Soin système avancé
Solved
supermamie54
-
nono -
nono -
Hello,
I have Advanced System Care on my computer, but I don’t know what it’s for or if it’s any good.
I also have Ad Aware and Avast, as well as Auslogics Disk Defrag.
Can you tell me if it’s good and what you recommend? I don’t know anything about computers.
Should I remove something or keep everything?
Thank you for your help.
Configuration: Windows 7 / Internet Explorer 9.0
I have Advanced System Care on my computer, but I don’t know what it’s for or if it’s any good.
I also have Ad Aware and Avast, as well as Auslogics Disk Defrag.
Can you tell me if it’s good and what you recommend? I don’t know anything about computers.
Should I remove something or keep everything?
Thank you for your help.
Configuration: Windows 7 / Internet Explorer 9.0
52 réponses
- 1
- 2
- 3
Suivant
Hello,
- Advanced SystemCare is a cleaning and optimization utility for PCs (... one of many others). Keep it or not...
- AdAware is antispyware, spyware protection software. Keep it or not...
- Avast is an antivirus, essential on Windows (... unfortunately)
- Auslogics Disk Defrag. It’s a disk defragmenter. Useless in my opinion. Windows does that very well...
Gilles.
- Advanced SystemCare is a cleaning and optimization utility for PCs (... one of many others). Keep it or not...
- AdAware is antispyware, spyware protection software. Keep it or not...
- Avast is an antivirus, essential on Windows (... unfortunately)
- Auslogics Disk Defrag. It’s a disk defragmenter. Useless in my opinion. Windows does that very well...
Gilles.
Thank you for your response, but I did some research on Google and I thought I saw that Advanced System Care is good. Do you recommend I keep it and remove the others? Or should I remove everything? Actually, my computer is slow and my stepdaughter saw that I have Avast, AVG, McAfee, and Norton, and she told me that it's too much. What should I do? She advised me to post a message here and that someone could help me. Thank you very much and I'm sorry to bother you.
So you should keep only one antivirus as there is a risk of crashing
https://forums.commentcamarche.net/forum/affich-25206601-advanced-system-care#2
We will provide you with the specific tools for uninstalling antivirus programs
As for the rest, I answered you earlier.
https://forums.commentcamarche.net/forum/affich-25206601-advanced-system-care#2
We will provide you with the specific tools for uninstalling antivirus programs
As for the rest, I answered you earlier.
I don't know why there are so many antivirus programs, but my youngest son put a lot of things on the computer, and since I don’t know much about it, I’m looking into it and I realize that he really messed things up.
Thank you very much for your responses.
Thank you very much for your responses.
So
First of all, I need a list of all the installed software
To do this, read this topic https://forums.cnetfrance.fr/tutoriels-logiciels-et-applis/165089-hijackthis-connaitre-la-liste-des-logiciels-installes-sur-son-pc
Install the suggested software and do exactly what is described in this topic
Then post the report here to see all the software on your computer
We will see what to do next based on the results
Good luck
First of all, I need a list of all the installed software
To do this, read this topic https://forums.cnetfrance.fr/tutoriels-logiciels-et-applis/165089-hijackthis-connaitre-la-liste-des-logiciels-installes-sur-son-pc
Install the suggested software and do exactly what is described in this topic
Then post the report here to see all the software on your computer
We will see what to do next based on the results
Good luck
Good evening,
* Download ZHPDiag to your desktop:
https://www.zebulon.fr/telechargements/securite/systeme/zhpdiag.html
or
http://www.premiumorange.com/zeb-help-process/zhpdiag.html
or
https://www.commentcamarche.net/telecharger/utilitaires/24803-zhpdiag/
* Follow the instructions during installation; it will launch automatically at the end.
/!\ Vista and Seven users: Right-click on the ZHPdiag logo, "Run as Administrator"
* Click on the icon representing a magnifying glass ("Start the diagnosis")
* Save the report to your Desktop using the icon representing a diskette
* Host the ZHPDiag.txt report on Cjoint, then copy/paste the provided link in your next response on the forum:
https://www.cjoint.com/ => https://www.commentcamarche.net/faq/29493-utiliser-cjoint-pour-heberger-des-fichiers
--
<bold>O.o°*♪♪♫ Member, Security Contributor CCM o°.Oø¤º°'°º¤ø
O.o°* ♪♪♫ Breathe deeply, write your message in proper French and clearly. It will go well, you'll see, at least we’ll try!!! o°.Oø¤º°'°º¤ø
* Download ZHPDiag to your desktop:
https://www.zebulon.fr/telechargements/securite/systeme/zhpdiag.html
or
http://www.premiumorange.com/zeb-help-process/zhpdiag.html
or
https://www.commentcamarche.net/telecharger/utilitaires/24803-zhpdiag/
* Follow the instructions during installation; it will launch automatically at the end.
/!\ Vista and Seven users: Right-click on the ZHPdiag logo, "Run as Administrator"
* Click on the icon representing a magnifying glass ("Start the diagnosis")
* Save the report to your Desktop using the icon representing a diskette
* Host the ZHPDiag.txt report on Cjoint, then copy/paste the provided link in your next response on the forum:
https://www.cjoint.com/ => https://www.commentcamarche.net/faq/29493-utiliser-cjoint-pour-heberger-des-fichiers
--
<bold>O.o°*♪♪♫ Member, Security Contributor CCM o°.Oø¤º°'°º¤ø
O.o°* ♪♪♫ Breathe deeply, write your message in proper French and clearly. It will go well, you'll see, at least we’ll try!!! o°.Oø¤º°'°º¤ø
So you can remove adware without worry, it’s not very effective. Read this https://forum.malekal.com/viewtopic.php?t=25480&start=
advanced system care, you can replace it with ccleaner, much simpler and more effective
keep avast and auslogics disc defrag, two very good software.
advanced system care, you can replace it with ccleaner, much simpler and more effective
keep avast and auslogics disc defrag, two very good software.
Hello,
You have two antivirus programs on your PC, Norton and Avast!
Which one do you use?
You should keep only one, the other needs to be uninstalled!
Your PC is infested with adware (infectious toolbars!)
Avoid installing them in the future :D
? Download and save ADWcleaner on your desktop (Thanks to Xplode):
https://toolslib.net
Run it,
click on Remove and post its report.
--
O.o°*♪♪♫ Member, Security Contributor CCM o°.Oø¤º°'°º¤ø
O.o°* ♪♪♫ Breathe deeply, write your message in good French and clearly. It will go well, you'll see, well, we’ll try!!! o°.Oø¤º°'°º¤ø
You have two antivirus programs on your PC, Norton and Avast!
Which one do you use?
You should keep only one, the other needs to be uninstalled!
Your PC is infested with adware (infectious toolbars!)
Avoid installing them in the future :D
? Download and save ADWcleaner on your desktop (Thanks to Xplode):
https://toolslib.net
Run it,
click on Remove and post its report.
--
O.o°*♪♪♫ Member, Security Contributor CCM o°.Oø¤º°'°º¤ø
O.o°* ♪♪♫ Breathe deeply, write your message in good French and clearly. It will go well, you'll see, well, we’ll try!!! o°.Oø¤º°'°º¤ø
super,
use this to uninstall Norton:
http://service1.symantec.com/SUPPORT/INTER/tsgeninfointl.nsf/en_docid/20050414110429924
A supplement:
https://www.commentcamarche.net/telecharger/utilitaires/22737-unlocker/
once Norton is uninstalled, run a new zhpdiag, go through cjoint to send me the link to the report :D
O.o°*??? Member, Security Contributor CCM o°.Oø¤º°'°º¤ø
O.o°* ??? Breathe deeply, write your message in proper French and clearly. It will go well, you will see, well let's try!!! o°.Oø¤º°'°º¤ø
use this to uninstall Norton:
http://service1.symantec.com/SUPPORT/INTER/tsgeninfointl.nsf/en_docid/20050414110429924
A supplement:
https://www.commentcamarche.net/telecharger/utilitaires/22737-unlocker/
once Norton is uninstalled, run a new zhpdiag, go through cjoint to send me the link to the report :D
O.o°*??? Member, Security Contributor CCM o°.Oø¤º°'°º¤ø
O.o°* ??? Breathe deeply, write your message in proper French and clearly. It will go well, you will see, well let's try!!! o°.Oø¤º°'°º¤ø
Hello,
Avast seems a bit damaged; it should be uninstalled and reinstalled later!
Install the latest version of Java and Adobe Reader from their dedicated websites, for Adobe, uncheck the Google toolbar before installation:
Java:
https://www.java.com/en/download/
Adobe:
https://get2.adobe.com/en/reader/otherversions/
* Launch ZHPFix via the shortcut on your Desktop
Click on the icon representing the letter H (“paste the Helper lines”)
* * Copy (Ctrl + C) and paste (Ctrl + V) the following bold lines into Zhpfix:
---------------------------------------------------------
SS - | Demand 01/15/2010 227232 | (McComponentHostService) . (.McAfee, Inc..) - C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [MD5.00000000000000000000000000000000] [APT] [Norton Error Analyzer] (...) -- C:\Program Files (x86)\Norton Internet Security\Engine\19.1.0.28\SymErr.exe (.not file.)
[MD5.00000000000000000000000000000000] [APT] [Norton Error Processor] (...) -- C:\Program Files (x86)\Norton Internet Security\Engine\19.1.0.28\SymErr.exe (.not file.)
O42 - Software: McAfee Security Scan Plus - (.McAfee, Inc..) [HKLM] -- McAfee Security Scan
[MD5.00000000000000000000000000000000] [APT] [Norton WSC Integration] (...) -- C:\Program Files (x86)\Norton Internet Security\Engine\19.1.0.28\WSCStub.exe (.not file.)
O23 - Service: Lavasoft Ad-Aware Service (Lavasoft Ad-Aware Service) . (.Lavasoft Limited - Ad-Aware Service Application.) - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
SR - | Auto 03/12/2011 2152152 | (Lavasoft Ad-Aware Service) . (.Lavasoft Limited.) - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
O87 - FAEL: "{5B34F80E-8EB5-468F-8C1B-C2649F5F228B}" |In - Public - P6 - TRUE | .(...) -- C:\Users\sylvie\AppData\Local\Temp\7zS43B6.tmp\SYMNRT.exe (.not file.)
O87 - FAEL: "{3EB32A6A-1EF6-4F48-A765-1485D174BB31}" |In - Public - P17 - TRUE | .(...) -- C:\Users\sylvie\AppData\Local\Temp\7zS43B6.tmp\SYMNRT.exe (.not file.)
