# ------------------------------- # Malwarebytes AdwCleaner 7.1.1.0 # ------------------------------- # Build: 04-27-2018 # Database: 2018-05-22.1 # Support: https://www.malwarebytes.com/support # # ------------------------------- # Mode: Clean # ------------------------------- # Start: 05-25-2018 # Duration: 00:00:47 # OS: Windows 10 Home # Cleaned: 255 # Failed: 3 ***** [ Services ] ***** Deleted NativeDesktopMediaService Deleted Windefender Deleted saiyitechnology ***** [ Folders ] ***** Deleted C:\Users\khera\AppData\Local\XService Deleted C:\ProgramData\Quoteexs Deleted C:\ProgramData\Logic Cramble Deleted C:\Users\khera\AppData\Local\cypjMERAky Deleted C:\Program Files\Microleaves Deleted C:\Users\khera\AppData\Roaming\Microleaves Deleted C:\Users\khera\AppData\Local\Temp\publicHotsp Deleted C:\Users\khera\AppData\Local\Temp\bestDownloader Deleted C:\Program Files\ShutdownTime Deleted C:\Users\khera\AppData\Local\Temp\ShutdownTime Deleted C:\ProgramData\{7DA67DFE-312C-1} Deleted C:\ProgramData\{706A1BBD-612C-1} Deleted C:\ProgramData\{63C14550-012C-0} Deleted C:\ProgramData\{6060265C-712C-0} Deleted C:\ProgramData\{5E630C01-512C-1} Deleted C:\ProgramData\{5DCE2B3B-412C-0} Deleted C:\ProgramData\{58571626-612C-1} Deleted C:\ProgramData\{521F5DEE-112C-1} Deleted C:\ProgramData\{4E3E018C-412C-1} Deleted C:\ProgramData\{4E374931-012C-0} Deleted C:\ProgramData\{4B6C4CD7-512C-0} Deleted C:\ProgramData\{40F7193A-412C-0} Deleted C:\ProgramData\{401A5A5D-612C-1} Deleted C:\ProgramData\{3D9A63A4-312C-0} Deleted C:\ProgramData\{325B74B4-412C-0} Deleted C:\ProgramData\{2E887CFC-712C-0} Deleted C:\ProgramData\{278279B8-012C-1} Deleted C:\ProgramData\{268C5790-212C-1} Deleted C:\ProgramData\{12772CB6-512C-0} Deleted C:\ProgramData\{00EB21B7-112C-1} Deleted C:\ProgramData\F7A2D9D1 Deleted C:\ProgramData\C4679E14-7993-0 Deleted C:\ProgramData\C4679E14-4657-1 Deleted C:\ProgramData\7EAF0D91-5135-0 Deleted C:\ProgramData\7EAF0D91-2233-1 Deleted C:\ProgramData\4B3565FC-67F1-1 Deleted C:\ProgramData\4B3565FC-67B1-0 Deleted C:\ProgramData\4B3565FC-5EA1-0 Deleted C:\ProgramData\4B3565FC-5BC7-1 Deleted C:\ProgramData\4B3565FC-4EF7-0 Deleted C:\ProgramData\4B3565FC-4951-0 Deleted C:\ProgramData\4B3565FC-45D3-1 Deleted C:\ProgramData\4B3565FC-4135-1 Deleted C:\ProgramData\4B3565FC-40C3-1 Deleted C:\ProgramData\4B3565FC-4055-1 Deleted C:\ProgramData\4B3565FC-3965-0 Deleted C:\ProgramData\4B3565FC-3453-0 Deleted C:\ProgramData\4B3565FC-1CD7-0 Deleted C:\ProgramData\4B3565FC-1983-1 Deleted C:\Program Files\yplCmHJcuoUn Deleted C:\Program Files\LfFoujfjU Deleted C:\Program Files\JwYYyjKjrIE Deleted C:\Program Files\pidIvTaYsJowC Deleted C:\Program Files\jzVqtpDsXbLU2 Deleted C:\Program Files\mAUzXDPkZrvZtXzyunR Deleted C:\ProgramData\ByteFence Deleted C:\Program Files\FastDataX Deleted C:\Users\khera\AppData\Local\FastDataX Deleted C:\Users\khera\AppData\Roaming\EpicNet Inc Deleted C:\ProgramData\Jetmedia Deleted C:\Program Files\Jetmedia Deleted C:\Users\khera\AppData\Local\?o??? ? ???e???? Deleted C:\Users\khera\AppData\Local\???c? ? ???e????? Deleted C:\Users\khera\AppData\Local\AdvinstAnalytics Deleted C:\ProgramData\yahoochrome_D Deleted C:\ProgramData\Quoteex Deleted C:\Users\khera\AppData\Roaming\wget Deleted C:\Users\khera\AppData\Local\yc Deleted C:\ProgramData\Mail.Ru Deleted C:\Program Files\Mail.Ru Deleted C:\Users\khera\AppData\Local\Mail.Ru Deleted C:\Program Files\OneSystemCare Deleted C:\Users\khera\AppData\Roaming\OneSystemCare Deleted C:\Windows\Installer\{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1} Deleted C:\ProgramData\97f29a35-8705-47de-97b4-45277a5a7676 Deleted C:\ProgramData\5ef56cd9-83de-4b9a-9c95-e64c97565d3e Deleted C:\Program Files\SystemHealer Deleted C:\Users\khera\AppData\Roaming\SystemHealer Deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Healer Deleted C:\Users\khera\AppData\Roaming\System Healer Deleted C:\Users\khera\AppData\Roaming\WidModule ***** [ Files ] ***** Deleted C:\Users\khera\Favorites\Mail.Ru ????? - ????????? ??? ???????!.url Deleted C:\Windows\System32\config\systemprofile\appdata\local\installationconfiguration.xml Deleted