# AdwCleaner v5.201 - Logfile created 23/07/2016 at 19:03:35 # Updated 30/06/2016 by ToolsLib # Database : 2016-07-21.2 [Server] # Operating system : Windows 8.1 (X64) # Username : Connor - CONNORS # Running from : C:\Users\Connor\Desktop\AdwCleaner.exe # Option : Clean # Support : https://toolslib.net/forum ***** [ Services ] ***** ***** [ Folders ] ***** [-] Folder Deleted : C:\Program Files (x86)\lavasoft\web companion [-] Folder Deleted : C:\Program Files (x86)\bruoweseandsHop [-] Folder Deleted : C:\Users\Connor\AppData\Roaming\RHEng [-] Folder Deleted : C:\Users\Connor\AppData\Roaming\Opera Software\Opera Stable\Extensions\nefahkmlidbmfcahifdnedaidfmmclie ***** [ Files ] ***** [-] File Deleted : C:\Windows\SysWOW64\lavasofttcpservice.dll [-] File Deleted : C:\Users\Connor\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage [-] File Deleted : C:\Users\Connor\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage-journal [-] File Deleted : C:\Windows\SysNative\LavasoftTcpService64.dll ***** [ DLLs ] ***** ***** [ WMI ] ***** ***** [ Shortcuts ] ***** ***** [ Scheduled tasks ] ***** ***** [ Registry ] ***** [-] Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.Protector [-] Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.Protector.1 [-] Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.ProtectorLib [-] Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.ProtectorLib.1 [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B33BD6CF-BF4C-4CF0-AC84-B2974BC14ABD} [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B08006D8-1D22-458E-9370-F459542E5AF2} [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B7298E57-3046-4F2A-B8C6-78CC8A60020C} [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{CB747D69-2EE7-40C0-BE35-BA6ED3EEA8A3} [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DB559C6A-03B9-4961-9BC3-80D769710C2D} [-] Key Deleted : HKCU\Software\SoftSuma [-] Key Deleted : HKCU\Software\WEBAPP [-] Key Deleted : HKCU\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA} [-] Key Deleted : HKLM\SOFTWARE\{12DA0E6F-5543-440C-BAA2-28BF01070AFA} [-] Key Deleted : HKLM\SOFTWARE\Lavasoft\Web Companion [-] Key Deleted : HKLM\SOFTWARE\AVSoftware [-] Key Deleted : [x64] HKLM\SOFTWARE\AVSoftware [-] Key Deleted : HKU\.DEFAULT\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA} [-] Key Deleted : HKU\S-1-5-19\Software\Browser [-] Key Deleted : HKU\S-1-5-20\Software\Browser [-] Data Restored : HKCU\Software\Microsoft\Internet Explorer\SearchUrl [Default] [-] Data Restored : HKU\S-1-5-21-3806172483-3420292488-1355022846-1001\Software\Microsoft\Internet Explorer\SearchUrl [Default] [-] Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{F04239F1-BA39-4987-9F85-78C0177A672B}] [-] Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{06B50314-528E-4173-BF49-B13B86B1CBEA}] [-] Value Deleted : HKU\S-1-5-21-3806172483-3420292488-1355022846-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run [Optimizer Pro] [-] Value Deleted : HKU\S-1-5-21-3806172483-3420292488-1355022846-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run [UpdateAdmin] [-] Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Web Companion] [#] Value Deleted : HKU\S-1-5-21-3806172483-3420292488-1355022846-1001\Software\Microsoft\Windows\CurrentVersion\Run [Web Companion] [-] Value Deleted : HKU\S-1-5-21-3806172483-3420292488-1355022846-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run [Web Companion] ***** [ Web browsers ] ***** [-] [C:\Users\Connor\AppData\Roaming\Mozilla\Firefox\Profiles\j72074fr.default-1459466698315\prefs.js] Deleted : user_pref("browser.search.defaultenginename", "SafeSearch"); [-] [C:\Users\Connor\AppData\Roaming\Mozilla\Firefox\Profiles\j72074fr.default-1459466698315\prefs.js] Deleted : user_pref("browser.search.order.1", "SafeSearch"); [-] [C:\Users\Connor\AppData\Roaming\Mozilla\Firefox\Profiles\j72074fr.default-1459466698315\prefs.js] Deleted : user_pref("browser.search.selectedEngine", "SafeSearch"); [-] [C:\Users\Connor\AppData\Roaming\Mozilla\Firefox\Profiles\j72074fr.default-1459466698315\prefs.js] Deleted : user_pref("keyword.url", "hxxp://www.safesear.ch/web/?type=ss-ff-kw&q="); ************************* :: "Tracing" keys deleted :: Winsock settings cleared ************************* C:\AdwCleaner\AdwCleaner[C1].txt - [4627 bytes] - [23/07/2016 19:03:35] C:\AdwCleaner\AdwCleaner[S1].txt - [4974 bytes] - [23/07/2016 19:01:24] ########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [4773 bytes] ##########