[MD5.5608E451B9D69B548103BA9CF39A3527] [APT] [Ad-Aware Update (Weekly)] (.Lavasoft Limited.) -- C:\Program Files (x86)\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe
[MD5.00000000000000000000000000000000] [APT] [{50A74C38-C703-45BC-AC21-9F31959407F9}] (...) -- C:\Users\sylvie\Desktop\OpenOffice.org 3.2 (fr) Installation Files\setup.exe (.not file.)
O43 - CFD: 03/04/2011 - 18:38:50 - [49,128] ----D C:\Program Files (x86)\Fluendo
O43 - CFD: 03/04/2011 - 18:38:50 - [49,128] ----D C:\Program Files (x86)\Fluendo
O87 - FAEL: "{630462C5-AACF-49B8-ADF5-010D7DD6548F}" |In - None - P17 - TRUE | .(...) -- C:\Program Files (x86)\Iminent\Iminent.exe (.not file.)
O87 - FAEL: "{C747C427-9F9A-4454-98A5-53468DCF3D51}" |In - None - P17 - TRUE | .(...) -- C:\Program Files (x86)\Iminent\Iminent.Messengers.exe (.not file.)
[HKLM\Software\Classes\TypeLib\{14816CF6-426C-40D7-904C-E5600F015EC2}]
[HKLM\Software\Classes\TypeLib\{282D18C0-5424-44F4-A531-55F9AC5B8FD8}]
[HKLM\Software\WOW6432Node\Classes\Interface\{7935436E-8F14-4C84-9ECF-BEB791296619}]
[HKLM\Software\WOW6432Node\Classes\Interface\{7CF4E72E-C9C0-4CA8-A039-1F5BAD426CCE}]
[HKLM\Software\WOW6432Node\Classes\Interface\{81B32B9F-AFDC-4F7E-8F13-E39BB8ECF638}]
[HKLM\Software\WOW6432Node\Classes\Interface\{925C24DC-0C0B-4AE7-98F5-18252822C89C}]
[HKLM\Software\WOW6432Node\Classes\Interface\{B3DBB2D5-5F06-4EC2-904D-812ECE520509}]
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C4A743DE-EAAC-4cd0-9BF6-378E8141868B}]
[HKLM\Software\WOW6432Node\Classes\Interface\{CA1BC665-4B6B-435C-80C1-0E12D993ED49}]
[HKLM\Software\WOW6432Node\Classes\Interface\{D5AB027D-C91A-4324-8C78-12CF1A588C48}]
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DCE997C8-5920-4c09-99EE-59F46634FE2C}] [HKLM\Software\WOW6432Node\Classes\Interface\{E5DB89B8-5BE1-461C-A7EF-89B68211889D}]
[HKLM\Software\Classes\TypeLib\{FD06B491-1EA6-4F5C-86D2-C86D3A3A3731}]
C:\Program Files (x86)\Fluendo\Moovida
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Moovida
C:\Program Files (x86)\rbjcl.vbs
SR - | Auto 932736 | (vToolbarUpdater11.0.2) . (...) - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.0.2\ToolbarUpdater.exe
[MD5.0307C96067C8659E9F168F7FB8AF5E72] - (.IWON - IWON Browser Plugin Loader.) -- C:\Program Files (x86)\IWONGIE\bar\1.bin\vrbrmon.exe [20480] [PID.2632]
[MD5.5414FB18161F794BAA1DBBB0764D9428] - (.IWON - IWON.) -- C:\Program Files (x86)\IWONGIE\bar\1.bin\vrbarsvc.exe [28766] [PID.]
[MD5.56E1E4442E4613FB2039A6B7421F4E58] - (.No owner - ToolbarU Application.) -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.0.2\ToolbarUpdater.exe [932736] [PID.]
O2 - BHO: Search Assistant BHO [64Bits] - {f0f3f55e-edfc-4ed4-affb-bcaf081ddeba} . (.IWON - IWON Search Assistant.) -- C:\Program Files (x86)\IWONGIE\bar\1.bin\vrSrcAs.dll
O2 - BHO: Toolbar BHO [64Bits] - {d6995d07-cd9b-4cc0-a22a-9e14684d6d64} . (.IWON - IWON.) -- C:\Program Files (x86)\IWONGIE\bar\1.bin\vrbar.dll
O4 - HKLM\..\Wow6432Node\Run: [IWONGIE Browser Plugin Loader] . (.IWON - IWON Browser Plugin Loader.) -- C:\Program Files (x86)\IWONGIE\bar\1.bin\vrbrmon.exe
O23 - Service: IWON Service (IWONGIEService) . (.IWON - IWON.) - C:\Program Files (x86)\IWONGIE\bar\1.bin\vrbarsvc.exe
O23 - Service: (vToolbarUpdater11.0.2) . (.No owner - ToolbarU Application.) - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.0.2\ToolbarUpdater.exe
[HKCU\Software\AppDataLow\Software\IWONGIE]
[HKLM\Software\IWONGIE]
O43 - CFD: 01/30/2011 - 14:17:40 - [1,943] ----D C:\Program Files (x86)\IWONGIE
O43 - CFD: 01/30/2011 - 14:17:40 - [1,943] ----D C:\Program Files (x86)\IWONGIE
R3 - URLSearchHook: (no name) [64Bits] - {2ad11eb6-a327-4dfe-88bf-c6071e09f05b} . (.IWON - IWON Search Assistant.) (1, 2, 3, 0) -- C:\Program Files (x86)\IWONGIE\bar\1.bin\vrSrcAs.dll
[MD5.417159584F4303DD5E23367C187064B7] - (.IObit - Advanced SystemCare 5 DelayLoad.) -- C:\Program Files (x86)\IObit\Advanced SystemCare 5\DelayLoad.exe [368472] [PID.1716]
[MD5.3D672573EF8F317F10C2AABBB2586262] - (.IObit - Advanced SystemCare Service.) -- C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCService.exe [500568] [PID.]
[MD5.71D52CA4553E033DDD5C07D6FC6666B2] - (.IObit - Advanced SystemCare 5.) -- C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASC.exe [4878680] [PID.]
[MD5.78B24A64F84603784A10C86F4CEF71AF] - (.IObit - Advanced SystemCare 5 Tray.) -
O4 - HKUS\S-1-5-18\..\Run: [Advanced SystemCare 5] . (.IObit - Advanced SystemCare 5 Tray.) -- C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCTray.exe
O4 - HKUS\S-1-5-18\..\Run: [Advanced SystemCare 5] . (.IObit - Advanced SystemCare 5 Tray.) -- C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCTray.exe
O23 - Service: Advanced SystemCare Service 5 (AdvancedSystemCareService5) . (.IObit - Advanced SystemCare Service.) - C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCService.exe
O42 - Software: Advanced SystemCare 5 - (.IObit.) [HKLM] -- Advanced SystemCare 5_is1
SR - | Auto 02/01/2012 500568 | (AdvancedSystemCareService5) . (.IObit.) - C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCService.exe
Emptytemp
----------------------------------------------------------
- Click on the "GO" button to start the cleanup,
- Copy/paste the entire report into your next response
Tutorial:
http://www.premiumorange.com/zeb-help-process/zhpfix.html
Download Malwarebytes' Anti-Malware and save it to your desktop:
https://fr.malwarebytes.com/mwb-download/
or:
https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
or here:
https://www.commentcamarche.net/telecharger/securite/14361-malwarebytes-anti-malware/
/!\ Vista and Windows 7 users: Right-click on the Malwarebytes' Anti-Malware logo, "run as Administrator"
. Double-click on the downloaded file to start the installation process.
. In the "update" tab, click on the "Check for updates" button
. If the firewall asks for permission to connect for Malwarebytes, accept it
. Once the update is complete
. go to the "Scan" tab
. Select Run a full scan
. Click on Scan
. The scan starts.
. At the end of the scan, a message will appear: The scan has completed normally. Click on 'Show results' to display all found items.
. Click OK to continue.
. If any malware has been detected, click on Show results
. Select all (or leave checked) and click on Remove the selected Malwarebytes will delete the files and registry keys and put a copy in quarantine.
. Malwarebytes will open Notepad and copy the scan report.
. Go to the report/log tab
. Click on it to display it once displayed
. Click on edit at the top of Notepad, then select all
. Click edit again and then copy, and return to the forum and in your reply
. Right-click in the reply box and paste
. At the end of the scan, Malwarebytes may need to restart the PC to finalize the removal, so don’t panic, restart your PC !!!
If you need help, check out this tutorial:
https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
I have to get to work, @ ++
--
O.o°*♪♪♫ Member, Security Contributor CCM o°.Oø¤º°'°º¤ø
O.o°* ♪♪♫ Breathe deeply, write your message clearly and in good French. It will go well, you’ll see, we’re trying!!! o°.Oø¤º°'°º¤ø
Avast seems a bit damaged; it should be uninstalled and reinstalled later!
Install the latest version of Java and Adobe Reader from their dedicated websites, for Adobe, uncheck the Google toolbar before installation:
Java:
https://www.java.com/en/download/
Adobe:
https://get2.adobe.com/en/reader/otherversions/
* Launch ZHPFix via the shortcut on your Desktop
Click on the icon representing the letter H (“paste the Helper lines”)
* * Copy (Ctrl + C) and paste (Ctrl + V) the following bold lines into Zhpfix:
---------------------------------------------------------
SS - | Demand 01/15/2010 227232 | (McComponentHostService) . (.McAfee, Inc..) - C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [MD5.00000000000000000000000000000000] [APT] [Norton Error Analyzer] (...) -- C:\Program Files (x86)\Norton Internet Security\Engine\19.1.0.28\SymErr.exe (.not file.)
[MD5.00000000000000000000000000000000] [APT] [Norton Error Processor] (...) -- C:\Program Files (x86)\Norton Internet Security\Engine\19.1.0.28\SymErr.exe (.not file.)
O42 - Software: McAfee Security Scan Plus - (.McAfee, Inc..) [HKLM] -- McAfee Security Scan
[MD5.00000000000000000000000000000000] [APT] [Norton WSC Integration] (...) -- C:\Program Files (x86)\Norton Internet Security\Engine\19.1.0.28\WSCStub.exe (.not file.)
O23 - Service: Lavasoft Ad-Aware Service (Lavasoft Ad-Aware Service) . (.Lavasoft Limited - Ad-Aware Service Application.) - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
SR - | Auto 03/12/2011 2152152 | (Lavasoft Ad-Aware Service) . (.Lavasoft Limited.) - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
O87 - FAEL: "{5B34F80E-8EB5-468F-8C1B-C2649F5F228B}" |In - Public - P6 - TRUE | .(...) -- C:\Users\sylvie\AppData\Local\Temp\7zS43B6.tmp\SYMNRT.exe (.not file.)
