Hello,
Here is the report in question.
~ Report from ZHPDiag v2014.4.26.45 - Nicolas Coolman (04/26/2014)
~ Launched by Samantha (04/27/2014 14:54:20)
~ Website Address http://nicolascoolman.webs.com
~ Free Disinfection Assistance Forums: http://nicolascoolman.webs.com/apps/links/
~ Translated by Nicolas Coolman
~ Version Status:
~ Whitelist: Enabled by the program
~ Privilege Escalation: OK
~ User Account Control (UAC): Activated by user
---\\ Internet Browsers
MSIE: Internet Explorer v11.0.9600.16659
MFIE: Mozilla Firefox 28.0
---\\ Windows Product Information
~ Language: French
Windows 7 Home Premium, 64-bit Service Pack 1 (Build 7601)
Windows Server License Manager Script: OK
~ Windows Operating System - Windows(R) 7, OEM_SLP channel
System Locked Preinstallation (OEM_SLP): OK
Windows ID Activation: OK
~ Windows Partial Key: 3Q6C9
Windows License: OK
~ Windows Remaining Initializations Number: 3
Software Protection Service: OK
Windows Automatic Updates: OK
Windows Activation Technologies: OK
---\\ System Protection Software
avast! Free Antivirus v8.0.1489.0
Ad-Aware Antivirus v11.1.5354.0
McAfee Security Scan Plus v3.0.285.6
Windows Defender W7
---\\ System Optimization Software
CCleaner v4.09 =>.Piriform Ltd
---\\ PeerToPeer Sharing Software
Pando Media Booster v2.6.0.7
Vuze v4.8 =>P2P.Azureus
---\\ Software Surveillance
Adobe Flash Player 13 Plugin
Java 7 Update 51
---\\ System Information
~ Processor: Intel64 Family 6 Model 37 Stepping 5, GenuineIntel
~ Operating System: 64 Bits
Boot mode: Normal (Normal boot)
Total RAM: 3959 MB (46% free)
System Restore: Enabled
System drive C: has 423 GB (46%) free of 918 GB
---\\ System Connection Mode
~ Computer Name: SAMANTHA-HP
~ User Name: Samantha
~ All Users Names: UpdatusUser, Samantha, HomeGroupUser$, Administrator,
~ Unselected Option: O45,O61,O62,O65,O66,O80,O82,O89
Logged in as Administrator
---\\ Environment Variables
~ System Unit: C:\
~ %AppZHP%: C:\Users\Samantha\AppData\Roaming\ZHP\
~ %AppData%: C:\Users\Samantha\AppData\Roaming\
~ %Desktop%: C:\Users\Samantha\Desktop\
~ %Favorites%: C:\Users\Samantha\Favorites\
~ %LocalAppData%: C:\Users\Samantha\AppData\Local\
~ %StartMenu%: C:\Users\Samantha\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir%: C:\Windows\
~ %System%: C:\Windows\System32\
---\\ Disk Unit Enumeration
C: Hard drive, Flash drive, Thumb drive (Free 423 GB of 918 GB)
D: Hard drive, Flash drive, Thumb drive (Free 2 GB of 14 GB)
E: CD-ROM drive (Not Inserted)
F: Floppy drive, Flash card reader, USB Key (Not Inserted)
G: CD-ROM drive (Not Inserted)
H: CD-ROM drive (Not Inserted)
---\\ Windows Security Center Status
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
~ Security Center: 44 Legitimate Filtered in 00mn 00s
---\\ Generic File Search
[MD5.332FEAB1435662FC6C672E25BEB37BE3] - (.Microsoft Corporation - Windows Explorer.) (.02/25/2011 - 07:19:30.) -- C:\Windows\Explorer.exe [2871808]
[MD5.94355C28C1970635A31B3FE52EB7CEBA] - (.Microsoft Corporation - Windows Startup Application.) (.07/14/2009 - 02:39:52.) -- C:\Windows\System32\Wininit.exe [129024]
[MD5.DF79CE9B950C62677D232154E93A81C7] - (.Microsoft Corporation - Internet Extensions for Win32.) (.03/01/2014 - 04:10:28.) -- C:\Windows\System32\wininet.dll [2334208]
[MD5.1151B1BAA6F350B1DB6598E0FEA7C457] - (.Microsoft Corporation - Windows Logon Application.) (.11/20/2010 - 14:25:30.) -- C:\Windows\System32\Winlogon.exe [390656]
[MD5.067FA52BFB59A56110A12312EF9AF243] - (.Microsoft Corporation - License Library.) (.11/20/2010 - 14:27:26.) -- C:\Windows\System32\sppcomapi.dll [232448]
