5 responses
Ambucias
Posts
47310
Registration date
Monday February 1, 2010
Status
Moderator
Last seen
February 15, 2023
11,163
Apr 26, 2016 at 06:20 PM
Apr 26, 2016 at 06:20 PM
What is the make and model?
What is your operating system?
Can you boot in safe mode with networking ?
Explain: "click close its line oh well nobody like u and cclose everything
What is your operating system?
Can you boot in safe mode with networking ?
Explain: "click close its line oh well nobody like u and cclose everything
Ambucias
Posts
47310
Registration date
Monday February 1, 2010
Status
Moderator
Last seen
February 15, 2023
11,163
Apr 28, 2016 at 04:35 AM
Apr 28, 2016 at 04:35 AM
To help you and prescribe the remedy, I must make a diagnostic and to do so, I require a report.
1. Open this link and download ZHPDiag3 :
https://nicolascoolman.eu
(Don't be alarmed is the site is in French, it sometimes happens, the tool will take your system language and allow the download if you get a warning message, ignore it.) Click on the download button
2. Save the file on your Desktop.
3. Double click on ZHPDiag.exe and follow the installation instructions.
(For Vista, Win 7 and 8 users, click right to ensure you execute with admin right)
4. Double click on the short cut ZHPDiag on your Destktop.
5 Click on scan
Wait for the tool to finished (maybe a long time)
6. Close ZHPDiag.
7. To transmit the report, click on this link :
https://authentification.site
8. Search the directory where you installed ZHPDiag (usually C:\desktop\zhpdiag.txt).
9. Copy the url link obtained from Speedyshare and paste it here in your reply.
Ambucias
Moderator and Virus/Security Contributor
1. Open this link and download ZHPDiag3 :
https://nicolascoolman.eu
(Don't be alarmed is the site is in French, it sometimes happens, the tool will take your system language and allow the download if you get a warning message, ignore it.) Click on the download button
2. Save the file on your Desktop.
3. Double click on ZHPDiag.exe and follow the installation instructions.
(For Vista, Win 7 and 8 users, click right to ensure you execute with admin right)
4. Double click on the short cut ZHPDiag on your Destktop.
5 Click on scan
Wait for the tool to finished (maybe a long time)
6. Close ZHPDiag.
7. To transmit the report, click on this link :
https://authentification.site
8. Search the directory where you installed ZHPDiag (usually C:\desktop\zhpdiag.txt).
9. Copy the url link obtained from Speedyshare and paste it here in your reply.
Ambucias
Moderator and Virus/Security Contributor
Ambucias
Posts
47310
Registration date
Monday February 1, 2010
Status
Moderator
Last seen
February 15, 2023
11,163
>
Grimfrog
Apr 28, 2016 at 04:17 PM
Apr 28, 2016 at 04:17 PM
Okay, will catch you later
Grimfrog
>
Ambucias
Posts
47310
Registration date
Monday February 1, 2010
Status
Moderator
Last seen
February 15, 2023
Apr 29, 2016 at 05:48 PM
Apr 29, 2016 at 05:48 PM
Here is the link you requested
Link: http://speedy.sh/8YQFs/ZHPDiag3.exe
Link: http://speedy.sh/8YQFs/ZHPDiag3.exe
Ambucias
Posts
47310
Registration date
Monday February 1, 2010
Status
Moderator
Last seen
February 15, 2023
11,163
Apr 30, 2016 at 05:54 AM
Apr 30, 2016 at 05:54 AM
Thanks ! Your computer is infected. I will send you disinfection instructions.
Ambucias
Posts
47310
Registration date
Monday February 1, 2010
Status
Moderator
Last seen
February 15, 2023
11,163
Apr 30, 2016 at 06:48 AM
Apr 30, 2016 at 06:48 AM
Hi again,
You are using three antivirus software, they will come in conflict, let virus through and considerably slowdown your system. Delete or disable all but one. You have Malwarebyte, Norton, Windows Defender.
To remove the viruses on your machine as well as other superfluous files which will slowdown or bug your system:
1. Download ZHPFix here
https://nicolascoolman.eu
2. Select and copy all of the following bold lines.
Script ZHPFix
FirewallRaz
EmptyPrefetch
EmptyTemp
EmptyFlash
O23 - Service: Search Protect Service (CltMngSvc) . (...) - C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe (.not file.)
