# AdwCleaner 7.0.4.0 - Logfile created on Wed Nov 15 21:02:04 2017 # Updated on 2017/27/10 by Malwarebytes # Running on Windows 7 Professional (X64) # Mode: clean # Support: https://www.malwarebytes.com/support ***** [ Services ] ***** No malicious services deleted. ***** [ Folders ] ***** No malicious folders deleted. ***** [ Files ] ***** Deleted: C:\Users\Gebruiker\AppData\Roaming\\appdataFr2.bin Deleted: C:\Users\Gebruiker\AppData\Roaming\\Installer.dat ***** [ DLL ] ***** No malicious DLLs cleaned. ***** [ WMI ] ***** No malicious WMI cleaned. ***** [ Shortcuts ] ***** No malicious shortcuts cleaned. ***** [ Tasks ] ***** No malicious tasks deleted. ***** [ Registry ] ***** Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|TCP Query User{70C1D0D5-A156-4977-9563-6B04DD0C1430}C:\users\gebruiker\appdata\local\popcorn time\node-webkit\popcorn time.exe Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|UDP Query User{5E6D60F6-DED2-438C-A8F1-B01E9331C713}C:\users\gebruiker\appdata\local\popcorn time\node-webkit\popcorn time.exe Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|TCP Query User{3BC23CC3-C731-49EB-BF5C-3A833617637D}C:\users\gebruiker\appdata\local\popcorn time\node-webkit\popcorn time.exe Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|UDP Query User{2313A73B-234A-4D61-B23B-02509E2C97F5}C:\users\gebruiker\appdata\local\popcorn time\node-webkit\popcorn time.exe Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|TCP Query User{9FF00CCF-FF8D-4E3F-8DE5-9F964005477B}C:\users\gebruiker\appdata\local\popcorn time\nw.exe Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|UDP Query User{DAA18075-CD32-4938-ABE1-336F632E9DA8}C:\users\gebruiker\appdata\local\popcorn time\nw.exe Deleted: [Value] - HKCU\Software\Microsoft\Internet Explorer\SearchScopes|SuggestionsURL_JSON Deleted: [Value] - HKU\S-1-5-21-1243184377-1695436347-1374857548-1000\Software\Microsoft\Internet Explorer\SearchScopes|SuggestionsURL_JSON Deleted: [Value] - HKU\S-1-5-21-1243184377-1695436347-1374857548-1000\Software\Microsoft\Internet Explorer\SearchScopes|SuggestionsURL_JSON Deleted: [Value] - HKU\S-1-5-21-1243184377-1695436347-1374857548-1003\Software\Microsoft\Internet Explorer\SearchScopes|SuggestionsURL_JSON Deleted: [Value] - HKU\S-1-5-21-1243184377-1695436347-1374857548-1003\Software\Microsoft\Internet Explorer\SearchScopes|SuggestionsURL_JSON Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A2616871-3463-BCEE-5AFA-73773317A381} Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C168639F-5810-4EC8-B1E8-0251AA8A771C} Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6C97A91E-4524-4019-86AF-2AA2D567BF5C} Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{3CCC052E-BDEE-408A-BEA7-90914EF2964B} Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{61F47056-E400-43D3-AF1E-AB7DFFD4C4AD} Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{E2B98EEA-EE55-4E9B-A8C1-6E5288DF785A} Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{D879A501-50A7-BEFC-A4C5-32DC6E0CB208} Deleted: [Key] - HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{ielnksrch} Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Quotenamron.exe Deleted: [Value] - HKCU\Software\Microsoft\Internet Explorer\SearchScopes|DoNotAskAgain Deleted: [Value] - HKU\S-1-5-21-1243184377-1695436347-1374857548-1000\Software\Microsoft\Internet Explorer\SearchScopes|DoNotAskAgain Deleted: [Value] - HKU\S-1-5-21-1243184377-1695436347-1374857548-1000\Software\Microsoft\Internet Explorer\SearchScopes|DoNotAskAgain Deleted: [Key] - HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\IELNKSRCH Deleted: [Key] - HKU\S-1-5-21-1243184377-1695436347-1374857548-1000\Software\drpsu Deleted: [Key] - HKCU\Software\drpsu ***** [ Firefox (and derivatives) ] ***** No malicious Firefox entries deleted. ***** [ Chromium (and derivatives) ] ***** No malicious Chromium entries deleted. ************************* ::Tracing keys deleted ::Winsock settings cleared ::Additional Actions: 0 ************************* C:/AdwCleaner/AdwCleaner[S0].txt - [4923 B] - [2017/11/15 21:1:19] ########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt ##########