# ------------------------------- # Malwarebytes AdwCleaner 7.2.1.0 # ------------------------------- # Build: 06-26-2018 # Database: 2018-08-17.2 # Support: https://www.malwarebytes.com/support # # ------------------------------- # Mode: Clean # ------------------------------- # Start: 08-19-2018 # Duration: 00:00:02 # OS: Windows 7 Professional # Cleaned: 54 # Failed: 0 ***** [ Services ] ***** Deleted SpyHunter 4 Service ***** [ Folders ] ***** Deleted C:\Program Files (x86)\Tencent Deleted C:\Program Files (x86)\Common Files\Tencent Deleted C:\Users\admin\AppData\Roaming\Tencent Deleted C:\Users\Public\Documents\Tencent Deleted C:\Users\admin\Start Menu\Programs\SpyHunter Deleted C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\spyhunter Deleted C:\sh4ldr Deleted C:\Program Files (x86)\Enigma Software Group ***** [ Files ] ***** Deleted C:\Users\admin\Desktop\SpyHunter.lnk ***** [ DLL ] ***** No malicious DLLs cleaned. ***** [ WMI ] ***** No malicious WMI cleaned. ***** [ Shortcuts ] ***** No malicious shortcuts cleaned. ***** [ Tasks ] ***** Deleted C:\Windows\System32\Tasks\SpyHunter4Startup ***** [ Registry ] ***** Deleted HKLM\Software\Wow6432Node\WOW6432NODE\POLICIES\GOOGLE\Chrome Deleted HKCU\Software\Classes\Tencent Deleted HKLM\Software\Classes\Tencent Deleted HKLM\Software\Wow6432Node\Classes\AppID\DownloadProxy.EXE Deleted HKLM\SOFTWARE\Classes\AppID\DownloadProxy.EXE Deleted HKLM\Software\Wow6432Node\Classes\TypeLib\{ED721A76-8160-4DA0-A18E-7FD7C4574774} Deleted HKLM\Software\Classes\TypeLib\{ED721A76-8160-4DA0-A18E-7FD7C4574774} Deleted HKLM\Software\Wow6432Node\Classes\CLSID\{DD67706E-819E-4EBD-BF8D-6D6147CC7A49} Deleted HKLM\Software\Wow6432Node\Classes\Interface\{C97AF157-6A27-4F57-9D47-E2D3E4761B77} Deleted HKLM\Software\Classes\Interface\{C97AF157-6A27-4F57-9D47-E2D3E4761B77} Deleted HKLM\Software\Wow6432Node\Classes\CLSID\{B1A429DB-FB06-4645-B7C0-0CC405EAD3CD} Deleted HKLM\Software\Wow6432Node\Classes\CLSID\{AE91F9CE-0900-4E2A-B673-F3F6E4FC54D9} Deleted HKLM\Software\Wow6432Node\Classes\Interface\{A4F6E1B3-469E-46EF-A936-FBA9D5EFD2B9} Deleted HKLM\Software\Classes\Interface\{A4F6E1B3-469E-46EF-A936-FBA9D5EFD2B9} Deleted HKLM\Software\Wow6432Node\Classes\CLSID\{9B7B034B-944A-4261-B487-862F642F7615} Deleted HKLM\Software\Wow6432Node\Classes\CLSID\{832599B2-55BF-4437-8F3E-030CF5AEB262} Deleted HKLM\Software\Wow6432Node\Classes\CLSID\{6EEBC7FF-67DA-4B90-9251-C2C5696E4B48} Deleted HKLM\Software\Wow6432Node\Classes\Interface\{5180FE16-2E09-497B-9C8B-5A6F029ECECB} Deleted HKLM\Software\Classes\Interface\{5180FE16-2E09-497B-9C8B-5A6F029ECECB} Deleted HKLM\Software\Wow6432Node\Classes\Interface\{46803190-228D-470E-90FE-F5E0CEA9C4F2} Deleted HKLM\Software\Classes\Interface\{46803190-228D-470E-90FE-F5E0CEA9C4F2} Deleted HKLM\Software\Wow6432Node\Classes\CLSID\{3E28F712-0D6C-4EE3-AC8C-8F060F5D7C33} Deleted HKLM\Software\Wow6432Node\Classes\Interface\{2C4B6DB8-6413-403B-A038-16A352CFE8B9} Deleted HKLM\Software\Classes\Interface\{2C4B6DB8-6413-403B-A038-16A352CFE8B9} Deleted HKLM\Software\Wow6432Node\Classes\Interface\{23C5311E-016D-4999-BCB1-499898429D6C} Deleted HKLM\Software\Classes\Interface\{23C5311E-016D-4999-BCB1-499898429D6C} Deleted HKLM\Software\Wow6432Node\Classes\Interface\{22511E2E-7970-414E-BC7C-28D16C4AF54D} Deleted HKLM\Software\Classes\Interface\{22511E2E-7970-414E-BC7C-28D16C4AF54D} Deleted HKLM\Software\Wow6432Node\Classes\Interface\{E7270EC6-0113-4A78-B610-E501D0A9E48E} Deleted HKLM\Software\Classes\Interface\{E7270EC6-0113-4A78-B610-E501D0A9E48E} Deleted HKLM\Software\Wow6432Node\Classes\AppID\{51BEE30D-EEC8-4BA3-930B-298B8E759EB1} Deleted HKLM\Software\Classes\AppID\{51BEE30D-EEC8-4BA3-930B-298B8E759EB1} Deleted HKLM\Software\Wow6432Node\Classes\AppID\{9DC8FA51-B596-4F77-802C-5B295919C205} Deleted HKLM\Software\Classes\AppID\{9DC8FA51-B596-4F77-802C-5B295919C205} Deleted HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{1A480F56-F79E-4209-BDA3-9283517220C5} Deleted HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{52638A21-FF62-427C-88A7-ADD44418DC1E} Deleted HKLM\Software\Classes\METNSD Deleted HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4FC9DA9D-F608-454E-8191-D7EFFDCC5726} Deleted HKLM\Software\Wow6432Node\EnigmaSoftwareGroup Deleted HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7BD8146798CEA704D860BE01414B8E51 Deleted HKLM\SOFTWARE\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications\SpyHunter4.exe Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C3E05E18-B67C-4CEB-84DD-D28E797BC4D9} Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SpyHunter4Startup ***** [ Chromium (and derivatives) ] ***** No malicious Chromium entries cleaned. ***** [ Chromium URLs ] ***** No malicious Chromium URLs cleaned. ***** [ Firefox (and derivatives) ] ***** No malicious Firefox entries cleaned. ***** [ Firefox URLs ] ***** No malicious Firefox URLs cleaned. ************************* [+] Delete Tracing Keys [+] Reset Winsock ************************* AdwCleaner[S00].txt - [15570 octets] - [30/07/2018 23:37:31] AdwCleaner[C00].txt - [13171 octets] - [30/07/2018 23:46:32] AdwCleaner[S01].txt - [6724 octets] - [19/08/2018 14:31:16] ########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C01].txt ##########