G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda]
O4 - HKCU\..\Run: [Weather] . (.AWS Convergence Technologies, Inc. - .) -- C:\Program Files (x86)\AWS\WeatherBug\Weather.exe
O4 - HKUS\S-1-5-21-1289048025-2900432012-1817540887-1000\..\Run: [Weather] . (.AWS Convergence Technologies, Inc. - .) -- C:\Program Files (x86)\AWS\WeatherBug\Weather.exe
O4 - GS\Quicklaunch [Administrator]: WeatherBug.lnk . (.AWS Convergence Technologies, Inc. - .) C:\Program Files (x86)\AWS\WeatherBug\Weather.exe
O4 - GS\Quicklaunch [Guest]: WeatherBug.lnk . (.AWS Convergence Technologies, Inc. - .) C:\Program Files (x86)\AWS\WeatherBug\Weather.exe
O4 - GS\Quicklaunch [Me]: WeatherBug.lnk . (.AWS Convergence Technologies, Inc. - .) C:\Program Files (x86)\AWS\WeatherBug\Weather.exe
O20 - AppInit_DLLs: . (...) - C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC64Loader.dll (.not file.)
O42 - Logiciel: GNotes Extension - (...) [HKLM][64Bits] -- {AD11DADE-C597-45D9-D8C5-1D2EB0B89613}
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
O42 - Logiciel: WeatherBug - (.Earth Networks, Inc..) [HKLM][64Bits] -- {297DCADA-86A1-4A42-8A13-66B7D7A09FD2}
O42 - Logiciel: youtubeadblocker - (...) [HKLM][64Bits] -- {4820778D-AB0D-6D18-C316-52A6A0E1D507}
HKLM\SOFTWARE\Wow6432Node\SecureWebChannel
3 - CFD: 22/03/2015 - [] D -- C:\Program Files (x86)\SalEEPolUs
3 - CFD: 22/03/2015 - [] D -- C:\Program Files (x86)\SAlePllUS
3 - CFD: 06/11/2015 - [] D -- C:\Users\Me\AppData\Roaming\RPEng
3 - CFD: 14/08/2014 - [] D -- C:\Users\Me\AppData\Roaming\WeatherBug
3 - CFD: 16/04/2016 - [] D -- C:\Users\Me\AppData\Local\WeatherBug
3 - CFD: 14/08/2014 - [] D -- C:\Users\Me\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WeatherBug
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ClearThink_RASAPI32
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ClearThink_RASMANCS
HKLM\SYSTEM\CurrentControlSet\Services\CltMngSvc
C:\Program Files (x86)\AWS\WeatherBug\Weather.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{297DCADA-86A1-4A42-8A13-66B7D7A09FD2}
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507}
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AD11DADE-C597-45D9-D8C5-1D2EB0B89613}
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{297DCADA-86A1-4A42-8A13-66B7D7A09FD2}
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507}
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{AD11DADE-C597-45D9-D8C5-1D2EB0B89613}
C:\Program Files (x86)\SalEEPolUs
C:\Program Files (x86)\SAlePllUS
C:\Users\Me\AppData\Roaming\RPEng
C:\Users\Me\AppData\Roaming\WeatherBug
C:\Users\Me\AppData\Local\WeatherBug
C:\Users\Me\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WeatherBug
O23 - Service: GamingWonderlandService (GamingWonderlandService) . (.Mindspark - Mindspark Toolbar Platform.) - C:\Program Files (x86)\GamingWonderland\bar\1.bin\gtbarsvc.exe
O23 - Service: PDFConverterHQService (PDFConverterHQ_fsService) . (.Mindspark - Mindspark Toolbar Platform.) - C:\Program Files (x86)\PDFConverterHQ_fs\bar\1.bin\fsbarsvc.exe
SS - Auto [14/03/2015] [ 90696] GamingWonderlandService (GamingWonderlandService) . (.Mindspark.) - C:\Program Files (x86)\GamingWonderland\bar\1.bin\gtbarsvc.exe
SS - Auto [14/12/2015] [ 89432] PDFConverterHQService (PDFConverterHQ_fsService) . (.Mindspark.) - C:\Program Files (x86)\PDFConverterHQ_fs\bar\1.bin\fsbarsvc.exe
R3 - URLSearchHook: (no name) - {a8625cb7-85fe-4936-92a4-b2a7c925209e} Orphean
R3 - URLSearchHook: (no name) - {3d9c838e-60a3-4b16-95b6-50bc3a0f0c6e} Orphean
O4 - HKLM\..\Wow6432Node\Run: [GamingWonderland EPM Support] . (.Mindspark - Mindspark Toolbar Platform.) -- C:\Program Files (x86)\GamingWonderland\bar\1.bin\gtmedint.exe
O4 - HKLM\..\Wow6432Node\Run: [GamingWonderland AppIntegrator 32-bit] . (.Mindspark - Mindspark Toolbar Platform.) -- C:\Program Files (x86)\GamingWonderland\bar\1.bin\AppIntegrator.exe
O4 - HKLM\..\Wow6432Node\Run: [GamingWonderland AppIntegrator 64-bit] . (.Mindspark - Mindspark Toolbar Platform.) -- C:\Program Files (x86)\GamingWonderland\bar\1.bin\AppIntegrator64.exe
O4 - HKLM\..\Wow6432Node\Run: [GamingWonderland Search Scope Monitor] C:\PROGRA~2\GAMING~2\bar\1.bin\gtsrchmn.exe (.not file.)
