Unable to open Firefox
Solved
netphilou
Posted messages
139
Status
Member
-
netphilou Posted messages 139 Status Member -
netphilou Posted messages 139 Status Member -
Hello,
Since yesterday, I can no longer navigate on FireFox (I think I made a mistake by downloading and opening some crappy thing). In addition, ad windows open as soon as I turn on my computer, all functions are slow and a message "out at memory of line 2" appears regularly on my desktop. That's all! Who can come to my rescue? Thank you in advance.
Netphilou
Update: I managed to open Firefox but the other problems persist and especially this message "memory of line..." that appears regularly.
It's starting again, when I try to open Firefox a message indicates that Firefox has crashed! What should I do?
Configuration: Windows XP / Internet Explorer 7.0
Since yesterday, I can no longer navigate on FireFox (I think I made a mistake by downloading and opening some crappy thing). In addition, ad windows open as soon as I turn on my computer, all functions are slow and a message "out at memory of line 2" appears regularly on my desktop. That's all! Who can come to my rescue? Thank you in advance.
Netphilou
Update: I managed to open Firefox but the other problems persist and especially this message "memory of line..." that appears regularly.
It's starting again, when I try to open Firefox a message indicates that Firefox has crashed! What should I do?
Configuration: Windows XP / Internet Explorer 7.0
24 answers
- 1
- 2
Next
-
Hello,
ad windows pop up as soon as I turn on my computer
there's a good chance your computer is infected.
* Download ZHPDiag(by Nicolas Coolman)
* Vista and Seven users: Right-click on the ZHPdiag logo, "run as Administrator"
* Follow the instructions during installation, it will launch automatically at the end.
* Click on the icon that looks like a magnifying glass ("Start the diagnosis")
* Save the report on your Desktop using the icon that looks like a floppy disk
Use Cjoint.com to post the link to your report:
https://www.cjoint.com/
- Click on Browse to find the report
- Click on Open then Create the Cjoint link
- In your next response, copy and paste the link that is shown...The link has been created:
You MUST host the report via Cjoint as requested, otherwise it will not fully pass on the forum
-
Hello, thank you for your response. I clicked on ZHPDiag but since I'm not very skilled, I don't know what to click to download it.
Thank you for your help.
Best regards.
Netphilou -
The direct link:
https://www.zebulon.fr/telechargements/securite/systeme/zhpdiag.html -
ZHPDiag report v1.27.204 by Nicolas Coolman, Updated on 14/05/2011
Run by HP_Owner at 15.05.2011 14:58:19
Web site: http://www.premiumorange.com/zeb-help-process/zhpdiag.html
---\\ Web Browser
MSIE: Internet Explorer v7.0.5730.13
MFIE: Mozilla Firefox 4.0.1 v4.0.1 (Default)
---\\ System Information
Windows XP Home Edition Service Pack 3 (Build 2600)
Processor: x86 Family 15 Model 4 Stepping 1, GenuineIntel
Operating System: 32 Bits
Boot mode: Normal (Normal boot)
Total RAM: 1023.4 MB (36% free)
System Restore: Enabled
System drive C: has 91 GB (40%) free of 227 GB
---\\ Logged in mode
Computer Name: NOM-EB85C523610
User Name: HP_Owner
All Users Names: SUPPORT_fddfa904, SUPPORT_388945a0, HP_Owner, HelpAssistant, Administrator,
Unselected Option: O45,O61,O62,O65,O66,O82
Logged in as Administrator
---\\ Environment Variables
%AppData%=C:\Documents and Settings\HP_Owner\Application Data
%LocalAppData%=C:\Documents and Settings\HP_Owner\Local Settings\Application Data
%StartMenu%=C:\Documents and Settings\HP_Owner\Start Menu
---\\ DOS/Devices
C:\ Hard drive, Flash drive, Thumb drive (Free 91 GB of 227 GB)
D:\ Hard drive, Flash drive, Thumb drive (Free 2 GB of 6 GB)
E:\ CD-ROM drive (Not Inserted)
F:\ CD-ROM drive (Not Inserted)
G:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
H:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
I:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
J:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
K:\ CD-ROM drive (Not Inserted)
N:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
---\\ Security Center & Tools Information
[HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center] FirewallDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center] UpdatesDisableNotify: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] DisableTaskMgr: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] DisableRegistryTools: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
---\\ Specific file search for generic files
[MD5.F2317622D29F9FF0F88AEECD5F60F0DD] - (.Microsoft Corporation - Windows Explorer.) (.14.04.2008 03:34:03.) -- C:\WINDOWS\Explorer.exe [1037824]
[MD5.0B09E07755F412A1A4F18DDC353BA155] - (.Microsoft Corporation - Internet Extensions for Win32.) (.17.02.2011 19:56:16.) -- C:\WINDOWS\system32\wininet.dll [832512]
[MD5.DD73D6B9F6B4CB630CF35B438B540174] - (.Microsoft Corporation - Windows NT Logon Application.) (.14.04.2008 03:34:28.) -- C:\WINDOWS\system32\Winlogon.exe [512000]
[MD5.00000000000000000000000000000000] - (.No owner - No description.) (.13.04.2008 00:00:00.) -- C:\WINDOWS\system32\drivers\atapi.sys [96512]
[MD5.78A08DD6A8D65E697C18E1DB01C5CDCA] - (.Microsoft Corporation - NT File System Driver.) (.13.04.2008 20:15:53.) -- C:\WINDOWS\system32\drivers\ntfs.sys [574976]
---\\ Running Processes
[MD5.20F6F19FE9E753F2780DC2FA083AD597] - (.Apple Inc. - MobileDeviceService.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [37664]
[MD5.F832F1505AD8B83474BD9A5B1B985E01] - (.Apple Inc. - Bonjour Service.) -- C:\Program Files\Bonjour\mDNSResponder.exe [345376]
[MD5.C9FFBD6B8EDC46CD3D13E3C6DB914FB7] - (.Matsushita Electric Industrial Co., Ltd. - DVD-RAM Utility Helper Service.) -- C:\WINDOWS\system32\DVDRAMSV.exe [110592]
[MD5.A9BE66E05254B20DF82E0F7CDDECA7DD] - (.F-Secure Corporation - F-Secure Anti-Virus Scanning Service.) -- C:\Program Files\Internet Security\Anti-Virus\fsgk32st.exe [215648]
[MD5.392E85687A902239C01BADDF212B1A36] - (.F-Secure Corporation - F-Secure Management Agent.) -- C:\Program Files\Internet Security\Common\FSMA32.EXE [186976]
[MD5.C296A91A89263600FC4B247188EC3160] - (.F-Secure Corporation - Gatekeeper Handler II 32-bit.) -- C:\Program Files\Internet Security\Anti-Virus\FSGK32.EXE [508584]
[MD5.7E48D9BC72C8A0A9525F309F92A284D4] - (.F-Secure Corporation - F-Secure DLL Hosting Plugin.) -- C:\Program Files\Internet Security\Common\FSHDLL32.EXE [88672]
[MD5.39133291CB607BDD87CFC565A4A1E7A5] - (.Sun Microsystems, Inc. - Java(TM) Quick Starter Service.) -- C:\Program Files\Java\jre6\bin\jqs.exe [153376]
[MD5.575ED0F5DCB34E5C243D2A7EBC860484] - (.Hewlett-Packard Company - No description.) -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe [53248]
[MD5.11F714F85530A2BD134074DC30E99FCA] - (.Microsoft Corporation - Machine Debug Manager.) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [322120]
[MD5.5705D065B450F03EC0743E601941DDFA] - (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 77.79.) -- C:\WINDOWS\system32\nvsvc32.exe [127043]
[MD5.2D091A99624FB9E7EEF0A86D872EC0C3] - (.HP - PML Driver.) -- C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE [73728]
[MD5.332D341D92B933600D41953B08360DFB] - (.Ulead Systems, Inc. - ULCDRSvr.) -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [49152]
[MD5.20F89E232173985A455BC9A5F70D1166] - (.Canon Inc. - Canon Camera Access Library 8.) -- C:\Program Files\Canon\CAL\CALMAIN.exe [96341]
[MD5.7F08A21197C0759F0C2E8FEBA81E27B0] - (.F-Secure Corporation - F-Secure Scanner Manager 32-bit.) -- C:\Program Files\Internet Security\Anti-Virus\fssm32.exe [918184]
[MD5.707C0C5D9BE7163182227470E9CD3C9A] - (.Belkin - Belkin Wireless Client Utility.) -- C:\Program Files\Belkin\F5D8055\v2\Belkinwcui.exe [1662976]
[MD5.DA057673D9CF8CACDF6A3C5C1423F150] - (.Logitech Inc. - Communications Manager.) -- C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe [488984]
[MD5.4ABB2B8396FB02BE582FE92024269815] - (.Logitech Inc. - LVCom Server.) -- C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe [244512]
[MD5.8D74462038DDAE95966EF5F1E53C96B0] - (.F-Secure Corporation - F-Secure Settings and Statistics.) -- C:\Program Files\Internet Security\Common\FSM32.EXE [199264]
[MD5.8E0BF7478CC3BAED48282ADBC97ADAFB] - (.F-Secure Corporation - F-Secure Internet Shield daemon.) -- C:\Program Files\Internet Security\FWES\Program\fsdfwd.exe [522848]
[MD5.B624202660474516E73AA95238FD9843] - (.Logitech, Inc. - Logitech SetPoint Event Manager (UNICODE).) -- C:\Program Files\Logitech\SetPoint\SetPoint.exe [813584]
[MD5.E96BC31E0114F0999FB0F92FC65D61CA] - (.Logitech, Inc. - Logitech KHAL Main Process.) -- C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE [55824]
[MD5.051BD9B27D8B89DA4AE5ED91F116ED7E] - (.F-Secure Corporation - FSAV Handler.) -- C:\Program Files\Internet Security\Anti-Virus\fsav32.exe [484520]
[MD5.E4A798DFDE7FE6E79F23548F0EF0F844] - (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe [634648]
[MD5.9E243ECD2DE787DE5033F80BF14DF17F] - (...) -- C:\WINDOWS\System32\regsvr32.exe [12288]
[MD5.AC42E793F760034FC6F0BACB17E94003] - (.Nicolas Coolman - Diagnostic Tool.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [646144]
---\\ Mozilla Firefox, Plugins, Startup, Search, Extensions (P2,M0,M1,M2,M3)
M3 - MFPP: Plugins - [HP_Owner] -- C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\2kkrg3eh.default\searchplugins\askcom.xml
M3 - MFPP: Plugins - [HP_Owner] -- C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\2kkrg3eh.default\searchplugins\search.xml
