2016-09-22 22:53:52 : [main] - Saving current options to the configuration file 2016-09-22 22:53:57 : [main.gui] - Scan requested 2016-09-22 22:53:57 : [scan] - Running from: C:\AdwCleaner 2016-09-22 22:53:57 : [scan] - Progress: 0% 2016-09-22 22:53:57 : [database] - Using local database 2016-09-22 22:53:57 : [scan] - Progress: 5% 2016-09-22 22:53:57 : [database] - Initialize the database 2016-09-22 22:53:57 : [database] - Loading sqlite3.dll 2016-09-22 22:53:57 : [database] - Opening the database 2016-09-22 22:53:58 : [database] - Querying database's version 2016-09-22 22:53:58 : [database] - Loading internal data 2016-09-22 22:53:58 : [database] - Loading detections 2016-09-22 22:54:01 : [database] - Loading generics 2016-09-22 22:54:01 : [database] - Closing the database 2016-09-22 22:54:01 : [database] - Closing database 2016-09-22 22:54:01 : [database] - Unloading sqlite3.dll 2016-09-22 22:54:01 : [scan] - Progress: 15% 2016-09-22 22:54:01 : [scan.generic] - Generating generic detections 2016-09-22 22:54:01 : [scan.generic] - Generating generic detections [1] 2016-09-22 22:54:01 : [scan.generic] - Generating generic detections [2] 2016-09-22 22:54:01 : [scan.generic] - Generating generic detections [3] 2016-09-22 22:54:01 : [scan.generic] - Generating generic detections [4] 2016-09-22 22:54:01 : [scan.generic] - Generating generic detections [5] 2016-09-22 22:54:01 : [scan.generic] - Generating generic detections [6] 2016-09-22 22:54:01 : [scan.generic] - Generating generic detections [7] 2016-09-22 22:54:01 : [scan.generic] - Generating generic detections [8] 2016-09-22 22:54:01 : [scan.generic] - Generating generic detections [9] 2016-09-22 22:54:01 : [scan.generic] - Generating generic detections [10] 2016-09-22 22:54:01 : [scan.generic] - Generating generic detections [11] 2016-09-22 22:54:01 : [scan.generic] - Generating generic detections [12] 2016-09-22 22:54:01 : [scan.generic] - Generating generic detections [13] 2016-09-22 22:54:01 : [scan.generic] - Generating generic detections [14] 2016-09-22 22:54:01 : [scan.generic] - Generating generic detections [15] 2016-09-22 22:54:01 : [scan.generic] - Generating generic detections [16] 2016-09-22 22:54:01 : [scan.generic] - Generating generic detections [17] 2016-09-22 22:54:01 : [scan.generic] - Generating generic detections [18] 2016-09-22 22:54:01 : [scan.generic] - Generating generic detections [19] 2016-09-22 22:54:01 : [scan.generic] - Generating generic detections [20] 2016-09-22 22:54:01 : [scan.generic] - Generating generic detections [21] 2016-09-22 22:54:01 : [scan.generic] - Generating generic detections [22] 2016-09-22 22:54:01 : [scan.generic] - Generating generic detections [23] 2016-09-22 22:54:01 : [scan.generic] - Generating generic detections [24] 2016-09-22 22:54:01 : [scan.generic] - Generating generic detections [25] 2016-09-22 22:54:01 : [scan.generic] - Generating generic detections [26] 2016-09-22 22:54:01 : [scan.generic] - Generating generic detections [27] 2016-09-22 22:54:01 : [scan.generic] - Generating generic detections [28] 2016-09-22 22:54:01 : [scan.generic] - Generating generic detections [29] 2016-09-22 22:54:01 : [scan.generic] - Generating generic detections [30] 2016-09-22 22:54:01 : [scan.generic] - Generating generic detections [31] 2016-09-22 22:54:01 : [scan.generic] - Generating generic detections [32] 2016-09-22 22:54:01 : [scan.generic] - Generating generic detections [33] 2016-09-22 22:54:01 : [scan.generic] - Generating generic detections [34] 2016-09-22 22:54:01 : [scan.generic] - Generating generic detections [35] 2016-09-22 22:54:01 : [scan.generic] - Generating generic detections [36] 2016-09-22 22:54:01 : [scan.generic] - Generating generic detections [37] 2016-09-22 22:54:01 : [scan.generic] - Generating generic detections [38] 2016-09-22 22:54:01 : [scan.generic] - Generating generic detections [39] 2016-09-22 22:54:01 : [scan.generic] - Generating generic detections [40] 2016-09-22 22:54:01 : [scan.generic] - Generating generic detections [41] 2016-09-22 22:54:01 : [scan.generic] - Generating generic detections [42] 2016-09-22 22:54:01 : [scan.generic] - Generating generic detections [43] 2016-09-22 22:54:01 : [scan.generic] - Generating generic detections [44] 2016-09-22 22:54:01 : [scan.generic] - Generating generic detections [45] 2016-09-22 22:54:01 : [scan.generic] - Generic detections generated 2016-09-22 22:54:01 : [scan] - Progress: 20% 2016-09-22 22:54:01 : [scan.generic] - Starting generic analysis 2016-09-22 22:54:21 : [scan] - Progress: 30% 2016-09-22 22:54:21 : [scan.services] - Starting services scan [1] 2016-09-22 22:54:21 : [scan.services] - Stopping services scan [1] 2016-09-22 22:54:21 : [scan.services] - Starting services scan [2] 2016-09-22 22:54:21 : [scan.services] - Stopping services scan [2] 2016-09-22 22:54:21 : [scan.services] - 0 malicious services found 2016-09-22 22:54:21 : [scan] - Progress: 40% 2016-09-22 22:54:21 : [scan.folders] - Starting folders scan 2016-09-22 22:54:22 : [scan.folders] - Found C:\Users\Admin\AppData\Local\SweetLabs App Platform 2016-09-22 22:54:22 : [scan.folders] - Found C:\Users\Admin\AppData\Local\torch 2016-09-22 22:54:41 : [scan.folders] - Found C:\ProgramData\torchcrashhandler 2016-09-22 22:54:42 : [scan.folders] - Found C:\ProgramData\Application Data\torchcrashhandler 2016-09-22 22:54:54 : [scan.folders] - Found C:\Users\Default User\AppData\Local\Pokki 2016-09-22 22:54:54 : [scan.folders] - Found C:\Users\Default\AppData\Local\Pokki 2016-09-22 22:54:54 : [scan.folders] - Stopping folders scan 2016-09-22 22:54:54 : [scan.folders] - 6 malicious folders found 2016-09-22 22:54:54 : [scan] - Progress: 50% 2016-09-22 22:54:54 : [scan.files] - Starting files scan 2016-09-22 22:54:57 : [scan.files] - Found C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Torch.lnk 2016-09-22 22:54:57 : [scan.files] - Found C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk 2016-09-22 22:55:04 : [scan.files] - Stopping files scan 2016-09-22 22:55:04 : [scan.files] - 2 malicious files found 2016-09-22 22:55:04 : [scan] - Progress: 55% 2016-09-22 22:55:04 : [scan.dll] - Starting DLL scan 2016-09-22 22:55:05 : [scan.dll] - Stopping DLL scan 2016-09-22 22:55:05 : [scan.dll] - 0 malicious DLL found 2016-09-22 22:55:05 : [scan] - Progress: 60% 2016-09-22 22:55:05 : [scan.wmi] - Starting WMI scan 2016-09-22 22:55:05 : [scan.wmi] - Stopping WMI scan 2016-09-22 22:55:05 : [scan.wmi] - 0 malicious WMI found 2016-09-22 22:55:05 : [scan] - Progress: 65% 2016-09-22 22:55:05 : [scan.shortcuts] - Starting shortcuts scan 2016-09-22 22:55:22 : [scan.shortcuts] - Stopping shortcuts scan 2016-09-22 22:55:22 : [scan.shortcuts] - 0 malicious shortcuts found 2016-09-22 22:55:22 : [scan] - Progress: 70% 2016-09-22 22:55:22 : [scan.tasks] - Starting tasks scan 2016-09-22 22:55:22 : [scan.tasks] - Found SweetLabs App Platform 2016-09-22 22:55:23 : [scan.tasks] - Stopping tasks scan 2016-09-22 22:55:23 : [scan.tasks] - 1 malicious tasks found 2016-09-22 22:55:23 : [scan] - Progress: 75% 2016-09-22 22:55:23 : [scan.registry] - Starting registry scan [1] 2016-09-22 22:55:23 : [scan.registry] - Found pokki 2016-09-22 22:55:23 : [scan.registry] - Found pokki 2016-09-22 22:55:23 : [scan.registry] - Found Microsoft.IIsScriptHelper 2016-09-22 22:55:23 : [scan.registry] - Found Microsoft.IIsScriptHelper.1.0 2016-09-22 22:55:24 : [scan.registry] - Found pokki 2016-09-22 22:55:24 : [scan.registry] - Found Microsoft.IIsScriptHelper 2016-09-22 22:55:24 : [scan.registry] - Found Microsoft.IIsScriptHelper.1.0 2016-09-22 22:55:25 : [scan.registry] - Stopping registry scan [1] 2016-09-22 22:55:25 : [scan.registry] - Starting registry scan [2] 2016-09-22 22:55:26 : [scan.registry] - Found {6E993643-8FBC-44FE-BC85-D318495C4D96} 2016-09-22 22:55:27 : [scan.registry] - Found {A43DE495-3D00-47D4-9D2C-303115707939} 2016-09-22 22:55:35 : [scan.registry] - Stopping registry scan [2] 2016-09-22 22:55:35 : [scan.registry] - Starting registry scan [3] 2016-09-22 22:55:37 : [scan.registry] - Found SweetLabs App Platform 2016-09-22 22:55:37 : [scan.registry] - Found torch 2016-09-22 22:55:37 : [scan.registry] - Found SweetLabs_AP 2016-09-22 22:55:37 : [scan.registry] - Found SweetLabs_Start_Menu 2016-09-22 22:55:37 : [scan.registry] - Found torch 2016-09-22 22:55:38 : [scan.registry] - Found SweetLabs App Platform 2016-09-22 22:55:38 : [scan.registry] - Found torch 2016-09-22 22:55:39 : [scan.registry] - Found torch 2016-09-22 22:55:39 : [scan.registry] - Found SweetLabs_AP 2016-09-22 22:55:39 : [scan.registry] - Found SweetLabs_Start_Menu 2016-09-22 22:55:39 : [scan.registry] - Found torch 2016-09-22 22:55:39 : [scan.registry] - Found SweetLabs App Platform 2016-09-22 22:55:39 : [scan.registry] - Found torch 2016-09-22 22:55:40 : [scan.registry] - Found SweetLabs_AP 2016-09-22 22:55:40 : [scan.registry] - Found SweetLabs_Start_Menu 2016-09-22 22:55:40 : [scan.registry] - Found torch 2016-09-22 22:55:40 : [scan.registry] - Stopping registry scan [3] 2016-09-22 22:55:40 : [scan] - Progress: 80% 2016-09-22 22:55:40 : [scan.registry] - Starting registry scan [4] 2016-09-22 22:55:40 : [scan.registry] - Stopping registry scan [4] 2016-09-22 22:55:40 : [scan.registry] - Starting registry scan [5] 2016-09-22 22:55:40 : [scan.registry] - Stopping registry scan [5] 2016-09-22 22:55:40 : [scan] - Progress: 82% 2016-09-22 22:55:40 : [scan.registry] - Starting registry scan [6] 2016-09-22 22:55:40 : [scan.registry] - Stopping registry scan [6] 2016-09-22 22:55:40 : [scan.registry] - Starting registry scan [7] 2016-09-22 22:55:40 : [scan.registry] - Stopping registry scan [7] 2016-09-22 22:55:40 : [scan.registry] - Starting registry scan [8] 2016-09-22 22:55:40 : [scan.registry] - Stopping registry scan [8] 2016-09-22 22:55:40 : [scan] - Progress: 84% 2016-09-22 22:55:40 : [scan.registry] - Starting registry scan [9] 2016-09-22 22:55:40 : [scan.registry] - Stopping registry scan [9] 2016-09-22 22:55:40 : [scan.registry] - Starting registry scan [10] 2016-09-22 22:55:40 : [scan.registry] - Stopping registry scan [10] 2016-09-22 22:55:40 : [scan.registry] - Starting registry scan [11] 2016-09-22 22:55:40 : [scan.registry] - Stopping registry scan [11] 2016-09-22 22:55:40 : [scan.registry] - Starting registry scan [12] 2016-09-22 22:55:40 : [scan.registry] - Stopping registry scan [12] 2016-09-22 22:55:40 : [scan.registry] - Starting registry scan [13] 2016-09-22 22:55:40 : [scan.registry] - Stopping registry scan [13] 2016-09-22 22:55:40 : [scan.registry] - Starting registry scan [14] 2016-09-22 22:55:40 : [scan.registry] - Stopping registry scan [14] 2016-09-22 22:55:40 : [scan.registry] - Starting registry scan [15] 2016-09-22 22:55:40 : [scan.registry] - Stopping registry scan [15] 2016-09-22 22:55:40 : [scan.registry] - Starting registry scan [16] 2016-09-22 22:55:40 : [scan.registry] - Stopping registry scan [16] 2016-09-22 22:55:40 : [scan.registry] - Starting registry scan [17] 2016-09-22 22:55:40 : [scan.registry] - Stopping registry scan [17] 2016-09-22 22:55:40 : [scan.registry] - Starting registry scan [18] 2016-09-22 22:55:41 : [scan.registry] - Stopping registry scan [18] 2016-09-22 22:55:41 : [scan] - Progress: 86% 2016-09-22 22:55:41 : [scan.registry] - Starting registry scan [19] 2016-09-22 22:55:41 : [scan.registry] - Found HKCU\Software\Classes\AllFileSystemObjects\shell\pokki 2016-09-22 22:55:41 : [scan.registry] - Found HKCU\Software\Classes\Directory\shell\pokki 2016-09-22 22:55:41 : [scan.registry] - Found HKCU\Software\Classes\Drive\shell\pokki 2016-09-22 22:55:41 : [scan.registry] - Found HKCU\Software\Classes\lnkfile\shell\pokki 2016-09-22 22:55:41 : [scan.registry] - Found HKCU\Software\MozillaPlugins\TorchVLC 2016-09-22 22:55:41 : [scan.registry] - Found HKLM\SOFTWARE\Classes\Applications\Torch.exe 2016-09-22 22:55:41 : [scan.registry] - Found HKLM\SOFTWARE\Clients\StartMenuInternet\Torch 2016-09-22 22:55:41 : [scan.registry] - Found HKLM\SOFTWARE\Classes\f 2016-09-22 22:55:41 : [scan.registry] - Stopping registry scan [19] 2016-09-22 22:55:41 : [scan] - Progress: 88% 2016-09-22 22:55:41 : [scan.registry] - 33 malicious registry element found 2016-09-22 22:55:41 : [scan] - Progress: 90% 2016-09-22 22:55:41 : [main] - Firefox is installed: True 2016-09-22 22:55:41 : [scan.firefox] - Starting Firefox based browsers scan [1] 2016-09-22 22:55:57 : [scan.firefox] - Stopping Firefox based browsers scan [1] 2016-09-22 22:55:57 : [scan.firefox] - Starting Firefox based browsers scan [2] 2016-09-22 22:55:59 : [scan.firefox] - Stopping Firefox based browsers scan [2] 2016-09-22 22:55:59 : [scan] - Progress: 92% 2016-09-22 22:55:59 : [scan.firefox] - Starting Firefox based browsers scan [3] 2016-09-22 22:55:59 : [scan.firefox] - Reading C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\ij40lcbc.default\prefs.js 2016-09-22 22:55:59 : [scan.firefox] - Reading C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\ij40lcbc.default\user.js 