Jump to content
Declan

ADW Doesn't Finish Cleaning

Recommended Posts

Hi everyone.

I can run ADW Cleaner and it scans my PC.

I click all as instructed and then it tries to remove stuff but never finishes removing.

Could someone tell me in plain English as to what to do please?

Share this post


Link to post
Share on other sites

***This is an automated reply***

Hi,

Thanks for posting in the AdwCleaner Help forum.

Someone will reply shortly, but in the meantime here are a few resources which may help resolve your issue:

Thanks in advance for your patience.

-The Malwarebytes Forum Team

Share this post


Link to post
Share on other sites

Greetings,

If you aren't using version 7.4.1 of ADWCleaner then please try that to see if it resolves the issue.  You can find more info and download it here.

If that doesn't correct the issue then it is probably a problem that will not be corrected until the next version (most likely 7.4.2) is released.

I hope this helps and if there is anything else we might assist you with please let us know.

Thanks

Share this post


Link to post
Share on other sites
2019-09-08 00:59:43 :  <INFO>      [Application] AdwCleaner  7 . 4 . 1  launched
2019-09-08 00:59:59 :  <INFO>      [MBInstaller] Checking Iris
2019-09-08 00:59:59 :  <INFO>      [IRIS] Making request
2019-09-08 01:00:01 :  <INFO>      [AdwUpgrade] Checking application updates
2019-09-08 01:00:01 :  <INFO>      [Telemetry] Sending hello
2019-09-08 01:00:02 :  <INFO>      [SslCert] Issued by ("DigiCert SHA2 High Assurance Server CA")
2019-09-08 01:00:02 :  <INFO>      [SslCert] Issued to ("*.malwarebytes.com")
2019-09-08 01:00:02 :  <INFO>      [SslCert] Locality Name ("Santa Clara")
2019-09-08 01:00:02 :  <INFO>      [SslCert] Organization ("Malwarebytes Inc")
2019-09-08 01:00:02 :  <INFO>      [SslCert] Certificate EffectiveDate:  "Mon Oct 2 00:00:00 2017 GMT"
2019-09-08 01:00:02 :  <INFO>      [SslCert] Certificate ExpirationDate:  "Tue Oct 6 12:00:00 2020 GMT"
2019-09-08 01:00:02 :  <INFO>      [SslCert] ALPN: None
2019-09-08 01:00:02 :  <INFO>      [SslCert] Cipher:  "ECDHE-RSA-AES256-GCM-SHA384"
2019-09-08 01:00:02 :  <INFO>      [SslCert] KXE:  "ECDH"
2019-09-08 01:00:02 :  <INFO>      [SslCert] Protocol:  "TLSv1.2"
2019-09-08 01:00:02 :  <INFO>      [SslCert] Issued by ("DigiCert SHA2 High Assurance Server CA")
2019-09-08 01:00:02 :  <INFO>      [SslCert] Issued to ("*.malwarebytes.com")
2019-09-08 01:00:02 :  <INFO>      [SslCert] Locality Name ("Santa Clara")
2019-09-08 01:00:02 :  <INFO>      [SslCert] Organization ("Malwarebytes Inc")
2019-09-08 01:00:02 :  <INFO>      [SslCert] Certificate EffectiveDate:  "Mon Oct 2 00:00:00 2017 GMT"
2019-09-08 01:00:02 :  <INFO>      [SslCert] Certificate ExpirationDate:  "Tue Oct 6 12:00:00 2020 GMT"
2019-09-08 01:00:02 :  <INFO>      [SslCert] ALPN: None
2019-09-08 01:00:02 :  <INFO>      [SslCert] Cipher:  "ECDHE-RSA-AES256-GCM-SHA384"
2019-09-08 01:00:02 :  <INFO>      [SslCert] KXE:  "ECDH"
2019-09-08 01:00:02 :  <INFO>      [SslCert] Protocol:  "TLSv1.2"
2019-09-08 01:00:02 :  <INFO>      [Telemetry] Status code:  QVariant(int, 200)
2019-09-08 01:00:02 :  <WARNING>   [File Downloader] Error downloading ( QNetworkReply::NetworkError(ContentNotFoundError) )
2019-09-08 01:00:02 :  <INFO>      [IRIS] Failed
2019-09-08 01:00:10 :  <INFO>      [Button clicked] Scan
2019-09-08 01:00:10 :  <INFO>      [Scan] Started
2019-09-08 01:00:10 :  <INFO>      [Database] Downloading database
2019-09-08 01:00:11 :  <INFO>      [Database] Checking integrity
2019-09-08 01:00:11 :  <INFO>      [Database] Found  2599  families
2019-09-08 01:00:11 :  <INFO>      [Database] Database v "2019-09-06.1"
2019-09-08 01:00:13 :  <INFO>      [Loading paths] Local paths loaded
2019-09-08 01:00:13 :  <INFO>      [Loading paths] Chrome paths loaded
2019-09-08 01:00:13 :  <INFO>      [Loading paths] User Keys loaded
2019-09-08 01:00:13 :  <INFO>      [Module initialized]  "File"
2019-09-08 01:00:13 :  <INFO>      [Module initialized]  "Folder"
2019-09-08 01:00:13 :  <INFO>      [Module initialized]  "RegistryKey"
2019-09-08 01:00:13 :  <INFO>      [Module initialized]  "RegistryValue"
2019-09-08 01:00:15 :  <INFO>      [Module initialized]  "TaskName"
2019-09-08 01:00:16 :  <INFO>      [Module initialized]  "Service"
2019-09-08 01:00:16 :  <INFO>      [Module initialized]  "Winlogon"
2019-09-08 01:00:34 :  <INFO>      [Module initialized]  "URL"
2019-09-08 01:00:34 :  <INFO>      [Module initialized]  "RegAppInit"
2019-09-08 01:00:34 :  <INFO>      [Module initialized]  "RegClasses"
2019-09-08 01:00:34 :  <INFO>      [Module initialized]  "DNS"
2019-09-08 01:00:35 :  <INFO>      [Module initialized]  "RegFirewallPolicy"
2019-09-08 01:00:35 :  <INFO>      [Module initialized]  "RegGuid"
2019-09-08 01:00:35 :  <INFO>      [Module initialized]  "RegIEElevationPolicy"
2019-09-08 01:00:35 :  <INFO>      [Module initialized]  "RegOther"
2019-09-08 01:00:35 :  <INFO>      [Module initialized]  "RegProductID"
2019-09-08 01:00:35 :  <INFO>      [Module initialized]  "RegSoftware"
2019-09-08 01:00:35 :  <INFO>      [Module initialized]  "RegStartup"
2019-09-08 01:00:36 :  <INFO>      [Module initialized]  "WMI"
2019-09-08 01:00:36 :  <INFO>      [Module initialized]  "ChromiumExt"
2019-09-08 01:00:36 :  <INFO>      [Module initialized]  "FirefoxExt"
2019-09-08 01:00:36 :  <INFO>      [Module initialize] Scan Browser
2019-09-08 01:00:40 :  <INFO>      [Module initialize] Scan Browser FF
2019-09-08 01:00:40 :  <INFO>      [Module initialize] FF start pages loaded
2019-09-08 01:00:40 :  <INFO>      [Module initialize] FF search providers loaded
2019-09-08 01:00:40 :  <INFO>      [Module initialize] FF plugin list loaded
2019-09-08 01:00:40 :  <INFO>      [Scan] Exclusions loaded
2019-09-08 01:00:43 :  <INFO>      [Scan] Item detected:  "PUP.Optional.Legacy" ,  "C:\\Windows\\System32\\drivers\\swdumon.sys" [ "File" ]
2019-09-08 01:00:47 :  <INFO>      [Scan] Item detected:  "PUP.Optional.Legacy" ,  "C:\\Users\\Public\\Documents\\Downloaded Installers" [ "Folder" ]
2019-09-08 01:01:08 :  <INFO>      [Scan] Item detected:  "PUP.Optional.Legacy" ,  "Search Here" [ "Chromium URLs" ]
2019-09-08 01:01:09 :  <INFO>      [Scan] Item detected:  "PUP.Optional.Legacy" ,  "http://search.b1.org/?bsrc=hmcor&chid=c167991" [ "Chromium URLs" ]
2019-09-08 01:01:59 :  <INFO>      [Scan] Item detected:  "PUP.Optional.Legacy" ,  "blekko" [ "Chromium URLs" ]
2019-09-08 01:01:59 :  <INFO>      [Scan] Item detected:  "PUP.Optional.Legacy" ,  "Blekko" [ "Chromium URLs" ]
2019-09-08 01:01:59 :  <INFO>      [Scan] Item detected:  "PUP.Optional.Legacy" ,  "http://blekko.com/ws/?source=5f97ddbe&tbp=homepage&u=94aa068e0000000000000016177e22d9" [ "Chromium URLs" ]
2019-09-08 01:02:07 :  <INFO>      [Scan] Item detected:  "PUP.Optional.Legacy" ,  "HKU\\.DEFAULT\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\zonemap\\domains\\dospop.com" [ "Registry" ]
2019-09-08 01:02:07 :  <INFO>      [Scan] Item detected:  "PUP.Optional.Legacy" ,  "HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\zonemap\\domains\\dospop.com" [ "Registry" ]
2019-09-08 01:02:07 :  <INFO>      [Scan] Item detected:  "PUP.Optional.Legacy" ,  "HKU\\S-1-5-18\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\zonemap\\domains\\dospop.com" [ "Registry" ]
2019-09-08 01:02:20 :  <INFO>      [Scan] Item detected:  "PUP.Optional.Legacy" ,  "HKU\\.DEFAULT\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\zonemap\\domains\\incredibar.com" [ "Registry" ]
2019-09-08 01:02:20 :  <INFO>      [Scan] Item detected:  "PUP.Optional.Legacy" ,  "HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\zonemap\\domains\\incredibar.com" [ "Registry" ]
2019-09-08 01:02:20 :  <INFO>      [Scan] Item detected:  "PUP.Optional.Legacy" ,  "HKU\\S-1-5-18\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\zonemap\\domains\\incredibar.com" [ "Registry" ]
2019-09-08 01:02:34 :  <INFO>      [Scan] Item detected:  "PUP.Optional.Legacy" ,  "VideoDownloadConverter" [ "Chromium URLs" ]
2019-09-08 01:02:46 :  <INFO>      [Scan] Item detected:  "PUP.Optional.Legacy" ,  "HKLM\\Software\\Wow6432Node\\\\Microsoft\\Windows\\CurrentVersion\\Run|Codec Settings UAC Manager" [ "Registry" ]
2019-09-08 01:02:47 :  <INFO>      [Scan] Item detected:  "PUP.Optional.SpyHunter" ,  "HKLM\\SOFTWARE\\Microsoft\\RADAR\\HeapLeakDetection\\DiagnosedApplications\\SpyHunter4.exe" [ "Registry" ]
2019-09-08 01:02:49 :  <INFO>      [Scan] Item detected:  "PUP.Optional.WinYahoo" ,  "C:\\Users\\Declan\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Search Powered by Yahoo!.lnk" [ "File" ]
2019-09-08 01:02:56 :  <INFO>      [Scan] Item detected:  "PUP.Optional.Carambis" ,  "C:\\Users\\Declan\\AppData\\Roaming\\Carambis" [ "Folder" ]
2019-09-08 01:02:57 :  <INFO>      [Scan] Item detected:  "PUP.Optional.Carambis" ,  "C:\\Program Files (x86)\\Carambis" [ "Folder" ]
2019-09-08 01:02:57 :  <INFO>      [Scan] Item detected:  "PUP.Optional.Carambis" ,  "HKCU\\Software\\Carambis" [ "Registry" ]
2019-09-08 01:02:57 :  <INFO>      [Scan] Item detected:  "PUP.Optional.SlimCleanerPlus" ,  "C:\\Users\\Declan\\AppData\\Local\\slimware utilities inc" [ "Folder" ]
2019-09-08 01:02:57 :  <INFO>      [Scan] Item detected:  "PUP.Optional.PCProtect" ,  "C:\\ProgramData\\SecuritySuite" [ "Folder" ]
