Sie sind auf Seite 1von 98

Anti-malware scan started at: 01.05.

2017 19:41:32
Anti-malware scan started at: 01.05.2017 19:42:08
01.05.2017 19:44:35 Running Processes
Probably Malicious: gplyra.exe =
C:\USERS\USER\APPDATA\ROAMING\GPLYRA\GPLYRA\GPLYRA.EXE
01.05.2017 19:44:35 Running Processes
Probably Malicious: kns53AD.tmp = C:\PROGRAM FILES (X86)\4C4C4544-1478816059-3610-
8051-C8C04F525831\KNS53AD.TMP
01.05.2017 19:44:35 Running Processes
Probably Malicious: winsecurity.exe = C:\PROGRAMDATA\WINDOWS
SECURITY\WINSECURITY.EXE
01.05.2017 19:44:35 Running Processes
Probably Malicious: sysnetwk.exe =
C:\PROGRAMDATA\MICROSOFT\NETWORK\DSQ\NETWORK\SYSNETWK.EXE
01.05.2017 19:44:35 Running Processes
Probably Malicious: syshostctl.exe =
C:\PROGRAMDATA\MICROSOFT\NETWORK\DSQ\BROWSER\SYSHOSTCTL.EXE
01.05.2017 19:44:35 Running Processes
Probably Malicious: gplyra.exe =
C:\USERS\USER\APPDATA\ROAMING\GPLYRA\GPLYRA\GPLYRA.EXE
01.05.2017 19:44:35 Running Processes
Probably Malicious: kns53AD.tmp = C:\PROGRAM FILES (X86)\4C4C4544-1478816059-3610-
8051-C8C04F525831\KNS53AD.TMP
01.05.2017 19:44:35 Running Processes
Probably Malicious: winsecurity.exe = C:\PROGRAMDATA\WINDOWS
SECURITY\WINSECURITY.EXE
01.05.2017 19:44:35 Running Processes
Probably Malicious: sysnetwk.exe =
C:\PROGRAMDATA\MICROSOFT\NETWORK\DSQ\NETWORK\SYSNETWK.EXE
01.05.2017 19:44:35 Running Processes
Probably Malicious: syshostctl.exe =
C:\PROGRAMDATA\MICROSOFT\NETWORK\DSQ\BROWSER\SYSHOSTCTL.EXE
Anti-malware scan finished at: 01.05.2017 19:46:00
01.05.2017 19:46:45 Applications
Probably Malicious: gplyra =
01.05.2017 19:47:02 Unwanted Software Files
Probably Malicious: C:\PROGRAM FILES (X86)\\WEATHERCHICKN\ = C:\PROGRAM FILES
(X86)\\WEATHERCHICKN\
01.05.2017 19:47:02 Unwanted Software Files
Probably Malicious: ZDENGINE.DLL = C:\WINDOWS\SYSWOW64\ZDENGINE.DLL
01.05.2017 19:47:02 Unwanted Software Files
Probably Malicious: C:\PROGRAM FILES (X86)\\BADU\ = C:\PROGRAM FILES (X86)\\BADU\
01.05.2017 19:47:02 Unwanted Software Files
Probably Malicious: C:\Users\user\AppData\Roaming\UPUPDATA\ =
C:\Users\user\AppData\Roaming\UPUPDATA\
01.05.2017 19:47:02 Unwanted Software Files
Probably Malicious: C:\ProgramData\QUOTEEX\ = C:\ProgramData\QUOTEEX\
01.05.2017 19:47:02 Unwanted Software Files
Probably Malicious: C:\PROGRAM FILES (X86)\\CONTENTPUSH\ = C:\PROGRAM FILES
(X86)\\CONTENTPUSH\
01.05.2017 19:47:02 Unwanted Software Files
Probably Malicious: C:\ProgramData\LOGIC HANDLER\ = C:\ProgramData\LOGIC HANDLER\
01.05.2017 19:47:02 Unwanted Software Files
Probably Malicious: C:\Program Files\ZIPTOOL\ = C:\Program Files\ZIPTOOL\
01.05.2017 19:47:02 Unwanted Software Files
Probably Malicious: KinJayfix.bin = C:\USERS\USER\APPDATA\ROAMING\KINJAYFIX.BIN
01.05.2017 19:47:02 Unwanted Software Files
Probably Malicious: Zuntop.bin = C:\USERS\USER\APPDATA\ROAMING\ZUNTOP.BIN
01.05.2017 19:47:02 Unwanted Software Files
Probably Malicious: C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER\ =
C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER\
01.05.2017 19:47:02 Unwanted Software Files
Probably Malicious: C:\ProgramData\WINDOWS SECURITY\ = C:\ProgramData\WINDOWS
SECURITY\
01.05.2017 19:47:02 Unwanted Software Files
Probably Malicious: C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK\ =
C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK\
01.05.2017 19:47:02 Unwanted Software Files
Probably Malicious: C:\Users\user\AppData\Roaming\EVENT MONITOR\ =
C:\Users\user\AppData\Roaming\EVENT MONITOR\
01.05.2017 19:47:02 Unwanted Software Files
Probably Malicious: SYSNETWK.EXE =
C:\PROGRAMDATA\MICROSOFT\NETWORK\DSQ\NETWORK\SYSNETWK.EXE
01.05.2017 19:47:02 Unwanted Software Files
Probably Malicious: C:\ProgramData\MICROSOFT\NETWORK\DSQ\ =
C:\ProgramData\MICROSOFT\NETWORK\DSQ\
01.05.2017 19:47:02 Unwanted Software Files
Probably Malicious:
C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE\ =
C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE\
01.05.2017 19:47:03 Unwanted Software Files
Probably Malicious: UNINSTALLRO.EXE = C:\USERS\USER\APPDATA\LOCAL\UNINSTALLRO.EXE
01.05.2017 19:47:03 Unwanted Software Files
Probably Malicious: C:\PROGRAM FILES (X86)\\PUBHOTSPOT\ = C:\PROGRAM FILES
(X86)\\PUBHOTSPOT\
01.05.2017 19:47:03 Unwanted Software Files
Probably Malicious: C:\PROGRAM FILES (X86)\FFF\ = C:\PROGRAM FILES (X86)\FFF\
01.05.2017 19:47:03 Unwanted Software Files
Suspicious: 2KZZKPY7UL = C:\PROGRAM FILES\2KZZKPY7UL\
01.05.2017 19:47:03 Unwanted Software Files
Suspicious: 2Y8DB5ZJCZ = C:\PROGRAM FILES\2Y8DB5ZJCZ\
01.05.2017 19:47:03 Unwanted Software Files
Suspicious: G1NPCI9BHG = C:\PROGRAM FILES\G1NPCI9BHG\
01.05.2017 19:47:03 Unwanted Software Files
Suspicious: K2BVHVQ9WG = C:\PROGRAM FILES\K2BVHVQ9WG\
01.05.2017 19:47:03 Unwanted Software Files
Suspicious: OZU7LPSW8F = C:\PROGRAM FILES\OZU7LPSW8F\
01.05.2017 19:47:03 Unwanted Software Files
Suspicious: PETFPODMG6 = C:\PROGRAM FILES\PETFPODMG6\
01.05.2017 19:47:03 Unwanted Software Files
Probably Malicious: SpaceSoundPro = C:\PROGRAM FILES\SPACESOUNDPRO\
01.05.2017 19:47:03 Unwanted Software Files
Suspicious: 2rfP2ar5Q4 = C:\PROGRAM FILES (X86)\2RFP2AR5Q4\
01.05.2017 19:47:03 Unwanted Software Files
Probably Malicious: Anerhspchpiry = C:\PROGRAM FILES (X86)\ANERHSPCHPIRY\
01.05.2017 19:47:03 Unwanted Software Files
Probably Malicious: Anobert = C:\PROGRAM FILES (X86)\ANOBERT\
01.05.2017 19:47:03 Unwanted Software Files
Probably Malicious: CleanBrowser = C:\PROGRAM FILES (X86)\CLEANBROWSER\
01.05.2017 19:47:03 Unwanted Software Files
Probably Malicious: ContentPush = C:\PROGRAM FILES (X86)\CONTENTPUSH\
01.05.2017 19:47:03 Unwanted Software Files
Probably Malicious: Joseck Helper = C:\PROGRAM FILES (X86)\JOSECK HELPER\
01.05.2017 19:47:03 Unwanted Software Files
Suspicious: Mozilla Firefox = C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\
01.05.2017 19:47:03 Unwanted Software Files
Probably Malicious: MPC Cleaner = C:\PROGRAM FILES (X86)\MPC CLEANER\
01.05.2017 19:47:03 Unwanted Software Files
Probably Malicious: mpck = C:\PROGRAM FILES (X86)\MPCK\
01.05.2017 19:47:03 Unwanted Software Files
Probably Malicious: pccleanplus = C:\PROGRAM FILES (X86)\PCCLEANPLUS\
01.05.2017 19:47:03 Unwanted Software Files
Suspicious: PubHotspot = C:\PROGRAM FILES (X86)\PUBHOTSPOT\
01.05.2017 19:47:03 Unwanted Software Files
Probably Malicious: surranderu = C:\PROGRAM FILES (X86)\SURRANDERU\
01.05.2017 19:47:03 Unwanted Software Files
Suspicious: Vegaght = C:\PROGRAM FILES (X86)\VEGAGHT\
01.05.2017 19:47:03 Unwanted Software Files
Probably Malicious: Youtube AdBlock1 = C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCK1\
01.05.2017 19:47:03 Unwanted Software Files
Probably Malicious: Youtube AdBlockjlrvmnhpdy = C:\PROGRAM FILES (X86)\YOUTUBE
ADBLOCKJLRVMNHPDY\
01.05.2017 19:47:03 Unwanted Software Files
Probably Malicious: Dlosarecertain = C:\USERS\USER\APPDATA\ROAMING\DLOSARECERTAIN\
01.05.2017 19:47:03 Unwanted Software Files
Probably Malicious: gplyra = C:\USERS\USER\APPDATA\ROAMING\GPLYRA\
01.05.2017 19:47:03 Unwanted Software Files
Probably Malicious: CloudPrinter = C:\PROGRAMDATA\CLOUDPRINTER\
01.05.2017 19:47:03 Unwanted Software Files
Suspicious: Quoteexs = C:\PROGRAMDATA\QUOTEEXS\
01.05.2017 19:47:03 Unwanted Software Files
Probably Malicious: Chromium = C:\USERS\USER\APPDATA\LOCAL\CHROMIUM\
01.05.2017 19:47:03 Unwanted Software Files
Probably Malicious: Ghetutainantigh = C:\USERS\USER\APPDATA\LOCAL\GHETUTAINANTIGH\
01.05.2017 19:47:03 Unwanted Software Files
Suspicious: Google = C:\USERS\USER\APPDATA\LOCAL\GOOGLE\
01.05.2017 19:47:03 Unwanted Software Files
Suspicious: Temp1 = C:\USERS\USER\APPDATA\LOCAL\TEMP1\
01.05.2017 19:47:03 Unwanted Software Files
Suspicious: Thuvet = C:\USERS\USER\APPDATA\LOCAL\THUVET\
01.05.2017 19:47:03 Unwanted Software Files
Probably Malicious: tuto_monetize_120160723 =
C:\USERS\USER\APPDATA\LOCAL\TUTO_MONETIZE_120160723\
01.05.2017 19:47:03 Unwanted Software Files
Probably Malicious: win_en_77 = C:\USERS\USER\APPDATA\LOCAL\WIN_EN_77\
01.05.2017 19:47:03 Unwanted Software Files
Probably Malicious: Youtube AdBlock = C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE
ADBLOCK\
01.05.2017 19:47:03 Unwanted Software Files
Probably Malicious: Youtube AdBlock1 = C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE
ADBLOCK1\
Anti-malware scan started at: 01.05.2017 19:48:41
01.05.2017 19:49:10 Unwanted Software Files
Probably Malicious: C:\PROGRAM FILES (X86)\\WEATHERCHICKN\ = C:\PROGRAM FILES
(X86)\\WEATHERCHICKN\
01.05.2017 19:49:10 Unwanted Software Files
Probably Malicious: ZDENGINE.DLL = C:\WINDOWS\SYSWOW64\ZDENGINE.DLL
01.05.2017 19:49:10 Unwanted Software Files
Probably Malicious: C:\PROGRAM FILES (X86)\\BADU\ = C:\PROGRAM FILES (X86)\\BADU\
01.05.2017 19:49:10 Unwanted Software Files
Probably Malicious: C:\Users\user\AppData\Roaming\UPUPDATA\ =
C:\Users\user\AppData\Roaming\UPUPDATA\
01.05.2017 19:49:10 Unwanted Software Files
Probably Malicious: C:\ProgramData\QUOTEEX\ = C:\ProgramData\QUOTEEX\
01.05.2017 19:49:10 Unwanted Software Files
Probably Malicious: C:\PROGRAM FILES (X86)\\CONTENTPUSH\ = C:\PROGRAM FILES
(X86)\\CONTENTPUSH\
01.05.2017 19:49:10 Unwanted Software Files
Probably Malicious: C:\ProgramData\LOGIC HANDLER\ = C:\ProgramData\LOGIC HANDLER\
01.05.2017 19:49:10 Unwanted Software Files
Probably Malicious: C:\Program Files\ZIPTOOL\ = C:\Program Files\ZIPTOOL\
01.05.2017 19:49:10 Unwanted Software Files
Probably Malicious: KinJayfix.bin = C:\USERS\USER\APPDATA\ROAMING\KINJAYFIX.BIN
01.05.2017 19:49:10 Unwanted Software Files
Probably Malicious: Zuntop.bin = C:\USERS\USER\APPDATA\ROAMING\ZUNTOP.BIN
01.05.2017 19:49:10 Unwanted Software Files
Probably Malicious: C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER\ =
C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER\
01.05.2017 19:49:10 Unwanted Software Files
Probably Malicious: C:\ProgramData\WINDOWS SECURITY\ = C:\ProgramData\WINDOWS
SECURITY\
01.05.2017 19:49:10 Unwanted Software Files
Probably Malicious: C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK\ =
C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK\
01.05.2017 19:49:10 Unwanted Software Files
Probably Malicious: C:\Users\user\AppData\Roaming\EVENT MONITOR\ =
C:\Users\user\AppData\Roaming\EVENT MONITOR\
01.05.2017 19:49:10 Unwanted Software Files
Probably Malicious: SYSNETWK.EXE =
C:\PROGRAMDATA\MICROSOFT\NETWORK\DSQ\NETWORK\SYSNETWK.EXE
01.05.2017 19:49:10 Unwanted Software Files
Probably Malicious: C:\ProgramData\MICROSOFT\NETWORK\DSQ\ =
C:\ProgramData\MICROSOFT\NETWORK\DSQ\
01.05.2017 19:49:10 Unwanted Software Files
Probably Malicious:
C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE\ =
C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE\
01.05.2017 19:49:10 Unwanted Software Files
Probably Malicious: UNINSTALLRO.EXE = C:\USERS\USER\APPDATA\LOCAL\UNINSTALLRO.EXE
01.05.2017 19:49:10 Unwanted Software Files
Probably Malicious: C:\PROGRAM FILES (X86)\\PUBHOTSPOT\ = C:\PROGRAM FILES
(X86)\\PUBHOTSPOT\
01.05.2017 19:49:10 Unwanted Software Files
Probably Malicious: C:\PROGRAM FILES (X86)\FFF\ = C:\PROGRAM FILES (X86)\FFF\
01.05.2017 19:49:10 Unwanted Software Files
Suspicious: 2KZZKPY7UL = C:\PROGRAM FILES\2KZZKPY7UL\
01.05.2017 19:49:10 Unwanted Software Files
Suspicious: 2Y8DB5ZJCZ = C:\PROGRAM FILES\2Y8DB5ZJCZ\
01.05.2017 19:49:10 Unwanted Software Files
Suspicious: G1NPCI9BHG = C:\PROGRAM FILES\G1NPCI9BHG\
01.05.2017 19:49:10 Unwanted Software Files
Suspicious: K2BVHVQ9WG = C:\PROGRAM FILES\K2BVHVQ9WG\
01.05.2017 19:49:10 Unwanted Software Files
Suspicious: OZU7LPSW8F = C:\PROGRAM FILES\OZU7LPSW8F\
01.05.2017 19:49:10 Unwanted Software Files
Suspicious: PETFPODMG6 = C:\PROGRAM FILES\PETFPODMG6\
01.05.2017 19:49:10 Unwanted Software Files
Probably Malicious: SpaceSoundPro = C:\PROGRAM FILES\SPACESOUNDPRO\
01.05.2017 19:49:10 Unwanted Software Files
Suspicious: 2rfP2ar5Q4 = C:\PROGRAM FILES (X86)\2RFP2AR5Q4\
01.05.2017 19:49:10 Unwanted Software Files
Probably Malicious: Anerhspchpiry = C:\PROGRAM FILES (X86)\ANERHSPCHPIRY\
01.05.2017 19:49:10 Unwanted Software Files
Probably Malicious: Anobert = C:\PROGRAM FILES (X86)\ANOBERT\
01.05.2017 19:49:10 Unwanted Software Files
Probably Malicious: CleanBrowser = C:\PROGRAM FILES (X86)\CLEANBROWSER\
01.05.2017 19:49:10 Unwanted Software Files
Probably Malicious: ContentPush = C:\PROGRAM FILES (X86)\CONTENTPUSH\
01.05.2017 19:49:10 Unwanted Software Files
Probably Malicious: Joseck Helper = C:\PROGRAM FILES (X86)\JOSECK HELPER\
01.05.2017 19:49:10 Unwanted Software Files
Suspicious: Mozilla Firefox = C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\
01.05.2017 19:49:10 Unwanted Software Files
Probably Malicious: MPC Cleaner = C:\PROGRAM FILES (X86)\MPC CLEANER\
01.05.2017 19:49:10 Unwanted Software Files
Probably Malicious: mpck = C:\PROGRAM FILES (X86)\MPCK\
01.05.2017 19:49:10 Unwanted Software Files
Probably Malicious: pccleanplus = C:\PROGRAM FILES (X86)\PCCLEANPLUS\
01.05.2017 19:49:10 Unwanted Software Files
Suspicious: PubHotspot = C:\PROGRAM FILES (X86)\PUBHOTSPOT\
01.05.2017 19:49:10 Unwanted Software Files
Probably Malicious: surranderu = C:\PROGRAM FILES (X86)\SURRANDERU\
01.05.2017 19:49:10 Unwanted Software Files
Suspicious: Vegaght = C:\PROGRAM FILES (X86)\VEGAGHT\
01.05.2017 19:49:10 Unwanted Software Files
Probably Malicious: Youtube AdBlock1 = C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCK1\
01.05.2017 19:49:10 Unwanted Software Files
Probably Malicious: Youtube AdBlockjlrvmnhpdy = C:\PROGRAM FILES (X86)\YOUTUBE
ADBLOCKJLRVMNHPDY\
01.05.2017 19:49:10 Unwanted Software Files
Probably Malicious: Dlosarecertain = C:\USERS\USER\APPDATA\ROAMING\DLOSARECERTAIN\
01.05.2017 19:49:10 Unwanted Software Files
Probably Malicious: gplyra = C:\USERS\USER\APPDATA\ROAMING\GPLYRA\
01.05.2017 19:49:10 Unwanted Software Files
Probably Malicious: CloudPrinter = C:\PROGRAMDATA\CLOUDPRINTER\
01.05.2017 19:49:10 Unwanted Software Files
Suspicious: Quoteexs = C:\PROGRAMDATA\QUOTEEXS\
01.05.2017 19:49:10 Unwanted Software Files
Probably Malicious: Chromium = C:\USERS\USER\APPDATA\LOCAL\CHROMIUM\
01.05.2017 19:49:10 Unwanted Software Files
Probably Malicious: Ghetutainantigh = C:\USERS\USER\APPDATA\LOCAL\GHETUTAINANTIGH\
01.05.2017 19:49:10 Unwanted Software Files
Suspicious: Google = C:\USERS\USER\APPDATA\LOCAL\GOOGLE\
01.05.2017 19:49:10 Unwanted Software Files
Suspicious: Temp1 = C:\USERS\USER\APPDATA\LOCAL\TEMP1\
01.05.2017 19:49:10 Unwanted Software Files
Suspicious: Thuvet = C:\USERS\USER\APPDATA\LOCAL\THUVET\
01.05.2017 19:49:10 Unwanted Software Files
Probably Malicious: tuto_monetize_120160723 =
C:\USERS\USER\APPDATA\LOCAL\TUTO_MONETIZE_120160723\
01.05.2017 19:49:10 Unwanted Software Files
Probably Malicious: win_en_77 = C:\USERS\USER\APPDATA\LOCAL\WIN_EN_77\
01.05.2017 19:49:10 Unwanted Software Files
Probably Malicious: Youtube AdBlock = C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE
ADBLOCK\
01.05.2017 19:49:10 Unwanted Software Files
Probably Malicious: Youtube AdBlock1 = C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE
ADBLOCK1\
Delete Marked Items Auto Start Apps->Unwanted Software Files. C:\Program
Files\ZIPTOOL\=C:\Program Files\ZIPTOOL\
Deleted: C:\Program Files\ZIPTOOL\sfx\Setup_chs.sfx
Deleted: C:\Program Files\ZIPTOOL\sfx
Cannot delete: C:\Program Files\ZIPTOOL\sfx
Deleted: C:\Program Files\ZIPTOOL\Uninst.dar0
Deleted: C:\Program Files\ZIPTOOL\Uninst.dar1
Deleted: C:\Program Files\ZIPTOOL
Cannot remove folder: C:\Program Files\ZIPTOOL\
Error: 0
Delete At reboot: C:\Program Files\ZIPTOOL
-------------------------------------------------------
01.05.2017 19:49:16 Approved File Replacement
Delete: C:\Program Files\ZIPTOOL
Delete Marked Items Auto Start Apps->Unwanted Software Files.
Anerhspchpiry=C:\PROGRAM FILES (X86)\ANERHSPCHPIRY\
Deleted: C:\PROGRAM FILES (X86)\ANERHSPCHPIRY\CrashReport.dll
Deleted: C:\PROGRAM FILES (X86)\ANERHSPCHPIRY\hoquther.exe
Deleted: C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Cannot remove folder: C:\PROGRAM FILES (X86)\ANERHSPCHPIRY\
Error: 0
Delete At reboot: C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
-------------------------------------------------------
01.05.2017 19:49:16 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete Marked Items Auto Start Apps->Unwanted Software Files.
SpaceSoundPro=C:\PROGRAM FILES\SPACESOUNDPRO\
Deleted: C:\PROGRAM FILES\SPACESOUNDPRO\config.conf
Deleted: C:\PROGRAM FILES\SPACESOUNDPRO
Cannot remove folder: C:\PROGRAM FILES\SPACESOUNDPRO\
Error: 0
Delete At reboot: C:\PROGRAM FILES\SPACESOUNDPRO
-------------------------------------------------------
01.05.2017 19:49:16 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: C:\PROGRAM FILES\SPACESOUNDPRO
Delete Marked Items Auto Start Apps->Unwanted Software Files.
Zuntop.bin=C:\USERS\USER\APPDATA\ROAMING\ZUNTOP.BIN
Safe Deleting:C:\USERS\USER\APPDATA\ROAMING\ZUNTOP.BIN. You must restart your
computer to fully delete this file.
Delete Marked Items Auto Start Apps->Unwanted Software Files.
KinJayfix.bin=C:\USERS\USER\APPDATA\ROAMING\KINJAYFIX.BIN
Safe Deleting:C:\USERS\USER\APPDATA\ROAMING\KINJAYFIX.BIN. You must restart your
computer to fully delete this file.
Delete Marked Items Auto Start Apps->Unwanted Software Files. Joseck
Helper=C:\PROGRAM FILES (X86)\JOSECK HELPER\
Deleted: C:\PROGRAM FILES (X86)\JOSECK HELPER\local64spl.dll
Deleted: C:\PROGRAM FILES (X86)\JOSECK HELPER\local64spl.dll.ini
Deleted: C:\PROGRAM FILES (X86)\JOSECK HELPER
Cannot remove folder: C:\PROGRAM FILES (X86)\JOSECK HELPER\
Error: 0
Delete At reboot: C:\PROGRAM FILES (X86)\JOSECK HELPER
-------------------------------------------------------
01.05.2017 19:49:16 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete Marked Items Auto Start Apps->Unwanted Software Files. C:\ProgramData\LOGIC
HANDLER\=C:\ProgramData\LOGIC HANDLER\
Deleted: C:\ProgramData\LOGIC HANDLER\Config.json
Deleted: C:\ProgramData\LOGIC HANDLER\System.Data.SQLite.xml
Deleted: C:\ProgramData\LOGIC HANDLER
Cannot remove folder: C:\ProgramData\LOGIC HANDLER\
Error: 0
Delete At reboot: C:\ProgramData\LOGIC HANDLER
-------------------------------------------------------
01.05.2017 19:49:17 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: C:\ProgramData\LOGIC HANDLER
Delete Marked Items Auto Start Apps->Unwanted Software Files.
ContentPush=C:\PROGRAM FILES (X86)\CONTENTPUSH\
Deleted: C:\PROGRAM FILES (X86)\CONTENTPUSH\Temp\_1.zip
Deleted: C:\PROGRAM FILES (X86)\CONTENTPUSH\Temp
Cannot delete: C:\PROGRAM FILES (X86)\CONTENTPUSH\Temp
Deleted: C:\PROGRAM FILES (X86)\CONTENTPUSH\version
Deleted: C:\PROGRAM FILES (X86)\CONTENTPUSH
Cannot remove folder: C:\PROGRAM FILES (X86)\CONTENTPUSH\
Error: 0
Delete At reboot: C:\PROGRAM FILES (X86)\CONTENTPUSH
-------------------------------------------------------
01.05.2017 19:49:17 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete Marked Items Auto Start Apps->Unwanted Software Files. Anobert=C:\PROGRAM
FILES (X86)\ANOBERT\
Deleted: C:\PROGRAM FILES (X86)\ANOBERT\Ckonagetoperght.dll
Deleted: C:\PROGRAM FILES (X86)\ANOBERT\CrashReport.dll
Deleted: C:\PROGRAM FILES (X86)\ANOBERT\hoquther.exe
Deleted: C:\PROGRAM FILES (X86)\ANOBERT\Vohuty.dll
Deleted: C:\PROGRAM FILES (X86)\ANOBERT
Cannot remove folder: C:\PROGRAM FILES (X86)\ANOBERT\
Error: 0
Delete At reboot: C:\PROGRAM FILES (X86)\ANOBERT
-------------------------------------------------------
01.05.2017 19:49:17 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: C:\PROGRAM FILES (X86)\ANOBERT
Delete Marked Items Auto Start Apps->Unwanted Software Files.
CleanBrowser=C:\PROGRAM FILES (X86)\CLEANBROWSER\
Deleted: C:\PROGRAM FILES (X86)\CLEANBROWSER\Temp\_1.zip
Deleted: C:\PROGRAM FILES (X86)\CLEANBROWSER\Temp
Cannot delete: C:\PROGRAM FILES (X86)\CLEANBROWSER\Temp
Deleted: C:\PROGRAM FILES (X86)\CLEANBROWSER
Cannot remove folder: C:\PROGRAM FILES (X86)\CLEANBROWSER\
Error: 0
Delete At reboot: C:\PROGRAM FILES (X86)\CLEANBROWSER
-------------------------------------------------------
01.05.2017 19:49:17 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete Marked Items Auto Start Apps->Unwanted Software Files.
UNINSTALLRO.EXE=C:\USERS\USER\APPDATA\LOCAL\UNINSTALLRO.EXE
Safe Deleting:C:\USERS\USER\APPDATA\LOCAL\UNINSTALLRO.EXE. You must restart your
computer to fully delete this file.
Delete Marked Items Auto Start Apps->Unwanted Software Files. C:\PROGRAM FILES
(X86)\\PUBHOTSPOT\=C:\PROGRAM FILES (X86)\\PUBHOTSPOT\
Deleted: C:\PROGRAM FILES (X86)\\PUBHOTSPOT\uninstaller.exe
Deleted: C:\PROGRAM FILES (X86)\\PUBHOTSPOT\uninstaller.exe.config
Deleted: C:\PROGRAM FILES (X86)\\PUBHOTSPOT
Cannot remove folder: C:\PROGRAM FILES (X86)\\PUBHOTSPOT\
Error: 0
Delete At reboot: C:\PROGRAM FILES (X86)\\PUBHOTSPOT
-------------------------------------------------------
01.05.2017 19:49:17 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: C:\PROGRAM FILES (X86)\\PUBHOTSPOT
Delete Marked Items Auto Start Apps->Unwanted Software Files.
C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE\=C:\Users\user\AppD
ata\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE\
Deleted:
C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE\Profiles\fnvrug3e.d
efault\prefs.js
Deleted:
C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE\Profiles\fnvrug3e.d
efault\profiles.ini
Deleted:
C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE\Profiles\fnvrug3e.d
efault\search-metadata.json
Deleted:
C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE\Profiles\fnvrug3e.d
efault
Cannot delete:
C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE\Profiles\fnvrug3e.d
efault
Deleted: C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE\Profiles
Cannot delete:
C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE\Profiles
Deleted: C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Cannot remove folder:
C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE\
Error: 0
Delete At reboot: C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
-------------------------------------------------------
01.05.2017 19:49:17 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete Marked Items Auto Start Apps->Unwanted Software Files.
SYSNETWK.EXE=C:\PROGRAMDATA\MICROSOFT\NETWORK\DSQ\NETWORK\SYSNETWK.EXE
Safe Deleting:C:\PROGRAMDATA\MICROSOFT\NETWORK\DSQ\NETWORK\SYSNETWK.EXE. You must
restart your computer to fully delete this file.
Delete Marked Items Auto Start Apps->Unwanted Software Files.
