Used MBAM to remove SlimCleaner Plus - removed quarantined files, now most normal PC files gone.

Jesse Finch

New Member
Thread author
Dec 19, 2018
1
I was helping my grandparents to remove SlimCleaner Plus from their PC as it was badgering them with pop-ups. I installed MBAM and did a scan, with around __ files related to SlimCleaner appeaing as PUP's. I quarantined and removed these files, and restarted the PC per MBAM's requests. After restarting, many files were deleted. There are also some invisible notifications appearing, and some strange crashes occuring so I believe some system files were deleted as well. Is there any way to recover these files? I did not know until after the deletion that they have Norton installed as well. Could that have interfered? I saw on another forum (bleeping computer) that someone else has had a very similar issue, but it was not resolved (SlimCleaner Plus - removed with Malwarebytes - files are now gone - Virus, Trojan, Spyware, and Malware Removal Help).

LOG OFSCAN:
Malwarebytes
www.malwarebytes.com

-Log Details-
Scan Date: 12/19/18
Scan Time: 2:22 PM
Log File: f0599c00-0349-11e9-8526-2cd05a04fef9.json

-Software Information-
Version: 3.6.1.2711
Components Version: 1.0.508
Update Package Version: 1.0.8389
License: Trial

-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: USER-PC\User

-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 263075
Threats Detected: 85
Threats Quarantined: 85
Time Elapsed: 2 min, 0 sec

-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect

-Scan Details-
Process: 5
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimService\SlimService.exe, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimService\SlimServiceFactory.exe, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.DriverUpdate, C:\PROGRAM FILES\DRIVERUPDATE\DRIVERUPDATE.EXE, Quarantined, [2897], [331450],1.0.8389
PUP.Optional.SlimCleanerPlus, C:\PROGRAM FILES\SLIMCLEANER PLUS\SLIMCLEANERPLUS.EXE, Quarantined, [1473], [452419],1.0.8389
PUP.Optional.SlimServices, C:\PROGRAM FILES\SLIMWARE UTILITIES\SERVICES\SLIMWARE.SERVICES.EXE, Quarantined, [7460], [452421],1.0.8389

Module: 12
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimService\MyDefragDll.dll, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimService\SlimService.exe, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimService\SlimServiceFactory.exe, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimService\UnifiedLogger.dll, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.DriverUpdate, C:\PROGRAM FILES\DRIVERUPDATE\DRIVERUPDATE.EXE, Quarantined, [2897], [331450],1.0.8389
PUP.Optional.SlimCleanerPlus, C:\PROGRAM FILES\SLIMCLEANER PLUS\SLIMCLEANERPLUS.EXE, Quarantined, [1473], [452419],1.0.8389
PUP.Optional.DriverUpdate, C:\Program Files\DriverUpdate\BugSplat.dll, Quarantined, [2897], [331449],1.0.8389
PUP.Optional.DriverUpdate, C:\Program Files\DriverUpdate\SlimWare.DriverUpdate.Services.dll, Quarantined, [2897], [331449],1.0.8389
PUP.Optional.DriverUpdate, C:\Program Files\DriverUpdate\SlimWare.Messaging.dll, Quarantined, [2897], [331449],1.0.8389
PUP.Optional.DriverUpdate, C:\Program Files\DriverUpdate\SlimWare.PushNotification.Services.dll, Quarantined, [2897], [331449],1.0.8389
PUP.Optional.DriverUpdate, C:\Program Files\DriverUpdate\UnifiedLogger.dll, Quarantined, [2897], [331449],1.0.8389
PUP.Optional.SlimServices, C:\PROGRAM FILES\SLIMWARE UTILITIES\SERVICES\SLIMWARE.SERVICES.EXE, Quarantined, [7460], [452421],1.0.8389

