# AdwCleaner v6.041 - Logfile created 03/01/2017 at 17:51:10 # Updated on 16/12/2016 by Malwarebytes # Database : 2017-01-03.1 [Server] # Operating System : Windows 7 Home Premium Service Pack 1 (X64) # Username : Akhlifi Med - AKHLIFIMED-PC # Running from : C:\Users\Akhlifi Med\Desktop\adwcleaner_6.041.exe # Mode: Clean # Support : https://www.malwarebytes.com/support ***** [ Services ] ***** [-] Service deleted: GoogleChromeUpService [-] Service deleted: ucdrv [-] Service deleted: SaFiSvc [-] Service deleted: dtldrvhelp ***** [ Folders ] ***** [-] Folder deleted: C:\Program Files (x86)\3948BD9C-1483197847-11E1-BCE9-BE15FAC94852 [-] Folder deleted: C:\Program Files (x86)\EnjOyCoUpon [-] Folder deleted: C:\Program Files (x86)\ExstraSavinggs [-] Folder deleted: C:\Program Files (x86)\Fun2SAive [-] Folder deleted: C:\Program Files (x86)\FunoDaeals [-] Folder deleted: C:\Program Files (x86)\RegUUlarDeAAls [-] Folder deleted: C:\Program Files (x86)\RoboSavveR [-] Folder deleted: C:\Program Files (x86)\SallePLUs [-] Folder deleted: C:\ProgramData\1a5ab6ac00001d07 [-] Folder deleted: C:\ProgramData\21c723c500006a4d [-] Folder deleted: C:\ProgramData\3270fe5e00004fdb [-] Folder deleted: C:\ProgramData\46fd71c80000070b [-] Folder deleted: C:\ProgramData\812a86140000723b [-] Folder deleted: C:\ProgramData\9148724837990743182 [-] Folder deleted: C:\ProgramData\bcapdgolamjladpmfhngajdclemfhehe [#] Folder deleted on reboot: C:\ProgramData\Application Data\bcapdgolamjladpmfhngajdclemfhehe [-] Folder deleted: C:\ProgramData\c61bbf3000004b4b [-] Folder deleted: C:\ProgramData\d6e0580700004b4c [-] Folder deleted: C:\ProgramData\dd297933000014ba [-] Folder deleted: C:\ProgramData\e884a540000004a2 [-] Folder deleted: C:\ProgramData\fe16680800004538 [-] Folder deleted: C:\ProgramData\hoippaacopmbaiokjmncjeoinmkhdcel [#] Folder deleted on reboot: C:\ProgramData\Application Data\hoippaacopmbaiokjmncjeoinmkhdcel [-] Folder deleted: C:\ProgramData\PC Faster [#] Folder deleted on reboot: C:\ProgramData\Application Data\PC Faster [-] Folder deleted: C:\Users\Public\Documents\PC Faster [-] Folder deleted: C:\ProgramData\{01d0ddd7-2064-1} [-] Folder deleted: C:\ProgramData\{049a8d15-6064-0} [-] Folder deleted: C:\ProgramData\{05cc54b8-00c8-0} [-] Folder deleted: C:\ProgramData\{07ee42a8-20c8-0} [-] Folder deleted: C:\ProgramData\{0814074b-50c8-1} [-] Folder deleted: C:\ProgramData\{15877dcd-d3bb-96ff-1587-77dcdd3bf737} [-] Folder deleted: C:\ProgramData\{1c159449-30c8-1} [-] Folder deleted: C:\ProgramData\{3fa6c51b-0bb5-22f9-3fa6-6c51b0bb146c} [-] Folder deleted: C:\ProgramData\{699cb3e5-acc7-589f-699c-cb3e5acccf96} [-] Folder deleted: C:\ProgramData\{d655ee5f-59a2-8e70-d655-5ee5f59ab97d} [-] Folder deleted: C:\Users\Akhlifi Med\AppData\Local\Mail.Ru [-] Folder deleted: C:\Users\Akhlifi Med\AppData\Local\kemgadeojglibflomicgnfeopkdfflnk [-] Folder deleted: C:\Users\Akhlifi Med\AppData\LocalLow\.acestream [-] Folder deleted: C:\Users\Akhlifi Med\AppData\LocalLow\TSearch [-] Folder deleted: C:\Users\Akhlifi Med\AppData\Roaming\.acestream [-] Folder deleted: C:\Users\Akhlifi Med\AppData\Roaming\acestream [-] Folder deleted: C:\Users\Akhlifi Med\AppData\Roaming\Advanced System Protector [-] Folder deleted: C:\Users\Akhlifi Med\AppData\Roaming\sweet-page [-] Folder deleted: C:\Users\Akhlifi Med\AppData\Roaming\Systweak [-] Folder deleted: C:\Users\Akhlifi Med\AppData\Roaming\MailProducts [-] Folder deleted: C:\Users\Akhlifi Med\AppData\Roaming\ContentPush [-] Folder deleted: C:\Users\Akhlifi Med\AppData\Roaming\Kuaizip [-] Folder deleted: C:\Users\Akhlifi Med\AppData\Roaming\LuDaShi [-] Folder deleted: C:\Users\Akhlifi Med\AppData\Roaming\lockhomepage [-] Folder deleted: C:\Users\Akhlifi Med\AppData\Roaming\Softlink [-] Folder deleted: C:\Users\Akhlifi Med\AppData\Roaming\Microleaves [-] Folder deleted: C:\Users\Akhlifi Med\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ace Stream Media [-] Folder deleted: C:\Program Files\Babylon [-] Folder deleted: C:\Program Files\SaFiPlayer [-] Folder deleted: C:\_acestream_cache_ [-] Folder deleted: C:\ProgramData\Mail.Ru [#] Folder deleted on reboot: C:\ProgramData\pc faster [-] Folder deleted: C:\ProgramData\Registry Helper [-] Folder deleted: C:\ProgramData\WindowsMsg [-] Folder deleted: C:\ProgramData\Microleaves [#] Folder deleted on reboot: C:\ProgramData\Application Data\Mail.Ru [#] Folder deleted on reboot: C:\ProgramData\Application Data\pc faster [#] Folder deleted on reboot: C:\ProgramData\Application Data\Registry Helper [#] Folder deleted on reboot: C:\ProgramData\Application Data\WindowsMsg [#] Folder deleted on reboot: C:\ProgramData\Application Data\Microleaves [-] Folder deleted: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cain [-] Folder deleted: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SaFiPlayer [#] Folder deleted on reboot: C:\Users\Public\Documents\pc faster [-] Folder deleted: C:\Program Files (x86)\Cain [-] Folder deleted: C:\Program Files (x86)\Mail.Ru [-] Folder deleted: C:\Program Files (x86)\ContentPush [-] Folder deleted: C:\Users\Akhlifi Med\AppData\Local\app ***** [ Files ] ***** [-] File deleted: C:\Users\Akhlifi Med\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mail.Ru.lnk [-] File deleted: C:\Users\Akhlifi Med\Favorites\Mail.Ru.url [-] File deleted: C:\Users\Akhlifi Med\Favorites\Mail.Ru Агент - используй для общения!.url [-] File deleted: C:\Windows\SysNative\roboot64.exe [-] File deleted: C:\ProgramData\service.exe [#] File deleted: C:\ProgramData\Application Data\service.exe [-] File deleted: C:\Windows\SysWOW64\RegistryHelperLM.ocx [#] File deleted: C:\ProgramData\service.exe [-] File deleted: C:\Users\Akhlifi Med\AppData\Roaming\appdataFr2.bin [-] File deleted: C:\Windows\run.vbs [#] File deleted: C:\ProgramData\igfxDH.dll ***** [ DLL ] ***** ***** [ WMI ] ***** ***** [ Shortcuts ] ***** [-] Shortcut disinfected: C:\Users\Public\Desktop\Mozilla Firefox.lnk [-] Shortcut disinfected: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk [-] Shortcut disinfected: C:\Users\Akhlifi Med\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk [-] Shortcut disinfected: C:\Users\Akhlifi Med\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Tor Browser.lnk [-] Shortcut disinfected: C:\Users\Akhlifi Med\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WorldofTanks551\WorldofTanks.lnk [-] Shortcut disinfected: C:\Users\Akhlifi Med\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk [-] Shortcut disinfected: C:\Users\Akhlifi Med\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk [!] Shortcut not deleted: C:\Users\Akhlifi Med\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mail.Ru.lnk [-] Shortcut disinfected: C:\Users\Akhlifi Med\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\WorldofTanks.lnk [-] Shortcut disinfected: C:\Users\Akhlifi Med\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk ***** [ Scheduled Tasks ] ***** [-] Task deleted: PC Faster [-] Task deleted: {1014B6F3-325E-0B88-BD18-7EEEFCEDF0F7} [-] Task deleted: {D18E1AEC-2D45-42DA-9BD7-6F477EA06813} [-] Task deleted: Advanced System Protector [-] Task deleted: WOT N [-] Task deleted: WOT T [-] Task deleted: WOT W1 [-] Task deleted: WOT W2 [-] Task deleted: WOT WFRI1 [-] Task deleted: WOT WMON1 [-] Task deleted: WOT WTHUR1 [-] Task deleted: WOT WTUE1 [-] Task deleted: WOT WW1 [-] Task deleted: WOT WW2 [-] Task deleted: WOT WWED1 [-] Task deleted: Superclean [-] Task deleted: osTip [-] Task deleted: SecureUpdater ***** [ Registry ] ***** [-] Key deleted: HKLM\SOFTWARE\d51fd3a3-8cd4-5df6-29c6-91b6edef8f7a [-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{b44f2bf7-0c4a-4e39-b366-3082af73f8a1} [#] Key deleted on reboot: HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{b44f2bf7-0c4a-4e39-b366-3082af73f8a1} [-] Key deleted: HKLM\SOFTWARE\Classes\Pb44f2bf7_0c4a_4e39_b366_3082af73f8a1_.Pb44f2bf7_0c4a_4e39_b366_3082af73f8a1_ [-] Key deleted: HKLM\SOFTWARE\Classes\Pb44f2bf7_0c4a_4e39_b366_3082af73f8a1_.Pb44f2bf7_0c4a_4e39_b366_3082af73f8a1_.9 [#] Key deleted on reboot: {832008D4-0A5E-4F74-A62E-7284F91F7681} [#] Key deleted on reboot: {EB559340-3A8F-4456-B24D-160098054EF0} [#] Key deleted on reboot: {FCE74B5F-13A9-47C3-B69E-5210C1EECBEF} [#] Key deleted on reboot: {FD5787DF-EF9A-4DCC-8EA3-43279F7BC560} [-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{0FFA016C-49EA-43E6-A635-773E4A768C34} [-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{1EA56CF8-1B08-4B8B-BAD9-77D0A2F55837} [-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{311AACFA-3DB4-4EEC-B430-E9FFF3C3F4EB} [-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{5C4ECEE2-D00F-4844-92B9-F2699746572C} [-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{8069EEE8-90E1-42E5-82B5-BE7D9D04E78B} [-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{937D76F0-C828-487A-A042-54CA1849F136} [-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{981C4037-A6DF-4B09-BEB9-2B6AFA9E8044} [-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{AFE44F7D-9EB4-426B-AB34-4DAB85ECDF91} [-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{C9B1623E-D1AB-46B1-9D60-12F35E65190B} [-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{D3EE4881-9CA4-46DD-BF2B-033422C7D0D9} [-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{D75E8573-4E73-4642-8517-A6348042151C} [-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{DC00432C-FF74-41C6-BE9E-7F2224FDB437} [-] Key