• Hi there and welcome to PC Help Forum (PCHF), a more effective way to get the Tech Support you need!
    We have Experts in all areas of Tech, including Malware Removal, Crash Fixing and BSOD's , Microsoft Windows, Computer DIY and PC Hardware, Networking, Gaming, Tablets and iPads, General and Specific Software Support and so much more.

    Why not Click Here To Sign Up and start enjoying great FREE Tech Support.

    This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Solved Friends Computer Needs a Checkup

Status
Not open for further replies.
Update all old programs with Patch My PC


Disable Test Mode.

ZHP Fix
4bd9Ugb.png

  • Disable your antivirus prior to this fix!
  • Download ZHP-Fix from here.
  • Install it.
  • Click Suivant 5 Times.
  • Then Installer.
  • Then Terminer.
  • Then right clcick the ZHP Fix icon Run as admin.
  • Copy the entire content of the code box below, the next step will grab it from your clipboard.
  • Then click on import.
  • Then click GO.
  • Allow completion.
  • A log file will appear on your desktop.
  • Post it here in your next reply.
Code:
Script ZhpFix
SysRestore
EmptyFlash
ProxyFix
EmptyCLSID
O39 - APT: Unknown - (...) -- C:\windows\System32\Tasks\{1426D1E5-5A00-4D59-985A-2107F1BEF83C} [3032]
O39 - APT: Unknown - (...) -- C:\windows\System32\Tasks\{2FB9F27A-DE3A-4CD6-B8B6-B233E63B6955} [2982]
O39 - APT: {65C76270-92BA-4F63-B82C-13F0D18DD623} - (...) -- C:\windows\System32\Tasks\{65C76270-92BA-4F63-B82C-13F0D18DD623} [3294]
O39 - APT: Unknown - (...) -- C:\windows\System32\Tasks\{A8D2B036-36FC-403B-8061-05969D1469A2} [2982]
G0 - GCSP: Preferences [User Data\Default][HomePage] http://connect.facebook.net =>.Facebook
G0 - GCSP: Preferences [User Data\Default][HomePage] http://fonts.googleapis.com =>.Google Inc.
G0 - GCSP: Preferences [User Data\Default][HomePage] http://fonts.gstatic.com =>.Google Inc.
G0 - GCSP: Preferences [User Data\Default][HomePage] http://nicolascoolman.com =>.Nicolas Coolman
G0 - GCSP: Preferences [User Data\Default][HomePage] http://staticxx.facebook.com =>.Facebook
G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.facebook.com =>.Facebook
G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.google-analytics.com =>.Google Inc.
G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.nicolascoolman.com =>.Nicolas Coolman
G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.paypalobjects.com
P2 - FPN: [HKLM] [@WildTangent.com/GamesAppPresenceDetector,Version=1.0] - (.WildTangent.) -- C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll =>.WildTangent
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ =>.Microsoft Corporation
R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphan =>.Microsoft Internet Explorer
R4 - HKCU\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,Enabled = 2
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 1
