# AdwCleaner 7.0.8.0 - Logfile created on Thu Feb 15 17:49:55 2018 # Updated on 2018/08/02 by Malwarebytes # Database: 02-15-2018.1 # Running on Windows 8.1 (X64) # Mode: scan # Support: https://www.malwarebytes.com/support ***** [ Services ] ***** No malicious services found. ***** [ Folders ] ***** PUP.Optional.Legacy, C:\Users\krystel\AppData\Local\SweetLabs App Platform PUP.Optional.Legacy, C:\Program Files (x86)\lavasoft\web companion PUP.Optional.Legacy, C:\Users\Public\Pokki PUP.Optional.WinZipMalwareProtector, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip Malware Protector PUP.Optional.WinZipMalwareProtector, C:\Program Files (x86)\WinZip Malware Protector PUP.Optional.WinZipMalwareProtector, C:\ProgramData\Nico Mak Computing\WinZip Malware Protector PUP.Optional.WinZipMalwareProtector, C:\ProgramData\Application Data\Nico Mak Computing\WinZip Malware Protector PUP.Optional.WinZipMalwareProtector, C:\Users\All Users\Nico Mak Computing\WinZip Malware Protector PUP.Optional.WinZipMalwareProtector, C:\Users\krystel\AppData\Roaming\Nico Mak Computing\WinZip Malware Protector PUP.Optional.Booking, C:\Program Files\Booking.com PUP.Optional.WebCompanion, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft\WebCompanion ***** [ Files ] ***** PUP.Optional.Legacy, C:\Windows\SysNative\wsusnative64.exe PUP.Optional.Legacy, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pokki Start Menu.lnk PUP.Optional.Legacy, C:\Users\krystel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pokki Start Menu.lnk PUP.Optional.WinZipMalwareProtector, C:\Users\All Users\Desktop\WinZip Malware Protector.lnk PUP.Optional.WinZipMalwareProtector, C:\Users\Public\Desktop\WinZip Malware Protector.lnk PUP.Optional.Booking, C:\Users\All Users\Desktop\Booking.com.lnk PUP.Optional.Booking, C:\Users\Public\Desktop\Booking.com.lnk PUP.Optional.WinYahoo, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HowToRemove.html.lnk PUP.Optional.PCAppStore, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk PUP.Optional.PCAppStore, C:\Users\krystel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk PUP.Optional.SearchProtect.AppFlsh, C:\Windows\AppPatch\Custom\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb ***** [ DLL ] ***** No malicious DLLs found. ***** [ WMI ] ***** No malicious WMI found. ***** [ Shortcuts ] ***** No malicious shortcuts found. ***** [ Tasks ] ***** PUP.Optional.Legacy, SweetLabs App Platform PUP.Optional.WinZipMalwareProtector, WinZip Malware Protector_startup PUP.Adware.Heuristic, WinZip Malware Protector_startup ***** [ Registry ] ***** PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Lavasoft\Web Companion PUP.Optional.Legacy, [Key] - HKU\S-1-5-21-3903720869-3876561350-3014114460-1001\Software\Lavasoft\Web Companion PUP.Optional.Legacy, [Key] - HKCU\Software\Lavasoft\Web Companion PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\MaxPower PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Interface\{41634761-D0BA-4C1A-9AC2-04AEE9511370} PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Interface\{88C20E16-1EB7-40CE-820C-6CFCB41B1D2F} PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\CLSID\{9C4EFBD5-1ADF-41E6-BE26-AF44326E30E4} PUP.Optional.Legacy, [Key] - HKCU\Software\Classes\CLSID\{9C4EFBD5-1ADF-41E6-BE26-AF44326E30E4} PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{5645E0E7-FC12-43BF-A6E4-F9751942B298} PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A} PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492} PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978} PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52} PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30} PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7} PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61} PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87} PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5} PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474} PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F} PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C} PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78} PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Interface\{023E9EC8-B147-40EB-B0B3-DF90618FB371} PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Interface\{0522D9A4-4D57-437D-978D-E5B3B6C9005D} PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Interface\{07F41522-AF7D-4F26-B394-094F059FDB8A} PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Interface\{0C40F472-7407-4467-8914-1DEA7C326972} PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Interface\{212E6D43-6062-492A-B8CC-144669FF11ED} PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Interface\{224FE662-1E6D-4BC0-AEBB-9E2FB4057BE9} PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Interface\{3A807417-B46D-4D37-8C9A-19AC6DE204F9} PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Interface\{3CC60715-D6C5-429D-830E-43FA3F86C61D} PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Interface\{4517D94C-19BA-46FA-BE66-2A30CEAC4A85} PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Interface\{555D7146-94A8-4C94-AE76-C39CDC7F7705} PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Interface\{59D188FA-757A-424E-8C93-F58FFD896BD7} PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Interface\{8120D9D6-785C-4413-9C0C-DF2028C56FAD} PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Interface\{823AE2EB