O42 - Logiciel: DriverUpdate - (.Slimware Utilities Holdings, Inc..) [HKLM][64Bits] -- {3B2D9BF5-A435-41C4-8118-F3D21A054F4D}
O42 - Logiciel: GamingWonderland Internet Explorer Toolbar - (.Mindspark Interactive Network.) [HKLM][64Bits] -- GamingWonderlandbar Uninstall Internet Explorer
O42 - Logiciel: PDFConverterHQ Internet Explorer Toolbar - (.Mindspark Interactive Network.) [HKLM][64Bits] -- PDFConverterHQ_fsbar Uninstall Internet Explorer
HKLM\SOFTWARE\Wow6432Node\SPPDCOM =>.Superfluous.PCSpeedUp
HKCU\SOFTWARE\WebApp
O43 - CFD: 19/03/2016 - [] D -- C:\Program Files (x86)\DriverUpdate
O43 - CFD: 14/03/2015 - [] D -- C:\Program Files (x86)\GamingWonderland
O43 - CFD: 19/03/2016 - [] D -- C:\Program Files (x86)\PDFConverterHQ_fs
O43 - CFD: 13/08/2014 - [0] D -- C:\Users\Me\AppData\Local\Programs\Common
O58 - SDL:2015/03/27 19:25:12 A . (...) -- C:\Windows\System32\drivers\SPPD.sys [21976]
O87 - FAEL: "{B5A6CE45-8D28-442A-892C-0266257687E7}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\Steam\bin\steamwebhelper.exe (.not file.)
O87 - FAEL: "{D7BF34A9-F9DE-41B7-8AAB-2914E6E9428A}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\Steam\bin\steamwebhelper.exe (.not file.)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GamingWonderlandbar Uninstall Internet Explorer
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PDFConverterHQ_fsbar Uninstall Internet Explorer
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3B2D9BF5-A435-41C4-8118-F3D21A054F4D} =>.Superfluous.SlimWareUtilities
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\GamingWonderlandbar Uninstall Internet Explorer
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\PDFConverterHQ_fsbar Uninstall Internet Explorer
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{3B2D9BF5-A435-41C4-8118-F3D21A054F4D}
HKLM\SOFTWARE\Wow6432Node\SPPDCOM =>.Superfluous.PCSpeedUp
HKCU\SOFTWARE\WebApp
3 Close all applications and open ZHP Fix
4. Click on the Import button and the lines will automatically paste themselves.
5. Click on the Go button to clean
6. Confirm by clicking OK
7. ZHP Fix may ask if you wish to empty the bin, click on your choice...it may take time
8. A report will appear on your desktop and on C:\ZHP\ZHPFix[R1].txt which you can copy and paste in your reply.
Good luck
You are using three antivirus software, they will come in conflict, let virus through and considerably slowdown your system. Delete or disable all but one. You have Malwarebyte, Norton, Windows Defender.
To remove the viruses on your machine as well as other superfluous files which will slowdown or bug your system:
1. Download ZHPFix here
https://nicolascoolman.eu
2. Select and copy all of the following bold lines.
Script ZHPFix
FirewallRaz
EmptyPrefetch
EmptyTemp
EmptyFlash
O23 - Service: Search Protect Service (CltMngSvc) . (...) - C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe (.not file.)