C:\ProgramData\MICROSOFT\NETWORK\DSQ\=C:\ProgramData\MICROSOFT\NETWORK\DSQ\
Deleted: C:\ProgramData\MICROSOFT\NETWORK\DSQ\browser\syshostctl.exe
Deleted: C:\ProgramData\MICROSOFT\NETWORK\DSQ\browser
Cannot delete: C:\ProgramData\MICROSOFT\NETWORK\DSQ\browser
Deleted: C:\ProgramData\MICROSOFT\NETWORK\DSQ\chrome\libvlc.dll
Deleted: C:\ProgramData\MICROSOFT\NETWORK\DSQ\chrome\vlc.exe
Deleted: C:\ProgramData\MICROSOFT\NETWORK\DSQ\chrome\work.dll
Deleted: C:\ProgramData\MICROSOFT\NETWORK\DSQ\chrome
Cannot delete: C:\ProgramData\MICROSOFT\NETWORK\DSQ\chrome
Deleted: C:\ProgramData\MICROSOFT\NETWORK\DSQ\func\ca.crt
Deleted: C:\ProgramData\MICROSOFT\NETWORK\DSQ\func\ca.key
Deleted: C:\ProgramData\MICROSOFT\NETWORK\DSQ\func\cert8.db
Deleted: C:\ProgramData\MICROSOFT\NETWORK\DSQ\func\certutil.exe
Deleted: C:\ProgramData\MICROSOFT\NETWORK\DSQ\func\freebl3.dll
Deleted: C:\ProgramData\MICROSOFT\NETWORK\DSQ\func\key3.db
Deleted: C:\ProgramData\MICROSOFT\NETWORK\DSQ\func\libnspr4.dll
Deleted: C:\ProgramData\MICROSOFT\NETWORK\DSQ\func\libplc4.dll
Deleted: C:\ProgramData\MICROSOFT\NETWORK\DSQ\func\libplds4.dll
Deleted: C:\ProgramData\MICROSOFT\NETWORK\DSQ\func\libvlc.dll
Deleted: C:\ProgramData\MICROSOFT\NETWORK\DSQ\func\msvcr100.dll
Deleted: C:\ProgramData\MICROSOFT\NETWORK\DSQ\func\nss3.dll
Deleted: C:\ProgramData\MICROSOFT\NETWORK\DSQ\func\nssckbi.dll
Deleted: C:\ProgramData\MICROSOFT\NETWORK\DSQ\func\nssdbm3.dll
Deleted: C:\ProgramData\MICROSOFT\NETWORK\DSQ\func\nssutil3.dll
Deleted: C:\ProgramData\MICROSOFT\NETWORK\DSQ\func\secmod.db
Deleted: C:\ProgramData\MICROSOFT\NETWORK\DSQ\func\smime3.dll
Deleted: C:\ProgramData\MICROSOFT\NETWORK\DSQ\func\softokn3.dll
Deleted: C:\ProgramData\MICROSOFT\NETWORK\DSQ\func\sqlite3.dll
Deleted: C:\ProgramData\MICROSOFT\NETWORK\DSQ\func\ssl3.dll
Deleted: C:\ProgramData\MICROSOFT\NETWORK\DSQ\func\vlc.exe
Deleted: C:\ProgramData\MICROSOFT\NETWORK\DSQ\func\work.dll
Deleted: C:\ProgramData\MICROSOFT\NETWORK\DSQ\func
Cannot delete: C:\ProgramData\MICROSOFT\NETWORK\DSQ\func
Deleted: C:\ProgramData\MICROSOFT\NETWORK\DSQ\network\ca.crt
Deleted: C:\ProgramData\MICROSOFT\NETWORK\DSQ\network\ca.key
Deleted: C:\ProgramData\MICROSOFT\NETWORK\DSQ\network\default_cse.js
Deleted: C:\ProgramData\MICROSOFT\NETWORK\DSQ\network\general.js
Deleted: C:\ProgramData\MICROSOFT\NETWORK\DSQ\network\SYSNETWK.del
Deleted: C:\ProgramData\MICROSOFT\NETWORK\DSQ\network
Cannot delete: C:\ProgramData\MICROSOFT\NETWORK\DSQ\network
Cannot delete: C:\ProgramData\MICROSOFT\NETWORK\DSQ
Cannot remove folder: C:\ProgramData\MICROSOFT\NETWORK\DSQ\
Error: 0
Delete At reboot: C:\ProgramData\MICROSOFT\NETWORK\DSQ
-------------------------------------------------------
01.05.2017 19:49:17 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete: C:\PROGRA~3\MICROS~1\NETWORK\DSQ
Delete Marked Items Auto Start Apps->Unwanted Software Files.
C:\ProgramData\WINDOWS SECURITY\=C:\ProgramData\WINDOWS SECURITY\
Deleted: C:\ProgramData\WINDOWS SECURITY\f\up\chrome.exe
Deleted: C:\ProgramData\WINDOWS SECURITY\f\up\libvlc.dll
Deleted: C:\ProgramData\WINDOWS SECURITY\f\up\work.dll
Deleted: C:\ProgramData\WINDOWS SECURITY\f\up
Cannot delete: C:\ProgramData\WINDOWS SECURITY\f\up
Deleted: C:\ProgramData\WINDOWS SECURITY\f\up.zip
Deleted: C:\ProgramData\WINDOWS SECURITY\f
Cannot delete: C:\ProgramData\WINDOWS SECURITY\f
Deleted: C:\ProgramData\WINDOWS SECURITY\tmp
Cannot delete: C:\ProgramData\WINDOWS SECURITY\tmp
Deleted: C:\ProgramData\WINDOWS SECURITY\winsecurity.exe
Deleted: C:\ProgramData\WINDOWS SECURITY
Cannot remove folder: C:\ProgramData\WINDOWS SECURITY\
Error: 0
Delete At reboot: C:\ProgramData\WINDOWS SECURITY
-------------------------------------------------------
01.05.2017 19:49:17 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete: \??\C:\PROGRA~3\MICROS~1\NETWORK\DSQ
Delete: C:\ProgramData\WINDOWS SECURITY
Delete Marked Items Auto Start Apps->Unwanted Software Files.
C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER\=C:\ProgramData\MICROSOFT\NETWORK\DSQ\
BROWSER\
Cannot delete: C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER
Cannot remove folder: C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER\
Error: 0
Delete At reboot: C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER
-------------------------------------------------------
01.05.2017 19:49:17 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete: \??\C:\PROGRA~3\MICROS~1\NETWORK\DSQ
Delete: \??\C:\ProgramData\WINDOWS SECURITY
Delete: C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER
Delete Marked Items Auto Start Apps->Unwanted Software Files.
C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK\=C:\Users\user\AppData
\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK\
Deleted:
C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK\close_white.png
Deleted:
C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK\content_script -
.js
Deleted:
C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK\content_script.js
Deleted: C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK\icon.png
Deleted: C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK\jquery-
1.8.3.min.js
Deleted: C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK\jquery.js
Deleted: C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK\manifest.json
Deleted: C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK\popup.html
Deleted: C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK\popup.js
Deleted: C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK
Cannot remove folder: C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK\
Error: 0
Delete At reboot: C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK
-------------------------------------------------------
01.05.2017 19:49:17 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete: \??\C:\PROGRA~3\MICROS~1\NETWORK\DSQ
Delete: \??\C:\ProgramData\WINDOWS SECURITY
Delete: \??\C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER
Delete: C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK
Delete Marked Items Auto Start Apps->Unwanted Software Files. C:\PROGRAM FILES
(X86)\FFF\=C:\PROGRAM FILES (X86)\FFF\
Deleted: C:\PROGRAM FILES (X86)\FFF\Bind.exe
Deleted: C:\PROGRAM FILES (X86)\FFF\fff.ini
Deleted: C:\PROGRAM FILES (X86)\FFF\uc.exe
Deleted: C:\PROGRAM FILES (X86)\FFF\unins000.dat
Deleted: C:\PROGRAM FILES (X86)\FFF\unins000.exe
Deleted: C:\PROGRAM FILES (X86)\FFF
Cannot remove folder: C:\PROGRAM FILES (X86)\FFF\
Error: 0
Delete At reboot: C:\PROGRAM FILES (X86)\FFF
-------------------------------------------------------
01.05.2017 19:49:17 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete: \??\C:\PROGRA~3\MICROS~1\NETWORK\DSQ
Delete: \??\C:\ProgramData\WINDOWS SECURITY
Delete: \??\C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER
Delete: \??\C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK
Delete: C:\PROGRAM FILES (X86)\FFF
Delete Marked Items Auto Start Apps->Unwanted Software Files.
C:\Users\user\AppData\Roaming\EVENT MONITOR\=C:\Users\user\AppData\Roaming\EVENT
MONITOR\
Deleted: C:\Users\user\AppData\Roaming\EVENT MONITOR\em.exe
Deleted: C:\Users\user\AppData\Roaming\EVENT MONITOR\eng_em.ini
Deleted: C:\Users\user\AppData\Roaming\EVENT MONITOR\French_em.ini
Deleted: C:\Users\user\AppData\Roaming\EVENT MONITOR\German_em.ini
Deleted: C:\Users\user\AppData\Roaming\EVENT MONITOR\ininotfound0.ini
Deleted: C:\Users\user\AppData\Roaming\EVENT MONITOR\isxdl.dll
Deleted: C:\Users\user\AppData\Roaming\EVENT MONITOR\japan_em.ini
Deleted: C:\Users\user\AppData\Roaming\EVENT MONITOR\log_04-17-2017.log
Deleted: C:\Users\user\AppData\Roaming\EVENT MONITOR\log_04-18-2017.log
Deleted: C:\Users\user\AppData\Roaming\EVENT MONITOR\log_04-19-2017.log
Deleted: C:\Users\user\AppData\Roaming\EVENT MONITOR\log_04-22-2017.log
Deleted: C:\Users\user\AppData\Roaming\EVENT MONITOR\log_04-23-2017.log
Deleted: C:\Users\user\AppData\Roaming\EVENT MONITOR\log_04-24-2017.log
Deleted: C:\Users\user\AppData\Roaming\EVENT MONITOR\update.ini
Deleted: C:\Users\user\AppData\Roaming\EVENT MONITOR
Cannot remove folder: C:\Users\user\AppData\Roaming\EVENT MONITOR\
Error: 0
Delete At reboot: C:\Users\user\AppData\Roaming\EVENT MONITOR
-------------------------------------------------------
01.05.2017 19:49:17 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete: \??\C:\PROGRA~3\MICROS~1\NETWORK\DSQ
Delete: \??\C:\ProgramData\WINDOWS SECURITY
Delete: \??\C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER
Delete: \??\C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK
Delete: \??\C:\PROGRAM FILES (X86)\FFF
Delete: C:\Users\user\AppData\Roaming\EVENT MONITOR
Delete Marked Items Auto Start Apps->Unwanted Software Files. MPC
Cleaner=C:\PROGRAM FILES (X86)\MPC CLEANER\
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Config\Clean.xf
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Config\DB\as.db
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Config\DB\cf.db
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Config\DB\run.db
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Config\DB\st.db
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Config\DB
Cannot delete: C:\PROGRAM FILES (X86)\MPC CLEANER\Config\DB
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Config\PlugIn.xf
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Config
Cannot delete: C:\PROGRAM FILES (X86)\MPC CLEANER\Config
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\ad_gray.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\ad_green.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\ad_org.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\ad_red.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\g1.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\g10.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\g11.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\g12.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\g2.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\g3.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\g4.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\g5.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\g6.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\g7.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\g8.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\g9.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\q1.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\q10.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\q11.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\q12.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\q2.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\q3.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\q4.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\q5.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\q6.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\q7.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\q8.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\q9.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\r1.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\r10.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\r11.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\r12.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\r2.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\r3.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\r4.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\r5.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\r6.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\r7.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\r8.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\r9.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\SearchIcon\toasts_waring.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\SearchIcon
Cannot delete: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\SearchIcon
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\SgIcon\adcapp.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\SgIcon\adcweb.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\SgIcon\block.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\SgIcon\home.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\SgIcon\ie.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\SgIcon\search.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\SgIcon
Cannot delete: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\SgIcon
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\SoIcon\AR_green.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\SoIcon\AR_org.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\SoIcon\AR_red.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\SoIcon\Bp_green.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\SoIcon\Bp_org.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\SoIcon\Bp_red.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\SoIcon\SpeedUp_green.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\SoIcon\SpeedUp_org.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\SoIcon\SpeedUp_red.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\SoIcon\SVC_green.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\SoIcon\SVC_org.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\SoIcon\SVC_red.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\SoIcon\TSK_green.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\SoIcon\TSK_org.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\SoIcon\TSK_red.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\SoIcon
Cannot delete: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\SoIcon
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\sys_gray.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\sys_green.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\sys_org.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\sys_red.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\y1.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\y10.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\y11.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\y12.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\y2.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\y3.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\y4.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\y5.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\y6.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\y7.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\y8.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image\y9.png
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Image
Cannot delete: C:\PROGRAM FILES (X86)\MPC CLEANER\Image
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\nmlct
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Skin\Cleaner\Lang.xf
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Skin\Cleaner\Skin.xf
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Skin\Cleaner
Cannot delete: C:\PROGRAM FILES (X86)\MPC CLEANER\Skin\Cleaner
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Skin\CrashReport\Lang.xf
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Skin\CrashReport\Skin.xf
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Skin\CrashReport
Cannot delete: C:\PROGRAM FILES (X86)\MPC CLEANER\Skin\CrashReport
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Skin\News\Lang.xf
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Skin\News\Skin.xf
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Skin\News
Cannot delete: C:\PROGRAM FILES (X86)\MPC CLEANER\Skin\News
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Skin\Tray\Lang.xf
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Skin\Tray\Skin.xf
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Skin\Tray
Cannot delete: C:\PROGRAM FILES (X86)\MPC CLEANER\Skin\Tray
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Skin\Uninstall\Lang.xf
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Skin\Uninstall\Skin.xf
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Skin\Uninstall
Cannot delete: C:\PROGRAM FILES (X86)\MPC CLEANER\Skin\Uninstall
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\Skin
Cannot delete: C:\PROGRAM FILES (X86)\MPC CLEANER\Skin
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\symsrv.yes
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER\wfhxte.dat
Deleted: C:\PROGRAM FILES (X86)\MPC CLEANER
Cannot remove folder: C:\PROGRAM FILES (X86)\MPC CLEANER\
Error: 0
Delete At reboot: C:\PROGRAM FILES (X86)\MPC CLEANER
-------------------------------------------------------
01.05.2017 19:49:17 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete: \??\C:\PROGRA~3\MICROS~1\NETWORK\DSQ
Delete: \??\C:\ProgramData\WINDOWS SECURITY
Delete: \??\C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER
Delete: \??\C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK
Delete: \??\C:\PROGRAM FILES (X86)\FFF
Delete: \??\C:\Users\user\AppData\Roaming\EVENT MONITOR
Delete: C:\PROGRAM FILES (X86)\MPC CLEANER
Delete Marked Items Auto Start Apps->Unwanted Software Files. C:\PROGRAM FILES
(X86)\\BADU\=C:\PROGRAM FILES (X86)\\BADU\
Deleted: C:\PROGRAM FILES (X86)\\BADU\unins000.dat
Deleted: C:\PROGRAM FILES (X86)\\BADU
Cannot remove folder: C:\PROGRAM FILES (X86)\\BADU\
Error: 0
Delete At reboot: C:\PROGRAM FILES (X86)\\BADU
-------------------------------------------------------
01.05.2017 19:49:17 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete: \??\C:\PROGRA~3\MICROS~1\NETWORK\DSQ
Delete: \??\C:\ProgramData\WINDOWS SECURITY
Delete: \??\C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER
Delete: \??\C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK
Delete: \??\C:\PROGRAM FILES (X86)\FFF
Delete: \??\C:\Users\user\AppData\Roaming\EVENT MONITOR
Delete: \??\C:\PROGRAM FILES (X86)\MPC CLEANER
Delete: C:\PROGRAM FILES (X86)\\BADU
Delete Marked Items Auto Start Apps->Unwanted Software Files.
ZDENGINE.DLL=C:\WINDOWS\SYSWOW64\ZDENGINE.DLL
Safe Deleting:C:\WINDOWS\SYSWOW64\ZDENGINE.DLL. You must restart your computer to
fully delete this file.
Delete Marked Items Auto Start Apps->Unwanted Software Files.
Ghetutainantigh=C:\USERS\USER\APPDATA\LOCAL\GHETUTAINANTIGH\
Deleted: C:\USERS\USER\APPDATA\LOCAL\GHETUTAINANTIGH
Cannot remove folder: C:\USERS\USER\APPDATA\LOCAL\GHETUTAINANTIGH\
Error: 0
Delete At reboot: C:\USERS\USER\APPDATA\LOCAL\GHETUTAINANTIGH
-------------------------------------------------------
01.05.2017 19:49:17 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete: \??\C:\PROGRA~3\MICROS~1\NETWORK\DSQ
Delete: \??\C:\ProgramData\WINDOWS SECURITY
Delete: \??\C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER
Delete: \??\C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK
Delete: \??\C:\PROGRAM FILES (X86)\FFF
Delete: \??\C:\Users\user\AppData\Roaming\EVENT MONITOR
Delete: \??\C:\PROGRAM FILES (X86)\MPC CLEANER
Delete: \??\C:\PROGRAM FILES (X86)\BADU
Delete: C:\USERS\USER\APPDATA\LOCAL\GHETUTAINANTIGH
Delete Marked Items Auto Start Apps->Unwanted Software Files.
C:\Users\user\AppData\Roaming\UPUPDATA\=C:\Users\user\AppData\Roaming\UPUPDATA\
Deleted: C:\Users\user\AppData\Roaming\UPUPDATA\webad.xml
Deleted: C:\Users\user\AppData\Roaming\UPUPDATA
Cannot remove folder: C:\Users\user\AppData\Roaming\UPUPDATA\
Error: 0
Delete At reboot: C:\Users\user\AppData\Roaming\UPUPDATA
-------------------------------------------------------
01.05.2017 19:49:18 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete: \??\C:\PROGRA~3\MICROS~1\NETWORK\DSQ
Delete: \??\C:\ProgramData\WINDOWS SECURITY
Delete: \??\C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER
Delete: \??\C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK
Delete: \??\C:\PROGRAM FILES (X86)\FFF
Delete: \??\C:\Users\user\AppData\Roaming\EVENT MONITOR
Delete: \??\C:\PROGRAM FILES (X86)\MPC CLEANER
Delete: \??\C:\PROGRAM FILES (X86)\BADU
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GHETUTAINANTIGH
Delete: C:\Users\user\AppData\Roaming\UPUPDATA
Delete Marked Items Auto Start Apps->Unwanted Software Files.
Chromium=C:\USERS\USER\APPDATA\LOCAL\CHROMIUM\
Deleted: C:\USERS\USER\APPDATA\LOCAL\CHROMIUM\Application\51.0.2683.0\Installer
Cannot delete:
C:\USERS\USER\APPDATA\LOCAL\CHROMIUM\Application\51.0.2683.0\Installer
Deleted: C:\USERS\USER\APPDATA\LOCAL\CHROMIUM\Application\51.0.2683.0
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\CHROMIUM\Application\51.0.2683.0
Deleted: C:\USERS\USER\APPDATA\LOCAL\CHROMIUM\Application\SetupMetrics.pma
Deleted: C:\USERS\USER\APPDATA\LOCAL\CHROMIUM\Application
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\CHROMIUM\Application
Deleted: C:\USERS\USER\APPDATA\LOCAL\CHROMIUM
Cannot remove folder: C:\USERS\USER\APPDATA\LOCAL\CHROMIUM\
Error: 0
Delete At reboot: C:\USERS\USER\APPDATA\LOCAL\CHROMIUM
-------------------------------------------------------
01.05.2017 19:49:18 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete: \??\C:\PROGRA~3\MICROS~1\NETWORK\DSQ
Delete: \??\C:\ProgramData\WINDOWS SECURITY
Delete: \??\C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER
Delete: \??\C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK
Delete: \??\C:\PROGRAM FILES (X86)\FFF
Delete: \??\C:\Users\user\AppData\Roaming\EVENT MONITOR
Delete: \??\C:\PROGRAM FILES (X86)\MPC CLEANER
Delete: \??\C:\PROGRAM FILES (X86)\BADU
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GHETUTAINANTIGH
Delete: \??\C:\Users\user\AppData\Roaming\UPUPDATA
Delete: C:\USERS\USER\APPDATA\LOCAL\CHROMIUM
Delete Marked Items Auto Start Apps->Unwanted Software Files. Youtube
AdBlock=C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK\
Deleted: C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK\local64spl.dll
Deleted: C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK\local64spl.dll.ini
Deleted: C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK
Cannot remove folder: C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK\
Error: 0
Delete At reboot: C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK
-------------------------------------------------------
01.05.2017 19:49:18 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete: \??\C:\PROGRA~3\MICROS~1\NETWORK\DSQ
Delete: \??\C:\ProgramData\WINDOWS SECURITY
Delete: \??\C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER
Delete: \??\C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK
Delete: \??\C:\PROGRAM FILES (X86)\FFF
Delete: \??\C:\Users\user\AppData\Roaming\EVENT MONITOR
Delete: \??\C:\PROGRAM FILES (X86)\MPC CLEANER
Delete: \??\C:\PROGRAM FILES (X86)\BADU
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GHETUTAINANTIGH
Delete: \??\C:\Users\user\AppData\Roaming\UPUPDATA
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\CHROMIUM
Delete: C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK
Delete Marked Items Auto Start Apps->Unwanted Software Files. Youtube
AdBlock1=C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK1\
Deleted: C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK1\local64spl.dll
Deleted: C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK1\local64spl.dll.ini
Deleted: C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK1
Cannot remove folder: C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK1\
Error: 0
Delete At reboot: C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK1
-------------------------------------------------------
01.05.2017 19:49:18 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete: \??\C:\PROGRA~3\MICROS~1\NETWORK\DSQ
Delete: \??\C:\ProgramData\WINDOWS SECURITY
Delete: \??\C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER
Delete: \??\C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK
Delete: \??\C:\PROGRAM FILES (X86)\FFF
Delete: \??\C:\Users\user\AppData\Roaming\EVENT MONITOR
Delete: \??\C:\PROGRAM FILES (X86)\MPC CLEANER
Delete: \??\C:\PROGRAM FILES (X86)\BADU
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GHETUTAINANTIGH
Delete: \??\C:\Users\user\AppData\Roaming\UPUPDATA
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\CHROMIUM
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK
Delete: C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK1
Delete Marked Items Auto Start Apps->Unwanted Software Files.
win_en_77=C:\USERS\USER\APPDATA\LOCAL\WIN_EN_77\
Deleted: C:\USERS\USER\APPDATA\LOCAL\WIN_EN_77\win_en_77\2.00\cnf.cyl
Deleted: C:\USERS\USER\APPDATA\LOCAL\WIN_EN_77\win_en_77\2.00\eorezo.cyl
Deleted: C:\USERS\USER\APPDATA\LOCAL\WIN_EN_77\win_en_77\2.00
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\WIN_EN_77\win_en_77\2.00
Deleted: C:\USERS\USER\APPDATA\LOCAL\WIN_EN_77\win_en_77
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\WIN_EN_77\win_en_77
Deleted: C:\USERS\USER\APPDATA\LOCAL\WIN_EN_77
Cannot remove folder: C:\USERS\USER\APPDATA\LOCAL\WIN_EN_77\
Error: 0
Delete At reboot: C:\USERS\USER\APPDATA\LOCAL\WIN_EN_77
-------------------------------------------------------
01.05.2017 19:49:18 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete: \??\C:\PROGRA~3\MICROS~1\NETWORK\DSQ
Delete: \??\C:\ProgramData\WINDOWS SECURITY
Delete: \??\C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER
Delete: \??\C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK
Delete: \??\C:\PROGRAM FILES (X86)\FFF
Delete: \??\C:\Users\user\AppData\Roaming\EVENT MONITOR
Delete: \??\C:\PROGRAM FILES (X86)\MPC CLEANER
Delete: \??\C:\PROGRAM FILES (X86)\BADU
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GHETUTAINANTIGH
Delete: \??\C:\Users\user\AppData\Roaming\UPUPDATA
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\CHROMIUM
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK1
Delete: C:\USERS\USER\APPDATA\LOCAL\WIN_EN_77
Delete Marked Items Auto Start Apps->Unwanted Software Files. C:\PROGRAM FILES
(X86)\\WEATHERCHICKN\=C:\PROGRAM FILES (X86)\\WEATHERCHICKN\
Deleted: C:\PROGRAM FILES (X86)\\WEATHERCHICKN
Cannot remove folder: C:\PROGRAM FILES (X86)\\WEATHERCHICKN\
Error: 0
Delete At reboot: C:\PROGRAM FILES (X86)\\WEATHERCHICKN
-------------------------------------------------------
01.05.2017 19:49:18 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete: \??\C:\PROGRA~3\MICROS~1\NETWORK\DSQ
Delete: \??\C:\ProgramData\WINDOWS SECURITY
Delete: \??\C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER
Delete: \??\C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK
Delete: \??\C:\PROGRAM FILES (X86)\FFF
Delete: \??\C:\Users\user\AppData\Roaming\EVENT MONITOR
Delete: \??\C:\PROGRAM FILES (X86)\MPC CLEANER
Delete: \??\C:\PROGRAM FILES (X86)\BADU
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GHETUTAINANTIGH
Delete: \??\C:\Users\user\AppData\Roaming\UPUPDATA
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\CHROMIUM
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\WIN_EN_77
Delete: C:\PROGRAM FILES (X86)\\WEATHERCHICKN
Delete Marked Items Auto Start Apps->Unwanted Software Files.
tuto_monetize_120160723=C:\USERS\USER\APPDATA\LOCAL\TUTO_MONETIZE_120160723\
Deleted:
C:\USERS\USER\APPDATA\LOCAL\TUTO_MONETIZE_120160723\tuto_monetize_120160723\2.00\cn
f.cyl
Deleted:
C:\USERS\USER\APPDATA\LOCAL\TUTO_MONETIZE_120160723\tuto_monetize_120160723\2.00
Cannot delete:
C:\USERS\USER\APPDATA\LOCAL\TUTO_MONETIZE_120160723\tuto_monetize_120160723\2.00
Deleted:
C:\USERS\USER\APPDATA\LOCAL\TUTO_MONETIZE_120160723\tuto_monetize_120160723
Cannot delete:
C:\USERS\USER\APPDATA\LOCAL\TUTO_MONETIZE_120160723\tuto_monetize_120160723
Deleted: C:\USERS\USER\APPDATA\LOCAL\TUTO_MONETIZE_120160723
Cannot remove folder: C:\USERS\USER\APPDATA\LOCAL\TUTO_MONETIZE_120160723\
Error: 0
Delete At reboot: C:\USERS\USER\APPDATA\LOCAL\TUTO_MONETIZE_120160723
-------------------------------------------------------
01.05.2017 19:49:18 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete: \??\C:\PROGRA~3\MICROS~1\NETWORK\DSQ
Delete: \??\C:\ProgramData\WINDOWS SECURITY
Delete: \??\C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER
Delete: \??\C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK
Delete: \??\C:\PROGRAM FILES (X86)\FFF
Delete: \??\C:\Users\user\AppData\Roaming\EVENT MONITOR
Delete: \??\C:\PROGRAM FILES (X86)\MPC CLEANER
Delete: \??\C:\PROGRAM FILES (X86)\BADU
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GHETUTAINANTIGH
Delete: \??\C:\Users\user\AppData\Roaming\UPUPDATA
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\CHROMIUM
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\WIN_EN_77
Delete: \??\C:\PROGRAM FILES (X86)\WEATHERCHICKN
Delete: C:\USERS\USER\APPDATA\LOCAL\TUTO_MONETIZE_120160723
Delete Marked Items Auto Start Apps->Unwanted Software Files. surranderu=C:\PROGRAM
FILES (X86)\SURRANDERU\
Deleted: C:\PROGRAM FILES (X86)\SURRANDERU\unins000.dat
Deleted: C:\PROGRAM FILES (X86)\SURRANDERU
Cannot remove folder: C:\PROGRAM FILES (X86)\SURRANDERU\
Error: 0
Delete At reboot: C:\PROGRAM FILES (X86)\SURRANDERU
-------------------------------------------------------
01.05.2017 19:49:18 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete: \??\C:\PROGRA~3\MICROS~1\NETWORK\DSQ
Delete: \??\C:\ProgramData\WINDOWS SECURITY
Delete: \??\C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER
Delete: \??\C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK
Delete: \??\C:\PROGRAM FILES (X86)\FFF
Delete: \??\C:\Users\user\AppData\Roaming\EVENT MONITOR
Delete: \??\C:\PROGRAM FILES (X86)\MPC CLEANER
Delete: \??\C:\PROGRAM FILES (X86)\BADU
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GHETUTAINANTIGH
Delete: \??\C:\Users\user\AppData\Roaming\UPUPDATA
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\CHROMIUM
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\WIN_EN_77
Delete: \??\C:\PROGRAM FILES (X86)\WEATHERCHICKN
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TUTO_MONETIZE_120160723
Delete: C:\PROGRAM FILES (X86)\SURRANDERU
Delete Marked Items Auto Start Apps->Unwanted Software Files.