O87 - FAEL: "{3EB32A6A-1EF6-4F48-A765-1485D174BB31}" |In - Public - P17 - TRUE | .(...) -- C:\Users\sylvie\AppData\Local\Temp\7zS43B6.tmp\SYMNRT.exe (.not file.)
[MD5.5608E451B9D69B548103BA9CF39A3527] [APT] [Ad-Aware Update (Weekly)] (.Lavasoft Limited.) -- C:\Program Files (x86)\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe
[MD5.00000000000000000000000000000000] [APT] [{50A74C38-C703-45BC-AC21-9F31959407F9}] (...) -- C:\Users\sylvie\Desktop\OpenOffice.org 3.2 (fr) Installation Files\setup.exe (.not file.)
O43 - CFD: 03/04/2011 - 18:38:50 - [49,128] ----D C:\Program Files (x86)\Fluendo
O43 - CFD: 03/04/2011 - 18:38:50 - [49,128] ----D C:\Program Files (x86)\Fluendo
O87 - FAEL: "{630462C5-AACF-49B8-ADF5-010D7DD6548F}" |In - None - P17 - TRUE | .(...) -- C:\Program Files (x86)\Iminent\Iminent.exe (.not file.)
O87 - FAEL: "{C747C427-9F9A-4454-98A5-53468DCF3D51}" |In - None - P17 - TRUE | .(...) -- C:\Program Files (x86)\Iminent\Iminent.Messengers.exe (.not file.)
[HKLM\Software\Classes\TypeLib\{14816CF6-426C-40D7-904C-E5600F015EC2}]
[HKLM\Software\Classes\TypeLib\{282D18C0-5424-44F4-A531-55F9AC5B8FD8}]
[HKLM\Software\WOW6432Node\Classes\Interface\{7935436E-8F14-4C84-9ECF-BEB791296619}]
[HKLM\Software\WOW6432Node\Classes\Interface\{7CF4E72E-C9C0-4CA8-A039-1F5BAD426CCE}]
[HKLM\Software\WOW6432Node\Classes\Interface\{81B32B9F-AFDC-4F7E-8F13-E39BB8ECF638}]
[HKLM\Software\WOW6432Node\Classes\Interface\{925C24DC-0C0B-4AE7-98F5-18252822C89C}]
[HKLM\Software\WOW6432Node\Classes\Interface\{B3DBB2D5-5F06-4EC2-904D-812ECE520509}]
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C4A743DE-EAAC-4cd0-9BF6-378E8141868B}]
[HKLM\Software\WOW6432Node\Classes\Interface\{CA1BC665-4B6B-435C-80C1-0E12D993ED49}]
[HKLM\Software\WOW6432Node\Classes\Interface\{D5AB027D-C91A-4324-8C78-12CF1A588C48}]
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DCE997C8-5920-4c09-99EE-59F46634FE2C}] [HKLM\Software\WOW6432Node\Classes\Interface\{E5DB89B8-5BE1-461C-A7EF-89B68211889D}]
[HKLM\Software\Classes\TypeLib\{FD06B491-1EA6-4F5C-86D2-C86D3A3A3731}]
C:\Program Files (x86)\Fluendo\Moovida
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Moovida
C:\Program Files (x86)\rbjcl.vbs
SR - | Auto 932736 | (vToolbarUpdater11.0.2) . (...) - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.0.2\ToolbarUpdater.exe
[MD5.0307C96067C8659E9F168F7FB8AF5E72] - (.IWON - IWON Browser Plugin Loader.) -- C:\Program Files (x86)\IWONGIE\bar\1.bin\vrbrmon.exe [20480] [PID.2632]
[MD5.5414FB18161F794BAA1DBBB0764D9428] - (.IWON - IWON.) -- C:\Program Files (x86)\IWONGIE\bar\1.bin\vrbarsvc.exe [28766] [PID.]
[MD5.56E1E4442E4613FB2039A6B7421F4E58] - (.No owner - ToolbarU Application.) -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.0.2\ToolbarUpdater.exe [932736] [PID.]
O2 - BHO: Search Assistant BHO [64Bits] - {f0f3f55e-edfc-4ed4-affb-bcaf081ddeba} . (.IWON - IWON Search Assistant.) -- C:\Program Files (x86)\IWONGIE\bar\1.bin\vrSrcAs.dll
O2 - BHO: Toolbar BHO [64Bits] - {d6995d07-cd9b-4cc0-a22a-9e14684d6d64} . (.IWON - IWON.) -- C:\Program Files (x86)\IWONGIE\bar\1.bin\vrbar.dll
O4 - HKLM\..\Wow6432Node\Run: [IWONGIE Browser Plugin Loader] . (.IWON - IWON Browser Plugin Loader.) -- C:\Program Files (x86)\IWONGIE\bar\1.bin\vrbrmon.exe
O23 - Service: IWON Service (IWONGIEService) . (.IWON - IWON.) - C:\Program Files (x86)\IWONGIE\bar\1.bin\vrbarsvc.exe
O23 - Service: (vToolbarUpdater11.0.2) . (.No owner - ToolbarU Application.) - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.0.2\ToolbarUpdater.exe
[HKCU\Software\AppDataLow\Software\IWONGIE]
[HKLM\Software\IWONGIE]
O43 - CFD: 01/30/2011 - 14:17:40 - [1,943] ----D C:\Program Files (x86)\IWONGIE
O43 - CFD: 01/30/2011 - 14:17:40 - [1,943] ----D C:\Program Files (x86)\IWONGIE
R3 - URLSearchHook: (no name) [64Bits] - {2ad11eb6-a327-4dfe-88bf-c6071e09f05b} . (.IWON - IWON Search Assistant.) (1, 2, 3, 0) -- C:\Program Files (x86)\IWONGIE\bar\1.bin\vrSrcAs.dll
[MD5.417159584F4303DD5E23367C187064B7] - (.IObit - Advanced SystemCare 5 DelayLoad.) -- C:\Program Files (x86)\IObit\Advanced SystemCare 5\DelayLoad.exe [368472] [PID.1716]
[MD5.3D672573EF8F317F10C2AABBB2586262] - (.IObit - Advanced SystemCare Service.) -- C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCService.exe [500568] [PID.]
[MD5.71D52CA4553E033DDD5C07D6FC6666B2] - (.IObit - Advanced SystemCare 5.) -- C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASC.exe [4878680] [PID.]
[MD5.78B24A64F84603784A10C86F4CEF71AF] - (.IObit - Advanced SystemCare 5 Tray.) -
O4 - HKUS\S-1-5-18\..\Run: [Advanced SystemCare 5] . (.IObit - Advanced SystemCare 5 Tray.) -- C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCTray.exe
O4 - HKUS\S-1-5-18\..\Run: [Advanced SystemCare 5] . (.IObit - Advanced SystemCare 5 Tray.) -- C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCTray.exe
O23 - Service: Advanced SystemCare Service 5 (AdvancedSystemCareService5) . (.IObit - Advanced SystemCare Service.) - C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCService.exe
O42 - Software: Advanced SystemCare 5 - (.IObit.) [HKLM] -- Advanced SystemCare 5_is1
SR - | Auto 02/01/2012 500568 | (AdvancedSystemCareService5) . (.IObit.) - C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCService.exe
Emptytemp
----------------------------------------------------------
- Click on the "GO" button to start the cleanup,
- Copy/paste the entire report into your next response
Tutorial:
http://www.premiumorange.com/zeb-help-process/zhpfix.html
Download Malwarebytes' Anti-Malware and save it to your desktop:
https://fr.malwarebytes.com/mwb-download/
or:
https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
or here:
https://www.commentcamarche.net/telecharger/securite/14361-malwarebytes-anti-malware/
/!\ Vista and Windows 7 users: Right-click on the Malwarebytes' Anti-Malware logo, "run as Administrator"
. Double-click on the downloaded file to start the installation process.
. In the "update" tab, click on the "Check for updates" button
. If the firewall asks for permission to connect for Malwarebytes, accept it
. Once the update is complete
. go to the "Scan" tab
. Select Run a full scan
. Click on Scan
. The scan starts.
. At the end of the scan, a message will appear: The scan has completed normally. Click on 'Show results' to display all found items.
. Click OK to continue.
. If any malware has been detected, click on Show results
. Select all (or leave checked) and click on Remove the selected Malwarebytes will delete the files and registry keys and put a copy in quarantine.
. Malwarebytes will open Notepad and copy the scan report.
. Go to the report/log tab
. Click on it to display it once displayed
. Click on edit at the top of Notepad, then select all
. Click edit again and then copy, and return to the forum and in your reply
. Right-click in the reply box and paste
. At the end of the scan, Malwarebytes may need to restart the PC to finalize the removal, so don’t panic, restart your PC !!!
If you need help, check out this tutorial:
https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
I have to get to work, @ ++
--
O.o°*♪♪♫ Member, Security Contributor CCM o°.Oø¤º°'°º¤ø
O.o°* ♪♪♫ Breathe deeply, write your message clearly and in good French. It will go well, you’ll see, we’re trying!!! o°.Oø¤º°'°º¤ø
Here is the report of ZHPFix
ZHPFix Report 1.2.06 by Nicolas Coolman, Updated on 05/17/2012
Registry export file: C:\ZHP\ZHPExportRegistry-05-22-2012-10-52-42.txt
Run by sylvie at 05/22/2012 10:52:39
Windows 7 Home Premium Edition, 64-bit Service Pack 1 (Build 7601)
Website: http://www.premiumorange.com/zeb-help-process/zhpfix.html
Website: http://nicolascoolman.skyrock.com/
========== Software(s) ==========
ABSENT Software Key: McAfee Security Scan
ABSENT Software Key: Advanced SystemCare 5_is1
========== Memory Processes ==========
REMOVE Reboot Memory Process: C:\Program Files (x86)\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe
REMOVE Reboot Memory Process: C:\Program Files (x86)\rbjcl.vbs
REMOVE Reboot Memory Process: C:\Program Files (x86)\IWONGIE\bar\1.bin\vrbrmon.exe
REMOVE Reboot Memory Process: C:\Program Files (x86)\IWONGIE\bar\1.bin\vrbarsvc.exe
REMOVE Reboot Memory Process: C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.0.2\ToolbarUpdater.exe
REMOVE Reboot Memory Process: C:\Program Files (x86)\IObit\Advanced SystemCare 5\DelayLoad.exe
REMOVE Reboot Memory Process: C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCService.exe
REMOVE Reboot Memory Process: C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASC.exe
========== Registry Key(s) ==========
ABSENT Key: Service: McComponentHostServiceyzer] (...
