Mozilla Firefox\plugin-container.exe [271016] [PID.560] [MD5.2B145A50EE1EF53989887A711A9F2981] - (.Mozilla Corporation - Plugin Container for Firefox.) -- C:\Program Files\Mozilla Firefox\plugin-container.exe [271016] [PID.4948] [MD5.63E20985B61368A6172D93D0245DC9F8] - (.Nicolas Coolman - ZHPDiag.) -- C:\Users\sedik\Downloads\Programs\ZHPDiag3.exe [1895424] [PID.3984] ---\\ Google Chrome, Démarrage,Recherche,Extensions (16) - 1s G0 - GCSP: Secure Preferences [User Data\Default][HomePage] http://www.oursurfing.com/ =>PUP.Optional.OurSurfing G2 - GCE: Preference [User Data\Default] [aapocclcgogkmnckokdopfmhonfmgoek] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [aohghmighlieiainnegkcijnfilokake] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [apdfllckaahabafndbhieahigkjlhalf] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [bhmmomiinigofkjcapegjjndpbikblnp] WOT: Web of Trust Website Reputation Ratings G2 - GCE: Preference [User Data\Default] [blpcfgokakmgnkcojhhkbfbldkacnbeo] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [cfhdojbkjhnklbpkdaibdccddilifddb] __MSG_name__ G2 - GCE: Preference [User Data\Default] [cmedhionkhpnakcndndgjdbohmhepckk] __MSG_extension_name__ G2 - GCE: Preference [User Data\Default] [coobgpohoikkiipiblmjeljniedjpjpf] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] __MSG_ExtensionName__ G2 - GCE: Preference [User Data\Default] [egljojpdbafibmmbdcemkdcdahloclop] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [felcaaldnbdncclmgdcncolpebgiejap] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [lccekmodgklaepjeofjdjpbminllajkg] Chrome Hotword Shared Module G2 - GCE: Preference [User Data\Default] [ngpampappnmepgilojfohadhhmbhlaek] IDM Integration Module G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [pjkljhegncpnkpknbcohdijeoejaedia] Google Chrome manifest =>.Google Inc. ---\\ Firefox, Plugins,Demarrage,Recherche,Extensions (25) - 2s P2 - EXT: (.Foxit Software Company - Foxit Reader Plug-In For Firefox and Netsca.) -- C:\Program Files\Mozilla Firefox\Plugins\npFoxitReaderPlugin.dll P2 - EXT: (.mozilla.org - Default Plug-in.) -- C:\Program Files\Mozilla Firefox\Plugins\npnul32.dll P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\Plugins\nppdf32.FRA P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\Plugins\QuickTimePlugin.class P2 - EXT FILE: (...) -- C:\Users\sedik\AppData\Roaming\Mozilla\Firefox\Profiles\hf6mu6xv.default\extensions\jid1-q4sG8pYhq8KGHs@jetpack.xpi P2 - EXT FILE: (...) -- C:\Users\sedik\AppData\Roaming\Mozilla\Firefox\Profiles\hf6mu6xv.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi P2 - EXT FILE: (...) -- C:\Users\sedik\AppData\Roaming\Mozilla\Firefox\Profiles\hf6mu6xv.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi P2 - EXT FILE: (...) -- C:\Users\sedik\AppData\Roaming\Mozilla\Firefox\Profiles\hf6mu6xv.default\searchplugins\oursurfing.xml =>PUP.Optional.OurSurfing P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\amazon-france.xml P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\bing.xml P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\cnrtl-tlfi-fr.xml P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\ddg.xml P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\eBay-france.xml P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\google.xml P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\wikipedia-fr.xml P2 - EXT: (...) -- C:\Program Files\Mozilla Firefox\browser\searchplugins\yahoo-france.xml P2 - EXT: (.Mozilla - Default.) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} P2 - EXT: (.roc - Default SearchProtected .) -- C:\Users\sedik\AppData\Roaming\Mozilla\Firefox\Profiles\hf6mu6xv.default\extensions\defsearchp@gmail.com P2 - EXT: (.lightningnewtab.com - deskCut.) -- C:\Users\sedik\AppData\Roaming\Mozilla\Firefox\Profiles\hf6mu6xv.default\extensions\deskCutv2@gmail.com =>PUP.Optional.LightningNewTab P2 - EXT: (.WOT Services Oy - WOT.) -- C:\Users\sedik\AppData\Roaming\Mozilla\Firefox\Profiles\hf6mu6xv.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} P2 - EXT: (.Wips.com -