# AdwCleaner 7.0.1.0 - Logfile created on Tue Aug 22 15:56:03 2017 # Updated on 2017/05/08 by Malwarebytes # Running on Windows 10 Home (X64) # Mode: clean # Support: https://www.malwarebytes.com/support ***** [ Services ] ***** Deleted: WinSnare Deleted: GubZL Deleted: WinAppSvr Deleted: AppleAzureSrv Deleted: AppleAzureSrv Deleted: ByteFenceService Deleted: BIT Deleted: WinSAPSvc Deleted: Archer Deleted: rtop ***** [ Folders ] ***** Deleted: C:\Program Files (x86)\Elex-tech Deleted: C:\Users\Cassandra\AppData\Roaming\Elex-tech Deleted: C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\amuleC Deleted: C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\amuleC Deleted: C:\Users\Cassandra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\amuleC Deleted: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\qksee Deleted: C:\Users\Cassandra\AppData\Local\CWASRE Deleted: C:\Users\Cassandra\AppData\Local\CSHMDR Deleted: C:\Users\Cassandra\AppData\Local\snare Deleted: C:\Program Files (x86)\Footjane Deleted: C:\Users\Cassandra\AppData\Local\Footjane Deleted: C:\Program Files (x86)\Antanna Deleted: C:\Users\Cassandra\AppData\Local\Antanna Deleted: C:\Users\Cassandra\AppData\Roaming\\Firefox Deleted: C:\Users\Cassandra\AppData\Roaming\eCyber Deleted: C:\Users\Cassandra\AppData\Local\Temp\iSafeRightKeyScan Deleted: C:\Program Files (x86)\yesbnd Deleted: C:\Program Files (x86)\TXQQBrowser Deleted: C:\Windows\System32\config\systemprofile\AppData\Roaming\Tencent Deleted: C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Tencent Deleted: C:\Windows\System32\config\systemprofile\AppData\Roaming\aMule Deleted: C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\aMule Deleted: C:\Users\Cassandra\AppData\Roaming\aMule Deleted: C:\Program Files (x86)\amuleC1 Deleted: C:\Windows\System32\_TSpm Deleted: C:\Windows\SysWOW64\_TSpm Deleted: C:\ProgramData\ByteFence Deleted: C:\ProgramData\Application Data\ByteFence Deleted: C:\Program Files\ByteFence Deleted: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ByteFence Anti-Malware Deleted: C:\Users\Cassandra\AppData\Local\eeaUDOiyy Deleted: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BikaQ Deleted: C:\Program Files (x86)\BikaQRss Deleted: C:\Program Files (x86)\58C6DDD4_jumpeasy Deleted: C:\Program Files (x86)\WinSnare(4.1.0) Deleted: C:\Program Files (x86)\WinSnare(4.3.2) Deleted: C:\ProgramData\DwinpD Deleted: C:\ProgramData\EwinpE Deleted: C:\ProgramData\hwinph Deleted: C:\ProgramData\{41258446-CB67-0E80-4DA1-90C2D7E31B0C} Deleted: C:\ProgramData\{42CA87A9-C888-0D6F-4E4E-932DD40C18E3} ***** [ Files ] ***** Deleted: C:\Users\Public\Documents\\report.dat Deleted: C:\Users\Public\Documents\\temp.dat Deleted: C:\Windows\SysNative\log\iSafeKrnlCall.log Deleted: C:\Users\Cassandra\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\dd1b66d4.xml Deleted: C:\Users\Cassandra\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F\searchplugins\dd1b66d4.xml Deleted: C:\Users\Cassandra\AppData\Roaming\Mozilla\Firefox\Profiles\q02uspjj.default\searchplugins\nuesearch.xml ***** [ DLL ] ***** No malicious DLLs cleaned. ***** [ WMI ] ***** No malicious WMI cleaned. ***** [ Shortcuts ] ***** No malicious shortcuts cleaned. ***** [ Tasks ] ***** Deleted: Windows-PG Deleted: ChelfNotify Task Deleted: ByteFence Scan Deleted: Browser Updater Task(Core) Deleted: ByteFence Deleted: BikaQ_FetchAndUpgrade_CanBeDel ***** [ Registry ] ***** Deleted: [Key] - HKLM\SOFTWARE\Elex-tech Deleted: [Key] - HKU\.DEFAULT\Software\Elex-tech Deleted: [Key] - HKU\S-1-5-18\Software\Elex-tech Deleted: [Key] - HKLM\SOFTWARE\WinArcher Deleted: [Key] - HKLM\SOFTWARE\WinSaberSvc Deleted: [Key] - HKU\S-1-5-21-3067375901-4248974826-504483381-1001\Software\WinSnare Deleted: [Key] - HKCU\Software\WinSnare Deleted: [Key] - HKLM\SOFTWARE\qkseeSvc Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{19539992-061C-4E8B-9053-07B175303AF4} Deleted: [Key] - HKLM\SOFTWARE\qksee Deleted: [Key] - HKU\S-1-5-21-3067375901-4248974826-504483381-1001\Software\deskapp Deleted: [Key] - HKCU\Software\deskapp Deleted: [Key] - HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application Deleted: [Key] - HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application Deleted: [Key] - HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application Deleted: [Key] - HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application Deleted: [Key] - HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application Deleted: [Key] - HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application Deleted: [Key] - HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application Deleted: [Key] - HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application Deleted: [Key] - HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application Deleted: [Key] - HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application Deleted: [Key] - HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application Deleted: [Key] - HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application Deleted: [Key] - HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application Deleted: [Key] - HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\Themes|DependOnService Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost|SNARE Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{EEBA3F62-0D33-44DD-9F34-B17CBC667355} Deleted: [Key] - HKLM\SOFTWARE\Footjane Deleted: [Key] - HKU\S-1-5-21-3067375901-4248974826-504483381-1001\Software\Footjane Deleted: [Key] - HKCU\Software\Footjane Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\DOMStorage\amisites.com Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.amisites.com Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\d19tqk5t6qcjac.cloudfront.net Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\d19tqk5t6qcjac.cloudfront.net Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\foxi69.tlscdn.com Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\mail.ru Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\my.mail.ru Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\nuesearch.com Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\nuesearch.com Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\onclickads.net Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\terraclicks.com Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\tlscdn.com Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\www.nuesearch.com Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\www.nuesearch.com Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\www.terraclicks.com Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\yessearches.com Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\d19tqk5t6qcjac.cloudfront.net Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\d19tqk5t6qcjac.cloudfront.net Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\foxi69.tlscdn.com Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\mail.ru Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\my.mail.ru Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\nuesearch.com Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\nuesearch.com Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\onclickads.net Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\terraclicks.com Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\tlscdn.com Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\www.nuesearch.com Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\www.nuesearch.com Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\www.terraclicks.com Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\yessearches.com Deleted: [Data] - HKCU\Software\Microsoft\Internet