How to check and correct file paths?

Solved
lajuli Posted messages 40 Status Member -  
billmaxime Posted messages 50522 Registration date   Status Contributor Last intervention   -
Hello everyone,

I am a complete beginner in computers and for the past few days, my PC has been preventing me from installing programs or apps that I download: it keeps telling me to "check that the paths or internet address are correct." I can't manage to install "UTORRENT" or "ADBLOCK PLUS." I uninstalled Chrome thinking it was the problem, but I'm getting the same message with Mozilla: "http: //dowload-servers.com/SysInfo/convertAd.html?topic=New%20offer%21.mozillafirefo-" is not found, check that the path or internet address is correct.
Do you have any idea what is going on?

I looked on forums and some people are talking about viruses.

Thank you in advance

28 answers

  • 1
  • 2
billmaxime Posted messages 50522 Registration date   Status Contributor Last intervention   6 149
 
Hello

to learn more, please do this

download zhpdiag to your desktop (diagnostic tool)

the link https://www.commentcamarche.net/telecharger/utilitaires/24803-zhpdiag/

the tutorial http://www.security-helpzone.com/forum/Thread-ZHPDiag-Generer-un-rapport

Vista-W7-W8 users run as administrator (right click)

click on configure and in the page that opens, click on the magnifying glass with the +

the report will display on your desktop and in C:\zhpdiag.txt

post the report via this link https://www.cjoint.com/

@+

--
the radiation level is higher at Pôle Emploi than at Chernobyl
1
lajuli Posted messages 40 Status Member
 
Hi Billmaxime, and thank you for your quick response :)

I followed the instructions and posted the report on the link, providing my email address. If I understand correctly, I need to wait to receive a "conclusion" on the report sent to my email before knowing what went wrong?
0
billmaxime Posted messages 50522 Registration date   Status Contributor Last intervention   6 149
 
re

no, you need to post the link that was created here in your reply

the cjoint tutorial http://www.pc-infopratique.com/forum-informatique/tutoriel-heberger-rapport-vt-67934.html

see you

--
the radiation level is higher at the employment center than at Chernobyl
0
lajuli Posted messages 40 Status Member
 
I’m sorry, I can’t assist with that.
0
lajuli Posted messages 40 Status Member
 
I need to upload the report: I just caught it.
0
billmaxime Posted messages 50522 Registration date   Status Contributor Last intervention   6 149
 
re

it's a zhpdiag you need to do and not zhpfix>>look at the image

@+

--
the radiation level is higher at the employment office than in Chernobyl
0
lajuli Posted messages 40 Status Member
 
Ok, I spent 3 hours looking for the icon right under my nose, but I found it :/

https://www.cjoint.com/c/CHtkYkQQs8A
0
billmaxime Posted messages 50522 Registration date   Status Contributor Last intervention   6 149
 
re

it's Vietnam on your PC... do this please

download adwcleaner to your desktop (click on the green arrow)

the link https://toolslib.net

users vista-w7-w8 run as administrator (right click)

choose the removal mode

the report will appear on your desktop and in C:\adw[S1].txt

post the report via this link https://www.cjoint.com/

@+

--
the radiation level is higher at the employment office than at Chernobyl
0
lajuli Posted messages 40 Status Member
 
I am posting the link: the report clearly stated that a lot of junk has been installed yet I try to be careful and uncheck the toolbars and others, but apparently I'm not vigilant enough. Thank you very much for your help because I think that without rereading your posts I would be unable to go through these steps again!

https://www.cjoint.com/c/CHtlVriPXtA
0
billmaxime Posted messages 50522 Registration date   Status Contributor Last intervention   6 149
 
re

ok, restart adwcleaner and choose uninstall

then do this please

Download roguekiller to your desktop

take the 32 and not the 64x>>look at the image

The link https://www.luanagames.com/index.fr.html

The tutorial http://tigzyrk.blogspot.be/2012/10/fr-roguekiller-tutoriel-officiel.html

Close all your running programs

Launch roguekiller (vista-w7-w8 users run as administrator - right-click)

Let the prescan run

Click on scan

The report will be displayed on your desktop and in C: RKReport[#].txt

Post the report via 1 copy/paste

@+

--
the radiation rate is higher at the employment office than at Chernobyl
0
lajuli Posted messages 40 Status Member
 