2019-09-08 01:02:57 :  <INFO>      [Scan] Item detected:  "PUP.Optional.SpeedItupFree" ,  "HKLM\\Software\\Classes\\AppID\\{A245B088-41FA-478E-8DEA-86177F1394BB}" [ "Registry" ]
2019-09-08 01:02:57 :  <INFO>      [Scan] Item detected:  "PUP.Optional.SpeedItupFree" ,  "HKLM\\Software\\Wow6432Node\\\\Classes\\AppID\\{A245B088-41FA-478E-8DEA-86177F1394BB}" [ "Registry" ]
2019-09-08 01:03:00 :  <INFO>      [Scan] Item detected:  "PUP.Optional.DriverUpdate" ,  "C:\\Users\\Declan\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Driver Updater" [ "Folder" ]
2019-09-08 01:03:00 :  <INFO>      [Scan] Item detected:  "PUP.Optional.DriverUpdate" ,  "C:\\Users\\Declan\\AppData\\Roaming\\Driver Updater" [ "Folder" ]
2019-09-08 01:03:00 :  <INFO>      [Scan] Item detected:  "PUP.Optional.ByteFence" ,  "C:\\Program Files\\ByteFence" [ "Folder" ]
2019-09-08 01:03:00 :  <INFO>      [Scan] Item detected:  "PUP.Optional.ByteFence" ,  "C:\\ProgramData\\ByteFence" [ "Folder" ]
2019-09-08 01:03:00 :  <INFO>      [Scan] Item detected:  "PUP.Optional.ByteFence" ,  "HKLM\\System\\CurrentControlSet\\Services\\EventLog\\Application\\ByteFenceService" [ "Registry" ]
2019-09-08 01:03:01 :  <INFO>      [Scan] Item detected:  "PUP.Optional.ByteFence" ,  "HKLM\\Software\\Wow6432Node\\\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_BROWSER_EMULATION|ByteFence.exe" [ "Registry" ]
2019-09-08 01:03:01 :  <INFO>      [Scan] Item detected:  "PUP.Optional.ByteFence" ,  "HKLM\\SYSTEM\\CurrentControlSet\\Services\\EventLog\\Reason\\ReasonByteFence" [ "Registry" ]
2019-09-08 01:03:01 :  <INFO>      [Scan] Item detected:  "PUP.Optional.ByteFence" ,  "HKLM\\SOFTWARE\\Microsoft\\RADAR\\HeapLeakDetection\\DiagnosedApplications\\ByteFence.exe" [ "Registry" ]
2019-09-08 01:03:01 :  <INFO>      [Scan] Item detected:  "PUP.Optional.ByteFence" ,  "HKLM\\Software\\ByteFence" [ "Registry" ]
2019-09-08 01:03:01 :  <INFO>      [Scan] Item detected:  "PUP.Optional.ByteFence" ,  "HKLM\\Software\\Wow6432Node\\ByteFence" [ "Registry" ]
2019-09-08 01:03:01 :  <INFO>      [Scan] Item detected:  "PUP.Optional.ByteFence" ,  "HKU\\.DEFAULT\\Software\\ByteFence" [ "Registry" ]
2019-09-08 01:03:01 :  <INFO>      [Scan] Item detected:  "PUP.Optional.ByteFence" ,  "HKCU\\Software\\ByteFence" [ "Registry" ]
2019-09-08 01:03:01 :  <INFO>      [Scan] Item detected:  "PUP.Optional.ByteFence" ,  "HKU\\S-1-5-18\\Software\\ByteFence" [ "Registry" ]
2019-09-08 01:03:01 :  <INFO>      [Scan] Item detected:  "PUP.Optional.DriverSupport" ,  "C:\\Windows\\SysWOW64\\rnd_chunk.bin" [ "File" ]
2019-09-08 01:03:03 :  <INFO>      [Scan] Item detected:  "Preinstalled.DellDataProtection" ,  "HKLM\\Software\\Wow6432Node\\\\Classes\\CLSID\\{2DC80C06-0687-5383-8B6B-2A9E50F53F64}" [ "Registry" ]
2019-09-08 01:03:03 :  <INFO>      [Scan] Item detected:  "Preinstalled.DellDataProtection" ,  "HKLM\\Software\\Wow6432Node\\\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{2DC80C06-0687-5383-8B6B-2A9E50F53F64}" [ "Registry" ]
2019-09-08 01:03:03 :  <INFO>      [Scan] Item detected:  "Preinstalled.DellDataProtection" ,  "HKLM\\Software\\Wow6432Node\\\\Microsoft\\Windows\\CurrentVersion\\Ext\\Preapproved\\{2DC80C06-0687-5383-8B6B-2A9E50F53F64}" [ "Registry" ]
2019-09-08 01:03:04 :  <INFO>      [Scan] Item detected:  "PUP.Optional.WebCompanion" ,  "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Lavasoft\\WebCompanion" [ "Folder" ]
2019-09-08 01:03:04 :  <INFO>      [Scan] Item detected:  "PUP.Optional.WebCompanion" ,  "C:\\Program Files (x86)\\Lavasoft\\Web Companion" [ "Folder" ]
2019-09-08 01:03:04 :  <INFO>      [Scan] Item detected:  "PUP.Optional.WebCompanion" ,  "C:\\ProgramData\\Lavasoft\\Web Companion" [ "Folder" ]
2019-09-08 01:03:04 :  <INFO>      [Scan] Item detected:  "PUP.Optional.WebCompanion" ,  "C:\\ProgramData\\Application Data\\Lavasoft\\Web Companion" [ "Folder" ]
2019-09-08 01:03:04 :  <INFO>      [Scan] Item detected:  "PUP.Optional.WebCompanion" ,  "C:\\Users\\Declan\\AppData\\Local\\Lavasoft\\WEBCOMPANION.EXE_URL_SIQ0LWF3TZGXP2KHFKLLYBK3IDTBEHNG" [ "Folder" ]
2019-09-08 01:03:04 :  <INFO>      [Scan] Item detected:  "PUP.Optional.WebCompanion" ,  "HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\Domains\\webcompanion.com" [ "Registry" ]
2019-09-08 01:03:04 :  <INFO>      [Scan] Item detected:  "PUP.Optional.WebCompanion" ,  "HKLM\\Software\\Wow6432Node\\Lavasoft\\Web Companion" [ "Registry" ]
2019-09-08 01:03:04 :  <INFO>      [Scan] Item detected:  "Preinstalled.LenovoPowerDVD" ,  "HKLM\\Software\\Wow6432Node\\\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}" [ "Registry" ]
2019-09-08 01:03:04 :  <INFO>      [Scan] Item detected:  "Preinstalled.LenovoPowerDVD" ,  "HKLM\\Software\\Wow6432Node\\\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{B46BEA36-0B71-4A4E-AE41-87241643FA0A}" [ "Registry" ]
2019-09-08 01:03:10 :  <INFO>      [Scan] Item detected:  "Preinstalled.CyberLinkShellExtension" ,  "HKLM\\Software\\Classes\\CLSID\\{3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2}" [ "Registry" ]
2019-09-08 01:03:10 :  <INFO>      [Scan] Item detected:  "Preinstalled.LenovoPower2Go" ,  "HKLM\\Software\\Wow6432Node\\\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}" [ "Registry" ]
2019-09-08 01:03:10 :  <INFO>      [Scan] Item detected:  "Preinstalled.LenovoPower2Go" ,  "HKLM\\Software\\Wow6432Node\\\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}" [ "Registry" ]
2019-09-08 01:03:10 :  <INFO>      [Scan] Item detected:  "Preinstalled.LenovoPower2Go" ,  "HKLM\\Software\\Wow6432Node\\\\Microsoft\\Windows\\CurrentVersion\\Run|CLMLServer_For_P2G8" [ "Registry" ]
2019-09-08 01:03:10 :  <INFO>      [Scan] Item detected:  "Preinstalled.LenovoPower2Go" ,  "HKLM\\Software\\Wow6432Node\\\\Microsoft\\Windows\\CurrentVersion\\Run|CLVirtualDrive" [ "Registry" ]
2019-09-08 01:03:11 :  <INFO>      [Scan] Item detected:  "PUP.Optional.AdvancedSystemRepairPro" ,  "HKLM\\Software\\Classes\\Interface\\{23387882-DEAA-4971-2222-5D5046F2B3BB}" [ "Registry" ]
2019-09-08 01:03:16 :  <INFO>      [Scan] Item detected:  "PUP.Optional.MySearch" ,  "Search Here" [ "Chromium URLs" ]
2019-09-08 01:03:19 :  <INFO>      [Scan] Item detected:  "PUP.Optional.SearchManager" ,  "HKCU\\Software\\ProductSetup\\Uninstall\\0B2U2Z1P0F1P1G1R1P1V0A1Q1Q0O1G" [ "Registry" ]
2019-09-08 01:03:19 :  <INFO>      [Scan] Item detected:  "PUP.Optional.SearchManager" ,  "HKCU\\Software\\ProductSetup\\Uninstall\\0S1P1T1C1R1MtT0P1C1F2X1L1Q1P1QtT1S2UtT0Y1T1M1F1F" [ "Registry" ]
2019-09-08 01:03:23 :  <INFO>      [Scan] Item detected:  "PUP.Optional.YTDToolbar" ,  "HKLM\\Software\\Wow6432Node\\{DAF8B7E5-449D-4180-8281-10E536E597F2}" [ "Registry" ]
2019-09-08 01:03:26 :  <INFO>      [Scan] Item detected:  "PUP.Optional.InstallCore" ,  "HKCU\\Software\\csastats" [ "Registry" ]
2019-09-08 01:03:27 :  <INFO>      [Scan] Item detected:  "Preinstalled.HPSupportAssistant" ,  "C:\\Program Files (x86)\\HEWLETT-PACKARD\\HP CUSTOMER FEEDBACK" [ "Folder" ]
2019-09-08 01:03:27 :  <INFO>      [Scan] Item detected:  "Preinstalled.HPSupportAssistant" ,  "C:\\Users\\Declan\\AppData\\Roaming\\HEWLETT-PACKARD\\HP SUPPORT FRAMEWORK" [ "Folder" ]
2019-09-08 01:03:27 :  <INFO>      [Scan] Item detected:  "Preinstalled.HPSupportAssistant" ,  "C:\\Users\\Declan\\AppData\\Local\\HEWLETT-PACKARD\\HP SUPPORT FRAMEWORK" [ "Folder" ]
2019-09-08 01:03:27 :  <INFO>      [Scan] Item detected:  "Preinstalled.HPSupportAssistant" ,  "C:\\Windows\\SysWOW64\\config\\systemprofile\\AppData\\Roaming\\HEWLETT-PACKARD\\HP SUPPORT FRAMEWORK" [ "Folder" ]
2019-09-08 01:03:27 :  <INFO>      [Scan] Item detected:  "Preinstalled.HPSupportAssistant" ,  "C:\\Program Files (x86)\\HEWLETT-PACKARD\\HP SUPPORT FRAMEWORK" [ "Folder" ]
2019-09-08 01:03:27 :  <INFO>      [Scan] Item detected:  "Preinstalled.HPSupportAssistant" ,  "C:\\ProgramData\\HEWLETT-PACKARD\\HP SUPPORT FRAMEWORK" [ "Folder" ]
2019-09-08 01:03:27 :  <INFO>      [Scan] Item detected:  "Preinstalled.HPSupportAssistant" ,  "C:\\Program Files (x86)\\HEWLETT-PACKARD\\HP SUPPORT SOLUTIONS" [ "Folder" ]
2019-09-08 01:03:27 :  <INFO>      [Scan] Item detected:  "Preinstalled.HPSupportAssistant" ,  "C:\\HP\\SUPPORT" [ "Folder" ]
2019-09-08 01:03:27 :  <INFO>      [Scan] Item detected:  "Preinstalled.HPSupportAssistant" ,  "HKLM\\Software\\Wow6432Node\\\\Classes\\CLSID\\{C0ABBA07-B636-47B8-B9E1-BB96D7CD4831}" [ "Registry" ]
2019-09-08 01:03:27 :  <INFO>      [Scan] Item detected:  "Preinstalled.HPRegistrationService" ,  "C:\\ProgramData\\HEWLETT-PACKARD\\HP REGISTRATION SERVICE" [ "Folder" ]
2019-09-08 01:03:27 :  <INFO>      [Scan] Item detected:  "Preinstalled.HPHealthCheck" ,  "C:\\Program Files (x86)\\HEWLETT-PACKARD\\HP HEALTH CHECK" [ "Folder" ]
2019-09-08 01:03:27 :  <INFO>      [Scan] Item detected:  "Preinstalled.HPHealthCheck" ,  "HKLM\\Software\\Wow6432Node\\\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{6F340107-F9AA-47C6-B54C-C3A19F11553F}" [ "Registry" ]
2019-09-08 01:03:30 :  <INFO>      [Scan] Item detected:  "PUP.Optional.ProductSetup.A" ,  "HKCU\\Software\\PRODUCTSETUP" [ "Registry" ]
2019-09-08 01:03:30 :  <INFO>      [Scan] Item detected:  "PUP.Optional.FreeMakeConverter" ,  "HKLM\\Software\\Wow6432Node\\\\Microsoft\\Windows\\CurrentVersion\\Run|ProductUpdater" [ "Registry" ]
2019-09-08 01:03:50 :  <INFO>      [Telemetry] Sending to Influx