C:\ProgramData\QUOTEEX\=C:\ProgramData\QUOTEEX\
Deleted: C:\ProgramData\QUOTEEX\Config.xml
Deleted: C:\ProgramData\QUOTEEX\Daltdom.dat
Deleted: C:\ProgramData\QUOTEEX\Dentoeco.bin
Deleted: C:\ProgramData\QUOTEEX\md.xml
Deleted: C:\ProgramData\QUOTEEX\ondemand
Cannot delete: C:\ProgramData\QUOTEEX\ondemand
Deleted: C:\ProgramData\QUOTEEX\QuoKeylex.dat
Deleted: C:\ProgramData\QUOTEEX\Quoteex.d.dat
Deleted: C:\ProgramData\QUOTEEX\Quoteex.dat
Deleted: C:\ProgramData\QUOTEEX\Solohotlab.bin
Deleted: C:\ProgramData\QUOTEEX\Statfan.bin
Deleted: C:\ProgramData\QUOTEEX\Tranlux.dat
Deleted: C:\ProgramData\QUOTEEX\uninstall.dat
Deleted: C:\ProgramData\QUOTEEX\WarmSailing.bin
Deleted: C:\ProgramData\QUOTEEX\Zamtrax.bin
Deleted: C:\ProgramData\QUOTEEX\ZenDubstring.bin
Deleted: C:\ProgramData\QUOTEEX\Zummais.bin
Deleted: C:\ProgramData\QUOTEEX
Cannot remove folder: C:\ProgramData\QUOTEEX\
Error: 0
Delete At reboot: C:\ProgramData\QUOTEEX
-------------------------------------------------------
01.05.2017 19:49:18 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete: \??\C:\PROGRA~3\MICROS~1\NETWORK\DSQ
Delete: \??\C:\ProgramData\WINDOWS SECURITY
Delete: \??\C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER
Delete: \??\C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK
Delete: \??\C:\PROGRAM FILES (X86)\FFF
Delete: \??\C:\Users\user\AppData\Roaming\EVENT MONITOR
Delete: \??\C:\PROGRAM FILES (X86)\MPC CLEANER
Delete: \??\C:\PROGRAM FILES (X86)\BADU
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GHETUTAINANTIGH
Delete: \??\C:\Users\user\AppData\Roaming\UPUPDATA
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\CHROMIUM
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\WIN_EN_77
Delete: \??\C:\PROGRAM FILES (X86)\WEATHERCHICKN
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TUTO_MONETIZE_120160723
Delete: \??\C:\PROGRAM FILES (X86)\SURRANDERU
Delete: C:\ProgramData\QUOTEEX
Delete Marked Items Auto Start Apps->Unwanted Software Files. C:\PROGRAM FILES
(X86)\\CONTENTPUSH\=C:\PROGRAM FILES (X86)\\CONTENTPUSH\
Cannot delete: C:\PROGRAM FILES (X86)\\CONTENTPUSH
Cannot remove folder: C:\PROGRAM FILES (X86)\\CONTENTPUSH\
Error: 0
Delete At reboot: C:\PROGRAM FILES (X86)\\CONTENTPUSH
-------------------------------------------------------
01.05.2017 19:49:18 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete: \??\C:\PROGRA~3\MICROS~1\NETWORK\DSQ
Delete: \??\C:\ProgramData\WINDOWS SECURITY
Delete: \??\C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER
Delete: \??\C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK
Delete: \??\C:\PROGRAM FILES (X86)\FFF
Delete: \??\C:\Users\user\AppData\Roaming\EVENT MONITOR
Delete: \??\C:\PROGRAM FILES (X86)\MPC CLEANER
Delete: \??\C:\PROGRAM FILES (X86)\BADU
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GHETUTAINANTIGH
Delete: \??\C:\Users\user\AppData\Roaming\UPUPDATA
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\CHROMIUM
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\WIN_EN_77
Delete: \??\C:\PROGRAM FILES (X86)\WEATHERCHICKN
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TUTO_MONETIZE_120160723
Delete: \??\C:\PROGRAM FILES (X86)\SURRANDERU
Delete: \??\C:\ProgramData\QUOTEEX
Delete: C:\PROGRAM FILES (X86)\\CONTENTPUSH
Delete Marked Items Auto Start Apps->Unwanted Software Files. mpck=C:\PROGRAM FILES
(X86)\MPCK\
Deleted: C:\PROGRAM FILES (X86)\MPCK\config.conf
Deleted: C:\PROGRAM FILES (X86)\MPCK\EPDKKWHERAO0DPM.exe
Deleted: C:\PROGRAM FILES (X86)\MPCK\unins000.dat
Deleted: C:\PROGRAM FILES (X86)\MPCK
Cannot remove folder: C:\PROGRAM FILES (X86)\MPCK\
Error: 0
Delete At reboot: C:\PROGRAM FILES (X86)\MPCK
-------------------------------------------------------
01.05.2017 19:49:19 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete: \??\C:\PROGRA~3\MICROS~1\NETWORK\DSQ
Delete: \??\C:\ProgramData\WINDOWS SECURITY
Delete: \??\C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER
Delete: \??\C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK
Delete: \??\C:\PROGRAM FILES (X86)\FFF
Delete: \??\C:\Users\user\AppData\Roaming\EVENT MONITOR
Delete: \??\C:\PROGRAM FILES (X86)\MPC CLEANER
Delete: \??\C:\PROGRAM FILES (X86)\BADU
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GHETUTAINANTIGH
Delete: \??\C:\Users\user\AppData\Roaming\UPUPDATA
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\CHROMIUM
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\WIN_EN_77
Delete: \??\C:\PROGRAM FILES (X86)\WEATHERCHICKN
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TUTO_MONETIZE_120160723
Delete: \??\C:\PROGRAM FILES (X86)\SURRANDERU
Delete: \??\C:\ProgramData\QUOTEEX
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: C:\PROGRAM FILES (X86)\MPCK
Delete Marked Items Auto Start Apps->Unwanted Software Files.
pccleanplus=C:\PROGRAM FILES (X86)\PCCLEANPLUS\
Deleted: C:\PROGRAM FILES (X86)\PCCLEANPLUS\uninstaller.exe.config
Deleted: C:\PROGRAM FILES (X86)\PCCLEANPLUS
Cannot remove folder: C:\PROGRAM FILES (X86)\PCCLEANPLUS\
Error: 0
Delete At reboot: C:\PROGRAM FILES (X86)\PCCLEANPLUS
-------------------------------------------------------
01.05.2017 19:49:19 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete: \??\C:\PROGRA~3\MICROS~1\NETWORK\DSQ
Delete: \??\C:\ProgramData\WINDOWS SECURITY
Delete: \??\C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER
Delete: \??\C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK
Delete: \??\C:\PROGRAM FILES (X86)\FFF
Delete: \??\C:\Users\user\AppData\Roaming\EVENT MONITOR
Delete: \??\C:\PROGRAM FILES (X86)\MPC CLEANER
Delete: \??\C:\PROGRAM FILES (X86)\BADU
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GHETUTAINANTIGH
Delete: \??\C:\Users\user\AppData\Roaming\UPUPDATA
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\CHROMIUM
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\WIN_EN_77
Delete: \??\C:\PROGRAM FILES (X86)\WEATHERCHICKN
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TUTO_MONETIZE_120160723
Delete: \??\C:\PROGRAM FILES (X86)\SURRANDERU
Delete: \??\C:\ProgramData\QUOTEEX
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\MPCK
Delete: C:\PROGRAM FILES (X86)\PCCLEANPLUS
Delete Marked Items Auto Start Apps->Unwanted Software Files.
gplyra=C:\USERS\USER\APPDATA\ROAMING\GPLYRA\
Deleted:
C:\USERS\USER\APPDATA\ROAMING\GPLYRA\gplyra\decredCapeverdegw256l4tc10624.bin
Deleted: C:\USERS\USER\APPDATA\ROAMING\GPLYRA\gplyra\gplyra.conf
Deleted: C:\USERS\USER\APPDATA\ROAMING\GPLYRA\gplyra\gplyra.exe
Deleted: C:\USERS\USER\APPDATA\ROAMING\GPLYRA\gplyra\kernel\aes_helper.cl
Deleted: C:\USERS\USER\APPDATA\ROAMING\GPLYRA\gplyra\kernel\blake.cl
Deleted: C:\USERS\USER\APPDATA\ROAMING\GPLYRA\gplyra\kernel\blake256.cl
Deleted: C:\USERS\USER\APPDATA\ROAMING\GPLYRA\gplyra\kernel\bmw.cl
Deleted: C:\USERS\USER\APPDATA\ROAMING\GPLYRA\gplyra\kernel\bmw256.cl
Deleted: C:\USERS\USER\APPDATA\ROAMING\GPLYRA\gplyra\kernel\cubehash.cl
Deleted: C:\USERS\USER\APPDATA\ROAMING\GPLYRA\gplyra\kernel\darkcoin-mod.cl
Deleted: C:\USERS\USER\APPDATA\ROAMING\GPLYRA\gplyra\kernel\decred.cl
Deleted: C:\USERS\USER\APPDATA\ROAMING\GPLYRA\gplyra\kernel\echo.cl
Deleted: C:\USERS\USER\APPDATA\ROAMING\GPLYRA\gplyra\kernel\fugue.cl
Deleted: C:\USERS\USER\APPDATA\ROAMING\GPLYRA\gplyra\kernel\groestl.cl
Deleted: C:\USERS\USER\APPDATA\ROAMING\GPLYRA\gplyra\kernel\groestl256.cl
Deleted: C:\USERS\USER\APPDATA\ROAMING\GPLYRA\gplyra\kernel\jh.cl
Deleted: C:\USERS\USER\APPDATA\ROAMING\GPLYRA\gplyra\kernel\keccak.cl
Deleted: C:\USERS\USER\APPDATA\ROAMING\GPLYRA\gplyra\kernel\keccak1600.cl
Deleted: C:\USERS\USER\APPDATA\ROAMING\GPLYRA\gplyra\kernel\luffa.cl
Deleted: C:\USERS\USER\APPDATA\ROAMING\GPLYRA\gplyra\kernel\lyra2.cl
Deleted: C:\USERS\USER\APPDATA\ROAMING\GPLYRA\gplyra\kernel\lyra2re.cl
Deleted: C:\USERS\USER\APPDATA\ROAMING\GPLYRA\gplyra\kernel\lyra2rev2.cl
Deleted: C:\USERS\USER\APPDATA\ROAMING\GPLYRA\gplyra\kernel\lyra2v2.cl
Deleted: C:\USERS\USER\APPDATA\ROAMING\GPLYRA\gplyra\kernel\neoscrypt.cl
Deleted: C:\USERS\USER\APPDATA\ROAMING\GPLYRA\gplyra\kernel\shabal.cl
Deleted: C:\USERS\USER\APPDATA\ROAMING\GPLYRA\gplyra\kernel\shavite.cl
Deleted: C:\USERS\USER\APPDATA\ROAMING\GPLYRA\gplyra\kernel\simd.cl
Deleted: C:\USERS\USER\APPDATA\ROAMING\GPLYRA\gplyra\kernel\skein.cl
Deleted: C:\USERS\USER\APPDATA\ROAMING\GPLYRA\gplyra\kernel\skein256.cl
Deleted: C:\USERS\USER\APPDATA\ROAMING\GPLYRA\gplyra\kernel\vanilla.cl
Deleted: C:\USERS\USER\APPDATA\ROAMING\GPLYRA\gplyra\kernel
Cannot delete: C:\USERS\USER\APPDATA\ROAMING\GPLYRA\gplyra\kernel
Deleted: C:\USERS\USER\APPDATA\ROAMING\GPLYRA\gplyra\msvcr120.dll
Deleted: C:\USERS\USER\APPDATA\ROAMING\GPLYRA\gplyra\start.cmd
Deleted: C:\USERS\USER\APPDATA\ROAMING\GPLYRA\gplyra
Cannot delete: C:\USERS\USER\APPDATA\ROAMING\GPLYRA\gplyra
Deleted: C:\USERS\USER\APPDATA\ROAMING\GPLYRA\gplyra-uninst.exe
Deleted: C:\USERS\USER\APPDATA\ROAMING\GPLYRA
Cannot remove folder: C:\USERS\USER\APPDATA\ROAMING\GPLYRA\
Error: 0
Delete At reboot: C:\USERS\USER\APPDATA\ROAMING\GPLYRA
-------------------------------------------------------
01.05.2017 19:49:19 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete: \??\C:\PROGRA~3\MICROS~1\NETWORK\DSQ
Delete: \??\C:\ProgramData\WINDOWS SECURITY
Delete: \??\C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER
Delete: \??\C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK
Delete: \??\C:\PROGRAM FILES (X86)\FFF
Delete: \??\C:\Users\user\AppData\Roaming\EVENT MONITOR
Delete: \??\C:\PROGRAM FILES (X86)\MPC CLEANER
Delete: \??\C:\PROGRAM FILES (X86)\BADU
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GHETUTAINANTIGH
Delete: \??\C:\Users\user\AppData\Roaming\UPUPDATA
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\CHROMIUM
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\WIN_EN_77
Delete: \??\C:\PROGRAM FILES (X86)\WEATHERCHICKN
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TUTO_MONETIZE_120160723
Delete: \??\C:\PROGRAM FILES (X86)\SURRANDERU
Delete: \??\C:\ProgramData\QUOTEEX
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\MPCK
Delete: \??\C:\PROGRAM FILES (X86)\PCCLEANPLUS
Delete: C:\USERS\USER\APPDATA\ROAMING\GPLYRA
Delete Marked Items Auto Start Apps->Unwanted Software Files.
CloudPrinter=C:\PROGRAMDATA\CLOUDPRINTER\
Deleted: C:\PROGRAMDATA\CLOUDPRINTER\CloudPrinter.dat
Deleted: C:\PROGRAMDATA\CLOUDPRINTER\Config.xml
Deleted: C:\PROGRAMDATA\CLOUDPRINTER
Cannot remove folder: C:\PROGRAMDATA\CLOUDPRINTER\
Error: 0
Delete At reboot: C:\PROGRAMDATA\CLOUDPRINTER
-------------------------------------------------------
01.05.2017 19:49:19 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete: \??\C:\PROGRA~3\MICROS~1\NETWORK\DSQ
Delete: \??\C:\ProgramData\WINDOWS SECURITY
Delete: \??\C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER
Delete: \??\C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK
Delete: \??\C:\PROGRAM FILES (X86)\FFF
Delete: \??\C:\Users\user\AppData\Roaming\EVENT MONITOR
Delete: \??\C:\PROGRAM FILES (X86)\MPC CLEANER
Delete: \??\C:\PROGRAM FILES (X86)\BADU
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GHETUTAINANTIGH
Delete: \??\C:\Users\user\AppData\Roaming\UPUPDATA
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\CHROMIUM
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\WIN_EN_77
Delete: \??\C:\PROGRAM FILES (X86)\WEATHERCHICKN
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TUTO_MONETIZE_120160723
Delete: \??\C:\PROGRAM FILES (X86)\SURRANDERU
Delete: \??\C:\ProgramData\QUOTEEX
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\MPCK
Delete: \??\C:\PROGRAM FILES (X86)\PCCLEANPLUS
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\GPLYRA
Delete: C:\PROGRAMDATA\CLOUDPRINTER
Delete Marked Items Auto Start Apps->Unwanted Software Files.
Dlosarecertain=C:\USERS\USER\APPDATA\ROAMING\DLOSARECERTAIN\
Deleted: C:\USERS\USER\APPDATA\ROAMING\DLOSARECERTAIN
Cannot remove folder: C:\USERS\USER\APPDATA\ROAMING\DLOSARECERTAIN\
Error: 0
Delete At reboot: C:\USERS\USER\APPDATA\ROAMING\DLOSARECERTAIN
-------------------------------------------------------
01.05.2017 19:49:19 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete: \??\C:\PROGRA~3\MICROS~1\NETWORK\DSQ
Delete: \??\C:\ProgramData\WINDOWS SECURITY
Delete: \??\C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER
Delete: \??\C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK
Delete: \??\C:\PROGRAM FILES (X86)\FFF
Delete: \??\C:\Users\user\AppData\Roaming\EVENT MONITOR
Delete: \??\C:\PROGRAM FILES (X86)\MPC CLEANER
Delete: \??\C:\PROGRAM FILES (X86)\BADU
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GHETUTAINANTIGH
Delete: \??\C:\Users\user\AppData\Roaming\UPUPDATA
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\CHROMIUM
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\WIN_EN_77
Delete: \??\C:\PROGRAM FILES (X86)\WEATHERCHICKN
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TUTO_MONETIZE_120160723
Delete: \??\C:\PROGRAM FILES (X86)\SURRANDERU
Delete: \??\C:\ProgramData\QUOTEEX
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\MPCK
Delete: \??\C:\PROGRAM FILES (X86)\PCCLEANPLUS
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\GPLYRA
Delete: \??\C:\PROGRAMDATA\CLOUDPRINTER
Delete: C:\USERS\USER\APPDATA\ROAMING\DLOSARECERTAIN
Delete Marked Items Auto Start Apps->Unwanted Software Files. Youtube
AdBlock1=C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCK1\
Deleted: C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCK1\local64spl.dll
Deleted: C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCK1\local64spl.dll.ini
Deleted: C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCK1
Cannot remove folder: C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCK1\
Error: 0
Delete At reboot: C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCK1
-------------------------------------------------------
01.05.2017 19:49:19 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete: \??\C:\PROGRA~3\MICROS~1\NETWORK\DSQ
Delete: \??\C:\ProgramData\WINDOWS SECURITY
Delete: \??\C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER
Delete: \??\C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK
Delete: \??\C:\PROGRAM FILES (X86)\FFF
Delete: \??\C:\Users\user\AppData\Roaming\EVENT MONITOR
Delete: \??\C:\PROGRAM FILES (X86)\MPC CLEANER
Delete: \??\C:\PROGRAM FILES (X86)\BADU
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GHETUTAINANTIGH
Delete: \??\C:\Users\user\AppData\Roaming\UPUPDATA
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\CHROMIUM
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\WIN_EN_77
Delete: \??\C:\PROGRAM FILES (X86)\WEATHERCHICKN
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TUTO_MONETIZE_120160723
Delete: \??\C:\PROGRAM FILES (X86)\SURRANDERU
Delete: \??\C:\ProgramData\QUOTEEX
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\MPCK
Delete: \??\C:\PROGRAM FILES (X86)\PCCLEANPLUS
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\GPLYRA
Delete: \??\C:\PROGRAMDATA\CLOUDPRINTER
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\DLOSARECERTAIN
Delete: C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCK1
Delete Marked Items Auto Start Apps->Unwanted Software Files. Youtube
AdBlockjlrvmnhpdy=C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCKJLRVMNHPDY\
Deleted: C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCKJLRVMNHPDY\local64spl.dll
Deleted: C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCKJLRVMNHPDY\local64spl.dll.ini
Deleted: C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCKJLRVMNHPDY
Cannot remove folder: C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCKJLRVMNHPDY\
Error: 0
Delete At reboot: C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCKJLRVMNHPDY
-------------------------------------------------------
01.05.2017 19:49:19 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete: \??\C:\PROGRA~3\MICROS~1\NETWORK\DSQ
Delete: \??\C:\ProgramData\WINDOWS SECURITY
Delete: \??\C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER
Delete: \??\C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK
Delete: \??\C:\PROGRAM FILES (X86)\FFF
Delete: \??\C:\Users\user\AppData\Roaming\EVENT MONITOR
Delete: \??\C:\PROGRAM FILES (X86)\MPC CLEANER
Delete: \??\C:\PROGRAM FILES (X86)\BADU
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GHETUTAINANTIGH
Delete: \??\C:\Users\user\AppData\Roaming\UPUPDATA
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\CHROMIUM
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\WIN_EN_77
Delete: \??\C:\PROGRAM FILES (X86)\WEATHERCHICKN
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TUTO_MONETIZE_120160723
Delete: \??\C:\PROGRAM FILES (X86)\SURRANDERU
Delete: \??\C:\ProgramData\QUOTEEX
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\MPCK
Delete: \??\C:\PROGRAM FILES (X86)\PCCLEANPLUS
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\GPLYRA
Delete: \??\C:\PROGRAMDATA\CLOUDPRINTER
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\DLOSARECERTAIN
Delete: \??\C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCK1
Delete: C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCKJLRVMNHPDY
Delete Marked Items Auto Start Apps->Unwanted Software Files. Vegaght=C:\PROGRAM
FILES (X86)\VEGAGHT\
Deleted: C:\PROGRAM FILES (X86)\VEGAGHT\arerpiph.exe
Deleted: C:\PROGRAM FILES (X86)\VEGAGHT\CrashReport.dll
Deleted: C:\PROGRAM FILES (X86)\VEGAGHT\Ferferrypekerkhlp.dll
Deleted: C:\PROGRAM FILES (X86)\VEGAGHT\launcher_43.dll
Deleted: C:\PROGRAM FILES (X86)\VEGAGHT\WedOct
Deleted: C:\PROGRAM FILES (X86)\VEGAGHT
Cannot remove folder: C:\PROGRAM FILES (X86)\VEGAGHT\
Error: 0
Delete At reboot: C:\PROGRAM FILES (X86)\VEGAGHT
-------------------------------------------------------
01.05.2017 19:49:19 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete: \??\C:\PROGRA~3\MICROS~1\NETWORK\DSQ
Delete: \??\C:\ProgramData\WINDOWS SECURITY
Delete: \??\C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER
Delete: \??\C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK
Delete: \??\C:\PROGRAM FILES (X86)\FFF
Delete: \??\C:\Users\user\AppData\Roaming\EVENT MONITOR
Delete: \??\C:\PROGRAM FILES (X86)\MPC CLEANER
Delete: \??\C:\PROGRAM FILES (X86)\BADU
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GHETUTAINANTIGH
Delete: \??\C:\Users\user\AppData\Roaming\UPUPDATA
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\CHROMIUM
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\WIN_EN_77
Delete: \??\C:\PROGRAM FILES (X86)\WEATHERCHICKN
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TUTO_MONETIZE_120160723
Delete: \??\C:\PROGRAM FILES (X86)\SURRANDERU
Delete: \??\C:\ProgramData\QUOTEEX
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\MPCK
Delete: \??\C:\PROGRAM FILES (X86)\PCCLEANPLUS
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\GPLYRA
Delete: \??\C:\PROGRAMDATA\CLOUDPRINTER
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\DLOSARECERTAIN
Delete: \??\C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCK1
Delete: \??\C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCKJLRVMNHPDY
Delete: C:\PROGRAM FILES (X86)\VEGAGHT
Delete Marked Items Auto Start Apps->Unwanted Software Files. PubHotspot=C:\PROGRAM
FILES (X86)\PUBHOTSPOT\
Cannot delete: C:\PROGRAM FILES (X86)\PUBHOTSPOT
Cannot remove folder: C:\PROGRAM FILES (X86)\PUBHOTSPOT\
Error: 0
Delete At reboot: C:\PROGRAM FILES (X86)\PUBHOTSPOT
-------------------------------------------------------
01.05.2017 19:49:20 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete: \??\C:\PROGRA~3\MICROS~1\NETWORK\DSQ
Delete: \??\C:\ProgramData\WINDOWS SECURITY
Delete: \??\C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER
Delete: \??\C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK
Delete: \??\C:\PROGRAM FILES (X86)\FFF
Delete: \??\C:\Users\user\AppData\Roaming\EVENT MONITOR
Delete: \??\C:\PROGRAM FILES (X86)\MPC CLEANER
Delete: \??\C:\PROGRAM FILES (X86)\BADU
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GHETUTAINANTIGH
Delete: \??\C:\Users\user\AppData\Roaming\UPUPDATA
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\CHROMIUM
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\WIN_EN_77
Delete: \??\C:\PROGRAM FILES (X86)\WEATHERCHICKN
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TUTO_MONETIZE_120160723
Delete: \??\C:\PROGRAM FILES (X86)\SURRANDERU
Delete: \??\C:\ProgramData\QUOTEEX
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\MPCK
Delete: \??\C:\PROGRAM FILES (X86)\PCCLEANPLUS
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\GPLYRA
Delete: \??\C:\PROGRAMDATA\CLOUDPRINTER
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\DLOSARECERTAIN
Delete: \??\C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCK1
Delete: \??\C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCKJLRVMNHPDY
Delete: \??\C:\PROGRAM FILES (X86)\VEGAGHT
Delete: C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete Marked Items Auto Start Apps->Unwanted Software Files. Mozilla
Firefox=C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\
Deleted: C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\browser\features\local64spl.dll
Deleted: C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\browser\features\local64spl.dll.ini
Deleted: C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\browser\features
Cannot delete: C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\browser\features
Deleted: C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\browser\features1\local64spl.dll
Deleted: C:\PROGRAM FILES (X86)\MOZILLA
FIREFOX\browser\features1\local64spl.dll.ini
Deleted: C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\browser\features1
Cannot delete: C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\browser\features1
Deleted: C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\browser
Cannot delete: C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\browser
Deleted: C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\plugins\nppdf32.dll
Deleted: C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\plugins
Cannot delete: C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\plugins
Deleted: C:\PROGRAM FILES (X86)\MOZILLA FIREFOX
Cannot remove folder: C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\
Error: 0
Delete At reboot: C:\PROGRAM FILES (X86)\MOZILLA FIREFOX
-------------------------------------------------------
01.05.2017 19:49:20 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete: \??\C:\PROGRA~3\MICROS~1\NETWORK\DSQ
Delete: \??\C:\ProgramData\WINDOWS SECURITY
Delete: \??\C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER
Delete: \??\C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK
Delete: \??\C:\PROGRAM FILES (X86)\FFF
Delete: \??\C:\Users\user\AppData\Roaming\EVENT MONITOR
Delete: \??\C:\PROGRAM FILES (X86)\MPC CLEANER
Delete: \??\C:\PROGRAM FILES (X86)\BADU
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GHETUTAINANTIGH
Delete: \??\C:\Users\user\AppData\Roaming\UPUPDATA
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\CHROMIUM
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\WIN_EN_77
Delete: \??\C:\PROGRAM FILES (X86)\WEATHERCHICKN
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TUTO_MONETIZE_120160723
Delete: \??\C:\PROGRAM FILES (X86)\SURRANDERU
Delete: \??\C:\ProgramData\QUOTEEX
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\MPCK
Delete: \??\C:\PROGRAM FILES (X86)\PCCLEANPLUS
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\GPLYRA
Delete: \??\C:\PROGRAMDATA\CLOUDPRINTER
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\DLOSARECERTAIN
Delete: \??\C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCK1
Delete: \??\C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCKJLRVMNHPDY
Delete: \??\C:\PROGRAM FILES (X86)\VEGAGHT
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: C:\PROGRAM FILES (X86)\MOZILLA FIREFOX
Delete Marked Items Auto Start Apps->Unwanted Software Files.
Quoteexs=C:\PROGRAMDATA\QUOTEEXS\
Deleted: C:\PROGRAMDATA\QUOTEEXS\ff.HP
Deleted: C:\PROGRAMDATA\QUOTEEXS\ff.NT
Deleted: C:\PROGRAMDATA\QUOTEEXS\snp.sc
Deleted: C:\PROGRAMDATA\QUOTEEXS
Cannot remove folder: C:\PROGRAMDATA\QUOTEEXS\
Error: 0
Delete At reboot: C:\PROGRAMDATA\QUOTEEXS
-------------------------------------------------------
01.05.2017 19:49:20 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete: \??\C:\PROGRA~3\MICROS~1\NETWORK\DSQ
Delete: \??\C:\ProgramData\WINDOWS SECURITY
Delete: \??\C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER
Delete: \??\C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK
Delete: \??\C:\PROGRAM FILES (X86)\FFF
Delete: \??\C:\Users\user\AppData\Roaming\EVENT MONITOR
Delete: \??\C:\PROGRAM FILES (X86)\MPC CLEANER
Delete: \??\C:\PROGRAM FILES (X86)\BADU
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GHETUTAINANTIGH
Delete: \??\C:\Users\user\AppData\Roaming\UPUPDATA
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\CHROMIUM
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\WIN_EN_77
Delete: \??\C:\PROGRAM FILES (X86)\WEATHERCHICKN
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TUTO_MONETIZE_120160723
Delete: \??\C:\PROGRAM FILES (X86)\SURRANDERU
Delete: \??\C:\ProgramData\QUOTEEX
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\MPCK
Delete: \??\C:\PROGRAM FILES (X86)\PCCLEANPLUS
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\GPLYRA
Delete: \??\C:\PROGRAMDATA\CLOUDPRINTER
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\DLOSARECERTAIN
Delete: \??\C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCK1
Delete: \??\C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCKJLRVMNHPDY
Delete: \??\C:\PROGRAM FILES (X86)\VEGAGHT
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\PROGRAM FILES (X86)\MOZILLA FIREFOX
Delete: C:\PROGRAMDATA\QUOTEEXS
Delete Marked Items Auto Start Apps->Unwanted Software Files.
