Factory reset, emachines EL1352 without backup CD/DVD.

Anonyme -  
billmaxime Posted messages 50527 Registration date   Status Contributor Last intervention   -
Hello,

I would like to reset my eMachines EL1352 without a backup CD/DVD as the title says, and I have no idea how to do it, so I am asking for help.

Thank you in advance.

27 answers

  • 1
  • 2
  1. billmaxime Posted messages 50527 Registration date   Status Contributor Last intervention   6 152
     
    hi

    check this out

    https://www.commentcamarche.net/faq/8775-restaurer-un-ordinateur-acer-a-son-etat-d-usine

    see you

    --
    the radiation level is higher at the job center than at Chernobyl
    1
  2. billmaxime Posted messages 50527 Registration date   Status Contributor Last intervention   6 152
     
    re

    look in disk management if you have 1 "recovery" partition

    to access it, start> right-click on computer> manage> disk management

    the partition should be about 13 to 15 GB

    @+

    --
    the radiation level is higher at the employment center than at Chernobyl
    1
  3. billmaxime Posted messages 50527 Registration date   Status Contributor Last intervention   6 152
     
    re

    well, you follow the link manipulation I gave you earlier (namely ALT+F10 or F10)

    without wanting to be intrusive, why do you want to restore your PC to factory settings?

    if you do, remember to back up your personal data first

    @+

    --
    the radiation level is higher at the job center than at Chernobyl
    1
  4. eMachines EL1352 Posted messages 14 Status Member 1
     
    Thank you for replying so quickly

    The problem is that I can't find Acer eRecovery Management.
    0
    1. fabul Posted messages 42275 Registration date   Status Moderator Last intervention   6 091
       
      Is it a PC that had Vista or Windows 7 pre-installed?
      0
  5. eMachines EL1352 Posted messages 14 Status Member 1
     
    Yes, I have a recovery partition and what do I do with that (yes, I know I'm not skilled).
    0
  6. billmaxime Posted messages 50527 Registration date   Status Contributor Last intervention   6 152
     
    re

    It has been a while since it has been functioning properly

    Do you think it is infected?

    I read that the factory settings were "a second youth" for the PC

    With the factory reset, your PC will be like the day you bought it

    @+

    --
    The radiation level is higher at the unemployment office than at Chernobyl
    0
  7. eMachines EL1352 Posted messages 14 Status Member 1
     
    I don't think it's infected. In fact, the updates that happen when I turn it off always end in failure, so they restart every time I turn it off and always end unsuccessfully.
    I've read that I'm not the only one, but the proposed solutions don't work, so I'm going straight to factory settings, hoping that will work.
    0
  8. billmaxime Posted messages 50527 Registration date   Status Contributor Last intervention   6 152
     
    re

    do you want to run a diagnostic on your pc?

    @+

    --
    the radiation level is higher at the unemployment office than in Chernobyl
    0
  9. eMachines EL1352 Posted messages 14 Status Member 1
     
    As long as we're here, why not, but I have to go; I'll be back around 3 or 4 PM.
    0
  10. billmaxime Posted messages 50527 Registration date   Status Contributor Last intervention   6 152
     
    re

    ok, so before you leave, please do this

    download zhpdiag on your desktop (diagnostic tool)

    the link https://www.commentcamarche.net/telecharger/utilitaires/24803-zhpdiag/

    the tutorial http://www.security-helpzone.com/forum/Thread-ZHPDiag-Generer-un-rapport

    vista-w7-w8 users run as administrator (right click)

    to start the scan, click on the magnifying glass with the + (2nd button at the top left)

    the report will be displayed on your desktop and in C:\zhpdiag.txt

    post the report via this link https://www.cjoint.com/

    @+

    --
    the radiation level is higher at the employment office than at Chernobyl
    0
  11. eMachines EL1352 Posted messages 14 Status Member 1
     
    Okay, I will do it
    The scan is in progress
    0
  12. billmaxime Posted messages 50527 Registration date   Status Contributor Last intervention   6 152
     
    Hello

    your PC is infected, do this

    download AdwCleaner on your desktop (click the green arrow)

    link http://general-changelog-team.fr/fr/downloads/viewdownload/20-outils-de-xplode/2-adwcleaner