M3 - MFPP: Plugins - [HP_Owner] -- C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\2kkrg3eh.default\searchplugins\conduit.xml
M3 - MFPP: Plugins - [HP_Owner] -- C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\2kkrg3eh.default\searchplugins\LphantWebSearch.xml
M3 - MFPP: Plugins - [HP_Owner] -- C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\2kkrg3eh.default\searchplugins\web-search.xml
M3 - MFPP: Plugins - [HP_Owner] -- C:\Program Files\Mozilla FireFox\searchplugins\amazon-france.xml
M3 - MFPP: Plugins - [HP_Owner] -- C:\Program Files\Mozilla FireFox\searchplugins\bing.xml
M3 - MFPP: Plugins - [HP_Owner] -- C:\Program Files\Mozilla FireFox\searchplugins\cnrtl-tlfi-fr.xml
M3 - MFPP: Plugins - [HP_Owner] -- C:\Program Files\Mozilla FireFox\searchplugins\eBay-france.xml
M3 - MFPP: Plugins - [HP_Owner] -- C:\Program Files\Mozilla FireFox\searchplugins\google.xml
M3 - MFPP: Plugins - [HP_Owner] -- C:\Program Files\Mozilla FireFox\searchplugins\wikipedia-fr.xml
M3 - MFPP: Plugins - [HP_Owner] -- C:\Program Files\Mozilla FireFox\searchplugins\yahoo-france.xml
P2 - FPN:Firefox Plugin Navigator . (.Microsoft Corporation - np-mswmp.) -- C:\Program Files\Mozilla Firefox\Plugins\np-mswmp.dll
P2 - FPN:Firefox Plugin Navigator . (.Sun Microsystems, Inc. - NPRuntime Script Plug-in Library for Java(TM) Deploy.) -- C:\Program Files\Mozilla Firefox\Plugins\npdeploytk.dll
P2 - FPN:Firefox Plugin Navigator . (.DivX, Inc. - DivX® Web Player.) -- C:\Program Files\Mozilla Firefox\Plugins\npdivx32.dll
P2 - FPN:Firefox Plugin Navigator . (.DivX, Inc - npdivxplayerplugin.) -- C:\Program Files\Mozilla Firefox\Plugins\npDivxPlayerPlugin.dll
P2 - FPN:Firefox Plugin Navigator . (.Microsoft Corporation - Office Plugin for Netscape Navigator.) -- C:\Program Files\Mozilla Firefox\Plugins\NPOFFICE.DLL
P2 - FPN:Firefox Plugin Navigator . (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape "9.4.4".) -- C:\Program Files\Mozilla Firefox\Plugins\nppdf32.dll
P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia content.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin.dll
P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia content.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin2.dll
P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia content.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin3.dll
P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia content.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin4.dll
P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia content.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin5.dll
P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia content.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin6.dll
P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia content.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin7.dll
P2 - FPN:Firefox Plugin Navigator . (.No owner - npsnapfish.) -- C:\Program Files\Mozilla Firefox\Plugins\npsnapfish.dll
P2 - FPN:Firefox Plugin Navigator . (.America Online, Inc. - npunagi2.) -- C:\Program Files\Mozilla Firefox\Plugins\npunagi2.dll
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.No owner - No description.) -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
P2 - FPN: [HKLM] [@Apple.com/iTunes, version=1.0] - (.No owner - No description.) -- C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
P2 - FPN: [HKLM] [@garmin.com/GpsControl] - (.GARMIN Corp. - Garmin Communicator Plug-In 2.8.2.0.) -- C:\Program Files\Garmin GPS Plugin\npGarmin.dll
P2 - FPN: [HKLM] [@Google.com/GoogleEarthPlugin] - (.Google - GEPlugin.) -- C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
P2 - FPN: [HKLM] [@microsoft.com/WPF, version=3.5] - (.Microsoft Corporation - Windows Presentation Foundation (WPF) plug-in for Mozilla browsers.) -- c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
P2 - FPN: [HKLM] [@pandasecurity.com/activescan] - (.No owner - No description.) -- C:\Program Files\Panda Security\ActiveScan 2.0\npwrapper.dll (.not file.)
P2 - FPN: [HKLM] [@tools.google.com/Google Update; version=3] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.21.53\npGoogleUpdate3.dll
P2 - FPN: [HKLM] [@tools.google.com/Google Update; version=9] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.21.53\npGoogleUpdate3.dll
M0 - MFSP: prefs.js [HP_Owner - 2kkrg3eh.default] https://www.bluewin.ch/de/index.html
M2 - MFEP: prefs.js [HP_Owner - 2kkrg3eh.default\engine@conduit.com] [] Conduit Engine v3.3.3.2 (.Conduit Ltd..)
M2 - MFEP: prefs.js [HP_Owner - 2kkrg3eh.default\fr@dictionaries.addons.mozilla.org] [] French Dictionary "1990 Reform" v3.5 (.Olivier R..)
M2 - MFEP: prefs.js [HP_Owner - 2kkrg3eh.default\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}] [] Garmin Communicator v3.5 (.Garmin International.)
M2 - MFEP: prefs.js [HP_Owner - 2kkrg3eh.default\{3112ca9c-de6d-4884-a869-9855de68056c}] [] Google Toolbar for Firefox v7.1.20101113Wb1 (.Google Inc..)
M2 - MFEP: prefs.js [HP_Owner - 2kkrg3eh.default\{4daac69c-cba7-45e2-9bc8-1044483d3352}] [] Softonic_France Community Toolbar v3.3.3.2 (.Conduit Ltd..)
---\\ Google Chrome, Startup, Search, Extensions (G0,G1,G2)
G1 - GCS: Preference [User Data\Default] None
G0 - GCSP: Preference [User Data\Default][HomePage] https://www.google.com/?gws_rd=ssl
---\\ Internet Explorer, Startup, Search, URLSearchHook, Phishing (R0,R1,R3,R4)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main, Start Page = https://www.bluewin.ch/de/index.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main, Start Page = https://www.microsoft.com/fr-fr/
R0 - HKUS\S-1-5-21-943731138-2747897866-4246271285-1008\Software\Microsoft\Internet Explorer\Main, Start Page = https://www.bluewin.ch/de/index.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main, Search Page = https://www.microsoft.com/fr-fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main, Search Page = https://www.microsoft.com/fr-fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main, Default_Page_URL = https://www.microsoft.com/fr-fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main, Default_Search_URL = https://www.microsoft.com/fr-fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main, Extensions Off Page = about:noadd-ons
R1 - HKLM\Software\Microsoft\Internet Explorer\Main, Security Risk Page = about:securityrisk
R1 - HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant = https://www.bing.com/?toHttps=1&redig=17DBE7D168544FA98200E890A8051984
R1 - HKUS\S-1-5-21-943731138-2747897866-4246271285-1008\Software\Microsoft\Internet Explorer\Main, SearchMigratedDefaultName = cherche.us
R1 - HKUS\S-1-5-21-943731138-2747897866-4246271285-1008\Software\Microsoft\Internet Explorer\Main, SearchMigratedDefaultURL = http://www.cherche.usso-8859-1&q={searchterms}&sourceid=ie7&rls=com.microsoft:en-us&ie=utf8&oe=utf8
R1 - HKUS\S-1-5-21-943731138-2747897866-4246271285-1008\Software\Microsoft\Internet Explorer\Main, Search Page = https://www.microsoft.com/fr-fr/
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} . (.Ask - Ask Toolbar.) (5.8.0.0) -- C:\Program Files\Ask.com\GenericAskToolbar.dll
R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Internet Explorer.) (7.00.6000.17096 (vista_gdr.110211-1830)) -- C:\WINDOWS\system32\ieframe.dll
R3 - URLSearchHook: Softonic_France Toolbar - {4daac69c-cba7-45e2-9bc8-1044483d3352} . (.Conduit Ltd. - Conduit Toolbar.) (6.3.2.0) -- C:\Program Files\Softonic_France\prxtbSof0.dll
R4 - HKCU\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter, Enabled = 2
---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings, ProxyOverride = *.local
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings, ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings, ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings, MigrateProxy = 1
R5 - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings, EnableHttp1_1 = 1
R5 - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings, AutoConfigProxy = wininet.dll
---\\ ---\\ Modified INI file value (Changed ini file value, mapped to Registry) (F2)
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,
F2 - REG:system.ini: VMApplet=rundll32 shell32, Control_RunDLL "sysdm.cpl"
---\\ Browser Helper Objects (O2)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} Orphaned key
O2 - BHO: AcroIEHelperStub -
The ZHPDiag report is not complete, but we will still begin the cleaning process.
Step 1
Uninstall the following software: (Start => Control Panel => Add/Remove Programs)
- Software: Ask Toolbar
- Software: Conduit Engine
- Software: Softonic_France Toolbar
Step 2
[*]Download AD-Remover (by Cyrildu17 / C_XX) to your Desktop.
- Temporarily disable only for the time you use AD-Remover, the real-time protection of your Antivirus and Antispyware, which may significantly hinder the cleaning procedure of the tool.
- Log out and close all running applications.
[*]Double-click the installer and install it in its default location (C:\Program files).
[*]Double-click on the AD-Remover icon located on your Desktop.
(Vista/Seven - Right-click on the AD-Remover icon on your Desktop and choose run as administrator.)
[*]In the main menu, choose the Clean option.
[*]Post the report that appears at the end.
(The report is also saved under C:\Ad-report(clean).Txt
(CTRL+A to select all, CTRL+C to copy and CTRL+V to paste)
Step 3
-Please post a new ZHPDiag report by strictly following the steps outlined to visualize the entire report.