2019-09-08 01:03:54 :  <INFO>      [SslCert] Issued by ("Let's Encrypt Authority X3")
2019-09-08 01:03:54 :  <INFO>      [SslCert] Issued to ("telemetry-02.adwc.mb.fr33tux.org")
2019-09-08 01:03:54 :  <INFO>      [SslCert] Locality Name ()
2019-09-08 01:03:54 :  <INFO>      [SslCert] Organization ()
2019-09-08 01:03:54 :  <INFO>      [SslCert] Certificate EffectiveDate:  "Sun Aug 18 10:50:38 2019 GMT"
2019-09-08 01:03:54 :  <INFO>      [SslCert] Certificate ExpirationDate:  "Sat Nov 16 10:50:38 2019 GMT"
2019-09-08 01:03:54 :  <INFO>      [SslCert] ALPN: Yes
2019-09-08 01:03:54 :  <INFO>      [SslCert] Cipher:  "ECDHE-RSA-AES256-GCM-SHA384"
2019-09-08 01:03:54 :  <INFO>      [SslCert] KXE:  "ECDH"
2019-09-08 01:03:54 :  <INFO>      [SslCert] Protocol:  "TLSv1.2"
2019-09-08 01:03:54 :  <INFO>      [Telemetry] Status code:  QVariant(int, 204)
2019-09-08 01:03:54 :  <INFO>      [Telemetry] Sending to DSE
2019-09-08 01:03:56 :  <INFO>      [SslCert] Issued by ("DigiCert SHA2 High Assurance Server CA")
2019-09-08 01:03:56 :  <INFO>      [SslCert] Issued to ("*.malwarebytes.com")
2019-09-08 01:03:56 :  <INFO>      [SslCert] Locality Name ("San Jose")
2019-09-08 01:03:56 :  <INFO>      [SslCert] Organization ("Malwarebytes Inc.")
2019-09-08 01:03:56 :  <INFO>      [SslCert] Certificate EffectiveDate:  "Thu Feb 22 00:00:00 2018 GMT"
2019-09-08 01:03:56 :  <INFO>      [SslCert] Certificate ExpirationDate:  "Wed Apr 22 12:00:00 2020 GMT"
2019-09-08 01:03:56 :  <INFO>      [SslCert] ALPN: Yes
2019-09-08 01:03:56 :  <INFO>      [SslCert] Cipher:  "ECDHE-RSA-AES256-GCM-SHA384"
2019-09-08 01:03:56 :  <INFO>      [SslCert] KXE:  "ECDH"
2019-09-08 01:03:56 :  <INFO>      [SslCert] Protocol:  "TLSv1.2"
2019-09-08 01:03:56 :  <INFO>      [Telemetry] Status code:  QVariant(int, 201)
2019-09-08 01:03:56 :  <INFO>      [Scan] Finished
2019-09-08 01:04:24 :  <INFO>      [Button clicked] Next
2019-09-08 01:04:36 :  <INFO>      [Button clicked] Bundleware found ok button
2019-09-08 01:04:52 :  <INFO>      [Button clicked] Clean & repair
2019-09-08 01:05:00 :  <INFO>      [Button clicked] Dialog button clicked [ 2 ]
2019-09-08 01:05:52 :  <INFO>      0x22e9fe8 "AdwCleaner_BeforeCleaning_08/09/2019_02:05:00" ]
2019-09-08 01:05:52 :  <INFO>      [Cleaning] Started
2019-09-08 01:05:52 :  <WARNING>   [Cleaning] Unable to Open process -  "[System Process]"   0
2019-09-08 01:05:52 :  <WARNING>   [Cleaning] Unable to Open process -  "System"   0
2019-09-08 01:05:52 :  <INFO>      [Quarantine] Session folder:  "C:\\AdwCleaner\\Quarantine\\v1\\20190908.020552"
2019-09-08 01:05:52 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.Legacy" ,  "C:\\Windows\\System32\\drivers\\swdumon.sys" [ "File" ]
2019-09-08 01:05:52 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.Legacy" ,  "C:\\Windows\\System32\\drivers\\swdumon.sys" [ "File" ]
2019-09-08 01:05:52 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.Legacy" ,  "C:\\Users\\Public\\Documents\\Downloaded Installers" [ "Folder" ]
2019-09-08 01:05:52 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.Legacy" ,  "C:\\Users\\Public\\Documents\\Downloaded Installers" [ "Folder" ]
2019-09-08 01:05:52 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.Legacy" ,  "Search Here" [ "Chromium URLs" ]
2019-09-08 01:05:56 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.Legacy" ,  "Search Here" [ "Chromium URLs" ]
2019-09-08 01:05:56 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.Legacy" ,  "http://search.b1.org/?bsrc=hmcor&chid=c167991" [ "Chromium URLs" ]
2019-09-08 01:05:56 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.Legacy" ,  "http://search.b1.org/?bsrc=hmcor&chid=c167991" [ "Chromium URLs" ]
2019-09-08 01:05:56 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.Legacy" ,  "blekko" [ "Chromium URLs" ]
2019-09-08 01:05:57 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.Legacy" ,  "blekko" [ "Chromium URLs" ]
2019-09-08 01:05:57 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.Legacy" ,  "Blekko" [ "Chromium URLs" ]
2019-09-08 01:06:00 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.Legacy" ,  "Blekko" [ "Chromium URLs" ]
2019-09-08 01:06:00 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.Legacy" ,  "http://blekko.com/ws/?source=5f97ddbe&tbp=homepage&u=94aa068e0000000000000016177e22d9" [ "Chromium URLs" ]
2019-09-08 01:06:00 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.Legacy" ,  "http://blekko.com/ws/?source=5f97ddbe&tbp=homepage&u=94aa068e0000000000000016177e22d9" [ "Chromium URLs" ]
2019-09-08 01:06:00 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.Legacy" ,  "HKU\\.DEFAULT\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\zonemap\\domains\\dospop.com" [ "Registry" ]
2019-09-08 01:06:01 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.Legacy" ,  "HKU\\.DEFAULT\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\zonemap\\domains\\dospop.com" [ "Registry" ]
2019-09-08 01:06:01 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.Legacy" ,  "HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\zonemap\\domains\\dospop.com" [ "Registry" ]
2019-09-08 01:06:01 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.Legacy" ,  "HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\zonemap\\domains\\dospop.com" [ "Registry" ]
2019-09-08 01:06:01 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.Legacy" ,  "HKU\\S-1-5-18\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\zonemap\\domains\\dospop.com" [ "Registry" ]
2019-09-08 01:06:01 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.Legacy" ,  "HKU\\S-1-5-18\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\zonemap\\domains\\dospop.com" [ "Registry" ]
2019-09-08 01:06:01 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.Legacy" ,  "HKU\\.DEFAULT\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\zonemap\\domains\\incredibar.com" [ "Registry" ]
2019-09-08 01:06:01 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.Legacy" ,  "HKU\\.DEFAULT\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\zonemap\\domains\\incredibar.com" [ "Registry" ]
2019-09-08 01:06:01 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.Legacy" ,  "HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\zonemap\\domains\\incredibar.com" [ "Registry" ]
2019-09-08 01:06:01 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.Legacy" ,  "HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\zonemap\\domains\\incredibar.com" [ "Registry" ]
2019-09-08 01:06:01 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.Legacy" ,  "HKU\\S-1-5-18\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\zonemap\\domains\\incredibar.com" [ "Registry" ]
2019-09-08 01:06:01 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.Legacy" ,  "HKU\\S-1-5-18\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\zonemap\\domains\\incredibar.com" [ "Registry" ]
2019-09-08 01:06:01 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.Legacy" ,  "VideoDownloadConverter" [ "Chromium URLs" ]
2019-09-08 01:06:02 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.Legacy" ,  "VideoDownloadConverter" [ "Chromium URLs" ]
2019-09-08 01:06:02 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.Legacy" ,  "HKLM\\Software\\Wow6432Node\\\\Microsoft\\Windows\\CurrentVersion\\Run|Codec Settings UAC Manager" [ "Registry" ]
2019-09-08 01:06:02 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.Legacy" ,  "HKLM\\Software\\Wow6432Node\\\\Microsoft\\Windows\\CurrentVersion\\Run|Codec Settings UAC Manager" [ "Registry" ]
2019-09-08 01:06:02 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.SpyHunter" ,  "HKLM\\SOFTWARE\\Microsoft\\RADAR\\HeapLeakDetection\\DiagnosedApplications\\SpyHunter4.exe" [ "Registry" ]
2019-09-08 01:06:02 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.SpyHunter" ,  "HKLM\\SOFTWARE\\Microsoft\\RADAR\\HeapLeakDetection\\DiagnosedApplications\\SpyHunter4.exe" [ "Registry" ]
2019-09-08 01:06:02 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.WinYahoo" ,  "C:\\Users\\Declan\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Search Powered by Yahoo!.lnk" [ "File" ]
2019-09-08 01:06:02 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.WinYahoo" ,  "C:\\Users\\Declan\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Search Powered by Yahoo!.lnk" [ "File" ]
2019-09-08 01:06:02 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.Carambis" ,  "C:\\Users\\Declan\\AppData\\Roaming\\Carambis" [ "Folder" ]
2019-09-08 01:06:03 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.Carambis" ,  "C:\\Users\\Declan\\AppData\\Roaming\\Carambis" [ "Folder" ]
2019-09-08 01:06:03 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.Carambis" ,  "C:\\Program Files (x86)\\Carambis" [ "Folder" ]
2019-09-08 01:06:03 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.Carambis" ,  "C:\\Program Files (x86)\\Carambis" [ "Folder" ]
2019-09-08 01:06:03 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.Carambis" ,  "HKCU\\Software\\Carambis" [ "Registry" ]
2019-09-08 01:06:03 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.Carambis" ,  "HKCU\\Software\\Carambis" [ "Registry" ]
2019-09-08 01:06:03 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.SlimCleanerPlus" ,  "C:\\Users\\Declan\\AppData\\Local\\slimware utilities inc" [ "Folder" ]
