# AdwCleaner v6.010 - Logfile created 28/08/2016 at 12:18:02
# Updated on 12/08/2016 by ToolsLib
# Database : 2016-08-27.1 [Server]
# Operating System : Windows 10 Home (X64)
# Username : User - BA
# Running from : C:\Users\User\Downloads\adwcleaner_6.010.exe
# Mode: Clean
# Support :
https://toolslib.net/forum***** [ Services ] *****
- Service deleted: vToolbarUpdater40.3.2
- Service deleted: WtuSystemSupport
***** [ Folders ] *****
- Folder deleted: C:\ProgramData\Avg_Update_1015tb
- Folder deleted: C:\ProgramData\HwinpH
- Folder deleted: C:\ProgramData\ywinpy
- Folder deleted: C:\Users\User\AppData\Local\globalUpdate
- Folder deleted: C:\Users\User\AppData\Local\avg web tuneup
- Folder deleted: C:\Users\User\AppData\Roaming\DriverCure
- Folder deleted: C:\Users\User\AppData\Roaming\eCyber
- Folder deleted: C:\Users\User\AppData\Roaming\ParetoLogic
- Folder deleted: C:\Users\User\AppData\Roaming\WinZiper
- Folder deleted: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ParetoLogic
- Folder deleted: C:\Program Files\avg web tuneup
- Folder deleted: C:\Program Files\Common Files\AVG Secure Search
- Folder deleted: C:\ProgramData\apn
- Folder deleted: C:\ProgramData\AVG Secure Search
- Folder deleted: C:\ProgramData\AVG Security Toolbar
- Folder deleted: C:\ProgramData\ParetoLogic
- Folder deleted: C:\ProgramData\avg web tuneup
- Folder deleted: C:\ProgramData\ChelfNotify
[#] Folder deleted on reboot: C:\ProgramData\Application Data\apn
[#] Folder deleted on reboot: C:\ProgramData\Application Data\AVG Secure Search
[#] Folder deleted on reboot: C:\ProgramData\Application Data\AVG Security Toolbar
[#] Folder deleted on reboot: C:\ProgramData\Application Data\ParetoLogic
[#] Folder deleted on reboot: C:\ProgramData\Application Data\avg web tuneup
[#] Folder deleted on reboot: C:\ProgramData\Application Data\ChelfNotify
- Folder deleted: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\myfree codec
- Folder deleted: C:\Program Files (x86)\globalUpdate
- Folder deleted: C:\Program Files (x86)\myfree codec
- Folder deleted: C:\Program Files (x86)\ParetoLogic
- Folder deleted: C:\Program Files (x86)\WinZipper
- Folder deleted: C:\Program Files (x86)\TData
- Folder deleted: C:\Program Files (x86)\avg web tuneup
- Folder deleted: C:\Program Files (x86)\QQBrowser
- Folder deleted: C:\Program Files (x86)\WinTsks
- Folder deleted: C:\Program Files (x86)\WinSvces
- Folder deleted: C:\Program Files (x86)\TXQQBrowser
- Folder deleted: C:\Program Files (x86)\Common Files\AVG Secure Search
- Folder deleted: C:\Program Files (x86)\Common Files\ParetoLogic
- Folder deleted: C:\Users\Public\Documents\dmp
- Folder deleted: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1
***** [ Files ] *****
- File deleted: C:\Users\User\Desktop\ParetoLogic PC Health Advisor.lnk
- File deleted: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\luhx3i40.default\extensions\Avg@toolbar.xpi
- File deleted: C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\wtu-secure-search.xml
[#] File deleted: C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\wtu-secure-search.xml
[#] File deleted: C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\wtu-secure-search.xml
***** [ DLL ] *****
***** [ WMI ] *****
***** [ Shortcuts ] *****
***** [ Scheduled Tasks ] *****
***** [ Registry ] *****
- Key deleted: HKLM\SOFTWARE\Classes\WinZippers.001
- Key deleted: HKLM\SOFTWARE\Classes\WinZippers.7z
- Key deleted: HKLM\SOFTWARE\Classes\WinZippers.arj
- Key deleted: HKLM\SOFTWARE\Classes\WinZippers.bz2
- Key deleted: HKLM\SOFTWARE\Classes\WinZippers.bzip2
- Key deleted: HKLM\SOFTWARE\Classes\WinZippers.cab
- Key deleted: HKLM\SOFTWARE\Classes\WinZippers.cpio
- Key deleted: HKLM\SOFTWARE\Classes\WinZippers.deb
- Key deleted: HKLM\SOFTWARE\Classes\WinZippers.dmg
- Key deleted: HKLM\SOFTWARE\Classes\WinZippers.fat
- Key deleted: HKLM\SOFTWARE\Classes\WinZippers.gz
- Key deleted: HKLM\SOFTWARE\Classes\WinZippers.gzip
- Key deleted: HKLM\SOFTWARE\Classes\WinZippers.hfs
- Key deleted: HKLM\SOFTWARE\Classes\WinZippers.iso
- Key deleted: HKLM\SOFTWARE\Classes\WinZippers.lha
- Key deleted: HKLM\SOFTWARE\Classes\WinZippers.lzh