Use Cjoint.com to post your report link:
https://www.cjoint.com/
- Click on Browse to find the report.
- Click on Open then Create the Cjoint link.
- In your next response, copy/paste the link that is displayed...The link has been created:
It is IMPERATIVE to host the report via Cjoint as requested, otherwise it will not fully appear on the forum.
-
Thank you,
Here is the report
======= AD-REMOVER REPORT 2.0.0.2,G | WINDOWS XP/VISTA/7 ONLY =======
Updated by TeamXscript on 12/04/11
Contact: AdRemover[DOT]contact[AT]gmail[DOT]com
Website: http://www.teamxscript.org
C:\Program Files\Ad-Remover\main.exe (CLEAN [1]) -> Launched at 17:26:18 on 15/05/2011, Normal mode
Microsoft Windows XP Home Edition Service Pack 3 (X86)
HP_Owner@NAME-EB85C523610 ( )
============== ACTION(S) ==============
File deleted: C:\WINDOWS\system32\c506b3da.exe
File deleted: C:\Program Files\Mozilla FireFox\Components\AskHPRFF.js
File deleted: C:\WINDOWS\system32\ConduitEngine.tmp
File deleted: C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
File deleted: C:\Documents and Settings\HP_Owner\Application Data\Mozilla\FireFox\Profiles\2kkrg3eh.default\searchplugins\askcom.xml
File deleted: C:\Documents and Settings\HP_Owner\Application Data\Mozilla\FireFox\Profiles\2kkrg3eh.default\searchplugins\search.xml
Folder deleted: C:\Documents and Settings\HP_Owner\Application Data\Mozilla\FireFox\Profiles\2kkrg3eh.default\conduit
Folder deleted: C:\Documents and Settings\HP_Owner\Application Data\Mozilla\FireFox\Profiles\2kkrg3eh.default\ConduitEngine
Folder deleted: C:\Documents and Settings\HP_Owner\Application Data\Mozilla\FireFox\Profiles\2kkrg3eh.default\extensions\engine@conduit.com
File deleted: C:\Documents and Settings\HP_Owner\Application Data\Mozilla\FireFox\Profiles\2kkrg3eh.default\searchplugins\conduit.xml
File deleted: C:\Documents and Settings\HP_Owner\Application Data\Mozilla\FireFox\Profiles\2kkrg3eh.default\searchplugins\web-search.xml
File deleted: C:\Documents and Settings\HP_Owner\scriptjava.html
File deleted: C:\Documents and Settings\HP_Owner\temp1.6
Folder deleted: C:\Program Files\Ask.com
Folder deleted: C:\Documents and Settings\HP_Owner\Local Settings\Application Data\AskToolbar
Folder deleted: C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Conduit
Folder deleted: C:\Program Files\Conduit
Folder deletion error: C:\Documents and Settings\HP_Owner\Local Settings\Application Data\ConduitEngine
Folder deleted: C:\Program Files\ConduitEngine
Folder deleted: C:\Documents and Settings\HP_Owner\Application Data\PriceGong
(!) -- Temporary files deleted.
-- Opened file: C:\Documents and Settings\HP_Owner\Application Data\Mozilla\FireFox\Profiles\2kkrg3eh.default\Prefs.js --
Line deleted: user_pref("CT1460988.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TER...
Line deleted: user_pref("CT1460988.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT146...
Line deleted: user_pref("CT1460988.ct1460988.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?q=UCM_...
Line deleted: user_pref("CT2542115.SearchEngine", "Recherche||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_...
Line deleted: user_pref("CT2542115.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT254...
Line deleted: user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/CH", "\"0\"")...
Line deleted: user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "...
Line deleted: user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.engine.conduit-services.com/DLG.pkg?ver=3.3.3...
Line deleted: user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "63...
Line deleted: user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=3/13/20...
Line deleted: user_pref("CommunityToolbar.EngineHiddenByUser", true);
Line deleted: user_pref("CommunityToolbar.EngineOwner", "ConduitEngine");
Line deleted: user_pref("CommunityToolbar.EngineOwnerGuid", "engine@conduit.com");
Line deleted: user_pref("CommunityToolbar.EngineOwnerToolbarId", "conduitengine");
Line deleted: user_pref("CommunityToolbar.IsEngineShown", false);
Line deleted: user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true);
Line deleted: user_pref("CommunityToolbar.OriginalEngineOwner", "ConduitEngine");
Line deleted: user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "engine@conduit.com");
Line deleted: user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "conduitengine");
Line deleted: user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://google.search.us/Result.php?clie...
Line deleted: user_pref("CommunityToolbar.ToolbarsList", "CT1460988,CT2542115,ConduitEngine");
Line deleted: user_pref("CommunityToolbar.ToolbarsList2", "CT1460988,CT2542115");
Line deleted: user_pref("CommunityToolbar.alert.alertDialogsGetterLastCheckTime", "Sun Mar 27 2011 10:21:38 GMT+02...
Line deleted: user_pref("CommunityToolbar.alert.alertInfoInterval", 1440);
Line deleted: user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Sun May 15 2011 10:50:12 GMT+0200");
Line deleted: user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com");
Line deleted: user_pref("CommunityToolbar.alert.locale", "en");
Line deleted: user_pref("CommunityToolbar.alert.loginIntervalMin", 1440);
Line deleted: user_pref("CommunityToolbar.alert.loginLastCheckTime", "Sat May 14 2011 20:39:21 GMT+0200");
Line deleted: user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1303303927");
Line deleted: user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);
Line deleted: user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com");
Line deleted: user_pref("CommunityToolbar.alert.showTrayIcon", false);
Line deleted: user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);
Line deleted: user_pref("CommunityToolbar.alert.userId", "c04f5034-35a7-4c43-a5d2-beb1955e97b6");
Line deleted: user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Mon Aug 30 2010 19:10:12 GMT+0200");
Line deleted: user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Line deleted: user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Line deleted: user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2542115");
Line deleted: user_pref("ConduitEngine.AppTrackingLastCheckTime", "Tue May 10 2011 21:34:31 GMT+0200");
Line deleted: user_pref("ConduitEngine.CTID", "ConduitEngine");
Line deleted: user_pref("ConduitEngine.DialogsGetterLastCheckTime", "Fri May 06 2011 18:31:00 GMT+0200");
Line deleted: user_pref("ConduitEngine.FirstServerDate", "03/27/2011 11");
Line deleted: user_pref("ConduitEngine.FirstTime", true);
Line deleted: user_pref("ConduitEngine.FirstTimeFF3", true);
Line deleted: user_pref("ConduitEngine.HasUserGlobalKeys", true);
Line deleted: user_pref("ConduitEngine.Initialize", true);
Line deleted: user_pref("ConduitEngine.InitializeCommonPrefs", true);
Line deleted: user_pref("ConduitEngine.InstalledDate", "Sun Mar 27 2011 10:21:39 GMT+0200");
Line deleted: user_pref("ConduitEngine.IsMulticommunity", false);
Line deleted: user_pref("ConduitEngine.IsOpenThankYouPage", false);
Line deleted: user_pref("ConduitEngine.IsOpenUninstallPage", true);
Line deleted: user_pref("ConduitEngine.LanguagePackLastCheckTime", "Sun May 08 2011 21:50:06 GMT+0200");
Line deleted: user_pref("ConduitEngine.LastLogin_3.3.3.2", "Sun May 08 2011 21:50:06 GMT+0200");
Line deleted: user_pref("ConduitEngine.SearchFromAddressBarIsInit", true);
Line deleted: user_pref("ConduitEngine.SettingsLastCheckTime", "Sun May 08 2011 21:50:19 GMT+0200");
Line deleted: user_pref("ConduitEngine.UserID", "UN94443869942007641");
Line deleted: user_pref("ConduitEngine.componentAlertEnabled", false);
Line deleted: user_pref("ConduitEngine.engineLocale", "fr");
Line deleted: user_pref("ConduitEngine.engineContextMenuLastCheckTime", "Sun May 08 2011 21:50:06 GMT+0200");
Line deleted: user_pref("ConduitEngine.globalFirstTimeInfoLastCheckTime", "Sun May 08 2011 21:50:06 GMT+0200");
Line deleted: user_pref("ConduitEngine.initDone", true);
Line deleted: user_pref("ConduitEngine.isAppTrackingManagerOn", true);
Line deleted: user_pref("ConduitEngine.usagesFlag", 2);
Line deleted: user_pref("browser.search.defaultengine", "Ask.com");
Line deleted: user_pref("browser.search.defaultenginename", "Ask.com");
Line deleted: user_pref("browser.search.defaulturl", "hxxp://flvdirect.iamwired.net/websearch.php?src=tops&search=...
Line deleted: user_pref("browser.search.order.1", "Ask.com");
Line deleted: user_pref("extensions.asktb.cbid", "RY");
Line deleted: user_pref("extensions.asktb.default-channel-url-mask", "hxxp://www.ask.com/web?q={query}&o={o}&l={l}...
Line deleted: user_pref("extensions.asktb.first-launch-url", "hxxp://www.ccleaner.com/update/?v=2.27.1070&l=1036" )...
Line deleted: user_pref("extensions.asktb.fresh-install", false);
Line deleted: user_pref("extensions.asktb.l", "dis");
Line deleted: user_pref("extensions.asktb.last-config-req", "1285603933370");
Line deleted: user_pref("extensions.asktb.locale", "en_US");
Line deleted: user_pref("extensions.asktb.o", "15184");
Line deleted: user_pref("extensions.asktb.overlay-reloaded-using-restart", true);
Line deleted: user_pref("extensions.asktb.qsrc", "2871");
Line deleted: user_pref("extensions.asktb.r", "2");
Line deleted: user_pref("extensions.asktb.search-plugin-suggestions-url", "hxxp://ss.websearch.ask.com/query?qsrc=...
Line deleted: user_pref("extensions.asktb.search-suggestions-enabled", true);
Line deleted: user_pref("extensions.asktb.search-suggestions-uri", "hxxp://ss.websearch.ask.com/query?qsrc=2922&li...