Explorer\Main|Search Page [http:\\www.amisites.com\search\?type=ds&ts=1481302125&z=6b399aa3d18c039cb886798g8z1bfg2c6e0o6gfe2m&from=archer1028&uid=TOSHIBAXMQ01ABD100_3592PLNZTXX3592PLNZT&q={searchTerms}] Deleted: [Data] - HKCU\Software\Microsoft\Internet Explorer\Main|Default_Page_URL [http:\\www.amisites.com\?type=hp&ts=1481302125&z=6b399aa3d18c039cb886798g8z1bfg2c6e0o6gfe2m&from=archer1028&uid=TOSHIBAXMQ01ABD100_3592PLNZTXX3592PLNZT] Deleted: [Data] - HKCU\Software\Microsoft\Internet Explorer\Main|Default_Search_URL [http:\\www.amisites.com\search\?type=ds&ts=1481302125&z=6b399aa3d18c039cb886798g8z1bfg2c6e0o6gfe2m&from=archer1028&uid=TOSHIBAXMQ01ABD100_3592PLNZTXX3592PLNZT&q={searchTerms}] Deleted: [Data] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main|Default_Page_URL [http:\\www.amisites.com\?type=hp&ts=1481302125&z=6b399aa3d18c039cb886798g8z1bfg2c6e0o6gfe2m&from=archer1028&uid=TOSHIBAXMQ01ABD100_3592PLNZTXX3592PLNZT] Deleted: [Data] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main|Default_Search_URL [http:\\www.nuesearch.com\search\?type=ds&ts=1466675520&z=3e4d58e0851ba749ba94e50g9zaqaq5q6m7w3zeb4o&from=wpm0616&uid=TOSHIBAXMQ01ABD100_3592PLNZTXX3592PLNZT&q={searchTerms}] Deleted: [Data] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main|Default_Search_URL [http:\\www.nuesearch.com\search\?type=ds&ts=1466675520&z=3e4d58e0851ba749ba94e50g9zaqaq5q6m7w3zeb4o&from=wpm0616&uid=TOSHIBAXMQ01ABD100_3592PLNZTXX3592PLNZT&q={searchTerms}] Deleted: [Data] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main|Search Page [http:\\www.nuesearch.com\search\?type=ds&ts=1466675520&z=3e4d58e0851ba749ba94e50g9zaqaq5q6m7w3zeb4o&from=wpm0616&uid=TOSHIBAXMQ01ABD100_3592PLNZTXX3592PLNZT&q={searchTerms}] Deleted: [Data] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main|Search Page [http:\\www.nuesearch.com\search\?type=ds&ts=1466675520&z=3e4d58e0851ba749ba94e50g9zaqaq5q6m7w3zeb4o&from=wpm0616&uid=TOSHIBAXMQ01ABD100_3592PLNZTXX3592PLNZT&q={searchTerms}] Deleted: [Key] - HKLM\SOFTWARE\hdcode Deleted: [Key] - HKLM\SOFTWARE\{A16B1AF7-982D-40C3-B5C1-633E1A6A6678} Deleted: [Key] - HKU\.DEFAULT\Software\{A16B1AF7-982D-40C3-B5C1-633E1A6A6678} Deleted: [Key] - HKU\S-1-5-18\Software\{A16B1AF7-982D-40C3-B5C1-633E1A6A6678} Deleted: [Key] - HKLM\SOFTWARE\{E6276374-DE18-4AA5-A365-9016A2F98A2D} Deleted: [Key] - HKLM\SOFTWARE\{G6276374-DEEE-4AAA-A355-9016A2F98A2D} Deleted: [Key] - HKLM\SOFTWARE\{8C4CE252-7DB2-4F8E-8E76-BAD0E5826A83} Deleted: [Key] - HKU\.DEFAULT\Software\{8C4CE252-7DB2-4F8E-8E76-BAD0E5826A83} Deleted: [Key] - HKU\S-1-5-18\Software\{8C4CE252-7DB2-4F8E-8E76-BAD0E5826A83} Deleted: [Key] - HKLM\SOFTWARE\WinZiper Deleted: [Key] - HKU\S-1-5-21-3067375901-4248974826-504483381-1001\Software\ICSW1.23 Deleted: [Key] - HKCU\Software\ICSW1.23 Deleted: [Key] - HKLM\SOFTWARE\InterSect Alliance Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{78A2D999-4673-4FCC-818E-57B0AF8F3B70} Deleted: [Key] - HKCU\SOFTWARE\Mozilla\Firefox\{EB52F1AB-3C2B-424F-9794-833C687025CF} Deleted: [Key] - HKLM\SOFTWARE\Mozilla\Firefox\{EB52F1AB-3C2B-424F-9794-833C687025CF} Deleted: [Key] - HKLM\SOFTWARE\Classes\*\shell\ByteFence File Scan Deleted: [Key] - HKLM\SOFTWARE\Classes\Directory\shell\ByteFence Folder Scan Deleted: [Key] - HKLM\SOFTWARE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF} Deleted: [Key] - HKCU\SOFTWARE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF} Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost|ArcherGroupEx Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost|WinSAPSvc Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost|GubZLGroEx Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost|SNARER Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost|BIT Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost|CWASRE Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost|CSHMDR