- Key deleted: HKLM\SOFTWARE\Classes\WinZippers.lzma
- Key deleted: HKLM\SOFTWARE\Classes\WinZippers.ntfs
- Key deleted: HKLM\SOFTWARE\Classes\WinZippers.rar
- Key deleted: HKLM\SOFTWARE\Classes\WinZippers.rpm
- Key deleted: HKLM\SOFTWARE\Classes\WinZippers.squashfs
- Key deleted: HKLM\SOFTWARE\Classes\WinZippers.swm
- Key deleted: HKLM\SOFTWARE\Classes\WinZippers.tar
- Key deleted: HKLM\SOFTWARE\Classes\WinZippers.taz
- Key deleted: HKLM\SOFTWARE\Classes\WinZippers.tbz
- Key deleted: HKLM\SOFTWARE\Classes\WinZippers.tbz2
- Key deleted: HKLM\SOFTWARE\Classes\WinZippers.tgz
- Key deleted: HKLM\SOFTWARE\Classes\WinZippers.tpz
- Key deleted: HKLM\SOFTWARE\Classes\WinZippers.txz
- Key deleted: HKLM\SOFTWARE\Classes\WinZippers.vhd
- Key deleted: HKLM\SOFTWARE\Classes\WinZippers.wim
- Key deleted: HKLM\SOFTWARE\Classes\WinZippers.xar
- Key deleted: HKLM\SOFTWARE\Classes\WinZippers.xz
- Key deleted: HKLM\SOFTWARE\Classes\WinZippers.z
- Key deleted: HKLM\SOFTWARE\Classes\WinZippers.zip
- Key deleted: HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\winzipersvc
- Key deleted: HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\qkseeService
- Key deleted: HKLM\SOFTWARE\Classes\ScriptHelper.GenericWnd
- Key deleted: HKLM\SOFTWARE\Classes\ScriptHelper.GenericWnd.1
- Key deleted: HKLM\SOFTWARE\Classes\ScriptHelper.NativeApi
- Key deleted: HKLM\SOFTWARE\Classes\ScriptHelper.NativeApi.1
- Key deleted: HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
- Key deleted: HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
- Key deleted: HKLM\SOFTWARE\Classes\WtuServer.WtuServerObj
- Key deleted: HKLM\SOFTWARE\Classes\WtuServer.WtuServerObj.1
- Key deleted: [x64] HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
- Key deleted: [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
- Key deleted: [x64] HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C}
- Key deleted: [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
- Key deleted: [x64] HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
- Key deleted: [x64] HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785}
- Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
- Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
- Key deleted: HKLM\SOFTWARE\Classes\CLSID\{35B8892D-C3FB-4D88-990D-31DB2EBD72BD}
- Key deleted: HKLM\SOFTWARE\Classes\CLSID\{6E993643-8FBC-44FE-BC85-D318495C4D96}
- Key deleted: HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
- Key deleted: HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
- Key deleted: HKLM\SOFTWARE\Classes\CLSID\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
- Key deleted: HKLM\SOFTWARE\Classes\CLSID\{CA3A5461-96B5-46DD-9341-5350D3C94615}
- Key deleted: HKLM\SOFTWARE\Classes\CLSID\{5C3B5DAA-0AFF-4808-90FB-0F2F2D760E36}
- Key deleted: HKLM\SOFTWARE\Classes\CLSID\{0757C9D8-D8A3-33F5-CEE2-11D09918BA8F}
- Key deleted: HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
- Key deleted: HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C}
- Key deleted: HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
- Key deleted: HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
- Key deleted: HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785}
- Key deleted: HKLM\SOFTWARE\Classes\TypeLib\{93E3D79C-0786-48FF-9329-93BC9F6DC2B3}
- Key deleted: HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
- Key deleted: HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
- Key deleted: HKLM\SOFTWARE\Classes\TypeLib\{4BC8AD89-AC5F-4DBD-A38F-C355C7DD33D7}
- Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
- Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
- Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
- Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
- Key deleted: [x64] HKLM\SOFTWARE\{8C4CE252-7DB2-4F8E-8E76-BAD0E5826A83}
- Key deleted: HKU\.DEFAULT\Software\{8C4CE252-7DB2-4F8E-8E76-BAD0E5826A83}
- Key deleted: HKU\S-1-5-21-42116740-2373976432-327316849-1001\Software\GlobalUpdate
- Key deleted: HKU\S-1-5-21-42116740-2373976432-327316849-1001\Software\Myfree Codec
- Key deleted: HKU\S-1-5-21-42116740-2373976432-327316849-1001\Software\ParetoLogic
