System logs
Yes, I've uploaded the FRST.txt logs
Joined
Dec 19, 2018
Messages
1
Operating System
Windows 7
Antivirus
Norton
#1
I was helping my grandparents to remove SlimCleaner Plus from their PC as it was badgering them with pop-ups. I installed MBAM and did a scan, with around __ files related to SlimCleaner appeaing as PUP's. I quarantined and removed these files, and restarted the PC per MBAM's requests. After restarting, many files were deleted. There are also some invisible notifications appearing, and some strange crashes occuring so I believe some system files were deleted as well. Is there any way to recover these files? I did not know until after the deletion that they have Norton installed as well. Could that have interfered? I saw on another forum (bleeping computer) that someone else has had a very similar issue, but it was not resolved (SlimCleaner Plus - removed with Malwarebytes - files are now gone - Virus, Trojan, Spyware, and Malware Removal Help).

LOG OFSCAN:
Malwarebytes
www.malwarebytes.com

-Log Details-
Scan Date: 12/19/18
Scan Time: 2:22 PM
Log File: f0599c00-0349-11e9-8526-2cd05a04fef9.json

-Software Information-
Version: 3.6.1.2711
Components Version: 1.0.508
Update Package Version: 1.0.8389
License: Trial

-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: USER-PC\User

-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 263075
Threats Detected: 85
Threats Quarantined: 85
Time Elapsed: 2 min, 0 sec

-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect

-Scan Details-
Process: 5
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimService\SlimService.exe, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimService\SlimServiceFactory.exe, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.DriverUpdate, C:\PROGRAM FILES\DRIVERUPDATE\DRIVERUPDATE.EXE, Quarantined, [2897], [331450],1.0.8389
PUP.Optional.SlimCleanerPlus, C:\PROGRAM FILES\SLIMCLEANER PLUS\SLIMCLEANERPLUS.EXE, Quarantined, [1473], [452419],1.0.8389
PUP.Optional.SlimServices, C:\PROGRAM FILES\SLIMWARE UTILITIES\SERVICES\SLIMWARE.SERVICES.EXE, Quarantined, [7460], [452421],1.0.8389

Module: 12
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimService\MyDefragDll.dll, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimService\SlimService.exe, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimService\SlimServiceFactory.exe, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimService\UnifiedLogger.dll, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.DriverUpdate, C:\PROGRAM FILES\DRIVERUPDATE\DRIVERUPDATE.EXE, Quarantined, [2897], [331450],1.0.8389
PUP.Optional.SlimCleanerPlus, C:\PROGRAM FILES\SLIMCLEANER PLUS\SLIMCLEANERPLUS.EXE, Quarantined, [1473], [452419],1.0.8389
PUP.Optional.DriverUpdate, C:\Program Files\DriverUpdate\BugSplat.dll, Quarantined, [2897], [331449],1.0.8389
PUP.Optional.DriverUpdate, C:\Program Files\DriverUpdate\SlimWare.DriverUpdate.Services.dll, Quarantined, [2897], [331449],1.0.8389
PUP.Optional.DriverUpdate, C:\Program Files\DriverUpdate\SlimWare.Messaging.dll, Quarantined, [2897], [331449],1.0.8389
PUP.Optional.DriverUpdate, C:\Program Files\DriverUpdate\SlimWare.PushNotification.Services.dll, Quarantined, [2897], [331449],1.0.8389
PUP.Optional.DriverUpdate, C:\Program Files\DriverUpdate\UnifiedLogger.dll, Quarantined, [2897], [331449],1.0.8389
PUP.Optional.SlimServices, C:\PROGRAM FILES\SLIMWARE UTILITIES\SERVICES\SLIMWARE.SERVICES.EXE, Quarantined, [7460], [452421],1.0.8389

