How to uninstall "Baidu"???

Solved
Hello,
Help, please
I have the same problem

Configuration: Windows 7 / Chrome 45.0.2453.0

36 answers

  1. Security Contributor
    Hello,
    Congratulations on this interesting topic ... and resolved.
    I also followed at Nicolas's. ;)
    Albert

    --
    Patience-Vigilance-Love.
    0
    1. :-)

      --
      O.o°* ???Breathe deeply, write your message in proper French and clearly. It will be fine, you’ll see, well we’ll try!!! o°.Oø¤º°'°º¤ø
      0
      1. Hello Electrician 69,

        could you help me because I'm facing the same problem.

        Thank you
        0
    2. A big THANK YOU for your help.
      0
      1. it's just a report, it changed places :P

        know that Delfix has created a new restore point, it might come in handy just in case :-)

        on that note, happy surfing ;-)

        --
        O.o°* ???Breathe deeply, write your message in proper French and clearly. it's going to be fine, you'll see, well we're trying!!! o°.Oø¤º°'°º¤ø
        0
        1. ok,

          we're finishing up:

          Download Delfix to your desktop:

          https://toolslib.net/downloads/viewdownload/2-delfix/

          or

          Check the following boxes:
          => Remove disinfecting tools (checked by default)
          => Purge system restore
          • Then click on Run and wait during the removal process.
          • When the procedures are completed, the tool will close and disappear from the desktop.
          • A report is saved to the clipboard: you just need to right-click and "paste" in your next reply to send me the report
            • the report is stored at this location: C:\DelFix.txt

          Warning: The report is unique and is deleted each time we re-run one or more options of DelFix.

          Note:
          Delfix does not uninstall MBAM, it's up to you to decide if you want to keep it or uninstall it.

          --
          O.o°* ???Breathe deeply, write your message in proper French and clearly. It'll be alright, you'll see, well we're trying !!! o°.Oø¤º°'°º¤ø
          0
          1. Here it is,
            Programs - ok
            Processes - ok
            I only see the files in ADW Quarantine
            0
            1. If you can no longer see it in the list of programs, nor in the processes, it means we've got it!

              Restart the PC to see,
              if there are no traces, we'll uninstall the tools, etc. etc. :-)

              --
              O.o°*??? Breathe deeply, write your message in proper French and clearly. It's going to be okay, you'll see, at least we'll try!!! o°.Oø¤º°'°º¤ø
              0
              1. It's always the same, the same message...
                If it's a ghost file, can we say the problem is solved?
                0
                1. try again to paste the script in the window to see,

                  we might be looking for a ghost file!

                  --
                  O.o°* ???Breathe deeply, write your message in proper French and clearly. It will be fine, you'll see, well we're trying!!! o°.Oø¤º°'°º¤ø
                  0
                  1. In the report, it presents itself as a plugin in Mozilla Firefox!
                    For the driver, it has become inactive!

                    Do you really want us to try to get rid of it?
                    Download The Avenger by Swandog46 to your Desktop:

                    http://www.geekstogo.com/forum/files/file/393-the-avenger-by-swandog46/

                    Click on Avenger.zip to open the file
                    Extract avenger.exe to your desktop

                    Now, launch The Avenger by clicking on its desktop icon

                    /!\ Vista and Seven users, right-click and run as administrator

                    Copy all the text in bold below: highlight it and press the keys (Ctrl+C):

                    Drivers to disable:
                    BDMNetMon.sys
                    Drivers to delete:
                    BDMNetMon.sys
                    Files to delete:
                    C:\Windows\System32\drivers\BDMNetMon.sys


                    Paste this text (Ctrl+V) into the box: Input script here

                    Press Execute

                    The PC will restart
                    If the report does not appear, it is located in C:\ avenger
                    Tutorial:
                    http://www.oxygenepc.com/forum/the-avenger-t594.html

                    --
                    O.o°* ???Breathe deeply, write your message in proper French and clearly. It’s going to be okay, you’ll see, well, we’ll try!!! o°.Oø¤º°'°º¤ø
                    0
                    1. At startup, nothing in Chinese anymore since the removal in safe mode by Revo Pro
                      Browser - ok
                      - AdwCleaner - 0 items
                      - Malwarebytes - 0 items
                      - Revo Pro - does not detect any remaining files

                      But it is still in the report
                      https://www.cjoint.com/c/EGquUA8NmD1

                      Thank you
                      0
                      1. ok,

                        restart the PC one more time and let me know if you see it

                        we'll finish by uninstalling the tools afterwards

                        --
                        O.o°* ???Breathe deeply, write your message in good French and clearly. It will be fine, you'll see, well, let's try!!! o°.Oø¤º°'°º¤ø
                        0
                        1. Here is
                          https://www.cjoint.com/c/EGqt71BXvn1

                          I can't find it in the path indicated in the report; and Revo doesn't detect it either...
                          C:\Program Files (x86)\Baidu\BaiduSd\4.0.0.6697\explugin\npBaiduSDDetectPlug.dll
                          0
                          1. the plugin and driver are still there,

                            restart the pc

                            run a new Zhpdiag afterwards to see

                            --
                            O.o°* ???Breathe deeply, write your message clearly and in good French. It will be fine, you'll see, well we're trying!!! o°.Oø¤º°'°º¤ø
                            0
                            1. /!\ Warning /!\, </li> this script is only valid for this PC, during the cleanup, do not use it on another PC, risk of crashing! </li></ul> Launch ZHPFix via the shortcut on your Desktop, the icon looks like a syringe.