deleted: [x64] HKLM\SOFTWARE\Classes\Interface\{0FFA016C-49EA-43E6-A635-773E4A768C34} [-] Key deleted: [x64] HKLM\SOFTWARE\Classes\Interface\{1EA56CF8-1B08-4B8B-BAD9-77D0A2F55837} [-] Key deleted: [x64] HKLM\SOFTWARE\Classes\Interface\{311AACFA-3DB4-4EEC-B430-E9FFF3C3F4EB} [-] Key deleted: [x64] HKLM\SOFTWARE\Classes\Interface\{5C4ECEE2-D00F-4844-92B9-F2699746572C} [-] Key deleted: [x64] HKLM\SOFTWARE\Classes\Interface\{8069EEE8-90E1-42E5-82B5-BE7D9D04E78B} [-] Key deleted: [x64] HKLM\SOFTWARE\Classes\Interface\{937D76F0-C828-487A-A042-54CA1849F136} [-] Key deleted: [x64] HKLM\SOFTWARE\Classes\Interface\{981C4037-A6DF-4B09-BEB9-2B6AFA9E8044} [-] Key deleted: [x64] HKLM\SOFTWARE\Classes\Interface\{AFE44F7D-9EB4-426B-AB34-4DAB85ECDF91} [-] Key deleted: [x64] HKLM\SOFTWARE\Classes\Interface\{C9B1623E-D1AB-46B1-9D60-12F35E65190B} [-] Key deleted: [x64] HKLM\SOFTWARE\Classes\Interface\{D3EE4881-9CA4-46DD-BF2B-033422C7D0D9} [-] Key deleted: [x64] HKLM\SOFTWARE\Classes\Interface\{D75E8573-4E73-4642-8517-A6348042151C} [-] Key deleted: [x64] HKLM\SOFTWARE\Classes\Interface\{DC00432C-FF74-41C6-BE9E-7F2224FDB437} [-] Key deleted: HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\Registry Helper Service [#] Key deleted on reboot: [x64] HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\Registry Helper Service [-] Key deleted: HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\GoogleChromeUpService [#] Key deleted on reboot: [x64] HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\GoogleChromeUpService [-] Key deleted: HKU\S-1-5-21-2784700871-1142390347-2527291130-1000\Software\Classes\.acelive [-] Key deleted: HKU\S-1-5-21-2784700871-1142390347-2527291130-1000\Software\Classes\.acemedia [-] Key deleted: HKU\S-1-5-21-2784700871-1142390347-2527291130-1000\Software\Classes\.acestream [-] Key deleted: HKU\S-1-5-21-2784700871-1142390347-2527291130-1000\Software\Classes\.tslive [-] Key deleted: HKU\S-1-5-21-2784700871-1142390347-2527291130-1000\Software\Classes\acestream [-] Key deleted: HKU\S-1-5-21-2784700871-1142390347-2527291130-1000\Software\Classes\AceStream.CDAudio [-] Key deleted: HKU\S-1-5-21-2784700871-1142390347-2527291130-1000\Software\Classes\AceStream.DVDMovie [-] Key deleted: HKU\S-1-5-21-2784700871-1142390347-2527291130-1000\Software\Classes\AceStream.file [-] Key deleted: HKU\S-1-5-21-2784700871-1142390347-2527291130-1000\Software\Classes\AceStream.OPENFolder [-] Key deleted: HKU\S-1-5-21-2784700871-1142390347-2527291130-1000\Software\Classes\AceStream.SVCDMovie [-] Key deleted: HKU\S-1-5-21-2784700871-1142390347-2527291130-1000\Software\Classes\AceStream.VCDMovie [#] Key deleted on reboot: HKCU\Software\Classes\.acelive [#] Key deleted on reboot: HKCU\Software\Classes\.acemedia [#] Key deleted on reboot: HKCU\Software\Classes\.acestream [#] Key deleted on reboot: HKCU\Software\Classes\.tslive [#] Key deleted on reboot: HKCU\Software\Classes\acestream [#] Key deleted on reboot: HKCU\Software\Classes\AceStream.CDAudio [#] Key deleted on reboot: HKCU\Software\Classes\AceStream.DVDMovie [#] Key deleted on reboot: HKCU\Software\Classes\AceStream.file [#] Key deleted on reboot: HKCU\Software\Classes\AceStream.OPENFolder [#] Key deleted on reboot: HKCU\Software\Classes\AceStream.SVCDMovie [#] Key deleted on reboot: HKCU\Software\Classes\AceStream.VCDMovie [-] Key deleted: HKLM\SOFTWARE\Classes\.acestream [#] Key deleted on reboot: [x64] HKCU\Software\Classes\.acelive [#] Key deleted on reboot: [x64] HKCU\Software\Classes\.acemedia [#] Key deleted on reboot: [x64] HKCU\Software\Classes\.acestream [#] Key deleted on reboot: [x64] HKCU\Software\Classes\.tslive [#] Key deleted on reboot: [x64] HKCU\Software\Classes\acestream [#] Key deleted on reboot: [x64] HKCU\Software\Classes\AceStream.CDAudio [#] Key deleted on reboot: [x64] HKCU\Software\Classes\AceStream.DVDMovie [#] Key deleted on reboot: [x64] HKCU\Software\Classes\AceStream.file [#] Key deleted on reboot: [x64] HKCU\Software\Classes\AceStream.OPENFolder [#] Key deleted on reboot: [x64] HKCU\Software\Classes\AceStream.SVCDMovie [#] Key deleted on reboot: [x64] HKCU\Software\Classes\AceStream.VCDMovie [#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\.acestream [-] Key deleted: HKU\S-1-5-21-2784700871-1142390347-2527291130-1000\Software\Classes\TypeLib\{157B1AA6-3E5C-404A-9118-C1D91F537040} [-] Key deleted: HKLM\SOFTWARE\Classes\AppID\{6536801B-F50C-449B-9476-093DFD3789E3} [-] Key deleted: HKCU\Software\Classes\CLSID\{F28C2F70-47DE-4EA5-8F6D-7D1476CD1EF5} [-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{00B11DA2-75ED-4364-ABA5-9A95B1F5E946} [-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} [-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52} [-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762} [-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{C379EAD1-CB34-4B09-AF6B-7E587F8BCD80} [-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{6E727987-C8EA-44DA-8749-310C0FBE3C3E} [-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{79690976-ED6E-403C-BBBA-F8928B5EDE17} [-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{8E8F97CD-60B5-456F-A201-73065652D099} [-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{03AE1B7B-A9E7-4D5A-9D34-89999C31B659} [-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{8BF0126F-A5B7-4720-ABB2-2414A0AF5474} [-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{DCFCC2EC-3F33-45A8-8ADF-A6C81F11232F} [-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB} [-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5} [-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{357D32FC-F0AE-4B37-B36F-D44AA31496F5} [-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{80B3B43F-7508-4627-BE66-00FB9AE5EE72} [-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{E7BC34A1-BA86-11CF-84B1-CBC2DA68BF6C} [#] Key deleted on reboot: HKCU\Software\Classes\TypeLib\{157B1AA6-3E5C-404A-9118-C1D91F537040} [-] Key deleted: HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66} [-] Key deleted: HKLM\SOFTWARE\Classes\TypeLib\{5A83D7C9-4A14-4000-BC05-389268238753} [-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E8F97CD-60B5-456F-A201-73065652D099} [-] Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6E727987-C8EA-44DA-8749-310C0FBE3C3E} [-] Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8E8F97CD-60B5-456F-A201-73065652D099} [-] Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8E8F97CD-60B5-456F-A201-73065652D099} [-] Value deleted: HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{6E727987-C8EA-44DA-8749-310C0FBE3C3E}] [-] Key deleted: HKU\.DEFAULT\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA} [-] Key deleted: HKU\S-1-5-21-2784700871-1142390347-2527291130-1000\Software\AceStream [-] Key deleted: HKU\S-1-5-21-2784700871-1142390347-2527291130-1000\Software\APN PIP [-] Key deleted: HKU\S-1-5-21-2784700871-1142390347-2527291130-1000\Software\cain [-] Key deleted: HKU\S-1-5-21-2784700871-1142390347-2527291130-1000\Software\InstallCore [-] Key deleted: HKU\S-1-5-21-2784700871-1142390347-2527291130-1000\Software\Installer [-] Key deleted: HKU\S-1-5-21-2784700871-1142390347-2527291130-1000\Software\Super Optimizer [-] Key deleted: HKU\S-1-5-21-2784700871-1142390347-2527291130-1000\Software\WEBAPP [-] Key deleted: HKU\S-1-5-21-2784700871-1142390347-2527291130-1000\Software\osTip [-] Key deleted: HKU\S-1-5-21-2784700871-1142390347-2527291130-1000\Software\Mail.Ru [-] Key deleted: HKU\S-1-5-21-2784700871-1142390347-2527291130-1000\Software\Amigo [-] Key deleted: HKU\S-1-5-21-2784700871-1142390347-2527291130-1000\Software\systweak [-] Key deleted: HKU\S-1-5-21-2784700871-1142390347-2527291130-1000\Software\UCBrowserPID [-] Key deleted: HKU\S-1-5-21-2784700871-1142390347-2527291130-1000\Software\AutoTime [-] Key deleted: HKU\S-1-5-21-2784700871-1142390347-2527291130-1000\Software\KuaiZip [-] Key deleted: HKU\S-1-5-21-2784700871-1142390347-2527291130-1000\Software\SNDA [-] Key deleted: HKU\S-1-5-21-2784700871-1142390347-2527291130-1000\Software\KuaiZipSFX [-] Key deleted: HKU\S-1-5-21-2784700871-1142390347-2527291130-1000\Software\Maoha [-] Key deleted: HKU\S-1-5-21-2784700871-1142390347-2527291130-1000\Software\Ludashi [-] Key deleted: HKU\S-1-5-21-2784700871-1142390347-2527291130-1000\Software\SaFiPlayer [-] Key deleted: HKU\S-1-5-21-2784700871-1142390347-2527291130-1000\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA} [-] Key deleted: HKU\S-1-5-21-2784700871-1142390347-2527291130-1000\Software\AppDataLow\Software\Mail.Ru [-] Key deleted: HKU\S-1-5-21-2784700871-1142390347-2527291130-1000\Software\Microsoft\Windows\CurrentVersion\Uninstall\AceStream [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-2784700871-1142390347-2527291130-1000\Software\webget [#] Key deleted on reboot: HKU\S-1-5-18\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA} [#] Key deleted on reboot: HKCU\Software\AceStream [#] Key deleted on reboot: HKCU\Software\APN PIP [#] Key deleted on reboot: HKCU\Software\cain [#] Key deleted on reboot: HKCU\Software\InstallCore [#] Key deleted on reboot: HKCU\Software\Installer [#] Key deleted on reboot: HKCU\Software\Super Optimizer [#] Key deleted on reboot: HKCU\Software\WEBAPP [#] Key deleted on reboot: HKCU\Software\osTip [#] Key deleted on reboot: HKCU\Software\Mail.Ru [#] Key deleted on reboot: HKCU\Software\Amigo [#] Key deleted on reboot: HKCU\Software\systweak [#] Key deleted on reboot: HKCU\Software\UCBrowserPID [#] Key deleted on reboot: HKCU\Software\AutoTime [#] Key deleted on reboot: HKCU\Software\KuaiZip [#] Key deleted on reboot: HKCU\Software\SNDA [#] Key deleted on reboot: HKCU\Software\KuaiZipSFX [#] Key deleted on reboot: HKCU\Software\Maoha [#] Key deleted on reboot: HKCU\Software\Ludashi [#] Key deleted on reboot: HKCU\Software\SaFiPlayer [#] Key deleted on reboot: HKCU\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA} [#] Key deleted on reboot: HKCU\Software\AppDataLow\Software\Mail.Ru [-] Key deleted: HKLM\SOFTWARE\{12A61307-94CD-4F8E-94BC-918E511FAA81} [-] Key deleted: HKLM\SOFTWARE\{12DA0E6F-5543-440C-BAA2-28BF01070AFA} [-] Key deleted: HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0} [-] Key deleted: HKLM\SOFTWARE\Registry Helper [-] Key deleted: HKLM\SOFTWARE\sweet-pageSoftware [-] Key deleted: HKLM\SOFTWARE\Mail.Ru [-] Key deleted: HKLM\SOFTWARE\systweak [-] Key deleted: HKLM\SOFTWARE\UCBrowserPID [-] Key deleted: HKLM\SOFTWARE\Maoha [-] Key deleted: HKLM\SOFTWARE\Microleaves [-] Key deleted: HKLM\SOFTWARE\SaFiPlayer [#] Key deleted on reboot: HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\AceStream [-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2DF3E224-05CD-4113-AA7A-86F2F6607B46} [-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{37476589-E48E-439E-A706-56189E2ED4C4}_is1 [-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{53B21E29-3967-C332-57EB-C02631658584} [-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7304C9D1-98AD-55F0-636E-22D8DD57F176} [-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9D9BEFAE-9499-F52B-6CC4-94818CCC2AB5} [-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A3FC46A0-9B62-0EF3-B475-743B3A2762B1} [-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AD11DADE-C597-45D9-D8C5-1D2EB0B89613} [-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B5DB572D-EA87-D3B0-08F6-4D153EA6A783} [-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B696F285-F54E-2524-58B1-E06A70ABE6BE} [-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\sweet-page uninstaller [-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ContentPush [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-2784700871-1142390347-2527291130-1000\Software\webget [#] Key deleted on reboot: [x64] HKCU\Software\AceStream [#] Key deleted on reboot: [x64] HKCU\Software\APN PIP [#] Key deleted on reboot: [x64] HKCU\Software\cain [#] Key deleted on reboot: [x64] HKCU\Software\InstallCore [#] Key deleted on reboot: [x64] HKCU\Software\Installer [#] Key deleted on reboot: [x64] HKCU\Software\Super Optimizer [#] Key deleted on reboot: [x64] HKCU\Software\WEBAPP [#] Key deleted on reboot: [x64] HKCU\Software\osTip [#] Key deleted on reboot: [x64] HKCU\Software\Mail.Ru [#] Key deleted on reboot: [x64] HKCU\Software\Amigo [#] Key deleted on reboot: [x64] HKCU\Software\systweak [#] Key deleted on reboot: [x64] HKCU\Software\UCBrowserPID [#] Key deleted on reboot: [x64] HKCU\Software\AutoTime [#] Key deleted on reboot: [x64] HKCU\Software\KuaiZip [#] Key deleted on reboot: [x64] HKCU\Software\SNDA [#] Key deleted on reboot: [x64] HKCU\Software\KuaiZipSFX [#] Key deleted on reboot: [x64] HKCU\Software\Maoha [#] Key deleted on reboot: [x64] HKCU\Software\Ludashi [#] Key deleted on reboot: [x64] HKCU\Software\SaFiPlayer [#] Key deleted on reboot: [x64] HKCU\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA} [#] Key deleted on reboot: [x64] HKCU\Software\AppDataLow\Software\Mail.Ru [-] Key deleted: [x64] HKLM\SOFTWARE\UCBrowser [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\AceStream [-] Data restored: HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL] [-] Data restored: HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] [-] Data