Unable to open Firefox

Solved
netphilou Posted messages 139 Status Membre -  
netphilou Posted messages 139 Status Membre -
Hello,
Since yesterday, I can no longer navigate on FireFox (I think I made a mistake by downloading and opening some crappy thing). In addition, ad windows open as soon as I turn on my computer, all functions are slow and a message "out at memory of line 2" appears regularly on my desktop. That's all! Who can come to my rescue? Thank you in advance.

Netphilou

Update: I managed to open Firefox but the other problems persist and especially this message "memory of line..." that appears regularly.

It's starting again, when I try to open Firefox a message indicates that Firefox has crashed! What should I do?

Configuration: Windows XP / Internet Explorer 7.0

24 réponses

  • 1
  • 2
*marc64* Posted messages 218 Status Membre 62
 
Hello,

ad windows pop up as soon as I turn on my computer


there's a good chance your computer is infected.

* Download ZHPDiag(by Nicolas Coolman)
* Vista and Seven users: Right-click on the ZHPdiag logo, "run as Administrator"
* Follow the instructions during installation, it will launch automatically at the end.
* Click on the icon that looks like a magnifying glass ("Start the diagnosis")
* Save the report on your Desktop using the icon that looks like a floppy disk
Use Cjoint.com to post the link to your report:
https://www.cjoint.com/

- Click on Browse to find the report
- Click on Open then Create the Cjoint link

- In your next response, copy and paste the link that is shown...The link has been created:

You MUST host the report via Cjoint as requested, otherwise it will not fully pass on the forum
0
netphilou Posted messages 139 Status Membre 2
 
Hello, thank you for your response. I clicked on ZHPDiag but since I'm not very skilled, I don't know what to click to download it.
Thank you for your help.
Best regards.

Netphilou
0
*marc64* Posted messages 218 Status Membre 62
 
0
netphilou Posted messages 139 Status Membre 2
 
ZHPDiag report v1.27.204 by Nicolas Coolman, Updated on 14/05/2011
Run by HP_Owner at 15.05.2011 14:58:19
Web site: http://www.premiumorange.com/zeb-help-process/zhpdiag.html

---\\ Web Browser
MSIE: Internet Explorer v7.0.5730.13
MFIE: Mozilla Firefox 4.0.1 v4.0.1 (Default)

---\\ System Information
Windows XP Home Edition Service Pack 3 (Build 2600)
Processor: x86 Family 15 Model 4 Stepping 1, GenuineIntel
Operating System: 32 Bits
Boot mode: Normal (Normal boot)
Total RAM: 1023.4 MB (36% free)
System Restore: Enabled
System drive C: has 91 GB (40%) free of 227 GB

---\\ Logged in mode
Computer Name: NOM-EB85C523610
User Name: HP_Owner
All Users Names: SUPPORT_fddfa904, SUPPORT_388945a0, HP_Owner, HelpAssistant, Administrator,
Unselected Option: O45,O61,O62,O65,O66,O82
Logged in as Administrator

---\\ Environment Variables
%AppData%=C:\Documents and Settings\HP_Owner\Application Data
%LocalAppData%=C:\Documents and Settings\HP_Owner\Local Settings\Application Data
%StartMenu%=C:\Documents and Settings\HP_Owner\Start Menu

---\\ DOS/Devices
C:\ Hard drive, Flash drive, Thumb drive (Free 91 GB of 227 GB)
D:\ Hard drive, Flash drive, Thumb drive (Free 2 GB of 6 GB)
E:\ CD-ROM drive (Not Inserted)
F:\ CD-ROM drive (Not Inserted)
G:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
H:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
I:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
J:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
K:\ CD-ROM drive (Not Inserted)
N:\ Floppy drive, Flash card reader, USB Key (Not Inserted)

---\\ Security Center & Tools Information
[HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center] FirewallDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center] UpdatesDisableNotify: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] DisableTaskMgr: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] DisableRegistryTools: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK

---\\ Specific file search for generic files
[MD5.F2317622D29F9FF0F88AEECD5F60F0DD] - (.Microsoft Corporation - Windows Explorer.) (.14.04.2008 03:34:03.) -- C:\WINDOWS\Explorer.exe [1037824]
[MD5.0B09E07755F412A1A4F18DDC353BA155] - (.Microsoft Corporation - Internet Extensions for Win32.) (.17.02.2011 19:56:16.) -- C:\WINDOWS\system32\wininet.dll [832512]
[MD5.DD73D6B9F6B4CB630CF35B438B540174] - (.Microsoft Corporation - Windows NT Logon Application.) (.14.04.2008 03:34:28.) -- C:\WINDOWS\system32\Winlogon.exe [512000]
[MD5.00000000000000000000000000000000] - (.No owner - No description.) (.13.04.2008 00:00:00.) -- C:\WINDOWS\system32\drivers\atapi.sys [96512]
[MD5.78A08DD6A8D65E697C18E1DB01C5CDCA] - (.Microsoft Corporation - NT File System Driver.) (.13.04.2008 20:15:53.) -- C:\WINDOWS\system32\drivers\ntfs.sys [574976]

---\\ Running Processes
[MD5.20F6F19FE9E753F2780DC2FA083AD597] - (.Apple Inc. - MobileDeviceService.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [37664]
[MD5.F832F1505AD8B83474BD9A5B1B985E01] - (.Apple Inc. - Bonjour Service.) -- C:\Program Files\Bonjour\mDNSResponder.exe [345376]
[MD5.C9FFBD6B8EDC46CD3D13E3C6DB914FB7] - (.Matsushita Electric Industrial Co., Ltd. - DVD-RAM Utility Helper Service.) -- C:\WINDOWS\system32\DVDRAMSV.exe [110592]
[MD5.A9BE66E05254B20DF82E0F7CDDECA7DD] - (.F-Secure Corporation - F-Secure Anti-Virus Scanning Service.) -- C:\Program Files\Internet Security\Anti-Virus\fsgk32st.exe [215648]
[MD5.392E85687A902239C01BADDF212B1A36] - (.F-Secure Corporation - F-Secure Management Agent.) -- C:\Program Files\Internet Security\Common\FSMA32.EXE [186976]
[MD5.C296A91A89263600FC4B247188EC3160] - (.F-Secure Corporation - Gatekeeper Handler II 32-bit.) -- C:\Program Files\Internet Security\Anti-Virus\FSGK32.EXE [508584]
[MD5.7E48D9BC72C8A0A9525F309F92A284D4] - (.F-Secure Corporation - F-Secure DLL Hosting Plugin.) -- C:\Program Files\Internet Security\Common\FSHDLL32.EXE [88672]
[MD5.39133291CB607BDD87CFC565A4A1E7A5] - (.Sun Microsystems, Inc. - Java(TM) Quick Starter Service.) -- C:\Program Files\Java\jre6\bin\jqs.exe [153376]
[MD5.575ED0F5DCB34E5C243D2A7EBC860484] - (.Hewlett-Packard Company - No description.) -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe [53248]
[MD5.11F714F85530A2BD134074DC30E99FCA] - (.Microsoft Corporation - Machine Debug Manager.) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [322120]
[MD5.5705D065B450F03EC0743E601941DDFA] - (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 77.79.) -- C:\WINDOWS\system32\nvsvc32.exe [127043]
[MD5.2D091A99624FB9E7EEF0A86D872EC0C3] - (.HP - PML Driver.) -- C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE [73728]
[MD5.332D341D92B933600D41953B08360DFB] - (.Ulead Systems, Inc. - ULCDRSvr.) -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [49152]
[MD5.20F89E232173985A455BC9A5F70D1166] - (.Canon Inc. - Canon Camera Access Library 8.) -- C:\Program Files\Canon\CAL\CALMAIN.exe [96341]
[MD5.7F08A21197C0759F0C2E8FEBA81E27B0] - (.F-Secure Corporation - F-Secure Scanner Manager 32-bit.) -- C:\Program Files\Internet Security\Anti-Virus\fssm32.exe [918184]
[MD5.707C0C5D9BE7163182227470E9CD3C9A] - (.Belkin - Belkin Wireless Client Utility.) -- C:\Program Files\Belkin\F5D8055\v2\Belkinwcui.exe [1662976]
[MD5.DA057673D9CF8CACDF6A3C5C1423F150] - (.Logitech Inc. - Communications Manager.) -- C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe [488984]
[MD5.4ABB2B8396FB02BE582FE92024269815] - (.Logitech Inc. - LVCom Server.) -- C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe [244512]
[MD5.8D74462038DDAE95966EF5F1E53C96B0] - (.F-Secure Corporation - F-Secure Settings and Statistics.) -- C:\Program Files\Internet Security\Common\FSM32.EXE [199264]
[MD5.8E0BF7478CC3BAED48282ADBC97ADAFB] - (.F-Secure Corporation - F-Secure Internet Shield daemon.) -- C:\Program Files\Internet Security\FWES\Program\fsdfwd.exe [522848]
[MD5.B624202660474516E73AA95238FD9843] - (.Logitech, Inc. - Logitech SetPoint Event Manager (UNICODE).) -- C:\Program Files\Logitech\SetPoint\SetPoint.exe [813584]
[MD5.E96BC31E0114F0999FB0F92FC65D61CA] - (.Logitech, Inc. - Logitech KHAL Main Process.) -- C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE [55824]
[MD5.051BD9B27D8B89DA4AE5ED91F116ED7E] - (.F-Secure Corporation - FSAV Handler.) -- C:\Program Files\Internet Security\Anti-Virus\fsav32.exe [484520]
[MD5.E4A798DFDE7FE6E79F23548F0EF0F844] - (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe [634648]
[MD5.9E243ECD2DE787DE5033F80BF14DF17F] - (...) -- C:\WINDOWS\System32\regsvr32.exe [12288]
[MD5.AC42E793F760034FC6F0BACB17E94003] - (.Nicolas Coolman - Diagnostic Tool.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [646144]

