Unable to uninstall 360 Total Security

Entilore Posted messages 18 Status Member -  
Malekal_morte- Posted messages 178136 Registration date   Status Moderator, Security Contributor Last intervention   -
Hello,

My sister installed Adblock yesterday based on my advice. The problem is she downloaded the wrong version and installed Adblock Pro via Softonic. I can't uninstall it; it doesn't show up in the Windows uninstaller tool.
I'm facing the same issue with a software installed by Softonic: 360 Total Security, which pretends to be an antivirus.
I tried to delete the 360 directory, but it doesn't work.
Last question: I want to back up her data. Is there a risk when copying her files to my computer? I use Ubuntu; is there a way to check for viruses on the USB stick?
I want to clarify that I have already run AdwCleaner once, and a thorough Avast scan is in progress.
Thanks in advance.

22 answers

  • 1
  • 2
  1. softsonic
     
    Hello,

    You should not install software from Softonic, as it installs undesirable programs as well.
    0
  2. Anonymous user
     
    Hello

    post this Adwcleaner report; thanks

    --
    ***-----------------------Security Contributor-------------------------***
    We have all been beginners at something at one time.
    But knowledge is the reward for diligence.
    0
  3. Entilore Posted messages 18 Status Member
     
    Thank you for your responses,

    I didn't think to save the adwcleaner report. Is it saved in a particular location?
    The remover didn't work. That's not surprising, the software is not provided by Norton.
    0
    1. Anonymous user
       
      The report is saved under C:\AdwCleaner[S1].txt
      0
    2. Entilore Posted messages 18 Status Member
       
      # AdwCleaner v3.310 - Report created on 09/27/2014 at 10:59:20
      # Updated on 09/12/2014 by Xplode
      # Operating System: Windows 8.1 (64 bits)
      # Username: Camille - CAMILLEHAREAU
      # Executed from: C:\Users\Camille\Downloads\adwcleaner_3.310.exe
      # Option: Clean

      ***** [ Services ] *****

      Service Removed: GlobalUpdater

      ***** [ Files / Folders ] *****

      Folder Removed: C:\Program Files (x86)\globalUpdate
      Folder Removed: C:\Program Files (x86)\Iminent
      Folder Removed: C:\Program Files (x86)\LPT
      Folder Removed: C:\Program Files (x86)\SmartSaver+ 15
      Folder Removed: C:\Program Files (x86)\Common Files\IMGUpdater
      Folder Removed: C:\Program Files (x86)\Common Files\Umbrella
      Folder Removed: C:\Users\Camille\AppData\Local\globalUpdate
      Folder Removed: C:\Users\Camille\AppData\Local\LPT
      Folder Removed: C:\Users\Camille\AppData\Local\Smartbar
      Folder Removed: C:\Users\Camille\AppData\Local\Temp\Iminent
      Folder Removed: C:\Users\Camille\AppData\Local\Temp\Smartbar
      Folder Removed: C:\Users\Camille\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
      File Removed: C:\Users\Camille\AppData\Roaming\Mozilla\Firefox\Profiles\v45d3n9e.default\Extensions\firefoxmini@go.im.xpi
      File Removed: C:\Program Files (x86)\Mozilla Firefox\defaults\pref\all-iminent.js
      File Removed: C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\StartWeb.xml
      File Removed: C:\Users\Camille\AppData\Roaming\Mozilla\Firefox\Profiles\v45d3n9e.default\searchplugins\Web Search.xml
      File Removed: C:\Users\Camille\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_igdhbblpcellaljokkpfhcjlagemhgjl_0.localstorage

      ***** [ Scheduled Tasks ] *****

      Task Removed: f650ec21-48d4-410c-a368-755a4bfa9358-1
      Task Removed: f650ec21-48d4-410c-a368-755a4bfa9358-11
      Task Removed: f650ec21-48d4-410c-a368-755a4bfa9358-2
      Task Removed: f650ec21-48d4-410c-a368-755a4bfa9358-3
      Task Removed: f650ec21-48d4-410c-a368-755a4bfa9358-4
      Task Removed: f650ec21-48d4-410c-a368-755a4bfa9358-5
      Task Removed: f650ec21-48d4-410c-a368-755a4bfa9358-5_user
      Task Removed: f650ec21-48d4-410c-a368-755a4bfa9358-6
      Task Removed: f650ec21-48d4-410c-a368-755a4bfa9358-7

      ***** [ Shortcuts ] *****

      Shortcut Cleaned: C:\Users\Camille\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk

      ***** [ Registry ] *****

      Key Removed: HKLM\SOFTWARE\Google\Chrome\Extensions\ehhlaekjfiiojlddgndcnefflngfmhen
      Key Removed: HKLM\SOFTWARE\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
      Key Removed: HKLM\SOFTWARE\Google\Chrome\Extensions\nbljechdpodpbchbmjcoamidppmpnmlc
      Key Removed: HKLM\SOFTWARE\Classes\AppID\Iminent.WebBooster.InternetExplorer.DLL
      Key Removed: HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
      Key Removed: HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
      Key Removed: HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
      Key Removed: HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
      Key Removed: HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
      Key Removed: HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
      Key Removed: HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
      Key Removed: HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
      Key Removed: HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
      Key Removed: HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
      Key Removed: HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
      Key Removed: HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
      Key Removed: HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
      Key Removed: HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
      Key Removed: HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
      Key Removed: HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
      Key Removed: HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
      Key Removed: HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
      Key Removed: HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
      Key Removed: HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
      Key Removed: HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
      Key Removed: HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
      Key Removed: HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
      Key Removed: HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
      Key Removed: HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
      Key Removed: HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
      Key Removed: HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
      Key Removed: HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
      Key Removed: HKLM\SOFTWARE\Classes\iesmartbar.bandobjectattribute
      Key Removed: HKLM\SOFTWARE\Classes\iesmartbar.bho
      Key Removed: HKLM\SOFTWARE\Classes\iesmartbar.dockingpanel
      Key Removed: HKLM\SOFTWARE\Classes\iesmartbar.iesmartbar
      Key Removed: HKLM\SOFTWARE\Classes\iesmartbar.iesmartbarbandobject
      Key Removed: HKLM\SOFTWARE\Classes\iesmartbar.smartbardisplaystate
      Key Removed: HKLM\SOFTWARE\Classes\iesmartbar.smartbarmenuform
      Key Removed: HKLM\SOFTWARE\Classes\Iminent
      Key Removed: HKLM\SOFTWARE\Classes\IminentWebBooster.BrowserHelperObject
      Key Removed: HKLM\SOFTWARE\Classes\IminentWebBooster.BrowserHelperObject.1
      Key Removed: HKLM\SOFTWARE\Classes\IminentWebBooster.ScriptExtender
      Key Removed: HKLM\SOFTWARE\Classes\IminentWebBooster.ScriptExtender.1
      Key Removed: HKLM\SOFTWARE\Microsoft\Tracing\smartbar_rasapi32
      Key Removed: HKLM\SOFTWARE\Microsoft\Tracing\smartbar_rasmancs
      Key Removed: HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
      Key Removed: HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
      Key Removed: HKLM\SOFTWARE\Classes\AppID\{01994268-3C10-4044-A1EA-7A9C1B739A11}
      Key Removed: HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
      Key Removed: HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
      Key Removed: HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
      Key Removed: HKLM\SOFTWARE\Classes\CLSID\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
      Key Removed: HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
      Key Removed: HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
      Key Removed: HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
      Key Removed: HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}
      Key Removed: HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
      Key Removed: HKLM\SOFTWARE\Classes\CLSID\{5C176BA0-6FC0-4EBD-8ACF-24AC592506B6}
      Key Removed: HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
      Key Removed: HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
      Key Removed: HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
      Key Removed: HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
      Key Removed: HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
      Key Removed: HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
      Key Removed: HKLM\SOFTWARE\Classes\CLSID\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}
      Key Removed: HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}
      Key Removed: HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
      Key Removed: HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
      Key Removed: HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}
      Key Removed: HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}
      Key Removed: HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
      Key Removed: HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}
      Key Removed: HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
      Key Removed: HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
      Key Removed: HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
      Key Removed: HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
      Key Removed: HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622172296}
      Key Removed: HKLM\SOFTWARE\Classes\Interface\{C58D664A-3DBC-4925-AE74-0382007DF113}
      Key Removed: HKLM\SOFTWARE\Classes\Interface\{C776D7F4-BA85-4B75-AAFC-3A0A11FE6E36}
      Key Removed: HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655175596}
      Key Removed: HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666176696}
      Key Removed: HKLM\SOFTWARE\Classes\TypeLib\{A9CAF365-EA35-45DA-BD8B-2EFA09D374AC}
      Key Removed: HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440644174496}
      Key Removed: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
      Key Removed: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{84FF7BD6-B47F-46F8-9130-01B2696B36CB}
      Key Removed: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}
      Key Removed: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
      Key Removed: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
      Key Removed: HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
      Key Removed: HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
      Key Removed: HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199}
      Key Removed: HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
      Key Removed: HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08}
      Key Removed: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{460C3D19-B3D4-4964-A550-77D263B0CCCB}
      Key Removed: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9CB96984-43C3-4D44-90EF-01466EFCF7BB}
      Key Removed: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{A33DB9FD-7A8A-496E-92D3-9CFCF9D9E1C9}
      Key Removed: HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
      Key Removed: HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9CB96984-43C3-4D44-90EF-01466EFCF7BB}
      Key Removed: HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BFFED5CA-8BDF-47CC-AED0-23F4E6D77732}
      Value Removed: HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
      Value Removed: HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{84FF7BD6-B47F-46F8-9130-01B2696B36CB}]
      Key Removed: [x64] HKLM\SOFTWARE\Classes\CLSID\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
      Key Removed: [x64] HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}
      Key Removed: [x64] HKLM\SOFTWARE\Classes\CLSID\{5C176BA0-6FC0-4EBD-8ACF-24AC592506B6}
      Key Removed: [x64] HKLM\SOFTWARE\Classes\CLSID\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}
      Key Removed: [x64] HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}
      Key Removed: [x64] HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}
      Key Removed: [x64] HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}
      Key Removed: [x64] HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}
      Key Removed: [x64] HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622172296}
      Key Removed: [x64] HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
      Key Removed: [x64] HKLM\SOFTWARE\Classes\Interface\{C58D664A-3DBC-4925-AE74-0382007DF113}
      Key Removed: [x64] HKLM\SOFTWARE\Classes\Interface\{C776D7F4-BA85-4B75-AAFC-3A0A11FE6E36}
      Key Removed: [x64] HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655175596}
      Key Removed: [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666176696}
      Key Removed: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
      Key Removed: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}
      Value Removed: [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
      Key Removed: HKCU\Software\GlobalUpdate
      Key Removed: HKCU\Software\InstalledBrowserExtensions
      Key Removed: HKCU\Software\SmartBar
      Key Removed: HKCU\Software\smartbarbackup
      Key Removed: HKCU\Software\smartbarlog
      Key Removed: HKCU\Software\Softonic
      Key Removed: HKCU\Software\AppDataLow\Software\Crossrider
      Key Removed: HKCU\Software\AppDataLow\Software\SmartSaver+ 15
      Key Removed: HKLM\SOFTWARE\GlobalUpdate
      Key Removed: HKLM\SOFTWARE\IMGUPDATER
      Key Removed: HKLM\SOFTWARE\Iminent
      Key Removed: HKLM\SOFTWARE\InstalledBrowserExtensions
      Key Removed: HKLM\SOFTWARE\Umbrella
      Key Removed: HKLM\SOFTWARE\SmartSaver+ 15
      Key Removed: [x64] HKLM\SOFTWARE\Iminent
      Key Removed: [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
      Key Removed: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
      Key Removed: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\5E8031606EB60A64C882918F8FF38DD4

      ***** [ Browsers ] *****

      -\\ Internet Explorer v11.0.9600.17278

      Restored Setting: HKCU\Software\Microsoft\Internet Explorer\Search [Default_Search_URL]
      Restored Setting: HKCU\Software\Microsoft\Internet Explorer\Search [SearchAssistant]

      -\\ Mozilla Firefox v32.0.3 (x86 fr)

      [ File: C:\Users\Camille\AppData\Roaming\Mozilla\Firefox\Profiles\v45d3n9e.default\prefs.js ]

      Line Removed: user_pref("extensions.atylerkeith11aolcom61796.61796.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssfiles.com%22%5D%7D%2C%22dealply_p%22%3A%7B%22urls%22%[...]
      Line Removed: user_pref("extensions.crossrider.bic", "148abe4012ec0a1408528c47c28c907c");
      Line Removed: user_pref("iminent.BirthDate", "1411682263");
      Line Removed: user_pref("iminent.enableToolbar", "true");
      Line Removed: user_pref("iminent.enabledAds", "false");
      Line Removed: user_pref("iminent.newtabredirect", "true");
      Line Removed: user_pref("iminent.nomsi", "true");
      Line Removed: user_pref("iminent.searchindex", "1");

