# AdwCleaner 7.0.4.0 - Logfile created on Sat Nov 25 03:25:04 2017 # Updated on 2017/27/10 by Malwarebytes # Running on Windows 7 Starter (X86) # Mode: clean # Support: https://www.malwarebytes.com/support ***** [ Services ] ***** Deleted: WCAssistantService Deleted: CCManagementService ***** [ Folders ] ***** Deleted: C:\ProgramData\IObit\Advanced SystemCare Deleted: C:\ProgramData\Application Data\IObit\Advanced SystemCare Deleted: C:\Program Files\IObit\Advanced SystemCare Deleted: C:\Program Files\Common Files\IObit\Advanced SystemCare Deleted: C:\Windows\System32\config\systemprofile\AppData\Roaming\IObit\Advanced SystemCare Deleted: C:\Windows\System32\config\systemprofile\AppData\LocalLow\IObit\Advanced SystemCare Deleted: C:\Users\All Users\IObit\Advanced SystemCare Deleted: C:\Users\widen-finalis\AppData\Roaming\IObit\Advanced SystemCare Deleted: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TweakBit Deleted: C:\ProgramData\TweakBit Deleted: C:\ProgramData\Application Data\TweakBit Deleted: C:\Program Files\TweakBit Deleted: C:\Users\All Users\TweakBit Deleted: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Optimizer Pro Deleted: C:\Program Files\RCP Deleted: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\advanced system optimizer 3 Deleted: C:\Program Files\advanced system optimizer 3 Deleted: C:\Program Files\ASP Deleted: C:\ProgramData\lavasoft\web companion Deleted: C:\ProgramData\Application Data\lavasoft\web companion Deleted: C:\Program Files\lavasoft\web companion Deleted: C:\Users\All Users\lavasoft\web companion Deleted: C:\Users\widen-finalis\AppData\Roaming\lavasoft\web companion Deleted: C:\ProgramData\Systweak\Advanced System Protector Deleted: C:\ProgramData\Application Data\Systweak\Advanced System Protector Deleted: C:\Users\All Users\Systweak\Advanced System Protector Deleted: C:\Users\widen-finalis\AppData\Local\Systweak\Advanced System Protector Deleted: C:\Users\widen-finalis\AppData\Roaming\Systweak\Advanced System Protector Deleted: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced System Optimizer 3 Deleted: C:\Program Files\Advanced System Optimizer 3 Deleted: C:\ProgramData\IObit\ASCDownloader Deleted: C:\ProgramData\Application Data\IObit\ASCDownloader Deleted: C:\Users\All Users\IObit\ASCDownloader Deleted: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare Deleted: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced System Protector Deleted: C:\ProgramData\CompuClever Deleted: C:\ProgramData\Application Data\CompuClever Deleted: C:\Program Files\CompuClever Deleted: C:\Users\All Users\CompuClever Deleted: C:\Users\widen-finalis\AppData\Local\CompuClever Deleted: C:\Users\widen-finalis\AppData\Roaming\CompuClever Deleted: C:\Users\widen-finalis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CompuClever Deleted: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft\WebCompanion Deleted: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced Driver Updater Deleted: C:\Program Files\Advanced Driver Updater Deleted: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegClean Pro Deleted: C:\ProgramData\Systweak Deleted: C:\ProgramData\Application Data\Systweak Deleted: C:\Users\All Users\Systweak Deleted: C:\Users\widen-finalis\AppData\Local\Systweak Deleted: C:\Users\widen-finalis\AppData\Roaming\Systweak Deleted: C:\Program Files\SecurityXploded Deleted: C:\Users\widen-finalis\AppData\Roaming\SecurityXploded Deleted: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics Deleted: C:\ProgramData\Auslogics Deleted: C:\ProgramData\Application Data\Auslogics Deleted: C:\Program Files\Auslogics Deleted: C:\Users\All Users\Auslogics ***** [ Files ] ***** Deleted: C:\Users\All Users\Desktop\Smart PC Care.lnk Deleted: C:\Users\Public\Desktop\Smart PC Care.lnk Deleted: C:\Users\All