restored: HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] [-] Data restored: [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL] [-] Data restored: [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] [-] Data restored: [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] [-] Key deleted: HKU\S-1-5-21-2784700871-1142390347-2527291130-1000\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} [-] Key deleted: HKU\S-1-5-21-2784700871-1142390347-2527291130-1000\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} [-] Key deleted: HKU\S-1-5-21-2784700871-1142390347-2527291130-1000\Software\Microsoft\Internet Explorer\SearchScopes\{FFEBBF0A-C22C-4172-89FF-45215A135AC7} [#] Key deleted on reboot: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} [#] Key deleted on reboot: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} [#] Key deleted on reboot: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{FFEBBF0A-C22C-4172-89FF-45215A135AC7} [-] Key deleted: HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} [-] Data restored: HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes [DefaultScope] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [-] Key deleted: HKCU\Software\Policies\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} [-] Key deleted: HKCU\Software\Policies\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} [-] Key deleted: HKCU\Software\Policies\Microsoft\Internet Explorer\SearchScopes\{FFEBBF0A-C22C-4172-89FF-45215A135AC7} [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{FFEBBF0A-C22C-4172-89FF-45215A135AC7} [-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} [-] Data restored: [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes [DefaultScope] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [#] Key deleted on reboot: [x64] HKCU\Software\Policies\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} [#] Key deleted on reboot: [x64] HKCU\Software\Policies\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} [#] Key deleted on reboot: [x64] HKCU\Software\Policies\Microsoft\Internet Explorer\SearchScopes\{FFEBBF0A-C22C-4172-89FF-45215A135AC7} [-] Data restored: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon [Userinit] C:\Windows\system32\userinit.exe, [-] Data restored: [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon [Userinit] C:\Windows\system32\userinit.exe, [-] Data restored: HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{623D40B1-D9A5-4757-9CB8-14FD1DBEB16D} [NameServer] [-] Data restored: HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{F11485CC-B4BD-4341-9107-CF26A3CEB67D} [NameServer] [-] Data restored: [x64] HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{623D40B1-D9A5-4757-9CB8-14FD1DBEB16D} [NameServer] [-] Data restored: [x64] HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{F11485CC-B4BD-4341-9107-CF26A3CEB67D} [NameServer] [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\bestpriceninja.com [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\pstatic.bestpriceninja.com [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\watch4.com [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\watch4.de [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.watch4.com [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.watch4.de [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\bestpriceninja.com [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\calcitapp.info [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\cmptch.com [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\eshopcomp.com [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\gboxapp.com [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\inst.shoppingate.info [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\land.pckeeper.software [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\nps.pastaleads.com [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\pastaleads.com [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\pckeeper.software [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\pricepeep.net [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\pstatic.bestpriceninja.com [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\pstatic.eshopcomp.com [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\re-markable.net [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\re-markit.co [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\reimageplus.com [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\search.gboxapp.com [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\shoppingate.info [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\static.cmptch.com [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\static.pricepeep00.pricepeep.net [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\static.re-markable00.re-markable.net [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\static.re-markit00.re-markit.co [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\staticimgfarm.com [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\sweet-page.com [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\ttdetect.staticimgfarm.com [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\utop.it [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\watch4.de [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\websearch.calcitapp.info [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.sweet-page.com [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.watch4.de [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\bestpriceninja.com [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\pstatic.bestpriceninja.com [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\watch4.com [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\watch4.de [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.watch4.com [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.watch4.de [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\bestpriceninja.com [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\calcitapp.info [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\cmptch.com [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\eshopcomp.com [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\gboxapp.com [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\inst.shoppingate.info [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\land.pckeeper.software [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\nps.pastaleads.com [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\pastaleads.com [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\pckeeper.software [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\pricepeep.net [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\pstatic.bestpriceninja.com [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\pstatic.eshopcomp.com [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\re-markable.net [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\re-markit.co [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\reimageplus.com [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\search.gboxapp.com [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\shoppingate.info [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\static.cmptch.com [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\static.pricepeep00.pricepeep.net [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\static.re-markable00.re-markable.net [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\static.re-markit00.re-markit.co [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\staticimgfarm.com [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\sweet-page.com [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\ttdetect.staticimgfarm.com [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\utop.it [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\watch4.de [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\websearch.calcitapp.info [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.sweet-page.com [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.watch4.de [-] Value deleted: HKU\S-1-5-21-2784700871-1142390347-2527291130-1000\Software\Microsoft\Windows\CurrentVersion\Run [apphide] [#] Value deleted on reboot: HKCU\Software\Microsoft\Windows\CurrentVersion\Run [apphide] [#] Value deleted on reboot: [x64] HKCU\Software\Microsoft\Windows\CurrentVersion\Run [apphide] [-] Value deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [Registry Helper] [-] Value deleted: HKU\S-1-5-21-2784700871-1142390347-2527291130-1000\Software\Microsoft\Windows\CurrentVersion\Run [osmsg] [#] Value deleted on reboot: HKCU\Software\Microsoft\Windows\CurrentVersion\Run [osmsg] [#] Value deleted on reboot: [x64] HKCU\Software\Microsoft\Windows\CurrentVersion\Run [osmsg] [-] Value deleted: HKU\S-1-5-21-2784700871-1142390347-2527291130-1000\Software\Microsoft\Windows\CurrentVersion\Run [msiql] [#] Value deleted on reboot: HKCU\Software\Microsoft\Windows\CurrentVersion\Run [msiql] [#] Value deleted on reboot: [x64] HKCU\Software\Microsoft\Windows\CurrentVersion\Run [msiql] [-] Value deleted: HKU\S-1-5-21-2784700871-1142390347-2527291130-1000\Software\Microsoft\Windows\CurrentVersion\Run [svchost0] [#] Value deleted on reboot: HKCU\Software\Microsoft\Windows\CurrentVersion\Run [svchost0] [#] Value deleted on reboot: [x64] HKCU\Software\Microsoft\Windows\CurrentVersion\Run [svchost0] [-] Key deleted: HKCU\Software\Classes\Applications\ace_player.exe [-] Key deleted: HKCU\Software\Classes\AudioCD\shell\PlayWithACEStream [-] Key deleted: HKCU\Software\Classes\DVD\shell\PlayWithACEStream [-] Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\ACEStreamPlayCDAudioOnArrival [-] Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\ACEStreamPlayDVDAudioOnArrival [-] Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\ACEStreamPlayDVDMovieOnArrival [-] Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\ACEStreamPlayMusicFilesOnArrival [-] Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\ACEStreamPlaySVCDMovieOnArrival [-] Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\ACEStreamPlayVCDMovieOnArrival [-] Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\ACEStreamPlayVideoFilesOnArrival [-] Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.acelive [-] Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.acemedia [-] Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.acestream [-] Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tslive [-] Key deleted: HKLM\SOFTWARE\Classes\AppID\BabylonHelper.EXE [-] Key deleted: HKLM\SOFTWARE\MICROSOFT\SYSTEMCERTIFICATES\ROOT\CERTIFICATES\26D9E607FFF0C58C7844B47FF8B6E079E5A2220E [#] Key deleted on reboot: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.acelive [#] Key deleted on reboot: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.acemedia [#] Key deleted on reboot: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.acestream [#] Key deleted on reboot: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tslive [#] Key deleted on reboot: HKCU\SOFTWARE\Classes\Applications\ace_player.exe [-] Value deleted: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost [kuaizipupdatesvc] [-] Key deleted: HKLM\SOFTWARE\Classes\Drive\shellex\ContextMenuHandlers\KuaiZipShlExt [-] Key deleted: HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\KuaiZipShlExt [-] Key deleted: HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\KuaiZipShlExt [-] Value deleted: HKLM\SOFTWARE\Mozilla\Firefox\Extensions [ocr@babylon.com] [-] Value deleted: HKCU\Software\Mozilla\Firefox\Extensions [acewebextension_unlisted@acestream.org] [#] Value deleted on reboot: [x64] HKCU\Software\Mozilla\Firefox\Extensions [acewebextension_unlisted@acestream.org] [#] Value deleted on reboot: HKCU\Software\Mozilla\Firefox\Extensions [acewebextension_unlisted@acestream.org] [#] Value deleted on reboot: [x64] HKCU\Software\Mozilla\Firefox\Extensions [acewebextension_unlisted@acestream.org] [#] Value deleted on reboot: HKLM\SOFTWARE\Mozilla\Firefox\Extensions [ocr@babylon.com] [#] Value deleted on reboot: HKCU\Software\Mozilla\Firefox\Extensions [acewebextension_unlisted@acestream.org] [#] Value deleted on reboot: [x64] HKCU\Software\Mozilla\Firefox\Extensions [acewebextension_unlisted@acestream.org] [#] Value deleted on reboot: HKCU\Software\Mozilla\Firefox\Extensions [acewebextension_unlisted@acestream.org] [#] Value deleted on reboot: [x64] HKCU\Software\Mozilla\Firefox\Extensions [acewebextension_unlisted@acestream.org] [#] Value deleted on reboot: HKLM\SOFTWARE\Mozilla\Firefox\Extensions [ocr@babylon.com] [#] Value deleted on reboot: HKCU\Software\Mozilla\Firefox\Extensions [acewebextension_unlisted@acestream.org] [#] Value deleted on reboot: [x64] HKCU\Software\Mozilla\Firefox\Extensions [acewebextension_unlisted@acestream.org] [#] Value deleted on reboot: HKCU\Software\Mozilla\Firefox\Extensions [acewebextension_unlisted@acestream.org] [#] Value deleted on reboot: [x64] HKCU\Software\Mozilla\Firefox\Extensions [acewebextension_unlisted@acestream.org] ***** [ Web browsers ] ***** ************************* :: "Tracing" keys deleted :: Winsock settings cleared ************************* C:\AdwCleaner\AdwCleaner[C0].txt - [40329 Bytes] - [03/01/2017 17:51:10] C:\AdwCleaner\AdwCleaner[S0].txt - [37980 Bytes] - [03/01/2017 17:42:27] C:\AdwCleaner\AdwCleaner[S1].txt - [38094 Bytes] - [03/01/2017 17:46:20] ########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [40551 Bytes] ##########