Here is the report:

RogueKiller V8.6.5 [Aug 5 2013] by Tigzy
email: tigzyRK<at>gmail<dot>com
Feedback: http://www.adlice.com/forum/
Website: https://www.luanagames.com/index.fr.html
Blog: http://tigzyrk.blogspot.com/

Operating System: Windows Vista (6.0.6001 Service Pack 1) 32-bit version
Boot: Normal mode
User: juju [Admin rights]
Mode: Scan -- Date: 08/19/2013 12:39:30
| ARK || FAK || MBR |

¤¤¤ Malicious processes: 1 ¤¤¤
[SUSP PATH] ConvertAd.exe -- C:\Users\juju\AppData\Local\ConvertAd\ConvertAd.exe [-] -> KILLED [TermProc]

¤¤¤ Registry entries: 6 ¤¤¤
[RUN][SUSP PATH] HKLM\[...]\Run : ConvertAd (C:\Users\juju\AppData\Local\ConvertAd\ConvertAd.exe [-]) -> FOUND
[PROXY IE] HKCU\[...]\Internet Settings : ProxyServer (hxxp=127.0.0.1:8877;hxxps=127.0.0.1:8877) -> FOUND
[PROXY IE] HKCU\[...]\Internet Settings : ProxyEnable (1) -> FOUND
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
[APPINIT][SUSP PATH] HKLM\[...]\Windows : AppInit_DLLs (c:\progra~2\browse~1\261562~1.220\{c16c1~1\browse~1.dll [7]) -> FOUND

¤¤¤ Scheduled tasks: 1 ¤¤¤
[V2][SUSP PATH] EPUpdater : C:\Users\juju\AppData\Roaming\BABSOL~1\Shared\BabMaint.exe [x] -> FOUND

¤¤¤ Startup entries: 0 ¤¤¤

¤¤¤ Web browsers: 0 ¤¤¤

¤¤¤ Specific files / folders: ¤¤¤

¤¤¤ Driver: [LOAD] ¤¤¤

¤¤¤ External hives: ¤¤¤

¤¤¤ Infection: ¤¤¤

¤¤¤ HOSTS file: ¤¤¤
---> %SystemRoot%\System32\drivers\etc\hosts


127.0.0.1 localhost
::1 localhost


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: ST9250827AS +++++
--- User ---
[MBR] e8e675bb94fc05dd9248e1b079c8ef8d
[BSP] 0eec192cbd5b2f4d1418e7444346eeb2 : Windows Vista/7/8 MBR Code
Partition table:
0 - [XXXXXX] FAT32-LBA (0x1c) [HIDDEN!] Offset (sectors): 2048 | Size: 8000 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 16386048 | Size: 138285 Mo
2 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 299593728 | Size: 92188 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Finished: << RKreport[0]_S_08192013_123930.txt >>




Thank you
0
lajuli Posted messages 40 Status Member
 
re

I imagine I need to remove what appears in the tabs?
0
billmaxime Posted messages 50522 Registration date   Status Contributor Last intervention   6 149
 
Hello

yes, restart roguekiller and click on delete >> look at the image

post the report via 1 copy/paste

then please do this

download MBAM to your desktop

the link https://www.malwarebytes.com/ (choose the free version)

the tutorial https://www.donnemoilinfo.com/tuto/Malwarebytes-Anti-Malware/

run it as administrator (right click)
update it (3rd button)

do a full scan (all drives)

the scan may take about 2 hours (let it work)
if MBAM finds anything, delete the selection (see tutorial 2nd page)

make sure everything is checked before deleting

if MBAM asks for a PC restart, do it

post the report via 1 copy/paste

the report will show up on your desktop and in MBAM report/log
=====================================================

then do this

download usbfix to your desktop (click on the green arrow)

the link https://toolslib.net

disable your antivirus during the download and scan

connect all your external data sources to your PC (USB stick, external hard drive, etc...) without opening them

the tutorial https://www.malekal.com/tutoriels-logiciels/

run it as administrator (right click)

choose the "delete" mode

the report will show up on your desktop and in C:\UsbFix.txt

post the report via 1 copy/paste

@+

--
the radiation level is higher at the employment office than at Chernobyl
0
lajuli Posted messages 40 Status Member
 
Re :)

So this is the copy-paste of the RogueKiller report after deletion.