2019-09-08 01:06:03 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.SlimCleanerPlus" ,  "C:\\Users\\Declan\\AppData\\Local\\slimware utilities inc" [ "Folder" ]
2019-09-08 01:06:03 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.PCProtect" ,  "C:\\ProgramData\\SecuritySuite" [ "Folder" ]
2019-09-08 01:06:03 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.PCProtect" ,  "C:\\ProgramData\\SecuritySuite" [ "Folder" ]
2019-09-08 01:06:03 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.SpeedItupFree" ,  "HKLM\\Software\\Classes\\AppID\\{A245B088-41FA-478E-8DEA-86177F1394BB}" [ "Registry" ]
2019-09-08 01:06:03 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.SpeedItupFree" ,  "HKLM\\Software\\Classes\\AppID\\{A245B088-41FA-478E-8DEA-86177F1394BB}" [ "Registry" ]
2019-09-08 01:06:03 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.SpeedItupFree" ,  "HKLM\\Software\\Wow6432Node\\\\Classes\\AppID\\{A245B088-41FA-478E-8DEA-86177F1394BB}" [ "Registry" ]
2019-09-08 01:06:03 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.SpeedItupFree" ,  "HKLM\\Software\\Wow6432Node\\\\Classes\\AppID\\{A245B088-41FA-478E-8DEA-86177F1394BB}" [ "Registry" ]
2019-09-08 01:06:03 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.DriverUpdate" ,  "C:\\Users\\Declan\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Driver Updater" [ "Folder" ]
2019-09-08 01:06:04 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.DriverUpdate" ,  "C:\\Users\\Declan\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Driver Updater" [ "Folder" ]
2019-09-08 01:06:04 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.DriverUpdate" ,  "C:\\Users\\Declan\\AppData\\Roaming\\Driver Updater" [ "Folder" ]
2019-09-08 01:06:04 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.DriverUpdate" ,  "C:\\Users\\Declan\\AppData\\Roaming\\Driver Updater" [ "Folder" ]
2019-09-08 01:06:04 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.ByteFence" ,  "C:\\Program Files\\ByteFence" [ "Folder" ]
2019-09-08 01:06:33 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.ByteFence" ,  "C:\\Program Files\\ByteFence" [ "Folder" ]
2019-09-08 01:06:33 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.ByteFence" ,  "C:\\ProgramData\\ByteFence" [ "Folder" ]
2019-09-08 01:06:33 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.ByteFence" ,  "C:\\ProgramData\\ByteFence" [ "Folder" ]
2019-09-08 01:06:33 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.ByteFence" ,  "HKLM\\System\\CurrentControlSet\\Services\\EventLog\\Application\\ByteFenceService" [ "Registry" ]
2019-09-08 01:06:33 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.ByteFence" ,  "HKLM\\System\\CurrentControlSet\\Services\\EventLog\\Application\\ByteFenceService" [ "Registry" ]
2019-09-08 01:06:33 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.ByteFence" ,  "HKLM\\Software\\Wow6432Node\\\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_BROWSER_EMULATION|ByteFence.exe" [ "Registry" ]
2019-09-08 01:06:33 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.ByteFence" ,  "HKLM\\Software\\Wow6432Node\\\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_BROWSER_EMULATION|ByteFence.exe" [ "Registry" ]
2019-09-08 01:06:33 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.ByteFence" ,  "HKLM\\SYSTEM\\CurrentControlSet\\Services\\EventLog\\Reason\\ReasonByteFence" [ "Registry" ]
2019-09-08 01:06:33 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.ByteFence" ,  "HKLM\\SYSTEM\\CurrentControlSet\\Services\\EventLog\\Reason\\ReasonByteFence" [ "Registry" ]
2019-09-08 01:06:33 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.ByteFence" ,  "HKLM\\SOFTWARE\\Microsoft\\RADAR\\HeapLeakDetection\\DiagnosedApplications\\ByteFence.exe" [ "Registry" ]
2019-09-08 01:06:34 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.ByteFence" ,  "HKLM\\SOFTWARE\\Microsoft\\RADAR\\HeapLeakDetection\\DiagnosedApplications\\ByteFence.exe" [ "Registry" ]
2019-09-08 01:06:34 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.ByteFence" ,  "HKLM\\Software\\ByteFence" [ "Registry" ]
2019-09-08 01:06:34 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.ByteFence" ,  "HKLM\\Software\\ByteFence" [ "Registry" ]
2019-09-08 01:06:34 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.ByteFence" ,  "HKLM\\Software\\Wow6432Node\\ByteFence" [ "Registry" ]
2019-09-08 01:06:34 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.ByteFence" ,  "HKLM\\Software\\Wow6432Node\\ByteFence" [ "Registry" ]
2019-09-08 01:06:34 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.ByteFence" ,  "HKU\\.DEFAULT\\Software\\ByteFence" [ "Registry" ]
2019-09-08 01:06:34 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.ByteFence" ,  "HKU\\.DEFAULT\\Software\\ByteFence" [ "Registry" ]
2019-09-08 01:06:34 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.ByteFence" ,  "HKCU\\Software\\ByteFence" [ "Registry" ]
2019-09-08 01:06:35 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.ByteFence" ,  "HKCU\\Software\\ByteFence" [ "Registry" ]
2019-09-08 01:06:35 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.ByteFence" ,  "HKU\\S-1-5-18\\Software\\ByteFence" [ "Registry" ]
2019-09-08 01:06:35 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.ByteFence" ,  "HKU\\S-1-5-18\\Software\\ByteFence" [ "Registry" ]
2019-09-08 01:06:35 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.DriverSupport" ,  "C:\\Windows\\SysWOW64\\rnd_chunk.bin" [ "File" ]
2019-09-08 01:06:35 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.DriverSupport" ,  "C:\\Windows\\SysWOW64\\rnd_chunk.bin" [ "File" ]
2019-09-08 01:06:35 :  <INFO>      [Cleaning] Processing:  "Preinstalled.DellDataProtection" ,  "HKLM\\Software\\Wow6432Node\\\\Classes\\CLSID\\{2DC80C06-0687-5383-8B6B-2A9E50F53F64}" [ "Registry" ]
2019-09-08 01:06:35 :  <INFO>      [Cleaning] Quarantined:  "Preinstalled.DellDataProtection" ,  "HKLM\\Software\\Wow6432Node\\\\Classes\\CLSID\\{2DC80C06-0687-5383-8B6B-2A9E50F53F64}" [ "Registry" ]
2019-09-08 01:06:35 :  <INFO>      [Cleaning] Processing:  "Preinstalled.DellDataProtection" ,  "HKLM\\Software\\Wow6432Node\\\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{2DC80C06-0687-5383-8B6B-2A9E50F53F64}" [ "Registry" ]
2019-09-08 01:06:35 :  <INFO>      [Cleaning] Quarantined:  "Preinstalled.DellDataProtection" ,  "HKLM\\Software\\Wow6432Node\\\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{2DC80C06-0687-5383-8B6B-2A9E50F53F64}" [ "Registry" ]
2019-09-08 01:06:35 :  <INFO>      [Cleaning] Processing:  "Preinstalled.DellDataProtection" ,  "HKLM\\Software\\Wow6432Node\\\\Microsoft\\Windows\\CurrentVersion\\Ext\\Preapproved\\{2DC80C06-0687-5383-8B6B-2A9E50F53F64}" [ "Registry" ]
2019-09-08 01:06:35 :  <INFO>      [Cleaning] Quarantined:  "Preinstalled.DellDataProtection" ,  "HKLM\\Software\\Wow6432Node\\\\Microsoft\\Windows\\CurrentVersion\\Ext\\Preapproved\\{2DC80C06-0687-5383-8B6B-2A9E50F53F64}" [ "Registry" ]
2019-09-08 01:06:35 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.WebCompanion" ,  "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Lavasoft\\WebCompanion" [ "Folder" ]
2019-09-08 01:06:35 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.WebCompanion" ,  "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Lavasoft\\WebCompanion" [ "Folder" ]
2019-09-08 01:06:35 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.WebCompanion" ,  "C:\\Program Files (x86)\\Lavasoft\\Web Companion" [ "Folder" ]
2019-09-08 01:06:35 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.WebCompanion" ,  "C:\\Program Files (x86)\\Lavasoft\\Web Companion" [ "Folder" ]
2019-09-08 01:06:35 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.WebCompanion" ,  "C:\\ProgramData\\Lavasoft\\Web Companion" [ "Folder" ]
2019-09-08 01:06:35 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.WebCompanion" ,  "C:\\ProgramData\\Lavasoft\\Web Companion" [ "Folder" ]
2019-09-08 01:06:35 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.WebCompanion" ,  "C:\\ProgramData\\Application Data\\Lavasoft\\Web Companion" [ "Folder" ]
2019-09-08 21:38:34 :  <INFO>      [Application] Close event: Can't be closed. Close button is disabled
2019-09-08 21:38:50 :  <INFO>      [Application] Close event: Can't be closed. Close button is disabled
2019-09-08 22:21:59 :  <INFO>      [Application] AdwCleaner  7 . 4 . 1  launched
2019-09-08 22:22:08 :  <INFO>      [MBInstaller] Checking Iris
2019-09-08 22:22:08 :  <INFO>      [IRIS] Making request
2019-09-08 22:22:11 :  <INFO>      [SslCert] Issued by ("DigiCert SHA2 High Assurance Server CA")
2019-09-08 22:22:11 :  <INFO>      [SslCert] Issued to ("*.malwarebytes.com")
2019-09-08 22:22:11 :  <INFO>      [SslCert] Locality Name ("Santa Clara")
2019-09-08 22:22:11 :  <INFO>      [SslCert] Organization ("Malwarebytes Inc")
2019-09-08 22:22:11 :  <INFO>      [SslCert] Certificate EffectiveDate:  "Mon Oct 2 00:00:00 2017 GMT"
2019-09-08 22:22:11 :  <INFO>      [SslCert] Certificate ExpirationDate:  "Tue Oct 6 12:00:00 2020 GMT"
2019-09-08 22:22:11 :  <INFO>      [SslCert] ALPN: None
2019-09-08 22:22:11 :  <INFO>      [SslCert] Cipher:  "ECDHE-RSA-AES256-GCM-SHA384"
2019-09-08 22:22:11 :  <INFO>      [SslCert] KXE:  "ECDH"
2019-09-08 22:22:11 :  <INFO>      [SslCert] Protocol:  "TLSv1.2"
