# AdwCleaner 7.0.6.0 - Logfile created on Sun Jan 14 11:32:48 2018 # Updated on 2017/21/12 by Malwarebytes # Database: 01-11-2018.1 # Running on Windows 10 Home (X64) # Mode: scan # Support: https://www.malwarebytes.com/support ***** [ Services ] ***** No malicious services found. ***** [ Folders ] ***** PUP.Optional.Legacy, C:\Users\azerty\AppData\Roaming\browsers PUP.Optional.Legacy, C:\Windows\System32\SSL PUP.Optional.Legacy, C:\Windows\SysWOW64\SSL PUP.Optional.Legacy, C:\Users\azerty\AppData\Local\AdvinstAnalytics PUP.Optional.DriverUpdatePlus, C:\Program Files (x86)\DriverUpdaterPlus PUP.Optional.DriverUpdatePlus, C:\Users\azerty\AppData\Local\Temp\DriverUpdaterPlus Adware.pokki, C:\Users\azerty\AppData\Local\Host App Service Adware.pokki, C:\Users\Default\AppData\Local\Host App Service Adware.pokki, C:\Users\Default User\AppData\Local\Host App Service Adware.pokki, C:\Users\defaultuser0\AppData\Local\Host App Service Adware.pokki, C:\Users\hakim\AppData\Local\Host App Service PUP.Optional.FastDataX, C:\Program Files (x86)\FastDataX PUP.Optional.Booking, C:\ProgramData\Booking.com PUP.Optional.Booking, C:\ProgramData\Application Data\Booking.com PUP.Optional.Booking, C:\Users\All Users\Booking.com PUP.Optional.ProxyGate, C:\Program Files (x86)\ProxyGate PUP.Optional.PCBooster, C:\Users\azerty\AppData\Local\PCBooster Adware.NeoBar, C:\Program Files (x86)\qTTaaczyWvUn Adware.NeoBar, C:\Program Files (x86)\aohGTEheqdnWC Adware.NeoBar, C:\Program Files (x86)\umkISPBbU Adware.NeoBar, C:\Program Files (x86)\TwPufLOWyrxU2 Adware.NeoBar, C:\Program Files (x86)\RrHYXuUpocPTIXdsppR Adware.NeoBar, C:\Program Files (x86)\GBeMZXQZBIE ***** [ Files ] ***** PUP.Optional.Legacy, C:\Users\azerty\Desktop\eBay.lnk PUP.Optional.Legacy, C:\Users\Default\Desktop\eBay.lnk PUP.Optional.Legacy, C:\Users\Default User\Desktop\eBay.lnk PUP.Optional.Legacy, C:\Users\defaultuser0\Desktop\eBay.lnk PUP.Optional.Legacy, C:\Users\hakim\Desktop\eBay.lnk Adware.BrowseFox, C:\Users\azerty\AppData\Roaming\xtexCalculator.exe ***** [ DLL ] ***** No malicious DLLs found. ***** [ WMI ] ***** No malicious WMI found. ***** [ Shortcuts ] ***** No malicious shortcuts found. ***** [ Tasks ] ***** Adware.NeoBar, pnIxobGIUDXdNt Adware.NeoBar, BcyoMZkjXMgFaPP Adware.NeoBar, saKXaLnxQURzlMgex2 Adware.NeoBar, BcyoMZkjXMgFaPP2 Adware.NeoBar, plaAVjRQXWCDePSecyr2 Adware.NeoBar, plaAVjRQXWCDePSecyr Adware.NeoBar, saKXaLnxQURzlMgex ***** [ Registry ] ***** PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Microsoft\{94ebd7b5-82ae-449t-b679-3d04078ed154} PUP.Optional.Legacy, [Key] - HKU\S-1-5-21-1161363882-2841013948-2172991090-1001\Software\Microsoft\{94ebd7b5-82ae-449t-b679-3d04078ed154} PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\{94ebd7b5-82ae-449t-b679-3d04078ed154} PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Microsoft\{1f7ee1a8-4436-4ffc-b97b-b5b01e87d3d2} PUP.Optional.Legacy, [Key] - HKU\S-1-5-21-1161363882-2841013948-2172991090-1001\Software\Microsoft\{1f7ee1a8-4436-4ffc-b97b-b5b01e87d3d2} PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\{1f7ee1a8-4436-4ffc-b97b-b5b01e87d3d2} PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Microsoft\{1f7ee1a8-4436-4ffc-b97b-b5b01e87d3d2} PUP.Optional.FastDataX, [Key] - HKU\S-1-5-21-1161363882-2841013948-2172991090-1001\Software\FastDataX PUP.Optional.FastDataX, [Key] - HKCU\Software\FastDataX