---\\ Mozilla Firefox, Plugins, Startup, Search, Extensions (P2,M0,M1,M2,M3)
M3 - MFPP: Plugins - [HP_Owner] -- C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\2kkrg3eh.default\searchplugins\askcom.xml
M3 - MFPP: Plugins - [HP_Owner] -- C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\2kkrg3eh.default\searchplugins\search.xml
M3 - MFPP: Plugins - [HP_Owner] -- C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\2kkrg3eh.default\searchplugins\conduit.xml
M3 - MFPP: Plugins - [HP_Owner] -- C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\2kkrg3eh.default\searchplugins\LphantWebSearch.xml
M3 - MFPP: Plugins - [HP_Owner] -- C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\2kkrg3eh.default\searchplugins\web-search.xml
M3 - MFPP: Plugins - [HP_Owner] -- C:\Program Files\Mozilla FireFox\searchplugins\amazon-france.xml
M3 - MFPP: Plugins - [HP_Owner] -- C:\Program Files\Mozilla FireFox\searchplugins\bing.xml
M3 - MFPP: Plugins - [HP_Owner] -- C:\Program Files\Mozilla FireFox\searchplugins\cnrtl-tlfi-fr.xml
M3 - MFPP: Plugins - [HP_Owner] -- C:\Program Files\Mozilla FireFox\searchplugins\eBay-france.xml
M3 - MFPP: Plugins - [HP_Owner] -- C:\Program Files\Mozilla FireFox\searchplugins\google.xml
M3 - MFPP: Plugins - [HP_Owner] -- C:\Program Files\Mozilla FireFox\searchplugins\wikipedia-fr.xml
M3 - MFPP: Plugins - [HP_Owner] -- C:\Program Files\Mozilla FireFox\searchplugins\yahoo-france.xml
P2 - FPN:Firefox Plugin Navigator . (.Microsoft Corporation - np-mswmp.) -- C:\Program Files\Mozilla Firefox\Plugins\np-mswmp.dll
P2 - FPN:Firefox Plugin Navigator . (.Sun Microsystems, Inc. - NPRuntime Script Plug-in Library for Java(TM) Deploy.) -- C:\Program Files\Mozilla Firefox\Plugins\npdeploytk.dll
P2 - FPN:Firefox Plugin Navigator . (.DivX, Inc. - DivX® Web Player.) -- C:\Program Files\Mozilla Firefox\Plugins\npdivx32.dll
P2 - FPN:Firefox Plugin Navigator . (.DivX, Inc - npdivxplayerplugin.) -- C:\Program Files\Mozilla Firefox\Plugins\npDivxPlayerPlugin.dll
P2 - FPN:Firefox Plugin Navigator . (.Microsoft Corporation - Office Plugin for Netscape Navigator.) -- C:\Program Files\Mozilla Firefox\Plugins\NPOFFICE.DLL
P2 - FPN:Firefox Plugin Navigator . (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape "9.4.4".) -- C:\Program Files\Mozilla Firefox\Plugins\nppdf32.dll
P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia content.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin.dll
P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia content.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin2.dll
P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia content.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin3.dll
P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia content.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin4.dll
P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia content.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin5.dll
P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia content.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin6.dll
P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia content.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin7.dll
P2 - FPN:Firefox Plugin Navigator . (.No owner - npsnapfish.) -- C:\Program Files\Mozilla Firefox\Plugins\npsnapfish.dll
P2 - FPN:Firefox Plugin Navigator . (.America Online, Inc. - npunagi2.) -- C:\Program Files\Mozilla Firefox\Plugins\npunagi2.dll
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.No owner - No description.) -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
P2 - FPN: [HKLM] [@Apple.com/iTunes, version=1.0] - (.No owner - No description.) -- C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
P2 - FPN: [HKLM] [@garmin.com/GpsControl] - (.GARMIN Corp. - Garmin Communicator Plug-In 2.8.2.0.) -- C:\Program Files\Garmin GPS Plugin\npGarmin.dll
P2 - FPN: [HKLM] [@Google.com/GoogleEarthPlugin] - (.Google - GEPlugin.) -- C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
P2 - FPN: [HKLM] [@microsoft.com/WPF, version=3.5] - (.Microsoft Corporation - Windows Presentation Foundation (WPF) plug-in for Mozilla browsers.) -- c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
P2 - FPN: [HKLM] [@pandasecurity.com/activescan] - (.No owner - No description.) -- C:\Program Files\Panda Security\ActiveScan 2.0\npwrapper.dll (.not file.)
P2 - FPN: [HKLM] [@tools.google.com/Google Update; version=3] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.21.53\npGoogleUpdate3.dll
P2 - FPN: [HKLM] [@tools.google.com/Google Update; version=9] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.21.53\npGoogleUpdate3.dll
M0 - MFSP: prefs.js [HP_Owner - 2kkrg3eh.default] https://www.bluewin.ch/de/index.html
M2 - MFEP: prefs.js [HP_Owner - 2kkrg3eh.default\engine@conduit.com] [] Conduit Engine v3.3.3.2 (.Conduit Ltd..)
M2 - MFEP: prefs.js [HP_Owner - 2kkrg3eh.default\fr@dictionaries.addons.mozilla.org] [] French Dictionary "1990 Reform" v3.5 (.Olivier R..)
M2 - MFEP: prefs.js [HP_Owner - 2kkrg3eh.default\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}] [] Garmin Communicator v3.5 (.Garmin International.)
M2 - MFEP: prefs.js [HP_Owner - 2kkrg3eh.default\{3112ca9c-de6d-4884-a869-9855de68056c}] [] Google Toolbar for Firefox v7.1.20101113Wb1 (.Google Inc..)
M2 - MFEP: prefs.js [HP_Owner - 2kkrg3eh.default\{4daac69c-cba7-45e2-9bc8-1044483d3352}] [] Softonic_France Community Toolbar v3.3.3.2 (.Conduit Ltd..)

---\\ Google Chrome, Startup, Search, Extensions (G0,G1,G2)
G1 - GCS: Preference [User Data\Default] None
G0 - GCSP: Preference [User Data\Default][HomePage] https://www.google.com/?gws_rd=ssl

---\\ Internet Explorer, Startup, Search, URLSearchHook, Phishing (R0,R1,R3,R4)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main, Start Page = https://www.bluewin.ch/de/index.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main, Start Page = https://www.microsoft.com/fr-fr/
R0 - HKUS\S-1-5-21-943731138-2747897866-4246271285-1008\Software\Microsoft\Internet Explorer\Main, Start Page = https://www.bluewin.ch/de/index.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main, Search Page = https://www.microsoft.com/fr-fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main, Search Page = https://www.microsoft.com/fr-fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main, Default_Page_URL = https://www.microsoft.com/fr-fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main, Default_Search_URL = https://www.microsoft.com/fr-fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main, Extensions Off Page = about:noadd-ons
R1 - HKLM\Software\Microsoft\Internet Explorer\Main, Security Risk Page = about:securityrisk
R1 - HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant = https://www.bing.com/?toHttps=1&redig=17DBE7D168544FA98200E890A8051984
R1 - HKUS\S-1-5-21-943731138-2747897866-4246271285-1008\Software\Microsoft\Internet Explorer\Main, SearchMigratedDefaultName = cherche.us
R1 - HKUS\S-1-5-21-943731138-2747897866-4246271285-1008\Software\Microsoft\Internet Explorer\Main, SearchMigratedDefaultURL = http://www.cherche.usso-8859-1&q={searchterms}&sourceid=ie7&rls=com.microsoft:en-us&ie=utf8&oe=utf8
R1 - HKUS\S-1-5-21-943731138-2747897866-4246271285-1008\Software\Microsoft\Internet Explorer\Main, Search Page = https://www.microsoft.com/fr-fr/
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} . (.Ask - Ask Toolbar.) (5.8.0.0) -- C:\Program Files\Ask.com\GenericAskToolbar.dll
R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Internet Explorer.) (7.00.6000.17096 (vista_gdr.110211-1830)) -- C:\WINDOWS\system32\ieframe.dll
R3 - URLSearchHook: Softonic_France Toolbar - {4daac69c-cba7-45e2-9bc8-1044483d3352} . (.Conduit Ltd. - Conduit Toolbar.) (6.3.2.0) -- C:\Program Files\Softonic_France\prxtbSof0.dll
R4 - HKCU\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter, Enabled = 2

---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings, ProxyOverride = *.local
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings, ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings, ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings, MigrateProxy = 1
R5 - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings, EnableHttp1_1 = 1
R5 - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings, AutoConfigProxy = wininet.dll

---\\ ---\\ Modified INI file value (Changed ini file value, mapped to Registry) (F2)
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,
F2 - REG:system.ini: VMApplet=rundll32 shell32, Control_RunDLL "sysdm.cpl"

---\\ Browser Helper Objects (O2)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} Orphaned key
O2 - BHO: AcroIEHelperStub
0
*marc64* Posted messages 218 Status Membre 62
 
The ZHPDiag report is not complete, but we will still begin the cleaning process.
Step 1
Uninstall the following software: (Start => Control Panel => Add/Remove Programs)
- Software: Ask Toolbar
- Software: Conduit Engine
- Software: Softonic_France Toolbar

Step 2
[*]Download AD-Remover (by Cyrildu17 / C_XX) to your Desktop.

- Temporarily disable only for the time you use AD-Remover, the real-time protection of your Antivirus and Antispyware, which may significantly hinder the cleaning procedure of the tool.
- Log out and close all running applications.

[*]Double-click the installer and install it in its default location (C:\Program files).

[*]Double-click on the AD-Remover icon located on your Desktop.
(Vista/Seven - Right-click on the AD-Remover icon on your Desktop and choose run as administrator.)

[*]In the main menu, choose the Clean option.

[*]Post the report that appears at the end.

(The report is also saved under C:\Ad-report(clean).Txt

(CTRL+A to select all, CTRL+C to copy and CTRL+V to paste)

Step 3
-Please post a new ZHPDiag report by strictly following the steps outlined to visualize the entire report.

Use Cjoint.com to post your report link:
https://www.cjoint.com/

- Click on Browse to find the report.
- Click on Open then Create the Cjoint link.

