ZHPDiag report consists of 4 groups, the modules of header, the basic modules, the optional modules and report modules.

The modules from header include general information such as the operating system, the RAM, the protections, browsers.

The base modules are the fixed structure of the report. The optional modules are related to the choice of the user which can turn them off in the control panel. The end modules provide specific information, alerts and links to the blog master records.


Web Browser : Lists internet browsers.
Alert message (MEAL) : Enumeration of the alert message.
Windows Product Information (WPI) : Information on the identity of the operating system.
System Protection : List the installed protection software.
System Optimizer : Lists system optimization software.
Peer To Peer (P2P) : List the installed Peer To Peer sharing software.
Software Update : Target some software whose update is required.
System Information : Various information on the operating system and memory.
Environment Variables : Lists system environment variables.
BACK/Devices : Details storage units.
Security Center & Tools Information (ITRS): Information on safety and the protection of the system.
Recherche particulière de fichiers génériques : Is likely to be infected system files.
State of hidden files (Hidden/Total) : Allows you to check the presence of an infection.



B0 – Opera, Start pages : The Opera browser start page.
B1 – Opera, Search pages : The Opera browser search page.
P1 – Opera, Browser extension : Lists the Opera browser plugins.


C0 – Comodo Dragon, Start page : The Comodo Dragon browser start page.
C1 – Comodo Dragon, Search page : The Comodo Dragon browser search page.
C2 – Comodo Dragon Extensions: Lists the extensions of the Comodo Dragon browser.


E0 – Microsoft Edge, Start page: The Edge browser start page.
E1 – Microsoft Edge, Search page : The Edge browser search page.
E2 – Microsoft Edge Extensions: Lists the Edge browser extensions.
E4 – Microsoft Edge Favorites : Lists the elements of the Edge Favorites bar.


G0 – Google Chrome, Start page : The Google Chrome browser start page.
G1 – Google Chrome, Search page : Search page of Google Chrome browser.
G2 – Google Chrome, Extensions : Lists the extensions of the Google Chrome browser.


P2 – Mozilla Firefox, Browser extension : Lists the Mozilla Firefox browser plugins.
M0 – Mozilla Firefox, Start page : The browser Mozilla Firefox start page.
M1 – Mozilla Firefox, Search page : The Mozilla Firefox browser search page.
M2 – Mozilla Firefox, Extension : Lists the extensions of Mozilla Firefox.
M3 – Plugins for browsers (MFPP) : Lists the Mozilla Firefox browser plugins.


R0 – Internet Explorer, Start page : The Internet Explorer start page.
R1 – Internet Explorer, Search page : The Internet Explorer search page.
R3 – Internet Explorer, URLSearchHook : URLSearchHook browser Internet Explorer settings.
R4 – Internet Explorer, Phishing : Phishing on the Internet Explorer browser.
R5 – Internet Explorer, Proxy Management : Lists the Internet Explorer Proxy settings.
F2 – Changing a value system. (MVS) : Lists some registry key values.
F3 – Changing a value Win.Ini (MVW) : Lists some registry key values.
O1 – The Hosts file redirection : Lists the contents of the Hosts file.
O2 – Browser Helper Objects in browser : Lists the BHO (Browser Helper Objects) Internet Explorer
O3 – Internet Explorer Toolbars : Lists the Internet Explorer toolbars.


S2 – Slimjet Extensions, Lists the Slimjet browser extensions.


V2 – Vivaldi Extensions, Lists the Vivaldi browser extensions.


O4 – Applications started automatically by the registry : Applications started by the system.
O4 – Global shortcuts Startup : Applications launched at system startup.
O8 – Additional lines in the context menu of Internet Explorer : Internet Explorer context menu.
Ø10 – Winsock hijacker (Layered Service Provider) : Pirate Winsock LSP.
O17 – Change address/domain DNS : Enumeration of the DNS server settings.
O18 – Additional protocols : Lists changes to the default protocols.
Ø19 – User Style Sheet hijack : Search for a possible hacking of style sheet.
O20 – AppInit_DLLs Registry value Autorun : Lists the files loaded by the AppInit_DLLs registry value.
O20 – Values of subkeys Winlogon Notify (Autorun) : Lists the files in the Winlogon Notify subkeys.
Ø21 – Autorun ShellServiceObjectDelayLoad registry key (SSODL) : Lists the SSODL registry keys.
Ø22 – SharedTaskScheduler : Identifies the CLSID of the SharedTaskScheduler registry key values.
O23 – Liste des services NT non Microsoft et non désactivés : Lists services that are started automatically.
O34 – BootExecute (BE) : Run through Session manager.
O35 – Key Explorer : Lists the Startup Approved key.
Ø36 – Session Manager AppCertDlls Key (AppCertDlls,KnownDLLs) : Session Manager subkey enumeration.
SR/SS – State General Services (EGS) : Enumerates the general status of the services.


Ø38 – Tâches planifiées en automatique (APT) : Lists the jobs that were started with the system.
Ø40 – ActiveSetup Installed Components (ASIC) : Lists the registry keys.
O41 – Pilots launched at startup (LDP) : Lists the drivers the system starts.
O42 – Software installed (FAR) : Lists installed software.
O42 – HKCU & HKLM Software Keys : Lists the registry keys Software.
O43 – Content of the Programes files (CFD): Lists the programs files.
O45 – Latest files created by Windows Prefetcher : Lists the latest files from the Prefetcher.
O46 – ShellExecuteHooks (SEH) : Lists the Operations and functions at the start of Windows Explorer.
Ø50 – Image File Execution Options (IFEO) : Lists the registry keys
O51 – MountPoints2 Key Shell (MPSK) : Tracking the infections from USB ports.
O53 – ShareTools MSconfig StartupReg (SMSR) : List the values and the StartupReg key data.
O58 – List of System Drivers (SDL) : List the system drivers.
O61 – Latest files modified or created (LFC) : Lists recently created files.
Ø67 – File Association Shell Spawning (FASS) : Lists certain file extensions.
O68 – Start Menu Internet (SMI) : Lists the installed Web browsers.
O69 – Search Browser Infection (SBI): Research of infections on browsers.
O81 – Internet Feature Controls (IFC) : Search infections IE with the compatibility mode of the documents management.
O82 – Crack & Keygen Files (CKF) : Research of crack or keygen file.
O83 – Search for services that are started by Svchost (SSS): Lists the Windows SvcHost services.
O87 – Firewall Active Exception List (FirewallRules): List some applications of Windows Firewall.
O88 – Additional scan (ACE) : Detections associated with the ZHPScan function.
Ø90 – Product Upgrade Codes : List the installed product codes.
O93 – Windows install Scan : List of MSI Windows Installer package files.
Ø100 – Research of Tracing registry keys : Enumerates the Tracing key pests.
O106 – Search for key ShellIconOverlayIdentifiers : Lists the sub key ShellIconOverlayIdentifiers.
O107 – Search for MRT files : Lists the files of Microsoft Removal Tool.
O108 – Research of key CMH : Lists the keys to contextual menu shortcuts.
O109 – Search Future control keys : Lists the registry keys Future control.


Alert Messages : Some infections alert message (Navipromo, ZeroAccess).
Malicius software Information (MSI) : Gives information about malware detections.
Additional information on the modules (FRIEND) : Link to further information.