C:\Users\khera\appdata\local\installationconfiguration.xml Deleted C:\Users\khera\Favorites\Mail.Ru.url Deleted C:\Users\khera\AppData\Local\Main.dat Deleted C:\Windows\Installer\SOURCEHASH{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1} Deleted C:\Windows\System32\findit.xml Deleted C:\Windows\System32\drivers\WinmonProcessMonitor.sys ***** [ DLL ] ***** No malicious DLLs cleaned. ***** [ WMI ] ***** No malicious WMI cleaned. ***** [ Shortcuts ] ***** Deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk Deleted C:\Users\khera\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk Deleted C:\Users\khera\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk ***** [ Tasks ] ***** Deleted C:\Windows\System32\Tasks\ScheduledUpdate Deleted C:\Windows\Tasks\Online Application V2G5.job Deleted C:\Windows\System32\Tasks\Online Application V2G5 Deleted C:\Windows\Tasks\Online Application V2G4.job Deleted C:\Windows\System32\Tasks\Online Application V2G4 Deleted C:\Windows\Tasks\Online Application V2G6.job Deleted C:\Windows\System32\Tasks\Online Application V2G6 Deleted C:\Windows\System32\Tasks\wutphost Deleted C:\Windows\System32\Tasks_Migrated\wutphost Deleted C:\Windows\System32\Tasks\FastDataX Task Deleted C:\Windows\System32\Tasks_Migrated\FastDataX Task Deleted C:\Windows\Tasks\Online Application V2G2.job Deleted C:\Windows\System32\Tasks\Online Application V2G2 Deleted C:\Windows\Tasks\Online Application V2G3.job Deleted C:\Windows\System32\Tasks\Online Application V2G3 Deleted C:\Windows\Tasks\Online Application V2G1.job Deleted C:\Windows\System32\Tasks\Online Application V2G1 Deleted C:\Windows\System32\Tasks\SVC Update Deleted C:\Windows\System32\Tasks\wget Deleted C:\Windows\System32\Tasks_Migrated\wget Deleted C:\Windows\Tasks\Updater_Online_Application.job Deleted C:\Windows\System32\Tasks\Updater_Online_Application Deleted C:\Windows\System32\Tasks\System Healer Delayed Deleted C:\Windows\System32\Tasks\System Healer Monitor Deleted C:\Windows\Tasks\System HealerPeriod.job Deleted C:\Windows\System32\Tasks\System HealerPeriod Deleted C:\Windows\Tasks\System HealerStartUp.job Deleted C:\Windows\System32\Tasks\System HealerStartUp ***** [ Registry ] ***** Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{42D4D830-7324-4745-B307-9237F5744548} Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ScheduledUpdate Deleted HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\11598763487076930564 Deleted HKLM\Software\mtQuoteex Deleted HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SILENTPROCESSEXIT\Quoteex.exe Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce|AwRWNQQxQn Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C0D38E5A-7CF8-4105-8FE8-31B81443A114} Deleted HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C0D38E5A-7CF8-4105-8FE8-31B81443A114} Deleted HKLM\Software\Classes\CLSID\{C0D38E5A-7CF8-4105-8FE8-31B81443A114} Deleted HKLM\Software\Microleaves Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{299F3552-0D4D-4447-8334-1541352FA9B4} Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{299F3552-0D4D-4447-8334-1541352FA9B4} Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Online Application V2G5 Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6C26EF31-2156-4AD3-A250-987CE09DDC25} Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6C26EF31-2156-4AD3-A250-987CE09DDC25} Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Online Application V2G4 Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{99106E5B-9DA7-4253-9E7F-84F192DDB124} Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{99106E5B-9DA7-4253-9E7F-84F192DDB124} Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Online Application V2G6 Deleted HKLM\Software\Microsoft\Windows\CurrentVersion\Run|ShutdownTime Deleted HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{f7a2d9d1} Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C6167101-7EC0-48D6-81DC-0DE15A93135B} Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C6167101-7EC0-48D6-81DC-0DE15A93135B} Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\wutphost Deleted HKCU\Software\Microsoft\BigTime Deleted HKLM\Software\Wow6432Node\ByteFence Deleted