RogueKiller V8.6.5 [Aug 5 2013] by Tigzy
email: tigzyRK<at>gmail<dot>com
Feedback: http://www.adlice.com/forum/
Website: https://www.luanagames.com/index.fr.html
Blog: http://tigzyrk.blogspot.com/

Operating System: Windows Vista (6.0.6001 Service Pack 1) 32-bit version



Startup: Normal mode
User: juju [Admin rights]
Mode: Deletion -- Date: 08/20/2013 21:23:10
| ARK || FAK || MBR |

¤¤¤ Malicious processes: 0 ¤¤¤

¤¤¤ Registry entries: 4 ¤¤¤
[RUN][SUSP PATH] HKLM\[...]\Run: ConvertAd (C:\Users\juju\AppData\Local\ConvertAd\ConvertAd.exe [-]) -> DELETED
[HJ DESK] HKLM\[...]\NewStartPanel: {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ DESK] HKLM\[...]\NewStartPanel: {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
[APPINIT][SUSP PATH] HKLM\[...]\Windows: AppInit_DLLs (c:\progra~2\browse~1\261562~1.220\{c16c1~1\browse~1.dll [7]) -> REPLACED ()

¤¤¤ Scheduled tasks: 1 ¤¤¤
[V2][SUSP PATH] EPUpdater: C:\Users\juju\AppData\Roaming\BABSOL~1\Shared\BabMaint.exe [x] -> DELETED

¤¤¤ Startup entries: 0 ¤¤¤

¤¤¤ Web browsers: 0 ¤¤¤

¤¤¤ Specific files/folders: ¤¤¤

¤¤¤ Driver: [NOT LOADED 0x2] ¤¤¤

¤¤¤ External hives: ¤¤¤

¤¤¤ Infection: ¤¤¤

¤¤¤ HOSTS file: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts


127.0.0.1 localhost
::1 localhost


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: ST9250827AS +++++
--- User ---
[MBR] e8e675bb94fc05dd9248e1b079c8ef8d
[BSP] 0eec192cbd5b2f4d1418e7444346eeb2: Windows Vista/7/8 MBR Code
Partition table:
0 - [XXXXXX] FAT32-LBA (0x1c) [HIDDEN!] Offset (sectors): 2048 | Size: 8000 MB
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 16386048 | Size: 138285 MB
2 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 299593728 | Size: 92188 MB
User = LL1 ... OK!
User = LL2 ... OK!

Completed: << RKreport[0]_D_08202013_212310.txt >>
RKreport[0]_S_08192013_123930.txt; RKreport[0]_S_08202013_211342.txt
0
billmaxime Posted messages 50522 Registration date   Status Contributor Last intervention   6 149
 
re

you can move on to the next step (MBAM and USBFIX) and post the reports

once done, do a search for updates via Windows Update because your PC

is not up to date

you have SP1 and there is SP2 for Vista

thank you

@+

--
the radiation level is higher at Pôle Emploi than at Chernobyl
0
lajuli Posted messages 40 Status Member
 
Ok thank you

this is the MBAM report after deletion:

Malwarebytes Anti-Malware (Trial) 1.75.0.1300
www.malwarebytes.org

Database version: v2013.08.20.06

Windows Vista Service Pack 1 x86 NTFS
Internet Explorer 7.0.6001.18000
juju :: PC-DE-JUJU [administrator]

Protection: Enabled

20/08/2013 21:31:39
mbam-log-2013-08-20 (21-31-39).txt

Scan type: Full scan (C:\|D:\|E:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristic/Extra | Heuristic/Shuriken | PUP | PUM
Scan options disabled: P2P
Items scanned: 349437
Elapsed time: 1 hour(s), 21 minute(s), 44 second(s)

Memory processes detected: 0
(No harmful items detected)

Memory modules detected: 0
(No harmful items detected)

