Unable to uninstall 360 Total Security
Entilore
Posted messages
18
Status
Member
-
Malekal_morte- Posted messages 178136 Registration date Status Moderator, Security Contributor Last intervention -
Malekal_morte- Posted messages 178136 Registration date Status Moderator, Security Contributor Last intervention -
Hello,
My sister installed Adblock yesterday based on my advice. The problem is she downloaded the wrong version and installed Adblock Pro via Softonic. I can't uninstall it; it doesn't show up in the Windows uninstaller tool.
I'm facing the same issue with a software installed by Softonic: 360 Total Security, which pretends to be an antivirus.
I tried to delete the 360 directory, but it doesn't work.
Last question: I want to back up her data. Is there a risk when copying her files to my computer? I use Ubuntu; is there a way to check for viruses on the USB stick?
I want to clarify that I have already run AdwCleaner once, and a thorough Avast scan is in progress.
Thanks in advance.
My sister installed Adblock yesterday based on my advice. The problem is she downloaded the wrong version and installed Adblock Pro via Softonic. I can't uninstall it; it doesn't show up in the Windows uninstaller tool.
I'm facing the same issue with a software installed by Softonic: 360 Total Security, which pretends to be an antivirus.
I tried to delete the 360 directory, but it doesn't work.
Last question: I want to back up her data. Is there a risk when copying her files to my computer? I use Ubuntu; is there a way to check for viruses on the USB stick?
I want to clarify that I have already run AdwCleaner once, and a thorough Avast scan is in progress.
Thanks in advance.
22 answers
- 1
- 2
Next
-
Hello,
You should not install software from Softonic, as it installs undesirable programs as well. -
Hello
post this Adwcleaner report; thanks
--
***-----------------------Security Contributor-------------------------***
We have all been beginners at something at one time.
But knowledge is the reward for diligence. -
Hi,
there's a remover: https://support.norton.com/sp/fr/fr/home/current/solutions/v60392881
--
Like the angel you are, you laugh creating a lightness in my chest,
Your eyes they penetrate me,
(Your answer's always 'maybe')
That's when I got up and left -
Thank you for your responses,
I didn't think to save the adwcleaner report. Is it saved in a particular location?
The remover didn't work. That's not surprising, the software is not provided by Norton.-
-
# AdwCleaner v3.310 - Report created on 09/27/2014 at 10:59:20
# Updated on 09/12/2014 by Xplode
# Operating System: Windows 8.1 (64 bits)
# Username: Camille - CAMILLEHAREAU
# Executed from: C:\Users\Camille\Downloads\adwcleaner_3.310.exe
# Option: Clean
***** [ Services ] *****
Service Removed: GlobalUpdater
***** [ Files / Folders ] *****
Folder Removed: C:\Program Files (x86)\globalUpdate
Folder Removed: C:\Program Files (x86)\Iminent
Folder Removed: C:\Program Files (x86)\LPT
Folder Removed: C:\Program Files (x86)\SmartSaver+ 15
Folder Removed: C:\Program Files (x86)\Common Files\IMGUpdater
Folder Removed: C:\Program Files (x86)\Common Files\Umbrella
Folder Removed: C:\Users\Camille\AppData\Local\globalUpdate
Folder Removed: C:\Users\Camille\AppData\Local\LPT
Folder Removed: C:\Users\Camille\AppData\Local\Smartbar
Folder Removed: C:\Users\Camille\AppData\Local\Temp\Iminent
Folder Removed: C:\Users\Camille\AppData\Local\Temp\Smartbar
Folder Removed: C:\Users\Camille\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
File Removed: C:\Users\Camille\AppData\Roaming\Mozilla\Firefox\Profiles\v45d3n9e.default\Extensions\firefoxmini@go.im.xpi
File Removed: C:\Program Files (x86)\Mozilla Firefox\defaults\pref\all-iminent.js
File Removed: C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\StartWeb.xml
File Removed: C:\Users\Camille\AppData\Roaming\Mozilla\Firefox\Profiles\v45d3n9e.default\searchplugins\Web Search.xml
File Removed: C:\Users\Camille\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_igdhbblpcellaljokkpfhcjlagemhgjl_0.localstorage
***** [ Scheduled Tasks ] *****
Task Removed: f650ec21-48d4-410c-a368-755a4bfa9358-1
Task Removed: f650ec21-48d4-410c-a368-755a4bfa9358-11
Task Removed: f650ec21-48d4-410c-a368-755a4bfa9358-2
Task Removed: f650ec21-48d4-410c-a368-755a4bfa9358-3
Task Removed: f650ec21-48d4-410c-a368-755a4bfa9358-4
Task Removed: f650ec21-48d4-410c-a368-755a4bfa9358-5
Task Removed: f650ec21-48d4-410c-a368-755a4bfa9358-5_user
Task Removed: f650ec21-48d4-410c-a368-755a4bfa9358-6
Task Removed: f650ec21-48d4-410c-a368-755a4bfa9358-7
***** [ Shortcuts ] *****
Shortcut Cleaned: C:\Users\Camille\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
***** [ Registry ] *****
Key Removed: HKLM\SOFTWARE\Google\Chrome\Extensions\ehhlaekjfiiojlddgndcnefflngfmhen
Key Removed: HKLM\SOFTWARE\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Key Removed: HKLM\SOFTWARE\Google\Chrome\Extensions\nbljechdpodpbchbmjcoamidppmpnmlc
Key Removed: HKLM\SOFTWARE\Classes\AppID\Iminent.WebBooster.InternetExplorer.DLL
Key Removed: HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
Key Removed: HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Key Removed: HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Key Removed: HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
Key Removed: HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Key Removed: HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Key Removed: HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Key Removed: HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Key Removed: HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Key Removed: HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Key Removed: HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Key Removed: HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Key Removed: HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Key Removed: HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Key Removed: HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Key Removed: HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Key Removed: HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Key Removed: HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Key Removed: HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Key Removed: HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Key Removed: HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Key Removed: HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Key Removed: HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Key Removed: HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Key Removed: HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Key Removed: HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Key Removed: HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Key Removed: HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Key Removed: HKLM\SOFTWARE\Classes\iesmartbar.bandobjectattribute
Key Removed: HKLM\SOFTWARE\Classes\iesmartbar.bho
Key Removed: HKLM\SOFTWARE\Classes\iesmartbar.dockingpanel
Key Removed: HKLM\SOFTWARE\Classes\iesmartbar.iesmartbar
Key Removed: HKLM\SOFTWARE\Classes\iesmartbar.iesmartbarbandobject
Key Removed: HKLM\SOFTWARE\Classes\iesmartbar.smartbardisplaystate
Key Removed: HKLM\SOFTWARE\Classes\iesmartbar.smartbarmenuform
