# AdwCleaner v6.046 - Logfile created 19/05/2017 at 15:31:06 # Updated on 24/04/2017 by Malwarebytes # Database : 2017-05-19.1 [Server] # Operating System : Windows 7 Home Premium Service Pack 1 (X64) # Username : paulinka - PAULINKA-TOSH # Running from : C:\Users\paulinka\Desktop\AdwCleaner.exe # Mode: Clean # Support : https://www.malwarebytes.com/support ***** [ Services ] ***** ***** [ Folders ] ***** [-] Folder deleted: C:\Users\paulinka\AppData\Local\Conduit [-] Folder deleted: C:\Users\paulinka\AppData\Local\FileViewPro [-] Folder deleted: C:\Users\paulinka\AppData\Local\globalUpdate [-] Folder deleted: C:\Users\paulinka\AppData\Local\PackageAware [-] Folder deleted: C:\Users\paulinka\AppData\LocalLow\Conduit [-] Folder deleted: C:\Users\paulinka\AppData\Roaming\Activeris [-] Folder deleted: C:\Users\paulinka\AppData\Roaming\Babylon [-] Folder deleted: C:\Users\paulinka\AppData\Roaming\Hola [-] Folder deleted: C:\Users\paulinka\AppData\Roaming\RPEng [-] Folder deleted: C:\Users\paulinka\AppData\Roaming\Solvusoft [-] Folder deleted: C:\Program Files\Hola [-] Folder deleted: C:\ProgramData\Babylon [-] Folder deleted: C:\ProgramData\DSearchLink [-] Folder deleted: C:\ProgramData\Partner [-] Folder deleted: C:\ProgramData\Tarma Installer [#] Folder deleted on reboot: C:\ProgramData\Application Data\Babylon [#] Folder deleted on reboot: C:\ProgramData\Application Data\DSearchLink [#] Folder deleted on reboot: C:\ProgramData\Application Data\Partner [#] Folder deleted on reboot: C:\ProgramData\Application Data\Tarma Installer [-] Folder deleted: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WajaInternetEn [-] Folder deleted: C:\Program Files (x86)\globalUpdate [-] Folder deleted: C:\Program Files (x86)\myfree codec [-] Folder deleted: C:\Program Files (x86)\predm [-] Folder deleted: C:\Users\paulinka\APPDATA\LOCALLOW\DELTA ***** [ Files ] ***** [-] File deleted: C:\Windows\SysNative\roboot64.exe [-] File deleted: C:\user.js ***** [ DLL ] ***** ***** [ WMI ] ***** ***** [ Shortcuts ] ***** ***** [ Scheduled Tasks ] ***** ***** [ Registry ] ***** [-] Value deleted: HKLM\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION [C:\Program Files (x86)\Plus-HD-9.1\Plus-HD-9.1-nova.exe] [-] Key deleted: HKCU\Software\5d53d988bd3abe14 [-] Key deleted: HKLM\SOFTWARE\5d53d988bd3abe14 [-] Key deleted: HKLM\SOFTWARE\Classes\Toolbar.CT3106777 [-] Key deleted: HKLM\SOFTWARE\Classes\OCComSDK.ComSDK [-] Key deleted: HKLM\SOFTWARE\Classes\OCComSDK.ComSDK.1 [-] Key deleted: HKLM\SOFTWARE\Classes\Prod.cap [-] Key deleted: HKLM\SOFTWARE\Classes\protector_dll.ProtectorBho [-] Key deleted: HKLM\SOFTWARE\Classes\protector_dll.ProtectorBho.1 [-] Key deleted: HKLM\SOFTWARE\Classes\SdcUser.SdcMailCtl [-] Key deleted: HKLM\SOFTWARE\Classes\SdcUser.SdcMailCtl.1 [#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\OCComSDK.ComSDK [#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\OCComSDK.ComSDK.1 [#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\Prod.cap [#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\protector_dll.ProtectorBho [#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\protector_dll.ProtectorBho.1 [#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\SdcUser.SdcMailCtl [#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\SdcUser.SdcMailCtl.1 [-] Key deleted: HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB} [-] Key deleted: HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3} [-] Key deleted: HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17} [-] Key deleted: HKCU\Software\Classes\CLSID\{BEBBC426-4F16-4567-8FE1-BE198C982027} [-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{B9D64D3B-BE75-4FA2-B94A-C4AE772A0146} [-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{47A1DF02-BCE4-40C3-AE47-E3EA09A65E4A} [-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5} [-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{FA7B2795-C0C8-4A58-8672-3F8D80CC0270} [-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{47A1DF02-BCE4-40C3-AE47-E3EA09A65E4A} [-] Key deleted: HKLM\SOFTWARE\Classes\TypeLib\{1112F282-7099-4624-A439-DB29D6551552} [-] Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} [-] Key deleted: HKU\.DEFAULT\Software\Hola [-] Key deleted: HKU\.DEFAULT\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F} [-] Key deleted: HKU\S-1-5-19\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F} [-] Key deleted: HKU\S-1-5-20\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F} [-] Key deleted: HKU\S-1-5-21-1822749172-3988503527-1915266406-1000\Software\APN PIP [-] Key deleted: HKU\S-1-5-21-1822749172-3988503527-1915266406-1000\Software\BABSOLUTION [-] Key deleted: HKU\S-1-5-21-1822749172-3988503527-1915266406-1000\Software\Cr_Installer [-] Key deleted: HKU\S-1-5-21-1822749172-3988503527-1915266406-1000\Software\DataMngr [-] Key deleted: HKU\S-1-5-21-1822749172-3988503527-1915266406-1000\Software\DataMngr_Toolbar [-] Key deleted: HKU\S-1-5-21-1822749172-3988503527-1915266406-1000\Software\dsiteproducts [-] Key deleted: HKU\S-1-5-21-1822749172-3988503527-1915266406-1000\Software\GlobalUpdate [-] Key deleted: HKU\S-1-5-21-1822749172-3988503527-1915266406-1000\Software\Hola [-] Key deleted: HKU\S-1-5-21-1822749172-3988503527-1915266406-1000\Software\InstallCore [-] Key deleted: HKU\S-1-5-21-1822749172-3988503527-1915266406-1000\Software\Softonic [-] Key deleted: HKU\S-1-5-21-1822749172-3988503527-1915266406-1000\Software\TutoTag [-] Key deleted: HKU\S-1-5-21-1822749172-3988503527-1915266406-1000\Software\WajIEnhance [-] Key deleted: HKU\S-1-5-21-1822749172-3988503527-1915266406-1000\Software\delta [#] Key deleted on reboot: HKU\S-1-5-21-1822749172-3988503527-1915266406-1000\Software\Datamngr [-] Key deleted: HKU\S-1-5-21-1822749172-3988503527-1915266406-1000\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F} [-] Key deleted: HKU\S-1-5-21-1822749172-3988503527-1915266406-1000\Software\AppDataLow\Software\Crossrider [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1822749172-3988503527-1915266406-1000\Software\SweetIM [#] Key deleted on reboot: HKU\S-1-5-18\Software\Hola [#] Key deleted on reboot: HKU\S-1-5-18\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F} [#] Key deleted on reboot: HKCU\Software\APN PIP [#] Key deleted on reboot: HKCU\Software\BABSOLUTION [#] Key deleted on reboot: HKCU\Software\Cr_Installer [#] Key deleted on reboot: HKCU\Software\DataMngr [#] Key deleted on reboot: HKCU\Software\DataMngr_Toolbar [#] Key deleted on reboot: HKCU\Software\dsiteproducts [#] Key deleted on reboot: HKCU\Software\GlobalUpdate [#] Key deleted on reboot: HKCU\Software\Hola [#] Key deleted on reboot: HKCU\Software\InstallCore [#] Key deleted on reboot: HKCU\Software\Softonic [#] Key deleted on reboot: HKCU\Software\TutoTag [#] Key deleted on reboot: HKCU\Software\WajIEnhance [#] Key deleted on reboot: HKCU\Software\delta [#] Key deleted on reboot: HKCU\Software\Datamngr [#] Key deleted on reboot: HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F} [#] Key deleted on reboot: HKCU\Software\AppDataLow\Software\Crossrider [-] Key deleted: HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F} [-] Key deleted: HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0} [-] Key deleted: HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C} [-] Key deleted: HKLM\SOFTWARE\Babylon [-] Key deleted: HKLM\SOFTWARE\BabylonToolbar [-] Key deleted: HKLM\SOFTWARE\Conduit [-] Key deleted: HKLM\SOFTWARE\DataMngr [-] Key deleted: HKLM\SOFTWARE\FreeSoftToday [-] Key deleted: HKLM\SOFTWARE\GlobalUpdate [-] Key deleted: HKLM\SOFTWARE\Taronja [-] Key deleted: HKLM\SOFTWARE\Tutorials [-] Key deleted: HKLM\SOFTWARE\V9Software [-] Key deleted: HKLM\SOFTWARE\WajaInternetEn [-] Key deleted: HKLM\SOFTWARE\delta [#] Key deleted on reboot: HKLM\SOFTWARE\Datamngr [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1822749172-3988503527-1915266406-1000\Software\SweetIM [#] Key deleted on reboot: [x64] HKCU\Software\APN PIP [#] Key deleted on reboot: [x64] HKCU\Software\BABSOLUTION [#] Key deleted on reboot: [x64] HKCU\Software\Cr_Installer [#] Key deleted on reboot: [x64] HKCU\Software\DataMngr [#] Key deleted on reboot: [x64] HKCU\Software\DataMngr_Toolbar [#] Key deleted on reboot: [x64] HKCU\Software\dsiteproducts [#] Key deleted on reboot: [x64] HKCU\Software\GlobalUpdate [#] Key deleted on reboot: [x64] HKCU\Software\Hola [#] Key deleted on reboot: [x64] HKCU\Software\InstallCore [#] Key deleted on reboot: [x64] HKCU\Software\Softonic [#] Key deleted on reboot: [x64] HKCU\Software\TutoTag [#] Key deleted on reboot: [x64] HKCU\Software\WajIEnhance [#] Key deleted on reboot: [x64] HKCU\Software\delta [#] Key deleted on reboot: [x64] HKCU\Software\Datamngr [#] Key deleted on reboot: [x64] HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F} [#] Key deleted on reboot: [x64] HKCU\Software\AppDataLow\Software\Crossrider [-] Key deleted: [x64] HKLM\SOFTWARE\Hola [-] Key deleted: [x64] HKLM\SOFTWARE\Tarma Installer [-] Key deleted: [x64] HKLM\SOFTWARE\WajaInternetEn [-] Key deleted: HKCU\Software\Google\Chrome\Extensions\bakijjialdiiboeaknfpmflphhmljfkd [-] Key deleted: HKLM\SOFTWARE\Google\Chrome\Extensions\bakijjialdiiboeaknfpmflphhmljfkd [#] Key deleted on reboot: [x64] HKCU\Software\Google\Chrome\Extensions\bakijjialdiiboeaknfpmflphhmljfkd [-] Key deleted: [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\bakijjialdiiboeaknfpmflphhmljfkd [-] Key deleted: HKCU\Software\Google\Chrome\Extensions\iagcajndpnfncplednpbnkahadegklfa [-] Key deleted: HKLM\SOFTWARE\Google\Chrome\Extensions\iagcajndpnfncplednpbnkahadegklfa [#] Key deleted on reboot: [x64] HKCU\Software\Google\Chrome\Extensions\iagcajndpnfncplednpbnkahadegklfa [-] Key deleted: [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\iagcajndpnfncplednpbnkahadegklfa ***** [ Web browsers ] ***** [-] [C:\Users\paulinka\AppData\Local\Google\Chrome\User Data\Profile 1] [extension] Deleted: iagcajndpnfncplednpbnkahadegklfa ************************* :: "Tracing" keys deleted :: Winsock settings cleared ************************* C:\AdwCleaner\AdwCleaner[C0].txt - [10415 Bytes] - [19/05/2017 15:31:06] C:\AdwCleaner\AdwCleaner[S0].txt - [11798 Bytes] - [14/05/2017 15:21:19] C:\AdwCleaner\AdwCleaner[S1].txt - [9693 Bytes] - [17/05/2017 03:08:05] C:\AdwCleaner\AdwCleaner[S2].txt - [9766 Bytes] - [19/05/2017 15:30:13] ########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [10709 Bytes] ##########