# AdwCleaner v6.020 - Logfile created 04/10/2016 at 19:27:02
# Updated on 14/09/2016 by ToolsLib
# Database : 2016-10-03.1 [Server]
# Operating System : Windows 10 Home (X64)
# Username : Office - OFF
# Running from : C:\Users\Office\Desktop\adwcleaner_6.020.exe
# Mode: Clean
# Support :
https://toolslib.net/forum
***** [ Services ] *****
[-] Service deleted: iSafeKrnlBoot
[-] Service deleted: iSafeKrnlMon
[-] Service deleted: iSafeNetFilter
[-] Service deleted: ggbugreport
[-] Service deleted: Winsere
[-] Service deleted: DeskTop_F
[-] Service deleted: CommandHandler
[-] Service deleted: FirefoxU
***** [ Folders ] *****
[-] Folder deleted: C:\ProgramData\AwinpA
[-] Folder deleted: C:\ProgramData\cwinpc
[-] Folder deleted: C:\ProgramData\ewinpe
[-] Folder deleted: C:\ProgramData\FwinpF
[-] Folder deleted: C:\ProgramData\GwinpG
[-] Folder deleted: C:\ProgramData\HwinpH
[-] Folder deleted: C:\ProgramData\QwinpQ
[-] Folder deleted: C:\ProgramData\twinpt
[-] Folder deleted: C:\ProgramData\YwinpY
[-] Folder deleted: C:\Users\Office\AppData\Local\Hola
[-] Folder deleted: C:\Users\Office\AppData\Local\3810282D-6C19-47B0-8283-5C6C29A7E108
[-] Folder deleted: C:\Users\Office\AppData\Local\eAHPeNhIUJ
[-] Folder deleted: C:\Users\Office\AppData\Local\ffgogogo
[#] Folder deleted on reboot: C:\Users\Office\AppData\Local\eahpenhiuj
[-] Folder deleted: C:\Users\Office\AppData\Roaming\eCyber
[-] Folder deleted: C:\Users\Office\AppData\Roaming\Elex-tech
[-] Folder deleted: C:\Users\Office\AppData\Roaming\Hola
[-] Folder deleted: C:\Users\Office\AppData\Roaming\Premium
[-] Folder deleted: C:\Users\Office\AppData\Roaming\RHEng
[-] Folder deleted: C:\Users\Office\AppData\Roaming\qksee
[-] Folder deleted: C:\Users\Office\AppData\Roaming\WinZiper
[-] Folder deleted: C:\Users\Office\AppData\Roaming\Uncheckit
[-] Folder deleted: C:\Users\Office\AppData\Roaming\ffgogogo
[-] Folder deleted: C:\Users\guest1\AppData\Roaming\Elex-tech
[-] Folder deleted: C:\Program Files\Hola
[-] Folder deleted: C:\ProgramData\desktopfind
[-] Folder deleted: C:\ProgramData\Uncheckit
[-] Folder deleted: C:\ProgramData\ChelfNotify
[-] Folder deleted: C:\ProgramData\uckt
[#] Folder deleted on reboot: C:\ProgramData\Application Data\desktopfind
[#] Folder deleted on reboot: C:\ProgramData\Application Data\Uncheckit
[#] Folder deleted on reboot: C:\ProgramData\Application Data\ChelfNotify
[#] Folder deleted on reboot: C:\ProgramData\Application Data\uckt
[-] Folder deleted: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\qksee
[-] Folder deleted: C:\Users\Public\Documents\eAHPeNhIUJ
[-] Folder deleted: C:\Users\Public\Documents\ffgogogo
[#] Folder deleted on reboot: C:\Users\Public\Documents\eahpenhiuj
[-] Folder deleted: C:\Program Files (x86)\Amazon\ABB
[-] Folder deleted: C:\Program Files (x86)\Elex-tech
[-] Folder deleted: C:\Program Files (x86)\ghokswa
[-] Folder deleted: C:\Program Files (x86)\SFK
[-] Folder deleted: C:\Program Files (x86)\SearchesToYesbnd
[-] Folder deleted: C:\Program Files (x86)\TData
[-] Folder deleted: C:\Program Files (x86)\Winsere
[-] Folder deleted: C:\Program Files (x86)\WinTaske
[-] Folder deleted: C:\Program Files (x86)\QQBrowser
[-] Folder deleted: C:\Program Files (x86)\Uncheckit
[-] Folder deleted: C:\Program Files (x86)\TXQQBrowser
[-] Folder deleted: C:\Program Files (x86)\eAHPeNhIUJ
[-] Folder deleted: C:\Program Files (x86)\ffgogogo Browser
[-] Folder deleted: C:\Program Files (x86)\WinSaber
[#] Folder deleted on reboot: C:\Program Files (x86)\winsaber
[#] Folder deleted on reboot: C:\Program Files (x86)\eahpenhiuj
[-] Folder deleted: C:\Program Files (x86)\_SSpm
[-] Folder deleted: C:\WINDOWS\SysWoW64\_SSpm
[-] Folder deleted: C:\Users\Public\Documents\dmp