Key Removed: HKLM\SOFTWARE\Classes\Iminent
Key Removed: HKLM\SOFTWARE\Classes\IminentWebBooster.BrowserHelperObject
Key Removed: HKLM\SOFTWARE\Classes\IminentWebBooster.BrowserHelperObject.1
Key Removed: HKLM\SOFTWARE\Classes\IminentWebBooster.ScriptExtender
Key Removed: HKLM\SOFTWARE\Classes\IminentWebBooster.ScriptExtender.1
Key Removed: HKLM\SOFTWARE\Microsoft\Tracing\smartbar_rasapi32
Key Removed: HKLM\SOFTWARE\Microsoft\Tracing\smartbar_rasmancs
Key Removed: HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Key Removed: HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Key Removed: HKLM\SOFTWARE\Classes\AppID\{01994268-3C10-4044-A1EA-7A9C1B739A11}
Key Removed: HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Removed: HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Removed: HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Key Removed: HKLM\SOFTWARE\Classes\CLSID\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Key Removed: HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Removed: HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Removed: HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Removed: HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}
Key Removed: HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Removed: HKLM\SOFTWARE\Classes\CLSID\{5C176BA0-6FC0-4EBD-8ACF-24AC592506B6}
Key Removed: HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Removed: HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Key Removed: HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Key Removed: HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Removed: HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Key Removed: HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Key Removed: HKLM\SOFTWARE\Classes\CLSID\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}
Key Removed: HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}
Key Removed: HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Key Removed: HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Removed: HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}
Key Removed: HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}
Key Removed: HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
Key Removed: HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}
Key Removed: HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Key Removed: HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
Key Removed: HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Key Removed: HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Key Removed: HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622172296}
Key Removed: HKLM\SOFTWARE\Classes\Interface\{C58D664A-3DBC-4925-AE74-0382007DF113}
Key Removed: HKLM\SOFTWARE\Classes\Interface\{C776D7F4-BA85-4B75-AAFC-3A0A11FE6E36}
Key Removed: HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655175596}
Key Removed: HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666176696}
Key Removed: HKLM\SOFTWARE\Classes\TypeLib\{A9CAF365-EA35-45DA-BD8B-2EFA09D374AC}
Key Removed: HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440644174496}
Key Removed: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Key Removed: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{84FF7BD6-B47F-46F8-9130-01B2696B36CB}
Key Removed: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}
Key Removed: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Removed: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Removed: HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Removed: HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Removed: HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199}
Key Removed: HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Removed: HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08}
Key Removed: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{460C3D19-B3D4-4964-A550-77D263B0CCCB}
Key Removed: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9CB96984-43C3-4D44-90EF-01466EFCF7BB}
Key Removed: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{A33DB9FD-7A8A-496E-92D3-9CFCF9D9E1C9}
Key Removed: HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Key Removed: HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9CB96984-43C3-4D44-90EF-01466EFCF7BB}
Key Removed: HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BFFED5CA-8BDF-47CC-AED0-23F4E6D77732}
Value Removed: HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Value Removed: HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{84FF7BD6-B47F-46F8-9130-01B2696B36CB}]
Key Removed: [x64] HKLM\SOFTWARE\Classes\CLSID\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Key Removed: [x64] HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}
Key Removed: [x64] HKLM\SOFTWARE\Classes\CLSID\{5C176BA0-6FC0-4EBD-8ACF-24AC592506B6}
Key Removed: [x64] HKLM\SOFTWARE\Classes\CLSID\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}
Key Removed: [x64] HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}
Key Removed: [x64] HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}
Key Removed: [x64] HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}
Key Removed: [x64] HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}
Key Removed: [x64] HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622172296}
Key Removed: [x64] HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Removed: [x64] HKLM\SOFTWARE\Classes\Interface\{C58D664A-3DBC-4925-AE74-0382007DF113}
Key Removed: [x64] HKLM\SOFTWARE\Classes\Interface\{C776D7F4-BA85-4B75-AAFC-3A0A11FE6E36}
Key Removed: [x64] HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655175596}
Key Removed: [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666176696}
Key Removed: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Key Removed: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}
Value Removed: [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Key Removed: HKCU\Software\GlobalUpdate
Key Removed: HKCU\Software\InstalledBrowserExtensions
Key Removed: HKCU\Software\SmartBar
Key Removed: HKCU\Software\smartbarbackup
Key Removed: HKCU\Software\smartbarlog
Key Removed: HKCU\Software\Softonic
Key Removed: HKCU\Software\AppDataLow\Software\Crossrider
Key Removed: HKCU\Software\AppDataLow\Software\SmartSaver+ 15
Key Removed: HKLM\SOFTWARE\GlobalUpdate
Key Removed: HKLM\SOFTWARE\IMGUPDATER
Key Removed: HKLM\SOFTWARE\Iminent
Key Removed: HKLM\SOFTWARE\InstalledBrowserExtensions
Key Removed: HKLM\SOFTWARE\Umbrella
Key Removed: HKLM\SOFTWARE\SmartSaver+ 15
Key Removed: [x64] HKLM\SOFTWARE\Iminent
Key Removed: [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
Key Removed: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
Key Removed: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\5E8031606EB60A64C882918F8FF38DD4
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17278
Restored Setting: HKCU\Software\Microsoft\Internet Explorer\Search [Default_Search_URL]
Restored Setting: HKCU\Software\Microsoft\Internet Explorer\Search [SearchAssistant]
-\\ Mozilla Firefox v32.0.3 (x86 fr)
[ File: C:\Users\Camille\AppData\Roaming\Mozilla\Firefox\Profiles\v45d3n9e.default\prefs.js ]
Line Removed: user_pref("extensions.atylerkeith11aolcom61796.61796.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssfiles.com%22%5D%7D%2C%22dealply_p%22%3A%7B%22urls%22%[...]
