# AdwCleaner v5.200 - Logfile created 26/06/2016 at 10:31:38 # Updated 14/06/2016 by ToolsLib # Database : 2016-06-25.3 [Server] # Operating system : Windows 10 Home (X64) # Username : HP - HP-PC # Running from : C:\Users\HP\Downloads\adwcleaner_5.200.exe # Option : Clean # Support : https://toolslib.net/forum ***** [ Services ] ***** [-] Service Deleted : winzipersvc [-] Service Deleted : SSFK [-] Service Deleted : IhPul [-] Service Deleted : WdMan [-] Service Deleted : TDataSvr [-] Service Deleted : MPCKpt [-] Service Deleted : qkseeService [-] Service Deleted : shefaleCloudservice [-] Service Deleted : LegpatP [-] Service Deleted : 8d32a4838c3768b3a530e7cba1338ca6 [-] Service Deleted : buwutofozbt [-] Service Deleted : cemyqepozbt [-] Service Deleted : cofebypyzbt [-] Service Deleted : derobucozbt [-] Service Deleted : duxokunuzbt [-] Service Deleted : fytohihyzbt [-] Service Deleted : gehulelezbt [-] Service Deleted : gojygidizbt [-] Service Deleted : gotymokizbt [-] Service Deleted : jevisuvyzbt [-] Service Deleted : jexiwuhyzbt [-] Service Deleted : jozivepyzbt [-] Service Deleted : kuvuhyruzbt [-] Service Deleted : lyrigonezbt [-] Service Deleted : midulybizbt [-] Service Deleted : nofyfukyzbt [-] Service Deleted : nyfepybezbt [-] Service Deleted : ruwydotozbt [-] Service Deleted : sutyhusuzbt [-] Service Deleted : sylomocezbt [-] Service Deleted : tocoforizbt [-] Service Deleted : totetulozbt [-] Service Deleted : velujokezbt [-] Service Deleted : vibypidyzbt [-] Service Deleted : vuvirocezbt [-] Service Deleted : xulugycizbt [-] Service Deleted : xurovuqezbt [-] Service Deleted : zifitoqozbt ***** [ Folders ] ***** [-] Folder Deleted : C:\ProgramData\Uncheckit [-] Folder Deleted : C:\ProgramData\Legpat [-] Folder Deleted : C:\ProgramData\kwinpk [-] Folder Deleted : C:\ProgramData\nwinpn [-] Folder Deleted : C:\ProgramData\TwinpT [#] Folder Deleted : C:\ProgramData\Application Data\Uncheckit [#] Folder Deleted : C:\ProgramData\Application Data\Legpat [#] Folder Deleted : C:\ProgramData\Application Data\kwinpk [#] Folder Deleted : C:\ProgramData\Application Data\nwinpn [#] Folder Deleted : C:\ProgramData\Application Data\TwinpT [-] Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\qksee [-] Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Social2Sear [-] Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Uncheckit [-] Folder Deleted : C:\Program Files (x86)\MPC Cleaner [-] Folder Deleted : C:\Program Files (x86)\SFK [-] Folder Deleted : C:\Program Files (x86)\WinZipper [-] Folder Deleted : C:\Program Files (x86)\TData [-] Folder Deleted : C:\Program Files (x86)\qksee [-] Folder Deleted : C:\Program Files (x86)\QQBrowser [-] Folder Deleted : C:\Program Files (x86)\Shefale [-] Folder Deleted : C:\Program Files (x86)\Uncheckit [-] Folder Deleted : C:\Program Files (x86)\Legpat [-] Folder Deleted : C:\Program Files (x86)\TXQQBrowser [-] Folder Deleted : C:\Program Files (x86)\2C9ECA04-1463828141-3656-1C8C-BA2555B59814 [-] Folder Deleted : C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Roaming\Uncheckit [#] Folder Deleted : C:\Users\HP\AppData\Local\3810282D-6C19-47B0-8283-5C6C29A7E108 [-] Folder Deleted : C:\Users\HP\AppData\Local\Legpat [-] Folder Deleted : C:\Users\HP\AppData\Roaming\eCyber [-] Folder Deleted : C:\Users\HP\AppData\Roaming\TSv [-] Folder Deleted : C:\Users\HP\AppData\Roaming\FreeVPN [-] Folder Deleted : C:\Users\HP\AppData\Roaming\qksee [-] Folder Deleted : C:\Users\HP\AppData\Roaming\ASPackage [-] Folder Deleted : C:\Users\HP\AppData\Roaming\WinZiper [-] Folder Deleted : C:\Users\HP\AppData\Roaming\MCorp [-] Folder Deleted : C:\Users\HP\AppData\Roaming\Uncheckit [-] Folder Deleted : C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASPackage [-] Folder Deleted : C:\Users\HP\AppData\Local\VirtualStore\Program Files (x86)\Uncheckit [-] Folder Deleted : C:\extensions [-] Folder Deleted : C:\Users\Public\Documents\dmp [-] Folder