- In your next response, copy/paste the link that is displayed...The link has been created:

It is IMPERATIVE to host the report via Cjoint as requested, otherwise it will not fully appear on the forum.
0
netphilou Posted messages 139 Status Membre 2
 
Thank you,
Here is the report
======= AD-REMOVER REPORT 2.0.0.2,G | WINDOWS XP/VISTA/7 ONLY =======

Updated by TeamXscript on 12/04/11
Contact: AdRemover[DOT]contact[AT]gmail[DOT]com
Website: http://www.teamxscript.org

C:\Program Files\Ad-Remover\main.exe (CLEAN [1]) -> Launched at 17:26:18 on 15/05/2011, Normal mode

Microsoft Windows XP Home Edition Service Pack 3 (X86)
HP_Owner@NAME-EB85C523610 ( )

============== ACTION(S) ==============

File deleted: C:\WINDOWS\system32\c506b3da.exe
File deleted: C:\Program Files\Mozilla FireFox\Components\AskHPRFF.js
File deleted: C:\WINDOWS\system32\ConduitEngine.tmp
File deleted: C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
File deleted: C:\Documents and Settings\HP_Owner\Application Data\Mozilla\FireFox\Profiles\2kkrg3eh.default\searchplugins\askcom.xml
File deleted: C:\Documents and Settings\HP_Owner\Application Data\Mozilla\FireFox\Profiles\2kkrg3eh.default\searchplugins\search.xml
Folder deleted: C:\Documents and Settings\HP_Owner\Application Data\Mozilla\FireFox\Profiles\2kkrg3eh.default\conduit
Folder deleted: C:\Documents and Settings\HP_Owner\Application Data\Mozilla\FireFox\Profiles\2kkrg3eh.default\ConduitEngine
Folder deleted: C:\Documents and Settings\HP_Owner\Application Data\Mozilla\FireFox\Profiles\2kkrg3eh.default\extensions\engine@conduit.com
File deleted: C:\Documents and Settings\HP_Owner\Application Data\Mozilla\FireFox\Profiles\2kkrg3eh.default\searchplugins\conduit.xml
File deleted: C:\Documents and Settings\HP_Owner\Application Data\Mozilla\FireFox\Profiles\2kkrg3eh.default\searchplugins\web-search.xml
File deleted: C:\Documents and Settings\HP_Owner\scriptjava.html
File deleted: C:\Documents and Settings\HP_Owner\temp1.6
Folder deleted: C:\Program Files\Ask.com
Folder deleted: C:\Documents and Settings\HP_Owner\Local Settings\Application Data\AskToolbar
Folder deleted: C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Conduit
Folder deleted: C:\Program Files\Conduit
Folder deletion error: C:\Documents and Settings\HP_Owner\Local Settings\Application Data\ConduitEngine
Folder deleted: C:\Program Files\ConduitEngine
Folder deleted: C:\Documents and Settings\HP_Owner\Application Data\PriceGong

(!) -- Temporary files deleted.

-- Opened file: C:\Documents and Settings\HP_Owner\Application Data\Mozilla\FireFox\Profiles\2kkrg3eh.default\Prefs.js --
Line deleted: user_pref("CT1460988.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TER...
Line deleted: user_pref("CT1460988.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT146...
Line deleted: user_pref("CT1460988.ct1460988.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?q=UCM_...
Line deleted: user_pref("CT2542115.SearchEngine", "Recherche||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_...
Line deleted: user_pref("CT2542115.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT254...
Line deleted: user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/CH", "\"0\"")...
Line deleted: user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "...
Line deleted: user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.engine.conduit-services.com/DLG.pkg?ver=3.3.3...
Line deleted: user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "63...
Line deleted: user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=3/13/20...
Line deleted: user_pref("CommunityToolbar.EngineHiddenByUser", true);
Line deleted: user_pref("CommunityToolbar.EngineOwner", "ConduitEngine");
Line deleted: user_pref("CommunityToolbar.EngineOwnerGuid", "engine@conduit.com");
Line deleted: user_pref("CommunityToolbar.EngineOwnerToolbarId", "conduitengine");
Line deleted: user_pref("CommunityToolbar.IsEngineShown", false);
Line deleted: user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true);
Line deleted: user_pref("CommunityToolbar.OriginalEngineOwner", "ConduitEngine");
Line deleted: user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "engine@conduit.com");
Line deleted: user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "conduitengine");
Line deleted: user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://google.search.us/Result.php?clie...
Line deleted: user_pref("CommunityToolbar.ToolbarsList", "CT1460988,CT2542115,ConduitEngine");
Line deleted: user_pref("CommunityToolbar.ToolbarsList2", "CT1460988,CT2542115");
Line deleted: user_pref("CommunityToolbar.alert.alertDialogsGetterLastCheckTime", "Sun Mar 27 2011 10:21:38 GMT+02...
Line deleted: user_pref("CommunityToolbar.alert.alertInfoInterval", 1440);
Line deleted: user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Sun May 15 2011 10:50:12 GMT+0200");
Line deleted: user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com");
Line deleted: user_pref("CommunityToolbar.alert.locale", "en");
Line deleted: user_pref("CommunityToolbar.alert.loginIntervalMin", 1440);
Line deleted: user_pref("CommunityToolbar.alert.loginLastCheckTime", "Sat May 14 2011 20:39:21 GMT+0200");
Line deleted: user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1303303927");
Line deleted: user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);
Line deleted: user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com");
Line deleted: user_pref("CommunityToolbar.alert.showTrayIcon", false);
Line deleted: user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);
Line deleted: user_pref("CommunityToolbar.alert.userId", "c04f5034-35a7-4c43-a5d2-beb1955e97b6");
Line deleted: user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Mon Aug 30 2010 19:10:12 GMT+0200");
Line deleted: user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Line deleted: user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Line deleted: user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2542115");
Line deleted: user_pref("ConduitEngine.AppTrackingLastCheckTime", "Tue May 10 2011 21:34:31 GMT+0200");
Line deleted: user_pref("ConduitEngine.CTID", "ConduitEngine");
Line deleted: user_pref("ConduitEngine.DialogsGetterLastCheckTime", "Fri May 06 2011 18:31:00 GMT+0200");
Line deleted: user_pref("ConduitEngine.FirstServerDate", "03/27/2011 11");
Line deleted: user_pref("ConduitEngine.FirstTime", true);
Line deleted: user_pref("ConduitEngine.FirstTimeFF3", true);
Line deleted: user_pref("ConduitEngine.HasUserGlobalKeys", true);
Line deleted: user_pref("ConduitEngine.Initialize", true);
Line deleted: user_pref("ConduitEngine.InitializeCommonPrefs", true);
Line deleted: user_pref("ConduitEngine.InstalledDate", "Sun Mar 27 2011 10:21:39 GMT+0200");
Line deleted: user_pref("ConduitEngine.IsMulticommunity", false);
Line deleted: user_pref("ConduitEngine.IsOpenThankYouPage", false);
Line deleted: user_pref("ConduitEngine.IsOpenUninstallPage", true);
Line deleted: user_pref("ConduitEngine.LanguagePackLastCheckTime", "Sun May 08 2011 21:50:06 GMT+0200");
Line deleted: user_pref("ConduitEngine.LastLogin_3.3.3.2", "Sun May 08 2011 21:50:06 GMT+0200");
Line deleted: user_pref("ConduitEngine.SearchFromAddressBarIsInit", true);
Line deleted: user_pref("ConduitEngine.SettingsLastCheckTime", "Sun May 08 2011 21:50:19 GMT+0200");
Line deleted: user_pref("ConduitEngine.UserID", "UN94443869942007641");
Line deleted: user_pref("ConduitEngine.componentAlertEnabled", false);
Line deleted: user_pref("ConduitEngine.engineLocale", "fr");
Line deleted: user_pref("ConduitEngine.engineContextMenuLastCheckTime", "Sun May 08 2011 21:50:06 GMT+0200");
Line deleted: user_pref("ConduitEngine.globalFirstTimeInfoLastCheckTime", "Sun May 08 2011 21:50:06 GMT+0200");
Line deleted: user_pref("ConduitEngine.initDone", true);
Line deleted: user_pref("ConduitEngine.isAppTrackingManagerOn", true);
Line deleted: user_pref("ConduitEngine.usagesFlag", 2);
Line deleted: user_pref("browser.search.defaultengine", "Ask.com");
Line deleted: user_pref("browser.search.defaultenginename", "Ask.com");
Line deleted: user_pref("browser.search.defaulturl", "hxxp://flvdirect.iamwired.net/websearch.php?src=tops&search=...
Line deleted: user_pref("browser.search.order.1", "Ask.com");
Line deleted: user_pref("extensions.asktb.cbid", "RY");
Line deleted: user_pref("extensions.asktb.default-channel-url-mask", "hxxp://www.ask.com/web?q={query}&o={o}&l={l}...
Line deleted: user_pref("extensions.asktb.first-launch-url", "hxxp://www.ccleaner.com/update/?v=2.27.1070&l=1036" )...
Line deleted: user_pref("extensions.asktb.fresh-install", false);
Line deleted: user_pref("extensions.asktb.l", "dis");
Line deleted: user_pref("extensions.asktb.last-config-req", "1285603933370");
Line deleted: user_pref("extensions.asktb.locale", "en_US");
Line deleted: user_pref("extensions.asktb.o", "15184");
Line deleted: user_pref("extensions.asktb.overlay-reloaded-using-restart", true);
Line deleted: user_pref("extensions.asktb.qsrc", "2871");
Line deleted: user_pref("extensions.asktb.r", "2");
Line deleted: user_pref("extensions.asktb.search-plugin-suggestions-url", "hxxp://ss.websearch.ask.com/query?qsrc=...
Line deleted: user_pref("extensions.asktb.search-suggestions-enabled", true);
Line deleted: user_pref("extensions.asktb.search-suggestions-uri", "hxxp://ss.websearch.ask.com/query?qsrc=2922&li...
-- File Closed --