Registry key(s) detected: 14
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{18DBB6CE-3148-4FEC-B481-103CB3290427} (PUP.Optional.SpeedAnalysis.A) -> Quarantined and successfully deleted.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{93488930-185C-4CED-AFEB-0FD4930F8423} (PUP.Optional.BestToolbars) -> Quarantined and successfully deleted.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{93488930-185C-4CED-AFEB-0FD4930F8423} (PUP.Optional.BestToolbars) -> Quarantined and successfully deleted.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B55EA302-4B9A-5420-6855-9F97315C9A66} (PUP.Optional.Tarma.A) -> Quarantined and successfully deleted.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5DF29C48-19DD-C296-5599-931D15788D0D} (PUP.Optional.Tarma.A) -> Quarantined and successfully deleted.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6DEE36DB-95CF-586A-970B-DCE33A6B5ECA} (PUP.Optional.Tarma.A) -> Quarantined and successfully deleted.
HKLM\SYSTEM\CurrentControlSet\Services\dealplylive (PUP.Optional.DealPly.A) -> Quarantined and successfully deleted.
HKLM\SYSTEM\CurrentControlSet\Services\dealplylivem (PUP.Optional.DealPly.A) -> Quarantined and successfully deleted.
HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WSYSSVC (PUP.Optional.Esafe.A) -> Quarantined and successfully deleted.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6473e2ea-65b5-48ee-9dae-0c142fb8c9fd} (PUP.Optional.LyricsAd) -> Quarantined and successfully deleted.
HKCR\CLSID\{6473e2ea-65b5-48ee-9dae-0c142fb8c9fd} (PUP.Optional.LyricsAd) -> Quarantined and successfully deleted.
HKCR\TypeLib\{aba3e078-3f17-413d-8b50-e8cad7347c1b} (PUP.Optional.LyricsAd) -> Quarantined and successfully deleted.
HKCR\Interface\{CCE3D376-B54F-41F3-925E-FFC5BD080D90} (PUP.Optional.LyricsAd) -> Quarantined and successfully deleted.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6473E2EA-65B5-48EE-9DAE-0C142FB8C9FD} (PUP.Optional.LyricsAd) -> Quarantined and successfully deleted.

Registry value(s) detected: 2
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes|bProtectorDefaultScope (PUP.BProtector) -> Data: {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} -> Quarantined and successfully deleted.
HKLM\SYSTEM\CurrentControlSet\Services\WsysSvc|ImagePath (PUP.Optional.Esafe.A) -> Data: C:\ProgramData\eSafe\eGdpSvc.exe -> Quarantined and successfully deleted.

Data element(s) detected in the registry: 0
(No harmful items detected)

Folder(s) detected: 4
C:\ProgramData\BrowserDefender\2.6.1562.220 (PUP.Optional.BrowserDefender.A) -> Quarantined and successfully deleted.
C:\ProgramData\BrowserDefender\2.6.1562.220\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8} (PUP.Optional.BrowserDefender.A) -> Quarantined and successfully deleted.
C:\ProgramData\BrowserDefender\2.6.1562.220\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension (PUP.Optional.BrowserDefender.A) -> Quarantined and successfully deleted.
C:\ProgramData\BrowserDefender\2.6.1562.220\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings (PUP.Optional.BrowserDefender.A) -> Quarantined and successfully deleted.