G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda]
O4 - HKCU\..\Run: [Weather] . (.AWS Convergence Technologies, Inc. - .) -- C:\Program Files (x86)\AWS\WeatherBug\Weather.exe
O4 - HKUS\S-1-5-21-1289048025-2900432012-1817540887-1000\..\Run: [Weather] . (.AWS Convergence Technologies, Inc. - .) -- C:\Program Files (x86)\AWS\WeatherBug\Weather.exe
O4 - GS\Quicklaunch [Administrator]: WeatherBug.lnk . (.AWS Convergence Technologies, Inc. - .) C:\Program Files (x86)\AWS\WeatherBug\Weather.exe
O4 - GS\Quicklaunch [Guest]: WeatherBug.lnk . (.AWS Convergence Technologies, Inc. - .) C:\Program Files (x86)\AWS\WeatherBug\Weather.exe
O4 - GS\Quicklaunch [Me]: WeatherBug.lnk . (.AWS Convergence Technologies, Inc. - .) C:\Program Files (x86)\AWS\WeatherBug\Weather.exe
O20 - AppInit_DLLs: . (...) - C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC64Loader.dll (.not file.)
O42 - Logiciel: GNotes Extension - (...) [HKLM][64Bits] -- {AD11DADE-C597-45D9-D8C5-1D2EB0B89613}
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
O42 - Logiciel: WeatherBug - (.Earth Networks, Inc..) [HKLM][64Bits] -- {297DCADA-86A1-4A42-8A13-66B7D7A09FD2}
O42 - Logiciel: youtubeadblocker - (...) [HKLM][64Bits] -- {4820778D-AB0D-6D18-C316-52A6A0E1D507}
HKLM\SOFTWARE\Wow6432Node\SecureWebChannel
3 - CFD: 22/03/2015 - [] D -- C:\Program Files (x86)\SalEEPolUs
3 - CFD: 22/03/2015 - [] D -- C:\Program Files (x86)\SAlePllUS
3 - CFD: 06/11/2015 - [] D -- C:\Users\Me\AppData\Roaming\RPEng
3 - CFD: 14/08/2014 - [] D -- C:\Users\Me\AppData\Roaming\WeatherBug
3 - CFD: 16/04/2016 - [] D -- C:\Users\Me\AppData\Local\WeatherBug
3 - CFD: 14/08/2014 - [] D -- C:\Users\Me\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WeatherBug
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ClearThink_RASAPI32
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ClearThink_RASMANCS
HKLM\SYSTEM\CurrentControlSet\Services\CltMngSvc
C:\Program Files (x86)\AWS\WeatherBug\Weather.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{297DCADA-86A1-4A42-8A13-66B7D7A09FD2}
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507}
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AD11DADE-C597-45D9-D8C5-1D2EB0B89613}
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{297DCADA-86A1-4A42-8A13-66B7D7A09FD2}
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507}
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{AD11DADE-C597-45D9-D8C5-1D2EB0B89613}
C:\Program Files (x86)\SalEEPolUs
C:\Program Files (x86)\SAlePllUS
C:\Users\Me\AppData\Roaming\RPEng
C:\Users\Me\AppData\Roaming\WeatherBug
C:\Users\Me\AppData\Local\WeatherBug
C:\Users\Me\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WeatherBug
O23 - Service: GamingWonderlandService (GamingWonderlandService) . (.Mindspark - Mindspark Toolbar Platform.) - C:\Program Files (x86)\GamingWonderland\bar\1.bin\gtbarsvc.exe
O23 - Service: PDFConverterHQService (PDFConverterHQ_fsService) . (.Mindspark - Mindspark Toolbar Platform.) - C:\Program Files (x86)\PDFConverterHQ_fs\bar\1.bin\fsbarsvc.exe
SS - Auto [14/03/2015] [ 90696] GamingWonderlandService (GamingWonderlandService) . (.Mindspark.) - C:\Program Files (x86)\GamingWonderland\bar\1.bin\gtbarsvc.exe
SS - Auto [14/12/2015] [ 89432] PDFConverterHQService (PDFConverterHQ_fsService) . (.Mindspark.) - C:\Program Files (x86)\PDFConverterHQ_fs\bar\1.bin\fsbarsvc.exe
R3 - URLSearchHook: (no name) - {a8625cb7-85fe-4936-92a4-b2a7c925209e} Orphean
R3 - URLSearchHook: (no name) - {3d9c838e-60a3-4b16-95b6-50bc3a0f0c6e} Orphean
O4 - HKLM\..\Wow6432Node\Run: [GamingWonderland EPM Support] . (.Mindspark - Mindspark Toolbar Platform.) -- C:\Program Files (x86)\GamingWonderland\bar\1.bin\gtmedint.exe
O4 - HKLM\..\Wow6432Node\Run: [GamingWonderland AppIntegrator 32-bit] . (.Mindspark - Mindspark Toolbar Platform.) -- C:\Program Files (x86)\GamingWonderland\bar\1.bin\AppIntegrator.exe
O4 - HKLM\..\Wow6432Node\Run: [GamingWonderland AppIntegrator 64-bit] . (.Mindspark - Mindspark Toolbar Platform.) -- C:\Program Files (x86)\GamingWonderland\bar\1.bin\AppIntegrator64.exe
O4 - HKLM\..\Wow6432Node\Run: [GamingWonderland Search Scope Monitor] C:\PROGRA~2\GAMING~2\bar\1.bin\gtsrchmn.exe (.not file.)