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
R5 - HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Parameters\Internet\ManualProxies [] =>.Microsoft
O42 - Logiciel: FreeTorrentViewer - (.Free Torrent Viewer.) [HKLM][64Bits] -- FreeTorrentViewer
O42 - Logiciel: Google Toolbar for Internet Explorer - (.Google Inc..) [HKLM][64Bits] -- {18455581-E099-4BA8-BC6B-F34B2F06600C} =>.Google Inc.
O42 - Logiciel: Java Auto Updater - (.Sun Microsystems, Inc..) [HKLM][64Bits] -- {4A03706F-666A-4037-7777-5F2748764D10} =>.Sun Microsystems, Inc.
O42 - Logiciel: Java(TM) 6 Update 25 - (.Oracle.) [HKLM][64Bits] -- {26A24AE4-039D-4CA4-87B4-2F83216025FF} =>.Oracle
O42 - Logiciel: REGSERVO - (.TuneUp System Software Pvt Ltd..) [HKLM][64Bits] -- REGSERVO_is1
O42 - Logiciel: Strongvault Online Backup - (.Strongvault.) [HKLM][64Bits] -- {59DB31A9-BCB0-4985-ACA6-F6477C7BE367}
O42 - Logiciel: Toshiba App Place - (.Toshiba.) [HKLM][64Bits] -- {ED3CBA78-488F-4E8C-B33F-8E3BF4DDB4D2} =>.Toshiba
O42 - Logiciel: TOSHIBA Application Installer - (.TOSHIBA.) [HKLM][64Bits] -- {970472D0-F5F9-4158-A6E3-1AE49EFEF2D3} =>.Toshiba
O42 - Logiciel: TOSHIBA Assist - (.TOSHIBA CORPORATION.) [HKLM][64Bits] -- {C2A276E3-154E-44DC-AAF1-FFDD7FD30E35} =>.Macrovision Corporation®
O42 - Logiciel: Toshiba Book Place - (.K-NFB Reading Technology, Inc..) [HKLM][64Bits] -- {A14962A7-2B7D-456E-BFCD-F54E3A88D41F} =>.K-NFB Reading Technology, Inc.
O42 - Logiciel: TOSHIBA Bulletin Board - (.TOSHIBA Corporation.) [HKLM][64Bits] -- {1C8C049A-145F-4A6E-8290-B5C245EBE39D} =>.Toshiba Corporation
O42 - Logiciel: TOSHIBA Bulletin Board - (.TOSHIBA Corporation.) [HKLM][64Bits] -- InstallShield_{1C8C049A-145F-4A6E-8290-B5C245EBE39D} =>.Toshiba Corporation
O42 - Logiciel: TOSHIBA Disc Creator - (.TOSHIBA Corporation.) [HKLM][64Bits] -- {5DA0E02F-970B-424B-BF41-513A5018E4C0} =>.Toshiba Corporation
O42 - Logiciel: TOSHIBA eco Utility - (.TOSHIBA Corporation.) [HKLM][64Bits] -- {C2F94B5E-201A-4754-8F2F-4395E1D90DA3} =>.Toshiba Corporation
O42 - Logiciel: TOSHIBA Face Recognition - (.TOSHIBA Corporation.) [HKLM][64Bits] -- {F67FA545-D8E5-4209-86B1-AEE045D1003F} =>.Toshiba Corporation
O42 - Logiciel: TOSHIBA Face Recognition - (.TOSHIBA Corporation.) [HKLM][64Bits] -- InstallShield_{F67FA545-D8E5-4209-86B1-AEE045D1003F} =>.Toshiba Corporation
O42 - Logiciel: TOSHIBA Hardware Setup - (.TOSHIBA.) [HKLM][64Bits] -- {C4FFA951-9678-4D51-84B4-AFD15D3C45AD} =>.Toshiba
O42 - Logiciel: TOSHIBA Hardware Setup - (.TOSHIBA.) [HKLM][64Bits] -- InstallShield_{C4FFA951-9678-4D51-84B4-AFD15D3C45AD} =>.Toshiba
O42 - Logiciel: TOSHIBA HDD/SSD Alert - (.TOSHIBA Corporation.) [HKLM][64Bits] -- {D4322448-B6AF-4316-B859-D8A0E84DCB38} =>.Toshiba Corporation
O42 - Logiciel: Toshiba Laptop Checkup - (.Symantec Corporation.) [HKLM][64Bits] -- NortonPCCheckup =>.Symantec Corporation®
