ikarus2557 | 14.09.2019 14:38 | Code:
# -------------------------------
# Malwarebytes AdwCleaner 7.4.1.0
# -------------------------------
# Build: 09-04-2019
# Database: 2019-08-27.1 (Local)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 09-14-2019
# Duration: 00:00:01
# OS: Windows 10 Pro
# Cleaned: 19
# Failed: 0
***** [ Services ] *****
No malicious services cleaned.
***** [ Folders ] *****
Deleted C:\Users\MSI_USER\AppData\Local\slimware utilities inc
Deleted C:\Users\MSI_USER\AppData\Roaming\DESKTOPICONAMAZON
Deleted C:\Users\Public\Documents\Downloaded Installers
***** [ Files ] *****
Deleted C:\Windows\System32\drivers\swdumon.sys
***** [ DLL ] *****
No malicious DLLs cleaned.
***** [ WMI ] *****
No malicious WMI cleaned.
***** [ Shortcuts ] *****
No malicious shortcuts cleaned.
***** [ Tasks ] *****
No malicious tasks cleaned.
***** [ Registry ] *****
Deleted HKCU\Software\Classes\.bgl
Deleted HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\hao123.com
Deleted HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\th.hao123.com
Deleted HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\hao123.com
Deleted HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\th.hao123.com
Deleted HKCU\Software\Lavasoft\Web Companion
Deleted HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{BDF61FAE-9D19-40F0-8F34-688DEB334CA9}
Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run|Web Companion
Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com
Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Run|Web Companion
Deleted HKCU\Software\SlimWare Utilities Inc
Deleted HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Reason\ReasonByteFence
Deleted HKLM\SYSTEM\Setup\FirstBoot\Services\SWDUMon
Deleted HKLM\Software\Wow6432Node\Lavasoft\Web Companion
Deleted HKLM\Software\Wow6432Node\SlimWare Utilities Inc
***** [ Chromium (and derivatives) ] *****
No malicious Chromium entries cleaned.
***** [ Chromium URLs ] *****
No malicious Chromium URLs cleaned.
***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries cleaned.
***** [ Firefox URLs ] *****
No malicious Firefox URLs cleaned.
***** [ Preinstalled Software ] *****
No Preinstalled Software cleaned.
*************************
[+] Delete IFEO
[+] Delete Tracing Keys
[+] Reset Chromium Policies
[+] Reset IE Policies
[+] Reset Winsock
*************************
AdwCleaner_Debug.log - [32213 octets] - [14/09/2019 20:14:38]
AdwCleaner[S00].txt - [3554 octets] - [14/09/2019 20:15:11]
AdwCleaner[S01].txt - [3616 octets] - [14/09/2019 20:20:49]
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C01].txt ########## Code:
# -------------------------------
# Malwarebytes AdwCleaner 7.4.1.0
# -------------------------------
# Build: 09-04-2019
# Database: 2019-09-13.1 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start: 09-14-2019
# Duration: 00:00:17
# OS: Windows 10 Pro
# Scanned: 35602
# Detected: 19
***** [ Services ] *****
No malicious services found.
***** [ Folders ] *****
PUP.Optional.Legacy C:\Users\MSI_USER\AppData\Roaming\DESKTOPICONAMAZON
PUP.Optional.Legacy C:\Users\Public\Documents\Downloaded Installers
PUP.Optional.SlimCleanerPlus C:\Users\MSI_USER\AppData\Local\slimware utilities inc
***** [ Files ] *****
PUP.Optional.Legacy C:\Windows\System32\drivers\swdumon.sys
***** [ DLL ] *****
No malicious DLLs found.
***** [ WMI ] *****
No malicious WMI found.
***** [ Shortcuts ] *****
No malicious shortcuts found.
***** [ Tasks ] *****
No malicious tasks found.
***** [ Registry ] *****
PUP.Optional.ByteFence HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Reason\ReasonByteFence
PUP.Optional.DriverUpdate HKLM\SYSTEM\Setup\FirstBoot\Services\SWDUMon
PUP.Optional.Legacy HKCU\Software\Classes\.bgl
PUP.Optional.Legacy HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\hao123.com
PUP.Optional.Legacy HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\th.hao123.com
PUP.Optional.Legacy HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\hao123.com
PUP.Optional.Legacy HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\th.hao123.com
PUP.Optional.Legacy HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{BDF61FAE-9D19-40F0-8F34-688DEB334CA9}
PUP.Optional.Legacy HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run|Web Companion
PUP.Optional.Legacy HKCU\Software\Microsoft\Windows\CurrentVersion\Run|Web Companion
PUP.Optional.SlimCleanerPlus HKCU\Software\SlimWare Utilities Inc
PUP.Optional.SlimCleanerPlus HKLM\Software\Wow6432Node\SlimWare Utilities Inc
PUP.Optional.WebCompanion HKCU\Software\Lavasoft\Web Companion
PUP.Optional.WebCompanion HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com
PUP.Optional.WebCompanion HKLM\Software\Wow6432Node\Lavasoft\Web Companion
***** [ Chromium (and derivatives) ] *****
No malicious Chromium entries found.
***** [ Chromium URLs ] *****
No malicious Chromium URLs found.
***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries found.
***** [ Firefox URLs ] *****
No malicious Firefox URLs found.
***** [ Preinstalled Software ] *****
No Preinstalled Software found.
AdwCleaner_Debug.log - [9029 octets] - [14/09/2019 20:14:38]
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S00].txt ########## Code:
# -------------------------------
# Malwarebytes AdwCleaner 7.4.1.0
# -------------------------------
# Build: 09-04-2019
# Database: 2019-08-27.1 (Local)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start: 09-14-2019
# Duration: 00:00:27
# OS: Windows 10 Pro
# Scanned: 35522
# Detected: 19
***** [ Services ] *****
No malicious services found.
***** [ Folders ] *****
PUP.Optional.Legacy C:\Users\MSI_USER\AppData\Roaming\DESKTOPICONAMAZON
PUP.Optional.Legacy C:\Users\Public\Documents\Downloaded Installers
PUP.Optional.SlimCleanerPlus C:\Users\MSI_USER\AppData\Local\slimware utilities inc
***** [ Files ] *****
PUP.Optional.Legacy C:\Windows\System32\drivers\swdumon.sys
***** [ DLL ] *****
No malicious DLLs found.
***** [ WMI ] *****
No malicious WMI found.
***** [ Shortcuts ] *****
No malicious shortcuts found.
***** [ Tasks ] *****
No malicious tasks found.
***** [ Registry ] *****
PUP.Optional.ByteFence HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Reason\ReasonByteFence
PUP.Optional.DriverUpdate HKLM\SYSTEM\Setup\FirstBoot\Services\SWDUMon
PUP.Optional.Legacy HKCU\Software\Classes\.bgl
PUP.Optional.Legacy HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\hao123.com
PUP.Optional.Legacy HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\th.hao123.com
PUP.Optional.Legacy HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\hao123.com
PUP.Optional.Legacy HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\th.hao123.com
PUP.Optional.Legacy HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{BDF61FAE-9D19-40F0-8F34-688DEB334CA9}
PUP.Optional.Legacy HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run|Web Companion
PUP.Optional.Legacy HKCU\Software\Microsoft\Windows\CurrentVersion\Run|Web Companion
PUP.Optional.SlimCleanerPlus HKCU\Software\SlimWare Utilities Inc
PUP.Optional.SlimCleanerPlus HKLM\Software\Wow6432Node\SlimWare Utilities Inc
PUP.Optional.WebCompanion HKCU\Software\Lavasoft\Web Companion
PUP.Optional.WebCompanion HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com
PUP.Optional.WebCompanion HKLM\Software\Wow6432Node\Lavasoft\Web Companion
***** [ Chromium (and derivatives) ] *****
No malicious Chromium entries found.
