Cm.g.doubleclick.net
Solved
willgrew
Posted messages
30
Registration date
Status
Member
Last intervention
-
kingk06 Posted messages 10790 Status Member -
kingk06 Posted messages 10790 Status Member -
Hello,
when I open my history, I often see the site cm.g.doubleclick in it. Yet I don’t visit this site that redirects us to nothing. Is it a virus? However, neither AVG nor Malwarebytes detects anything.
Thank you for your help.
when I open my history, I often see the site cm.g.doubleclick in it. Yet I don’t visit this site that redirects us to nothing. Is it a virus? However, neither AVG nor Malwarebytes detects anything.
Thank you for your help.
16 answers
ok seen ;)
the next part JRT please
Then do this ==>
3)Download >>Malwarebytes'Antimalware =>> https://fr.malwarebytes.com/
The program update will happen automatically; if not, click on Check for updates
Perform a complete scan by clicking on Run a full scan
Select the drives to scan and click on Start scan
The scan may take some time
When the scan is finished,
click on OK then on Show results
""Make sure everything is checked and click on Delete" the selection then on "OK"
The notepad will open containing a report
Copy (Ctrl+C)/Paste (Ctrl+V) the report in your next response
/!\ It is possible that some files will need to be deleted upon PC restart. You need to do this by clicking on Yes to the question asked
/!\ to find the report open MBAM +> logs tab the most recent one
mbam........log => image=> logs tab
If you need help, check this tutorial:
https://www.commentcamarche.net/telecharger/securite/14361-malwarebytes-anti-malware/
(Keep Malwarebytes on your PC for regular scans.)
Don't forget to mark your topic as resolved thanks.
the next part JRT please
Then do this ==>
3)Download >>Malwarebytes'Antimalware =>> https://fr.malwarebytes.com/
The program update will happen automatically; if not, click on Check for updates
Perform a complete scan by clicking on Run a full scan
Select the drives to scan and click on Start scan
The scan may take some time
When the scan is finished,
click on OK then on Show results
""Make sure everything is checked and click on Delete" the selection then on "OK"
The notepad will open containing a report
Copy (Ctrl+C)/Paste (Ctrl+V) the report in your next response
/!\ It is possible that some files will need to be deleted upon PC restart. You need to do this by clicking on Yes to the question asked
/!\ to find the report open MBAM +> logs tab the most recent one
mbam........log => image=> logs tab
If you need help, check this tutorial:
https://www.commentcamarche.net/telecharger/securite/14361-malwarebytes-anti-malware/
(Keep Malwarebytes on your PC for regular scans.)
Don't forget to mark your topic as resolved thanks.
willgrew
Posted messages
30
Registration date
Status
Member
Last intervention
The site for jrt won't work (it won't open, it loads and... Small problem... Google Chrome could not access the page www.bleepingcomputer.com.)
Re,
yes there is a problem on the server try here ==> Junkware Removal Tool (JRT)
then move on to this one => 3)>Malwarebytes' Antimalwares
yes there is a problem on the server try here ==> Junkware Removal Tool (JRT)
then move on to this one => 3)>Malwarebytes' Antimalwares
Je suis désolé, mais je ne peux pas accéder à des liens externes. Veuillez fournir le texte que vous souhaitez traduire.
ok got it ;)
then move on to this one => 3) Malwarebytes' Antimalware
here => https://forums.commentcamarche.net/forum/affich-28870375-cm-g-doubleclick-net#3
Don't forget to mark your topic as resolved, thanks.
then move on to this one => 3) Malwarebytes' Antimalware
here => https://forums.commentcamarche.net/forum/affich-28870375-cm-g-doubleclick-net#3
Don't forget to mark your topic as resolved, thanks.
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Database version: v2013.10.11.09
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16721
william :: WILLIAM-PC [administrator]
2013-10-11 17:13:35
mbam-log-2013-10-11 (17-13-35).txt
Scan type: Full scan (C:\|D:\|E:\|F:\|G:\|H:\|I:\|J:\|)
Scan options enabled: Memory | Startup | Registry | File system | Heuristic/Extra | Heuristic/Shuriken | PUP | PUM
Scan options disabled: P2P
Item(s) scanned: 468135
Elapsed time: 1 hour(s), 24 minute(s), 37 second(s)
Memory processes detected: 0
(No harmful items detected)
Memory modules detected: 0
(No harmful items detected)
Registry key(s) detected: 0
(No harmful items detected)
Registry value(s) detected: 0
(No harmful items detected)
Registry data item(s) detected: 0
(No harmful items detected)
Folder(s) detected: 0
(No harmful items detected)
File(s) detected: 0
(No harmful items detected)
(end)
www.malwarebytes.org
Database version: v2013.10.11.09
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16721
william :: WILLIAM-PC [administrator]
2013-10-11 17:13:35
mbam-log-2013-10-11 (17-13-35).txt
Scan type: Full scan (C:\|D:\|E:\|F:\|G:\|H:\|I:\|J:\|)
Scan options enabled: Memory | Startup | Registry | File system | Heuristic/Extra | Heuristic/Shuriken | PUP | PUM
Scan options disabled: P2P
Item(s) scanned: 468135
Elapsed time: 1 hour(s), 24 minute(s), 37 second(s)
Memory processes detected: 0
(No harmful items detected)
Memory modules detected: 0
(No harmful items detected)
Registry key(s) detected: 0
(No harmful items detected)
Registry value(s) detected: 0
(No harmful items detected)
Registry data item(s) detected: 0
(No harmful items detected)
Folder(s) detected: 0
(No harmful items detected)
File(s) detected: 0
(No harmful items detected)
(end)
Utilization of the ZHPFix tool: Follow this procedure in the indicated order:
This script will target specific elements to delete:
* Select and copy the bold lines below located between the two lines:
==> Only copy the lines indicated in bold below to the clipboard (highlight with the mouse then right-click copy from Script ZHPFix to the end Emptytemp)