O42 - Logiciel: TOSHIBA Media Controller - (.TOSHIBA CORPORATION.) [HKLM][64Bits] -- {C7A4F26F-F9B0-41B2-8659-99181108CDE3} =>.Macrovision Corporation®
O42 - Logiciel: TOSHIBA Media Controller Plug-in - (.TOSHIBA CORPORATION.) [HKLM][64Bits] -- {F26FDF57-483E-42C8-A9C9-EEE1EDB256E0} =>.Toshiba Corporation
O42 - Logiciel: Toshiba Online Backup - (.Toshiba.) [HKLM][64Bits] -- {C57BCDE1-7CB9-467D-B3BA-7E119916CDC1} =>.Toshiba
O42 - Logiciel: TOSHIBA PC Health Monitor - (.TOSHIBA Corporation.) [HKLM][64Bits] -- {9DECD0F9-D3E8-48B0-A390-1CF09F54E3A4} =>.Toshiba Corporation
O42 - Logiciel: TOSHIBA Quality Application - (.TOSHIBA.) [HKLM][64Bits] -- {E69992ED-A7F6-406C-9280-1C156417BC49} =>.Toshiba
O42 - Logiciel: TOSHIBA Recovery Media Creator - (.TOSHIBA CORPORATION.) [HKLM][64Bits] -- {B65BBB06-1F8E-48F5-8A54-B024A9E15FDF} =>.TOSHIBA CORPORATION®
O42 - Logiciel: TOSHIBA ReelTime - (.TOSHIBA Corporation.) [HKLM][64Bits] -- {24811C12-F4A9-4D0F-8494-A7B8FE46123C} =>.Toshiba Corporation
O42 - Logiciel: TOSHIBA ReelTime - (.TOSHIBA Corporation.) [HKLM][64Bits] -- InstallShield_{24811C12-F4A9-4D0F-8494-A7B8FE46123C} =>.Toshiba Corporation
O42 - Logiciel: TOSHIBA Resolution+ Plug-in for Windows Media Player - (.TOSHIBA Corporation.) [HKLM][64Bits] -- {6CB76C9D-80C2-4CB3-A4CD-D96B239E3F94} =>.Toshiba Corporation
O42 - Logiciel: TOSHIBA Service Station - (.TOSHIBA.) [HKLM][64Bits] -- {AC6569FA-6919-442A-8552-073BE69E247A} =>.Toshiba
O42 - Logiciel: TOSHIBA Sleep Utility - (.TOSHIBA Corporation.) [HKLM][64Bits] -- {654F7484-88C5-46DC-AB32-C66BCB0E2102} =>.TOSHIBA CORPORATION®
O42 - Logiciel: TOSHIBA Supervisor Password - (.TOSHIBA.) [HKLM][64Bits] -- {CBD6B23D-41D5-4A46-8019-6208516C9712} =>.Toshiba
O42 - Logiciel: TOSHIBA Supervisor Password - (.TOSHIBA.) [HKLM][64Bits] -- InstallShield_{CBD6B23D-41D5-4A46-8019-6208516C9712} =>.Toshiba
O42 - Logiciel: TOSHIBA Value Added Package - (.TOSHIBA Corporation.) [HKLM][64Bits] -- {066CFFF8-12BF-4390-A673-75F95EFF188E} =>.Toshiba Corporation
O42 - Logiciel: TOSHIBA Value Added Package - (.TOSHIBA Corporation.) [HKLM][64Bits] -- InstallShield_{066CFFF8-12BF-4390-A673-75F95EFF188E} =>.TOSHIBA CORPORATION®
O42 - Logiciel: TOSHIBARegistration - (.TOSHIBA.) [HKLM][64Bits] -- {5AF550B4-BB67-4E7E-82F1-2C4300279050} =>.Toshiba
HKLM\SOFTWARE\Wow6432Node\Norton =>.Symantec Corporation
HKLM\SOFTWARE\Wow6432Node\Norton PC Checkup =>.Symantec Corporation
HKLM\SOFTWARE\Wow6432Node\Symantec =>.Symantec
HKCU\SOFTWARE\Stronghold Online Backup
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\Norton PC Checkup =>.Symantec Corporation
O43 - CFD: 14/08/2012 - [] D -- C:\Program Files (x86)\NortonInstaller =>.Symantec
O43 - CFD: 14/08/2012 - [] D -- C:\ProgramData\Norton =>.Symantec Corporation
O43 - CFD: 27/01/2012 - [] HD -- C:\ProgramData\NortonInstaller =>.Symantec
EmptyTemp
 