    Vista-W7-W8 users run as administrator (right click)

    choose the cleanup mode

    the report will appear on your desktop and in C:\adw[S1].txt

    post the report via 1 copy/paste
    =====================================================
    Avira AntiVir Personal - Free Antivirus v10.2.0.1950 is not up to date>>>

    update Avira
    =====================================================uninstall Adobe Reader 9.1 MUI via programs and features from the

    control panel and download the latest version here

    https://www.commentcamarche.net/telecharger/bureautique/2625-adobe-reader/
    =====================================================
    download UsbFix on your desktop (click the green arrow)

    link http://general-changelog-team.fr/fr/downloads/viewdownload/15-outils-de-el-desaparecido/79-usbfix

    disable your antivirus during the download and scan

    connect all your external data sources to your PC (USB sticks, external hard drives, etc...) without opening them

    the tutorial https://www.malekal.com/tutoriels-logiciels/

    run it as administrator (right click)

    choose the mode "cleanup"

    the report will appear on your desktop and in C:\UsbFix.txt

    post the report via 1 copy/paste

    see you

    --
    the radiation level is higher at the employment office than at Chernobyl
    0
  13. eMachines EL1352 Posted messages 14 Status Member 1
     
    Wow, really that much!
    Well, I’m going to do what you told me, it’s going to take some time.
    1
  14. billmaxime Posted messages 50527 Registration date   Status Contributor Last intervention   6 152
     
    re

    No problem, I'm at my computer all evening

    @+

    --
    the radiation level is higher at the employment office than in Chernobyl
    0
  15. eMachines EL1352 Posted messages 14 Status Member 1
     
    Sure, here is the translation: Ok, that works well for me too
    Here is the first report:

    ***** [Services] *****

    Stopped & Removed: Application Updater

    ***** [Files / Folders] *****

    Folder Removed: C:\Program Files (x86)\Application Updater
    Folder Removed: C:\Program Files (x86)\Common Files\spigot
    Folder Removed: C:\Program Files (x86)\DAEMON Tools Toolbar
    Folder Removed: C:\Program Files (x86)\pdfforge Toolbar
    Folder Removed: C:\Program Files (x86)\QuestBrwSearch
    Folder Removed: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ShopperReports
    Folder Removed: C:\ProgramData\Partner
    Folder Removed: C:\ProgramData\QuestBrwSearch
    Folder Removed: C:\Users\LOC~1\AppData\Local\Temp\boost_interprocess
    Folder Removed: C:\Users\LOC~1\AppData\Local\Temp\Iminent
    Folder Removed: C:\Users\Loïc\AppData\LocalLow\pdfforge
    Folder Removed: C:\Users\Loïc\AppData\LocalLow\Search Settings
    Folder Removed: C:\Users\Loïc\AppData\Roaming\CrazyLoader
    Folder Removed: C:\Users\Loïc\AppData\Roaming\pdfforge
    Folder Removed: C:\Users\Loïc\AppData\Roaming\ShopperReports3

