# AdwCleaner 7.0.1.0 - Logfile created on Wed Aug 02 15:55:00 2017 # Updated on 2017/05/08 by Malwarebytes # Running on Windows 10 Pro (X64) # Mode: clean # Support: https://www.malwarebytes.com/support ***** [ Services ] ***** No malicious services deleted. ***** [ Folders ] ***** Deleted: C:\Windows\System32\\SSL Deleted: C:\Windows\SysWOW64\\SSL ***** [ Files ] ***** Deleted: C:\Users\Utilisateur\appdata\local\installationconfiguration.xml ***** [ DLL ] ***** No malicious DLLs cleaned. ***** [ WMI ] ***** No malicious WMI cleaned. ***** [ Shortcuts ] ***** No malicious shortcuts cleaned. ***** [ Tasks ] ***** No malicious tasks deleted. ***** [ Registry ] ***** Deleted: [Key] - HKU\S-1-5-21-515103281-1040508896-2374480369-1001\Software\TuCao Deleted: [Key] - HKCU\Software\TuCao Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Searchy Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DD0688A5-FC8B-4E93-A485-CBF606A56D49} Deleted: [Key] - HKLM\SOFTWARE\Microsoft\DMunversion Deleted: [Value] - HKU\S-1-5-21-515103281-1040508896-2374480369-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run|safe_urls768 Deleted: [Key] - HKLM\SOFTWARE\Microsoft\MediaPlayer\ShimInclusionList\UCBrowser.exe Deleted: [Key] - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\UCBrowser.exe Deleted: [Value] - HKCU\SOFTWARE\Classes\.crx\OpenWithProgids|UCHTML.AssocFile.CRX Deleted: [Value] - HKCU\SOFTWARE\Classes\.htm\OpenWithProgids|UCHTML.AssocFile.HTM Deleted: [Value] - HKCU\SOFTWARE\Classes\.html\OpenWithProgids|UCHTML.AssocFile.HTML Deleted: [Value] - HKCU\SOFTWARE\Classes\.mht\OpenWithProgids|UCHTML.AssocFile.MHT Deleted: [Value] - HKCU\SOFTWARE\Classes\.shtm\OpenWithProgids|UCHTML.AssocFile.SHTM Deleted: [Value] - HKCU\SOFTWARE\Classes\.shtml\OpenWithProgids|UCHTML.AssocFile.SHTML Deleted: [Value] - HKCU\SOFTWARE\Classes\.webp\OpenWithProgids|UCHTML.AssocFile.WEBP Deleted: [Value] - HKCU\SOFTWARE\Classes\.xht\OpenWithProgids|UCHTML.AssocFile.XHT Deleted: [Value] - HKCU\SOFTWARE\Classes\.xhtml\OpenWithProgids|UCHTML.AssocFile.XHTML Deleted: [Value] - HKLM\SOFTWARE\Classes\.crx\OpenWithProgids|UCHTML.AssocFile.CRX Deleted: [Value] - HKLM\SOFTWARE\Classes\.htm\OpenWithProgids|UCHTML.AssocFile.HTM Deleted: [Value] - HKLM\SOFTWARE\Classes\.html\OpenWithProgids|UCHTML.AssocFile.HTML Deleted: [Value] - HKLM\SOFTWARE\Classes\.mht\OpenWithProgids|UCHTML.AssocFile.MHT Deleted: [Value] - HKLM\SOFTWARE\Classes\.shtm\OpenWithProgids|UCHTML.AssocFile.SHTM Deleted: [Value] - HKLM\SOFTWARE\Classes\.shtml\OpenWithProgids|UCHTML.AssocFile.SHTML Deleted: [Value] - HKLM\SOFTWARE\Classes\.webp\OpenWithProgids|UCHTML.AssocFile.WEBP Deleted: [Value] - HKLM\SOFTWARE\Classes\.xht\OpenWithProgids|UCHTML.AssocFile.XHT Deleted: [Value] - HKLM\SOFTWARE\Classes\.xhtml\OpenWithProgids|UCHTML.AssocFile.XHTML Deleted: [Key] - HKU\S-1-5-21-515103281-1040508896-2374480369-1001\Software\Installer Deleted: [Key] - HKCU\Software\Installer Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION|ByteFence.exe Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\pchandller Deleted: [Key] - HKLM\SOFTWARE\Classes\UCHTML Deleted: [Key] - HKLM\SOFTWARE\Classes\UCHTML.AssocFile.CRX Deleted: [Key] - HKLM\SOFTWARE\Classes\UCHTML.AssocFile.HTM Deleted: [Key] - HKLM\SOFTWARE\Classes\UCHTML.AssocFile.HTML Deleted: [Key] - HKLM\SOFTWARE\Classes\UCHTML.AssocFile.MHT Deleted: [Key] - HKLM\SOFTWARE\Classes\UCHTML.AssocFile.SHTM Deleted: [Key] - HKLM\SOFTWARE\Classes\UCHTML.AssocFile.SHTML Deleted: [Key] - HKLM\SOFTWARE\Classes\UCHTML.AssocFile.WEBP Deleted: [Key] - HKLM\SOFTWARE\Classes\UCHTML.AssocFile.XHT Deleted: [Key] - HKLM\SOFTWARE\Classes\UCHTML.AssocFile.XHTML ***** [ Firefox (and derivatives) ] ***** No malicious Firefox entries deleted. ***** [ Chromium (and derivatives) ] ***** No malicious Chromium entries deleted. ************************* ::Tracing keys deleted ::Winsock settings cleared ::Additional Actions: 0 ************************* C:/AdwCleaner/AdwCleaner[C0].txt - [8839 B] - [2017/5/30 15:22:20] C:/AdwCleaner/AdwCleaner[S0].txt - [8075 B] - [2017/5/30 13:45:40] C:/AdwCleaner/AdwCleaner[S1].txt - [5561 B] - [2017/8/2 14:30:18] C:/AdwCleaner/AdwCleaner[S2].txt - [4948 B] - [2017/8/2 15:54:15] ########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt ##########