      -\\ Google Chrome v37.0.2062.124

      [ File: C:\Users\Camille\AppData\Local\Google\Chrome\User Data\Default\preferences ]


      *************************

      AdwCleaner[R0].txt - [16790 bytes] - [09/27/2014 10:53:42]
      AdwCleaner[S0].txt - [15363 bytes] - [09/27/2014 10:59:20]

      ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [15424 bytes] ##########
      0
  4. Anonymous user
     
    Re

    Download Malwarebytes Anti-Malware here
    https://www.commentcamarche.net/telecharger/securite/14361-malwarebytes-anti-malware/

    --->> Install it (make sure to choose French); do not modify the installation settings
    --->> Uncheck the box Activate the free trial of Malwarebytes Anti-Malware Premium at the end of the installation
    --->> /!\ Windows Vista/7/8/8.1 users: right-click on the Malwarebytes Anti-Malware shortcut and choose Run as administrator
    --->> Click on Update in the Dashboard to update the database.
    --->> In the Scan tab, select Scan Threats then click on Scan Now.
    --->> Once the scan is complete, click on Quarantine All then on Apply Actions

    --->> (If a message asks to restart the PC to complete the removal, agree)

    --->> The report is available in History > Application Logs > Scan Log. (Make sure to choose the most recent one)
    Select the file and request the display
    In the bottom left, there is a export button; click on it and choose text file and then choose where to save it so you can post it in your next response

    Thank you

    @+

    --
    ***-----------------------Security Contributor-------------------------***
    We have all been beginners at something at one point.
    But knowledge is the reward of diligence.
    0
  5. Entilore Posted messages 18 Status Member
     
    Is he not going to confront Avast?
    0
    1. Anonymous user
       
      non
      0
    2. Entilore Posted messages 18 Status Member
       
      it wasn't enough, 360 total security still launches.
      It still found some files, here is the report.


      Malwarebytes Anti-Malware
      www.malwarebytes.org

      Date of scan: 09/27/2014
      Time of scan: 15:57:56
      Log file:
      Administrator: Yes

      Version: 2.00.2.1012
      Malware database: v2014.09.27.05
      Rootkit database: v2014.09.19.01
      License: Free
      Malware protection: Disabled
      Web malware protection: Disabled
      Self-protection: Disabled

      Operating system: Windows 8.1
      Processor: x64
      File system: NTFS
      User: Camille

      Scan type: "Threat" scan
      Result: Completed
      Objects scanned: 365700
      Elapsed time: 23 min, 3 sec

      Memory: Enabled
      Startup: Enabled
      File system: Enabled
      Archives: Enabled
      Rootkits: Disabled
      Heuristics: Enabled
      PUP: Enabled
      PUM: Enabled

      Processes: 0
      (No malicious items detected)

      Modules: 0
      (No malicious items detected)

      Registry keys: 6
      PUP.Optional.Snapdo.T, HKU\S-1-5-21-2190123621-3127979045-682105981-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006ee092-9658-4fd6-bd8e-a21a348e59f5}, Quarantined, [376a1fd32952f442e3af4884c83a2ed2],
      PUP.Optional.SmartSaver.A, HKLM\SOFTWARE\WOW6432NODE\SmartSaver+ 15-nv, Quarantined, [9110539f68133afc9625192116ed3ec2],
      PUP.Optional.SmartSaver.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\SmartSaver+ 15, Quarantined, [dbc6d61ce9920630eccc8daddd261fe1],
      PUP.Optional.Iminent.A, HKU\S-1-5-21-2190123621-3127979045-682105981-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOWREGISTRY\Iminent, Quarantined, [e9b8e30f89f2de588bdf03298e758c74],
      PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, Quarantined, [0b96559d86f543f33a5f52a47f838977],
      PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, Quarantined, [0b96559d86f543f33a5f52a47f838977],

      Registry values: 0
      (No malicious items detected)

      Registry data: 6
      PUP.Optional.HelperBar.A, HKU\S-1-5-21-2190123621-3127979045-682105981-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, https://search.safefinder.com/?st=ds&q={searchTerms}, Good: (www.google.com), Bad: (https://search.safefinder.com/?st=ds&q={searchTerms}),Replaced,[703146acdf9c42f45a4a798c3fc6b54b]
      PUP.Optional.HelperBar.A, HKU\S-1-5-21-2190123621-3127979045-682105981-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, https://www.google.com/#u_ip=91.209.35.218 Good: (www.google.com), Bad: (https://www.google.com/#u_ip=91.209.35.218[772ab1413843db5b3d6820e59f6601ff]
      PUP.Optional.HelperBar.A, HKU\S-1-5-21-2190123621-3127979045-682105981-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, https://search.safefinder.com/?st=ds&q={searchTerms}, Good: (www.google.com), Bad: (https://search.safefinder.com/?st=ds&q={searchTerms}),Replaced,[3f62a44efc7fb4821e858283917455ab]
      PUP.Optional.HelperBar.A, HKU\S-1-5-21-2190123621-3127979045-682105981-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, https://search.safefinder.com/?st=ds&q={searchTerms}, Good: (www.google.com), Bad: (https://search.safefinder.com/?st=ds&q={searchTerms}),Replaced,[aaf779791665171ff9ad8d7811f4bd43]
      PUP.Optional.HelperBar.A, HKU\S-1-5-21-2190123621-3127979045-682105981-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, https://search.safefinder.com/?st=ds&q={searchTerms}, Good: (www.google.com), Bad: (https://search.safefinder.com/?st=ds&q={searchTerms}),Replaced,[326f5c9655263ff7c2e5778e3fc637c9]
      PUP.Optional.HelperBar.A, HKU\S-1-5-21-2190123621-3127979045-682105981-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, https://search.safefinder.com/?st=ds&q={searchTerms}, Good: (www.google.com), Bad: (https://search.safefinder.com/?st=ds&q={searchTerms}),Replaced,[d8c9559d681347ef6939e520877e21df]

      Folders: 1
      PUP.Optional.GlobalUpdate.A, C:\Users\Camille\AppData\Local\Temp\comh.268388, Quarantined, [0b96559d86f543f33a5f52a47f838977],