Key deleted: HKLM\Software\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}
Key deleted: HKLM\Software\Classes\CLSID\{27F69C85-64E1-43CE-98B5-3C9F22FB408E}
Key deleted: HKLM\Software\Classes\AppID\{1301A8A5-3DFB-4731-A162-B357D00C9644}
Key deleted: HKLM\Software\Classes\CLSID\{a42b8c5c-9c90-c7a7-3814-28e0bcd9add0}
Key deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a42b8c5c-9c90-c7a7-3814-28e0bcd9add0}
Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{a42b8c5c-9c90-c7a7-3814-28e0bcd9add0}
Key deleted: HKLM\Software\Classes\CLSID\{B543EF05-9758-464E-9F37-4C28525B4A4C}
Key deleted: HKLM\Software\Classes\CLSID\{BB76A90B-2B4C-4378-8506-9A2B6E16943C}
Key deleted: HKLM\Software\Classes\CLSID\{C3AB94A4-BFD0-4BBA-A331-DE504F07D2DB}
Key deleted: HKLM\Software\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key deleted: HKLM\Software\Classes\Interface\{03C390E8-B836-4B82-8D56-1BFDDC06AE8A}
Key deleted: HKLM\Software\Classes\Interface\{2C4470A2-E099-4B9E-ABFE-BBA56D046AFD}
Key deleted: HKLM\Software\Classes\Interface\{391769AE-D8EC-45EC-967D-F5120456E514}
Key deleted: HKLM\Software\Classes\Interface\{39AEF150-C270-4690-AE7D-955E51BC8960}
Key deleted: HKLM\Software\Classes\Interface\{477F210A-2A86-4666-9C4B-1189634D2C84}
Key deleted: HKLM\Software\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Key deleted: HKLM\Software\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Key deleted: HKLM\Software\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Key deleted: HKLM\Software\Classes\Interface\{CD73B1AB-3403-4E47-B196-517C57BE76A2}
Key deleted: HKLM\Software\Classes\Interface\{FF871E51-2655-4D06-AED5-745962A96B32}
Key deleted: HKLM\Software\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
Key deleted: HKLM\Software\Classes\TypeLib\{8F5F1CB6-EA9E-40AF-A5CA-C7FD63CC1971}
Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\c506b3da
Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\QhTuW-
Key deleted: HKLM\Software\Classes\BandooCore.BandooCore
Key deleted: HKLM\Software\Classes\BandooCore.BandooCore.1
Key deleted: HKLM\Software\Classes\BandooCore.ResourcesMngr
Key deleted: HKLM\Software\Classes\BandooCore.ResourcesMngr.1
Key deleted: HKLM\Software\Classes\BandooCore.SettingsMngr
Key deleted: HKLM\Software\Classes\BandooCore.SettingsMngr.1
Key deleted: HKLM\Software\Classes\BandooCore.StatisticMngr
Key deleted: HKLM\Software\Classes\BandooCore.StatisticMngr.1
Key deleted: HKLM\Software\Classes\Conduit.Engine
Key deleted: HKLM\Software\Classes\GenericAskToolbar.ToolbarWnd
Key deleted: HKLM\Software\Classes\GenericAskToolbar.ToolbarWnd.1
Key deleted: HKLM\Software\Classes\Toolbar.CT2504091
Key deleted: HKLM\Software\Classes\Toolbar.CT2542115
Key deleted: HKLM\Software\Classes\AppID\BandooCore.EXE
Key deleted: HKLM\Software\Classes\AppID\GenericAskToolbar.DLL
Key deleted: HKLM\Software\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Key deleted: HKLM\Software\bandoo
Key deleted: HKLM\Software\Conduit
Key deleted: HKCU\Software\Ask.com
Key deleted: HKCU\Software\AskToolbar
Key deleted: HKCU\Software\conduitEngine
Key deleted: HKCU\Software\PriceGong
Key deleted: HKCU\Software\AppDataLow\AskBarDis
Key deleted: HKCU\Software\AppDataLow\AskHomePage
Key deleted: HKCU\Software\AppDataLow\AskToolbarInfo
Key deleted: HKCU\Software\AppDataLow\HavingFunOnline
Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Bandoo
Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Dealio
Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\FLV Direct Player
Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\WhenU
Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Zango
Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Zango Programs
Key deleted: HKLM\Software\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
Key deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF
Key deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
Key deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}
Key deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{557C21FE-7274-410D-853E-9ED4471BF193}
Key deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Key deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{F1B1E52E-E3C3-4B98-9A76-4450479EF8C1}
Key deleted: HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key deleted: HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Key deleted: HKCU\Software\Microsoft\Internet Explorer\MenuExt\Search with search.us
Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}

Value deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0|goicfboogidikkejccmclpieicihhlpo hpfanicgkffmccehnpkikogcffaepkfp
Value deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0|goicfboogidikkejccmclpieicihhlpo dgnckdmmolaijpbbakmplfhlfpdhglgc
Value deleted: HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks|{00000000-6E41-4FD3-8538-502F5495E5FC}
Value deleted: HKLM\Software\Microsoft\Internet Explorer\Toolbar|{D4027C7F-154A-4066-A1AD-4243D8127440}
Value deleted: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser|{D4027C7F-154A-4066-A1AD-4243D8127440}

============== ADDITIONAL SCAN ==============

**** Mozilla Firefox Version [4.0.1 (fr)] ****

Plugins\npdivx32.dll (DivX, Inc.)
Plugins\npDivxPlayerPlugin.dll (DivX, Inc)
Plugins\npsnapfish.dll ( )
Plugins\npunagi2.dll (America Online, Inc.)
HKLM_MozillaPlugins\@garmin.com/GpsControl (x)
Searchplugins\bing.xml ( hxxp://www.bing.com/search)
Components\browsercomps.dll (Mozilla Foundation)
Extensions\{3112ca9c-de6d-4884-a869-9855de68056c} (Google Toolbar for Firefox)
Extensions\{5a085e73-a120-c70f-2540-810f57ee2fe8} (z)
HKLM_Extensions|litmus-ff@f-secure.com - C:\Program Files\Internet Security\NRS\litmus-ff@f-secure.com

-- C:\Documents and Settings\HP_Owner\Application Data\Mozilla\FireFox\Profiles\2kkrg3eh.default --
Extensions\fr@dictionaries.addons.mozilla.org (French dictionary "Reform 1990")
Extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E} (Garmin Communicator)
Extensions\{3112ca9c-de6d-4884-a869-9855de68056c} (Google Toolbar for Firefox)
Extensions\{4daac69c-cba7-45e2-9bc8-1044483d3352} (Softonic_France Community Toolbar)
Searchplugins\LphantWebSearch.xml ( hxxp://search.lphant.com/webResults.html?src=ffb&q={searchTerms}/)
Searchplugins\Search.xml (?)
Prefs.js - browser.download.dir, C:\\Documents and Settings\\HP_Owner\\Desktop
Prefs.js - browser.search.selectedEngine, Google
Prefs.js - browser.startup.homepage, hxxp://www.bluewin.ch/
Prefs.js - browser.startup.homepage_override.buildID, 20110413222027
Prefs.js - browser.startup.homepage_override.mstone, rv:2.0.1
Prefs.js - keyword.URL, hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=

========================================

**** Internet Explorer Version [7.0.5730.13] ****

Plugins\NPEvery.dll (Broderbund)
HKCU_Main|Default_Page_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
HKCU_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU_Main|Search bar - hxxp://go.microsoft.com/fwlink/?linkid=54896
HKCU_Main|Start Page - hxxp://fr.msn.com/
HKLM_Main|Default_Page_URL - hxxp://go.microsoft.com/fwlink/?LinkId=54896
HKLM_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM_Main|Search bar - hxxp://search.msn.com/spbasic.htm
HKLM_Main|Search Page - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM_Main|Start Page - hxxp://fr.msn.com/
HKCU_SearchScopes\{9091C5EC-8529-4EE0-9B0D-96A0520FFB90} - "Search" (hxxp://flvdirect.iamwired.net/websearch.php?src=tops&search={SearchTerms})
HKCU_SearchScopes\{B320F28C-6347-46e4-98FF-5261CA66FEDA} - "Web Search" (hxxp://search.lphant.com/webResults.html?src=ieb&q={searchTerms})
HKCU_Toolbar\ShellBrowser|{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} (x)
HKLM_Toolbar|{327C2873-E90D-4c37-AA9D-10AC9BABA46C} (C:\Program Files\Canon\Easy-WebPrint\Toolband.dll)
HKLM_Toolbar|{265EEE8E-3228-44D3-AEA5-F7FDF5860049} (C:\Program Files\Internet Security\NRS\iescript\baselitmus.dll)
HKLM_ElevationPolicy\2a7a56c0-6991-4c84-a11d-ea1bcd9d89c0 - C:\Program Files\Vuze_Remote\Vuze_RemoteToolbarHelper.exe (x)
HKLM_ElevationPolicy\4fbb75e9-648a-4919-96c3-80d265c43805 - C:\Program Files\Vuze_Remote\Vuze_RemoteToolbarHelper.exe (x)
HKLM_ElevationPolicy\8f0c59f4-ea24-4319-add6-a04fc0e63095 - C:\Program Files\Vuze_Remote\Vuze_RemoteToolbarHelper.exe (x)
HKLM_ElevationPolicy\{1CC6F2D4-61C2-41d9-AF15-1D886DF98B2B} - C:\Program Files\Lphant Applications\Lphant\Lphant.exe (Discordia, LTD)
HKLM_ElevationPolicy\{2A9467B4-C085-11DD-BC92-869555D89593} - C:\Program Files\LphantTb\uninstall.exe (Visicom Media Inc.)
HKLM_ElevationPolicy\{44295CB8-D71B-11DA-8750-001185653D78} - c:\program files\google\googletoolbar2user.exe (?)
HKLM_ElevationPolicy\{F9F9EFDD-8B1F-4D2F-AF13-D7A6CCF1E4C1} - C:\Program Files\Common Files\Motive\McciControlHost.exe (Motive Communications, Inc.)
HKLM_Extensions\{E2D4D26B-0180-43a4-B05F-462D6D54C789} - "Connection Help" (C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\conn_support.ico)
HKLM_Extensions\{e2e2dd38-d088-4134-82b7-f2ba38496583} - "?" (?)
BHO\{02478D38-C3F9-4efb-9B51-7695ECA05670} (?)
BHO\{55BD16AA-37AD-C8C4-0305-060D9C3832CE} - "uberclicks browser extension" (C:\WINDOWS\system32\ndhjdfuzjilvrjrjp.dll)
BHO\{C6867EB7-8350-4856-877F-93CF8AE3DC9C} - "Browsing Protection Class" (C:\Program Files\Internet Security\NRS\iescript\baselitmus.dll)