2019-09-08 22:22:11 :  <WARNING>   [File Downloader] Error downloading ( QNetworkReply::NetworkError(ContentNotFoundError) )
2019-09-08 22:22:11 :  <INFO>      [IRIS] Failed
2019-09-08 22:22:16 :  <INFO>      [Button clicked] Survey score:  8
2019-09-08 22:22:16 :  <INFO>      [Telemetry] Sending NPS Survey
2019-09-08 22:22:20 :  <INFO>      [AdwUpgrade] Checking application updates
2019-09-08 22:22:20 :  <INFO>      [Telemetry] Sending hello
2019-09-08 22:22:21 :  <INFO>      [SslCert] Issued by ("DigiCert SHA2 High Assurance Server CA")
2019-09-08 22:22:21 :  <INFO>      [SslCert] Issued to ("*.malwarebytes.com")
2019-09-08 22:22:21 :  <INFO>      [SslCert] Locality Name ("Santa Clara")
2019-09-08 22:22:21 :  <INFO>      [SslCert] Organization ("Malwarebytes Inc")
2019-09-08 22:22:21 :  <INFO>      [SslCert] Certificate EffectiveDate:  "Mon Oct 2 00:00:00 2017 GMT"
2019-09-08 22:22:21 :  <INFO>      [SslCert] Certificate ExpirationDate:  "Tue Oct 6 12:00:00 2020 GMT"
2019-09-08 22:22:21 :  <INFO>      [SslCert] ALPN: None
2019-09-08 22:22:21 :  <INFO>      [SslCert] Cipher:  "ECDHE-RSA-AES256-GCM-SHA384"
2019-09-08 22:22:21 :  <INFO>      [SslCert] KXE:  "ECDH"
2019-09-08 22:22:21 :  <INFO>      [SslCert] Protocol:  "TLSv1.2"
2019-09-08 22:22:21 :  <INFO>      [Telemetry] Status code:  QVariant(int, 200)
2019-09-08 22:22:21 :  <INFO>      [SslCert] Issued by ("Let's Encrypt Authority X3")
2019-09-08 22:22:21 :  <INFO>      [SslCert] Issued to ("telemetry-02.adwc.mb.fr33tux.org")
2019-09-08 22:22:21 :  <INFO>      [SslCert] Locality Name ()
2019-09-08 22:22:21 :  <INFO>      [SslCert] Organization ()
2019-09-08 22:22:21 :  <INFO>      [SslCert] Certificate EffectiveDate:  "Sun Aug 18 10:50:38 2019 GMT"
2019-09-08 22:22:21 :  <INFO>      [SslCert] Certificate ExpirationDate:  "Sat Nov 16 10:50:38 2019 GMT"
2019-09-08 22:22:21 :  <INFO>      [SslCert] ALPN: Yes
2019-09-08 22:22:21 :  <INFO>      [SslCert] Cipher:  "ECDHE-RSA-AES256-GCM-SHA384"
2019-09-08 22:22:21 :  <INFO>      [SslCert] KXE:  "ECDH"
2019-09-08 22:22:21 :  <INFO>      [SslCert] Protocol:  "TLSv1.2"
2019-09-08 22:22:21 :  <INFO>      [Telemetry] Status code:  QVariant(int, 204)
2019-09-08 22:22:27 :  <INFO>      [Button clicked] Scan
2019-09-08 22:22:27 :  <INFO>      [Scan] Started
2019-09-08 22:22:27 :  <INFO>      [Database] Downloading database
2019-09-08 22:22:29 :  <INFO>      [Database] Checking integrity
2019-09-08 22:22:29 :  <INFO>      [Database] Found  2599  families
2019-09-08 22:22:29 :  <INFO>      [Database] Database v "2019-09-06.1"
2019-09-08 22:22:31 :  <INFO>      [Loading paths] Local paths loaded
2019-09-08 22:22:31 :  <INFO>      [Loading paths] Chrome paths loaded
2019-09-08 22:22:31 :  <INFO>      [Loading paths] User Keys loaded
2019-09-08 22:22:31 :  <INFO>      [Module initialized]  "File"
2019-09-08 22:22:31 :  <INFO>      [Module initialized]  "Folder"
2019-09-08 22:22:31 :  <INFO>      [Module initialized]  "RegistryKey"
2019-09-08 22:22:31 :  <INFO>      [Module initialized]  "RegistryValue"
2019-09-08 22:22:33 :  <INFO>      [Module initialized]  "TaskName"
2019-09-08 22:22:34 :  <INFO>      [Module initialized]  "Service"
2019-09-08 22:22:34 :  <INFO>      [Module initialized]  "Winlogon"
2019-09-08 22:22:46 :  <INFO>      [Module initialized]  "URL"
2019-09-08 22:22:46 :  <INFO>      [Module initialized]  "RegAppInit"
2019-09-08 22:22:46 :  <INFO>      [Module initialized]  "RegClasses"
2019-09-08 22:22:46 :  <INFO>      [Module initialized]  "DNS"
2019-09-08 22:22:46 :  <INFO>      [Module initialized]  "RegFirewallPolicy"
2019-09-08 22:22:46 :  <INFO>      [Module initialized]  "RegGuid"
2019-09-08 22:22:47 :  <INFO>      [Module initialized]  "RegIEElevationPolicy"
2019-09-08 22:22:47 :  <INFO>      [Module initialized]  "RegOther"
2019-09-08 22:22:47 :  <INFO>      [Module initialized]  "RegProductID"
2019-09-08 22:22:47 :  <INFO>      [Module initialized]  "RegSoftware"
2019-09-08 22:22:47 :  <INFO>      [Module initialized]  "RegStartup"
2019-09-08 22:22:47 :  <INFO>      [Module initialized]  "WMI"
2019-09-08 22:22:47 :  <INFO>      [Module initialized]  "ChromiumExt"
2019-09-08 22:22:47 :  <INFO>      [Module initialized]  "FirefoxExt"
2019-09-08 22:22:47 :  <INFO>      [Module initialize] Scan Browser
2019-09-08 22:22:50 :  <INFO>      [Module initialize] Scan Browser FF
2019-09-08 22:22:50 :  <INFO>      [Module initialize] FF start pages loaded
2019-09-08 22:22:50 :  <INFO>      [Module initialize] FF search providers loaded
2019-09-08 22:22:50 :  <INFO>      [Module initialize] FF plugin list loaded
2019-09-08 22:22:50 :  <INFO>      [Scan] Exclusions loaded
2019-09-08 22:23:16 :  <INFO>      [Scan] Item detected:  "PUP.Optional.Legacy" ,  "Search Here" [ "Chromium URLs" ]
2019-09-08 22:23:16 :  <INFO>      [Scan] Item detected:  "PUP.Optional.Legacy" ,  "http://search.b1.org/?bsrc=hmcor&chid=c167991" [ "Chromium URLs" ]
2019-09-08 22:23:58 :  <INFO>      [Scan] Item detected:  "PUP.Optional.Legacy" ,  "blekko" [ "Chromium URLs" ]
2019-09-08 22:23:58 :  <INFO>      [Scan] Item detected:  "PUP.Optional.Legacy" ,  "Blekko" [ "Chromium URLs" ]
2019-09-08 22:23:58 :  <INFO>      [Scan] Item detected:  "PUP.Optional.Legacy" ,  "http://blekko.com/ws/?source=5f97ddbe&tbp=homepage&u=94aa068e0000000000000016177e22d9" [ "Chromium URLs" ]
2019-09-08 22:24:31 :  <INFO>      [Scan] Item detected:  "PUP.Optional.Legacy" ,  "VideoDownloadConverter" [ "Chromium URLs" ]
2019-09-08 22:25:00 :  <INFO>      [Scan] Item detected:  "PUP.Optional.WebCompanion" ,  "C:\\Users\\Declan\\AppData\\Local\\Lavasoft\\WEBCOMPANION.EXE_URL_SIQ0LWF3TZGXP2KHFKLLYBK3IDTBEHNG" [ "Folder" ]
2019-09-08 22:25:00 :  <INFO>      [Scan] Item detected:  "PUP.Optional.WebCompanion" ,  "HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\Domains\\webcompanion.com" [ "Registry" ]
2019-09-08 22:25:00 :  <INFO>      [Scan] Item detected:  "PUP.Optional.WebCompanion" ,  "HKLM\\Software\\Wow6432Node\\Lavasoft\\Web Companion" [ "Registry" ]
2019-09-08 22:25:00 :  <INFO>      [Scan] Item detected:  "Preinstalled.LenovoPowerDVD" ,  "HKLM\\Software\\Wow6432Node\\\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}" [ "Registry" ]
2019-09-08 22:25:00 :  <INFO>      [Scan] Item detected:  "Preinstalled.LenovoPowerDVD" ,  "HKLM\\Software\\Wow6432Node\\\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{B46BEA36-0B71-4A4E-AE41-87241643FA0A}" [ "Registry" ]
2019-09-08 22:25:06 :  <INFO>      [Scan] Item detected:  "Preinstalled.CyberLinkShellExtension" ,  "HKLM\\Software\\Classes\\CLSID\\{3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2}" [ "Registry" ]
2019-09-08 22:25:06 :  <INFO>      [Scan] Item detected:  "Preinstalled.LenovoPower2Go" ,  "HKLM\\Software\\Wow6432Node\\\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}" [ "Registry" ]
2019-09-08 22:25:06 :  <INFO>      [Scan] Item detected:  "Preinstalled.LenovoPower2Go" ,  "HKLM\\Software\\Wow6432Node\\\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}" [ "Registry" ]
2019-09-08 22:25:06 :  <INFO>      [Scan] Item detected:  "Preinstalled.LenovoPower2Go" ,  "HKLM\\Software\\Wow6432Node\\\\Microsoft\\Windows\\CurrentVersion\\Run|CLMLServer_For_P2G8" [ "Registry" ]
2019-09-08 22:25:06 :  <INFO>      [Scan] Item detected:  "Preinstalled.LenovoPower2Go" ,  "HKLM\\Software\\Wow6432Node\\\\Microsoft\\Windows\\CurrentVersion\\Run|CLVirtualDrive" [ "Registry" ]
2019-09-08 22:25:06 :  <INFO>      [Scan] Item detected:  "PUP.Optional.AdvancedSystemRepairPro" ,  "HKLM\\Software\\Classes\\Interface\\{23387882-DEAA-4971-2222-5D5046F2B3BB}" [ "Registry" ]
2019-09-08 22:25:11 :  <INFO>      [Scan] Item detected:  "PUP.Optional.MySearch" ,  "Search Here" [ "Chromium URLs" ]
2019-09-08 22:25:14 :  <INFO>      [Scan] Item detected:  "PUP.Optional.SearchManager" ,  "HKCU\\Software\\ProductSetup\\Uninstall\\0B2U2Z1P0F1P1G1R1P1V0A1Q1Q0O1G" [ "Registry" ]
2019-09-08 22:25:14 :  <INFO>      [Scan] Item detected:  "PUP.Optional.SearchManager" ,  "HKCU\\Software\\ProductSetup\\Uninstall\\0S1P1T1C1R1MtT0P1C1F2X1L1Q1P1QtT1S2UtT0Y1T1M1F1F" [ "Registry" ]
2019-09-08 22:25:18 :  <INFO>      [Scan] Item detected:  "PUP.Optional.YTDToolbar" ,  "HKLM\\Software\\Wow6432Node\\{DAF8B7E5-449D-4180-8281-10E536E597F2}" [ "Registry" ]
2019-09-08 22:25:20 :  <INFO>      [Scan] Item detected:  "PUP.Optional.InstallCore" ,  "HKCU\\Software\\csastats" [ "Registry" ]
2019-09-08 22:25:21 :  <INFO>      [Scan] Item detected:  "Preinstalled.HPSupportAssistant" ,  "C:\\Program Files (x86)\\HEWLETT-PACKARD\\HP CUSTOMER FEEDBACK" [ "Folder" ]
2019-09-08 22:25:21 :  <INFO>      [Scan] Item detected:  "Preinstalled.HPSupportAssistant" ,  "C:\\Users\\Declan\\AppData\\Roaming\\HEWLETT-PACKARD\\HP SUPPORT FRAMEWORK" [ "Folder" ]
2019-09-08 22:25:21 :  <INFO>      [Scan] Item detected:  "Preinstalled.HPSupportAssistant" ,  "C:\\Users\\Declan\\AppData\\Local\\HEWLETT-PACKARD\\HP SUPPORT FRAMEWORK" [ "Folder" ]
2019-09-08 22:25:21 :  <INFO>      [Scan] Item detected:  "Preinstalled.HPSupportAssistant" ,  "C:\\Windows\\SysWOW64\\config\\systemprofile\\AppData\\Roaming\\HEWLETT-PACKARD\\HP SUPPORT FRAMEWORK" [ "Folder" ]
2019-09-08 22:25:21 :  <INFO>      [Scan] Item detected:  "Preinstalled.HPSupportAssistant" ,  "C:\\Program Files (x86)\\HEWLETT-PACKARD\\HP SUPPORT FRAMEWORK" [ "Folder" ]
