Hola Daniela.
Por fin he podido hacer todos los pasos. Espero haberlos hecho bien.
Pego a continuacion los reportes. De AdwCleaner tenia dos logs y los he puesto los dos por si era necesario.
Dentro de lo poco que he podido comprobar el ordenador, no tiene mala pinta. Si me gustaria saber si podia recibir algun consejo de algun antivirus y/o antimalware y/o optimizador gratuito
para tener el pc con la maxima salud posible.
Pues Daniela, espero algun consejo si surge despues de ver los reportes. Una vez mas, muchas gracias.
Malwarebytes
www.malwarebytes.com
-Detalles del registro-
Fecha del análisis: 8/5/20
Hora del análisis: 13:03
Archivo de registro: 8a9b4ac4-911b-11ea-ab7d-c85b766b5d50.json
-Información del software-
Versión: 4.1.0.56
Versión de los componentes: 1.0.896
Versión del paquete de actualización: 1.0.23618
Licencia: Prueba
-Información del sistema-
SO: Windows 10 (Build 18362.778)
CPU: x64
Sistema de archivos: NTFS
Usuario: LAPTOP-IUVNOHHJ\Javi
-Resumen del análisis-
Tipo de análisis: Análisis personalizado
Análisis iniciado por:: Manual
Resultado: Completado
Objetos analizados: 865583
Amenazas detectadas: 46
Amenazas en cuarentena: 46
Tiempo transcurrido: 22 hr, 42 min, 39 seg
-Opciones de análisis-
Memoria: Activado
Inicio: Activado
Sistema de archivos: Activado
Archivo: Activado
Rootkits: Activado
Heurística: Activado
PUP: Detectar
PUM: Detectar
-Detalles del análisis-
Proceso: 0
(No hay elementos maliciosos detectados)
Módulo: 0
(No hay elementos maliciosos detectados)
Clave del registro: 12
PUP.Optional.Conduit, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, En cuarentena, 194, 236865, , , ,
PUP.Optional.Conduit, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, En cuarentena, 194, 236865, , , ,
PUP.Optional.Conduit, HKU\S-1-5-21-290510076-2018776080-814419295-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}, En cuarentena, 194, 236865, 1.0.23618, , ame,
PUP.Optional.AuslogicsDriverUpdater, HKLM\SOFTWARE\WOW6432NODE\AUSLOGICS\Driver Updater, En cuarentena, 3523, 341776, 1.0.23618, , ame,
PUP.Optional.AuslogicsDriverUpdater, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{23BB1B18-3537-48F7-BEF7-42BC65DBF993}_IS1, En cuarentena, 3523, 769158, 1.0.23618, , ame,
PUP.Optional.AdvancedSystemCare, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IOBIT_MONITOR_SERVER, En cuarentena, 3831, 580520, 1.0.23618, , ame,
Trojan.Glupteba.E, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{A789461C-19A0-41C0-9F51-DB8F5230DF72}, En cuarentena, 493, 781223, , , ,
Trojan.Glupteba.E, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\LOGON\{A789461C-19A0-41C0-9F51-DB8F5230DF72}, En cuarentena, 493, 781223, , , ,
Trojan.Glupteba.E, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\ScheduledUpdate, En cuarentena, 493, 781223, 1.0.23618, , ame,
PUP.Optional.AuslogicsDriverUpdater, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Auslogics\Driver Updater\Scan, En cuarentena, 3523, 818931, , , ,
PUP.Optional.AuslogicsDriverUpdater, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{0E22041F-ED0F-489E-BA5B-46CF77CC428D}, En cuarentena, 3523, 818931, , , ,