- Key deleted: HKU\S-1-5-21-42116740-2373976432-327316849-1001\Software\WEBAPP
- Key deleted: HKU\S-1-5-21-42116740-2373976432-327316849-1001\Software\INSTALLPATH\STATUS
- Key deleted: HKU\S-1-5-21-42116740-2373976432-327316849-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec
- Key deleted: HKU\S-1-5-21-42116740-2373976432-327316849-1004\Software\Myfree Codec
[#] Key deleted on reboot: HKU\S-1-5-18\Software\{8C4CE252-7DB2-4F8E-8E76-BAD0E5826A83}
[#] Key deleted on reboot: HKCU\Software\GlobalUpdate
[#] Key deleted on reboot: HKCU\Software\Myfree Codec
[#] Key deleted on reboot: HKCU\Software\ParetoLogic
[#] Key deleted on reboot: HKCU\Software\WEBAPP
[#] Key deleted on reboot: HKCU\Software\INSTALLPATH\STATUS
- Key deleted: HKLM\SOFTWARE\hdcode
- Key deleted: HKLM\SOFTWARE\Myfree Codec
- Key deleted: HKLM\SOFTWARE\ParetoLogic
- Key deleted: HKLM\SOFTWARE\AVG Tuneup
- Key deleted: HKLM\SOFTWARE\qkseeSvc
- Key deleted: HKLM\SOFTWARE\qksee
- Key deleted: HKLM\SOFTWARE\{A16B1AF7-982D-40C3-B5C1-633E1A6A6678}
- Key deleted: HKLM\SOFTWARE\{E6276374-DE18-4AA5-A365-9016A2F98A2D}
- Key deleted: HKLM\SOFTWARE\{G6276374-DEEE-4AAA-A355-9016A2F98A2D}
- Key deleted: HKLM\SOFTWARE\{8C4CE252-7DB2-4F8E-8E76-BAD0E5826A83}
[#] Key deleted on reboot: HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec
- Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3CBF3EBB-235D-4c29-A68B-2BB1F428586E}
- Data restored: HKU\S-1-5-21-42116740-2373976432-327316849-1001\Software\Microsoft\Internet Explorer\Main [Start Page]
- Data restored: HKU\S-1-5-21-42116740-2373976432-327316849-1004\Software\Microsoft\Internet Explorer\Main [Start Page]
- Data restored: HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
- Key deleted: HKU\S-1-5-21-42116740-2373976432-327316849-1001\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
- Key deleted: HKU\S-1-5-21-42116740-2373976432-327316849-1004\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
[#] Key deleted on reboot: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
- Value deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32 [ApnTBMon]
- Value deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32 [CommonToolkitTray]
- Value deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32 [vProt]
- Value deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
- Key deleted: HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\WinZipper
- Key deleted: HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\WinZipper
- Key deleted: HKLM\SOFTWARE\Classes\lnkfile\shellex\ContextMenuHandlers\WinZipper
- Key deleted: HKLM\SOFTWARE\Google\Chrome\NativeMessagingHosts\avgsh
- Key deleted: HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
- Key deleted: HKLM\SOFTWARE\Classes\f
***** [ Web browsers ] *****
- Chrome preferences cleaned: "avg.wtu.ext.extParams" - "{\"action\":\"extParams\",\"data\":{\"searchParams\":{\"pid\":\"wtu\",\"cid\":\"{1c0150d8-506c-40d7-977b-21c5e96e55e6}\",\"mid\":\"c8346dd77beb47cdb879bd389f200b05-d5cfd13f24deb4d7729f9aa91c4202d99bb29c20\",\"ds\":\"ZEN\",\"v\":\"4.3.2.18\",\"lang\":\"da\",\"pr\":\"fr\",\"d\":\"2015-12-25%2016%3A54%3A45\",\"ud\":\"2016-07-25%2011%3A50%3A20\",\"cmpid\":\"0816tb\",\"domain\":\"mysearch.avg.com\",\"protocol\":\"hxxps\",\"FileUpdateDate\":\"\",\"form\":\"AVGSDF\",\"pc\":\"AVG2\"},\"cmpIds\":{\"hp\":\"0816tb\",\"nt\":\"0816tb\",\"dsp\":\"\"},\"install\":{\"RevertUrlHp\":\"hxxps://www.google.dk/?gws_rd=cr,ssl&ei=RnZfVKCAO4XYPL3cgZAE\",\"RevertUrlSp\":\"\",\"RevertUrlNt\":\"about:newtab\",\"hp\":1,\"sp\":1,\"nt\":1},\"manifest\":{\"domain_display_name\":\"AVG Secure Search\"}}}"
- Chrome preferences cleaned: "browser.search.defaultenginename" - "AVG Secure Search"
- Chrome preferences cleaned: "browser.search.selectedEngine" - "AVG Secure Search"
*************************
:: "Tracing" keys deleted
:: Winsock settings cleared
*************************
C:\AdwCleaner\AdwCleaner[C0].txt - [13746 Bytes] - [28/08/2016 12:18:02]
C:\AdwCleaner\AdwCleaner[S0].txt - [13090 Bytes] - [28/08/2016 12:13:13]
########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [13894 Bytes] ##########