***** [ Chromium URLs ] *****
No malicious Chromium URLs found.
***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries found.
***** [ Firefox URLs ] *****
No malicious Firefox URLs found.
***** [ Preinstalled Software ] *****
No Preinstalled Software found.
AdwCleaner_Debug.log - [21237 octets] - [14/09/2019 20:14:38]
AdwCleaner[S00].txt - [3554 octets] - [14/09/2019 20:15:11]
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S01].txt ########## Code:
2019-09-14 13:14:38 : <INFO> [Application] AdwCleaner 7 . 4 . 1 launched
2019-09-14 13:14:39 : <INFO> [MBInstaller] Checking Iris
2019-09-14 13:14:39 : <INFO> [IRIS] Making request
2019-09-14 13:14:39 : <INFO> [AdwUpgrade] Checking application updates
2019-09-14 13:14:39 : <INFO> [Telemetry] Sending hello
2019-09-14 13:14:40 : <INFO> [SslCert] Issued by ("DigiCert SHA2 High Assurance Server CA")
2019-09-14 13:14:40 : <INFO> [SslCert] Issued to ("*.malwarebytes.com")
2019-09-14 13:14:40 : <INFO> [SslCert] Locality Name ("Santa Clara")
2019-09-14 13:14:40 : <INFO> [SslCert] Organization ("Malwarebytes Inc")
2019-09-14 13:14:40 : <INFO> [SslCert] Certificate EffectiveDate: "Mo. Okt 2 00:00:00 2017 GMT"
2019-09-14 13:14:40 : <INFO> [SslCert] Certificate ExpirationDate: "Di. Okt 6 12:00:00 2020 GMT"
2019-09-14 13:14:40 : <INFO> [SslCert] ALPN: None
2019-09-14 13:14:40 : <INFO> [SslCert] Cipher: "ECDHE-RSA-AES256-GCM-SHA384"
2019-09-14 13:14:40 : <INFO> [SslCert] KXE: "ECDH"
2019-09-14 13:14:40 : <INFO> [SslCert] Protocol: "TLSv1.2"
2019-09-14 13:14:42 : <INFO> [SslCert] Issued by ("DigiCert SHA2 High Assurance Server CA")
2019-09-14 13:14:42 : <INFO> [SslCert] Issued to ("*.malwarebytes.com")
2019-09-14 13:14:42 : <INFO> [SslCert] Locality Name ("Santa Clara")
2019-09-14 13:14:42 : <INFO> [SslCert] Organization ("Malwarebytes Inc")
2019-09-14 13:14:42 : <INFO> [SslCert] Certificate EffectiveDate: "Mo. Okt 2 00:00:00 2017 GMT"
2019-09-14 13:14:42 : <INFO> [SslCert] Certificate ExpirationDate: "Di. Okt 6 12:00:00 2020 GMT"
2019-09-14 13:14:42 : <INFO> [SslCert] ALPN: None
2019-09-14 13:14:42 : <INFO> [SslCert] Cipher: "ECDHE-RSA-AES256-GCM-SHA384"
2019-09-14 13:14:42 : <INFO> [SslCert] KXE: "ECDH"
2019-09-14 13:14:42 : <INFO> [SslCert] Protocol: "TLSv1.2"
2019-09-14 13:14:42 : <INFO> [Telemetry] Status code: QVariant(int, 200)
2019-09-14 13:14:42 : <WARNING> [File Downloader] Error downloading ( QNetworkReply::NetworkError(ContentNotFoundError) )
2019-09-14 13:14:42 : <INFO> [IRIS] Failed
2019-09-14 13:14:48 : <INFO> [Button clicked] EULA agreed
2019-09-14 13:14:54 : <INFO> [Button clicked] Scan
2019-09-14 13:14:54 : <INFO> [Scan] Started
2019-09-14 13:14:54 : <INFO> [Database] Downloading database
2019-09-14 13:15:03 : <INFO> [Database] Checking integrity
2019-09-14 13:15:03 : <INFO> [Database] Found 2599 families
2019-09-14 13:15:03 : <INFO> [Database] Database v "2019-09-13.1"
2019-09-14 13:15:03 : <INFO> [Loading paths] Local paths loaded
2019-09-14 13:15:03 : <INFO> [Loading paths] Chrome paths loaded
2019-09-14 13:15:03 : <INFO> [Loading paths] User Keys loaded
2019-09-14 13:15:03 : <INFO> [Module initialized] "File"
2019-09-14 13:15:03 : <INFO> [Module initialized] "Folder"
2019-09-14 13:15:03 : <INFO> [Module initialized] "RegistryKey"
2019-09-14 13:15:03 : <INFO> [Module initialized] "RegistryValue"
2019-09-14 13:15:03 : <INFO> [Module initialized] "TaskName"
2019-09-14 13:15:03 : <INFO> [Module initialized] "Service"
2019-09-14 13:15:03 : <INFO> [Module initialized] "Winlogon"
2019-09-14 13:15:04 : <INFO> [Module initialized] "URL"
2019-09-14 13:15:04 : <INFO> [Module initialized] "RegAppInit"
2019-09-14 13:15:04 : <INFO> [Module initialized] "RegClasses"
2019-09-14 13:15:04 : <INFO> [Module initialized] "DNS"
2019-09-14 13:15:04 : <INFO> [Module initialized] "RegFirewallPolicy"
2019-09-14 13:15:04 : <INFO> [Module initialized] "RegGuid"
2019-09-14 13:15:05 : <INFO> [Module initialized] "RegIEElevationPolicy"
2019-09-14 13:15:05 : <INFO> [Module initialized] "RegOther"
2019-09-14 13:15:05 : <INFO> [Module initialized] "RegProductID"
2019-09-14 13:15:05 : <INFO> [Module initialized] "RegSoftware"
2019-09-14 13:15:05 : <INFO> [Module initialized] "RegStartup"
2019-09-14 13:15:05 : <INFO> [Module initialized] "WMI"
2019-09-14 13:15:05 : <INFO> [Module initialized] "ChromiumExt"
2019-09-14 13:15:05 : <INFO> [Module initialized] "FirefoxExt"
2019-09-14 13:15:05 : <INFO> [Module initialize] Scan Browser
2019-09-14 13:15:05 : <INFO> [Module initialize] Scan Browser FF
2019-09-14 13:15:05 : <INFO> [Module initialize] FF start pages loaded
2019-09-14 13:15:05 : <INFO> [Module initialize] FF search providers loaded
2019-09-14 13:15:05 : <INFO> [Module initialize] FF plugin list loaded
2019-09-14 13:15:05 : <INFO> [Scan] Exclusions loaded
2019-09-14 13:15:05 : <INFO> [Scan] Item detected: "PUP.Optional.Legacy" , "C:\\Windows\\System32\\drivers\\swdumon.sys" [ "File" ]
2019-09-14 13:15:05 : <INFO> [Scan] Item detected: "PUP.Optional.Legacy" , "C:\\Users\\MSI_USER\\AppData\\Roaming\\DESKTOPICONAMAZON" [ "Folder" ]