-- File Closed --
Key deleted: HKLM\Software\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}
Key deleted: HKLM\Software\Classes\CLSID\{27F69C85-64E1-43CE-98B5-3C9F22FB408E}
Key deleted: HKLM\Software\Classes\AppID\{1301A8A5-3DFB-4731-A162-B357D00C9644}
Key deleted: HKLM\Software\Classes\CLSID\{a42b8c5c-9c90-c7a7-3814-28e0bcd9add0}
Key deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a42b8c5c-9c90-c7a7-3814-28e0bcd9add0}
Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{a42b8c5c-9c90-c7a7-3814-28e0bcd9add0}
Key deleted: HKLM\Software\Classes\CLSID\{B543EF05-9758-464E-9F37-4C28525B4A4C}
Key deleted: HKLM\Software\Classes\CLSID\{BB76A90B-2B4C-4378-8506-9A2B6E16943C}
Key deleted: HKLM\Software\Classes\CLSID\{C3AB94A4-BFD0-4BBA-A331-DE504F07D2DB}
Key deleted: HKLM\Software\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key deleted: HKLM\Software\Classes\Interface\{03C390E8-B836-4B82-8D56-1BFDDC06AE8A}
Key deleted: HKLM\Software\Classes\Interface\{2C4470A2-E099-4B9E-ABFE-BBA56D046AFD}
Key deleted: HKLM\Software\Classes\Interface\{391769AE-D8EC-45EC-967D-F5120456E514}
Key deleted: HKLM\Software\Classes\Interface\{39AEF150-C270-4690-AE7D-955E51BC8960}
Key deleted: HKLM\Software\Classes\Interface\{477F210A-2A86-4666-9C4B-1189634D2C84}
Key deleted: HKLM\Software\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Key deleted: HKLM\Software\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Key deleted: HKLM\Software\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Key deleted: HKLM\Software\Classes\Interface\{CD73B1AB-3403-4E47-B196-517C57BE76A2}
Key deleted: HKLM\Software\Classes\Interface\{FF871E51-2655-4D06-AED5-745962A96B32}
Key deleted: HKLM\Software\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
Key deleted: HKLM\Software\Classes\TypeLib\{8F5F1CB6-EA9E-40AF-A5CA-C7FD63CC1971}
Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\c506b3da
Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\QhTuW-
Key deleted: HKLM\Software\Classes\BandooCore.BandooCore
Key deleted: HKLM\Software\Classes\BandooCore.BandooCore.1
Key deleted: HKLM\Software\Classes\BandooCore.ResourcesMngr
Key deleted: HKLM\Software\Classes\BandooCore.ResourcesMngr.1
Key deleted: HKLM\Software\Classes\BandooCore.SettingsMngr
Key deleted: HKLM\Software\Classes\BandooCore.SettingsMngr.1
Key deleted: HKLM\Software\Classes\BandooCore.StatisticMngr
Key deleted: HKLM\Software\Classes\BandooCore.StatisticMngr.1
Key deleted: HKLM\Software\Classes\Conduit.Engine
Key deleted: HKLM\Software\Classes\GenericAskToolbar.ToolbarWnd
Key deleted: HKLM\Software\Classes\GenericAskToolbar.ToolbarWnd.1
Key deleted: HKLM\Software\Classes\Toolbar.CT2504091
Key deleted: HKLM\Software\Classes\Toolbar.CT2542115
Key deleted: HKLM\Software\Classes\AppID\BandooCore.EXE
Key deleted: HKLM\Software\Classes\AppID\GenericAskToolbar.DLL
Key deleted: HKLM\Software\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Key deleted: HKLM\Software\bandoo
Key deleted: HKLM\Software\Conduit
Key deleted: HKCU\Software\Ask.com
Key deleted: HKCU\Software\AskToolbar
Key deleted: HKCU\Software\conduitEngine
Key deleted: HKCU\Software\PriceGong
Key deleted: HKCU\Software\AppDataLow\AskBarDis
Key deleted: HKCU\Software\AppDataLow\AskHomePage
Key deleted: HKCU\Software\AppDataLow\AskToolbarInfo
Key deleted: HKCU\Software\AppDataLow\HavingFunOnline
Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Bandoo
Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Dealio
Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\FLV Direct Player
Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\WhenU
Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Zango
Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Zango Programs
Key deleted: HKLM\Software\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
Key deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF
Key deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
Key deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}
Key deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{557C21FE-7274-410D-853E-9ED4471BF193}
Key deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Key deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{F1B1E52E-E3C3-4B98-9A76-4450479EF8C1}
Key deleted: HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key deleted: HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Key deleted: HKCU\Software\Microsoft\Internet Explorer\MenuExt\Search with search.us
Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}
Value deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0|goicfboogidikkejccmclpieicihhlpo hpfanicgkffmccehnpkikogcffaepkfp
Value deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0|goicfboogidikkejccmclpieicihhlpo dgnckdmmolaijpbbakmplfhlfpdhglgc
Value deleted: HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks|{00000000-6E41-4FD3-8538-502F5495E5FC}
Value deleted: HKLM\Software\Microsoft\Internet Explorer\Toolbar|{D4027C7F-154A-4066-A1AD-4243D8127440}
Value deleted: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser|{D4027C7F-154A-4066-A1AD-4243D8127440}
============== ADDITIONAL SCAN ==============
**** Mozilla Firefox Version [4.0.1 (fr)] ****
Plugins\npdivx32.dll (DivX, Inc.)
Plugins\npDivxPlayerPlugin.dll (DivX, Inc)
Plugins\npsnapfish.dll ( )
Plugins\npunagi2.dll (America Online, Inc.)
HKLM_MozillaPlugins\@garmin.com/GpsControl (x)
Searchplugins\bing.xml ( hxxp://www.bing.com/search)
Components\browsercomps.dll (Mozilla Foundation)
Extensions\{3112ca9c-de6d-4884-a869-9855de68056c} (Google Toolbar for Firefox)
Extensions\{5a085e73-a120-c70f-2540-810f57ee2fe8} (z)
HKLM_Extensions|litmus-ff@f-secure.com - C:\Program Files\Internet Security\NRS\litmus-ff@f-secure.com
-- C:\Documents and Settings\HP_Owner\Application Data\Mozilla\FireFox\Profiles\2kkrg3eh.default --
Extensions\fr@dictionaries.addons.mozilla.org (French dictionary "Reform 1990")
Extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E} (Garmin Communicator)
Extensions\{3112ca9c-de6d-4884-a869-9855de68056c} (Google Toolbar for Firefox)
Extensions\{4daac69c-cba7-45e2-9bc8-1044483d3352} (Softonic_France Community Toolbar)
Searchplugins\LphantWebSearch.xml ( hxxp://search.lphant.com/webResults.html?src=ffb&q={searchTerms}/)
Searchplugins\Search.xml (?)
Prefs.js - browser.download.dir, C:\\Documents and Settings\\HP_Owner\\Desktop
Prefs.js - browser.search.selectedEngine, Google
Prefs.js - browser.startup.homepage, hxxp://www.bluewin.ch/
Prefs.js - browser.startup.homepage_override.buildID, 20110413222027
Prefs.js - browser.startup.homepage_override.mstone, rv:2.0.1
Prefs.js - keyword.URL, hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=
========================================
**** Internet Explorer Version [7.0.5730.13] ****
Plugins\NPEvery.dll (Broderbund)
HKCU_Main|Default_Page_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
HKCU_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU_Main|Search bar - hxxp://go.microsoft.com/fwlink/?linkid=54896
HKCU_Main|Start Page - hxxp://fr.msn.com/
HKLM_Main|Default_Page_URL - hxxp://go.microsoft.com/fwlink/?LinkId=54896
HKLM_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM_Main|Search bar - hxxp://search.msn.com/spbasic.htm
HKLM_Main|Search Page - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM_Main|Start Page - hxxp://fr.msn.com/
HKCU_SearchScopes\{9091C5EC-8529-4EE0-9B0D-96A0520FFB90} - "Search" (hxxp://flvdirect.iamwired.net/websearch.php?src=tops&search={SearchTerms})
HKCU_SearchScopes\{B320F28C-6347-46e4-98FF-5261CA66FEDA} - "Web Search" (hxxp://search.lphant.com/webResults.html?src=ieb&q={searchTerms})
HKCU_Toolbar\ShellBrowser|{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} (x)
HKLM_Toolbar|{327C2873-E90D-4c37-AA9D-10AC9BABA46C} (C:\Program Files\Canon\Easy-WebPrint\Toolband.dll)
HKLM_Toolbar|{265EEE8E-3228-44D3-AEA5-F7FDF5860049} (C:\Program Files\Internet Security\NRS\iescript\baselitmus.dll)
HKLM_ElevationPolicy\2a7a56c0-6991-4c84-a11d-ea1bcd9d89c0 - C:\Program Files\Vuze_Remote\Vuze_RemoteToolbarHelper.exe (x)
HKLM_ElevationPolicy\4fbb75e9-648a-4919-96c3-80d265c43805 - C:\Program Files\Vuze_Remote\Vuze_RemoteToolbarHelper.exe (x)
HKLM_ElevationPolicy\8f0c59f4-ea24-4319-add6-a04fc0e63095 - C:\Program Files\Vuze_Remote\Vuze_RemoteToolbarHelper.exe (x)
HKLM_ElevationPolicy\{1CC6F2D4-61C2-41d9-AF15-1D886DF98B2B} - C:\Program Files\Lphant Applications\Lphant\Lphant.exe (Discordia, LTD)
HKLM_ElevationPolicy\{2A9467B4-C085-11DD-BC92-869555D89593} - C:\Program Files\LphantTb\uninstall.exe (Visicom Media Inc.)
HKLM_ElevationPolicy\{44295CB8-D71B-11DA-8750-001185653D78} - c:\program files\google\googletoolbar2user.exe (?)
HKLM_ElevationPolicy\{F9F9EFDD-8B1F-4D2F-AF13-D7A6CCF1E4C1} - C:\Program Files\Common Files\Motive\McciControlHost.exe (Motive Communications, Inc.)
HKLM_Extensions\{E2D4D26B-0180-43a4-B05F-462D6D54C789} - "Connection Help" (C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\conn_support.ico)
HKLM_Extensions\{e2e2dd38-d088-4134-82b7-f2ba38496583} - "?" (?)
