Windows 10 Start button, network volume, battery and action center don't work

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Jeremie
    PCHF Member
    • Jan 2017
    • 27

    #31
    since the problem is clearly in the O.S., if I restore from a restore point that was made a month (approx) ago, will it make the OS work like it did before or will it only change my programs?

    Comment

    • Malnutrition
      PCHF Moderator
      • Jul 2016
      • 7041

      #32
      I think you should go ahead and run the fix, within the fix is the solution.

      Comment

      • Jeremie
        PCHF Member
        • Jan 2017
        • 27

        #33
        [HEADING=1]Fix result of Farbar Recovery Scan Tool (x64) Version: 01-01-2017
        Ran by Quelqu’un (06-01-2017 20:09:01) Run:1
        Running from C:\Users\Quelqu’un\Desktop
        Loaded Profiles: Quelqu’un (Available Profiles: Quelqu’un & battlecruiser)
        Boot Mode: Normal[/HEADING]
        fixlist content:


        Start
        CreateRestorePoint:
        Closeprocesses:
        Emptytemp:
        HKU\S-1-5-21-3980963936-1557843195-203842877-1001...\Policies\system: [NoDispAppearancePage] 0
        HKU\S-1-5-21-3980963936-1557843195-203842877-1001...\Policies\Explorer: [NoPreviewPane] 0
        HKU\S-1-5-21-3980963936-1557843195-203842877-1001...\Policies\Explorer: [NoTrayContextMenu] 0
        HKU\S-1-5-21-3980963936-1557843195-203842877-1001...\Policies\Explorer: [NoSetTaskbar] 0
        HKU\S-1-5-21-3980963936-1557843195-203842877-1001...\Policies\Explorer: [NoViewContextMenu] 0
        HKU\S-1-5-21-3980963936-1557843195-203842877-1001...\Policies\Explorer: [NoWinkeys] 0
        HKU\S-1-5-21-3980963936-1557843195-203842877-1001...\Policies\Explorer: [NoTrayItemsDisplay] 0
        HKU\S-1-5-21-3980963936-1557843195-203842877-1001...\Policies\Explorer: [HideClock] 0
        HKU\S-1-5-21-3980963936-1557843195-203842877-1001...\Policies\Explorer: [HideSCANetwork] 0
        HKU\S-1-5-21-3980963936-1557843195-203842877-1001...\Policies\Explorer: [HideSCAVolume] 0
        HKU\S-1-5-21-3980963936-1557843195-203842877-1001...\Policies\Explorer: [NoInstrumentation] 1
        Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
        Tcpip..\Interfaces{05ef7c5a-aaf5-4007-a27d-38eb014e8614}: [NameServer] 198.101.242.72,23.253.163.53,25.0.0.1
        Tcpip..\Interfaces{1e857cd1-da1f-4ef5-bf7a-348a2afe1988}: [NameServer] 198.101.242.72,23.253.163.53
        Tcpip..\Interfaces{1e857cd1-da1f-4ef5-bf7a-348a2afe1988}: [DhcpNameServer] 10.17.0.1
        Tcpip..\Interfaces{360f2aa3-d847-493b-95c3-e7ed0bddc2b2}: [NameServer] 198.101.242.72,23.253.163.53
        Tcpip..\Interfaces{360f2aa3-d847-493b-95c3-e7ed0bddc2b2}: [DhcpNameServer] 8.8.8.8 8.8.4.4
        Tcpip..\Interfaces{39461d4f-e9a6-4516-86b0-6cb9ce9f4ea9}: [NameServer] 198.101.242.72,23.253.163.53
        Tcpip..\Interfaces{77c6b013-46a0-4bb6-89f9-8e7ea791f25e}: [NameServer] 198.101.242.72,23.253.163.53
        Tcpip..\Interfaces{79816788-6263-4ca0-9ac7-68e40a1b3678}: [NameServer] 198.101.242.72,23.253.163.53
        Tcpip..\Interfaces{9fc13bb4-5466-4402-a923-c247d0df61e4}: [NameServer] 198.101.242.72,23.253.163.53
        Tcpip..\Interfaces{9fc13bb4-5466-4402-a923-c247d0df61e4}: [DhcpNameServer] 10.10.10.10
        Tcpip..\Interfaces{c173450f-f5a5-46db-8693-2cc6eb093a35}: [NameServer] 198.101.242.72,23.253.163.53
        Tcpip..\Interfaces{d8485dc9-462b-4d4b-b356-c770f8ee2a2c}: [NameServer] 198.101.242.72,23.253.163.53,192.168.1.1
        Tcpip..\Interfaces{d8485dc9-462b-4d4b-b356-c770f8ee2a2c}: [DhcpNameServer] 192.168.1.1
        HKU\S-1-5-21-3980963936-1557843195-203842877-1001\Software\Microsoft\Internet Explorer\Main,Start Page = file:///C:/Users/Quelqu’un/Documents/Home/Homepage.html
        HKU\S-1-5-21-3980963936-1557843195-203842877-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer15.msn.com/?pc=ACTE
        SearchScopes: HKLM → {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://cf.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms}
        SearchScopes: HKLM-x32 → {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://cf.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms}
        SearchScopes: HKU\S-1-5-21-3980963936-1557843195-203842877-1001 → DefaultScope {7628DB24-0587-48AE-9CE3-B830B02E9BC0} URL =
        SearchScopes: HKU\S-1-5-21-3980963936-1557843195-203842877-1001 → {7628DB24-0587-48AE-9CE3-B830B02E9BC0} URL =
        SearchScopes: HKU\S-1-5-21-3980963936-1557843195-203842877-1001 → {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://cf.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms}
        BHO: Java™ Plug-In SSV Helper → {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} → C:\Program Files\Java\jre1.8.0_101\bin\ssv.dll [2016-10-04] (Oracle Corporation)
        BHO: No Name → {B4F3A835-0E21-4959-BA22-42B3008E02FF} → No File
        Toolbar: HKLM - QT Command Bar - {d2bf470e-ed1c-487f-a666-2bd8835eb6ce} - C:\WINDOWS\SYSTEM32\mscoree.dll [2016-07-16] (Microsoft Corporation)
        Toolbar: HKLM - QT Command Bar 2 - {d2bf470e-ed1c-487f-a777-2bd8835eb6ce} - C:\WINDOWS\SYSTEM32\mscoree.dll [2016-07-16] (Microsoft Corporation)
        Toolbar: HKLM - QTTabBar - {d2bf470e-ed1c-487f-a333-2bd8835eb6ce} - C:\WINDOWS\SYSTEM32\mscoree.dll [2016-07-16] (Microsoft Corporation)
        Toolbar: HKLM - QT Base Toolbar - {d2bf470e-ed1c-487f-a300-2bd8835eb6ce} - C:\WINDOWS\SYSTEM32\mscoree.dll [2016-07-16] (Microsoft Corporation)
        Toolbar: HKLM-x32 - QT Command Bar - {d2bf470e-ed1c-487f-a666-2bd8835eb6ce} - C:\WINDOWS\SYSTEM32\mscoree.dll [2016-07-16] (Microsoft Corporation)
        Toolbar: HKLM-x32 - QT Command Bar 2 - {d2bf470e-ed1c-487f-a777-2bd8835eb6ce} - C:\WINDOWS\SYSTEM32\mscoree.dll [2016-07-16] (Microsoft Corporation)
        Toolbar: HKLM-x32 - QTTabBar - {d2bf470e-ed1c-487f-a333-2bd8835eb6ce} - C:\WINDOWS\SYSTEM32\mscoree.dll [2016-07-16] (Microsoft Corporation)
        Toolbar: HKLM-x32 - QT Base Toolbar - {d2bf470e-ed1c-487f-a300-2bd8835eb6ce} - C:\WINDOWS\SYSTEM32\mscoree.dll [2016-07-16] (Microsoft Corporation)
        FF Homepage: Mozilla\Firefox\Profiles\u676v7ok.default → file:///C:/Users/Quelqu’un/Documents/Home/New Homepage.html
        FF NetworkProxy: Mozilla\Firefox\Profiles\u676v7ok.default → ftp", “127.0.0.1”
        FF NetworkProxy: Mozilla\Firefox\Profiles\u676v7ok.default → ftp_port", 4444
        FF NetworkProxy: Mozilla\Firefox\Profiles\u676v7ok.default → http", “127.0.0.1”
        FF NetworkProxy: Mozilla\Firefox\Profiles\u676v7ok.default → http_port", 4444