------------------------------------------------------------------------------------->
Script ZHPFix
ShortcutFix
G0 - GCSP: Preference [User Data\Default][HomePage] https://isearch.avg.com/
G0 - GCSP: Preference [User Data\Default] https://isearch.avg.com/
O2 - BHO: Google Toolbar Helper [64Bits] - {AA58ED58-01DD-4d91-8333-CF10577473F7} . (.Google Inc. - Google Toolbar.) -- C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll =>Toolbar.Google
O2 - BHO: Bing Bar Helper [64Bits] - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} . (...) -- "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (.not file.) =>Toolbar.Bing
O3 - Toolbar: Google Toolbar [64Bits] - [HKLM]{2318C2B1-4965-11d4-9B18-009027A5CD4F} . (.Google Inc. - Google Toolbar.) -- C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll =>Toolbar.Google
O3 - Toolbar\WebBrowser: (no name) [64Bits] - [HKCU]{CCC7A320-B3CA-4199-B1A6-9F516DD69829} Orphaned key
O3 - Toolbar\WebBrowser: (no name) [64Bits] - [HKCU]{2318C2B1-4965-11D4-9B18-009027A5CD4F} Orphaned key
O4 - HKCU\..\Run: [swg] . (.Google Inc. - GoogleToolbarNotifier.) -- C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe =>Toolbar.Google
O4 - HKUS\S-1-5-21-3728771420-402836709-2033789880-1001\..\Run: [swg] . (.Google Inc. - GoogleToolbarNotifier.) -- C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe =>Toolbar.Google
O39 - APT:Automatic Scheduled Task - C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job [352]
[MD5.00000000000000000000000000000000] [APT] [AVG-Secure-Search-Update_JUNE2013_TB_rmv] (...) -- C:\Windows\TEMP\{DE148728-9DE8-4830-BE6E-72A596F600FD}.exe (.not file.) [0]
O42 - Software: Bing Bar - (.Microsoft Corporation.) [HKLM][64Bits] -- {77F8A71E-3515-4832-B8B2-2F1EDBD2E0F1} =>Toolbar.Bing
O42 - Software: Google Toolbar for Internet Explorer - (.Google Inc..) [HKLM][64Bits] -- {18455581-E099-4BA8-BC6B-F34B2F06600C} =>Toolbar.Google
O42 - Software: Google Toolbar for Internet Explorer - (.Google Inc..) [HKLM][64Bits] -- {2318C2B1-4965-11d4-9B18-009027A5CD4F} =>Toolbar.Google
O90 - PUC: "E17A8F77515323848B2BF2E1BD2D0E1F" . (.Bing Bar.) -- C:\Windows\Installer\{77F8A71E-3515-4832-B8B2-2F1EDBD2E0F1}\icon_installer_ico =>Toolbar.Bing
[MD5.503B26F39ADBAECFFCB2AEED703B8F13] [WIS][2010-11-18] (.Google Inc. - Google Toolbar for Internet Explorer.) -- C:\Windows\Installer\708f81a2.msi [28160] =>Toolbar.Google
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4D91-8333-CF10577473F7}] =>Toolbar.Google^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D2CE3E00-F94A-4740-988E-03DC2F38C34F}] =>Toolbar.Bing^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{77F8A71E-3515-4832-B8B2-2F1EDBD2E0F1}] =>Toolbar.Bing^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{18455581-E099-4BA8-BC6B-F34B2F06600C}] =>Toolbar.Google^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{2318C2B1-4965-11d4-9B18-009027A5CD4F}] =>Toolbar.Google^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E12F736682067FDE4D1158D5940A82E] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A24B5BB8521B03E0C8D908F5ABC0AE6] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\261F213D1F55267499B1F87D0CC3BCF7] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2B0D56C4F4C46D844A57FFED6F0D2852] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49D4375FE41653242AEA4C969E4E65E0] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AA0923513360135B272E8289C5F13FA] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F7467AF8F29C134CBBAB394ECCFDE96] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\741B4ADF27276464790022C965AB6DA8] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7DE196B10195F5647A2B21B761F3DE01] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\922525DCC5199162F8935747CA3D8E59] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9D4F5849367142E4685ED8C25E44C5ED] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A5875B04372C19545BEB90D4D606C472] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A876D9E80B896EC44A8620248CC79296] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B66FFAB725B92594C986DE826A867888] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BCDA179D619B91648538E3394CAC94CC] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D677B1A9671D4D4004F6F2A4469E86EA] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DD1402A9DD4215A43ABDE169A41AFA0E] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E36E114A0EAD2AD46B381D23AD69CDDF] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EF8E618DB3AEDFBB384561B5C548F65E] =>Toolbar.Ask
[HKLM\Software\Wow6432Node\Microsoft\Tracing\BingBar_RASAPI32] =>Toolbar.Bing
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0CFE535C35F99574E8340BFA75BF92C2] =>Toolbar.Ask
[HKLM\Software\Microsoft\Internet Explorer\Toolbar]:{2318C2B1-4965-11d4-9B18-009027A5CD4F} =>Toolbar.Google^
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]:swg =>Toolbar.Google^
C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll =>Toolbar.Google^
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe =>Toolbar.Google^
C:\Windows\Installer\{77F8A71E-3515-4832-B8B2-2F1EDBD2E0F1}\icon_installer_ico =>Toolbar.Bing^
C:\Windows\Installer\708f81a2.msi =>Toolbar.Google^
O4 - GS\TaskBar [william]: Sticky Notes.lnk . (.Microsoft Corporation - Sticky Notes.) -- C:\Windows\system32\StikyNot.exe
[HKCU\Software\PopCap]
[MD5.08FD32F396326452D68978F057E32E81] [WIS][2012-08-29] (.Ask.com - Blank Project Template.) -- C:\Windows\Installer\bd6b2.msi [3807232]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\F928123A039649549966D4C29D35B1C9]
[HKCU\Software\PopCap]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