Deleted: [Key] - HKLM\SYSTEM\CurrentControlSet\Control\iSafeKrnlBoot Deleted: [Key] - HKLM\SOFTWARE\ByteFence Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ByteFence Deleted: [Key] - HKU\S-1-5-21-3067375901-4248974826-504483381-1001\Software\ByteFence Deleted: [Key] - HKCU\Software\ByteFence Deleted: [Key] - HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application Deleted: [Key] - HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION|ByteFence.exe Deleted: [Key] - HKLM\SOFTWARE\CLIENTS\Corner Sunshine Deleted: [Key] - HKLM\SOFTWARE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF} Deleted: [Key] - HKLM\SOFTWARE\ScreenShot Deleted: [Key] - HKLM\SOFTWARE\amisitesSoftware Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\les-sims-3.fr.softonic.com Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\softonic.com Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\the-sims-3.fr.softonic.com Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\les-sims-3.fr.softonic.com Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\softonic.com Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\the-sims-3.fr.softonic.com Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost|WINSNARE Deleted: [Key] - HKU\S-1-5-21-3067375901-4248974826-504483381-1001\Software\csastats Deleted: [Key] - HKCU\Software\csastats Deleted: [Key] - HKU\S-1-5-21-3067375901-4248974826-504483381-1001\Software\PRODUCTSETUP Deleted: [Key] - HKCU\Software\PRODUCTSETUP Deleted: [Key] - HKLM\SOFTWARE\yessearchesSoftware Deleted: [Key] - HKLM\SOFTWARE\Classes\WinZippers.001 Deleted: [Key] - HKLM\SOFTWARE\Classes\WinZippers.7z Deleted: [Key] - HKLM\SOFTWARE\Classes\WinZippers.arj Deleted: [Key] - HKLM\SOFTWARE\Classes\WinZippers.bz2 Deleted: [Key] - HKLM\SOFTWARE\Classes\WinZippers.bzip2 Deleted: [Key] - HKLM\SOFTWARE\Classes\WinZippers.cab Deleted: [Key] - HKLM\SOFTWARE\Classes\WinZippers.cpio Deleted: [Key] - HKLM\SOFTWARE\Classes\WinZippers.deb Deleted: [Key] - HKLM\SOFTWARE\Classes\WinZippers.dmg Deleted: [Key] - HKLM\SOFTWARE\Classes\WinZippers.fat Deleted: [Key] - HKLM\SOFTWARE\Classes\WinZippers.gz Deleted: [Key] - HKLM\SOFTWARE\Classes\WinZippers.gzip Deleted: [Key] - HKLM\SOFTWARE\Classes\WinZippers.hfs Deleted: [Key] - HKLM\SOFTWARE\Classes\WinZippers.iso Deleted: [Key] - HKLM\SOFTWARE\Classes\WinZippers.lha Deleted: [Key] - HKLM\SOFTWARE\Classes\WinZippers.lzh Deleted: [Key] - HKLM\SOFTWARE\Classes\WinZippers.lzma Deleted: [Key] - HKLM\SOFTWARE\Classes\WinZippers.ntfs Deleted: [Key] - HKLM\SOFTWARE\Classes\WinZippers.rar Deleted: [Key] - HKLM\SOFTWARE\Classes\WinZippers.rpm Deleted: [Key] - HKLM\SOFTWARE\Classes\WinZippers.squashfs Deleted: [Key] - HKLM\SOFTWARE\Classes\WinZippers.swm Deleted: [Key] - HKLM\SOFTWARE\Classes\WinZippers.tar Deleted: [Key] - HKLM\SOFTWARE\Classes\WinZippers.taz Deleted: [Key] - HKLM\SOFTWARE\Classes\WinZippers.tbz Deleted: [Key] - HKLM\SOFTWARE\Classes\WinZippers.tbz2 Deleted: [Key] - HKLM\SOFTWARE\Classes\WinZippers.tgz Deleted: [Key] - HKLM\SOFTWARE\Classes\WinZippers.tpz Deleted: [Key] - HKLM\SOFTWARE\Classes\WinZippers.txz Deleted: [Key] - HKLM\SOFTWARE\Classes\WinZippers.vhd Deleted: [Key] - HKLM\SOFTWARE\Classes\WinZippers.wim Deleted: [Key] - HKLM\SOFTWARE\Classes\WinZippers.xar Deleted: [Key] - HKLM\SOFTWARE\Classes\WinZippers.xz Deleted: [Key] - HKLM\SOFTWARE\Classes\WinZippers.z Deleted: [Key] - HKLM\SOFTWARE\Classes\WinZippers.zip ***** [ Firefox (and derivatives) ] ***** No malicious Firefox entries deleted. ***** [ Chromium (and derivatives) ] ***** No malicious Chromium entries deleted. ************************* ::Tracing keys deleted ::Winsock settings cleared ::Additional Actions: 0 ************************* C:/AdwCleaner/AdwCleaner[S0].txt - [23551 B] - [2017/8/22 15:45:50] ########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt ##########