# AdwCleaner 7.0.8.0 - Logfile created on Fri Mar 09 18:24:44 2018 # Updated on 2018/08/02 by Malwarebytes # Running on Windows 7 Professional (X64) # Mode: clean # Support: https://www.malwarebytes.com/support ***** [ Services ] ***** No malicious services deleted. ***** [ Folders ] ***** Deleted: C:\ProgramData\Tmp0x0x Deleted: C:\ProgramData\Application Data\Tmp0x0x Deleted: C:\Users\All Users\Tmp0x0x Deleted: C:\ProgramData\Auslogics Deleted: C:\ProgramData\Application Data\Auslogics Deleted: C:\Users\All Users\Auslogics Deleted: C:\ProgramData\2WdM2 ***** [ Files ] ***** Deleted: C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat Deleted: C:\ProgramData\Application Data\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat Deleted: C:\Users\All Users\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat ***** [ DLL ] ***** No malicious DLLs cleaned. ***** [ WMI ] ***** No malicious WMI cleaned. ***** [ Shortcuts ] ***** No malicious shortcuts cleaned. ***** [ Tasks ] ***** Deleted: WarThunder sat Deleted: WarThunder sun Deleted: WarThunder24 ***** [ Registry ] ***** Deleted: [Key] - HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application Deleted: [Key] - HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application Deleted: [Data] - HKCU\Software\Microsoft\Internet Explorer\Main|Search Page [http:\\yoursites123.com\web?type=ds&ts=1457964779&z=6111626130c5b9f8c08ce29g8z6wam2t0qdz6m2mdm&from=wpm0314&uid=ST9500325AS_6VE42YWVXXXX6VE42YWV&q={searchTerms}] Deleted: [Data] - HKCU\Software\Microsoft\Internet Explorer\Main|Default_Page_URL [http:\\www.yoursites123.com\?type=hp&ts=1452609464&z=0b2f228cecc2316c38a99c2gfz1w5oaqee4t5zawft&from=ient12253&uid=ST9500325AS_6VE42YWVXXXX6VE42YWV] Deleted: [Data] - HKCU\Software\Microsoft\Internet Explorer\Main|Default_Search_URL [http:\\yoursites123.com\web?type=ds&ts=1457964779&z=6111626130c5b9f8c08ce29g8z6wam2t0qdz6m2mdm&from=wpm0314&uid=ST9500325AS_6VE42YWVXXXX6VE42YWV&q={searchTerms}] Deleted: [Data] - HKCU\Software\Microsoft\Internet Explorer\Main|Start Page_TIMESTAMP [밧搲냂Ǔ:\\yoursites123.com\web?type=ds&ts=1457964779&z=6111626130c5b9f8c08ce29g8z6wam2t0qdz6m2mdm&from=wpm0314&uid=ST9500325AS_6VE42YWVXXXX6VE42YWV&q={searchTerms}] Deleted: [Data] - HKCU\Software\Microsoft\Internet Explorer\Main|SyncHomePage Protected - It is a violation of Windows Policy to modify. See aka.ms\browserpolicy [밧搲냂Ǔ:\\yoursites123.com\web?type=ds&ts=1457964779&z=6111626130c5b9f8c08ce29g8z6wam2t0qdz6m2mdm&from=wpm0314&uid=ST9500325AS_6VE42YWVXXXX6VE42YWV&q={searchTerms}] Deleted: [Data] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main|Default_Search_URL [http:\\yoursites123.com\web?type=ds&ts=1452609464&z=0b2f228cecc2316c38a99c2gfz1w5oaqee4t5zawft&from=ient12253&uid=ST9500325AS_6VE42YWVXXXX6VE42YWV&q={searchTerms}] Deleted: [Data] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main|Default_Page_URL [http:\\www.yoursites123.com\?type=hp&ts=1452609464&z=0b2f228cecc2316c38a99c2gfz1w5oaqee4t5zawft&from=ient12253&uid=ST9500325AS_6VE42YWVXXXX6VE42YWV] Deleted: [Data] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main|Search Page [http:\\yoursites123.com\web?type=ds&ts=1452609464&z=0b2f228cecc2316c38a99c2gfz1w5oaqee4t5zawft&from=ient12253&uid=ST9500325AS_6VE42YWVXXXX6VE42YWV&q={searchTerms}] Deleted: [Value] - HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command| Deleted: [Key] - HKLM\SOFTWARE\dt soft\daemon tools toolbar Deleted: [Key] - HKU\S-1-5-21-170041769-2645518904-2340773898-1001\Software\dt soft\daemon tools toolbar Deleted: [Key] - HKCU\Software\dt soft\daemon tools toolbar Deleted: [Key] - HKLM\SOFTWARE\hdcode Deleted: [Key] - HKLM\SOFTWARE\torch Deleted: [Key] - HKU\S-1-5-21-170041769-2645518904-2340773898-1001\Software\torch Deleted: [Key] - HKCU\Software\torch Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{08337871-0E50-4031-9110-3BD21CA3C065} Deleted: [Key] - HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application Deleted: [Key] - HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application Deleted: [Key] - HKLM\SOFTWARE\Clients\StartMenuInternet\Torch Deleted: [Key] - HKLM\SOFTWARE\MozillaPlugins\@pandonetworks.com\PandoWebPlugin Deleted: [Key] - HKU\S-1-5-21-170041769-2645518904-2340773898-1001\Software\Softonic Deleted: [Key] - HKCU\Software\Softonic Deleted: [Key] - HKLM\SOFTWARE\yoursites123Software Deleted: [Key] - HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application Deleted: [Key] - HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application Deleted: [Value] - HKCU\Software\Microsoft\Internet Explorer\TabbedBrowsing|bProtectShowTabsWelcome Deleted: [Key] - HKLM\SOFTWARE\Auslogics Deleted: [Key] - HKLM\SOFTWARE\istartpageingSoftware Deleted: [Key] - HKU\S-1-5-21-170041769-2645518904-2340773898-1001\Software\PRODUCTSETUP Deleted: [Key] - HKCU\Software\PRODUCTSETUP Deleted: [Key] - HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application Deleted: [Key] - HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application ***** [ Firefox (and derivatives) ] ***** No malicious Firefox entries deleted. ***** [ Chromium (and derivatives) ] ***** No malicious Chromium entries deleted. ************************* ::Tracing keys deleted ::Winsock settings cleared ::Additional Actions: 0 ************************* C:/AdwCleaner/AdwCleaner[S0].txt - [6118 B] - [2018/3/9 15:57:57] C:/AdwCleaner/AdwCleaner[S1].txt - [6185 B] - [2018/3/9 18:7:57] ########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt ##########