Line Removed: user_pref("extensions.crossrider.bic", "148abe4012ec0a1408528c47c28c907c");
Line Removed: user_pref("iminent.BirthDate", "1411682263");
Line Removed: user_pref("iminent.enableToolbar", "true");
Line Removed: user_pref("iminent.enabledAds", "false");
Line Removed: user_pref("iminent.newtabredirect", "true");
Line Removed: user_pref("iminent.nomsi", "true");
Line Removed: user_pref("iminent.searchindex", "1");
-\\ Google Chrome v37.0.2062.124
[ File: C:\Users\Camille\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [16790 bytes] - [09/27/2014 10:53:42]
AdwCleaner[S0].txt - [15363 bytes] - [09/27/2014 10:59:20]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [15424 bytes] ##########
-
-
Re
Download Malwarebytes Anti-Malware here
https://www.commentcamarche.net/telecharger/securite/14361-malwarebytes-anti-malware/
--->> Install it (make sure to choose French); do not modify the installation settings
--->> Uncheck the box Activate the free trial of Malwarebytes Anti-Malware Premium at the end of the installation
--->> /!\ Windows Vista/7/8/8.1 users: right-click on the Malwarebytes Anti-Malware shortcut and choose Run as administrator
--->> Click on Update in the Dashboard to update the database.
--->> In the Scan tab, select Scan Threats then click on Scan Now.
--->> Once the scan is complete, click on Quarantine All then on Apply Actions
--->> (If a message asks to restart the PC to complete the removal, agree)
--->> The report is available in History > Application Logs > Scan Log. (Make sure to choose the most recent one)
Select the file and request the display
In the bottom left, there is a export button; click on it and choose text file and then choose where to save it so you can post it in your next response
Thank you
@+
--
***-----------------------Security Contributor-------------------------***
We have all been beginners at something at one point.
But knowledge is the reward of diligence. -
-
-
it wasn't enough, 360 total security still launches.
It still found some files, here is the report.
Malwarebytes Anti-Malware
www.malwarebytes.org
Date of scan: 09/27/2014
Time of scan: 15:57:56
Log file:
Administrator: Yes
Version: 2.00.2.1012
Malware database: v2014.09.27.05
Rootkit database: v2014.09.19.01
License: Free
Malware protection: Disabled
Web malware protection: Disabled
Self-protection: Disabled
Operating system: Windows 8.1
Processor: x64
File system: NTFS
User: Camille
Scan type: "Threat" scan
Result: Completed
Objects scanned: 365700
Elapsed time: 23 min, 3 sec
Memory: Enabled
Startup: Enabled
File system: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry keys: 6
PUP.Optional.Snapdo.T, HKU\S-1-5-21-2190123621-3127979045-682105981-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006ee092-9658-4fd6-bd8e-a21a348e59f5}, Quarantined, [376a1fd32952f442e3af4884c83a2ed2],
PUP.Optional.SmartSaver.A, HKLM\SOFTWARE\WOW6432NODE\SmartSaver+ 15-nv, Quarantined, [9110539f68133afc9625192116ed3ec2],
PUP.Optional.SmartSaver.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\SmartSaver+ 15, Quarantined, [dbc6d61ce9920630eccc8daddd261fe1],
PUP.Optional.Iminent.A, HKU\S-1-5-21-2190123621-3127979045-682105981-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOWREGISTRY\Iminent, Quarantined, [e9b8e30f89f2de588bdf03298e758c74],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, Quarantined, [0b96559d86f543f33a5f52a47f838977],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, Quarantined, [0b96559d86f543f33a5f52a47f838977],
Registry values: 0
(No malicious items detected)
Registry data: 6
PUP.Optional.HelperBar.A, HKU\S-1-5-21-2190123621-3127979045-682105981-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, https://search.safefinder.com/?st=ds&q={searchTerms}, Good: (www.google.com), Bad: (https://search.safefinder.com/?st=ds&q={searchTerms}),Replaced,[703146acdf9c42f45a4a798c3fc6b54b]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-2190123621-3127979045-682105981-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, https://www.google.com/#u_ip=91.209.35.218 Good: (www.google.com), Bad: (https://www.google.com/#u_ip=91.209.35.218[772ab1413843db5b3d6820e59f6601ff]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-2190123621-3127979045-682105981-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, https://search.safefinder.com/?st=ds&q={searchTerms}, Good: (www.google.com), Bad: (https://search.safefinder.com/?st=ds&q={searchTerms}),Replaced,[3f62a44efc7fb4821e858283917455ab]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-2190123621-3127979045-682105981-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, https://search.safefinder.com/?st=ds&q={searchTerms}, Good: (www.google.com), Bad: (https://search.safefinder.com/?st=ds&q={searchTerms}),Replaced,[aaf779791665171ff9ad8d7811f4bd43]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-2190123621-3127979045-682105981-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, https://search.safefinder.com/?st=ds&q={searchTerms}, Good: (www.google.com), Bad: (https://search.safefinder.com/?st=ds&q={searchTerms}),Replaced,[326f5c9655263ff7c2e5778e3fc637c9]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-2190123621-3127979045-682105981-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, https://search.safefinder.com/?st=ds&q={searchTerms}, Good: (www.google.com), Bad: (https://search.safefinder.com/?st=ds&q={searchTerms}),Replaced,[d8c9559d681347ef6939e520877e21df]