PUP.Optional.AuslogicsDriverUpdater, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\PLAIN\{0E22041F-ED0F-489E-BA5B-46CF77CC428D}, En cuarentena, 3523, 818931, , , ,
Valor del registro: 10
PUP.Optional.Conduit, HKU\S-1-5-21-290510076-2018776080-814419295-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|URL, En cuarentena, 194, 236865, 1.0.23618, , ame,
PUP.Optional.Conduit, HKU\S-1-5-21-290510076-2018776080-814419295-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|TOPRESULTURL, En cuarentena, 194, 236865, 1.0.23618, , ame,
PUP.Optional.AuslogicsDriverUpdater, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{23BB1B18-3537-48F7-BEF7-42BC65DBF993}_IS1|INNO SETUP: APP PATH, En cuarentena, 3523, 769158, 1.0.23618, , ame,
PUP.Optional.AuslogicsDriverUpdater, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{23BB1B18-3537-48F7-BEF7-42BC65DBF993}_IS1|INSTALLLOCATION, En cuarentena, 3523, 769158, 1.0.23618, , ame,
PUP.Optional.AuslogicsDriverUpdater, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{23BB1B18-3537-48F7-BEF7-42BC65DBF993}_IS1|INNO SETUP: ICON GROUP, En cuarentena, 3523, 769158, 1.0.23618, , ame,
PUP.Optional.AuslogicsDriverUpdater, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{23BB1B18-3537-48F7-BEF7-42BC65DBF993}_IS1|DISPLAYNAME, En cuarentena, 3523, 769158, 1.0.23618, , ame,
PUP.Optional.AuslogicsDriverUpdater, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{23BB1B18-3537-48F7-BEF7-42BC65DBF993}_IS1|DISPLAYICON, En cuarentena, 3523, 769158, 1.0.23618, , ame,
PUP.Optional.AuslogicsDriverUpdater, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{23BB1B18-3537-48F7-BEF7-42BC65DBF993}_IS1|UNINSTALLSTRING, En cuarentena, 3523, 769158, 1.0.23618, , ame,
PUP.Optional.AuslogicsDriverUpdater, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{23BB1B18-3537-48F7-BEF7-42BC65DBF993}_IS1|QUIETUNINSTALLSTRING, En cuarentena, 3523, 769158, 1.0.23618, , ame,
PUP.Optional.AdvancedSystemCare, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IOBIT_MONITOR_SERVER|IMAGEPATH, En cuarentena, 3831, 580520, 1.0.23618, , ame,
Datos del registro: 1
PUP.Optional.Conduit, HKU\S-1-5-21-290510076-2018776080-814419295-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|START PAGE, Sustituido, 194, 293058, 1.0.23618, , ame,
Secuencia de datos: 0
(No hay elementos maliciosos detectados)
Carpeta: 4
PUP.Optional.AuslogicsDriverUpdater, C:\Program Files (x86)\Auslogics\Driver Updater, En cuarentena, 3523, 818931, 1.0.23618, , ame,
PUP.Optional.AuslogicsDriverUpdater, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics\Driver Updater, En cuarentena, 3523, 341779, 1.0.23618, , ame,
PUP.Optional.AuslogicsDriverUpdater, C:\ProgramData\Auslogics\Driver Updater, En cuarentena, 3523, 818932, 1.0.23618, , ame,
PUP.Optional.AuslogicsDriverUpdater, C:\Windows\System32\Tasks\Auslogics\Driver Updater, En cuarentena, 3520, 341781, 1.0.23618, , ame,
Archivo: 19
PUP.Optional.AuslogicsDriverUpdater, C:\WINDOWS\SYSTEM32\TASKS\Auslogics\Driver Updater\Scan, En cuarentena, 3523, 818931, , , ,