Registry Key: 29
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\DRIVERUPDATE SCAN, Quarantined, [2897], [331466],1.0.8389
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{EAF368C5-1E41-40F8-B3E9-518010D8DAB3}, Quarantined, [2897], [331466],1.0.8389
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\PLAIN\{EAF368C5-1E41-40F8-B3E9-518010D8DAB3}, Quarantined, [2897], [331466],1.0.8389
PUP.Optional.SlimCleanerPlus, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\SlimCleaner Plus (Scheduled Scan - User), Quarantined, [1473], [334098],1.0.8389
PUP.Optional.SlimCleanerPlus, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{C847C50D-0C99-454D-9E29-8152FEE60238}, Quarantined, [1473], [334098],1.0.8389
PUP.Optional.SlimCleanerPlus, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\PLAIN\{C847C50D-0C99-454D-9E29-8152FEE60238}, Quarantined, [1473], [334098],1.0.8389
PUP.Optional.SlimCleanerPlus, HKLM\SOFTWARE\CLASSES\TYPELIB\{95F57E4A-1FFA-4814-9AEC-34D22DF3D8FA}, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.SlimCleanerPlus, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{95F57E4A-1FFA-4814-9AEC-34D22DF3D8FA}, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.SlimCleanerPlus, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{95F57E4A-1FFA-4814-9AEC-34D22DF3D8FA}, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.SlimCleanerPlus, HKLM\SOFTWARE\CLASSES\TYPELIB\{A5FF3EB5-BF62-4D59-84DF-DC518E46FCB3}, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.SlimCleanerPlus, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{A5FF3EB5-BF62-4D59-84DF-DC518E46FCB3}, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.SlimCleanerPlus, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{A5FF3EB5-BF62-4D59-84DF-DC518E46FCB3}, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.SlimCleanerPlus, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SlimService, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\DriverUpdate, Quarantined, [2897], [331449],1.0.8389
PUP.Optional.SlimServices, HKLM\SOFTWARE\CLASSES\TYPELIB\{58A8BF1A-3608-41EA-AAD1-581AB79105E6}, Quarantined, [7460], [452421],1.0.8389
PUP.Optional.SlimServices, HKLM\SOFTWARE\CLASSES\INTERFACE\{E58DA376-0D39-45ED-A6EE-A7B6DD10BED2}, Quarantined, [7460], [452421],1.0.8389
PUP.Optional.SlimServices, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{58A8BF1A-3608-41EA-AAD1-581AB79105E6}, Quarantined, [7460], [452421],1.0.8389
PUP.Optional.SlimServices, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{58A8BF1A-3608-41EA-AAD1-581AB79105E6}, Quarantined, [7460], [452421],1.0.8389
PUP.Optional.SlimServices, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SlimWareServices, Quarantined, [7460], [452421],1.0.8389
PUP.Optional.SlimCleanerPlus, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{7E03DFCF-3091-4D7A-91AB-59994A7A36B6}, Quarantined, [1473], [335437],1.0.8389
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{1BD47D21-01F4-4538-9290-39FD569A0F24}, Quarantined, [2897], [335822],1.0.8389
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\{1BD47D21-01F4-4538-9290-39FD569A0F24}, Quarantined, [2897], [335822],1.0.8389
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\CLASSES\APPID\{1BD47D21-01F4-4538-9290-39FD569A0F24}, Quarantined, [2897], [335822],1.0.8389
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\CLASSES\CLSID\{BAF87BD0-A924-4108-AFA5-A5FA720A2E86}, Quarantined, [2897], [335831],1.0.8389
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\CLASSES\CLSID\{959D527D-6C27-4879-A644-065526D6969C}, Quarantined, [2897], [335833],1.0.8389
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\CLASSES\APPID\{149622B2-F1C5-492D-BFDF-8E5ED85854A0}, Quarantined, [2897], [335820],1.0.8389
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{149622B2-F1C5-492D-BFDF-8E5ED85854A0}, Quarantined, [2897], [335820],1.0.8389
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\{149622B2-F1C5-492D-BFDF-8E5ED85854A0}, Quarantined, [2897], [335820],1.0.8389
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\CLASSES\CLSID\{6DC6EE87-F3BB-40EB-BCEE-12F7D6E3EEDF}, Quarantined, [2897], [335836],1.0.8389

Registry Value: 5
PUP.Optional.DriverUpdate, HKU\S-1-5-21-3658810515-2502364871-1149701184-1004\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|DRIVERUPDATE, Quarantined, [2897], [331450],1.0.8389
PUP.Optional.SlimCleanerPlus, HKU\S-1-5-21-3658810515-2502364871-1149701184-1004\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|SLIMCLEANER PLUS, Quarantined, [1473], [452419],1.0.8389
PUP.Optional.SlimCleanerPlus, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{C847C50D-0C99-454D-9E29-8152FEE60238}|PATH, Quarantined, [1473], [334102],1.0.8389
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{EAF368C5-1E41-40F8-B3E9-518010D8DAB3}|PATH, Quarantined, [2897], [335435],1.0.8389
PUP.Optional.SlimCleanerPlus, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{7E03DFCF-3091-4D7A-91AB-59994A7A36B6}|DISPLAYNAME, Quarantined, [1473], [335437],1.0.8389

Registry Data: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 2
PUP.Optional.SlimCleanerPlus, C:\PROGRAM FILES\SLIMSERVICE, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.DriverUpdate, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\DRIVERUPDATE, Quarantined, [2897], [331462],1.0.8389