2019-09-14 13:15:05 : <INFO> [Scan] Item detected: "PUP.Optional.Legacy" , "C:\\Users\\Public\\Documents\\Downloaded Installers" [ "Folder" ]
2019-09-14 13:15:06 : <INFO> [Scan] Item detected: "SubScan" , "HKCU\\Software\\Microsoft\\Internet Explorer\\SearchScopes\\{BDF61FAE-9D19-40F0-8F34-688DEB334CA9}|URL" [ "Registry" ]
2019-09-14 13:15:06 : <INFO> [Scan] Item detected: "SubScan" , "HKCU\\Software\\Microsoft\\Internet Explorer\\SearchScopes\\{BDF61FAE-9D19-40F0-8F34-688DEB334CA9}|FaviconURL" [ "Registry" ]
2019-09-14 13:15:06 : <INFO> [Scan] Item detected: "SubScan" , "HKCU\\Software\\Microsoft\\Internet Explorer\\SearchScopes\\{BDF61FAE-9D19-40F0-8F34-688DEB334CA9}|TopResultURL" [ "Registry" ]
2019-09-14 13:15:06 : <INFO> [Scan] Item detected: "PUP.Optional.Legacy" , "HKCU\\Software\\Microsoft\\Internet Explorer\\SearchScopes\\{BDF61FAE-9D19-40F0-8F34-688DEB334CA9}" [ "Registry" ]
2019-09-14 13:15:06 : <INFO> [Scan] Item detected: "PUP.Optional.Legacy" , "HKCU\\Software\\Classes\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\AppContainer\\Storage\\microsoft.microsoftedge_8wekyb3d8bbwe\\Children\\001\\Internet Explorer\\EdpDomStorage\\hao123.com" [ "Registry" ]
2019-09-14 13:15:06 : <INFO> [Scan] Item detected: "PUP.Optional.Legacy" , "HKCU\\Software\\Classes\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\AppContainer\\Storage\\microsoft.microsoftedge_8wekyb3d8bbwe\\Children\\001\\Internet Explorer\\EdpDomStorage\\th.hao123.com" [ "Registry" ]
2019-09-14 13:15:06 : <INFO> [Scan] Item detected: "PUP.Optional.Legacy" , "HKCU\\Software\\Classes\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\AppContainer\\Storage\\microsoft.microsoftedge_8wekyb3d8bbwe\\Children\\001\\Internet Explorer\\DOMStorage\\hao123.com" [ "Registry" ]
2019-09-14 13:15:06 : <INFO> [Scan] Item detected: "PUP.Optional.Legacy" , "HKCU\\Software\\Classes\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\AppContainer\\Storage\\microsoft.microsoftedge_8wekyb3d8bbwe\\Children\\001\\Internet Explorer\\DOMStorage\\th.hao123.com" [ "Registry" ]
2019-09-14 13:15:06 : <INFO> [Scan] Item detected: "PUP.Optional.Legacy" , "HKCU\\Software\\Classes\\.bgl" [ "Registry" ]
2019-09-14 13:15:07 : <INFO> [Scan] Item detected: "PUP.Optional.Legacy" , "HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run|Web Companion" [ "Registry" ]
2019-09-14 13:15:07 : <INFO> [Scan] Item detected: "PUP.Optional.Legacy" , "HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartupApproved\\Run|Web Companion" [ "Registry" ]
2019-09-14 13:15:08 : <INFO> [Scan] Item detected: "PUP.Optional.SlimCleanerPlus" , "C:\\Users\\MSI_USER\\AppData\\Local\\slimware utilities inc" [ "Folder" ]
2019-09-14 13:15:08 : <INFO> [Scan] Item detected: "PUP.Optional.SlimCleanerPlus" , "HKLM\\Software\\Wow6432Node\\SlimWare Utilities Inc" [ "Registry" ]
2019-09-14 13:15:08 : <INFO> [Scan] Item detected: "PUP.Optional.SlimCleanerPlus" , "HKCU\\Software\\SlimWare Utilities Inc" [ "Registry" ]
2019-09-14 13:15:08 : <INFO> [Scan] Item detected: "PUP.Optional.DriverUpdate" , "HKLM\\SYSTEM\\Setup\\FirstBoot\\Services\\SWDUMon" [ "Registry" ]
2019-09-14 13:15:08 : <INFO> [Scan] Item detected: "PUP.Optional.ByteFence" , "HKLM\\SYSTEM\\CurrentControlSet\\Services\\EventLog\\Reason\\ReasonByteFence" [ "Registry" ]
2019-09-14 13:15:08 : <INFO> [Scan] Item detected: "PUP.Optional.WebCompanion" , "HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\Domains\\webcompanion.com" [ "Registry" ]
2019-09-14 13:15:08 : <INFO> [Scan] Item detected: "PUP.Optional.WebCompanion" , "HKLM\\Software\\Wow6432Node\\Lavasoft\\Web Companion" [ "Registry" ]
2019-09-14 13:15:08 : <INFO> [Scan] Item detected: "PUP.Optional.WebCompanion" , "HKCU\\Software\\Lavasoft\\Web Companion" [ "Registry" ]
2019-09-14 13:15:11 : <INFO> [Telemetry] Sending to Influx
2019-09-14 13:15:13 : <INFO> [SslCert] Issued by ("Let's Encrypt Authority X3")
2019-09-14 13:15:13 : <INFO> [SslCert] Issued to ("telemetry-02.adwc.mb.fr33tux.org")
2019-09-14 13:15:13 : <INFO> [SslCert] Locality Name ()
2019-09-14 13:15:13 : <INFO> [SslCert] Organization ()
2019-09-14 13:15:13 : <INFO> [SslCert] Certificate EffectiveDate: "So. Aug 18 10:50:38 2019 GMT"
2019-09-14 13:15:13 : <INFO> [SslCert] Certificate ExpirationDate: "Sa. Nov 16 10:50:38 2019 GMT"
2019-09-14 13:15:13 : <INFO> [SslCert] ALPN: Yes
2019-09-14 13:15:13 : <INFO> [SslCert] Cipher: "ECDHE-RSA-AES256-GCM-SHA384"
2019-09-14 13:15:13 : <INFO> [SslCert] KXE: "ECDH"
2019-09-14 13:15:13 : <INFO> [SslCert] Protocol: "TLSv1.2"
2019-09-14 13:15:13 : <INFO> [Telemetry] Status code: QVariant(int, 204)
2019-09-14 13:15:13 : <INFO> [Telemetry] Sending to DSE
2019-09-14 13:15:14 : <INFO> [SslCert] Issued by ("DigiCert SHA2 High Assurance Server CA")
2019-09-14 13:15:14 : <INFO> [SslCert] Issued to ("*.malwarebytes.com")
2019-09-14 13:15:14 : <INFO> [SslCert] Locality Name ("San Jose")
2019-09-14 13:15:14 : <INFO> [SslCert] Organization ("Malwarebytes Inc.")