PUP.Optional.AuslogicsDriverUpdater, C:\PROGRAM FILES (X86)\AUSLOGICS\DRIVER UPDATER\TASKSCHEDULERHELPER.DLL, En cuarentena, 3523, 818931, 1.0.23618, , ame,
PUP.Optional.AuslogicsDriverUpdater, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics\Driver Updater\Auslogics Driver Updater on the Web.url, En cuarentena, 3523, 341779, , , ,
PUP.Optional.AuslogicsDriverUpdater, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics\Driver Updater\Auslogics Driver Updater.lnk, En cuarentena, 3523, 341779, , , ,
PUP.Optional.AuslogicsDriverUpdater, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics\Driver Updater\Uninstall Auslogics Driver Updater.lnk, En cuarentena, 3523, 341779, , , ,
Malware.Generic.4229473235, C:\SYSTEM VOLUME INFORMATION\SYSTEMRESTORE\FRSTAGING\USERS\JAVI\VIDEOS\WONDERSHARE.FILMORA.9.4.6.2.MULTILENGUAJE.ES.INC.CRACK-\PATCH\FILMORA9 PATCH BY THIRDZKY.EXE, En cuarentena, 1000000, 0, 1.0.23618, D7586F715D8BE6E4FC18A3D3, dds, 00710445
PUP.Optional.Amazon1Button, C:\USERS\JAVI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\QWAGR2AF.DEFAULT-1539189531436\EXTENSIONS\[email protected], En cuarentena, 3198, 493346, 1.0.23618, , ame,
PUP.Optional.Conduit, C:\USERS\JAVI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\QWAGR2AF.DEFAULT-1539189531436\PREFS.JS, Sustituido, 194, 301520, 1.0.23618, , ame,
PUP.Optional.AuslogicsDriverUpdater, C:\USERS\JAVI\DESKTOP\AUSLOGICS DRIVER UPDATER.LNK, En cuarentena, 3523, 341778, 1.0.23618, , ame,
Generic.Malware/Suspicious, C:\USERS\JAVI\DOCUMENTS\PROGRAMAS\CCLEANER.V5.66.7716.PRO.BUSINESS.TECH.MULTILENGUAJE.ES.INC.SERIAL\CCLEANERPROACTIVATOR\CCLEANERPROACTIVATOR.EXE, En cuarentena, 0, 392686, 1.0.23618, , shuriken,
RiskWare.Agent.Keygen, C:\USERS\JAVI\DOCUMENTS\PROGRAMAS\CCLEANER.V5.66.7716.PRO.BUSINESS.TECH.MULTILENGUAJE.ES.INC.SERIAL\PIRIFORM.ALL.PRODUCTS.KEYGEN-CORE\CR-PIRIFORM.EXE, En cuarentena, 7962, 352886, 1.0.23618, B53F264D906D7484DB892D9F, dds, 00710445
Malware.Generic.4229473235, C:\USERS\JAVI\DOCUMENTS\PROGRAMAS\WONDERSHARE.FILMORA.9.4.6.2.MULTILENGUAJE.ES.INC.CRACK-\PATCH\FILMORA9 PATCH BY THIRDZKY.EXE, En cuarentena, 1000000, 0, 1.0.23618, D7586F715D8BE6E4FC18A3D3, dds, 00710445
Generic.Malware/Suspicious, C:\USERS\JAVI\DOWNLOADS\AUSLOGICS.DRIVER.UPDATER.V1.24.0.0.MULTILENGUAJE.ES.INC.CRACK\DRIVER-UPDATER-SETUP.EXE, En cuarentena, 0, 392686, 1.0.23618, , shuriken,
HackTool.WinActivator, C:\USERS\JAVI\DOWNLOADS\WINDOWS DESCARGAS\MICROSOFT WINDOWS 10 TH2 RTM MSDN ESP.X64\_ACTIVAD_RES\RE-LOADER_BYR_1N_V21FINAL_SVN18012016_2150.ZIP, En cuarentena, 7936, 595564, 1.0.23618, BBD58F8613FE79E4F090C35C, dds, 00710445
Ransom.Mamo, C:\USERS\JAVI\DOWNLOADS\COGER OTRO EASEUS.DATA.RECOVERY.WIZARD.TECH.13.3.MULTILENGUAJE.ES.INC.CRACK.KEYGEN\CRACK\KEYGEN.RAR, En cuarentena, 7588, 772195, 1.0.23618, 8CD7CF1AE319AF56FCF0C880, dds, 00710445
Ransom.Mamo, C:\USERS\JAVI\DOWNLOADS\COGER OTRO EASEUS.DATA.RECOVERY.WIZARD.TECH.13.3.MULTILENGUAJE.ES.INC.CRACK.KEYGEN\CRACK\KEYGEN.EXE, En cuarentena, 7588, 772195, 1.0.23618, 8CD7CF1AE319AF56FCF0C880, dds, 00710445