HKLM\SOFTWARE\MICROSOFT\SYSTEMCERTIFICATES\ROOT\CERTIFICATES\26D9E607FFF0C58C7844B47FF8B6E079E5A2220E Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\CloudNet Deleted HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\FastDataX_is1 Deleted HKCU\Software\FastDataX Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{70E86D89-4CE8-49F2-8AD6-29C876A3D45D} Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{70E86D89-4CE8-49F2-8AD6-29C876A3D45D} Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\FastDataX Task Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Run|cloudnet Deleted HKCU\Software\EpicNet Inc. Deleted HKCU\Software\csastats Deleted HKLM\Software\Jetmedia Deleted HKCU\Software\Microsoft\KometaInstaller Deleted HKCU\Software\NetBox Deleted HKLM\Software\Microsoft\DMunversion Deleted HKLM\Software\WebBar Deleted HKCU\Software\Microsoft\Gosearch Deleted HKCU\Software\Microsoft\Gosearchq Deleted HKU\S-1-5-18\Environment|SNP Deleted HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{ielnksrch} Deleted HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AE298D-7E8A-4F53-BE55-15D2B065F6C0} Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8E8F97CD-60B5-456F-A201-73065652D099} Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8E8F97CD-60B5-456F-A201-73065652D099} Deleted HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E8F97CD-60B5-456F-A201-73065652D099} Deleted HKLM\Software\Classes\CLSID\{8E8F97CD-60B5-456F-A201-73065652D099} Deleted HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{5a6fa12f-6944-4f96-9b7c-d5e4bd674ba7}|NameServer - "82.163.143.176" Deleted HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{45f297fe-3819-401c-afe7-62e17e83863c}|NameServer - "82.163.143.176" Deleted HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{45f297fe-3819-401c-afe7-62e17e83863c}|DhcpNameServer - "82.163.143.176" Deleted HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0f6bbd98-9a5e-49f7-bcae-2a9e220be8e4}|NameServer - "82.163.143.176" Deleted HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0f6bbd98-9a5e-49f7-bcae-2a9e220be8e4}|DhcpNameServer - "82.163.143.176" Deleted HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{5a6fa12f-6944-4f96-9b7c-d5e4bd674ba7}|NameServer - "82.163.142.178" Deleted HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{45f297fe-3819-401c-afe7-62e17e83863c}|NameServer - "82.163.142.178" Deleted HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0f6bbd98-9a5e-49f7-bcae-2a9e220be8e4}|NameServer - "82.163.142.178" Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{05897394-CBD9-4885-8B85-A477C1416B91} Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{05897394-CBD9-4885-8B85-A477C1416B91} Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Online Application V2G2 Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D76D38B5-BB9D-4EC2-B3CA-E13BF65B3353} Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D76D38B5-BB9D-4EC2-B3CA-E13BF65B3353} Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Online Application V2G3 Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B05D4793-B864-448D-92BC-5BD11DCFDC77} Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B05D4793-B864-448D-92BC-5BD11DCFDC77} Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Online Application V2G1 Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{909E89CC-6FF2-47C5-B9E7-FECA60AE1CF8} Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{909E89CC-6FF2-47C5-B9E7-FECA60AE1CF8} Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SVC Update Deleted HKCU\Software\Microsoft\Internet Explorer\DOMStorage\rambler.ru Deleted HKCU\Software\Microsoft\Internet Explorer\DOMStorage\news.rambler.ru Deleted HKCU\Software\Microsoft\Internet Explorer\DOMStorage\mail.rambler.ru Deleted HKCU\Software\Microsoft\Internet Explorer\DOMStorage\pogoda.mail.ru Deleted HKCU\Software\Microsoft\Internet Explorer\DOMStorage\otvet.mail.ru Deleted HKCU\Software\Microsoft\Internet Explorer\DOMStorage\news.mail.ru Deleted HKCU\Software\Microsoft\Internet Explorer\DOMStorage\my.mail.ru Deleted HKCU\Software\Microsoft\Internet Explorer\DOMStorage\mail.ru Deleted HKCU\Software\Microsoft\Internet