        FF NetworkProxy: Mozilla\Firefox\Profiles\u676v7ok.default → socks", “127.0.0.1”
        FF NetworkProxy: Mozilla\Firefox\Profiles\u676v7ok.default → socks_port", 4444
        FF NetworkProxy: Mozilla\Firefox\Profiles\u676v7ok.default → ssl", “127.0.0.1”
        FF NetworkProxy: Mozilla\Firefox\Profiles\u676v7ok.default → ssl_port", 4444
        FF NetworkProxy: Mozilla\Firefox\Profiles\u676v7ok.default → type", 0
        FF Extension: (newtab.url) - C:\Users\Quelqu’un\AppData\Roaming\Mozilla\Firefox \Profiles\u676v7ok.default\Extensions@newtaburl.xpi [2016-06-28]
        FF Extension: (Amazon Assistant for Firefox) - C:\Users\Quelqu’un\AppData\Roaming\Mozilla\Firefox \Profiles\u676v7ok.default\Extensions\abb@amazon.com.xpi [2016-06-09]
        FF Extension: (Adblock Plus) - C:\Users\Quelqu’un\AppData\Roaming\Mozilla\Firefox \Profiles\u676v7ok.default\Extensions{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-08-25]
        FF Extension: (newtab.url) - C:\Users\Quelqu’un\AppData\Roaming\Mozilla\Firefox \Profiles\36kffurb.Default User\Extensions@newtaburl.xpi [2016-09-02]
        FF Extension: (HackBar) - C:\Users\Quelqu’un\AppData\Roaming\Mozilla\Firefox \Profiles\36kffurb.Default User\Extensions{F5DDF39C-9293-4d5e-9AA8-E04E6DD5E9B4}.xpi [2016-12-22]
        FF HKLM-x32...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt => not found
        FF Plugin-x32: @tools.google.com/Google Update;version=3 → C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)
        FF Plugin-x32: @tools.google.com/Google Update;version=9 → C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)
        CHR StartupUrls: Profile 2 → “file:///C:/Users/Quelqu’un/Documents/Home/Homepage.html”
        CHR Extension: (YouTube) - C:\Users\Quelqu’un\AppData\Local\Google\Chrome\Use r Data\Profile 2\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-12-05]
        CHR Extension: (Proxy SwitchySharp) - C:\Users\Quelqu’un\AppData\Local\Google\Chrome\Use r Data\Profile 2\Extensions\dpplabbmogkhghncfbfdeeokoefdjegm [2016-12-05]
        CHR HKLM...\Chrome\Extension: [pfcgjlglddicjopgimohdcbmabacamll] - <no Path/update_url>
        CHR HKLM-x32...\Chrome\Extension: [fhoibnponjcgjgcnfacekaijdbbplhib] - hxxps://chrome.google.com/webstore/detail/fhoibnponjcgjgcnfacekaijdbbplhib
        CHR HKLM-x32...\Chrome\Extension: [pfcgjlglddicjopgimohdcbmabacamll] - <no Path/update_url>
        S4 TenorshareReibootService; C:\Users\Quelqu’un\Downloads\ReiBoot\TenorshareRei bootService.exe
        S3 klids; ??\C:\ProgramData\Kaspersky Lab\AVP16.0.1\Bases\klids.sys
        2017-01-05 18:51 - 2016-10-07 10:31 - 00000000 ____D C:\ProgramData\KMSAutoS
        2016-07-06 15:05 - 2016-07-06 15:08 - 0000820 _____ () C:\Users\Quelqu’un\AppData\Roaming\MPQEditor.ini
        2016-11-28 23:05 - 2017-01-05 15:39 - 0000600 _____ () C:\Users\Quelqu’un\AppData\Roaming\winscp.rnd
        2016-08-15 17:20 - 2016-08-15 17:20 - 0001472 _____ () C:\Users\Quelqu’un\AppData\Local\recently-used.xbel
        2016-08-15 10:45 - 2016-08-15 10:45 - 0007595 _____ () C:\Users\Quelqu’un\AppData\Local\Resmon.ResmonCfg
        2016-11-18 14:41 - 2016-11-18 14:41 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
        2016-08-07 05:49 - 2017-01-05 22:48 - 0019535 _____ () C:\ProgramData\empty.ico
        Task: {652A4EC9-22E8-4D31-820F-4E725660E947} - System32\Tasks\KMSAutoNet => C:\ProgramData\KMSAutoS\KMSAuto Net.exe [2016-10-07] (MSFree Inc.)
        Task: {7524F6F3-9C4A-47DE-83ED-28443E912CDB} - System32\Tasks\FUBTrackingByPLD => C:\OEM\Preload\FubTracking\FubTracking.exe [2015-05-14] ()
        Task: {A69D6F30-4E24-44A0-892B-D433473ED42B} - System32\Tasks\Quick Access => C:\Program Files\Acer\Acer Quick Access\QALauncher.exe [2015-07-17] (Acer Incorporated)
        Task: {B8CD01D7-F313-4F66-92C9-98A4E9451BFB} - \OfficeSoftwareProtectionPlatform\SvcRestartTask → No File <==== ATTENTION
        Task: {E83293C0-83EE-42A1-AE7F-802CD4C7BDF0} - System32\Tasks\UbtFrameworkService => C:\Program Files\Acer\User Experience Improvement Program\Framework\TriggerFramework.exe [2014-03-12] (TODO: )
        C:\Program Files\Acer\User Experience Improvement Program
        ShortcutWithArgument: C:\Users\Quelqu’un\AppData\Roaming\Microsoft\Inter net Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\9501e18d7c2ab92e\Googl e Chrome.lnk → C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) → --profile-directory=“Profile 2”
        ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk → C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) → --disable-new-avatar-menu – “%1”
        HKLM...\Policies\Explorer: [NoRecentDocsNetHood] 0
        HKLM...\Policies\Explorer: [NoChangeStartMenu] 0
        CHR HKLM...\Chrome\Extension: [fhoibnponjcgjgcnfacekaijdbbplhib] - hxxps://chrome.google.com/webstore/detail/fhoibnponjcgjgcnfacekaijdbbplhib
        CHR HKLM-x32...\Chrome\Extension: [fhoibnponjcgjgcnfacekaijdbbplhib] - hxxps://chrome.google.com/webstore/detail/fhoibnponjcgjgcnfacekaijdbbplhib
        BHO: No Name → {B4F3A835-0E21-4959-BA22-42B3008E02FF} → No File
        HKLM\Software\Policies\Microsoft\Windows NT\SystemRestore: [DisableSR/DisableConfig] <===== ATTENTION
        GroupPolicy: Restriction <======= ATTENTION
        HKU\S-1-5-21-3980963936-1557843195-203842877-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
        S4 KMSEmulator; C:\ProgramData\KMSAutoS\bin\KMSSS.exe [301056 2015-07-23] (MDL Forum, mod by Ratiborus) [File not signed]
        2017-01-05 18:51 - 2016-10-07 10:31 - 00000000 ____D C:\ProgramData\KMSAutoS
        Bonjour (HKLM...{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
        YTD Video Downloader 5.3 (HKLM-x32...{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}) (Version: 5.3 - GreenTree Applications SRL) <==== ATTENTION
        Task: {B8CD01D7-F313-4F66-92C9-98A4E9451BFB} - \OfficeSoftwareProtectionPlatform\SvcRestartTask → No File <==== ATTENTION
        Task: {B8CD01D7-F313-4F66-92C9-98A4E9451BFB} - \OfficeSoftwareProtectionPlatform\SvcRestartTask → No File <==== ATTENTION
        Task: {652A4EC9-22E8-4D31-820F-4E725660E947} - System32\Tasks\KMSAutoNet => C:\ProgramData\KMSAutoS\KMSAuto Net.exe [2016-10-07] (MSFree Inc.)
        RemoveProxy:
        CMD: netsh advfirewall reset
        CMD: netsh advfirewall set allprofiles state Off
        CMD: ipconfig /flushdns
        CMD: netsh winsock reset catalog
        CMD: netsh int ip reset c:\resetlog.txt
        CMD: ipconfig /release
        CMD: ipconfig /renew
        CMD: netsh int ipv4 reset
        CMD: netsh int ipv6 reset
        reboot:
        End