-E62C-4847-B192-C99B91B92416} PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Interface\{9B4F7CFE-987D-410E-A8E4-20182E0B3C24} PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Interface\{9B9A45F4-18FC-484A-BACA-076D78273D8E} PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Interface\{A6D54287-7939-466A-8579-92546D946C8C} PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Interface\{A78EDAFB-926F-4D93-AB13-8232D7378EB1} PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Interface\{A8F7D0A5-7074-40B8-9BDC-1174BDD0A132} PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Interface\{D14D64BC-A0E4-42E3-BB72-FB41EA43C198} PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Interface\{DD1F043F-ABC8-4643-8B95-D2C5B22BB019} PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Interface\{E3F3E8F9-F747-4DD6-BA6B-82A6CE1E0860} PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Interface\{ED0B64D4-BF27-4521-AD27-190F49BF5EA7} PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\CLSID\{0757C9D8-D8A3-33F5-CEE2-11D09918BA8F} PUP.Optional.Legacy, [Key] - HKCU\Software\Classes\AllFileSystemObjects\shell\pokki PUP.Optional.Legacy, [Key] - HKCU\Software\Classes\Directory\shell\pokki PUP.Optional.Legacy, [Key] - HKCU\Software\Classes\Drive\shell\pokki PUP.Optional.Legacy, [Key] - HKCU\Software\Classes\lnkfile\shell\pokki PUP.Optional.Legacy, [Value] - HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\chrome.exe | {8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb PUP.Optional.Legacy, [Value] - HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\firefox.exe | {8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com PUP.Optional.Legacy, [Value] - HKLM\SOFTWARE\MICROSOFT\Windows NT\CurrentVersion\AppCompatFlags\Custom\chrome.exe | {8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb PUP.Optional.Legacy, [Value] - HKLM\SOFTWARE\MICROSOFT\Windows NT\CurrentVersion\AppCompatFlags\Custom\firefox.exe | {8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb PUP.Optional.Legacy, [Value] - HKLM\SOFTWARE\MICROSOFT\Windows NT\CurrentVersion\AppCompatFlags\Custom\iexplore.exe | {8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb PUP.Optional.Legacy, [Value] - HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\software_removal_tool.exe | {8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb PUP.Optional.Legacy, [Value] - HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\software_reporter_tool.exe | {8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb PUP.Optional.Legacy, [Value] - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION | StormWatchApp.exe PUP.Optional.ByteFence, [Value] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION | ByteFence.exe PUP.Optional.ByteFence, [Key] - HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Reason\ReasonByteFence PUP.Optional.ByteFence, [Value] - HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store | C:\Program Files\ByteFence\Uninstall.exe PUP.Optional.CrossRider, [Key] - HKU\S-1-5-21-3903720869-3876561350-3014114460-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\Crossrider Adware.pokki, [Key] - HKU\S-1-5-21-3903720869-3876561350-3014114460-1001\Software\SweetLabs App Platform Adware.pokki, [Key] - HKCU\Software\SweetLabs App Platform PUP.Optional.WinZipMalwareProtector, [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinZip Malware Protector_is1 PUP.Optional.WinZipMalwareProtector, [Key] - HKLM\SOFTWARE\NICO MAK COMPUTING\WINZIP MALWARE PROTECTOR PUP.Optional.WinZipMalwareProtector, [Key] - HKU\S-1-5-21-3903720869-3876561350-3014114460-1001\Software\NICO MAK COMPUTING\WINZIP MALWARE PROTECTOR PUP.Optional.WinZipMalwareProtector, [Key] - HKCU\Software\NICO MAK COMPUTING\WINZIP MALWARE PROTECTOR PUP.Optional.WinZipMalwareProtector, [Key] - HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application PUP.Optional.WinZipMalwareProtector, [Key] - HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application PUP.Optional.SupTab, [Value] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID | {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} PUP.Optional.Trovi, [Value] - HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\explorer.xxx | {8A4D5A43-C64A-45AB-BDF4-804FE18CEAFD}.SDB Adware.FileTour, [Key] - HKU\.DEFAULT\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\Installer Adware.FileTour, [Key] - HKU\S-1-5-21-3903720869-3876561350-3014114460-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\Installer Adware.FileTour, [Key] - HKU\S-1-5-18\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\Installer PUP.Optional.CrossRider.C, [Key] - HKU\S-1-5-21-3903720869-3876561350-3014114460-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\Crossrider PUP.Optional.MindSpark, [Key] - HKU\S-1-5-21-3903720869-3876561350-3014114460-1001\Software\Spark PUP.Optional.MindSpark, [Key] - HKCU\Software\Spark ***** [ Firefox (and derivatives) ] ***** No malicious Firefox entries. ***** [ Chromium (and derivatives) ] ***** PUP.Optional.Legacy, SearchProvider found: omiga-plus - isearch.omiga-plus.com PUP.Optional.Legacy, SearchProvider found: omiga-plus - omiga-plus /!\ Please Reset the Chrome Synchronization before cleaning the Chrome Preferences: https://support.google.com/chrome/answer/3097271 ************************* C:/AdwCleaner/AdwCleaner[S0].txt - [3638 B] - [2015/1/20 8:6:18] ########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt ##########