2019-09-14 13:15:14 : <INFO> [SslCert] Certificate EffectiveDate: "Do. Feb 22 00:00:00 2018 GMT"
2019-09-14 13:15:14 : <INFO> [SslCert] Certificate ExpirationDate: "Mi. Apr 22 12:00:00 2020 GMT"
2019-09-14 13:15:14 : <INFO> [SslCert] ALPN: Yes
2019-09-14 13:15:14 : <INFO> [SslCert] Cipher: "ECDHE-RSA-AES256-GCM-SHA384"
2019-09-14 13:15:14 : <INFO> [SslCert] KXE: "ECDH"
2019-09-14 13:15:14 : <INFO> [SslCert] Protocol: "TLSv1.2"
2019-09-14 13:15:14 : <INFO> [Telemetry] Status code: QVariant(int, 201)
2019-09-14 13:15:14 : <INFO> [Scan] Finished
2019-09-14 13:15:19 : <INFO> [Button clicked] Settings menu item
2019-09-14 13:16:42 : <INFO> [Application] Closing AdwCleaner
2019-09-14 13:17:13 : <INFO> [Application] AdwCleaner 7 . 4 . 1 launched
2019-09-14 13:17:14 : <INFO> [MBInstaller] Checking Iris
2019-09-14 13:17:14 : <INFO> [IRIS] Making request
2019-09-14 13:17:15 : <INFO> [SslCert] Issued by ("DigiCert SHA2 High Assurance Server CA")
2019-09-14 13:17:15 : <INFO> [SslCert] Issued to ("*.malwarebytes.com")
2019-09-14 13:17:15 : <INFO> [SslCert] Locality Name ("Santa Clara")
2019-09-14 13:17:15 : <INFO> [SslCert] Organization ("Malwarebytes Inc")
2019-09-14 13:17:15 : <INFO> [SslCert] Certificate EffectiveDate: "Mo. Okt 2 00:00:00 2017 GMT"
2019-09-14 13:17:15 : <INFO> [SslCert] Certificate ExpirationDate: "Di. Okt 6 12:00:00 2020 GMT"
2019-09-14 13:17:15 : <INFO> [SslCert] ALPN: None
2019-09-14 13:17:15 : <INFO> [SslCert] Cipher: "ECDHE-RSA-AES256-GCM-SHA384"
2019-09-14 13:17:15 : <INFO> [SslCert] KXE: "ECDH"
2019-09-14 13:17:15 : <INFO> [SslCert] Protocol: "TLSv1.2"
2019-09-14 13:17:16 : <WARNING> [File Downloader] Error downloading ( QNetworkReply::NetworkError(ContentNotFoundError) )
2019-09-14 13:17:16 : <INFO> [IRIS] Failed
2019-09-14 13:17:17 : <INFO> [Button clicked] Survey closed
2019-09-14 13:17:17 : <INFO> [Telemetry] Sending NPS Survey
2019-09-14 13:17:17 : <INFO> [AdwUpgrade] Checking application updates
2019-09-14 13:17:17 : <INFO> [Telemetry] Sending hello
2019-09-14 13:17:18 : <INFO> [SslCert] Issued by ("DigiCert SHA2 High Assurance Server CA")
2019-09-14 13:17:18 : <INFO> [SslCert] Issued to ("*.malwarebytes.com")
2019-09-14 13:17:18 : <INFO> [SslCert] Locality Name ("Santa Clara")
2019-09-14 13:17:18 : <INFO> [SslCert] Organization ("Malwarebytes Inc")
2019-09-14 13:17:18 : <INFO> [SslCert] Certificate EffectiveDate: "Mo. Okt 2 00:00:00 2017 GMT"
2019-09-14 13:17:18 : <INFO> [SslCert] Certificate ExpirationDate: "Di. Okt 6 12:00:00 2020 GMT"
2019-09-14 13:17:18 : <INFO> [SslCert] ALPN: None
2019-09-14 13:17:18 : <INFO> [SslCert] Cipher: "ECDHE-RSA-AES256-GCM-SHA384"
2019-09-14 13:17:18 : <INFO> [SslCert] KXE: "ECDH"
2019-09-14 13:17:18 : <INFO> [SslCert] Protocol: "TLSv1.2"
2019-09-14 13:17:18 : <INFO> [Telemetry] Status code: QVariant(int, 200)
2019-09-14 13:17:19 : <INFO> [SslCert] Issued by ("Let's Encrypt Authority X3")
2019-09-14 13:17:19 : <INFO> [SslCert] Issued to ("telemetry-02.adwc.mb.fr33tux.org")
2019-09-14 13:17:19 : <INFO> [SslCert] Locality Name ()
2019-09-14 13:17:19 : <INFO> [SslCert] Organization ()
2019-09-14 13:17:19 : <INFO> [SslCert] Certificate EffectiveDate: "So. Aug 18 10:50:38 2019 GMT"
2019-09-14 13:17:19 : <INFO> [SslCert] Certificate ExpirationDate: "Sa. Nov 16 10:50:38 2019 GMT"
2019-09-14 13:17:19 : <INFO> [SslCert] ALPN: Yes
2019-09-14 13:17:19 : <INFO> [SslCert] Cipher: "ECDHE-RSA-AES256-GCM-SHA384"
2019-09-14 13:17:19 : <INFO> [SslCert] KXE: "ECDH"
2019-09-14 13:17:19 : <INFO> [SslCert] Protocol: "TLSv1.2"
2019-09-14 13:17:19 : <INFO> [Telemetry] Status code: QVariant(int, 204)
2019-09-14 13:17:24 : <INFO> [Button clicked] Settings menu item
2019-09-14 13:20:11 : <INFO> [Button clicked] Dashboard menu item
2019-09-14 13:20:21 : <INFO> [Button clicked] Scan
2019-09-14 13:20:21 : <INFO> [Scan] Started
2019-09-14 13:20:21 : <INFO> [Database] Downloading database
2019-09-14 13:20:41 : <INFO> [Scan] Loading local database
2019-09-14 13:20:41 : <INFO> [Database] Checking integrity
2019-09-14 13:20:41 : <INFO> [Database] Found 2595 families
2019-09-14 13:20:41 : <INFO> [Database] Database v "2019-08-27.1"
2019-09-14 13:20:42 : <INFO> [Loading paths] Local paths loaded
2019-09-14 13:20:42 : <INFO> [Loading paths] Chrome paths loaded
2019-09-14 13:20:42 : <INFO> [Loading paths] User Keys loaded
2019-09-14 13:20:42 : <INFO> [Module initialized] "File"
2019-09-14 13:20:42 : <INFO> [Module initialized] "Folder"
2019-09-14 13:20:42 : <INFO> [Module initialized] "RegistryKey"
2019-09-14 13:20:42 : <INFO> [Module initialized] "RegistryValue"
2019-09-14 13:20:42 : <INFO> [Module initialized] "TaskName"
2019-09-14 13:20:42 : <INFO> [Module initialized] "Service"
2019-09-14 13:20:42 : <INFO> [Module initialized] "Winlogon"
2019-09-14 13:20:43 : <INFO> [Module initialized] "URL"
2019-09-14 13:20:43 : <INFO> [Module initialized] "RegAppInit"
2019-09-14 13:20:43 : <INFO> [Module initialized] "RegClasses"
2019-09-14 13:20:43 : <INFO> [Module initialized] "DNS"
2019-09-14 13:20:43 : <INFO> [Module initialized] "RegFirewallPolicy"
2019-09-14 13:20:43 : <INFO> [Module initialized] "RegGuid"
2019-09-14 13:20:43 : <INFO> [Module initialized] "RegIEElevationPolicy"
2019-09-14 13:20:43 : <INFO> [Module initialized] "RegOther"
2019-09-14 13:20:43 : <INFO> [Module initialized] "RegProductID"
2019-09-14 13:20:43 : <INFO> [Module initialized] "RegSoftware"
2019-09-14 13:20:43 : <INFO> [Module initialized] "RegStartup"
2019-09-14 13:20:43 : <INFO> [Module initialized] "WMI"
2019-09-14 13:20:43 : <INFO> [Module initialized] "ChromiumExt"
2019-09-14 13:20:43 : <INFO> [Module initialized] "FirefoxExt"