HackTool.FilePatch, C:\USERS\JAVI\DOWNLOADS\MOVAVI PHOTO EDITOR V6.4.0.MULTILENGUAJE.ES.INC.CRACK-X64\PATCH.RAR, En cuarentena, 7529, 281135, 1.0.23618, 2335858C56377C0EFA288A38, dds, 00710445
Trojan.MalPack.GS, C:\WINDOWS\SYSTEM32\CONFIG\SYSTEMPROFILE\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCACHE\IE\APP[1].EXE, En cuarentena, 8206, 817856, 1.0.23618, 16B5AAA64A4CBA669AA768EF, dds, 00710445
Trojan.MalPack.GS, C:\WINDOWS\SYSTEM32\CONFIG\SYSTEMPROFILE\APPDATA\LOCALLOW\MICROSOFT\CRYPTNETURLCACHE\CONTENT\829226B0FB58B4903A5513D04E3201C4, En cuarentena, 8206, 819478, 1.0.23618, , ame,
Sector físico: 0
(No hay elementos maliciosos detectados)
WMI: 0
(No hay elementos maliciosos detectados)
(end)
# -------------------------------
# Malwarebytes AdwCleaner 8.0.4.0
# -------------------------------
# Build: 04-03-2020
# Database: 2020-04-08.2 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 05-09-2020
# Duration: 00:00:29
# OS: Windows 10 Home
# Cleaned: 44
# Failed: 0
***** [ Services ] *****
No malicious services cleaned.
***** [ Folders ] *****
Deleted C:\Program Files (x86)\Common Files\IObit\Advanced SystemCare
Deleted C:\ProgramData\54F3DE4E-B7BA-4EBD-8B3B-385D272CC583
Deleted C:\ProgramData\Application Data\Lavasoft\Web Companion
Deleted C:\ProgramData\BSD\DriverHive
Deleted C:\ProgramData\BSD\DriverHiveEngine
Deleted C:\ProgramData\FA87C1D4
Deleted C:\ProgramData\Host App Service
Deleted C:\ProgramData\IObit\Advanced SystemCare
Deleted C:\Users\Default\AppData\Local\Host App Service
Deleted C:\Users\Javi\AppData\LocalLow\IObit\Advanced SystemCare
Deleted C:\Users\Javi\AppData\Local\DriverToolkit
Deleted C:\Users\Javi\AppData\Local\Host App Service
Deleted C:\Users\Javi\AppData\Roaming\IObit\Advanced SystemCare
Deleted C:\Users\Javi\AppData\Roaming\MPC
Deleted C:\Windows\ServiceProfiles\LocalService\AppData\Local\Host App Service
Deleted C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Host App Service
Deleted C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\IObit\Advanced SystemCare
Deleted C:\Windows\rss
***** [ Files ] *****
Deleted C:\Users\Public\Desktop\ScreenShot.lnk
Deleted C:\Windows\System32\Tasks_Migrated\App Explorer
***** [ DLL ] *****
No malicious DLLs cleaned.
***** [ WMI ] *****
No malicious WMI cleaned.
***** [ Shortcuts ] *****
No malicious shortcuts cleaned.
***** [ Tasks ] *****
Deleted C:\Windows\System32\Tasks\APP EXPLORER
***** [ Registry ] *****
Deleted HKCU\Software\BSD
Deleted HKCU\Software\Host App Service
Deleted HKCU\Software\Lavasoft\Web Companion
Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run|cloudnet
Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com
Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Host App Service
Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B59A5BDD-FC01-4E9F-81DE-3B6647D4DA58}
Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\App Explorer
Deleted HKLM\Software\Wow6432Node\BSD
Deleted HKLM\Software\Wow6432Node\IOBIT\ASC
Deleted HKLM\Software\Wow6432Node\IObit\Advanced SystemCare
Deleted HKLM\Software\Wow6432Node\Lavasoft\Web Companion
***** [ Chromium (and derivatives) ] *****
No malicious Chromium entries cleaned.