        Restore point was successfully created.
        Processes closed successfully.
        HKU\S-1-5-21-3980963936-1557843195-203842877-1001\Software\Microsoft\Windows\CurrentVersion\Pol icies\system\NoDispAppearancePage => value removed successfully
        HKU\S-1-5-21-3980963936-1557843195-203842877-1001\Software\Microsoft\Windows\CurrentVersion\Pol icies\Explorer\NoPreviewPane => value removed successfully
        HKU\S-1-5-21-3980963936-1557843195-203842877-1001\Software\Microsoft\Windows\CurrentVersion\Pol icies\Explorer\NoTrayContextMenu => value removed successfully
        HKU\S-1-5-21-3980963936-1557843195-203842877-1001\Software\Microsoft\Windows\CurrentVersion\Pol icies\Explorer\NoSetTaskbar => value removed successfully
        HKU\S-1-5-21-3980963936-1557843195-203842877-1001\Software\Microsoft\Windows\CurrentVersion\Pol icies\Explorer\NoViewContextMenu => value removed successfully
        HKU\S-1-5-21-3980963936-1557843195-203842877-1001\Software\Microsoft\Windows\CurrentVersion\Pol icies\Explorer\NoWinkeys => value removed successfully
        HKU\S-1-5-21-3980963936-1557843195-203842877-1001\Software\Microsoft\Windows\CurrentVersion\Pol icies\Explorer\NoTrayItemsDisplay => value removed successfully
        HKU\S-1-5-21-3980963936-1557843195-203842877-1001\Software\Microsoft\Windows\CurrentVersion\Pol icies\Explorer\HideClock => value removed successfully
        HKU\S-1-5-21-3980963936-1557843195-203842877-1001\Software\Microsoft\Windows\CurrentVersion\Pol icies\Explorer\HideSCANetwork => value removed successfully
        HKU\S-1-5-21-3980963936-1557843195-203842877-1001\Software\Microsoft\Windows\CurrentVersion\Pol icies\Explorer\HideSCAVolume => value removed successfully
        HKU\S-1-5-21-3980963936-1557843195-203842877-1001\Software\Microsoft\Windows\CurrentVersion\Pol icies\Explorer\NoInstrumentation => value removed successfully
        HKLM\System\CurrentControlSet\Services\Tcpip\Param eters\DhcpNameServer => value removed successfully
        HKLM\System\CurrentControlSet\Services\Tcpip\Param eters\Interfaces{05ef7c5a-aaf5-4007-a27d-38eb014e8614}\NameServer => value removed successfully
        HKLM\System\CurrentControlSet\Services\Tcpip\Param eters\Interfaces{1e857cd1-da1f-4ef5-bf7a-348a2afe1988}\NameServer => value removed successfully
        HKLM\System\CurrentControlSet\Services\Tcpip\Param eters\Interfaces{1e857cd1-da1f-4ef5-bf7a-348a2afe1988}\DhcpNameServer => value removed successfully
        HKLM\System\CurrentControlSet\Services\Tcpip\Param eters\Interfaces{360f2aa3-d847-493b-95c3-e7ed0bddc2b2}\NameServer => value removed successfully
        HKLM\System\CurrentControlSet\Services\Tcpip\Param eters\Interfaces{360f2aa3-d847-493b-95c3-e7ed0bddc2b2}\DhcpNameServer => value removed successfully
        HKLM\System\CurrentControlSet\Services\Tcpip\Param eters\Interfaces{39461d4f-e9a6-4516-86b0-6cb9ce9f4ea9}\NameServer => value removed successfully
        HKLM\System\CurrentControlSet\Services\Tcpip\Param eters\Interfaces{77c6b013-46a0-4bb6-89f9-8e7ea791f25e}\NameServer => value removed successfully
        HKLM\System\CurrentControlSet\Services\Tcpip\Param eters\Interfaces{79816788-6263-4ca0-9ac7-68e40a1b3678}\NameServer => value removed successfully
        HKLM\System\CurrentControlSet\Services\Tcpip\Param eters\Interfaces{9fc13bb4-5466-4402-a923-c247d0df61e4}\NameServer => value removed successfully
        HKLM\System\CurrentControlSet\Services\Tcpip\Param eters\Interfaces{9fc13bb4-5466-4402-a923-c247d0df61e4}\DhcpNameServer => value removed successfully
        HKLM\System\CurrentControlSet\Services\Tcpip\Param eters\Interfaces{c173450f-f5a5-46db-8693-2cc6eb093a35}\NameServer => value removed successfully
        HKLM\System\CurrentControlSet\Services\Tcpip\Param eters\Interfaces{d8485dc9-462b-4d4b-b356-c770f8ee2a2c}\NameServer => value removed successfully
        HKLM\System\CurrentControlSet\Services\Tcpip\Param eters\Interfaces{d8485dc9-462b-4d4b-b356-c770f8ee2a2c}\DhcpNameServer => value removed successfully
        HKU\S-1-5-21-3980963936-1557843195-203842877-1001\Software\Microsoft\Internet Explorer\Main\Start Page => value restored successfully
        HKU\S-1-5-21-3980963936-1557843195-203842877-1001\Software\Microsoft\Internet Explorer\Main\Default_Page_URL => value restored successfully
        HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes{AA9A4890-4262-4441-8977-E2FFCBFB706C} => key removed successfully
        HKCR\CLSID{AA9A4890-4262-4441-8977-E2FFCBFB706C} => key not found.
        HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes{AA9A4890-4262-4441-8977-E2FFCBFB706C} => key removed successfully
        HKCR\Wow6432Node\CLSID{AA9A4890-4262-4441-8977-E2FFCBFB706C} => key not found.
        HKU\S-1-5-21-3980963936-1557843195-203842877-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\DefaultScope => value removed successfully
        HKU\S-1-5-21-3980963936-1557843195-203842877-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes{7628DB24-0587-48AE-9CE3-B830B02E9BC0} => key removed successfully
        HKCR\CLSID{7628DB24-0587-48AE-9CE3-B830B02E9BC0} => key not found.
        HKU\S-1-5-21-3980963936-1557843195-203842877-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes{AA9A4890-4262-4441-8977-E2FFCBFB706C} => key removed successfully
        HKCR\CLSID{AA9A4890-4262-4441-8977-E2FFCBFB706C} => key not found.
        HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} => key removed successfully
        HKCR\CLSID{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} => key not found.
        HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects{B4F3A835-0E21-4959-BA22-42B3008E02FF} => key removed successfully
        HKCR\CLSID{B4F3A835-0E21-4959-BA22-42B3008E02FF} => key not found.
        HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{d2bf470e-ed1c-487f-a666-2bd8835eb6ce} => value removed successfully
        HKCR\CLSID{d2bf470e-ed1c-487f-a666-2bd8835eb6ce} => key not found.
        HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{d2bf470e-ed1c-487f-a777-2bd8835eb6ce} => value removed successfully
        HKCR\CLSID{d2bf470e-ed1c-487f-a777-2bd8835eb6ce} => key not found.
        HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{d2bf470e-ed1c-487f-a333-2bd8835eb6ce} => value removed successfully
        HKCR\CLSID{d2bf470e-ed1c-487f-a333-2bd8835eb6ce} => key not found.
        HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{d2bf470e-ed1c-487f-a300-2bd8835eb6ce} => value removed successfully
        HKCR\CLSID{d2bf470e-ed1c-487f-a300-2bd8835eb6ce} => key not found.
        HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{d2bf470e-ed1c-487f-a666-2bd8835eb6ce} => value removed successfully
        HKCR\Wow6432Node\CLSID{d2bf470e-ed1c-487f-a666-2bd8835eb6ce} => key not found.
        HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{d2bf470e-ed1c-487f-a777-2bd8835eb6ce} => value removed successfully
        HKCR\Wow6432Node\CLSID{d2bf470e-ed1c-487f-a777-2bd8835eb6ce} => key not found.
        HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{d2bf470e-ed1c-487f-a333-2bd8835eb6ce} => value removed successfully
        HKCR\Wow6432Node\CLSID{d2bf470e-ed1c-487f-a333-2bd8835eb6ce} => key not found.
        HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{d2bf470e-ed1c-487f-a300-2bd8835eb6ce} => value removed successfully
        HKCR\Wow6432Node\CLSID{d2bf470e-ed1c-487f-a300-2bd8835eb6ce} => key not found.
        Firefox “homepage” removed successfully
        Firefox Proxy settings were reset.
        FF NetworkProxy: Mozilla\Firefox\Profiles\u676v7ok.default → ftp_port", 4444 => not found
        FF NetworkProxy: Mozilla\Firefox\Profiles\u676v7ok.default → http", “127.0.0.1” => not found
        FF NetworkProxy: Mozilla\Firefox\Profiles\u676v7ok.default → http_port", 4444 => not found
        FF NetworkProxy: Mozilla\Firefox\Profiles\u676v7ok.default → socks", “127.0.0.1” => not found
        FF NetworkProxy: Mozilla\Firefox\Profiles\u676v7ok.default → socks_port", 4444 => not found
        FF NetworkProxy: Mozilla\Firefox\Profiles\u676v7ok.default → ssl", “127.0.0.1” => not found
        FF NetworkProxy: Mozilla\Firefox\Profiles\u676v7ok.default → ssl_port", 4444 => not found
        FF NetworkProxy: Mozilla\Firefox\Profiles\u676v7ok.default → type", 0 => not found
        C:\Users\Quelqu’un\AppData\Roaming\Mozilla\Firefox \Profiles\u676v7ok.default\Extensions@newtaburl.xpi => moved successfully
        C:\Users\Quelqu’un\AppData\Roaming\Mozilla\Firefox \Profiles\u676v7ok.default\Extensions\abb@amazon.com.xpi => moved successfully
        C:\Users\Quelqu’un\AppData\Roaming\Mozilla\Firefox \Profiles\u676v7ok.default\Extensions{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi => moved successfully
        C:\Users\Quelqu’un\AppData\Roaming\Mozilla\Firefox \Profiles\36kffurb.Default User\Extensions@newtaburl.xpi => moved successfully
        C:\Users\Quelqu’un\AppData\Roaming\Mozilla\Firefox \Profiles\36kffurb.Default User\Extensions{F5DDF39C-9293-4d5e-9AA8-E04E6DD5E9B4}.xpi => moved successfully
        C:\Users\Quelqu’un\AppData\Roaming\Mozilla\Firefox \Profiles\36kffurb.Default User\Extensions{F5DDF39C-9293-4d5e-9AA8-E04E6DD5E9B4}.xpi => path removed successfully
        HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensio ns\{F003DA68-8256-4b37-A6C4-350FA04494DF} => value removed successfully
        HKLM\Software\Wow6432Node\MozillaPlugins@tools.google.com/Google Update;version=3 => key removed successfully
        C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll => moved successfully
        HKLM\Software\Wow6432Node\MozillaPlugins@tools.google.com/Google Update;version=9 => key removed successfully
        C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll => not found.
        Chrome StartupUrls => removed successfully
        C:\Users\Quelqu’un\AppData\Local\Google\Chrome\Use r Data\Profile 2\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo => moved successfully
        C:\Users\Quelqu’un\AppData\Local\Google\Chrome\Use r Data\Profile 2\Extensions\dpplabbmogkhghncfbfdeeokoefdjegm => moved successfully
        HKLM\SOFTWARE\Google\Chrome\Extensions\pfcgjlglddi cjopgimohdcbmabacamll => key removed successfully
        HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions \fhoibnponjcgjgcnfacekaijdbbplhib => key removed successfully
        HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions \pfcgjlglddicjopgimohdcbmabacamll => key removed successfully
        HKLM\System\CurrentControlSet\Services\TenorshareR eibootService => key removed successfully
        TenorshareReibootService => service removed successfully
        HKLM\System\CurrentControlSet\Services\klids => key could not remove, key could be protected