Thuvet=C:\USERS\USER\APPDATA\LOCAL\THUVET\
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\Certificate Revocation Lists
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\CertificateTransparency\322\manifest.fingerprint
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\CertificateTransparency\322\manifest.json
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\CertificateTransparency\322\_platform_specific\a
ll\sths\293c519654c83965baaa50fc5807d4b76fbf587a2972dca4c30cf4e54547f478.sth
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\CertificateTransparency\322\_platform_specific\a
ll\sths\34bb6ad6c3df9c03eea8a499ff7891486c9d5e5cac92d01f7bfd1bce19db48ef.sth
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\CertificateTransparency\322\_platform_specific\a
ll\sths\41b2dc2e89e63ce4af1ba7bb29bf68c6dee6f9f1cc047e30dffae3b3ba259263.sth
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\CertificateTransparency\322\_platform_specific\a
ll\sths\5614069a2fd7c2ecd3f5e1bd44b23ec74676b9bc99115cc0ef949855d689d0dd.sth
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\CertificateTransparency\322\_platform_specific\a
ll\sths\68f698f81f6482be3a8ceeb9281d4cfc71515d6793d444d10a67acbb4f4ffbc4.sth
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\CertificateTransparency\322\_platform_specific\a
ll\sths\7461b4a09cfb3d41d75159575b2e7649a445a8d27709b0cc564a6482b7eb41a3.sth
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\CertificateTransparency\322\_platform_specific\a
ll\sths\a4b90990b418581487bb13a2cc67700a3c359804f91bdfb8e377cd0ec80ddc10.sth
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\CertificateTransparency\322\_platform_specific\a
ll\sths\a577ac9ced7548dd8f025b67a241089df86e0f476ec203c2ecbedb185f282638.sth
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\CertificateTransparency\322\_platform_specific\a
ll\sths\ac3b9aed7fa9674757159e6d7d575672f9d98100941e9bdeffeca1313b75782d.sth
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\CertificateTransparency\322\_platform_specific\a
ll\sths\bbd9dfbc1f8a71b593942397aa927b473857950aab52e81a909664368e1ed185.sth
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\CertificateTransparency\322\_platform_specific\a
ll\sths\bc78e1dfc5f63c684649334da10fa15f0979692009c081b4f3f6917f3ed9b8a5.sth
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\CertificateTransparency\322\_platform_specific\a
ll\sths\cdb5179b7fc1c046feea31136a3f8f002e6182faf8896fecc8b2f5b5ab604900.sth
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\CertificateTransparency\322\_platform_specific\a
ll\sths\ddeb1d2b7a0d4fa6208b81ad8168707e2e8e9d01d55c888d3d11c4cdb6ecbecc.sth
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\CertificateTransparency\322\_platform_specific\a
ll\sths\ee4bbdb775ce60bae142691fabe19e66a30f7e5fb072d88300c47b897aa8fdcb.sth
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\CertificateTransparency\322\_platform_specific\a
ll\sths
Cannot delete:
C:\USERS\USER\APPDATA\LOCAL\THUVET\CertificateTransparency\322\_platform_specific\a
ll\sths
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\CertificateTransparency\322\_platform_specific\a
ll
Cannot delete:
C:\USERS\USER\APPDATA\LOCAL\THUVET\CertificateTransparency\322\_platform_specific\a
ll
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\CertificateTransparency\322\_platform_specific
Cannot delete:
C:\USERS\USER\APPDATA\LOCAL\THUVET\CertificateTransparency\322\_platform_specific
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\CertificateTransparency\322
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\CertificateTransparency\322
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\CertificateTransparency
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\CertificateTransparency
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Bookmarks
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Bookmarks.bak
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Cookies
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Cookies-journal
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Current Session
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Current Tabs
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\databases\Databases.db
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\databases\Databases.db-journal
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\databases
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\databases
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\data_reduction_proxy_leveldb\0
00003.log
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\data_reduction_proxy_leveldb\C
URRENT
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\data_reduction_proxy_leveldb\L
OCK
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\data_reduction_proxy_leveldb\L
OG
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\data_reduction_proxy_leveldb\L
OG.old
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\data_reduction_proxy_leveldb\M
ANIFEST-000001
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\data_reduction_proxy_leveldb
Cannot delete:
C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\data_reduction_proxy_leveldb
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Extension
Rules\000003.log
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Extension
Rules\CURRENT
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Extension Rules\LOCK
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Extension Rules\LOG
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Extension
Rules\LOG.old
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Extension
Rules\MANIFEST-000001
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Extension Rules
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Extension Rules
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Extension
State\000005.ldb
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Extension
State\000007.log
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Extension
State\000008.ldb
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Extension
State\CURRENT
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Extension State\LOCK
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Extension State\LOG
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Extension
State\LOG.old
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Extension
State\MANIFEST-000001
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Extension State
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Extension State
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Extensions
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Extensions
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Favicons
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Favicons-journal
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Google Profile.ico
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\History
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\History Provider
Cache
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\History-journal
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\IndexedDB\https_www.youtube.co
m_0.indexeddb.leveldb\000003.log
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\IndexedDB\https_www.youtube.co
m_0.indexeddb.leveldb\CURRENT
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\IndexedDB\https_www.youtube.co
m_0.indexeddb.leveldb\LOCK
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\IndexedDB\https_www.youtube.co
m_0.indexeddb.leveldb\LOG
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\IndexedDB\https_www.youtube.co
m_0.indexeddb.leveldb\LOG.old
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\IndexedDB\https_www.youtube.co
m_0.indexeddb.leveldb\MANIFEST-000001
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\IndexedDB\https_www.youtube.co
m_0.indexeddb.leveldb
Cannot delete:
C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\IndexedDB\https_www.youtube.co
m_0.indexeddb.leveldb
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\IndexedDB
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\IndexedDB
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\JumpListIcons\81D6.tmp
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\JumpListIcons\81D7.tmp
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\JumpListIcons\81D8.tmp
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\JumpListIcons
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\JumpListIcons
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\JumpListIconsOld\54C6.tmp
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\JumpListIconsOld\54C7.tmp
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\JumpListIconsOld
Cannot delete:
C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\JumpListIconsOld
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Last Session
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Last Tabs
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local Extension
Settings\ghbmnnjooekpmoecnnnilnnbdlolhkhi\000003.log
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local Extension
Settings\ghbmnnjooekpmoecnnnilnnbdlolhkhi\CURRENT
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local Extension
Settings\ghbmnnjooekpmoecnnnilnnbdlolhkhi\LOCK
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local Extension
Settings\ghbmnnjooekpmoecnnnilnnbdlolhkhi\LOG
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local Extension
Settings\ghbmnnjooekpmoecnnnilnnbdlolhkhi\LOG.old
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local Extension
Settings\ghbmnnjooekpmoecnnnilnnbdlolhkhi\MANIFEST-000001
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local Extension
Settings\ghbmnnjooekpmoecnnnilnnbdlolhkhi
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local Extension
Settings\ghbmnnjooekpmoecnnnilnnbdlolhkhi
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local Extension
Settings\lgblnfidahcdcjddiepkckcfdhpknnjh\000003.log
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local Extension
Settings\lgblnfidahcdcjddiepkckcfdhpknnjh\CURRENT
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local Extension
Settings\lgblnfidahcdcjddiepkckcfdhpknnjh\LOCK
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local Extension
Settings\lgblnfidahcdcjddiepkckcfdhpknnjh\LOG
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local Extension
Settings\lgblnfidahcdcjddiepkckcfdhpknnjh\LOG.old
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local Extension
Settings\lgblnfidahcdcjddiepkckcfdhpknnjh\MANIFEST-000001
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local Extension
Settings\lgblnfidahcdcjddiepkckcfdhpknnjh
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local Extension
Settings\lgblnfidahcdcjddiepkckcfdhpknnjh
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local Extension
Settings
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local Extension
Settings
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local Storage\chrome-
extension_pinhfkamckbogjgmbmdkdebbbpnmlaef_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local Storage\chrome-
extension_pkedcjkdefgpdelpbcmbmeomcjbeemfm_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local Storage\chrome-
extension_pkedcjkdefgpdelpbcmbmeomcjbeemfm_0.localstorage-journal
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_1337x.to_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_7labs.heypub.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_accounts.google.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_books.google.co.in_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_c.betrad.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_cdncache-a.akamaihd.net_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_cdncache-a.akamaihd.net_0.localstorage-journal
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_cdnins.aqovd.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_cdnins.aqovd.com_0.localstorage-journal
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_chrome.google.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_chrome.google.com_0.localstorage-journal
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_clients5.google.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_commons.wikimedia.org_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_connexity.net_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_cse.google.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_d19tqk5t6qcjac.cloudfront.net_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_dailyuploads.net_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_delivery.g.switchadhub.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_disqus.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_disqus.com_0.localstorage-journal
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_en.wikipedia.org_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_faminta.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_fossbytes.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_foxi69.tlscdn.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_foxi69.tlscdn.com_0.localstorage-journal
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_get.adobe.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_get3.adobe.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_helpx.adobe.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_ievaphone.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_isohunt.to_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_k8t3w3m6.ssl.hwcdn.net_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_k8t3w3m6.ssl.hwcdn.net_0.localstorage-journal
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_mylinkgen.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_plus.google.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_pstatic.davebestdeals.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_pstatic.davebestdeals.com_0.localstorage-journal
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_s0.2mdn.net_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_s0.2mdn.net_0.localstorage-journal
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_static.cmptch.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_static.cmptch.com_0.localstorage-journal
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_support.google.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_tinychat.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_training.linuxfoundation.org_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_trueayurveda.wordpress.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_universal.iperceptions.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_uplod.ws_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_widgets.outbrain.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_www.dll-files.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_www.donation-tools.org_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_www.donation-tools.org_0.localstorage-journal
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_www.facebook.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_www.flirtymania.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_www.google.co.in_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_www.google.co.in_0.localstorage-journal
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_www.google.co.uk_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_www.google.co.uk_0.localstorage-journal
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_www.google.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_www.imaios.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_www.microsoft.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_www.poptox.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_www.powerdatarecovery.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_www.redtube.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_www.redtube.com_0.localstorage-journal
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_www.torrentfunk.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_www.youtube.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_www.youtube.com_0.localstorage-journal
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\https_www.zbigz.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_ad.adpop-1.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_answers.microsoft.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_ati-graphic-card-performance-booster.en.informer.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_bh.contextweb.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_cdn.cxense.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_connexity.net_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_digitalmediarecovery.blogspot.in_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_directx-11.en.lo4d.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_disqus.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_downnloadzone.blogspot.in_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_dropant.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_dwtricks.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_en.community.dell.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_en.savefrom.net_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_epomads2.4shared.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_external.informer.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_filehippo.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_files.alltypehacks.in_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_gameofthrones.wikia.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_ganool.ph_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_ge.tt_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_giphy.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_gradestack.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_ic-dc.deliverydlcenter.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_n162adserv.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_play-bar.net_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_playit.pk_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_rivatuner.software.informer.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_s1-adfly.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_serve.adworldmedia.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_teachmeanatomy.info_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_technovirux.blogspot.in_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_tinychat.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_view.vzaar.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_w.uptolike.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_widgets.outbrain.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_windows-activ.net_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_www.4shared.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_www.adnetworkperformance.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_www.anatomy-diagram.info_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_www.carddata-recovery.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_www.cracksfiles.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_www.dailymotion.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_www.dell.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_www.direct-torrents.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_www.directx.com.es_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_www.easeus.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_www.eblog24.net_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_www.flipkart.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_www.freewarefiles.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_www.ganool.cc_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_www.ganool.fr_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_www.google.co.in_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_www.guru3d.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_www.hotstar.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_www.hotstar.com_0.localstorage-journal
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_www.imdb.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_www.lingvozone.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_www.mediafire.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_www.medicalgeek.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_www.mirrorcreator.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_www.neowin.net_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_www.opera.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_www.partition-tool.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_www.pes-patch.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_www.powerdatarecovery.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_www.redtube.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_www.saavn.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_www.sharekhan.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_www.slideshare.net_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_www.smartserials.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_www.softpoint.in_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_www.technologietrudeau.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_www.terraclicks.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_www.tradeadexchange.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_www.tricksworldzz.in_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_www.trotux.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local
Storage\http_www.utorrent.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local Storage
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Local Storage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Login Data
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Login Data-journal
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Network Action
Predictor
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Network Action
Predictor-journal
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Network Persistent
State
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Pepper Data\Shockwave
Flash\CacheWritableAdobeRoot\AssetCache\D55BQS4C
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Pepper
Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache\D55BQS4C
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Pepper Data\Shockwave
Flash\CacheWritableAdobeRoot\AssetCache
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Pepper
Data\Shockwave Flash\CacheWritableAdobeRoot\AssetCache
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Pepper Data\Shockwave
Flash\CacheWritableAdobeRoot
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Pepper
Data\Shockwave Flash\CacheWritableAdobeRoot
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Pepper Data\Shockwave
Flash
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Pepper
Data\Shockwave Flash
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Pepper Data
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Pepper Data
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Plugin Data\Google
Gears\localserver.db
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Plugin Data\Google
Gears\permissions.db
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Plugin Data\Google
Gears
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Plugin
Data\Google Gears
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Plugin Data
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Plugin Data
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Preferences
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\previews_opt_out.db
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\previews_opt_out.db-
journal
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\QuotaManager
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\QuotaManager-journal
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Secure Preferences
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Secure
Preferencesgoobackup
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Service
Worker\Database\000003.log
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Service
Worker\Database\CURRENT
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Service
Worker\Database\LOCK
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Service
Worker\Database\LOG
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Service
Worker\Database\LOG.old
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Service
Worker\Database\MANIFEST-000001
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Service
Worker\Database
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Service
Worker\Database
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Service
Worker\ScriptCache\7b4fd8111178d5b1_0
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Service
Worker\ScriptCache\7b4fd8111178d5b1_1
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Service
Worker\ScriptCache\index
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Service
Worker\ScriptCache\index-dir\the-real-index
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Service
Worker\ScriptCache\index-dir
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Service
Worker\ScriptCache\index-dir
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Service
Worker\ScriptCache
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Service
Worker\ScriptCache
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Service Worker
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Service Worker
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Session
Storage\000005.ldb
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Session
Storage\000029.ldb
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Session
Storage\000030.log
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Session
Storage\000031.ldb
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Session
Storage\CURRENT
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Session Storage\LOCK
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Session Storage\LOG
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Session
Storage\LOG.old
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Session
Storage\MANIFEST-000001
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Session Storage
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Session Storage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Shortcuts
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Shortcuts-journal
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Storage\ext\chrome-
signin\def
Cannot delete:
C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Storage\ext\chrome-signin\def
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Storage\ext\chrome-
signin
Cannot delete:
C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Storage\ext\chrome-signin
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Storage\ext
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Storage\ext
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Storage
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Storage
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Sync Extension
Settings\lgblnfidahcdcjddiepkckcfdhpknnjh\000003.log
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Sync Extension
Settings\lgblnfidahcdcjddiepkckcfdhpknnjh\CURRENT
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Sync Extension
Settings\lgblnfidahcdcjddiepkckcfdhpknnjh\LOCK
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Sync Extension
Settings\lgblnfidahcdcjddiepkckcfdhpknnjh\LOG
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Sync Extension
Settings\lgblnfidahcdcjddiepkckcfdhpknnjh\LOG.old
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Sync Extension
Settings\lgblnfidahcdcjddiepkckcfdhpknnjh\MANIFEST-000001
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Sync Extension
Settings\lgblnfidahcdcjddiepkckcfdhpknnjh
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Sync Extension
Settings\lgblnfidahcdcjddiepkckcfdhpknnjh
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Sync Extension
Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\000003.log
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Sync Extension
Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\CURRENT
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Sync Extension
Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\LOCK
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Sync Extension
Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\LOG
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Sync Extension
Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\LOG.old
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Sync Extension
Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\MANIFEST-000001
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Sync Extension
Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Sync Extension
Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Sync Extension
Settings
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Sync Extension
Settings
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Thumbnails
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Top Sites
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Top Sites-journal
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\TransportSecurity
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Visited Links
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Web
Applications\_crx_aohghmighlieiainnegkcijnfilokake\Google Docs.ico
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Web
Applications\_crx_aohghmighlieiainnegkcijnfilokake\Google Docs.ico.md5
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Web
Applications\_crx_aohghmighlieiainnegkcijnfilokake
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Web
Applications\_crx_aohghmighlieiainnegkcijnfilokake
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Web Applications
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Web
Applications
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Web Data
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData\Web Data-journal
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\ChromeDefaultData
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\Crashpad\metadata
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\Crashpad\reports\645675bd-f1c2-4706-
b422-69784dec9ac3.dmp
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\Crashpad\reports
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\Crashpad\reports
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\Crashpad\settings.dat
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\Crashpad
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\Crashpad
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\en-GB-7-1.bdic
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\EVWhitelist\7\manifest.fingerprint
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\EVWhitelist\7\manifest.json
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\EVWhitelist\7\_metadata\verified_contents.json
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\EVWhitelist\7\_metadata
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\EVWhitelist\7\_metadata
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\EVWhitelist\7\_platform_specific\all\ev_hashes_w
hitelist.bin
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\EVWhitelist\7\_platform_specific\all
Cannot delete:
C:\USERS\USER\APPDATA\LOCAL\THUVET\EVWhitelist\7\_platform_specific\all
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\EVWhitelist\7\_platform_specific
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\EVWhitelist\7\_platform_specific
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\EVWhitelist\7
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\EVWhitelist\7
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\EVWhitelist
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\EVWhitelist
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\FileTypePolicies\8\download_file_types.pb
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\FileTypePolicies\8\manifest.fingerprint
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\FileTypePolicies\8\manifest.json
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\FileTypePolicies\8
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\FileTypePolicies\8
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\FileTypePolicies
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\FileTypePolicies
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\First Run
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\Local State
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\local64spl.dll
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\local64spl.dll.ini
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\OriginTrials
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\OriginTrials
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\PepperFlash\24.0.0.221\manifest.fingerprint
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\PepperFlash\24.0.0.221\manifest.json
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\PepperFlash\24.0.0.221\pepflashplayer.dll
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\PepperFlash\24.0.0.221
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\PepperFlash\24.0.0.221
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\PepperFlash
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\PepperFlash
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\pnacl\0.57.44.2492\manifest.fingerprint
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\pnacl\0.57.44.2492\manifest.json
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\pnacl\0.57.44.2492\_metadata\verified_contents.j
son
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\pnacl\0.57.44.2492\_metadata
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\pnacl\0.57.44.2492\_metadata
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\pnacl\0.57.44.2492\_platform_specific\x86_64\pna
cl_public_pnacl_json
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\pnacl\0.57.44.2492\_platform_specific\x86_64\pna
cl_public_x86_64_crtbegin_for_eh_o
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\pnacl\0.57.44.2492\_platform_specific\x86_64\pna
cl_public_x86_64_crtbegin_o
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\pnacl\0.57.44.2492\_platform_specific\x86_64\pna
cl_public_x86_64_crtend_o
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\pnacl\0.57.44.2492\_platform_specific\x86_64\pna
cl_public_x86_64_ld_nexe
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\pnacl\0.57.44.2492\_platform_specific\x86_64\pna
cl_public_x86_64_libcrt_platform_a
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\pnacl\0.57.44.2492\_platform_specific\x86_64\pna
cl_public_x86_64_libgcc_a
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\pnacl\0.57.44.2492\_platform_specific\x86_64\pna
cl_public_x86_64_libpnacl_irt_shim_a
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\pnacl\0.57.44.2492\_platform_specific\x86_64\pna
cl_public_x86_64_libpnacl_irt_shim_dummy_a
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\pnacl\0.57.44.2492\_platform_specific\x86_64\pna
cl_public_x86_64_pnacl_llc_nexe
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\pnacl\0.57.44.2492\_platform_specific\x86_64\pna
cl_public_x86_64_pnacl_sz_nexe
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\pnacl\0.57.44.2492\_platform_specific\x86_64
Cannot delete:
C:\USERS\USER\APPDATA\LOCAL\THUVET\pnacl\0.57.44.2492\_platform_specific\x86_64
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\pnacl\0.57.44.2492\_platform_specific
Cannot delete:
C:\USERS\USER\APPDATA\LOCAL\THUVET\pnacl\0.57.44.2492\_platform_specific
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\pnacl\0.57.44.2492
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\pnacl\0.57.44.2492
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\pnacl
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\pnacl
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\Safe Browsing Bloom
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\Safe Browsing Bloom Prefix Set
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\Safe Browsing Cookies
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\Safe Browsing Cookies-journal
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\Safe Browsing Csd Whitelist
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\Safe Browsing Download
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\Safe Browsing Download Whitelist
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\Safe Browsing Extension Blacklist
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\Safe Browsing IP Blacklist
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\Safe Browsing Module Whitelist
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\Safe Browsing Resource Blacklist
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\Safe Browsing UwS List
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\Safe Browsing UwS List Prefix Set
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\ShaderCache
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\ShaderCache
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\Subresource Filter\Indexed
Rules\11\4\LICENSE
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\Subresource Filter\Indexed
Rules\11\4\Ruleset Data
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\Subresource Filter\Indexed Rules\11\4
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\Subresource Filter\Indexed
Rules\11\4
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\Subresource Filter\Indexed Rules\11
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\Subresource Filter\Indexed
Rules\11
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\Subresource Filter\Indexed Rules
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\Subresource Filter\Indexed Rules
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\Subresource Filter\Unindexed
Rules\4\Filtering Rules
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\Subresource Filter\Unindexed
Rules\4\LICENSE
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\Subresource Filter\Unindexed
Rules\4\manifest.fingerprint
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\Subresource Filter\Unindexed
Rules\4\manifest.json
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\Subresource Filter\Unindexed Rules\4
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\Subresource Filter\Unindexed
Rules\4
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\Subresource Filter\Unindexed Rules
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\Subresource Filter\Unindexed
Rules
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\Subresource Filter
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\Subresource Filter
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\SwReporter\17.95.0\manifest.fingerprint
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\SwReporter\17.95.0\manifest.json
Deleted:
C:\USERS\USER\APPDATA\LOCAL\THUVET\SwReporter\17.95.0\software_reporter_tool.exe
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\SwReporter\17.95.0
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\SwReporter\17.95.0
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\SwReporter
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\SwReporter
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\Webstore Downloads
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\Webstore Downloads
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET\WidevineCdm
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\THUVET\WidevineCdm
Deleted: C:\USERS\USER\APPDATA\LOCAL\THUVET
Cannot remove folder: C:\USERS\USER\APPDATA\LOCAL\THUVET\
Error: 0
Delete At reboot: C:\USERS\USER\APPDATA\LOCAL\THUVET
-------------------------------------------------------
01.05.2017 19:49:21 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete: \??\C:\PROGRA~3\MICROS~1\NETWORK\DSQ
Delete: \??\C:\ProgramData\WINDOWS SECURITY
Delete: \??\C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER
Delete: \??\C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK
Delete: \??\C:\PROGRAM FILES (X86)\FFF
Delete: \??\C:\Users\user\AppData\Roaming\EVENT MONITOR
Delete: \??\C:\PROGRAM FILES (X86)\MPC CLEANER
Delete: \??\C:\PROGRAM FILES (X86)\BADU
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GHETUTAINANTIGH
Delete: \??\C:\Users\user\AppData\Roaming\UPUPDATA
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\CHROMIUM
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\WIN_EN_77
Delete: \??\C:\PROGRAM FILES (X86)\WEATHERCHICKN
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TUTO_MONETIZE_120160723
Delete: \??\C:\PROGRAM FILES (X86)\SURRANDERU
Delete: \??\C:\ProgramData\QUOTEEX
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\MPCK
Delete: \??\C:\PROGRAM FILES (X86)\PCCLEANPLUS
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\GPLYRA
Delete: \??\C:\PROGRAMDATA\CLOUDPRINTER
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\DLOSARECERTAIN
Delete: \??\C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCK1
Delete: \??\C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCKJLRVMNHPDY
Delete: \??\C:\PROGRAM FILES (X86)\VEGAGHT
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\PROGRAM FILES (X86)\MOZILLA FIREFOX
Delete: \??\C:\PROGRAMDATA\QUOTEEXS
Delete: C:\USERS\USER\APPDATA\LOCAL\THUVET
Delete Marked Items Auto Start Apps->Unwanted Software Files.
Temp1=C:\USERS\USER\APPDATA\LOCAL\TEMP1\
Deleted: C:\USERS\USER\APPDATA\LOCAL\TEMP1\local64spl.dll
Deleted: C:\USERS\USER\APPDATA\LOCAL\TEMP1\local64spl.dll.ini
Deleted: C:\USERS\USER\APPDATA\LOCAL\TEMP1
Cannot remove folder: C:\USERS\USER\APPDATA\LOCAL\TEMP1\
Error: 0
Delete At reboot: C:\USERS\USER\APPDATA\LOCAL\TEMP1
-------------------------------------------------------
01.05.2017 19:49:21 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete: \??\C:\PROGRA~3\MICROS~1\NETWORK\DSQ
Delete: \??\C:\ProgramData\WINDOWS SECURITY
Delete: \??\C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER
Delete: \??\C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK
Delete: \??\C:\PROGRAM FILES (X86)\FFF
Delete: \??\C:\Users\user\AppData\Roaming\EVENT MONITOR
Delete: \??\C:\PROGRAM FILES (X86)\MPC CLEANER
Delete: \??\C:\PROGRAM FILES (X86)\BADU
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GHETUTAINANTIGH
Delete: \??\C:\Users\user\AppData\Roaming\UPUPDATA
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\CHROMIUM
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\WIN_EN_77
Delete: \??\C:\PROGRAM FILES (X86)\WEATHERCHICKN
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TUTO_MONETIZE_120160723
Delete: \??\C:\PROGRAM FILES (X86)\SURRANDERU
Delete: \??\C:\ProgramData\QUOTEEX
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\MPCK
Delete: \??\C:\PROGRAM FILES (X86)\PCCLEANPLUS
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\GPLYRA
Delete: \??\C:\PROGRAMDATA\CLOUDPRINTER
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\DLOSARECERTAIN
Delete: \??\C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCK1
Delete: \??\C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCKJLRVMNHPDY
Delete: \??\C:\PROGRAM FILES (X86)\VEGAGHT
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\PROGRAM FILES (X86)\MOZILLA FIREFOX
Delete: \??\C:\PROGRAMDATA\QUOTEEXS
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\THUVET
Delete: C:\USERS\USER\APPDATA\LOCAL\TEMP1
Delete Marked Items Auto Start Apps->Unwanted Software Files.
Google=C:\USERS\USER\APPDATA\LOCAL\GOOGLE\
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\7FD1.tmp
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\Certificate Revocation
Lists
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\CertificateTransparency\322\manifest.fingerprint
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\CertificateTransparency\322\manifest.json
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\CertificateTransparency\322\_platform_specific\all\sths\293c519654c83965baaa50
fc5807d4b76fbf587a2972dca4c30cf4e54547f478.sth
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\CertificateTransparency\322\_platform_specific\all\sths\34bb6ad6c3df9c03eea8a4
99ff7891486c9d5e5cac92d01f7bfd1bce19db48ef.sth
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\CertificateTransparency\322\_platform_specific\all\sths\41b2dc2e89e63ce4af1ba7
bb29bf68c6dee6f9f1cc047e30dffae3b3ba259263.sth
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\CertificateTransparency\322\_platform_specific\all\sths\5614069a2fd7c2ecd3f5e1
bd44b23ec74676b9bc99115cc0ef949855d689d0dd.sth
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\CertificateTransparency\322\_platform_specific\all\sths\68f698f81f6482be3a8cee
b9281d4cfc71515d6793d444d10a67acbb4f4ffbc4.sth
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\CertificateTransparency\322\_platform_specific\all\sths\7461b4a09cfb3d41d75159
575b2e7649a445a8d27709b0cc564a6482b7eb41a3.sth
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\CertificateTransparency\322\_platform_specific\all\sths\a4b90990b418581487bb13
a2cc67700a3c359804f91bdfb8e377cd0ec80ddc10.sth
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\CertificateTransparency\322\_platform_specific\all\sths\a577ac9ced7548dd8f025b
67a241089df86e0f476ec203c2ecbedb185f282638.sth
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\CertificateTransparency\322\_platform_specific\all\sths\ac3b9aed7fa9674757159e
6d7d575672f9d98100941e9bdeffeca1313b75782d.sth
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\CertificateTransparency\322\_platform_specific\all\sths\bbd9dfbc1f8a71b5939423
97aa927b473857950aab52e81a909664368e1ed185.sth
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\CertificateTransparency\322\_platform_specific\all\sths\bc78e1dfc5f63c68464933
4da10fa15f0979692009c081b4f3f6917f3ed9b8a5.sth
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\CertificateTransparency\322\_platform_specific\all\sths\cdb5179b7fc1c046feea31
136a3f8f002e6182faf8896fecc8b2f5b5ab604900.sth
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\CertificateTransparency\322\_platform_specific\all\sths\ddeb1d2b7a0d4fa6208b81
ad8168707e2e8e9d01d55c888d3d11c4cdb6ecbecc.sth
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\CertificateTransparency\322\_platform_specific\all\sths\ee4bbdb775ce60bae14269
1fabe19e66a30f7e5fb072d88300c47b897aa8fdcb.sth
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\CertificateTransparency\322\_platform_specific\all\sths
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\CertificateTransparency\322\_platform_specific\all\sths
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\CertificateTransparency\322\_platform_specific\all
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\CertificateTransparency\322\_platform_specific\all
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\CertificateTransparency\322\_platform_specific
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\CertificateTransparency\322\_platform_specific
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\CertificateTransparency\322
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\CertificateTransparency\322
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\CertificateTransparency
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\CertificateTransparency
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\58B1.tmp
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Bookmarks
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Bookmarks.bak
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\data_0
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\data_1
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\data_2
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\data_3
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000004
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000005
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000006
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000007
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000008
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000009
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_00000a
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_00000b
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_00000c
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_00000d
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_00000e
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_00000f
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000010
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000011
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000012
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000014
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000015
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000016
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000017
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000018
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000019
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_00001a
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_00001b
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_00001c
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_00001d
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_00001e
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_00001f
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000020
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000021
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000023
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000024
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000025
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000026
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000027
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000028
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000029
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_00002a
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_00002b
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_00002c
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_00002d
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_00002e
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_00002f
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000030
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000031
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000032
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000033
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000034
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000035
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000036
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000037
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000038
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000039
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_00003a
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_00003b
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_00003c
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_00003d
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_00003e
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_00003f
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000040
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000042
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000043
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000044
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000045
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000046
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000047
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000048
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000049
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_00004a
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_00004c
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_00004d
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_00004e
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_00004f
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000050
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000051
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000052
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000053
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000054
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000055
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000056
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000058
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000059
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_00005a
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_00005b
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_00005c
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_00005d
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_00005e
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_00005f
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000060
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000061
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000062
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000063
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000064
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000065
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000066
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000067
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000068
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000069
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_00006a
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_00006b
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_00006c
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_00006d
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_00006e
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_00006f
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000070
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000071
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000072
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000073
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000074
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000075
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000076
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000077
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000078
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_000079
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\f_00007a
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache\index
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cache
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cookies
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Cookies-journal
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Current Session
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Current Tabs
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\databases\Databases.db
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\databases\Databases.db-journal
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\databases
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\databases
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\data_reduction_proxy_leveldb\000003.log
