How to check and correct file paths? - Page 2

Solved
Previous
  • 1
  • 2
  1. billmaxime Posted messages 50538 Registration date   Status Contributor Last intervention   6 154
     
    re

    The icons that have appeared are not bothersome at all and allow you to access more

    quickly what they inform

    let me know if you still have any issues with your PC

    @+

    --
    The radiation level is higher at Pôle Emploi than at Chernobyl.
    0
    1. lajuli Posted messages 40 Status Member
       
      Good evening,

      yes, that's what I was thinking too, but I was wondering why they appeared. However, it’s true that it’s not bothersome.

      So far, it seems fine: I no longer have ads or pages that open unexpectedly :) and I was able to download and install Utorrent without any issue (no more messages about the access paths). Of course, I took a closer look at the site from which I installed it and was careful during the installation phases!!!

      Are there any other manipulations to do?

      In any case, thank you for your help.
      0
  2. billmaxime Posted messages 50538 Registration date   Status Contributor Last intervention   6 154
     
    re

    yes, you still need to do this

    download Delfix to your desktop

    the link http://general-changelog-team.fr/fr/downloads/viewdownload/20-outils-de-xplode/9-delfix

    run it as administrator (right-click)

    make sure all the boxes are checked:5

    click on run

    the report will appear on your desktop and in C:\delfix.txt

    post the report via copy/paste

    @+

    --
    the radiation level is higher at the employment office than in Chernobyl
    0
    1. lajuli Posted messages 40 Status Member
       
      Hello,

      I'm starting to despair with my PC :-\ but I guess you have a clearer view of things than I do :-)

      I'm pasting the Delfix report that I just ran. Thanks

      # DelFix v10.4 - Report created on 30/08/2013 at 08:08:12
      # Updated on 19/07/2013 by Xplode
      # Username: juju - PC-DE-JUJU
      # Operating System: Windows Vista (TM) Home Premium Service Pack 2 (32 bits)

      ~ UAC activation ... OK

      ~ Removal of disinfection tools ...

      Deleted: C:\USBFix
      Deleted: C:\pre_scan
      Deleted: C:\ZHP
      Deleted: C:\Users\juju\Desktop\RK_Quarantine
      Deleted: C:\Program Files\ZHPDiag
      Deleted: C:\PhysicalDisk0_MBR.bin
      Deleted: C:\Pre_Scan_21_08_2013_09_28_06.txt
      Deleted: C:\Pre_Scan_21_08_2013_10_29_37.txt
      Deleted: C:\UsbFix [Clean 2] PC-DE-JUJU.txt
      Deleted: C:\UsbFix [Clean 3] PC-DE-JUJU.txt
      Deleted: C:\UsbFix [Clean 5] PC-DE-JUJU.txt
      Deleted: C:\UsbFix [Listing 1 ] PC-DE-JUJU.txt
      Deleted: C:\UsbFix [Scan 1] PC-DE-JUJU.txt
      Deleted: C:\UsbFix [Scan 2] PC-DE-JUJU.txt
      Deleted: C:\Users\juju\Desktop\winlogon.exe
      Deleted: C:\Users\Public\Desktop\MBRCheck.lnk
      Deleted: C:\Users\Public\Desktop\ZHPDiag.lnk
      Deleted: C:\Users\Public\Desktop\ZHPFix.lnk
      Deleted: HKCU\Software\g3n-h@ckm@n
      Deleted: HKCU\Software\USBFix
      Deleted: HKLM\SOFTWARE\g3n-h@ckm@n
      Deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\USBFix
      Deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZHPDiag_is1

      ~ Backup of the registry ... OK

      ~ Purge of system restore ...

      Deleted: RP #728 [Scheduled restore point | 08/29/2013 07:34:04]

      New restore point created!

      ~ Resetting system settings ... OK

      ########## - EOF - ##########
      0
  3. billmaxime Posted messages 50538 Registration date   Status Contributor Last intervention   6 154
     
    Hi Lajuli,

    I'm starting to despair with my PC :-\ but I guess you see things more clearly than I do :-)

    Is something wrong?

