How to uninstall "Baidu"???
Solved
Hello,
Help, please
I have the same problem
Configuration: Windows 7 / Chrome 45.0.2453.0
Help, please
I have the same problem
Configuration: Windows 7 / Chrome 45.0.2453.0
36 answers
-
Security ContributorHello,
Congratulations on this interesting topic ... and resolved.
I also followed at Nicolas's. ;)
Albert
--
Patience-Vigilance-Love. -
:-)
--
O.o°* ???Breathe deeply, write your message in proper French and clearly. It will be fine, you’ll see, well we’ll try!!! o°.Oø¤º°'°º¤ø-
-
@Lily97269Hello,
with Malekal, you are in good hands :)
https://forums.commentcamarche.net/forum/affich-32265757-impossible-de-desinstaller-virus-baidu#3
-
-
A big THANK YOU for your help.
-
it's just a report, it changed places :P
know that Delfix has created a new restore point, it might come in handy just in case :-)
on that note, happy surfing ;-)
--
O.o°* ???Breathe deeply, write your message in proper French and clearly. it's going to be fine, you'll see, well we're trying!!! o°.Oø¤º°'°º¤ø -
It is not in the location: C:\DelFix.txt
It is on my desktop, is that normal?
https://www.cjoint.com/c/EGrnWK7tOo1 -
ok,
we're finishing up:
Download Delfix to your desktop:
https://toolslib.net/downloads/viewdownload/2-delfix/
or
Check the following boxes:=> Remove disinfecting tools (checked by default)
=> Purge system restore- Then click on Run and wait during the removal process.
- When the procedures are completed, the tool will close and disappear from the desktop.
- A report is saved to the clipboard: you just need to right-click and "paste" in your next reply to send me the report
- the report is stored at this location: C:\DelFix.txt
Warning: The report is unique and is deleted each time we re-run one or more options of DelFix.
Note:
Delfix does not uninstall MBAM, it's up to you to decide if you want to keep it or uninstall it.
--
O.o°* ???Breathe deeply, write your message in proper French and clearly. It'll be alright, you'll see, well we're trying !!! o°.Oø¤º°'°º¤ø -
Here it is,
Programs - ok
Processes - ok
I only see the files in ADW Quarantine -
If you can no longer see it in the list of programs, nor in the processes, it means we've got it!
Restart the PC to see,
if there are no traces, we'll uninstall the tools, etc. etc. :-)
--
O.o°*??? Breathe deeply, write your message in proper French and clearly. It's going to be okay, you'll see, at least we'll try!!! o°.Oø¤º°'°º¤ø -
It's always the same, the same message...
If it's a ghost file, can we say the problem is solved? -
try again to paste the script in the window to see,
we might be looking for a ghost file!
--
O.o°* ???Breathe deeply, write your message in proper French and clearly. It will be fine, you'll see, well we're trying!!! o°.Oø¤º°'°º¤ø -
Here is the message that appears
https://www.cjoint.com/c/EGrh1hYkER1 -
In the report, it presents itself as a plugin in Mozilla Firefox!
For the driver, it has become inactive!
Do you really want us to try to get rid of it?
Download The Avenger by Swandog46 to your Desktop:
http://www.geekstogo.com/forum/files/file/393-the-avenger-by-swandog46/
Click on Avenger.zip to open the file
Extract avenger.exe to your desktop
Now, launch The Avenger by clicking on its desktop icon
/!\ Vista and Seven users, right-click and run as administrator
Copy all the text in bold below: highlight it and press the keys (Ctrl+C):
Drivers to disable:
BDMNetMon.sys
Drivers to delete:
BDMNetMon.sys
Files to delete:
C:\Windows\System32\drivers\BDMNetMon.sys
Paste this text (Ctrl+V) into the box: Input script here
Press Execute
The PC will restart
If the report does not appear, it is located in C:\ avenger
Tutorial:
http://www.oxygenepc.com/forum/the-avenger-t594.html
--
O.o°* ???Breathe deeply, write your message in proper French and clearly. It’s going to be okay, you’ll see, well, we’ll try!!! o°.Oø¤º°'°º¤ø -
At startup, nothing in Chinese anymore since the removal in safe mode by Revo Pro
Browser - ok
- AdwCleaner - 0 items
- Malwarebytes - 0 items
- Revo Pro - does not detect any remaining files
But it is still in the report
https://www.cjoint.com/c/EGquUA8NmD1
Thank you -
ok,
restart the PC one more time and let me know if you see it
we'll finish by uninstalling the tools afterwards
--
O.o°* ???Breathe deeply, write your message in good French and clearly. It will be fine, you'll see, well, let's try!!! o°.Oø¤º°'°º¤ø -
Here is
https://www.cjoint.com/c/EGqt71BXvn1
I can't find it in the path indicated in the report; and Revo doesn't detect it either...
C:\Program Files (x86)\Baidu\BaiduSd\4.0.0.6697\explugin\npBaiduSDDetectPlug.dll -
the plugin and driver are still there,
restart the pc
run a new Zhpdiag afterwards to see
--
O.o°* ???Breathe deeply, write your message clearly and in good French. It will be fine, you'll see, well we're trying!!! o°.Oø¤º°'°º¤ø -
https://www.cjoint.com/c/EGqpNvSBNd1
ZHPDiag scan done after the restart
https://www.cjoint.com/c/EGqpOfZqJ11 -
/!\ Warning /!\, </li> this script is only valid for this PC, during the cleanup, do not use it on another PC, risk of crashing! </li></ul> Launch ZHPFix via the shortcut on your Desktop, the icon looks like a syringe.