REMOVE Key: Service: Lavasoft Ad-Aware Service
REMOVE Key: HKLM\Software\Classes\TypeLib\{14816CF6-426C-40D7-904C-E5600F015EC2}
REMOVE Key: HKLM\Software\Classes\TypeLib\{282D18C0-5424-44F4-A531-55F9AC5B8FD8}
REMOVE Key: HKLM\Software\WOW6432Node\Classes\Interface\{7935436E-8F14-4C84-9ECF-BEB791296619}
REMOVE Key: HKLM\Software\WOW6432Node\Classes\Interface\{7CF4E72E-C9C0-4CA8-A039-1F5BAD426CCE}
REMOVE Key: HKLM\Software\WOW6432Node\Classes\Interface\{81B32B9F-AFDC-4F7E-8F13-E39BB8ECF638}
REMOVE Key: HKLM\Software\WOW6432Node\Classes\Interface\{925C24DC-0C0B-4AE7-98F5-18252822C89C}
REMOVE Key: HKLM\Software\WOW6432Node\Classes\Interface\{B3DBB2D5-5F06-4EC2-904D-812ECE520509}
REMOVE Key: HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C4A743DE-EAAC-4cd0-9BF6-378E8141868B}
REMOVE Key: HKLM\Software\WOW6432Node\Classes\Interface\{CA1BC665-4B6B-435C-80C1-0E12D993ED49}
REMOVE Key: HKLM\Software\WOW6432Node\Classes\Interface\{D5AB027D-C91A-4324-8C78-12CF1A588C48}
ABSENT Key: HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DCE997C8-5920-4c09-99EE-59F46634FE2C} \Software\WOW6432Node\Classes\Interface\{E5DB89B8-5BE1-461C-A7EF-89B68211889D}
REMOVE Key: HKLM\Software\Classes\TypeLib\{FD06B491-1EA6-4F5C-86D2-C86D3A3A3731}
REMOVE Key: Service: vToolbarUpdater11.0.2
ABSENT Key: CLSID BHO: {f0f3f55e-edfc-4ed4-affb-bcaf081ddeba}
ABSENT Key: CLSID BHO: {d6995d07-cd9b-4cc0-a22a-9e14684d6d64}
REMOVE Key: Service: IWONGIEService
REMOVE Key*: HKCU\Software\AppDataLow\Software\IWONGIE
ABSENT Key: HKLM\Software\IWONGIE
REMOVE Key: Service: AdvancedSystemCareService5
========== Registry Value(s) ==========
ABSENT {5B34F80E-8EB5-468F-8C1B-C2649F5F228B}
ABSENT {3EB32A6A-1EF6-4F48-A765-1485D174BB31}
ABSENT {630462C5-AACF-49B8-ADF5-010D7DD6548F}
ABSENT {C747C427-9F9A-4454-98A5-53468DCF3D51}
ABSENT RunValue: IWONGIE Browser Plugin Loader
REMOVE URLSearchHook: {2ad11eb6-a327-4dfe-88bf-c6071e09f05b}
ABSENT RunValue: Advanced SystemCare 5
========== Folder(s) ==========
REMOVE Reboot Folder**: C:\Program Files (x86)\Fluendo
REMOVE Reboot Folder**: c:\program files (x86)\fluendo\moovida
REMOVE Folder: c:\programdata\microsoft\windows\start menu\programs\moovida
REMOVE Reboot Folder**: C:\Program Files (x86)\IWONGIE
REMOVE Temporary Windows:
========== File(s) ==========
REMOVE Reboot c:\program files (x86)\mcafee security scan\2.0.181\mcchsvc.exe
REMOVE Temporary Windows:
========== Scheduled Task ==========
ABSENT Task: Norton Error Processor
ABSENT Task: Norton WSC Integration
ABSENT Task: Ad-Aware Update (Weekly)
ABSENT Task: {50A74C38-C703-45BC-AC21-9F31959407F9}
========== Other ==========
NOT PROCESSED [MD5.78B24A64F84603784A10C86F4CEF71AF] - (.IObit - Advanced SystemCare 5 Tray.) -
========== Summary ==========
8: Memory Processes
21: Registry Key(s)
7: Registry Value(s)
5: Folder(s)
2: File(s)
2: Software(s)
4: Scheduled Task
1: Other
End of clean in 00mn 41s
========== Report file path ==========
C:\ZHP\ZHPFix[R1].txt - 05/22/2012 10:52:39 [4491]
ZHPFix Report 1.2.06 by Nicolas Coolman, Updated on 05/17/2012
Registry export file: C:\ZHP\ZHPExportRegistry-05-22-2012-10-52-42.txt
Run by sylvie at 05/22/2012 10:52:39
Windows 7 Home Premium Edition, 64-bit Service Pack 1 (Build 7601)
Website: http://www.premiumorange.com/zeb-help-process/zhpfix.html
Website: http://nicolascoolman.skyrock.com/
========== Software(s) ==========
ABSENT Software Key: McAfee Security Scan
ABSENT Software Key: Advanced SystemCare 5_is1
========== Memory Processes ==========
REMOVE Reboot Memory Process: C:\Program Files (x86)\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe
REMOVE Reboot Memory Process: C:\Program Files (x86)\rbjcl.vbs
REMOVE Reboot Memory Process: C:\Program Files (x86)\IWONGIE\bar\1.bin\vrbrmon.exe
REMOVE Reboot Memory Process: C:\Program Files (x86)\IWONGIE\bar\1.bin\vrbarsvc.exe
REMOVE Reboot Memory Process: C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.0.2\ToolbarUpdater.exe
REMOVE Reboot Memory Process: C:\Program Files (x86)\IObit\Advanced SystemCare 5\DelayLoad.exe
REMOVE Reboot Memory Process: C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCService.exe
REMOVE Reboot Memory Process: C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASC.exe
========== Registry Key(s) ==========
ABSENT Key: Service: McComponentHostServiceyzer] (...
REMOVE Key: Service: Lavasoft Ad-Aware Service
REMOVE Key: HKLM\Software\Classes\TypeLib\{14816CF6-426C-40D7-904C-E5600F015EC2}
REMOVE Key: HKLM\Software\Classes\TypeLib\{282D18C0-5424-44F4-A531-55F9AC5B8FD8}
REMOVE Key: HKLM\Software\WOW6432Node\Classes\Interface\{7935436E-8F14-4C84-9ECF-BEB791296619}
REMOVE Key: HKLM\Software\WOW6432Node\Classes\Interface\{7CF4E72E-C9C0-4CA8-A039-1F5BAD426CCE}
REMOVE Key: HKLM\Software\WOW6432Node\Classes\Interface\{81B32B9F-AFDC-4F7E-8F13-E39BB8ECF638}
REMOVE Key: HKLM\Software\WOW6432Node\Classes\Interface\{925C24DC-0C0B-4AE7-98F5-18252822C89C}
REMOVE Key: HKLM\Software\WOW6432Node\Classes\Interface\{B3DBB2D5-5F06-4EC2-904D-812ECE520509}
REMOVE Key: HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C4A743DE-EAAC-4cd0-9BF6-378E8141868B}
REMOVE Key: HKLM\Software\WOW6432Node\Classes\Interface\{CA1BC665-4B6B-435C-80C1-0E12D993ED49}
REMOVE Key: HKLM\Software\WOW6432Node\Classes\Interface\{D5AB027D-C91A-4324-8C78-12CF1A588C48}
ABSENT Key: HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DCE997C8-5920-4c09-99EE-59F46634FE2C} \Software\WOW6432Node\Classes\Interface\{E5DB89B8-5BE1-461C-A7EF-89B68211889D}
REMOVE Key: HKLM\Software\Classes\TypeLib\{FD06B491-1EA6-4F5C-86D2-C86D3A3A3731}
REMOVE Key: Service: vToolbarUpdater11.0.2
ABSENT Key: CLSID BHO: {f0f3f55e-edfc-4ed4-affb-bcaf081ddeba}
ABSENT Key: CLSID BHO: {d6995d07-cd9b-4cc0-a22a-9e14684d6d64}
REMOVE Key: Service: IWONGIEService
REMOVE Key*: HKCU\Software\AppDataLow\Software\IWONGIE
ABSENT Key: HKLM\Software\IWONGIE
REMOVE Key: Service: AdvancedSystemCareService5
========== Registry Value(s) ==========
ABSENT {5B34F80E-8EB5-468F-8C1B-C2649F5F228B}
ABSENT {3EB32A6A-1EF6-4F48-A765-1485D174BB31}
ABSENT {630462C5-AACF-49B8-ADF5-010D7DD6548F}
ABSENT {C747C427-9F9A-4454-98A5-53468DCF3D51}
ABSENT RunValue: IWONGIE Browser Plugin Loader
REMOVE URLSearchHook: {2ad11eb6-a327-4dfe-88bf-c6071e09f05b}
ABSENT RunValue: Advanced SystemCare 5
========== Folder(s) ==========
REMOVE Reboot Folder**: C:\Program Files (x86)\Fluendo
REMOVE Reboot Folder**: c:\program files (x86)\fluendo\moovida
REMOVE Folder: c:\programdata\microsoft\windows\start menu\programs\moovida
REMOVE Reboot Folder**: C:\Program Files (x86)\IWONGIE
REMOVE Temporary Windows:
========== File(s) ==========
REMOVE Reboot c:\program files (x86)\mcafee security scan\2.0.181\mcchsvc.exe
REMOVE Temporary Windows:
========== Scheduled Task ==========
ABSENT Task: Norton Error Processor
ABSENT Task: Norton WSC Integration
ABSENT Task: Ad-Aware Update (Weekly)
ABSENT Task: {50A74C38-C703-45BC-AC21-9F31959407F9}
========== Other ==========
NOT PROCESSED [MD5.78B24A64F84603784A10C86F4CEF71AF] - (.IObit - Advanced SystemCare 5 Tray.) -
========== Summary ==========
8: Memory Processes
21: Registry Key(s)
7: Registry Value(s)
5: Folder(s)
2: File(s)
2: Software(s)
4: Scheduled Task
1: Other
End of clean in 00mn 41s
========== Report file path ==========
C:\ZHP\ZHPFix[R1].txt - 05/22/2012 10:52:39 [4491]
ZHPFix Report 1.2.06 by Nicolas Coolman, Update of 05/17/2012
Export Registry File: C:\ZHP\ZHPExportRegistry-22-05-2012-10-52-42.txt
Run by sylvie on 05/22/2012 10:52:39
Windows 7 Home Premium Edition, 64-bit Service Pack 1 (Build 7601)
Website: http://www.premiumorange.com/zeb-help-process/zhpfix.html
Website: http://nicolascoolman.skyrock.com/
========== Software(s) ==========
ABSENT Software Key: McAfee Security Scan
ABSENT Software Key: Advanced SystemCare 5_is1
========== Memory Processes ==========
DELETE Reboot Memory Process: C:\Program Files (x86)\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe
DELETE Reboot Memory Process: C:\Program Files (x86)\rbjcl.vbs
DELETE Reboot Memory Process: C:\Program Files (x86)\IWONGIE\bar\1.bin\vrbrmon.exe
DELETE Reboot Memory Process: C:\Program Files (x86)\IWONGIE\bar\1.bin\vrbarsvc.exe
DELETE Reboot Memory Process: C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.0.2\ToolbarUpdater.exe
DELETE Reboot Memory Process: C:\Program Files (x86)\IObit\Advanced SystemCare 5\DelayLoad.exe
DELETE Reboot Memory Process: C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCService.exe
DELETE Reboot Memory Process: C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASC.exe
========== Registry Key(s) ==========
ABSENT Key: Service: McComponentHostServiceyzer] (...
