siobhannx
Members-
Posts
14 -
Joined
-
Last visited
Content Type
Events
Profiles
Forums
Everything posted by siobhannx
-
Thank you so so so much! Don't know what I would've done without your help
-
Microsoft Windows Malicious Software Removal Tool v5.42, November 2016 (build 5.42.13202.0) Started On Tue Dec 06 20:45:26 2016 Engine: 1.1.13202.0 Signatures: 1.231.682.0 Run Mode: Preparing Heartbeat Telemetry Heartbeat Will be Sent in 2 Days Microsoft Windows Malicious Software Removal Tool Finished On Tue Dec 06 20:45:29 2016 Return code: 0 (0x0) Is that all you need?
-
I think its gone! I'd have usually gotten the popup by now
-
Fixlog.txt
-
The popup is still coming up even when I dont have a browser open. Addition.txt FRST.txt 2016.12.10-19.32.43-i0-t92-d0.txt
-
I left the scan running all night and the progress bar hadn't moved at all so I cancelled it. The nanocore dialog box us still popping up. Thanks
-
Do you have any idea how long the sophos scan takes? The progress bar is still at like 2% but I'll leave it over night and report back.
-
# AdwCleaner v6.040 - Logfile created 09/12/2016 at 23:45:23 # Updated on 02/12/2016 by Malwarebytes # Database : 2016-12-09.3 [Server] # Operating System : Windows 10 Home (X64) # Username : Siobhan - SIOBHAN-PC # Running from : C:\Users\Siobhan\Downloads\AdwCleaner.exe # Mode: Clean # Support : https://www.malwarebytes.com/support ***** [ Services ] ***** ***** [ Folders ] ***** [-] Folder deleted: C:\ProgramData\{c792037a-d00a-d850-c792-2037ad000deb} [-] Folder deleted: C:\Users\Siobhan\AppData\Local\3810282D-6C19-47B0-8283-5C6C29A7E108 [-] Folder deleted: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\myfree codec [-] Folder deleted: C:\Program Files (x86)\myfree codec [-] Folder deleted: C:\Users\Siobhan\AppData\Roaming\Profiles\dbz4xwqa.default ***** [ Files ] ***** ***** [ DLL ] ***** ***** [ WMI ] ***** ***** [ Shortcuts ] ***** ***** [ Scheduled Tasks ] ***** ***** [ Registry ] ***** [-] Key deleted: HKCU\Software\Classes\CLSID\{F28C2F70-47DE-4EA5-8F6D-7D1476CD1EF5} [-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{5C3B5DAA-0AFF-4808-90FB-0F2F2D760E36} [-] Key deleted: HKU\.DEFAULT\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA} [-] Key deleted: HKU\S-1-5-21-3246843572-2054726850-958999675-1000\Software\Myfree Codec [-] Key deleted: HKU\S-1-5-21-3246843572-2054726850-958999675-1000\Software\WEBAPP [-] Key deleted: HKU\S-1-5-21-3246843572-2054726850-958999675-1000\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA} [-] Key deleted: HKU\S-1-5-21-3246843572-2054726850-958999675-1000\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec [#] Key deleted on reboot: HKU\S-1-5-18\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA} [#] Key deleted on reboot: HKCU\Software\Myfree Codec [#] Key deleted on reboot: HKCU\Software\WEBAPP [#] Key deleted on reboot: HKCU\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA} [-] Key deleted: HKLM\SOFTWARE\{12A61307-94CD-4F8E-94BC-918E511FAA81} [-] Key deleted: HKLM\SOFTWARE\Myfree Codec [-] Key deleted: HKLM\SOFTWARE\{A16B1AF7-982D-40C3-B5C1-633E1A6A6678} [-] Key deleted: HKLM\SOFTWARE\{E6276374-DE18-4AA5-A365-9016A2F98A2D} [#] Key deleted on reboot: HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec [-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4CEE92A3-9F0C-51AB-ADC0-34EC24AD7B7E} [#] Key deleted on reboot: [x64] HKCU\Software\Myfree Codec [#] Key deleted on reboot: [x64] HKCU\Software\WEBAPP [#] Key deleted on reboot: [x64] HKCU\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA} [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec ***** [ Web browsers ] ***** [-] Firefox fake profile cleaned: Profile1 [-] [C:\Users\Siobhan\AppData\Local\Google\Chrome\User Data\Default] [extension] Deleted: aidgmjkfmbhldhnhkopojimkhhhcpenl [-] [C:\Users\Siobhan\AppData\Local\Google\Chrome\User Data\Default] [extension] Deleted: nonjdcjchghhkdoolnlbekcfllmednbl ************************* :: "Tracing" keys deleted :: Winsock settings cleared ************************* C:\AdwCleaner\AdwCleaner[C0].txt - [3191 Bytes] - [09/12/2016 23:45:23] C:\AdwCleaner\AdwCleaner[S0].txt - [3288 Bytes] - [09/12/2016 23:42:48] ########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [3337 Bytes] ##########
-
Yes I did sorry forgot to attach it Fixlog.txt
-
Malwarebytes Anti-Malware www.malwarebytes.org Scan Date: 09-Dec-16 Scan Time: 11:23 PM Logfile: Administrator: Yes Version: 2.2.1.1043 Malware Database: v2016.12.09.19 Rootkit Database: v2016.11.20.01 License: Trial Malware Protection: Enabled Malicious Website Protection: Enabled Self-protection: Disabled OS: Windows 10 CPU: x64 File System: NTFS User: Siobhan Scan Type: Threat Scan Result: Completed Objects Scanned: 385388 Time Elapsed: 11 min, 24 sec Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Enabled Heuristics: Enabled PUP: Enabled PUM: Enabled Processes: 0 (No malicious items detected) Modules: 0 (No malicious items detected) Registry Keys: 0 (No malicious items detected) Registry Values: 0 (No malicious items detected) Registry Data: 0 (No malicious items detected) Folders: 0 (No malicious items detected) Files: 0 (No malicious items detected) Physical Sectors: 0 (No malicious items detected) (end)
-
Nevermind I get it now..
-
When I open FRST it just opens in notepad? Am i meant to be opening it with something else? There's no fix button..
-
Thanks for the quick reply! report.txt
-
Hi So I yesterday I was installing a software and I've gotten an infection on my computer. I've tried running malwarebytes and a couple of other softwares to remove it but this dialog box asking me if I "would like to install nanocore" keeps popping up. I've tried editing the registry too but it won't go away. Any help would be greatly appreciated thanks! Addition.txt FRST.txt