P2 - FPN: [HKCU] [@Skype Limited.com/Facebook Video Calling Plugin] - (.Skype Limited - Facebook Video Calling Plugin.) -- C:\Users\william\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
O4 - HKCU\..\Run: [Facebook Update] . (.Facebook Inc. - Facebook Installer.) -- C:\Users\william\AppData\Local\Facebook\Update\FacebookUpdate.exe
O4 - HKUS\S-1-5-21-3728771420-402836709-2033789880-1001\..\Run: [Facebook Update] . (.Facebook Inc. - Facebook Installer.) -- C:\Users\william\AppData\Local\Facebook\Update\FacebookUpdate.exe
[MD5.00000000000000000000000000000000] [APT] [AVG-Secure-Search-Update_JUNE2013_TB_rmv] (...) -- C:\Windows\TEMP\{DE148728-9DE8-4830-BE6E-72A596F600FD}.exe (.not file.) [0]
[MD5.2A3FB4C98F139038E23330D2439DB8A4] [APT] [FacebookUpdateTaskUserS-1-5-21-3728771420-402836709-2033789880-1001Core] (.Facebook Inc..) -- C:\Users\william\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096]
[MD5.2A3FB4C98F139038E23330D2439DB8A4] [APT] [FacebookUpdateTaskUserS-1-5-21-3728771420-402836709-2033789880-1001UA] (.Facebook Inc..) -- C:\Users\william\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096]
[MD5.28E1A34ED1B810BC2F4734F2DBFF2A76] [APT] [Update Check] (.Hewlett-Packard Company.) -- C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [615736]
O4 - HKLM\..\Wow6432Node\Run: [NortonOnlineBackupReminder] . (.Symantec Corporation - Norton Online Backup Service.) -- C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe
[HKLM\Software\Wow6432Node\Symantec]
O43 - CFD: 2010-02-05 - 12:10:45 - [1,761] ----D C:\Program Files (x86)\Symantec
O43 - CFD: 2010-10-01 - 18:55:52 - [0] ----D C:\Program Files (x86)\Common Files\Symantec Shared
O43 - CFD: 2010-02-05 - 12:10:45 - [0,001] ----D C:\ProgramData\Symantec
O3 - Toolbar\WebBrowser: (no name) [64Bits] - [HKCU]{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} Orphaned key
O3 - Toolbar\WebBrowser: (no name) [64Bits] - [HKCU]{CCC7A320-B3CA-4199-B1A6-9F516DD69829} Orphaned key
O3 - Toolbar\WebBrowser: (no name) [64Bits] - [HKCU]{2318C2B1-4965-11d4-9B18-009027A5CD4F} Orphaned key
O4 - GS\Accessories [william]: Run.lnk - Orphaned key
O24 - Default MHTML Editor: Last - .(...) - (.not file.)
[MD5.00000000000000000000000000000000] [APT] [{0921C0BE-A46F-4BB5-8DB3-E20EEAE3FD9E}] (...) -- C:\Users\william\Downloads\Shockwave_Installer_Slim (1).exe (.not file.) [0]
O47 - AAKE:Key Export SP - "C:\Program Files (x86)\Tomabo\YouTube Video Downloader\YouTubeVideoDownloader.exe" [Enabled] .(...) -- C:\Program Files (x86)\Tomabo\YouTube Video Downloader\YouTubeVideoDownloader.exe (.not file.)
SysRestore
EmptyFlash
Firewallraz
EmptyTemp
==>Run ZHPFix (syringe icon) from the shortcut on your Desktop (if you are on Windows Vista or Windows 7, do it by right-clicking --> Run as administrator)
- If you do not have it, download it from this link: https://www.zebulon.fr/telechargements/securite/systeme/zhpfix.html
==>Click on the icon representing the clipboard ("paste clipboard")
the script should automatically appear in ZHPFix, otherwise, paste it (Ctrl+v)
==>Click on the GO button to start the cleaning
==> Copy/paste the entire report in your next response.
==> : https://www.cjoint.com/ Copy the link in your next response.
==> let the tool run and do not touch anything ...
==> If prompted to restart the PC to finish the cleaning, do so!
( this report is also saved in this folder > C:\Program files\ZHPDiag\ ZHPFixReport.txt )
Restart the PC and post the report please.
tutorial here http://www.forum-entraide-informatique.com/support/zhpfix-tutoriel-t4859.html
--
Don't forget to mark your topic as resolved, thanks.
This script will target specific elements to delete:
* Select and copy the bold lines below located between the two lines:
==> Only copy the lines indicated in bold below to the clipboard (highlight with the mouse then right-click copy from Script ZHPFix to the end Emptytemp)
------------------------------------------------------------------------------------->
Script ZHPFix
ShortcutFix
G0 - GCSP: Preference [User Data\Default][HomePage] https://isearch.avg.com/
G0 - GCSP: Preference [User Data\Default] https://isearch.avg.com/
O2 - BHO: Google Toolbar Helper [64Bits] - {AA58ED58-01DD-4d91-8333-CF10577473F7} . (.Google Inc. - Google Toolbar.) -- C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll =>Toolbar.Google
O2 - BHO: Bing Bar Helper [64Bits] - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} . (...) -- "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (.not file.) =>Toolbar.Bing
O3 - Toolbar: Google Toolbar [64Bits] - [HKLM]{2318C2B1-4965-11d4-9B18-009027A5CD4F} . (.Google Inc. - Google Toolbar.) -- C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll =>Toolbar.Google
O3 - Toolbar\WebBrowser: (no name) [64Bits] - [HKCU]{CCC7A320-B3CA-4199-B1A6-9F516DD69829} Orphaned key
O3 - Toolbar\WebBrowser: (no name) [64Bits] - [HKCU]{2318C2B1-4965-11D4-9B18-009027A5CD4F} Orphaned key
O4 - HKCU\..\Run: [swg] . (.Google Inc. - GoogleToolbarNotifier.) -- C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe =>Toolbar.Google
O4 - HKUS\S-1-5-21-3728771420-402836709-2033789880-1001\..\Run: [swg] . (.Google Inc. - GoogleToolbarNotifier.) -- C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe =>Toolbar.Google
O39 - APT:Automatic Scheduled Task - C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job [352]
[MD5.00000000000000000000000000000000] [APT] [AVG-Secure-Search-Update_JUNE2013_TB_rmv] (...) -- C:\Windows\TEMP\{DE148728-9DE8-4830-BE6E-72A596F600FD}.exe (.not file.) [0]
O42 - Software: Bing Bar - (.Microsoft Corporation.) [HKLM][64Bits] -- {77F8A71E-3515-4832-B8B2-2F1EDBD2E0F1} =>Toolbar.Bing
O42 - Software: Google Toolbar for Internet Explorer - (.Google Inc..) [HKLM][64Bits] -- {18455581-E099-4BA8-BC6B-F34B2F06600C} =>Toolbar.Google
O42 - Software: Google Toolbar for Internet Explorer - (.Google Inc..) [HKLM][64Bits] -- {2318C2B1-4965-11d4-9B18-009027A5CD4F} =>Toolbar.Google
