2017-03-11 - Back for more

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Fla_Panther
    PCHF Member
    • Sep 2016
    • 38

    #31
    Fix scan never prompted me to install certificates, so I proceeded with the rest of the instructions.

    ---------- | AdsFix | g3n-h@ckm@n | V4_03.04.17.4

    ----- Vista | 7 | 8 | 8.1 | 10 - 32/64 bits ----- Start 22:12:37 - 04/04/2017

    update on : 03/04/2017 | 14.20 (GMT) by g3n-h@ckm@n
    Contact : http://www.sosvirus.net
    Assistance : Dépannage Informatique à Distance - Assistance Informatique | SOSVirus
    Feedbacks : Télécharger KMSPico Activator Windows 11 et Office 2021
    Facebook : AdsFix-Anti-Adware
    C:\Users*\Desktop\AdsFix.exe
    Boot: Normal boot
    [
    * (Administrator)] - [******-PC] - (USA [0409])
    SID = S-1-5-21-3113485377-2953679804-1031508582-1000 || [5374657665205e5e]
    PC : MSI - B75MA-E33 (MS-7808) - To be filled by O.E.M.
    Processor : X64 - 3192 - Intel(R) Core™ i5-3470 CPU @ 3.20GHz
    Bios : American Megatrends Inc. - 01/21/2013 - V.V1.4
    CoreTemp : 29.8 C

    CPU #1 value:0 %
    CPU #2 value:18 %
    CPU #3 value:0 %
    CPU #4 value:0 %
    Total Overall CPU Usage value:4 %

    System : Windows 7 Home Premium (64 bits) HomePremium Service Pack 1
    RAM memory = Total (MB) : 8318 | Free (MB) : 6493
    Pagefile = Total (MB) : 16634 | Free (MB) : 14643
    Virtual = Total (MB) : 4194 | Free (MB) : 3971

    C:\ → [Fixed] | | Total : 465.66 Go | Free : 215.43 Go → NTFS [SATA]

    Registry saved, to restore : Click on Options & Restore the register (C:\AdsFix\Save\Registry [04.04.2017 @ 22_12_34]) or an element
    Restore files or folders deleted by mistake : Click on Options & Restore Files | Folders, Select an item >> “restore”

    ---------- | Windows Updates

    Last detection : 2017-04-04 16:45:01
    Last downloaded : 2017-03-11 19:50:15
    Last installation : 2017-03-11 19:52:47
    Next search : 2017-04-05 12:20:02

    Windows Is Activated

    ---------- | Browsers

    IE : 11.0.9600.18538 (© Microsoft Corporation. All rights reserved.)
    FF : 52.0.2.6291 (©Firefox and Mozilla Developers; available under the MPL 2 license.)

    ---------- | Security (atcav : 0)

    AV :
    AS : Windows Defender Disabled
    FW :
    WMI : OK
    WU: Windows Update Service [Auto(2)] = Started
    AS: Windows Defender [Auto(2)] = Order
    FW: Windows FireWall Service [Auto(2)] = Started
    WMI: Windows Management Instrumentation (System Information) [Auto(2)] = Started

