# AdwCleaner 7.0.8.0 - Logfile created on Mon Feb 26 15:31:24 2018 # Updated on 2018/08/02 by Malwarebytes # Running on Windows 10 Home Single Language (X64) # Mode: clean # Support: https://www.malwarebytes.com/support ***** [ Services ] ***** Deleted: WtuSystemSupport Deleted: vToolbarUpdater40.3.8 ***** [ Folders ] ***** Deleted: C:\Users\Juan\AppData\Roaming\IObit\Advanced SystemCare V8 Deleted: C:\Users\Juan\AppData\Local\Mobogenie Deleted: C:\ProgramData\AVG Secure Search Deleted: C:\Program Files\Common Files\AVG Secure Search Deleted: C:\Program Files (x86)\Common Files\AVG Secure Search Deleted: C:\Users\All Users\AVG Secure Search Deleted: C:\Users\Todos os Usuários\AVG Secure Search Deleted: C:\ProgramData\AVG Security Toolbar Deleted: C:\Users\All Users\AVG Security Toolbar Deleted: C:\Users\Todos os Usuários\AVG Security Toolbar Deleted: C:\Users\Juan\AppData\Roaming\acestream Deleted: C:\Users\Juan\AppData\LocalLow\.acestream Deleted: C:\Users\Juan\AppData\Roaming\.acestream Deleted: C:\_acestream_cache_ Deleted: C:\Users\Juan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ace Stream Media Deleted: C:\avg web tuneup Deleted: C:\ProgramData\avg web tuneup Deleted: C:\Program Files\avg web tuneup Deleted: C:\Program Files (x86)\avg web tuneup Deleted: C:\Users\All Users\avg web tuneup Deleted: C:\Users\Juan\AppData\Local\avg web tuneup Deleted: C:\Users\Juan\AppData\LocalLow\avg web tuneup Deleted: C:\Users\Todos os Usuários\avg web tuneup Deleted: C:\Program Files (x86)\Common Files\freemake shared Deleted: C:\ProgramData\Avg_Update_0116av Deleted: C:\ProgramData\Avg_Update_0615tb Deleted: C:\ProgramData\Avg_Update_1014av Deleted: C:\ProgramData\Avg_Update_1015av Deleted: C:\ProgramData\Avg_Update_1015tb Deleted: C:\ProgramData\Avg_Update_1215av ***** [ Files ] ***** Deleted: C:\Users\Juan\daemonprocess.txt Deleted: C:\Windows\System32\drivers\DRVAGENT64.SYS ***** [ DLL ] ***** No malicious DLLs cleaned. ***** [ WMI ] ***** No malicious WMI cleaned. ***** [ Shortcuts ] ***** No malicious shortcuts cleaned. ***** [ Tasks ] ***** Deleted: 0615tbUpdateInfo Deleted: 0615tbUpdateInfo ***** [ Registry ] ***** Deleted: [Key] - HKLM\SOFTWARE\IObit\RealTimeProtector Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\mysearch.avg.com Deleted: [Key] - HKU\S-1-5-21-3817476712-227097123-3840079092-1007\Software\AceStream Deleted: [Key] - HKU\S-1-5-21-3817476712-227097123-3840079092-1007\Software\Microsoft\Windows\CurrentVersion\Uninstall\AceStream Deleted: [Key] - HKCU\Software\AceStream Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\AceStream Deleted: [Key] - HKLM\SOFTWARE\AVG Secure Search Deleted: [Key] - HKLM\SOFTWARE\hdcode Deleted: [Key] - HKLM\SOFTWARE\AVG Tuneup Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23} Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID|{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F} Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{2974C985-8151-4DE5-B23C-B875F0A8522F} Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2974C985-8151-4DE5-B23C-B875F0A8522F} Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3} Deleted: [Key] - HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94} Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6} Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{79690976-ED6E-403C-BBBA-F8928B5EDE17} Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{CA3A5461-96B5-46DD-9341-5350D3C94615} Deleted: [Key] - HKLM\SOFTWARE\Classes\TypeLib\{4BC8AD89-AC5F-4DBD-A38F-C355C7DD33D7} Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32|mobilegeni daemon Deleted: [Key] - HKLM\SOFTWARE\MozillaPlugins\@avg.com\AVG SiteSafety plugin,version=11.0.0.1,application\x-avg-sitesafety-plugin Deleted: [Key] - HKLM\SOFTWARE\Google\Chrome\NativeMessagingHosts\avgsh Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\###MegaShellExtPending Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\###MegaShellExtSynced Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\###MegaShellExtSyncing Deleted: [Key] - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.acelive Deleted: [Key] - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.acemedia Deleted: [Key] - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.acestream Deleted: [Key] - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tslive Deleted: [Key] - HKCU\SOFTWARE\Classes\Applications\ace_player.exe Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\ACEStreamPlayCDAudioOnArrival Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\ACEStreamPlayDVDAudioOnArrival Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\ACEStreamPlayDVDMovieOnArrival Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\ACEStreamPlayMusicFilesOnArrival Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\ACEStreamPlaySVCDMovieOnArrival Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\ACEStreamPlayVCDMovieOnArrival Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\ACEStreamPlayVideoFilesOnArrival Deleted: [Key] - HKCU\Software\Classes\AudioCD\shell\PlayWithACEStream Deleted: [Key] - HKCU\Software\Classes\DVD\shell\PlayWithACEStream Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32|mobilegeni daemon Deleted: [Key] - HKCU\Software\Classes\Applications\ace_player.exe Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.acelive Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.acemedia Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.acestream Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tslive Deleted: [Key] - HKLM\SOFTWARE\MozillaPlugins\@pandonetworks.com\PandoWebPlugin Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\DOMStorage\castplatform.com Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\DOMStorage\cdn.castplatform.com Deleted: [Key] - HKU\S-1-5-21-3817476712-227097123-3840079092-1007\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\Crossrider Deleted: [Key] - HKU\S-1-5-21-3817476712-227097123-3840079092-1007\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\Crossrider Deleted: [Key] - HKLM\SOFTWARE\Auslogics Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|ProductUpdater Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32|ProductUpdater Deleted: [Value] - HKCU\Software\RegisteredApplications|AceStream Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\Program Files (x86)\Common Files\Freemake Shared\ProductUpdater\ProductUpdater.exe Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\Program Files (x86)\Common Files\Freemake Shared\ProductUpdater\FMUpdater.dll Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\Program Files (x86)\Common Files\Freemake Shared\ProductUpdater\Newtonsoft.Json.dll Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\Program Files (x86)\Common Files\Freemake Shared\ProductUpdater\GAnalytics.dll Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\Program Files (x86)\Common Files\Freemake Shared\ProductUpdater\GoCartMonad.dll Deleted: [Key] - HKLM\SOFTWARE\MimarSinan Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\0615tbUpdateInfo ***** [ Firefox (and derivatives) ] ***** No malicious Firefox entries deleted. ***** [ Chromium (and derivatives) ] ***** No malicious Chromium entries deleted. ************************* ::Winsock settings cleared ::Image File Execution Options%s keys deleted ::Proxy settings cleared ::IE policies deleted ::Chrome policies deleted ::Hosts file cleared ::Additional Actions: 0 ************************* C:/AdwCleaner/AdwCleaner[S0].txt - [10237 B] - [2018/2/26 15:9:54] ########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt ##########