# AdwCleaner v6.046 - Logfile created 03/05/2017 at 21:55:58
# Updated on 24/04/2017 by Malwarebytes
# Database : 2017-05-02.1 [Server]
# Operating System : Windows 10 Home Single Language (X64)
# Username : Marvelous A.J - REIN
# Running from : D:\adwcleaner_6.046.exe
# Mode: Clean
# Support :
Customer Support & Help Center
***** [ Services ] *****
[-] Service deleted: SpyHunter 4 Service
[-] Service deleted: esgiguard
***** [ Folders ] *****
[-] Folder deleted: C:\Users\Marvelous A.J\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\spyhunter
[-] Folder deleted: C:\Users\Marvelous A.J\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\UC浏览器
[-] Folder deleted: C:\sh4ldr
[-] Folder deleted: C:\Program Files (x86)\Enigma Software Group
[-] Folder deleted: C:\WINDOWS\Update\psgo
***** [ Files ] *****
[-] File deleted: C:\Users\Marvelous A.J\Desktop\SpyHunter.lnk
[-] File deleted: C:\WINDOWS\SysNative\log\iSafeKrnlCall.log
[-] File deleted: C:\END
[-] File deleted: C:\spyhunter.fix
[-] File deleted: C:\WINDOWS\SysWOW64\kz.exe
[-] File deleted: C:\Users\Public\Documents\temp.dat
[-] File deleted: C:\Users\Public\Documents\report.dat
[-] File deleted: C:\Users\Marvelous A.J\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_st.chatango.com_0.localstorage
[-] File deleted: C:\Users\Marvelous A.J\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_st.chatango.com_0.localstorage-journal
[#] File deleted: C:\Users\Marvelous A.J\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_st.chatango.com_0.localstorage
[#] File deleted: C:\Users\Marvelous A.J\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\hxxp_st.chatango.com_0.localstorage-journal
***** [ DLL ] *****
***** [ WMI ] *****
***** [ Shortcuts ] *****
***** [ Scheduled Tasks ] *****
[-] Task deleted: SpyHunter4Startup
[-] Task deleted: Milimili
***** [ Registry ] *****
[-] Key deleted: HKU\.DEFAULT\Software\UpgSvr
[-] Key deleted: HKU\S-1-5-21-3624755597-3157177985-3930298230-1002\Software\PopWnd
[-] Key deleted: HKU\S-1-5-21-3624755597-3157177985-3930298230-1002\Software\UpgSvr
[#] Key deleted on reboot: HKU\S-1-5-18\Software\UpgSvr
[#] Key deleted on reboot: HKCU\Software\PopWnd
[#] Key deleted on reboot: HKCU\Software\UpgSvr
[-] Key deleted: HKLM\SOFTWARE\ScreenShot
[-] Key deleted: HKLM\SOFTWARE\EnigmaSoftwareGroup
[-] Key deleted: HKLM\SOFTWARE\msServer
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4FC9DA9D-F608-454E-8191-D7EFFDCC5726}
[#] Key deleted on reboot: [x64] HKCU\Software\PopWnd
[#] Key deleted on reboot: [x64] HKCU\Software\UpgSvr
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7BD8146798CEA704D860BE01414B8E51
[-] Value deleted: HKU\S-1-5-21-3624755597-3157177985-3930298230-1002\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run [Yeaplayer]
[-] Value deleted: HKU\S-1-5-21-3624755597-3157177985-3930298230-1002\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run [msiql]