      Files: 21
      PUP.Optional.SmartSaver.A, C:\Users\Camille\AppData\Roaming\UCE.exe, Quarantined, [dec3e40e6b1044f281deb7b624dd2fd1],
      PUP.Optional.Softonic, C:\Users\Camille\Desktop\SoftonicDownloader_for_adblock.exe, Quarantined, [930e30c22259f541f7ffab0da35ea25e],
      PUP.Optional.Somoto, C:\Users\Camille\AppData\Local\Temp\nsp1495.tmp, Quarantined, [831e1dd51e5d91a5d94daffdcf328e72],
      PUP.Optional.Somoto, C:\Users\Camille\AppData\Local\Temp\bitool.dll, Quarantined, [dec30be72a515bdb6aed88d8e61c3bc5],
      PUP.Optional.NSXgen, C:\Users\Camille\AppData\Local\Temp\s4s15.exe, Quarantined, [7c2508ea3e3d6fc7fe4c368350b12cd4],
      PUP.Optional.OpenCandy, C:\Users\Camille\Downloads\DTLite4491-0356.exe, Quarantined, [653cf9f96c0f181e23d8b57f8f768f71],
      PUP.Optional.SnapDo.A, C:\Windows\Installer\a146afd.msi, Quarantined, [821f965c5229f046244f54418978f709],
      PUP.Optional.SmartBar, C:\Windows\Installer\MSI5E38.tmp-\Smartbar.Installer.CustomActions.dll, Quarantined, [d8c97082c4b7ee48cf821b13ae52c739],
      PUP.Optional.Iminent.A, C:\Users\Camille\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ehhlaekjfiiojlddgndcnefflngfmhen_0.localstorage, Quarantined, [3071d121f5867eb84448cc4441c208f8],
      PUP.Optional.Iminent.A, C:\Users\Camille\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_nbljechdpodpbchbmjcoamidppmpnmlc_0.localstorage, Quarantined, [a3fe0be798e33105eba242ced82b27d9],
      PUP.Optional.Iminent.A, C:\Users\Camille\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_jdkokpcldhneihjdhigfjmoeojkdcbmg_0.localstorage, Quarantined, [2c7508eacbb0092d35e54bce778c0df3],
      PUP.Optional.GlobalUpdate.A, C:\Users\Camille\AppData\Local\Temp\comh.268388\GoogleCrashHandler.exe, Quarantined, [0b96559d86f543f33a5f52a47f838977],
      PUP.Optional.GlobalUpdate.A, C:\Users\Camille\AppData\Local\Temp\comh.268388\GoogleUpdate.exe, Quarantined, [0b96559d86f543f33a5f52a47f838977],
      PUP.Optional.GlobalUpdate.A, C:\Users\Camille\AppData\Local\Temp\comh.268388\GoogleUpdateBroker.exe, Quarantined, [0b96559d86f543f33a5f52a47f838977],
      PUP.Optional.GlobalUpdate.A, C:\Users\Camille\AppData\Local\Temp\comh.268388\GoogleUpdateHelper.msi, Quarantined, [0b96559d86f543f33a5f52a47f838977],
      PUP.Optional.GlobalUpdate.A, C:\Users\Camille\AppData\Local\Temp\comh.268388\GoogleUpdateOnDemand.exe, Quarantined, [0b96559d86f543f33a5f52a47f838977],
      PUP.Optional.GlobalUpdate.A, C:\Users\Camille\AppData\Local\Temp\comh.268388\goopdate.dll, Quarantined, [0b96559d86f543f33a5f52a47f838977],
      PUP.Optional.GlobalUpdate.A, C:\Users\Camille\AppData\Local\Temp\comh.268388\goopdateres_en.dll, Quarantined, [0b96559d86f543f33a5f52a47f838977],
      PUP.Optional.GlobalUpdate.A, C:\Users\Camille\AppData\Local\Temp\comh.268388\npGoogleUpdate4.dll, Quarantined, [0b96559d86f543f33a5f52a47f838977],
      PUP.Optional.GlobalUpdate.A, C:\Users\Camille\AppData\Local\Temp\comh.268388\psmachine.dll, Quarantined, [0b96559d86f543f33a5f52a47f838977],
      PUP.Optional.GlobalUpdate.A, C:\Users\Camille\AppData\Local\Temp\comh.268388\psuser.dll, Quarantined, [0b96559d86f543f33a5f52a47f838977],

      Physical sectors: 0
      (No malicious items detected)


      (end)
      0
  6. Anonymous user
     
    Re

    Have you noticed any improvement?

    --
    ***-----------------------Security Contributor-------------------------***
    We have all been beginners at something at some point.
    But knowledge is the reward for diligence.
    0
  7. Entilore Posted messages 18 Status Member
     
    Not really, no.
    0
  8. Anonymous user
     
    Re

    For more information, please do this

    Open this link and download ZHPDiag from Nicolas Coolman:

    https://nicolascoolman.eu

    Or

    https://www.commentcamarche.net/telecharger/utilitaires/24803-zhpdiag/

    Once the download is complete,

    Double-click the icon to launch the program. Under Vista; Seven or Windows 8 right-click "run as administrator"

    In the ZHPDiag window that just opened, click on "Configure"

    Click on the magnifying glass at the bottom left with the plus sign to start the scan.

    Let the tool work, it may take a while.

    A report will open. This report is also located on your desktop

    To send the report, click on this link:
    http://pjjoint.malekal.com/

    If there is a problem, use one of the following

    https://forums-fec.be/upload
    https://www.cjoint.com/

    Check your desktop

    Select the ZHPDiag.txt file.

    Click on "Click here to upload the file".

    A link of this form:

    http://www.cijoint.com/cjlink.php?file=cj200905/cijSKAP5fU.txt

    will be added to the page.

    Copy this link into your response.

    Thank you

    @+

    --
    ***-----------------------Security Contributor-------------------------***
    We have all been beginners at something at some point.
    But knowledge is the reward for diligence.
    0
  9. Entilore Posted messages 18 Status Member
     
    I can't run it; 360 Total Security automatically deletes it (apparently ZHP diag is a Trojan ... Haha).
    0
  10. Anonymous user
     
    Re

    [*] Download to the desktop RogueKiller (by tigzy) (choose between the 32 and 64-bit version depending on your Windows, if you don't know, just ask me!)
    [*] Close all programs
    [*] Launch RogueKiller.exe.
    [*] Wait for the Prescan to finish ...
    [*] Click on Scan. Click on Report and copy-paste the content of the report

    @+

    --
    ***-----------------------Security Contributor-------------------------***
    We've all been beginners at something at some point.
    But knowledge is the reward for diligence.
    0
  11. Entilore Posted messages 18 Status Member
     
    Here's the report:
    RogueKiller V9.2.13.0 (x64) [Sep 25 2014] by Adlice Software
    Email: https://www.adlice.com/contact/
    Reports: https://forum.adlice.com/
    Website: https://www.surlatoile.org/RogueKiller/
    Blog: https://www.adlice.com/

    Operating System: Windows 8.1 (6.3.9200) 64-bit version
    Startup: Normal mode
    User: Camille [Admin rights]
    Mode: Removal -- Date: 09/27/2014 17:36:21

