Hello,

Firsttime user and newby.

Attaching the logfile image.

I'd need the help.

Thanks

 

Re: I'm not sure what to clean/remove.

Hi Chapi

Sorry about my confusing words, here's the ZHFixReport (1):

Script ZHPFix P2 - EXT FILE: (...) -- C:\Users\My Computer\AppData\Roaming\Mozilla\Firefox\Profiles\8kyk8yzd.default-1436897542862\extensions\jid1-ZAdIEUB7XOzOJw@jetpack.xpi HKCU\SOFTWARE\AppDataLow\Software\arcadeparlorconfig O43 - CFD: 15/03/2015 - [] D -- C:\ProgramData\{65AB91D4-DDD0-48D4-804D-C24E1FC90D44} HKCU\SOFTWARE\DriverSupport O43 - CFD: 21/11/2015 - [] D -- C:\ProgramData\ProductData O43 - CFD: 28/01/2014 - [] D -- C:\Users\My Computer\AppData\Roaming\ProductData O42 - Logiciel: Kaspersky Security Scan - (.Kaspersky Lab.) [HKLM][64Bits] -- {56009CA3-423B-41F8-884A-E5B049534F15} O2 - BHO: ExplorerWnd Helper [64Bits] - {10921475-03CE-4E04-90CE-E2E7EF20C814}  (Orphean) HKLM\SOFTWARE\Wow6432Node\Safer Networking Limited HKCU\SOFTWARE\Safer Networking Limited O43 - CFD: 08/03/2015 - [] D -- C:\Program Files (x86)\Spybot - Search & Destroy O53 - SMSR:HKLM\...\startupreg\SpybotSD TeaTimer  [Key] . (...) -- c:\program files (x86)\spybot - search & destroy\teatimer.exe (.not file.) HKLM\SOFTWARE\Wow6432Node\Eset HKLM\SOFTWARE\Wow6432Node\SpywareBlaster HKCU\SOFTWARE\MCAFEE O43 - CFD: 17/08/2014 - [0] D -- C:\Program Files (x86)\McAfee O43 - CFD: 22/11/2015 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpywareBlaster O43 - CFD: 17/08/2014 - [] D -- C:\ProgramData\McAfee FirewallRaz EmptyPrefetch EmptyTemp EmptyFlash

Dowlnoaded a fresh copy again of ZhpFix and this the report (2):

Script ZHPFix P2 - EXT FILE: (...) -- C:\Users\My Computer\AppData\Roaming\Mozilla\Firefox\Profiles\8kyk8yzd.default-1436897542862\extensions\jid1-ZAdIEUB7XOzOJw@jetpack.xpi HKCU\SOFTWARE\AppDataLow\Software\arcadeparlorconfig O43 - CFD: 15/03/2015 - [] D -- C:\ProgramData\{65AB91D4-DDD0-48D4-804D-C24E1FC90D44} HKCU\SOFTWARE\DriverSupport O43 - CFD: 21/11/2015 - [] D -- C:\ProgramData\ProductData O43 - CFD: 28/01/2014 - [] D -- C:\Users\My Computer\AppData\Roaming\ProductData O42 - Logiciel: Kaspersky Security Scan - (.Kaspersky Lab.) [HKLM][64Bits] -- {56009CA3-423B-41F8-884A-E5B049534F15} O2 - BHO: ExplorerWnd Helper [64Bits] - {10921475-03CE-4E04-90CE-E2E7EF20C814}  (Orphean) HKLM\SOFTWARE\Wow6432Node\Safer Networking Limited HKCU\SOFTWARE\Safer Networking Limited O43 - CFD: 08/03/2015 - [] D -- C:\Program Files (x86)\Spybot - Search & Destroy O53 - SMSR:HKLM\...\startupreg\SpybotSD TeaTimer  [Key] . (...) -- c:\program files (x86)\spybot - search & destroy\teatimer.exe (.not file.) HKLM\SOFTWARE\Wow6432Node\Eset HKLM\SOFTWARE\Wow6432Node\SpywareBlaster HKCU\SOFTWARE\MCAFEE O43 - CFD: 17/08/2014 - [0] D -- C:\Program Files (x86)\McAfee O43 - CFD: 22/11/2015 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpywareBlaster O43 - CFD: 17/08/2014 - [] D -- C:\ProgramData\McAfee FirewallRaz EmptyPrefetch EmptyTemp EmptyFlash

Hope this is OK.

 

Re: I'm not sure what to clean/remove.