        C:\ProgramData\KMSAutoS => moved successfully
        C:\Users\Quelqu’un\AppData\Roaming\MPQEditor.ini => moved successfully
        C:\Users\Quelqu’un\AppData\Roaming\winscp.rnd => moved successfully
        C:\Users\Quelqu’un\AppData\Local\recently-used.xbel => moved successfully
        C:\Users\Quelqu’un\AppData\Local\Resmon.ResmonCfg => moved successfully
        C:\ProgramData\DP45977C.lfl => moved successfully
        C:\ProgramData\empty.ico => moved successfully
        HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{652A4EC 9-22E8-4D31-820F-4E725660E947} => key removed successfully
        HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{652A4EC 9-22E8-4D31-820F-4E725660E947} => key removed successfully
        C:\WINDOWS\System32\Tasks\KMSAutoNet => moved successfully
        HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\KMSAutoN et => key removed successfully
        HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon{7524F6F 3-9C4A-47DE-83ED-28443E912CDB} => key removed successfully
        HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{7524F6F 3-9C4A-47DE-83ED-28443E912CDB} => key removed successfully
        C:\WINDOWS\System32\Tasks\FUBTrackingByPLD => moved successfully
        HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\FUBTrack ingByPLD => key removed successfully
        HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon{A69D6F3 0-4E24-44A0-892B-D433473ED42B} => key removed successfully
        HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{A69D6F3 0-4E24-44A0-892B-D433473ED42B} => key removed successfully
        C:\WINDOWS\System32\Tasks\Quick Access => moved successfully
        HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Quick Access => key removed successfully
        HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{B8CD01D 7-F313-4F66-92C9-98A4E9451BFB} => key removed successfully
        HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{B8CD01D 7-F313-4F66-92C9-98A4E9451BFB} => key removed successfully
        HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OfficeSo ftwareProtectionPlatform\SvcRestartTask => key removed successfully
        HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon{E83293C 0-83EE-42A1-AE7F-802CD4C7BDF0} => key removed successfully
        HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{E83293C 0-83EE-42A1-AE7F-802CD4C7BDF0} => key removed successfully
        C:\WINDOWS\System32\Tasks\UbtFrameworkService => moved successfully
        HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\UbtFrame workService => key removed successfully
        C:\Program Files\Acer\User Experience Improvement Program => moved successfully
        C:\Users\Quelqu’un\AppData\Roaming\Microsoft\Inter net Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\9501e18d7c2ab92e\Googl e Chrome.lnk => Shortcut argument removed successfully.
        C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk => Shortcut argument removed successfully.
        HKLM\Software\Microsoft\Windows\CurrentVersion\Pol icies\Explorer\NoRecentDocsNetHood => value removed successfully
        HKLM\Software\Microsoft\Windows\CurrentVersion\Pol icies\Explorer\NoChangeStartMenu => value removed successfully
        HKLM\SOFTWARE\Google\Chrome\Extensions\fhoibnponjc gjgcnfacekaijdbbplhib => key removed successfully
        HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions \fhoibnponjcgjgcnfacekaijdbbplhib => key not found.
        HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects{B4F3A835-0E21-4959-BA22-42B3008E02FF} => key not found.
        HKCR\CLSID{B4F3A835-0E21-4959-BA22-42B3008E02FF} => key not found.
        HKLM\Software\Policies\Microsoft\Windows NT\SystemRestore => key removed successfully
        C:\WINDOWS\system32\GroupPolicy\Machine => moved successfully
        C:\WINDOWS\system32\GroupPolicy\GPT.ini => moved successfully
        C:\WINDOWS\SysWOW64\GroupPolicy\GPT.ini => moved successfully
        HKU\S-1-5-21-3980963936-1557843195-203842877-1001\SOFTWARE\Policies\Microsoft\Internet Explorer => key removed successfully
        HKLM\System\CurrentControlSet\Services\KMSEmulator => key removed successfully
        KMSEmulator => service removed successfully
        “C:\ProgramData\KMSAutoS” => not found.
        Bonjour (HKLM...{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.) => Error: No automatic fix found for this entry.
        YTD Video Downloader 5.3 (HKLM-x32...{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}) (Version: 5.3 - GreenTree Applications SRL) <==== ATTENTION => Error: No automatic fix found for this entry.
        HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{B8CD01D 7-F313-4F66-92C9-98A4E9451BFB} => key not found.
        HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OfficeSo ftwareProtectionPlatform\SvcRestartTask => key not found.
        HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{B8CD01D 7-F313-4F66-92C9-98A4E9451BFB} => key not found.
        HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OfficeSo ftwareProtectionPlatform\SvcRestartTask => key not found.
        HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{652A4EC 9-22E8-4D31-820F-4E725660E947} => key not found.
        C:\WINDOWS\System32\Tasks\KMSAutoNet => not found.
        HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\KMSAutoN et => key not found.