File: 32
PUP.Optional.DriverUpdate, C:\USERS\PUBLIC\DESKTOP\DRIVERUPDATE.LNK, Quarantined, [2897], [331456],1.0.8389
PUP.Optional.DriverUpdate, C:\WINDOWS\SYSTEM32\TASKS\DRIVERUPDATE SCAN, Quarantined, [2897], [331466],1.0.8389
PUP.Optional.SlimCleanerPlus, C:\WINDOWS\SYSTEM32\TASKS\SlimCleaner Plus (Scheduled Scan - User), Quarantined, [1473], [334098],1.0.8389
PUP.Optional.SlimCleanerPlus, C:\PROGRAM FILES\SLIMSERVICE\CLEANER.DB, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimService\Analyze.MyD, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimService\Full.MyD, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimService\icudt46l.dat, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimService\MyDefragDll.dll, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimService\Quick.MyD, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimService\SlimService.exe, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimService\SlimServiceFactory.exe, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimService\Ssd.MyD, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimService\UnifiedLogger.dll, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.SlimCleanerPlus, C:\Program Files\SlimService\WinRT.dll, Quarantined, [1473], [331454],1.0.8389
PUP.Optional.SlimCleanerPlus, C:\USERS\PUBLIC\DESKTOP\SlimCleaner Plus.lnk, Quarantined, [1473], [398509],1.0.8389
PUP.Optional.DriverUpdate, C:\PROGRAM FILES\DRIVERUPDATE\DRIVERUPDATE.EXE, Quarantined, [2897], [331450],1.0.8389
PUP.Optional.SlimCleanerPlus, C:\PROGRAM FILES\SLIMCLEANER PLUS\SLIMCLEANERPLUS.EXE, Quarantined, [1473], [452419],1.0.8389
PUP.Optional.DriverUpdate, C:\Program Files\DriverUpdate\BsSndRpt.exe, Quarantined, [2897], [331449],1.0.8389
PUP.Optional.DriverUpdate, C:\Program Files\DriverUpdate\BugSplat.dll, Quarantined, [2897], [331449],1.0.8389
PUP.Optional.DriverUpdate, C:\Program Files\DriverUpdate\BugSplatRc.dll, Quarantined, [2897], [331449],1.0.8389
PUP.Optional.DriverUpdate, C:\Program Files\DriverUpdate\htmlayout.dll, Quarantined, [2897], [331449],1.0.8389
PUP.Optional.DriverUpdate, C:\Program Files\DriverUpdate\InAppBrowserProxy.dll, Quarantined, [2897], [331449],1.0.8389
PUP.Optional.DriverUpdate, C:\Program Files\DriverUpdate\lib-inappbrowser.dll, Quarantined, [2897], [331449],1.0.8389
PUP.Optional.DriverUpdate, C:\Program Files\DriverUpdate\Open-Source Licenses.txt, Quarantined, [2897], [331449],1.0.8389
PUP.Optional.DriverUpdate, C:\Program Files\DriverUpdate\SlimWare.DriverUpdate.Services.dll, Quarantined, [2897], [331449],1.0.8389
PUP.Optional.DriverUpdate, C:\Program Files\DriverUpdate\SlimWare.Messaging.dll, Quarantined, [2897], [331449],1.0.8389
PUP.Optional.DriverUpdate, C:\Program Files\DriverUpdate\SlimWare.PushNotification.Services.dll, Quarantined, [2897], [331449],1.0.8389
PUP.Optional.DriverUpdate, C:\Program Files\DriverUpdate\UnifiedLogger.dll, Quarantined, [2897], [331449],1.0.8389
PUP.Optional.DriverUpdate, C:\Program Files\DriverUpdate\UninstallStub.exe, Quarantined, [2897], [331449],1.0.8389
PUP.Optional.DriverUpdate, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverUpdate\DriverUpdate Help.lnk, Quarantined, [2897], [331462],1.0.8389
PUP.Optional.DriverUpdate, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverUpdate\DriverUpdate.lnk, Quarantined, [2897], [331462],1.0.8389
PUP.Optional.SlimServices, C:\PROGRAM FILES\SLIMWARE UTILITIES\SERVICES\SLIMWARE.SERVICES.EXE, Quarantined, [7460], [452421],1.0.8389

Physical Sector: 0
(No malicious items detected)

WMI: 0
(No malicious items detected)


(end)


Any help is much appreciated :)
 
Operating System
Windows 7
Infection date and initial symptoms
19DEC2018
Current issues and symptoms
Deleted Personal files, possibly deleted system files.
Steps taken in order to remove the infection
restarting PC.
Likes: oldschool