Jump to content

Welcome to Geeks to Go
Geeks to Go Welcome
Create Account Login to Account
Photo

Removal instructions for Advanced Driver Updater

- - - - - systweak

  • Please log in to reply
No replies to this topic

#1
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 33,101 posts
Content is republished with permission from Malwarebytes.

What is Advanced Driver Updater?

The Malwarebytes research team has determined that Advanced Driver Updater is a "driver updater". These so-called "system optimizers" sometimes use intentional false positives to convince users that their systems have problems. Then they try to sell you their software, claiming it will remove these problems.
More information can be found on our Malwarebytes Labs blog.

How do I know if I am infected with Advanced Driver Updater?

This is how the main screen of the system optimizer looks:

main.png

You will find these icons in your taskbar, your startmenu, and on your desktop:

icons.png

and see these warnings during install:

warning1.png

warning2.png

and this type of screens during "operations":

warning5.png

warning6.png

You may see this entry in your list of installed programs:

warning4.png

and these tasks in your list of Scheduled Tasks:

warning3.png

How did Advanced Driver Updater get on my computer?

These so-called system optimizers use different methods of getting installed. This particular one was downloaded from their website:

website.png

How do I remove Advanced Driver Updater?

Our program Malwarebytes can detect and remove this potentially unwanted application.
  • Please download Malwarebytes for Windows to your desktop.
  • Double-click MBSetup.exe and follow the prompts to install the program.
  • When your Malwarebytes for Windows installation completes, the program opens to the Welcome to Malwarebytes screen.
  • Click on the Get started button.
  • Click Scan to start a Threat Scan.
  • When the scan is finished click Quarantine to remove the found threats.
  • Reboot the system if prompted to complete the removal process.
Is there anything else I need to do to get rid of Advanced Driver Updater?
  • No, Malwarebytes removes Advanced Driver Updater completely.
  • This PUP creates some scheduled tasks. You can read here how to check for and, if necessary, remove Scheduled Tasks.
How would the full version of Malwarebytes help protect me?

We hope our application and this guide have helped you eradicate this system optimizer.

As you can see below the full version of Malwarebytes would have protected you against the Advanced Driver Updater installer. It would have warned you before the application could install itself, giving you a chance to stop it before it became too late.

protection1.png


Technical details for experts

You may see these entries in FRST logs:

(SYSTWEAK SOFTWARE PVT. LTD. -> Systweak) C:\Program Files (x86)\Advanced Driver Updater\ADU.exe
Task: {12B434B4-F265-41FD-A6B3-C198F786C9F3} - System32\Tasks\Advanced Driver UpdaterNotifier => C:\Program Files (x86)\Advanced Driver Updater\adunotifier.exe [3458808 2020-04-03] (SYSTWEAK SOFTWARE PVT. LTD. -> Systweak Software)
Task: {210DF4AF-F245-477F-9B2D-AB4502C11EFB} - System32\Tasks\AdvancedDriverUpdater_UPDATES => C:\Program Files (x86)\Advanced Driver Updater\ADU.exe [5445368 2020-04-03] (SYSTWEAK SOFTWARE PVT. LTD. -> Systweak)
Task: {69E0BB72-3A6D-4B12-847D-355809219F8B} - System32\Tasks\Advanced Driver UpdaterNotifier_startup => C:\Program Files (x86)\Advanced Driver Updater\adunotifier.exe [3458808 2020-04-03] (SYSTWEAK SOFTWARE PVT. LTD. -> Systweak Software)
Task: {84D4A5AE-4E9C-4FA0-89F6-4CB61749E43D} - System32\Tasks\AdvancedDriverUpdaterRunAtStartup => C:\Program Files (x86)\Advanced Driver Updater\ADU.exe [5445368 2020-04-03] (SYSTWEAK SOFTWARE PVT. LTD. -> Systweak)
Task: {8EF5CD39-427F-424B-B22A-016C4B33A65C} - System32\Tasks\Advanced Driver UpdaterNotifier_trigger => C:\Program Files (x86)\Advanced Driver Updater\adunotifier.exe [3458808 2020-04-03] (SYSTWEAK SOFTWARE PVT. LTD. -> Systweak Software)
C:\Windows\system32\Tasks\AdvancedDriverUpdater_UPDATES
C:\Windows\system32\Tasks\AdvancedDriverUpdaterRunAtStartup
C:\Windows\system32\Tasks\Advanced Driver UpdaterNotifier_trigger
C:\Windows\system32\Tasks\Advanced Driver UpdaterNotifier
C:\Windows\system32\Tasks\Advanced Driver UpdaterNotifier_startup
C:\Program Files (x86)\Advanced Driver Updater
C:\Users\Public\Desktop\Advanced Driver Updater.lnk
C:\ProgramData\Desktop\Advanced Driver Updater.lnk
C:\Users\{username}\AppData\Roaming\Systweak
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced Driver Updater
(Systweak Software, 1999-2020 All rights reserved. ) C:\Users\{username}\Desktop\adug_systweak-default.exe