2019-09-14 13:20:43 : <INFO> [Module initialize] Scan Browser
2019-09-14 13:20:43 : <INFO> [Module initialize] Scan Browser FF
2019-09-14 13:20:43 : <INFO> [Module initialize] FF start pages loaded
2019-09-14 13:20:43 : <INFO> [Module initialize] FF search providers loaded
2019-09-14 13:20:43 : <INFO> [Module initialize] FF plugin list loaded
2019-09-14 13:20:43 : <INFO> [Scan] Exclusions loaded
2019-09-14 13:20:43 : <INFO> [Scan] Item detected: "PUP.Optional.Legacy" , "C:\\Windows\\System32\\drivers\\swdumon.sys" [ "File" ]
2019-09-14 13:20:43 : <INFO> [Scan] Item detected: "PUP.Optional.Legacy" , "C:\\Users\\MSI_USER\\AppData\\Roaming\\DESKTOPICONAMAZON" [ "Folder" ]
2019-09-14 13:20:43 : <INFO> [Scan] Item detected: "PUP.Optional.Legacy" , "C:\\Users\\Public\\Documents\\Downloaded Installers" [ "Folder" ]
2019-09-14 13:20:44 : <INFO> [Scan] Item detected: "SubScan" , "HKCU\\Software\\Microsoft\\Internet Explorer\\SearchScopes\\{BDF61FAE-9D19-40F0-8F34-688DEB334CA9}|URL" [ "Registry" ]
2019-09-14 13:20:44 : <INFO> [Scan] Item detected: "SubScan" , "HKCU\\Software\\Microsoft\\Internet Explorer\\SearchScopes\\{BDF61FAE-9D19-40F0-8F34-688DEB334CA9}|FaviconURL" [ "Registry" ]
2019-09-14 13:20:44 : <INFO> [Scan] Item detected: "SubScan" , "HKCU\\Software\\Microsoft\\Internet Explorer\\SearchScopes\\{BDF61FAE-9D19-40F0-8F34-688DEB334CA9}|TopResultURL" [ "Registry" ]
2019-09-14 13:20:44 : <INFO> [Scan] Item detected: "PUP.Optional.Legacy" , "HKCU\\Software\\Microsoft\\Internet Explorer\\SearchScopes\\{BDF61FAE-9D19-40F0-8F34-688DEB334CA9}" [ "Registry" ]
2019-09-14 13:20:44 : <INFO> [Scan] Item detected: "PUP.Optional.Legacy" , "HKCU\\Software\\Classes\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\AppContainer\\Storage\\microsoft.microsoftedge_8wekyb3d8bbwe\\Children\\001\\Internet Explorer\\EdpDomStorage\\hao123.com" [ "Registry" ]
2019-09-14 13:20:44 : <INFO> [Scan] Item detected: "PUP.Optional.Legacy" , "HKCU\\Software\\Classes\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\AppContainer\\Storage\\microsoft.microsoftedge_8wekyb3d8bbwe\\Children\\001\\Internet Explorer\\EdpDomStorage\\th.hao123.com" [ "Registry" ]
2019-09-14 13:20:44 : <INFO> [Scan] Item detected: "PUP.Optional.Legacy" , "HKCU\\Software\\Classes\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\AppContainer\\Storage\\microsoft.microsoftedge_8wekyb3d8bbwe\\Children\\001\\Internet Explorer\\DOMStorage\\hao123.com" [ "Registry" ]
2019-09-14 13:20:44 : <INFO> [Scan] Item detected: "PUP.Optional.Legacy" , "HKCU\\Software\\Classes\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\AppContainer\\Storage\\microsoft.microsoftedge_8wekyb3d8bbwe\\Children\\001\\Internet Explorer\\DOMStorage\\th.hao123.com" [ "Registry" ]
2019-09-14 13:20:44 : <INFO> [Scan] Item detected: "PUP.Optional.Legacy" , "HKCU\\Software\\Classes\\.bgl" [ "Registry" ]
2019-09-14 13:20:45 : <INFO> [Scan] Item detected: "PUP.Optional.Legacy" , "HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run|Web Companion" [ "Registry" ]
2019-09-14 13:20:45 : <INFO> [Scan] Item detected: "PUP.Optional.Legacy" , "HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartupApproved\\Run|Web Companion" [ "Registry" ]
2019-09-14 13:20:46 : <INFO> [Scan] Item detected: "PUP.Optional.SlimCleanerPlus" , "C:\\Users\\MSI_USER\\AppData\\Local\\slimware utilities inc" [ "Folder" ]
2019-09-14 13:20:46 : <INFO> [Scan] Item detected: "PUP.Optional.SlimCleanerPlus" , "HKLM\\Software\\Wow6432Node\\SlimWare Utilities Inc" [ "Registry" ]
2019-09-14 13:20:46 : <INFO> [Scan] Item detected: "PUP.Optional.SlimCleanerPlus" , "HKCU\\Software\\SlimWare Utilities Inc" [ "Registry" ]
2019-09-14 13:20:46 : <INFO> [Scan] Item detected: "PUP.Optional.DriverUpdate" , "HKLM\\SYSTEM\\Setup\\FirstBoot\\Services\\SWDUMon" [ "Registry" ]
2019-09-14 13:20:46 : <INFO> [Scan] Item detected: "PUP.Optional.ByteFence" , "HKLM\\SYSTEM\\CurrentControlSet\\Services\\EventLog\\Reason\\ReasonByteFence" [ "Registry" ]
2019-09-14 13:20:46 : <INFO> [Scan] Item detected: "PUP.Optional.WebCompanion" , "HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\Domains\\webcompanion.com" [ "Registry" ]
2019-09-14 13:20:46 : <INFO> [Scan] Item detected: "PUP.Optional.WebCompanion" , "HKLM\\Software\\Wow6432Node\\Lavasoft\\Web Companion" [ "Registry" ]
2019-09-14 13:20:46 : <INFO> [Scan] Item detected: "PUP.Optional.WebCompanion" , "HKCU\\Software\\Lavasoft\\Web Companion" [ "Registry" ]
2019-09-14 13:20:49 : <INFO> [Telemetry] Sending to Influx
2019-09-14 13:20:50 : <INFO> [SslCert] Issued by ("Let's Encrypt Authority X3")
2019-09-14 13:20:50 : <INFO> [SslCert] Issued to ("telemetry-02.adwc.mb.fr33tux.org")
2019-09-14 13:20:50 : <INFO> [SslCert] Locality Name ()
2019-09-14 13:20:50 : <INFO> [SslCert] Organization ()
2019-09-14 13:20:50 : <INFO> [SslCert] Certificate EffectiveDate: "So. Aug 18 10:50:38 2019 GMT"
2019-09-14 13:20:50 : <INFO> [SslCert] Certificate ExpirationDate: "Sa. Nov 16 10:50:38 2019 GMT"
2019-09-14 13:20:50 : <INFO> [SslCert] ALPN: Yes
2019-09-14 13:20:50 : <INFO> [SslCert] Cipher: "ECDHE-RSA-AES256-GCM-SHA384"
2019-09-14 13:20:50 : <INFO> [SslCert] KXE: "ECDH"
2019-09-14 13:20:50 : <INFO> [SslCert] Protocol: "TLSv1.2"
2019-09-14 13:20:50 : <INFO> [Telemetry] Status code: QVariant(int, 204)
2019-09-14 13:20:50 : <INFO> [Telemetry] Sending to DSE
2019-09-14 13:20:52 : <INFO> [SslCert] Issued by ("DigiCert SHA2 High Assurance Server CA")
2019-09-14 13:20:52 : <INFO> [SslCert] Issued to ("*.malwarebytes.com")
2019-09-14 13:20:52 : <INFO> [SslCert] Locality Name ("San Jose")
2019-09-14 13:20:52 : <INFO> [SslCert] Organization ("Malwarebytes Inc.")