Explorer\DOMStorage\love.mail.ru Deleted HKCU\Software\Microsoft\Internet Explorer\DOMStorage\hi-tech.mail.ru Deleted HKCU\Software\Microsoft\Internet Explorer\DOMStorage\deti.mail.ru Deleted HKCU\Software\Microsoft\Internet Explorer\DOMStorage\auto.mail.ru Deleted HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\reimageplus.com Deleted HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\fr.reimageplus.com Deleted HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\reimageplus.com Deleted HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\fr.reimageplus.com Deleted HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\www.alphashoppers.co Deleted HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\alphashoppers.co Deleted HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\www.alphashoppers.co Deleted HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\alphashoppers.co Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Quoteex.exe Deleted HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\IELNKSRCH Deleted HKCU\Software\AppDataLow\Software\Mail.Ru Deleted HKCU\Software\Mail.Ru Deleted HKLM\Software\Mail.Ru Deleted HKLM\Software\Classes\IESearchPlugin.MailRuBHO Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{17B061A4-CF53-4A3A-B49E-972FF45A06B0} Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{17B061A4-CF53-4A3A-B49E-972FF45A06B0} Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\wget Deleted HKU\S-1-5-18\Software\Caphyon\Advanced Updater\{F039D4A9-14D3-4425-A4FA-F2F9D5B0E014} Deleted HKU\.DEFAULT\Software\Caphyon\Advanced Updater\{F039D4A9-14D3-4425-A4FA-F2F9D5B0E014} Deleted HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1} Deleted HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\436F6625D7B77354DBCD89DDC6CFAB1A Deleted HKLM\Software\Classes\Installer\Products\436F6625D7B77354DBCD89DDC6CFAB1A Deleted HKLM\Software\Classes\Installer\Features\436F6625D7B77354DBCD89DDC6CFAB1A Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FC307E1F-7E3B-4B13-9370-FFA9F63F6626} Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FC307E1F-7E3B-4B13-9370-FFA9F63F6626} Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Updater_Online_Application Deleted HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\E3605470-291B-44EB-8648-745EE356599A Deleted HKCU\Software\One System Care Deleted HKCU\Software\PRODUCTSETUP Deleted HKU\.DEFAULT\Environment|SNP Deleted HKCU\Software\System Healer Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F4E8A964-0AE1-4A74-858E-52518DFBA26B} Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F4E8A964-0AE1-4A74-858E-52518DFBA26B} Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\System Healer Delayed Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A51EFAC4-F450-4692-BD7B-20B98FAF401B} Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\System Healer Monitor Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F8A98EE1-6B92-4E58-A4B7-8D6300CDDEC1} Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F8A98EE1-6B92-4E58-A4B7-8D6300CDDEC1} Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\System HealerPeriod Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{85B42DA4-613B-4810-B465-DABC876BF6D8} Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\System HealerStartUp Deleted HKCU\Software\MICROSOFT\wewewe Deleted HKCU\Software\Microsoft\{cc6eb6d8-85b7-435p-8b86-51e4d16ea76d} Deleted HKLM\Software\Microsoft\PrIncub Deleted HKLM\Software\Microsoft\MPrForShutT Deleted HKLM\Software\Microsoft\PrAmNP Deleted HKLM\Software\Microsoft\NSaveA Deleted HKLM\Software\Microsoft\APreSam Deleted HKCU\Software\WidModule ***** [ Chromium (and derivatives) ] ***** No malicious Chromium entries cleaned. ***** [ Chromium URLs ] ***** No malicious Chromium URLs cleaned. ***** [ Firefox (and derivatives) ] ***** Not Deleted System Table Not Deleted System Table ***** [ Firefox URLs ] ***** Not Deleted suggestqueries.google.com Deleted C:\\ProgramData\\Quoteexs\\ff.HP ************************* [+] Delete Tracing Keys [+] Reset Winsock ************************* ########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########