2016-09-22 22:55:59 : [scan.firefox] - No profile to scan, skipping 2016-09-22 22:55:59 : [scan.firefox] - No profile to scan, skipping 2016-09-22 22:55:59 : [scan.firefox] - No profile to scan, skipping 2016-09-22 22:55:59 : [scan] - Progress: 94% 2016-09-22 22:55:59 : [scan.firefox] - Stopping Firefox based browsers scan [3] 2016-09-22 22:55:59 : [scan.firefox] - 0 malicious Firefox preferences found 2016-09-22 22:55:59 : [scan] - Progress: 95% 2016-09-22 22:55:59 : [main] - Chrome is installed: True 2016-09-22 22:55:59 : [scan.chromium] - Starting Chromium based browsers scan [1] 2016-09-22 22:56:03 : [scan.chromium] - Stopping Chromium based browsers scan [1] 2016-09-22 22:56:03 : [scan] - Progress: 97% 2016-09-22 22:56:03 : [scan.chromium] - Starting Chromium based browsers scan [2] 2016-09-22 22:56:03 : [scan.chromium] - No profile to scan, skipping 2016-09-22 22:56:03 : [scan.chromium] - Opening C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Web Data 2016-09-22 22:56:03 : [scan.chromium] - Found C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] ask.com 2016-09-22 22:56:03 : [scan.chromium] - Found C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] aol.com 2016-09-22 22:56:03 : [scan.chromium] - Found C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] vlc-media-player.en.softonic.com 2016-09-22 22:56:03 : [scan.chromium] - Found C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] blackberry-desktop-software.en.softonic.com 2016-09-22 22:56:03 : [scan.chromium] - Closing C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Web Data 2016-09-22 22:56:03 : [scan.chromium] - Opening C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences 2016-09-22 22:56:04 : [scan.chromium] - No profile to scan, skipping 2016-09-22 22:56:04 : [scan.chromium] - No profile to scan, skipping 2016-09-22 22:56:04 : [scan.chromium] - No profile to scan, skipping 2016-09-22 22:56:04 : [scan.chromium] - No profile to scan, skipping 2016-09-22 22:56:04 : [scan.chromium] - No profile to scan, skipping 2016-09-22 22:56:04 : [scan.chromium] - Stopping Chromium based browsers scan [2] 2016-09-22 22:56:04 : [scan] - Progress: 99% 2016-09-22 22:56:04 : [scan.chromium] - Starting Chromium based browsers scan [3] 2016-09-22 22:56:04 : [scan.chromium] - Stopping Chromium based browsers scan [3] 2016-09-22 22:56:04 : [scan.chromium] - 4 malicious Chromium preferences elements found 2016-09-22 22:56:04 : [scan] - Progress: 100% 2016-09-22 22:56:04 : [scan] - Stopping scan 2016-09-22 22:57:25 : [main.gui] - Clean requested 2016-09-22 22:57:26 : [main.gui] - Killing all processes 2016-09-22 22:57:26 : [main] - Killing [System Process](0) 2016-09-22 22:57:26 : [main] - Killing System(4) 2016-09-22 22:57:26 : [main] - smss.exe - (4) not killed - whitelisted 2016-09-22 22:57:26 : [main] - csrss.exe - (4) not killed - whitelisted 2016-09-22 22:57:26 : [main] - wininit.exe - (4) not killed - whitelisted 2016-09-22 22:57:26 : [main] - csrss.exe - (4) not killed - whitelisted 2016-09-22 22:57:26 : [main] - winlogon.exe - (4) not killed - whitelisted 2016-09-22 22:57:26 : [main] - services.exe - (4) not killed - whitelisted 2016-09-22 22:57:26 : [main] - lsass.exe - (4) not killed - whitelisted 2016-09-22 