~ ZHPDiag v2016.9.24.170 Par Nicolas Coolman (2016/09/24) ~ Démarré par Adrien (Administrator) (2016/12/09 22:08:20) ~ Web: https://www.nicolascoolman.com ~ Blog: https://www.anti-malware.top ~ Facebook: https://www.facebook.com/nicolascoolman1 ~ Etat de la version: ~ Mode: Scanner ~ Rapport: C:\Users\Adrien\Desktop\ZHPDiag.txt ~ Rapport: C:\Users\Adrien\AppData\Roaming\ZHP\ZHPDiag.txt ~ UAC: Activate ~ Démarrage du système: Normal (Normal boot) Windows 7 Ultimate, 32-bit Service Pack 1 (Build 7601) =>.Microsoft Corporation ---\\ Navigateurs Internet (3) - 8s ~ MFIE: Mozilla Firefox 50.0.2 (x86 fr) ~ OPIE: Opera 41.0.2353.69 ~ MSIE: Internet Explorer v11.0.9600.18524 ---\\ Informations sur les produits Windows (10) - 2s ~ Windows Server License Manager Script : OK ~ Licence Script File Génération : OK ~ Windows Operating System - Windows(R) 7, OEM_SLP channel System Locked Preinstallation (OEM_SLP) : OK Windows ID Activation : OK ~ Windows Partial Key : HYRR2 Windows License : OK ~ Windows Remaining Initializations Number : 4 Windows Automatic Updates : OK Windows Activation Technologies : KO ---\\ Logiciels de protection (1) - 114s Kaspersky Anti-Virus v16.0.1.445 ---\\ Logiciels d'optimisation (1) - 129s CCleaner v5.24 ---\\ Surveillance de Logiciels (2) - 129s Adobe Flash Player 23 PPAPI Adobe Acrobat Reader DC - Français ---\\ Informations sur le système (6) - 1s ~ Operating System: x86 Family 6 Model 23 Stepping 10, GenuineIntel ~ Operating System: 32-bit ~ Boot mode: Normal (Normal boot) Total RAM: 3075.004 MB (20% free) System Restore: Activé (Enable) System drive C: has 104 GB () free of 238 GB ---\\ Mode de connexion au système (3) - 0s ~ Computer Name: ADRIEN ~ User Name: Adrien ~ Logged in as Administrator ---\\ Enumération des unités disques (1) - 0s ~ Drive C: has 104 GB free of 238 GB (System) ---\\ Etat du Centre de Sécurité Windows (11) - 1s [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK [HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] Load: OK [HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK ---\\ Recherche particulière de fichiers génériques (25) - 61s [MD5.6DDCA324434FFA506CF7DC4E51DB7935] - 29/08/2016 - (.Microsoft Corporation - Explorateur Windows.) -- C:\Windows\Explorer.exe [2972672] =>.Microsoft Corporation [MD5.51138BEEA3E2C21EC44D0932C71762A8] - 14/07/2009 - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) -- C:\Windows\System32\rundll32.exe [44544] =>.Microsoft Corporation [MD5.B5C5DCAD3899512020D135600129D665] - 14/07/2009 - (.Microsoft Corporation - Application de démarrage de Windows.) -- C:\Windows\System32\Wininit.exe [96256] =>.Microsoft Corporation [MD5.19465502D25C5B7D54B792E3695C2A90] - 22/10/2016 - (.Microsoft Corporation - Extensions Internet pour Win32.) -- C:\Windows\System32\wininet.dll [2444800] =>.Microsoft Corporation [MD5.52449FD429D6053B78AE564DEF303870] - 17/07/2014 - (.Microsoft Corporation - Application d’ouverture de session Windows.) -- C:\Windows\System32\Winlogon.exe [304128] =>.Microsoft Corporation [MD5.E3AE23569749DE12D45BA3B489A036AE] - 20/11/2010 - (.Microsoft Corporation - Bibliothèque de licences.) -- C:\Windows\System32\sppcomapi.dll [193536] =>.Microsoft Corporation [MD5.B40420876B9288E0A1C8CCA8A84E5DC9] - 03/03/2011 - (.Microsoft Corporation - DNS DLL de l’API Client.) -- C:\Windows\System32\dnsapi.dll [270336] =>.Microsoft Corporation [MD5.129F80D7868E30DF3E3DE33A1D3132B4] - 20/11/2010 - (.Microsoft Corporation - DLL client de l’API uilisateur de Windows m.) -- C:\Windows\System32\fr-FR\user32.dll.mui [20480] =>.Microsoft Corporation [MD5.93B49FA857F7036A4EFF32371F6E7391] - 13/10/2015 - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) -- C:\Windows\System32\drivers\AFD.sys [338944] =>.Microsoft Corporation [MD5.338C86357871C167A96AB976519BF59E] - 14/07/2009 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\Windows\System32\drivers\atapi.sys [21584] =>.Microsoft Windows® [MD5.77EA11B065E0A8AB902D78145CA51E10] - 14/07/2009 - (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\Windows\System32\drivers\Cdfs.sys [70656] =>.Microsoft Corporation [MD5.BE167ED0FDB9C1FA1133953C18D5A6C9] - 20/11/2010 - (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\Windows\System32\drivers\Cdrom.sys [108544] =>.Microsoft Corporation [MD5.EA9DBD76CE9254C77BAAB4339DD4C4FB] - 08/09/2016 - (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\Windows\System32\drivers\DfsC.sys [81408] =>.Microsoft Corporation [MD5.9036377B8A6C15DC2EEC53E489D159B5] - 20/11/2010 - (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\Windows\System32\drivers\HDAudBus.sys [108544] =>.Microsoft Corporation [MD5.F151F0BDC47F4A28B1B20A0818EA36D6] - 14/07/2009 - (.Microsoft Corporation - Pilote de port i8042.) -- C:\Windows\System32\drivers\i8042prt.sys [80896] =>.Microsoft Corporation [MD5.A5FA468D67ABCDAA36264E463A7BB0CD] - 14/07/2009 - (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\drivers\IpNat.sys [101888] =>.Microsoft Corporation [MD5.E15146EA99447CDBD2C952CF9B792BEA] - 10/10/2016 - (.Microsoft Corporation - Windows NT SMB Minirdr.) -- C:\Windows\System32\drivers\MRxSmb.sys [124416] =>.Microsoft Corporation [MD5.A00996C9BFEF29A93B9F21DBE1DC502D] - 11/05/2016 - (.Microsoft Corporation - MBT Transport driver.) -- C:\Windows\System32\drivers\netBT.sys [188928] =>.Microsoft Corporation [MD5.978E7A2E4BF4E8E70D0776EF0D9E97FB] - 11/01/2016 - (.Microsoft Corporation - Pilote du système de fichiers NT.) -- C:\Windows\System32\drivers\ntfs.sys [1212352] =>.Microsoft Windows® [MD5.2EA877ED5DD9713C5AC74E8EA7348D14] - 14/07/2009 - (.Microsoft Corporation - Pilote de port parallèle.) -- C:\Windows\System32\drivers\Parport.sys [79360] =>.Microsoft Corporation [MD5.D9F91EAFEC2815365CBE6D167E4E332A] - 14/07/2009 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\Windows\System32\drivers\Rasl2tp.sys [78848] =>.Microsoft Corporation [MD5.B973FCFC50DC1434E1970A146F7E3885] - 20/11/2010 - (.Microsoft Corporation - Microsoft RDP Device redirector.) -- C:\Windows\System32\drivers\rdpdr.sys [133632] =>.Microsoft Corporation [MD5.3E21C083B8A01CB70BA1F09303010FCE] - 14/07/2009 - (.Microsoft Corporation - SMB Transport driver.) -- C:\Windows\System32\drivers\smb.sys [71168] =>.Microsoft Corporation [MD5.BB8817D0508DD5EA69C770C8DEF5AB67] - 13/10/2015 - (.Microsoft Corporation - TDI Translation Driver.) -- C:\Windows\System32\drivers\tdx.sys [74752] =>.Microsoft Corporation [MD5.F497F67932C6FA693D7DE2780631CFE7] - 20/11/2010 - (.Microsoft Corporation - Pilote de cliché instantané du volume.) -- C:\Windows\System32\drivers\volsnap.sys [245632] =>.Microsoft Windows® ---\\ Liste des services NT non Microsoft et non désactivés (10) - 19s O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe =>.Adobe Systems, Incorporated® O23 - Service: Kaspersky Anti-Virus Service 16.0.1 (AVP16.0.1) . (.AO Kaspersky Lab - Kaspersky Anti-Virus.) - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 16.0.1\avp.exe =>.Kaspersky Lab® O23 - Service: Service Bonjour (Bonjour Service) . (.Apple Inc. - Bonjour Service.) - C:\Program Files\Bonjour\mDNSResponder.exe =>.Apple Inc.® O23 - Service: Origin Web Helper Service (Origin Web Helper Service) . (.Electronic Arts - OriginWebHelperService.) - C:\Program Files\Origin\OriginWebHelperService.exe =>.Electronic Arts, Inc.