[MD5.79059559E89D06E8B80CE2944BE20228] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.09/28/2013 - 02:09:10.) -- C:\Windows\system32\Drivers\AFD.sys [497152]
[MD5.02062C0B390B7729EDC9E69C680A6F3C] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.07/14/2009 - 02:52:21.) -- C:\Windows\system32\Drivers\atapi.sys [24128]
[MD5.B8BD2BB284668C84865658C77574381A] - (.Microsoft Corporation - CD-ROM File System Driver.) (.07/14/2009 - 00:19:47.) -- C:\Windows\system32\Drivers\Cdfs.sys [92160]
[MD5.F036CE71586E93D94DAB220D7BDF4416] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.11/20/2010 - 10:19:21.) -- C:\Windows\system32\Drivers\Cdrom.sys [147456]
[MD5.9BB2EF44EAA163B29C4A4587887A0FE4] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.11/20/2010 - 10:26:32.) -- C:\Windows\system32\Drivers\DfsC.sys [102400]
[MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.11/20/2010 - 11:43:43.) -- C:\Windows\system32\Drivers\HDAudBus.sys [122368]
[MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - (.Microsoft Corporation - i8042 Port Driver.) (.07/14/2009 - 00:19:57.) -- C:\Windows\system32\Drivers\i8042prt.sys [105472]
[MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - (.Microsoft Corporation - IP Network Address Translator.) (.07/14/2009 - 01:10:03.) -- C:\Windows\system32\Drivers\IpNat.sys [116224]
[MD5.A5D9106A73DC88564C825D317CAC68AC] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.04/27/2011 - 03:40:40.) -- C:\Windows\system32\Drivers\MRxSmb.sys [158208]
[MD5.09594D1089C523423B32A4229263F068] - (.Microsoft Corporation - MBT Transport driver.) (.11/20/2010 - 10:23:20.) -- C:\Windows\system32\Drivers\netBT.sys [261632]
[MD5.1A29A59A4C5BA6F8C85062A613B7E2B2] - (.Microsoft Corporation - NT File System Driver.) (.01/24/2014 - 03:37:55.) -- C:\Windows\system32\Drivers\ntfs.sys [1684928]
[MD5.0086431C29C35BE1DBC43F52CC273887] - (.Microsoft Corporation - Parallel Port Driver.) (.07/14/2009 - 01:00:41.) -- C:\Windows\system32\Drivers\Parport.sys [97280]
[MD5.471815800AE33E6F1C32FB1B97C490CA] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.11/20/2010 - 11:52:35.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [129536]
[MD5.548260A7B8654E024DC30BF8A7C5BAA4] - (.Microsoft Corporation - SMB Transport driver.) (.07/14/2009 - 01:09:09.) -- C:\Windows\system32\Drivers\smb.sys [93184]
[MD5.DDAD5A7AB24D8B65F8D724F5C20FD806] - (.Microsoft Corporation - TDI Translation Driver.) (.11/20/2010 - 10:21:56.) -- C:\Windows\system32\Drivers\tdx.sys [119296]
[MD5.0D08D2F3B3FF84E433346669B5E0F639] - (.Microsoft Corporation - Volume Shadow Copy Driver.) (.11/20/2010 - 14:34:02.) -- C:\Windows\system32\Drivers\volsnap.sys [295808]
~ Generic Processes: Scanned in 00mn 00s
---\\ Status of Hidden Files (Hidden/Total)
~ My Pictures: 1/110
~ My Musics: 1/10
~ My Favorites: 1/21
~ My Documents: 1/6125
~ My Desktop: 1/9452
~ Start Menu: 1/51
~ Hidden Files: Scanned in 00mn 14s
---\\ Running Processes
[MD5.43561AE883C36EF9C52FB9C7765FE8ED] - (...) -- C:\Windows\SysWOW64\jmdp\stij.exe [1100592] [PID.3148]
[MD5.554A50B5310E702029D3A675459108FF] - (.Hewlett-Packard - hpsysdrv.) -- C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe [62768] [PID.1160]
[MD5.CC78200C3ECFFA178E78308A0E160D80] - (.Akamai Technologies, Inc. - Akamai NetSession Client.) -- C:\Users\Samantha\AppData\Local\Akamai\netsession_win.exe [4672920] [PID.1780]
[MD5.3F11B20D12D89365D7721BDC860CE5F0] - (.AVAST Software - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe [4858968] [PID.3796]