[-] Folder deleted: C:\Users\Office\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F
[-] Folder deleted: C:\Program Files (x86)\Firefox
[-] Folder deleted: C:\Users\Office\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcfenmboojpjinhpgggodefccipikbpd
***** [ Files ] *****
[-] File deleted: C:\WINDOWS\SysNative\log\iSafeKrnlCall.log
[-] File deleted: C:\WINDOWS\SysNative\drivers\iSafeKrnlBoot.sys
[-] File deleted: C:\WINDOWS\SysNative\drivers\iSafeNetFilter.sys
***** [ DLL ] *****
***** [ WMI ] *****
***** [ Shortcuts ] *****
[-] Shortcut disinfected: C:\Users\Public\Desktop\Mozilla Firefox.lnk
[-] Shortcut disinfected: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk
[-] Shortcut disinfected: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[-] Shortcut disinfected: C:\Users\Office\Desktop\Internet Explorer.lnk
[-] Shortcut disinfected: C:\Users\Office\Desktop\Google office\Facebook.lnk
[-] Shortcut disinfected: C:\Users\Office\Desktop\Google office\Google.lnk
[-] Shortcut disinfected: C:\Users\Office\Desktop\Google office\Twitter.lnk
[-] Shortcut disinfected: C:\Users\Office\Desktop\Google office\Youtube.lnk
[-] Shortcut disinfected: C:\Users\Office\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk
[-] Shortcut disinfected: C:\Users\Office\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[-] Shortcut disinfected: C:\Users\Office\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk
[-] Shortcut disinfected: C:\Users\Office\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk
[-] Shortcut disinfected: C:\Users\Office\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Google Chrome.lnk
***** [ Scheduled Tasks ] *****
***** [ Registry ] *****
[-] Key deleted: HKLM\SOFTWARE\Classes\WinZippers.001
[-] Key deleted: HKLM\SOFTWARE\Classes\WinZippers.7z
[-] Key deleted: HKLM\SOFTWARE\Classes\WinZippers.arj
[-] Key deleted: HKLM\SOFTWARE\Classes\WinZippers.bz2
[-] Key deleted: HKLM\SOFTWARE\Classes\WinZippers.bzip2
[-] Key deleted: HKLM\SOFTWARE\Classes\WinZippers.cab
[-] Key deleted: HKLM\SOFTWARE\Classes\WinZippers.cpio
[-] Key deleted: HKLM\SOFTWARE\Classes\WinZippers.deb
[-] Key deleted: HKLM\SOFTWARE\Classes\WinZippers.dmg
[-] Key deleted: HKLM\SOFTWARE\Classes\WinZippers.fat
[-] Key deleted: HKLM\SOFTWARE\Classes\WinZippers.gz
[-] Key deleted: HKLM\SOFTWARE\Classes\WinZippers.gzip
[-] Key deleted: HKLM\SOFTWARE\Classes\WinZippers.hfs
[-] Key deleted: HKLM\SOFTWARE\Classes\WinZippers.iso
[-] Key deleted: HKLM\SOFTWARE\Classes\WinZippers.lha
[-] Key deleted: HKLM\SOFTWARE\Classes\WinZippers.lzh
[-] Key deleted: HKLM\SOFTWARE\Classes\WinZippers.lzma
[-] Key deleted: HKLM\SOFTWARE\Classes\WinZippers.ntfs
[-] Key deleted: HKLM\SOFTWARE\Classes\WinZippers.rar
[-] Key deleted: HKLM\SOFTWARE\Classes\WinZippers.rpm
[-] Key deleted: HKLM\SOFTWARE\Classes\WinZippers.squashfs
[-] Key deleted: HKLM\SOFTWARE\Classes\WinZippers.swm
[-] Key deleted: HKLM\SOFTWARE\Classes\WinZippers.tar
[-] Key deleted: HKLM\SOFTWARE\Classes\WinZippers.taz
[-] Key deleted: HKLM\SOFTWARE\Classes\WinZippers.tbz
[-] Key deleted: HKLM\SOFTWARE\Classes\WinZippers.tbz2
[-] Key deleted: HKLM\SOFTWARE\Classes\WinZippers.tgz
[-] Key deleted: HKLM\SOFTWARE\Classes\WinZippers.tpz
[-] Key deleted: HKLM\SOFTWARE\Classes\WinZippers.txz
[-] Key deleted: HKLM\SOFTWARE\Classes\WinZippers.vhd
[-] Key deleted: HKLM\SOFTWARE\Classes\WinZippers.wim
[-] Key deleted: HKLM\SOFTWARE\Classes\WinZippers.xar
[-] Key deleted: HKLM\SOFTWARE\Classes\WinZippers.xz
[-] Key deleted: HKLM\SOFTWARE\Classes\WinZippers.z
[-] Key deleted: HKLM\SOFTWARE\Classes\WinZippers.zip
[-] Key deleted: HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\winzipersvc