PUP.Optional.DiskPower, [Key] - HKLM\SOFTWARE\Microsoft\{6711eba6-cf08-4edw-9528-86004fa424bb} PUP.Optional.DiskPower, [Key] - HKU\S-1-5-21-1161363882-2841013948-2172991090-1001\Software\Microsoft\{6711eba6-cf08-4edw-9528-86004fa424bb} PUP.Optional.DiskPower, [Key] - HKCU\Software\Microsoft\{6711eba6-cf08-4edw-9528-86004fa424bb} Adware.Yelloader, [Key] - HKU\S-1-5-21-1161363882-2841013948-2172991090-1001\Software\notepad3k Adware.Yelloader, [Key] - HKCU\Software\notepad3k Adware.OnlineIO, [Key] - HKLM\SOFTWARE\Microleaves PUP.Optional.WeatherAlerts, [Key] - HKU\S-1-5-21-1161363882-2841013948-2172991090-1001\Software\Microsoft\APreSam PUP.Optional.WeatherAlerts, [Key] - HKCU\Software\Microsoft\APreSam PUP.Optional.WeatherAlerts, [Key] - HKU\S-1-5-21-1161363882-2841013948-2172991090-1001\Software\Microsoft\NSaveA PUP.Optional.WeatherAlerts, [Key] - HKCU\Software\Microsoft\NSaveA PUP.Optional.WeatherAlerts, [Key] - HKU\S-1-5-21-1161363882-2841013948-2172991090-1001\Software\Microsoft\PrAmNP PUP.Optional.WeatherAlerts, [Key] - HKCU\Software\Microsoft\PrAmNP PUP.Optional.WeatherAlerts, [Key] - HKU\S-1-5-21-1161363882-2841013948-2172991090-1001\Software\Microsoft\PrIncub PUP.Optional.WeatherAlerts, [Key] - HKCU\Software\Microsoft\PrIncub PUP.Optional.WeatherAlerts, [Key] - HKLM\SOFTWARE\Microsoft\{cc6eb6d8-85b7-435p-8b86-51e4d16ea76d} PUP.Optional.WeatherAlerts, [Key] - HKU\S-1-5-21-1161363882-2841013948-2172991090-1001\Software\Microsoft\{cc6eb6d8-85b7-435p-8b86-51e4d16ea76d} PUP.Optional.WeatherAlerts, [Key] - HKCU\Software\Microsoft\{cc6eb6d8-85b7-435p-8b86-51e4d16ea76d} PUP.Optional.AdService, [Key] - HKU\S-1-5-21-1161363882-2841013948-2172991090-1001\Software\SetupCompany PUP.Optional.AdService, [Key] - HKCU\Software\SetupCompany PUP.Optional.Microleaves, [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\436F6625D7B77354DBCD89DDC6CFAB1A PUP.Optional.Microleaves, [Key] - HKLM\SOFTWARE\Classes\Installer\Features\436F6625D7B77354DBCD89DDC6CFAB1A PUP.Optional.Microleaves, [Key] - HKLM\SOFTWARE\Classes\Installer\Products\436F6625D7B77354DBCD89DDC6CFAB1A PUP.Optional.Microleaves, [Value] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders | C:\Program Files (x86)\Microleaves\Online Application\ PUP.Optional.Microleaves, [Value] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders | C:\Program Files (x86)\Microleaves\ PUP.Optional.Microleaves, [Value] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders | C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\ PUP.Optional.GenericTools, [Key] - HKU\S-1-5-21-1161363882-2841013948-2172991090-1001\Software\GenericTools PUP.Optional.GenericTools, [Key] - HKCU\Software\GenericTools PUP.Optional.MyPrintScreen, [Key] - HKU\S-1-5-21-1161363882-2841013948-2172991090-1001\Software\myprintscreen.com PUP.Optional.MyPrintScreen, [Key] - HKCU\Software\myprintscreen.com ***** [ Firefox (and derivatives) ] ***** No malicious Firefox entries. ***** [ Chromium (and derivatives) ] ***** PUP.Optional.Legacy, Plugin found: Chrome Cleaner Pro - PUP.Optional.22ChromeEXT, Plugin found: Tiempo en colombia en vivo - /!\ Please Reset the Chrome Synchronization before cleaning the Chrome Preferences: https://support.google.com/chrome/answer/3097271 ************************* ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt ##########