Registry Key: 29
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\DRIVERUPDATE SCAN, Quarantined, [2897], [331466],1.0.8389
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{EAF368C5-1E41-40F8-B3E9-518010D8DAB3}, Quarantined, [2897], [331466],1.0.8389
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\PLAIN\{EAF368C5-1E41-40F8-B3E9-518010D8DAB3}, Quarantined, [2897], [331466],1.0.8389
PUP.Optional.SlimCleanerPlus, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\SlimCleaner Plus (Scheduled Scan - User), Quarantined, [1473], [334098],1.0.8389
PUP.Optional.SlimCleanerPlus, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{C847C50D-0C99-454D-9E29-8152FEE60238}, Quarantined, [1473], [334098],1.0.8389
PUP.Optional.SlimCleanerPlus, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\PLAIN\{C847C50D-0C99-454D-9E29-8152FEE60238}, Quarantined, [1473], [334098],1.0.8389
PUP.Optional.SlimCleanerPlus, HKLM\SOFTWARE\CLASSES\TYPELIB\{95F57E4A-1FFA-4814-9AEC-34D22DF3D8FA}, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.SlimCleanerPlus, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{95F57E4A-1FFA-4814-9AEC-34D22DF3D8FA}, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.SlimCleanerPlus, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{95F57E4A-1FFA-4814-9AEC-34D22DF3D8FA}, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.SlimCleanerPlus, HKLM\SOFTWARE\CLASSES\TYPELIB\{A5FF3EB5-BF62-4D59-84DF-DC518E46FCB3}, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.SlimCleanerPlus, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{A5FF3EB5-BF62-4D59-84DF-DC518E46FCB3}, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.SlimCleanerPlus, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{A5FF3EB5-BF62-4D59-84DF-DC518E46FCB3}, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.SlimCleanerPlus, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SlimService, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\DriverUpdate, Quarantined, [2897], [331449],1.0.8389
PUP.Optional.SlimServices, HKLM\SOFTWARE\CLASSES\TYPELIB\{58A8BF1A-3608-41EA-AAD1-581AB79105E6}, Quarantined, [7460], [452421],1.0.8389
PUP.Optional.SlimServices, HKLM\SOFTWARE\CLASSES\INTERFACE\{E58DA376-0D39-45ED-A6EE-A7B6DD10BED2}, Quarantined, [7460], [452421],1.0.8389
PUP.Optional.SlimServices, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{58A8BF1A-3608-41EA-AAD1-581AB79105E6}, Quarantined, [7460], [452421],1.0.8389
PUP.Optional.SlimServices, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{58A8BF1A-3608-41EA-AAD1-581AB79105E6}, Quarantined, [7460], [452421],1.0.8389
PUP.Optional.SlimServices, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SlimWareServices, Quarantined, [7460], [452421],1.0.8389
PUP.Optional.SlimCleanerPlus, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{7E03DFCF-3091-4D7A-91AB-59994A7A36B6}, Quarantined, [1473], [335437],1.0.8389
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{1BD47D21-01F4-4538-9290-39FD569A0F24}, Quarantined, [2897], [335822],1.0.8389
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\{1BD47D21-01F4-4538-9290-39FD569A0F24}, Quarantined, [2897], [335822],1.0.8389
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\CLASSES\APPID\{1BD47D21-01F4-4538-9290-39FD569A0F24}, Quarantined, [2897], [335822],1.0.8389
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\CLASSES\CLSID\{BAF87BD0-A924-4108-AFA5-A5FA720A2E86}, Quarantined, [2897], [335831],1.0.8389
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\CLASSES\CLSID\{959D527D-6C27-4879-A644-065526D6969C}, Quarantined, [2897], [335833],1.0.8389
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\CLASSES\APPID\{149622B2-F1C5-492D-BFDF-8E5ED85854A0}, Quarantined, [2897], [335820],1.0.8389
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{149622B2-F1C5-492D-BFDF-8E5ED85854A0}, Quarantined, [2897], [335820],1.0.8389
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\{149622B2-F1C5-492D-BFDF-8E5ED85854A0}, Quarantined, [2897], [335820],1.0.8389
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\CLASSES\CLSID\{6DC6EE87-F3BB-40EB-BCEE-12F7D6E3EEDF}, Quarantined, [2897], [335836],1.0.8389

Registry Value: 5
PUP.Optional.DriverUpdate, HKU\S-1-5-21-3658810515-2502364871-1149701184-1004\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|DRIVERUPDATE, Quarantined, [2897], [331450],1.0.8389
PUP.Optional.SlimCleanerPlus, HKU\S-1-5-21-3658810515-2502364871-1149701184-1004\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|SLIMCLEANER PLUS, Quarantined, [1473], [452419],1.0.8389
PUP.Optional.SlimCleanerPlus, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{C847C50D-0C99-454D-9E29-8152FEE60238}|PATH, Quarantined, [1473], [334102],1.0.8389
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{EAF368C5-1E41-40F8-B3E9-518010D8DAB3}|PATH, Quarantined, [2897], [335435],1.0.8389
PUP.Optional.SlimCleanerPlus, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{7E03DFCF-3091-4D7A-91AB-59994A7A36B6}|DISPLAYNAME, Quarantined, [1473], [335437],1.0.8389