® O23 - Service: Skype Updater (SkypeUpdate) . (.Skype Technologies - Skype Updater Service.) - C:\Program Files\Skype\Updater\Updater.exe =>.Skype Software Sarl® O23 - Service: Audio Service (STacSV) . (.IDT, Inc. - IDT PC Audio.) - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9691412ff1876250\stacsv.exe =>.IDT, Inc. O23 - Service: VMware Authorization Service (VMAuthdService) . (.VMware, Inc. - VMware Authorization Service.) - C:\Program Files\VMware\VMware Player\vmware-authd.exe =>.VMware, Inc.® O23 - Service: VMware DHCP Service (VMnetDHCP) . (.VMware, Inc. - VMware VMnet DHCP service.) - C:\Windows\System32\vmnetdhcp.exe =>.VMware, Inc.® O23 - Service: VMware USB Arbitration Service (VMUSBArbService) . (.VMware, Inc. - VMware USB Arbitration Service.) - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe =>.VMware, Inc.® O23 - Service: VMware NAT Service (VMware NAT Service) . (.VMware, Inc. - VMware NAT Service.) - C:\Windows\System32\vmnat.exe =>.VMware, Inc.® ---\\ Services non Microsoft (SR=Démarré,SS=Stoppé) (17) - 293s SR - Auto [21/10/2016] [ 82128] Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe =>.Adobe Systems, Incorporated® SS - Demand [08/11/2016] [ 270016] Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe =>.Adobe Systems Incorporated® SS - Disabl [02/03/2009] [ 81920] Andrea ST Filters Service (AESTFilters) . (.Andrea Electronics Corporation.) - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9691412ff1876250\AEstSrv.exe =>.Andrea Electronics Corporation SR - Auto [22/12/2015] [ 236928] Kaspersky Anti-Virus Service 16.0.1 (AVP16.0.1) . (.AO Kaspersky Lab.) - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 16.0.1\avp.exe =>.Kaspersky Lab® SR - Auto [12/08/2015] [ 390416] Service Bonjour (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe =>.Apple Inc.® SS - Demand [22/10/2004] [ 73728] InstallDriver Table Manager (IDriverT) . (.Macrovision Corporation.) - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe =>.Macrovision Corporation SS - Demand [01/06/2016] [ 548152] Service de l’iPod (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe =>.Apple Inc.® SS - Demand [02/12/2016] [ 172488] Mozilla Maintenance Service (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe =>.Mozilla Corporation® SS - Demand [09/12/2016] [ 2119688] Origin Client Service (Origin Client Service) . (.Electronic Arts.) - C:\Program Files\Origin\OriginClientService.exe =>.Electronic Arts, Inc.® SR - Auto [09/12/2016] [ 2180624] Origin Web Helper Service (Origin Web Helper Service) . (.Electronic Arts.) - C:\Program Files\Origin\OriginWebHelperService.exe =>.Electronic Arts, Inc.® SS - Auto [20/09/2016] [ 324224] Skype Updater (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files\Skype\Updater\Updater.exe =>.Skype Software Sarl® SR - Auto [23/03/2010] [ 229458] Audio Service (STacSV) . (.IDT, Inc..) - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9691412ff1876250\stacsv.exe =>.IDT, Inc. SR - Auto [24/06/2015] [ 87256] VMware Authorization Service (VMAuthdService) . (.VMware, Inc..) - C:\Program Files\VMware\VMware Player\vmware-authd.exe =>.VMware, Inc.® SR - Auto [24/06/2015] [ 359128] VMware DHCP Service (VMnetDHCP) . (.VMware, Inc..) - C:\Windows\System32\vmnetdhcp.exe =>.VMware, Inc.® SR - Auto [21/08/2014] [ 722624] VMware USB Arbitration Service (VMUSBArbService) . (.VMware, Inc..) - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe =>.VMware, Inc.® SR - Auto [24/06/2015] [ 437976] VMware NAT Service (VMware NAT Service) . (.VMware, Inc..) - C:\Windows\System32\vmnat.exe =>.VMware, Inc.