File(s) detected: 67
C:\ProgramData\InstallMate\{054E5404-9D90-4E43-ACA8-D5B2DEAD76F2}\Setup.exe (PUP.Optional.Tarma.A) -> Quarantined and successfully deleted.
C:\ProgramData\InstallMate\{054E5404-9D90-4E43-ACA8-D5B2DEAD76F2}\TsuDll.dll (PUP.Optional.Tarma.A) -> Quarantined and successfully deleted.
C:\ProgramData\InstallMate\{88258212-9A9A-4CCA-AE21-D2B853C6A0E4}\Setup.exe (PUP.Optional.Tarma.A) -> Quarantined and successfully deleted.
C:\ProgramData\InstallMate\{88258212-9A9A-4CCA-AE21-D2B853C6A0E4}\TsuDll.dll (PUP.Optional.Tarma.A) -> Quarantined and successfully deleted.
C:\ProgramData\InstallMate\{F4FBC712-3D95-4CB3-AE58-75B72F18E5E4}\Setup.exe (PUP.Optional.Tarma.A) -> Quarantined and successfully deleted.
C:\ProgramData\InstallMate\{F4FBC712-3D95-4CB3-AE58-75B72F18E5E4}\TsuDll.dll (PUP.Optional.Tarma.A) -> Quarantined and successfully deleted.
C:\Users\juju\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2JTNQ01V\rcpsetup_26117[1].exe (PUP.Optional.RegCleanerPro) -> Quarantined and successfully deleted.
C:\Users\juju\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QYCXU2BA\pack[1].7z (PUP.Optional.BrowserDefender.A) -> Quarantined and successfully deleted.
C:\Users\juju\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QYCXU2BA\wajam_install[1].exe (PUP.Optional.Wajam.A) -> Quarantined and successfully deleted.
C:\Users\juju\AppData\Local\Temp\Shortcut_sweetim_0711-adf025c2.exe (PUP.Optional.SweetIM) -> Quarantined and successfully deleted.
C:\Users\juju\AppData\Local\Temp\4244F967-BAB0-7891-A406-552D95A238EF\NTRedirect.dll (PUP.Optional.Babylon.A) -> Quarantined and successfully deleted.
C:\Users\juju\AppData\Local\Temp\4244F967-BAB0-7891-A406-552D95A238EF\BabMaint.exe (PUP.Optional.Babylon.A) -> Quarantined and successfully deleted.
C:\Users\juju\AppData\Local\Temp\4244F967-BAB0-7891-A406-552D95A238EF\BUSolution.dll (PUP.Optional.BabSolution.A) -> Quarantined and successfully deleted.
C:\Users\juju\AppData\Local\Temp\nsaC2A6.tmp\OCSetupHlp.dll (PUP.Optional.OpenCandy) -> Quarantined and successfully deleted.
C:\Users\juju\AppData\Local\Temp\is1590112554\MyBabylonTB.exe (PUP.Optional.Babylon.A) -> Quarantined and successfully deleted.
C:\Users\juju\AppData\Local\Temp\is1668783924\wajam_download.exe (PUP.Optional.Wajam) -> Quarantined and successfully deleted.
C:\Users\juju\AppData\Local\Temp\is1754315082\MyBabylonTB.exe (PUP.Optional.Babylon.A) -> Quarantined and successfully deleted.
C:\Users\juju\AppData\Local\Temp\is1754315082\PricePeepInstaller.exe (Adware.Agent) -> Quarantined and successfully deleted.
C:\Users\juju\AppData\Local\Temp\is45637729\DeltaTB.exe (PUP.Optional.Babylon.A) -> Quarantined and successfully deleted.
C:\Users\juju\AppData\Local\Temp\is45637729\Tuto4PC_Setup_FR.exe (Adware.EoRezo) -> Quarantined and successfully deleted.
C:\Users\juju\AppData\Local\Temp\is45637729\wajam_download.exe (PUP.Optional.Wajam) -> Quarantined and successfully deleted.
C:\Users\juju\AppData\Local\Temp\is-UKU6T.tmp\babylon_download.exe (PUP.Optional.Babylon.A) -> Quarantined and successfully deleted.
C:\Users\juju\AppData\Local\Temp\is1275519350\DeltaTB.exe (PUP.Optional.Babylon.A) -> Quarantined and successfully deleted.
C:\Users\juju\AppData\Local\Temp\is1275519350\Tuto4PC_Setup_FR.exe (Adware.EoRezo) -> Quarantined and successfully deleted.
C:\Users\juju\AppData\Local\Temp\96503F49-BAB0-7891-BEEF-D1181FD40C33\Latest\BabMaint.exe (PUP.Optional.Babylon.A) -> Quarantined and successfully deleted.
C:\Users\juju\AppData\Local\Temp\96503F49-BAB0-7891-BEEF-D1181FD40C33\Latest\BUSolution.dll (PUP.Optional.BabSolution.A) -> Quarantined and successfully deleted.
C:\Users\juju\AppData\Local\Temp\96503F49-BAB0-7891-BEEF-D1181FD40C33\Latest\MyDeltaTB.exe (PUP.Optional.Delta) -> Quarantined and successfully deleted.
C:\Users\juju\AppData\Local\Temp\96503F49-BAB0-7891-BEEF-D1181FD40C33\Latest\Setup.exe (PUP.Babylon.A) -> Quarantined and successfully deleted.
C:\Users\juju\Downloads\AVS_Media_Player (1).exe (Trojan.Repacked) -> Quarantined and successfully deleted.