Advanced Driver Updater (HKLM-x32\...\DA71BA65-680A-4212-9150-6239217B53DC_Systweak_Ad~8C5446C9_is1) (Version: 4.5.1086.17939 - Systweak Software, 1999-2020 All rights reserved.) <==== ATTENTION
( (CodePlex Community) [File not signed])  [File is in use ] C:\Program Files (x86)\Advanced Driver Updater\Microsoft.Win32.TaskScheduler.dll
( (Thomas Levesque) [File not signed])  [File is in use ] C:\Program Files (x86)\Advanced Driver Updater\WpfAnimatedGif.dll
( (Xceed Software Inc.) [File not signed])  [File is in use ] C:\Program Files (x86)\Advanced Driver Updater\Xceed.Wpf.Toolkit.dll
Alterations made by the installer:

File system details [View: All details] (Selection)
---------------------------------------------------
    Adds the folder C:\Program Files (x86)\Advanced Driver Updater
       Adds the file ADU.exe"="4/3/2020 3:51 PM, 5445368 bytes, A
       Adds the file ADU.exe.config"="3/3/2020 11:56 AM, 2554 bytes, A
       Adds the file adunotifier.exe"="4/3/2020 3:51 PM, 3458808 bytes, A
       Adds the file ADUNotifier_Corruptlog.txt"="5/7/2020 8:51 AM, 0 bytes, A
       Adds the file ADUNotifier_log.txt"="5/7/2020 8:52 AM, 1260 bytes, A
       Adds the file ADUNotifier_OutOfMemorylog.txt"="5/7/2020 8:51 AM, 0 bytes, A
       Adds the file Chinese_adu.ini"="3/13/2020 5:11 PM, 104864 bytes, A
       Adds the file Danish_adu.ini"="3/13/2020 5:11 PM, 184510 bytes, A
       Adds the file Delimon.Win32.IO.dll"="12/3/2019 2:38 PM, 950272 bytes, A
       Adds the file difxapi.dll"="7/4/2019 4:16 PM, 323464 bytes, A
       Adds the file difxapi64.dll"="6/26/2019 12:47 PM, 519048 bytes, A
       Adds the file Dutch_adu.ini"="3/13/2020 5:11 PM, 195616 bytes, A
       Adds the file eng_adu_en.ini"="4/1/2020 3:56 PM, 91655 bytes, A
       Adds the file Finnish_adu.ini"="3/13/2020 5:11 PM, 171396 bytes, A
       Adds the file French_adu.ini"="3/13/2020 5:11 PM, 196824 bytes, A
       Adds the file German_adu.ini"="3/13/2020 5:11 PM, 191278 bytes, A
       Adds the file input.xml"="5/7/2020 8:52 AM, 23572 bytes, A
       Adds the file isxdl.dll"="12/3/2019 2:38 PM, 155712 bytes, A
       Adds the file Italian_adu.ini"="3/13/2020 5:11 PM, 180638 bytes, A
       Adds the file Japanese_adu.ini"="3/13/2020 5:11 PM, 129308 bytes, A
       Adds the file Microsoft.Win32.TaskScheduler.dll"="12/3/2019 2:38 PM, 115200 bytes, A
       Adds the file Norwegian_adu.ini"="3/13/2020 5:11 PM, 168842 bytes, A
       Adds the file notifier.ini"="4/3/2020 1:22 PM, 577 bytes, A
       Adds the file notifier.json"="5/7/2020 8:52 AM, 14668 bytes, A
       Adds the file notifierlib.dll"="4/3/2020 3:51 PM, 407712 bytes, A
       Adds the file output.xml"="5/7/2020 8:52 AM, 1054 bytes, A
       Adds the file portuguese_adu.ini"="3/13/2020 5:11 PM, 172924 bytes, A
       Adds the file russian_adu.ini"="3/13/2020 5:11 PM, 181260 bytes, A
       Adds the file spanish_adu.ini"="3/13/2020 5:11 PM, 189776 bytes, A
       Adds the file swedish_adu.ini"="3/13/2020 5:11 PM, 174054 bytes, A
       Adds the file unins000.dat"="5/7/2020 8:50 AM, 163263 bytes, A
       Adds the file unins000.exe"="5/7/2020 8:50 AM, 1268472 bytes, A
       Adds the file unins000.msg"="5/7/2020 8:50 AM, 22701 bytes, A
       Adds the file unrar.dll"="7/4/2019 4:16 PM, 269016 bytes, A
       Adds the file webbrowser.exe"="4/3/2020 3:51 PM, 139000 bytes, A