    ¤¤¤ Malicious Processes: 0 ¤¤¤

    ¤¤¤ Registry Entries: 13 ¤¤¤
    [PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> NOT SELECTED
    [PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> NOT SELECTED
    [PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> NOT SELECTED
    [PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> NOT SELECTED
    [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows | AppInit_DLLs : C:\Users\Camille\AppData\Local\Smartbar\Application\Resources\crdlil64.dll [x] -> REPLACED ()
    [PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-2190123621-3127979045-682105981-1001\Software\Microsoft\Internet Explorer\Main | Start Page : www.google.com -> NOT SELECTED
    [PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-2190123621-3127979045-682105981-1001\Software\Microsoft\Internet Explorer\Main | Start Page : www.google.com -> NOT SELECTED
    [PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-2190123621-3127979045-682105981-1002\Software\Microsoft\Internet Explorer\Main | Start Page : https://fr.yahoo.com?fr=hp-avast&type=avastbcl -> NOT SELECTED
    [PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-2190123621-3127979045-682105981-1002\Software\Microsoft\Internet Explorer\Main | Start Page : https://fr.yahoo.com?fr=hp-avast&type=avastbcl -> NOT SELECTED
    [PUM.SearchPage] (X64) HKEY_USERS\S-1-5-21-2190123621-3127979045-682105981-1001\Software\Microsoft\Internet Explorer\Main | Search Page : www.google.com -> NOT SELECTED
    [PUM.SearchPage] (X86) HKEY_USERS\S-1-5-21-2190123621-3127979045-682105981-1001\Software\Microsoft\Internet Explorer\Main | Search Page : www.google.com -> NOT SELECTED
    [PUM.SearchPage] (X64) HKEY_USERS\S-1-5-21-2190123621-3127979045-682105981-1002\Software\Microsoft\Internet Explorer\Main | Search Page : https://fr.search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms} -> NOT SELECTED
    [PUM.SearchPage] (X86) HKEY_USERS\S-1-5-21-2190123621-3127979045-682105981-1002\Software\Microsoft\Internet Explorer\Main | Search Page : https://fr.search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms} -> NOT SELECTED

    ¤¤¤ Scheduled Tasks: 4 ¤¤¤
    [Suspicious.Path] IAVUSUXT.job -- C:\Users\Camille\AppData\Roaming\IAVUSUXT.exe (/infocmdline=JxbBtRUVIp3nbm9zeKblL0j2tiy4m6nb5eFzhrqXfpJ0la9e4fUsOvn55G2U/Yvz5M+RCDG1qTPzLSmW5QXcP2SApQMomw8fkPYRKKwVx9k1vnJvdQNA2B3PWa9/EfSLXeu5ucRUUsd0pS4XlQE1VYNzPGXoTAT26qQUk95aBR+q7oXOm8K6ThZ2uBA8evg4uMG6/pldh4GIvbrwFhEkMdzSjuY/tmF3kyY4nuaKxP5Ov/ghfwWqI+NVrnJ05Ip8Ssn8Pup757waKc9zoh85ok/f17CJ7t6UD61VUjvXrKNEZ9fxa4wmKk6KW7tKpowFElDRlNlmObLszkJ/QAKWWq81HiXscOWx6FdCkw3aixMHZtAJ3k3Y3bJ26ThoNCAW1rhIUMp6K5VmSHJ8ovmaV+CITagyN8JGJoxwVdUbDYpZnTSC9RjwAqKw+E4vC9Td7vFRCqX7D2VlcSoY/TX03GrY2Jm8zrCVEPduTpJDQCgWqz1alIEhjtaGBvuaUcBisZkLutK+wRg09MBTdV6esMVJAnVrHQ18v7KwLAnjHLQ6qygpZwcc4FRKmt288xLM80NNLghoNjL7A5LleUPNwEK91s0rHvKmd83SdnKb64/+DklNpVBvfiP1S7ufH9ZR3T06y0c1dfgiSyZsKto8dEXbr5D/fQu+D2xz3adWKyg=) -> DELETED
    [Suspicious.Path] UCE.job -- C:\Users\Camille\AppData\Roaming\UCE.exe (/infocmdline=hDSI3/bcH73NU4W+lcr2rbiya9qRceU2rJq28CvUq1h1W1OfjMhcGoe3LOg6UBOv74hFIMHs2nsF/gt30sPNhWJLPRHKv+w/4QD6FFsKqeRdQQ/Gz8kHvL0g7hIwl1M7vgpKsBidchw/qc5KemmVCOQQNMPotJgvC0mmkB7gia0rk1M+IHGNNVf58Ulm+aEKtmS0t+peaw6v9qfklHWR2MMkFy1QToiD32HI/L2thjtpa61wUebR3E+atQTYnEiqkc/7WbdnRCW1zCBffGRiKEeGXNA99eiYCZNwJ2/+P7NhTavLIVV8/SwZeqQHmegckI0MLMKAOJRGEUC772A/7qdiGwBkcKE4KhDoDPewilDCT9f+dCrPchlomMvI4uEVskwHt0HzLQBpO/p+WCbaW0r50cL6R1poYscjzSWwdlXTE5yHtTNYt+pZW0D6m7ZXSQi+p/u4a3A7NcLGYISUtA8AkxctHTq9gJkHA4rFcjAj/iwC2l5vUU35w9X1zf8s) -> DELETED
    [Suspicious.Path] \\IAVUSUXT -- C:\Users\Camille\AppData\Roaming\IAVUSUXT.exe (/infocmdline=JxbBtRUVIp3nbm9zeKblL0j2tiy4m6nb5eFzhrqXfpJ0la9e4fUsOvn55G2U/Yvz5M+RCDG1qTPzLSmW5QXcP2SApQMomw8fkPYRKKwVx9k1vnJvdQNA2B3PWa9/EfSLXeu5ucRUUsd0pS4XlQE1VYNzPGXoTAT26qQUk95aBR+q7oXOm8K6ThZ2uBA8evg4uMG6/pldh4GIvbrwFhEkMdzSjuY/tmF3kyY4nuaKxP5Ov/ghfwWqI+NVrnJ05Ip8Ssn8Pup757waKc9zoh85ok/f17CJ7t6UD61VUjvXrKNEZ9fxa4wmKk6KW7tKpowFElDRlNlmObLszkJ/QAKWWq81HiXscOWx6FdCkw3aixMHZtAJ3k3Y3bJ26ThoNCAW1rhIUMp6K5VmSHJ8ovmaV+CITagyN8JGJoxwVdUbDYpZnTSC9RjwAqKw+E4vC9Td7vFRCqX7D2VlcSoY/TX03GrY2Jm8zrCVEPduTpJDQCgWqz1alIEhjtaGBvuaUcBisZkLutK+wRg09MBTdV6esMVJAnVrHQ18v7KwLAnjHLQ6qygpZwcc4FRKmt288xLM80NNLghoNjL7A5LleUPNwEK91s0rHvKmd83SdnKb64/+DklNpVBvfiP1S7ufH9ZR3T06y0c1dfgiSyZsKto8dEXbr5D/fQu+D2xz3adWKyg=) -> DELETED
    [Suspicious.Path] \\UCE -- C:\Users\Camille\AppData\Roaming\UCE.exe (/infocmdline=hDSI3/bcH73NU4W+lcr2rbiya9qRceU2rJq28CvUq1h1W1OfjMhcGoe3LOg6UBOv74hFIMHs2nsF/gt30sPNhWJLPRHKv+w/4QD6FFsKqeRdQQ/Gz8kHvL0g7hIwl1M7vgpKsBidchw/qc5KemmVCOQQNMPotJgvC0mmkB7gia0rk1M+IHGNNVf58Ulm+aEKtmS0t+peaw6v9qfklHWR2MMkFy1QToiD32HI/L2thjtpa61wUebR3E+atQTYnEiqkc/7WbdnRCW1zCBffGRiKEeGXNA99eiYCZNwJ2/+P7NhTavLIVV8/SwZeqQHmegckI0MLMKAOJRGEUC772A/7qdiGwBkcKE4KhDoDPewilDCT9f+dCrPchlomMvI4uEVskwHt0HzLQBpO/p+WCbaW0r50cL6R1poYscjzSWwdlXTE5yHtTNYt+pZW0D6m7ZXSQi+p/u4a3A7NcLGYISUtA8AkxctHTq9gJkHA4rFcjAj/iwC2l5vUU35w9X1zf8s) -> ERROR [0]