C:\Users\juju\Downloads\AVS_Media_Player.exe (Trojan.Repacked) -> Quarantined and successfully deleted.
C:\Users\juju\Downloads\Babylon9_setup (1).exe (PUP.Optional.Babylon.A) -> Quarantined and successfully deleted.
C:\Users\juju\Downloads\Babylon9_setup.exe (PUP.Optional.Babylon.A) -> Quarantined and successfully deleted.
C:\Users\juju\Downloads\Download (1).exe (PUP.Optional.Installex) -> Quarantined and successfully deleted.
C:\Users\juju\Downloads\Download.exe (PUP.Optional.Installex) -> Quarantined and successfully deleted.
C:\Users\juju\Downloads\iLividSetupV1 (3).exe (PUP.Optional.Bandoo) -> Quarantined and successfully deleted.
C:\Users\juju\Downloads\Setup (7).exe (PUP.Optional.Solimba) -> Quarantined and successfully deleted.
C:\Users\juju\Downloads\FlashPlayer_V.104859329c.exe (PUP.DomaIQ) -> Quarantined and successfully deleted.
C:\Users\juju\Downloads\iLividSetup-r362-n-bc (1).exe (PUP.Optional.Bandoo) -> Quarantined and successfully deleted.
C:\Users\juju\Downloads\iLividSetup-r362-n-bc.exe (PUP.Optional.Bandoo) -> Quarantined and successfully deleted.
C:\Users\juju\Downloads\iLividSetupV1 (1).exe (PUP.Optional.Bandoo) -> Quarantined and successfully deleted.
C:\Users\juju\Downloads\iLividSetupV1 (2).exe (PUP.Optional.Bandoo) -> Quarantined and successfully deleted.
C:\Users\juju\Downloads\iLividSetupV1 (4).exe (PUP.Optional.Bandoo) -> Quarantined and successfully deleted.
C:\Users\juju\Downloads\iLividSetupV1 (5).exe (PUP.Optional.Bandoo) -> Quarantined and successfully deleted.
C:\Users\juju\Downloads\iLividSetupV1 (6).exe (PUP.Optional.Bandoo) -> Quarantined and successfully deleted.
C:\Users\juju\Downloads\iLividSetupV1.exe (PUP.Optional.Bandoo) -> Quarantined and successfully deleted.
C:\Users\juju\Downloads\01net_AVG_Antivirus_Free_Edition.exe (PUP.Optional.OpenCandy) -> Quarantined and successfully deleted.
C:\Users\juju\Downloads\Les_Oubliees_De_Juarez_RepacK-Team-DsT.avi.exe (PUP.Optional.Installex) -> Quarantined and successfully deleted.
C:\Users\juju\Downloads\rcpsetupmarm_marm161806974fr.exe (PUP.Optional.RegCleanerPro) -> Quarantined and successfully deleted.
C:\Users\juju\Downloads\Setup (3).exe (PUP.Optional.IBryte.A) -> Quarantined and successfully deleted.
C:\Users\juju\Downloads\Setup (4).exe (PUP.Optional.Solimba) -> Quarantined and successfully deleted.
C:\Users\juju\Downloads\Setup (5).exe (PUP.Optional.MSILLauncher) -> Quarantined and successfully deleted.
C:\Users\juju\Downloads\Setup (6).exe (PUP.Optional.Solimba) -> Quarantined and successfully deleted.
C:\Users\juju\Downloads\SweetImSetup.exe (PUP.Optional.SweetIM) -> Quarantined and successfully deleted.
C:\Users\juju\Downloads\veetle-0.9.19 (1).exe (PUP.Optional.OpenCandy) -> Quarantined and successfully deleted.
C:\Users\juju\Downloads\veetle-0.9.19.exe (PUP.Optional.OpenCandy) -> Quarantined and successfully deleted.
C:\Users\juju\Downloads\VideoPerformerSetup.exe (PUP.Optional.InstallBrain) -> Quarantined and successfully deleted.
C:\Users\juju\Downloads\WiseConvert_1.5.exe (PUP.Optional.OpenCandy) -> Quarantined and successfully deleted.
C:\Windows\Tasks\DealPlyLiveUpdateTaskMachineCore.job (PUP.Optional.DealPly.A) -> Quarantined and successfully deleted.
C:\ProgramData\BrowserDefender\2.6.1562.220\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\bl (PUP.Optional.BrowserDefender.A) -> Quarantined and successfully deleted.
C:\ProgramData\BrowserDefender\2.6.1562.220\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.dll (PUP.Optional.BrowserDefender.A) -> Quarantined and successfully deleted.
C:\ProgramData\BrowserDefender\2.6.1562.220\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe (PUP.Optional.BrowserDefender.A) -> Quarantined and successfully deleted.
C:\ProgramData\BrowserDefender\2.6.1562.220\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\dm (PUP.Optional.BrowserDefender.A) -> Quarantined and successfully deleted.
C:\ProgramData\BrowserDefender\2.6.1562.220\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\uninstall.exe (PUP.Optional.BrowserDefender.A) -> Quarantined and successfully deleted.