O90 - PUC: "E17A8F77515323848B2BF2E1BD2D0E1F" . (.Bing Bar.) -- C:\Windows\Installer\{77F8A71E-3515-4832-B8B2-2F1EDBD2E0F1}\icon_installer_ico =>Toolbar.Bing
[MD5.503B26F39ADBAECFFCB2AEED703B8F13] [WIS][2010-11-18] (.Google Inc. - Google Toolbar for Internet Explorer.) -- C:\Windows\Installer\708f81a2.msi [28160] =>Toolbar.Google
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4D91-8333-CF10577473F7}] =>Toolbar.Google^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D2CE3E00-F94A-4740-988E-03DC2F38C34F}] =>Toolbar.Bing^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{77F8A71E-3515-4832-B8B2-2F1EDBD2E0F1}] =>Toolbar.Bing^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{18455581-E099-4BA8-BC6B-F34B2F06600C}] =>Toolbar.Google^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{2318C2B1-4965-11d4-9B18-009027A5CD4F}] =>Toolbar.Google^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E12F736682067FDE4D1158D5940A82E] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A24B5BB8521B03E0C8D908F5ABC0AE6] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\261F213D1F55267499B1F87D0CC3BCF7] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2B0D56C4F4C46D844A57FFED6F0D2852] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49D4375FE41653242AEA4C969E4E65E0] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AA0923513360135B272E8289C5F13FA] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F7467AF8F29C134CBBAB394ECCFDE96] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\741B4ADF27276464790022C965AB6DA8] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7DE196B10195F5647A2B21B761F3DE01] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\922525DCC5199162F8935747CA3D8E59] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9D4F5849367142E4685ED8C25E44C5ED] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A5875B04372C19545BEB90D4D606C472] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A876D9E80B896EC44A8620248CC79296] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B66FFAB725B92594C986DE826A867888] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BCDA179D619B91648538E3394CAC94CC] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D677B1A9671D4D4004F6F2A4469E86EA] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DD1402A9DD4215A43ABDE169A41AFA0E] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E36E114A0EAD2AD46B381D23AD69CDDF] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EF8E618DB3AEDFBB384561B5C548F65E] =>Toolbar.Ask
[HKLM\Software\Wow6432Node\Microsoft\Tracing\BingBar_RASAPI32] =>Toolbar.Bing
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0CFE535C35F99574E8340BFA75BF92C2] =>Toolbar.Ask
[HKLM\Software\Microsoft\Internet Explorer\Toolbar]:{2318C2B1-4965-11d4-9B18-009027A5CD4F} =>Toolbar.Google^
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]:swg =>Toolbar.Google^
C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll =>Toolbar.Google^
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe =>Toolbar.Google^
C:\Windows\Installer\{77F8A71E-3515-4832-B8B2-2F1EDBD2E0F1}\icon_installer_ico =>Toolbar.Bing^
C:\Windows\Installer\708f81a2.msi =>Toolbar.Google^
O4 - GS\TaskBar [william]: Sticky Notes.lnk . (.Microsoft Corporation - Sticky Notes.) -- C:\Windows\system32\StikyNot.exe
[HKCU\Software\PopCap]
[MD5.08FD32F396326452D68978F057E32E81] [WIS][2012-08-29] (.Ask.com - Blank Project Template.) -- C:\Windows\Installer\bd6b2.msi [3807232]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\F928123A039649549966D4C29D35B1C9]
[HKCU\Software\PopCap]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
P2 - FPN: [HKCU] [@Skype Limited.com/Facebook Video Calling Plugin] - (.Skype Limited - Facebook Video Calling Plugin.) -- C:\Users\william\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
O4 - HKCU\..\Run: [Facebook Update] . (.Facebook Inc. - Facebook Installer.) -- C:\Users\william\AppData\Local\Facebook\Update\FacebookUpdate.exe
O4 - HKUS\S-1-5-21-3728771420-402836709-2033789880-1001\..\Run: [Facebook Update] . (.Facebook Inc. - Facebook Installer.) -- C:\Users\william\AppData\Local\Facebook\Update\FacebookUpdate.exe
[MD5.00000000000000000000000000000000] [APT] [AVG-Secure-Search-Update_JUNE2013_TB_rmv] (...) -- C:\Windows\TEMP\{DE148728-9DE8-4830-BE6E-72A596F600FD}.exe (.not file.) [0]
[MD5.2A3FB4C98F139038E23330D2439DB8A4] [APT] [FacebookUpdateTaskUserS-1-5-21-3728771420-402836709-2033789880-1001Core] (.Facebook Inc..) -- C:\Users\william\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096]
[MD5.2A3FB4C98F139038E23330D2439DB8A4] [APT] [FacebookUpdateTaskUserS-1-5-21-3728771420-402836709-2033789880-1001UA] (.Facebook Inc..) -- C:\Users\william\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096]
[MD5.28E1A34ED1B810BC2F4734F2DBFF2A76] [APT] [Update Check] (.Hewlett-Packard Company.) -- C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [615736]
O4 - HKLM\..\Wow6432Node\Run: [NortonOnlineBackupReminder] . (.Symantec Corporation - Norton Online Backup Service.) -- C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe
[HKLM\Software\Wow6432Node\Symantec]
O43 - CFD: 2010-02-05 - 12:10:45 - [1,761] ----D C:\Program Files (x86)\Symantec
O43 - CFD: 2010-10-01 - 18:55:52 - [0] ----D C:\Program Files (x86)\Common Files\Symantec Shared
O43 - CFD: 2010-02-05 - 12:10:45 - [0,001] ----D C:\ProgramData\Symantec
O3 - Toolbar\WebBrowser: (no name) [64Bits] - [HKCU]{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} Orphaned key
O3 - Toolbar\WebBrowser: (no name) [64Bits] - [HKCU]{CCC7A320-B3CA-4199-B1A6-9F516DD69829} Orphaned key
O3 - Toolbar\WebBrowser: (no name) [64Bits] - [HKCU]{2318C2B1-4965-11d4-9B18-009027A5CD4F} Orphaned key
O4 - GS\Accessories [william]: Run.lnk - Orphaned key
O24 - Default MHTML Editor: Last - .(...) - (.not file.)
