When I ran AdwCleaner I got this:
-------------------------------
# Malwarebytes AdwCleaner 7.2.1.0
# -------------------------------
# Build: 06-26-2018
# Database: 2018-07-04.1
# Support:
https://www.malwarebytes.com/support#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 07-11-2018
# Duration: 00:00:07
# OS: Windows 10 Home
# Cleaned: 19
# Failed: 3
***** [ Services ] *****
No malicious services cleaned.
***** [ Folders ] *****
Deleted C:\Users\Jack C. Catalano\AppData\Roaming\AGData
Deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AnonymizerGadget
Deleted C:\Program Files (x86)\AnonymizerGadget
Deleted C:\Program Files (x86)\ScanGuard
Deleted C:\Program Files (x86)\WebDiscoverBrowser
***** [ Files ] *****
Deleted C:\Users\Public\Desktop\Driver Booster.lnk
Deleted C:\Users\Jack C. Catalano\Desktop\ScanGuard.lnk
***** [ DLL ] *****
No malicious DLLs cleaned.
***** [ WMI ] *****
No malicious WMI cleaned.
***** [ Shortcuts ] *****
No malicious shortcuts cleaned.
***** [ Tasks ] *****
No malicious tasks cleaned.
***** [ Registry ] *****
Deleted HKCU\Software\csastats
Deleted HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{1711FC25-F05A-40CE-B859-A0C1CF01FD18}
Deleted HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION|PCAcceleratePro.exe
Deleted HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION|PCAcceleratePro.exe
Deleted HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ScanGuard
Not Deleted HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\windows-7-easy-transfer-xp.en.softonic.com
Deleted HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\softonic.com
Deleted HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\en.softonic.com
Not Deleted HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\windows-7-easy-transfer-xp.en.softonic.com
Deleted HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\softonic.com
Deleted HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\en.softonic.com
Deleted HKCU\Software\SpecialSearchOffer
***** [ Chromium (and derivatives) ] *****
Deleted SpecialSearchOffer
***** [ Chromium URLs ] *****
Deleted Ask
Not Deleted nortonsafe.search.ask.com
***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries cleaned.
***** [ Firefox URLs ] *****
No malicious Firefox URLs cleaned.
*************************
- Delete Tracing Keys
- Reset Winsock
*************************
AdwCleaner[S00].txt - [3874 octets] - [11/07/2018 16:25:50]
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########
Malwarebytes
www.malwarebytes.com-Log Details-
Scan Date: 7/11/18
Scan Time: 4:37 PM
Log File: 49c152b6-854a-11e8-a1ed-f430b9c6d1ce.json
Administrator: Yes
-Software Information-
Version: 3.5.1.2522
Components Version: 1.0.391
Update Package Version: 1.0.5873
License: Trial
-System Information-
OS: Windows 10 (Build 14393.2007)
CPU: x64
File System: NTFS
User: LAPTOP-0N766CCD\Jack C. Catalano
-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 255873
Threats Detected: 19
Threats Quarantined: 19
Time Elapsed: 3 min, 16 sec
-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect
-Scan Details-
Process: 3
PUP.Optional.SpecialSearchOffer, C:\Program Files (x86)\Common Files\Roraccoon\Roraccoon.exe, Quarantined, [1657], [511633],1.0.5873
Adware.GorillaPrice, C:\PROGRAMDATA\MICROSOFT\WINDOWS\MKEEPERSTAT\MKEEPER.EXE, Quarantined, [9999], [504078],1.0.5873
Adware.GorillaPrice, C:\PROGRAMDATA\MICROSOFT\WINDOWS\MKEEPERSTAT\MKEEPER.EXE, Quarantined, [9999], [504078],1.0.5873
Module: 3
PUP.Optional.SpecialSearchOffer, C:\Program Files (x86)\Common Files\Roraccoon\Roraccoon.exe, Quarantined, [1657], [511633],1.0.5873
Adware.GorillaPrice, C:\PROGRAMDATA\MICROSOFT\WINDOWS\MKEEPERSTAT\MKEEPER.EXE, Quarantined, [9999], [504078],1.0.5873
Adware.GorillaPrice, C:\PROGRAMDATA\MICROSOFT\WINDOWS\MKEEPERSTAT\MKEEPER.EXE, Quarantined, [9999], [504078],1.0.5873
Registry Key: 4
PUP.Optional.PCAcceleratePro, HKLM\SOFTWARE\WOW6432NODE\PCAccelPro, Quarantined, [1268], [500818],1.0.5873
Trojan.Roraccoon, HKLM\SOFTWARE\SSO, Quarantined, [5476], [511495],1.0.5873
PUP.Optional.SpecialSearchOffer, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Roraccoon, Quarantined, [1657], [511633],1.0.5873
Adware.GorillaPrice, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\mkeeper, Quarantined, [9999], [504078],1.0.5873
Registry Value: 1
Trojan.Roraccoon, HKLM\SOFTWARE\SSO|TM, Quarantined, [5476], [511495],1.0.5873
Registry Data: 0
(No malicious items detected)
Data Stream: 0
(No malicious items detected)
Folder: 1
PUP.Optional.SpecialSearchOffer, C:\PROGRAM FILES (X86)\COMMON FILES\RORACCOON, Quarantined, [1657], [511633],1.0.5873
File: 7
PUP.Optional.SpecialSearchOffer, C:\Program Files (x86)\Common Files\Roraccoon\Roraccoon.exe, Quarantined, [1657], [511633],1.0.5873
Adware.GorillaPrice, C:\PROGRAMDATA\MICROSOFT\WINDOWS\MKEEPERSTAT\MKEEPER.EXE, Quarantined, [9999], [504078],1.0.5873
PUP.Optional.SpecialSearchOffer, C:\USERS\JACK C. CATALANO\APPDATA\ROAMING\APUSBIRD\APUSSETUP.EXE, Quarantined, [1657], [515961],1.0.5873
PUP.Optional.SpecialSearchOffer, C:\USERS\JACK C. CATALANO\APPDATA\ROAMING\APUSBIRD\_APUSSETUP.EXE, Quarantined, [1657], [515961],1.0.5873
PUP.Optional.PrimeUpdater, C:\USERS\JACK C. CATALANO\APPDATA\ROAMING\PRUPDATER\PRUPDATER.EXE, Quarantined, [854], [513570],1.0.5873
PUP.Optional.ScanGuard, C:\USERS\JACK C. CATALANO\VIDEOS\SCANGUARD_SETUP (1).EXE, Delete-on-Reboot, [4590], [503748],1.0.5873
PUP.Optional.ScanGuard, C:\USERS\JACK C. CATALANO\VIDEOS\SCANGUARD_SETUP.EXE, Delete-on-Reboot, [4590], [503748],1.0.5873
Physical Sector: 0
(No malicious items detected)
WMI: 0
(No malicious items detected)
(end)
When I downloaded Security Check, I got this:
Results of screen317's Security Check version 1.014 --- 12/23/15
x64 (UAC is enabled)
Internet Explorer 11
``````````````Antivirus/Firewall Check:``````````````[/u]
Windows Firewall Enabled!
Windows Defender
WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:`````````[/u]
Google Chrome (67.0.3396.99)
Google Chrome (SetupMetrics...)
````````Process Check: objlist.exe by Laurent````````[/u]
Windows Defender MSMpEng.exe
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbam.exe
Malwarebytes Anti-Malware mbamtray.exe
Windows Defender MSASCuiL.exe
`````````````````System Health check`````````````````[/u]
Total Fragmentation on Drive C: %
````````````````````End of Log``````````````````````[/u]