2019-09-14 13:20:52 : <INFO> [SslCert] Certificate EffectiveDate: "Do. Feb 22 00:00:00 2018 GMT"
2019-09-14 13:20:52 : <INFO> [SslCert] Certificate ExpirationDate: "Mi. Apr 22 12:00:00 2020 GMT"
2019-09-14 13:20:52 : <INFO> [SslCert] ALPN: Yes
2019-09-14 13:20:52 : <INFO> [SslCert] Cipher: "ECDHE-RSA-AES256-GCM-SHA384"
2019-09-14 13:20:52 : <INFO> [SslCert] KXE: "ECDH"
2019-09-14 13:20:52 : <INFO> [SslCert] Protocol: "TLSv1.2"
2019-09-14 13:20:52 : <INFO> [Telemetry] Status code: QVariant(int, 201)
2019-09-14 13:20:52 : <INFO> [Scan] Finished
2019-09-14 13:22:46 : <INFO> [Button clicked] Log files menu item
2019-09-14 13:24:29 : <INFO> [Button clicked] Quarantine menu item
2019-09-14 13:24:36 : <INFO> [Button clicked] Dashboard menu item
2019-09-14 13:24:42 : <INFO> [Button clicked] Clean & repair
2019-09-14 13:24:53 : <INFO> [Button clicked] Dialog button clicked [ 2 ]
2019-09-14 13:24:53 : <INFO> [Cleaning] Started
2019-09-14 13:24:53 : <WARNING> [Cleaning] Unable to Open process - "[System Process]" 0
2019-09-14 13:24:53 : <WARNING> [Cleaning] Unable to Open process - "System" 0
2019-09-14 13:24:53 : <WARNING> [Cleaning] Unable to Open process - "Registry" 0
2019-09-14 13:24:53 : <WARNING> [Cleaning] Unable to Open process - "Memory Compression" 0
2019-09-14 13:24:53 : <WARNING> [Cleaning] Unable to Open process - "SecurityHealthService.exe" 0
2019-09-14 13:24:53 : <WARNING> [Cleaning] Unable to Open process - "SgrmBroker.exe" 0
2019-09-14 13:24:53 : <WARNING> [Cleaning] Unable to Open process - "sppsvc.exe" 0
2019-09-14 13:24:53 : <INFO> [Quarantine] Session folder: "C:\\AdwCleaner\\Quarantine\\v1\\20190914.202453"
2019-09-14 13:24:53 : <INFO> [Cleaning] Processing: "PUP.Optional.Legacy" , "C:\\Windows\\System32\\drivers\\swdumon.sys" [ "File" ]
2019-09-14 13:24:53 : <INFO> [Cleaning] Quarantined: "PUP.Optional.Legacy" , "C:\\Windows\\System32\\drivers\\swdumon.sys" [ "File" ]
2019-09-14 13:24:53 : <INFO> [Cleaning] Processing: "PUP.Optional.Legacy" , "C:\\Users\\MSI_USER\\AppData\\Roaming\\DESKTOPICONAMAZON" [ "Folder" ]
2019-09-14 13:24:53 : <INFO> [Cleaning] Quarantined: "PUP.Optional.Legacy" , "C:\\Users\\MSI_USER\\AppData\\Roaming\\DESKTOPICONAMAZON" [ "Folder" ]
2019-09-14 13:24:53 : <INFO> [Cleaning] Processing: "PUP.Optional.Legacy" , "C:\\Users\\Public\\Documents\\Downloaded Installers" [ "Folder" ]
2019-09-14 13:24:53 : <INFO> [Cleaning] Quarantined: "PUP.Optional.Legacy" , "C:\\Users\\Public\\Documents\\Downloaded Installers" [ "Folder" ]
2019-09-14 13:24:53 : <INFO> [Cleaning] Processing: "PUP.Optional.Legacy" , "HKCU\\Software\\Microsoft\\Internet Explorer\\SearchScopes\\{BDF61FAE-9D19-40F0-8F34-688DEB334CA9}" [ "Registry" ]
2019-09-14 13:24:53 : <INFO> [Cleaning] Quarantined: "PUP.Optional.Legacy" , "HKCU\\Software\\Microsoft\\Internet Explorer\\SearchScopes\\{BDF61FAE-9D19-40F0-8F34-688DEB334CA9}" [ "Registry" ]
2019-09-14 13:24:53 : <INFO> [Cleaning] Processing: "PUP.Optional.Legacy" , "HKCU\\Software\\Classes\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\AppContainer\\Storage\\microsoft.microsoftedge_8wekyb3d8bbwe\\Children\\001\\Internet Explorer\\EdpDomStorage\\hao123.com" [ "Registry" ]
2019-09-14 13:24:53 : <INFO> [Cleaning] Quarantined: "PUP.Optional.Legacy" , "HKCU\\Software\\Classes\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\AppContainer\\Storage\\microsoft.microsoftedge_8wekyb3d8bbwe\\Children\\001\\Internet Explorer\\EdpDomStorage\\hao123.com" [ "Registry" ]
2019-09-14 13:24:53 : <INFO> [Cleaning] Processing: "PUP.Optional.Legacy" , "HKCU\\Software\\Classes\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\AppContainer\\Storage\\microsoft.microsoftedge_8wekyb3d8bbwe\\Children\\001\\Internet Explorer\\EdpDomStorage\\th.hao123.com" [ "Registry" ]
2019-09-14 13:24:53 : <INFO> [Cleaning] Quarantined: "PUP.Optional.Legacy" , "HKCU\\Software\\Classes\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\AppContainer\\Storage\\microsoft.microsoftedge_8wekyb3d8bbwe\\Children\\001\\Internet Explorer\\EdpDomStorage\\th.hao123.com" [ "Registry" ]
2019-09-14 13:24:53 : <INFO> [Cleaning] Processing: "PUP.Optional.Legacy" , "HKCU\\Software\\Classes\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\AppContainer\\Storage\\microsoft.microsoftedge_8wekyb3d8bbwe\\Children\\001\\Internet Explorer\\DOMStorage\\hao123.com" [ "Registry" ]
2019-09-14 13:24:53 : <INFO> [Cleaning] Quarantined: "PUP.Optional.Legacy" , "HKCU\\Software\\Classes\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\AppContainer\\Storage\\microsoft.microsoftedge_8wekyb3d8bbwe\\Children\\001\\Internet Explorer\\DOMStorage\\hao123.com" [ "Registry" ]
2019-09-14 13:24:53 : <INFO> [Cleaning] Processing: "PUP.Optional.Legacy" , "HKCU\\Software\\Classes\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\AppContainer\\Storage\\microsoft.microsoftedge_8wekyb3d8bbwe\\Children\\001\\Internet Explorer\\DOMStorage\\th.hao123.com" [ "Registry" ]
2019-09-14 13:24:53 : <INFO> [Cleaning] Quarantined: "PUP.Optional.Legacy" , "HKCU\\Software\\Classes\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\AppContainer\\Storage\\microsoft.microsoftedge_8wekyb3d8bbwe\\Children\\001\\Internet Explorer\\DOMStorage\\th.hao123.com" [ "Registry" ]
