Re: File not disinfected: C:\WINDOWS\System32\dnsapi.dll

Thanks fr33tux, here is the log:

1. ========================= SEAF 1.0.1.0 - C_XX 2.  3. Commencé à: 06:43:11 le 06/10/2016 4.  5. Valeur(s) recherchée(s): 6. dnsapi.dll 7.  8. Légende: TC => Date de création, TM => Date de modification, DA => Dernier accès 9.  10.  11. ====== Fichier(s) ====== 12.  13.  14. "C:\Windows\System32\dnsapi.dll" [ ARCHIVE | 499 Ko ] 15. TC: 25/08/2016,07:11:35 | T...

Re: File not disinfected: C:\WINDOWS\System32\dnsapi.dll

Hello,

Can you do the following to look for "dnsapi.dll" files on your computer ?

  • Download SEAF : https://toolslib.net/downloads/viewdownload/155-seaf/
  • Right-click on the icon -> Execute as Administrator.
  • In the search field, type "dnsapi.dll".
  • Then, start the search. A report will open when the search is over (it contains the search results). Please share it here.

Best regards,

File not disinfected: C:\WINDOWS\System32\dnsapi.dll

As the title suggests. I believe this virus is responsible for Windows Defender not being to update its definitions or run at all. Log:

# AdwCleaner v6.020 - Logfile created 05/10/2016 at 20:24:47
# Updated on 14/09/2016 by ToolsLib
# Database : 2016-10-03.1 [Server]
# Operating System : Windows Embedded 8.1 Industry Pro  (X64)
# Username : Jamie - JAMIES-PC
# Running from : C:\Users\Jamie\Do...

Re: A whole lot of damage

Thanks for your reply. There was one more thing that wasn't working that I forgot to mention, the HP Simple Pass fingerprint reader for logging in. There may have been more. Fortunately I did have a system image, and I restored everything. I have to say I was more than surprised that 18 items were flagged for deletion, I have MalwareBytes and AntiExploit Premium running, I am very picky when it...

Re: Adwcleaner false positive?

# AdwCleaner v6.020 - Logfile created 01/10/2016 at 07:53:28 # Updated on 14/09/2016 by ToolsLib # Database : 2016-09-30.1 [Server] # Operating System : Windows 7 Professional Service Pack 1 (X64) # Username : paulm - DESIGN2015 # Running from : C:\Users\Paulm.TOOLS\Downloads\adwcleaner_6.020.exe # Mode: Scan # Support : https://toolslib.net/forum



***** [ Services ] *****

No malicious serv...

Re: False Positive (Firefox add-on)

# AdwCleaner v6.020 - Logfile created 30/09/2016 at 15:03:49
# Updated on 14/09/2016 by ToolsLib
# Database : 2016-09-28.1 [Server]
# Operating System : Windows 7 Ultimate Service Pack 1 (X86)
# Running from : C:\Users\xxxxx\Desktop\Programs and Stuff\AdwCleaner\adwcleaner_6.020.exe
# Mode: Scan
# Support : https://toolslib.net/forum


***** [ Services ] *****

No malicious services found.

**...

Can't delete UCGuard

Hello, I saw a similar post of a guy that had his adwcleaner crashing whenever he tried to clean "UCGuard". I'm having the exact same problem. If someone could please guide me on how to remove it I would be very pleased. Sorry for the inconvenience. Here is a link to the infected parts: https://gyazo.com/8ef4445d8ab9eb2d5c64b111436a04e0  

Re: Adwcleaner ne fonctionne pas, messages que je ne comprends pas

Bonsoir, cette fois Adwcleaner à bien fonctionné, et il a trouvé 43 infections, voici le rapport après avoir cliqué sur "Nettoyer"

# AdwCleaner v6.020 - Rapport créé le 28/09/2016 à 19:51:16 # Mis à jour le 14/09/2016 par ToolsLib # Base de données : 2016-09-27.2 [Serveur] # Système d'exploitation : Windows 10 Home  (X64) # Nom d'utilisateur : ROLANDIN - ROLAND # Exécuté depuis : C:\Users\ROLA...

Fausse détection

Bonjour.

Je viens de passer Adwcleaner, qui aujourd'hui vient de me trouver un raccourci existant depuis 2013, infecté.

Celui ci faisant référence à ATIH (Acronis True Image Home)

Assurément une erreur ?

***** [ Raccourcis ] *****

Raccourci infecté:  C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acronis\True Image\Outils et utilitaires\Monter une image.lnk ( /mount_image )

Re: Does not Work

yes it takes time but it depends , if the hard drive is full , if there's many sessions , in the computer is very infected.... it depends of so many things...... this tools reads almost all the unknown keys/folders/files by windows