Click on "import"
You will see a warning message, click OK.
Open this document and copy and paste the entire content into the Zhpfix window:- * Copy (Ctrl + C) and paste (Ctrl + V) the following bold lines into the Zhpfix window:
---------------------------------------------------------
Zhpfix Script
P2 - FPN: [HKLM] [@baidu.com/BaidusdDetectNPPlugin] - (.BeiJing Baidu Netcom Science Technology Co., Ltd.) -- C:\Program Files (x86)\Baidu\BaiduSd\4.0.0.6697\explugin\npBaiduSDDetectPlug.dll
P2 - FPN: [HKLM] [@qq.com/npAndroidAssistant] - (.Tencent, Inc..) -- C:\Program Files (x86)\Common Files\Tencent\QQPhoneManager\2.0.201.3198\npQQPhoneManagerExt.dll
P2 - FPN: [HKLM] [@qq.com/QQPCMgr] - (.Tencent.) -- C:\Program Files (x86)\Tencent\QQPCMgr\10.10.16434.218\npQMExtensionsMozilla.dll
O2 - BHO: WebGuard BHO Class [64Bits] - {1B2639A9-EE25-4AE7-A2E3-B308F08125C4} (Orphean)
O2 - BHO: (no name) [64Bits] - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} (Orphean)
O2 - BHO: (no name) [64Bits] - {9030D464-4C02-4ABF-8ECC-5164760863C6} (Orphean)
O23 - Service: 10809 (10809) . (...) - C:\Windows\temp\10809 (.not file.)
O42 - Software: Íýíñè Äðþ. Ïëàòüå äëÿ ïåðâîé ëåäè - (...) [HKLM][64Bits] -- Íýíñè Äðþ. Ïëàòüå äëÿ ïåðâîé ëåäè_is1
O42 - Software: Íýíñè Äðþ. Ñåêðåò ñòàðèííûõ ÷àñîâ - (...) [HKLM][64Bits] -- Íýíñè Äðþ. Ñåêðåò ñòàðèííûõ ÷àñîâ_is1
O42 - Software: Íýíñè Äðþ. Ñåêðåòû ìîãóò óáèâàòü - (...) [HKLM][64Bits] -- Íýíñè Äðþ. Ñåêðåòû ìîãóò óáèâàòü_is1
O42 - Software: Íýíñè Äðþ. Ñîêðîâèùå êîðîëåâñêîé áàøíè - (...) [HKLM][64Bits] -- Íýíñè Äðþ. Ñîêðîâèùå êîðîëåâñêîé áàøíè_is1
O42 - Software: Íýíñè Äðþ. Òàéíà àëîé ðóêè - (...) [HKLM][64Bits] -- Íýíñè Äðþ. Òàéíà àëîé ðóêè_is1
O42 - Software: À-Ç-Î-Â (v.1.0) - (...) [HKLM][64Bits] -- ÒÉ: À-Ç-Î-Â_is1
O42 - Software: Àñòðàëüíàÿ Ïðîåêöèÿ (v.1.1) - (...) [HKLM][64Bits] -- ÒÉ: Àñòðàëüíàÿ Ïðîåêöèÿ_is1
O42 - Software: Ìãíîâåííàÿ Ýâîëþöèÿ (v.1.2) - (...) [HKLM][64Bits] -- ÒÉ: Ìãíîâåííàÿ Ýâîëþöèÿ_is1
O42 - Software: Ìåäèòàöèÿ íà ÎÌ (v.1.1) - (...) [HKLM][64Bits] -- ÒÉ: Ìåäèòàöèÿ íà ÎÌ_is1
O42 - Software: Ðàçâèòèå ñèñòåìû ÷àêð (v.1.1) - (...) [HKLM][64Bits] -- ÒÉ: Ðàçâèòèå ñèñòåìû ÷àêð_is1
O43 - CFD: 2015/07/12 22:51:06 - [] D -- C:\Program Files (x86)\Common Files\Baidu
O58 - SDL:2015/04/03 07:02:20 A . (.Baidu - Network Monitor.) -- C:\Windows\System32\drivers\BDMNetMon.sys [241992]
Proxyfix
Firewallraz
EmptyPrefetch
ShortcutFix
Emptytemp
EmptyClsid
----------------------------------------------------------
- Click the "GO" button to start the cleanup,
- confirm the cleanup
- Host the ZHPFIX.txt report on
https://www.cjoint.com/
Then copy/paste the provided link in your next response on the forum.
Tutorial at the bottom of this page:
https://nicolascoolman.eu
--
O.o°* ???Breathe deeply, write your message in good French and clearly. It will go well, you'll see, well we try !!! o°.Oø¤º°'°º¤ø -
-
Hello,
If you can't see it anymore,
but start the PC in normal mode,
send me a new Zhpdiag report via cjoint so we can see what remains!
--
O.o°* ???Breathe deeply, write your message in good French and clearly. It will be fine, you'll see, well we'll try!!! o°.Oø¤º°'°º¤ø
- 1
- 2
Next