You are on page 1of 3

# AdwCleaner v6.

030 - Logfile created 01/12/2016 at 21:51:11


# Updated on 19/10/2016 by Malwarebytes
# Database : 2016-12-01.1 [Server]
# Operating System : Windows 7 Ultimate Service Pack 1 (X64)
# Username : Renno Underscore - RENNOUNDERSCORE
# Running from : C:\Users\Renno Underscore\Pictures\adwcleaner_6.030.exe
# Mode: Clean
# Support : hxxps://www.malwarebytes.com/support

***** [ Services ] *****

[-] Service deleted: WinSAPSvc


[-] Service deleted: Archer
[-] Service deleted: ed2kidle

***** [ Folders ] *****

[-] Folder deleted: C:\ProgramData\ChelfNotify


[-] Folder deleted: C:\ProgramData\Thunder Network
[-] Folder deleted: C:\ProgramData\WinSAPSvc
[#] Folder deleted on reboot: C:\ProgramData\thunder network
[#] Folder deleted on reboot: C:\ProgramData\Application Data\ChelfNotify
[#] Folder deleted on reboot: C:\ProgramData\Application Data\Thunder Network
[#] Folder deleted on reboot: C:\ProgramData\Application Data\WinSAPSvc
[#] Folder deleted on reboot: C:\ProgramData\Application Data\thunder network
[-] Folder deleted: C:\Program Files (x86)\WinArcher
[-] Folder deleted: C:\Program Files (x86)\UvConverter

***** [ Files ] *****

***** [ DLL ] *****

***** [ WMI ] *****

***** [ Shortcuts ] *****

[-] Shortcut disinfected: C:\ProgramData\Microsoft\Windows\Start


Menu\Programs\Avast SafeZone Browser.lnk
[-] Shortcut disinfected: C:\ProgramData\Microsoft\Windows\Start
Menu\Programs\Google Chrome.lnk
[-] Shortcut disinfected: C:\Users\Renno Underscore\Desktop\New folder\Google
Chrome.lnk
[-] Shortcut disinfected: C:\Users\Renno
Underscore\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet
Explorer Browser.lnk
[-] Shortcut disinfected: C:\Users\Renno
Underscore\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User
Pinned\TaskBar\Google Chrome.lnk
[-] Shortcut disinfected: C:\Users\Renno
Underscore\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User
Pinned\StartMenu\Google Chrome.lnk

***** [ Scheduled Tasks ] *****

***** [ Registry ] *****

[-] Key deleted: HKU\S-1-5-21-2477263743-4060048676-798255805-


1000\Software\UCBrowser
[-] Key deleted: HKU\S-1-5-21-2477263743-4060048676-798255805-
1000\Software\UCBrowserPID
[#] Key deleted on reboot: HKCU\Software\UCBrowser
[#] Key deleted on reboot: HKCU\Software\UCBrowserPID
[-] Key deleted: HKLM\SOFTWARE\UCBrowser
[-] Key deleted: HKLM\SOFTWARE\UCBrowserPID
[-] Key deleted: HKLM\SOFTWARE\ScreenShot
[-] Key deleted: HKLM\SOFTWARE\ompndb
[-] Key deleted: HKLM\SOFTWARE\WinArcher
[#] Key deleted on reboot: [x64] HKCU\Software\UCBrowser
[#] Key deleted on reboot: [x64] HKCU\Software\UCBrowserPID
[-] Key deleted: [x64] HKLM\SOFTWARE\ompndb
[-] Key deleted:
HKLM\SOFTWARE\Classes\Installer\Features\F39E5917C417B4041A46F88010121C6E
[-] Key deleted:
HKLM\SOFTWARE\Classes\Installer\Products\F39E5917C417B4041A46F88010121C6E
[-] Key deleted: [x64]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-
18\Products\F39E5917C417B4041A46F88010121C6E
[#] Key deleted on reboot: [x64]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-
18\Products\F39E5917C417B4041A46F88010121C6E
[#] Key deleted on reboot: [x64]
HKLM\SOFTWARE\Classes\Installer\Features\F39E5917C417B4041A46F88010121C6E
[#] Key deleted on reboot: [x64]
HKLM\SOFTWARE\Classes\Installer\Products\F39E5917C417B4041A46F88010121C6E
[-] Data restored: HKU\S-1-5-21-2477263743-4060048676-798255805-
1000\Software\Microsoft\Internet Explorer\Main [Start Page]
[-] Data restored: HKU\S-1-5-21-2477263743-4060048676-798255805-
1000\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
[-] Data restored: HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
[-] Data restored: HKCU\Software\Microsoft\Internet Explorer\Main
[Default_Page_URL]
[-] Data restored: HKLM\SOFTWARE\Microsoft\Internet Explorer\Main
[Default_Page_URL]
[-] Data restored: HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
[-] Data restored: [x64] HKCU\Software\Microsoft\Internet Explorer\Main [Start
Page]
[-] Data restored: [x64] HKCU\Software\Microsoft\Internet Explorer\Main
[Default_Page_URL]
[-] Data restored: [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main
[Default_Page_URL]
[-] Data restored: [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start
Page]
[-] Key deleted: HKU\S-1-5-21-2477263743-4060048676-798255805-
1000\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-
49120163DE86}
[-] Data restored: HKU\S-1-5-21-2477263743-4060048676-798255805-
1000\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope] {0633EE93-
D776-472f-A0FF-E1416B8B2E3A}
[#] Key deleted on reboot: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\
{33BB0A4E-99AF-4226-BDF6-49120163DE86}
[-] Data restored: HKCU\Software\Microsoft\Internet Explorer\SearchScopes
[DefaultScope] {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-
99AF-4226-BDF6-49120163DE86}
[-] Data restored: HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
[DefaultScope] {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet
Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
[-] Data restored: [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes
[DefaultScope] {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\
{33BB0A4E-99AF-4226-BDF6-49120163DE86}
[-] Data restored: [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
[DefaultScope] {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[-] Data restored:
HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command [Default]
[-] Value deleted: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost
[WinSAPSvc]
[-] Value deleted: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost
[ArcherGroupEx]

***** [ Web browsers ] *****

*************************

:: "Tracing" keys deleted


:: Winsock settings cleared

*************************

C:\AdwCleaner\AdwCleaner[C0].txt - [9128 Bytes] - [01/12/2016 01:46:39]


C:\AdwCleaner\AdwCleaner[C2].txt - [6197 Bytes] - [01/12/2016 21:51:11]
C:\AdwCleaner\AdwCleaner[S0].txt - [10417 Bytes] - [01/12/2016 01:27:41]
C:\AdwCleaner\AdwCleaner[S1].txt - [7952 Bytes] - [01/12/2016 20:37:51]

########## EOF - C:\AdwCleaner\AdwCleaner[C2].txt - [6417 Bytes] ##########

You might also like