# AdwCleaner v6.043 - Logfile created 24/02/2017 at 11:51:28 # Updated on 27/01/2017 by Malwarebytes # Database : 2017-02-23.4 [Local] # Operating System : Windows 7 Ultimate Service Pack 1 (X64) # Username : mati - PC # Running from : C:\Users\mati\Downloads\AdwCleaner.exe # Mode: Clean # Support : https://www.malwarebytes.com/support ***** [ Services ] ***** ***** [ Folders ] ***** [-] Folder deleted: C:\Users\mati\AppData\Local\FileViewPro [-] Folder deleted: C:\Users\mati\AppData\LocalLow\smartdownloader [-] Folder deleted: C:\Users\mati\AppData\Roaming\OpenCandy [-] Folder deleted: C:\Users\mati\AppData\Roaming\Solvusoft [-] Folder deleted: C:\Users\mati\AppData\Roaming\sweet-page [-] Folder deleted: C:\Users\Guest\AppData\Roaming\Solvusoft [-] Folder deleted: C:\Program Files\Przyspiesz Komputer [-] Folder deleted: C:\ProgramData\Solvusoft [#] Folder deleted on reboot: C:\ProgramData\Application Data\Solvusoft [-] Folder deleted: C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\AVG Secure Search ***** [ Files ] ***** [-] File deleted: C:\Users\mati\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Check PC for Errors.lnk [-] File deleted: C:\Users\mati\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Desk 365.lnk [-] File deleted: C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.funkymediatabsearch.com_0.localstorage [-] File deleted: C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.funkymediatabsearch.com_0.localstorage-journal ***** [ DLL ] ***** ***** [ WMI ] ***** ***** [ Shortcuts ] ***** [-] Shortcut disinfected: C:\Users\mati\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WorldofTanks\WorldofTanks.lnk [-] Shortcut disinfected: C:\Users\mati\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\WorldofTanks.lnk ***** [ Scheduled Tasks ] ***** [-] Task deleted: WOT N [-] Task deleted: WOT T [-] Task deleted: WOT W1 [-] Task deleted: WOT W2 [-] Task deleted: WOT WFRI1 [-] Task deleted: WOT WMON1 [-] Task deleted: WOT WTHUR1 [-] Task deleted: WOT WTUE1 [-] Task deleted: WOT WW1 [-] Task deleted: WOT WW2 [-] Task deleted: WOT WWED1 [-] Task deleted: OpenCandyHelperRunOnce ***** [ Registry ] ***** [-] Key deleted: HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\eSafeSvc [#] Key deleted on reboot: [x64] HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\eSafeSvc [-] Key deleted: HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\WebCakeUpdaterService [#] Key deleted on reboot: [x64] HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\WebCakeUpdaterService [-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762} [-] Key deleted: HKU\.DEFAULT\Software\DealPly [-] Key deleted: HKU\.DEFAULT\Software\ImInstaller [-] Key deleted: HKU\.DEFAULT\Software\WNLT [-] Key deleted: HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Uninstall\DealPly [-] Key deleted: HKU\S-1-5-21-3372699847-3746653199-2843972665-1000\Software\dobreprogramy [-] Key deleted: HKU\S-1-5-21-3372699847-3746653199-2843972665-1000\Software\InstallCore [-] Key deleted: HKU\S-1-5-21-3372699847-3746653199-2843972665-1000\Software\YahooPartnerToolbar [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3372699847-3746653199-2843972665-1000\Software\SweetIM [#] Key deleted on reboot: HKU\S-1-5-18\Software\DealPly [#] Key deleted on reboot: HKU\S-1-5-18\Software\ImInstaller [#] Key deleted on reboot: HKU\S-1-5-18\Software\WNLT [#] Key deleted on reboot: HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Uninstall\DealPly [#] Key deleted on reboot: HKCU\Software\dobreprogramy [#] Key deleted on reboot: HKCU\Software\InstallCore [#] Key deleted on reboot: HKCU\Software\YahooPartnerToolbar [-] Key deleted: HKLM\SOFTWARE\sweet-pageSoftware [-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{80107F16-CB2E-42AB-AB9D-6C11540D5A8B} [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3372699847-3746653199-2843972665-1000\Software\SweetIM [#] Key deleted on reboot: [x64] HKCU\Software\dobreprogramy [#] Key deleted on reboot: [x64] HKCU\Software\InstallCore [#] Key deleted on reboot: [x64] HKCU\Software\YahooPartnerToolbar [-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\90C64EA18BA25EE488BF80DCF07F2FFD [-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467 [#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\90C64EA18BA25EE488BF80DCF07F2FFD [-] Key deleted: HKLM\SOFTWARE\Classes\Applications\WinThrusterSetup.exe ***** [ Web browsers ] ***** [-] Chrome preferences cleaned: "extensions.quick_start.enable_search1" - false [-] Chrome preferences cleaned: "extensions.quick_start.sd.closeWindowWithLastTab_prev_state" - false [-] [C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: aol.com [-] [C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: ask.com ************************* :: "Tracing" keys deleted :: Winsock settings cleared ************************* C:\AdwCleaner\AdwCleaner[C0].txt - [5543 Bytes] - [24/02/2017 11:51:28] C:\AdwCleaner\AdwCleaner[S0].txt - [5567 Bytes] - [24/02/2017 11:50:49] ########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [5689 Bytes] ##########