========================================

C:\Program Files\Ad-Remover\Quarantine: 251 File(s)
C:\Program Files\Ad-Remover\Backup: 27 File(s)

C:\Ad-Report-CLEAN[1].txt - 15/05/2011 17:26:31 (18470 Bytes)

Finished at: 17:28:19, 15/05/2011

============== E.O.F ==============
0
netphilou Posted messages 139 Status Membre 2
 
0
*marc64* Posted messages 218 Status Membre 62
 
Hello,
Restart AD Remover and click on Uninstall

Step 1

* Launch ZHPFix (if you are on Windows Vista or Windows 7, run it by right-clicking --> run as administrator).
* Copy the following lines:

---------------------------------------------------

M3 - MFPP: Plugins - [HP_Owner] -- C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\2kkrg3eh.default\searchplugins\LphantWebSearch.xml
M2 - MFEP: prefs.js [HP_Owner - 2kkrg3eh.default\{4daac69c-cba7-45e2-9bc8-1044483d3352}] [] Softonic_France Community Toolbar v3.3.3.2 (.Conduit Ltd..)
O15 - Trusted Zone: [HKCU\...\Domains] *.chat-land.org
O15 - Trusted Zone: [HKCU\...\Domains\www] *.chat-land.org
[HKCU\Software\Totem]
O43 - CFD: 15.05.2011 - 17:17:24 - [175912] ----D- C:\Program Files\Softonic_France
O43 - CFD: 08.01.2010 - 23:34:48 - [1731411] ----D- C:\Program Files\Spybot - Search & Destroy
O43 - CFD: 18.04.2010 - 08:01:52 - [1509200] ----D- C:\Program Files\vghd
O43 - CFD: 16.11.2008 - 14:44:06 - [801] ----D- C:\Program Files\Common Files\Companion Wizard
O43 - CFD: 15.05.2011 - 17:27:24 - [327] ----D- C:\Documents and Settings\HP_Owner\Local Settings\Application Data\ConduitEngine
O43 - CFD: 15.05.2011 - 17:17:22 - [4589815] ----D- C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Softonic_France
[HKCR\imweb.imwebcontrol]
[HKCR\nctaudiocdwriter2.audiocdwriter2]
[HKCR\nctaudiocdwriter2.audiocdwriter2.1]
[HKCR\Interface\{06DE5702-44CF-4B79-B4EF-3DDF653358F5}]
[HKLM\Software\Classes\Interface\{06DE5702-44CF-4B79-B4EF-3DDF653358F5}]
[HKCR\AppID\{1fc41815-fa4c-4f8b-b143-2c045c8ea2fc}]
[HKLM\Software\Classes\AppID\{1fc41815-fa4c-4f8b-b143-2c045c8ea2fc}]
[HKCR\AppID\{21493C1F-D071-496A-9C27-450578888291}]
[HKLM\Software\Classes\AppID\{21493C1F-D071-496A-9C27-450578888291}]
[HKCR\TypeLib\{2D77AC8A-0A4C-40D0-9557-51907A575E45}]
[HKLM\Software\Classes\TypeLib\{2D77AC8A-0A4C-40D0-9557-51907A575E45}]
[HKCR\Interface\{3EDDA953-1C3B-4823-8F25-D075FBB2D2B5}]
[HKLM\Software\Classes\Interface\{3EDDA953-1C3B-4823-8F25-D075FBB2D2B5}]
[HKCR\AppID\{403A885F-CB00-40C1-BDC1-EB09053194F7}]
[HKCR\TypeLib\{403A885F-CB00-40C1-BDC1-EB09053194F7}]
[HKLM\Software\Classes\AppID\{403A885F-CB00-40C1-BDC1-EB09053194F7}]
[HKLM\Software\Classes\TypeLib\{403A885F-CB00-40C1-BDC1-EB09053194F7}]
[HKCR\TypeLib\{43B4B831-F41F-4F73-8F14-4FFF0BA75B1B}]
[HKLM\Software\Classes\TypeLib\{43B4B831-F41F-4F73-8F14-4FFF0BA75B1B}]
[HKCR\TypeLib\{4C1E5902-FE99-4591-8582-2A2605462857}]
[HKLM\Software\Classes\TypeLib\{4C1E5902-FE99-4591-8582-2A2605462857}]
[HKCR\AppID\{55C1727F-5535-4C2A-9601-8C2458608B48}]
[HKCR\TypeLib\{55C1727F-5535-4C2A-9601-8C2458608B48}]
[HKLM\Software\Classes\AppID\{55C1727F-5535-4C2A-9601-8C2458608B48}]
[HKLM\Software\Classes\TypeLib\{55C1727F-5535-4C2A-9601-8C2458608B48}]
[HKCR\CLSID\{5C00A371-2011-4AF3-97C8-6CE66AA744CB}]
[HKLM\Software\Classes\CLSID\{5C00A371-2011-4AF3-97C8-6CE66AA744CB}]
[HKCR\AppID\{5e50ae1d-bc76-418b-94c4-efeac0cef80c}]
[HKLM\Software\Classes\AppID\{5e50ae1d-bc76-418b-94c4-efeac0cef80c}]
[HKCR\AppID\{69E54DE2-C4ED-4BEC-8046-E3F9AC74B4B0}]
[HKLM\Software\Classes\AppID\{69E54DE2-C4ED-4BEC-8046-E3F9AC74B4B0}]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6A87B991-A31F-4130-AE72-6D0C294BF082}]
[HKCR\TypeLib\{6C9945B7-1D19-46CB-88C0-45A24DF6CD6E}]
[HKLM\Software\Classes\TypeLib\{6C9945B7-1D19-46CB-88C0-45A24DF6CD6E}]
[HKCR\TypeLib\{81ca8fcd-1420-4a07-b47d-b30f3dda79e1}]
[HKLM\Software\Classes\TypeLib\{81ca8fcd-1420-4a07-b47d-b30f3dda79e1}]
[HKCR\TypeLib\{84B9B044-17C0-48FB-A300-C9747D5DF29C}]
[HKLM\Software\Classes\TypeLib\{84B9B044-17C0-48FB-A300-C9747D5DF29C}]
[HKCR\TypeLib\{85672EDB-2CC8-40B9-A9E8-77D3478F2EFB}]
[HKLM\Software\Classes\TypeLib\{85672EDB-2CC8-40B9-A9E8-77D3478F2EFB}]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{872F3C0B-4462-424c-BB9F-74C6899B9F92}]
[HKCR\CLSID\{9F038672-0425-4792-BC9C-36DE3308E8AA}]
[HKLM\Software\Classes\CLSID\{9F038672-0425-4792-BC9C-36DE3308E8AA}]
[HKCR\AppID\{A7DDCBDE-5C86-415c-8A37-763AE183E7E4}]
[HKLM\Software\Classes\AppID\{A7DDCBDE-5C86-415c-8A37-763AE183E7E4}]
[HKCR\AppID\{AD71F65D-CD13-4837-A2DC-E4D90020E7D4}]
[HKLM\Software\Classes\AppID\{AD71F65D-CD13-4837-A2DC-E4D90020E7D4}]
[HKCR\Interface\{B67A4CBA-520A-43DB-B03F-414E539F90EC}]
[HKLM\Software\Classes\Interface\{B67A4CBA-520A-43DB-B03F-414E539F90EC}]
[HKCR\CLSID\{B6F8DA9F-2696-419e-A8A3-19BE41EF51BD}]
[HKLM\Software\Classes\CLSID\{B6F8DA9F-2696-419e-A8A3-19BE41EF51BD}]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B6F8DA9F-2696-419e-A8A3-19BE41EF51BD}]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F}]
[HKCR\CLSID\{E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F}]
[HKLM\Software\Classes\CLSID\{E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F}]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{e908b145-c847-4e85-b315-07e2e70decf8}]
[HKCR\AppID\{F54A0D21-6A53-460C-8301-C694EC9E1033}]
[HKLM\Software\Classes\AppID\{F54A0D21-6A53-460C-8301-C694EC9E1033}]
[HKCR\AppID\{F7BCCFD4-2FA6-477D-A1B0-EF7500B3C49E}]
[HKLM\Software\Classes\AppID\{F7BCCFD4-2FA6-477D-A1B0-EF7500B3C49E}]
[HKCR\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF]
[HKLM\Software\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF]
[HKCR\Installer\UpgradeCodes\CC94835868BCA58489B0D79DE655BCB1]
EmptyTemp
EmptyFlash

---------------------------------------------------

* * Click on the icon representing the letter H (“paste Helper lines”)
* The lines will automatically be pasted into ZHPFix.
* Click on the "GO" button to start the cleanup,
* Copy/paste the entire report in your next response

Post the report saved in this folder (via Cjoint please) -> ( C:\Program files\ZHPFix\ZHPFixReport.txt )

Step 2
[*] Download Malwarebytes

[*] You will have a tutorial available to install and use it correctly.

[*]Update the software (this usually happens during installation)

[*] Run a full scan by clicking on "Run a full scan"

[*] Select all your local and removable drives and click on "Start scan"

[*] The scan may take a while.....

[*] Once the scan is complete, click "OK" and then "Show results"

[*] Ensure everything is checked and click on "Remove selected" => and then click "OK"

[*] A report will open in Notepad... Copy/paste the report in your next response on the forum

* Some files may need to be deleted at the next PC restart... Do so by clicking "yes" to the prompt
0
netphilou Posted messages 139 Status Membre 2
 
Good evening,

I tried to do what you asked me. Below is the report (I did a copy-paste because I don't know where to find "attached") I hope it will be fine, otherwise, please give me more details (I am ignorant in this area)
Thanks again for your help and patience.
Best regards.