2019-09-08 22:25:21 :  <INFO>      [Scan] Item detected:  "Preinstalled.HPSupportAssistant" ,  "C:\\ProgramData\\HEWLETT-PACKARD\\HP SUPPORT FRAMEWORK" [ "Folder" ]
2019-09-08 22:25:21 :  <INFO>      [Scan] Item detected:  "Preinstalled.HPSupportAssistant" ,  "C:\\Program Files (x86)\\HEWLETT-PACKARD\\HP SUPPORT SOLUTIONS" [ "Folder" ]
2019-09-08 22:25:21 :  <INFO>      [Scan] Item detected:  "Preinstalled.HPSupportAssistant" ,  "C:\\HP\\SUPPORT" [ "Folder" ]
2019-09-08 22:25:21 :  <INFO>      [Scan] Item detected:  "Preinstalled.HPSupportAssistant" ,  "HKLM\\Software\\Wow6432Node\\\\Classes\\CLSID\\{C0ABBA07-B636-47B8-B9E1-BB96D7CD4831}" [ "Registry" ]
2019-09-08 22:25:21 :  <INFO>      [Scan] Item detected:  "Preinstalled.HPRegistrationService" ,  "C:\\ProgramData\\HEWLETT-PACKARD\\HP REGISTRATION SERVICE" [ "Folder" ]
2019-09-08 22:25:21 :  <INFO>      [Scan] Item detected:  "Preinstalled.HPHealthCheck" ,  "C:\\Program Files (x86)\\HEWLETT-PACKARD\\HP HEALTH CHECK" [ "Folder" ]
2019-09-08 22:25:21 :  <INFO>      [Scan] Item detected:  "Preinstalled.HPHealthCheck" ,  "HKLM\\Software\\Wow6432Node\\\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{6F340107-F9AA-47C6-B54C-C3A19F11553F}" [ "Registry" ]
2019-09-08 22:25:24 :  <INFO>      [Scan] Item detected:  "PUP.Optional.ProductSetup.A" ,  "HKCU\\Software\\PRODUCTSETUP" [ "Registry" ]
2019-09-08 22:25:25 :  <INFO>      [Scan] Item detected:  "PUP.Optional.FreeMakeConverter" ,  "HKLM\\Software\\Wow6432Node\\\\Microsoft\\Windows\\CurrentVersion\\Run|ProductUpdater" [ "Registry" ]
2019-09-08 22:25:46 :  <INFO>      [Telemetry] Sending to Influx
2019-09-08 22:25:46 :  <INFO>      [SslCert] Issued by ("Let's Encrypt Authority X3")
2019-09-08 22:25:46 :  <INFO>      [SslCert] Issued to ("telemetry-02.adwc.mb.fr33tux.org")
2019-09-08 22:25:46 :  <INFO>      [SslCert] Locality Name ()
2019-09-08 22:25:46 :  <INFO>      [SslCert] Organization ()
2019-09-08 22:25:46 :  <INFO>      [SslCert] Certificate EffectiveDate:  "Sun Aug 18 10:50:38 2019 GMT"
2019-09-08 22:25:46 :  <INFO>      [SslCert] Certificate ExpirationDate:  "Sat Nov 16 10:50:38 2019 GMT"
2019-09-08 22:25:46 :  <INFO>      [SslCert] ALPN: Yes
2019-09-08 22:25:46 :  <INFO>      [SslCert] Cipher:  "ECDHE-RSA-AES256-GCM-SHA384"
2019-09-08 22:25:46 :  <INFO>      [SslCert] KXE:  "ECDH"
2019-09-08 22:25:46 :  <INFO>      [SslCert] Protocol:  "TLSv1.2"
2019-09-08 22:25:46 :  <INFO>      [Telemetry] Status code:  QVariant(int, 204)
2019-09-08 22:25:46 :  <INFO>      [Telemetry] Sending to DSE
2019-09-08 22:25:47 :  <INFO>      [SslCert] Issued by ("DigiCert SHA2 High Assurance Server CA")
2019-09-08 22:25:47 :  <INFO>      [SslCert] Issued to ("*.malwarebytes.com")
2019-09-08 22:25:47 :  <INFO>      [SslCert] Locality Name ("San Jose")
2019-09-08 22:25:47 :  <INFO>      [SslCert] Organization ("Malwarebytes Inc.")
2019-09-08 22:25:47 :  <INFO>      [SslCert] Certificate EffectiveDate:  "Thu Feb 22 00:00:00 2018 GMT"
2019-09-08 22:25:47 :  <INFO>      [SslCert] Certificate ExpirationDate:  "Wed Apr 22 12:00:00 2020 GMT"
2019-09-08 22:25:47 :  <INFO>      [SslCert] ALPN: Yes
2019-09-08 22:25:47 :  <INFO>      [SslCert] Cipher:  "ECDHE-RSA-AES256-GCM-SHA384"
2019-09-08 22:25:47 :  <INFO>      [SslCert] KXE:  "ECDH"
2019-09-08 22:25:47 :  <INFO>      [SslCert] Protocol:  "TLSv1.2"
2019-09-08 22:25:47 :  <INFO>      [Telemetry] Status code:  QVariant(int, 201)
2019-09-08 22:25:47 :  <INFO>      [Scan] Finished
2019-09-08 22:26:02 :  <INFO>      [Button clicked] Next
2019-09-08 22:26:12 :  <INFO>      [Button clicked] Clean & repair
2019-09-08 22:26:18 :  <INFO>      [Button clicked] Dialog button clicked [ 2 ]
2019-09-08 22:27:05 :  <INFO>      0x2399fe8 "AdwCleaner_BeforeCleaning_08/09/2019_23:26:18" ]
2019-09-08 22:27:05 :  <INFO>      [Cleaning] Started
2019-09-08 22:27:05 :  <WARNING>   [Cleaning] Unable to Open process -  "[System Process]"   0
2019-09-08 22:27:05 :  <WARNING>   [Cleaning] Unable to Open process -  "System"   0
2019-09-08 22:27:05 :  <INFO>      [Quarantine] Session folder:  "C:\\AdwCleaner\\Quarantine\\v1\\20190908.232705"
2019-09-08 22:27:05 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.Legacy" ,  "Search Here" [ "Chromium URLs" ]
2019-09-08 22:27:08 :  <WARNING>   Quarantined items list is empty
2019-09-08 22:27:08 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.Legacy" ,  "Search Here" [ "Chromium URLs" ]
2019-09-08 22:27:08 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.Legacy" ,  "http://search.b1.org/?bsrc=hmcor&chid=c167991" [ "Chromium URLs" ]
2019-09-08 22:27:09 :  <WARNING>   Quarantined items list is empty
2019-09-08 22:27:09 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.Legacy" ,  "http://search.b1.org/?bsrc=hmcor&chid=c167991" [ "Chromium URLs" ]
2019-09-08 22:27:09 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.Legacy" ,  "blekko" [ "Chromium URLs" ]
2019-09-08 22:27:10 :  <WARNING>   Quarantined items list is empty
2019-09-08 22:27:10 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.Legacy" ,  "blekko" [ "Chromium URLs" ]
2019-09-08 22:27:10 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.Legacy" ,  "Blekko" [ "Chromium URLs" ]
2019-09-08 22:27:10 :  <WARNING>   Quarantined items list is empty
2019-09-08 22:27:10 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.Legacy" ,  "Blekko" [ "Chromium URLs" ]
2019-09-08 22:27:10 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.Legacy" ,  "http://blekko.com/ws/?source=5f97ddbe&tbp=homepage&u=94aa068e0000000000000016177e22d9" [ "Chromium URLs" ]
2019-09-08 22:27:10 :  <WARNING>   Quarantined items list is empty
2019-09-08 22:27:11 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.Legacy" ,  "http://blekko.com/ws/?source=5f97ddbe&tbp=homepage&u=94aa068e0000000000000016177e22d9" [ "Chromium URLs" ]
2019-09-08 22:27:11 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.Legacy" ,  "VideoDownloadConverter" [ "Chromium URLs" ]
2019-09-08 22:27:11 :  <WARNING>   Quarantined items list is empty
2019-09-08 22:27:11 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.Legacy" ,  "VideoDownloadConverter" [ "Chromium URLs" ]
2019-09-08 22:27:11 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.WebCompanion" ,  "C:\\Users\\Declan\\AppData\\Local\\Lavasoft\\WEBCOMPANION.EXE_URL_SIQ0LWF3TZGXP2KHFKLLYBK3IDTBEHNG" [ "Folder" ]
2019-09-08 22:27:11 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.WebCompanion" ,  "C:\\Users\\Declan\\AppData\\Local\\Lavasoft\\WEBCOMPANION.EXE_URL_SIQ0LWF3TZGXP2KHFKLLYBK3IDTBEHNG" [ "Folder" ]
2019-09-08 22:27:11 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.WebCompanion" ,  "HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\Domains\\webcompanion.com" [ "Registry" ]
2019-09-08 22:27:11 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.WebCompanion" ,  "HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\Domains\\webcompanion.com" [ "Registry" ]
2019-09-08 22:27:11 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.WebCompanion" ,  "HKLM\\Software\\Wow6432Node\\Lavasoft\\Web Companion" [ "Registry" ]
2019-09-08 22:27:11 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.WebCompanion" ,  "HKLM\\Software\\Wow6432Node\\Lavasoft\\Web Companion" [ "Registry" ]
2019-09-08 22:27:11 :  <INFO>      [Cleaning] Processing:  "Preinstalled.LenovoPowerDVD" ,  "HKLM\\Software\\Wow6432Node\\\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}" [ "Registry" ]
2019-09-08 22:27:12 :  <INFO>      [Cleaning] Quarantined:  "Preinstalled.LenovoPowerDVD" ,  "HKLM\\Software\\Wow6432Node\\\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}" [ "Registry" ]
2019-09-08 22:27:12 :  <INFO>      [Cleaning] Processing:  "Preinstalled.LenovoPowerDVD" ,  "HKLM\\Software\\Wow6432Node\\\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{B46BEA36-0B71-4A4E-AE41-87241643FA0A}" [ "Registry" ]
2019-09-08 22:27:12 :  <INFO>      [Cleaning] Quarantined:  "Preinstalled.LenovoPowerDVD" ,  "HKLM\\Software\\Wow6432Node\\\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{B46BEA36-0B71-4A4E-AE41-87241643FA0A}" [ "Registry" ]
2019-09-08 22:27:12 :  <INFO>      [Cleaning] Processing:  "Preinstalled.CyberLinkShellExtension" ,  "HKLM\\Software\\Classes\\CLSID\\{3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2}" [ "Registry" ]
2019-09-08 22:27:12 :  <INFO>      [Cleaning] Quarantined:  "Preinstalled.CyberLinkShellExtension" ,  "HKLM\\Software\\Classes\\CLSID\\{3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2}" [ "Registry" ]
2019-09-08 22:27:12 :  <INFO>      [Cleaning] Processing:  "Preinstalled.LenovoPower2Go" ,  "HKLM\\Software\\Wow6432Node\\\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}" [ "Registry" ]
2019-09-08 22:27:12 :  <INFO>      [Cleaning] Quarantined:  "Preinstalled.LenovoPower2Go" ,  "HKLM\\Software\\Wow6432Node\\\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}" [ "Registry" ]
2019-09-08 22:27:12 :  <INFO>      [Cleaning] Processing:  "Preinstalled.LenovoPower2Go" ,  "HKLM\\Software\\Wow6432Node\\\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}" [ "Registry" ]
2019-09-08 22:27:12 :  <INFO>      [Cleaning] Quarantined:  "Preinstalled.LenovoPower2Go" ,  "HKLM\\Software\\Wow6432Node\\\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}" [ "Registry" ]