    ¤¤¤ Files: 0 ¤¤¤

    ¤¤¤ HOSTS File: 0 ¤¤¤

    ¤¤¤ Antirootkit: 0 (Driver: CHARGE) ¤¤¤

    ¤¤¤ Web Browsers: 0 ¤¤¤

    ¤¤¤ MBR Check: ¤¤¤
    +++++ PhysicalDrive0: ST1000LM024 HN-M101MBB +++++
    --- User ---
    [MBR] 27e1843659451c18b582d4bcf7e5786c
    [BSP] 9cb9bd99896f179553067dcea5b1f913 : Unknown MBR Code
    Partition table:
    0 - [XXXXXX] UNKNOWN (0x0) [VISIBLE] Offset (sectors): 1 | Size: 2097152 MB
    User = LL1 ... OK
    User = LL2 ... OK

    ============================================
    RKreport_SCN_09272014_173609.log
    0
  12. Anonymous user
     
    Re

    try to post me a ZHPDiag report now; thank you

    @+

    --
    ***-----------------------Security Contributor-------------------------***
    We have all been beginners at something at some point.
    But knowledge is the reward for diligence.
    0
  13. Entilore Posted messages 18 Status Member
     
    I'm not sure at all about that, I have none of the options you mentioned: no configure, no magnifier, just repair.

    ~ ZHPCleaner v2014.9.26.147 by Nicolas Coolman (26/09/2014)
    ~ Run by Camille (Administrator) (27/09/2014 17:51:14)
    ~ WebSite : https://nicolascoolman.eu
    ~ Forum : https://nicolascoolman.eu
    ~ State version : Updated version
    ~ Report : C:\Users\Camille\Desktop\ZHPCleaner.txt
    ~ Quarantine : C:\Users\Camille\AppData\Roaming\ZHP\ZHPCleaner_Quarantine.txt
    ~ Windows 81, 64-bit (Build 9600)

    ---\\ Restoration of default proxy settings.
    REPLACED PARAMETERS: EnableHttp1_1 ( 1 )

    ---\\ Repair of Microsoft Internet Explorer browser.
    REPLACED PARAMETERS: Start Page ( https://fr.yahoo.com?fr=hp-avast&type=avastbcl )
    REPLACED PARAMETERS: Search Page ( https://fr.search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms} )
    REPLACED PARAMETERS: Search Page ( https://fr.search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms} )

    ---\\ Deletion of harmful Browser Helper Objects from browsers (BHO).
    DELETED: [X64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611171196}\\f3b99230f329013156aa33422def983b0061796 (PUP.CrossRider)
    DELETED: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611171196}\\f3b99230f329013156aa33422def983b0061796 (PUP.CrossRider)

    ---\\ Repair of the host file.
    ~ The host file is legitimate. (21)

    ---\\ Deletion of harmful extensions from Google Chrome (Manifest).
    DELETED EXT: eofcbnmajmjmplflapaojjnihcjkigck [Orphean]

    ---\\ Deletion of Adwares, PUPs, Spywares.
    MOVED: C:\WINDOWS\Prefetch\IMINENTMINIBARIE.EXE-5F5CED2A.pf (PUP.Minibar)
    MOVED: C:\WINDOWS\Prefetch\MINIBARFIREFOX.EXE-AD2AFDA7.pf (PUP.Minibar)
    MOVED: C:\WINDOWS\Prefetch\SOFTONICDOWNLOADER_POUR_ADBLO-4BA27204.pf (PUP.Softonic)
    MOVED: C:\WINDOWS\Prefetch\UMBRELLA236.EXE-6A77BC7A.pf (Adware.IMBooster)

    ---\\ Repair summary
    ~ Repair successfully completed
    ~ This browser is absent (Opera Software)
    ~ Repair canceled by the user (Internet Explorer)

    End of clean at 17:51:58
    ===================
    ZHPCleaner-27092014-17_51_58.txt
    0
  14. Anonymous user
     
    Re

    You posted a ZHPcleaner and not a ZHPDiag.
    Please read the procedure carefully before posting

    Thank you

    --
    ***-----------------------Security Contributor-------------------------***
    We have all been beginners at something at one point.
    But knowledge is the reward of diligence.
    0
  15. Anonymous user
     
    Re

    Use of the ZHPFix tool:

    * Copy all the text present in the box below (select it with your mouse / Right-click on it and choose "copy" or press Ctrl+C)