BHO\{02478D38-C3F9-4efb-9B51-7695ECA05670} (?)
BHO\{55BD16AA-37AD-C8C4-0305-060D9C3832CE} - "uberclicks browser extension" (C:\WINDOWS\system32\ndhjdfuzjilvrjrjp.dll)
BHO\{C6867EB7-8350-4856-877F-93CF8AE3DC9C} - "Browsing Protection Class" (C:\Program Files\Internet Security\NRS\iescript\baselitmus.dll)
========================================
C:\Program Files\Ad-Remover\Quarantine: 251 File(s)
C:\Program Files\Ad-Remover\Backup: 27 File(s)
C:\Ad-Report-CLEAN[1].txt - 15/05/2011 17:26:31 (18470 Bytes)
Finished at: 17:28:19, 15/05/2011
============== E.O.F ============== -
-
Hello,
Restart AD Remover and click on Uninstall
Step 1
* Launch ZHPFix (if you are on Windows Vista or Windows 7, run it by right-clicking --> run as administrator).
* Copy the following lines:
---------------------------------------------------
M3 - MFPP: Plugins - [HP_Owner] -- C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\2kkrg3eh.default\searchplugins\LphantWebSearch.xml
M2 - MFEP: prefs.js [HP_Owner - 2kkrg3eh.default\{4daac69c-cba7-45e2-9bc8-1044483d3352}] [] Softonic_France Community Toolbar v3.3.3.2 (.Conduit Ltd..)
O15 - Trusted Zone: [HKCU\...\Domains] *.chat-land.org
O15 - Trusted Zone: [HKCU\...\Domains\www] *.chat-land.org
[HKCU\Software\Totem]
O43 - CFD: 15.05.2011 - 17:17:24 - [175912] ----D- C:\Program Files\Softonic_France
O43 - CFD: 08.01.2010 - 23:34:48 - [1731411] ----D- C:\Program Files\Spybot - Search & Destroy
O43 - CFD: 18.04.2010 - 08:01:52 - [1509200] ----D- C:\Program Files\vghd
O43 - CFD: 16.11.2008 - 14:44:06 - [801] ----D- C:\Program Files\Common Files\Companion Wizard
O43 - CFD: 15.05.2011 - 17:27:24 - [327] ----D- C:\Documents and Settings\HP_Owner\Local Settings\Application Data\ConduitEngine
O43 - CFD: 15.05.2011 - 17:17:22 - [4589815] ----D- C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Softonic_France
[HKCR\imweb.imwebcontrol]
[HKCR\nctaudiocdwriter2.audiocdwriter2]
[HKCR\nctaudiocdwriter2.audiocdwriter2.1]
[HKCR\Interface\{06DE5702-44CF-4B79-B4EF-3DDF653358F5}]
[HKLM\Software\Classes\Interface\{06DE5702-44CF-4B79-B4EF-3DDF653358F5}]
[HKCR\AppID\{1fc41815-fa4c-4f8b-b143-2c045c8ea2fc}]
[HKLM\Software\Classes\AppID\{1fc41815-fa4c-4f8b-b143-2c045c8ea2fc}]
[HKCR\AppID\{21493C1F-D071-496A-9C27-450578888291}]
[HKLM\Software\Classes\AppID\{21493C1F-D071-496A-9C27-450578888291}]
[HKCR\TypeLib\{2D77AC8A-0A4C-40D0-9557-51907A575E45}]
[HKLM\Software\Classes\TypeLib\{2D77AC8A-0A4C-40D0-9557-51907A575E45}]
[HKCR\Interface\{3EDDA953-1C3B-4823-8F25-D075FBB2D2B5}]
[HKLM\Software\Classes\Interface\{3EDDA953-1C3B-4823-8F25-D075FBB2D2B5}]
[HKCR\AppID\{403A885F-CB00-40C1-BDC1-EB09053194F7}]
[HKCR\TypeLib\{403A885F-CB00-40C1-BDC1-EB09053194F7}]
[HKLM\Software\Classes\AppID\{403A885F-CB00-40C1-BDC1-EB09053194F7}]
[HKLM\Software\Classes\TypeLib\{403A885F-CB00-40C1-BDC1-EB09053194F7}]
[HKCR\TypeLib\{43B4B831-F41F-4F73-8F14-4FFF0BA75B1B}]
[HKLM\Software\Classes\TypeLib\{43B4B831-F41F-4F73-8F14-4FFF0BA75B1B}]
[HKCR\TypeLib\{4C1E5902-FE99-4591-8582-2A2605462857}]
[HKLM\Software\Classes\TypeLib\{4C1E5902-FE99-4591-8582-2A2605462857}]
[HKCR\AppID\{55C1727F-5535-4C2A-9601-8C2458608B48}]
[HKCR\TypeLib\{55C1727F-5535-4C2A-9601-8C2458608B48}]
[HKLM\Software\Classes\AppID\{55C1727F-5535-4C2A-9601-8C2458608B48}]
[HKLM\Software\Classes\TypeLib\{55C1727F-5535-4C2A-9601-8C2458608B48}]
[HKCR\CLSID\{5C00A371-2011-4AF3-97C8-6CE66AA744CB}]
[HKLM\Software\Classes\CLSID\{5C00A371-2011-4AF3-97C8-6CE66AA744CB}]
[HKCR\AppID\{5e50ae1d-bc76-418b-94c4-efeac0cef80c}]
[HKLM\Software\Classes\AppID\{5e50ae1d-bc76-418b-94c4-efeac0cef80c}]
[HKCR\AppID\{69E54DE2-C4ED-4BEC-8046-E3F9AC74B4B0}]
[HKLM\Software\Classes\AppID\{69E54DE2-C4ED-4BEC-8046-E3F9AC74B4B0}]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6A87B991-A31F-4130-AE72-6D0C294BF082}]
[HKCR\TypeLib\{6C9945B7-1D19-46CB-88C0-45A24DF6CD6E}]
[HKLM\Software\Classes\TypeLib\{6C9945B7-1D19-46CB-88C0-45A24DF6CD6E}]
[HKCR\TypeLib\{81ca8fcd-1420-4a07-b47d-b30f3dda79e1}]
[HKLM\Software\Classes\TypeLib\{81ca8fcd-1420-4a07-b47d-b30f3dda79e1}]
[HKCR\TypeLib\{84B9B044-17C0-48FB-A300-C9747D5DF29C}]
[HKLM\Software\Classes\TypeLib\{84B9B044-17C0-48FB-A300-C9747D5DF29C}]
[HKCR\TypeLib\{85672EDB-2CC8-40B9-A9E8-77D3478F2EFB}]
[HKLM\Software\Classes\TypeLib\{85672EDB-2CC8-40B9-A9E8-77D3478F2EFB}]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{872F3C0B-4462-424c-BB9F-74C6899B9F92}]
[HKCR\CLSID\{9F038672-0425-4792-BC9C-36DE3308E8AA}]
[HKLM\Software\Classes\CLSID\{9F038672-0425-4792-BC9C-36DE3308E8AA}]
[HKCR\AppID\{A7DDCBDE-5C86-415c-8A37-763AE183E7E4}]
[HKLM\Software\Classes\AppID\{A7DDCBDE-5C86-415c-8A37-763AE183E7E4}]
[HKCR\AppID\{AD71F65D-CD13-4837-A2DC-E4D90020E7D4}]
[HKLM\Software\Classes\AppID\{AD71F65D-CD13-4837-A2DC-E4D90020E7D4}]
[HKCR\Interface\{B67A4CBA-520A-43DB-B03F-414E539F90EC}]
[HKLM\Software\Classes\Interface\{B67A4CBA-520A-43DB-B03F-414E539F90EC}]
[HKCR\CLSID\{B6F8DA9F-2696-419e-A8A3-19BE41EF51BD}]
[HKLM\Software\Classes\CLSID\{B6F8DA9F-2696-419e-A8A3-19BE41EF51BD}]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B6F8DA9F-2696-419e-A8A3-19BE41EF51BD}]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F}]
[HKCR\CLSID\{E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F}]
[HKLM\Software\Classes\CLSID\{E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F}]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{e908b145-c847-4e85-b315-07e2e70decf8}]
[HKCR\AppID\{F54A0D21-6A53-460C-8301-C694EC9E1033}]
[HKLM\Software\Classes\AppID\{F54A0D21-6A53-460C-8301-C694EC9E1033}]
[HKCR\AppID\{F7BCCFD4-2FA6-477D-A1B0-EF7500B3C49E}]
[HKLM\Software\Classes\AppID\{F7BCCFD4-2FA6-477D-A1B0-EF7500B3C49E}]
[HKCR\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF]
[HKLM\Software\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF]
[HKCR\Installer\UpgradeCodes\CC94835868BCA58489B0D79DE655BCB1]
EmptyTemp
EmptyFlash
---------------------------------------------------
* * Click on the icon representing the letter H (“paste Helper lines”)
* The lines will automatically be pasted into ZHPFix.
* Click on the "GO" button to start the cleanup,
* Copy/paste the entire report in your next response
Post the report saved in this folder (via Cjoint please) -> ( C:\Program files\ZHPFix\ZHPFixReport.txt )
Step 2
[*] Download Malwarebytes
[*] You will have a tutorial available to install and use it correctly.
[*]Update the software (this usually happens during installation)
[*] Run a full scan by clicking on "Run a full scan"
[*] Select all your local and removable drives and click on "Start scan"
[*] The scan may take a while.....
[*] Once the scan is complete, click "OK" and then "Show results"
[*] Ensure everything is checked and click on "Remove selected" => and then click "OK"
[*] A report will open in Notepad... Copy/paste the report in your next response on the forum
* Some files may need to be deleted at the next PC restart... Do so by clicking "yes" to the prompt -
Good evening,
I tried to do what you asked me. Below is the report (I did a copy-paste because I don't know where to find "attached") I hope it will be fine, otherwise, please give me more details (I am ignorant in this area)
Thanks again for your help and patience.
Best regards.