Folders: 1
PUP.Optional.GlobalUpdate.A, C:\Users\Camille\AppData\Local\Temp\comh.268388, Quarantined, [0b96559d86f543f33a5f52a47f838977],
Files: 21
PUP.Optional.SmartSaver.A, C:\Users\Camille\AppData\Roaming\UCE.exe, Quarantined, [dec3e40e6b1044f281deb7b624dd2fd1],
PUP.Optional.Softonic, C:\Users\Camille\Desktop\SoftonicDownloader_for_adblock.exe, Quarantined, [930e30c22259f541f7ffab0da35ea25e],
PUP.Optional.Somoto, C:\Users\Camille\AppData\Local\Temp\nsp1495.tmp, Quarantined, [831e1dd51e5d91a5d94daffdcf328e72],
PUP.Optional.Somoto, C:\Users\Camille\AppData\Local\Temp\bitool.dll, Quarantined, [dec30be72a515bdb6aed88d8e61c3bc5],
PUP.Optional.NSXgen, C:\Users\Camille\AppData\Local\Temp\s4s15.exe, Quarantined, [7c2508ea3e3d6fc7fe4c368350b12cd4],
PUP.Optional.OpenCandy, C:\Users\Camille\Downloads\DTLite4491-0356.exe, Quarantined, [653cf9f96c0f181e23d8b57f8f768f71],
PUP.Optional.SnapDo.A, C:\Windows\Installer\a146afd.msi, Quarantined, [821f965c5229f046244f54418978f709],
PUP.Optional.SmartBar, C:\Windows\Installer\MSI5E38.tmp-\Smartbar.Installer.CustomActions.dll, Quarantined, [d8c97082c4b7ee48cf821b13ae52c739],
PUP.Optional.Iminent.A, C:\Users\Camille\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ehhlaekjfiiojlddgndcnefflngfmhen_0.localstorage, Quarantined, [3071d121f5867eb84448cc4441c208f8],
PUP.Optional.Iminent.A, C:\Users\Camille\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_nbljechdpodpbchbmjcoamidppmpnmlc_0.localstorage, Quarantined, [a3fe0be798e33105eba242ced82b27d9],
PUP.Optional.Iminent.A, C:\Users\Camille\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_jdkokpcldhneihjdhigfjmoeojkdcbmg_0.localstorage, Quarantined, [2c7508eacbb0092d35e54bce778c0df3],
PUP.Optional.GlobalUpdate.A, C:\Users\Camille\AppData\Local\Temp\comh.268388\GoogleCrashHandler.exe, Quarantined, [0b96559d86f543f33a5f52a47f838977],
PUP.Optional.GlobalUpdate.A, C:\Users\Camille\AppData\Local\Temp\comh.268388\GoogleUpdate.exe, Quarantined, [0b96559d86f543f33a5f52a47f838977],
PUP.Optional.GlobalUpdate.A, C:\Users\Camille\AppData\Local\Temp\comh.268388\GoogleUpdateBroker.exe, Quarantined, [0b96559d86f543f33a5f52a47f838977],
PUP.Optional.GlobalUpdate.A, C:\Users\Camille\AppData\Local\Temp\comh.268388\GoogleUpdateHelper.msi, Quarantined, [0b96559d86f543f33a5f52a47f838977],
PUP.Optional.GlobalUpdate.A, C:\Users\Camille\AppData\Local\Temp\comh.268388\GoogleUpdateOnDemand.exe, Quarantined, [0b96559d86f543f33a5f52a47f838977],
PUP.Optional.GlobalUpdate.A, C:\Users\Camille\AppData\Local\Temp\comh.268388\goopdate.dll, Quarantined, [0b96559d86f543f33a5f52a47f838977],
PUP.Optional.GlobalUpdate.A, C:\Users\Camille\AppData\Local\Temp\comh.268388\goopdateres_en.dll, Quarantined, [0b96559d86f543f33a5f52a47f838977],
PUP.Optional.GlobalUpdate.A, C:\Users\Camille\AppData\Local\Temp\comh.268388\npGoogleUpdate4.dll, Quarantined, [0b96559d86f543f33a5f52a47f838977],
PUP.Optional.GlobalUpdate.A, C:\Users\Camille\AppData\Local\Temp\comh.268388\psmachine.dll, Quarantined, [0b96559d86f543f33a5f52a47f838977],
PUP.Optional.GlobalUpdate.A, C:\Users\Camille\AppData\Local\Temp\comh.268388\psuser.dll, Quarantined, [0b96559d86f543f33a5f52a47f838977],
Physical sectors: 0
(No malicious items detected)
(end)
-
-
Re
Have you noticed any improvement?
--
***-----------------------Security Contributor-------------------------***
We have all been beginners at something at some point.
But knowledge is the reward for diligence. -
-
Re
For more information, please do this
Open this link and download ZHPDiag from Nicolas Coolman:
https://nicolascoolman.eu
Or
https://www.commentcamarche.net/telecharger/utilitaires/24803-zhpdiag/
Once the download is complete,
Double-click the icon to launch the program. Under Vista; Seven or Windows 8 right-click "run as administrator"
In the ZHPDiag window that just opened, click on "Configure"
Click on the magnifying glass at the bottom left with the plus sign to start the scan.
Let the tool work, it may take a while.
A report will open. This report is also located on your desktop
To send the report, click on this link:
http://pjjoint.malekal.com/
If there is a problem, use one of the following
https://forums-fec.be/upload
https://www.cjoint.com/
Check your desktop
Select the ZHPDiag.txt file.
Click on "Click here to upload the file".
A link of this form:
http://www.cijoint.com/cjlink.php?file=cj200905/cijSKAP5fU.txt
will be added to the page.
Copy this link into your response.
Thank you
@+
--
***-----------------------Security Contributor-------------------------***
We have all been beginners at something at some point.
But knowledge is the reward for diligence. -
I can't run it; 360 Total Security automatically deletes it (apparently ZHP diag is a Trojan ... Haha).
-
Re
[*] Download to the desktop RogueKiller (by tigzy) (choose between the 32 and 64-bit version depending on your Windows, if you don't know, just ask me!)
[*] Close all programs
[*] Launch RogueKiller.exe.
[*] Wait for the Prescan to finish ...
[*] Click on Scan. Click on Report and copy-paste the content of the report
@+
--
***-----------------------Security Contributor-------------------------***
We've all been beginners at something at some point.