2019-09-14 13:24:53 : <INFO> [Cleaning] Processing: "PUP.Optional.Legacy" , "HKCU\\Software\\Classes\\.bgl" [ "Registry" ]
2019-09-14 13:24:53 : <INFO> [Cleaning] Quarantined: "PUP.Optional.Legacy" , "HKCU\\Software\\Classes\\.bgl" [ "Registry" ]
2019-09-14 13:24:53 : <INFO> [Cleaning] Processing: "PUP.Optional.Legacy" , "HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run|Web Companion" [ "Registry" ]
2019-09-14 13:24:54 : <INFO> [Cleaning] Quarantined: "PUP.Optional.Legacy" , "HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run|Web Companion" [ "Registry" ]
2019-09-14 13:24:54 : <INFO> [Cleaning] Processing: "PUP.Optional.Legacy" , "HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartupApproved\\Run|Web Companion" [ "Registry" ]
2019-09-14 13:24:54 : <INFO> [Cleaning] Quarantined: "PUP.Optional.Legacy" , "HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartupApproved\\Run|Web Companion" [ "Registry" ]
2019-09-14 13:24:54 : <INFO> [Cleaning] Processing: "PUP.Optional.SlimCleanerPlus" , "C:\\Users\\MSI_USER\\AppData\\Local\\slimware utilities inc" [ "Folder" ]
2019-09-14 13:24:54 : <INFO> [Cleaning] Quarantined: "PUP.Optional.SlimCleanerPlus" , "C:\\Users\\MSI_USER\\AppData\\Local\\slimware utilities inc" [ "Folder" ]
2019-09-14 13:24:54 : <INFO> [Cleaning] Processing: "PUP.Optional.SlimCleanerPlus" , "HKLM\\Software\\Wow6432Node\\SlimWare Utilities Inc" [ "Registry" ]
2019-09-14 13:24:54 : <INFO> [Cleaning] Quarantined: "PUP.Optional.SlimCleanerPlus" , "HKLM\\Software\\Wow6432Node\\SlimWare Utilities Inc" [ "Registry" ]
2019-09-14 13:24:54 : <INFO> [Cleaning] Processing: "PUP.Optional.SlimCleanerPlus" , "HKCU\\Software\\SlimWare Utilities Inc" [ "Registry" ]
2019-09-14 13:24:54 : <INFO> [Cleaning] Quarantined: "PUP.Optional.SlimCleanerPlus" , "HKCU\\Software\\SlimWare Utilities Inc" [ "Registry" ]
2019-09-14 13:24:54 : <INFO> [Cleaning] Processing: "PUP.Optional.DriverUpdate" , "HKLM\\SYSTEM\\Setup\\FirstBoot\\Services\\SWDUMon" [ "Registry" ]
2019-09-14 13:24:54 : <INFO> [Cleaning] Quarantined: "PUP.Optional.DriverUpdate" , "HKLM\\SYSTEM\\Setup\\FirstBoot\\Services\\SWDUMon" [ "Registry" ]
2019-09-14 13:24:54 : <INFO> [Cleaning] Processing: "PUP.Optional.ByteFence" , "HKLM\\SYSTEM\\CurrentControlSet\\Services\\EventLog\\Reason\\ReasonByteFence" [ "Registry" ]
2019-09-14 13:24:54 : <INFO> [Cleaning] Quarantined: "PUP.Optional.ByteFence" , "HKLM\\SYSTEM\\CurrentControlSet\\Services\\EventLog\\Reason\\ReasonByteFence" [ "Registry" ]
2019-09-14 13:24:54 : <INFO> [Cleaning] Processing: "PUP.Optional.WebCompanion" , "HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\Domains\\webcompanion.com" [ "Registry" ]
2019-09-14 13:24:54 : <INFO> [Cleaning] Quarantined: "PUP.Optional.WebCompanion" , "HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\Domains\\webcompanion.com" [ "Registry" ]
2019-09-14 13:24:54 : <INFO> [Cleaning] Processing: "PUP.Optional.WebCompanion" , "HKLM\\Software\\Wow6432Node\\Lavasoft\\Web Companion" [ "Registry" ]
2019-09-14 13:24:54 : <INFO> [Cleaning] Quarantined: "PUP.Optional.WebCompanion" , "HKLM\\Software\\Wow6432Node\\Lavasoft\\Web Companion" [ "Registry" ]
2019-09-14 13:24:54 : <INFO> [Cleaning] Processing: "PUP.Optional.WebCompanion" , "HKCU\\Software\\Lavasoft\\Web Companion" [ "Registry" ]
2019-09-14 13:24:54 : <INFO> [Cleaning] Quarantined: "PUP.Optional.WebCompanion" , "HKCU\\Software\\Lavasoft\\Web Companion" [ "Registry" ]
2019-09-14 13:24:54 : <INFO> [Engine Additional Action] "Delete IFEO"
2019-09-14 13:24:54 : <INFO> [Engine Additional Action] "Delete Tracing Keys"
2019-09-14 13:24:54 : <INFO> [Engine Additional Action] "Reset Chromium Policies"
2019-09-14 13:24:54 : <INFO> [Engine Additional Action] "Reset IE Policies"
2019-09-14 13:24:55 : <INFO> [Engine Additional Action] "Reset Winsock"
2019-09-14 13:24:55 : <INFO> [Telemetry] Sending to Influx
2019-09-14 13:24:56 : <INFO> [SslCert] Issued by ("Let's Encrypt Authority X3")
2019-09-14 13:24:56 : <INFO> [SslCert] Issued to ("telemetry-02.adwc.mb.fr33tux.org")
2019-09-14 13:24:56 : <INFO> [SslCert] Locality Name ()
2019-09-14 13:24:56 : <INFO> [SslCert] Organization ()
2019-09-14 13:24:56 : <INFO> [SslCert] Certificate EffectiveDate: "So. Aug 18 10:50:38 2019 GMT"
2019-09-14 13:24:56 : <INFO> [SslCert] Certificate ExpirationDate: "Sa. Nov 16 10:50:38 2019 GMT"
2019-09-14 13:24:56 : <INFO> [SslCert] ALPN: Yes
2019-09-14 13:24:56 : <INFO> [SslCert] Cipher: "ECDHE-RSA-AES256-GCM-SHA384"
2019-09-14 13:24:56 : <INFO> [SslCert] KXE: "ECDH"
2019-09-14 13:24:56 : <INFO> [SslCert] Protocol: "TLSv1.2"
2019-09-14 13:24:56 : <INFO> [Telemetry] Status code: QVariant(int, 204)
2019-09-14 13:24:56 : <INFO> [Telemetry] Sending to DSE
2019-09-14 13:24:57 : <INFO> [SslCert] Issued by ("DigiCert SHA2 High Assurance Server CA")
2019-09-14 13:24:57 : <INFO> [SslCert] Issued to ("*.malwarebytes.com")
2019-09-14 13:24:57 : <INFO> [SslCert] Locality Name ("San Jose")
2019-09-14 13:24:57 : <INFO> [SslCert] Organization ("Malwarebytes Inc.")