Okay either I will see this friend later tonight or possibly tomorrow for our weekly hang out. I will run those last steps you posted in that order. After words should we do a scan with anything else to double check? Like Combofix or something?
 
We need you to run ESET Online Scanner to check and report on your PC.

As Eset may take an extended time to run it is important to ensure your PC does not enter Sleep Mode. See HERE if you are not sure how to disable sleep mode.

Click HERE to download ESET Online Scanner and save it to your desktop.
Disable all Antivirus/Antimalware software. If you are unsure how to do this please ask?
Right click on the downloaded Esetonlinescanner_enu.exe desktop icon and select "Run as Administrator" from the drop down menu.
If you receive any security warnings you can safely allow Eset to run.
On the opening screen click on Accept to agree with the Terms of Use.
As per picture below

  1. Click "Enable detection of potentially unsafe applications"
  2. Click the Advanced settings link.
  3. Ensure all options shown ticked here are selected.
  4. Click "Scan".
vqE2ZEA.png


Eset will download a virus signature database and commence the scan. Depending on the amount of data on your PC this may take some time, please be patient.
At the completion of the scan Eset will display a results dialogue:

fm7QxeE.png


  1. Click "Save to text file" Another box will open and ask you to name it and also where to save it. Suggest call it Eset.txt and save it to the Desktop.
  2. Then choose "Select all".
  3. Finally "Clean all".
Another dialogue box will open where you can select Finish to complete the scan and clean.

Please Copy and paste the contents of the new Eset.txt file in your next reply
clear.png
 
Rapport de ZHPFix 2015.10.19.9 par Nicolas Coolman, Update du 19/10/2015
Fichier d'export Registre :
Run by Mitch at 5/4/2017 3:46:55 PM
High Elevated Privileges : OK
Windows 7 Home Premium Edition, 64-bit Service Pack 1 (Build 7601)

Recycle Bin emptied (02mn AMs)

========== Software ==========
ABSENT Uninstall Process: c:\program files (x86)\freetorrentviewer\uninst.exe
REMOVES: Google Toolbar for Internet Explorer
REMOVES: Java(TM) 6 Update 25
REMOVES: Strongvault Online Backup
REMOVES: Toshiba App Place
REMOVES: TOSHIBA Application Installer
ABSENT Uninstall Process: c:\program files (x86)\installshield installation information\{c2a276e3-154e-44dc-aaf1-ffdd7fd30e35}\setup.exe
REMOVES: Toshiba Book Place
ABSENT Uninstall Process: c:\program files (x86)\installshield installation information\{1c8c049a-145f-4a6e-8290-b5c245ebe39d}\setup.exe
ABSENT Uninstall Process: c:\program files (x86)\installshield installation information\{f67fa545-d8e5-4209-86b1-aee045d1003f}\setup.exe
ABSENT Uninstall Process: c:\progra~2\common~1\instal~1\driver\11\intel3~1\idriver.exe
REMOVES: Toshiba Laptop Checkup
ABSENT Uninstall Process: c:\program files (x86)\installshield installation information\{c7a4f26f-f9b0-41b2-8659-99181108cde3}\setup.exe
REMOVES: TOSHIBA Media Controller Plug-in
REMOVES: Toshiba Online Backup
REMOVES: TOSHIBA Quality Application
ABSENT Uninstall Process: c:\program files (x86)\installshield installation information\{b65bbb06-1f8e-48f5-8a54-b024a9e15fdf}\setup.exe
ABSENT Uninstall Process: c:\program files (x86)\installshield installation information\{24811c12-f4a9-4d0f-8494-a7b8fe46123c}\setup.exe
ABSENT Uninstall Process: c:\program files (x86)\installshield installation information\{6cb76c9d-80c2-4cb3-a4cd-d96b239e3f94}\setup.exe
ABSENT Uninstall Process: c:\program files (x86)\installshield installation information\{ac6569fa-6919-442a-8552-073be69e247a}\setup.exe
ABSENT Uninstall Process: c:\program files (x86)\installshield installation information\{654f7484-88c5-46dc-ab32-c66bcb0e2102}\setup.exe
ABSENT Uninstall Process: c:\program files\toshiba\tvap\setup.exe
REMOVES: TOSHIBARegistration