But knowledge is the reward for diligence. -
Here's the report:
RogueKiller V9.2.13.0 (x64) [Sep 25 2014] by Adlice Software
Email: https://www.adlice.com/contact/
Reports: https://forum.adlice.com/
Website: https://www.surlatoile.org/RogueKiller/
Blog: https://www.adlice.com/
Operating System: Windows 8.1 (6.3.9200) 64-bit version
Startup: Normal mode
User: Camille [Admin rights]
Mode: Removal -- Date: 09/27/2014 17:36:21
¤¤¤ Malicious Processes: 0 ¤¤¤
¤¤¤ Registry Entries: 13 ¤¤¤
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> NOT SELECTED
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> NOT SELECTED
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> NOT SELECTED
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> NOT SELECTED
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows | AppInit_DLLs : C:\Users\Camille\AppData\Local\Smartbar\Application\Resources\crdlil64.dll [x] -> REPLACED ()
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-2190123621-3127979045-682105981-1001\Software\Microsoft\Internet Explorer\Main | Start Page : www.google.com -> NOT SELECTED
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-2190123621-3127979045-682105981-1001\Software\Microsoft\Internet Explorer\Main | Start Page : www.google.com -> NOT SELECTED
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-2190123621-3127979045-682105981-1002\Software\Microsoft\Internet Explorer\Main | Start Page : https://fr.yahoo.com?fr=hp-avast&type=avastbcl -> NOT SELECTED
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-2190123621-3127979045-682105981-1002\Software\Microsoft\Internet Explorer\Main | Start Page : https://fr.yahoo.com?fr=hp-avast&type=avastbcl -> NOT SELECTED
[PUM.SearchPage] (X64) HKEY_USERS\S-1-5-21-2190123621-3127979045-682105981-1001\Software\Microsoft\Internet Explorer\Main | Search Page : www.google.com -> NOT SELECTED
[PUM.SearchPage] (X86) HKEY_USERS\S-1-5-21-2190123621-3127979045-682105981-1001\Software\Microsoft\Internet Explorer\Main | Search Page : www.google.com -> NOT SELECTED
[PUM.SearchPage] (X64) HKEY_USERS\S-1-5-21-2190123621-3127979045-682105981-1002\Software\Microsoft\Internet Explorer\Main | Search Page : https://fr.search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms} -> NOT SELECTED
[PUM.SearchPage] (X86) HKEY_USERS\S-1-5-21-2190123621-3127979045-682105981-1002\Software\Microsoft\Internet Explorer\Main | Search Page : https://fr.search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms} -> NOT SELECTED
¤¤¤ Scheduled Tasks: 4 ¤¤¤
[Suspicious.Path] IAVUSUXT.job -- C:\Users\Camille\AppData\Roaming\IAVUSUXT.exe (/infocmdline=JxbBtRUVIp3nbm9zeKblL0j2tiy4m6nb5eFzhrqXfpJ0la9e4fUsOvn55G2U/Yvz5M+RCDG1qTPzLSmW5QXcP2SApQMomw8fkPYRKKwVx9k1vnJvdQNA2B3PWa9/EfSLXeu5ucRUUsd0pS4XlQE1VYNzPGXoTAT26qQUk95aBR+q7oXOm8K6ThZ2uBA8evg4uMG6/pldh4GIvbrwFhEkMdzSjuY/tmF3kyY4nuaKxP5Ov/ghfwWqI+NVrnJ05Ip8Ssn8Pup757waKc9zoh85ok/f17CJ7t6UD61VUjvXrKNEZ9fxa4wmKk6KW7tKpowFElDRlNlmObLszkJ/QAKWWq81HiXscOWx6FdCkw3aixMHZtAJ3k3Y3bJ26ThoNCAW1rhIUMp6K5VmSHJ8ovmaV+CITagyN8JGJoxwVdUbDYpZnTSC9RjwAqKw+E4vC9Td7vFRCqX7D2VlcSoY/TX03GrY2Jm8zrCVEPduTpJDQCgWqz1alIEhjtaGBvuaUcBisZkLutK+wRg09MBTdV6esMVJAnVrHQ18v7KwLAnjHLQ6qygpZwcc4FRKmt288xLM80NNLghoNjL7A5LleUPNwEK91s0rHvKmd83SdnKb64/+DklNpVBvfiP1S7ufH9ZR3T06y0c1dfgiSyZsKto8dEXbr5D/fQu+D2xz3adWKyg=) -> DELETED
[Suspicious.Path] UCE.job -- C:\Users\Camille\AppData\Roaming\UCE.exe (/infocmdline=hDSI3/bcH73NU4W+lcr2rbiya9qRceU2rJq28CvUq1h1W1OfjMhcGoe3LOg6UBOv74hFIMHs2nsF/gt30sPNhWJLPRHKv+w/4QD6FFsKqeRdQQ/Gz8kHvL0g7hIwl1M7vgpKsBidchw/qc5KemmVCOQQNMPotJgvC0mmkB7gia0rk1M+IHGNNVf58Ulm+aEKtmS0t+peaw6v9qfklHWR2MMkFy1QToiD32HI/L2thjtpa61wUebR3E+atQTYnEiqkc/7WbdnRCW1zCBffGRiKEeGXNA99eiYCZNwJ2/+P7NhTavLIVV8/SwZeqQHmegckI0MLMKAOJRGEUC772A/7qdiGwBkcKE4KhDoDPewilDCT9f+dCrPchlomMvI4uEVskwHt0HzLQBpO/p+WCbaW0r50cL6R1poYscjzSWwdlXTE5yHtTNYt+pZW0D6m7ZXSQi+p/u4a3A7NcLGYISUtA8AkxctHTq9gJkHA4rFcjAj/iwC2l5vUU35w9X1zf8s) -> DELETED