       Adds the file WpfAnimatedGif.dll"="12/3/2019 2:38 PM, 40448 bytes, A
       Adds the file WPFToolkit.dll"="12/3/2019 2:38 PM, 467288 bytes, A
       Adds the file Xceed.Wpf.Toolkit.dll"="12/3/2019 2:38 PM, 1352704 bytes, A
    Adds the folder C:\Program Files (x86)\Advanced Driver Updater\updater\amd64Helper
       Adds the file difxapi.dll"="7/4/2019 4:16 PM, 519048 bytes, A
       Adds the file DriverUpdateHelper64.exe"="4/3/2020 3:51 PM, 537848 bytes, A
       Adds the file DriverUpdateHelper64.manifest"="7/4/2019 4:16 PM, 689 bytes, A
    Adds the folder C:\Program Files (x86)\Advanced Driver Updater\updater\extract
       Adds the file 7z.dll"="4/3/2020 3:51 PM, 740600 bytes, A
       Adds the file 7z.exe"="4/3/2020 3:51 PM, 164600 bytes, A
       Adds the file copying.txt"="10/4/2017 6:25 PM, 26948 bytes, A
       Adds the file History.txt"="10/4/2017 6:25 PM, 29037 bytes, A
       Adds the file license.txt"="10/4/2017 6:25 PM, 2049 bytes, A
       Adds the file readme.txt"="10/4/2017 6:25 PM, 1616 bytes, A
    Adds the folder C:\Program Files (x86)\Advanced Driver Updater\updater\x86Helper
       Adds the file difxapi.dll"="12/3/2019 2:38 PM, 323464 bytes, A
       Adds the file DriverUpdateHelperx86.exe"="4/3/2020 3:51 PM, 341752 bytes, A
       Adds the file DriverUpdateHelperx86.manifest"="12/3/2019 2:38 PM, 690 bytes, A
    Adds the folder C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced Driver Updater
       Adds the file Advanced Driver Updater.lnk"="5/7/2020 8:50 AM, 1099 bytes, A
       Adds the file Uninstall Advanced Driver Updater.lnk"="5/7/2020 8:50 AM, 1130 bytes, A
    Adds the folder C:\Users\{username}\AppData\Roaming\Systweak\adu\4.5.1086.17939
    Adds the folder C:\Users\{username}\AppData\Roaming\Systweak\adu\Advanced Driver Updater
       Adds the file dbupdate.ini"="5/7/2020 8:52 AM, 516 bytes, A
       Adds the file exc.xml"="5/7/2020 8:51 AM, 14 bytes, A
       Adds the file fResults.du"="5/7/2020 8:52 AM, 1054 bytes, A
       Adds the file notifier.ini"="5/7/2020 8:52 AM, 622 bytes, A
       Adds the file Results.du"="5/7/2020 8:52 AM, 91161 bytes, A
       Adds the file Update.ini"="5/7/2020 8:52 AM, 22 bytes, A
    Adds the folder C:\Users\{username}\AppData\Roaming\Systweak\adu\Advanced Driver Updater\Backup
    Adds the folder C:\Users\{username}\AppData\Roaming\Systweak\adu\Advanced Driver Updater\Download
    Adds the folder C:\Users\{username}\AppData\Roaming\Systweak\adu\Advanced Driver Updater\Logs
       Adds the file adu.txt"="5/7/2020 8:52 AM, 58378 bytes, A
       Adds the file adu_1.txt"="5/7/2020 8:50 AM, 0 bytes, A
    Adds the folder C:\Users\{username}\AppData\Roaming\Systweak\adu\Advanced Driver Updater\update
    In the existing folder C:\Users\Public\Desktop
       Adds the file Advanced Driver Updater.lnk"="5/7/2020 8:50 AM, 1081 bytes, A
    In the existing folder C:\Windows\System32\Tasks
       Adds the file Advanced Driver UpdaterNotifier"="5/7/2020 8:51 AM, 3326 bytes, A
       Adds the file Advanced Driver UpdaterNotifier_startup"="5/7/2020 8:51 AM, 3236 bytes, A
       Adds the file Advanced Driver UpdaterNotifier_trigger"="5/7/2020 8:51 AM, 3358 bytes, A
       Adds the file AdvancedDriverUpdater_UPDATES"="5/7/2020 8:51 AM, 3606 bytes, A
       Adds the file AdvancedDriverUpdaterRunAtStartup"="5/7/2020 8:51 AM, 3398 bytes, A

