# AdwCleaner 7.0.8.0 - Logfile created on Sat Mar 03 11:37:34 2018 # Updated on 2018/08/02 by Malwarebytes # Database: 02-08-2018.1 # Running on Windows 10 Home (X64) # Mode: scan # Support: https://www.malwarebytes.com/support ***** [ Services ] ***** No malicious services found. ***** [ Folders ] ***** PUP.Optional.Legacy, C:\Program Files (x86)\DriverToolkit PUP.Optional.Legacy, C:\Users\JS\AppData\Local\DriverToolkit PUP.Optional.Legacy, C:\ProgramData\MyMemory PUP.Optional.Legacy, C:\Users\All Users\MyMemory ***** [ Files ] ***** PUP.Optional.Booking, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Booking.com.lnk ***** [ DLL ] ***** No malicious DLLs found. ***** [ WMI ] ***** No malicious WMI found. ***** [ Shortcuts ] ***** No malicious shortcuts found. ***** [ Tasks ] ***** No malicious tasks found. ***** [ Registry ] ***** PUP.Optional.Legacy, [Key] - HKU\S-1-5-21-3263638176-2896341206-883201096-1001\Software\DriverToolkit PUP.Optional.Legacy, [Key] - HKCU\Software\DriverToolkit PUP.Optional.InstallCore, [Key] - HKU\S-1-5-21-3263638176-2896341206-883201096-1001\Software\csastats PUP.Optional.InstallCore, [Key] - HKCU\Software\csastats ***** [ Firefox (and derivatives) ] ***** No malicious Firefox entries. ***** [ Chromium (and derivatives) ] ***** PUP.Optional.Legacy, SearchProvider found: Ask.com - dts.search.ask.com PUP.Optional.Legacy, SearchProvider found: Ask - ask.com PUP.Optional.Legacy, SearchProvider found: Conduit Search - conduit.search PUP.Optional.Legacy, Startpage found: http://search.conduit.com/?gd=&ctid=CT3322197&octid=EB_ORIGINAL_CTID&ISID=M30FF40F8-E7D3-4112-9BE0-1B8F77F5BE97&SearchSource=55&CUI=&UM=5&UP=SP59263023-9642-4A9C-BCF3-F9AB69429B26&SSPV= PUP.Optional.Legacy, Startpage found: http://search.conduit.com/?gd=&ctid=CT3322197&octid=EB_ORIGINAL_CTID&ISID=M30FF40F8-E7D3-4112-9BE0-1B8F77F5BE97&SearchSource=55&CUI=&UM=5&UP=SP59263023-9642-4A9C-BCF3-F9AB69429B26&SSPV= PUP.Optional.Legacy, Startpage found: http://google.pl/ PUP.Optional.Legacy, Startpage found: http://www.gazeta.pl/0,0.html?p=153 PUP.Optional.Legacy, Startpage found: http://www.search.ask.com/?o=APN10640A&gct=hp&d=473-102&v=n10781-219&t=4 PUP.Optional.Legacy, Startpage found: http://www.search.ask.com/?o=APN10640A&gct=hp&d=473-102&v=a11465-219&t=4 PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hp&ts=1399718615&from=cvs1&uid=HGSTXHTS545050A7E380_130717TM8514TF1T285PX PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399728565&from=cvs1&uid=HGSTXHTS545050A7E380_130717TM8514TF1T285PX PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399880531&from=cvs1&uid=HGSTXHTS545050A7E380_130717TM8514TF1T285PX PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399967491&from=cvs1&uid=HGSTXHTS545050A7E380_130717TM8514TF1T285PX PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1400218644&from=cvs1&uid=HGSTXHTS545050A7E380_130717TM8514TF1T285PX PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1400422826&from=cvs1&uid=HGSTXHTS545050A7E380_130717TM8514TF1T285PX PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1400507051&from=cvs1&uid=HGSTXHTS545050A7E380_130717TM8514TF1T285PX PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1400612919&from=cvs1&uid=HGSTXHTS545050A7E380_130717TM8514TF1T285PX PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1402492225&from=cvs1&uid=HGSTXHTS545050A7E380_130717TM8514TF1T285PX PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1402492521&from=cvs1&uid=HGSTXHTS545050A7E380_130717TM8514TF1T285PX PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1402495295&from=cvs1&uid=HGSTXHTS545050A7E380_130717TM8514TF1T285PX PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1402497236&from=cvs1&uid=HGSTXHTS545050A7E380_130717TM8514TF1T285PX PUP.Optional.Legacy, Startpage found: http://search.conduit.com/?gd=&ctid=CT3322197&octid=EB_ORIGINAL_CTID&ISID=M30FF40F8-E7D3-4112-9BE0-1B8F77F5BE97&SearchSource=55&CUI=&UM=5&UP=SP59263023-9642-4A9C-BCF3-F9AB69429B26&SSPV= PUP.Optional.Legacy, Startpage found: http://search.conduit.com/?gd=&ctid=CT3322197&octid=EB_ORIGINAL_CTID&ISID=M30FF40F8-E7D3-4112-9BE0-1B8F77F5BE97&SearchSource=55&CUI=&UM=5&UP=SP59263023-9642-4A9C-BCF3-F9AB69429B26&SSPV= PUP.Optional.Legacy, Startpage found: http://google.pl/ PUP.Optional.Legacy, Startpage found: http://www.gazeta.pl/0,0.html?p=153 PUP.Optional.Legacy, Startpage found: http://www.search.ask.com/?o=APN10640A&gct=hp&d=473-102&v=n10781-219&t=4 PUP.Optional.Legacy, Startpage found: http://www.search.ask.com/?o=APN10640A&gct=hp&d=473-102&v=a11465-219&t=4 PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hp&ts=1399718615&from=cvs1&uid=HGSTXHTS545050A7E380_130717TM8514TF1T285PX PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399728565&from=cvs1&uid=HGSTXHTS545050A7E380_130717TM8514TF1T285PX PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399880531&from=cvs1&uid=HGSTXHTS545050A7E380_130717TM8514TF1T285PX PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399967491&from=cvs1&uid=HGSTXHTS545050A7E380_130717TM8514TF1T285PX PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1400218644&from=cvs1&uid=HGSTXHTS545050A7E380_130717TM8514TF1T285PX PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1400422826&from=cvs1&uid=HGSTXHTS545050A7E380_130717TM8514TF1T285PX PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1400507051&from=cvs1&uid=HGSTXHTS545050A7E380_130717TM8514TF1T285PX PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1400612919&from=cvs1&uid=HGSTXHTS545050A7E380_130717TM8514TF1T285PX PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1402492225&from=cvs1&uid=HGSTXHTS545050A7E380_130717TM8514TF1T285PX PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1402492521&from=cvs1&uid=HGSTXHTS545050A7E380_130717TM8514TF1T285PX PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1402495295&from=cvs1&uid=HGSTXHTS545050A7E380_130717TM8514TF1T285PX PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1402497236&from=cvs1&uid=HGSTXHTS545050A7E380_130717TM8514TF1T285PX PUP.Optional.Legacy, Startpage found: http://search.conduit.com/?gd=&ctid=CT3322197&octid=EB_ORIGINAL_CTID&ISID=M30FF40F8-E7D3-4112-9BE0-1B8F77F5BE97&SearchSource=55&CUI=&UM=5&UP=SP59263023-9642-4A9C-BCF3-F9AB69429B26&SSPV= PUP.Optional.Legacy, Startpage found: http://search.conduit.com/?gd=&ctid=CT3322197&octid=EB_ORIGINAL_CTID&ISID=M30FF40F8-E7D3-4112-9BE0-1B8F77F5BE97&SearchSource=55&CUI=&UM=5&UP=SP59263023-9642-4A9C-BCF3-F9AB69429B26&SSPV= PUP.Optional.Legacy, Startpage found: http://google.pl/ PUP.Optional.Legacy, Startpage found: http://www.gazeta.pl/0,0.html?p=153 PUP.Optional.Legacy, Startpage found: http://www.search.ask.com/?o=APN10640A&gct=hp&d=473-102&v=n10781-219&t=4 PUP.Optional.Legacy, Startpage found: http://www.search.ask.com/?o=APN10640A&gct=hp&d=473-102&v=a11465-219&t=4 PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hp&ts=1399718615&from=cvs1&uid=HGSTXHTS545050A7E380_130717TM8514TF1T285PX PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399728565&from=cvs1&uid=HGSTXHTS545050A7E380_130717TM8514TF1T285PX PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399880531&from=cvs1&uid=HGSTXHTS545050A7E380_130717TM8514TF1T285PX PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399967491&from=cvs1&uid=HGSTXHTS545050A7E380_130717TM8514TF1T285PX PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1400218644&from=cvs1&uid=HGSTXHTS545050A7E380_130717TM8514TF1T285PX PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1400422826&from=cvs1&uid=HGSTXHTS545050A7E380_130717TM8514TF1T285PX PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1400507051&from=cvs1&uid=HGSTXHTS545050A7E380_130717TM8514TF1T285PX PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1400612919&from=cvs1&uid=HGSTXHTS545050A7E380_130717TM8514TF1T285PX PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1402492225&from=cvs1&uid=HGSTXHTS545050A7E380_130717TM8514TF1T285PX PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1402492521&from=cvs1&uid=HGSTXHTS545050A7E380_130717TM8514TF1T285PX PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1402495295&from=cvs1&uid=HGSTXHTS545050A7E380_130717TM8514TF1T285PX PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1402497236&from=cvs1&uid=HGSTXHTS545050A7E380_130717TM8514TF1T285PX PUP.Optional.Legacy, Startpage found: http://search.conduit.com/?gd=&ctid=CT3322197&octid=EB_ORIGINAL_CTID&ISID=M30FF40F8-E7D3-4112-9BE0-1B8F77F5BE97&SearchSource=55&CUI=&UM=5&UP=SP59263023-9642-4A9C-BCF3-F9AB69429B26&SSPV= PUP.Optional.Legacy, Startpage found: http://search.conduit.com/?gd=&ctid=CT3322197&octid=EB_ORIGINAL_CTID&ISID=M30FF40F8-E7D3-4112-9BE0-1B8F77F5BE97&SearchSource=55&CUI=&UM=5&UP=SP59263023-9642-4A9C-BCF3-F9AB69429B26&SSPV= PUP.Optional.Legacy, Startpage found: http://google.pl/ PUP.Optional.Legacy, Startpage found: http://www.gazeta.pl/0,0.html?p=153 PUP.Optional.Legacy, Startpage found: http://www.search.ask.com/?o=APN10640A&gct=hp&d=473-102&v=n10781-219&t=4 PUP.Optional.Legacy, Startpage found: http://www.search.ask.com/?o=APN10640A&gct=hp&d=473-102&v=a11465-219&t=4 PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hp&ts=1399718615&from=cvs1&uid=HGSTXHTS545050A7E380_130717TM8514TF1T285PX PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399728565&from=cvs1&uid=HGSTXHTS545050A7E380_130717TM8514TF1T285PX PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399880531&from=cvs1&uid=HGSTXHTS545050A7E380_130717TM8514TF1T285PX PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399967491&from=cvs1&uid=HGSTXHTS545050A7E380_130717TM8514TF1T285PX PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1400218644&from=cvs1&uid=HGSTXHTS545050A7E380_130717TM8514TF1T285PX PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1400422826&from=cvs1&uid=HGSTXHTS545050A7E380_130717TM8514TF1T285PX PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1400507051&from=cvs1&uid=HGSTXHTS545050A7E380_130717TM8514TF1T285PX PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1400612919&from=cvs1&uid=HGSTXHTS545050A7E380_130717TM8514TF1T285PX PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1402492225&from=cvs1&uid=HGSTXHTS545050A7E380_130717TM8514TF1T285PX PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1402492521&from=cvs1&uid=HGSTXHTS545050A7E380_130717TM8514TF1T285PX PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1402495295&from=cvs1&uid=HGSTXHTS545050A7E380_130717TM8514TF1T285PX PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1402497236&from=cvs1&uid=HGSTXHTS545050A7E380_130717TM8514TF1T285PX PUP.Optional.CrossRider, Plugin found: Site Pages - /!\ Please Reset the Chrome Synchronization before cleaning the Chrome Preferences: https://support.google.com/chrome/answer/3097271 ************************* ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt ##########