(end)



I continue following your instructions and as soon as possible I will post.
0
billmaxime Posted messages 50522 Registration date   Status Contributor Last intervention   6 149
 
re

ok, and if you have an issue with usbfix in normal mode, do it in safe mode with networking

safe mode

@+

--
the radiation level is higher at the employment center than at Chernobyl
0
lajuli Posted messages 40 Status Member
 
Oh, I just saw your post. Thank you because I was struggling: "search" okay, but "delete"... it's blocking. I'll try right away.
0
billmaxime Posted messages 50522 Registration date   Status Contributor Last intervention   6 149
 
re

ok, if it's not okay, let me know

@+

--
the radiation level is higher at Pôle Emploi than at Chernobyl
0
lajuli
 
Ok rerere thanks. It's at 95% now but I have a message from Microsoft Windows saying that Go.exe has stopped working. It's asking me to close it. If I don't click, it blocks Usbfix from deleting it :-/
0
billmaxime Posted messages 50522 Registration date   Status Contributor Last intervention   6 149
 
re

have you tried in safe mode?

see you

--
the radiation level is higher at the unemployment office than in Chernobyl
0
lajuli Posted messages 40 Status Member
 
Yes, yes, and I believed it because before it didn’t exceed 10%, and now we were at 95%... I closed Go.exe via the message, and I have a black screen with "safe mode" in the four corners...
0
lajuli Posted messages 40 Status Member
 
Yes yes, and I believed it because before it didn’t exceed 10% and now we were at 95%... I closed Go.exe via the message and I have a black screen with "safe mode" in the four corners...
0
billmaxime Posted messages 50522 Registration date   Status Contributor Last intervention   6 149
 
re

ok, please do this (read the instructions carefully before proceeding)

http://security-helpzone.com/gen-hackman/pre_scan-2/canned-speech/

ps: I will read the report tomorrow>> sleep now

take care and good night

@+

--
the radiation level is higher at the unemployment office than at Chernobyl
0
lajuli Posted messages 40 Status Member
 
Good night to you. I think I'll do the same...
See you tomorrow and thanks again: often the friends who claim to know give up after an hour of racking their brains.
0
billmaxime Posted messages 50522 Registration date   Status Contributor Last intervention   6 149
 
Hello

no worries for the help^^

I'll take a look at your report tonight

@+

--
the radiation level is higher at the employment center than in Chernobyl
0
lajuli Posted messages 40 Status Member
 
Uh... I've been working on this since this morning and... the first launch executed all the way but no report showed up. So I took the initiative to relaunch it and now... it got stuck halfway on "sending to the server." I left it running for a while to see but nothing happened. So I abandoned the process.
I searched in my desk and my documents for the report, just in case it loaded without me noticing, but I couldn't find it.
Should I try again or not?
0
billmaxime Posted messages 50522 Registration date   Status Contributor Last intervention   6 149
 
re

Look in C:\

Post Pre_Scan_the_date_and_time.txt that will appear at the root of the system drive (usually C:\)

@+

--
The radiation level is higher at the unemployment office than at Chernobyl
0
lajuli Posted messages 40 Status Member
 
ok I wasn't opening the drive actually.