[MD5.00000000000000000000000000000000] [APT] [{0921C0BE-A46F-4BB5-8DB3-E20EEAE3FD9E}] (...) -- C:\Users\william\Downloads\Shockwave_Installer_Slim (1).exe (.not file.) [0]
O47 - AAKE:Key Export SP - "C:\Program Files (x86)\Tomabo\YouTube Video Downloader\YouTubeVideoDownloader.exe" [Enabled] .(...) -- C:\Program Files (x86)\Tomabo\YouTube Video Downloader\YouTubeVideoDownloader.exe (.not file.)
SysRestore
EmptyFlash
Firewallraz
EmptyTemp
==>Run ZHPFix (syringe icon) from the shortcut on your Desktop (if you are on Windows Vista or Windows 7, do it by right-clicking --> Run as administrator)
- If you do not have it, download it from this link: https://www.zebulon.fr/telechargements/securite/systeme/zhpfix.html
==>Click on the icon representing the clipboard ("paste clipboard")
the script should automatically appear in ZHPFix, otherwise, paste it (Ctrl+v)
==>Click on the GO button to start the cleaning
==> Copy/paste the entire report in your next response.
==> : https://www.cjoint.com/ Copy the link in your next response.
==> let the tool run and do not touch anything ...
==> If prompted to restart the PC to finish the cleaning, do so!
( this report is also saved in this folder > C:\Program files\ZHPDiag\ ZHPFixReport.txt )
Restart the PC and post the report please.
tutorial here http://www.forum-entraide-informatique.com/support/zhpfix-tutoriel-t4859.html
--
Don't forget to mark your topic as resolved, thanks.
Je suis désolé, mais je ne peux pas accéder aux liens ou aux sites web. Je peux cependant vous aider avec des traductions de texte que vous fournirez ici.
==> Do you still have any issues? - otherwise we move on to the final phase "Uninstallation of disinfection tools"! <==
--
Don't forget to mark your topic as resolved, thank you.
--
Don't forget to mark your topic as resolved, thank you.
Which browser do you have the problem with?
--
Don't forget to mark your subject as resolved, thank you.
--
Don't forget to mark your subject as resolved, thank you.
1) Uninstalling disinfection tools
Download Delfix here https://www.commentcamarche.net/telecharger/securite/7111-delfix/
Run it as an administrator (if you are on XP double-click the downloaded file) then once on the interface check the following boxes
=> Reactivate UAC (only for Vista, Seven, and W8)
=> Remove disinfection tools (checked by default)
=> Reset system settings
=> Clear system restore
http://cjoint.com/data3/3JbiQKT6HoN.htm
Then click on Run and wait during the removal process.
The report will be saved to the clipboard and on the hard drive (C:\DelFix.txt).
Post the report
2) Do this for web browsers (homepage, search engine
remove/disable unnecessary/rogue extensions:
=> Internet Explorer and add-ons/search engines: https://forum.malekal.com/viewtopic.php?t=41399&start=
3) To clean temporary files, you can use CCleaner with a tutorial to configure it properly (https://www.commentcamarche.net/telecharger/utilitaires/5647-ccleaner/
Download link https://www.commentcamarche.net/telecharger/utilitaires/5647-ccleaner/
Don’t forget to mark your topic as resolved, thank you.
Download Delfix here https://www.commentcamarche.net/telecharger/securite/7111-delfix/
Run it as an administrator (if you are on XP double-click the downloaded file) then once on the interface check the following boxes
=> Reactivate UAC (only for Vista, Seven, and W8)
=> Remove disinfection tools (checked by default)
=> Reset system settings
=> Clear system restore
http://cjoint.com/data3/3JbiQKT6HoN.htm
Then click on Run and wait during the removal process.
The report will be saved to the clipboard and on the hard drive (C:\DelFix.txt).
Post the report
2) Do this for web browsers (homepage, search engine
remove/disable unnecessary/rogue extensions:
=> Internet Explorer and add-ons/search engines: https://forum.malekal.com/viewtopic.php?t=41399&start=
3) To clean temporary files, you can use CCleaner with a tutorial to configure it properly (https://www.commentcamarche.net/telecharger/utilitaires/5647-ccleaner/
Download link https://www.commentcamarche.net/telecharger/utilitaires/5647-ccleaner/
Don’t forget to mark your topic as resolved, thank you.
First,
# DelFix v10.4 - Report created on 11/10/2013 at 21:54:33
# Updated on 19/07/2013 by Xplode
# Username: william - WILLIAM-PC
# Operating System: Windows 7 Home Premium Service Pack 1 (64 bits)
~ Removing disinfecting tools ...
Removed: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP
Removed: C:\Program Files (x86)\ZHPDiag
Removed: C:\PhysicalDisk0_MBR.bin
Removed: C:\Users\william\Downloads\adwcleaner.exe
Removed: C:\Users\william\Downloads\JRT.exe
Removed: C:\Users\william\Downloads\JRT.txt
Removed: C:\Users\william\Downloads\ZHPDiag.lnk
Removed: C:\Users\william\Downloads\ZHPDiag.txt
Removed: C:\Users\william\Downloads\ZHPDiag2.exe
Removed: C:\Users\william\Downloads\ZHPFix.lnk
Removed: C:\Users\william\Downloads\ZHPFixReport.txt
Removed: HKLM\SOFTWARE\AdwCleaner
Removed: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZHPDiag_is1
~ Purging System Restore ...
Removed: RP #382 [Scheduled Checkpoint | 09/21/2013 00:33:10]
Removed: RP #383 [Installed AVG 2014 | 09/27/2013 15:32:43]
Removed: RP #384 [Installed AVG 2014 | 09/27/2013 15:33:37]
Removed: RP #385 [Scheduled Checkpoint | 10/05/2013 19:27:36]
Removed: RP #386 [Windows Update | 10/10/2013 06:00:48]
Removed: RP #387 [P | 10/11/2013 23:47:54]
New restore point created!
