# AdwCleaner v5.013 - Logfile created 14/10/2015 at 19:57:58 # Updated 09/10/2015 by Xplode # Database : 2015-10-13.2 [Server] # Operating system : Windows 7 Ultimate (x86) # Username : Elke - ELKE-PC # Running from : C:\Users\Elke\Documents\adwcleaner_5.013.exe # Option : Cleaning # Support : http://toolslib.net/forum ***** [ Services ] ***** [-] Service Deleted : globalUpdate [-] Service Deleted : globalUpdatem [-] Service Deleted : SSFK [-] Service Deleted : WdsManPro [-] Service Deleted : ihpmServer [-] Service Deleted : dijojyvi [-] Service Deleted : fudiziti [-] Service Deleted : kilibyti [-] Service Deleted : swsedrvr_vt_1_10_0_25 ***** [ Folders ] ***** [-] Folder Deleted : C:\Program Files\globalUpdate [-] Folder Deleted : C:\Program Files\predm [-] Folder Deleted : C:\Program Files\SFK [-] Folder Deleted : C:\Program Files\RayDld [-] Folder Deleted : C:\Program Files\4BCFE6DC-1444835490-5B3F-8A7F-C5AD01251115 [-] Folder Deleted : C:\ProgramData\Convertor [-] Folder Deleted : C:\ProgramData\4WdsManPro4 [-] Folder Deleted : C:\ProgramData\nWdsManPron [-] Folder Deleted : C:\ProgramData\rWdsManPror [-] Folder Deleted : C:\ProgramData\XWdsManProX [-] Folder Deleted : C:\Users\Elke\AppData\Local\globalUpdate [-] Folder Deleted : C:\Users\Elke\AppData\Local\SmartWeb [-] Folder Deleted : C:\Users\Elke\AppData\Local\MalwareProtectionLive [-] Folder Deleted : C:\Users\Elke\AppData\Local\28484 [-] Folder Deleted : C:\Users\Elke\AppData\Local\4BCFE6DC-1444842746-5B3F-8A7F-C5AD01251115 [-] Folder Deleted : C:\Users\Elke\AppData\Local\Temp\wizz [-] Folder Deleted : C:\Users\Elke\AppData\Roaming\istartsurf [-] Folder Deleted : C:\Users\Elke\AppData\Roaming\mystartsearch [-] Folder Deleted : C:\Users\Elke\AppData\Roaming\Mozilla\Firefox\Profiles\prwxdqng.default\Extensions\deskCutv2@gmail.com [-] Folder Deleted : C:\Users\Elke\AppData\Roaming\Mozilla\Firefox\Profiles\prwxdqng.default\Extensions\defsearchp@gmail.com ***** [ Files ] ***** [-] File Deleted : C:\END [-] File Deleted : C:\Users\Elke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Malware Protection Live.lnk [-] File Deleted : C:\Users\Elke\AppData\Roaming\Mozilla\Firefox\Profiles\prwxdqng.default\Extensions\jid0-zs24wecdcQo0Lp18D7QOV4WSZFo@jetpack.xpi [-] File Deleted : C:\Users\Elke\AppData\Roaming\Mozilla\Firefox\Profiles\prwxdqng.default\searchplugins\istartsurf.xml [-] File Deleted : C:\Users\Elke\AppData\Roaming\Mozilla\Firefox\Profiles\prwxdqng.default\searchplugins\mystartsearch.xml [-] File Deleted : C:\Users\Elke\AppData\Roaming\Mozilla\Firefox\Profiles\prwxdqng.default\searchplugins\oursurfing.xml [-] File Deleted : C:\Users\Elke\Desktop\Continue Live Installation.lnk [-] File Deleted : C:\Windows\system32\drivers\{b666938f-73a7-45e6-be3c-578b46fc5b7e}Gw.sys ***** [ DLLs ] ***** ***** [ Shortcuts ] ***** [-] Shortcut Disinfected : C:\Users\Public\Desktop\Google Chrome.lnk [-] Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk [-] Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk [-] Shortcut Disinfected : C:\Users\Elke\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk [-] Shortcut Disinfected : C:\Users\Elke\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk ***** [ Scheduled tasks ] ***** [-] Task Deleted : globalUpdateUpdateTaskMachineCore [-] Task Deleted : globalUpdateUpdateTaskMachineUA [-] Task Deleted : SmartWeb Upgrade Trigger Task [-] Task Deleted : WinKit [-] Task Deleted : amiupdaterExd [-] Task Deleted : amiupdaterExi [-] Task Deleted : globalUpdateUpdateTaskMachineCore [-] Task Deleted : globalUpdateUpdateTaskMachineUA ***** [ Registry ] ***** [-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10 [-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine [-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0 [-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4 [-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync [-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0 [-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass [-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1 [-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass [-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1 [-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine [-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0 [-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine [-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0 [-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback [-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0 [-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc [-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0 [-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher [-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0 [-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService [-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0 [-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine [-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0 [-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback [-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0 [-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc [-] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0 [-] Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho [-] Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1 [-] Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10 [-] Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4 [-] Key Deleted : HKCU\Software\Mozilla\Extends [-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\globalupdate.exe [-] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [SpaceSoundPro] [-] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [MalwareProtectionLive] [-] Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WdsManPro [-] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [mbot_be_014010113] [-] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [gmsd_be_005010111] [-] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [rec_en_77] [-] Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [deskCutv2@gmail.com] [-] Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [defsearchp@gmail.com] [-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492} [-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52} [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492} [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978} [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298} [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52} [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1} [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30} [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7} [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61} [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87} [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5} [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474} [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A} [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC} [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F} [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A} [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C} [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78} [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6EDBF8C0-C94C-4A13-956F-E393BCA5BA4B} [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A8F7D0A5-7074-40B8-9BDC-1174BDD0A132} [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D14D64BC-A0E4-42E3-BB72-FB41EA43C198} [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DD1F043F-ABC8-4643-8B95-D2C5B22BB019} [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E3F3E8F9-F747-4DD6-BA6B-82A6CE1E0860} [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{ED0B64D4-BF27-4521-AD27-190F49BF5EA7} [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{023E9EC8-B147-40EB-B0B3-DF90618FB371} [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0522D9A4-4D57-437D-978D-E5B3B6C9005D} [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{07F41522-AF7D-4F26-B394-094F059FDB8A} [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0C40F472-7407-4467-8914-1DEA7C326972} [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{212E6D43-6062-492A-B8CC-144669FF11ED} [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{224FE662-1E6D-4BC0-AEBB-9E2FB4057BE9} [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3A807417-B46D-4D37-8C9A-19AC6DE204F9} [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3CC60715-D6C5-429D-830E-43FA3F86C61D} [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4517D94C-19BA-46FA-BE66-2A30CEAC4A85} [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