    @+

    --
    The radiation level is higher at the employment office than at Chernobyl.
    0
    1. lajuli Posted messages 40 Status Member
       
      No no, my PC is definitely better now, it's just that with all the scans and reports I think it must have been really messed up inside... and I was wondering if there’s still a lot of work to be done on it?!

      Sorry for the false alarm ^^
      0
  4. billmaxime Posted messages 50538 Registration date   Status Contributor Last intervention   6 154
     
    re

    I just reread the topic from the beginning, and only usbfix hasn't gone all the way..

    I would suggest trying usbfix again in search mode to see if it finds something

    let me know what you think

    @+

    --
    the radiation levels are higher at the employment center than at Chernobyl
    0
    1. lajuli Posted messages 40 Status Member
       
      Okay, no worries, I'll launch that right away

      see you soon
      0
    2. lajuli Posted messages 40 Status Member
       
      Here is the research report:


      ############################## | UsbFix V 7.133 | [Research]

      User: juju (Administrator) # PC-DE-JUJU
      Updated on 27/08/2013 by El Desaparecido
      Launched at 09:16:26 | 30/08/2013

      Website: https://www.sosvirus.net/
      Upload Malware: http://sosvirus.net/viewtopic.php?f=6&t=489
      Contact: eldesaparecido@sosvirus.net

      PC: ASUSTeK Computer Inc. (F7Se ) (X86-based PC)
      CPU: Intel(R) Core(TM)2 Duo CPU T5550 @ 1.83GHz (1833)
      RAM -> [Total: 3070 | Free: 1688]
      BIOS: Default System BIOS
      BOOT: Normal boot

      OS: Microsoft® Windows Vista(TM) Home Premium Edition (6.0.6002 32-Bit) # Service Pack 2
      WB: Windows Internet Explorer 9.0.8112.16421

      SC: Security Center Service [Enabled]
      WU: Windows Update Service [Enabled]
      AV: AVG Internet Security 2013 [Enabled | Updated]
      FW: Windows FireWall Service [Enabled]

      A:\ -> Removable drive # 1 MB (1 MB free - 48%) [] # FAT
      C:\ (%systemdrive%) -> Fixed drive # 135 GB (95 GB free - 70%) [VistaOS] # NTFS
      D:\ -> Fixed drive # 90 GB (87 GB free - 96%) [DATA] # NTFS
      E:\ -> Removable drive # 4 GB (895 MB free - 23%) [AHMAD] # FAT32
      F:\ -> Fixed drive # 298 GB (61 GB free - 20%) [My Passport] # FAT32
      G:\ -> Removable drive # 979 MB (88 MB free - 9%) [JULIETTEUSB] # FAT
      H:\ -> CD-ROM
      I:\ -> CD-ROM
      J:\ -> Removable drive # 4 GB (1 GB free - 31%) [Cruzer] # FAT32