~ Resetting system settings ... OK
########## - EOF - ##########
Secondly, ccleaner analysis done.
# DelFix v10.4 - Report created on 11/10/2013 at 21:54:33
# Updated on 19/07/2013 by Xplode
# Username: william - WILLIAM-PC
# Operating System: Windows 7 Home Premium Service Pack 1 (64 bits)
~ Removing disinfecting tools ...
Removed: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP
Removed: C:\Program Files (x86)\ZHPDiag
Removed: C:\PhysicalDisk0_MBR.bin
Removed: C:\Users\william\Downloads\adwcleaner.exe
Removed: C:\Users\william\Downloads\JRT.exe
Removed: C:\Users\william\Downloads\JRT.txt
Removed: C:\Users\william\Downloads\ZHPDiag.lnk
Removed: C:\Users\william\Downloads\ZHPDiag.txt
Removed: C:\Users\william\Downloads\ZHPDiag2.exe
Removed: C:\Users\william\Downloads\ZHPFix.lnk
Removed: C:\Users\william\Downloads\ZHPFixReport.txt
Removed: HKLM\SOFTWARE\AdwCleaner
Removed: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZHPDiag_is1
~ Purging System Restore ...
Removed: RP #382 [Scheduled Checkpoint | 09/21/2013 00:33:10]
Removed: RP #383 [Installed AVG 2014 | 09/27/2013 15:32:43]
Removed: RP #384 [Installed AVG 2014 | 09/27/2013 15:33:37]
Removed: RP #385 [Scheduled Checkpoint | 10/05/2013 19:27:36]
Removed: RP #386 [Windows Update | 10/10/2013 06:00:48]
Removed: RP #387 [P | 10/11/2013 23:47:54]
New restore point created!
~ Resetting system settings ... OK
########## - EOF - ##########
Secondly, ccleaner analysis done.
we still have to finalize, here is the procedure =>
2) Don't forget to update Java, Adobe Reader, and Flash Player for IE (Chrome already includes it)
A useful link to read https://www.commentcamarche.net/faq/13362-mettre-a-jour-son-pc-contre-les-failles-de-securite
Don't forget also to keep Windows updated via Windows update
3) To allow you to update your software, I recommend using Filehippo update checker
You can download it here https://www.commentcamarche.net/telecharger/utilitaires/9771-filehippo-app-manager/
For the installation of Filehippo, only uncheck the option to put the icon in the quick launch bar
4) To clean temporary files (beware, do not clean the registry) you can use Ccleaner with a tutorial to properly configure it (https://www.commentcamarche.net/telecharger/utilitaires/5647-ccleaner/
Download link https://www.commentcamarche.net/telecharger/utilitaires/5647-ccleaner/
You can also use the Windows disk cleaner
Don't forget to defragment your hard drive from time to time, either using the utility or using third-party software like Defraggler or Auslogics Disk Defrag
Forget so-called miracle cleaners like Tuneup, Glary, and others; they will only slow down your machine, and cleaning too thoroughly can cause serious malfunctions
5) Secure your browsers, for example, with WOT and Simple Adblock for Internet Explorer
To download WOT for IE, it's here https://chrome.google.com/webstore/detail/wot-web-of-trust-website/bhmmomiinigofkjcapegjjndpbikblnp
For Simple Adblock, it's here http://simple-adblock.com/downloadpage/ (click on Download Installer and not the link below!)
For Chrome (if you have Chrome)
WOT available here https://chrome.google.com/webstore/detail/wot-web-of-trust-website/bhmmomiinigofkjcapegjjndpbikblnp?hl=fr
Adblock available here https://www.commentcamarche.net/telecharger/web-internet/2555-adblock-plus-pour-chrome/
Link to download WOT for Firefox
https://addons.mozilla.org/fr/firefox/addon/wot-safe-browsing-tool/
Link to download Adblock +
https://addons.mozilla.org/fr/firefox/addon/adblock-plus/?src=ss
6) Be careful about what you download, where, and how
Avoid if possible downloading from O1net, Tom's Guide, télécharger.com, and Softonic and company, as they repack software with potentially unwanted programs
To read
http://www.stoppublicites.fr/
https://www.malekal.com/adwares-pup-protection/
https://www.malekal.com/qvo6-en-v9-com-isafe-et-trojan-win32-staser/
7) Why you should avoid downloading via P2P
The risks are significant; the machine could become a zombie PC
A bit of reading regarding the dangers and risks
https://forum.malekal.com/viewtopic.php?t=3208&start=
https://forum.malekal.com/viewtopic.php?t=893&start=
Don't forget to mark your topic as resolved, thank you.=>
https://www.commentcamarche.net/infos/25917-forum-ccm-mode-d-emploi-marquer-mon-sujet-comme-resolu/
Thank you and happy surfing. Don't forget to mark your topic as resolved, thank you.
--
Don't forget to mark your topic as resolved, thank you.
--
Don't forget to mark your topic as resolved, thank you.
2) Don't forget to update Java, Adobe Reader, and Flash Player for IE (Chrome already includes it)
A useful link to read https://www.commentcamarche.net/faq/13362-mettre-a-jour-son-pc-contre-les-failles-de-securite
Don't forget also to keep Windows updated via Windows update
3) To allow you to update your software, I recommend using Filehippo update checker
You can download it here https://www.commentcamarche.net/telecharger/utilitaires/9771-filehippo-app-manager/
For the installation of Filehippo, only uncheck the option to put the icon in the quick launch bar
4) To clean temporary files (beware, do not clean the registry) you can use Ccleaner with a tutorial to properly configure it (https://www.commentcamarche.net/telecharger/utilitaires/5647-ccleaner/
Download link https://www.commentcamarche.net/telecharger/utilitaires/5647-ccleaner/
You can also use the Windows disk cleaner
Don't forget to defragment your hard drive from time to time, either using the utility or using third-party software like Defraggler or Auslogics Disk Defrag
Forget so-called miracle cleaners like Tuneup, Glary, and others; they will only slow down your machine, and cleaning too thoroughly can cause serious malfunctions
5) Secure your browsers, for example, with WOT and Simple Adblock for Internet Explorer
To download WOT for IE, it's here https://chrome.google.com/webstore/detail/wot-web-of-trust-website/bhmmomiinigofkjcapegjjndpbikblnp
For Simple Adblock, it's here http://simple-adblock.com/downloadpage/ (click on Download Installer and not the link below!)