Deleted : C:\Users\HP\AppData\Local\app [-] Folder Deleted : C:\Users\HP\AppData\Local\com [#] Folder Deleted : C:\Users\HP\AppData\Roaming\MCorp ***** [ Files ] ***** ***** [ DLLs ] ***** ***** [ WMI ] ***** ***** [ Shortcuts ] ***** ***** [ Scheduled tasks ] ***** [-] Task Deleted : Browser Updater Task(Core) [-] Task Deleted : Microsoft\Windows\Apps\UpService [-] Task Deleted : UncheckitTaskMN [-] Task Deleted : UncheckitUpdateTaskC [-] Task Deleted : UncheckitUpdateTaskDB ***** [ Registry ] ***** [-] Key Deleted : HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\WinZipper [-] Key Deleted : HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\WinZipper [-] Key Deleted : HKLM\SOFTWARE\Classes\lnkfile\shellex\ContextMenuHandlers\WinZipper [-] Key Deleted : HKCU\SOFTWARE\Mozilla\Firefox\{EB52F1AB-3C2B-424F-9794-833C687025CF} [-] Key Deleted : HKLM\SOFTWARE\Mozilla\Firefox\{EB52F1AB-3C2B-424F-9794-833C687025CF} [-] Key Deleted : HKLM\SYSTEM\CurrentControlSet\Control\Class\{0014298C-A9BA-440D-AAA8-AD12C7010EE5} [-] Key Deleted : HKLM\SYSTEM\CurrentControlSet\Control\Class\{181A06EA-B82C-47DE-B851-E20FD0E1CC7D} [-] Key Deleted : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\zdwfp [-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\3045035B-3C14-4698-8AC4-ADB18CC42C1E [-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.001 [-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.7z [-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.arj [-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.bz2 [-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.bzip2 [-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.cab [-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.cpio [-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.deb [-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.dmg [-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.fat [-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.gz [-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.gzip [-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.hfs [-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.iso [-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.lha [-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.lzh [-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.lzma [-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.ntfs [-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.rar [-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.rpm [-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.squashfs [-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.swm [-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.tar [-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.taz [-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.tbz [-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.tbz2 [-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.tgz [-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.tpz [-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.txz [-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.vhd [-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.wim [-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.xar [-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.xz [-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.z [-] Key Deleted : HKLM\SOFTWARE\Classes\WinZippers.zip [-] Key Deleted : HKLM\SOFTWARE\Classes\SOFTWARE\Classes\CLSID\{03AE1B7B-A9E7-4D5A-9D34-89999C31B659} [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{357D32FC-F0AE-4B37-B36F-D44AA31496F5} [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{80B3B43F-7508-4627-BE66-00FB9AE5EE72} [-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{5A83D7C9-4A14-4000-BC05-389268238753} [-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6E727987-C8EA-44DA-8749-310C0FBE3C3E} [-] Key Deleted : HKCU\Software\IM [-] Key Deleted : HKCU\Software\WajIEnhance [-] Key Deleted : HKCU\Software\Uncheckit [-] Key Deleted : HKLM\SOFTWARE\hdcode [-] Key Deleted : HKLM\SOFTWARE\hohosearchSoftware [-] Key Deleted : HKLM\SOFTWARE\qkseeSvc [-] Key Deleted : HKLM\SOFTWARE\qksee [-] Key Deleted : HKLM\SOFTWARE\{A16B1AF7-982D-40C3-B5C1-633E1A6A6678} [-] Key Deleted : HKLM\SOFTWARE\Social2Sear [-] Key Deleted : HKLM\SOFTWARE\{E6276374-DE18-4AA5-A365-9016A2F98A2D} [-] Key Deleted : HKLM\SOFTWARE\Uncheckit [-] Key Deleted : HKLM\SOFTWARE\MaxPower [-] Key Deleted : HKLM\SOFTWARE\{8C4CE252-7DB2-4F8E-8E76-BAD0E5826A83} [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ASPackage [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VOPackage [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\YSPackage [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\qksee [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Uncheckit [-] Key Deleted : [x64] HKLM\SOFTWARE\{A16B1AF7-982D-40C3-B5C1-633E1A6A6678} [-] Key Deleted : [x64] HKLM\SOFTWARE\Social2Sear [-] Key Deleted : [x64] HKLM\SOFTWARE\{8C4CE252-7DB2-4F8E-8E76-BAD0E5826A83} [-] Key Deleted : HKU\.DEFAULT\Software\{A16B1AF7-982D-40C3-B5C1-633E1A6A6678} [-] Key Deleted : HKU\.DEFAULT\Software\{8C4CE252-7DB2-4F8E-8E76-BAD0E5826A83} [-] Data Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Search Page] [-] Data Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Search_URL] [-] Data Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] [-] Data Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL] [-] Data Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL] [-] Data Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] [-] Data Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] [-] Data Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL] [-] Data Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL] [-] Data Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] [-] Data Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] [-] Data Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL] [-] Data Restored : HKU\S-1-5-21-3290641272-513186550-857201850-1000\Software\Microsoft\Internet Explorer\Main [Search Page] [-] Data Restored : HKU\S-1-5-21-3290641272-513186550-857201850-1000\Software\Microsoft\Internet Explorer\Main [Default_Search_URL] [-] Data Restored : HKU\S-1-5-21-3290641272-513186550-857201850-1000\Software\Microsoft\Internet Explorer\Main [Start Page] [-] Data Restored : HKU\S-1-5-21-3290641272-513186550-857201850-1000\Software\Microsoft\Internet Explorer\Main [Default_Page_URL] [-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} [-] Data Restored : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope] [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} [-] Data Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes [DefaultScope] [-] Data Restored : HKU\S-1-5-21-3290641272-513186550-857201850-1000\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope] [-] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [sun3] [-] Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\winzipersvc [-] Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\qkseeService ***** [ Web browsers ] ***** ************************* :: "Tracing" keys deleted :: Winsock settings cleared ************************* C:\AdwCleaner\AdwCleaner[C1].txt - [17335 bytes] - [12/02/2016 21:30:50] C:\AdwCleaner\AdwCleaner[C2].txt - [11891 bytes] - [26/06/2016 10:31:38] C:\AdwCleaner\AdwCleaner[R0].txt - [27647 bytes] - [30/10/2014 08:46:11] C:\AdwCleaner\AdwCleaner[R1].txt - [27219 bytes] - [15/11/2014 13:50:23] C:\AdwCleaner\AdwCleaner[R2].txt - [22060 bytes] - [22/04/2015 08:13:41] C:\AdwCleaner\AdwCleaner[S0].txt - [25808 bytes] - [30/10/2014 08:56:05] C:\AdwCleaner\AdwCleaner[S1].txt - [39726 bytes] - [15/11/2014 13:54:52] C:\AdwCleaner\AdwCleaner[S2].txt - [23586 bytes] - [22/04/2015 08:15:18] ########## EOF - C:\AdwCleaner\AdwCleaner[C2].txt - [12409 bytes] ##########