DELETE Key: Service: Lavasoft Ad-Aware Service
DELETE Key: HKLM\Software\Classes\TypeLib\{14816CF6-426C-40D7-904C-E5600F015EC2}
DELETE Key: HKLM\Software\Classes\TypeLib\{282D18C0-5424-44F4-A531-55F9AC5B8FD8}
DELETE Key: HKLM\Software\WOW6432Node\Classes\Interface\{7935436E-8F14-4C84-9ECF-BEB791296619}
DELETE Key: HKLM\Software\WOW6432Node\Classes\Interface\{7CF4E72E-C9C0-4CA8-A039-1F5BAD426CCE}
DELETE Key: HKLM\Software\WOW6432Node\Classes\Interface\{81B32B9F-AFDC-4F7E-8F13-E39BB8ECF638}
DELETE Key: HKLM\Software\WOW6432Node\Classes\Interface\{925C24DC-0C0B-4AE7-98F5-18252822C89C}
DELETE Key: HKLM\Software\WOW6432Node\Classes\Interface\{B3DBB2D5-5F06-4EC2-904D-812ECE520509}
DELETE Key: HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C4A743DE-EAAC-4cd0-9BF6-378E8141868B}
DELETE Key: HKLM\Software\WOW6432Node\Classes\Interface\{CA1BC665-4B6B-435C-80C1-0E12D993ED49}
DELETE Key: HKLM\Software\WOW6432Node\Classes\Interface\{D5AB027D-C91A-4324-8C78-12CF1A588C48}
ABSENT Key: HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DCE997C8-5920-4c09-99EE-59F46634FE2C} \Software\WOW6432Node\Classes\Interface\{E5DB89B8-5BE1-461C-A7EF-89B68211889D}
DELETE Key: HKLM\Software\Classes\TypeLib\{FD06B491-1EA6-4F5C-86D2-C86D3A3A3731}
DELETE Key: Service: vToolbarUpdater11.0.2
ABSENT Key: CLSID BHO: {f0f3f55e-edfc-4ed4-affb-bcaf081ddeba}
ABSENT Key: CLSID BHO: {d6995d07-cd9b-4cc0-a22a-9e14684d6d64}
DELETE Key: Service: IWONGIEService
DELETE Key*: HKCU\Software\AppDataLow\Software\IWONGIE
ABSENT Key: HKLM\Software\IWONGIE
DELETE Key: Service: AdvancedSystemCareService5
========== Registry Value(s) ==========
ABSENT {5B34F80E-8EB5-468F-8C1B-C2649F5F228B}
ABSENT {3EB32A6A-1EF6-4F48-A765-1485D174BB31}
ABSENT {630462C5-AACF-49B8-ADF5-010D7DD6548F}
ABSENT {C747C427-9F9A-4454-98A5-53468DCF3D51}
ABSENT RunValue: IWONGIE Browser Plugin Loader
DELETE URLSearchHook: {2ad11eb6-a327-4dfe-88bf-c6071e09f05b}
ABSENT RunValue: Advanced SystemCare 5
========== Folder(s) ==========
DELETE Reboot Folder**: C:\Program Files (x86)\Fluendo
DELETE Reboot Folder**: c:\program files (x86)\fluendo\moovida
DELETE Folder: c:\programdata\microsoft\windows\start menu\programs\moovida
DELETE Reboot Folder**: C:\Program Files (x86)\IWONGIE
DELETE Windows Temp:
========== File(s) ==========
DELETE Reboot c:\program files (x86)\mcafee security scan\2.0.181\mcchsvc.exe
DELETE Windows Temp:
========== Scheduled Task ==========
ABSENT Task: Norton Error Processor
ABSENT Task: Norton WSC Integration
ABSENT Task: Ad-Aware Update (Weekly)
ABSENT Task: {50A74C38-C703-45BC-AC21-9F31959407F9}
========== Other ==========
NOT PROCESSED [MD5.78B24A64F84603784A10C86F4CEF71AF] - (.IObit - Advanced SystemCare 5 Tray.) -
========== Summary ==========
8 : Memory Processes
21 : Key(s) of the Registry
7 : Value(s) of the Registry
5 : Folder(s)
2 : File(s)
2 : Software(s)
4 : Scheduled Task
1 : Other
End of clean in 00mn 41s
========== File path report ==========
C:\ZHP\ZHPFix[R1].txt - 05/22/2012 10:52:39 [4491]
Malwarebytes Anti-Malware (Trial) 1.61.0.1400
www.malwarebytes.org
Database version: v2012.05.22.01
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
sylvie :: SYLVIE-PC [administrator]
Protection: Enabled
05/22/2012 11:02:51
mbam-log-2012-05-22 (11-02-51).txt
Scan type: Full scan
Enabled scan options: Memory | Startup | Registry | File system | Heuristic/Extra | Heuristic/Shuriken | PUP | PUM
Disabled scan options: P2P
Items scanned: 436750
Elapsed time: 53 minute(s), 8 second(s)
Detected memory process(es): 0
(No harmful item detected)
Detected memory module(s): 0
(No harmful item detected)
Detected registry key(s): 0
(No harmful item detected)
Detected registry value(s): 0
(No harmful item detected)
Detected registry data item(s): 0
(No harmful item detected)
Detected folder(s): 0
(No harmful item detected)
Detected file(s): 1
C:\Program Files (x86)\rbjcl.vbs (Trojan.StartPage) -> Quarantined and successfully deleted.
(end)
Here is the malwarebytes scan report.
I don't know how you manage it but I didn't understand anything ^^
Export Registry File: C:\ZHP\ZHPExportRegistry-22-05-2012-10-52-42.txt
Run by sylvie on 05/22/2012 10:52:39
Windows 7 Home Premium Edition, 64-bit Service Pack 1 (Build 7601)
Website: http://www.premiumorange.com/zeb-help-process/zhpfix.html
Website: http://nicolascoolman.skyrock.com/
========== Software(s) ==========
ABSENT Software Key: McAfee Security Scan
ABSENT Software Key: Advanced SystemCare 5_is1
========== Memory Processes ==========
DELETE Reboot Memory Process: C:\Program Files (x86)\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe
DELETE Reboot Memory Process: C:\Program Files (x86)\rbjcl.vbs
DELETE Reboot Memory Process: C:\Program Files (x86)\IWONGIE\bar\1.bin\vrbrmon.exe
DELETE Reboot Memory Process: C:\Program Files (x86)\IWONGIE\bar\1.bin\vrbarsvc.exe
DELETE Reboot Memory Process: C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.0.2\ToolbarUpdater.exe
DELETE Reboot Memory Process: C:\Program Files (x86)\IObit\Advanced SystemCare 5\DelayLoad.exe
DELETE Reboot Memory Process: C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCService.exe
DELETE Reboot Memory Process: C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASC.exe
========== Registry Key(s) ==========
ABSENT Key: Service: McComponentHostServiceyzer] (...