========== Registry keys ==========
REMOVES Logiciel Key: [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\FreeTorrentViewer]
REMOVES: [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{18455581-E099-4BA8-BC6B-F34B2F06600C}]
REMOVES Software Key: {4A03706F-666A-4037-7777-5F2748764D10} [Java Auto Updater]
REMOVES: [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{26A24AE4-039D-4CA4-87B4-2F83216025FF}]
REMOVES: [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{59DB31A9-BCB0-4985-ACA6-F6477C7BE367}]
REMOVES: [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{ED3CBA78-488F-4E8C-B33F-8E3BF4DDB4D2}]
REMOVES: [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{970472D0-F5F9-4158-A6E3-1AE49EFEF2D3}]
REMOVES Logiciel Key: [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C2A276E3-154E-44DC-AAF1-FFDD7FD30E35}]
REMOVES: [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A14962A7-2B7D-456E-BFCD-F54E3A88D41F}]
REMOVES Software Key: {1C8C049A-145F-4A6E-8290-B5C245EBE39D} [TOSHIBA Bulletin Board]
REMOVES Logiciel Key: [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{1C8C049A-145F-4A6E-8290-B5C245EBE39D}]
REMOVES Logiciel Key: [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{F67FA545-D8E5-4209-86B1-AEE045D1003F}]
REMOVES Logiciel Key: [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{C4FFA951-9678-4D51-84B4-AFD15D3C45AD}]
REMOVES Logiciel Key: [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C7A4F26F-F9B0-41B2-8659-99181108CDE3}]
REMOVES: [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F26FDF57-483E-42C8-A9C9-EEE1EDB256E0}]
REMOVES: [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C57BCDE1-7CB9-467D-B3BA-7E119916CDC1}]
REMOVES: [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{E69992ED-A7F6-406C-9280-1C156417BC49}]
REMOVES Logiciel Key: [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}]
REMOVES Software Key: {24811C12-F4A9-4D0F-8494-A7B8FE46123C} [TOSHIBA ReelTime]
REMOVES Logiciel Key: [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{24811C12-F4A9-4D0F-8494-A7B8FE46123C}]
REMOVES Logiciel Key: [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{6CB76C9D-80C2-4CB3-A4CD-D96B239E3F94}]
REMOVES Logiciel Key: [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{AC6569FA-6919-442A-8552-073BE69E247A}]
REMOVES Logiciel Key: [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{654F7484-88C5-46DC-AB32-C66BCB0E2102}]
REMOVES Logiciel Key: [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{CBD6B23D-41D5-4A46-8019-6208516C9712}]
REMOVES Software Key: {066CFFF8-12BF-4390-A673-75F95EFF188E} [TOSHIBA Value Added Package]
REMOVES Logiciel Key: [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{066CFFF8-12BF-4390-A673-75F95EFF188E}]
REMOVES: [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5AF550B4-BB67-4E7E-82F1-2C4300279050}]
REMOVES: HKLM\SOFTWARE\Wow6432Node\Norton
REMOVES: HKLM\SOFTWARE\Wow6432Node\Norton PC Checkup
REMOVES: HKLM\SOFTWARE\Wow6432Node\Symantec
REMOVES: HKCU\SOFTWARE\Stronghold Online Backup

========== Registry values ==========
ProxyFix : Proxy configuration successfully removed
REMOVES ProxyServer Value
REMOVES ProxyEnable Value
REMOVES EnableHttp1_1 Value
REMOVES ProxyHttp1.1 Value
REMOVES ProxyOverride Value
REMOVES: URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497}

========== Elements of the registry data ==========
REMOVES: R0 - Main,Start Page = KLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page
REMOVES: R0 - Main,Start Page = KLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page
REMOVES: R1 Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
REMOVES: R1 Search Page = http://go.microsoft.com/fwlink/?LinkId=69157
REMOVES: R1 Search Page = about:NoAdd-ons
REMOVES: R1 Search Page = about:SecurityRisk
REMOVES: R1 Search Page = *.local
REMOVES: R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable
REMOVES: R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy
REMOVES: R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1
REMOVES: R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1
REMOVES: R5 AutoConfigProxy = wininet.dll