O42 - Logiciel: DriverUpdate - (.Slimware Utilities Holdings, Inc..) [HKLM][64Bits] -- {3B2D9BF5-A435-41C4-8118-F3D21A054F4D}
O42 - Logiciel: GamingWonderland Internet Explorer Toolbar - (.Mindspark Interactive Network.) [HKLM][64Bits] -- GamingWonderlandbar Uninstall Internet Explorer
O42 - Logiciel: PDFConverterHQ Internet Explorer Toolbar - (.Mindspark Interactive Network.) [HKLM][64Bits] -- PDFConverterHQ_fsbar Uninstall Internet Explorer
HKLM\SOFTWARE\Wow6432Node\SPPDCOM =>.Superfluous.PCSpeedUp
HKCU\SOFTWARE\WebApp
O43 - CFD: 19/03/2016 - [] D -- C:\Program Files (x86)\DriverUpdate
O43 - CFD: 14/03/2015 - [] D -- C:\Program Files (x86)\GamingWonderland
O43 - CFD: 19/03/2016 - [] D -- C:\Program Files (x86)\PDFConverterHQ_fs
O43 - CFD: 13/08/2014 - [0] D -- C:\Users\Me\AppData\Local\Programs\Common
O58 - SDL:2015/03/27 19:25:12 A . (...) -- C:\Windows\System32\drivers\SPPD.sys [21976]
O87 - FAEL: "{B5A6CE45-8D28-442A-892C-0266257687E7}" [In-None-P6-TRUE] .(...) -- C:\Program Files (x86)\Steam\bin\steamwebhelper.exe (.not file.)
O87 - FAEL: "{D7BF34A9-F9DE-41B7-8AAB-2914E6E9428A}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\Steam\bin\steamwebhelper.exe (.not file.)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GamingWonderlandbar Uninstall Internet Explorer
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PDFConverterHQ_fsbar Uninstall Internet Explorer
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3B2D9BF5-A435-41C4-8118-F3D21A054F4D} =>.Superfluous.SlimWareUtilities
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\GamingWonderlandbar Uninstall Internet Explorer
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\PDFConverterHQ_fsbar Uninstall Internet Explorer
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{3B2D9BF5-A435-41C4-8118-F3D21A054F4D}
