# AdwCleaner v5.020 - Logfile created 13/11/2015 at 15:00:55 # Updated 13/11/2015 by Xplode # Database : 2015-11-13.3 [Server] # Operating system : Windows 7 Home Premium Service Pack 1 (x64) # Username : Doris - DORIS-PC # Running from : C:\Users\Doris\Desktop\AdwCleaner.exe # Option : Cleaning # Support : http://toolslib.net/forum ***** [ Services ] ***** ***** [ Folders ] ***** [-] Folder Deleted : C:\Program Files (x86)\SAlePleus [-] Folder Deleted : C:\Program Files (x86)\SalePloues [-] Folder Deleted : C:\Program Files (x86)\SalePlus [-] Folder Deleted : C:\ProgramData\15150566467654266173 [-] Folder Deleted : C:\ProgramData\Avg_Update_1114tb [-] Folder Deleted : C:\ProgramData\Avg_Update_1214tb [-] Folder Deleted : C:\ProgramData\{0185d0db-f708-e632-0185-5d0dbf70436f} [-] Folder Deleted : C:\ProgramData\{3c38b53b-d1f0-e8bb-3c38-8b53bd1fd4ef} [-] Folder Deleted : C:\ProgramData\angonckecngdhihefcjpdhnkcknciehm [-] Folder Deleted : C:\ProgramData\enhjkhpkmohedpiegkpcmmnbaeiibehm [-] Folder Deleted : C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnfgmigibdamhiimcbcnhhfmgegejhpf [-] Folder Deleted : C:\Users\Kevin\AppData\Roaming\Elex-tech ***** [ Files ] ***** [-] File Deleted : C:\Windows\SysNative\log\iSafeKrnlCall.log ***** [ DLLs ] ***** ***** [ Shortcuts ] ***** ***** [ Scheduled tasks ] ***** ***** [ Registry ] ***** [-] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [mobilegeni daemon] [-] Key Deleted : HKLM\SOFTWARE\5b404de3-25fb-c751-e9a4-3bc79075a6bb [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}{763bdca1} [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{311AACFA-3DB4-4EEC-B430-E9FFF3C3F4EB} [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5C4ECEE2-D00F-4844-92B9-F2699746572C} [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8069EEE8-90E1-42E5-82B5-BE7D9D04E78B} [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{981C4037-A6DF-4B09-BEB9-2B6AFA9E8044} [-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{EB559340-3A8F-4456-B24D-160098054EF0} [-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{311AACFA-3DB4-4EEC-B430-E9FFF3C3F4EB} [-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{5C4ECEE2-D00F-4844-92B9-F2699746572C} [-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{8069EEE8-90E1-42E5-82B5-BE7D9D04E78B} [-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{981C4037-A6DF-4B09-BEB9-2B6AFA9E8044} [-] Key Deleted : HKU\.DEFAULT\Software\AVG SafeGuard toolbar [-] Key Deleted : HKU\.DEFAULT\Software\Avg Secure Update [-] Key Deleted : HKU\.DEFAULT\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA} [-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\ask.com [-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\autopcbackup.dl.tb.ask.com [-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\mytransitguide.dl.tb.ask.com [-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\televisionfanatic.dl.tb.ask.com ***** [ Web browsers ] ***** [-] [C:\Users\Doris\AppData\Roaming\Mozilla\Firefox\Profiles\rpsub9od.default\prefs.js] [Preference] Deleted : user_pref("extensions.0vmKDQTMNdO6WgqB.scode", "(function(){try{if(window.location.href.indexOf(\"rjgEqjkFpdaGqdgFqTn6qHk6qHC\")>-1){return;}}catch(e){}try{var d=[[\"www.ebay.com\",\"www.ewoss.com\",\[...] [-] [C:\Users\Doris\AppData\Roaming\Mozilla\Firefox\Profiles\rpsub9od.default\prefs.js] [Preference] Deleted : user_pref("extensions.bZTdqmQGxZ4M8kw0.scode", "(function(){try{if(window.location.href.indexOf(\"rjgEqjkFpdaGqdgFqTn6qHk6qHC\")>-1){return;}}catch(e){}try{var d=[[\"www.ebay.com\",\"www.ewoss.com\",\[...] [-] [C:\Users\Doris\AppData\Roaming\Mozilla\Firefox\Profiles\rpsub9od.default\prefs.js] [Preference] Deleted : user_pref("extensions.gNfA2LuKcISa3xHG.scode", "(function(){try{if(window.location.href.indexOf(\"rjgEqjkFpdaGqdgFqTn6qHk6qHC\")>-1){return;}}catch(e){}try{var d=[[\"www.ebay.com\",\"www.ewoss.com\",\[...] [-] [C:\Users\Doris\AppData\Roaming\Mozilla\Firefox\Profiles\rpsub9od.default\prefs.js] [Preference] Deleted : user_pref("keyword.URL", "hxxp://websearch.goodforsearch.info/?pid=24388&r=2015/04/28&hid=16055180246164775777&lg=EN&cc=US&unqvl=86&l=1&q="); [-] [C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : aol.com [-] [C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : ask.com [-] [C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : angonckecngdhihefcjpdhnkcknciehm [-] [C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : enhjkhpkmohedpiegkpcmmnbaeiibehm [-] [C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : hnfgmigibdamhiimcbcnhhfmgegejhpf ************************* :: "Tracing" keys removed :: Winsock settings cleared ########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [5160 bytes] ##########