    ***** [Registry] *****

    Key Removed: HKCU\Software\AppDataLow\Software\pdfforge
    Key Removed: HKCU\Software\AppDataLow\Software\Search Settings
    Key Removed: HKCU\Software\IM
    Key Removed: HKCU\Software\ImInstaller
    Key Removed: HKCU\Software\InstallCore
    Key Removed: HKCU\Software\JavaSoft\Prefs\crazyloader
    Key Removed: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{100EB1FD-D03E-47FD-81F3-EE91287F9465}
    Key Removed: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{32099AAC-C132-4136-9E9A-4E364A424E17}
    Key Removed: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B922D405-6D13-4A2B-AE89-08A030DA4402}
    Key Removed: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
    Key Removed: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{32099AAC-C132-4136-9E9A-4E364A424E17}
    Key Removed: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A7CDDCDC-BEEB-4685-A062-978F5E07CEEE}
    Key Removed: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B922D405-6D13-4A2B-AE89-08A030DA4402}
    Key Removed: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
    Key Removed: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
    Key Removed: HKCU\Software\pdfforge
    Key Removed: HKCU\Software\Search Settings
    Key Removed: HKCU\Software\ShopperReports3
    Key Removed: HKCU\Software\Softonic
    Key Removed: HKCU\Software\YahooPartnerToolbar
    Key Removed: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4FC7-90CC-5EA0ABBE9EB8}
    Key Removed: HKLM\Software\Application Updater
    Key Removed: HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}
    Key Removed: HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL
    Key Removed: HKLM\SOFTWARE\Classes\DTToolbar.ToolBandObj
    Key Removed: HKLM\SOFTWARE\Classes\DTToolbar.ToolBandObj.1
    Key Removed: HKLM\SOFTWARE\Classes\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967}
    Key Removed: HKLM\SOFTWARE\Classes\YontooIEClient.Api
    Key Removed: HKLM\SOFTWARE\Classes\YontooIEClient.Api.1
    Key Removed: HKLM\SOFTWARE\Classes\YontooIEClient.Layers
    Key Removed: HKLM\SOFTWARE\Classes\YontooIEClient.Layers.1
    Key Removed: HKLM\Software\Iminent
    Key Removed: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{89F88394-3828-4D03-A0CF-8203604C3DA6}
    Key Removed: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D4233F04-1789-483C-A137-731E8F113DD5}
    Key Removed: HKLM\Software\pdfforge
    Key Removed: HKLM\Software\QuestBrowse
    Key Removed: HKLM\Software\Search Settings
    Key Removed: HKLM\Software\ShopperReports3
    Key Removed: HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
    Key Removed: HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}
    Key Removed: HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
    Key Removed: HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{B922D405-6D13-4A2B-AE89-08A030DA4402}
    Key Removed: HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
    Key Removed: HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
    Key Removed: HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
    Key Removed: HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
    Key Removed: HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A078F691-9C07-4AF2-BF43-35E79EECF8B7}
    Key Removed: HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}
    Key Removed: HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
    Key Removed: HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\QuestBrowse
    Key Removed: HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ShopperReportsSA
    Key Removed: HKLM\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}
    Key Removed: HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
    Key Removed: HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
    Key Removed: HKLM\SOFTWARE\Classes\Interface\{21BA420E-161C-413A-B21E-4E42AE1F4226}
    Key Removed: HKLM\SOFTWARE\Classes\Interface\{453DB0C5-F41C-4D97-8DD6-CC72ECD5F699}
    Key Removed: HKLM\SOFTWARE\Classes\Interface\{4AFC07D0-59BB-46B8-B097-1A46E88EEF71}
    Key Removed: HKLM\SOFTWARE\Classes\Interface\{6511CE4C-4722-40D0-AD3D-4AFA2F50978A}
    Key Removed: HKLM\SOFTWARE\Classes\Interface\{65A16874-2ED0-460E-A547-5FE2EC3A13A7}
    Key Removed: HKLM\SOFTWARE\Classes\Interface\{71E02280-5212-45C3-B174-4D5A35DA254F}
    Key Removed: HKLM\SOFTWARE\Classes\Interface\{8AD9AD05-36BE-4E40-BA62-5422EB0D02FB}
    Key Removed: HKLM\SOFTWARE\Classes\Interface\{9BEC9B38-BF39-4899-806E-A1C5DFEB60A2}
    Key Removed: HKLM\SOFTWARE\Classes\Interface\{AEBF09E2-0C15-43C8-99BF-928C645D98A0}
    Key Removed: HKLM\SOFTWARE\Classes\Interface\{B86D82BF-D39F-439A-A07C-43EDDC6F6EA6}
    Key Removed: HKLM\SOFTWARE\Classes\Interface\{D8560AC2-21B5-4C1A-BDD4-BD12BC83B082}
    Key Removed: HKLM\SOFTWARE\Classes\Interface\{DA6305B9-0869-4235-8C1D-533A65E639E5}
    Key Removed: HKLM\SOFTWARE\Classes\Interface\{E25DA6D6-C365-46CF-ABAF-DC5893135D7A}
    Key Removed: HKLM\SOFTWARE\Classes\Interface\{E6961C59-CFCE-4CCD-B794-BC78DB98413A}
    Key Removed: HKLM\SOFTWARE\Classes\Interface\{F8B4EC8A-2407-4BE0-AEE2-0F430D65A90D}
    Key Removed: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CrazyLoader
    Value Removed: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{32099AAC-C132-4136-9E9A-4E364A424E17}]
    Value Removed: HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{B922D405-6D13-4A2B-AE89-08A030DA4402}]
    Value Removed: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [SearchSettings]
    Value Removed: HKLM\SOFTWARE\Mozilla\Firefox\Extensions [ShopperReports@ShopperReports.com]
    Value Removed: HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{32099AAC-C132-4136-9E9A-4E364A424E17}]
    Value Removed: HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{B922D405-6D13-4A2B-AE89-08A030DA4402}]
    Value Removed: HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{32099AAC-C132-4136-9E9A-4E364A424E17}]

    ***** [Browsers] *****

    -\\ Internet Explorer v9.0.8112.16483

    [OK] The registry does not contain any illegitimate entries.