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\data_reduction_proxy_leveldb\CURRENT
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\data_reduction_proxy_leveldb\LOCK
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\data_reduction_proxy_leveldb\LOG
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\data_reduction_proxy_leveldb\LOG.old
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\data_reduction_proxy_leveldb\MANIFEST-000001
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\data_reduction_proxy_leveldb
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\data_reduction_proxy_leveldb
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\DownloadMetadata
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Extension Cookies
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Extension Cookies-journal
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Extension Rules\000003.log
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Extension Rules\CURRENT
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Extension Rules\LOCK
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Extension Rules\LOG
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Extension Rules\LOG.old
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Extension Rules\MANIFEST-000001
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Extension Rules
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Extension Rules
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Extension State\000005.ldb
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Extension State\000007.log
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Extension State\000008.ldb
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Extension State\CURRENT
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Extension State\LOCK
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Extension State\LOG
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Extension State\LOG.old
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Extension State\MANIFEST-000001
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Extension State
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Extension State
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Extensions
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Extensions
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Favicons
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Favicons-journal
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Google Profile.ico
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\GPUCache\data_0
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\GPUCache\data_1
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\GPUCache\data_2
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\GPUCache\data_3
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\GPUCache\index
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\GPUCache
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\GPUCache
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\History
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\History Provider Cache
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\History-journal
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\IndexedDB
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\IndexedDB
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\JumpListIcons\C802.tmp
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\JumpListIcons\C812.tmp
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\JumpListIcons\C813.tmp
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\JumpListIcons
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\JumpListIcons
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\JumpListIconsOld\C9C5.tmp
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\JumpListIconsOld\C9C6.tmp
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\JumpListIconsOld\C9C7.tmp
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\JumpListIconsOld
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\JumpListIconsOld
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\ChromeDefaultData\Last
Session
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\ChromeDefaultData\Last
Tabs
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Local Extension
Settings\ghbmnnjooekpmoecnnnilnnbdlolhkhi\000003.log
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Local Extension
Settings\ghbmnnjooekpmoecnnnilnnbdlolhkhi\CURRENT
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Local Extension
Settings\ghbmnnjooekpmoecnnnilnnbdlolhkhi\LOCK
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Local Extension
Settings\ghbmnnjooekpmoecnnnilnnbdlolhkhi\LOG
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Local Extension
Settings\ghbmnnjooekpmoecnnnilnnbdlolhkhi\LOG.old
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Local Extension
Settings\ghbmnnjooekpmoecnnnilnnbdlolhkhi\MANIFEST-000001
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Local Extension Settings\ghbmnnjooekpmoecnnnilnnbdlolhkhi
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Local Extension Settings\ghbmnnjooekpmoecnnnilnnbdlolhkhi
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Local Extension
Settings\lgblnfidahcdcjddiepkckcfdhpknnjh\000003.log
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Local Extension
Settings\lgblnfidahcdcjddiepkckcfdhpknnjh\CURRENT
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Local Extension
Settings\lgblnfidahcdcjddiepkckcfdhpknnjh\LOCK
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Local Extension
Settings\lgblnfidahcdcjddiepkckcfdhpknnjh\LOG
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Local Extension
Settings\lgblnfidahcdcjddiepkckcfdhpknnjh\LOG.old
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Local Extension
Settings\lgblnfidahcdcjddiepkckcfdhpknnjh\MANIFEST-000001
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Local Extension Settings\lgblnfidahcdcjddiepkckcfdhpknnjh
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Local Extension Settings\lgblnfidahcdcjddiepkckcfdhpknnjh
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Local Extension Settings
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Local Extension Settings
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Local Storage\chrome-
extension_pinhfkamckbogjgmbmdkdebbbpnmlaef_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Local Storage\chrome-
extension_pkedcjkdefgpdelpbcmbmeomcjbeemfm_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Local Storage\chrome-
extension_pkedcjkdefgpdelpbcmbmeomcjbeemfm_0.localstorage-journal
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Local Storage\http_192.168.43.1_33455.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Local Storage\http_192.168.43.1_33455.localstorage-journal
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Local Storage\http_pstatic.davebestdeals.com_0.localstorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Local Storage\http_pstatic.davebestdeals.com_0.localstorage-
journal
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Local Storage
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Local Storage
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Login Data
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Login Data-journal
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Media Cache\data_0
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Media Cache\data_1
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Media Cache\data_2
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Media Cache\data_3
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Media Cache\f_000001
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Media Cache\index
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Media Cache
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Media Cache
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Network Action Predictor
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Network Action Predictor-journal
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Network Persistent State
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Origin Bound Certs
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Origin Bound Certs-journal
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Pepper Data\Shockwave
Flash\CacheWritableAdobeRoot\AssetCache\D55BQS4C
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Pepper Data\Shockwave
Flash\CacheWritableAdobeRoot\AssetCache\D55BQS4C
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Pepper Data\Shockwave
Flash\CacheWritableAdobeRoot\AssetCache
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Pepper Data\Shockwave
Flash\CacheWritableAdobeRoot\AssetCache
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Pepper Data\Shockwave Flash\CacheWritableAdobeRoot
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Pepper Data\Shockwave
Flash\WritableRoot\#SharedObjects\UC9J7RAQ\macromedia.com\support\flashplayer\sys\s
ettings.sol
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Pepper Data\Shockwave
Flash\WritableRoot\#SharedObjects\UC9J7RAQ\macromedia.com\support\flashplayer\sys
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Pepper Data\Shockwave
Flash\WritableRoot\#SharedObjects\UC9J7RAQ\macromedia.com\support\flashplayer\sys
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Pepper Data\Shockwave
Flash\WritableRoot\#SharedObjects\UC9J7RAQ\macromedia.com\support\flashplayer
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Pepper Data\Shockwave
Flash\WritableRoot\#SharedObjects\UC9J7RAQ\macromedia.com\support\flashplayer
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Pepper Data\Shockwave
Flash\WritableRoot\#SharedObjects\UC9J7RAQ\macromedia.com\support
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Pepper Data\Shockwave
Flash\WritableRoot\#SharedObjects\UC9J7RAQ\macromedia.com\support
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Pepper Data\Shockwave
Flash\WritableRoot\#SharedObjects\UC9J7RAQ\macromedia.com
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Pepper Data\Shockwave
Flash\WritableRoot\#SharedObjects\UC9J7RAQ\macromedia.com
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Pepper Data\Shockwave
Flash\WritableRoot\#SharedObjects\UC9J7RAQ
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Pepper Data\Shockwave
Flash\WritableRoot\#SharedObjects\UC9J7RAQ
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Pepper Data\Shockwave Flash\WritableRoot
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Pepper Data\Shockwave Flash\WritableRoot
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Pepper Data\Shockwave Flash
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Pepper Data\Shockwave Flash
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Pepper Data
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Pepper Data
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Platform Notifications\000003.log
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Platform Notifications\CURRENT
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Platform Notifications\LOCK
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Platform Notifications\LOG
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Platform Notifications\MANIFEST-000001
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Platform Notifications
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Platform Notifications
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Plugin Data\Google Gears\localserver.db
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Plugin Data\Google Gears\permissions.db
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Plugin Data\Google Gears
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Plugin Data\Google Gears
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Plugin Data
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Plugin Data
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Preferences
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\previews_opt_out.db
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\previews_opt_out.db-journal
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\QuotaManager
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\QuotaManager-journal
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Secure Preferences
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Secure Preferencesgoobackup
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Service
Worker\CacheStorage\0fa95b80667bf657a6ff1012ac31d0fb34f2fa66\c5aa18fc-f4df-4f74-
b844-a88a21961d5b\index-dir\the-real-index
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Service
Worker\CacheStorage\0fa95b80667bf657a6ff1012ac31d0fb34f2fa66\c5aa18fc-f4df-4f74-
b844-a88a21961d5b\index-dir
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Service
Worker\CacheStorage\0fa95b80667bf657a6ff1012ac31d0fb34f2fa66\c5aa18fc-f4df-4f74-
b844-a88a21961d5b\index-dir
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Service
Worker\CacheStorage\0fa95b80667bf657a6ff1012ac31d0fb34f2fa66\c5aa18fc-f4df-4f74-
b844-a88a21961d5b
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Service
Worker\CacheStorage\0fa95b80667bf657a6ff1012ac31d0fb34f2fa66\c5aa18fc-f4df-4f74-
b844-a88a21961d5b
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Service
Worker\CacheStorage\0fa95b80667bf657a6ff1012ac31d0fb34f2fa66
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Service
Worker\CacheStorage\0fa95b80667bf657a6ff1012ac31d0fb34f2fa66
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Service Worker\CacheStorage
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Service Worker\CacheStorage
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Service Worker\Database\000003.log
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Service Worker\Database\CURRENT
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Service Worker\Database\LOCK
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Service Worker\Database\LOG
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Service Worker\Database\LOG.old
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Service Worker\Database\MANIFEST-000001
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Service Worker\Database
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Service Worker\Database
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Service Worker\ScriptCache\index
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Service Worker\ScriptCache\index-dir\the-real-index
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Service Worker\ScriptCache\index-dir
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Service Worker\ScriptCache\index-dir
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Service Worker\ScriptCache
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Service Worker\ScriptCache
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Service Worker
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Service Worker
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Session Storage\000005.ldb
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Session Storage\000038.log
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Session Storage\000040.ldb
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Session Storage\CURRENT
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Session Storage\LOCK
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Session Storage\LOG
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Session Storage\LOG.old
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Session Storage\MANIFEST-000001
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Session Storage
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Session Storage
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Shortcuts
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Shortcuts-journal
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Storage\ext\chrome-signin\def\GPUCache\data_0
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Storage\ext\chrome-signin\def\GPUCache\data_1
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Storage\ext\chrome-signin\def\GPUCache\data_2
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Storage\ext\chrome-signin\def\GPUCache\data_3
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Storage\ext\chrome-signin\def\GPUCache\index
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Storage\ext\chrome-signin\def\GPUCache
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Storage\ext\chrome-signin\def\GPUCache
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Storage\ext\chrome-signin\def
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Storage\ext\chrome-signin\def
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Storage\ext\chrome-signin
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Storage\ext\chrome-signin
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Storage\ext
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Storage\ext
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Storage
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Storage
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\ChromeDefaultData\Sync
Extension Settings\lgblnfidahcdcjddiepkckcfdhpknnjh\000003.log
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\ChromeDefaultData\Sync
Extension Settings\lgblnfidahcdcjddiepkckcfdhpknnjh\CURRENT
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\ChromeDefaultData\Sync
Extension Settings\lgblnfidahcdcjddiepkckcfdhpknnjh\LOCK
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\ChromeDefaultData\Sync
Extension Settings\lgblnfidahcdcjddiepkckcfdhpknnjh\LOG
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\ChromeDefaultData\Sync
Extension Settings\lgblnfidahcdcjddiepkckcfdhpknnjh\LOG.old
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\ChromeDefaultData\Sync
Extension Settings\lgblnfidahcdcjddiepkckcfdhpknnjh\MANIFEST-000001
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\ChromeDefaultData\Sync
Extension Settings\lgblnfidahcdcjddiepkckcfdhpknnjh
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Sync Extension Settings\lgblnfidahcdcjddiepkckcfdhpknnjh
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\ChromeDefaultData\Sync
Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\000003.log
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\ChromeDefaultData\Sync
Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\CURRENT
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\ChromeDefaultData\Sync
Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\LOCK
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\ChromeDefaultData\Sync
Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\LOG
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\ChromeDefaultData\Sync
Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\LOG.old
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\ChromeDefaultData\Sync
Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\MANIFEST-000001
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\ChromeDefaultData\Sync
Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\ChromeDefaultData\Sync
Extension Settings
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Sync Extension Settings
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Thumbnails
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\ChromeDefaultData\Top
Sites
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\ChromeDefaultData\Top
Sites-journal
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\TransportSecurity
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Visited Links
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\ChromeDefaultData\Web
Applications\_crx_aohghmighlieiainnegkcijnfilokake\Google Docs.ico
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\ChromeDefaultData\Web
Applications\_crx_aohghmighlieiainnegkcijnfilokake\Google Docs.ico.md5
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\ChromeDefaultData\Web
Applications\_crx_aohghmighlieiainnegkcijnfilokake
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Web Applications\_crx_aohghmighlieiainnegkcijnfilokake
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\ChromeDefaultData\Web
Applications
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData\Web Applications
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\ChromeDefaultData\Web
Data
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ChromeDefaultData
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\Crashpad\metadata
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\Crashpad\reports\645675bd-f1c2-4706-b422-69784dec9ac3.dmp
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\Crashpad\reports
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\Crashpad\reports
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\Crashpad\settings.dat
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\Crashpad
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\Crashpad
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\Default
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\Default
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\en-GB-7-1.bdic
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\EVWhitelist\7\manifest.fingerprint
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\EVWhitelist\7\manifest.json
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\EVWhitelist\7\_metadata\verified_contents.json
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\EVWhitelist\7\_metadata
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\EVWhitelist\7\_metadata
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\EVWhitelist\7\_platform_specific\all\ev_hashes_whitelist.bin
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\EVWhitelist\7\_platform_specific\all
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\EVWhitelist\7\_platform_specific\all
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\EVWhitelist\7\_platform_specific
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\EVWhitelist\7\_platform_specific
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\EVWhitelist\7
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\EVWhitelist\7
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\EVWhitelist
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\EVWhitelist
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\F225.tmp
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\F22B.tmp
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\FileTypePolicies\8\download_file_types.pb
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\FileTypePolicies\8\manifest.fingerprint
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\FileTypePolicies\8\manifest.json
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\FileTypePolicies\8
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\FileTypePolicies\8
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\FileTypePolicies
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\FileTypePolicies
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\First Run
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\Local State
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\local64spl.dll
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\local64spl.dll.ini
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\OriginTrials
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\OriginTrials
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\PepperFlash\24.0.0.221\manifest.fingerprint
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\PepperFlash\24.0.0.221\manifest.json
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\PepperFlash\24.0.0.221\pepflashplayer.dll
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\PepperFlash\24.0.0.221
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\PepperFlash\24.0.0.221
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\PepperFlash
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\PepperFlash
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\pnacl\0.57.44.2492\manifest.fingerprint
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\pnacl\0.57.44.2492\manifest.json
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\pnacl\0.57.44.2492\_metadata\verified_contents.json
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\pnacl\0.57.44.2492\_metadata
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\pnacl\0.57.44.2492\_metadata
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\pnacl\0.57.44.2492\_platform_specific\x86_64\pnacl_public_pnacl_json
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\pnacl\0.57.44.2492\_platform_specific\x86_64\pnacl_public_x86_64_crtbegin_for_
eh_o
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\pnacl\0.57.44.2492\_platform_specific\x86_64\pnacl_public_x86_64_crtbegin_o
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\pnacl\0.57.44.2492\_platform_specific\x86_64\pnacl_public_x86_64_crtend_o
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\pnacl\0.57.44.2492\_platform_specific\x86_64\pnacl_public_x86_64_ld_nexe
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\pnacl\0.57.44.2492\_platform_specific\x86_64\pnacl_public_x86_64_libcrt_platfo
rm_a
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\pnacl\0.57.44.2492\_platform_specific\x86_64\pnacl_public_x86_64_libgcc_a
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\pnacl\0.57.44.2492\_platform_specific\x86_64\pnacl_public_x86_64_libpnacl_irt_
shim_a
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\pnacl\0.57.44.2492\_platform_specific\x86_64\pnacl_public_x86_64_libpnacl_irt_
shim_dummy_a
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\pnacl\0.57.44.2492\_platform_specific\x86_64\pnacl_public_x86_64_pnacl_llc_nex
e
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\pnacl\0.57.44.2492\_platform_specific\x86_64\pnacl_public_x86_64_pnacl_sz_nexe
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\pnacl\0.57.44.2492\_platform_specific\x86_64
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\pnacl\0.57.44.2492\_platform_specific\x86_64
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\pnacl\0.57.44.2492\_platform_specific
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\pnacl\0.57.44.2492\_platform_specific
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\pnacl\0.57.44.2492
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\pnacl\0.57.44.2492
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\pnacl
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\pnacl
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\PnaclTranslationCache\data_0
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\PnaclTranslationCache\data_1
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\PnaclTranslationCache\data_2
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\PnaclTranslationCache\data_3
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\PnaclTranslationCache\index
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\PnaclTranslationCache
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\PnaclTranslationCache
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\Safe Browsing Bloom
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\Safe Browsing Bloom
Prefix Set
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\Safe Browsing Cookies
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\Safe Browsing Cookies-
journal
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\Safe Browsing Csd
Whitelist
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\Safe Browsing Download
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\Safe Browsing Download
Whitelist
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\Safe Browsing
Extension Blacklist
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\Safe Browsing IP
Blacklist
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\Safe Browsing Module
Whitelist
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\Safe Browsing Resource
Blacklist
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\Safe Browsing UwS List
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\Safe Browsing UwS List
Prefix Set
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ShaderCache\GPUCache\data_0
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ShaderCache\GPUCache\data_1
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ShaderCache\GPUCache\data_2
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ShaderCache\GPUCache\data_3
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ShaderCache\GPUCache\index
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\ShaderCache\GPUCache
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\ShaderCache\GPUCache
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\ShaderCache
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\ShaderCache
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\Subresource
Filter\Indexed Rules\11\4\LICENSE
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\Subresource
Filter\Indexed Rules\11\4\Ruleset Data
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\Subresource
Filter\Indexed Rules\11\4
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\Subresource
Filter\Indexed Rules\11\4
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\Subresource
Filter\Indexed Rules\11
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\Subresource
Filter\Indexed Rules\11
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\Subresource
Filter\Indexed Rules
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\Subresource
Filter\Indexed Rules
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\Subresource
Filter\Unindexed Rules\4\Filtering Rules
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\Subresource
Filter\Unindexed Rules\4\LICENSE
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\Subresource
Filter\Unindexed Rules\4\manifest.fingerprint
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\Subresource
Filter\Unindexed Rules\4\manifest.json
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\Subresource
Filter\Unindexed Rules\4
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\Subresource
Filter\Unindexed Rules\4
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\Subresource
Filter\Unindexed Rules
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\Subresource
Filter\Unindexed Rules
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\Subresource Filter
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\Subresource
Filter
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\SwReporter\18.102.0\manifest.fingerprint
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\SwReporter\18.102.0\manifest.json
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\SwReporter\18.102.0\software_reporter_tool.exe
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\SwReporter\18.102.0
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User
Data\SwReporter\18.102.0
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\SwReporter
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\SwReporter
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\Webstore Downloads
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\Webstore
Downloads
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\WidevineCdm
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data\WidevineCdm
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data1\local64spl.dll
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data1\local64spl.dll.ini
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data1
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome\User Data1
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Chrome
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\CrashReports
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\CrashReports
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Software Reporter Tool\metadata
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Software Reporter Tool\reports
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Software Reporter Tool\reports
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Software Reporter Tool\settings.dat
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Software Reporter
Tool\software_reporter_tool-crashpad.log
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Software Reporter
Tool\software_reporter_tool.log
Deleted: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Software Reporter Tool
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\Software Reporter Tool
Cannot delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE
Cannot remove folder: C:\USERS\USER\APPDATA\LOCAL\GOOGLE\
Error: 0
Delete At reboot: C:\USERS\USER\APPDATA\LOCAL\GOOGLE
-------------------------------------------------------
01.05.2017 19:49:22 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete: \??\C:\PROGRA~3\MICROS~1\NETWORK\DSQ
Delete: \??\C:\ProgramData\WINDOWS SECURITY
Delete: \??\C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER
Delete: \??\C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK
Delete: \??\C:\PROGRAM FILES (X86)\FFF
Delete: \??\C:\Users\user\AppData\Roaming\EVENT MONITOR
Delete: \??\C:\PROGRAM FILES (X86)\MPC CLEANER
Delete: \??\C:\PROGRAM FILES (X86)\BADU
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GHETUTAINANTIGH
Delete: \??\C:\Users\user\AppData\Roaming\UPUPDATA
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\CHROMIUM
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\WIN_EN_77
Delete: \??\C:\PROGRAM FILES (X86)\WEATHERCHICKN
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TUTO_MONETIZE_120160723
Delete: \??\C:\PROGRAM FILES (X86)\SURRANDERU
Delete: \??\C:\ProgramData\QUOTEEX
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\MPCK
Delete: \??\C:\PROGRAM FILES (X86)\PCCLEANPLUS
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\GPLYRA
Delete: \??\C:\PROGRAMDATA\CLOUDPRINTER
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\DLOSARECERTAIN
Delete: \??\C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCK1
Delete: \??\C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCKJLRVMNHPDY
Delete: \??\C:\PROGRAM FILES (X86)\VEGAGHT
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\PROGRAM FILES (X86)\MOZILLA FIREFOX
Delete: \??\C:\PROGRAMDATA\QUOTEEXS
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\THUVET
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TEMP1
Delete: C:\USERS\USER\APPDATA\LOCAL\GOOGLE
Delete Marked Items Auto Start Apps->Unwanted Software Files. G1NPCI9BHG=C:\PROGRAM
FILES\G1NPCI9BHG\
Deleted: C:\PROGRAM FILES\G1NPCI9BHG\cast.config
Deleted: C:\PROGRAM FILES\G1NPCI9BHG\G1NPCI9BH.exe
Deleted: C:\PROGRAM FILES\G1NPCI9BHG\G1NPCI9BH.exe.config
Deleted: C:\PROGRAM FILES\G1NPCI9BHG\uninstaller.exe
Deleted: C:\PROGRAM FILES\G1NPCI9BHG\uninstaller.exe.config
Deleted: C:\PROGRAM FILES\G1NPCI9BHG
Cannot remove folder: C:\PROGRAM FILES\G1NPCI9BHG\
Error: 0
Delete At reboot: C:\PROGRAM FILES\G1NPCI9BHG
-------------------------------------------------------
01.05.2017 19:49:22 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete: \??\C:\PROGRA~3\MICROS~1\NETWORK\DSQ
Delete: \??\C:\ProgramData\WINDOWS SECURITY
Delete: \??\C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER
Delete: \??\C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK
Delete: \??\C:\PROGRAM FILES (X86)\FFF
Delete: \??\C:\Users\user\AppData\Roaming\EVENT MONITOR
Delete: \??\C:\PROGRAM FILES (X86)\MPC CLEANER
Delete: \??\C:\PROGRAM FILES (X86)\BADU
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GHETUTAINANTIGH
Delete: \??\C:\Users\user\AppData\Roaming\UPUPDATA
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\CHROMIUM
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\WIN_EN_77
Delete: \??\C:\PROGRAM FILES (X86)\WEATHERCHICKN
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TUTO_MONETIZE_120160723
Delete: \??\C:\PROGRAM FILES (X86)\SURRANDERU
Delete: \??\C:\ProgramData\QUOTEEX
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\MPCK
Delete: \??\C:\PROGRAM FILES (X86)\PCCLEANPLUS
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\GPLYRA
Delete: \??\C:\PROGRAMDATA\CLOUDPRINTER
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\DLOSARECERTAIN
Delete: \??\C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCK1
Delete: \??\C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCKJLRVMNHPDY
Delete: \??\C:\PROGRAM FILES (X86)\VEGAGHT
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\PROGRAM FILES (X86)\MOZILLA FIREFOX
Delete: \??\C:\PROGRAMDATA\QUOTEEXS
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\THUVET
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TEMP1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GOOGLE
Delete: C:\PROGRAM FILES\G1NPCI9BHG
Delete Marked Items Auto Start Apps->Unwanted Software Files. 2Y8DB5ZJCZ=C:\PROGRAM
FILES\2Y8DB5ZJCZ\
Deleted: C:\PROGRAM FILES\2Y8DB5ZJCZ\cast.config
Deleted: C:\PROGRAM FILES\2Y8DB5ZJCZ\CNL1RDZ9T.exe
Deleted: C:\PROGRAM FILES\2Y8DB5ZJCZ\CNL1RDZ9T.exe.config
Deleted: C:\PROGRAM FILES\2Y8DB5ZJCZ\uninstaller.exe
Deleted: C:\PROGRAM FILES\2Y8DB5ZJCZ\uninstaller.exe.config
Deleted: C:\PROGRAM FILES\2Y8DB5ZJCZ
Cannot remove folder: C:\PROGRAM FILES\2Y8DB5ZJCZ\
Error: 0
Delete At reboot: C:\PROGRAM FILES\2Y8DB5ZJCZ
-------------------------------------------------------
01.05.2017 19:49:23 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete: \??\C:\PROGRA~3\MICROS~1\NETWORK\DSQ
Delete: \??\C:\ProgramData\WINDOWS SECURITY
Delete: \??\C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER
Delete: \??\C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK
Delete: \??\C:\PROGRAM FILES (X86)\FFF
Delete: \??\C:\Users\user\AppData\Roaming\EVENT MONITOR
Delete: \??\C:\PROGRAM FILES (X86)\MPC CLEANER
Delete: \??\C:\PROGRAM FILES (X86)\BADU
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GHETUTAINANTIGH
Delete: \??\C:\Users\user\AppData\Roaming\UPUPDATA
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\CHROMIUM
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\WIN_EN_77
Delete: \??\C:\PROGRAM FILES (X86)\WEATHERCHICKN
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TUTO_MONETIZE_120160723
Delete: \??\C:\PROGRAM FILES (X86)\SURRANDERU
Delete: \??\C:\ProgramData\QUOTEEX
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\MPCK
Delete: \??\C:\PROGRAM FILES (X86)\PCCLEANPLUS
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\GPLYRA
Delete: \??\C:\PROGRAMDATA\CLOUDPRINTER
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\DLOSARECERTAIN
Delete: \??\C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCK1
Delete: \??\C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCKJLRVMNHPDY
Delete: \??\C:\PROGRAM FILES (X86)\VEGAGHT
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\PROGRAM FILES (X86)\MOZILLA FIREFOX
Delete: \??\C:\PROGRAMDATA\QUOTEEXS
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\THUVET
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TEMP1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GOOGLE
Delete: \??\C:\PROGRAM FILES\G1NPCI9BHG
Delete: C:\PROGRAM FILES\2Y8DB5ZJCZ
Delete Marked Items Auto Start Apps->Unwanted Software Files. 2KZZKPY7UL=C:\PROGRAM
FILES\2KZZKPY7UL\
Deleted: C:\PROGRAM FILES\2KZZKPY7UL\2KZZKPY7U.exe
Deleted: C:\PROGRAM FILES\2KZZKPY7UL\2KZZKPY7U.exe.config
Deleted: C:\PROGRAM FILES\2KZZKPY7UL\cast.config
Deleted: C:\PROGRAM FILES\2KZZKPY7UL\uninstaller.exe.config
Deleted: C:\PROGRAM FILES\2KZZKPY7UL
Cannot remove folder: C:\PROGRAM FILES\2KZZKPY7UL\
Error: 0
Delete At reboot: C:\PROGRAM FILES\2KZZKPY7UL
-------------------------------------------------------
01.05.2017 19:49:23 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete: \??\C:\PROGRA~3\MICROS~1\NETWORK\DSQ
Delete: \??\C:\ProgramData\WINDOWS SECURITY
Delete: \??\C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER
Delete: \??\C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK
Delete: \??\C:\PROGRAM FILES (X86)\FFF
Delete: \??\C:\Users\user\AppData\Roaming\EVENT MONITOR
Delete: \??\C:\PROGRAM FILES (X86)\MPC CLEANER
Delete: \??\C:\PROGRAM FILES (X86)\BADU
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GHETUTAINANTIGH
Delete: \??\C:\Users\user\AppData\Roaming\UPUPDATA
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\CHROMIUM
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\WIN_EN_77
Delete: \??\C:\PROGRAM FILES (X86)\WEATHERCHICKN
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TUTO_MONETIZE_120160723
Delete: \??\C:\PROGRAM FILES (X86)\SURRANDERU
Delete: \??\C:\ProgramData\QUOTEEX
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\MPCK
Delete: \??\C:\PROGRAM FILES (X86)\PCCLEANPLUS
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\GPLYRA
Delete: \??\C:\PROGRAMDATA\CLOUDPRINTER
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\DLOSARECERTAIN
Delete: \??\C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCK1
Delete: \??\C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCKJLRVMNHPDY
Delete: \??\C:\PROGRAM FILES (X86)\VEGAGHT
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\PROGRAM FILES (X86)\MOZILLA FIREFOX
Delete: \??\C:\PROGRAMDATA\QUOTEEXS
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\THUVET
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TEMP1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GOOGLE
Delete: \??\C:\PROGRAM FILES\G1NPCI9BHG
Delete: \??\C:\PROGRAM FILES\2Y8DB5ZJCZ
Delete: C:\PROGRAM FILES\2KZZKPY7UL
Delete Marked Items Auto Start Apps->Unwanted Software Files. K2BVHVQ9WG=C:\PROGRAM
FILES\K2BVHVQ9WG\
Deleted: C:\PROGRAM FILES\K2BVHVQ9WG\K2BVHVQ9W.exe.config
Deleted: C:\PROGRAM FILES\K2BVHVQ9WG\uninstaller.exe.config
Deleted: C:\PROGRAM FILES\K2BVHVQ9WG
Cannot remove folder: C:\PROGRAM FILES\K2BVHVQ9WG\
Error: 0
Delete At reboot: C:\PROGRAM FILES\K2BVHVQ9WG
-------------------------------------------------------
01.05.2017 19:49:23 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete: \??\C:\PROGRA~3\MICROS~1\NETWORK\DSQ
Delete: \??\C:\ProgramData\WINDOWS SECURITY
Delete: \??\C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER
Delete: \??\C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK
Delete: \??\C:\PROGRAM FILES (X86)\FFF
Delete: \??\C:\Users\user\AppData\Roaming\EVENT MONITOR
Delete: \??\C:\PROGRAM FILES (X86)\MPC CLEANER
Delete: \??\C:\PROGRAM FILES (X86)\BADU
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GHETUTAINANTIGH
Delete: \??\C:\Users\user\AppData\Roaming\UPUPDATA
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\CHROMIUM
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\WIN_EN_77
Delete: \??\C:\PROGRAM FILES (X86)\WEATHERCHICKN
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TUTO_MONETIZE_120160723
Delete: \??\C:\PROGRAM FILES (X86)\SURRANDERU
Delete: \??\C:\ProgramData\QUOTEEX
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\MPCK
Delete: \??\C:\PROGRAM FILES (X86)\PCCLEANPLUS
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\GPLYRA
Delete: \??\C:\PROGRAMDATA\CLOUDPRINTER
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\DLOSARECERTAIN
Delete: \??\C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCK1
Delete: \??\C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCKJLRVMNHPDY
Delete: \??\C:\PROGRAM FILES (X86)\VEGAGHT
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\PROGRAM FILES (X86)\MOZILLA FIREFOX
Delete: \??\C:\PROGRAMDATA\QUOTEEXS
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\THUVET
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TEMP1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GOOGLE
Delete: \??\C:\PROGRAM FILES\G1NPCI9BHG
Delete: \??\C:\PROGRAM FILES\2Y8DB5ZJCZ
Delete: \??\C:\PROGRAM FILES\2KZZKPY7UL
Delete: C:\PROGRAM FILES\K2BVHVQ9WG
Delete Marked Items Auto Start Apps->Unwanted Software Files. 2rfP2ar5Q4=C:\PROGRAM
FILES (X86)\2RFP2AR5Q4\
Deleted: C:\PROGRAM FILES (X86)\2RFP2AR5Q4\data.dt
Deleted: C:\PROGRAM FILES (X86)\2RFP2AR5Q4\dlog.txt
Deleted: C:\PROGRAM FILES (X86)\2RFP2AR5Q4\kl.dll
Deleted: C:\PROGRAM FILES (X86)\2RFP2AR5Q4\kl.ecf
Deleted: C:\PROGRAM FILES (X86)\2RFP2AR5Q4\kl__100E414E__C0000005.dmp
Deleted: C:\PROGRAM FILES (X86)\2RFP2AR5Q4\nss\certutil.exe
Deleted: C:\PROGRAM FILES (X86)\2RFP2AR5Q4\nss\mozcrt19.dll
Deleted: C:\PROGRAM FILES (X86)\2RFP2AR5Q4\nss\nspr4.dll
Deleted: C:\PROGRAM FILES (X86)\2RFP2AR5Q4\nss\nss3.dll
Deleted: C:\PROGRAM FILES (X86)\2RFP2AR5Q4\nss\plc4.dll
Deleted: C:\PROGRAM FILES (X86)\2RFP2AR5Q4\nss\plds4.dll
Deleted: C:\PROGRAM FILES (X86)\2RFP2AR5Q4\nss\smime3.dll
Deleted: C:\PROGRAM FILES (X86)\2RFP2AR5Q4\nss\softokn3.dll
Deleted: C:\PROGRAM FILES (X86)\2RFP2AR5Q4\nss
Cannot delete: C:\PROGRAM FILES (X86)\2RFP2AR5Q4\nss
Deleted: C:\PROGRAM FILES (X86)\2RFP2AR5Q4\s.xml
Deleted: C:\PROGRAM FILES (X86)\2RFP2AR5Q4\slite.exe
Deleted: C:\PROGRAM FILES (X86)\2RFP2AR5Q4\SSL\cert.db
Deleted: C:\PROGRAM FILES (X86)\2RFP2AR5Q4\SSL\OtherSearch Inc CA 2.cer
Deleted: C:\PROGRAM FILES (X86)\2RFP2AR5Q4\SSL\xtls.db
Deleted: C:\PROGRAM FILES (X86)\2RFP2AR5Q4\SSL
Cannot delete: C:\PROGRAM FILES (X86)\2RFP2AR5Q4\SSL
Deleted: C:\PROGRAM FILES (X86)\2RFP2AR5Q4\uninstall.exe
Deleted: C:\PROGRAM FILES (X86)\2RFP2AR5Q4\updengine.exe
Deleted: C:\PROGRAM FILES (X86)\2RFP2AR5Q4
Cannot remove folder: C:\PROGRAM FILES (X86)\2RFP2AR5Q4\
Error: 0
Delete At reboot: C:\PROGRAM FILES (X86)\2RFP2AR5Q4
-------------------------------------------------------
01.05.2017 19:49:23 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete: \??\C:\PROGRA~3\MICROS~1\NETWORK\DSQ
Delete: \??\C:\ProgramData\WINDOWS SECURITY
Delete: \??\C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER
Delete: \??\C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK
Delete: \??\C:\PROGRAM FILES (X86)\FFF
Delete: \??\C:\Users\user\AppData\Roaming\EVENT MONITOR
Delete: \??\C:\PROGRAM FILES (X86)\MPC CLEANER
Delete: \??\C:\PROGRAM FILES (X86)\BADU
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GHETUTAINANTIGH
Delete: \??\C:\Users\user\AppData\Roaming\UPUPDATA
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\CHROMIUM
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\WIN_EN_77
Delete: \??\C:\PROGRAM FILES (X86)\WEATHERCHICKN
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TUTO_MONETIZE_120160723
Delete: \??\C:\PROGRAM FILES (X86)\SURRANDERU
Delete: \??\C:\ProgramData\QUOTEEX
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\MPCK
Delete: \??\C:\PROGRAM FILES (X86)\PCCLEANPLUS
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\GPLYRA
Delete: \??\C:\PROGRAMDATA\CLOUDPRINTER
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\DLOSARECERTAIN
Delete: \??\C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCK1
Delete: \??\C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCKJLRVMNHPDY
Delete: \??\C:\PROGRAM FILES (X86)\VEGAGHT
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\PROGRAM FILES (X86)\MOZILLA FIREFOX
Delete: \??\C:\PROGRAMDATA\QUOTEEXS
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\THUVET
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TEMP1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GOOGLE
Delete: \??\C:\PROGRAM FILES\G1NPCI9BHG
Delete: \??\C:\PROGRAM FILES\2Y8DB5ZJCZ
Delete: \??\C:\PROGRAM FILES\2KZZKPY7UL
Delete: \??\C:\PROGRAM FILES\K2BVHVQ9WG
Delete: C:\PROGRAM FILES (X86)\2RFP2AR5Q4
Delete Marked Items Auto Start Apps->Unwanted Software Files. PETFPODMG6=C:\PROGRAM
FILES\PETFPODMG6\
Deleted: C:\PROGRAM FILES\PETFPODMG6\cast.config
Deleted: C:\PROGRAM FILES\PETFPODMG6\PETFPODMG.exe
Deleted: C:\PROGRAM FILES\PETFPODMG6\PETFPODMG.exe.config
Deleted: C:\PROGRAM FILES\PETFPODMG6\uninstaller.exe
Deleted: C:\PROGRAM FILES\PETFPODMG6\uninstaller.exe.config
Deleted: C:\PROGRAM FILES\PETFPODMG6
Cannot remove folder: C:\PROGRAM FILES\PETFPODMG6\
Error: 0
Delete At reboot: C:\PROGRAM FILES\PETFPODMG6
-------------------------------------------------------
01.05.2017 19:49:23 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete: \??\C:\PROGRA~3\MICROS~1\NETWORK\DSQ
Delete: \??\C:\ProgramData\WINDOWS SECURITY
Delete: \??\C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER
Delete: \??\C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK
Delete: \??\C:\PROGRAM FILES (X86)\FFF
Delete: \??\C:\Users\user\AppData\Roaming\EVENT MONITOR
Delete: \??\C:\PROGRAM FILES (X86)\MPC CLEANER
Delete: \??\C:\PROGRAM FILES (X86)\BADU
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GHETUTAINANTIGH
Delete: \??\C:\Users\user\AppData\Roaming\UPUPDATA
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\CHROMIUM
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\WIN_EN_77
Delete: \??\C:\PROGRAM FILES (X86)\WEATHERCHICKN
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TUTO_MONETIZE_120160723
Delete: \??\C:\PROGRAM FILES (X86)\SURRANDERU
Delete: \??\C:\ProgramData\QUOTEEX
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\MPCK
Delete: \??\C:\PROGRAM FILES (X86)\PCCLEANPLUS
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\GPLYRA
Delete: \??\C:\PROGRAMDATA\CLOUDPRINTER
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\DLOSARECERTAIN
Delete: \??\C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCK1
Delete: \??\C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCKJLRVMNHPDY
Delete: \??\C:\PROGRAM FILES (X86)\VEGAGHT
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\PROGRAM FILES (X86)\MOZILLA FIREFOX
Delete: \??\C:\PROGRAMDATA\QUOTEEXS
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\THUVET
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TEMP1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GOOGLE
Delete: \??\C:\PROGRAM FILES\G1NPCI9BHG
Delete: \??\C:\PROGRAM FILES\2Y8DB5ZJCZ
Delete: \??\C:\PROGRAM FILES\2KZZKPY7UL
Delete: \??\C:\PROGRAM FILES\K2BVHVQ9WG
Delete: \??\C:\PROGRAM FILES (X86)\2RFP2AR5Q4
Delete: C:\PROGRAM FILES\PETFPODMG6
Delete Marked Items Auto Start Apps->Unwanted Software Files. OZU7LPSW8F=C:\PROGRAM
FILES\OZU7LPSW8F\
Deleted: C:\PROGRAM FILES\OZU7LPSW8F\cast.config
Deleted: C:\PROGRAM FILES\OZU7LPSW8F\OZU7LPSW8.exe
Deleted: C:\PROGRAM FILES\OZU7LPSW8F\OZU7LPSW8.exe.config
Deleted: C:\PROGRAM FILES\OZU7LPSW8F\uninstaller.exe
Deleted: C:\PROGRAM FILES\OZU7LPSW8F\uninstaller.exe.config
Deleted: C:\PROGRAM FILES\OZU7LPSW8F
Cannot remove folder: C:\PROGRAM FILES\OZU7LPSW8F\
Error: 0
Delete At reboot: C:\PROGRAM FILES\OZU7LPSW8F
-------------------------------------------------------
01.05.2017 19:49:23 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete: \??\C:\PROGRA~3\MICROS~1\NETWORK\DSQ
Delete: \??\C:\ProgramData\WINDOWS SECURITY
Delete: \??\C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER
Delete: \??\C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK
Delete: \??\C:\PROGRAM FILES (X86)\FFF
Delete: \??\C:\Users\user\AppData\Roaming\EVENT MONITOR
Delete: \??\C:\PROGRAM FILES (X86)\MPC CLEANER
Delete: \??\C:\PROGRAM FILES (X86)\BADU
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GHETUTAINANTIGH
Delete: \??\C:\Users\user\AppData\Roaming\UPUPDATA
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\CHROMIUM
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\WIN_EN_77
Delete: \??\C:\PROGRAM FILES (X86)\WEATHERCHICKN
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TUTO_MONETIZE_120160723
Delete: \??\C:\PROGRAM FILES (X86)\SURRANDERU
Delete: \??\C:\ProgramData\QUOTEEX
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\MPCK
Delete: \??\C:\PROGRAM FILES (X86)\PCCLEANPLUS
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\GPLYRA
Delete: \??\C:\PROGRAMDATA\CLOUDPRINTER
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\DLOSARECERTAIN
Delete: \??\C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCK1
Delete: \??\C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCKJLRVMNHPDY
Delete: \??\C:\PROGRAM FILES (X86)\VEGAGHT
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\PROGRAM FILES (X86)\MOZILLA FIREFOX
Delete: \??\C:\PROGRAMDATA\QUOTEEXS
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\THUVET
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TEMP1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GOOGLE
Delete: \??\C:\PROGRAM FILES\G1NPCI9BHG
Delete: \??\C:\PROGRAM FILES\2Y8DB5ZJCZ
Delete: \??\C:\PROGRAM FILES\2KZZKPY7UL
Delete: \??\C:\PROGRAM FILES\K2BVHVQ9WG
Delete: \??\C:\PROGRAM FILES (X86)\2RFP2AR5Q4
Delete: \??\C:\PROGRAM FILES\PETFPODMG6
Delete: C:\PROGRAM FILES\OZU7LPSW8F
01.05.2017 19:49:38 User Shortcuts
Probably Malicious: C:\Users\Public\Desktop\Google Chrome.lnk = C:\PROGRAM FILES
(X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
01.05.2017 19:49:38 User Shortcuts
Unknown: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick
Launch\User Pinned\TaskBar\Don Bradman Cricket 14.lnk = C:\PROGRAM FILES
(X86)\DBC14\CRICKET14.EXE
01.05.2017 19:49:38 User Shortcuts
Probably Malicious: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google
Chrome.lnk = C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
01.05.2017 19:49:38 Registry Run
Suspicious: teklon = C:\USERS\USER\APPDATA\LOCAL\TEKLON.DLL
01.05.2017 19:49:38 Registry Run
Probably Malicious: svchost0 = C:\Program Files (x86)\fff\uc.exe
01.05.2017 19:49:38 Registry Run
Suspicious: YYLGS4MQ3G = "C:\Program Files\G1NPCI9BHG\G1NPCI9BH.exe"
01.05.2017 19:49:38 Registry Run
Probably Malicious: Z#AsP1-dj3.exe = C:\Program Files\Cypress\{db6-13-2a-ea4f5-
befb9-401f-66fc0}\Z#AsP1-dj3.exe -r1_1 -r2_1
01.05.2017 19:49:38 Registry Run
Suspicious: FXJE00F4IN = "C:\Program Files\PETFPODMG6\PETFPODMG.exe"
01.05.2017 19:49:38 Registry Run
Suspicious: RE4F2GGR2G = "C:\Program Files\OZU7LPSW8F\OZU7LPSW8.exe"
01.05.2017 19:49:38 Registry Run
Suspicious: ZB3DFN5FML = "C:\Program Files\2Y8DB5ZJCZ\CNL1RDZ9T.exe"
01.05.2017 19:49:38 Registry Run
Suspicious: GAEDGFTYAK.exe = C:\USERS\USER\APPDATA\LOCAL\TEMP\E8-7D6AD-2F3-86191-
BF59B359BED00\GAEDGFTYAK.EXE
01.05.2017 19:49:38 Registry Run
Suspicious: M24L9MWKE9RADH5 = "C:\Program Files\2KZZKPY7UL\2KZZKPY7U.exe"
01.05.2017 19:49:38 Registry Run(x64)
Probably Malicious: gplyra = C:\Users\user\AppData\Roaming\gplyra\gplyra\start.cmd
01.05.2017 19:49:38 Registry RunOnce
Suspicious: CYERPQDWSI.exe = C:\USERS\USER\APPDATA\LOCAL\TEMP\E8-7D6AD-2F3-86191-
BF59B359BED00\CYERPQDWSI.EXE
01.05.2017 19:49:38 Registry RunOnce(x64)
Probably Malicious: OTUTPRODUCT_6V3ZA = "C:\Program Files
(x86)\mpck\EPDKKWHERAO0DPM.exe"
01.05.2017 19:49:38 Scheduled Tasks 2
Probably Malicious: C:\WINDOWS\SYSNATIVE\TASKS\77cf4b3dfabc9e11de3765bb9c0b2422 =
rundll32.exe "C:\Program Files
(x86)\Vegaght\75cbel.dll",e62dc6c6547f46bda862da2d05af6862
01.05.2017 19:49:38 Scheduled Tasks 2
Probably Malicious: C:\WINDOWS\SYSNATIVE\TASKS\Dermopyckatile = MSIEXEC
01.05.2017 19:49:38 Scheduled Tasks 2
Suspicious: C:\WINDOWS\SYSNATIVE\TASKS\Joseck Helper = "C:\Program Files
(x86)\Anerhspchpiry\hoquther.exe"
01.05.2017 19:49:38 Scheduled Tasks 2
Probably Malicious: C:\WINDOWS\SYSNATIVE\TASKS\KbhLni9OK4 = C:\Program Files
(x86)\2rfP2ar5Q4\updengine.exe
01.05.2017 19:49:38 Scheduled Tasks 2
Suspicious: C:\WINDOWS\SYSNATIVE\TASKS\Origin =
C:\USERS\USER\APPDATA\ROAMING\ORIGIN\UPDATE.VBE
01.05.2017 19:49:38 Scheduled Tasks 2
Suspicious: C:\WINDOWS\SYSNATIVE\TASKS\Pluperryarejotion Log = "C:\Program Files
(x86)\Vegaght\arerpiph.exe"
01.05.2017 19:49:38 Scheduled Tasks 2
Probably Malicious: C:\WINDOWS\SYSNATIVE\TASKS\RunAtStartup =
C:\Users\user\AppData\Roaming\Event Monitor\em.exe
01.05.2017 19:49:38 Scheduled Tasks 2
Suspicious: C:\WINDOWS\SYSNATIVE\TASKS\{97B71CFC-536E-4008-894A-BDE8C5724C92} =
E:\ascs\Assassin's Creed Syndicate-Black Box\Setup.exe
01.05.2017 19:49:38 Scheduled Tasks 2.0 Cached
Probably Malicious: Joseck Helper =
01.05.2017 19:49:38 Scheduled Tasks 2.0 Cached
Probably Malicious: RunAtStartup =
Delete Marked Items Auto Start Apps->Registry RunOnce(x64).