Netphilou
HKCR\imweb.imwebcontrol => Key successfully deleted
HKCR\nctaudiocdwriter2.audiocdwriter2 => Key successfully deleted
HKCR\nctaudiocdwriter2.audiocdwriter2.1 => Key successfully deleted
HKCR\Interface\{06DE5702-44CF-4B79-B4EF-3DDF653358F5} => Key successfully deleted
HKLM\Software\Classes\Interface\{06DE5702-44CF-4B79-B4EF-3DDF653358F5} => Key missing
HKCR\AppID\{1fc41815-fa4c-4f8b-b143-2c045c8ea2fc} => Key successfully deleted
HKLM\Software\Classes\AppID\{1fc41815-fa4c-4f8b-b143-2c045c8ea2fc} => Key missing
HKCR\AppID\{21493C1F-D071-496A-9C27-450578888291} => Key successfully deleted
HKLM\Software\Classes\AppID\{21493C1F-D071-496A-9C27-450578888291} => Key missing
HKCR\TypeLib\{2D77AC8A-0A4C-40D0-9557-51907A575E45} => Key successfully deleted
HKLM\Software\Classes\TypeLib\{2D77AC8A-0A4C-40D0-9557-51907A575E45} => Key missing
HKCR\Interface\{3EDDA953-1C3B-4823-8F25-D075FBB2D2B5} => Key successfully deleted
HKLM\Software\Classes\Interface\{3EDDA953-1C3B-4823-8F25-D075FBB2D2B5} => Key missing
HKCR\AppID\{403A885F-CB00-40C1-BDC1-EB09053194F7} => Key successfully deleted
HKCR\TypeLib\{403A885F-CB00-40C1-BDC1-EB09053194F7} => Key successfully deleted
HKLM\Software\Classes\AppID\{403A885F-CB00-40C1-BDC1-EB09053194F7} => Key missing
HKLM\Software\Classes\TypeLib\{403A885F-CB00-40C1-BDC1-EB09053194F7} => Key missing
HKCR\TypeLib\{43B4B831-F41F-4F73-8F14-4FFF0BA75B1B} => Key successfully deleted
HKLM\Software\Classes\TypeLib\{43B4B831-F41F-4F73-8F14-4FFF0BA75B1B} => Key missing
HKCR\TypeLib\{4C1E5902-FE99-4591-8582-2A2605462857} => Key successfully deleted
HKLM\Software\Classes\TypeLib\{4C1E5902-FE99-4591-8582-2A2605462857} => Key missing
HKCR\AppID\{55C1727F-5535-4C2A-9601-8C2458608B48} => Key successfully deleted
HKCR\TypeLib\{55C1727F-5535-4C2A-9601-8C2458608B48} => Key successfully deleted
HKLM\Software\Classes\AppID\{55C1727F-5535-4C2A-9601-8C2458608B48} => Key missing
HKLM\Software\Classes\TypeLib\{55C1727F-5535-4C2A-9601-8C2458608B48} => Key missing
HKCR\CLSID\{5C00A371-2011-4AF3-97C8-6CE66AA744CB} => Key successfully deleted
HKLM\Software\Classes\CLSID\{5C00A371-2011-4AF3-97C8-6CE66AA744CB} => Key missing
HKCR\AppID\{5e50ae1d-bc76-418b-94c4-efeac0cef80c} => Key successfully deleted
HKLM\Software\Classes\AppID\{5e50ae1d-bc76-418b-94c4-efeac0cef80c} => Key missing
HKCR\AppID\{69E54DE2-C4ED-4BEC-8046-E3F9AC74B4B0} => Key successfully deleted
HKLM\Software\Classes\AppID\{69E54DE2-C4ED-4BEC-8046-E3F9AC74B4B0} => Key missing
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6A87B991-A31F-4130-AE72-6D0C294BF082} => Key successfully deleted
HKCR\TypeLib\{6C9945B7-1D19-46CB-88C0-45A24DF6CD6E} => Key successfully deleted
HKLM\Software\Classes\TypeLib\{6C9945B7-1D19-46CB-88C0-45A24DF6CD6E} => Key missing
HKCR\TypeLib\{81ca8fcd-1420-4a07-b47d-b30f3dda79e1} => Key successfully deleted
HKLM\Software\Classes\TypeLib\{81ca8fcd-1420-4a07-b47d-b30f3dda79e1} => Key missing
HKCR\TypeLib\{84B9B044-17C0-48FB-A300-C9747D5DF29C} => Key successfully deleted
HKLM\Software\Classes\TypeLib\{84B9B044-17C0-48FB-A300-C9747D5DF29C} => Key missing
HKCR\TypeLib\{85672EDB-2CC8-40B9-A9E8-77D3478F2EFB} => Key successfully deleted
HKLM\Software\Classes\TypeLib\{85672EDB-2CC8-40B9-A9E8-77D3478F2EFB} => Key missing
HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{872F3C0B-4462-424c-BB9F-74C6899B9F92} => Key successfully deleted
HKCR\CLSID\{9F038672-0425-4792-BC9C-36DE3308E8AA} => Key successfully deleted
HKLM\Software\Classes\CLSID\{9F038672-0425-4792-BC9C-36DE3308E8AA} => Key missing
HKCR\AppID\{A7DDCBDE-5C86-415c-8A37-763AE183E7E4} => Key successfully deleted
HKLM\Software\Classes\AppID\{A7DDCBDE-5C86-415c-8A37-763AE183E7E4} => Key missing
HKCR\AppID\{AD71F65D-CD13-4837-A2DC-E4D90020E7D4} => Key successfully deleted
HKLM\Software\Classes\AppID\{AD71F65D-CD13-4837-A2DC-E4D90020E7D4} => Key missing
HKCR\Interface\{B67A4CBA-520A-43DB-B03F-414E539F90EC} => Key successfully deleted
HKLM\Software\Classes\Interface\{B67A4CBA-520A-43DB-B03F-414E539F90EC} => Key missing
HKCR\CLSID\{B6F8DA9F-2696-419e-A8A3-19BE41EF51BD} => Key successfully deleted
HKLM\Software\Classes\CLSID\{B6F8DA9F-2696-419e-A8A3-19BE41EF51BD} => Key missing
HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B6F8DA9F-2696-419e-A8A3-19BE41EF51BD} => Key successfully deleted
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} => Key successfully deleted
HKCR\CLSID\{E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} => Key successfully deleted
HKLM\Software\Classes\CLSID\{E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} => Key missing
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{e908b145-c847-4e85-b315-07e2e70decf8} => Key successfully deleted
HKCR\AppID\{F54A0D21-6A53-460C-8301-C694EC9E1033} => Key successfully deleted
HKLM\Software\Classes\AppID\{F54A0D21-6A53-460C-8301-C694EC9E1033} => Key missing
HKCR\AppID\{F7BCCFD4-2FA6-477D-A1B0-EF7500B3C49E} => Key successfully deleted
HKLM\Software\Classes\AppID\{F7BCCFD4-2FA6-477D-A1B0-EF7500B3C49E} => Key missing
HKCR\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF => Key successfully deleted
HKLM\Software\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF => Key missing
HKCR\Installer\UpgradeCodes\CC94835868BCA58489B0D79DE655BCB1 => Key successfully deleted
========== Registry Value(s) ==========
O15 - Trusted Zone: [HKCU\...\Domains\http://www] *.chat-land.org => Value missing
========== Registry Data Item(s) ==========
O15 - Trusted Zone: [HKCU\...\Domains] *.chat-land.org => Data successfully deleted
========== Folder(s) ==========
C:\Documents and Settings\HP_Propriétaire\Application Data\Mozilla\Firefox\Profiles\2kkrg3eh.default\extensions\{4daac69c-cba7-45e2-9bc8-1044483d3352} => Deleted and quarantined
C:\Program Files\Softonic_France => Deleted and quarantined
C:\Program Files\Spybot - Search & Destroy => File deleted at reboot
C:\Program Files\vghd => Deleted and quarantined
C:\Program Files\Common Files\Companion Wizard => Deleted and quarantined
C:\Documents and Settings\HP_Propriétaire\Local Settings\Application Data\ConduitEngine => Deleted and quarantined
C:\Documents and Settings\HP_Propriétaire\Local Settings\Application Data\Softonic_France => Deleted and quarantined
========== File(s) ==========
c:\documents and settings\hp_propriétaire\application data\mozilla\firefox\profiles\2kkrg3eh.default\searchplugins\lphantwebsearch.xml => File missing
========== Summary ==========
64 : Registry Key(s)
1 : Registry Value(s)
1 : Registry Data Item(s)
7 : Folder(s)
1 : File(s)
End of the scan -
Hi,
For Malwarebyte's, you will find the .txt report by following this procedure:
-Open Malwarebyte's
-Click on Reports/Logs
-Double-click on mbam-log, the notepad will open
-Select all and copy/paste the report in your next response
all functions are slow and a message "out of memory on line 2" keeps appearing on my desktop.
What is the status of this issue currently? -
Hello,
Actually, I had already used Malwarebytes in the meantime and the infected files have been cleaned. Here is the latest report anyway. Since the cleanup, I no longer have any ad pages and I don't see the "at memory..." message anymore. However, I still can't open Firefox! And I'm still getting the same message "oops, Firefox crashed..."
Thanks again
Best regards
Netphilou
www.malwarebytes.org
Database version: 6589
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13
05/17/2011 21:11:11
mbam-log-2011-05-17 (21-11-11).txt
Scan type: Full scan (C:\|D:\|E:\|F:\|G:\|H:\|I:\|J:\|K:\|N:\|)
Item(s) scanned: 389731
Elapsed time: 2 hour(s), 33 minute(s), 16 second(s)
Infected memory process(es): 0
Infected memory module(s): 0
Infected Registry key(s): 0
Infected Registry value(s): 0
Infected Registry data item(s): 0
Infected folder(s): 0
Infected file(s): 0
Infected memory process(es):
(No harmful items detected)
Infected memory module(s):
(No harmful items detected)
Infected Registry key(s):
(No harmful items detected)
Infected Registry value(s):
(No harmful items detected)
Infected Registry data item(s):
(No harmful items detected) -
- Please post a new ZHPDiag report via Cjoint.
For Firefox.