[Suspicious.Path] \\IAVUSUXT -- C:\Users\Camille\AppData\Roaming\IAVUSUXT.exe (/infocmdline=JxbBtRUVIp3nbm9zeKblL0j2tiy4m6nb5eFzhrqXfpJ0la9e4fUsOvn55G2U/Yvz5M+RCDG1qTPzLSmW5QXcP2SApQMomw8fkPYRKKwVx9k1vnJvdQNA2B3PWa9/EfSLXeu5ucRUUsd0pS4XlQE1VYNzPGXoTAT26qQUk95aBR+q7oXOm8K6ThZ2uBA8evg4uMG6/pldh4GIvbrwFhEkMdzSjuY/tmF3kyY4nuaKxP5Ov/ghfwWqI+NVrnJ05Ip8Ssn8Pup757waKc9zoh85ok/f17CJ7t6UD61VUjvXrKNEZ9fxa4wmKk6KW7tKpowFElDRlNlmObLszkJ/QAKWWq81HiXscOWx6FdCkw3aixMHZtAJ3k3Y3bJ26ThoNCAW1rhIUMp6K5VmSHJ8ovmaV+CITagyN8JGJoxwVdUbDYpZnTSC9RjwAqKw+E4vC9Td7vFRCqX7D2VlcSoY/TX03GrY2Jm8zrCVEPduTpJDQCgWqz1alIEhjtaGBvuaUcBisZkLutK+wRg09MBTdV6esMVJAnVrHQ18v7KwLAnjHLQ6qygpZwcc4FRKmt288xLM80NNLghoNjL7A5LleUPNwEK91s0rHvKmd83SdnKb64/+DklNpVBvfiP1S7ufH9ZR3T06y0c1dfgiSyZsKto8dEXbr5D/fQu+D2xz3adWKyg=) -> DELETED
[Suspicious.Path] \\UCE -- C:\Users\Camille\AppData\Roaming\UCE.exe (/infocmdline=hDSI3/bcH73NU4W+lcr2rbiya9qRceU2rJq28CvUq1h1W1OfjMhcGoe3LOg6UBOv74hFIMHs2nsF/gt30sPNhWJLPRHKv+w/4QD6FFsKqeRdQQ/Gz8kHvL0g7hIwl1M7vgpKsBidchw/qc5KemmVCOQQNMPotJgvC0mmkB7gia0rk1M+IHGNNVf58Ulm+aEKtmS0t+peaw6v9qfklHWR2MMkFy1QToiD32HI/L2thjtpa61wUebR3E+atQTYnEiqkc/7WbdnRCW1zCBffGRiKEeGXNA99eiYCZNwJ2/+P7NhTavLIVV8/SwZeqQHmegckI0MLMKAOJRGEUC772A/7qdiGwBkcKE4KhDoDPewilDCT9f+dCrPchlomMvI4uEVskwHt0HzLQBpO/p+WCbaW0r50cL6R1poYscjzSWwdlXTE5yHtTNYt+pZW0D6m7ZXSQi+p/u4a3A7NcLGYISUtA8AkxctHTq9gJkHA4rFcjAj/iwC2l5vUU35w9X1zf8s) -> ERROR [0]
¤¤¤ Files: 0 ¤¤¤
¤¤¤ HOSTS File: 0 ¤¤¤
¤¤¤ Antirootkit: 0 (Driver: CHARGE) ¤¤¤
¤¤¤ Web Browsers: 0 ¤¤¤
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: ST1000LM024 HN-M101MBB +++++
--- User ---
[MBR] 27e1843659451c18b582d4bcf7e5786c
[BSP] 9cb9bd99896f179553067dcea5b1f913 : Unknown MBR Code
Partition table:
0 - [XXXXXX] UNKNOWN (0x0) [VISIBLE] Offset (sectors): 1 | Size: 2097152 MB
User = LL1 ... OK
User = LL2 ... OK
============================================
RKreport_SCN_09272014_173609.log -
Re
try to post me a ZHPDiag report now; thank you
@+
--
***-----------------------Security Contributor-------------------------***
We have all been beginners at something at some point.
But knowledge is the reward for diligence. -
I'm not sure at all about that, I have none of the options you mentioned: no configure, no magnifier, just repair.
~ ZHPCleaner v2014.9.26.147 by Nicolas Coolman (26/09/2014)
~ Run by Camille (Administrator) (27/09/2014 17:51:14)
~ WebSite : https://nicolascoolman.eu
~ Forum : https://nicolascoolman.eu
~ State version : Updated version
~ Report : C:\Users\Camille\Desktop\ZHPCleaner.txt
~ Quarantine : C:\Users\Camille\AppData\Roaming\ZHP\ZHPCleaner_Quarantine.txt
~ Windows 81, 64-bit (Build 9600)
---\\ Restoration of default proxy settings.
REPLACED PARAMETERS: EnableHttp1_1 ( 1 )
---\\ Repair of Microsoft Internet Explorer browser.
REPLACED PARAMETERS: Start Page ( https://fr.yahoo.com?fr=hp-avast&type=avastbcl )
REPLACED PARAMETERS: Search Page ( https://fr.search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms} )
REPLACED PARAMETERS: Search Page ( https://fr.search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms} )
---\\ Deletion of harmful Browser Helper Objects from browsers (BHO).
DELETED: [X64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611171196}\\f3b99230f329013156aa33422def983b0061796 (PUP.CrossRider)
DELETED: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611171196}\\f3b99230f329013156aa33422def983b0061796 (PUP.CrossRider)
---\\ Repair of the host file.
~ The host file is legitimate. (21)
---\\ Deletion of harmful extensions from Google Chrome (Manifest).
DELETED EXT: eofcbnmajmjmplflapaojjnihcjkigck [Orphean]
---\\ Deletion of Adwares, PUPs, Spywares.
MOVED: C:\WINDOWS\Prefetch\IMINENTMINIBARIE.EXE-5F5CED2A.pf (PUP.Minibar)
MOVED: C:\WINDOWS\Prefetch\MINIBARFIREFOX.EXE-AD2AFDA7.pf (PUP.Minibar)
MOVED: C:\WINDOWS\Prefetch\SOFTONICDOWNLOADER_POUR_ADBLO-4BA27204.pf (PUP.Softonic)
MOVED: C:\WINDOWS\Prefetch\UMBRELLA236.EXE-6A77BC7A.pf (Adware.IMBooster)
---\\ Repair summary
~ Repair successfully completed
~ This browser is absent (Opera Software)
~ Repair canceled by the user (Internet Explorer)
End of clean at 17:51:58
===================
ZHPCleaner-27092014-17_51_58.txt -
Re
You posted a ZHPcleaner and not a ZHPDiag.
Please read the procedure carefully before posting
Thank you
--
***-----------------------Security Contributor-------------------------***
We have all been beginners at something at one point.
