# ------------------------------- # Malwarebytes AdwCleaner 7.1.1.0 # ------------------------------- # Build: 04-27-2018 # Database: 2018-05-02.2 # Support: https://www.malwarebytes.com/support # # ------------------------------- # Mode: Clean # ------------------------------- # Start: 05-04-2018 # Duration: 00:00:28 # OS: Windows 10 Home # Cleaned: 121 # Failed: 0 ***** [ Services ] ***** Deleted AppApcVerifier Deleted IMFservice Deleted AdvancedSystemCareService9 Deleted rtop ***** [ Folders ] ***** Deleted C:\Users\user\AppData\Local\28050 Deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverWhiz Deleted C:\Program Files (x86)\DriverWhiz Deleted C:\ProgramData\AppApcVerifier Deleted C:\ProgramData\IObit\Advanced SystemCare Deleted C:\Program Files (x86)\IObit\Advanced SystemCare Deleted C:\Program Files (x86)\Common Files\IObit\Advanced SystemCare Deleted C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\IObit\Advanced SystemCare Deleted C:\Users\user\AppData\LocalLow\IObit\Advanced SystemCare Deleted C:\Users\Alex\AppData\Roaming\IObit\Advanced SystemCare Deleted C:\Users\user\AppData\Roaming\IObit\Advanced SystemCare Deleted C:\Users\user\AppData\Local\Amazon Browser Settings Deleted C:\ProgramData\ByteFence Deleted C:\Program Files\ByteFence Deleted C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\ByteFence Deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare Deleted C:\ProgramData\IObit\ASCDownloader Deleted C:\ProgramData\Pokki Deleted C:\Users\Public\Pokki Deleted C:\Users\Alex\AppData\Local\Pokki Deleted C:\ProgramData\App-verifier Deleted C:\Users\user\AppData\Local\SweetLabs App Platform Deleted C:\Program Files (x86)\Uniblue Deleted C:\Users\user\AppData\Roaming\Uniblue ***** [ Files ] ***** Deleted C:\Windows\System32\REGISTRYDEFRAGBOOTTIME.EXE Deleted C:\Users\Alex\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\AmazonAssistant.lnk Deleted C:\Users\user\Downloads\DriverToolkitInstaller.exe Deleted C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sdj1qlke.default\searchplugins\Web Search.xml Deleted C:\appverifier.txt Deleted C:\END Deleted C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk ***** [ DLL ] ***** No malicious DLLs cleaned. ***** [ WMI ] ***** No malicious WMI cleaned. ***** [ Shortcuts ] ***** No malicious shortcuts cleaned. ***** [ Tasks ] ***** Deleted C:\Windows\System32\Tasks\ASC9_PerformanceMonitor Deleted C:\Windows\Tasks\Driver Booster Scheduler.job Deleted C:\Windows\System32\Tasks\Driver Booster Scheduler ***** [ Registry ] ***** Deleted HKCU\Software\SweetLabs App Platform Deleted HKCU\Software\DriverWhiz Deleted HKLM\Software\DriverWhiz Deleted HKLM\Software\Wow6432Node\MICROSOFT\WINDOWS\CURRENTVERSION\APP PATHS\DriverWhiz.exe Deleted HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\APP PATHS\DriverWhiz.exe Deleted HKLM\Software\AppApcVerifier Deleted HKLM\System\CurrentControlSet\Services\EventLog\Application\AppApcVerifier Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run|Advanced SystemCare 9 Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Run|Advanced SystemCare 9 Deleted HKLM\Software\Wow6432Node\IObit\RealTimeProtector Deleted HKLM\Software\Wow6432Node\IObit\Advanced SystemCare Deleted HKLM\Software\Wow6432Node\IOBIT\ASC Deleted HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\Advanced SystemCare Deleted HKLM\Software\Wow6432Node\Google\Chrome\NativeMessagingHosts\com.ascplugin.protect Deleted HKLM\SOFTWARE\CLASSES\LNKFILE\SHELLEX\CONTEXTMENUHANDLERS\Advanced SystemCare Deleted HKLM\SOFTWARE\CLASSES\DRIVE\SHELLEX\CONTEXTMENUHANDLERS\Advanced SystemCare Deleted HKLM\SOFTWARE\CLASSES\DIRECTORY\SHELLEX\CONTEXTMENUHANDLERS\Advanced SystemCare Deleted HKLM\Software\Wow6432Node\Classes\TypeLib\{60AD0991-ECD4-49DC-B170-8B7E7C60F51B} Deleted HKLM\Software\Classes\TypeLib\{60AD0991-ECD4-49DC-B170-8B7E7C60F51B} Deleted HKLM\Software\Classes\CLSID\{2803063F-4B8D-4dc6-8874-D1802487FE2D} Deleted HKLM\Software\Wow6432Node\Classes\Interface\{BA935377-E17C-4475-B1BF-DE3110613A99} Deleted HKLM\Software\Classes\Interface\{BA935377-E17C-4475-B1BF-DE3110613A99} Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DB09B5EC-41CB-4F06-AD92-D54B45B483B1} Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ASC9_PerformanceMonitor Deleted HKCU\Software\Classes\Software\APPDATALOW\SOFTWARE\AMAZON\Amazon1ButtonApp Deleted