# AdwCleaner 7.0.1.0 - Logfile created on Sun Aug 20 18:52:21 2017 # Updated on 2017/05/08 by Malwarebytes # Running on Windows 8.1 (X64) # Mode: clean # Support: https://www.malwarebytes.com/support ***** [ Services ] ***** No malicious services deleted. ***** [ Folders ] ***** Deleted: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverToolkit Deleted: C:\Program Files (x86)\DriverToolkit Deleted: C:\ProgramData\Performancer Deleted: C:\ProgramData\Application Data\Performancer Deleted: C:\Users\All Users\Performancer Deleted: C:\ProgramData\IObit\ASCDownloader Deleted: C:\ProgramData\Application Data\IObit\ASCDownloader Deleted: C:\Users\All Users\IObit\ASCDownloader Deleted: C:\Users\Maria Rita\AppData\Roaming\RHEng Deleted: C:\Users\Maria Rita\AppData\LocalLow\Smartbar Deleted: C:\Program Files (x86)\dowwnnllooaditKeep Deleted: C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 Deleted: C:\ProgramData\a950d1abba0e5ea3 Deleted: C:\ProgramData\doewnloadiitkiEepa Deleted: C:\ProgramData\dowwnnllooaditKeep Deleted: C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7 Deleted: C:\ProgramData\{324F76CC-D8DD-4D87-B77D-D4AF5E1AA7B3}.log Deleted: C:\ProgramData\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D} Deleted: C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log Deleted: C:\ProgramData\{B7A0CE06-068E-11D6-97FD-0050BACBF861}.log Deleted: C:\ProgramData\{D6E853EC-8960-4D44-AF03-7361BB93227C}.log Deleted: C:\ProgramData\{EAAB5A83-3809-4B0E-83A6-E4B0DBF2157E} ***** [ Files ] ***** Deleted: C:\Users\Maria Rita\AppData\Roaming\LiveSupport.exe_log.txt Deleted: C:\Users\Maria Rita\AppData\Roaming\regsvr32.exe_log.txt ***** [ DLL ] ***** No malicious DLLs cleaned. ***** [ WMI ] ***** No malicious WMI cleaned. ***** [ Shortcuts ] ***** No malicious shortcuts cleaned. ***** [ Tasks ] ***** No malicious tasks deleted. ***** [ Registry ] ***** Deleted: [Key] - HKLM\SOFTWARE\IOBIT\ASC Deleted: [Key] - HKLM\SOFTWARE\CLASSES\LNKFILE\SHELLEX\CONTEXTMENUHANDLERS\Advanced SystemCare Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\DOMStorage\ask.com Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\DOMStorage\nortonsafe.search.ask.com Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\DOMStorage\superfish.com Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.superfish.com Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\ask.com Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\azlyrics.com Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\cloudfront.net Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\cloudfront.net Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\d16fk4ms6rqz1v.cloudfront.net Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\d16fk4ms6rqz1v.cloudfront.net Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\d22j4fzzszoii2.cloudfront.net Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\d22j4fzzszoii2.cloudfront.net Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\d3jdlwnuo8nsnr.cloudfront.net Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\d3jdlwnuo8nsnr.cloudfront.net Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\dsms0mj1bbhn4.cloudfront.net Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\dsms0mj1bbhn4.cloudfront.net Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\dwq4do82y8xi7.cloudfront.net Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\dwq4do82y8xi7.cloudfront.net Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\nortonsafe.search.ask.com Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\reimageplus.com Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\reimageplus.com Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\solvusoft.com Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\staticimgfarm.com Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\superfish.com Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\videodownloadconverter.dl.tb.ask.com Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.azlyrics.com Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.solvusoft.com Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.superfish.com Deleted: [Key] - HKU\S-1-5-21-838929920-3368600397-1854171334-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Internet Explorer\DOMStorage\chatango.com Deleted: [Key] - HKU\S-1-5-21-838929920-3368600397-1854171334-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Internet Explorer\DOMStorage\cloudfront.net Deleted: [Key] - HKU\S-1-5-21-838929920-3368600397-1854171334-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Internet Explorer\DOMStorage\cloudfront.net Deleted: [Key] - HKU\S-1-5-21-838929920-3368600397-1854171334-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Internet Explorer\DOMStorage\d10lpsik1i8c69.cloudfront.net Deleted: [Key] - HKU\S-1-5-21-838929920-3368600397-1854171334-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Internet Explorer\DOMStorage\d10lpsik1i8c69.cloudfront.net Deleted: [Key] - HKU\S-1-5-21-838929920-3368600397-1854171334-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Internet Explorer\DOMStorage\d16fk4ms6rqz1v.cloudfront.net Deleted: [Key] - HKU\S-1-5-21-838929920-3368600397-1854171334-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Internet Explorer\DOMStorage\d16fk4ms6rqz1v.cloudfront.net Deleted: [Key] - HKU\S-1-5-21-838929920-3368600397-1854171334-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Internet Explorer\DOMStorage\d22j4fzzszoii2.cloudfront.net Deleted: [Key] - HKU\S-1-5-21-838929920-3368600397-1854171334-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Internet Explorer\DOMStorage\d22j4fzzszoii2.cloudfront.net Deleted: [Key] - HKU\S-1-5-21-838929920-3368600397-1854171334-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Internet Explorer\DOMStorage\st.chatango.com Deleted: [Key] - HKU\S-1-5-21-838929920-3368600397-1854171334-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Internet Explorer\DOMStorage\st.chatango.com Deleted: [Key] - HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B} Deleted: [Key] - HKU\S-1-5-21-838929920-3368600397-1854171334-1002\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B} Deleted: [Key] - HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B} Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1C52B8B6-FFA2-12F6-0A5A-E8301F96A568} Deleted: [Key] - HKU\S-1-5-21-838929920-3368600397-1854171334-1002\Software\DriverToolkit Deleted: [Key] - HKCU\Software\DriverToolkit Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D66BF89F-B0A2-48F5-A2E4-242EB645AB76}_is1 Deleted: [Key] - HKLM\SOFTWARE\{77D46E27-0E41-4478-87A6-AABE6FBCF252} Deleted: [Key] - HKLM\SOFTWARE\Uniblue Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{30C85A3D-1D96-4589-B63F-91FB7EF45A41} Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30C85A3D-1D96-4589-B63F-91FB7EF45A41} Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{30C85A3D-1D96-4589-B63F-91FB7EF45A41} Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{30C85A3D-1D96-4589-B63F-91FB7EF45A41} Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\{9C81D00A-3DAA-48AB-90C7-8252119ABB93} Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\{1DA17428-323D-48FF-857C-98CFEE48BFD5} Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{25A3A431-30BB-47C8-AD6A-E1063801134F} Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{25A3A431-30BB-47C8-AD6A-E1063801134F} Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25A3A431-30BB-47C8-AD6A-E1063801134F} Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{25A3A431-30BB-47C8-AD6A-E1063801134F} Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8F0B76E1-4E46-427B-B55B-B90593468AC6} Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8F0B76E1-4E46-427B-B55B-B90593468AC6} Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468} Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Deleted: [Key] - HKU\S-1-5-21-838929920-3368600397-1854171334-1002\Software\AppDataLow\Software\Crossrider Deleted: [Key] - HKU\S-1-5-21-838929920-3368600397-1854171334-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\Crossrider Deleted: [Key] - HKCU\Software\AppDataLow\Software\Crossrider Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\en.softonic.com Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\nitro-pro.nl.softonic.com Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\softonic.com Deleted: [Key] - HKU\S-1-5-21-838929920-3368600397-1854171334-1002\Software\AppDataLow\Software\Crossrider Deleted: [Key] - HKU\S-1-5-21-838929920-3368600397-1854171334-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\Crossrider Deleted: [Key] - HKCU\Software\AppDataLow\Software\Crossrider Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\DOMStorage\castplatform.com Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\DOMStorage\cdn.castplatform.com Deleted: [Key] - HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B} ***** [ Firefox (and derivatives) ] ***** No malicious Firefox entries deleted. ***** [ Chromium (and derivatives) ] ***** No malicious Chromium entries deleted. ************************* ::Tracing keys deleted ::Winsock settings cleared ::Additional Actions: 0 ************************* C:/AdwCleaner/AdwCleaner[S0].txt - [12651 B] - [2017/8/20 18:50:1] ########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt ##########