    -\\ Google Chrome v27.0.1453.116

    File: C:\Users\Loïc\AppData\Local\Google\Chrome\User Data\Default\Preferences

    Removed [l.2593]: homepage = "hxxp://isearch.babylon.com/?affID=120307&babsrc=HP_ss&mntrId=d6fc3d360000000000005ca[...]
    Removed [l.3458]: urls_to_restore_on_startup = [ "hxxp://isearch.babylon.com/?affID=120307&babsrc=HP_ss&mntrId=[...]

    *************************

    AdwCleaner[S1].txt - [8611 bytes] - [07/07/2013 18:55:24]

    ########## EOF - C:\AdwCleaner[S1].txt - [8671 bytes] ##########
    0
  16. eMachines EL1352 Posted messages 14 Status Member 1
     
    Sorry for taking so long, here is the last report:

    ############################## | UsbFix V 7.129 | [Removal]

    User: Loïc (Administrator) # XBOX-CONNECTION
    Updated on 24/06/2013 by El Desaparecido
    Launched at 20:58:49 | 07/07/2013

    Website: https://www.sosvirus.net/
    Upload Malware: http://www.sosvirus.net/upload-malware-pour-analyse-t489.html
    Contact: contact@sosvirus.net

    PC: eMachines (EL1352) (x64-based PC)
    CPU: AMD Athlon(tm) II 170u Processor (2000)
    RAM -> [Total: 1791 | Free: 866]
    BIOS: Default System BIOS
    BOOT: Normal boot

    OS: Microsoft Windows 7 Home Premium Edition (6.1.7601 64-Bit) # Service Pack 1
    WB: Windows Internet Explorer 9.0.8112.16421

    SC: Security Center Service [Enabled]
    WU: Windows Update Service [Enabled]
    AV: AntiVir Desktop [(!) Disabled | Updated]
    FW: Windows FireWall Service [Enabled]

    C:\ (%systemdrive%) -> Fixed disk # 282 Go (215 Go free(s) - 76%) [eMachines] # NTFS
    D:\ -> CD-ROM
    G:\ -> CD-ROM

    ################## | El Desaparecido Section |

    HKLM\SOFTWARE | Run : [NortonOnlineBackupReminder] - "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED
    HKLM\SOFTWARE | Run : [Hotkey Utility] - C:\Program Files (x86)\eMachines\Hotkey Utility\HotkeyUtility.exe
    HKLM\SOFTWARE | Run : [avgnt] - "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
    HKLM\SOFTWARE | Run : [SunJavaUpdateSched] - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    HKLM\SOFTWARE | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
    HKLM\SOFTWARE | Run : [iTunesHelper] - "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
    HKLM\SOFTWARE | Run : [jswtrayutil] - "C:\Program Files (x86)\NETGEAR\WN111v2\jswtrayutil.exe"
    HKLM\SOFTWARE | Run : [] -
    HKLM\SOFTWARE | Run : [BingDesktop] - C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe /fromkey
    HKLM\SOFTWARE | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    HKLM\SOFTWARE\wow6432Node | Run : [NortonOnlineBackupReminder] - "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED
    HKLM\SOFTWARE\wow6432Node | Run : [Hotkey Utility] - C:\Program Files (x86)\eMachines\Hotkey Utility\HotkeyUtility.exe
    HKLM\SOFTWARE\wow6432Node | Run : [avgnt] - "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
    HKLM\SOFTWARE\wow6432Node | Run : [SunJavaUpdateSched] - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    HKLM\SOFTWARE\wow6432Node | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
    HKLM\SOFTWARE\wow6432Node | Run : [iTunesHelper] - "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
    HKLM\SOFTWARE\wow6432Node | Run : [jswtrayutil] - "C:\Program Files (x86)\NETGEAR\WN111v2\jswtrayutil.exe"
    HKLM\SOFTWARE\wow6432Node | Run : [] -
    HKLM\SOFTWARE\wow6432Node | Run : [BingDesktop] - C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe /fromkey
    HKLM\SOFTWARE\wow6432Node | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    HKLM\SOFTWARE | RunOnce : [] -
    HKLM\SOFTWARE\wow6432Node | RunOnce : [] -
    HKU\S-1-5-19\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
    HKU\S-1-5-20\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
    HKU\S-1-5-21-661664250-2286156421-458702171-1000\SOFTWARE | Run : [swg] - "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
    HKU\S-1-5-21-661664250-2286156421-458702171-1000\SOFTWARE | Run : [Google Update] - "C:\Users\Loïc\AppData\Local\Google\Update\GoogleUpdate.exe" /c
    HKU\S-1-5-21-661664250-2286156421-458702171-1000\SOFTWARE | Run : [Steam] - "C:\Program Files (x86)\Steam\Steam.exe" -silent
    HKU\S-1-5-21-661664250-2286156421-458702171-1000\SOFTWARE | Run : [DAEMON Tools Lite] - "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
    HKU\S-1-5-21-661664250-2286156421-458702171-1000\SOFTWARE | Run : [Skype] - "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
    HKU\S-1-5-21-661664250-2286156421-458702171-1003\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
    HKU\S-1-5-19\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
    HKU\S-1-5-20\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
    HKU\S-1-5-21-661664250-2286156421-458702171-1003\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
    HKU\S-1-5-21-661664250-2286156421-458702171-1003\SOFTWARE | RunOnce : [ScrSav] - C:\Program Files (x86)\eMachines\Screensaver\run_eMachines.exe /default