Netphilou

HKCR\imweb.imwebcontrol => Key successfully deleted
HKCR\nctaudiocdwriter2.audiocdwriter2 => Key successfully deleted
HKCR\nctaudiocdwriter2.audiocdwriter2.1 => Key successfully deleted
HKCR\Interface\{06DE5702-44CF-4B79-B4EF-3DDF653358F5} => Key successfully deleted
HKLM\Software\Classes\Interface\{06DE5702-44CF-4B79-B4EF-3DDF653358F5} => Key missing
HKCR\AppID\{1fc41815-fa4c-4f8b-b143-2c045c8ea2fc} => Key successfully deleted
HKLM\Software\Classes\AppID\{1fc41815-fa4c-4f8b-b143-2c045c8ea2fc} => Key missing
HKCR\AppID\{21493C1F-D071-496A-9C27-450578888291} => Key successfully deleted
HKLM\Software\Classes\AppID\{21493C1F-D071-496A-9C27-450578888291} => Key missing
HKCR\TypeLib\{2D77AC8A-0A4C-40D0-9557-51907A575E45} => Key successfully deleted
HKLM\Software\Classes\TypeLib\{2D77AC8A-0A4C-40D0-9557-51907A575E45} => Key missing
HKCR\Interface\{3EDDA953-1C3B-4823-8F25-D075FBB2D2B5} => Key successfully deleted
HKLM\Software\Classes\Interface\{3EDDA953-1C3B-4823-8F25-D075FBB2D2B5} => Key missing
HKCR\AppID\{403A885F-CB00-40C1-BDC1-EB09053194F7} => Key successfully deleted
HKCR\TypeLib\{403A885F-CB00-40C1-BDC1-EB09053194F7} => Key successfully deleted
HKLM\Software\Classes\AppID\{403A885F-CB00-40C1-BDC1-EB09053194F7} => Key missing
HKLM\Software\Classes\TypeLib\{403A885F-CB00-40C1-BDC1-EB09053194F7} => Key missing
HKCR\TypeLib\{43B4B831-F41F-4F73-8F14-4FFF0BA75B1B} => Key successfully deleted
HKLM\Software\Classes\TypeLib\{43B4B831-F41F-4F73-8F14-4FFF0BA75B1B} => Key missing
HKCR\TypeLib\{4C1E5902-FE99-4591-8582-2A2605462857} => Key successfully deleted
HKLM\Software\Classes\TypeLib\{4C1E5902-FE99-4591-8582-2A2605462857} => Key missing
HKCR\AppID\{55C1727F-5535-4C2A-9601-8C2458608B48} => Key successfully deleted
HKCR\TypeLib\{55C1727F-5535-4C2A-9601-8C2458608B48} => Key successfully deleted
HKLM\Software\Classes\AppID\{55C1727F-5535-4C2A-9601-8C2458608B48} => Key missing
HKLM\Software\Classes\TypeLib\{55C1727F-5535-4C2A-9601-8C2458608B48} => Key missing
HKCR\CLSID\{5C00A371-2011-4AF3-97C8-6CE66AA744CB} => Key successfully deleted
HKLM\Software\Classes\CLSID\{5C00A371-2011-4AF3-97C8-6CE66AA744CB} => Key missing
HKCR\AppID\{5e50ae1d-bc76-418b-94c4-efeac0cef80c} => Key successfully deleted
HKLM\Software\Classes\AppID\{5e50ae1d-bc76-418b-94c4-efeac0cef80c} => Key missing
HKCR\AppID\{69E54DE2-C4ED-4BEC-8046-E3F9AC74B4B0} => Key successfully deleted
HKLM\Software\Classes\AppID\{69E54DE2-C4ED-4BEC-8046-E3F9AC74B4B0} => Key missing
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6A87B991-A31F-4130-AE72-6D0C294BF082} => Key successfully deleted
HKCR\TypeLib\{6C9945B7-1D19-46CB-88C0-45A24DF6CD6E} => Key successfully deleted
HKLM\Software\Classes\TypeLib\{6C9945B7-1D19-46CB-88C0-45A24DF6CD6E} => Key missing
HKCR\TypeLib\{81ca8fcd-1420-4a07-b47d-b30f3dda79e1} => Key successfully deleted
HKLM\Software\Classes\TypeLib\{81ca8fcd-1420-4a07-b47d-b30f3dda79e1} => Key missing
HKCR\TypeLib\{84B9B044-17C0-48FB-A300-C9747D5DF29C} => Key successfully deleted
HKLM\Software\Classes\TypeLib\{84B9B044-17C0-48FB-A300-C9747D5DF29C} => Key missing
HKCR\TypeLib\{85672EDB-2CC8-40B9-A9E8-77D3478F2EFB} => Key successfully deleted
HKLM\Software\Classes\TypeLib\{85672EDB-2CC8-40B9-A9E8-77D3478F2EFB} => Key missing
HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{872F3C0B-4462-424c-BB9F-74C6899B9F92} => Key successfully deleted
HKCR\CLSID\{9F038672-0425-4792-BC9C-36DE3308E8AA} => Key successfully deleted
HKLM\Software\Classes\CLSID\{9F038672-0425-4792-BC9C-36DE3308E8AA} => Key missing
HKCR\AppID\{A7DDCBDE-5C86-415c-8A37-763AE183E7E4} => Key successfully deleted
HKLM\Software\Classes\AppID\{A7DDCBDE-5C86-415c-8A37-763AE183E7E4} => Key missing
HKCR\AppID\{AD71F65D-CD13-4837-A2DC-E4D90020E7D4} => Key successfully deleted
HKLM\Software\Classes\AppID\{AD71F65D-CD13-4837-A2DC-E4D90020E7D4} => Key missing
HKCR\Interface\{B67A4CBA-520A-43DB-B03F-414E539F90EC} => Key successfully deleted
HKLM\Software\Classes\Interface\{B67A4CBA-520A-43DB-B03F-414E539F90EC} => Key missing
HKCR\CLSID\{B6F8DA9F-2696-419e-A8A3-19BE41EF51BD} => Key successfully deleted
HKLM\Software\Classes\CLSID\{B6F8DA9F-2696-419e-A8A3-19BE41EF51BD} => Key missing
HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B6F8DA9F-2696-419e-A8A3-19BE41EF51BD} => Key successfully deleted
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} => Key successfully deleted
HKCR\CLSID\{E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} => Key successfully deleted
HKLM\Software\Classes\CLSID\{E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} => Key missing
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{e908b145-c847-4e85-b315-07e2e70decf8} => Key successfully deleted
HKCR\AppID\{F54A0D21-6A53-460C-8301-C694EC9E1033} => Key successfully deleted
HKLM\Software\Classes\AppID\{F54A0D21-6A53-460C-8301-C694EC9E1033} => Key missing
HKCR\AppID\{F7BCCFD4-2FA6-477D-A1B0-EF7500B3C49E} => Key successfully deleted
HKLM\Software\Classes\AppID\{F7BCCFD4-2FA6-477D-A1B0-EF7500B3C49E} => Key missing
HKCR\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF => Key successfully deleted
HKLM\Software\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF => Key missing
HKCR\Installer\UpgradeCodes\CC94835868BCA58489B0D79DE655BCB1 => Key successfully deleted

========== Registry Value(s) ==========
O15 - Trusted Zone: [HKCU\...\Domains\http://www] *.chat-land.org => Value missing

========== Registry Data Item(s) ==========
O15 - Trusted Zone: [HKCU\...\Domains] *.chat-land.org => Data successfully deleted

========== Folder(s) ==========
C:\Documents and Settings\HP_Propriétaire\Application Data\Mozilla\Firefox\Profiles\2kkrg3eh.default\extensions\{4daac69c-cba7-45e2-9bc8-1044483d3352} => Deleted and quarantined
C:\Program Files\Softonic_France => Deleted and quarantined
C:\Program Files\Spybot - Search & Destroy => File deleted at reboot
C:\Program Files\vghd => Deleted and quarantined
C:\Program Files\Common Files\Companion Wizard => Deleted and quarantined
C:\Documents and Settings\HP_Propriétaire\Local Settings\Application Data\ConduitEngine => Deleted and quarantined
C:\Documents and Settings\HP_Propriétaire\Local Settings\Application Data\Softonic_France => Deleted and quarantined

========== File(s) ==========
c:\documents and settings\hp_propriétaire\application data\mozilla\firefox\profiles\2kkrg3eh.default\searchplugins\lphantwebsearch.xml => File missing

========== Summary ==========
64 : Registry Key(s)
1 : Registry Value(s)
1 : Registry Data Item(s)
7 : Folder(s)
1 : File(s)

End of the scan
0
*marc64* Posted messages 218 Status Membre 62
 
Hi,
For Malwarebyte's, you will find the .txt report by following this procedure:
-Open Malwarebyte's
-Click on Reports/Logs
-Double-click on mbam-log, the notepad will open
-Select all and copy/paste the report in your next response

all functions are slow and a message "out of memory on line 2" keeps appearing on my desktop. 

What is the status of this issue currently?
0
netphilou Posted messages 139 Status Membre 2
 
Hello,
Actually, I had already used Malwarebytes in the meantime and the infected files have been cleaned. Here is the latest report anyway. Since the cleanup, I no longer have any ad pages and I don't see the "at memory..." message anymore. However, I still can't open Firefox! And I'm still getting the same message "oops, Firefox crashed..."
Thanks again
Best regards

Netphilou

www.malwarebytes.org

Database version: 6589

Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13

05/17/2011 21:11:11
mbam-log-2011-05-17 (21-11-11).txt

Scan type: Full scan (C:\|D:\|E:\|F:\|G:\|H:\|I:\|J:\|K:\|N:\|)
Item(s) scanned: 389731
Elapsed time: 2 hour(s), 33 minute(s), 16 second(s)

Infected memory process(es): 0
Infected memory module(s): 0
Infected Registry key(s): 0
Infected Registry value(s): 0
Infected Registry data item(s): 0
Infected folder(s): 0
Infected file(s): 0

Infected memory process(es):
(No harmful items detected)

Infected memory module(s):
(No harmful items detected)

Infected Registry key(s):
(No harmful items detected)

Infected Registry value(s):
(No harmful items detected)

Infected Registry data item(s):
(No harmful items detected)
0
*marc64* Posted messages 218 Status Membre 62
 
- Please post a new ZHPDiag report via Cjoint.