{555D7146-94A8-4C94-AE76-C39CDC7F7705} [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{59D188FA-757A-424E-8C93-F58FFD896BD7} [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8120D9D6-785C-4413-9C0C-DF2028C56FAD} [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{823AE2EB-E62C-4847-B192-C99B91B92416} [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9B4F7CFE-987D-410E-A8E4-20182E0B3C24} [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9B9A45F4-18FC-484A-BACA-076D78273D8E} [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A6D54287-7939-466A-8579-92546D946C8C} [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A78EDAFB-926F-4D93-AB13-8232D7378EB1} [-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{54739D49-AC03-4C57-9264-C5195596B3A1} [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{5645E0E7-FC12-43BF-A6E4-F9751942B298} [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A} [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298} [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A} [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298} [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1} [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A} [-] Key Deleted : HKU\.DEFAULT\Software\AppDataLow\Software\_CrossriderRegNamePlaceHolder_ [-] Key Deleted : HKCU\Software\GlobalUpdate [-] Key Deleted : HKCU\Software\MyBestOffersToday [-] Key Deleted : HKCU\Software\TutoTag [-] Key Deleted : HKCU\Software\Super Optimizer [-] Key Deleted : HKCU\Software\Crossbrowse [-] Key Deleted : HKCU\Software\Linkey [-] Key Deleted : HKCU\Software\YorkNewCin [-] Key Deleted : HKCU\Software\HighDefAction [-] Key Deleted : HKCU\Software\ArenaHD [-] Key Deleted : HKCU\Software\DAILYPCCLEAN [-] Key Deleted : HKCU\Software\PDFConvert [-] Key Deleted : HKCU\Software\WEBAPP [-] Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider [-] Key Deleted : HKLM\SOFTWARE\AppDataLow\SOFTWARE\Crossrider [-] Key Deleted : HKLM\SOFTWARE\AppDataLow\SOFTWARE\_CrossriderRegNamePlaceHolder_ [-] Key Deleted : HKLM\SOFTWARE\GlobalUpdate [-] Key Deleted : HKLM\SOFTWARE\istartsurfSoftware [-] Key Deleted : HKLM\SOFTWARE\Tutorials [-] Key Deleted : HKLM\SOFTWARE\mystartsearchSoftware [-] Key Deleted : HKLM\SOFTWARE\Crossbrowse [-] Key Deleted : HKLM\SOFTWARE\YorkNewCin [-] Key Deleted : HKLM\SOFTWARE\HighDefAction [-] Key Deleted : HKLM\SOFTWARE\oursurfingSoftware [-] Key Deleted : HKLM\SOFTWARE\ArenaHD [-] Key Deleted : HKLM\SOFTWARE\FFPluginHp [-] Key Deleted : HKLM\SOFTWARE\WdsManPro [-] Key Deleted : HKLM\SOFTWARE\RayDld [-] Key Deleted : HKLM\SOFTWARE\ihpmserver [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VOPackage [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7ADF667E-E14D-4D2C-827C-B0108F0D93BC} [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MalwareProtectionLive [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SU [!] Key Not Deleted : HKU\.DEFAULT\Software\AppDataLow\Software\_CrossriderRegNamePlaceHolder_ [!] Key Not Deleted : HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\AppDataLow\Software\_CrossriderRegNamePlaceHolder_ [!] Key Not Deleted : HKU\S-1-5-21-2414527585-3944006083-3816331441-1000\Software\AppDataLow\Software\Crossrider [!] Key Not Deleted : HKU\S-1-5-21-2414527585-3944006083-3816331441-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\AppDataLow\Software\Crossrider [!] Key Not Deleted : HKU\S-1-5-18\Software\AppDataLow\Software\_CrossriderRegNamePlaceHolder_ [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GLOBALUPDATE.EXE [-] Data Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] [-] Data Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL] [-] Data Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] [-] Data Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] [-] Data Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL] [-] Data Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL] [-] Data Restored : HKU\S-1-5-21-2414527585-3944006083-3816331441-1000\Software\Microsoft\Internet Explorer\Main [Start Page] [-] Data Restored : HKU\S-1-5-21-2414527585-3944006083-3816331441-1000\Software\Microsoft\Internet Explorer\Main [Default_Page_URL] [!] Data Not Restored : HKU\S-1-5-21-2414527585-3944006083-3816331441-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main [Start