Jump to content

siobhannx

Members
  • Posts

    14
  • Joined

  • Last visited

Everything posted by siobhannx

  1. Thank you so so so much! Don't know what I would've done without your help
  2. Microsoft Windows Malicious Software Removal Tool v5.42, November 2016 (build 5.42.13202.0) Started On Tue Dec 06 20:45:26 2016 Engine: 1.1.13202.0 Signatures: 1.231.682.0 Run Mode: Preparing Heartbeat Telemetry Heartbeat Will be Sent in 2 Days Microsoft Windows Malicious Software Removal Tool Finished On Tue Dec 06 20:45:29 2016 Return code: 0 (0x0) Is that all you need?
  3. I think its gone! I'd have usually gotten the popup by now
  4. The popup is still coming up even when I dont have a browser open. Addition.txt FRST.txt 2016.12.10-19.32.43-i0-t92-d0.txt
  5. I left the scan running all night and the progress bar hadn't moved at all so I cancelled it. The nanocore dialog box us still popping up. Thanks
  6. Do you have any idea how long the sophos scan takes? The progress bar is still at like 2% but I'll leave it over night and report back.
  7. # AdwCleaner v6.040 - Logfile created 09/12/2016 at 23:45:23 # Updated on 02/12/2016 by Malwarebytes # Database : 2016-12-09.3 [Server] # Operating System : Windows 10 Home (X64) # Username : Siobhan - SIOBHAN-PC # Running from : C:\Users\Siobhan\Downloads\AdwCleaner.exe # Mode: Clean # Support : https://www.malwarebytes.com/support ***** [ Services ] ***** ***** [ Folders ] ***** [-] Folder deleted: C:\ProgramData\{c792037a-d00a-d850-c792-2037ad000deb} [-] Folder deleted: C:\Users\Siobhan\AppData\Local\3810282D-6C19-47B0-8283-5C6C29A7E108 [-] Folder deleted: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\myfree codec [-] Folder deleted: C:\Program Files (x86)\myfree codec [-] Folder deleted: C:\Users\Siobhan\AppData\Roaming\Profiles\dbz4xwqa.default ***** [ Files ] ***** ***** [ DLL ] ***** ***** [ WMI ] ***** ***** [ Shortcuts ] ***** ***** [ Scheduled Tasks ] ***** ***** [ Registry ] ***** [-] Key deleted: HKCU\Software\Classes\CLSID\{F28C2F70-47DE-4EA5-8F6D-7D1476CD1EF5} [-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{5C3B5DAA-0AFF-4808-90FB-0F2F2D760E36} [-] Key deleted: HKU\.DEFAULT\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA} [-] Key deleted: HKU\S-1-5-21-3246843572-2054726850-958999675-1000\Software\Myfree Codec [-] Key deleted: HKU\S-1-5-21-3246843572-2054726850-958999675-1000\Software\WEBAPP [-] Key deleted: HKU\S-1-5-21-3246843572-2054726850-958999675-1000\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA} [-] Key deleted: HKU\S-1-5-21-3246843572-2054726850-958999675-1000\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec [#] Key deleted on reboot: HKU\S-1-5-18\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA} [#] Key deleted on reboot: HKCU\Software\Myfree Codec [#] Key deleted on reboot: HKCU\Software\WEBAPP [#] Key deleted on reboot: HKCU\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA} [-] Key deleted: HKLM\SOFTWARE\{12A61307-94CD-4F8E-94BC-918E511FAA81} [-] Key deleted: HKLM\SOFTWARE\Myfree Codec [-] Key deleted: HKLM\SOFTWARE\{A16B1AF7-982D-40C3-B5C1-633E1A6A6678} [-] Key deleted: HKLM\SOFTWARE\{E6276374-DE18-4AA5-A365-9016A2F98A2D} [#] Key deleted on reboot: HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec [-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4CEE92A3-9F0C-51AB-ADC0-34EC24AD7B7E} [#] Key deleted on reboot: [x64] HKCU\Software\Myfree Codec [#] Key deleted on reboot: [x64] HKCU\Software\WEBAPP [#] Key deleted on reboot: [x64] HKCU\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA} [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec ***** [ Web browsers ] ***** [-] Firefox fake profile cleaned: Profile1 [-] [C:\Users\Siobhan\AppData\Local\Google\Chrome\User Data\Default] [extension] Deleted: aidgmjkfmbhldhnhkopojimkhhhcpenl [-] [C:\Users\Siobhan\AppData\Local\Google\Chrome\User Data\Default] [extension] Deleted: nonjdcjchghhkdoolnlbekcfllmednbl ************************* :: "Tracing" keys deleted :: Winsock settings cleared ************************* C:\AdwCleaner\AdwCleaner[C0].txt - [3191 Bytes] - [09/12/2016 23:45:23] C:\AdwCleaner\AdwCleaner[S0].txt - [3288 Bytes] - [09/12/2016 23:42:48] ########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [3337 Bytes] ##########
  8. Yes I did sorry forgot to attach it Fixlog.txt
  9. Malwarebytes Anti-Malware www.malwarebytes.org Scan Date: 09-Dec-16 Scan Time: 11:23 PM Logfile: Administrator: Yes Version: 2.2.1.1043 Malware Database: v2016.12.09.19 Rootkit Database: v2016.11.20.01 License: Trial Malware Protection: Enabled Malicious Website Protection: Enabled Self-protection: Disabled OS: Windows 10 CPU: x64 File System: NTFS User: Siobhan Scan Type: Threat Scan Result: Completed Objects Scanned: 385388 Time Elapsed: 11 min, 24 sec Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Enabled Heuristics: Enabled PUP: Enabled PUM: Enabled Processes: 0 (No malicious items detected) Modules: 0 (No malicious items detected) Registry Keys: 0 (No malicious items detected) Registry Values: 0 (No malicious items detected) Registry Data: 0 (No malicious items detected) Folders: 0 (No malicious items detected) Files: 0 (No malicious items detected) Physical Sectors: 0 (No malicious items detected) (end)
  10. When I open FRST it just opens in notepad? Am i meant to be opening it with something else? There's no fix button..
  11. Hi So I yesterday I was installing a software and I've gotten an infection on my computer. I've tried running malwarebytes and a couple of other softwares to remove it but this dialog box asking me if I "would like to install nanocore" keeps popping up. I've tried editing the registry too but it won't go away. Any help would be greatly appreciated thanks! Addition.txt FRST.txt
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.