# AdwCleaner 7.0.1.0 - Logfile created on Sun Aug 27 14:23:03 2017 # Updated on 2017/05/08 by Malwarebytes # Running on Windows 7 Home Premium (X64) # Mode: clean # Support: https://www.malwarebytes.com/support ***** [ Services ] ***** Deleted: BIT ***** [ Folders ] ***** Deleted: C:\Program Files\\MK Deleted: C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\amuleC Deleted: C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\amuleC Deleted: C:\Program Files (x86)\Bangtony Deleted: C:\Users\ANGE\AppData\Local\Bangtony ***** [ Files ] ***** Deleted: C:\Users\ANGE\AppData\Roaming\Main.dat Deleted: C:\Users\ANGE\AppData\Roaming\\Installer.dat Deleted: C:\Users\Public\Documents\\report.dat Deleted: C:\Users\Public\Documents\\temp.dat Deleted: C:\Users\ANGE\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\BigFarm.lnk Deleted: C:\Users\ANGE\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\big_bang_empire.lnk ***** [ DLL ] ***** No malicious DLLs cleaned. ***** [ WMI ] ***** No malicious WMI cleaned. ***** [ Shortcuts ] ***** No malicious shortcuts cleaned. ***** [ Tasks ] ***** No malicious tasks deleted. ***** [ Registry ] ***** Deleted: [Key] - HKU\S-1-5-21-1239623885-3463719494-2586923840-1000\Software\deskapp Deleted: [Key] - HKCU\Software\deskapp Deleted: [Key] - HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application Deleted: [Key] - HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost|apple_upgrader Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{7804246A-CFF4-4BFE-87A8-ED65AD4670B1} Deleted: [Key] - HKLM\SOFTWARE\Microsoft\DMunversion Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost|ArcherGroupEx Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost|WinSAPSvc Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost|GubedZLGroupEx Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost|GubZLGroEx Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost|SNARER Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost|Kitty Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost|BIT Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost|3DM Deleted: [Key] - HKLM\SOFTWARE\Microsoft\{6711eba6-cf08-4edw-9528-86004fa424bb} Deleted: [Key] - HKLM\SOFTWARE\Gunlamp Deleted: [Key] - HKU\S-1-5-21-1239623885-3463719494-2586923840-1000\Software\Gunlamp Deleted: [Key] - HKCU\Software\Gunlamp Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost|WINSNARE ***** [ Firefox (and derivatives) ] ***** No malicious Firefox entries deleted. ***** [ Chromium (and derivatives) ] ***** No malicious Chromium entries deleted. ************************* ::Tracing keys deleted ::Winsock settings cleared ::Additional Actions: 0 ************************* C:/AdwCleaner/AdwCleaner[C0].txt - [18350 B] - [2016/11/26 16:57:22] C:/AdwCleaner/AdwCleaner[S0].txt - [20276 B] - [2016/11/26 16:51:18] C:/AdwCleaner/AdwCleaner[S1].txt - [20162 B] - [2016/11/26 16:52:58] C:/AdwCleaner/AdwCleaner[S2].txt - [20237 B] - [2016/11/26 16:56:45] C:/AdwCleaner/AdwCleaner[S3].txt - [3845 B] - [2017/8/27 14:21:35] ########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt ##########