Page] [!] Data Not Restored : HKU\S-1-5-21-2414527585-3944006083-3816331441-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main [Default_Page_URL] [-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} [-] Data Restored : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope] [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} [-] Data Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes [DefaultScope] [!] Key Not Deleted : HKU\S-1-5-21-2414527585-3944006083-3816331441-1000\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} [-] Data Restored : HKU\S-1-5-21-2414527585-3944006083-3816331441-1000\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope] [!] Key Not Deleted : HKU\S-1-5-21-2414527585-3944006083-3816331441-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} [!] Data Not Restored : HKU\S-1-5-21-2414527585-3944006083-3816331441-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope] [-] Data Restored : HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command [] [-] Data Restored : HKLM\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command [] ***** [ Web browsers ] ***** [-] [C:\Users\Elke\AppData\Roaming\Mozilla\Firefox\Profiles\prwxdqng.default\prefs.js] [Preference] Deleted : user_pref("browser.newtab.url", "chrome://quick_start/content/index.html"); [-] [C:\Users\Elke\AppData\Roaming\Mozilla\Firefox\Profiles\prwxdqng.default\prefs.js] [Preference] Deleted : user_pref("browser.search.defaultenginename", "istartsurf"); [-] [C:\Users\Elke\AppData\Roaming\Mozilla\Firefox\Profiles\prwxdqng.default\prefs.js] [Preference] Deleted : user_pref("browser.search.selectedEngine", "istartsurf"); [-] [C:\Users\Elke\AppData\Roaming\Mozilla\Firefox\Profiles\prwxdqng.default\prefs.js] [Preference] Deleted : user_pref("browser.startup.homepage", "hxxp://www.istartsurf.com/?type=hp&ts=1444838545&z=c6cad46ab87c559b3585ef8gczdz3z1bac6bcc1g1t&from=face&uid=WDCXWD800JD-08MSA1_WD-WMAM9ZV7840778407"); [-] [C:\Users\Elke\AppData\Roaming\Mozilla\Firefox\Profiles\prwxdqng.default\prefs.js] [Preference] Deleted : user_pref("extensions.crossrider.bic", "15066e48809318cf9e15ea66ba253175"); [-] [C:\Users\Elke\AppData\Roaming\Mozilla\Firefox\Profiles\prwxdqng.default\prefs.js] [Preference] Deleted : user_pref("extensions.quick_start.enable_search1", false); [-] [C:\Users\Elke\AppData\Roaming\Mozilla\Firefox\Profiles\prwxdqng.default\prefs.js] [Preference] Deleted : user_pref("extensions.quick_start.sd.closeWindowWithLastTab_prev_state", false); ************************* :: Winsock settings cleared ########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [18457 bytes] ########## # AdwCleaner v5.036 - Logfile created 22/02/2016 at 13:50:32 # Updated 22/02/2016 by Xplode # Database : 2016-02-22.1 [Server] # Operating system : Windows 7 Ultimate (x86) # Username : Elke - ELKE-PC # Running from : C:\Users\Elke\Downloads\adwcleaner_5.036.exe # Option : Cleaning # Support : http://toolslib.net/forum ***** [ Services ] ***** ***** [ Folders ] ***** [-] Folder Deleted : C:\ProgramData\ab5b5a28-5387-1 [-] Folder Deleted : C:\ProgramData\ab5b5a28-60f3-0 ***** [ Files ] ***** [-] File Deleted : C:\Users\Elke\AppData\Roaming\Mozilla\Firefox\Profiles\prwxdqng.default\user.js [-] File Deleted : C:\Windows\system32\lavasofttcpservice.dll [-] File Deleted : C:\Windows\system32\LavasoftTcpServiceOff.ini ***** [ DLLs ] ***** ***** [ Shortcuts ] ***** ***** [ Scheduled tasks ] ***** ***** [ Registry ] ***** [-] Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\bopakagnckmlgajfccecajhnimjiiedh [-] Key Deleted : HKCU\Software\gameo [-] Key Deleted : HKCU\Software\GoldenGate [-] Key Deleted : HKCU\Software\Microsoft\Tinstalls [-] Key Deleted : HKCU\Software\PRODUCTSETUP [-] Key Deleted : HKCU\Software\tstamptoken [-] Key Deleted : HKLM\SOFTWARE\Uniblue [-] Key Deleted : HKLM\SOFTWARE\Classes\AndyAPK [-] Key Deleted : HKLM\SOFTWARE\Classes\AndyApp ***** [ Web browsers ] ***** ************************* :: "Tracing" keys removed :: Winsock settings cleared ************************* C:\AdwCleaner\AdwCleaner[C1].txt - [20021 bytes] - [14/10/2015 18:57:58] C:\AdwCleaner\AdwCleaner[S1].txt - [21632 bytes] - [14/10/2015 18:50:46] C:\AdwCleaner\AdwCleaner[S2].txt - [20022 bytes] - [14/10/2015 18:53:37] ########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [20243 bytes] ##########