    ################## | Stopped Processes |

    Stopped! C:\Windows\system32\nvvsvc.exe (756)
    Stopped! C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (320)
    Stopped! C:\Windows\system32\nvvsvc.exe (780)
    Stopped! C:\Windows\System32\spoolsv.exe (1484)
    Stopped! C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (1568)
    Stopped! C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (1576)
    Stopped! C:\Program Files (x86)\Steam\Steam.exe (1592)
    Stopped! C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (1600)
    Stopped! C:\Program Files (x86)\NETGEAR\WN111v2\WN111v2.exe (1624)
    Stopped! C:\Windows\system32\taskhost.exe (1644)
    Stopped! C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (1692)
    Stopped! C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (1700)
    Stopped! C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (1724)
    Stopped! C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (1964)
    Stopped! C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (1992)
    Stopped! C:\Windows\SysWOW64\AstSrv.exe (1064)
    Stopped! C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe (1288)
    Stopped! C:\Program Files\Bonjour\mDNSResponder.exe (1372)
    Stopped! C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe (1632)
    Stopped! C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (1316)
    Stopped! C:\Windows\system32\conhost.exe (1832)
    Stopped! C:\Program Files (x86)\eMachines\Hotkey Utility\HotkeyUtility.exe (1912)
    Stopped! C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (984)
    Stopped! C:\Program Files (x86)\iTunes\iTunesHelper.exe (2008)
    Stopped! C:\Program Files (x86)\eMachines\Registration\GregHSRW.exe (2172)
    Stopped! C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe (2452)
    Stopped! C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe (2512)
    Stopped! C:\Program Files (x86)\SFR\Gestionnaire de Connexion SFR\SFRABCDService.exe (2636)
    Stopped! C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (2924)
    Stopped! C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe (1276)
    Stopped! C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (2916)
    Stopped! C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe (1824)
    Stopped! C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (3520)
    Stopped! C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (3708)
    Stopped! C:\Windows\System32\alg.exe (3496)
    Stopped! C:\Program Files\iPod\bin\iPodService.exe (684)
    Stopped! C:\Windows\System32\WUDFHost.exe (4208)
    Stopped! C:\Program Files (x86)\SFR\Gestionnaire de Connexion SFR\ABCd.exe (5108)
    Stopped! C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (3928)
    Stopped! C:\Program Files\Windows Media Player\wmpnetwk.exe (3540)
    Stopped! C:\Windows\system32\wuauclt.exe (3016)
    Stopped! C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (4292)
    Stopped! C:\Windows\system32\SearchIndexer.exe (5060)

    ################## | Infectious Items |

    Deleted! C:\install.exe

    (!) Temporary files deleted.

    ################## | Registry |

    ################## | Mountpoints2 |

    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{6f6aa7d3-1e5c-11e0-a89f-00262d3fc368}

