# AdwCleaner v6.044 - Logfile created 19/03/2017 at 08:36:05 # Updated on 28/02/2017 by Malwarebytes # Database : 2017-03-18.1 [Server] # Operating System : Windows 7 Home Premium Service Pack 1 (X64) # Username : Clinic1 - CLINIC2-HTPB # Running from : C:\Users\Clinic1\Downloads\adwcleaner_6.044.exe # Mode: Clean # Support : https://www.malwarebytes.com/support ***** [ Services ] ***** [-] Service deleted: GoogleChromeUpService ***** [ Folders ] ***** [-] Folder deleted: C:\Users\Clinic1\AppData\Local\kemgadeojglibflomicgnfeopkdfflnk [-] Folder deleted: C:\Users\Clinic1\AppData\Roaming\Event Monitor [-] Folder deleted: C:\Users\Clinic1\AppData\Roaming\win-svc [-] Folder deleted: C:\Program Files (x86)\pccleanplus ***** [ Files ] ***** [-] File deleted: C:\appverifier.txt ***** [ DLL ] ***** ***** [ WMI ] ***** ***** [ Shortcuts ] ***** [-] Shortcut disinfected: C:\Users\Public\Desktop\Google Chrome.lnk [-] Shortcut disinfected: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk [-] Shortcut disinfected: C:\Users\Clinic1\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk ***** [ Scheduled Tasks ] ***** [-] Task deleted: Drderlyguqerk [-] Task deleted: RunAtStartup [-] Task deleted: RunAtStartup ***** [ Registry ] ***** [#] Key deleted on reboot: HKLM\SYSTEM\CurrentControlSet\services\googlechromeupservice [-] Key deleted: HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\GoogleChromeUpService [#] Key deleted on reboot: [x64] HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\GoogleChromeUpService [#] Key deleted on reboot: HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\googlechromeupservice [#] Key deleted on reboot: [x64] HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\googlechromeupservice [-] Key deleted: HKU\.DEFAULT\Software\ompndb [-] Key deleted: HKU\.DEFAULT\Software\jhdbca [-] Key deleted: HKU\.DEFAULT\Software\Auslogics [-] Key deleted: HKU\S-1-5-21-1780543155-2672639281-3466938897-1001\Software\Bitberry Software [-] Key deleted: HKU\S-1-5-21-1780543155-2672639281-3466938897-1001\Software\Installer [-] Key deleted: HKU\S-1-5-21-1780543155-2672639281-3466938897-1001\Software\PC [-] Key deleted: HKU\S-1-5-21-1780543155-2672639281-3466938897-1001\Software\AutoTime [-] Key deleted: HKU\S-1-5-21-1780543155-2672639281-3466938897-1001\Software\Event Monitor [-] Key deleted: HKU\S-1-5-21-1780543155-2672639281-3466938897-1001\Software\PopWnd [#] Key deleted on reboot: HKU\S-1-5-18\Software\ompndb [#] Key deleted on reboot: HKU\S-1-5-18\Software\jhdbca [#] Key deleted on reboot: HKU\S-1-5-18\Software\Auslogics [#] Key deleted on reboot: HKCU\Software\Bitberry Software [#] Key deleted on reboot: HKCU\Software\Installer [#] Key deleted on reboot: HKCU\Software\PC [#] Key deleted on reboot: HKCU\Software\AutoTime [#] Key deleted on reboot: HKCU\Software\Event Monitor [#] Key deleted on reboot: HKCU\Software\PopWnd [-] Key deleted: HKLM\SOFTWARE\Jawego [-] Key deleted: HKLM\SOFTWARE\Uniblue [-] Key deleted: HKLM\SOFTWARE\PC [-] Key deleted: HKLM\SOFTWARE\Event Monitor [-] Key deleted: HKLM\SOFTWARE\trotuxSoftware [-] Key deleted: HKLM\SOFTWARE\ompndb [-] Key deleted: HKLM\SOFTWARE\jhdbca [-] Key deleted: HKLM\SOFTWARE\msServer [-] Key deleted: HKLM\SOFTWARE\{84416237-6490-494D-9AD6-4994DD978971} [#] Key deleted on reboot: [x64] HKCU\Software\Bitberry Software [#] Key deleted on reboot: [x64] HKCU\Software\Installer [#] Key deleted on reboot: [x64] HKCU\Software\PC [#] Key deleted on reboot: [x64] HKCU\Software\AutoTime [#] Key deleted on reboot: [x64] HKCU\Software\Event Monitor [#] Key deleted on reboot: [x64] HKCU\Software\PopWnd [-] Key deleted: [x64] HKLM\SOFTWARE\ompndb [-] Key deleted: [x64] HKLM\SOFTWARE\jhdbca [-] Key deleted: [x64] HKLM\SOFTWARE\asc-pr [-] Key deleted: HKU\S-1-5-21-1780543155-2672639281-3466938897-1001\Software\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827} [#] Key deleted on reboot: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827} [-] Key deleted: HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827} [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827} [-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827} [-] Value deleted: HKU\S-1-5-21-1780543155-2672639281-3466938897-1001\Software\Microsoft\Windows\CurrentVersion\Run [msiql] [#] Value deleted on reboot: HKCU\Software\Microsoft\Windows\CurrentVersion\Run [msiql] [#] Value deleted on reboot: [x64] HKCU\Software\Microsoft\Windows\CurrentVersion\Run [msiql] [-] Value deleted: HKLM\SOFTWARE\Classes\Unknown\shell\openas\command [windowsfileopener.Dat] [-] Value deleted: HKLM\SOFTWARE\Classes\Unknown\shell\opendlg\command [windowsfileopener.Dat] ***** [ Web browsers ] ***** [-] [C:\Users\Clinic1\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: aol.com [-] [C:\Users\Clinic1\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: ask.com ************************* :: "Tracing" keys deleted :: Winsock settings cleared ************************* C:\AdwCleaner\AdwCleaner[C0].txt - [5399 Bytes] - [19/03/2017 08:36:05] C:\AdwCleaner\AdwCleaner[S0].txt - [5377 Bytes] - [19/03/2017 08:34:35] ########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [5545 Bytes] ##########