[#] Key deleted on reboot: [x64] HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\winzipersvc
[-] Key deleted: HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\WdMan
[#] Key deleted on reboot: [x64] HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\WdMan
[-] Key deleted: HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\qkseeService
[#] Key deleted on reboot: [x64] HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\qkseeService
[-] Key deleted: HKU\.DEFAULT\Software\Elex-tech
[-] Key deleted: HKU\.DEFAULT\Software\Hola
[-] Key deleted: HKU\.DEFAULT\Software\{A16B1AF7-982D-40C3-B5C1-633E1A6A6678}
[-] Key deleted: HKU\.DEFAULT\Software\{8C4CE252-7DB2-4F8E-8E76-BAD0E5826A83}
[-] Key deleted: HKU\S-1-5-21-3405886302-3877856416-3159069044-1001\Software\Hola
[-] Key deleted: HKU\S-1-5-21-3405886302-3877856416-3159069044-1001\Software\{8C4CE252-7DB2-4F8E-8E76-BAD0E5826A83}
[-] Key deleted: HKU\S-1-5-21-3405886302-3877856416-3159069044-1001\Software\ffgogogo
[-] Key deleted: HKU\S-1-5-21-3405886302-3877856416-3159069044-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\Hola
[#] Key deleted on reboot: HKU\S-1-5-18\Software\Elex-tech
[#] Key deleted on reboot: HKU\S-1-5-18\Software\Hola
[#] Key deleted on reboot: HKU\S-1-5-18\Software\{A16B1AF7-982D-40C3-B5C1-633E1A6A6678}
[#] Key deleted on reboot: HKU\S-1-5-18\Software\{8C4CE252-7DB2-4F8E-8E76-BAD0E5826A83}
[#] Key deleted on reboot: HKCU\Software\Hola
[#] Key deleted on reboot: HKCU\Software\{8C4CE252-7DB2-4F8E-8E76-BAD0E5826A83}
[#] Key deleted on reboot: HKCU\Software\ffgogogo
[-] Key deleted: HKLM\SOFTWARE\Elex-tech
[-] Key deleted: HKLM\SOFTWARE\hdcode
[-] Key deleted: HKLM\SOFTWARE\TSv
[-] Key deleted: HKLM\SOFTWARE\yessearchesSoftware
[-] Key deleted: HKLM\SOFTWARE\qkseeSvc
[-] Key deleted: HKLM\SOFTWARE\qksee
[-] Key deleted: HKLM\SOFTWARE\{A16B1AF7-982D-40C3-B5C1-633E1A6A6678}
[-] Key deleted: HKLM\SOFTWARE\{E6276374-DE18-4AA5-A365-9016A2F98A2D}
[-] Key deleted: HKLM\SOFTWARE\{G6276374-DEEE-4AAA-A355-9016A2F98A2D}
[-] Key deleted: HKLM\SOFTWARE\{8C4CE252-7DB2-4F8E-8E76-BAD0E5826A83}
[-] Key deleted: HKLM\SOFTWARE\WinZiper
[-] Key deleted: HKLM\SOFTWARE\WinSaberSvc
[#] Key deleted on reboot: HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Hola
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0A7D6F3C-F2AB-48ED-BE23-99791BFF87D6}
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\qksee
[-] Key deleted: HKLM\SOFTWARE\CLIENTS\Corner Sunshine
[#] Key deleted on reboot: [x64] HKCU\Software\Hola
[#] Key deleted on reboot: [x64] HKCU\Software\{8C4CE252-7DB2-4F8E-8E76-BAD0E5826A83}
[#] Key deleted on reboot: [x64] HKCU\Software\ffgogogo
[-] Key deleted: [x64] HKLM\SOFTWARE\Hola
[-] Key deleted: [x64] HKLM\SOFTWARE\{A16B1AF7-982D-40C3-B5C1-633E1A6A6678}
[-] Key deleted: [x64] HKLM\SOFTWARE\{8C4CE252-7DB2-4F8E-8E76-BAD0E5826A83}
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Hola
[#] Key deleted on reboot: [x64] HKLM\SOFTWARE\CLIENTS\Corner Sunshine
[-] Data restored: HKU\S-1-5-21-3405886302-3877856416-3159069044-1001\Software\Microsoft\Internet Explorer\Main [Search Page]
[-] Data restored: HKU\S-1-5-21-3405886302-3877856416-3159069044-1001\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
[-] Data restored: HKU\S-1-5-21-3405886302-3877856416-3159069044-1001\Software\Microsoft\Internet Explorer\Main [Default_Search_URL]
[-] Data restored: HKU\S-1-5-21-3405886302-3877856416-3159069044-1001\Software\Microsoft\Internet Explorer\Main [Start Page]
[-] Data restored: HKCU\Software\Microsoft\Internet Explorer\Main [Search Page]
[-] Data restored: HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
[-] Data restored: HKCU\Software\Microsoft\Internet Explorer\Main [Default_Search_URL]