    ################## | Listing |

    [17/01/2011 - 18:47:23 | SHD ] C:\$Recycle.Bin
    [07/07/2013 - 18:56:45 | N | 8698] C:\AdwCleaner[S1].txt
    [13/09/2010 - 03:08:44 | D ] C:\book
    [06/05/2010 - 18:27:32 | N | 8192] C:\BOOTSECT.BAK
    [07/07/2013 - 19:49:44 | D ] C:\Config.Msi
    [14/07/2009 - 07:08:56 | SHD ] C:\Documents and Settings
    [07/11/2007 - 09:00:40 | N | 17734] C:\eula.1028.txt
    [07/11/2007 - 09:00:40 | N | 17734] C:\eula.1031.txt
    [07/11/2007 - 09:00:40 | N | 10134] C:\eula.1033.txt
    [07/11/2007 - 09:00:40 | N | 17734] C:\eula.1036.txt
    [07/11/2007 - 09:00:40 | N | 17734] C:\eula.1040.txt
    [07/11/2007 - 09:00:40 | N | 118] C:\eula.1041.txt
    [07/11/2007 - 09:00:40 | N | 17734] C:\eula.1042.txt
    [07/11/2007 - 09:00:40 | N | 17734] C:\eula.2052.txt
    [07/11/2007 - 09:00:40 | N | 17734] C:\eula.3082.txt
    [07/11/2007 - 09:00:40 | N | 1110] C:\globdata.ini
    [07/07/2013 - 18:58:37 | ASH | 1408786432] C:\hiberfil.sys
    [07/11/2007 - 09:00:40 | N | 843] C:\install.ini
    [07/11/2007 - 09:44:20 | N | 75280] C:\install.res.1028.dll
    [07/11/2007 - 09:44:20 | N | 95248] C:\install.res.1031.dll
    [07/11/2007 - 09:44:20 | N | 90128] C:\install.res.1033.dll
    [07/11/2007 - 09:44:20 | N | 96272] C:\install.res.1036.dll
    [07/11/2007 - 09:44:20 | N | 94224] C:\install.res.1040.dll
    [07/11/2007 - 09:44:20 | N | 80400] C:\install.res.1041.dll
    [07/11/2007 - 09:44:20 | N | 78864] C:\install.res.1042.dll
    [07/11/2007 - 09:44:20 | N | 74768] C:\install.res.2052.dll
    [07/11/2007 - 09:44:20 | N | 95248] C:\install.res.3082.dll
    [18/01/2011 - 17:35:58 | RHD ] C:\MSOCache
    [12/01/2011 - 17:03:07 | D ] C:\OEM
    [07/07/2013 - 18:58:42 | ASH | 1878384640] C:\pagefile.sys
    [14/07/2009 - 05:20:08 | D ] C:\PerfLogs
    [07/07/2013 - 16:59:40 | N | 512] C:\PhysicalDisk0_MBR.bin
    [16/05/2013 - 12:27:28 | D ] C:\Program Files
    [07/07/2013 - 18:55:40 | D ] C:\Program Files (x86)
    [07/07/2013 - 18:55:39 | HD ] C:\ProgramData
    [12/01/2011 - 17:01:28 | SHD ] C:\Recovery
    [13/09/2010 - 03:05:06 | N | 2246] C:\RHDSetup.log
    [07/07/2013 - 19:51:18 | SHD ] C:\System Volume Information
    [21/05/2013 - 17:57:23 | D ] C:\Temp
    [07/07/2013 - 21:04:03 | D ] C:\UsbFix
    [07/07/2013 - 21:04:19 | A | 10334] C:\UsbFix [Clean 2] XBOX-CONNECTION.txt
    [21/05/2013 - 17:57:29 | D ] C:\Users
    [07/11/2007 - 09:00:40 | N | 5686] C:\vcredist.bmp
    [07/11/2007 - 09:50:40 | N | 1927956] C:\VC_RED.cab
    [07/11/2007 - 09:53:12 | N | 242176] C:\VC_RED.MSI
    [07/07/2013 - 10:13:41 | D ] C:\Windows
    [07/07/2013 - 16:56:47 | D ] C:\ZHP
    [13/11/2011 - 23:03:03 | N | 22] C:\zzz.txt

    ################## | Vaccine |

    C:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)

    ################## | E.O.F | https://www.sosvirus.net/ |
    0
  17. billmaxime Posted messages 50527 Registration date   Status Contributor Last intervention   6 152
     
    re

    ok, run adwcleaner in delete mode and post the report

    thank you

    @+

    --
    the radiation level is higher at the employment agency than at Chernobyl
    0
  18. billmaxime Posted messages 50527 Registration date   Status Contributor Last intervention   6 152
     
    re

    ok, restart adwcleaner and choose uninstall

    then do a zhpdiag again by clicking on the magnifying glass with the + and post the report

    via this link https://www.cjoint.com/

    thank you

    @+

    --
    the radiation level is higher at the employment office than in Chernobyl
    0
  • 1
  • 2