2019-09-14 13:24:57 : <INFO> [SslCert] Certificate EffectiveDate: "Do. Feb 22 00:00:00 2018 GMT"
2019-09-14 13:24:57 : <INFO> [SslCert] Certificate ExpirationDate: "Mi. Apr 22 12:00:00 2020 GMT"
2019-09-14 13:24:57 : <INFO> [SslCert] ALPN: Yes
2019-09-14 13:24:57 : <INFO> [SslCert] Cipher: "ECDHE-RSA-AES256-GCM-SHA384"
2019-09-14 13:24:57 : <INFO> [SslCert] KXE: "ECDH"
2019-09-14 13:24:57 : <INFO> [SslCert] Protocol: "TLSv1.2"
2019-09-14 13:24:57 : <INFO> [Telemetry] Status code: QVariant(int, 201)
2019-09-14 13:24:57 : <INFO> [Cleaning] Finished
2019-09-14 13:25:04 : <INFO> [Button clicked] Dialog button clicked [ 6 ]
2019-09-14 13:25:04 : <INFO> [Application] Closing AdwCleaner
2019-09-14 13:25:51 : <INFO> [Application] AdwCleaner 7 . 4 . 1 launched
2019-09-14 13:25:53 : <INFO> [MBInstaller] Checking Iris
2019-09-14 13:25:54 : <INFO> [IRIS] Making request
2019-09-14 13:26:00 : <INFO> [MBBanner] Checking Iris
2019-09-14 13:26:01 : <INFO> [SslCert] Issued by ("DigiCert SHA2 High Assurance Server CA")
2019-09-14 13:26:01 : <INFO> [SslCert] Issued to ("*.malwarebytes.com")
2019-09-14 13:26:01 : <INFO> [SslCert] Locality Name ("Santa Clara")
2019-09-14 13:26:01 : <INFO> [SslCert] Organization ("Malwarebytes Inc")
2019-09-14 13:26:01 : <INFO> [SslCert] Certificate EffectiveDate: "Mo. Okt 2 00:00:00 2017 GMT"
2019-09-14 13:26:01 : <INFO> [SslCert] Certificate ExpirationDate: "Di. Okt 6 12:00:00 2020 GMT"
2019-09-14 13:26:01 : <INFO> [SslCert] ALPN: None
2019-09-14 13:26:01 : <INFO> [SslCert] Cipher: "ECDHE-RSA-AES256-GCM-SHA384"
2019-09-14 13:26:01 : <INFO> [SslCert] KXE: "ECDH"
2019-09-14 13:26:01 : <INFO> [SslCert] Protocol: "TLSv1.2"
2019-09-14 13:26:01 : <INFO> [IRIS] Making request
2019-09-14 13:26:01 : <INFO> [AdwUpgrade] Checking application updates
2019-09-14 13:26:02 : <INFO> [SslCert] Issued by ("DigiCert SHA2 High Assurance Server CA")
2019-09-14 13:26:02 : <INFO> [SslCert] Issued to ("*.malwarebytes.com")
2019-09-14 13:26:02 : <INFO> [SslCert] Locality Name ("Santa Clara")
2019-09-14 13:26:02 : <INFO> [SslCert] Organization ("Malwarebytes Inc")
2019-09-14 13:26:02 : <INFO> [SslCert] Certificate EffectiveDate: "Mo. Okt 2 00:00:00 2017 GMT"
2019-09-14 13:26:02 : <INFO> [SslCert] Certificate ExpirationDate: "Di. Okt 6 12:00:00 2020 GMT"
2019-09-14 13:26:02 : <INFO> [SslCert] ALPN: None
2019-09-14 13:26:02 : <INFO> [IRIS] Failed
2019-09-14 13:26:02 : <INFO> [SslCert] Cipher: "ECDHE-RSA-AES256-GCM-SHA384"
2019-09-14 13:26:02 : <INFO> [SslCert] KXE: "ECDH"
2019-09-14 13:26:02 : <INFO> [SslCert] Protocol: "TLSv1.2"
2019-09-14 13:26:03 : <INFO> [SslCert] Issued by ("DigiCert SHA2 High Assurance Server CA")
2019-09-14 13:26:03 : <INFO> [SslCert] Issued to ("*.malwarebytes.com")
2019-09-14 13:26:03 : <INFO> [SslCert] Locality Name ("Santa Clara")
2019-09-14 13:26:03 : <INFO> [SslCert] Organization ("Malwarebytes Inc")
2019-09-14 13:26:03 : <INFO> [SslCert] Certificate EffectiveDate: "Mo. Okt 2 00:00:00 2017 GMT"
2019-09-14 13:26:03 : <INFO> [SslCert] Certificate ExpirationDate: "Di. Okt 6 12:00:00 2020 GMT"
2019-09-14 13:26:03 : <INFO> [SslCert] ALPN: None
2019-09-14 13:26:03 : <INFO> [SslCert] Cipher: "ECDHE-RSA-AES256-GCM-SHA384"
2019-09-14 13:26:03 : <INFO> [SslCert] KXE: "ECDH"
2019-09-14 13:26:03 : <INFO> [SslCert] Protocol: "TLSv1.2"
2019-09-14 13:26:03 : <INFO> [Telemetry] Status code: QVariant(int, 200)
2019-09-14 13:26:03 : <WARNING> [File Downloader] Error downloading ( QNetworkReply::NetworkError(ContentNotFoundError) )
2019-09-14 13:26:03 : <INFO> [IRIS] Failed
2019-09-14 13:26:14 : <INFO> [Button clicked] Log files menu item |