# AdwCleaner 7.0.0.0 - Logfile created on Mon Jul 31 14:47:12 2017 # Updated on 2017/17/07 by Malwarebytes # Running on Windows 10 Home (X64) # Mode: clean # Support: https://www.malwarebytes.com/support ***** [ Services ] ***** No malicious services deleted. ***** [ Folders ] ***** Deleted: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YAC Deleted: C:\Users\ASUS\AppData\Roaming\iSafe Deleted: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\mipony Deleted: C:\Users\ASUS\Documents\mipony Deleted: C:\Users\DefaultAppPool\AppData\Local\AskToolbar Deleted: C:/Users\ASUS\AppData\Roaming\\app Deleted: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics Deleted: C:\ProgramData\Auslogics Deleted: C:\ProgramData\Application Data\Auslogics Deleted: C:\Program Files (x86)\Auslogics Deleted: C:\Windows\SysNative\Tasks\Auslogics Deleted: C:\Users\All Users\Auslogics Deleted: C:\Users\ASUS\AppData\Roaming\Auslogics ***** [ Files ] ***** Deleted: C:/\user.js Deleted: C:\Users\ASUS\AppData\LocalLow\Microsoft\Internet Explorer\Services\Search_ask.com.xml Deleted: C:\Windows\SysNative\roboot64.exe ***** [ DLL ] ***** No malicious DLLs cleaned. ***** [ WMI ] ***** No malicious WMI cleaned. ***** [ Shortcuts ] ***** No malicious shortcuts cleaned. ***** [ Tasks ] ***** Deleted: ASP Deleted: Advanced System Protector Deleted: GoforFilesUpdate Deleted: 0915avUpdateInfo Deleted: 0915avUpdateInfo ***** [ Registry ] ***** Deleted: [Data] - HKCU\Software\Microsoft\Internet Explorer\Main|IconCache [v90rsyc] Deleted: [Key] - HKLM\SOFTWARE\iSafe Deleted: [Key] - HKLM\SOFTWARE\AVG Nation toolbar Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Plants Vs Zombies Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1 Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762} Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534} Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID|{58124A0B-DC32-4180-9BFF-E0E21AE34026} Deleted: [Key] - HKCU\Software\Classes\TypeLib\{5C9A2304-70A5-11D5-AFB0-0050DAC67890} Deleted: [Key] - HKU\S-1-5-21-3272233705-1310129333-4282898114-1001\Software\Classes\TypeLib\{5C9A2304-70A5-11D5-AFB0-0050DAC67890} Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID|{A09AB6EB-31B5-454C-97EC-9B294D92EE2A} Deleted: [Key] - HKLM\SOFTWARE\Classes\TypeLib\{DCABB943-792E-44C4-9029-ECBEE6265AF9} Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0CFE535C35F99574E8340BFA75BF92C2 Deleted: [Key] - HKLM\SOFTWARE\Classes\Installer\UpgradeCodes\F928123A039649549966d4C29D35B1C9 Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\F928123A039649549966d4C29D35B1C9 Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\18C9E3869A16248439FE3FF9EB02207A Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B5BAE2ED018083A4C8DA86D6E3F4B024 Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\120DFADEB50841F408F04D2A278F9509 Deleted: [Value] - HKLM\SOFTWARE\CLASSES\UNKNOWN\SHELL\OPENDLG\COMMAND|ADVANCED SYSTEM PROTECTOR.BAK Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID|{977AE9CC-AF83-45E8-9E03-E2798216E2D5} Deleted: [Key] - HKU\S-1-5-21-3272233705-1310129333-4282898114-1001\Software\AppDataLow\Software\Show-Password Deleted: [Key] - HKCU\Software\AppDataLow\Software\Show-Password Deleted: [Key] - HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID|{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} Deleted: [Key] - HKLM\SOFTWARE\GoforFiles Deleted: [Key] - HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IePluginService Deleted: [Key] - HKLM\SOFTWARE\Auslogics Deleted: [Key] - HKU\S-1-5-21-3272233705-1310129333-4282898114-1001\Software\Auslogics Deleted: [Key] - HKCU\Software\Auslogics ***** [ Firefox (and derivatives) ] ***** No malicious Firefox entries deleted. ***** [ Chromium (and derivatives) ] ***** No malicious Chromium entries deleted. ************************* ::Tracing keys deleted ::Winsock settings cleared ::Additional Actions: 0 ************************* C:/AdwCleaner/AdwCleaner[S0].txt - [15016 B] - [2014/2/7 21:42:55] C:/AdwCleaner/AdwCleaner[S1].txt - [5518 B] - [2017/7/31 14:41:56] ########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt ##########