========== Preferences browser ==========
NOW Chrome File: C:\Users\Mitch\AppData\Local\Google\Chrome\User Data\Default\Preferences
ABSENT Chrome Site: http://connect.facebook.net
NOW Chrome File: C:\Users\Mitch\AppData\Local\Google\Chrome\User Data\Default\Preferences
ABSENT Chrome Site: http://fonts.googleapis.com
NOW Chrome File: C:\Users\Mitch\AppData\Local\Google\Chrome\User Data\Default\Preferences
ABSENT Chrome Site: http://fonts.gstatic.com
NOW Chrome File: C:\Users\Mitch\AppData\Local\Google\Chrome\User Data\Default\Preferences
ABSENT Chrome Site: http://nicolascoolman.com
NOW Chrome File: C:\Users\Mitch\AppData\Local\Google\Chrome\User Data\Default\Preferences
ABSENT Chrome Site: http://staticxx.facebook.com
NOW Chrome File: C:\Users\Mitch\AppData\Local\Google\Chrome\User Data\Default\Preferences
ABSENT Chrome Site: http://www.facebook.com
NOW Chrome File: C:\Users\Mitch\AppData\Local\Google\Chrome\User Data\Default\Preferences
ABSENT Chrome Site: http://www.google-analytics.com
NOW Chrome File: C:\Users\Mitch\AppData\Local\Google\Chrome\User Data\Default\Preferences
ABSENT Chrome Site: http://www.nicolascoolman.com
NOW Chrome File: C:\Users\Mitch\AppData\Local\Google\Chrome\User Data\Default\Preferences
ABSENT Chrome Site: http://www.paypalobjects.com

========== Folders ==========
No folders empty CLSID Local user
REMOVES: C:\Program Files (x86)\NortonInstaller
REMOVES: C:\ProgramData\Norton
REMOVES: C:\ProgramData\NortonInstaller
Deletes temporary Windows (13)

========== Files ==========
REMOVES Flash Cookies (0) (0 octets)
REMOVES Reboot: c:\windows\system32\tasks\{1426d1e5-5a00-4d59-985a-2107f1bef83c}
REMOVES Reboot: c:\windows\system32\tasks\{2fb9f27a-de3a-4cd6-b8b6-b233e63b6955}
REMOVES Reboot: c:\windows\system32\tasks\{65c76270-92ba-4f63-b82c-13f0d18dd623}
REMOVES Reboot: c:\windows\system32\tasks\{a8d2b036-36fc-403b-8061-05969d1469a2}
REMOVES: c:\program files (x86)\wildtangent games\app\browserintegration\registered\0\np_wtapp.dll
Deletes temporary Windows (27) (4,413,394 octets)

========== System restore ==========
The system successfully created restore point

========== Other ==========
NON-TREATY R5 - HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Parameters\Internet\ManualProxies []


========== Summary ==========
31 : Registry keys
7 : Registry values
12 : Elements of the registry data
5 : Folders
7 : Files
23 : Software
18 : Preferences browser
1 : System restore
1 : Other


End of clean in 20mn AMs

========== Path to file report ==========
C:\Users\Mitch\AppData\Roaming\ZHP\ZHPFix[R1].txt - 5/4/2017 3:46:58 PM [9538]
 
Glad to have helped!! Please tell a friend ...... or two about us.
smile.png


Optimize your internet connection.

Click here for instructions.


suggest the following in place of adblock.
Alternate DNS Server. Ad Blocking DNS.
Ublock Origin.
Anti Ad Block Killer.



Also, keep your browsing private with these tools:

Self Destructing Cookies.
Self Destructing Cookies Chrome.





Some items to keep you safe on the internet.


VooDoo Shield. control of what is running on your machine
Qualys BrowserCheck
To update plugins.
Web Of Trust To Avoid Shady Websites.
Unchecky To Avoid Bundled Software.
Privazer To Clean up your mahcine.



Now Lets Clean up the tools we used and remove old restore points.



Download DelFix by "Xplode" to your Desktop.

Right Click the tool and Run as Admin ( Xp Users Double Click)
Put a check mark next the items below:


Remove disinfection tools
Create registry backup
Purge System Restore




Now click on "Run" button.
allow the program to complete its work.
all the tools we used will be removed.
Tool will create and open a log report (DelFix.txt)
Note: The report can be located at the following location C:\DelFix.txt
 
Status
Not open for further replies.