# ------------------------------- # Malwarebytes AdwCleaner 7.2.3.1 # ------------------------------- # Build: 09-03-2018 # Database: 2018-09-06.1 (Cloud) # Support: https://www.malwarebytes.com/support # # ------------------------------- # Mode: Clean # ------------------------------- # Start: 09-07-2018 # Duration: 00:00:32 # OS: Windows 8 # Cleaned: 83 # Failed: 6 ***** [ Services ] ***** Deleted rtop Deleted SparkUpdater Deleted SparkSvc Deleted WinZip Smart Monitor Service ***** [ Folders ] ***** Deleted C:\ProgramData\efixmypc.com Deleted C:\Users\All Users\efixmypc.com Deleted C:\Users\Jean-Marie\AppData\Roaming\efixmypc.com Deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advance-PC-Care Deleted C:\Program Files\Advance-PC-Care Deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ByteFence Anti-Malware Not Deleted C:\ProgramData\ByteFence Not Deleted C:\Program Files\ByteFence Not Deleted C:\Users\All Users\ByteFence Not Deleted C:\Program Files\WinZip Smart Monitor Deleted C:\ProgramData\WinZip\WinZip Smart Monitor Deleted C:\Users\All Users\WinZip\WinZip Smart Monitor Deleted C:\ProgramData\WinZip\WinZip Driver Updater Deleted C:\Users\All Users\WinZip\WinZip Driver Updater Deleted C:\Users\All Users\Documents\Guid Deleted C:\Users\Public\Documents\Guid Not Deleted C:\Program Files\WebDiscoverBrowser Deleted C:\Windows\SysWOW64\config\systemprofile\AppData\Local\WebDiscoverBrowser Not Deleted C:\Users\Jean-Marie\AppData\Local\WebDiscoverBrowser Deleted C:\Program Files\WinZip Driver Updater Deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WiperSoft Deleted C:\Program Files\WiperSoft Deleted C:\Users\Jean-Marie\AppData\Roaming\WiperSoft ***** [ Files ] ***** Deleted C:\Users\All Users\Desktop\Advance-PC-Care.lnk Deleted C:\Users\Public\Desktop\Advance-PC-Care.lnk Deleted C:\Users\Jean-Marie\Desktop\ByteFence Anti-Malware.lnk Deleted C:\Users\All Users\Desktop\ASHAMPOO DEALS.URL Deleted C:\Users\Public\Desktop\ASHAMPOO DEALS.URL Deleted C:\Users\Jean-Marie\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Facebook.lnk Deleted C:\Users\All Users\Desktop\Facebook.lnk Deleted C:\Users\Public\Desktop\Facebook.lnk Deleted C:\Users\All Users\Desktop\eBay.lnk Deleted C:\Users\Public\Desktop\eBay.lnk Deleted C:\Users\Jean-Marie\Desktop\PC App Store.lnk ***** [ DLL ] ***** No malicious DLLs cleaned. ***** [ WMI ] ***** No malicious WMI cleaned. ***** [ Shortcuts ] ***** No malicious shortcuts cleaned. ***** [ Tasks ] ***** Deleted C:\Windows\Tasks\START WINZIP DRIVER UPDATER FOR LFS_HYPER_UEFM@JEAN-MARIE(LOGON).JOB Deleted C:\Windows\System32\Tasks\START WINZIP DRIVER UPDATER UPDATE Deleted C:\Windows\System32\Tasks\START WINZIP DRIVER UPDATER FOR LFS_HYPER_UEFM@JEAN-MARIE(LOGON) Deleted C:\Windows\System32\Tasks\Advance-PC-Care_Logon Deleted C:\Windows\System32\Tasks\ByteFence Deleted C:\Windows\System32\Tasks\SparkUpdater Deleted C:\Windows\System32\Tasks\WebDiscover Browser Update Task Deleted C:\Windows\System32\Tasks\WebDiscover Browser Launch Task Deleted C:\Windows\System32\Tasks\Start WinZip Driver Updater Schedule ***** [ Registry ] ***** Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A52C8819-2BDF-407C-B53F-EEDBD906AF01} Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A52C8819-2BDF-407C-B53F-EEDBD906AF01} Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Start WinZip Driver Updater Update Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{294718F0-43DE-4C10-849C-8A5B27C9135C} Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Start WinZip Driver Updater for LFS_HYPER_UEFM@Jean-Marie(logon) Deleted HKCU\Software\efixmypc.com Deleted HKLM\Software\efixmypc.com Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{94AC006B-9C07-49D0-8C90-20F6DB0D9BF7} Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Advance-PC-Care_Logon Deleted HKU\S-1-5-18\Software\ByteFence Deleted HKCU\Software\ByteFence Deleted HKU\.DEFAULT\Software\ByteFence Deleted HKLM\Software\Wow6432Node\ByteFence Deleted HKLM\Software\ByteFence Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{301700FF-3B9F-40F4-BB33-FEC291282F8D} Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ByteFence Deleted HKCU\Software\drpsu Deleted HKLM\Software\Wow6432Node\drpsu Deleted HKCU\Software\Microsoft\Internet Explorer\DOMStorage\drp.su Deleted HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run|WebDiscoverBrowser Deleted HKLM\Software\Microsoft\Windows\CurrentVersion\Run|WebDiscoverBrowser Deleted HKLM\Software\pcv-var Deleted HKU\S-1-5-18\Software\WebDiscoverBrowser Deleted HKCU\Software\WebDiscoverBrowser Deleted HKU\.DEFAULT\Software\WebDiscoverBrowser Deleted HKLM\Software\WebDiscoverBrowser Deleted HKLM\SOFTWARE\Classes\Directory\shell\ByteFence Folder Scan Deleted HKLM\SOFTWARE\Classes\*\shell\ByteFence File Scan Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EFA4ECF9-2619-41A3-8242-0E742DE24B22} Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SparkUpdater Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{99159531-A92F-45F9-9FA8-8342F4128362} Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{99159531-A92F-45F9-9FA8-8342F4128362} Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WebDiscover Browser Update Task Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2BD1A69A-A852-42A9-B123-E86043495AFB} Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WebDiscover Browser Launch Task Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Spark Deleted HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Spark Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6F27A218-B4A3-4077-8344-8B89AE4D3634} Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6F27A218-B4A3-4077-8344-8B89AE4D3634} Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Start WinZip Driver Updater Schedule Deleted HKCU\Software\WiperSoft ***** [ Chromium (and derivatives) ] ***** No malicious Chromium entries cleaned. ***** [ Chromium URLs ] ***** No malicious Chromium URLs cleaned. ***** [ Firefox (and derivatives) ] ***** Deleted ?????????? ???????? ***** [ Firefox URLs ] ***** No malicious Firefox URLs cleaned. ************************* [+] Delete IFEO [+] Delete Prefetch [+] Delete Tracing Keys [+] Reset BITS [+] Reset Windows Firewall [+] Reset Hosts File [+] Reset IPSec [+] Reset Chromium Policies [+] Reset IE Policies [+] Reset Proxy Settings [+] Reset TCP/IP [+] Reset Winsock ************************* AdwCleaner_Debug.log - [40311 octets] - [07/09/2018 16:22:59] AdwCleaner[S00].txt - [9219 octets] - [07/09/2018 16:46:59] ########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########