But knowledge is the reward of diligence. -
-
Re
Use of the ZHPFix tool:
* Copy all the text present in the box below (select it with your mouse / Right-click on it and choose "copy" or press Ctrl+C)
ZHPFix Script
O4 - HKLM\..\Wow6432Node\Run: [QHSafeTray] . (.Qihu Software Co. Limited - 360 Total Security.) -- C:\Program Files (x86)\360\Total Security\safemon\360Tray.exe
O23 - Service: 360 Total Security (QHActiveDefense) . (.No owner - 360 Total Security.) - C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe
[MD5.07605ABEB10FC533881C91F19DECF69A] [APT] [AutoKMS] (...) -- C:\WINDOWS\AutoKMS\AutoKMS.exe [1923584]
O39 - APT: AutoKMS - (...) -- C:\Windows\Tasks\AutoKMS.job [302]
O39 - APT: AutoKMS - (...) -- C:\Windows\System32\Tasks\AutoKMS [302]
O42 - Software: Yahoo Community Smartbar Engine - (.Linkury Inc..) [HKCU][64Bits] -- {072e8fb1-c93b-499a-9ace-efee4d773f97}
[HKCU\Software\360]
O43 - CFD: 25/09/2014 - 23:57:58 - [] ----D C:\Program Files (x86)\360
O43 - CFD: 26/09/2014 - 00:02:43 - [] ----D C:\ProgramData\360safe
O45 - LFCP:[MD5.94F2FF3D17FFF3DE4434C353E48CE03A] - 25/09/2014 - 22:57:18 ---A- - C:\Windows\Prefetch\IMINENTSOFTONICREADY.EXE-516DAE4C.pf
O61 - LFC: 25/09/2014 - 18:04:17 ---A- . (...) -- C:\Users\Camille\AppData\Local\Microsoft\Windows\INetCache\IE\2QKE9YZB\MinibarFirefox[1].exe [1144648]
O61 - LFC: 25/09/2014 - 18:04:17 ---A- . (.Sien SA.) -- C:\Users\Camille\AppData\Local\Microsoft\Windows\INetCache\IE\F0ZTZ020\MinibarChrome[1].exe [755840]
O61 - LFC: 25/09/2014 - 18:04:18 ---A- . (...) -- C:\Users\Camille\AppData\Local\Microsoft\Windows\INetCache\IE\OMZTKQ7N\IminentMinibarIE[1].exe [1062760]
O90 - PUC: "F274703B9DB704042955ECD6A611693A" . (.Software Updater.) -- C:\WINDOWS\Installer\{B307472F-7BD9-4040-9255-CE6D6A1196A3}\icon.ico
[MD5.103F619246C8BEFBA0EFA12CD1092648] [WIS][27/08/2014] (.LPT - LPT System Updater Service.) -- C:\Windows\Installer\a146b02.msi [2154496]
SR - | Auto 10/09/2014 707184 | (QHActiveDefense) . (...) - C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe
[HKLM\Software\Wow6432Node\360Safe]
C:\WINDOWS\AutoKMS\AutoKMS.exe
C:\Windows\Tasks\AutoKMS.job
C:\Windows\System32\Tasks\AutoKMS
C:\Windows\Installer\a146b02.msi
C:\Users\Camille\AppData\Local\Temp\IminentSoftonicReady.exe
O39 - APT: - (..) -- C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2190123621-3127979045-682105981-1002Core [942]
O39 - APT: - (..) -- C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2190123621-3127979045-682105981-1002UA [964]
O41 - Driver: (360Box64) . (.360.cn - 360Box64.) - C:\Windows\System32\DRIVERS\360Box64.sys
O41 - Driver: (360Camera) . (.360.cn - 360???? ???????.) - C:\Windows\System32\Drivers\360Camera64.sys
O41 - Driver: (360FsFlt) . (.Qihu 360 Software Co., Ltd. - 360 Internet Security Proactive Defense.) - C:\Windows\System32\DRIVERS\360FsFlt.sys
[HKLM\Software\Wow6432Node\360TotalSecurity]
[HKLM\Software\Wow6432Node\360softmgr]
O44 - LFC:[MD5.A583F4DAAA4DB87BF92FD033966ABC4B] - 25/09/2014 - 22:58:23 ---A- . (.360.cn - 360Box64.) -- C:\Windows\System32\Drivers\360Box64.sys [305736]
O44 - LFC:[MD5.D31541708A595BCA380105D44C2C2AD5] - 25/09/2014 - 22:58:24 ---A- . (.360.cn - 360???? ???????.) -- C:\Windows\System32\Drivers\360Camera64.sys [40520]
O44 - LFC:[MD5.15FE196A71357AC9FF6E5A4B360BDB20] - 25/09/2014 - 22:58:24 ---A- . (.360.cn - 360???? ??????.) -- C:\Windows\System32\Drivers\360AntiHacker64.sys [100424]
O44 - LFC:[MD5.3AA0D07082BF4B4EFF8BAE9F4EDF783B] - 25/09/2014 - 22:58:27 ---A- . (.Qihu 360 Software Co., Ltd. - 360 Internet Security Proactive Defense.) -- C:\Windows\System32\Drivers\360fsflt.sys [311888]
O58 - SDL:10/09/2014 - 11:53:14 ---A- . (.360.cn - 360???? ??????.) -- C:\Windows\System32\Drivers\360AntiHacker64.sys [100424]
O58 - SDL:10/09/2014 - 11:53:14 ---A- . (.360.cn - 360Box64.) -- C:\Windows\System32\Drivers\360Box64.sys [305736]
O58 - SDL:10/09/2014 - 11:53:14 ---A- . (.360.cn - 360???? ???????.) -- C:\Windows\System32\Drivers\360Camera64.sys [40520]
O58 - SDL:10/09/2014 - 11:53:14 ---A- . (.Qihu 360 Software Co., Ltd. - 360 Internet Security Proactive Defense.) -- C:\Windows\System32\Drivers\360fsflt.sys [311888]
O61 - LFC: 25/09/2014 - 18:04:31 ---A- . (...) -- C:\Users\Camille\Desktop\abp.exe [448783]
O61 - LFC: 27/09/2014 - 18:04:31 ---A- . (...) -- C:\Users\Camille\Desktop\Norton_Removal_Tool.exe [870728]
[MD5.C0B59FF7EE933362B2D5D1941094C879] [SPRF][25/09/2014] (...) -- C:\Users\Camille\Desktop\abp.exe [448783]
[MD5.9631FA36F4784888F0918394778B8B07] [SPRF][27/09/2014] (...) -- C:\Users\Camille\Desktop\Norton_Removal_Tool.exe [870728]
ShortcutFix
EmptyPrefetch
FirewallRAZ
Emptytemp
EmptyCLSID
--------------------------------------------------------------------------------------------
Run ZHPFix from the shortcut on your Desktop (if you are using Windows Vista, 7, or 8, do it by right-clicking --> Run as administrator)
Click on the Import button. The content of the clipboard will be pasted into the input area of ZHPFix
NB (W8) : In some cases, the script is automatically pasted into the script area and does not require clicking the "IMPORT" button.
