# AdwCleaner 7.0.6.0 - Logfile created on Mon Jan 15 15:34:00 2018 # Updated on 2017/21/12 by Malwarebytes # Running on Windows 10 Home (X64) # Mode: clean # Support: https://www.malwarebytes.com/support ***** [ Services ] ***** No malicious services deleted. ***** [ Folders ] ***** Deleted: C:\Program Files (x86)\Common Files\freemake shared Deleted: C:\ProgramData\BaofengUpdate_U Deleted: C:\ProgramData\Application Data\BaofengUpdate_U Deleted: C:\Users\All Users\BaofengUpdate_U Deleted: C:\ProgramData\chuvc Deleted: C:\ProgramData\Application Data\chuvc Deleted: C:\Users\All Users\chuvc Deleted: C:\Program Files (x86)\Easthas Deleted: C:\Users\famille parmentier\AppData\Local\Easthas Deleted: C:\Program Files (x86)\Legness Deleted: C:\Users\famille parmentier\AppData\Local\Legness Deleted: C:\Users\famille parmentier\AppData\Roaming\efo ***** [ Files ] ***** Deleted: C:\Users\All Users\Documents\\report.dat Deleted: C:\Users\Public\Documents\\report.dat Deleted: C:\Users\All Users\Documents\\temp.dat Deleted: C:\Users\Public\Documents\\temp.dat Deleted: C:\Users\famille parmentier\daemonprocess.txt Deleted: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HowToRemove.html.lnk Deleted: C:\Windows\System32\drivers\DRVAGENT64.SYS ***** [ DLL ] ***** No malicious DLLs cleaned. ***** [ WMI ] ***** No malicious WMI cleaned. ***** [ Shortcuts ] ***** No malicious shortcuts cleaned. ***** [ Tasks ] ***** No malicious tasks deleted. ***** [ Registry ] ***** Deleted: [Key] - HKLM\SOFTWARE\pcv-var Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|AppTrailers Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32|AppTrailers Deleted: [Value] - HKU\S-1-5-21-472306285-140838384-185580478-1002\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run|ProxyGate Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION|ByteFence.exe Deleted: [Key] - HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Reason\ReasonByteFence Deleted: [Value] - HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Program Files\ByteFence\Uninstall.exe Deleted: [Key] - HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application Deleted: [Key] - HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application Deleted: [Key] - HKLM\SOFTWARE\CLIENTS\Corner Sunshine Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|ProductUpdater Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32|ProductUpdater Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\Program Files (x86)\Common Files\Freemake Shared\ProductUpdater\ProductUpdater.exe Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\Program Files (x86)\Common Files\Freemake Shared\ProductUpdater\FMUpdater.dll Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\Program Files (x86)\Common Files\Freemake Shared\ProductUpdater\Toggling.dll Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\Program Files (x86)\Common Files\Freemake Shared\ProductUpdater\Newtonsoft.Json.dll Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\Program Files (x86)\Common Files\Freemake Shared\ProductUpdater\GAnalytics.dll Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\Program Files (x86)\Common Files\Freemake Shared\ProductUpdater\GoCartMonad.dll ***** [ Firefox (and derivatives) ] ***** No malicious Firefox entries deleted. ***** [ Chromium (and derivatives) ] ***** No malicious Chromium entries deleted. ************************* ::Tracing keys deleted ::Winsock settings cleared ::Additional Actions: 0 ************************* C:/AdwCleaner/AdwCleaner[S0].txt - [4555 B] - [2018/1/13 18:50:38] C:/AdwCleaner/AdwCleaner[S1].txt - [4623 B] - [2018/1/15 15:28:19] C:/AdwCleaner/AdwCleaner[S2].txt - [4691 B] - [2018/1/15 15:29:44] ########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt ##########