Users\Desktop\RegClean Pro.lnk Deleted: C:\Users\Public\Desktop\RegClean Pro.lnk Deleted: C:\Windows\System32\sasnative32.exe Deleted: C:\Users\All Users\Desktop\Advanced System Protector.lnk Deleted: C:\Users\Public\Desktop\Advanced System Protector.lnk Deleted: C:\Users\widen-finalis\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Facebook.lnk Deleted: C:\Windows\System32\roboot.exe Deleted: C:\Users\All Users\Desktop\Advanced System Optimizer.lnk Deleted: C:\Users\Public\Desktop\Advanced System Optimizer.lnk Deleted: C:\Users\widen-finalis\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Advanced System Optimizer.lnk Deleted: C:\Users\widen-finalis\Desktop\DriverUpdater.lnk Deleted: C:\Users\All Users\Desktop\Smart PC Care.lnk Deleted: C:\Users\Public\Desktop\Smart PC Care.lnk Deleted: C:\Users\All Users\Desktop\Advanced Driver Updater.lnk Deleted: C:\Users\Public\Desktop\Advanced Driver Updater.lnk ***** [ DLL ] ***** No malicious DLLs cleaned. ***** [ WMI ] ***** No malicious WMI cleaned. ***** [ Shortcuts ] ***** No malicious shortcuts cleaned. ***** [ Tasks ] ***** No malicious tasks deleted. ***** [ Registry ] ***** Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{C99650F6-688D-4BAB-86E4-BC045EF0FFBF} Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{12AB121E-44C6-488B-8773-B0AE25E662E1} Deleted: [Key] - HKLM\SOFTWARE\Classes\TypeLib\{003B9C22-6FE0-4BCA-A73F-9AA99B9BBDAA} Deleted: [Key] - HKLM\SOFTWARE\Classes\lnkfile\shellex\ContextMenuHandlers\PCProCtxMenu Deleted: [Key] - HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\PCProCtxMenu Deleted: [Key] - HKLM\SOFTWARE\Lavasoft\Web Companion Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Advanced SystemCare_is1 Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762} Deleted: [Key] - HKLM\SOFTWARE\Classes\TypeLib\{2A03A149-3CD3-429D-B4A4-28D9D2974874} Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{D23C3BA7-6DC3-4DDF-9BDF-12599E852A40} Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{B0F3F4F9-CB76-9A52-9442-B481A5FF49D3} Deleted: [Value] - HKLM\SOFTWARE\CLASSES\UNKNOWN\SHELL\OPENAS\COMMAND|ADVANCED SYSTEM PROTECTOR.BAK Deleted: [Value] - HKLM\SOFTWARE\CLASSES\UNKNOWN\SHELL\OPENDLG\COMMAND|ADVANCED SYSTEM PROTECTOR.BAK Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Advanced Driver Updater_is1 Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{00212D92-C5D8-4FF4-AE50-B20F0F85C40A} Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RegClean Pro_is1 Deleted: [Key] - HKLM\SOFTWARE\SecurityXploded Deleted: [Key] - HKLM\SOFTWARE\Auslogics Deleted: [Data] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{b6f4477f-d742-47e6-8f64-ed95bfc4d4f1}|DisplayName [] Deleted: [Data] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{b6f4477f-d742-47e6-8f64-ed95bfc4d4f1}|DisplayIcon [] Deleted: [Data] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{b6f4477f-d742-47e6-8f64-ed95bfc4d4f1}|UninstallString [] ***** [ Firefox (and derivatives) ] ***** No malicious Firefox entries deleted. ***** [ Chromium (and derivatives) ] ***** No malicious Chromium entries deleted. ************************* ::Tracing keys deleted ::Winsock settings cleared ::Image File Execution Options%s keys deleted ::Prefetch files deleted ::Proxy settings cleared ::TCP/IP settings cleared ::Firewall rules cleared ::IPSec settings cleared ::BITS queue cleared ::IE policies deleted ::Chrome policies deleted ::Hosts file cleared ::Additional Actions: 0 ************************* C:/AdwCleaner/AdwCleaner[C0].txt - [2505 B] - [2017/2/5 11:55:11] C:/AdwCleaner/AdwCleaner[S0].txt - [2083 B] - [2016/12/21 21:53:18] C:/AdwCleaner/AdwCleaner[S1].txt - [2157 B] - [2017/2/5 11:27:18] C:/AdwCleaner/AdwCleaner[S2].txt - [9303 B] - [2017/11/25 2:34:6] ########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt ##########