# -------------------------------
# Malwarebytes AdwCleaner 7.2.3.1
# -------------------------------
# Build: 09-03-2018
# Database: 2018-09-10.1 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 09-10-2018
# Duration: 00:00:13
# OS: Windows 10 Home
# Cleaned: 35
# Failed: 4


***** [ Services ] *****

Deleted saiyitechnology

***** [ Folders ] *****

Deleted C:\ProgramData\Quoteexs
Deleted C:\ProgramData\0E132D28-4FB1-0
Deleted C:\ProgramData\0E132D28-2767-1
Deleted C:\Users\user01\AppData\Local\BrowserAir
Deleted C:\ProgramData\yahoochrome_D
Deleted C:\Users\user01\AppData\Local\SearchModule

***** [ Files ] *****

Deleted C:\Windows\System32\drivers\powzip.sys
Deleted C:\Windows\SysWOW64\findit.xml

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

Deleted HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\11598763487076930564
Deleted HKLM\Software\MICROSOFT\TechnologyDesktopnew
Deleted HKLM\SOFTWARE\MICROSOFT\Speedycar
Deleted HKLM\Software\Wow6432Node\mtQuoteex
Deleted HKLM\Software\Wow6432Node\MICROSOFT\WINDOWS NT\CURRENTVERSION\SILENTPROCESSEXIT\Quoteex.exe
Deleted HKCU\Software\Microsoft\BigTime
Deleted HKCU\Software\FastDataX
Deleted HKLM\Software\Microsoft\DMunversion
Deleted HKLM\Software\Wow6432Node\Classes\Interface\{47A1DF02-BCE4-40C3-AE47-E3EA09A65E4A}
Deleted HKLM\Software\Classes\Interface\{47A1DF02-BCE4-40C3-AE47-E3EA09A65E4A}
Deleted HKLM\Software\Wow6432Node\Classes\Interface\{FA7B2795-C0C8-4A58-8672-3F8D80CC0270}
Deleted HKLM\Software\Classes\Interface\{FA7B2795-C0C8-4A58-8672-3F8D80CC0270}
Deleted HKLM\Software\Wow6432Node\Classes\TypeLib\{1112F282-7099-4624-A439-DB29D6551552}
Deleted HKLM\Software\Classes\TypeLib\{1112F282-7099-4624-A439-DB29D6551552}
Deleted HKLM\Software\Microsoft\Shared Tools\MSConfig\services\saiyitechnology
Deleted HKLM\Software\Microsoft\Shared Tools\MSConfig\services\backlh
Deleted HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes|DefaultScope
Deleted HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Quoteex.exe
Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Quoteex.exe
Deleted HKCU\Software\One System Care
Deleted HKU\.DEFAULT\Environment|SNP
Deleted HKU\S-1-5-18\Environment|SNP

***** [ Chromium (and derivatives) ] *****

Deleted Chameleon

***** [ Chromium URLs ] *****

Deleted Conduit
Deleted Ask

***** [ Firefox (and derivatives) ] *****

Deleted SaveFrom.net helper

***** [ Firefox URLs ] *****

Not Deleted suggestqueries.google.com
Not Deleted api.searchpredict.com
Not Deleted api.searchpredict.com
Not Deleted api.searchpredict.com


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [4031 octets] - [10/09/2018 09:11:34]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########