Registry details [View: All details] (Selection)
------------------------------------------------
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\DA71BA65-680A-4212-9150-6239217B53DC_Systweak_Ad~8C5446C9_is1]
       "DisplayIcon"="REG_SZ", "C:\Program Files (x86)\Advanced Driver Updater\ADU.exe"
       "DisplayName"="REG_SZ", "Advanced Driver Updater"
       "DisplayVersion"="REG_SZ", "4.5.1086.17939"
       "EstimatedSize"="REG_DWORD", 19469
       "HelpLink"="REG_SZ", "http://www.systweak.com/"
       "Inno Setup: App Path"="REG_SZ", "C:\Program Files (x86)\Advanced Driver Updater"
       "Inno Setup: Icon Group"="REG_SZ", "Advanced Driver Updater"
       "Inno Setup: Language"="REG_SZ", "en"
       "Inno Setup: Setup Version"="REG_SZ", "5.5.5 (u)"
       "Inno Setup: User"="REG_SZ", "{username}"
       "InstallDate"="REG_SZ", "20200507"
       "InstallLocation"="REG_SZ", "C:\Program Files (x86)\Advanced Driver Updater\"
       "MajorVersion"="REG_DWORD", 4
       "MinorVersion"="REG_DWORD", 5
       "NoModify"="REG_DWORD", 1
       "NoRepair"="REG_DWORD", 1
       "Publisher"="REG_SZ", "Systweak Software, 1999-2020 All rights reserved."
       "QuietUninstallString"="REG_SZ", ""C:\Program Files (x86)\Advanced Driver Updater\unins000.exe" /SILENT"
       "UninstallString"="REG_SZ", ""C:\Program Files (x86)\Advanced Driver Updater\unins000.exe""
       "URLInfoAbout"="REG_SZ", "http://www.systweak.com/"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Systweak\adu]
       "affiliate"="REG_SZ", ""
       "affiliateid"="REG_SZ", ""
       "afterInstallUrl"="REG_SZ", "http://www.systweak.com/advanced-driver-updater/after-install?newaduw=1&utm_content=AfterInstall&utm_term=Setup&page=install"
       "AFTINSTS"="REG_DWORD", 0
       "bdts"="REG_SZ", "03042020 15:51:28"
       "bdts_new"="REG_SZ", "03-04-2020"
       "BUILD_FOR"="REG_SZ", "systweak"
       "BuyNowURL"="REG_SZ", "http://www.systweak.com/adu/price.asp?&appversion=4.5.1086.17939&utm_cid=&macid=1361824443874848900"
       "BuyNowURLADU"="REG_SZ", "http://powerbundle.systweak.com/pb/price/?pname=adu&"
       "BuyNowURLASP"="REG_SZ", "http://powerbundle.systweak.com/pb/price/?pname=asp&"
       "BuyNowURLPB"="REG_SZ", "http://powerbundle.systweak.com/PB/purchase/?pname=adu&"
       "BuyNowURLRCP"="REG_SZ", "http://powerbundle.systweak.com/pb/price/?pname=rcp&"
       "CplURL"="REG_SZ", ""
       "crsi"="REG_DWORD", 1
       "dwIsPCHelpOnlineBuild"="REG_DWORD", 0
       "dwIsSilentBuildForRCP"="REG_DWORD", -1
       "escn"="REG_DWORD", 1