2019-09-08 22:27:12 :  <INFO>      [Cleaning] Processing:  "Preinstalled.LenovoPower2Go" ,  "HKLM\\Software\\Wow6432Node\\\\Microsoft\\Windows\\CurrentVersion\\Run|CLMLServer_For_P2G8" [ "Registry" ]
2019-09-08 22:27:12 :  <INFO>      [Cleaning] Quarantined:  "Preinstalled.LenovoPower2Go" ,  "HKLM\\Software\\Wow6432Node\\\\Microsoft\\Windows\\CurrentVersion\\Run|CLMLServer_For_P2G8" [ "Registry" ]
2019-09-08 22:27:12 :  <INFO>      [Cleaning] Processing:  "Preinstalled.LenovoPower2Go" ,  "HKLM\\Software\\Wow6432Node\\\\Microsoft\\Windows\\CurrentVersion\\Run|CLVirtualDrive" [ "Registry" ]
2019-09-08 22:27:12 :  <INFO>      [Cleaning] Quarantined:  "Preinstalled.LenovoPower2Go" ,  "HKLM\\Software\\Wow6432Node\\\\Microsoft\\Windows\\CurrentVersion\\Run|CLVirtualDrive" [ "Registry" ]
2019-09-08 22:27:12 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.AdvancedSystemRepairPro" ,  "HKLM\\Software\\Classes\\Interface\\{23387882-DEAA-4971-2222-5D5046F2B3BB}" [ "Registry" ]
2019-09-08 22:27:12 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.AdvancedSystemRepairPro" ,  "HKLM\\Software\\Classes\\Interface\\{23387882-DEAA-4971-2222-5D5046F2B3BB}" [ "Registry" ]
2019-09-08 22:27:12 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.MySearch" ,  "Search Here" [ "Chromium URLs" ]
2019-09-08 22:27:12 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.MySearch" ,  "Search Here" [ "Chromium URLs" ]
2019-09-08 22:27:12 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.SearchManager" ,  "HKCU\\Software\\ProductSetup\\Uninstall\\0B2U2Z1P0F1P1G1R1P1V0A1Q1Q0O1G" [ "Registry" ]
2019-09-08 22:27:13 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.SearchManager" ,  "HKCU\\Software\\ProductSetup\\Uninstall\\0B2U2Z1P0F1P1G1R1P1V0A1Q1Q0O1G" [ "Registry" ]
2019-09-08 22:27:13 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.SearchManager" ,  "HKCU\\Software\\ProductSetup\\Uninstall\\0S1P1T1C1R1MtT0P1C1F2X1L1Q1P1QtT1S2UtT0Y1T1M1F1F" [ "Registry" ]
2019-09-08 22:27:13 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.SearchManager" ,  "HKCU\\Software\\ProductSetup\\Uninstall\\0S1P1T1C1R1MtT0P1C1F2X1L1Q1P1QtT1S2UtT0Y1T1M1F1F" [ "Registry" ]
2019-09-08 22:27:13 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.YTDToolbar" ,  "HKLM\\Software\\Wow6432Node\\{DAF8B7E5-449D-4180-8281-10E536E597F2}" [ "Registry" ]
2019-09-08 22:27:13 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.YTDToolbar" ,  "HKLM\\Software\\Wow6432Node\\{DAF8B7E5-449D-4180-8281-10E536E597F2}" [ "Registry" ]
2019-09-08 22:27:13 :  <INFO>      [Cleaning] Processing:  "PUP.Optional.InstallCore" ,  "HKCU\\Software\\csastats" [ "Registry" ]
2019-09-08 22:27:13 :  <INFO>      [Cleaning] Quarantined:  "PUP.Optional.InstallCore" ,  "HKCU\\Software\\csastats" [ "Registry" ]
2019-09-08 22:27:13 :  <INFO>      [Cleaning] Processing:  "Preinstalled.HPSupportAssistant" ,  "C:\\Program Files (x86)\\HEWLETT-PACKARD\\HP CUSTOMER FEEDBACK" [ "Folder" ]
2019-09-08 22:27:13 :  <INFO>      [Cleaning] Quarantined:  "Preinstalled.HPSupportAssistant" ,  "C:\\Program Files (x86)\\HEWLETT-PACKARD\\HP CUSTOMER FEEDBACK" [ "Folder" ]
2019-09-08 22:27:13 :  <INFO>      [Cleaning] Processing:  "Preinstalled.HPSupportAssistant" ,  "C:\\Users\\Declan\\AppData\\Roaming\\HEWLETT-PACKARD\\HP SUPPORT FRAMEWORK" [ "Folder" ]
2019-09-08 22:27:13 :  <INFO>      [Cleaning] Quarantined:  "Preinstalled.HPSupportAssistant" ,  "C:\\Users\\Declan\\AppData\\Roaming\\HEWLETT-PACKARD\\HP SUPPORT FRAMEWORK" [ "Folder" ]
2019-09-08 22:27:13 :  <INFO>      [Cleaning] Processing:  "Preinstalled.HPSupportAssistant" ,  "C:\\Users\\Declan\\AppData\\Local\\HEWLETT-PACKARD\\HP SUPPORT FRAMEWORK" [ "Folder" ]
2019-09-08 22:27:14 :  <INFO>      [Cleaning] Quarantined:  "Preinstalled.HPSupportAssistant" ,  "C:\\Users\\Declan\\AppData\\Local\\HEWLETT-PACKARD\\HP SUPPORT FRAMEWORK" [ "Folder" ]
2019-09-08 22:27:14 :  <INFO>      [Cleaning] Processing:  "Preinstalled.HPSupportAssistant" ,  "C:\\Windows\\SysWOW64\\config\\systemprofile\\AppData\\Roaming\\HEWLETT-PACKARD\\HP SUPPORT FRAMEWORK" [ "Folder" ]
2019-09-08 22:27:14 :  <INFO>      [Cleaning] Quarantined:  "Preinstalled.HPSupportAssistant" ,  "C:\\Windows\\SysWOW64\\config\\systemprofile\\AppData\\Roaming\\HEWLETT-PACKARD\\HP SUPPORT FRAMEWORK" [ "Folder" ]
2019-09-08 22:27:14 :  <INFO>      [Cleaning] Processing:  "Preinstalled.HPSupportAssistant" ,  "C:\\Program Files (x86)\\HEWLETT-PACKARD\\HP SUPPORT FRAMEWORK" [ "Folder" ]
2019-09-08 22:27:15 :  <INFO>      [Cleaning] Quarantined:  "Preinstalled.HPSupportAssistant" ,  "C:\\Program Files (x86)\\HEWLETT-PACKARD\\HP SUPPORT FRAMEWORK" [ "Folder" ]
2019-09-08 22:27:15 :  <INFO>      [Cleaning] Processing:  "Preinstalled.HPSupportAssistant" ,  "C:\\ProgramData\\HEWLETT-PACKARD\\HP SUPPORT FRAMEWORK" [ "Folder" ]
2019-09-08 22:27:15 :  <INFO>      [Cleaning] Quarantined:  "Preinstalled.HPSupportAssistant" ,  "C:\\ProgramData\\HEWLETT-PACKARD\\HP SUPPORT FRAMEWORK" [ "Folder" ]
2019-09-08 22:27:15 :  <INFO>      [Cleaning] Processing:  "Preinstalled.HPSupportAssistant" ,  "C:\\Program Files (x86)\\HEWLETT-PACKARD\\HP SUPPORT SOLUTIONS" [ "Folder" ]
2019-09-08 22:45:42 :  <INFO>      [Button clicked] Log files menu item
2019-09-08 22:46:03 :  <INFO>      [Application] Close event: Can't be closed. Close button is disabled
2019-09-08 22:46:05 :  <INFO>      [Application] Close event: Can't be closed. Close button is disabled
2019-09-08 22:46:05 :  <INFO>      [Application] Close event: Can't be closed. Close button is disabled
2019-09-08 22:46:06 :  <INFO>      [Application] Close event: Can't be closed. Close button is disabled
2019-09-08 22:46:07 :  <INFO>      [Application] Close event: Can't be closed. Close button is disabled
2019-09-08 22:46:07 :  <INFO>      [Application] Close event: Can't be closed. Close button is disabled
2019-09-08 22:46:08 :  <INFO>      [Application] Close event: Can't be closed. Close button is disabled
2019-09-08 22:46:08 :  <INFO>      [Application] Close event: Can't be closed. Close button is disabled
2019-09-08 22:46:11 :  <INFO>      [Button clicked] Settings menu item
2019-09-08 22:46:41 :  <INFO>      [Button clicked] Help menu item
2019-09-08 22:46:54 :  <INFO>      [Button clicked] Open URL
2019-09-08 22:59:49 :  <INFO>      [Application] Close event: Can't be closed. Close button is disabled
2019-09-08 22:59:52 :  <INFO>      [Application] Close event: Can't be closed. Close button is disabled
2019-09-08 23:00:02 :  <INFO>      [Application] Close event: Can't be closed. Close button is disabled
2019-09-08 23:00:04 :  <INFO>      [Application] Close event: Can't be closed. Close button is disabled
2019-09-08 23:00:05 :  <INFO>      [Application] Close event: Can't be closed. Close button is disabled
2019-09-08 23:00:06 :  <INFO>      [Application] Close event: Can't be closed. Close button is disabled
2019-09-08 23:00:06 :  <INFO>      [Application] Close event: Can't be closed. Close button is disabled
2019-09-08 23:37:07 :  <INFO>      [Application] Close event: Can't be closed. Close button is disabled
2019-09-09 15:03:32 :  <INFO>      [Application] AdwCleaner  7 . 4 . 1  launched
2019-09-09 15:03:39 :  <INFO>      [MBInstaller] Checking Iris
2019-09-09 15:03:39 :  <INFO>      [IRIS] Making request
2019-09-09 15:03:41 :  <INFO>      [AdwUpgrade] Checking application updates
2019-09-09 15:03:41 :  <INFO>      [Telemetry] Sending hello
2019-09-09 15:03:41 :  <INFO>      [SslCert] Issued by ("DigiCert SHA2 High Assurance Server CA")
2019-09-09 15:03:42 :  <INFO>      [SslCert] Issued to ("*.malwarebytes.com")
2019-09-09 15:03:42 :  <INFO>      [SslCert] Locality Name ("Santa Clara")
2019-09-09 15:03:42 :  <INFO>      [SslCert] Organization ("Malwarebytes Inc")
2019-09-09 15:03:42 :  <INFO>      [SslCert] Certificate EffectiveDate:  "Mon Oct 2 00:00:00 2017 GMT"
2019-09-09 15:03:42 :  <INFO>      [SslCert] Certificate ExpirationDate:  "Tue Oct 6 12:00:00 2020 GMT"
2019-09-09 15:03:42 :  <INFO>      [SslCert] ALPN: None
2019-09-09 15:03:42 :  <INFO>      [SslCert] Cipher:  "ECDHE-RSA-AES256-GCM-SHA384"
2019-09-09 15:03:42 :  <INFO>      [SslCert] KXE:  "ECDH"
2019-09-09 15:03:42 :  <INFO>      [SslCert] Protocol:  "TLSv1.2"
2019-09-09 15:03:42 :  <INFO>      [SslCert] Issued by ("DigiCert SHA2 High Assurance Server CA")
2019-09-09 15:03:42 :  <INFO>      [SslCert] Issued to ("*.malwarebytes.com")
2019-09-09 15:03:42 :  <INFO>      [SslCert] Locality Name ("Santa Clara")
2019-09-09 15:03:42 :  <INFO>      [SslCert] Organization ("Malwarebytes Inc")
2019-09-09 15:03:42 :  <INFO>      [SslCert] Certificate EffectiveDate:  "Mon Oct 2 00:00:00 2017 GMT"
2019-09-09 15:03:42 :  <INFO>      [SslCert] Certificate ExpirationDate:  "Tue Oct 6 12:00:00 2020 GMT"
2019-09-09 15:03:42 :  <INFO>      [SslCert] ALPN: None
2019-09-09 15:03:42 :  <INFO>      [SslCert] Cipher:  "ECDHE-RSA-AES256-GCM-SHA384"
2019-09-09 15:03:42 :  <INFO>      [SslCert] KXE:  "ECDH"
2019-09-09 15:03:42 :  <INFO>      [SslCert] Protocol:  "TLSv1.2"
2019-09-09 15:03:42 :  <INFO>      [Telemetry] Status code:  QVariant(int, 200)
2019-09-09 15:03:42 :  <WARNING>   [File Downloader] Error downloading ( QNetworkReply::NetworkError(ContentNotFoundError) )
2019-09-09 15:03:42 :  <INFO>      [IRIS] Failed
2019-09-09 15:03:47 :  <INFO>      [Button clicked] Log files menu item