        ========= RemoveProxy: =========

        HKU.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVers ion\Internet Settings\Connections\DefaultConnectionSettings => value removed successfully
        HKU.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVers ion\Internet Settings\Connections\SavedLegacySettings => value removed successfully
        HKU\S-1-5-21-3980963936-1557843195-203842877-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Int ernet Settings\Connections\DefaultConnectionSettings => value removed successfully
        HKU\S-1-5-21-3980963936-1557843195-203842877-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Int ernet Settings\Connections\SavedLegacySettings => value removed successfully

        ========= End of RemoveProxy: =========

        ========= netsh advfirewall reset =========

        Ok.

        ========= End of CMD: =========

        ========= netsh advfirewall set allprofiles state Off =========

        Ok.

        ========= End of CMD: =========

        ========= ipconfig /flushdns =========

        Windows IP Configuration

        Successfully flushed the DNS Resolver Cache.

        ========= End of CMD: =========

        ========= netsh winsock reset catalog =========

        Sucessfully reset the Winsock Catalog.
        You must restart the computer in order to complete the reset.

        ========= End of CMD: =========

        ========= netsh int ip reset c:\resetlog.txt =========

        Resetting Global, OK!
        Resetting Interface, OK!
        Resetting Unicast Address, OK!
        Resetting Neighbor, OK!
        Resetting Path, OK!
        Resetting Route, OK!
        Resetting , failed.
        Access is denied.

        Resetting , OK!
        Restart the computer to complete this action.

        ========= End of CMD: =========

        ========= ipconfig /release =========

        Windows IP Configuration

        No operation can be performed on Ethernet while it has its media disconnected.
        No operation can be performed on Connexion au r‚seau local* 3 while it has its media disconnected.
        No operation can be performed on Connexion au r‚seau local* 5 while it has its media disconnected.
        No operation can be performed on Ethernet 2 while it has its media disconnected.
        No operation can be performed on Ethernet 3 while it has its media disconnected.
        No operation can be performed on Ethernet 4 while it has its media disconnected.
        No operation can be performed on Ethernet 5 while it has its media disconnected.
        No operation can be performed on Connexion r‚seau Bluetooth while it has its media disconnected.