Registry Data: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 2
PUP.Optional.SlimCleanerPlus, C:\PROGRAM FILES\SLIMSERVICE, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.DriverUpdate, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\DRIVERUPDATE, Quarantined, [2897], [331462],1.0.8389

File: 32
PUP.Optional.DriverUpdate, C:\USERS\PUBLIC\DESKTOP\DRIVERUPDATE.LNK, Quarantined, [2897], [331456],1.0.8389
PUP.Optional.DriverUpdate, C:\WINDOWS\SYSTEM32\TASKS\DRIVERUPDATE SCAN, Quarantined, [2897], [331466],1.0.8389
PUP.Optional.SlimCleanerPlus, C:\WINDOWS\SYSTEM32\TASKS\SlimCleaner Plus (Scheduled Scan - User), Quarantined, [1473], [334098],1.0.8389
PUP.Optional.SlimCleanerPlus, C:\PROGRAM FILES\SLIMSERVICE\CLEANER.DB, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimService\Analyze.MyD, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimService\Full.MyD, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimService\icudt46l.dat, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimService\MyDefragDll.dll, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimService\Quick.MyD, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimService\SlimService.exe, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimService\SlimServiceFactory.exe, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimService\Ssd.MyD, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimService\UnifiedLogger.dll, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimService\WinRT.dll, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.SlimCleanerPlus, C:\USERS\PUBLIC\DESKTOP\SlimCleaner Plus.lnk, Quarantined, [1473], [398509],1.0.8389
PUP.Optional.DriverUpdate, C:\PROGRAM FILES\DRIVERUPDATE\DRIVERUPDATE.EXE, Quarantined, [2897], [331450],1.0.8389
PUP.Optional.SlimCleanerPlus, C:\PROGRAM FILES\SLIMCLEANER PLUS\SLIMCLEANERPLUS.EXE, Quarantined, [1473], [452419],1.0.8389
PUP.Optional.DriverUpdate, C:\Program Files\DriverUpdate\BsSndRpt.exe, Quarantined, [2897], [331449],1.0.8389
PUP.Optional.DriverUpdate, C:\Program Files\DriverUpdate\BugSplat.dll, Quarantined, [2897], [331449],1.0.8389
PUP.Optional.DriverUpdate, C:\Program Files\DriverUpdate\BugSplatRc.dll, Quarantined, [2897], [331449],1.0.8389
PUP.Optional.DriverUpdate, C:\Program Files\DriverUpdate\htmlayout.dll, Quarantined, [2897], [331449],1.0.8389
PUP.Optional.DriverUpdate, C:\Program Files\DriverUpdate\InAppBrowserProxy.dll, Quarantined, [2897], [331449],1.0.8389
PUP.Optional.DriverUpdate, C:\Program Files\DriverUpdate\lib-inappbrowser.dll, Quarantined, [2897], [331449],1.0.8389
PUP.Optional.DriverUpdate, C:\Program Files\DriverUpdate\Open-Source Licenses.txt, Quarantined, [2897], [331449],1.0.8389
PUP.Optional.DriverUpdate, C:\Program Files\DriverUpdate\SlimWare.DriverUpdate.Services.dll, Quarantined, [2897], [331449],1.0.8389
PUP.Optional.DriverUpdate, C:\Program Files\DriverUpdate\SlimWare.Messaging.dll, Quarantined, [2897], [331449],1.0.8389
PUP.Optional.DriverUpdate, C:\Program Files\DriverUpdate\SlimWare.PushNotification.Services.dll, Quarantined, [2897], [331449],1.0.8389
PUP.Optional.DriverUpdate, C:\Program Files\DriverUpdate\UnifiedLogger.dll, Quarantined, [2897], [331449],1.0.8389
PUP.Optional.DriverUpdate, C:\Program Files\DriverUpdate\UninstallStub.exe, Quarantined, [2897], [331449],1.0.8389
PUP.Optional.DriverUpdate, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverUpdate\DriverUpdate Help.lnk, Quarantined, [2897], [331462],1.0.8389
PUP.Optional.DriverUpdate, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverUpdate\DriverUpdate.lnk, Quarantined, [2897], [331462],1.0.8389
PUP.Optional.SlimServices, C:\PROGRAM FILES\SLIMWARE UTILITIES\SERVICES\SLIMWARE.SERVICES.EXE, Quarantined, [7460], [452421],1.0.8389

Physical Sector: 0
(No malicious items detected)

WMI: 0
(No malicious items detected)


(end)


Any help is much appreciated :)
 
  • Like
Reactions: oldschool

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top