HKLM\SOFTWARE\Wow6432Node\SPPDCOM =>.Superfluous.PCSpeedUp
HKCU\SOFTWARE\WebApp
3 Close all applications and open ZHP Fix
4. Click on the Import button and the lines will automatically paste themselves.
5. Click on the Go button to clean
6. Confirm by clicking OK
7. ZHP Fix may ask if you wish to empty the bin, click on your choice...it may take time
8. A report will appear on your desktop and on C:\ZHP\ZHPFix[R1].txt which you can copy and paste in your reply.
Good luck
is this the right thing
TXT FILE: Rapport de ZHPFix 2015.10.19.9 par Nicolas Coolman, Update du 19/10/2015
Fichier d'export Registre :
Run by Me at 4/30/2016 6:47:15 AM
High Elevated Privileges : OK
Windows 7 Home Premium Edition, 64-bit Service Pack 1 (Build 7601)
Recycle Bin emptied (08mn AMs)
Prefetcher emptied
========== Software ==========
ABSENT Uninstall Process: c:\program files (x86)\gnotes extension\gnotes extension.exe
REMOVES: Google Update Helper
REMOVES: WeatherBug
ABSENT Uninstall Process: c:\program files (x86)\youtubeadblocker\htni5jze36q1yx.exe
REMOVES: DriverUpdate
REMOVES: GamingWonderland Internet Explorer Toolbar
REMOVES: PDFConverterHQ Internet Explorer Toolbar
========== Registry keys ==========
REMOVES Logiciel Key: [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{AD11DADE-C597-45D9-D8C5-1D2EB0B89613}]
REMOVES: [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}]
REMOVES: [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{297DCADA-86A1-4A42-8A13-66B7D7A09FD2}]
REMOVES Logiciel Key: [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507}]
REMOVES: [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{3B2D9BF5-A435-41C4-8118-F3D21A054F4D}]
REMOVES: [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\GamingWonderlandbar Uninstall Internet Explorer]
REMOVES: [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\PDFConverterHQ_fsbar Uninstall Internet Explorer]
REMOVES: Service: CltMngSvc
REMOVES: HKLM\SOFTWARE\Wow6432Node\SecureWebChannel
REMOVES: HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ClearThink_RASAPI32
REMOVES: HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ClearThink_RASMANCS
REMOVES: Service: GamingWonderlandService
REMOVES: Service: PDFConverterHQ_fsService
REMOVES: HKLM\SOFTWARE\Wow6432Node\SPPDCOM
REMOVES: HKCU\SOFTWARE\WebApp
========== Registry values ==========
ABSENT value Standard Profile: FirewallRaz :
ABSENT value Domain Profile: FirewallRaz :
REMOVES: FirewallRaz (Private) : TCP Query User{3CB742E1-32C5-4A94-B121-021280BBAED3}C:\program files (x86)\java\jre7\bin\javaw.exe
REMOVES: FirewallRaz (Private) : UDP Query User{FC5254E3-10B0-49D0-A547-4DA6EC6A9F5F}C:\program files (x86)\java\jre7\bin\javaw.exe
REMOVES: FirewallRaz (Domain) : {7C596285-AA11-4B02-A4FF-60C5935F421B}
REMOVES: FirewallRaz (Domain) : {61579975-8A97-4D65-AE34-622F82A239BB}
REMOVES: FirewallRaz (Domain) : {B5A6CE45-8D28-442A-892C-0266257687E7}
REMOVES: FirewallRaz (Domain) : {D7BF34A9-F9DE-41B7-8AAB-2914E6E9428A}
REMOVES: FirewallRaz (Private) : TCP Query User{CFB06A7F-14DD-437C-80E6-9FFEC140CCE4}C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe
REMOVES: FirewallRaz (Private) : UDP Query User{F46DE5BD-BFF7-45A5-AC8F-BE6AFA3E7E2E}C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe
REMOVES RunValue: Weather
REMOVES: URLSearchHook: {a8625cb7-85fe-4936-92a4-b2a7c925209e}
REMOVES: URLSearchHook: {3d9c838e-60a3-4b16-95b6-50bc3a0f0c6e}
REMOVES RunValue: GamingWonderland EPM Support
REMOVES RunValue: GamingWonderland AppIntegrator 32-bit
REMOVES RunValue: GamingWonderland AppIntegrator 64-bit
REMOVES RunValue: GamingWonderland Search Scope Monitor
========== Elements of the registry data ==========
REMOVES AppInit: \PROGRA~2\SearchProtect\SearchProtect\bin\VC64Loader.dll
========== Folders ==========
Deletes temporary Windows (17)
REMOVES Flash Cookies (0)
REMOVES: c:\program files (x86)\saleepolus
REMOVES: c:\program files (x86)\salepllus
REMOVES: c:\users\me\appdata\roaming\rpeng
REMOVES: c:\users\me\appdata\roaming\weatherbug
REMOVES: c:\users\me\appdata\local\weatherbug
REMOVES: c:\users\me\appdata\roaming\microsoft\windows\start menu\programs\weatherbug