      ################## | Active Processes |

      C:\PROGRA~1\AVG\AVG2013\avgrsx.exe (608)
      C:\Program Files\AVG\AVG2013\avgcsrvx.exe (648)
      C:\Windows\system32\csrss.exe (856)
      C:\Windows\system32\wininit.exe (916)
      C:\Windows\system32\csrss.exe (928)
      C:\Windows\system32\services.exe (964)
      C:\Windows\system32\lsass.exe (980)
      C:\Windows\system32\lsm.exe (988)
      C:\Windows\system32\winlogon.exe (1092)
      C:\Windows\system32\svchost.exe (1176)
      C:\Windows\system32\svchost.exe (1236)
      C:\Windows\system32\Ati2evxx.exe (1372)
      C:\Windows\System32\svchost.exe (1388)
      C:\Windows\System32\svchost.exe (1456)
      C:\Windows\system32\svchost.exe (1468)
      C:\Windows\system32\svchost.exe (1572)
      C:\Windows\system32\SLsvc.exe (1588)
      C:\Windows\system32\svchost.exe (1640)
      C:\Windows\system32\Ati2evxx.exe (1744)
      C:\Windows\system32\svchost.exe (1800)
      C:\Program Files\ATK Hotkey\ASLDRSrv.exe (1908)
      C:\Program Files\ATKGFNEX\GFNEXSrv.exe (1920)
      C:\Windows\System32\spoolsv.exe (2016)
      C:\Windows\system32\svchost.exe (124)
      C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (1184)
      C:\Program Files\AVG\AVG2013\avgfws.exe (1348)
      C:\Program Files\AVG\AVG2013\avgidsagent.exe (1796)
      C:\Program Files\AVG\AVG2013\avgwdsvc.exe (580)
      C:\Windows\system32\svchost.exe (2072)
      C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (2124)
      C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (2196)
      C:\Windows\System32\svchost.exe (2304)
      C:\Windows\System32\svchost.exe (2348)
      C:\Windows\system32\svchost.exe (2380)
      C:\Windows\system32\svchost.exe (2468)
      C:\Program Files\sysTPL\sysTPLMonitor.exe (2492)
      C:\Program Files\sysTPL\sysTPLService.exe (2640)
      C:\Program Files\AVG\AVG2013\avgnsx.exe (2724)
      C:\Program Files\AVG\AVG2013\avgemcx.exe (2732)
      C:\Windows\System32\svchost.exe (2840)
      C:\Windows\system32\SearchIndexer.exe (2868)
      C:\Windows\System32\WUDFHost.exe (3108)
      C:\Windows\system32\taskeng.exe (3276)
      C:\Program Files\AVG\AVG2013\avgcsrvx.exe (3660)
      C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (3456)
      C:\Windows\system32\Dwm.exe (3796)
      C:\Windows\Explorer.EXE (4012)
      C:\Program Files\ATK Hotkey\Hcontrol.exe (3936)
      C:\Program Files\Wireless Console 2\wcourier.exe (2084)
      C:\Windows\system32\taskeng.exe (2792)
      C:\Program Files\ATK Hotkey\ATKOSD.exe (3944)
      C:\Program Files\ATK Hotkey\KBFiltr.exe (2332)
      C:\Program Files\ATK Hotkey\WDC.exe (4064)
      C:\Program Files\ATKOSD2\ATKOSD2.exe (3964)
      C:\Windows\RtHDVCpl.exe (3532)
      C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (1788)
      C:\Program Files\Common Files\Java\Java Update\jusched.exe (1208)
      C:\Program Files\AVG\AVG2013\avgui.exe (1500)
      C:\Program Files\Windows Sidebar\sidebar.exe (4060)
      C:\Windows\ehome\ehtray.exe (3892)
      C:\Users\juju\AppData\Local\Facebook\Update\FacebookUpdate.exe (3336)
      C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe (2880)
      C:\Users\juju\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (1264)
      C:\Windows\ehome\ehmsas.exe (4116)
      C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE (4124)
      C:\Program Files\Windows Media Player\wmpnscfg.exe (4132)
      C:\Windows\ehome\ehsched.exe (4360)
      C:\Program Files\Windows Media Player\wmpnetwk.exe (4828)
      C:\Windows\system32\svchost.exe (5936)
      C:\Program Files\Sony\Sony PC Companion\PCCompanionInfo.exe (5204)
      C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (5372)
      C:\Windows\system32\svchost.exe (5996)
      C:\Windows\ehome\ehRecvr.exe (4760)
      C:\Program Files\Skype\Phone\Skype.exe (3748)
      C:\Windows\system32\conime.exe (5460)
      C:\Windows\system32\wbem\wmiprvse.exe (5620)
      C:\Windows\system32\SearchProtocolHost.exe (1452)
      C:\Windows\system32\SearchFilterHost.exe (2244)
      C:\UsbFix\Go.exe (5788)