***** [ Chromium URLs ] *****
No malicious Chromium URLs cleaned.
***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries cleaned.
***** [ Firefox URLs ] *****
No malicious Firefox URLs cleaned.
***** [ Hosts File Entries ] *****
No malicious hosts file entries cleaned.
***** [ Preinstalled Software ] *****
Deleted Preinstalled.LenovoPower2Go Registry HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32|CLMLServer_For_P2G8
Deleted Preinstalled.LenovoPower2Go Registry HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32|CLVirtualDrive
Deleted Preinstalled.LenovoPowerDVD Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0ABB54E5-323C-4557-9631-4BB8742BE88D}
Deleted Preinstalled.LenovoPowerDVD Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PDVDServ12 Task
Deleted Preinstalled.LenovoPowerDVD Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}
Deleted Preinstalled.LenovoPowerDVD Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{B46BEA36-0B71-4A4E-AE41-87241643FA0A}
Deleted Preinstalled.LenovoPowerDVD Task C:\Windows\System32\Tasks\PDVDSERV12 TASK
Deleted Preinstalled.LenovoQuickOptimizer Folder C:\Program Files\LENOVO\QUICKOPTIMIZER
Deleted Preinstalled.LenovoQuickOptimizer Registry HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{8D2C871B-1B9F-45AC-9C43-2BB18089CDFA}
Deleted Preinstalled.LenovoServiceBridge Folder C:\Users\Javi\AppData\Local\PROGRAMS\LENOVO\LENOVO SERVICE BRIDGE
Deleted Preinstalled.LenovoServiceBridge Registry HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{2C74547D-EF88-47F4-85F5-BE46A31E26B7}_is1
*************************
[+] Delete Tracing Keys
[+] Reset Winsock
*************************
AdwCleaner[S00].txt - [6437 octets] - [09/05/2020 13:04:18]
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########
# -------------------------------
# Malwarebytes AdwCleaner 8.0.4.0
# -------------------------------
# Build: 04-03-2020
# Database: 2020-04-08.2 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start: 05-09-2020
# Duration: 00:01:45
# OS: Windows 10 Home
# Scanned: 31802
# Detected: 53
***** [ Services ] *****
No malicious services found.
***** [ Folders ] *****
Adware.pokki C:\ProgramData\Host App Service
Adware.pokki C:\Users\Default\AppData\Local\Host App Service
Adware.pokki C:\Users\Javi\AppData\Local\Host App Service
Adware.pokki C:\Windows\ServiceProfiles\LocalService\AppData\Local\Host App Service
Adware.pokki C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Host App Service
PUP.Adware.Heuristic C:\ProgramData\FA87C1D4
PUP.Optional.AdvancedSystemCare C:\Program Files (x86)\Common Files\IObit\Advanced SystemCare
PUP.Optional.AdvancedSystemCare C:\ProgramData\IObit\Advanced SystemCare
PUP.Optional.AdvancedSystemCare C:\Users\Javi\AppData\LocalLow\IObit\Advanced SystemCare
PUP.Optional.AdvancedSystemCare C:\Users\Javi\AppData\Roaming\IObit\Advanced SystemCare
PUP.Optional.AdvancedSystemCare C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\IObit\Advanced SystemCare
PUP.Optional.Legacy C:\ProgramData\54F3DE4E-B7BA-4EBD-8B3B-385D272CC583
PUP.Optional.Legacy C:\ProgramData\BSD\DriverHiveEngine
PUP.Optional.Legacy C:\Users\Javi\AppData\Local\DriverToolkit
PUP.Optional.Legacy C:\Users\Javi\AppData\Roaming\MPC
PUP.Optional.TweakBit C:\ProgramData\BSD\DriverHive
PUP.Optional.WebCompanion C:\ProgramData\Application Data\Lavasoft\Web Companion
Trojan.Agent C:\Windows\rss
***** [ Files ] *****
Adware.pokki C:\Windows\System32\Tasks_Migrated\App Explorer
PUP.Optional.Legacy C:\Users\Public\Desktop\ScreenShot.lnk
***** [ DLL ] *****
No malicious DLLs found.