For Firefox.
If you've sent crash reports, do the following:
* type about:crashes in the address bar and press Enter
* you should get this:

http://www.zimagez.com/zimage/2009-11-04161231.php

* Click on the report IDs to open them

http://www.zimagez.com/zimage/2009-11-04162509.php

* If you have multiple, include 2 or 3

If that doesn't work in normal mode, close Firefox and launch it in safe mode without checking anything (Shift + Firefox icon)
0
netphilou Posted messages 139 Status Membre 2
 
Here are two of the reports.
A+

Mozilla Crash Reports

Product:
Report:

Advanced Search
Firefox 4.0.1 Crash Report [@ mozalloc_abort(char const* const) | NS_DebugBreak_P | nsCycleCollectingAutoRefCnt::decr(nsISupports*) ]
Search Mozilla Support for Help
ID: f5e4ea48-3048-47af-8055-bb7762110518
Signature: mozalloc_abort(char const* const) | NS_DebugBreak_P | nsCycleCollectingAutoRefCnt::decr(nsISupports*)

Details
Modules
Raw Dump
Extensions
Comments
Correlations

Signature mozalloc_abort(char const* const) | NS_DebugBreak_P | nsCycleCollectingAutoRefCnt::decr(nsISupports*)
UUID f5e4ea48-3048-47af-8055-bb7762110518
Uptime
Last Crash 75121 seconds (20.9 hours) before submission
Install Age 893001 seconds (1.5 weeks) since version was first installed.
Install Time 2011-05-08 08:27:45
Product Firefox
Version 4.0.1
Build ID 20110413222027
Release Channel release
Branch 2.0
OS Windows NT
OS Version 5.1.2600 Service Pack 3
CPU x86
CPU Info GenuineIntel family 15 model 4 stepping 1
Crash Reason EXCEPTION_BREAKPOINT
Crash Address 0x3f1a39
User Comments
App Notes AdapterVendorID: 10de, AdapterDeviceID: 0162, AdapterDriverVersion: 7.7.7.9
D3D10 Layers? D3D10 Layers-
D3D9 Layers? D3D9 Layers-
xpcom_runtime_abort(###!!! ABORT: Main-thread-only object used off the main thread: file e:/builds/moz2_slave/rel-2.0-w32-bld/build/xpcom/base/nsCycleCollector.cpp, line 1195)
Processor Notes
EMCheckCompatibility True
Winsock LSP MSAFD Tcpip [TCP/IP] : 2 : 1 : MSAFD Tcpip [UDP/IP] : 2 : 2 : MSAFD Tcpip [RAW/IP] : 2 : 3 : RSVP UDP Service Provider : 6 : 2 : RSVP TCP Service Provider : 6 : 1 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{B0DF61DC-37C8-463A-BDD5-EEAF141F9FB7}] SEQPACKET 8 : 2 : 5 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{B0DF61DC-37C8-463A-BDD5-EEAF141F9FB7}] DATAGRAM 8 : 2 : 2 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{7311E81C-00F2-4AA3-94A5-C5A7EC25082F}] SEQPACKET 7 : 2 : 5 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{7311E81C-00F2-4AA3-94A5-C5A7EC25082F}] DATAGRAM 7 : 2 : 2 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{3F36D747-77D9-4CA0-A856-1777C0EFF934}] SEQPACKET 6 : 2 : 5 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{3F36D747-77D9-4CA0-A856-1777C0EFF934}] DATAGRAM 6 : 2 : 2 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{2B0B9A7C-4C74-4F27-A8B1-6456C30027AF}] SEQPACKET 5 : 2 : 5 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{2B0B9A7C-4C74-4F27-A8B1-6456C30027AF}] DATAGRAM 5 : 2 : 2 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{950DBBCB-0955-4705-A9F5-7C74FCD37A5D}] SEQPACKET 4 : 2 : 5 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{950DBBCB-0955-4705-A9F5-7C74FCD37A5D}] DATAGRAM 4 : 2 : 2 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{36E5B2A8-0B1C-4161-836B-508331E1C3D3}] SEQPACKET 1 : 2 : 5 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{36E5B2A8-0B1C-4161-836B-508331E1C3D3}] DATAGRAM 1 : 2 : 2 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{DE246E2C-8697-44FE-A5BB-FA04D12D4DEC}] SEQPACKET 0 : 2 : 5 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{DE246E2C-8697-44FE-A5BB-FA04D12D4DEC}] DATAGRAM 0 : 2 : 2 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{E658C067-685E-4840-9EC2-ADC9EA7F2B73}] SEQPACKET 2 : 2 : 5 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{E658C067-685E-4840-9EC2-ADC9EA7F2B73}] DATAGRAM 2 : 2 : 2 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{89939DAA-FFF0-44C3-855E-96DF39B920E1}] SEQPACKET 3 : 2 : 5 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{89939DAA-FFF0-44C3-855E-96DF39B920E1}] DATAGRAM 3 : 2 : 2 :
Adapter Vendor ID
Adapter Device ID
Bugzilla - Report this Crash
Related Bugs

OPEN

633445 NEW Crash [@ mozalloc_abort(char const* const) | NS_DebugBreak_P | nsCycleCollectingAutoRefCnt::decr(nsISupports*) ] [@ mozalloc_abort(char const* const) | NS_DebugBreak_P | AbortIfOffMainThreadIfCheckFast ]

Crashing Thread
Frame Module Signature [Expand] Source
0 mozalloc.dll mozalloc_abort memory/mozalloc/mozalloc_abort.cpp:77
1 xul.dll NS_DebugBreak_P xpcom/base/nsDebugImpl.cpp:350
2 xul.dll nsCycleCollectingAutoRefCnt::decr
3 xul.dll nsGenericElement::Release content/base/src/nsGenericElement.cpp:4505
4 a42e9b8f.dll a42e9b8f.dll@0x325a2
5 a42e9b8f.dll a42e9b8f.dll@0x224b7
6 a42e9b8f.dll a42e9b8f.dll@0x1adb0a
7 a42e9b8f.dll a42e9b8f.dll@0x13a7
8 a42e9b8f.dll a42e9b8f.dll@0xebf8
9 a42e9b8f.dll a42e9b8f.dll@0x13615
10 a42e9b8f.dll a42e9b8f.dll@0x1ae5e7
11 a42e9b8f.dll a42e9b8f.dll@0xfde8
12 a42e9b8f.dll a42e9b8f.dll@0x1aef9f
13 a42e9b8f.dll a42e9b8f.dll@0x649cd
14 ntdll.dll RtlAllocateHeap
15 nss3.dll PKIX_RevocationChecker_Create security/nss/lib/libpkix/pkix/checker/pkix_revocationchecker.c:210
16 nss3.dll CERT_FindNameConstraintsExten security/nss/lib/certdb/genname.c:1570
17 mozjs.dll js::mjit::ic::BindName js/src/methodjit/PolyIC.cpp:1933
18 ntdll.dll RtlFreeHeap
19 a42e9b8f.dll a42e9b8f.dll@0x13ad92
20 a42e9b8f.dll a42e9b8f.dll@0x1b53d5
21 a42e9b8f.dll a42e9b8f.dll@0x64ff5
22 ntdll.dll RtlFreeHeap
23 mozjs.dll BindNameToSlot js/src/jsemit.cpp:2225
24 nss3.dll pkix_pl_PrimHashTable_Remove security/nss/lib/libpkix/pkix_pl_nss/system/pkix_pl_primhash.c:345
25 ssl3.dll ssl_ConfigSecureServer security/nss/lib/ssl/sslsecur.c:723
26 a42e9b8f.dll a42e9b8f.dll@0x1c604f
27 a42e9b8f.dll a42e9b8f.dll@0x1c61b7
28 a42e9b8f.dll a42e9b8f.dll@0x1c6531
29 a42e9b8f.dll a42e9b8f.dll@0x1c03e4
30 a42e9b8f.dll a42e9b8f.dll@0x1c0ebd
31 a42e9b8f.dll a42e9b8f.dll@0x1b7bc0
32 a42e9b8f.dll a42e9b8f.dll@0x1b7f65
33 a42e9b8f.dll a42e9b8f.dll@0x1b31ff
34 a42e9b8f.dll a42e9b8f.dll@0x1c6b6f
35 kernel32.dll GetCodePageFileInfo
36 kernel32.dll BaseThreadStart
37 a42e9b8f.dll a42e9b8f.dll@0x15c7ff

Show/hide other threads
Mozilla Crash Reports - Powered by Socorro

Server Status
Project Info
Source Code
Breakpad Wiki
Privacy Policy

Mozilla Crash Reports

Product:
Report:

Advanced Search
Firefox 4.0.1 Crash Report [@ mozalloc_abort(char const* const) | NS_DebugBreak_P | nsCycleCollectingAutoRefCnt::decr(nsISupports*) ]
Search Mozilla Support for Help
ID: 2e57dc9e-c37a-4fb3-8079-ab36c2110516
Signature: mozalloc_abort(char const* const) | NS_DebugBreak_P | nsCycleCollectingAutoRefCnt::decr(nsISupports*)