       "finalparams"="REG_SZ", "&pxl=ADU_DEF_PIXEL&pcrts=07-05-2020 07:55:52&pcrt=637244349529649300&scrr=1920x975&scrsf=1&bdts=03-04-2020&instdts=07-05-2020&bdt=637215258880000000&instdt=637244382410000000&scrsd=1&OfferType=1&sn=adug_systweak-default.exe"
       "GA"="REG_DWORD", 1
       "installDate"="REG_SZ", "07/05/2020 08:50:41"
       "InstalledPath"="REG_SZ", "C:\Program Files (x86)\Advanced Driver Updater"
       "instdts"="REG_SZ", "07052020 08:50:41"
       "instdts_new"="REG_SZ", "07-05-2020"
       "IsLbBuild"="REG_SZ", "0"
       "IsNLBuild"="REG_DWORD", 0
       "IsPbEnabled"="REG_DWORD", 1
       "IsSendKeyStatus"="REG_DWORD", 0
       "issilent"="REG_DWORD", 1
       "IsTelNoEnabled"="REG_DWORD", 1
       "IsUpdateBuild"="REG_SZ", "0"
       "MachineUniqueId"="REG_SZ", "136824443874848900"
       "model"="REG_SZ", "innotek GmbH VirtualBox"
       "nAppendParamsFromReg"="REG_DWORD", 1
       "os"="REG_SZ", "Microsoft+Windows+7+Ultimate"
       "ovbt"="REG_DWORD", 0
       "prdid"="REG_SZ", "135"
       "pxl"="REG_SZ", "ADU_DEF_PIXEL"
       "RenewNowURL"="REG_SZ", "http://www.systweak.com/adu/renewal.asp?&appversion=4.5.1086.17939&utm_cid="
       "RenewNowURLADU"="REG_SZ", "http://powerbundle.systweak.com/pb/renewal/?pname=adu&"
       "RenewNowURLASP"="REG_SZ", "http://powerbundle.systweak.com/pb/renewal/?pname=asp&"
       "RenewNowURLPB"="REG_SZ", "http://powerbundle.systweak.com/PB/pbrenewal/?pname=adu&"
       "RenewNowURLRCP"="REG_SZ", "http://powerbundle.systweak.com/pb/renewal/?pname=rcp&"
       "scn"="REG_DWORD", 0
       "sen"="REG_DWORD", 1
       "send"="REG_DWORD", 0
       "setup_type"="REG_SZ", "11"
       "strayalertnag"="REG_DWORD", 1
       "TELNO"="REG_SZ", "(855)532-3907"
       "utm_campaign"="REG_SZ", "default"
       "utm_cid"="REG_SZ", ""
       "utm_days"="REG_SZ", "0"
       "utm_medium"="REG_SZ", "newbuild"
       "utm_source"="REG_SZ", "systweak"
       "x-at"="REG_SZ", ""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Systweak\adu\4.5.1086.17939]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Systweak\adu\LANG]
       "LangCode"="REG_SZ", "en"
       "LangID"="REG_DWORD", 0
    [HKEY_CURRENT_USER\Software\Systweak\adu]
       "affiliate"="REG_SZ", ""
       "affiliateid"="REG_SZ", ""
       "afterInstallUrl"="REG_SZ", "http://www.systweak.com/advanced-driver-updater/after-install?newaduw=1&utm_content=AfterInstall&utm_term=Setup&page=install"
       "AFTINSTS"="REG_DWORD", 0
       "aoign"="REG_SZ", "0"
       "AppDriverScanStatus"="REG_DWORD", 1
       "Backup Path"="REG_SZ", "C:\Users\{username}\AppData\Roaming\Systweak\adu\Advanced Driver Updater\Backup\"
       "bdt"="REG_SZ", "637215258880000000"