OTUTPRODUCT_6V3ZA="C:\Program Files (x86)\mpck\EPDKKWHERAO0DPM.exe"
Delete Marked Items Auto Start Apps->Scheduled Tasks 2.
C:\WINDOWS\SYSNATIVE\TASKS\77cf4b3dfabc9e11de3765bb9c0b2422=rundll32.exe
"C:\Program Files (x86)\Vegaght\75cbel.dll",e62dc6c6547f46bda862da2d05af6862
-------------------------------------------------------
01.05.2017 19:49:42 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete: \??\C:\PROGRA~3\MICROS~1\NETWORK\DSQ
Delete: \??\C:\ProgramData\WINDOWS SECURITY
Delete: \??\C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER
Delete: \??\C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK
Delete: \??\C:\PROGRAM FILES (X86)\FFF
Delete: \??\C:\Users\user\AppData\Roaming\EVENT MONITOR
Delete: \??\C:\PROGRAM FILES (X86)\MPC CLEANER
Delete: \??\C:\PROGRAM FILES (X86)\BADU
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GHETUTAINANTIGH
Delete: \??\C:\Users\user\AppData\Roaming\UPUPDATA
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\CHROMIUM
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\WIN_EN_77
Delete: \??\C:\PROGRAM FILES (X86)\WEATHERCHICKN
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TUTO_MONETIZE_120160723
Delete: \??\C:\PROGRAM FILES (X86)\SURRANDERU
Delete: \??\C:\ProgramData\QUOTEEX
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\MPCK
Delete: \??\C:\PROGRAM FILES (X86)\PCCLEANPLUS
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\GPLYRA
Delete: \??\C:\PROGRAMDATA\CLOUDPRINTER
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\DLOSARECERTAIN
Delete: \??\C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCK1
Delete: \??\C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCKJLRVMNHPDY
Delete: \??\C:\PROGRAM FILES (X86)\VEGAGHT
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\PROGRAM FILES (X86)\MOZILLA FIREFOX
Delete: \??\C:\PROGRAMDATA\QUOTEEXS
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\THUVET
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TEMP1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GOOGLE
Delete: \??\C:\PROGRAM FILES\G1NPCI9BHG
Delete: \??\C:\PROGRAM FILES\2Y8DB5ZJCZ
Delete: \??\C:\PROGRAM FILES\2KZZKPY7UL
Delete: \??\C:\PROGRAM FILES\K2BVHVQ9WG
Delete: \??\C:\PROGRAM FILES (X86)\2RFP2AR5Q4
Delete: \??\C:\PROGRAM FILES\PETFPODMG6
Delete: \??\C:\PROGRAM FILES\OZU7LPSW8F
Delete: C:\WINDOWS\SYSNATIVE\TASKS\77cf4b3dfabc9e11de3765bb9c0b2422
Delete Marked Items Auto Start Apps->Scheduled Tasks 2.
C:\WINDOWS\SYSNATIVE\TASKS\Dermopyckatile=MSIEXEC
-------------------------------------------------------
01.05.2017 19:49:43 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete: \??\C:\PROGRA~3\MICROS~1\NETWORK\DSQ
Delete: \??\C:\ProgramData\WINDOWS SECURITY
Delete: \??\C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER
Delete: \??\C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK
Delete: \??\C:\PROGRAM FILES (X86)\FFF
Delete: \??\C:\Users\user\AppData\Roaming\EVENT MONITOR
Delete: \??\C:\PROGRAM FILES (X86)\MPC CLEANER
Delete: \??\C:\PROGRAM FILES (X86)\BADU
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GHETUTAINANTIGH
Delete: \??\C:\Users\user\AppData\Roaming\UPUPDATA
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\CHROMIUM
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\WIN_EN_77
Delete: \??\C:\PROGRAM FILES (X86)\WEATHERCHICKN
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TUTO_MONETIZE_120160723
Delete: \??\C:\PROGRAM FILES (X86)\SURRANDERU
Delete: \??\C:\ProgramData\QUOTEEX
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\MPCK
Delete: \??\C:\PROGRAM FILES (X86)\PCCLEANPLUS
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\GPLYRA
Delete: \??\C:\PROGRAMDATA\CLOUDPRINTER
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\DLOSARECERTAIN
Delete: \??\C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCK1
Delete: \??\C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCKJLRVMNHPDY
Delete: \??\C:\PROGRAM FILES (X86)\VEGAGHT
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\PROGRAM FILES (X86)\MOZILLA FIREFOX
Delete: \??\C:\PROGRAMDATA\QUOTEEXS
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\THUVET
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TEMP1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GOOGLE
Delete: \??\C:\PROGRAM FILES\G1NPCI9BHG
Delete: \??\C:\PROGRAM FILES\2Y8DB5ZJCZ
Delete: \??\C:\PROGRAM FILES\2KZZKPY7UL
Delete: \??\C:\PROGRAM FILES\K2BVHVQ9WG
Delete: \??\C:\PROGRAM FILES (X86)\2RFP2AR5Q4
Delete: \??\C:\PROGRAM FILES\PETFPODMG6
Delete: \??\C:\PROGRAM FILES\OZU7LPSW8F
Delete: \??\C:\WINDOWS\SYSNATIVE\TASKS\77cf4b3dfabc9e11de3765bb9c0b2422
Delete: C:\WINDOWS\SYSNATIVE\TASKS\Dermopyckatile
Delete Marked Items Auto Start Apps->Registry Run. svchost0=C:\Program Files
(x86)\fff\uc.exe
Delete Marked Items Auto Start Apps->Registry Run. Z#AsP1-dj3.exe=C:\Program
Files\Cypress\{db6-13-2a-ea4f5-befb9-401f-66fc0}\Z#AsP1-dj3.exe -r1_1 -r2_1
Delete Marked Items Auto Start Apps->Registry Run(x64).
gplyra=C:\Users\user\AppData\Roaming\gplyra\gplyra\start.cmd
Delete Marked Items Auto Start Apps->Scheduled Tasks 2.
C:\WINDOWS\SYSNATIVE\TASKS\KbhLni9OK4=C:\Program Files
(x86)\2rfP2ar5Q4\updengine.exe
-------------------------------------------------------
01.05.2017 19:49:43 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete: \??\C:\PROGRA~3\MICROS~1\NETWORK\DSQ
Delete: \??\C:\ProgramData\WINDOWS SECURITY
Delete: \??\C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER
Delete: \??\C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK
Delete: \??\C:\PROGRAM FILES (X86)\FFF
Delete: \??\C:\Users\user\AppData\Roaming\EVENT MONITOR
Delete: \??\C:\PROGRAM FILES (X86)\MPC CLEANER
Delete: \??\C:\PROGRAM FILES (X86)\BADU
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GHETUTAINANTIGH
Delete: \??\C:\Users\user\AppData\Roaming\UPUPDATA
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\CHROMIUM
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\WIN_EN_77
Delete: \??\C:\PROGRAM FILES (X86)\WEATHERCHICKN
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TUTO_MONETIZE_120160723
Delete: \??\C:\PROGRAM FILES (X86)\SURRANDERU
Delete: \??\C:\ProgramData\QUOTEEX
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\MPCK
Delete: \??\C:\PROGRAM FILES (X86)\PCCLEANPLUS
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\GPLYRA
Delete: \??\C:\PROGRAMDATA\CLOUDPRINTER
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\DLOSARECERTAIN
Delete: \??\C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCK1
Delete: \??\C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCKJLRVMNHPDY
Delete: \??\C:\PROGRAM FILES (X86)\VEGAGHT
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\PROGRAM FILES (X86)\MOZILLA FIREFOX
Delete: \??\C:\PROGRAMDATA\QUOTEEXS
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\THUVET
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TEMP1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GOOGLE
Delete: \??\C:\PROGRAM FILES\G1NPCI9BHG
Delete: \??\C:\PROGRAM FILES\2Y8DB5ZJCZ
Delete: \??\C:\PROGRAM FILES\2KZZKPY7UL
Delete: \??\C:\PROGRAM FILES\K2BVHVQ9WG
Delete: \??\C:\PROGRAM FILES (X86)\2RFP2AR5Q4
Delete: \??\C:\PROGRAM FILES\PETFPODMG6
Delete: \??\C:\PROGRAM FILES\OZU7LPSW8F
Delete: \??\C:\WINDOWS\SYSNATIVE\TASKS\77cf4b3dfabc9e11de3765bb9c0b2422
Delete: \??\C:\WINDOWS\SYSNATIVE\TASKS\Dermopyckatile
Delete: C:\WINDOWS\SYSNATIVE\TASKS\KbhLni9OK4
Delete Marked Items Auto Start Apps->Scheduled Tasks 2.
C:\WINDOWS\SYSNATIVE\TASKS\RunAtStartup=C:\Users\user\AppData\Roaming\Event
Monitor\em.exe
-------------------------------------------------------
01.05.2017 19:49:43 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete: \??\C:\PROGRA~3\MICROS~1\NETWORK\DSQ
Delete: \??\C:\ProgramData\WINDOWS SECURITY
Delete: \??\C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER
Delete: \??\C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK
Delete: \??\C:\PROGRAM FILES (X86)\FFF
Delete: \??\C:\Users\user\AppData\Roaming\EVENT MONITOR
Delete: \??\C:\PROGRAM FILES (X86)\MPC CLEANER
Delete: \??\C:\PROGRAM FILES (X86)\BADU
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GHETUTAINANTIGH
Delete: \??\C:\Users\user\AppData\Roaming\UPUPDATA
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\CHROMIUM
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\WIN_EN_77
Delete: \??\C:\PROGRAM FILES (X86)\WEATHERCHICKN
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TUTO_MONETIZE_120160723
Delete: \??\C:\PROGRAM FILES (X86)\SURRANDERU
Delete: \??\C:\ProgramData\QUOTEEX
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\MPCK
Delete: \??\C:\PROGRAM FILES (X86)\PCCLEANPLUS
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\GPLYRA
Delete: \??\C:\PROGRAMDATA\CLOUDPRINTER
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\DLOSARECERTAIN
Delete: \??\C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCK1
Delete: \??\C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCKJLRVMNHPDY
Delete: \??\C:\PROGRAM FILES (X86)\VEGAGHT
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\PROGRAM FILES (X86)\MOZILLA FIREFOX
Delete: \??\C:\PROGRAMDATA\QUOTEEXS
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\THUVET
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TEMP1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GOOGLE
Delete: \??\C:\PROGRAM FILES\G1NPCI9BHG
Delete: \??\C:\PROGRAM FILES\2Y8DB5ZJCZ
Delete: \??\C:\PROGRAM FILES\2KZZKPY7UL
Delete: \??\C:\PROGRAM FILES\K2BVHVQ9WG
Delete: \??\C:\PROGRAM FILES (X86)\2RFP2AR5Q4
Delete: \??\C:\PROGRAM FILES\PETFPODMG6
Delete: \??\C:\PROGRAM FILES\OZU7LPSW8F
Delete: \??\C:\WINDOWS\SYSNATIVE\TASKS\77cf4b3dfabc9e11de3765bb9c0b2422
Delete: \??\C:\WINDOWS\SYSNATIVE\TASKS\Dermopyckatile
Delete: \??\C:\WINDOWS\SYSNATIVE\TASKS\KbhLni9OK4
Delete: C:\WINDOWS\SYSNATIVE\TASKS\RunAtStartup
Delete Marked Items Windows Shell->User Shortcuts. C:\Users\Public\Desktop\Google
Chrome.lnk=C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
Resetting shortcut: C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
Resetting shortcut: C:\Users\Public\Desktop\GOOGLE~1.LNK
Success: C:\Users\Public\Desktop\GOOGLE~1.LNK
Delete Marked Items Windows Shell->User Shortcuts.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk=C:\PROGRAM
FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
Resetting shortcut: C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
Resetting shortcut: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\GOOGLE~1.LNK
Success: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\GOOGLE~1.LNK
Delete Marked Items Auto Start Apps->Scheduled Tasks 2.0 Cached. RunAtStartup=
Deleted Key:SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Schedule\TaskCache\Tree\RunAtStartup
Error deleting registry key:SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Schedule\TaskCache\Boot\{6C579561-6C10-4C13-9225-802E3A34F440}
The DelAnyKey failed too.
Deleted Key:SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\
{6C579561-6C10-4C13-9225-802E3A34F440}
Error deleting registry key:SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Schedule\TaskCache\Maintenance\{6C579561-6C10-4C13-9225-
802E3A34F440}
The DelAnyKey failed too.
Error deleting registry key:SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Schedule\TaskCache\Plain\{6C579561-6C10-4C13-9225-802E3A34F440}
The DelAnyKey failed too.
Deleted Key:SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\
{6C579561-6C10-4C13-9225-802E3A34F440}
Delete Marked Items Auto Start Apps->Scheduled Tasks 2.0 Cached. Joseck Helper=
Deleted Key:SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Schedule\TaskCache\Tree\Joseck Helper
Error deleting registry key:SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Schedule\TaskCache\Boot\{231359A4-349B-43E5-AA3D-355308272654}
The DelAnyKey failed too.
Error deleting registry key:SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Schedule\TaskCache\Logon\{231359A4-349B-43E5-AA3D-355308272654}
The DelAnyKey failed too.
Error deleting registry key:SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Schedule\TaskCache\Maintenance\{231359A4-349B-43E5-AA3D-
355308272654}
The DelAnyKey failed too.
Deleted Key:SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\
{231359A4-349B-43E5-AA3D-355308272654}
Deleted Key:SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\
{231359A4-349B-43E5-AA3D-355308272654}
Delete Marked Items Auto Start Apps->Registry Run. RE4F2GGR2G="C:\Program
Files\OZU7LPSW8F\OZU7LPSW8.exe"
Delete Marked Items Auto Start Apps->Registry Run. FXJE00F4IN="C:\Program
Files\PETFPODMG6\PETFPODMG.exe"
Delete Marked Items Auto Start Apps->Registry Run. YYLGS4MQ3G="C:\Program
Files\G1NPCI9BHG\G1NPCI9BH.exe"
Delete Marked Items Auto Start Apps->Registry Run. ZB3DFN5FML="C:\Program
Files\2Y8DB5ZJCZ\CNL1RDZ9T.exe"
Delete Marked Items Auto Start Apps->Scheduled Tasks 2.
C:\WINDOWS\SYSNATIVE\TASKS\Pluperryarejotion Log="C:\Program Files
(x86)\Vegaght\arerpiph.exe"
-------------------------------------------------------
01.05.2017 19:49:43 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete: \??\C:\PROGRA~3\MICROS~1\NETWORK\DSQ
Delete: \??\C:\ProgramData\WINDOWS SECURITY
Delete: \??\C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER
Delete: \??\C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK
Delete: \??\C:\PROGRAM FILES (X86)\FFF
Delete: \??\C:\Users\user\AppData\Roaming\EVENT MONITOR
Delete: \??\C:\PROGRAM FILES (X86)\MPC CLEANER
Delete: \??\C:\PROGRAM FILES (X86)\BADU
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GHETUTAINANTIGH
Delete: \??\C:\Users\user\AppData\Roaming\UPUPDATA
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\CHROMIUM
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\WIN_EN_77
Delete: \??\C:\PROGRAM FILES (X86)\WEATHERCHICKN
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TUTO_MONETIZE_120160723
Delete: \??\C:\PROGRAM FILES (X86)\SURRANDERU
Delete: \??\C:\ProgramData\QUOTEEX
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\MPCK
Delete: \??\C:\PROGRAM FILES (X86)\PCCLEANPLUS
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\GPLYRA
Delete: \??\C:\PROGRAMDATA\CLOUDPRINTER
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\DLOSARECERTAIN
Delete: \??\C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCK1
Delete: \??\C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCKJLRVMNHPDY
Delete: \??\C:\PROGRAM FILES (X86)\VEGAGHT
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\PROGRAM FILES (X86)\MOZILLA FIREFOX
Delete: \??\C:\PROGRAMDATA\QUOTEEXS
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\THUVET
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TEMP1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GOOGLE
Delete: \??\C:\PROGRAM FILES\G1NPCI9BHG
Delete: \??\C:\PROGRAM FILES\2Y8DB5ZJCZ
Delete: \??\C:\PROGRAM FILES\2KZZKPY7UL
Delete: \??\C:\PROGRAM FILES\K2BVHVQ9WG
Delete: \??\C:\PROGRAM FILES (X86)\2RFP2AR5Q4
Delete: \??\C:\PROGRAM FILES\PETFPODMG6
Delete: \??\C:\PROGRAM FILES\OZU7LPSW8F
Delete: \??\C:\WINDOWS\SYSNATIVE\TASKS\77cf4b3dfabc9e11de3765bb9c0b2422
Delete: \??\C:\WINDOWS\SYSNATIVE\TASKS\Dermopyckatile
Delete: \??\C:\WINDOWS\SYSNATIVE\TASKS\KbhLni9OK4
Delete: \??\C:\WINDOWS\SYSNATIVE\TASKS\RunAtStartup
Delete: C:\WINDOWS\SYSNATIVE\TASKS\Pluperryarejotion Log
Delete Marked Items Auto Start Apps->Scheduled Tasks 2.
C:\WINDOWS\SYSNATIVE\TASKS\Joseck Helper="C:\Program Files
(x86)\Anerhspchpiry\hoquther.exe"
-------------------------------------------------------
01.05.2017 19:49:43 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete: \??\C:\PROGRA~3\MICROS~1\NETWORK\DSQ
Delete: \??\C:\ProgramData\WINDOWS SECURITY
Delete: \??\C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER
Delete: \??\C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK
Delete: \??\C:\PROGRAM FILES (X86)\FFF
Delete: \??\C:\Users\user\AppData\Roaming\EVENT MONITOR
Delete: \??\C:\PROGRAM FILES (X86)\MPC CLEANER
Delete: \??\C:\PROGRAM FILES (X86)\BADU
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GHETUTAINANTIGH
Delete: \??\C:\Users\user\AppData\Roaming\UPUPDATA
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\CHROMIUM
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\WIN_EN_77
Delete: \??\C:\PROGRAM FILES (X86)\WEATHERCHICKN
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TUTO_MONETIZE_120160723
Delete: \??\C:\PROGRAM FILES (X86)\SURRANDERU
Delete: \??\C:\ProgramData\QUOTEEX
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\MPCK
Delete: \??\C:\PROGRAM FILES (X86)\PCCLEANPLUS
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\GPLYRA
Delete: \??\C:\PROGRAMDATA\CLOUDPRINTER
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\DLOSARECERTAIN
Delete: \??\C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCK1
Delete: \??\C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCKJLRVMNHPDY
Delete: \??\C:\PROGRAM FILES (X86)\VEGAGHT
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\PROGRAM FILES (X86)\MOZILLA FIREFOX
Delete: \??\C:\PROGRAMDATA\QUOTEEXS
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\THUVET
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TEMP1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GOOGLE
Delete: \??\C:\PROGRAM FILES\G1NPCI9BHG
Delete: \??\C:\PROGRAM FILES\2Y8DB5ZJCZ
Delete: \??\C:\PROGRAM FILES\2KZZKPY7UL
Delete: \??\C:\PROGRAM FILES\K2BVHVQ9WG
Delete: \??\C:\PROGRAM FILES (X86)\2RFP2AR5Q4
Delete: \??\C:\PROGRAM FILES\PETFPODMG6
Delete: \??\C:\PROGRAM FILES\OZU7LPSW8F
Delete: \??\C:\WINDOWS\SYSNATIVE\TASKS\77cf4b3dfabc9e11de3765bb9c0b2422
Delete: \??\C:\WINDOWS\SYSNATIVE\TASKS\Dermopyckatile
Delete: \??\C:\WINDOWS\SYSNATIVE\TASKS\KbhLni9OK4
Delete: \??\C:\WINDOWS\SYSNATIVE\TASKS\RunAtStartup
Delete: \??\C:\WINDOWS\SYSNATIVE\TASKS\Pluperryarejotion Log
Delete: C:\WINDOWS\SYSNATIVE\TASKS\Joseck Helper
Delete Marked Items Auto Start Apps->Scheduled Tasks 2. C:\WINDOWS\SYSNATIVE\TASKS\
{97B71CFC-536E-4008-894A-BDE8C5724C92}=E:\ascs\Assassin's Creed Syndicate-Black
Box\Setup.exe
-------------------------------------------------------
01.05.2017 19:49:44 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete: \??\C:\PROGRA~3\MICROS~1\NETWORK\DSQ
Delete: \??\C:\ProgramData\WINDOWS SECURITY
Delete: \??\C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER
Delete: \??\C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK
Delete: \??\C:\PROGRAM FILES (X86)\FFF
Delete: \??\C:\Users\user\AppData\Roaming\EVENT MONITOR
Delete: \??\C:\PROGRAM FILES (X86)\MPC CLEANER
Delete: \??\C:\PROGRAM FILES (X86)\BADU
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GHETUTAINANTIGH
Delete: \??\C:\Users\user\AppData\Roaming\UPUPDATA
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\CHROMIUM
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\WIN_EN_77
Delete: \??\C:\PROGRAM FILES (X86)\WEATHERCHICKN
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TUTO_MONETIZE_120160723
Delete: \??\C:\PROGRAM FILES (X86)\SURRANDERU
Delete: \??\C:\ProgramData\QUOTEEX
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\MPCK
Delete: \??\C:\PROGRAM FILES (X86)\PCCLEANPLUS
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\GPLYRA
Delete: \??\C:\PROGRAMDATA\CLOUDPRINTER
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\DLOSARECERTAIN
Delete: \??\C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCK1
Delete: \??\C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCKJLRVMNHPDY
Delete: \??\C:\PROGRAM FILES (X86)\VEGAGHT
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\PROGRAM FILES (X86)\MOZILLA FIREFOX
Delete: \??\C:\PROGRAMDATA\QUOTEEXS
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\THUVET
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TEMP1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GOOGLE
Delete: \??\C:\PROGRAM FILES\G1NPCI9BHG
Delete: \??\C:\PROGRAM FILES\2Y8DB5ZJCZ
Delete: \??\C:\PROGRAM FILES\2KZZKPY7UL
Delete: \??\C:\PROGRAM FILES\K2BVHVQ9WG
Delete: \??\C:\PROGRAM FILES (X86)\2RFP2AR5Q4
Delete: \??\C:\PROGRAM FILES\PETFPODMG6
Delete: \??\C:\PROGRAM FILES\OZU7LPSW8F
Delete: \??\C:\WINDOWS\SYSNATIVE\TASKS\77cf4b3dfabc9e11de3765bb9c0b2422
Delete: \??\C:\WINDOWS\SYSNATIVE\TASKS\Dermopyckatile
Delete: \??\C:\WINDOWS\SYSNATIVE\TASKS\KbhLni9OK4
Delete: \??\C:\WINDOWS\SYSNATIVE\TASKS\RunAtStartup
Delete: \??\C:\WINDOWS\SYSNATIVE\TASKS\Pluperryarejotion Log
Delete: \??\C:\WINDOWS\SYSNATIVE\TASKS\Joseck Helper
Delete: C:\WINDOWS\SYSNATIVE\TASKS\{97B71CFC-536E-4008-894A-BDE8C5724C92}
Delete Marked Items Auto Start Apps->Registry Run. M24L9MWKE9RADH5="C:\Program
Files\2KZZKPY7UL\2KZZKPY7U.exe"
Delete Marked Items Auto Start Apps->Registry RunOnce.