 

Edited by fr33tux
Add <code>

Share this post


Link to post
Share on other sites

Noticed that earlier (than 7.41) AdwCleaner existed, removed AdwCleaner 7.30; operation normal.  Issue solved.

Share this post


Link to post
Share on other sites

Hello @nvsoar

To help us narrow down the issue can you please provide us a memory dump of the AdwCleaner process when it's stuck ?

1. Run AdwCleaner and initiate the scan and Cleanup.

2. Open the task manager.

3. When the cleanup gets stuck, right click on the awecleaner process and click "Create dump file"

4. Can you please send us the dump file using WeTransfer.(https://wetransfer.com/)

Thank you.

 

image.png.89e4424419b5cadc85ff07904ba5cf59.png

Share this post


Link to post
Share on other sites

Sure, for info, the log still exists and is attached.  What is the desired email address to send the log?  Not at all familiar with wetransfer.com

Please be advised that the issue no longer exists since I deleted an earlier (than 7.4.1) version; and that the log was attached to my initial message.

What format is preferred? Zipped?

nvsoar

AdwCleaner_Debug.log

Share this post


Link to post
Share on other sites

 

You can post with just a link to your file.

 

Upload File(s) to WeTransfer:

  • Visit WeTransfer.com
  • Click on I Agree
    4ENbg3P.png
  • Click on the icon on the lower left indicated in the below image
    qKOjzXD.png
  • Select the Link option
    Cyzhcx1.png
  • Click on +Add Files
    CvZMyrC.png
  • Browse to the location of the file and double-click on it or click once on it and select Open
    S5Ty834.png
  • Click on Transfer
    8eYfZGi.png
  • Once the transfer completes, click on Copy link
    fkb0tkR.png
  • Once you receive the Copied! message as indicated below, paste the link into your next reply
    ndpEstA.png

 

Share this post


Link to post
Share on other sites

Hello @nvsoar

I sent you a Private message with alternate upload instructions.

Let me know if you have any issues.

Thank you.

Share this post


Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

  • Recently Browsing   0 members

    No registered users viewing this page.

×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.