Hi,

Sadly, that's not what I'm waitting for. Here is an example of a ZHPFix script :

Rapport de ZHPFix 2015.10.19.9 par Nicolas Coolman, Update du 19/10/2015
Fichier d'export Registre : 
Run by Chapi at 27/11/2015 17:43:39
High Elevated Privileges : OK
Windows 8 Home Premium Edition, 64-bit Service Pack 1 (9600)

Corbeille vidée (Annulé par l'utilisateur)


========== Récapitulatif ==========


End of clean in 00mn 03s

========== Chemin de fichier rapport ==========
C:\Users\Chapi\AppData\Roaming\ZHP\ZHPFix[R1].txt - 29/08/2014 17:10:42 [2567]
C:\Users\Chapi\AppData\Roaming\ZHP\ZHPFix[R2].txt - 29/08/2014 17:14:09 [668]

 

So just to repeat the instructions.

  • Go on the download page of ZhpFix, click on the blue button "Download Now".
  • Save the file where do you want and launch it with right click : "launch as administrator".
  • Follow the instructions during the installation.
  • Then click on the shortcut for ZhpFix on your desktop, and as usual, launch it as administrator.
  • Select "Import"
  • Copy paste this script including "Script ZHPFix":
Script ZHPFix
P2 - EXT FILE: (...) -- C:\Users\My Computer\AppData\Roaming\Mozilla\Firefox\Profiles\8kyk8yzd.default-1436897542862\extensions\jid1-ZAdIEUB7XOzOJw@jetpack.xpi
HKCU\SOFTWARE\AppDataLow\Software\arcadeparlorconfig
O43 - CFD: 15/03/2015 - [] D -- C:\ProgramData\{65AB91D4-DDD0-48D4-804D-C24E1FC90D44}
HKCU\SOFTWARE\DriverSupport
O43 - CFD: 21/11/2015 - [] D -- C:\ProgramData\ProductData
O43 - CFD: 28/01/2014 - [] D -- C:\Users\My Computer\AppData\Roaming\ProductData
O42 - Logiciel: Kaspersky Security Scan - (.Kaspersky Lab.) [HKLM][64Bits] -- {56009CA3-423B-41F8-884A-E5B049534F15}
O2 - BHO: ExplorerWnd Helper [64Bits] - {10921475-03CE-4E04-90CE-E2E7EF20C814}  (Orphean)
HKLM\SOFTWARE\Wow6432Node\Safer Networking Limited
HKCU\SOFTWARE\Safer Networking Limited
O43 - CFD: 08/03/2015 - [] D -- C:\Program Files (x86)\Spybot - Search & Destroy
O53 - SMSR:HKLM\...\startupreg\SpybotSD TeaTimer  [Key] . (...) -- c:\program files (x86)\spybot - search & destroy\teatimer.exe (.not file.)
HKLM\SOFTWARE\Wow6432Node\Eset
HKLM\SOFTWARE\Wow6432Node\SpywareBlaster
HKCU\SOFTWARE\MCAFEE
O43 - CFD: 17/08/2014 - [0] D -- C:\Program Files (x86)\McAfee
O43 - CFD: 22/11/2015 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpywareBlaster
O43 - CFD: 17/08/2014 - [] D -- C:\ProgramData\McAfee
FirewallRaz
EmptyPrefetch
EmptyTemp
EmptyFlash
  • Then click on Go to launch the tool.
  • At the end, a report named ZHPFixReport.txt will be create and save on your desktop
  • Please Copy/Paste its content in your answer.

If there is a step that block you, just tell me and I will try to make it more easy.

Good luck

Re: I'm not sure what to clean/remove.

Hello Chapi,

You are saying above

"Import" What does supposedly import?

"Copy (what?) paste (to where?) this script including "Script ZHPFix"(above line only?)". This statement reffers two items + ZHPFixReport.txt = 3 items?

barsim

 

 

Re: I'm not sure what to clean/remove.

Ok, so I've made a more detailled explanation (all the links refer to a picture with what to do) :