    ZHPFix Script
    O4 - HKLM\..\Wow6432Node\Run: [QHSafeTray] . (.Qihu Software Co. Limited - 360 Total Security.) -- C:\Program Files (x86)\360\Total Security\safemon\360Tray.exe
    O23 - Service: 360 Total Security (QHActiveDefense) . (.No owner - 360 Total Security.) - C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe
    [MD5.07605ABEB10FC533881C91F19DECF69A] [APT] [AutoKMS] (...) -- C:\WINDOWS\AutoKMS\AutoKMS.exe [1923584]
    O39 - APT: AutoKMS - (...) -- C:\Windows\Tasks\AutoKMS.job [302]
    O39 - APT: AutoKMS - (...) -- C:\Windows\System32\Tasks\AutoKMS [302]
    O42 - Software: Yahoo Community Smartbar Engine - (.Linkury Inc..) [HKCU][64Bits] -- {072e8fb1-c93b-499a-9ace-efee4d773f97}
    [HKCU\Software\360]
    O43 - CFD: 25/09/2014 - 23:57:58 - [] ----D C:\Program Files (x86)\360
    O43 - CFD: 26/09/2014 - 00:02:43 - [] ----D C:\ProgramData\360safe
    O45 - LFCP:[MD5.94F2FF3D17FFF3DE4434C353E48CE03A] - 25/09/2014 - 22:57:18 ---A- - C:\Windows\Prefetch\IMINENTSOFTONICREADY.EXE-516DAE4C.pf
    O61 - LFC: 25/09/2014 - 18:04:17 ---A- . (...) -- C:\Users\Camille\AppData\Local\Microsoft\Windows\INetCache\IE\2QKE9YZB\MinibarFirefox[1].exe [1144648]
    O61 - LFC: 25/09/2014 - 18:04:17 ---A- . (.Sien SA.) -- C:\Users\Camille\AppData\Local\Microsoft\Windows\INetCache\IE\F0ZTZ020\MinibarChrome[1].exe [755840]
    O61 - LFC: 25/09/2014 - 18:04:18 ---A- . (...) -- C:\Users\Camille\AppData\Local\Microsoft\Windows\INetCache\IE\OMZTKQ7N\IminentMinibarIE[1].exe [1062760]
    O90 - PUC: "F274703B9DB704042955ECD6A611693A" . (.Software Updater.) -- C:\WINDOWS\Installer\{B307472F-7BD9-4040-9255-CE6D6A1196A3}\icon.ico
    [MD5.103F619246C8BEFBA0EFA12CD1092648] [WIS][27/08/2014] (.LPT - LPT System Updater Service.) -- C:\Windows\Installer\a146b02.msi [2154496]
    SR - | Auto 10/09/2014 707184 | (QHActiveDefense) . (...) - C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe
    [HKLM\Software\Wow6432Node\360Safe]
    C:\WINDOWS\AutoKMS\AutoKMS.exe
    C:\Windows\Tasks\AutoKMS.job
    C:\Windows\System32\Tasks\AutoKMS
    C:\Windows\Installer\a146b02.msi
    C:\Users\Camille\AppData\Local\Temp\IminentSoftonicReady.exe
    O39 - APT: - (..) -- C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2190123621-3127979045-682105981-1002Core [942]
    O39 - APT: - (..) -- C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2190123621-3127979045-682105981-1002UA [964]
    O41 - Driver: (360Box64) . (.360.cn - 360Box64.) - C:\Windows\System32\DRIVERS\360Box64.sys
    O41 - Driver: (360Camera) . (.360.cn - 360???? ???????.) - C:\Windows\System32\Drivers\360Camera64.sys
    O41 - Driver: (360FsFlt) . (.Qihu 360 Software Co., Ltd. - 360 Internet Security Proactive Defense.) - C:\Windows\System32\DRIVERS\360FsFlt.sys
    [HKLM\Software\Wow6432Node\360TotalSecurity]
    [HKLM\Software\Wow6432Node\360softmgr]
    O44 - LFC:[MD5.A583F4DAAA4DB87BF92FD033966ABC4B] - 25/09/2014 - 22:58:23 ---A- . (.360.cn - 360Box64.) -- C:\Windows\System32\Drivers\360Box64.sys [305736]
    O44 - LFC:[MD5.D31541708A595BCA380105D44C2C2AD5] - 25/09/2014 - 22:58:24 ---A- . (.360.cn - 360???? ???????.) -- C:\Windows\System32\Drivers\360Camera64.sys [40520]
    O44 - LFC:[MD5.15FE196A71357AC9FF6E5A4B360BDB20] - 25/09/2014 - 22:58:24 ---A- . (.360.cn - 360???? ??????.) -- C:\Windows\System32\Drivers\360AntiHacker64.sys [100424]
    O44 - LFC:[MD5.3AA0D07082BF4B4EFF8BAE9F4EDF783B] - 25/09/2014 - 22:58:27 ---A- . (.Qihu 360 Software Co., Ltd. - 360 Internet Security Proactive Defense.) -- C:\Windows\System32\Drivers\360fsflt.sys [311888]
    O58 - SDL:10/09/2014 - 11:53:14 ---A- . (.360.cn - 360???? ??????.) -- C:\Windows\System32\Drivers\360AntiHacker64.sys [100424]
    O58 - SDL:10/09/2014 - 11:53:14 ---A- . (.360.cn - 360Box64.) -- C:\Windows\System32\Drivers\360Box64.sys [305736]
    O58 - SDL:10/09/2014 - 11:53:14 ---A- . (.360.cn - 360???? ???????.) -- C:\Windows\System32\Drivers\360Camera64.sys [40520]
    O58 - SDL:10/09/2014 - 11:53:14 ---A- . (.Qihu 360 Software Co., Ltd. - 360 Internet Security Proactive Defense.) -- C:\Windows\System32\Drivers\360fsflt.sys [311888]
    O61 - LFC: 25/09/2014 - 18:04:31 ---A- . (...) -- C:\Users\Camille\Desktop\abp.exe [448783]
    O61 - LFC: 27/09/2014 - 18:04:31 ---A- . (...) -- C:\Users\Camille\Desktop\Norton_Removal_Tool.exe [870728]
    [MD5.C0B59FF7EE933362B2D5D1941094C879] [SPRF][25/09/2014] (...) -- C:\Users\Camille\Desktop\abp.exe [448783]
    [MD5.9631FA36F4784888F0918394778B8B07] [SPRF][27/09/2014] (...) -- C:\Users\Camille\Desktop\Norton_Removal_Tool.exe [870728]
    ShortcutFix
    EmptyPrefetch
    FirewallRAZ
    Emptytemp
    EmptyCLSID

    --------------------------------------------------------------------------------------------
    Run ZHPFix from the shortcut on your Desktop (if you are using Windows Vista, 7, or 8, do it by right-clicking --> Run as administrator)

    Click on the Import button. The content of the clipboard will be pasted into the input area of ZHPFix

    NB (W8) : In some cases, the script is automatically pasted into the script area and does not require clicking the "IMPORT" button.