DELETE Key: Service: Lavasoft Ad-Aware Service
DELETE Key: HKLM\Software\Classes\TypeLib\{14816CF6-426C-40D7-904C-E5600F015EC2}
DELETE Key: HKLM\Software\Classes\TypeLib\{282D18C0-5424-44F4-A531-55F9AC5B8FD8}
DELETE Key: HKLM\Software\WOW6432Node\Classes\Interface\{7935436E-8F14-4C84-9ECF-BEB791296619}
DELETE Key: HKLM\Software\WOW6432Node\Classes\Interface\{7CF4E72E-C9C0-4CA8-A039-1F5BAD426CCE}
DELETE Key: HKLM\Software\WOW6432Node\Classes\Interface\{81B32B9F-AFDC-4F7E-8F13-E39BB8ECF638}
DELETE Key: HKLM\Software\WOW6432Node\Classes\Interface\{925C24DC-0C0B-4AE7-98F5-18252822C89C}
DELETE Key: HKLM\Software\WOW6432Node\Classes\Interface\{B3DBB2D5-5F06-4EC2-904D-812ECE520509}
DELETE Key: HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C4A743DE-EAAC-4cd0-9BF6-378E8141868B}
DELETE Key: HKLM\Software\WOW6432Node\Classes\Interface\{CA1BC665-4B6B-435C-80C1-0E12D993ED49}
DELETE Key: HKLM\Software\WOW6432Node\Classes\Interface\{D5AB027D-C91A-4324-8C78-12CF1A588C48}
ABSENT Key: HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DCE997C8-5920-4c09-99EE-59F46634FE2C} \Software\WOW6432Node\Classes\Interface\{E5DB89B8-5BE1-461C-A7EF-89B68211889D}
DELETE Key: HKLM\Software\Classes\TypeLib\{FD06B491-1EA6-4F5C-86D2-C86D3A3A3731}
DELETE Key: Service: vToolbarUpdater11.0.2
ABSENT Key: CLSID BHO: {f0f3f55e-edfc-4ed4-affb-bcaf081ddeba}
ABSENT Key: CLSID BHO: {d6995d07-cd9b-4cc0-a22a-9e14684d6d64}
DELETE Key: Service: IWONGIEService
DELETE Key*: HKCU\Software\AppDataLow\Software\IWONGIE
ABSENT Key: HKLM\Software\IWONGIE
DELETE Key: Service: AdvancedSystemCareService5
========== Registry Value(s) ==========
ABSENT {5B34F80E-8EB5-468F-8C1B-C2649F5F228B}
ABSENT {3EB32A6A-1EF6-4F48-A765-1485D174BB31}
ABSENT {630462C5-AACF-49B8-ADF5-010D7DD6548F}
ABSENT {C747C427-9F9A-4454-98A5-53468DCF3D51}
ABSENT RunValue: IWONGIE Browser Plugin Loader
DELETE URLSearchHook: {2ad11eb6-a327-4dfe-88bf-c6071e09f05b}
ABSENT RunValue: Advanced SystemCare 5
========== Folder(s) ==========
DELETE Reboot Folder**: C:\Program Files (x86)\Fluendo
DELETE Reboot Folder**: c:\program files (x86)\fluendo\moovida
DELETE Folder: c:\programdata\microsoft\windows\start menu\programs\moovida
DELETE Reboot Folder**: C:\Program Files (x86)\IWONGIE
DELETE Windows Temp:
========== File(s) ==========
DELETE Reboot c:\program files (x86)\mcafee security scan\2.0.181\mcchsvc.exe
DELETE Windows Temp:
========== Scheduled Task ==========
ABSENT Task: Norton Error Processor
ABSENT Task: Norton WSC Integration
ABSENT Task: Ad-Aware Update (Weekly)
ABSENT Task: {50A74C38-C703-45BC-AC21-9F31959407F9}
========== Other ==========
NOT PROCESSED [MD5.78B24A64F84603784A10C86F4CEF71AF] - (.IObit - Advanced SystemCare 5 Tray.) -
========== Summary ==========
8 : Memory Processes
21 : Key(s) of the Registry
7 : Value(s) of the Registry
5 : Folder(s)
2 : File(s)
2 : Software(s)
4 : Scheduled Task
1 : Other
End of clean in 00mn 41s
========== File path report ==========
C:\ZHP\ZHPFix[R1].txt - 05/22/2012 10:52:39 [4491]
Malwarebytes Anti-Malware (Trial) 1.61.0.1400
www.malwarebytes.org
Database version: v2012.05.22.01
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
sylvie :: SYLVIE-PC [administrator]
Protection: Enabled
05/22/2012 11:02:51
mbam-log-2012-05-22 (11-02-51).txt
Scan type: Full scan
Enabled scan options: Memory | Startup | Registry | File system | Heuristic/Extra | Heuristic/Shuriken | PUP | PUM
Disabled scan options: P2P
Items scanned: 436750
Elapsed time: 53 minute(s), 8 second(s)
Detected memory process(es): 0
(No harmful item detected)
Detected memory module(s): 0
(No harmful item detected)
Detected registry key(s): 0
(No harmful item detected)
Detected registry value(s): 0
(No harmful item detected)
Detected registry data item(s): 0
(No harmful item detected)
Detected folder(s): 0
(No harmful item detected)
Detected file(s): 1
C:\Program Files (x86)\rbjcl.vbs (Trojan.StartPage) -> Quarantined and successfully deleted.
(end)
Here is the malwarebytes scan report.
I don't know how you manage it but I didn't understand anything ^^
On the other hand, I still have Advanced SystemCare launching at startup. I may be mistaken, but I thought it was something undesirable that could be removed, just like McAfee Security, although that one doesn't seem to launch (from what I've noticed). I just wanted to know if I should keep it (now that it's in place, maybe it's better to keep it) or if I should remove it to reinstall Avast.
I also have several accounts on the computer; do I need to perform all these manipulations on all the accounts or just on the "admin" account?
I know I'm asking a lot of things, but I prefer to get informed rather than make mistakes.
In any case, thank you for your help.
I also have several accounts on the computer; do I need to perform all these manipulations on all the accounts or just on the "admin" account?
I know I'm asking a lot of things, but I prefer to get informed rather than make mistakes.
In any case, thank you for your help.
super for the manipulations :D
for Advanced system care, I tried to remove it, we're going in that direction :D
for the rest, you will keep avast, since Macafric has been uninstalled (there were some remnants, but now deleted)
restart MBAM, just empty its quarantine :D
restart your pc,
Download SEAF.exe (from C_XX) to your desktop.
http://general-changelog-team.fr/telechargements/logiciels/viewdownload/83-outils-de-cxx/52-seaf
? Double click on SEAF.exe (Run as administrator for Vista) .
? Check the boxes:
- Also search in the registry
- Additional information
? Type exactly this text in this window and confirm by [Enter] :
Advanced systemcare
? Wait during the search, and don't touch anything ...
? A window with a .txt log will appear.
? Copy/paste this report into your next reply.
--
O.o°*♪♪♫ Member, Security Contributor CCM o°.Oø¤º°'°º¤ø
O.o°* ♪♪♫ Breathe deeply, write your message in good French and clearly. It's going to be fine, you'll see, at least we're trying!!! o°.Oø¤º°'°º¤ø
for Advanced system care, I tried to remove it, we're going in that direction :D
for the rest, you will keep avast, since Macafric has been uninstalled (there were some remnants, but now deleted)
restart MBAM, just empty its quarantine :D
restart your pc,
Download SEAF.exe (from C_XX) to your desktop.
http://general-changelog-team.fr/telechargements/logiciels/viewdownload/83-outils-de-cxx/52-seaf
? Double click on SEAF.exe (Run as administrator for Vista) .
? Check the boxes:
- Also search in the registry
- Additional information
? Type exactly this text in this window and confirm by [Enter] :
Advanced systemcare
? Wait during the search, and don't touch anything ...
? A window with a .txt log will appear.
? Copy/paste this report into your next reply.
--
O.o°*♪♪♫ Member, Security Contributor CCM o°.Oø¤º°'°º¤ø
O.o°* ♪♪♫ Breathe deeply, write your message in good French and clearly. It's going to be fine, you'll see, at least we're trying!!! o°.Oø¤º°'°º¤ø
Here is the SEAF report seaf log.txt
1. ========================= SEAF 1.0.1.0 - C_XX
2.
3. Started at: 21:15:28 on 22/05/2012
4.
5. Value(s) searched:
6. advanced systemcare
7.
8. Legend: TC => Creation date, TM => Modification date, DA => Last access
9.
10. (!) --- Additional information
11. (!) --- Registry search
12.
13. ====== File(s) ======
14.
15.
16. "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 5\Advanced SystemCare 5.lnk" [ ARCHIVE | 1 Ko ]
17. TC: 06/05/2012,18:39:18 | TM: 06/05/2012,18:39:19 | DA: 06/05/2012,18:39:18
18.
19.
20. =========================
21.
22.
23. "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 5\Uninstall Advanced SystemCare.lnk" [ ARCHIVE | 1 Ko ]
24. TC: 06/05/2012,18:39:19 | TM: 06/05/2012,18:39:19 | DA: 06/05/2012,18:39:19
25.
26.
27. =========================
28.
29.
30. "C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 5\Advanced SystemCare 5.lnk" [ ARCHIVE | 1 Ko ]
31. TC: 06/05/2012,18:39:18 | TM: 06/05/2012,18:39:19 | DA: 06/05/2012,18:39:18
32.
33.
34. =========================
35.
36.
37. "C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 5\Uninstall Advanced SystemCare.lnk" [ ARCHIVE | 1 Ko ]
38. TC: 06/05/2012,18:39:19 | TM: 06/05/2012,18:39:19 | DA: 06/05/2012,18:39:19
39.
40.
41. =========================
42.
43.
44.
45. ====== Registry entry(ies) ======
46.
47.
48. [HKLM\Software\IObit\Advanced SystemCare 5]
49. DA: 06/05/2012 18:39:21
50.
51. [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Advanced SystemCare 5_is1]
52. DA: 22/05/2012 21:05:03
53.
54. [HKLM\Software\Wow6432Node\IObit\Advanced SystemCare 5]
55. DA: 06/05/2012 18:39:21
56.
57. [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Advanced SystemCare 5_is1]
58. DA: 22/05/2012 21:05:03
59.
60. [HKLM\Software\Wow6432Node\Classes\*\shellex\ContextMenuHandlers\Advanced SystemCare]
61. DA: 22/05/2012 21:00:46
62.
63. [HKLM\Software\Wow6432Node\Classes\Directory\shellex\ContextMenuHandlers\Advanced SystemCare]
64. DA: 06/05/2012 18:39:31
65.
66. [HKLM\Software\Wow6432Node\Classes\Drive\shellex\ContextMenuHandlers\Advanced SystemCare]
67. DA: 22/05/2012 21:00:46
68.
69. [HKLM\Software\Wow6432Node\Classes\lnkfile\shellex\ContextMenuHandlers\Advanced SystemCare]
70. DA: 06/05/2012 18:39:31
71.
72. [HKLM\Software\Wow6432Node\Classes\TypeLib\{38A6E5EA-6854-4F3C-AD6C-7FB6E92C5A8C}\1.0\0\win64]
73. ""="C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCv5ExtMenu_64.dll" (REG_SZ)
74.
75. [HKLM\Software\Wow6432Node\Classes\TypeLib\{38A6E5EA-6854-4F3C-AD6C-7FB6E92C5A8C}\1.0\HELPDIR]
76. ""="C:\Program Files (x86)\IObit\Advanced SystemCare 5" (REG_SZ)
77.
78. [HKLM\Software\Wow6432Node\Classes\Wow6432Node\TypeLib\{38A6E5EA-6854-4F3C-AD6C-7FB6E92C5A8C}\1.0\0\win64]
79. ""="C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCv5ExtMenu_64.dll" (REG_SZ)
80.
81. [HKLM\Software\Wow6432Node\Classes\Wow6432Node\TypeLib\{38A6E5EA-6854-4F3C-AD6C-7FB6E92C5A8C}\1.0\HELPDIR]
82. ""="C:\Program Files (x86)\IObit\Advanced SystemCare 5" (REG_SZ)
83.
84. [HKLM\Software\Classes\*\shellex\ContextMenuHandlers\Advanced SystemCare]
85. DA: 22/05/2012 21:00:46
86.
87. [HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\Advanced SystemCare]
88. DA: 06/05/2012 18:39:31
89.
90. [HKLM\Software\Classes\Drive\shellex\ContextMenuHandlers\Advanced SystemCare]
91. DA: 22/05/2012 21:00:46
92.
93. [HKLM\Software\Classes\lnkfile\shellex\ContextMenuHandlers\Advanced SystemCare]
94. DA: 06/05/2012 18:39:31
95.
96. [HKLM\Software\Classes\TypeLib\{38A6E5EA-6854-4F3C-AD6C-7FB6E92C5A8C}\1.0\0\win64]
97. ""="C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCv5ExtMenu_64.dll" (REG_SZ)
98.