If you've sent crash reports, do the following:
* type about:crashes in the address bar and press Enter
* you should get this:
http://www.zimagez.com/zimage/2009-11-04161231.php
* Click on the report IDs to open them
http://www.zimagez.com/zimage/2009-11-04162509.php
* If you have multiple, include 2 or 3
If that doesn't work in normal mode, close Firefox and launch it in safe mode without checking anything (Shift + Firefox icon) -
Here are two of the reports.
A+
Mozilla Crash Reports
Product:
Report:
Advanced Search
Firefox 4.0.1 Crash Report [@ mozalloc_abort(char const* const) | NS_DebugBreak_P | nsCycleCollectingAutoRefCnt::decr(nsISupports*) ]
Search Mozilla Support for Help
ID: f5e4ea48-3048-47af-8055-bb7762110518
Signature: mozalloc_abort(char const* const) | NS_DebugBreak_P | nsCycleCollectingAutoRefCnt::decr(nsISupports*)
Details
Modules
Raw Dump
Extensions
Comments
Correlations
Signature mozalloc_abort(char const* const) | NS_DebugBreak_P | nsCycleCollectingAutoRefCnt::decr(nsISupports*)
UUID f5e4ea48-3048-47af-8055-bb7762110518
Uptime
Last Crash 75121 seconds (20.9 hours) before submission
Install Age 893001 seconds (1.5 weeks) since version was first installed.
Install Time 2011-05-08 08:27:45
Product Firefox
Version 4.0.1
Build ID 20110413222027
Release Channel release
Branch 2.0
OS Windows NT
OS Version 5.1.2600 Service Pack 3
CPU x86
CPU Info GenuineIntel family 15 model 4 stepping 1
Crash Reason EXCEPTION_BREAKPOINT
Crash Address 0x3f1a39
User Comments
App Notes AdapterVendorID: 10de, AdapterDeviceID: 0162, AdapterDriverVersion: 7.7.7.9
D3D10 Layers? D3D10 Layers-
D3D9 Layers? D3D9 Layers-
xpcom_runtime_abort(###!!! ABORT: Main-thread-only object used off the main thread: file e:/builds/moz2_slave/rel-2.0-w32-bld/build/xpcom/base/nsCycleCollector.cpp, line 1195)
Processor Notes
EMCheckCompatibility True
Winsock LSP MSAFD Tcpip [TCP/IP] : 2 : 1 : MSAFD Tcpip [UDP/IP] : 2 : 2 : MSAFD Tcpip [RAW/IP] : 2 : 3 : RSVP UDP Service Provider : 6 : 2 : RSVP TCP Service Provider : 6 : 1 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{B0DF61DC-37C8-463A-BDD5-EEAF141F9FB7}] SEQPACKET 8 : 2 : 5 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{B0DF61DC-37C8-463A-BDD5-EEAF141F9FB7}] DATAGRAM 8 : 2 : 2 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{7311E81C-00F2-4AA3-94A5-C5A7EC25082F}] SEQPACKET 7 : 2 : 5 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{7311E81C-00F2-4AA3-94A5-C5A7EC25082F}] DATAGRAM 7 : 2 : 2 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{3F36D747-77D9-4CA0-A856-1777C0EFF934}] SEQPACKET 6 : 2 : 5 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{3F36D747-77D9-4CA0-A856-1777C0EFF934}] DATAGRAM 6 : 2 : 2 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{2B0B9A7C-4C74-4F27-A8B1-6456C30027AF}] SEQPACKET 5 : 2 : 5 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{2B0B9A7C-4C74-4F27-A8B1-6456C30027AF}] DATAGRAM 5 : 2 : 2 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{950DBBCB-0955-4705-A9F5-7C74FCD37A5D}] SEQPACKET 4 : 2 : 5 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{950DBBCB-0955-4705-A9F5-7C74FCD37A5D}] DATAGRAM 4 : 2 : 2 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{36E5B2A8-0B1C-4161-836B-508331E1C3D3}] SEQPACKET 1 : 2 : 5 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{36E5B2A8-0B1C-4161-836B-508331E1C3D3}] DATAGRAM 1 : 2 : 2 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{DE246E2C-8697-44FE-A5BB-FA04D12D4DEC}] SEQPACKET 0 : 2 : 5 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{DE246E2C-8697-44FE-A5BB-FA04D12D4DEC}] DATAGRAM 0 : 2 : 2 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{E658C067-685E-4840-9EC2-ADC9EA7F2B73}] SEQPACKET 2 : 2 : 5 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{E658C067-685E-4840-9EC2-ADC9EA7F2B73}] DATAGRAM 2 : 2 : 2 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{89939DAA-FFF0-44C3-855E-96DF39B920E1}] SEQPACKET 3 : 2 : 5 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{89939DAA-FFF0-44C3-855E-96DF39B920E1}] DATAGRAM 3 : 2 : 2 :
Adapter Vendor ID
Adapter Device ID
Bugzilla - Report this Crash
Related Bugs
OPEN
633445 NEW Crash [@ mozalloc_abort(char const* const) | NS_DebugBreak_P | nsCycleCollectingAutoRefCnt::decr(nsISupports*) ] [@ mozalloc_abort(char const* const) | NS_DebugBreak_P | AbortIfOffMainThreadIfCheckFast ]
Crashing Thread
Frame Module Signature [Expand] Source
0 mozalloc.dll mozalloc_abort memory/mozalloc/mozalloc_abort.cpp:77
1 xul.dll NS_DebugBreak_P xpcom/base/nsDebugImpl.cpp:350
2 xul.dll nsCycleCollectingAutoRefCnt::decr
3 xul.dll nsGenericElement::Release content/base/src/nsGenericElement.cpp:4505
4 a42e9b8f.dll a42e9b8f.dll@0x325a2
5 a42e9b8f.dll a42e9b8f.dll@0x224b7
6 a42e9b8f.dll a42e9b8f.dll@0x1adb0a
7 a42e9b8f.dll a42e9b8f.dll@0x13a7
8 a42e9b8f.dll a42e9b8f.dll@0xebf8
9 a42e9b8f.dll a42e9b8f.dll@0x13615
10 a42e9b8f.dll a42e9b8f.dll@0x1ae5e7
11 a42e9b8f.dll a42e9b8f.dll@0xfde8
12 a42e9b8f.dll a42e9b8f.dll@0x1aef9f
13 a42e9b8f.dll a42e9b8f.dll@0x649cd
14 ntdll.dll RtlAllocateHeap
15 nss3.dll PKIX_RevocationChecker_Create security/nss/lib/libpkix/pkix/checker/pkix_revocationchecker.c:210
16 nss3.dll CERT_FindNameConstraintsExten security/nss/lib/certdb/genname.c:1570
17 mozjs.dll js::mjit::ic::BindName js/src/methodjit/PolyIC.cpp:1933
18 ntdll.dll RtlFreeHeap
19 a42e9b8f.dll a42e9b8f.dll@0x13ad92
20 a42e9b8f.dll a42e9b8f.dll@0x1b53d5
21 a42e9b8f.dll a42e9b8f.dll@0x64ff5
22 ntdll.dll RtlFreeHeap
23 mozjs.dll BindNameToSlot js/src/jsemit.cpp:2225
24 nss3.dll pkix_pl_PrimHashTable_Remove security/nss/lib/libpkix/pkix_pl_nss/system/pkix_pl_primhash.c:345
25 ssl3.dll ssl_ConfigSecureServer security/nss/lib/ssl/sslsecur.c:723
26 a42e9b8f.dll a42e9b8f.dll@0x1c604f
27 a42e9b8f.dll a42e9b8f.dll@0x1c61b7
28 a42e9b8f.dll a42e9b8f.dll@0x1c6531
29 a42e9b8f.dll a42e9b8f.dll@0x1c03e4
30 a42e9b8f.dll a42e9b8f.dll@0x1c0ebd
31 a42e9b8f.dll a42e9b8f.dll@0x1b7bc0
32 a42e9b8f.dll a42e9b8f.dll@0x1b7f65
33 a42e9b8f.dll a42e9b8f.dll@0x1b31ff
34 a42e9b8f.dll a42e9b8f.dll@0x1c6b6f
35 kernel32.dll GetCodePageFileInfo
36 kernel32.dll BaseThreadStart
37 a42e9b8f.dll a42e9b8f.dll@0x15c7ff
Show/hide other threads
Mozilla Crash Reports - Powered by Socorro
Server Status
Project Info
Source Code
Breakpad Wiki
Privacy Policy
Mozilla Crash Reports
Product:
Report:
Advanced Search
Firefox 4.0.1 Crash Report [@ mozalloc_abort(char const* const) | NS_DebugBreak_P | nsCycleCollectingAutoRefCnt::decr(nsISupports*) ]
Search Mozilla Support for Help
ID: 2e57dc9e-c37a-4fb3-8079-ab36c2110516
Signature: mozalloc_abort(char const* const) | NS_DebugBreak_P | nsCycleCollectingAutoRefCnt::decr(nsISupports*)
Details
Modules
Raw Dump
Extensions
Comments
Correlations
Signature mozalloc_abort(char const* const) | NS_DebugBreak_P | nsCycleCollectingAutoRefCnt::decr(nsISupports*)
UUID 2e57dc9e-c37a-4fb3-8079-ab36c2110516
Uptime
Last Crash 102405 seconds (1.2 days) before submission
Install Age 734457 seconds (1.2 weeks) since version was first installed.
