# AdwCleaner 7.0.1.0 - Logfile created on Thu Aug 10 16:20:58 2017 # Updated on 2017/05/08 by Malwarebytes # Database: 08-09-2017.2 # Running on Windows 7 Home Premium (X86) # Mode: scan # Support: https://www.malwarebytes.com/support ***** [ Services ] ***** No malicious services found. ***** [ Folders ] ***** PUP.Optional.SpyHunter, C:\Program Files\Enigma Software Group PUP.Adware.Heuristic, C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log PUP.Adware.Heuristic, C:\ProgramData\{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}.log PUP.Adware.Heuristic, C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log PUP.Adware.Heuristic, C:\ProgramData\{B7A0CE06-068E-11D6-97FD-0050BACBF861}.log PUP.Adware.Heuristic, C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log PUP.Adware.Heuristic, C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log ***** [ Files ] ***** No malicious files found. ***** [ DLL ] ***** No malicious DLLs found. ***** [ WMI ] ***** No malicious WMI found. ***** [ Shortcuts ] ***** No malicious shortcuts found. ***** [ Tasks ] ***** No malicious tasks found. ***** [ Registry ] ***** PUP.Optional.Legacy, [Data] - HKCU\Software\Microsoft\Internet Explorer\Main | Search Page [https:\\safesearch.avira.com\#web\result?source=art&q=] PUP.Optional.Legacy, [Data] - HKCU\Software\Microsoft\Internet Explorer\Main | Search Page [https:\\safesearch.avira.com\#web\result?source=art&q=] PUP.Optional.Legacy, [Data] - HKCU\Software\Microsoft\Internet Explorer\Main | Default_Page_URL [https:\\safesearch.avira.com\#web\result?source=art&q=] PUP.Optional.Legacy, [Data] - HKCU\Software\Microsoft\Internet Explorer\Main | Default_Page_URL [https:\\safesearch.avira.com\#web\result?source=art&q=] PUP.Optional.Legacy, [Data] - HKCU\Software\Microsoft\Internet Explorer\Main | Default_Search_URL [https:\\safesearch.avira.com\#web\result?source=art&q=] PUP.Optional.Legacy, [Data] - HKCU\Software\Microsoft\Internet Explorer\Main | Default_Search_URL [https:\\safesearch.avira.com\#web\result?source=art&q=] PUP.Optional.Legacy, [Data] - HKCU\Software\Microsoft\Internet Explorer\Main | Start Page_TIMESTAMP [㙚덺ἦǒs:\\safesearch.avira.com\#web\result?source=art&q=] PUP.Optional.Legacy, [Data] - HKCU\Software\Microsoft\Internet Explorer\Main | Start Page_TIMESTAMP [㙚덺ἦǒs:\\safesearch.avira.com\#web\result?source=art&q=] PUP.Optional.Legacy, [Data] - HKCU\Software\Microsoft\Internet Explorer\Main | SyncHomePage Protected - It is a violation of Windows Policy to modify. See aka.ms\browserpolicy [㙚덺ἦǒs:\\safesearch.avira.com\#web\result?source=art&q=] PUP.Optional.Legacy, [Data] - HKCU\Software\Microsoft\Internet Explorer\Main | SyncHomePage Protected - It is a violation of Windows Policy to modify. See aka.ms\browserpolicy [㙚덺ἦǒs:\\safesearch.avira.com\#web\result?source=art&q=] PUP.Optional.Legacy, [Data] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main | Default_Search_URL [https:\\safesearch.avira.com\#web\result?source=art&q=] PUP.Optional.Legacy, [Data] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main | Default_Search_URL [https:\\safesearch.avira.com\#web\result?source=art&q=] PUP.Optional.Legacy, [Data] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main | Default_Page_URL [https:\\safesearch.avira.com\#web\result?source=art&q=] PUP.Optional.Legacy, [Data] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main | Default_Page_URL [https:\\safesearch.avira.com\#web\result?source=art&q=] PUP.Optional.Legacy, [Data] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main | Start Page [https:\\safesearch.avira.com\#web\result?source=art&q=] PUP.Optional.Legacy, [Data] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main | Start Page [https:\\safesearch.avira.com\#web\result?source=art&q=] PUP.Optional.Legacy, [Data] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main | Search Page [https:\\safesearch.avira.com\#web\result?source=art&q=] PUP.Optional.Legacy, [Data] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main | Search Page [https:\\safesearch.avira.com\#web\result?source=art&q=] PUP.Optional.Legacy, [Value] - HKCU\Software\Microsoft\Internet Explorer\SearchScopes | DoNotAskAgain PUP.Optional.Legacy, [Value] - HKU\S-1-5-21-1871111397-3539990770-1974983793-1000\Software\Microsoft\Internet Explorer\SearchScopes | DoNotAskAgain PUP.Optional.Legacy, [Value] - HKU\S-1-5-21-1871111397-3539990770-1974983793-1000\Software\Microsoft\Internet Explorer\SearchScopes | DoNotAskAgain PUP.Optional.Legacy, [Key] - HKU\S-1-5-21-1871111397-3539990770-1974983793-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\MediaPlayerplus PUP.Optional.Legacy, [Value] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID | {58124A0B-DC32-4180-9BFF-E0E21AE34026} PUP.Optional.Legacy, [Value] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID | {A09AB6EB-31B5-454C-97EC-9B294D92EE2A} PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Interface\{94952EC4-DB66-3F32-BE4C-F0BB875EA98E} PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Installer\UpgradeCodes\5B4758C25396ECF468E04F8E063287FF PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\18C9E3869A16248439FE3FF9EB02207A PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{9522B3FB-7A2B-4646-8AF6-36E7F593073C} PUP.Optional.Legacy, [Value] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext | DisableAddonLoadTimePerformanceNotifications PUP.Optional.Iminent, [Value] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID | {977AE9CC-AF83-45E8-9E03-E2798216E2D5} PUP.Optional.SpyHunter, [Key] - HKLM\SOFTWARE\EnigmaSoftwareGroup PUP.Optional.SupTab, [Value] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID | {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} ***** [ Firefox (and derivatives) ] ***** No malicious Firefox entries. ***** [ Chromium (and derivatives) ] ***** SearchProvider found: Ask - ask.com /!\ Please Reset the Chrome Synchronization before cleaning the Chrome Preferences: https://support.google.com/chrome/answer/3097271 ************************* ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt ##########