        Ethernet adapter Ethernet:

        Media State . . . . . . . . . . . : Media disconnected
        Connection-specific DNS Suffix . :

        Wireless LAN adapter Connexion au r‚seau local* 3:

        Media State . . . . . . . . . . . : Media disconnected
        Connection-specific DNS Suffix . :

        Wireless LAN adapter Connexion au r‚seau local* 5:

        Media State . . . . . . . . . . . : Media disconnected
        Connection-specific DNS Suffix . :

        Ethernet adapter Ethernet 2:

        Media State . . . . . . . . . . . : Media disconnected
        Connection-specific DNS Suffix . :

        Ethernet adapter Ethernet 3:

        Media State . . . . . . . . . . . : Media disconnected
        Connection-specific DNS Suffix . :

        Ethernet adapter Ethernet 4:

        Media State . . . . . . . . . . . : Media disconnected
        Connection-specific DNS Suffix . :

        Ethernet adapter Ethernet 5:

        Media State . . . . . . . . . . . : Media disconnected
        Connection-specific DNS Suffix . :

        Wireless LAN adapter Wi-Fi:

        Connection-specific DNS Suffix . :
        Link-local IPv6 Address . . . . . : fe80::a495:2271:fa60:dcb9%20
        Default Gateway . . . . . . . . . :

        Ethernet adapter Connexion r‚seau Bluetooth:

        Media State . . . . . . . . . . . : Media disconnected
        Connection-specific DNS Suffix . :

        ========= End of CMD: =========

        ========= ipconfig /renew =========

        Windows IP Configuration

        No operation can be performed on Ethernet while it has its media disconnected.
        No operation can be performed on Connexion au r‚seau local* 3 while it has its media disconnected.
        No operation can be performed on Connexion au r‚seau local* 5 while it has its media disconnected.
        No operation can be performed on Ethernet 2 while it has its media disconnected.
        No operation can be performed on Ethernet 3 while it has its media disconnected.
        No operation can be performed on Ethernet 4 while it has its media disconnected.
        No operation can be performed on Ethernet 5 while it has its media disconnected.
        No operation can be performed on Connexion r‚seau Bluetooth while it has its media disconnected.

        Ethernet adapter Ethernet:

        Media State . . . . . . . . . . . : Media disconnected
        Connection-specific DNS Suffix . :

        Wireless LAN adapter Connexion au r‚seau local* 3:

        Media State . . . . . . . . . . . : Media disconnected
        Connection-specific DNS Suffix . :

        Wireless LAN adapter Connexion au r‚seau local* 5:

        Media State . . . . . . . . . . . : Media disconnected
        Connection-specific DNS Suffix . :

        Ethernet adapter Ethernet 2:

        Media State . . . . . . . . . . . : Media disconnected
        Connection-specific DNS Suffix . :

        Ethernet adapter Ethernet 3:

        Media State . . . . . . . . . . . : Media disconnected
        Connection-specific DNS Suffix . :

        Ethernet adapter Ethernet 4:

        Media State . . . . . . . . . . . : Media disconnected
        Connection-specific DNS Suffix . :

        Ethernet adapter Ethernet 5:

        Media State . . . . . . . . . . . : Media disconnected
        Connection-specific DNS Suffix . :

        Wireless LAN adapter Wi-Fi:

        Connection-specific DNS Suffix . :
        Link-local IPv6 Address . . . . . : fe80::a495:2271:fa60:dcb9%20
        IPv4 Address. . . . . . . . . . . : 192.168.1.7
        Subnet Mask . . . . . . . . . . . : 255.255.255.0
        Default Gateway . . . . . . . . . : 192.168.1.1

        Ethernet adapter Connexion r‚seau Bluetooth:

        Media State . . . . . . . . . . . : Media disconnected
        Connection-specific DNS Suffix . :

        ========= End of CMD: =========

        ========= netsh int ipv4 reset =========

        Resetting Interface, OK!
        Resetting , failed.
        Access is denied.

        Restart the computer to complete this action.

        ========= End of CMD: =========

        ========= netsh int ipv6 reset =========

        Resetting Interface, OK!
        Resetting Unicast Address, OK!
        Resetting Neighbor, OK!
        Resetting Path, OK!
        Resetting Route, OK!
        Resetting , failed.
        Access is denied.

        Resetting , OK!
        Resetting , OK!
        Restart the computer to complete this action.

        ========= End of CMD: =========

        =========== EmptyTemp: ==========

        BITS transfer queue => 0 B
        DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 52145232 B
        Java, Flash, Steam htmlcache => 244406856 B
        Windows/system/drivers => 23359943 B
        Edge => 10839703 B
        Chrome => 423377427 B
        Firefox => 78354257 B
        Opera => 0 B

        Temp, IE cache, history, cookies, recent:
        Default => 0 B
        Users => 0 B
        ProgramData => 0 B
        Public => 0 B
        systemprofile => 0 B
        systemprofile32 => 0 B
        LocalService => 928742 B
        NetworkService => 0 B
        Quelqu’un => 5013784555 B
        battlecruiser => 0 B

        RecycleBin => 257702 B
        EmptyTemp: => 5.4 GB temporary data Removed.

        ================================

        The system needed a reboot.

        ==== End of Fixlog 20:11:28 ====

        Comment

        • Malnutrition
          PCHF Moderator
          • Jul 2016
          • 7041

          #34
          How is your machine running now?

          Comment

          • Jeremie
            PCHF Member
            • Jan 2017
            • 27

            #35
            Still buggy… button dont work

            Comment

            • Malnutrition
              PCHF Moderator
              • Jul 2016
              • 7041

              #36
              Is the computer working correctly now?

              Comment

              • Malnutrition
                PCHF Moderator
                • Jul 2016
                • 7041

                #37
                I do not think that a system restore point will work since, it was disabled.

                I think the best course of action is for you to run the other tools, then we will repair the OS with the windows all in one repair tool. You are not out of the hot water yet, I suspect there is still malware on this machine.

                Comment

                • Jeremie
                  PCHF Member
                  • Jan 2017
                  • 27

                  #38
                  Originally posted by Malnutrition
                  Is the computer working correctly now?
                  It works… I guess, but it works as it did before… My issue is still here, The windows start button, network, volume, battery and action center wont work

                  Comment

                  • Malnutrition
                    PCHF Moderator
                    • Jul 2016
                    • 7041

                    #39
                    So, go ahead and run the other tools that I posted.
                    Once I am certain that you are clear of malware then we will attempt to fix the error.
                    Trying to fix it at this point may just lead back to the same errors.

                    Comment

                    • Jeremie
                      PCHF Member
                      • Jan 2017
                      • 27

                      #40
                      What tools?

                      Comment

                      • Malnutrition
                        PCHF Moderator
                        • Jul 2016
                        • 7041

                        #41
                        The tools in this post.