99. [HKLM\Software\Classes\TypeLib\{38A6E5EA-6854-4F3C-AD6C-7FB6E92C5A8C}\1.0\HELPDIR]
100. ""="C:\Program Files (x86)\IObit\Advanced SystemCare 5" (REG_SZ)
101.
102. [HKLM\Software\Classes\Wow6432Node\TypeLib\{38A6E5EA-6854-4F3C-AD6C-7FB6E92C5A8C}\1.0\0\win64]
103. ""="C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCv5ExtMenu_64.dll" (REG_SZ)
104.
105. [HKLM\Software\Classes\Wow6432Node\TypeLib\{38A6E5EA-6854-4F3C-AD6C-7FB6E92C5A8C}\1.0\HELPDIR]
106. ""="C:\Program Files (x86)\IObit\Advanced SystemCare 5" (REG_SZ)
107.
108. [HKLM\System\ControlSet001\services\AdvancedSystemCareService5]
109. "ImagePath"="C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCService.exe" (REG_EXPAND_SZ)
110.
111. [HKLM\System\ControlSet001\services\AdvancedSystemCareService5]
112. "DisplayName"="Advanced SystemCare Service 5" (REG_SZ)
113.
114. [HKLM\System\ControlSet001\services\AdvancedSystemCareService5]
115. "Description"="Advanced SystemCare Service" (REG_SZ)
116.
117. [HKLM\System\ControlSet002\services\AdvancedSystemCareService5]
118. "ImagePath"="C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCService.exe" (REG_EXPAND_SZ)
119.
120. [HKLM\System\ControlSet002\services\AdvancedSystemCareService5]
121. "DisplayName"="Advanced SystemCare Service 5" (REG_SZ)
122.
123. [HKLM\System\ControlSet002\services\AdvancedSystemCareService5]
124. "Description"="Advanced SystemCare Service" (REG_SZ)
125.
126. [HKLM\System\CurrentControlSet\services\AdvancedSystemCareService5]
127. "ImagePath"="C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCService.exe" (REG_EXPAND_SZ)
128.
129. [HKLM\System\CurrentControlSet\services\AdvancedSystemCareService5]
130. "DisplayName"="Advanced SystemCare Service 5" (REG_SZ)
131.
132. [HKLM\System\CurrentControlSet\services\AdvancedSystemCareService5]
133. "Description"="Advanced SystemCare Service" (REG_SZ)
134.
135. [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
136. "Advanced SystemCare 5"=""C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCTray.exe" /AutoStart" (REG_SZ)
137.
138. [HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run]
139. "Advanced SystemCare 5"=""C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCTray.exe" /AutoStart" (REG_SZ)
140.
141. =========================
142.
143. End at: 21:18:45 on 22/05/2012
144. 531983 Items analyzed
145.
146. =========================
147. E.O.F
1. ========================= SEAF 1.0.1.0 - C_XX
2.
3. Started at: 21:15:28 on 22/05/2012
4.
5. Value(s) searched:
6. advanced systemcare
7.
8. Legend: TC => Creation date, TM => Modification date, DA => Last access
9.
10. (!) --- Additional information
11. (!) --- Registry search
12.
13. ====== File(s) ======
14.
15.
16. "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 5\Advanced SystemCare 5.lnk" [ ARCHIVE | 1 Ko ]
17. TC: 06/05/2012,18:39:18 | TM: 06/05/2012,18:39:19 | DA: 06/05/2012,18:39:18
18.
19.
20. =========================
21.
22.
23. "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 5\Uninstall Advanced SystemCare.lnk" [ ARCHIVE | 1 Ko ]
24. TC: 06/05/2012,18:39:19 | TM: 06/05/2012,18:39:19 | DA: 06/05/2012,18:39:19
25.
26.
27. =========================
28.
29.
30. "C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 5\Advanced SystemCare 5.lnk" [ ARCHIVE | 1 Ko ]
31. TC: 06/05/2012,18:39:18 | TM: 06/05/2012,18:39:19 | DA: 06/05/2012,18:39:18
32.
33.
34. =========================
35.
36.
37. "C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 5\Uninstall Advanced SystemCare.lnk" [ ARCHIVE | 1 Ko ]
38. TC: 06/05/2012,18:39:19 | TM: 06/05/2012,18:39:19 | DA: 06/05/2012,18:39:19
39.
40.
41. =========================
42.
43.
44.
45. ====== Registry entry(ies) ======
46.
47.
48. [HKLM\Software\IObit\Advanced SystemCare 5]
49. DA: 06/05/2012 18:39:21
50.
51. [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Advanced SystemCare 5_is1]
52. DA: 22/05/2012 21:05:03
53.
54. [HKLM\Software\Wow6432Node\IObit\Advanced SystemCare 5]
55. DA: 06/05/2012 18:39:21
56.
57. [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Advanced SystemCare 5_is1]
58. DA: 22/05/2012 21:05:03
59.
60. [HKLM\Software\Wow6432Node\Classes\*\shellex\ContextMenuHandlers\Advanced SystemCare]
61. DA: 22/05/2012 21:00:46
62.
63. [HKLM\Software\Wow6432Node\Classes\Directory\shellex\ContextMenuHandlers\Advanced SystemCare]
64. DA: 06/05/2012 18:39:31
65.
66. [HKLM\Software\Wow6432Node\Classes\Drive\shellex\ContextMenuHandlers\Advanced SystemCare]
67. DA: 22/05/2012 21:00:46
68.
69. [HKLM\Software\Wow6432Node\Classes\lnkfile\shellex\ContextMenuHandlers\Advanced SystemCare]
70. DA: 06/05/2012 18:39:31
71.
72. [HKLM\Software\Wow6432Node\Classes\TypeLib\{38A6E5EA-6854-4F3C-AD6C-7FB6E92C5A8C}\1.0\0\win64]
73. ""="C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCv5ExtMenu_64.dll" (REG_SZ)
74.
75. [HKLM\Software\Wow6432Node\Classes\TypeLib\{38A6E5EA-6854-4F3C-AD6C-7FB6E92C5A8C}\1.0\HELPDIR]
76. ""="C:\Program Files (x86)\IObit\Advanced SystemCare 5" (REG_SZ)
77.
78. [HKLM\Software\Wow6432Node\Classes\Wow6432Node\TypeLib\{38A6E5EA-6854-4F3C-AD6C-7FB6E92C5A8C}\1.0\0\win64]
79. ""="C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCv5ExtMenu_64.dll" (REG_SZ)
80.
81. [HKLM\Software\Wow6432Node\Classes\Wow6432Node\TypeLib\{38A6E5EA-6854-4F3C-AD6C-7FB6E92C5A8C}\1.0\HELPDIR]
82. ""="C:\Program Files (x86)\IObit\Advanced SystemCare 5" (REG_SZ)
83.
84. [HKLM\Software\Classes\*\shellex\ContextMenuHandlers\Advanced SystemCare]
85. DA: 22/05/2012 21:00:46
86.
87. [HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\Advanced SystemCare]
88. DA: 06/05/2012 18:39:31
89.
90. [HKLM\Software\Classes\Drive\shellex\ContextMenuHandlers\Advanced SystemCare]
91. DA: 22/05/2012 21:00:46
92.
93. [HKLM\Software\Classes\lnkfile\shellex\ContextMenuHandlers\Advanced SystemCare]
94. DA: 06/05/2012 18:39:31
95.
96. [HKLM\Software\Classes\TypeLib\{38A6E5EA-6854-4F3C-AD6C-7FB6E92C5A8C}\1.0\0\win64]
97. ""="C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCv5ExtMenu_64.dll" (REG_SZ)
98.
99. [HKLM\Software\Classes\TypeLib\{38A6E5EA-6854-4F3C-AD6C-7FB6E92C5A8C}\1.0\HELPDIR]
100. ""="C:\Program Files (x86)\IObit\Advanced SystemCare 5" (REG_SZ)
101.
102. [HKLM\Software\Classes\Wow6432Node\TypeLib\{38A6E5EA-6854-4F3C-AD6C-7FB6E92C5A8C}\1.0\0\win64]
103. ""="C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCv5ExtMenu_64.dll" (REG_SZ)
104.
105. [HKLM\Software\Classes\Wow6432Node\TypeLib\{38A6E5EA-6854-4F3C-AD6C-7FB6E92C5A8C}\1.0\HELPDIR]
106. ""="C:\Program Files (x86)\IObit\Advanced SystemCare 5" (REG_SZ)
107.
108. [HKLM\System\ControlSet001\services\AdvancedSystemCareService5]
109. "ImagePath"="C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCService.exe" (REG_EXPAND_SZ)
110.
111. [HKLM\System\ControlSet001\services\AdvancedSystemCareService5]
112. "DisplayName"="Advanced SystemCare Service 5" (REG_SZ)
113.
114. [HKLM\System\ControlSet001\services\AdvancedSystemCareService5]
115. "Description"="Advanced SystemCare Service" (REG_SZ)
116.
117. [HKLM\System\ControlSet002\services\AdvancedSystemCareService5]
118. "ImagePath"="C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCService.exe" (REG_EXPAND_SZ)
119.
120. [HKLM\System\ControlSet002\services\AdvancedSystemCareService5]
121. "DisplayName"="Advanced SystemCare Service 5" (REG_SZ)
122.
123. [HKLM\System\ControlSet002\services\AdvancedSystemCareService5]
124. "Description"="Advanced SystemCare Service" (REG_SZ)
125.
126. [HKLM\System\CurrentControlSet\services\AdvancedSystemCareService5]
127. "ImagePath"="C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCService.exe" (REG_EXPAND_SZ)
128.
129. [HKLM\System\CurrentControlSet\services\AdvancedSystemCareService5]
130. "DisplayName"="Advanced SystemCare Service 5" (REG_SZ)
131.
132. [HKLM\System\CurrentControlSet\services\AdvancedSystemCareService5]
133. "Description"="Advanced SystemCare Service" (REG_SZ)
134.
135. [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
136. "Advanced SystemCare 5"=""C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCTray.exe" /AutoStart" (REG_SZ)
137.
138. [HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run]
139. "Advanced SystemCare 5"=""C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCTray.exe" /AutoStart" (REG_SZ)
140.
141. =========================
142.
143. End at: 21:18:45 on 22/05/2012
144. 531983 Items analyzed
145.
146. =========================
147. E.O.F
Hello,
for the moment, do not reinstall Avast!