                              Click on "import"

                              You will see a warning message, click OK.

                              Open this document and copy and paste the entire content into the Zhpfix window:
                              • * Copy (Ctrl + C) and paste (Ctrl + V) the following bold lines into the Zhpfix window:

                              ---------------------------------------------------------

                              Zhpfix Script
                              P2 - FPN: [HKLM] [@baidu.com/BaidusdDetectNPPlugin] - (.BeiJing Baidu Netcom Science Technology Co., Ltd.) -- C:\Program Files (x86)\Baidu\BaiduSd\4.0.0.6697\explugin\npBaiduSDDetectPlug.dll
                              P2 - FPN: [HKLM] [@qq.com/npAndroidAssistant] - (.Tencent, Inc..) -- C:\Program Files (x86)\Common Files\Tencent\QQPhoneManager\2.0.201.3198\npQQPhoneManagerExt.dll
                              P2 - FPN: [HKLM] [@qq.com/QQPCMgr] - (.Tencent.) -- C:\Program Files (x86)\Tencent\QQPCMgr\10.10.16434.218\npQMExtensionsMozilla.dll
                              O2 - BHO: WebGuard BHO Class [64Bits] - {1B2639A9-EE25-4AE7-A2E3-B308F08125C4} (Orphean)
                              O2 - BHO: (no name) [64Bits] - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} (Orphean)
                              O2 - BHO: (no name) [64Bits] - {9030D464-4C02-4ABF-8ECC-5164760863C6} (Orphean)
                              O23 - Service: 10809 (10809) . (...) - C:\Windows\temp\10809 (.not file.)
                              O42 - Software: Íýíñè Äðþ. Ïëàòüå äëÿ ïåðâîé ëåäè - (...) [HKLM][64Bits] -- Íýíñè Äðþ. Ïëàòüå äëÿ ïåðâîé ëåäè_is1
                              O42 - Software: Íýíñè Äðþ. Ñåêðåò ñòàðèííûõ ÷àñîâ - (...) [HKLM][64Bits] -- Íýíñè Äðþ. Ñåêðåò ñòàðèííûõ ÷àñîâ_is1
                              O42 - Software: Íýíñè Äðþ. Ñåêðåòû ìîãóò óáèâàòü - (...) [HKLM][64Bits] -- Íýíñè Äðþ. Ñåêðåòû ìîãóò óáèâàòü_is1
                              O42 - Software: Íýíñè Äðþ. Ñîêðîâèùå êîðîëåâñêîé áàøíè - (...) [HKLM][64Bits] -- Íýíñè Äðþ. Ñîêðîâèùå êîðîëåâñêîé áàøíè_is1
                              O42 - Software: Íýíñè Äðþ. Òàéíà àëîé ðóêè - (...) [HKLM][64Bits] -- Íýíñè Äðþ. Òàéíà àëîé ðóêè_is1
                              O42 - Software: À-Ç-Î-Â (v.1.0) - (...) [HKLM][64Bits] -- ÒÉ: À-Ç-Î-Â_is1
                              O42 - Software: Àñòðàëüíàÿ Ïðîåêöèÿ (v.1.1) - (...) [HKLM][64Bits] -- ÒÉ: Àñòðàëüíàÿ Ïðîåêöèÿ_is1
                              O42 - Software: Ìãíîâåííàÿ Ýâîëþöèÿ (v.1.2) - (...) [HKLM][64Bits] -- ÒÉ: Ìãíîâåííàÿ Ýâîëþöèÿ_is1
                              O42 - Software: Ìåäèòàöèÿ íà ÎÌ (v.1.1) - (...) [HKLM][64Bits] -- ÒÉ: Ìåäèòàöèÿ íà ÎÌ_is1
                              O42 - Software: Ðàçâèòèå ñèñòåìû ÷àêð (v.1.1) - (...) [HKLM][64Bits] -- ÒÉ: Ðàçâèòèå ñèñòåìû ÷àêð_is1
                              O43 - CFD: 2015/07/12 22:51:06 - [] D -- C:\Program Files (x86)\Common Files\Baidu
                              O58 - SDL:2015/04/03 07:02:20 A . (.Baidu - Network Monitor.) -- C:\Windows\System32\drivers\BDMNetMon.sys [241992]
                              Proxyfix
                              Firewallraz
                              EmptyPrefetch
                              ShortcutFix
                              Emptytemp
                              EmptyClsid


                              ----------------------------------------------------------
                              - Click the "GO" button to start the cleanup,
                              - confirm the cleanup
                              - Host the ZHPFIX.txt report on
                              https://www.cjoint.com/

                              Then copy/paste the provided link in your next response on the forum.

                              Tutorial at the bottom of this page:
                              https://nicolascoolman.eu

                              --
                              O.o°* ???Breathe deeply, write your message in good French and clearly. It will go well, you'll see, well we try !!! o°.Oø¤º°'°º¤ø
                              0
                              1. Hello,

                                If you can't see it anymore,

                                but start the PC in normal mode,

                                send me a new Zhpdiag report via cjoint so we can see what remains!

                                --
                                O.o°* ???Breathe deeply, write your message in good French and clearly. It will be fine, you'll see, well we'll try!!! o°.Oø¤º°'°º¤ø
                                0
                                • 1
                                • 2