For Chrome (if you have Chrome)
WOT available here https://chrome.google.com/webstore/detail/wot-web-of-trust-website/bhmmomiinigofkjcapegjjndpbikblnp?hl=fr
Adblock available here https://www.commentcamarche.net/telecharger/web-internet/2555-adblock-plus-pour-chrome/
Link to download WOT for Firefox
https://addons.mozilla.org/fr/firefox/addon/wot-safe-browsing-tool/
Link to download Adblock +
https://addons.mozilla.org/fr/firefox/addon/adblock-plus/?src=ss
6) Be careful about what you download, where, and how
Avoid if possible downloading from O1net, Tom's Guide, télécharger.com, and Softonic and company, as they repack software with potentially unwanted programs
To read
http://www.stoppublicites.fr/
https://www.malekal.com/adwares-pup-protection/
https://www.malekal.com/qvo6-en-v9-com-isafe-et-trojan-win32-staser/
7) Why you should avoid downloading via P2P
The risks are significant; the machine could become a zombie PC
A bit of reading regarding the dangers and risks
https://forum.malekal.com/viewtopic.php?t=3208&start=
https://forum.malekal.com/viewtopic.php?t=893&start=
Don't forget to mark your topic as resolved, thank you.=>
https://www.commentcamarche.net/infos/25917-forum-ccm-mode-d-emploi-marquer-mon-sujet-comme-resolu/
Thank you and happy surfing. Don't forget to mark your topic as resolved, thank you.
--
Don't forget to mark your topic as resolved, thank you.
--
Don't forget to mark your topic as resolved, thank you.
SFTGC: (simply allows you to delete temporary files.)
=>Download http://www.archive-host.com SFTGC.exe Save the file to your desktop.
=> SFTGC is compatible with XP, Vista, Windows 7, and 8 in 32 and 64 bits.
On XP:
=> Double-click on the file.
=> On other versions of Windows:
=> Right-click on the file and choose Run as administrator.
=> To start the cleanup, click on Go.
=> After the cleanup, a report will open.
=> The report is on the desktop (SFT.txt)
=> To post it, host it here => https://www.cjoint.com/
Important! If SFTGC prompts you to restart, please do so immediately. If not prompted, restart the machine manually anyway to ensure a complete cleanup.
Then this ends nicely, good night
--
Don't forget to mark your topic as resolved, thank you.
=>Download http://www.archive-host.com SFTGC.exe Save the file to your desktop.
=> SFTGC is compatible with XP, Vista, Windows 7, and 8 in 32 and 64 bits.
On XP:
=> Double-click on the file.
=> On other versions of Windows:
=> Right-click on the file and choose Run as administrator.
=> To start the cleanup, click on Go.
=> After the cleanup, a report will open.
=> The report is on the desktop (SFT.txt)
=> To post it, host it here => https://www.cjoint.com/
Important! If SFTGC prompts you to restart, please do so immediately. If not prompted, restart the machine manually anyway to ensure a complete cleanup.
Then this ends nicely, good night
--
Don't forget to mark your topic as resolved, thank you.
Good evening,
Hello,
If you have adware, follow these steps in order
1) Download http://general-changelog-team.fr/fr/downloads/viewdownload/20-outils-de-xplode/2-adwcleaner AdwCleaner (by Xplode) to your desktop
Double-click on the icon on your desktop to launch it (Vista/7/8 --> Right-click and "Run as administrator"
Click on the "Scan" button
When the scan is finished, it will say "Waiting. Please uncheck items...." above the progress bar
Click on the Clean button
Accept the message to close applications
Confirm, after reading, the information window about PUP/LPI
Accept the restart message
Wait during the removal
The PC will restart and a report will automatically open in Notepad after restarting Copy/paste its content into your next reply
------------------------------------------------------------------>>>
We will use a tool in addition to AdwCleaner
-> 2) Download Junkware Removal Tool at this address (do not click on download, the download will start automatically): https://www.bleepingcomputer.com/download/junkware-removal-tool/dl/131/
-> Save it to your desktop.
-> Close all running applications.
-> Open JRT.exe and press Enter: if you are using Windows Vista, 7, or 8, open it by doing: right-click => Run as administrator.
-> Wait while the tool works: the desktop will disappear for a few moments, this is completely normal.
-> At the end of the scan, a report named JRT.txt will open. Host it like this http://www.forum-entraide-informatique.com/support/cjoint-com-tutoriel-t2939.html and post the link obtained in your next reply.
Tutorial: ==> JRT HERE
--
Don't forget to mark your topic as resolved, thank you.
Hello,
If you have adware, follow these steps in order
1) Download http://general-changelog-team.fr/fr/downloads/viewdownload/20-outils-de-xplode/2-adwcleaner AdwCleaner (by Xplode) to your desktop
Double-click on the icon on your desktop to launch it (Vista/7/8 --> Right-click and "Run as administrator"
Click on the "Scan" button
When the scan is finished, it will say "Waiting. Please uncheck items...." above the progress bar
Click on the Clean button
Accept the message to close applications
Confirm, after reading, the information window about PUP/LPI
Accept the restart message
Wait during the removal
The PC will restart and a report will automatically open in Notepad after restarting Copy/paste its content into your next reply
------------------------------------------------------------------>>>
We will use a tool in addition to AdwCleaner
-> 2) Download Junkware Removal Tool at this address (do not click on download, the download will start automatically): https://www.bleepingcomputer.com/download/junkware-removal-tool/dl/131/
-> Save it to your desktop.
-> Close all running applications.
-> Open JRT.exe and press Enter: if you are using Windows Vista, 7, or 8, open it by doing: right-click => Run as administrator.
-> Wait while the tool works: the desktop will disappear for a few moments, this is completely normal.
