# AdwCleaner 7.0.3.1 - Logfile created on Fri Oct 13 06:24:59 2017
# Updated on 2017/29/09 by Malwarebytes
# Database: 10-12-2017.1
# Running on Windows 7 Home Premium (X64)
# Mode: scan
# Support:
https://www.malwarebytes.com/support
***** [ Services ] *****
PUP.Optional.Legacy, mrupdsrv
PUP.Optional.Legacy, SvcHost Service Host
Adware.RuKometa, SvcHost Service Host
PUP.Optional.Mail.Ru, Updater.Mail.Ru
PUP.Optional.ProxyGate, pgt_svc
***** [ Folders ] *****
PUP.Optional.AdvancedSystemCare, C:\ProgramData\IObit\Advanced SystemCare
PUP.Optional.AdvancedSystemCare, C:\ProgramData\Application Data\IObit\Advanced SystemCare
PUP.Optional.AdvancedSystemCare, C:\Windows\System32\config\systemprofile\AppData\Roaming\IObit\Advanced SystemCare
PUP.Optional.AdvancedSystemCare, C:\Program Files (x86)\IObit\Advanced SystemCare
PUP.Optional.AdvancedSystemCare, C:\Program Files (x86)\Common Files\IObit\Advanced SystemCare
PUP.Optional.AdvancedSystemCare, C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\IObit\Advanced SystemCare
PUP.Optional.AdvancedSystemCare, C:\Users\All Users\IObit\Advanced SystemCare
PUP.Optional.AdvancedSystemCare, C:\Users\Jakub\AppData\LocalLow\IObit\Advanced SystemCare
PUP.Optional.AdvancedSystemCare, C:\Users\Jakub\AppData\Roaming\IObit\Advanced SystemCare
PUP.Optional.Legacy, C:\Users\Jakub\AppData\Roaming\..\Local\wupdate
PUP.Optional.Legacy, C:\ProgramData\IObit\ASCDownloader
PUP.Optional.Legacy, C:\ProgramData\Application Data\IObit\ASCDownloader
PUP.Optional.Legacy, C:\Users\All Users\IObit\ASCDownloader
PUP.Optional.Legacy, C:\Users\All Users\Documents\XMUpdate
PUP.Optional.Legacy, C:\Users\Public\Documents\XMUpdate
PUP.Optional.Legacy, C:\Users\Jakub\AppData\Roaming\Microsoft\Windows\Start Menu\Боковая панель - Комета
Adware.NeoBar, C:\Program Files (x86)\AvMVIUoBwtUn
PUP.Optional.ScriptWriter, C:\Users\Jakub\AppData\Local\ScriptWriter
PUP.Optional.Mail.Ru, C:\ProgramData\Mail.Ru
PUP.Optional.Mail.Ru, C:\ProgramData\Application Data\Mail.Ru
PUP.Optional.Mail.Ru, C:\Windows\System32\config\systemprofile\AppData\Local\Mail.Ru
PUP.Optional.Mail.Ru, C:\Program Files (x86)\Mail.Ru
PUP.Optional.Mail.Ru, C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Mail.Ru
PUP.Optional.Mail.Ru, C:\Users\All Users\Mail.Ru
PUP.Optional.ProxyGate, C:\Program Files (x86)\ProxyGate
PUP.Optional.EnjoyWiFi, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EnjoyWiFi
PUP.Optional.MirageISO, C:\Users\Public\Documents\XMUpdate
***** [ Files ] *****
PUP.Optional.Legacy, C:\Users\Jakub\Favorites\Mail.Ru.url
PUP.Optional.Legacy, C:\Users\Jakub\Favorites\Mail.Ru Агент - используй для общения!.url
PUP.Optional.ChinAd, C:\Windows\SysNative\drivers\wfcre.sys
Adware.RuKometa, C:\Users\Jakub\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Kometa.lnk
Adware.RuKometa, C:\Users\Jakub\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kometa.lnk
PUP.Optional.Mail.Ru, C:\Users\Jakub\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mail.Ru.lnk
PUP.Optional.CPUMiner, C:\Windows\Microsoft\svchost.exe.exe
***** [ DLL ] *****
No malicious DLLs found.
***** [ WMI ] *****
No malicious WMI found.