[MD5.5B6E8E09BE6401A7E022F52FDFCB2FF8] - (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336] [PID.3216]
[MD5.A2C1288BD3DEDE03B2327E5972678C2E] - (.McAfee, Inc. - McAfee Security Scanner Scheduler.) -- C:\Program Files (x86)\McAfee Security Scan\3.0.285\SSScheduler.exe [271808] [PID.3720]
[MD5.ECCA7F72A24C7CF43131946C076689D1] - (.Google Inc. - Google Chrome.) -- C:\Users\Samantha\AppData\Local\Google\Chrome\Application\chrome.exe [846288] [PID.652]
[MD5.7DCE7A74764EB7C67D21A32BC579453D] - (.Oracle Corporation - Java(TM) Update Checker.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe [507264] [PID.4516]
[MD5.7EA50DC775B557AD1E06ABF3C7A2A24D] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [7869952] [PID.608]
[MD5.28D6701C710AD7BA3CB95E75F8F1A9AA] - (.AVAST Software - avast! Service.) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808] [PID.1516]
[MD5.CA793DCC1D5F619021EF1D37CC7A831E] - (.EasyBits Software AS - Shared EasyBits services for Windows.) -- C:\Windows\SysWOW64\ezSharedSvcHost.exe [514232] [PID.1932]
[MD5.2AF0E02A92BEE89E84EF1000F695AA7E] - (...) -- C:\Program Files\IB Updater\ExtensionUpdaterService.exe [188760] [PID.2804] =>Adware.InstallBrain
[MD5.E38775922D4A4C05B5D96733AB4CE169] - (.Intel Corporation - Local Manageability Service.) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [268824] [PID.2916]
[MD5.12B7C7668E6441529E087D1D0E1E032A] - (.PDF Complete Inc - Dispatcher.) -- C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1119768] [PID.3012]
[MD5.D319343661F7FEBFB6F43C453C26E779] - (.Ralink Technology, Corp. - RalinkRegistryWriter.) -- C:\Program Files (x86)\Boulanger\Common\RaRegistry.exe [193888] [PID.2076]
[MD5.02C298382359653BEC4C737C2AB7F9C5] - (.Intel Corporation - User Notification Service.) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2320920] [PID.5092]
~ Processes Running: Scanned in 00mn 01s
---\\ Google Chrome, Startup, Search, Extensions (G0,G1,G2)
C:\Users\Samantha\AppData\Local\Google\Chrome\User Data\Default\Preferences
G2 - GCE: Preference [User Data\Default] [gaiilaahiahdejapggenmdmafpmbipje] DealPly v.3.8.0.0 (Disabled) =>PUP.DealPly
G2 - GCE: Preference [User Data\Default] [jcdgjdiieiljkfkdcloehkohchhpekkn] SweetIM for Facebook v.1.0.0.0 (Disabled) =>PUP.SweetIM
G2 - GCE: Preference [User Data\Default] [mmapnhgbanipillmolcbaidjboadhngn] The Settlers Online v.1.2.5 (Enabled)
---\\ List of Google Chrome Extension Folders
~ Google Lines Browser: 22 Legitimate Filtered in 00mn 27s
---\\ Mozilla Firefox, Plugins, Startup, Search, Extensions (P2,M0,M1,M2,M3)
P2 - FPN: [HKCU] [@bitmanagement.com/BS Contact] - (.Bitmanagement Software GmbH - BS Contact VRML/X3D FireFox plug-in.) -- C:\Users\Samantha\AppData\Local\Bitmanagement Software\BS Contact\npBSContact.dll
P2 - FPN: [HKCU] [@bitmanagement.com/BSVersion,version=1.006] - (.Bitmanagement Software GmbH - BS Version Control.) -- C:\Users\Samantha\AppData\Local\Bitmanagement Software\BS Contact\npBSVersion_6.dll
~ Firefox Browser: 25 Legitimate Filtered in 00mn 00s
---\\ Internet Explorer, Startup, Search, URLSearchHook, Phishing (R0,R1,R3,R4)
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com =>PUP.Babylon
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.babylon.com =>PUP.Babylon
~ IE Browser: 24 Legitimate Filtered in 00mn 00s
---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = <local>
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s
---\\ Analysis of lines F0, F1, F2, F3 - IniFiles, Autoloading programs
F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn 00s
---\\ Hosts file redirection (O1)
~ The hosts file is clean.