-> At the end of the scan, a report named JRT.txt will open. Host it like this http://www.forum-entraide-informatique.com/support/cjoint-com-tutoriel-t2939.html and post the link obtained in your next reply.
Tutorial: ==> JRT HERE
--
Don't forget to mark your topic as resolved, thank you.
Here's the translation:
# AdwCleaner v3.007 - Report created on 10/10/2013 at 18:56:50
# Updated on 09/10/2013 by Xplode
# Operating System: Windows 7 Home Premium Service Pack 1 (64-bit)
# Username: william - WILLIAM-PC
# Executed from: C:\Users\william\Downloads\adwcleaner.exe
# Option: Clean
***** [ Services ] *****
Service Removed: vToolbarUpdater15.2.0
***** [ Files / Folders ] *****
Folder Removed: C:\Program Files (x86)\AVG Secure Search
Folder Removed: C:\Program Files (x86)\Common Files\AVG Secure Search
Folder Removed: C:\Users\william\AppData\Local\Temp\boost_interprocess
File Removed: C:\Windows\System32\Tasks\Scheduled Update for Ask Toolbar
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Removed: HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Key Removed: HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Key Removed: HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS
Key Removed: HKLM\SOFTWARE\Microsoft\Tracing\HPSF_Tasks_RASAPI32
Key Removed: HKLM\SOFTWARE\Microsoft\Tracing\HPSF_Tasks_RASMANCS
Key Removed: HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32
Key Removed: HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS
Key Removed: HKLM\SOFTWARE\Classes\CLSID\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}
Key Removed: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}
Key Removed: HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}
Key Removed: [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}
Key Removed: [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}
Key Removed: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
***** [ Browsers ] *****
-\\ Internet Explorer v10.0.9200.16720
-\\ Google Chrome v30.0.1599.69
[ File: C:\Users\william\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Removed: homepage
Removed: urls_to_restore_on_startup
*************************
AdwCleaner[R0].txt - [2310 bytes] - [10/10/2013 18:54:02]
AdwCleaner[S0].txt - [2251 bytes] - [10/10/2013 18:56:50]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2311 bytes] ##########
# AdwCleaner v3.007 - Report created on 10/10/2013 at 18:56:50
# Updated on 09/10/2013 by Xplode
# Operating System: Windows 7 Home Premium Service Pack 1 (64-bit)
# Username: william - WILLIAM-PC
# Executed from: C:\Users\william\Downloads\adwcleaner.exe
# Option: Clean
***** [ Services ] *****
Service Removed: vToolbarUpdater15.2.0
***** [ Files / Folders ] *****
Folder Removed: C:\Program Files (x86)\AVG Secure Search
Folder Removed: C:\Program Files (x86)\Common Files\AVG Secure Search
Folder Removed: C:\Users\william\AppData\Local\Temp\boost_interprocess
File Removed: C:\Windows\System32\Tasks\Scheduled Update for Ask Toolbar
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Removed: HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Key Removed: HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Key Removed: HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS
Key Removed: HKLM\SOFTWARE\Microsoft\Tracing\HPSF_Tasks_RASAPI32
Key Removed: HKLM\SOFTWARE\Microsoft\Tracing\HPSF_Tasks_RASMANCS
Key Removed: HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32
Key Removed: HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS
Key Removed: HKLM\SOFTWARE\Classes\CLSID\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}
Key Removed: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}
Key Removed: HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}
Key Removed: [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}
Key Removed: [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}
Key Removed: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
***** [ Browsers ] *****
-\\ Internet Explorer v10.0.9200.16720
-\\ Google Chrome v30.0.1599.69
[ File: C:\Users\william\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Removed: homepage
Removed: urls_to_restore_on_startup
*************************
AdwCleaner[R0].txt - [2310 bytes] - [10/10/2013 18:54:02]
AdwCleaner[S0].txt - [2251 bytes] - [10/10/2013 18:56:50]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2311 bytes] ##########
ok got it ;)
ZHPDiag scan:
We are going to use this diagnostic tool now to see all the issues and make sure nothing is left:
Download ZHPDiag (by Nicolas Coolman) to your desktop
=> Under Vista/Win7 and Win8, start the installation by right-clicking and "Run as administrator"
==> Above all, don’t forget to install its icon on the desktop, the icon is in the shape of a scroll
The tool has created 2 icons ZHPDiag, ZHPFix
=> Let yourself be guided during the installation, it will launch automatically at the end.
=> If the program does not launch automatically, click on this icon on your desktop for Vista/7: right-click and "run as administrator"
=> The program window will open
=> Click on the big button "Configure"
=> Then click at the bottom left on the magnifying glass that has neither a "+" nor a "-"
A dialog box will open "do you want a full options report?" : click on "yes"
Once the analysis is complete, a report will open in Notepad. Close it
You need to host this report which is on the desktop, as it is too long
to be posted on the forum To host the report: please post it here >> https://www.cjoint.com/
To help you http://www.pc-infopratique.com/forum-informatique/tutoriel-heberger-rapport-vt-67934.html
tutorial => zhpdiag
--
Don't forget to mark your topic as resolved, thank you.
ZHPDiag scan:
We are going to use this diagnostic tool now to see all the issues and make sure nothing is left:
Download ZHPDiag (by Nicolas Coolman) to your desktop
=> Under Vista/Win7 and Win8, start the installation by right-clicking and "Run as administrator"
==> Above all, don’t forget to install its icon on the desktop, the icon is in the shape of a scroll
The tool has created 2 icons ZHPDiag, ZHPFix
=> Let yourself be guided during the installation, it will launch automatically at the end.
=> If the program does not launch automatically, click on this icon on your desktop for Vista/7: right-click and "run as administrator"
=> The program window will open
=> Click on the big button "Configure"
=> Then click at the bottom left on the magnifying glass that has neither a "+" nor a "-"
A dialog box will open "do you want a full options report?" : click on "yes"
Once the analysis is complete, a report will open in Notepad. Close it
You need to host this report which is on the desktop, as it is too long
to be posted on the forum To host the report: please post it here >> https://www.cjoint.com/
To help you http://www.pc-infopratique.com/forum-informatique/tutoriel-heberger-rapport-vt-67934.html
tutorial => zhpdiag
--
Don't forget to mark your topic as resolved, thank you.