REMOVES: C:\Program Files (x86)\DriverUpdate
REMOVES: C:\Program Files (x86)\GamingWonderland
REMOVES: C:\Program Files (x86)\PDFConverterHQ_fs
REMOVES: C:\Users\Me\AppData\Local\Programs\Common
========== Files ==========
Deletes temporary Windows (57) (11,943,856 octets)
REMOVES Flash Cookies (0) (0 octets)
REMOVES: c:\program files (x86)\aws\weatherbug\weather.exe
REMOVES Reboot: c:\windows\system32\drivers\sppd.sys
========== Other ==========
NON-TREATY 3 - CFD: 22/03/2015 - [] D -- C:\Program Files (x86)\SalEEPolUs
NON-TREATY 3 - CFD: 22/03/2015 - [] D -- C:\Program Files (x86)\SAlePllUS
NON-TREATY 3 - CFD: 06/11/2015 - [] D -- C:\Users\Me\AppData\Roaming\RPEng
NON-TREATY 3 - CFD: 14/08/2014 - [] D -- C:\Users\Me\AppData\Roaming\WeatherBug
NON-TREATY 3 - CFD: 16/04/2016 - [] D -- C:\Users\Me\AppData\Local\WeatherBug
NON-TREATY 3 - CFD: 14/08/2014 - [] D -- C:\Users\Me\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WeatherBug
========== Summary ==========
15 : Registry keys
17 : Registry values
1 : Elements of the registry data
12 : Folders
4 : Files
7 : Software
6 : Other
End of clean in 32mn AMs
========== Path to file report ==========
C:\Users\Me\AppData\Roaming\ZHP\ZHPFix[R1].txt - 4/30/2016 6:47:25 AM [5080]
TXT FILE: Rapport de ZHPFix 2015.10.19.9 par Nicolas Coolman, Update du 19/10/2015
Fichier d'export Registre :
Run by Me at 4/30/2016 6:47:15 AM
High Elevated Privileges : OK
Windows 7 Home Premium Edition, 64-bit Service Pack 1 (Build 7601)
Recycle Bin emptied (08mn AMs)
Prefetcher emptied
========== Software ==========
ABSENT Uninstall Process: c:\program files (x86)\gnotes extension\gnotes extension.exe
REMOVES: Google Update Helper
REMOVES: WeatherBug
ABSENT Uninstall Process: c:\program files (x86)\youtubeadblocker\htni5jze36q1yx.exe
REMOVES: DriverUpdate
REMOVES: GamingWonderland Internet Explorer Toolbar
REMOVES: PDFConverterHQ Internet Explorer Toolbar
========== Registry keys ==========
REMOVES Logiciel Key: [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{AD11DADE-C597-45D9-D8C5-1D2EB0B89613}]
REMOVES: [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}]
REMOVES: [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{297DCADA-86A1-4A42-8A13-66B7D7A09FD2}]
REMOVES Logiciel Key: [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507}]
REMOVES: [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{3B2D9BF5-A435-41C4-8118-F3D21A054F4D}]
REMOVES: [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\GamingWonderlandbar Uninstall Internet Explorer]
REMOVES: [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\PDFConverterHQ_fsbar Uninstall Internet Explorer]
REMOVES: Service: CltMngSvc
REMOVES: HKLM\SOFTWARE\Wow6432Node\SecureWebChannel
REMOVES: HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ClearThink_RASAPI32
REMOVES: HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ClearThink_RASMANCS
REMOVES: Service: GamingWonderlandService
REMOVES: Service: PDFConverterHQ_fsService
REMOVES: HKLM\SOFTWARE\Wow6432Node\SPPDCOM
REMOVES: HKCU\SOFTWARE\WebApp
========== Registry values ==========
ABSENT value Standard Profile: FirewallRaz :
ABSENT value Domain Profile: FirewallRaz :
REMOVES: FirewallRaz (Private) : TCP Query User{3CB742E1-32C5-4A94-B121-021280BBAED3}C:\program files (x86)\java\jre7\bin\javaw.exe
REMOVES: FirewallRaz (Private) : UDP Query User{FC5254E3-10B0-49D0-A547-4DA6EC6A9F5F}C:\program files (x86)\java\jre7\bin\javaw.exe
REMOVES: FirewallRaz (Domain) : {7C596285-AA11-4B02-A4FF-60C5935F421B}
REMOVES: FirewallRaz (Domain) : {61579975-8A97-4D65-AE34-622F82A239BB}
REMOVES: FirewallRaz (Domain) : {B5A6CE45-8D28-442A-892C-0266257687E7}
REMOVES: FirewallRaz (Domain) : {D7BF34A9-F9DE-41B7-8AAB-2914E6E9428A}
REMOVES: FirewallRaz (Private) : TCP Query User{CFB06A7F-14DD-437C-80E6-9FFEC140CCE4}C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe
REMOVES: FirewallRaz (Private) : UDP Query User{F46DE5BD-BFF7-45A5-AC8F-BE6AFA3E7E2E}C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe
REMOVES RunValue: Weather
REMOVES: URLSearchHook: {a8625cb7-85fe-4936-92a4-b2a7c925209e}
REMOVES: URLSearchHook: {3d9c838e-60a3-4b16-95b6-50bc3a0f0c6e}