    ---------- | FlashPlayer

    ActiveX : 25.0.0.127
    Plugin : 25.0.0.127

    ---------- | Killed processes

    828 | [Owner : SYSTEM |Parent : 592(services.exe)] - (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 341.44.) - (8.17.13.4144) = C:\Windows\System32\nvvsvc.exe
    852 | [Owner : SYSTEM |Parent : 592(services.exe)] - (.NVIDIA Corporation - Stereo Vision Control Panel API Server.) - (7.17.13.4144) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
    1348 | [Owner : SYSTEM |Parent : 828()] - (.NVIDIA Corporation - NVIDIA User Experience Driver Component.) - (8.17.13.4144) = C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
    1356 | [Owner : SYSTEM |Parent : 828()] - (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 341.44.) - (8.17.13.4144) = C:\Windows\System32\nvvsvc.exe
    1484 | [Owner : SYSTEM |Parent : 592(services.exe)] - (.Microsoft Corporation - Spooler SubSystem App.) - (6.1.7601.17777) = C:\Windows\System32\spoolsv.exe
    1640 | [Owner : SYSTEM |Parent : 592(services.exe)] - (.Apple Inc. - MobileDeviceService.) - (17.374.70.8) = C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    1696 | [Owner : SYSTEM |Parent : 592(services.exe)] - (.Apple Inc. - Bonjour Service.) - (3.1.0.1) = C:\Program Files\Bonjour\mDNSResponder.exe
    1800 | [Owner : SYSTEM |Parent : 592(services.exe)] - (.Foxit Software Inc. - Foxit Reader ConnectedPDF Windows Service..) - (8.2.0.1206) = C:\Program Files (x86)\Foxit Software\Foxit Reader\FoxitConnectedPDFService.exe
    1912 | [Owner : SYSTEM |Parent : 592(services.exe)] - (.Aladdin Knowledge Systems Ltd. - Aladdin HASP License Manager Service.) - (12.47.1.11911) = C:\Windows\System32\hasplms.exe
    1988 | [Owner : SYSTEM |Parent : 592(services.exe)] - (.Microsoft Corporation - Machine Debug Manager.) - (7.10.3077.0) = C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\mdm.exe
    1188 | [Owner : ****** |Parent : 592(services.exe)] - (.Microsoft Corporation - Host Process for Windows Tasks.) - (6.1.7601.18010) = C:\Windows\System32\taskhost.exe
    2228 | [Owner : SYSTEM |Parent : 592(services.exe)] - (.BUFFALO INC. - NAS Power Management Service.) - (1.0.9.1121) = C:\Program Files (x86)\BUFFALO\NASNAVI\nassvc.exe
    2300 | [Owner : SYSTEM |Parent : 592(services.exe)] - (.NVIDIA Corporation - NVIDIA Network Service.) - (1.0.8.24) = C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
    2332 | [Owner : SYSTEM |Parent : 592(services.exe)] - (.NVIDIA Corporation - NVIDIA Streamer Service.) - (3.1.100.0) = C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
    2476 | [Owner : SYSTEM |Parent : 592(services.exe)] - (.PACE Anti-Piracy, Inc. - PACE License Service.) - (2.4.7.852) = C:\Program Files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe
    2580 | [Owner : SYSTEM |Parent : 592(services.exe)] - (.Paramount Software UK Ltd - Reflect Service - Enables mounting of images.) - (6.1.865.0) = C:\Program Files\Macrium\Reflect\ReflectService.exe
    2724 | [Owner : SYSTEM |Parent : 592(services.exe)] - (.Copyright 2017. - ZAM.) - (2.72.0.324) = C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe
    3364 | [Owner : ****** |Parent : 1348()] - (.NVIDIA Corporation - NVIDIA Settings.) - (7.17.13.4144) = C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
    3392 | [Owner : ****** |Parent : 3364()] - (.NVIDIA Corporation - NVIDIA GeForce Experience Backend.) - (15.3.33.0) = C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
    3492 | [Owner : LOCAL SERVICE |Parent : 592(services.exe)] - (.Microsoft Corporation - PresentationFontCache.exe.) - (3.0.6920.5011) = C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\Pres entationFontCache.exe
    2192 | [Owner : SYSTEM |Parent : 2332()] - (.NVIDIA Corporation - NVIDIA Streamer Service.) - (3.1.100.0) = C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
    4152 | [Owner : ****** |Parent : 2424(explorer.exe)] - (.Microsoft Corporation - Notepad.) - (6.1.7601.18917) = C:\Windows\System32\notepad.exe
    4324 | [Owner : NETWORK SERVICE |Parent : 592(services.exe)] - (.Microsoft Corporation - Windows Media Player Network Sharing Service.) - (12.0.7601.17514) = C:\Program Files\Windows Media Player\wmpnetwk.exe
    4744 | [Owner : ****** |Parent : 2424(explorer.exe)] - (.Mozilla Corporation - Firefox.) - (52.0.2.6291) = C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    1164 | [Owner : ****** |Parent : 4744(firefox.exe)] - (.Mozilla Corporation - Firefox.) - (52.0.2.6291) = C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    1812 | [Owner : NETWORK SERVICE |Parent : 592(services.exe)] - (.Microsoft Corporation - Microsoft Software Protection Platform Service.) - (6.1.7601.17514) = C:\Windows\System32\sppsvc.exe
    4132 | [Owner : SYSTEM |Parent : 592(services.exe)] - (.Microsoft Corporation - Windows Modules Installer.) - (6.1.7601.17514) = C:\Windows\servicing\TrustedInstaller.exe

    ---------- | Tasks

    Deleted successfully : Trojan Remover

    ---------- | Services

    Deleted service : rpcapd : “%ProgramFiles(x86)%\WinPcap\rpcapd.exe” -d -f “%ProgramFiles(x86)%\WinPcap\rpcapd.ini”

    ---------- | AppCertDlls | AppInit_DLLs

    ---------- | DNSapi.dll

    C:\Windows\System32\dnsapi.dll : \drivers\etc\hosts
    C:\Windows\SysWOW64\dnsapi.dll : \drivers\etc\hosts

    ---------- | Hosts

    ---------- | SafeBoot

    ---------- | Winsock

    ---------- | DNS

    ---------- | Register

    VirusTotal

    Comment

    • Malnutrition
      PCHF Moderator
      • Jul 2016
      • 7045

      #32
      From what I see you are malware free…

      Comment

      Working...