      ################## | El Desaparecido Section |

      HKLM\SOFTWARE | Run : [Windows Defender] - %ProgramFiles%\Windows Defender\MSASCui.exe -hide
      HKLM\SOFTWARE | Run : [StartCCC] - "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
      HKLM\SOFTWARE | Run : [ATKOSD2] - "C:\Program Files\ATKOSD2\ATKOSD2.exe"
      HKLM\SOFTWARE | Run : [RtHDVCpl] - RtHDVCpl.exe
      HKLM\SOFTWARE | Run : [Skytel] - Skytel.exe
      HKLM\SOFTWARE | Run : [SMSERIAL] - C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
      HKLM\SOFTWARE | Run : [APSDaemon] - "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
      HKLM\SOFTWARE | Run : [SunJavaUpdateSched] - "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
      HKLM\SOFTWARE | Run : [AVG_UI] - "C:\Program Files\AVG\AVG2013\avgui.exe" /TRAYONLY
      HKLM\SOFTWARE | Run : [Adobe ARM] - "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
      HKLM\SOFTWARE | RunOnce : [] -
      HKU\S-1-5-19\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem
      HKU\S-1-5-19\SOFTWARE | Run : [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
      HKU\S-1-5-20\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem
      HKU\S-1-5-20\SOFTWARE | Run : [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
      HKU\S-1-5-21-653066466-3458025753-1810980726-1000\SOFTWARE | Run : [Sidebar] - C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
      HKU\S-1-5-21-653066466-3458025753-1810980726-1000\SOFTWARE | Run : [ehTray.exe] - C:\Windows\ehome\ehTray.exe
      HKU\S-1-5-21-653066466-3458025753-1810980726-1000\SOFTWARE | Run : [Facebook Update] - "C:\Users\juju\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
      HKU\S-1-5-21-653066466-3458025753-1810980726-1000\SOFTWARE | Run : [Sony PC Companion] - "C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe" /Background
      HKU\S-1-5-21-653066466-3458025753-1810980726-1000\SOFTWARE | Run : [Spotify Web Helper] - "C:\Users\juju\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
      HKU\S-1-5-21-653066466-3458025753-1810980726-1000\SOFTWARE | Run : [FileHippo.com] - "C:\Program Files\FileHippo.com\UpdateChecker.exe" /background

      ################## | Infectious Items |

      Present! A:\autorun.inf
      Present! G:\autorun.inf
      Present! I:\autorun.inf

      ################## | Registry |


      ################## | Mountpoints2 |



      ################## | Vaccine |

      C:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
      D:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)

      ################## | E.O.F | https://www.sosvirus.net/ |
      0
  5. billmaxime Posted messages 50538 Registration date   Status Contributor Last intervention   6 154
     
    re

    put it in deletion mode and post the report

    thank you

    @+

    --
    the radiation level is higher at the employment agency than at Chernobyl
    0
    1. lajuli Posted messages 40 Status Member
       
      Re,

      It got stuck at 14%... should I try it in safe mode?

      See you!
      0
  6. billmaxime Posted messages 50538 Registration date   Status Contributor Last intervention   6 154
     
    re

    switch to safe mode>> safe mode

    see you

    --
    the radiation level is higher at the employment office than at Chernobyl
    0
    1. lajuli Posted messages 40 Status Member
       
      Hi,

      I ran it in safe mode with network support like last time and the deletion went through completely. Is everything okay?
      Here is the link to the report

      https://www.cjoint.com/c/CHExPD4hMMg

      If it needs to be in "simple" safe mode, just let me know.

      Thank you
      and have a good evening
      0
  7. billmaxime Posted messages 50538 Registration date   Status Contributor Last intervention   6 154
     
    re

    for me it’s good... tell me how your computer is doing

    @+

    --
    the radiation level is higher at the employment office than at Chernobyl
    0
    1. lajuli Posted messages 40 Status Member
       
      Hello,

      Well, I must say, it's great: I can do whatever I want without those error messages or 35 pages of ads opening up. It must have done him a world of good!
      A big thank you to you, your patience, and your knowledge. It was a pleasure to have someone competent and approachable: as soon as the vocabulary gets too technical, I lose track :-), so thank you for your simplicity.
      0
  8. billmaxime Posted messages 50538 Registration date   Status Contributor Last intervention   6 154
     
    re

    I’ve attached a little reading for you so you won't make the same mistakes when you're

    on the internet

    https://forum.malekal.com/viewtopic.php?t=6173&start=

    https://www.malekal.com/proteger-pc-virus-pirates/?t=381&start=

    You can also download and install update checker to keep your programs

    up to date

    the link http://www.filehippo.com/fr/updatechecker/

    ps: I don’t download beta versions

    if everything is okay for you, you can mark your topic as resolved

    https://www.commentcamarche.net/infos/25917-marquer-un-fil-de-discussion-comme-etant-resolu/

    @+ and happy surfing

    --
    the radiation level is higher at the unemployment office than at Chernobyl
    0
Previous
  • 1
  • 2