Here is the link to the report of the first scan that was successful.

https://www.cjoint.com/c/CHvn5n3nxmO

if you need the other one too just let me know.

have a nice day and see you tonight
0
lajuli Posted messages 40 Status Member
 
Good evening,

just to let you know that I'm not on my PC tonight, so I won't be able to continue the inspection.

Have a good evening!
0
billmaxime Posted messages 50522 Registration date   Status Contributor Last intervention   6 149
 
re

ok, do a search for updates via Windows Update in the Control Panel and install the updates (especially SP2)

then you can run ZHPDiag again as shown in this tutorial>>the tutorial

thanks

@+

the radiation level is higher at the employment office than at Chernobyl
0
lajuli Posted messages 40 Status Member
 
Good evening Bilmaxime,

I am launching the Windows updates.

See you later.
0
lajuli Posted messages 40 Status Member
 
Re ;)

I'm sending you the link to the zhpdiag report after a successful update.

http://cjoint.com/?CHwwGRbZ9Wx

Thank you
0
billmaxime Posted messages 50522 Registration date   Status Contributor Last intervention   6 149
 
Hello lajuli

I'm posting you the link to the zhpdiag report after a successful update.

Are there any updates that failed?

Please do this

Uninstall Adobe Reader X via Programs and Features in the

Control Panel and download the latest version here

https://www.commentcamarche.net/telecharger/bureautique/2625-adobe-reader/
=====================================================

Then do this

Run zhpfix as Administrator (right-click)

Click on this link to open the text to copy https://www.cjoint.com/c/CHxadSpxmeJ

Copy the text, then click on the 2nd button at the top left (paste from clipboard)

Click on GO at the bottom of the page and confirm with yes to start cleaning the data

The report will appear on your desktop and in C:\zhpfix.txt

Post the report via this link https://www.cjoint.com/

@+
--
The radiation level is higher at Pôle Emploi than at Chernobyl
0
lajuli Posted messages 40 Status Member
 
re,

ok thanks, I'm executing, but is it normal that it wasn't reported to me?

see you later
0
lajuli Posted messages 40 Status Member
 
Finally,

here is the report: https://www.cjoint.com/c/CHxb7KM7M8G

Is it normal that as I go through the steps, icons have appeared on my desktop? Computer, network, control panel, but I don’t have a blue arrow on them like I do for shortcuts.

Thank you and see you tomorrow, perhaps.
0
billmaxime Posted messages 50522 Registration date   Status Contributor Last intervention   6 149
 
Hello

Is it normal that as I go through the steps, I have icons that appeared on my desktop? Computer, network, control panel, but I don't have a blue arrow on them like I do for shortcuts.

For your issue with the icons appearing on the desktop, do the following

Click on Start > Control Panel > Folder Options > View

In the window, check the box like in the image

Then click apply

Ok, thanks, I'll do that, but is it normal that I wasn't notified about this?

During installation, you can choose automatic updates for Adobe

There's also this software to keep your programs up to date >> update checker

The link http://www.filehippo.com/fr/updatechecker/

P.S.: I don't download beta versions

When it's done, come back because there are more manipulations to do

If you have any questions...

@+

--
The radiation level is higher at the employment agency than at Chernobyl.
0
lajuli Posted messages 40 Status Member
 
Re,

so in the folder options, the display was already checked to not show hidden folders... it's not a big deal, it's not the most annoying thing.
I'm waiting for the next steps of course.

See you soon.
0
billmaxime Posted messages 50522 Registration date   Status Contributor Last intervention   6 149
 
re

check if this box is checked (in folder options...etc..)

look at the image

@+

--
the radiation level is higher at the job center than at Chernobyl
0
lajuli Posted messages 40 Status Member
 
Good evening Billmaxime,

I didn't have the opportunity to check before.
Now I've done it and yes, it is checked.

See you soon
0
billmaxime Posted messages 50522 Registration date   Status Contributor Last intervention   6 149
 
Salut Lajuli,

can you take a screenshot of your computer desktop and post it in your next response

thanks

@+

--
the radiation level is higher at Pôle Emploi than in Chernobyl
0
lajuli Posted messages 40 Status Member
 
Hello,

I'm sending you the link to the screenshot: http://getwebb.org/v/bY7nxTWw

Thank you :)
0
  • 1
  • 2