    * Click the GO button to start the cleanup.

    -> let the tool work and do not touch anything ...
    -> If you are asked to restart the PC to complete the cleaning, do it!

    Once completed, a new report will be displayed: post the content of this report in your next response ...
    This report is copied to the desktop

    ( this report is also saved in this folder:
    - For XP: C:\Documents and Settings\username\Local Settings\Application Data\ZHP
    - Since Vista: C:\Users\username\AppData\Roaming\ZHP\ZHPFix [R1].txt
    )

    @+

    --
    ***-----------------------Security Contributor-------------------------***
    We have all been a beginner at something.
    But knowledge is the reward of diligence.
    0
  16. Entilore Posted messages 18 Status Member
     
    Here is the result:

    ZHPFix Report 2014.9.16.7 by Nicolas Coolman, Update of 09/16/2014
    Registry export file:
    Run by Camille at 09/27/2014 06:29:20 PM
    High Elevated Privileges: OK
    Windows 8 Home Premium Edition, 64-bit Service Pack 1 (9600)

    Trash emptied (00mn 09s)
    Prefetcher folder emptied
    Browser shortcut repair

    ========== Memory Processes ==========
    DELETED: Memory Process: C:\WINDOWS\AutoKMS\AutoKMS.exe
    DELETED: Memory Process: C:\Users\Camille\AppData\Local\Temp\IminentSoftonicReady.exe

    ========== Registry Keys ==========
    DELETED:³ Service: QHActiveDefense
    DELETED: HKCU\Software\360
    DELETED: [HKLM\Software\Classes\Installer\Products\\F274703B9DB704042955ECD6A611693A]
    DELETED: [HKLM\Software\Classes\Installer\Features\F274703B9DB704042955ECD6A611693A]
    DELETED:³ HKLM\Software\Wow6432Node\360Safe
    DELETED:³ HKLM\Software\Wow6432Node\360TotalSecurity
    DELETED: HKLM\Software\Wow6432Node\360softmgr

    ========== Registry Values ==========
    ERROR RunValue: QHSafeTray
    No Standard Profile Value: FirewallRaz :
    No Domain Profile Value: FirewallRaz :
    DELETED: FirewallRaz (Domain) : {9E3D57FC-7C37-4424-9352-4831E97D029D}
    DELETED: FirewallRaz (Domain) : {548DCF8C-BFF2-4BA4-AA88-FBAF9AC8BCC6}
    DELETED: FirewallRaz (Domain) : NetPres-In-TCP-NoScope
    DELETED: FirewallRaz (Domain) : NetPres-Out-TCP-NoScope
    DELETED: FirewallRaz (None) : NetPres-WSD-In-UDP
    DELETED: FirewallRaz (None) : NetPres-WSD-Out-UDP
    DELETED: FirewallRaz (Public) : NetPres-In-TCP
    DELETED: FirewallRaz (Public) : NetPres-Out-TCP
    DELETED: FirewallRaz (None) : MCX-Prov-Out-TCP
    DELETED: FirewallRaz (None) : MCX-McrMgr-Out-TCP
    DELETED: FirewallRaz (Private) : {A67D968A-3E32-450B-88C6-2916D3C0CBED}
    DELETED: FirewallRaz (Private) : {6FB17EE1-9F79-4F63-933B-22B90C6C4123}
    DELETED: FirewallRaz (Public) : {9CBDB688-1560-4EC3-B3C4-13B86FD1A88A}
    DELETED: FirewallRaz (Public) : {99AB5382-1059-45AC-AAEB-E32736E99DF9}
    DELETED: FirewallRaz (Domain) : {E7985E1D-C36F-4787-80A8-6350D07E9266}
    DELETED: FirewallRaz (None) : {808F1451-4108-46FD-ADBB-F17324B5F0BD}
    DELETED: FirewallRaz (Private) : {9AEFA097-386D-4148-94C1-1B123FA68813}
    DELETED: FirewallRaz (Private) : {3D4C61C0-E773-4672-AE52-48130E65BA61}

    ========== Folders ==========
    No empty Local user CLSID folders

    ========== Files ==========
    DELETED Restart: c:\program files (x86)\360\total security\safemon\360tray.exe
    DELETED: c:\windows\prefetch\iminentsoftonicready.exe-516dae4c.pf
    DELETED: c:\users\camille\appdata\local\microsoft\windows\inetcache\ie\2qke9yzb\minibarfirefox[1].exe
    DELETED: c:\users\camille\appdata\local\microsoft\windows\inetcache\ie\f0ztz020\minibarchrome[1].exe
    DELETED: c:\users\camille\appdata\local\microsoft\windows\inetcache\ie\omztkq7n\iminentminibarie[1].exe
    DELETED: C:\Windows\Installer\a146b02.msi
    DELETED Restart: c:\windows\system32\tasks\facebookupdatetaskusers-1-5-21-2190123621-3127979045-682105981-1002core
    DELETED Restart: c:\windows\system32\tasks\facebookupdatetaskusers-1-5-21-2190123621-3127979045-682105981-1002ua
    DELETED Restart: c:\windows\system32\drivers\360box64.sys
    DELETED Restart: c:\windows\system32\drivers\360camera64.sys
    DELETED Restart: c:\windows\system32\drivers\360antihacker64.sys
    DELETED Restart: c:\windows\system32\drivers\360fsflt.sys
    DELETED: c:\users\camille\desktop\abp.exe
    DELETED: c:\users\camille\desktop\norton_removal_tool.exe
    DELETED Temporary Windows (874) (307 528 646 bytes)

    ========== Scheduled Task ==========
    DELETED: AutoKMS
    DELETED: AutoKMS

    ========== Summary ==========
    2: Memory Processes
    7: Registry Keys
    21: Registry Values
    1: Folders
    15: Files
    2: Scheduled Tasks

    End of clean in 02mn 04s

    ========== File Path Report ==========
    C:\Users\Camille\AppData\Roaming\ZHP\ZHPFix[R1].txt - 09/27/2014 06:29:30 PM [3879]
    0
  17. Anonymous user
     
    Re

    Do you still have any problems?

    See you soon

    --
    ***-----------------------Security Contributor-------------------------***
    We have all been beginners at something at one point.
    But knowledge is the reward of diligence.
    0
  18. Entilore Posted messages 18 Status Member
     
    No, 360 still exists.

    I think I'm going to do a system recovery. We'll see what happens.
    0
  • 1
  • 2