***** [ WMI ] *****
No malicious WMI found.
***** [ Shortcuts ] *****
No malicious shortcuts found.
***** [ Tasks ] *****
Adware.pokki C:\Windows\System32\Tasks\APP EXPLORER
***** [ Registry ] *****
Adware.pokki HKCU\Software\Host App Service
Adware.pokki HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Host App Service
Adware.pokki HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B59A5BDD-FC01-4E9F-81DE-3B6647D4DA58}
Adware.pokki HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\App Explorer
PUP.Optional.AdvancedSystemCare HKLM\Software\Wow6432Node\IOBIT\ASC
PUP.Optional.AdvancedSystemCare HKLM\Software\Wow6432Node\IObit\Advanced SystemCare
PUP.Optional.DriverUpdatePlus HKCU\Software\BSD
PUP.Optional.DriverUpdatePlus HKLM\Software\Wow6432Node\BSD
PUP.Optional.Glupteba HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run|cloudnet
PUP.Optional.WebCompanion HKCU\Software\Lavasoft\Web Companion
PUP.Optional.WebCompanion HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com
PUP.Optional.WebCompanion HKLM\Software\Wow6432Node\Lavasoft\Web Companion
***** [ Chromium (and derivatives) ] *****
No malicious Chromium entries found.
***** [ Chromium URLs ] *****
No malicious Chromium URLs found.
***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries found.
***** [ Firefox URLs ] *****
No malicious Firefox URLs found.
***** [ Hosts File Entries ] *****
No malicious hosts file entries found.
***** [ Preinstalled Software ] *****
Preinstalled.LenovoIMController Folder C:\ProgramData\LENOVO\IMCONTROLLER
Preinstalled.LenovoIMController Folder C:\Users\Javi\AppData\Local\LENOVO\IMCONTROLLER
Preinstalled.LenovoIMController Folder C:\Windows\LENOVO\IMCONTROLLER
Preinstalled.LenovoIMController Folder C:\Windows\System32\Tasks\LENOVO\IMCONTROLLER
Preinstalled.LenovoIMController Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\Lenovo Dependency Package_is1
Preinstalled.LenovoPower2Go Registry HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32|CLMLServer_For_P2G8
Preinstalled.LenovoPower2Go Registry HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32|CLVirtualDrive
Preinstalled.LenovoPowerDVD Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0ABB54E5-323C-4557-9631-4BB8742BE88D}
Preinstalled.LenovoPowerDVD Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PDVDServ12 Task
Preinstalled.LenovoPowerDVD Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}
Preinstalled.LenovoPowerDVD Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{B46BEA36-0B71-4A4E-AE41-87241643FA0A}
Preinstalled.LenovoPowerDVD Task C:\Windows\System32\Tasks\PDVDSERV12 TASK
Preinstalled.LenovoQuickOptimizer Folder C:\Program Files\LENOVO\QUICKOPTIMIZER
Preinstalled.LenovoQuickOptimizer Registry HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{8D2C871B-1B9F-45AC-9C43-2BB18089CDFA}
Preinstalled.LenovoServiceBridge Folder C:\Users\Javi\AppData\Local\PROGRAMS\LENOVO\LENOVO SERVICE BRIDGE
Preinstalled.LenovoServiceBridge Registry HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{2C74547D-EF88-47F4-85F5-BE46A31E26B7}_is1
Preinstalled.LenovoUpdate Folder C:\Program Files (x86)\LENOVO\SYSTEM UPDATE
Preinstalled.LenovoUpdate Registry HKLM\Software\Wow6432Node\\Classes\CLSID\{03C6CC92-68F2-4961-9A73-CAECA350BD08}
Preinstalled.LenovoUpdate Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\TVSU_is1
Preinstalled.LenovoUtility Registry HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run|LenovoUtility
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S00].txt ##########