# -------------------------------
# Malwarebytes AdwCleaner 7.3.0.0
# -------------------------------
# Build: 04-04-2019
# Database: 2019-06-18.1 (Cloud)
# Support:
https://www.malwarebytes.com/support#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 06-18-2019
# Duration: 00:00:15
# OS: Windows 8.1 Connected
# Cleaned: 62
# Failed: 0
***** [ Services ] *****
Deleted CltMngSvc
Deleted WCAssistantService
Deleted pgt_svc
Deleted windowsmanagementservice
***** [ Folders ] *****
Deleted C:\Program Files (x86)\Amazon\ABB
Deleted C:\Program Files (x86)\LenovoBrowserGuard
Deleted C:\Program Files (x86)\ProxyGate
Deleted C:\ProgramData\Application Data\Lavasoft\Web Companion
Deleted C:\ProgramData\Lavasoft\Web Companion
Deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DreamTrips
Deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft\WebCompanion
Deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Up Pro (Verified)
Deleted C:\Users\Heidi\AppData\Local\Lavasoft\WEBCOMPANION.EXE_URL_SIQ0LWF3TZGXP2KHFKLLYBK3IDTBEHNG
Deleted C:\Users\Heidi\AppData\Local\LenovoBrowserGuard
Deleted C:\Users\Heidi\AppData\Roaming\AGData
Deleted C:\Users\Heidi\AppData\Roaming\Lavasoft\Web Companion
Deleted C:\Users\Heidi\AppData\Roaming\Microleaves
Deleted C:\Users\Heidi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnonymizerGadget
Deleted C:\Users\Heidi\AppData\Roaming\UpProVerified
Deleted C:\Windows\SysWOW64\config\systemprofile\AppData\Local\WebDiscoverBrowser
***** [ Files ] *****
Deleted C:\Users\Heidi\Downloads\SysInfo.exe
***** [ DLL ] *****
No malicious DLLs cleaned.
***** [ WMI ] *****
No malicious WMI cleaned.
***** [ Shortcuts ] *****
No malicious shortcuts cleaned.
***** [ Tasks ] *****
Deleted C:\Windows\System32\Tasks\AGPROXYCHECK
***** [ Registry ] *****
Deleted HKCU\Software\Classes\pokki
Deleted HKCU\Software\DreamTrips
Deleted HKCU\Software\Lavasoft\Web Companion
Deleted HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run|Web Companion
Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com
Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Run|Web Companion
Deleted HKCU\Software\SetupCompany
Deleted HKCU\Software\WebDiscoverBrowser
Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B3C6CD8E-EB6A-4764-AF6D-55E1CE8840EA}
Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AGProxyCheck
Deleted HKLM\Software\Classes\Installer\Features\C3F6D7A0BA2FDE84EB329997B1FF786D
Deleted HKLM\Software\Classes\Installer\Products\C3F6D7A0BA2FDE84EB329997B1FF786D
Deleted HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32|AnonymizerGadget
Deleted HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run|WebDiscoverBrowser
Deleted HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\C3F6D7A0BA2FDE84EB329997B1FF786D
Deleted HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\foldershare
Deleted HKLM\Software\WebDiscoverBrowser
Deleted HKLM\Software\Wow6432Node\Lavasoft\Web Companion
Deleted HKLM\Software\Wow6432Node\LenovoBrowserGuard
Deleted HKLM\Software\Wow6432Node\SHMADDON
Deleted HKLM\Software\Wow6432Node\WebDiscoverBrowser
Deleted HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Run|AnonymizerGadget
Deleted HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\LenovoBrowserGuard
Deleted HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\s5m
Deleted HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{0A7D6F3C-F2AB-48ED-BE23-99791BFF87D6}
Deleted HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{13E374E4-E610-4F9E-ACC4-E461DA17D869}_is1
Deleted HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{1EC095EE-8CA3-43D6-B9F5-0C55B82ED3D7}}_is1
Deleted HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{716D2234-E822-4AB0-874A-1DD7F75047DB}_is1
Deleted HKLM\Software\Wow6432Node\xs
Deleted HKLM\Software\foldershare
Deleted HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com
Deleted HKU\.DEFAULT\Software\WebDiscoverBrowser
Deleted HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com
Deleted HKU\S-1-5-18\Software\WebDiscoverBrowser
***** [ Chromium (and derivatives) ] *****
Deleted Amazon Assistant for Chrome
***** [ Chromium URLs ] *****
Deleted Bing
Deleted
http://search.conduit.com/?ctid=CT3298578&SearchSource=48&CUI=UN22948076422779013&UM=2Deleted
http://search.conduit.com/?ctid=CT3302998&SearchSource=48&CUI=UN30487700961502075&UM=2Deleted
http://search.conduit.com/?ctid=CT3302998&SearchSource=48&CUI=UN30487700961502075&UM=2&UP=SP056BBF62-07ED-4013-8B9D-11B3A716A8A0***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries cleaned.
***** [ Firefox URLs ] *****
No malicious Firefox URLs cleaned.
*************************
- Delete Tracing Keys
- Reset Winsock
*************************
AdwCleaner[S00].txt - [6959 octets] - [18/06/2019 18:23:37]
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########