                        Comment

                        • Jeremie
                          PCHF Member
                          • Jan 2017
                          • 27

                          #42
                          Code:
                          Junkware Removal Tool (JRT) by Malwarebytes
                          Version: 8.1.0 (12.05.2016)
                          Operating System: Windows 10 Home x64
                          Ran by Quelqu'un (Administrator) on 2017-01-06 at 20:37:35.40
                          File System: 4

                          Successfully deleted: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ytd video downloader.lnk (Shortcut)
                          Successfully deleted: C:\ProgramData\ytd video downloader (Folder)
                          Successfully deleted: C:\Users\Quelqu’un\AppData\Local\crashrpt (Folder)
                          Successfully deleted: C:\Users\Quelqu’un\AppData\Local\vghd (Folder)

                          Registry: 2

                          Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{093F479D-712E-46CD-9E06-62E734A05F68} (Registry Value)
                          Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{093F479D-712E-46CD-9E06-62E734A05F68} (Registry Value)
                          Code:
                          Scan was completed on 2017-01-06 at 20:42:27.92
                          End of JRT log
                          [HEADING=1]AdwCleaner v6.042 - Rapport créé le 06/01/2017 à 20:45:09[/HEADING]
                          [HEADING=1]Mis à jour le 06/01/2017 par Malwarebytes[/HEADING]
                          [HEADING=1]Base de données : 2017-01-06.1 [Serveur][/HEADING]
                          [HEADING=1]Système d’exploitation : Windows 10 Home (X64)[/HEADING]
                          [HEADING=1]Nom d’utilisateur : Quelqu’un - PC[/HEADING]
                          [HEADING=1]Exécuté depuis : C:\Users\Quelqu’un\Downloads\adwcleaner_6.042.exe[/HEADING]
                          [HEADING=1]Mode: Scan[/HEADING]
                          [HEADING=1]Support : https://www.malwarebytes.com/support[/HEADING]
                          ***** [ Services ] *****

                          Aucun service malveillant trouvé.

                          ***** [ Dossiers ] *****

                          Dossier trouvé: C:\Users\Quelqu’un\AppData\Roaming\Hola
                          Dossier trouvé: C:\Program Files\Hola
                          Dossier trouvé: C:\Program Files (x86)\GreenTree Applications
                          Dossier trouvé: C:\Users\Public\Pokki

                          ***** [ Fichiers ] *****

                          Aucun fichier malveillant trouvé.

                          ***** [ DLL ] *****

                          Aucune DLL patchée trouvée.

                          ***** [ WMI ] *****

                          Aucune clé malveillante trouvée.

                          ***** [ Raccourcis ] *****

                          Aucun raccourci infecté trouvé.

                          ***** [ Tâches planifiées ] *****

                          Tâche trouvée: Software Update Application

                          ***** [ Registre ] *****

                          Clé trouvée: HKU.DEFAULT\Software\Hola
                          Clé trouvée: HKU\S-1-5-18\Software\Hola
                          Clé trouvée: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uni nstall{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}
                          Clé trouvée: [x64] HKLM\SOFTWARE\Hola
                          Clé trouvée: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\castplatform.com
                          Clé trouvée: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\cdn.castplatform.com
                          Clé trouvée: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion \AppContainer\Storage\microsoft.microsoftedge_8wek yb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\solvusoft.com
                          Clé trouvée: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion \AppContainer\Storage\microsoft.microsoftedge_8wek yb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage[www.solvusoft.com](http://www.solvusoft.com)
                          Clé trouvée: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion \AppContainer\Storage\microsoft.microsoftedge_8wek yb3d8bbwe\Children\001\Internet Explorer\DOMStorage\solvusoft.com
                          Clé trouvée: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion \AppContainer\Storage\microsoft.microsoftedge_8wek yb3d8bbwe\Children\001\Internet Explorer\DOMStorage[www.solvusoft.com](http://www.solvusoft.com)
                          Clé trouvée: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\castplatform.com
                          Clé trouvée: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\cdn.castplatform.com
                          Clé trouvée: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion \AppContainer\Storage\microsoft.microsoftedge_8wek yb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\solvusoft.com
                          Clé trouvée: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion \AppContainer\Storage\microsoft.microsoftedge_8wek yb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage[www.solvusoft.c](http://www.solvusoft.c)
                          Clé trouvée: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion \AppContainer\Storage\microsoft.microsoftedge_8wek yb3d8bbwe\Children\001\Internet Explorer\DOMStorage\solvusoft.com
                          Clé trouvée: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion \AppContainer\Storage\microsoft.microsoftedge_8wek yb3d8bbwe\Children\001\Internet Explorer\DOMStorage[www.solvusoft.com](http://www.solvusoft.com)

                          ***** [ Navigateurs web ] *****

                          Aucune préférence Firefox malveillante trouvée.
                          Chromium préf trouvée: [C:\Users\Quelqu’un\AppData\Local\Google\Chrome\Use r Data\Default\Web data] - ask.com
                          Chromium préf trouvée: [C:\Users\Quelqu’un\AppData\Local\Google\Chrome\Use r Data\Profile 2\Web data] - ask.com


                          C:\AdwCleaner\AdwCleaner[S0].txt - [3740 octets] - [06/01/2017 20:45:10]

                          ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [3814 octets] ##########

                          those two are finished, the other two are running

                          Comment

                          • Malnutrition
                            PCHF Moderator
                            • Jul 2016
                            • 7041

                            #43
                            Your adware cleaner log indicates that you did not remove the items. You should run these tools in the order I have listed. Once the other tools are ran, then run adware cleaner again and post the new log.

                            Comment

                            • Jeremie
                              PCHF Member
                              • Jan 2017
                              • 27

                              #44
                              Of course I didn’t remove them, I need those apps There were on my PC since the begging, I can assure you they are not the problem

                              Comment

                              • Malnutrition
                                PCHF Moderator
                                • Jul 2016
                                • 7041

                                #45
                                Hola & Pokki are known malware.

                                Hola uses your machine as a bot.
                                Pokki is straight up malware.

                                As well as the other apps, you should certainly remove them. They might not be the exact problem, but a little of this and little of that… Build up to be a whole lot of something. Leaving these malwares on your machine is a terrible idea.

                                Comment

                                Working...