CYERPQDWSI.exe=C:\USERS\USER\APPDATA\LOCAL\TEMP\E8-7D6AD-2F3-86191-
BF59B359BED00\CYERPQDWSI.EXE
Delete Marked Items Auto Start Apps->Registry Run.
GAEDGFTYAK.exe=C:\USERS\USER\APPDATA\LOCAL\TEMP\E8-7D6AD-2F3-86191-
BF59B359BED00\GAEDGFTYAK.EXE
Delete Marked Items Auto Start Apps->Scheduled Tasks 2.
C:\WINDOWS\SYSNATIVE\TASKS\Origin=C:\USERS\USER\APPDATA\ROAMING\ORIGIN\UPDATE.VBE
-------------------------------------------------------
01.05.2017 19:49:44 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete: \??\C:\PROGRA~3\MICROS~1\NETWORK\DSQ
Delete: \??\C:\ProgramData\WINDOWS SECURITY
Delete: \??\C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER
Delete: \??\C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK
Delete: \??\C:\PROGRAM FILES (X86)\FFF
Delete: \??\C:\Users\user\AppData\Roaming\EVENT MONITOR
Delete: \??\C:\PROGRAM FILES (X86)\MPC CLEANER
Delete: \??\C:\PROGRAM FILES (X86)\BADU
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GHETUTAINANTIGH
Delete: \??\C:\Users\user\AppData\Roaming\UPUPDATA
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\CHROMIUM
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\WIN_EN_77
Delete: \??\C:\PROGRAM FILES (X86)\WEATHERCHICKN
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TUTO_MONETIZE_120160723
Delete: \??\C:\PROGRAM FILES (X86)\SURRANDERU
Delete: \??\C:\ProgramData\QUOTEEX
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\MPCK
Delete: \??\C:\PROGRAM FILES (X86)\PCCLEANPLUS
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\GPLYRA
Delete: \??\C:\PROGRAMDATA\CLOUDPRINTER
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\DLOSARECERTAIN
Delete: \??\C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCK1
Delete: \??\C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCKJLRVMNHPDY
Delete: \??\C:\PROGRAM FILES (X86)\VEGAGHT
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\PROGRAM FILES (X86)\MOZILLA FIREFOX
Delete: \??\C:\PROGRAMDATA\QUOTEEXS
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\THUVET
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TEMP1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GOOGLE
Delete: \??\C:\PROGRAM FILES\G1NPCI9BHG
Delete: \??\C:\PROGRAM FILES\2Y8DB5ZJCZ
Delete: \??\C:\PROGRAM FILES\2KZZKPY7UL
Delete: \??\C:\PROGRAM FILES\K2BVHVQ9WG
Delete: \??\C:\PROGRAM FILES (X86)\2RFP2AR5Q4
Delete: \??\C:\PROGRAM FILES\PETFPODMG6
Delete: \??\C:\PROGRAM FILES\OZU7LPSW8F
Delete: \??\C:\WINDOWS\SYSNATIVE\TASKS\77cf4b3dfabc9e11de3765bb9c0b2422
Delete: \??\C:\WINDOWS\SYSNATIVE\TASKS\Dermopyckatile
Delete: \??\C:\WINDOWS\SYSNATIVE\TASKS\KbhLni9OK4
Delete: \??\C:\WINDOWS\SYSNATIVE\TASKS\RunAtStartup
Delete: \??\C:\WINDOWS\SYSNATIVE\TASKS\Pluperryarejotion Log
Delete: \??\C:\WINDOWS\SYSNATIVE\TASKS\Joseck Helper
Delete: \??\C:\WINDOWS\SYSNATIVE\TASKS\{97B71CFC-536E-4008-894A-BDE8C5724C92}
Delete: C:\WINDOWS\SYSNATIVE\TASKS\Origin
Delete Marked Items Auto Start Apps->Registry Run.
teklon=C:\USERS\USER\APPDATA\LOCAL\TEKLON.DLL
01.05.2017 19:49:45 User Shortcuts
Unknown: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick
Launch\User Pinned\TaskBar\Don Bradman Cricket 14.lnk = C:\PROGRAM FILES
(X86)\DBC14\CRICKET14.EXE
Delete Marked Items Windows Shell->User Shortcuts.
C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User
Pinned\TaskBar\Don Bradman Cricket 14.lnk=C:\PROGRAM FILES
(X86)\DBC14\CRICKET14.EXE
Safe
Deleting:C:\USERS\USER\APPDATA\ROAMING\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\TASKBAR\
DONBRA~1.LNK. You must restart your computer to fully delete this file.
01.05.2017 19:50:53 Auto Services
Suspicious: gemeloki = C:\PROGRAM FILES (X86)\4C4C4544-1478816059-3610-8051-
C8C04F525831\PROA11967A9-EA41-4142-85ED-3FF121804030.EXE
01.05.2017 19:50:53 Auto Services
Probably Malicious: OtherSearch = RUNDLL32.EXE "C:\PROGRAM FILES
(X86)\2RFP2AR5Q4\KL.DLL",SVC
01.05.2017 19:50:53 Auto Services
Probably Malicious: serverss = C:\WINDOWS\TEMP\CF24.TMP
01.05.2017 19:50:53 Auto Services
Probably Malicious: WindowsSecurity = C:\PROGRAMDATA\WINDOWS
SECURITY\WINSECURITY.EXE
01.05.2017 19:50:53 Auto Services
Suspicious: XBox = C:\PROGRAM FILES\XBOX\XBLIVE.EXE
01.05.2017 19:50:53 Svchost DLLs
Suspicious: Ferbayrepecult = C:\Program Files (x86)\Vegaght\Ferferrypekerkhlp.dll
01.05.2017 19:50:53 Print Providers
Suspicious: 0i8k93v7 = C:\Program Files (x86)\Mozilla
Firefox\browser\features1\local64spl.dll
01.05.2017 19:50:53 Print Providers
Suspicious: 0yfoyqxl = C:\Users\user\AppData\Local\Google\Chrome\User
Data1\local64spl.dll
01.05.2017 19:50:53 Print Providers
Suspicious: 13urjqhh = E:\MUSIC VIDEOS1\LOCAL64SPL.DLL
01.05.2017 19:50:53 Print Providers
Suspicious: 14m6xx0e = E:\ascs\\local64spl.dll
01.05.2017 19:50:53 Print Providers
Suspicious: 18g20lhr = C:\Users\user\AppData\Local\Temp1\local64spl.dll
01.05.2017 19:50:53 Print Providers
Suspicious: 2v24kn2g = C:\1\LOCAL64SPL.DLL
01.05.2017 19:50:53 Print Providers
Suspicious: 447bwijt = C:\\LOCAL64SPL.DLL
01.05.2017 19:50:53 Print Providers
Probably Malicious: 5ckkokhp = C:\Users\user\AppData\LocalLow\Youtube
AdBlock\local64spl.dll
01.05.2017 19:50:53 Print Providers
Suspicious: 81k5heu0 = D:\DBC CRACK1\LOCAL64SPL.DLL
01.05.2017 19:50:53 Print Providers
Suspicious: 94hmrrrr = C:\USERS\USER\APPDATA\LOCAL\TEMP\LOCAL64SPL.DLL
01.05.2017 19:50:53 Print Providers
Probably Malicious: 9i2il8fb = C:\Users\user\AppData\LocalLow\Youtube
AdBlock1\local64spl.dll
01.05.2017 19:50:53 Print Providers
Suspicious: ag56rwk9 = C:\WINDOWS\TEMP\LOCAL64SPL.DLL
01.05.2017 19:50:53 Print Providers
Probably Malicious: bmvpults = C:\Program Files (x86)\Youtube
AdBlock\local64spl.dll
01.05.2017 19:50:53 Print Providers
Suspicious: cpo1jf2q = E:\ascs1\local64spl.dll
01.05.2017 19:50:53 Print Providers
Suspicious: cr7tve1n = C:\Program Files (x86)\Mozilla
Firefox\browser\features\local64spl.dll
01.05.2017 19:50:53 Print Providers
Suspicious: d0iglg8j = C:\1\LOCAL64SPL.DLL
01.05.2017 19:50:53 Print Providers
Suspicious: dlbu9gkb = E:\ascs\\local64spl.dll
01.05.2017 19:50:53 Print Providers
Suspicious: dpg1mmuq = E:\DBC141\LOCAL64SPL.DLL
01.05.2017 19:50:53 Print Providers
Suspicious: ea5lzskm = D:\DBC CRACK\\LOCAL64SPL.DLL
01.05.2017 19:50:53 Print Providers
Suspicious: eflqpi1k = C:\Program Files (x86)\Joseck Helper\local64spl.dll
01.05.2017 19:50:53 Print Providers
Probably Malicious: fbk8tihj = C:\Users\user\AppData\LocalLow\Youtube
AdBlock\local64spl.dll
01.05.2017 19:50:53 Print Providers
Suspicious: fjl9v9iz = C:\Program Files (x86)\Mozilla
Firefox\browser\features1\local64spl.dll
01.05.2017 19:50:53 Print Providers
Suspicious: h37cw6vh = E:\DBC141\LOCAL64SPL.DLL
01.05.2017 19:50:53 Print Providers
Suspicious: hf2qa0f5 = C:\USERS\USER\APPDATA\LOCAL\TEMP\LOCAL64SPL.DLL
01.05.2017 19:50:53 Print Providers
Suspicious: i4cmpu90 = E:\ascs1\local64spl.dll
01.05.2017 19:50:53 Print Providers
Probably Malicious: jbaf93yw = C:\Program Files (x86)\Youtube
AdBlock1\local64spl.dll
01.05.2017 19:50:53 Print Providers
Suspicious: jq5embb7 = C:\Users\user\AppData\Local\Temp1\local64spl.dll
01.05.2017 19:50:53 Print Providers
Suspicious: l17n76jv = D:\DBC CRACK\\LOCAL64SPL.DLL
01.05.2017 19:50:53 Print Providers
Probably Malicious: l1hatv8l = C:\Program Files (x86)\Youtube
AdBlock1\local64spl.dll
01.05.2017 19:50:53 Print Providers
Suspicious: m6qtf9jh = E:\DBC14\\LOCAL64SPL.DLL
01.05.2017 19:50:53 Print Providers
Suspicious: mnbv0wy6 = C:\WINDOWS\TEMP1\LOCAL64SPL.DLL
01.05.2017 19:50:53 Print Providers
Suspicious: n7lfgzk9 = C:\Users\user\AppData\Local\Google\Chrome\User
Data1\local64spl.dll
01.05.2017 19:50:53 Print Providers
Suspicious: nc0brfeh = E:\MUSIC VIDEOS1\LOCAL64SPL.DLL
01.05.2017 19:50:53 Print Providers
Suspicious: ndupftwi = D:\DBC CRACK1\LOCAL64SPL.DLL
01.05.2017 19:50:53 Print Providers
Suspicious: nsbh22jo = C:\WINDOWS\TEMP1\LOCAL64SPL.DLL
01.05.2017 19:50:53 Print Providers
Probably Malicious: pvfb4soz = C:\Program Files (x86)\Youtube
AdBlock\local64spl.dll
01.05.2017 19:50:53 Print Providers
Suspicious: pvj4943e = E:\DBC14\\LOCAL64SPL.DLL
01.05.2017 19:50:53 Print Providers
Suspicious: qh08uu4r = C:\WINDOWS\TEMP\LOCAL64SPL.DLL
01.05.2017 19:50:53 Print Providers
Suspicious: qudc8boa = C:\Users\user\AppData\Local\Google\Chrome\User
Data\local64spl.dll
01.05.2017 19:50:53 Print Providers
Suspicious: uxwadwte = E:\MUSIC VIDEOS\\LOCAL64SPL.DLL
01.05.2017 19:50:53 Print Providers
Suspicious: v62tpou5 = C:\Users\user\AppData\Local\Google\Chrome\User
Data\local64spl.dll
01.05.2017 19:50:53 Print Providers
Suspicious: y7esir3a = E:\MUSIC VIDEOS\\LOCAL64SPL.DLL
01.05.2017 19:50:53 Print Providers
Suspicious: z1hwa9zl = C:\\LOCAL64SPL.DLL
01.05.2017 19:50:53 Print Providers
Probably Malicious: z5wmuh5r = C:\Users\user\AppData\LocalLow\Youtube
AdBlock1\local64spl.dll
01.05.2017 19:50:53 Print Providers
Suspicious: zrg2zdpb = C:\Program Files (x86)\Mozilla
Firefox\browser\features\local64spl.dll
Delete Marked Items Kernel Auto Boot->Print Providers.
9i2il8fb=C:\Users\user\AppData\LocalLow\Youtube AdBlock1\local64spl.dll
Delete Marked Items Kernel Auto Boot->Print Providers.
5ckkokhp=C:\Users\user\AppData\LocalLow\Youtube AdBlock\local64spl.dll
Delete Marked Items Kernel Auto Boot->Print Providers. pvfb4soz=C:\Program Files
(x86)\Youtube AdBlock\local64spl.dll
Delete Marked Items Kernel Auto Boot->Print Providers. bmvpults=C:\Program Files
(x86)\Youtube AdBlock\local64spl.dll
Delete Marked Items Kernel Auto Boot->Print Providers. jbaf93yw=C:\Program Files
(x86)\Youtube AdBlock1\local64spl.dll
Delete Marked Items Kernel Auto Boot->Print Providers.
fbk8tihj=C:\Users\user\AppData\LocalLow\Youtube AdBlock\local64spl.dll
Delete Marked Items Kernel Auto Boot->Print Providers. l1hatv8l=C:\Program Files
(x86)\Youtube AdBlock1\local64spl.dll
Delete Marked Items Kernel Auto Boot->Auto Services.
WindowsSecurity=C:\PROGRAMDATA\WINDOWS SECURITY\WINSECURITY.EXE
Delete Marked Items Kernel Auto Boot->Auto Services.
serverss=C:\WINDOWS\TEMP\CF24.TMP
Delete Marked Items Kernel Auto Boot->Print Providers.
z5wmuh5r=C:\Users\user\AppData\LocalLow\Youtube AdBlock1\local64spl.dll
Delete Marked Items Kernel Auto Boot->Auto Services. OtherSearch=RUNDLL32.EXE
"C:\PROGRAM FILES (X86)\2RFP2AR5Q4\KL.DLL",SVC
Delete Marked Items Kernel Auto Boot->Print Providers.
dlbu9gkb=E:\ascs\\local64spl.dll
Delete Marked Items Kernel Auto Boot->Print Providers. fjl9v9iz=C:\Program Files
(x86)\Mozilla Firefox\browser\features1\local64spl.dll
Delete Marked Items Kernel Auto Boot->Print Providers. eflqpi1k=C:\Program Files
(x86)\Joseck Helper\local64spl.dll
Delete Marked Items Kernel Auto Boot->Print Providers. cr7tve1n=C:\Program Files
(x86)\Mozilla Firefox\browser\features\local64spl.dll
Delete Marked Items Kernel Auto Boot->Print Providers.
0yfoyqxl=C:\Users\user\AppData\Local\Google\Chrome\User Data1\local64spl.dll
Delete Marked Items Kernel Auto Boot->Print Providers.
18g20lhr=C:\Users\user\AppData\Local\Temp1\local64spl.dll
Delete Marked Items Kernel Auto Boot->Print Providers.
14m6xx0e=E:\ascs\\local64spl.dll
Delete Marked Items Kernel Auto Boot->Print Providers.
cpo1jf2q=E:\ascs1\local64spl.dll
Delete Marked Items Kernel Auto Boot->Svchost DLLs. Ferbayrepecult=C:\Program Files
(x86)\Vegaght\Ferferrypekerkhlp.dll
The service has been marked for deletion->Partizan:Ferbayrepecult
Delete Marked Items Kernel Auto Boot->Print Providers. 0i8k93v7=C:\Program Files
(x86)\Mozilla Firefox\browser\features1\local64spl.dll
Delete Marked Items Kernel Auto Boot->Print Providers.
qudc8boa=C:\Users\user\AppData\Local\Google\Chrome\User Data\local64spl.dll
Delete Marked Items Kernel Auto Boot->Print Providers.
v62tpou5=C:\Users\user\AppData\Local\Google\Chrome\User Data\local64spl.dll
Delete Marked Items Kernel Auto Boot->Print Providers.
n7lfgzk9=C:\Users\user\AppData\Local\Google\Chrome\User Data1\local64spl.dll
Delete Marked Items Kernel Auto Boot->Print Providers.
jq5embb7=C:\Users\user\AppData\Local\Temp1\local64spl.dll
Delete Marked Items Kernel Auto Boot->Print Providers. zrg2zdpb=C:\Program Files
(x86)\Mozilla Firefox\browser\features\local64spl.dll
Delete Marked Items Kernel Auto Boot->Print Providers.
i4cmpu90=E:\ascs1\local64spl.dll
Delete Marked Items Kernel Auto Boot->Auto Services. gemeloki=C:\PROGRAM FILES
(X86)\4C4C4544-1478816059-3610-8051-C8C04F525831\PROA11967A9-EA41-4142-85ED-
3FF121804030.EXE
Delete Marked Items Kernel Auto Boot->Print Providers. 13urjqhh=E:\MUSIC
VIDEOS1\LOCAL64SPL.DLL
Delete Marked Items Kernel Auto Boot->Print Providers. nc0brfeh=E:\MUSIC
VIDEOS1\LOCAL64SPL.DLL
Delete Marked Items Kernel Auto Boot->Print Providers. y7esir3a=E:\MUSIC
VIDEOS\\LOCAL64SPL.DLL
Delete Marked Items Kernel Auto Boot->Print Providers. uxwadwte=E:\MUSIC
VIDEOS\\LOCAL64SPL.DLL
Delete Marked Items Kernel Auto Boot->Print Providers. 81k5heu0=D:\DBC
CRACK1\LOCAL64SPL.DLL
Delete Marked Items Kernel Auto Boot->Print Providers.
pvj4943e=E:\DBC14\\LOCAL64SPL.DLL
Delete Marked Items Kernel Auto Boot->Print Providers. ndupftwi=D:\DBC
CRACK1\LOCAL64SPL.DLL
Delete Marked Items Kernel Auto Boot->Print Providers.
m6qtf9jh=E:\DBC14\\LOCAL64SPL.DLL
Delete Marked Items Kernel Auto Boot->Print Providers.
dpg1mmuq=E:\DBC141\LOCAL64SPL.DLL
Delete Marked Items Kernel Auto Boot->Print Providers.
h37cw6vh=E:\DBC141\LOCAL64SPL.DLL
Delete Marked Items Kernel Auto Boot->Print Providers. l17n76jv=D:\DBC
CRACK\\LOCAL64SPL.DLL
Delete Marked Items Kernel Auto Boot->Print Providers. ea5lzskm=D:\DBC
CRACK\\LOCAL64SPL.DLL
Delete Marked Items Kernel Auto Boot->Print Providers.
ag56rwk9=C:\WINDOWS\TEMP\LOCAL64SPL.DLL
Delete Marked Items Kernel Auto Boot->Print Providers.
hf2qa0f5=C:\USERS\USER\APPDATA\LOCAL\TEMP\LOCAL64SPL.DLL
Delete Marked Items Kernel Auto Boot->Print Providers.
94hmrrrr=C:\USERS\USER\APPDATA\LOCAL\TEMP\LOCAL64SPL.DLL
Delete Marked Items Kernel Auto Boot->Print Providers. z1hwa9zl=C:\\LOCAL64SPL.DLL
Delete Marked Items Kernel Auto Boot->Print Providers.
mnbv0wy6=C:\WINDOWS\TEMP1\LOCAL64SPL.DLL
Delete Marked Items Kernel Auto Boot->Print Providers. 2v24kn2g=C:\1\LOCAL64SPL.DLL
Delete Marked Items Kernel Auto Boot->Print Providers. 447bwijt=C:\\LOCAL64SPL.DLL
Delete Marked Items Kernel Auto Boot->Print Providers.
qh08uu4r=C:\WINDOWS\TEMP\LOCAL64SPL.DLL
Delete Marked Items Kernel Auto Boot->Print Providers.
nsbh22jo=C:\WINDOWS\TEMP1\LOCAL64SPL.DLL
Delete Marked Items Kernel Auto Boot->Print Providers. d0iglg8j=C:\1\LOCAL64SPL.DLL
Delete Marked Items Kernel Auto Boot->Auto Services. XBox=C:\PROGRAM
FILES\XBOX\XBLIVE.EXE
01.05.2017 19:51:35 IE Extensions - All Users
Unknown: {2670000A-7350-4f3c-8081-5663EE0C6C49} =
Delete Marked Items Internet Explorer->IE Extensions - All Users. {2670000A-7350-
4f3c-8081-5663EE0C6C49}=
01.05.2017 19:51:45 Current Home Page(x64)
Unknown: Start Page = https://in.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-
fullyhosted_003&type=wbf_vit_16_27&param1=1&param2=f%3D1%26b%3DIE%26cc%3Din%26pa
%3DWincy%26cd
%3D2XzuyEtN2Y1L1QzuyByEzzyCyB0AyEtBzzyDyBtDtAyB0DtAtN0D0Tzu0StCyCyDtDtN1L2XzutAtFtB
tAtFtCtFtAtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2StBtDyEyDyEtD0FyCtGyE0ByDyDtGyD0D0FyBtGyDt
CtB0BtG0CzyyByDtByDyC0B0CyByE0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0C0AyEyDyB0CyDtDtGtCtB0FtB
tGyEzz0C0BtG0AtB0AyCtG0DyC0FtDzz0CzytBzytCtC0D2QtN0A0LzuyE%26cr%3D1425905069%26a
%3Dwbf_vit_16_27%26os_ver%3D6.1%26os%3DWindows%2B7%2BUltimate
01.05.2017 19:51:45 Search Provider for All Users
Probably Malicious: {0633EE93-D776-472f-A0FF-E1416B8B2E3A} =
https://in.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-
fullyhosted_003&type=wbf_vit_16_27&param1=1&param2=f%3D4%26b%3DIE%26cc%3Din%26pa
%3DWincy%26cd
%3D2XzuyEtN2Y1L1QzuyByEzzyCyB0AyEtBzzyDyBtDtAyB0DtAtN0D0Tzu0StCyCyDtDtN1L2XzutAtFtB
tAtFtCtFtAtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2StBtDyEyDyEtD0FyCtGyE0ByDyDtGyD0D0FyBtGyDt
CtB0BtG0CzyyByDtByDyC0B0CyByE0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0C0AyEyDyB0CyDtDtGtCtB0FtB
tGyEzz0C0BtG0AtB0AyCtG0DyC0FtDzz0CzytBzytCtC0D2QtN0A0LzuyE%26cr%3D1425905069%26a
%3Dwbf_vit_16_27%26os_ver%3D6.1%26os%3DWindows%2B7%2BUltimate&p={searchTerms}
01.05.2017 19:51:45 Search Provider for All Users(x64)
Probably Malicious: {0633EE93-D776-472f-A0FF-E1416B8B2E3A} =
https://in.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-
fullyhosted_003&type=wbf_vit_16_27&param1=1&param2=f%3D4%26b%3DIE%26cc%3Din%26pa
%3DWincy%26cd
%3D2XzuyEtN2Y1L1QzuyByEzzyCyB0AyEtBzzyDyBtDtAyB0DtAtN0D0Tzu0StCyCyDtDtN1L2XzutAtFtB
tAtFtCtFtAtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2StBtDyEyDyEtD0FyCtGyE0ByDyDtGyD0D0FyBtGyDt
CtB0BtG0CzyyByDtByDyC0B0CyByE0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0C0AyEyDyB0CyDtDtGtCtB0FtB
tGyEzz0C0BtG0AtB0AyCtG0DyC0FtDzz0CzytBzytCtC0D2QtN0A0LzuyE%26cr%3D1425905069%26a
%3Dwbf_vit_16_27%26os_ver%3D6.1%26os%3DWindows%2B7%2BUltimate&p={searchTerms}
01.05.2017 19:51:45 Proxy
Unknown: ProxyServer = http=127.0.0.1:8080;https=127.0.0.1:8080
01.05.2017 19:51:45 FireFox Settings
Probably Malicious: browser.startup.homepage = http://www-searching.com/?
site=shyosffdefault&prd=set_ff&s=h51ztrmbl10bu,5157e9a5-612f-4c40-a626-
b294fd6e41da,
01.05.2017 19:51:45 FireFox Settings
Probably Malicious: browser.newtab.url = http://www-searching.com/?
site=shyosffdefault&prd=set_ff&s=h51ztrmbl10bu,5157e9a5-612f-4c40-a626-
b294fd6e41da,
01.05.2017 19:51:45 Firefox Search Engine (search-metadata)
Probably Malicious: [global].current = Search Module
Delete Marked Items Internet Explorer->Search Provider for All Users. {0633EE93-
D776-472f-A0FF-E1416B8B2E3A}=https://in.search.yahoo.com/yhs/search?
hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_vit_16_27&param1=1&param2=f%3D4%26b
%3DIE%26cc%3Din%26pa%3DWincy%26cd
%3D2XzuyEtN2Y1L1QzuyByEzzyCyB0AyEtBzzyDyBtDtAyB0DtAtN0D0Tzu0StCyCyDtDtN1L2XzutAtFtB
tAtFtCtFtAtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2StBtDyEyDyEtD0FyCtGyE0ByDyDtGyD0D0FyBtGyDt
CtB0BtG0CzyyByDtByDyC0B0CyByE0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0C0AyEyDyB0CyDtDtGtCtB0FtB
tGyEzz0C0BtG0AtB0AyCtG0DyC0FtDzz0CzytBzytCtC0D2QtN0A0LzuyE%26cr%3D1425905069%26a
%3Dwbf_vit_16_27%26os_ver%3D6.1%26os%3DWindows%2B7%2BUltimate&p={searchTerms}
Delete Marked Items Internet Explorer->Search Provider for All Users(x64).
{0633EE93-D776-472f-A0FF-E1416B8B2E3A}=https://in.search.yahoo.com/yhs/search?
hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_vit_16_27&param1=1&param2=f%3D4%26b
%3DIE%26cc%3Din%26pa%3DWincy%26cd
%3D2XzuyEtN2Y1L1QzuyByEzzyCyB0AyEtBzzyDyBtDtAyB0DtAtN0D0Tzu0StCyCyDtDtN1L2XzutAtFtB
tAtFtCtFtAtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2StBtDyEyDyEtD0FyCtGyE0ByDyDtGyD0D0FyBtGyDt
CtB0BtG0CzyyByDtByDyC0B0CyByE0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0C0AyEyDyB0CyDtDtGtCtB0FtB
tGyEzz0C0BtG0AtB0AyCtG0DyC0FtDzz0CzytBzytCtC0D2QtN0A0LzuyE%26cr%3D1425905069%26a
%3Dwbf_vit_16_27%26os_ver%3D6.1%26os%3DWindows%2B7%2BUltimate&p={searchTerms}
File has been saved to:
C:\@RestoreQuarantine\2017-May-01_19hour\search-metadata.json
Added restore batch file to \@RestoreQuarantine
Deleting file:
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fnvrug3e.default\search-
metadata.json
File will be deleted at next reboot.
-------------------------------------------------------
01.05.2017 19:51:48 Approved File Replacement
Delete: \??\C:\Program Files\ZIPTOOL
Delete: \??\C:\PROGRAM FILES (X86)\ANERHSPCHPIRY
Delete: \??\C:\PROGRAM FILES\SPACESOUNDPRO
Delete: \??\C:\PROGRAM FILES (X86)\JOSECK HELPER
Delete: \??\C:\ProgramData\LOGIC HANDLER
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\ANOBERT
Delete: \??\C:\PROGRAM FILES (X86)\CLEANBROWSER
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\Users\user\AppData\Roaming\MOZILLA\FIREFOX\NAWERIWEENTCOFISE
Delete: \??\C:\PROGRA~3\MICROS~1\NETWORK\DSQ
Delete: \??\C:\ProgramData\WINDOWS SECURITY
Delete: \??\C:\ProgramData\MICROSOFT\NETWORK\DSQ\BROWSER
Delete: \??\C:\Users\user\AppData\Local\KEMGADEOJGLIBFLOMICGNFEOPKDFFLNK
Delete: \??\C:\PROGRAM FILES (X86)\FFF
Delete: \??\C:\Users\user\AppData\Roaming\EVENT MONITOR
Delete: \??\C:\PROGRAM FILES (X86)\MPC CLEANER
Delete: \??\C:\PROGRAM FILES (X86)\BADU
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GHETUTAINANTIGH
Delete: \??\C:\Users\user\AppData\Roaming\UPUPDATA
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\CHROMIUM
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK
Delete: \??\C:\USERS\USER\APPDATA\LOCALLOW\YOUTUBE ADBLOCK1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\WIN_EN_77
Delete: \??\C:\PROGRAM FILES (X86)\WEATHERCHICKN
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TUTO_MONETIZE_120160723
Delete: \??\C:\PROGRAM FILES (X86)\SURRANDERU
Delete: \??\C:\ProgramData\QUOTEEX
Delete: \??\C:\PROGRAM FILES (X86)\CONTENTPUSH
Delete: \??\C:\PROGRAM FILES (X86)\MPCK
Delete: \??\C:\PROGRAM FILES (X86)\PCCLEANPLUS
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\GPLYRA
Delete: \??\C:\PROGRAMDATA\CLOUDPRINTER
Delete: \??\C:\USERS\USER\APPDATA\ROAMING\DLOSARECERTAIN
Delete: \??\C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCK1
Delete: \??\C:\PROGRAM FILES (X86)\YOUTUBE ADBLOCKJLRVMNHPDY
Delete: \??\C:\PROGRAM FILES (X86)\VEGAGHT
Delete: \??\C:\PROGRAM FILES (X86)\PUBHOTSPOT
Delete: \??\C:\PROGRAM FILES (X86)\MOZILLA FIREFOX
Delete: \??\C:\PROGRAMDATA\QUOTEEXS
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\THUVET
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\TEMP1
Delete: \??\C:\USERS\USER\APPDATA\LOCAL\GOOGLE
Delete: \??\C:\PROGRAM FILES\G1NPCI9BHG
Delete: \??\C:\PROGRAM FILES\2Y8DB5ZJCZ
Delete: \??\C:\PROGRAM FILES\2KZZKPY7UL
Delete: \??\C:\PROGRAM FILES\K2BVHVQ9WG
Delete: \??\C:\PROGRAM FILES (X86)\2RFP2AR5Q4
Delete: \??\C:\PROGRAM FILES\PETFPODMG6
Delete: \??\C:\PROGRAM FILES\OZU7LPSW8F
Delete: \??\C:\WINDOWS\SYSNATIVE\TASKS\77cf4b3dfabc9e11de3765bb9c0b2422
Delete: \??\C:\WINDOWS\SYSNATIVE\TASKS\Dermopyckatile
Delete: \??\C:\WINDOWS\SYSNATIVE\TASKS\KbhLni9OK4
Delete: \??\C:\WINDOWS\SYSNATIVE\TASKS\RunAtStartup
Delete: \??\C:\WINDOWS\SYSNATIVE\TASKS\Pluperryarejotion Log
Delete: \??\C:\WINDOWS\SYSNATIVE\TASKS\Joseck Helper
Delete: \??\C:\WINDOWS\SYSNATIVE\TASKS\{97B71CFC-536E-4008-894A-BDE8C5724C92}
Delete: \??\C:\WINDOWS\SYSNATIVE\TASKS\Origin
Delete:
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fnvrug3e.default\search-
metadata.json
01.05.2017 19:51:49 Current Home Page(x64)
Unknown: Start Page = https://in.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-
fullyhosted_003&type=wbf_vit_16_27&param1=1&param2=f%3D1%26b%3DIE%26cc%3Din%26pa
%3DWincy%26cd
%3D2XzuyEtN2Y1L1QzuyByEzzyCyB0AyEtBzzyDyBtDtAyB0DtAtN0D0Tzu0StCyCyDtDtN1L2XzutAtFtB
tAtFtCtFtAtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2StBtDyEyDyEtD0FyCtGyE0ByDyDtGyD0D0FyBtGyDt
CtB0BtG0CzyyByDtByDyC0B0CyByE0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0C0AyEyDyB0CyDtDtGtCtB0FtB
tGyEzz0C0BtG0AtB0AyCtG0DyC0FtDzz0CzytBzytCtC0D2QtN0A0LzuyE%26cr%3D1425905069%26a
%3Dwbf_vit_16_27%26os_ver%3D6.1%26os%3DWindows%2B7%2BUltimate
01.05.2017 19:51:49 Proxy
Unknown: ProxyServer = http=127.0.0.1:8080;https=127.0.0.1:8080
Anti-malware scan started at: 02.05.2017 17:35:16
02.05.2017 17:35:54 Running Processes
Probably Malicious: chrome.exe = C:\PROGRAM FILES
(X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
02.05.2017 17:36:18 User Shortcuts
Unknown: C:\Users\Public\Desktop\Beetel 3G Data Card.lnk = C:\PROGRAM FILES
(X86)\BEETEL 3G DATA CARD\WIRELESSMODEM.EXE
02.05.2017 17:36:18 User Shortcuts
Probably Malicious: C:\Users\Public\Desktop\Google Chrome.lnk = C:\PROGRAM FILES
(X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
02.05.2017 17:36:18 User Shortcuts
Probably Malicious: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick
Launch\Google Chrome.lnk = C:\PROGRAM FILES
(X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
02.05.2017 17:36:18 User Shortcuts
Probably Malicious: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick
Launch\User Pinned\TaskBar\Google Chrome.lnk = C:\PROGRAM FILES
(X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
02.05.2017 17:36:18 User Shortcuts
Probably Malicious: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google
Chrome.lnk = C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
02.05.2017 17:37:48 Google Chrome Addons
Probably Malicious: pilplloabdedfmialnfchjomjmpjcoej =
C:\Users\user\AppData\Local\Google\Chrome\User
Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.0.54_0
Anti-malware scan finished at: 02.05.2017 17:37:49
Anti-malware scan started at: 02.05.2017 17:48:34
02.05.2017 17:49:13 User Shortcuts
Unknown: C:\Users\Public\Desktop\Beetel 3G Data Card.lnk = C:\PROGRAM FILES
(X86)\BEETEL 3G DATA CARD\WIRELESSMODEM.EXE
02.05.2017 17:49:13 User Shortcuts
Probably Malicious: C:\Users\Public\Desktop\Google Chrome.lnk = C:\PROGRAM FILES
(X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
02.05.2017 17:49:13 User Shortcuts
Probably Malicious: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick
Launch\Google Chrome.lnk = C:\PROGRAM FILES
(X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
02.05.2017 17:49:13 User Shortcuts
Probably Malicious: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick
Launch\User Pinned\TaskBar\Google Chrome.lnk = C:\PROGRAM FILES
(X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
02.05.2017 17:49:13 User Shortcuts
Probably Malicious: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google
Chrome.lnk = C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
02.05.2017 17:49:13 User Shortcuts
Unknown: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download
Manager\Internet Download Manager.lnk = C:\PROGRAM FILES (X86)\INTERNET DOWNLOAD
MANAGER\IDMAN.EXE
02.05.2017 17:49:13 Registry Run
Suspicious: IDMan = C:\PROGRAM FILES (X86)\INTERNET DOWNLOAD MANAGER\IDMAN.EXE
Delete Marked Items Windows Shell->User Shortcuts.