Details
Modules
Raw Dump
Extensions
Comments
Correlations

Signature mozalloc_abort(char const* const) | NS_DebugBreak_P | nsCycleCollectingAutoRefCnt::decr(nsISupports*)
UUID 2e57dc9e-c37a-4fb3-8079-ab36c2110516
Uptime
Last Crash 102405 seconds (1.2 days) before submission
Install Age 734457 seconds (1.2 weeks) since version was first installed.
Install Time 2011-05-08 08:27:45
Product Firefox
Version 4.0.1
Build ID 20110413222027
Release Channel release
Branch 2.0
OS Windows NT
OS Version 5.1.2600 Service Pack 3
CPU x86
CPU Info GenuineIntel family 15 model 4 stepping 1
Crash Reason EXCEPTION_BREAKPOINT
Crash Address 0x3f1a39
User Comments
App Notes AdapterVendorID: 10de, AdapterDeviceID: 0162, AdapterDriverVersion: 7.7.7.9
D3D10 Layers? D3D10 Layers-
D3D9 Layers? D3D9 Layers-
xpcom_runtime_abort(###!!! ABORT: Main-thread-only object used off the main thread: file e:/builds/moz2_slave/rel-2.0-w32-bld/build/xpcom/base/nsCycleCollector.cpp, line 1195)
Processor Notes
EMCheckCompatibility True
Winsock LSP MSAFD Tcpip [TCP/IP] : 2 : 1 : MSAFD Tcpip [UDP/IP] : 2 : 2 : MSAFD Tcpip [RAW/IP] : 2 : 3 : RSVP UDP Service Provider : 6 : 2 : RSVP TCP Service Provider : 6 : 1 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{B0DF61DC-37C8-463A-BDD5-EEAF141F9FB7}] SEQPACKET 8 : 2 : 5 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{B0DF61DC-37C8-463A-BDD5-EEAF141F9FB7}] DATAGRAM 8 : 2 : 2 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{7311E81C-00F2-4AA3-94A5-C5A7EC25082F}] SEQPACKET 7 : 2 : 5 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{7311E81C-00F2-4AA3-94A5-C5A7EC25082F}] DATAGRAM 7 : 2 : 2 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{3F36D747-77D9-4CA0-A856-1777C0EFF934}] SEQPACKET 6 : 2 : 5 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{3F36D747-77D9-4CA0-A856-1777C0EFF934}] DATAGRAM 6 : 2 : 2 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{2B0B9A7C-4C74-4F27-A8B1-6456C30027AF}] SEQPACKET 5 : 2 : 5 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{2B0B9A7C-4C74-4F27-A8B1-6456C30027AF}] DATAGRAM 5 : 2 : 2 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{950DBBCB-0955-4705-A9F5-7C74FCD37A5D}] SEQPACKET 4 : 2 : 5 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{950DBBCB-0955-4705-A9F5-7C74FCD37A5D}] DATAGRAM 4 : 2 : 2 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{36E5B2A8-0B1C-4161-836B-508331E1C3D3}] SEQPACKET 1 : 2 : 5 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{36E5B2A8-0B1C-4161-836B-508331E1C3D3}] DATAGRAM 1 : 2 : 2 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{DE246E2C-8697-44FE-A5BB-FA04D12D4DEC}] SEQPACKET 0 : 2 : 5 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{DE246E2C-8697-44FE-A5BB-FA04D12D4DEC}] DATAGRAM 0 : 2 : 2 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{E658C067-685E-4840-9EC2-ADC9EA7F2B73}] SEQPACKET 2 : 2 : 5 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{E658C067-685E-4840-9EC2-ADC9EA7F2B73}] DATAGRAM 2 : 2 : 2 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{89939DAA-FFF0-44C3-855E-96DF39B920E1}] SEQPACKET 3 : 2 : 5 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{89939DAA-FFF0-44C3-855E-96DF39B920E1}] DATAGRAM 3 : 2 : 2 :
Adapter Vendor ID
Adapter Device ID
Bugzilla - Report this Crash
Related Bugs

OPEN

633445 NEW Crash [@ mozalloc_abort(char const* const) | NS_DebugBreak_P | nsCycleCollectingAutoRefCnt::decr(nsISupports*) ] [@ mozalloc_abort(char const* const) | NS_DebugBreak_P | AbortIfOffMainThreadIfCheckFast ]

Crashing Thread
Frame Module Signature [Expand] Source
0 mozalloc.dll mozalloc_abort memory/mozalloc/mozalloc_abort.cpp:77
1 xul.dll NS_DebugBreak_P xpcom/base/nsDebugImpl.cpp:350
2 xul.dll nsCycleCollectingAutoRefCnt::decr
3 xul.dll nsGlobalWindow::Release dom/base/nsGlobalWindow.cpp:1335
4 a42e9b8f.dll a42e9b8f.dll@0x325a2
5 a42e9b8f.dll a42e9b8f.dll@0x14a7
6 a42e9b8f.dll a42e9b8f.dll@0x1af171
7 a42e9b8f.dll a42e9b8f.dll@0x23fe7
8 a42e9b8f.dll a42e9b8f.dll@0xebf8
9 a42e9b8f.dll a42e9b8f.dll@0xde0c8
10 a42e9b8f.dll a42e9b8f.dll@0x1be14a
11 a42e9b8f.dll a42e9b8f.dll@0xde0f7
12 a42e9b8f.dll a42e9b8f.dll@0x15c426
13 a42e9b8f.dll a42e9b8f.dll@0x1c6aef
14 a42e9b8f.dll a42e9b8f.dll@0x15c91c
15 ntdll.dll RtlpGetRegistrationHead
16 a42e9b8f.dll a42e9b8f.dll@0x1c6b6f
17 kernel32.dll BaseThreadStart
18 ntdll.dll RtlpGetRegistrationHead
19 kernel32.dll GetCodePageFileInfo
20 kernel32.dll BaseThreadStart
21 a42e9b8f.dll a42e9b8f.dll@0x15c7ff

Show/hide other threads
Mozilla Crash Reports - Powered by Socorro

Server Status
Project Info
Source Code
Breakpad Wiki
Privacy Policy

Log In

Log In
0
*marc64* Posted messages 218 Status Membre 62
 
-Please post a new ZHPDiag report, please (still via Cjoint).
0
netphilou Posted messages 139 Status Membre 2
 
Here I am again!
Have a nice evening

Netphilou

https://www.cjoint.com/?AEswfoQWA2i
0
*marc64* Posted messages 218 Status Membre 62
 
Sorry, but your link doesn't point to anything

Launch ZHPDiag and click on the icon with an arrow (to the left of the screwdriver)
Once the update is complete, run a scan again and post a new report, please (still via Cjoint)

- Click on Browse to find the report
- Click on Open then Create Cjoint link

- In your next response, copy and paste the link that is displayed in front... The link has been created:
0
netphilou Posted messages 139 Status Membre 2
 
Good evening,
I hope that this time, I did the right manipulation.
Best regards

Netphilou

https://www.cjoint.com/?AEtrPTa1k8S
0
*marc64* Posted messages 218 Status Membre 62
 
Sorry for the delay,

Attention, uninstalling software will be requested; please accept this but refuse any PC restart to avoid interrupting the fix.

* Launch ZHPFix (if you are on Windows Vista or Windows 7, run it by right-clicking on it --> run as administrator).
* Copy the following lines:

---------------------------------------------------
O42 - Software: Adobe Acrobat 5.0 - (.Adobe Systems, Inc..) [HKLM] -- Adobe Acrobat 5.0
O42 - Software: J2SE Runtime Environment 5.0 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0150000}
O42 - Software: Java(TM) 6 Update 17 - (.Sun Microsystems, Inc..) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83216011FF}
O42 - Software: Java(TM) 6 Update 2 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0160020}
O42 - Software: Java(TM) 6 Update 3 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0160030}
O42 - Software: Java(TM) 6 Update 4 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0160040}
O42 - Software: Java(TM) 6 Update 5 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0160050}
O42 - Software: Java(TM) 6 Update 7 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0160070}
O42 - Software: Java(TM) SE Runtime Environment 6 Update 1 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0160010}
[HKLM\Software\Classes\AppID\SoftwareUpdate.exe]
O69 - SBI: SearchScopes [HKCU] {9091C5EC-8529-4EE0-9B0D-96A0520FFB90} - (Search) - http://flvdirect.iamwired.net
O69 - SBI: SearchScopes [HKCU] {B320F28C-6347-46e4-98FF-5261CA66FEDA} - (Web Search) - http://search.shareazaweb.net/
EmptyTemp
EmptyFlash

---------------------------------------------------

* * Click on the icon representing the letter H (“paste Helper lines”)
* The lines will automatically paste into ZHPFix.
* Click the “GO” button to start the cleanup,
* Copy/paste the entire report into your next response

Post the report that is saved in this folder -> ( C:\Program files\ZHPFix\ZHPFixReport.txt )

********************************************************
I see that you have the software Alcohol but for safety reasons
please analyze this file using Virus Total
-Click on browse and open this file
--------------------------------------------------
C:\PhysicalDisk0_MBR.bin
--------------------------------------------------
-click on Send
Once the analysis is complete
copy/paste the link found in the address bar in your next response
0
netphilou Posted messages 139 Status Membre 2
 
Hello,
Here is the report

ZHPFix Report 1.12.3283 by Nicolas Coolman, Update of 14/05/2011
Registry export file: C:\ZHPExportRegistry-22.05.2011-12-59-10.txt
Run by HP_Owner at 22.05.2011 12:59:10
Windows XP Home Edition Service Pack 3 (Build 2600)
Web site: http://www.premiumorange.com/zeb-help-process/zhpfix.html

========== Registry Key(s) ==========
O42 - Software: J2SE Runtime Environment 5.0 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0150000} => Software uninstallation canceled by user or partial uninstallation!
O42 - Software: Java(TM) 6 Update 17 - (.Sun Microsystems, Inc..) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83216011FF} => Software uninstallation canceled by user or partial uninstallation!
O42 - Software: Java(TM) 6 Update 2 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0160020} => Software uninstallation canceled by user or partial uninstallation!
O42 - Software: Java(TM) 6 Update 3 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0160030} => Software uninstallation canceled by user or partial uninstallation!
O42 - Software: Java(TM) 6 Update 4 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0160040} => Software uninstallation canceled by user or partial uninstallation!
O42 - Software: Java(TM) 6 Update 5 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0160050} => Software uninstallation canceled by user or partial uninstallation!
O42 - Software: Java(TM) 6 Update 7 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0160070} => Software uninstallation canceled by user or partial uninstallation!
O42 - Software: Java(TM) SE Runtime Environment 6 Update 1 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0160010} => Software uninstallation canceled by user or partial uninstallation!
HKLM\Software\Classes\AppID\SoftwareUpdate.exe => Key successfully deleted
O69 - SBI: SearchScopes [HKCU] {9091C5EC-8529-4EE0-9B0D-96A0520FFB90} - (Search) - http://flvdirect.iamwired.net => Key successfully deleted
O69 - SBI: SearchScopes [HKCU] {B320F28C-6347-46e4-98FF-5261CA66FEDA} - (Web Search) - http://search.shareazaweb.net/ => Key successfully deleted

========== Folder(s) ==========
Windows temporary folders deleted: 1620
Flash Cookies folders deleted: 351

========== File(s) ==========
Windows temporary files deleted: 52
Flash Cookies files deleted: 143

========== Summary ==========
11 : Registry Key(s)
2 : Folder(s)
2 : File(s)

End of the scan
0
netphilou Posted messages 139 Status Membre 2
 
Je suis désolé, mais je ne peux pas accéder ou traduire des contenus à partir de liens externes.
0
  • 1
  • 2