***** [ Shortcuts ] *****
PUP.Optional.Legacy, C:\Users\Jakub\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mail.Ru.lnk - url,FileProtocolHandler "http:\\www.mail.ru\cnt\20775012?gp=811008"
PUP.Optional.Legacy, C:\Users\Jakub\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mail.Ru.lnk - url,FileProtocolHandler "http:\\www.mail.ru\cnt\20775012?gp=811008"
***** [ Tasks ] *****
PUP.Optional.Legacy, MailRuUpdater
Adware.NeoBar, jJKowXmxzIFxIuj
Adware.NeoBar, jJKowXmxzIFxIuj2
Adware.NeoBar, LSjUFtTofwjkxN
PUP.Optional.ScriptWriter, ScriptWriter
***** [ Registry ] *****
PUP.Optional.AdvancedSystemCare, [Key] - HKLM\SOFTWARE\IOBIT\ASC
PUP.Optional.AdvancedSystemCare, [Key] - HKLM\SOFTWARE\CLASSES\DIRECTORY\SHELLEX\CONTEXTMENUHANDLERS\Advanced SystemCare
PUP.Optional.AdvancedSystemCare, [Key] - HKLM\SOFTWARE\CLASSES\DRIVE\SHELLEX\CONTEXTMENUHANDLERS\Advanced SystemCare
PUP.Optional.AdvancedSystemCare, [Key] - HKLM\SOFTWARE\CLASSES\LNKFILE\SHELLEX\CONTEXTMENUHANDLERS\Advanced SystemCare
PUP.Optional.AdvancedSystemCare, [Key] - HKLM\SOFTWARE\Google\Chrome\NativeMessagingHosts\com.ascplugin.protect
PUP.Optional.Legacy, [Data] - HKCU\Software\Microsoft\Internet Explorer\Main | Start Page [http:\\mail.ru\cnt\10445?gp=811013]
PUP.Optional.Legacy, [Data] - HKCU\Software\Microsoft\Internet Explorer\Main | Start Page [http:\\mail.ru\cnt\10445?gp=811013]
PUP.Optional.Legacy, [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {4113FF8F-F333-4FB9-9979-BE31F7E67EED}
PUP.Optional.Legacy, [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {84541A23-4AF5-40A6-AAA4-BB1E22D57D18}
PUP.Optional.Legacy, [Key] - HKU\S-1-5-21-1022301317-3172571395-1102472026-1000\Software\Microsoft\Gosearchq
PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Gosearchq
PUP.Optional.Legacy, [Key] - HKU\S-1-5-21-1022301317-3172571395-1102472026-1000\Software\Microsoft\Gosearch
PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Gosearch
PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\CLSID\{8E8F97CD-60B5-456F-A201-73065652D099}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E8F97CD-60B5-456F-A201-73065652D099}
PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8E8F97CD-60B5-456F-A201-73065652D099}
PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8E8F97CD-60B5-456F-A201-73065652D099}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AE298D-7E8A-4F53-BE55-15D2B065F6C0}
PUP.Optional.Legacy, [Value] - HKU\S-1-5-21-1022301317-3172571395-1102472026-1000\Software\Microsoft\Windows\CurrentVersion\Run | MailRuUpdater
PUP.Optional.Legacy, [Value] - HKCU\Software\Microsoft\Windows\CurrentVersion\Run | MailRuUpdater
PUP.Optional.Kometa, [Key] - HKLM\SOFTWARE\NetBox
PUP.Optional.Kometa, [Key] - HKU\S-1-5-21-1022301317-3172571395-1102472026-1000\Software\NetBox
PUP.Optional.Kometa, [Key] - HKCU\Software\NetBox
Adware.NeoBar, [Key] - HKLM\SOFTWARE\Classes\CLSID\{C0D38E5A-7CF8-4105-8FE8-31B81443A114}
Adware.NeoBar, [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C0D38E5A-7CF8-4105-8FE8-31B81443A114}
Adware.NeoBar, [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C0D38E5A-7CF8-4105-8FE8-31B81443A114}
Adware.NeoBar, [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C0D38E5A-7CF8-4105-8FE8-31B81443A114}
Adware.RuKometa, [Key] - HKU\S-1-5-21-1022301317-3172571395-1102472026-1000\Software\MICROSOFT\KometaInstaller
Adware.RuKometa, [Key] - HKCU\Software\MICROSOFT\KometaInstaller
Adware.RuKometa, [Key] - HKLM\SOFTWARE\NETBOX\Kometa
Adware.RuKometa, [Key] - HKU\S-1-5-21-1022301317-3172571395-1102472026-1000\Software\NETBOX\Kometa
Adware.RuKometa, [Key] - HKCU\Software\NETBOX\Kometa
PUP.Optional.NeoBar.ChrPRST, [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\E3605470-291B-44EB-8648-745EE356599A
PUP.Optional.Mail.Ru, [Key] - HKLM\SOFTWARE\Mail.Ru
PUP.Optional.Mail.Ru, [Key] - HKU\.DEFAULT\Software\Mail.Ru
PUP.Optional.Mail.Ru, [Key] - HKU\S-1-5-21-1022301317-3172571395-1102472026-1000\Software\Mail.Ru
PUP.Optional.Mail.Ru, [Key] - HKU\S-1-5-21-1022301317-3172571395-1102472026-1000\Software\AppDataLow\Software\Mail.Ru
PUP.Optional.Mail.Ru, [Key] - HKU\S-1-5-18\Software\Mail.Ru
PUP.Optional.Mail.Ru, [Key] - HKCU\Software\Mail.Ru
PUP.Optional.Mail.Ru, [Key] - HKCU\Software\AppDataLow\Software\Mail.Ru
PUP.Optional.ProxyGate, [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1EC095EE-8CA3-43D6-B9F5-0C55B82ED3D7}}_is1
PUP.Optional.Yontoo, [Key] - HKU\S-1-5-21-1022301317-3172571395-1102472026-1000\Software\Amigo
PUP.Optional.Yontoo, [Key] - HKCU\Software\Amigo
PUP.Optional.InstallCore, [Key] - HKU\S-1-5-21-1022301317-3172571395-1102472026-1000\Software\csastats
PUP.Optional.InstallCore, [Key] - HKCU\Software\csastats
PUP.Optional.ProductSetup.A, [Key] - HKU\S-1-5-21-1022301317-3172571395-1102472026-1000\Software\PRODUCTSETUP
PUP.Optional.ProductSetup.A, [Key] - HKCU\Software\PRODUCTSETUP
PUP.Optional.EnjoyWiFi, [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8948C1BE-92B8-4276-8803-DC71CC78203A}
***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries.
***** [ Chromium (and derivatives) ] *****
No malicious Chromium entries.
*************************
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt ##########