HKU\S-1-5-18\Software\APPDATALOW\SOFTWARE\AMAZON\Amazon1ButtonApp Deleted HKCU\Software\APPDATALOW\SOFTWARE\AMAZON\Amazon1ButtonApp Deleted HKU\.DEFAULT\Software\APPDATALOW\SOFTWARE\AMAZON\Amazon1ButtonApp Deleted HKLM\Software\Wow6432Node\APPDATALOW\SOFTWARE\AMAZON\Amazon1ButtonApp Deleted HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION|Amazon1ButtonTaskbarApp.exe Deleted HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION|Amazon1ButtonTaskbarApp.exe Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0ddcea2a-7b00-4349-8acb-af7ba6da251f} Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0ddcea2a-7b00-4349-8acb-af7ba6da251f} Deleted HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0ddcea2a-7b00-4349-8acb-af7ba6da251f} Deleted HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0ddcea2a-7b00-4349-8acb-af7ba6da251f} Deleted HKLM\Software\Wow6432Node\Classes\CLSID\{0ddcea2a-7b00-4349-8acb-af7ba6da251f} Deleted HKLM\Software\Classes\CLSID\{0ddcea2a-7b00-4349-8acb-af7ba6da251f} Deleted HKLM\System\CurrentControlSet\Services\EventLog\Application\Amazon Assistant Service Deleted HKU\S-1-5-18\Software\ByteFence Deleted HKU\.DEFAULT\Software\ByteFence Deleted HKLM\Software\Wow6432Node\ByteFence Deleted HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Reason\ReasonByteFence Deleted HKCU\Software\Microsoft\Internet Explorer\DOMStorage\fr.bytefence.com Deleted HKCU\Software\Microsoft\Internet Explorer\DOMStorage\bytefence.com Deleted HKCU\Software\csastats Deleted HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Advanced SystemCare_is1 Deleted HKLM\Software\pcv-var Deleted HKLM\Software\Wow6432Node\Uniblue Deleted HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Driver Whiz Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\SweetLabs_Start_Menu Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\SweetLabs_AP Deleted HKCU\Software\distromatic Deleted HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3DCCCD6BD02558446B24CF1C63EC213C Deleted HKCU\Software\Classes\lnkfile\shell\pokki Deleted HKCU\Software\Classes\Drive\shell\pokki Deleted HKCU\Software\Classes\Directory\shell\pokki Deleted HKCU\Software\Classes\AllFileSystemObjects\shell\pokki Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BD6ECB00-7C4A-4F97-B425-44117F2A7AAE} Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} Deleted HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} Deleted HKLM\Software\Wow6432Node\Classes\CLSID\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} Deleted HKCU\Software\Classes\pokki Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{45F2767B-85E5-467C-A7C5-45E00BD44B50} Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster Scheduler Deleted HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Internet Explorer\DOMStorage\ttdetect.staticimgfarm.com Deleted HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Internet Explorer\DOMStorage\staticimgfarm.com Deleted HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\analytics.app.amazonbrowserapp.com Deleted HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\amazonbrowserapp.com Deleted HKCU\Software\Microsoft\Internet Explorer\DOMStorage\titan.service.amazonbrowserapp.co.uk Deleted HKCU\Software\Microsoft\Internet Explorer\DOMStorage\amazonbrowserapp.co.uk Deleted HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Internet Explorer\DOMStorage\pconverter.dl.tb.ask.com Deleted HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Internet Explorer\DOMStorage\ask.com Deleted HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\televisionfanatic.dl.tb.ask.com Deleted HKLM\Software\Microsoft\Internet Explorer\Main|Start Page Deleted HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Internet Explorer\DOMStorage\homepage-web.com Deleted HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\homepage-web.com Deleted HKCU\Software\Norassie Deleted HKCU\Software\PRODUCTSETUP ***** [ Chromium (and derivatives) ] ***** Deleted Search Manager ***** [ Chromium URLs ] ***** Deleted Surf Live ***** [ Firefox (and derivatives) ] ***** Deleted IObit Surfing Protection & Ads Removal ***** [ Firefox URLs ] ***** Deleted https://homepage-web.com/?s=lenovo&m=start ************************* [+] Delete Tracing Keys [+] Reset Winsock ************************* ########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########