Step 1: Run AdwCleaner
https://www.softpedia.com/get/Antivirus/Removal-Tools/AdwCleaner.shtml
AdwCleaner is a free program that searches for and deletes Adware, Toolbars, Potentially Unwanted Programs (PUP), and browser Hijackers from your computer. By using AdwCleaner you can easily remove many of these types of programs for a better user experience on your computer and while browsing...
www.bleepingcomputer.com
AdwCleaner is a free removal tool for : Adware (ads software) PUP/LPI (Potentially Undesirable Program) Toolbars Hijacker (Hijack of the ...
toolslib.net
Download Malwarebytes AdwCleaner 2023 for free to remove adware, bloatware, unwanted toolbars, and other potentially unwanted programs (PUPs) from your Windows PC. AdwCleaner destroys adware and restores your PC's performance.
www.malwarebytes.com
Close all open programs and internet browsers.
Double click on AdwCleaner.exe to run the tool.
Click Scan Now
Click on Quarantine for all it finds.
Reboot.
Please Copy & Paste the contents of that logfile with your next reply.
View: https://i.imgur.com/qERgl4y.gif
Step 2: Run Malwarebytes Anti-Malware ( MBAM ) Use Threat Scan. Make sure Rootkit scan is on.
https://www.softpedia.com/get/Antivirus/Malwarebytes-Anti-Malware.shtml
Malwarebytes Anti Malware - An easy-to-use, effective application to detect and remove malware.
www.freewarefiles.com
https://www.freewarefiles.com/screenshot.php?programid=54166
Protect your home and business PCs, Macs, iOS and Android devices from the latest cyber threats and malware, including ransomware.
www.malwarebytes.org
Forum
www.malwarebytes.org
FAQ - Malwarebytes won't run or failed to resolve my issues
Greetings, While prevention is always better than having to deal with infections after the fact, and since cleanup can often be an incredibly difficult process, the following tutorials were created to assist you with using known methods to get Malwarebytes up and running when it is being prevente...
forums.malwarebytes.com
Scanning, you will get something like this.
View: https://i.imgur.com/4NZ5Qw0.gif
View: https://i.imgur.com/rRfr1oD.gif
View: https://i.imgur.com/tShE6tQ.gif
View: https://i.imgur.com/iJZHDC0.gif
After a restart ( if required ) Copy & Paste the contents of the scan into your reply.
If too large, upload to a site of your choosing.
Follow these directions, until you get to Export.
https://support.malwarebytes.com/hc/en-us/articles/360038479194
# -------------------------------
# Malwarebytes AdwCleaner 8.1.0.0
# -------------------------------
# Build: 02-15-2021
# Database: 2021-01-26.1 (Cloud)
# Support:
https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 03-01-2021
# Duration: 00:00:01
# OS: Windows 10 Home
# Cleaned: 16
# Failed: 0
* [ Services ]
*
Deleted Update service
* [ Folders ]
*
No malicious folders cleaned.
* [ Files ]
*
No malicious files cleaned.
* [ DLL ]
*
No malicious DLLs cleaned.
* [ WMI ]
*
No malicious WMI cleaned.
* [ Shortcuts ]
*
No malicious shortcuts cleaned.
* [ Tasks ]
*
No malicious tasks cleaned.
* [ Registry ]
*
Deleted HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|TCP Query User{B6CC6C34-120C-4106-8165-EA814D4DF542}C:\program files (x86)\popcorn time\nodejs\node.exe
Deleted HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|UDP Query User{04BD1627-9B8F-4511-BDCF-E9A81729BB1A}C:\program files (x86)\popcorn time\nodejs\node.exe
Deleted HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{35C30888-8C82-4291-B409-8A6622A031F2}
Deleted HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{4E75F98D-1484-4BC6-98B4-AF97CEC0DE11}
Deleted HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{8A6E0076-252F-4C47-AABE-E4048B3CEECA}
Deleted HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{8D0EC103-856C-46C3-BADE-337FCE159A0B}
Deleted HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{9C45EA96-544E-4F72-921A-E959E7D456D0}
Deleted HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{AFC2B06D-C28F-4BA0-980C-262E262E9481}
Deleted HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{C011CD24-B6D8-4DE1-9520-C08BE336945C}
Deleted HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{F38F2B01-A3CA-45CC-873F-3C1AF9F3F3CC}
* [ Chromium (and derivatives) ]
*
No malicious Chromium entries cleaned.
* [ Chromium URLs ]
*
No malicious Chromium URLs cleaned.
* [ Firefox (and derivatives) ]
*
No malicious Firefox entries cleaned.
* [ Firefox URLs ]
*
No malicious Firefox URLs cleaned.
* [ Hosts File Entries ]
*
No malicious hosts file entries cleaned.
* [ Preinstalled Software ]
*
Deleted Preinstalled.LenovoPowerDVD Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EFCFA2C4-5FB1-40C5-A05B-D12DF33B6151}
Deleted Preinstalled.LenovoPowerDVD Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PDVDServ12 Task
Deleted Preinstalled.LenovoPowerDVD Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}
Deleted Preinstalled.LenovoPowerDVD Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{B46BEA36-0B71-4A4E-AE41-87241643FA0A}
Deleted Preinstalled.LenovoPowerDVD Task C:\Windows\System32\Tasks\PDVDSERV12 TASK
*
[+] Delete Tracing Keys
[+] Reset Winsock
*
AdwCleaner[S00].txt - [3813 octets] - [01/03/2021 18:46:42]
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########