® ---\\ Processus lancés (18) - 19s [MD5.FE7F776F2590C8331123BDA3A3A21DE6] - (.IDT, Inc. - IDT PC Audio.) -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9691412ff1876250\stacsv.exe [229458] [PID.1068] =>.IDT, Inc. [MD5.C92B0A0957ACAD3CEEF502A2CA10ACB8] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [82128] [PID.1812] =>.Adobe Systems, Incorporated® [MD5.09F0E4D1F66C40AB770AD1540758C59E] - (.AO Kaspersky Lab - Kaspersky Anti-Virus.) -- C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 16.0.1\avp.exe [236928] [PID.1836] =>.Kaspersky Lab® [MD5.5EA9C80F18CBC393EA7D9A2991DED4B5] - (.Apple Inc. - Bonjour Service.) -- C:\Program Files\Bonjour\mDNSResponder.exe [390416] [PID.1868] =>.Apple Inc.® [MD5.2B2BB1F8BFEBE6B847FDB32F89EA2A3E] - (.VMware, Inc. - VMware NAT Service.) -- C:\Windows\System32\vmnat.exe [437976] [PID.2076] =>.VMware, Inc.® [MD5.338CD01BD29805A93902B9237A39CAC5] - (.VMware, Inc. - VMware VMnet DHCP service.) -- C:\Windows\System32\vmnetdhcp.exe [359128] [PID.2148] =>.VMware, Inc.® [MD5.21C8747CF038796D59A5B88A4BAAC7B4] - (.VMware, Inc. - VMware USB Arbitration Service.) -- C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe [722624] [PID.2172] =>.VMware, Inc.® [MD5.BD00A8CFB76E6BB0E89DB191E3712528] - (.VMware, Inc. - VMware Authorization Service.) -- C:\Program Files\VMware\VMware Player\vmware-authd.exe [87256] [PID.2220] =>.VMware, Inc.® [MD5.287C64659B259AA170B91E9BA4F1878A] - (.AO Kaspersky Lab - Kaspersky Anti-Virus.) -- C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 16.0.1\avpui.exe [218648] [PID.3148] =>.Kaspersky Lab® [MD5.031E0AC7341FBF5699011D71D4157D60] - (.IDT, Inc. - IDT PC Audio.) -- C:\Program Files\IDT\WDM\sttray.exe [495708] [PID.3796] =>.IDT, Inc. [MD5.F88BDA587AFB96E5253D9E373981B670] - (.Almico Software (www.almico.com) - .) -- C:\Program Files\SpeedFan\speedfan.exe [4768360] [PID.128] =>.SOKNO S.R.L.® [MD5.D6F38FD2B90CD7DC139279BB73DD0C7B] - (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe [510920] [PID.2240] =>.Mozilla Corporation® [MD5.24A2F04AC23974DD91FB9FCB8EC6B1E8] - (.Mozilla Corporation - Plugin Container for Firefox.) -- C:\Program Files\Mozilla Firefox\plugin-container.exe [156616] [PID.5652] =>.Mozilla Corporation® [MD5.788363C87EBD90AC1EAD2DC5A9A40759] - (.Electronic Arts - OriginWebHelperService.) -- C:\Program Files\Origin\OriginWebHelperService.exe [2180624] [PID.5484] =>.Electronic Arts, Inc.® [MD5.94444693EA13A72F6820DFF844A1122E] - (.Synaptics Incorporated - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2299176] [PID.3364] =>.Synaptics Incorporated® [MD5.3E802CE450D0E7A234978E9A2EA4772A] - (.Synaptics Incorporated - Synaptics Pointing Device Helper.) -- C:\PROGRAM FILES\SYNAPTICS\SynTP\SYNTPHELPER.EXE [107816] [PID.5100] =>.Synaptics Incorporated® [MD5.382221669A48E195BDE6D2750C385446] - (.Nicolas Coolman - ZHPDiag.) -- C:\Users\Adrien\Downloads\zhpdiag_2016.11.28.232.exe [2503680] [PID.1140] =>.Nicolas Coolman [MD5.9E5C0CFB6EB36699F9CB1B383D0AEACB] - (.Nicolas Coolman - ZHPDiag.) -- C:\Users\Adrien\AppData\Roaming\ZHP\ZHPDiag3.exe [2364416] [PID.3020] =>.Nicolas Coolman ---\\ Firefox, Plugins,Demarrage,Recherche,Extensions (7) - 47s P2 - EXT FILE: (.ReloadEvery - Reloads webpages every so many seconds.) -- C:\Users\Adrien\AppData\Roaming\Mozilla\Firefox\Profiles\gn8gs0sa.default-1468168574309\extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}.xpi =>.ReloadEvery P2 - EXT FILE: (.Adblock Plus - Ads were yesterday!.) -- C:\Users\Adrien\AppData\Roaming\Mozilla\Firefox\Profiles\gn8gs0sa.default-1468168574309\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi =>.Adblock Plus P2 - EXT: (.Wips.com -