* Click the GO button to start the cleanup.
-> let the tool work and do not touch anything ...
-> If you are asked to restart the PC to complete the cleaning, do it!
Once completed, a new report will be displayed: post the content of this report in your next response ...
This report is copied to the desktop
( this report is also saved in this folder:
- For XP: C:\Documents and Settings\username\Local Settings\Application Data\ZHP
- Since Vista: C:\Users\username\AppData\Roaming\ZHP\ZHPFix [R1].txt)
@+
--
***-----------------------Security Contributor-------------------------***
We have all been a beginner at something.
But knowledge is the reward of diligence. -
Here is the result:
ZHPFix Report 2014.9.16.7 by Nicolas Coolman, Update of 09/16/2014
Registry export file:
Run by Camille at 09/27/2014 06:29:20 PM
High Elevated Privileges: OK
Windows 8 Home Premium Edition, 64-bit Service Pack 1 (9600)
Trash emptied (00mn 09s)
Prefetcher folder emptied
Browser shortcut repair
========== Memory Processes ==========
DELETED: Memory Process: C:\WINDOWS\AutoKMS\AutoKMS.exe
DELETED: Memory Process: C:\Users\Camille\AppData\Local\Temp\IminentSoftonicReady.exe
========== Registry Keys ==========
DELETED:³ Service: QHActiveDefense
DELETED: HKCU\Software\360
DELETED: [HKLM\Software\Classes\Installer\Products\\F274703B9DB704042955ECD6A611693A]
DELETED: [HKLM\Software\Classes\Installer\Features\F274703B9DB704042955ECD6A611693A]
DELETED:³ HKLM\Software\Wow6432Node\360Safe
DELETED:³ HKLM\Software\Wow6432Node\360TotalSecurity
DELETED: HKLM\Software\Wow6432Node\360softmgr
========== Registry Values ==========
ERROR RunValue: QHSafeTray
No Standard Profile Value: FirewallRaz :
No Domain Profile Value: FirewallRaz :
DELETED: FirewallRaz (Domain) : {9E3D57FC-7C37-4424-9352-4831E97D029D}
DELETED: FirewallRaz (Domain) : {548DCF8C-BFF2-4BA4-AA88-FBAF9AC8BCC6}
DELETED: FirewallRaz (Domain) : NetPres-In-TCP-NoScope
DELETED: FirewallRaz (Domain) : NetPres-Out-TCP-NoScope
DELETED: FirewallRaz (None) : NetPres-WSD-In-UDP
DELETED: FirewallRaz (None) : NetPres-WSD-Out-UDP
DELETED: FirewallRaz (Public) : NetPres-In-TCP
DELETED: FirewallRaz (Public) : NetPres-Out-TCP
DELETED: FirewallRaz (None) : MCX-Prov-Out-TCP
DELETED: FirewallRaz (None) : MCX-McrMgr-Out-TCP
DELETED: FirewallRaz (Private) : {A67D968A-3E32-450B-88C6-2916D3C0CBED}
DELETED: FirewallRaz (Private) : {6FB17EE1-9F79-4F63-933B-22B90C6C4123}
DELETED: FirewallRaz (Public) : {9CBDB688-1560-4EC3-B3C4-13B86FD1A88A}
DELETED: FirewallRaz (Public) : {99AB5382-1059-45AC-AAEB-E32736E99DF9}
DELETED: FirewallRaz (Domain) : {E7985E1D-C36F-4787-80A8-6350D07E9266}
DELETED: FirewallRaz (None) : {808F1451-4108-46FD-ADBB-F17324B5F0BD}
DELETED: FirewallRaz (Private) : {9AEFA097-386D-4148-94C1-1B123FA68813}
DELETED: FirewallRaz (Private) : {3D4C61C0-E773-4672-AE52-48130E65BA61}
========== Folders ==========
No empty Local user CLSID folders
========== Files ==========
DELETED Restart: c:\program files (x86)\360\total security\safemon\360tray.exe
DELETED: c:\windows\prefetch\iminentsoftonicready.exe-516dae4c.pf
DELETED: c:\users\camille\appdata\local\microsoft\windows\inetcache\ie\2qke9yzb\minibarfirefox[1].exe
DELETED: c:\users\camille\appdata\local\microsoft\windows\inetcache\ie\f0ztz020\minibarchrome[1].exe
DELETED: c:\users\camille\appdata\local\microsoft\windows\inetcache\ie\omztkq7n\iminentminibarie[1].exe
DELETED: C:\Windows\Installer\a146b02.msi
DELETED Restart: c:\windows\system32\tasks\facebookupdatetaskusers-1-5-21-2190123621-3127979045-682105981-1002core
DELETED Restart: c:\windows\system32\tasks\facebookupdatetaskusers-1-5-21-2190123621-3127979045-682105981-1002ua
DELETED Restart: c:\windows\system32\drivers\360box64.sys
DELETED Restart: c:\windows\system32\drivers\360camera64.sys
DELETED Restart: c:\windows\system32\drivers\360antihacker64.sys
DELETED Restart: c:\windows\system32\drivers\360fsflt.sys
DELETED: c:\users\camille\desktop\abp.exe
DELETED: c:\users\camille\desktop\norton_removal_tool.exe
DELETED Temporary Windows (874) (307 528 646 bytes)
========== Scheduled Task ==========
DELETED: AutoKMS
DELETED: AutoKMS
========== Summary ==========
2: Memory Processes
7: Registry Keys
21: Registry Values
1: Folders
15: Files
2: Scheduled Tasks
End of clean in 02mn 04s
========== File Path Report ==========
C:\Users\Camille\AppData\Roaming\ZHP\ZHPFix[R1].txt - 09/27/2014 06:29:30 PM [3879] -
Re
Do you still have any problems?
See you soon
--
***-----------------------Security Contributor-------------------------***
We have all been beginners at something at one point.
But knowledge is the reward of diligence. -
No, 360 still exists.
I think I'm going to do a system recovery. We'll see what happens.
- 1
- 2
Next