~ Hosts File: Scanned in 00mn 00s
~ Number of lines: 21
---\\ Browser Helper Objects (O2)
O2 - BHO: IB Updater Helper [64Bits] - {336D0C35-8A85-403a-B9D2-65C292C39087} . (...) -- C:\Program Files\IB Updater\Extension32.dll =>Adware.InstallBrain
O2 - BHO: Incredibar.com Helper Object [64Bits] - {6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99} . (.Montera Technologies LTD - No description.) -- C:\Program Files (x86)\Incredibar.com\incredibar\1.5.11.14\bh\incredibar.dll =>Adware.IncrediBar
~ BHO: 13 Legitimate Filtered in 00mn 00s
---\\ Internet Explorer Toolbars (O3)
O3 - Toolbar: (no name) - [HKLM]{ae07101b-46d4-4a98-af68-0333ea26e113} Orphaned key
O3 - Toolbar: avast! Online Security - [HKLM]{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} . (.AVAST Software - IE Webrep plugin.) -- C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
O3 - Toolbar\WebBrowser: (no name) - [HKCU]{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} Orphaned key
O3 - Toolbar\WebBrowser: (no name) - [HKCU]{EEE6C35B-6118-11DC-9C72-001320C79847} Orphaned key
~ Toolbar: Scanned in 00mn 00s
---\\ Other User Links (O4)
O4 - GS\Desktop [Public]: Vuze.lnk . (...) -- C:\Program Files (x86)\Vuze\Azureus.exe (.not file.) =>P2P.Azureus
O4 - GS\Program [Public]: Vuze.lnk . (...) -- C:\Program Files (x86)\Vuze\Azureus.exe (.not file.) =>P2P.Azureus
O4 - GS\QuickLaunch [Samantha]: Vuze.lnk . (...) -- C:\Program Files (x86)\Vuze\Azureus.exe (.not file.) =>P2P.Azureus
O4 - GS\Desktop [Samantha]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) -- C:\Users\Samantha\AppData\Roaming\uTorrent\uTorrent.exe =>P2P.BitTorrent
~ Global Startup: 6 Legitimate Filtered in 00mn 04s
---\\ Applications launched at system startup (O4)
O4 - HKLM\..\Run: [hpsysdrv] . (.Hewlett-Packard - hpsysdrv.) -- c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe =>.Hewlett-Packard Co
O4 - HKLM\..\Run: [AdAwareTray] . (...) -- C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5354.0\AdAwareTray.exe
O4 - HKLM\..\RunOnce: [NCPluginUpdater] . (.Hewlett-Packard - NCPluginUpdater.) -- C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe
O4 - HKCU\..\Run: [Akamai NetSession Interface] . (.Akamai Technologies, Inc. - Akamai NetSession Client.) -- C:\Users\Samantha\AppData\Local\Akamai\netsession_win.exe
O4 - HKCU\..\Run: [Google Update] . (.Google Inc. - Google Installer.) -- C:\Users\Samantha\AppData\Local\Google\Update\GoogleUpdate.exe =>.Google Inc
O4 - HKLM\..\Wow6432Node\Run: [PDF Complete] . (.PDF Complete Inc - Sentry for PDF.) -- C:\Program Files (x86)\PDF Complete\pdfsty.exe =>.PDF Complete Inc
O4 - HKLM\..\Wow6432Node\Run: [avast] . (.AVAST Software - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\avastUI.exe
O4 - HKLM\..\Wow6432Node\Run: [APSDaemon] . (.Apple Inc. - Apple Push.) -- C:\Program Files