       "bdts"="REG_SZ", "03042020 15:51:28"
       "bdts_new"="REG_SZ", "03-04-2020"
       "bShowTrayOffer"="REG_DWORD", 1
       "BuyNowURL"="REG_SZ", "http://www.systweak.com/adu/price.asp?&appversion=4.5.1086.17939&utm_cid=&macid=1361824443874848900"
       "CplURL"="REG_SZ", ""
       "crsi"="REG_DWORD", 1
       "DeviceIconIDNDriverName"="REG_SZ", "38;Intel(R) PRO/1000 MT Desktop Adapter"
       "Download Path"="REG_SZ", "C:\Users\{username}\AppData\Roaming\Systweak\adu\Advanced Driver Updater\Download\"
       "DriverAge"="REG_DWORD", 0
       "DriverOutdatedCount"="REG_SZ", "1"
       "DriverOutdatedNames"="REG_SZ", "Intel(R) PRO/1000 MT Desktop Adapter"
       "dTelNoNeeded"="REG_DWORD", 0
       "escn"="REG_DWORD", 1
       "ExitNagType"="REG_DWORD", 0
       "Expired"="REG_DWORD", 0
       "finalparams"="REG_SZ", "&pxl=ADU_DEF_PIXEL&pcrts=07-05-2020 07:55:52&pcrt=637244349529649300&scrr=1920x975&scrsf=1&bdts=03-04-2020&instdts=07-05-2020&bdt=637215258880000000&instdt=637244382410000000&scrsd=1&OfferType=1&sn=adug_systweak-default.exe"
       "FirstInstallDate"="REG_SZ", "07052020 08:51:24"
       "GA"="REG_DWORD", 1
       "GoToSystemTrayOnClose"="REG_DWORD", 1
       "ibv"="REG_SZ", "1"
       "iev"="REG_SZ", "9"
       "ImprovementProgram"="REG_DWORD", 0
       "InstalledPath"="REG_SZ", "C:\Program Files (x86)\Advanced Driver Updater"
       "instdt"="REG_SZ", "637244382410000000"
       "instdts"="REG_SZ", "07052020 08:50:41"
       "instdts_new"="REG_SZ", "07-05-2020"
       "IsFIrstScanComplete"="REG_DWORD", 1
       "IsHidePopup"="REG_DWORD", 0
       "IsLbBuild"="REG_SZ", "0"
       "IsNLBuild"="REG_DWORD", 0
       "issilent"="REG_DWORD", 1
       "IsUpdateBuild"="REG_SZ", "0"
       "Key"="REG_SZ", ""
       "LearnMoreNagType"="REG_DWORD", 0
       "macid"="REG_SZ", "136824443874848900"
       "Manufacturer"="REG_DWORD", 31
       "ManufacturerName"="REG_SZ", "Oracle Corporation"
       "MaxFixLimit"="REG_DWORD", 2
       "model"="REG_SZ", "VirtualBox"
       "nMaxFixLimit"="REG_DWORD", 0
       "NumTimesRCPRunned"="REG_DWORD", 0
       "OldestDriverAgeInYears"="REG_DWORD", 4244
       "os"="REG_SZ", "Microsoft+Windows+7+Ultimate"
       "OSFriendlyName"="REG_SZ", "Windows 7"
       "ovbt"="REG_DWORD", 0
       "pcname"="REG_SZ", "{computername}"
       "pcrt"="REG_SZ", "63724449529649300"
       "pcrts"="REG_SZ", "07-05-2020 07:55:52"
       "prdmsg"="REG_DWORD", 1
       "proc"="REG_SZ", "Intel(R) Core(TM) i7-7700HQ CPU @ 2.80GHz"
       "ProcessorName"="REG_SZ", "Intel(R) Core(TM) i7-7700HQ CPU @ 2.80GHz"
       "pxl"="REG_SZ", "ADU_DEF_PIXEL"
       "ram"="REG_SZ", "2.00 GB"