Use this to remove the remainder of Advanced SystemCare:
http://www.forum-vista.net/forum/
If you can't manage, I'll script it :D
--
O.o°*♪♪♫ Member, Security Contributor CCM o°.Oø¤º°'°º¤ø
O.o°* ♪♪♫ Breathe deeply, write your message in proper French and clearly. It'll be fine, you'll see, well let's try!!! o°.Oø¤º°'°º¤ø
for the moment, do not reinstall Avast!
Use this to remove the remainder of Advanced SystemCare:
http://www.forum-vista.net/forum/
If you can't manage, I'll script it :D
--
O.o°*♪♪♫ Member, Security Contributor CCM o°.Oø¤º°'°º¤ø
O.o°* ♪♪♫ Breathe deeply, write your message in proper French and clearly. It'll be fine, you'll see, well let's try!!! o°.Oø¤º°'°º¤ø
Hello,
great, for the report, no worries :D
is the computer working normally before we proceed?
--
O.o°*♪♪♫ Member, CCM security contributor o°.Oø¤º°'°º¤ø
O.o°* ♪♪♫ Breathe deeply, write your message in good French and clearly. It will be fine, you'll see, well we're trying!!! o°.Oø¤º°'°º¤ø
great, for the report, no worries :D
is the computer working normally before we proceed?
--
O.o°*♪♪♫ Member, CCM security contributor o°.Oø¤º°'°º¤ø
O.o°* ♪♪♫ Breathe deeply, write your message in good French and clearly. It will be fine, you'll see, well we're trying!!! o°.Oø¤º°'°º¤ø
Good evening, yes it seems so. It turns on faster which is already quite positive!!
However, I have had a long-standing issue with the control deck at startup. A window opens and tells me it's not responding, is this related to all that or is it a different problem? And I still can't access the games on my account. On the others, there are no issues with any game, but on my account, I can't access the games.
Thank you, have a good evening.
However, I have had a long-standing issue with the control deck at startup. A window opens and tells me it's not responding, is this related to all that or is it a different problem? And I still can't access the games on my account. On the others, there are no issues with any game, but on my account, I can't access the games.
Thank you, have a good evening.
Good evening,
what is the exact message at startup?
--
O.o°*♪♪♫ Member, Security Contributor CCM o°.Oø¤º°'°º¤ø
O.o°* ♪♪♫ Breathe deeply, Write your message in good French and clearly. It will be fine, you'll see, well we will try!!! o°.Oø¤º°'°º¤ø
what is the exact message at startup?
--
O.o°*♪♪♫ Member, Security Contributor CCM o°.Oø¤º°'°º¤ø
O.o°* ♪♪♫ Breathe deeply, Write your message in good French and clearly. It will be fine, you'll see, well we will try!!! o°.Oø¤º°'°º¤ø
I have two small things that pop up, one at the bottom right saying "unable to connect to all network drives"
and the second is a small window that opens if I'm too quick, saying "control deck is not responding; wait for the program to respond; or cancel."
and the second is a small window that opens if I'm too quick, saying "control deck is not responding; wait for the program to respond; or cancel."
impossible to connect all network drives "
how many connections do you have configured on your PC?
there's one causing you this message!
for Control Panel:
you need to create a key in the registry, use this as a guide:
https://www.aidoweb.com/forum/controldeck-ne-repond-pas-36851#p339164
--
O.o°*♪♪♫ Member, Security Contributor CCM o°.Oø¤º°'°º¤ø
O.o°* ♪♪♫ Breathe deeply, write your message in good French and clearly. It will be fine, you'll see, well we’ll try!!! o°.Oø¤º°'°º¤ø
how many connections do you have configured on your PC?
there's one causing you this message!
for Control Panel:
you need to create a key in the registry, use this as a guide:
https://www.aidoweb.com/forum/controldeck-ne-repond-pas-36851#p339164
--
O.o°*♪♪♫ Member, Security Contributor CCM o°.Oø¤º°'°º¤ø
O.o°* ♪♪♫ Breathe deeply, write your message in good French and clearly. It will be fine, you'll see, well we’ll try!!! o°.Oø¤º°'°º¤ø
However, this evening I have a big problem: it turns off by itself. Of course, I've checked my connections and I've even changed chargers (better safe than sorry). I thought it might be the battery and that the charger wasn't doing its job, but actually the battery is charging well. I don't know if everything is connected or not, but I'm starting to panic.
Hello,
no panic!
when did it turn off by itself?
restart zhpdiag,
* Click on the icon representing a magnifying glass (“Run the diagnostic”)
* Save the report to your Desktop using the icon representing a floppy disk
* Host the ZHPDiag.txt report on Cjoint, then copy/paste the provided link in your next response on the forum:
https://www.cjoint.com/ => https://www.commentcamarche.net/faq/29493-utiliser-cjoint-pour-heberger-des-fichiers
--
O.o°*♪♪♫ Member, Security Contributor CCM o°.Oø¤º°'°º¤ø
O.o°* ♪♪♫ Breathe deeply, write your message in good French and clearly. It will be fine, you will see, well we will try !!! o°.Oø¤º°'°º¤ø
no panic!
when did it turn off by itself?
restart zhpdiag,
* Click on the icon representing a magnifying glass (“Run the diagnostic”)
* Save the report to your Desktop using the icon representing a floppy disk
* Host the ZHPDiag.txt report on Cjoint, then copy/paste the provided link in your next response on the forum:
https://www.cjoint.com/ => https://www.commentcamarche.net/faq/29493-utiliser-cjoint-pour-heberger-des-fichiers
--
O.o°*♪♪♫ Member, Security Contributor CCM o°.Oø¤º°'°º¤ø
O.o°* ♪♪♫ Breathe deeply, write your message in good French and clearly. It will be fine, you will see, well we will try !!! o°.Oø¤º°'°º¤ø
Hello,
not cool,
* /!\Warning:
This software should only be used as prescribed by a qualified helper.
Do not use outside of this situation: dangerous!
► Download ComboFix from this link and save it on your desktop:
https://forum.pcastuces.com/combofix_renomme_au_telechargement-f31s22.htm
or here:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
Read this
https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
Before using ComboFix:
► close all program windows.
► Temporarily disable and only for the duration of using ComboFix, the real-time protection of your Antivirus and Anti-spywares, which can significantly interfere with the searching and cleaning process of the tool.
Once done, double-click on Combofix.exe on your desktop.
/!\ Vista user: Right-click on the ComboFix logo, "Run as Administrator"
- Answer yes to the warning message, so the program can start to analyze the pc.
- ComboFix may need to connect to the internet to find updates, so you need to allow it.
/!\ During this step, do not use the pc and do not open any programs.
- At the end of the scan, ComboFix may need to restart the pc to complete the disinfection/search, let it do so.
- A report will then open in Notepad, this report file ComboFix.txt is automatically saved and stored at C:\ComboFix\ComboFix.txt)
► Reactivate the real-time protection of your Antivirus and Anti-spywares before reconnecting to the internet.
► Return to the forum, and copy and paste the entire content of C:\Combofix.txt into your next message.
--
O.o°*♪♪♫ Member, Security Contributor CCM o°.Oø¤º°'°º¤ø
O.o°* ♪♪♫ Breathe deeply, write your message clearly in proper French. It will go well, you'll see, at least we're trying!!! o°.Oø¤º°'°º¤ø
not cool,
* /!\Warning:
This software should only be used as prescribed by a qualified helper.
Do not use outside of this situation: dangerous!
► Download ComboFix from this link and save it on your desktop:
https://forum.pcastuces.com/combofix_renomme_au_telechargement-f31s22.htm
or here:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
Read this
https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
Before using ComboFix:
► close all program windows.
► Temporarily disable and only for the duration of using ComboFix, the real-time protection of your Antivirus and Anti-spywares, which can significantly interfere with the searching and cleaning process of the tool.
Once done, double-click on Combofix.exe on your desktop.
/!\ Vista user: Right-click on the ComboFix logo, "Run as Administrator"
- Answer yes to the warning message, so the program can start to analyze the pc.
- ComboFix may need to connect to the internet to find updates, so you need to allow it.
/!\ During this step, do not use the pc and do not open any programs.
- At the end of the scan, ComboFix may need to restart the pc to complete the disinfection/search, let it do so.
- A report will then open in Notepad, this report file ComboFix.txt is automatically saved and stored at C:\ComboFix\ComboFix.txt)
► Reactivate the real-time protection of your Antivirus and Anti-spywares before reconnecting to the internet.
► Return to the forum, and copy and paste the entire content of C:\Combofix.txt into your next message.
--
O.o°*♪♪♫ Member, Security Contributor CCM o°.Oø¤º°'°º¤ø
O.o°* ♪♪♫ Breathe deeply, write your message clearly in proper French. It will go well, you'll see, at least we're trying!!! o°.Oø¤º°'°º¤ø
Good evening
thank you but I just have a few questions:
I haven't reinstalled Avast. Should I do it before running ComboFix or after I have done everything?
And how do I disable my anti-spywares?
And just now, McAfee wanted to start a scan (which I refused!!) What should I do about that?
I'm completely lost.
thank you but I just have a few questions:
I haven't reinstalled Avast. Should I do it before running ComboFix or after I have done everything?
And how do I disable my anti-spywares?
And just now, McAfee wanted to start a scan (which I refused!!) What should I do about that?
I'm completely lost.
Hello,
uninstall Avast (if you still have it on your PC) and any protection software like antispyware (especially if it’s AVG), then run ComboFix
the steps will proceed, let it work :D
normally, it creates a system restore point before launching, if for some reason the PC crashes or doesn't respond on startup, perform a system restore using the point created by ComboFix :D
--
O.o°*♪♪♫ Member, Security Contributor CCM o°.Oø¤º°'°º¤ø
O.o°* ♪♪♫ Breathe deeply, write your message in good French and clearly. It will be fine, you'll see, at least we’ll try!!! o°.Oø¤º°'°º¤ø
uninstall Avast (if you still have it on your PC) and any protection software like antispyware (especially if it’s AVG), then run ComboFix
the steps will proceed, let it work :D
normally, it creates a system restore point before launching, if for some reason the PC crashes or doesn't respond on startup, perform a system restore using the point created by ComboFix :D
--
O.o°*♪♪♫ Member, Security Contributor CCM o°.Oø¤º°'°º¤ø
O.o°* ♪♪♫ Breathe deeply, write your message in good French and clearly. It will be fine, you'll see, at least we’ll try!!! o°.Oø¤º°'°º¤ø
- 1
- 2
- 3
Suivant
I'm not entirely in agreement with Gilles90: I've been using Ccleaner for a long time, and it's true that it does a good job. However, I recently discovered ASC and I find the software much more complete and extremely effective (in the paid version. But still, €14!!). With this software, I made an old laptop that was unusable due to its slowness perfectly smooth.