# AdwCleaner 7.0.8.0 - Logfile created on Wed Mar 21 21:23:27 2018 # Updated on 2018/08/02 by Malwarebytes # Running on Windows 10 Home (X64) # Mode: clean # Support: https://www.malwarebytes.com/support ***** [ Services ] ***** No malicious services deleted. ***** [ Folders ] ***** Deleted: C:\ProgramData\lavasoft\web companion Deleted: C:\ProgramData\Application Data\lavasoft\web companion Deleted: C:\Program Files (x86)\lavasoft\web companion Deleted: C:\Users\All Users\lavasoft\web companion Deleted: C:\Users\anja_\AppData\Roaming\lavasoft\web companion Deleted: C:\Users\Public\Pokki Deleted: C:\Users\anja_\AppData\Local\Host App Service Deleted: C:\Users\Default\AppData\Local\Host App Service Deleted: C:\Users\Default User\AppData\Local\Host App Service Deleted: C:\ProgramData\Booking.com Deleted: C:\ProgramData\Application Data\Booking.com Deleted: C:\Users\All Users\Booking.com Deleted: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft\WebCompanion ***** [ Files ] ***** Deleted: C:\Users\anja_\Desktop\eBay.lnk Deleted: C:\Users\Default\Desktop\eBay.lnk Deleted: C:\Users\Default User\Desktop\eBay.lnk ***** [ DLL ] ***** No malicious DLLs cleaned. ***** [ WMI ] ***** No malicious WMI cleaned. ***** [ Shortcuts ] ***** No malicious shortcuts cleaned. ***** [ Tasks ] ***** Deleted: App Explorer ***** [ Registry ] ***** Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\tweakbit.com Deleted: [Key] - HKLM\SOFTWARE\Lavasoft\Web Companion Deleted: [Key] - HKU\S-1-5-21-179002463-3422626409-1712273760-1001\Software\Lavasoft\Web Companion Deleted: [Key] - HKU\S-1-5-21-179002463-3422626409-1712273760-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-03212018214858107\Software\Lavasoft\Web Companion Deleted: [Key] - HKCU\Software\Lavasoft\Web Companion Deleted: [Value] - HKU\S-1-5-21-179002463-3422626409-1712273760-1001\Software\Microsoft\Windows\CurrentVersion\Run|Web Companion Deleted: [Value] - HKU\S-1-5-21-179002463-3422626409-1712273760-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run|Web Companion Deleted: [Value] - HKU\S-1-5-21-179002463-3422626409-1712273760-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-03212018214858107\Software\Microsoft\Windows\CurrentVersion\Run|Web Companion Deleted: [Value] - HKU\S-1-5-21-179002463-3422626409-1712273760-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-03212018214858107\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run|Web Companion Deleted: [Value] - HKCU\Software\Microsoft\Windows\CurrentVersion\Run|Web Companion Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com Deleted: [Key] - HKU\S-1-5-21-179002463-3422626409-1712273760-1001\Software\Host App Service Deleted: [Key] - HKU\S-1-5-21-179002463-3422626409-1712273760-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\Host App Service Deleted: [Key] - HKU\S-1-5-21-179002463-3422626409-1712273760-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-03212018214858107\Software\Host App Service Deleted: [Key] - HKU\S-1-5-21-179002463-3422626409-1712273760-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-03212018214858107\Software\Microsoft\Windows\CurrentVersion\Uninstall\Host App Service Deleted: [Key] - HKCU\Software\Host App Service Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Host App Service ***** [ Firefox (and derivatives) ] ***** No malicious Firefox entries deleted. ***** [ Chromium (and derivatives) ] ***** No malicious Chromium entries deleted. ************************* ::Tracing keys deleted ::Winsock settings cleared ::Additional Actions: 0 ************************* C:/AdwCleaner/AdwCleaner[S0].txt - [4132 B] - [2018/3/21 20:57:44] ########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt ##########