[-] Data restored: HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
[-] Data restored: HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
[-] Data restored: HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
[-] Data restored: HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
[-] Data restored: HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
[-] Data restored: [x64] HKCU\Software\Microsoft\Internet Explorer\Main [Search Page]
[-] Data restored: [x64] HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
[-] Data restored: [x64] HKCU\Software\Microsoft\Internet Explorer\Main [Default_Search_URL]
[-] Data restored: [x64] HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
[-] Data restored: [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
[-] Data restored: [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
[-] Data restored: [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
[-] Data restored: [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
[-] Key deleted: HKU\S-1-5-21-3405886302-3877856416-3159069044-1001\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
[-] Data restored: HKU\S-1-5-21-3405886302-3877856416-3159069044-1001\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope] {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[#] Key deleted on reboot: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
[-] Data restored: HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope] {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
[-] Data restored: HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes [DefaultScope] {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
[-] Data restored: [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope] {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
[-] Data restored: [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes [DefaultScope] {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[-] Data restored: HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command [Default]
[-] Value deleted: HKU\S-1-5-21-3405886302-3877856416-3159069044-1001\Software\Microsoft\Windows\CurrentVersion\Run [hola]
[-] Value deleted: HKU\S-1-5-21-3405886302-3877856416-3159069044-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run [hola]
[#] Value deleted on reboot: HKCU\Software\Microsoft\Windows\CurrentVersion\Run [hola]
[#] Value deleted on reboot: [x64] HKCU\Software\Microsoft\Windows\CurrentVersion\Run [hola]
[-] Value deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run [hola]
[-] Key deleted: HKCU\Software\MozillaPlugins\@hola.org/FlashPlayer
[-] Key deleted: HKCU\Software\MozillaPlugins\@hola.org/vlc
[-] Key deleted: HKLM\SOFTWARE\Classes\lnkfile\shellex\ContextMenuHandlers\WinZipper
[-] Key deleted: HKCU\SOFTWARE\Mozilla\Firefox\{EB52F1AB-3C2B-424F-9794-833C687025CF}
[-] Key deleted: HKLM\SOFTWARE\Mozilla\Firefox\{EB52F1AB-3C2B-424F-9794-833C687025CF}
[-] Key deleted: HKCU\Software\Google\Chrome\Extensions\fcfenmboojpjinhpgggodefccipikbpd
[#] Key deleted on reboot: [x64] HKCU\Software\Google\Chrome\Extensions\fcfenmboojpjinhpgggodefccipikbpd
***** [ Web browsers ] *****
[-] [C:\Users\Office\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: google
[-] [C:\Users\Office\AppData\Local\Google\Chrome\User Data\Default] [extension] Deleted: fcfenmboojpjinhpgggodefccipikbpd
*************************
:: "Tracing" keys deleted
:: Winsock settings cleared
*************************
C:\AdwCleaner\AdwCleaner[C0].txt - [15807 Bytes] - [04/10/2016 19:27:02]
C:\AdwCleaner\AdwCleaner[S0].txt - [18889 Bytes] - [04/10/2016 19:06:16]
########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [15955 Bytes] ##########