C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User
Pinned\TaskBar\Google Chrome.lnk=C:\PROGRAM FILES
(X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
Resetting shortcut: C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
Resetting shortcut:
C:\Users\user\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\TaskBar\GOOGLE~1.
LNK
Success:
C:\Users\user\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\USERPI~1\TaskBar\GOOGLE~1.
LNK
Delete Marked Items Windows Shell->User Shortcuts.
C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google
Chrome.lnk=C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
Resetting shortcut: C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
Resetting shortcut:
C:\Users\user\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\GOOGLE~1.LNK
Success: C:\Users\user\AppData\Roaming\MICROS~1\INTERN~1\QUICKL~1\GOOGLE~1.LNK
Delete Marked Items Windows Shell->User Shortcuts. C:\Users\Public\Desktop\Google
Chrome.lnk=C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
Resetting shortcut: C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
Resetting shortcut: C:\Users\Public\Desktop\GOOGLE~1.LNK
Success: C:\Users\Public\Desktop\GOOGLE~1.LNK
Delete Marked Items Windows Shell->User Shortcuts.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk=C:\PROGRAM
FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
Resetting shortcut: C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
Resetting shortcut: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\GOOGLE~1.LNK
Success: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\GOOGLE~1.LNK
Delete Marked Items Auto Start Apps->Registry Run. IDMan=C:\PROGRAM FILES
(X86)\INTERNET DOWNLOAD MANAGER\IDMAN.EXE
02.05.2017 18:00:04 User Shortcuts
Unknown: C:\Users\Public\Desktop\Beetel 3G Data Card.lnk = C:\PROGRAM FILES
(X86)\BEETEL 3G DATA CARD\WIRELESSMODEM.EXE
02.05.2017 18:00:04 User Shortcuts
Unknown: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download
Manager\Internet Download Manager.lnk = C:\PROGRAM FILES (X86)\INTERNET DOWNLOAD
MANAGER\IDMAN.EXE
Anti-malware scan finished at: 02.05.2017 18:00:12
Anti-malware scan started at: 04.05.2017 01:01:20
04.05.2017 01:01:29 Applications
Probably Malicious: BrowserAir =
C:\Users\user\AppData\Local\BrowserAir\Application\unins000.exe
04.05.2017 01:01:29 Applications
Probably Malicious: Search module = C:\Program Files\Common
Files\Noobzo\GNUpdate\smUninstall.exe
04.05.2017 01:01:45 Unwanted Software Files
Probably Malicious: C:\ProgramData\SEARCHMODULE\ = C:\ProgramData\SEARCHMODULE\
04.05.2017 01:01:45 Unwanted Software Files
Probably Malicious: SMP2.EXE = C:\PROGRAMDATA\SMP2.EXE
04.05.2017 01:01:45 Unwanted Software Files
Probably Malicious: BI3.EXE = C:\WINDOWS\SYSNATIVE\BI3.EXE
04.05.2017 01:01:45 Unwanted Software Files
Probably Malicious: BrowserAir = C:\USERS\USER\APPDATA\LOCAL\BROWSERAIR\
04.05.2017 01:01:54 User Shortcuts
Probably Malicious: C:\Users\user\Desktop\BrowserAir.lnk =
C:\USERS\USER\APPDATA\LOCAL\BROWSERAIR\APPLICATION\BROWSERAIREXEC.EXE
04.05.2017 01:01:54 User Shortcuts
Unknown: C:\Users\Public\Desktop\Beetel 3G Data Card.lnk = C:\PROGRAM FILES
(X86)\BEETEL 3G DATA CARD\WIRELESSMODEM.EXE
04.05.2017 01:01:54 User Shortcuts
Probably Malicious: C:\Users\Public\Desktop\Google Chrome.lnk = C:\PROGRAM FILES
(X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
04.05.2017 01:01:54 User Shortcuts
Probably Malicious: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick
Launch\BrowserAir.lnk =
C:\USERS\USER\APPDATA\LOCAL\BROWSERAIR\APPLICATION\BROWSERAIREXEC.EXE
04.05.2017 01:01:54 User Shortcuts
Probably Malicious: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick
Launch\Google Chrome.lnk = C:\PROGRAM FILES
(X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
04.05.2017 01:01:54 User Shortcuts
Probably Malicious: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick
Launch\User Pinned\ImplicitAppShortcuts\360c22b137d62ce9\Google Chrome.lnk =
C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
04.05.2017 01:01:54 User Shortcuts
Probably Malicious: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick
Launch\User Pinned\TaskBar\BrowserAir.lnk =
C:\USERS\USER\APPDATA\LOCAL\BROWSERAIR\APPLICATION\BROWSERAIREXEC.EXE
04.05.2017 01:01:54 User Shortcuts
Probably Malicious: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick
Launch\User Pinned\TaskBar\Google Chrome.lnk = C:\PROGRAM FILES
(X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
04.05.2017 01:01:54 User Shortcuts
Probably Malicious: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google
Chrome.lnk = C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
04.05.2017 01:01:54 User Shortcuts
Unknown: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download
Manager\Internet Download Manager.lnk = C:\PROGRAM FILES (X86)\INTERNET DOWNLOAD
MANAGER\IDMAN.EXE
04.05.2017 01:01:54 Registry Run
Suspicious: IDMan = C:\PROGRAM FILES (X86)\INTERNET DOWNLOAD MANAGER\IDMAN.EXE
04.05.2017 01:01:54 Scheduled Tasks 2
Probably Malicious: C:\WINDOWS\SYSNATIVE\TASKS\IBUpd =
C:\USERS\USER\APPDATA\LOCAL\BROWSERAIR\48.0.0.0\UPDATER.EXE
04.05.2017 01:01:54 Scheduled Tasks 2
Probably Malicious: C:\WINDOWS\SYSNATIVE\TASKS\IBUpd2 =
C:\USERS\USER\APPDATA\LOCAL\BROWSERAIR\48.0.0.0\UPDATER.EXE
04.05.2017 01:01:54 Scheduled Tasks 2
Probably Malicious: C:\WINDOWS\SYSNATIVE\TASKS\SMW_P = C:\PROGRAMDATA\SMP2.EXE
04.05.2017 01:01:54 Scheduled Tasks 2.0 Cached
Probably Malicious: IBUpd2 =
04.05.2017 01:01:54 Scheduled Tasks 2.0 Cached
Probably Malicious: SMW_P =
04.05.2017 01:01:54 Scheduled Tasks 2.0 Cached
Probably Malicious:
SMW_UpdateTask_Time_3534343931313834372d5755326c785a5a5737414534 =
Anti-malware scan started at: 04.05.2017 16:32:08
04.05.2017 16:32:20 Applications
Probably Malicious: BrowserAir =
C:\Users\user\AppData\Local\BrowserAir\Application\unins000.exe
04.05.2017 16:32:20 Applications
Probably Malicious: Search module = C:\Program Files\Common
Files\Noobzo\GNUpdate\smUninstall.exe
04.05.2017 16:32:27 Unwanted Software Files
Probably Malicious: C:\ProgramData\SEARCHMODULE\ = C:\ProgramData\SEARCHMODULE\
04.05.2017 16:32:27 Unwanted Software Files
Probably Malicious: SMP2.EXE = C:\PROGRAMDATA\SMP2.EXE
04.05.2017 16:32:27 Unwanted Software Files
Probably Malicious: BI3.EXE = C:\WINDOWS\SYSNATIVE\BI3.EXE
04.05.2017 16:32:27 Unwanted Software Files
Probably Malicious: BrowserAir = C:\USERS\USER\APPDATA\LOCAL\BROWSERAIR\
04.05.2017 16:32:34 User Shortcuts
Probably Malicious: C:\Users\user\Desktop\BrowserAir.lnk =
C:\USERS\USER\APPDATA\LOCAL\BROWSERAIR\APPLICATION\BROWSERAIREXEC.EXE
04.05.2017 16:32:34 User Shortcuts
Unknown: C:\Users\Public\Desktop\Beetel 3G Data Card.lnk = C:\PROGRAM FILES
(X86)\BEETEL 3G DATA CARD\WIRELESSMODEM.EXE
04.05.2017 16:32:34 User Shortcuts
Probably Malicious: C:\Users\Public\Desktop\Google Chrome.lnk = C:\PROGRAM FILES
(X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
04.05.2017 16:32:34 User Shortcuts
Probably Malicious: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick
Launch\BrowserAir.lnk =
C:\USERS\USER\APPDATA\LOCAL\BROWSERAIR\APPLICATION\BROWSERAIREXEC.EXE
04.05.2017 16:32:34 User Shortcuts
Probably Malicious: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick
Launch\Google Chrome.lnk = C:\PROGRAM FILES
(X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
04.05.2017 16:32:34 User Shortcuts
Probably Malicious: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick
Launch\User Pinned\ImplicitAppShortcuts\360c22b137d62ce9\Google Chrome.lnk =
C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
04.05.2017 16:32:34 User Shortcuts
Probably Malicious: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick
Launch\User Pinned\TaskBar\BrowserAir.lnk =
C:\USERS\USER\APPDATA\LOCAL\BROWSERAIR\APPLICATION\BROWSERAIREXEC.EXE
04.05.2017 16:32:34 User Shortcuts
Probably Malicious: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick
Launch\User Pinned\TaskBar\Google Chrome.lnk = C:\PROGRAM FILES
(X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
04.05.2017 16:32:34 User Shortcuts
Probably Malicious: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google
Chrome.lnk = C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
04.05.2017 16:32:34 User Shortcuts
Unknown: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download
Manager\Internet Download Manager.lnk = C:\PROGRAM FILES (X86)\INTERNET DOWNLOAD
MANAGER\IDMAN.EXE
04.05.2017 16:32:34 Registry Run
Suspicious: IDMan = C:\PROGRAM FILES (X86)\INTERNET DOWNLOAD MANAGER\IDMAN.EXE
04.05.2017 16:32:34 Scheduled Tasks 2
Probably Malicious: C:\WINDOWS\SYSNATIVE\TASKS\IBUpd =
C:\USERS\USER\APPDATA\LOCAL\BROWSERAIR\48.0.0.0\UPDATER.EXE
04.05.2017 16:32:34 Scheduled Tasks 2
Probably Malicious: C:\WINDOWS\SYSNATIVE\TASKS\IBUpd2 =
C:\USERS\USER\APPDATA\LOCAL\BROWSERAIR\48.0.0.0\UPDATER.EXE
04.05.2017 16:32:34 Scheduled Tasks 2
Probably Malicious: C:\WINDOWS\SYSNATIVE\TASKS\SMW_P = C:\PROGRAMDATA\SMP2.EXE
04.05.2017 16:32:34 Scheduled Tasks 2.0 Cached
Probably Malicious: IBUpd2 =
04.05.2017 16:32:34 Scheduled Tasks 2.0 Cached
Probably Malicious: SMW_P =
04.05.2017 16:32:34 Scheduled Tasks 2.0 Cached
Probably Malicious:
SMW_UpdateTask_Time_3534343931313834372d5755326c785a5a5737414534 =
Anti-malware scan started at: 05.05.2017 15:57:18
05.05.2017 15:57:27 Applications
Probably Malicious: BrowserAir =
C:\Users\user\AppData\Local\BrowserAir\Application\unins000.exe
05.05.2017 15:57:27 Applications
Probably Malicious: Search module = C:\Program Files\Common
Files\Noobzo\GNUpdate\smUninstall.exe
05.05.2017 15:57:41 Unwanted Software Files
Probably Malicious: C:\ProgramData\SEARCHMODULE\ = C:\ProgramData\SEARCHMODULE\
05.05.2017 15:57:41 Unwanted Software Files
Probably Malicious: SMP2.EXE = C:\PROGRAMDATA\SMP2.EXE
05.05.2017 15:57:41 Unwanted Software Files
Probably Malicious: BI3.EXE = C:\WINDOWS\SYSNATIVE\BI3.EXE
05.05.2017 15:57:41 Unwanted Software Files
Probably Malicious: BrowserAir = C:\USERS\USER\APPDATA\LOCAL\BROWSERAIR\
05.05.2017 15:57:50 User Shortcuts
Probably Malicious: C:\Users\user\Desktop\BrowserAir.lnk =
C:\USERS\USER\APPDATA\LOCAL\BROWSERAIR\APPLICATION\BROWSERAIREXEC.EXE
05.05.2017 15:57:50 User Shortcuts
Unknown: C:\Users\Public\Desktop\Beetel 3G Data Card.lnk = C:\PROGRAM FILES
(X86)\BEETEL 3G DATA CARD\WIRELESSMODEM.EXE
05.05.2017 15:57:50 User Shortcuts
Probably Malicious: C:\Users\Public\Desktop\Google Chrome.lnk = C:\PROGRAM FILES
(X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
05.05.2017 15:57:50 User Shortcuts
Probably Malicious: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick
Launch\BrowserAir.lnk =
C:\USERS\USER\APPDATA\LOCAL\BROWSERAIR\APPLICATION\BROWSERAIREXEC.EXE
05.05.2017 15:57:50 User Shortcuts
Probably Malicious: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick
Launch\Google Chrome.lnk = C:\PROGRAM FILES
(X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
05.05.2017 15:57:50 User Shortcuts
Probably Malicious: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick
Launch\User Pinned\ImplicitAppShortcuts\360c22b137d62ce9\Google Chrome.lnk =
C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
05.05.2017 15:57:50 User Shortcuts
Probably Malicious: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick
Launch\User Pinned\TaskBar\BrowserAir.lnk =
C:\USERS\USER\APPDATA\LOCAL\BROWSERAIR\APPLICATION\BROWSERAIREXEC.EXE
05.05.2017 15:57:50 User Shortcuts
Probably Malicious: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick
Launch\User Pinned\TaskBar\Google Chrome.lnk = C:\PROGRAM FILES
(X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
05.05.2017 15:57:50 User Shortcuts
Probably Malicious: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google
Chrome.lnk = C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
05.05.2017 15:57:50 User Shortcuts
Unknown: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download
Manager\Internet Download Manager.lnk = C:\PROGRAM FILES (X86)\INTERNET DOWNLOAD
MANAGER\IDMAN.EXE
05.05.2017 15:57:50 Registry Run
Suspicious: IDMan = C:\PROGRAM FILES (X86)\INTERNET DOWNLOAD MANAGER\IDMAN.EXE
05.05.2017 15:57:50 Scheduled Tasks 2
Probably Malicious: C:\WINDOWS\SYSNATIVE\TASKS\IBUpd =
C:\USERS\USER\APPDATA\LOCAL\BROWSERAIR\48.0.0.0\UPDATER.EXE
05.05.2017 15:57:50 Scheduled Tasks 2
Probably Malicious: C:\WINDOWS\SYSNATIVE\TASKS\IBUpd2 =
C:\USERS\USER\APPDATA\LOCAL\BROWSERAIR\48.0.0.0\UPDATER.EXE
05.05.2017 15:57:50 Scheduled Tasks 2
Probably Malicious: C:\WINDOWS\SYSNATIVE\TASKS\SMW_P = C:\PROGRAMDATA\SMP2.EXE
05.05.2017 15:57:50 Scheduled Tasks 2.0 Cached
Probably Malicious: IBUpd2 =
05.05.2017 15:57:50 Scheduled Tasks 2.0 Cached
Probably Malicious: SMW_P =
05.05.2017 15:57:50 Scheduled Tasks 2.0 Cached
Probably Malicious:
SMW_UpdateTask_Time_3534343931313834372d5755326c785a5a5737414534 =
Anti-malware scan started at: 07.05.2017 20:34:07
07.05.2017 20:34:22 Running Processes
Probably Malicious: smu.exe = C:\PROGRAM FILES\COMMON FILES\NOOBZO\GNUPDATE\SMU.EXE
07.05.2017 20:34:24 Applications
Probably Malicious: BrowserAir =
C:\Users\user\AppData\Local\BrowserAir\Application\unins000.exe
07.05.2017 20:34:24 Applications
Probably Malicious: Search module = C:\Program Files\Common
Files\Noobzo\GNUpdate\smUninstall.exe
07.05.2017 20:34:36 Unwanted Software Files
Probably Malicious: C:\ProgramData\SEARCHMODULE\ = C:\ProgramData\SEARCHMODULE\
07.05.2017 20:34:36 Unwanted Software Files
Probably Malicious: SMP2.EXE = C:\PROGRAMDATA\SMP2.EXE
07.05.2017 20:34:36 Unwanted Software Files
Probably Malicious: BI3.EXE = C:\WINDOWS\SYSNATIVE\BI3.EXE
07.05.2017 20:34:36 Unwanted Software Files
Probably Malicious: BrowserAir = C:\USERS\USER\APPDATA\LOCAL\BROWSERAIR\
07.05.2017 20:34:44 User Shortcuts
Probably Malicious: C:\Users\user\Desktop\BrowserAir.lnk =
C:\USERS\USER\APPDATA\LOCAL\BROWSERAIR\APPLICATION\BROWSERAIREXEC.EXE
07.05.2017 20:34:44 User Shortcuts
Unknown: C:\Users\Public\Desktop\Beetel 3G Data Card.lnk = C:\PROGRAM FILES
(X86)\BEETEL 3G DATA CARD\WIRELESSMODEM.EXE
07.05.2017 20:34:44 User Shortcuts
Probably Malicious: C:\Users\Public\Desktop\Google Chrome.lnk = C:\PROGRAM FILES
(X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
07.05.2017 20:34:44 User Shortcuts
Probably Malicious: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick
Launch\BrowserAir.lnk =
C:\USERS\USER\APPDATA\LOCAL\BROWSERAIR\APPLICATION\BROWSERAIREXEC.EXE
07.05.2017 20:34:44 User Shortcuts
Probably Malicious: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick
Launch\Google Chrome.lnk = C:\PROGRAM FILES
(X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
07.05.2017 20:34:44 User Shortcuts
Probably Malicious: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick
Launch\User Pinned\ImplicitAppShortcuts\360c22b137d62ce9\Google Chrome.lnk =
C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
07.05.2017 20:34:44 User Shortcuts
Probably Malicious: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick
Launch\User Pinned\TaskBar\BrowserAir.lnk =
C:\USERS\USER\APPDATA\LOCAL\BROWSERAIR\APPLICATION\BROWSERAIREXEC.EXE
07.05.2017 20:34:44 User Shortcuts
Probably Malicious: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick
Launch\User Pinned\TaskBar\Google Chrome.lnk = C:\PROGRAM FILES
(X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
07.05.2017 20:34:44 User Shortcuts
Probably Malicious: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google
Chrome.lnk = C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
07.05.2017 20:34:44 User Shortcuts
Unknown: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download
Manager\Internet Download Manager.lnk = C:\PROGRAM FILES (X86)\INTERNET DOWNLOAD
MANAGER\IDMAN.EXE
07.05.2017 20:34:44 Registry Run
Suspicious: IDMan = C:\PROGRAM FILES (X86)\INTERNET DOWNLOAD MANAGER\IDMAN.EXE
07.05.2017 20:34:44 Scheduled Tasks 2
Probably Malicious: C:\WINDOWS\SYSNATIVE\TASKS\IBUpd =
C:\USERS\USER\APPDATA\LOCAL\BROWSERAIR\48.0.0.0\UPDATER.EXE
07.05.2017 20:34:44 Scheduled Tasks 2
Probably Malicious: C:\WINDOWS\SYSNATIVE\TASKS\IBUpd2 =
C:\USERS\USER\APPDATA\LOCAL\BROWSERAIR\48.0.0.0\UPDATER.EXE
07.05.2017 20:34:44 Scheduled Tasks 2
Probably Malicious: C:\WINDOWS\SYSNATIVE\TASKS\SMW_P = C:\PROGRAMDATA\SMP2.EXE
07.05.2017 20:34:44 Scheduled Tasks 2.0 Cached
Probably Malicious: IBUpd2 =
07.05.2017 20:34:44 Scheduled Tasks 2.0 Cached
Probably Malicious: SMW_P =
07.05.2017 20:34:44 Scheduled Tasks 2.0 Cached
Probably Malicious:
SMW_UpdateTask_Time_3534343931313834372d5755326c785a5a5737414534 =
07.05.2017 20:35:36 Auto Services
Probably Malicious: SMUpd = C:\PROGRAM FILES\COMMON FILES\NOOBZO\GNUPDATE\SMU.EXE
07.05.2017 20:35:36 Drivers
Probably Malicious: SMUpdd = C:\PROGRAM FILES\COMMON FILES\NOOBZO\GNUPDATE\SMW.SYS
07.05.2017 20:35:40 Google Chrome Addons
Unknown: ngpampappnmepgilojfohadhhmbhlaek =
C:\Users\user\AppData\Local\Google\Chrome\User
Data\Default\Extensions\ngpampappnmepgilojfohadhhmbhlaek\6.28.7_0
07.05.2017 20:35:40 Google Chrome Addons
Unknown: ngpampappnmepgilojfohadhhmbhlaek = C:\PROGRAM FILES (X86)\INTERNET
DOWNLOAD MANAGER\IDMGCEXT.CRX
07.05.2017 20:35:40 Pre-installed extensions
Unknown: ngpampappnmepgilojfohadhhmbhlaek = C:\Program Files (x86)\Internet
Download Manager\IDMGCExt.crx
07.05.2017 20:35:40 Chrome Protected Settings
Probably Malicious: session.startup_urls = ["http:\/\/www-searching.com\/?
pid=s&s=h51ztrmbl10bu,5157e9a5-612f-4c40-a626-b294fd6e41da,&vp=ch&prd=set_ch"]
07.05.2017 20:35:40 Chrome Protected Settings
Probably Malicious: homepage = http://www-searching.com/?
pid=s&s=h51ztrmbl10bu,5157e9a5-612f-4c40-a626-b294fd6e41da,&vp=ch&prd=set_ch
Anti-malware scan finished at: 07.05.2017 20:35:40
Anti-malware scan started at: 09.05.2017 22:49:46
09.05.2017 22:49:57 Applications
Probably Malicious: BrowserAir =
C:\Users\user\AppData\Local\BrowserAir\Application\unins000.exe
09.05.2017 22:49:57 Applications
Probably Malicious: Search module = C:\Program Files\Common
Files\Noobzo\GNUpdate\smUninstall.exe
09.05.2017 22:50:09 Unwanted Software Files
Probably Malicious: C:\ProgramData\SEARCHMODULE\ = C:\ProgramData\SEARCHMODULE\
09.05.2017 22:50:09 Unwanted Software Files
Probably Malicious: SMP2.EXE = C:\PROGRAMDATA\SMP2.EXE
09.05.2017 22:50:09 Unwanted Software Files
Probably Malicious: BI3.EXE = C:\WINDOWS\SYSNATIVE\BI3.EXE
09.05.2017 22:50:09 Unwanted Software Files
Probably Malicious: BrowserAir = C:\USERS\USER\APPDATA\LOCAL\BROWSERAIR\
09.05.2017 22:50:17 User Shortcuts
Probably Malicious: C:\Users\user\Desktop\BrowserAir.lnk =
C:\USERS\USER\APPDATA\LOCAL\BROWSERAIR\APPLICATION\BROWSERAIREXEC.EXE
09.05.2017 22:50:17 User Shortcuts
Unknown: C:\Users\Public\Desktop\Beetel 3G Data Card.lnk = C:\PROGRAM FILES
(X86)\BEETEL 3G DATA CARD\WIRELESSMODEM.EXE
09.05.2017 22:50:17 User Shortcuts
Probably Malicious: C:\Users\Public\Desktop\Google Chrome.lnk = C:\PROGRAM FILES
(X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
09.05.2017 22:50:17 User Shortcuts
Probably Malicious: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick
Launch\BrowserAir.lnk =
C:\USERS\USER\APPDATA\LOCAL\BROWSERAIR\APPLICATION\BROWSERAIREXEC.EXE
09.05.2017 22:50:17 User Shortcuts
Probably Malicious: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick
Launch\Google Chrome.lnk = C:\PROGRAM FILES
(X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
09.05.2017 22:50:17 User Shortcuts
Probably Malicious: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick
Launch\User Pinned\ImplicitAppShortcuts\360c22b137d62ce9\Google Chrome.lnk =
C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
09.05.2017 22:50:17 User Shortcuts
Probably Malicious: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick
Launch\User Pinned\TaskBar\BrowserAir.lnk =
C:\USERS\USER\APPDATA\LOCAL\BROWSERAIR\APPLICATION\BROWSERAIREXEC.EXE
09.05.2017 22:50:17 User Shortcuts
Probably Malicious: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick
Launch\User Pinned\TaskBar\Google Chrome.lnk = C:\PROGRAM FILES
(X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
09.05.2017 22:50:17 User Shortcuts
Probably Malicious: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google
Chrome.lnk = C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE
09.05.2017 22:50:17 User Shortcuts
Unknown: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download
Manager\Internet Download Manager.lnk = C:\PROGRAM FILES (X86)\INTERNET DOWNLOAD
MANAGER\IDMAN.EXE
09.05.2017 22:50:17 Registry Run
Suspicious: IDMan = C:\PROGRAM FILES (X86)\INTERNET DOWNLOAD MANAGER\IDMAN.EXE
09.05.2017 22:50:17 Scheduled Tasks 2
Probably Malicious: C:\WINDOWS\SYSNATIVE\TASKS\IBUpd =
C:\USERS\USER\APPDATA\LOCAL\BROWSERAIR\48.0.0.0\UPDATER.EXE
09.05.2017 22:50:17 Scheduled Tasks 2
Probably Malicious: C:\WINDOWS\SYSNATIVE\TASKS\IBUpd2 =
C:\USERS\USER\APPDATA\LOCAL\BROWSERAIR\48.0.0.0\UPDATER.EXE
09.05.2017 22:50:17 Scheduled Tasks 2
Probably Malicious: C:\WINDOWS\SYSNATIVE\TASKS\SMW_P = C:\PROGRAMDATA\SMP2.EXE
09.05.2017 22:50:17 Scheduled Tasks 2.0 Cached
Probably Malicious: IBUpd2 =
09.05.2017 22:50:17 Scheduled Tasks 2.0 Cached
Probably Malicious: SMW_P =
09.05.2017 22:50:17 Scheduled Tasks 2.0 Cached
Probably Malicious:
SMW_UpdateTask_Time_3534343931313834372d5755326c785a5a5737414534 =
09.05.2017 22:51:11 Auto Services
Probably Malicious: SMUpd = C:\PROGRAM FILES\COMMON FILES\NOOBZO\GNUPDATE\SMU.EXE
09.05.2017 22:51:11 Drivers
Probably Malicious: SMUpdd = C:\PROGRAM FILES\COMMON FILES\NOOBZO\GNUPDATE\SMW.SYS
09.05.2017 22:51:14 Google Chrome Addons
Unknown: ngpampappnmepgilojfohadhhmbhlaek =
C:\Users\user\AppData\Local\Google\Chrome\User
Data\Default\Extensions\ngpampappnmepgilojfohadhhmbhlaek\6.28.7_0
09.05.2017 22:51:14 Google Chrome Addons
Unknown: ngpampappnmepgilojfohadhhmbhlaek = C:\PROGRAM FILES (X86)\INTERNET
DOWNLOAD MANAGER\IDMGCEXT.CRX
09.05.2017 22:51:14 Pre-installed extensions
Unknown: ngpampappnmepgilojfohadhhmbhlaek = C:\Program Files (x86)\Internet
Download Manager\IDMGCExt.crx
09.05.2017 22:51:14 Chrome Protected Settings
Probably Malicious: session.startup_urls = ["http:\/\/www-searching.com\/?
pid=s&s=h51ztrmbl10bu,5157e9a5-612f-4c40-a626-b294fd6e41da,&vp=ch&prd=set_ch"]
09.05.2017 22:51:14 Chrome Protected Settings
Probably Malicious: homepage = http://www-searching.com/?
pid=s&s=h51ztrmbl10bu,5157e9a5-612f-4c40-a626-b294fd6e41da,&vp=ch&prd=set_ch
Anti-malware scan finished at: 09.05.2017 22:51:14

Das könnte Ihnen auch gefallen