REMOVES RunValue: GamingWonderland EPM Support
REMOVES RunValue: GamingWonderland AppIntegrator 32-bit
REMOVES RunValue: GamingWonderland AppIntegrator 64-bit
REMOVES RunValue: GamingWonderland Search Scope Monitor
========== Elements of the registry data ==========
REMOVES AppInit: \PROGRA~2\SearchProtect\SearchProtect\bin\VC64Loader.dll
========== Folders ==========
Deletes temporary Windows (17)
REMOVES Flash Cookies (0)
REMOVES: c:\program files (x86)\saleepolus
REMOVES: c:\program files (x86)\salepllus
REMOVES: c:\users\me\appdata\roaming\rpeng
REMOVES: c:\users\me\appdata\roaming\weatherbug
REMOVES: c:\users\me\appdata\local\weatherbug
REMOVES: c:\users\me\appdata\roaming\microsoft\windows\start menu\programs\weatherbug
REMOVES: C:\Program Files (x86)\DriverUpdate
REMOVES: C:\Program Files (x86)\GamingWonderland
REMOVES: C:\Program Files (x86)\PDFConverterHQ_fs
REMOVES: C:\Users\Me\AppData\Local\Programs\Common
========== Files ==========
Deletes temporary Windows (57) (11,943,856 octets)
REMOVES Flash Cookies (0) (0 octets)
REMOVES: c:\program files (x86)\aws\weatherbug\weather.exe
REMOVES Reboot: c:\windows\system32\drivers\sppd.sys
========== Other ==========
NON-TREATY 3 - CFD: 22/03/2015 - [] D -- C:\Program Files (x86)\SalEEPolUs
NON-TREATY 3 - CFD: 22/03/2015 - [] D -- C:\Program Files (x86)\SAlePllUS
NON-TREATY 3 - CFD: 06/11/2015 - [] D -- C:\Users\Me\AppData\Roaming\RPEng
NON-TREATY 3 - CFD: 14/08/2014 - [] D -- C:\Users\Me\AppData\Roaming\WeatherBug
NON-TREATY 3 - CFD: 16/04/2016 - [] D -- C:\Users\Me\AppData\Local\WeatherBug
NON-TREATY 3 - CFD: 14/08/2014 - [] D -- C:\Users\Me\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WeatherBug
========== Summary ==========
15 : Registry keys
17 : Registry values
1 : Elements of the registry data
12 : Folders
4 : Files
7 : Software
6 : Other
End of clean in 32mn AMs
========== Path to file report ==========
C:\Users\Me\AppData\Roaming\ZHP\ZHPFix[R1].txt - 4/30/2016 6:47:25 AM [5080]
Didn't find the answer you are looking for?
Ask a question
Ambucias
Posts
47310
Registration date
Monday February 1, 2010
Status
Moderator
Last seen
February 15, 2023
11,163
Apr 30, 2016 at 04:36 PM
Apr 30, 2016 at 04:36 PM
Yes it is the right thing.
Now, please
1. download and run:
https://ccm.net/downloads/security-and-maintenance/6911-adwcleaner/
2. Download and install:
https://ccm.net/downloads/security-and-maintenance/4555-ccleaner/
When installing please uncheck installing McAfee Virus scan
3. Run Ccleaner to delete all of your junk files
4. Run CCleaner registry cleaning tool
5. Defragment your hard drive. (This may take long, you can read Tolstoy's "War and Peace" or watch a rerun of Gone with the Wind.) Do not allow your machine to go to sleep as it may stop the processing.
Once you have completed the above, tell me if your computer runs better in normal mode. If you still have a glitch, I will require a new ZHP Diag report.
Now, please
1. download and run:
https://ccm.net/downloads/security-and-maintenance/6911-adwcleaner/
2. Download and install:
https://ccm.net/downloads/security-and-maintenance/4555-ccleaner/
When installing please uncheck installing McAfee Virus scan
3. Run Ccleaner to delete all of your junk files
4. Run CCleaner registry cleaning tool
5. Defragment your hard drive. (This may take long, you can read Tolstoy's "War and Peace" or watch a rerun of Gone with the Wind.) Do not allow your machine to go to sleep as it may stop the processing.
Once you have completed the above, tell me if your computer runs better in normal mode. If you still have a glitch, I will require a new ZHP Diag report.
ok so it gave me internet acess in normal mode for a little bit but then the computer crashed, then when I turned it back on I lost internet again and it freezes up but doesn't do that thing where it says it has stopped responding when nothing is open and takes away everything but my background I have to go bowling with some friends I promised tonight but tomorrow ill check the computer one last time in normal mode and if it doesn't work ill give you a new ZHP Diag report
Apr 27, 2016 at 06:29 PM