# AdwCleaner 7.0.1.0 - Logfile created on Tue Aug 01 14:51:09 2017 # Updated on 2017/05/08 by Malwarebytes # Running on Windows 7 Starter (X86) # Mode: clean # Support: https://www.malwarebytes.com/support ***** [ Services ] ***** No malicious services deleted. ***** [ Folders ] ***** Deleted: C:\Users\F N L\AppData\Local\VirtualStore\Program Files\Yahoo!\Companion Deleted: C:\Users\All Users\Documents\XMUpdate Deleted: C:\Users\Public\Documents\XMUpdate Deleted: C:\ProgramData\Logic Cramble Deleted: C:\ProgramData\Application Data\Logic Cramble Deleted: C:\Users\All Users\Logic Cramble Deleted: C:\ProgramData\Voyasollams Deleted: C:\ProgramData\Application Data\Voyasollams Deleted: C:\Users\All Users\Voyasollams Deleted: C:\Program Files\ByteFence Deleted: C:\Users\F N L\AppData\Roaming\BROWSERMODULE Deleted: C:\Windows\Temp\Smartbar Deleted: C:\Program Files\Easeware Deleted: C:\Users\F N L\AppData\Roaming\Easeware Deleted: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Easy Deleted: C:\Users\F N L\AppData\Roaming\EpicNet Inc Deleted: C:\Users\F N L\AppData\Roaming\EpicNet Inc. Deleted: \Downloaded Installers\E3605470-291B-44EB-8648-745EE356599A Deleted: \Installer\E3605470-291B-44EB-8648-745EE356599A ***** [ Files ] ***** Deleted: C:\Users\F N L\AppData\Local\Main.dat Deleted: C:\Program Files\Yahoo!\Common\unyt.exe Deleted: C:\Windows\System32\config\systemprofile\appdata\local\installationconfiguration.xml Deleted: C:\Users\F N L\appdata\local\installationconfiguration.xml Deleted: C:\Users\F N L\AppData\Roaming\Mozilla\Firefox\Profiles\qwr87gwr.default\searchplugins\findit.xml Deleted: C:\Windows\System32\findit.xml ***** [ DLL ] ***** No malicious DLLs cleaned. ***** [ WMI ] ***** No malicious WMI cleaned. ***** [ Shortcuts ] ***** No malicious shortcuts cleaned. ***** [ Tasks ] ***** No malicious tasks deleted. ***** [ Registry ] ***** Deleted: [Value] - HKCU\Software\Microsoft\Internet Explorer\SearchScopes|DefaultScope Deleted: [Value] - HKU\S-1-5-21-859490447-3434522011-3663908016-1000\Software\Microsoft\Internet Explorer\SearchScopes|DefaultScope Deleted: [Value] - HKU\S-1-5-21-859490447-3434522011-3663908016-1000\Software\Microsoft\Internet Explorer\SearchScopes|DefaultScope Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes|DefaultScope Deleted: [Key] - HKLM\SOFTWARE\Yahoo\Companion Deleted: [Key] - HKU\S-1-5-21-859490447-3434522011-3663908016-1000\Software\Yahoo\Companion Deleted: [Key] - HKCU\Software\Yahoo\Companion Deleted: [Key] - HKU\S-1-5-21-859490447-3434522011-3663908016-1000\Software\Yahoo\YFriendsBar Deleted: [Key] - HKCU\Software\Yahoo\YFriendsBar Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Searchy Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{24F5E422-6A70-4FAA-8CAD-E23D5DC1DAE6} Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DD0688A5-FC8B-4E93-A485-CBF606A56D49} Deleted: [Key] - HKLM\SOFTWARE\Microsoft\DMunversion Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Deleted: [Value] - HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser|{EF99BD32-C1FB-11D2-892F-0090271D4F88} Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Deleted: [Key] - HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application Deleted: [Key] - HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application Deleted: [Key] - HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{ielnksrch} Deleted: [Key] - HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SILENTPROCESSEXIT\Voyasollam.exe Deleted: [Key] - HKLM\SOFTWARE\WISECLEANER Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\E3605470-291B-44EB-8648-745EE356599A Deleted: [Key] - HKU\S-1-5-21-859490447-3434522011-3663908016-1000\Software\MICROSOFT\wewewe Deleted: [Key] - HKCU\Software\MICROSOFT\wewewe Deleted: [Key] - HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application Deleted: [Key] - HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application Deleted: [Key] - HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\IELNKSRCH Deleted: [Key] - HKU\S-1-5-21-859490447-3434522011-3663908016-1000\Software\csastats Deleted: [Key] - HKCU\Software\csastats Deleted: [Key] - HKU\S-1-5-21-859490447-3434522011-3663908016-1000\Software\PRODUCTSETUP Deleted: [Key] - HKCU\Software\PRODUCTSETUP Deleted: [Key] - HKLM\SOFTWARE\mtVoyasollam Deleted: [Key] - HKU\S-1-5-21-859490447-3434522011-3663908016-1000\Software\mtVoyasollam Deleted: [Key] - HKCU\Software\mtVoyasollam Deleted: [Key] - HKU\S-1-5-21-859490447-3434522011-3663908016-1000\Software\EpicNet Inc. Deleted: [Key] - HKCU\Software\EpicNet Inc. Deleted: [Key] - HKCU\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\E3605470-291B-44EB-8648-745EE356599A ***** [ Firefox (and derivatives) ] ***** No malicious Firefox entries deleted. ***** [ Chromium (and derivatives) ] ***** No malicious Chromium entries deleted. ************************* ::Tracing keys deleted ::Winsock settings cleared ::Additional Actions: 0 ************************* C:/AdwCleaner/AdwCleaner[S0].txt - [6632 B] - [2017/8/1 14:50:13] ########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt ##########