       "REGVER"="REG_DWORD", 0
       "REGVER-UNINSTALL"="REG_DWORD", 0
       "RenewNowURL"="REG_SZ", "http://www.systweak.com/adu/renewal.asp?&appversion=4.5.1086.17939&utm_cid="
       "scn"="REG_DWORD", 0
       "scrr"="REG_SZ", "1920x975"
       "scrsd"="REG_SZ", "1"
       "scrsf"="REG_SZ", "1"
       "sen"="REG_DWORD", 1
       "send"="REG_DWORD", 0
       "SetChkDontShowRedTrayPopup"="REG_DWORD", 0
       "SetChkPeriodicUpDate"="REG_DWORD", 1
       "setup_type"="REG_SZ", "11"
       "StartAutoScanOnLaunch"="REG_DWORD", 0
       "StartAutoScanPMUI"="REG_DWORD", 1
       "StartAutoTutorial"="REG_DWORD", 1
       "StartMinimized"="REG_DWORD", 0
       "StartScan"="REG_DWORD", 0
       "StartWhenWinBoots"="REG_DWORD", 1
       "strayalertnag"="REG_DWORD", 1
       "StrLastScan"="REG_SZ", "637244383483853849"
       "StrLastScanResults"="REG_SZ", "1"
       "TELNO"="REG_SZ", "(855)532-3907"
       "TotalOutOfDateDrivers"="REG_DWORD", 1
       "TotalScannedDrivers"="REG_DWORD", 37
       "TotalUpToDateDrivers"="REG_DWORD", 36
       "uninstallfinalparams"="REG_SZ", "pn=Advanced Driver Updater&appversion=4.5.1086.17939&cdbid=&firstinstall=0&utm_days=0&langcode=en&isreg=0&isexpired=0&macid=1361824443874848900&productid=135&os=Microsoft+Windows+7+Ultimate&ram=Microsoft+Windows+7+Ultimate&model=VirtualBox&proc=Intel(R) Core(TM) i7-7700HQ CPU @ 2.80GHz&x-isvm=1&iev=9&setup_type=11&utm_source=systweak&utm_medium=newbuild&utm_campaign=default&affiliate=&utm_cid=&utm_updt=&utm_updatedate=&nagparent=&x-lip=90_145_230_242&lipl=1519511282&x-lipnw=90_145_230_242&od=0&pxl=ADU_DEF_PIXEL&pcrts=07-05-2020 07:55:52&pcrt=637244349529649300&scrr=1920x975&scrsf=1&bdts=03-04-2020&instdts=07-05-2020&bdt=637215258880000000&instdt=637244382410000000&scrsd=1&OfferType=1&sn=adug_systweak-default.exe"
       "UpdateAllNagType"="REG_DWORD", 0
       "UpdateDriverNagType"="REG_DWORD", 0
       "utm_campaign"="REG_SZ", "default"
       "utm_cid"="REG_SZ", ""
       "utm_days"="REG_SZ", "0"
       "utm_installdate"="REG_BINARY, ........
       "utm_medium"="REG_SZ", "newbuild"
       "utm_source"="REG_SZ", "systweak"
       "utmnag_days"="REG_SZ", "0"
       "x-at"="REG_SZ", ""
       "x-lip"="REG_SZ", "90.145.230.242"
    [HKEY_CURRENT_USER\Software\Systweak\adu\4.5.1086.17939]
    [HKEY_CURRENT_USER\Software\Systweak\adu\LANG]
       "LangCode"="REG_SZ", "en"
       "LangID"="REG_DWORD", 0
    [HKEY_CURRENT_USER\Software\Systweak\adu\notifier]
       "nst"="REG_DWORD", 0
    [HKEY_CURRENT_USER\Software\Systweak\Notifier]
       "BaseUID"="REG_SZ", "Advanced Driver Updater"
Malwarebytes log:

Malwarebytes
www.malwarebytes.com

-Log Details-
Scan Date: 5/7/20
Scan Time: 9:00 AM
Log File: 7bc720c2-9030-11ea-9411-00ffdcc6fdfc.json

-Software Information-
Version: 4.1.0.56
Components Version: 1.0.896
Update Package Version: 1.0.23556
License: Premium

-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: {computername}\{username}

-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 233401
Threats Detected: 77
Threats Quarantined: 77
Time Elapsed: 2 min, 43 sec

-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect

-Scan Details-
Process: 1
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\ADU.exe, Quarantined, 4431, 258375, , , , 

Module: 4
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\ADU.exe, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\Microsoft.Win32.TaskScheduler.dll, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\WpfAnimatedGif.dll, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\Xceed.Wpf.Toolkit.dll, Quarantined, 4431, 258375, , , , 

Registry Key: 18
PUP.Optional.SysTweak, HKLM\SOFTWARE\WOW6432NODE\Systweak, Quarantined, 795, 327155, 1.0.23556, , ame, 
PUP.Optional.SysTweak, HKCU\SOFTWARE\Systweak, Quarantined, 795, 327156, 1.0.23556, , ame, 
PUP.Optional.AdvancedDriverUpdater, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\AdvancedDriverUpdater_UPDATES, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{210DF4AF-F245-477F-9B2D-AB4502C11EFB}, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\PLAIN\{210DF4AF-F245-477F-9B2D-AB4502C11EFB}, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\AdvancedDriverUpdaterRunAtStartup, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{84D4A5AE-4E9C-4FA0-89F6-4CB61749E43D}, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\LOGON\{84D4A5AE-4E9C-4FA0-89F6-4CB61749E43D}, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Advanced Driver UpdaterNotifier, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{12B434B4-F265-41FD-A6B3-C198F786C9F3}, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\PLAIN\{12B434B4-F265-41FD-A6B3-C198F786C9F3}, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Advanced Driver UpdaterNotifier_startup, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{69E0BB72-3A6D-4B12-847D-355809219F8B}, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\LOGON\{69E0BB72-3A6D-4B12-847D-355809219F8B}, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Advanced Driver UpdaterNotifier_trigger, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{8EF5CD39-427F-424B-B22A-016C4B33A65C}, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\PLAIN\{8EF5CD39-427F-424B-B22A-016C4B33A65C}, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\DA71BA65-680A-4212-9150-6239217B53DC_Systweak_Ad~8C5446C9_is1, Quarantined, 4431, 258375, , , , 

Registry Value: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 1
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\updater\extract, Quarantined, 4431, 258375, , , , 

File: 53
PUP.Optional.AdvancedDriverUpdater, C:\PROGRAM FILES (X86)\ADVANCED DRIVER UPDATER\unins000.dat, Quarantined, 4431, 258375, 1.0.23556, , ame, 
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\updater\amd64Helper\DriverUpdateHelper64.exe, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\updater\amd64Helper\DriverUpdateHelper64.manifest, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\updater\extract\7z.dll, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\updater\extract\7z.exe, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\updater\extract\copying.txt, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\updater\extract\History.txt, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\updater\extract\license.txt, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\updater\extract\readme.txt, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\updater\x86Helper\DriverUpdateHelperx86.exe, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\updater\x86Helper\DriverUpdateHelperx86.manifest, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\ADU.exe, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\ADU.exe.config, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\adunotifier.exe, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\ADUNotifier_Corruptlog.txt, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\ADUNotifier_log.txt, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\ADUNotifier_OutOfMemorylog.txt, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\Chinese_adu.ini, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\Danish_adu.ini, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\Delimon.Win32.IO.dll, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\Dutch_adu.ini, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\eng_adu_en.ini, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\Finnish_adu.ini, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\French_adu.ini, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\German_adu.ini, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\input.xml, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\isxdl.dll, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\Italian_adu.ini, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\Japanese_adu.ini, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\Microsoft.Win32.TaskScheduler.dll, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\Norwegian_adu.ini, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\notifier.ini, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\notifier.json, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\notifierlib.dll, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\output.xml, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\portuguese_adu.ini, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\russian_adu.ini, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\spanish_adu.ini, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\swedish_adu.ini, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\unins000.exe, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\unins000.msg, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\unrar.dll, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\webbrowser.exe, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\WpfAnimatedGif.dll, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\Program Files (x86)\Advanced Driver Updater\Xceed.Wpf.Toolkit.dll, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\WINDOWS\SYSTEM32\TASKS\AdvancedDriverUpdater_UPDATES, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\WINDOWS\SYSTEM32\TASKS\AdvancedDriverUpdaterRunAtStartup, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\DOCUMENTS AND SETTINGS\PUBLIC\Desktop\Advanced Driver Updater.lnk, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\USERS\PUBLIC\Desktop\Advanced Driver Updater.lnk, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\WINDOWS\SYSTEM32\TASKS\Advanced Driver UpdaterNotifier, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\WINDOWS\SYSTEM32\TASKS\Advanced Driver UpdaterNotifier_startup, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\WINDOWS\SYSTEM32\TASKS\Advanced Driver UpdaterNotifier_trigger, Quarantined, 4431, 258375, , , , 
PUP.Optional.AdvancedDriverUpdater, C:\USERS\{username}\DESKTOP\ADUG_SYSTWEAK-DEFAULT.EXE, Quarantined, 4431, 817832, 1.0.23556, , ame, 

Physical Sector: 0
(No malicious items detected)

WMI: 0
(No malicious items detected)


(end)
As mentioned before the full version of Malwarebytes could have protected your computer against this threat.
We use different ways of protecting your computer(s):
  • Dynamically Blocks Malware Sites & Servers
  • Malware Execution Prevention
Save yourself the hassle and get protected.
  • 0

Advertisements






Also tagged with one or more of these keywords: systweak

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

featured
Malware Removal How to Guides Windows 7 System Building Download Files Register welcome

Never used a forum? Learn how.