Script ZHPFix
P2 - EXT FILE: (...) -- C:\Users\My Computer\AppData\Roaming\Mozilla\Firefox\Profiles\8kyk8yzd.default-1436897542862\extensions\jid1-ZAdIEUB7XOzOJw@jetpack.xpi
HKCU\SOFTWARE\AppDataLow\Software\arcadeparlorconfig
O43 - CFD: 15/03/2015 - [] D -- C:\ProgramData\{65AB91D4-DDD0-48D4-804D-C24E1FC90D44}
HKCU\SOFTWARE\DriverSupport
O43 - CFD: 21/11/2015 - [] D -- C:\ProgramData\ProductData
O43 - CFD: 28/01/2014 - [] D -- C:\Users\My Computer\AppData\Roaming\ProductData
O42 - Logiciel: Kaspersky Security Scan - (.Kaspersky Lab.) [HKLM][64Bits] -- {56009CA3-423B-41F8-884A-E5B049534F15}
O2 - BHO: ExplorerWnd Helper [64Bits] - {10921475-03CE-4E04-90CE-E2E7EF20C814}  (Orphean)
HKLM\SOFTWARE\Wow6432Node\Safer Networking Limited
HKCU\SOFTWARE\Safer Networking Limited
O43 - CFD: 08/03/2015 - [] D -- C:\Program Files (x86)\Spybot - Search & Destroy
O53 - SMSR:HKLM\...\startupreg\SpybotSD TeaTimer  [Key] . (...) -- c:\program files (x86)\spybot - search & destroy\teatimer.exe (.not file.)
HKLM\SOFTWARE\Wow6432Node\Eset
HKLM\SOFTWARE\Wow6432Node\SpywareBlaster
HKCU\SOFTWARE\MCAFEE
O43 - CFD: 17/08/2014 - [0] D -- C:\Program Files (x86)\McAfee
O43 - CFD: 22/11/2015 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpywareBlaster
O43 - CFD: 17/08/2014 - [] D -- C:\ProgramData\McAfee
FirewallRaz
EmptyPrefetch
EmptyTemp
EmptyFlash

I hope this will be uselfull.

Chapi

Re: I'm not sure what to clean/remove.

Hi Chapi,

This is ZHPFixReport without using Drop-box opton:

Rapport de ZHPFix 2015.10.19.9 par Nicolas Coolman, Update du 19/10/2015 Fichier d'export Registre : Run by My Computer at 11/27/2015 2:39:30 PM High Elevated Privileges : OK Windows Vista Business Edition, 64-bit  (Build 6000)

Recycle Bin emptied (14mn AMs) Prefetcher emptied

========== Software ========== REMOVES: Kaspersky Security Scan

========== Registry keys ========== REMOVES: [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{56009CA3-423B-41F8-884A-E5B049534F15}] REMOVES: HKCU\SOFTWARE\AppDataLow\Software\arcadeparlorconfig REMOVES: HKCU\SOFTWARE\DriverSupport REMOVES: HKLM\SOFTWARE\Wow6432Node\Safer Networking Limited REMOVES: HKCU\SOFTWARE\Safer Networking Limited REMOVES:*  StartupReg: SpybotSD TeaTimer REMOVES: HKLM\SOFTWARE\Wow6432Node\Eset REMOVES: HKLM\SOFTWARE\Wow6432Node\SpywareBlaster REMOVES: HKCU\SOFTWARE\MCAFEE

========== Registry values ========== ABSENT value Standard Profile: FirewallRaz : ABSENT value Domain Profile: FirewallRaz :

========== Folders ========== REMOVES: C:\ProgramData\{65AB91D4-DDD0-48D4-804D-C24E1FC90D44} REMOVES: C:\ProgramData\ProductData REMOVES: C:\Users\My Computer\AppData\Roaming\ProductData REMOVES: C:\Program Files (x86)\Spybot - Search & Destroy REMOVES: C:\Program Files (x86)\McAfee REMOVES: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpywareBlaster REMOVES: C:\ProgramData\McAfee Deletes temporary Windows (21) REMOVES Flash Cookies (0)

========== Files ========== Deletes temporary Windows (70) (132,309,748 octets) REMOVES Flash Cookies (0) (0 octets)

========== Summary ========== 9 : Registry keys 2 : Registry values 9 : Folders 2 : Files 1 : Software

End of clean in 57mn AMs

========== Path to file report ========== C:\Users\My Computer\AppData\Roaming\ZHP\ZHPFix[R1].txt - 11/27/2015 2:39:44 PM [1795]

As comment: thank you very much putting up with difficult reactions. Additionally what confused me was

"Copy paste this script including "Script ZHPFix" " the lack of comma beetwen the words Script and Including, therefore the instruction reffering to 2 files.

barsim

 

 

Re: I'm not sure what to clean/remove.

Hi,

that's what i was expecting ! Thank you for the feedback, as a non native english speaker, I dont really see the difference...

We will end with that script, just keep on mind to keep your softwares update, using Secunia PSI for example. Of course, if you have another question, just ask !

Bye

Chapi

Re: I'm not sure what to clean/remove.

Hello,

Just some more information :

  1. Keep your softwares update, you can check it whith secunia PSI, or use the avast fonctonality.
  2. Use CCleaner every month to erase unecessary files, that could help you to accelerate a bit your computer and your browser.
  3. Last instructions :
    • Download DelFix from Xplode on your desktop.
    • Launch it with administrator rights.
    • Select all the option except the one proposing to save the registry.
    • Then click on the "Execute" button.
    • When everything is finish, the software will close itself.
    • Then a report appear on the notepad, please copy paste it's content in your answer.

Bye,

Chapi