Install Time 2011-05-08 08:27:45
Product Firefox
Version 4.0.1
Build ID 20110413222027
Release Channel release
Branch 2.0
OS Windows NT
OS Version 5.1.2600 Service Pack 3
CPU x86
CPU Info GenuineIntel family 15 model 4 stepping 1
Crash Reason EXCEPTION_BREAKPOINT
Crash Address 0x3f1a39
User Comments
App Notes AdapterVendorID: 10de, AdapterDeviceID: 0162, AdapterDriverVersion: 7.7.7.9
D3D10 Layers? D3D10 Layers-
D3D9 Layers? D3D9 Layers-
xpcom_runtime_abort(###!!! ABORT: Main-thread-only object used off the main thread: file e:/builds/moz2_slave/rel-2.0-w32-bld/build/xpcom/base/nsCycleCollector.cpp, line 1195)
Processor Notes
EMCheckCompatibility True
Winsock LSP MSAFD Tcpip [TCP/IP] : 2 : 1 : MSAFD Tcpip [UDP/IP] : 2 : 2 : MSAFD Tcpip [RAW/IP] : 2 : 3 : RSVP UDP Service Provider : 6 : 2 : RSVP TCP Service Provider : 6 : 1 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{B0DF61DC-37C8-463A-BDD5-EEAF141F9FB7}] SEQPACKET 8 : 2 : 5 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{B0DF61DC-37C8-463A-BDD5-EEAF141F9FB7}] DATAGRAM 8 : 2 : 2 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{7311E81C-00F2-4AA3-94A5-C5A7EC25082F}] SEQPACKET 7 : 2 : 5 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{7311E81C-00F2-4AA3-94A5-C5A7EC25082F}] DATAGRAM 7 : 2 : 2 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{3F36D747-77D9-4CA0-A856-1777C0EFF934}] SEQPACKET 6 : 2 : 5 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{3F36D747-77D9-4CA0-A856-1777C0EFF934}] DATAGRAM 6 : 2 : 2 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{2B0B9A7C-4C74-4F27-A8B1-6456C30027AF}] SEQPACKET 5 : 2 : 5 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{2B0B9A7C-4C74-4F27-A8B1-6456C30027AF}] DATAGRAM 5 : 2 : 2 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{950DBBCB-0955-4705-A9F5-7C74FCD37A5D}] SEQPACKET 4 : 2 : 5 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{950DBBCB-0955-4705-A9F5-7C74FCD37A5D}] DATAGRAM 4 : 2 : 2 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{36E5B2A8-0B1C-4161-836B-508331E1C3D3}] SEQPACKET 1 : 2 : 5 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{36E5B2A8-0B1C-4161-836B-508331E1C3D3}] DATAGRAM 1 : 2 : 2 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{DE246E2C-8697-44FE-A5BB-FA04D12D4DEC}] SEQPACKET 0 : 2 : 5 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{DE246E2C-8697-44FE-A5BB-FA04D12D4DEC}] DATAGRAM 0 : 2 : 2 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{E658C067-685E-4840-9EC2-ADC9EA7F2B73}] SEQPACKET 2 : 2 : 5 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{E658C067-685E-4840-9EC2-ADC9EA7F2B73}] DATAGRAM 2 : 2 : 2 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{89939DAA-FFF0-44C3-855E-96DF39B920E1}] SEQPACKET 3 : 2 : 5 : MSAFD NetBIOS [\Device\NetBT_Tcpip_{89939DAA-FFF0-44C3-855E-96DF39B920E1}] DATAGRAM 3 : 2 : 2 :
Adapter Vendor ID
Adapter Device ID
Bugzilla - Report this Crash
Related Bugs
OPEN
633445 NEW Crash [@ mozalloc_abort(char const* const) | NS_DebugBreak_P | nsCycleCollectingAutoRefCnt::decr(nsISupports*) ] [@ mozalloc_abort(char const* const) | NS_DebugBreak_P | AbortIfOffMainThreadIfCheckFast ]
Crashing Thread
Frame Module Signature [Expand] Source
0 mozalloc.dll mozalloc_abort memory/mozalloc/mozalloc_abort.cpp:77
1 xul.dll NS_DebugBreak_P xpcom/base/nsDebugImpl.cpp:350
2 xul.dll nsCycleCollectingAutoRefCnt::decr
3 xul.dll nsGlobalWindow::Release dom/base/nsGlobalWindow.cpp:1335
4 a42e9b8f.dll a42e9b8f.dll@0x325a2
5 a42e9b8f.dll a42e9b8f.dll@0x14a7
6 a42e9b8f.dll a42e9b8f.dll@0x1af171
7 a42e9b8f.dll a42e9b8f.dll@0x23fe7
8 a42e9b8f.dll a42e9b8f.dll@0xebf8
9 a42e9b8f.dll a42e9b8f.dll@0xde0c8
10 a42e9b8f.dll a42e9b8f.dll@0x1be14a
11 a42e9b8f.dll a42e9b8f.dll@0xde0f7
12 a42e9b8f.dll a42e9b8f.dll@0x15c426
13 a42e9b8f.dll a42e9b8f.dll@0x1c6aef
14 a42e9b8f.dll a42e9b8f.dll@0x15c91c
15 ntdll.dll RtlpGetRegistrationHead
16 a42e9b8f.dll a42e9b8f.dll@0x1c6b6f
17 kernel32.dll BaseThreadStart
18 ntdll.dll RtlpGetRegistrationHead
19 kernel32.dll GetCodePageFileInfo
20 kernel32.dll BaseThreadStart
21 a42e9b8f.dll a42e9b8f.dll@0x15c7ff
Show/hide other threads
Mozilla Crash Reports - Powered by Socorro
Server Status
Project Info
Source Code
Breakpad Wiki
Privacy Policy
Log In
Log In -
-Please post a new ZHPDiag report, please (still via Cjoint).
-
-
Sorry, but your link doesn't point to anything
Launch ZHPDiag and click on the icon with an arrow (to the left of the screwdriver)
Once the update is complete, run a scan again and post a new report, please (still via Cjoint)
- Click on Browse to find the report
- Click on Open then Create Cjoint link
- In your next response, copy and paste the link that is displayed in front... The link has been created: -
Good evening,
I hope that this time, I did the right manipulation.
Best regards
Netphilou
https://www.cjoint.com/?AEtrPTa1k8S -
Sorry for the delay,
Attention, uninstalling software will be requested; please accept this but refuse any PC restart to avoid interrupting the fix.
* Launch ZHPFix (if you are on Windows Vista or Windows 7, run it by right-clicking on it --> run as administrator).
* Copy the following lines:
---------------------------------------------------
O42 - Software: Adobe Acrobat 5.0 - (.Adobe Systems, Inc..) [HKLM] -- Adobe Acrobat 5.0
O42 - Software: J2SE Runtime Environment 5.0 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0150000}
O42 - Software: Java(TM) 6 Update 17 - (.Sun Microsystems, Inc..) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83216011FF}
O42 - Software: Java(TM) 6 Update 2 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0160020}
O42 - Software: Java(TM) 6 Update 3 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0160030}
O42 - Software: Java(TM) 6 Update 4 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0160040}
O42 - Software: Java(TM) 6 Update 5 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0160050}
O42 - Software: Java(TM) 6 Update 7 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0160070}
O42 - Software: Java(TM) SE Runtime Environment 6 Update 1 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0160010}
[HKLM\Software\Classes\AppID\SoftwareUpdate.exe]
O69 - SBI: SearchScopes [HKCU] {9091C5EC-8529-4EE0-9B0D-96A0520FFB90} - (Search) - http://flvdirect.iamwired.net
O69 - SBI: SearchScopes [HKCU] {B320F28C-6347-46e4-98FF-5261CA66FEDA} - (Web Search) - http://search.shareazaweb.net/
EmptyTemp
EmptyFlash
---------------------------------------------------
* * Click on the icon representing the letter H (“paste Helper lines”)
* The lines will automatically paste into ZHPFix.
* Click the “GO” button to start the cleanup,
* Copy/paste the entire report into your next response
Post the report that is saved in this folder -> ( C:\Program files\ZHPFix\ZHPFixReport.txt )
********************************************************
I see that you have the software Alcohol but for safety reasons
please analyze this file using Virus Total
-Click on browse and open this file
--------------------------------------------------
C:\PhysicalDisk0_MBR.bin
--------------------------------------------------
-click on Send
Once the analysis is complete
copy/paste the link found in the address bar in your next response -
Hello,
Here is the report
ZHPFix Report 1.12.3283 by Nicolas Coolman, Update of 14/05/2011
Registry export file: C:\ZHPExportRegistry-22.05.2011-12-59-10.txt
Run by HP_Owner at 22.05.2011 12:59:10
Windows XP Home Edition Service Pack 3 (Build 2600)
Web site: http://www.premiumorange.com/zeb-help-process/zhpfix.html
========== Registry Key(s) ==========
O42 - Software: J2SE Runtime Environment 5.0 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0150000} => Software uninstallation canceled by user or partial uninstallation!
O42 - Software: Java(TM) 6 Update 17 - (.Sun Microsystems, Inc..) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83216011FF} => Software uninstallation canceled by user or partial uninstallation!
O42 - Software: Java(TM) 6 Update 2 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0160020} => Software uninstallation canceled by user or partial uninstallation!
O42 - Software: Java(TM) 6 Update 3 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0160030} => Software uninstallation canceled by user or partial uninstallation!
O42 - Software: Java(TM) 6 Update 4 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0160040} => Software uninstallation canceled by user or partial uninstallation!
O42 - Software: Java(TM) 6 Update 5 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0160050} => Software uninstallation canceled by user or partial uninstallation!
O42 - Software: Java(TM) 6 Update 7 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0160070} => Software uninstallation canceled by user or partial uninstallation!
O42 - Software: Java(TM) SE Runtime Environment 6 Update 1 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0160010} => Software uninstallation canceled by user or partial uninstallation!
HKLM\Software\Classes\AppID\SoftwareUpdate.exe => Key successfully deleted
O69 - SBI: SearchScopes [HKCU] {9091C5EC-8529-4EE0-9B0D-96A0520FFB90} - (Search) - http://flvdirect.iamwired.net => Key successfully deleted
O69 - SBI: SearchScopes [HKCU] {B320F28C-6347-46e4-98FF-5261CA66FEDA} - (Web Search) - http://search.shareazaweb.net/ => Key successfully deleted
========== Folder(s) ==========
Windows temporary folders deleted: 1620
Flash Cookies folders deleted: 351
========== File(s) ==========
Windows temporary files deleted: 52
Flash Cookies files deleted: 143
========== Summary ==========
11 : Registry Key(s)
2 : Folder(s)
2 : File(s)
End of the scan -
Je suis désolé, mais je ne peux pas accéder ou traduire des contenus à partir de liens externes.
- 1
- 2
Next