22:57:26 : [main] - svchost.exe - (4) not killed - whitelisted 2016-09-22 22:57:26 : [main] - svchost.exe - (4) not killed - whitelisted 2016-09-22 22:57:26 : [main] - dwm.exe - (4) not killed - whitelisted 2016-09-22 22:57:26 : [main] - svchost.exe - (4) not killed - whitelisted 2016-09-22 22:57:26 : [main] - svchost.exe - (4) not killed - whitelisted 2016-09-22 22:57:26 : [main] - svchost.exe - (4) not killed - whitelisted 2016-09-22 22:57:26 : [main] - svchost.exe - (4) not killed - whitelisted 2016-09-22 22:57:26 : [main] - svchost.exe - (4) not killed - whitelisted 2016-09-22 22:57:26 : [main] - Killing WUDFHost.exe(1284) 2016-09-22 22:57:26 : [main] - svchost.exe - (1284) not killed - whitelisted 2016-09-22 22:57:26 : [main] - dasHost.exe - (1284) not killed - whitelisted 2016-09-22 22:57:26 : [main] - Killing hmpalert.exe(1640) 2016-09-22 22:57:27 : [main] - Killing igfxCUIService.exe(1744) 2016-09-22 22:57:27 : [main] - svchost.exe - (1744) not killed - whitelisted 2016-09-22 22:57:27 : [main] - svchost.exe - (1744) not killed - whitelisted 2016-09-22 22:57:27 : [main] - svchost.exe - (1744) not killed - whitelisted 2016-09-22 22:57:27 : [main] - Killing spoolsv.exe(2124) 2016-09-22 22:57:27 : [main] - svchost.exe - (2124) not killed - whitelisted 2016-09-22 22:57:27 : [main] - svchost.exe - (2124) not killed - whitelisted 2016-09-22 22:57:27 : [main] - svchost.exe - (2124) not killed - whitelisted 2016-09-22 22:57:27 : [main] - Killing sqlwriter.exe(2460) 2016-09-22 22:57:27 : [main] - Killing HeciServer.exe(2476) 2016-09-22 22:57:27 : [main] - Killing mbamservice.exe(2484) 2016-09-22 22:57:27 : [main] - Killing mbamscheduler.exe(2492) 2016-09-22 22:57:27 : [main] - Killing HuaweiHiSuiteService64.exe(2500) 2016-09-22 22:57:27 : [main] - Killing mqsvc.exe(2508) 2016-09-22 22:57:27 : [main] - Killing NLSSRV32.EXE(2524) 2016-09-22 22:57:27 : [main] - Killing CxAudMsg64.exe(2532) 2016-09-22 22:57:27 : [main] - Killing BtwRSupportService.exe(2540) 2016-09-22 22:57:27 : [main] - Killing NitroPDFDriverService8x64.exe(2556) 2016-09-22 22:57:27 : [main] - svchost.exe - (2556) not killed - whitelisted 2016-09-22 22:57:27 : [main] - svchost.exe - (2556) not killed - whitelisted 2016-09-22 22:57:27 : [main] - svchost.exe - (2556) not killed - whitelisted 2016-09-22 22:57:27 : [main] - Killing RichVideo64.exe(2664) 2016-09-22 22:57:27 : [main] - Killing inetinfo.exe(2672) 2016-09-22 22:57:27 : [main] - Killing MsMpEng.exe(2684) 2016-09-22 22:57:27 : [main] - Killing SynTPEnhService.exe(2700) 2016-09-22 22:57:28 : [main] - svchost.exe - (2700) not killed - whitelisted 2016-09-22 22:57:28 : [main] - Killing webservd.exe(2868) 2016-09-22 22:57:28 : [main] - Killing SDWSCSvc.exe(2928) 2016-09-22 22:57:28 : [main] - Killing Memory Compression(3012) 2016-09-22 22:57:28 : [main] - Killing startsys.exe(3112) 2016-09-22 22:57:28 : [main] - conhost.exe - (3112) not killed - whitelisted 2016-09-22 22:57:28 : [main] - userAgent.exe - (3112) not killed - whitelisted 2016-09-22 22:57:28 : [main] - conhost.exe - (3112) not killed - whitelisted 2016-09-22 22:57:28 : [main] - Killing webcategory.exe(3216) 2016-09-22 22:57:28 : [main] - conhost.exe - (3216) not killed - whitelisted 2016-09-22 22:57:28 : [main] - SMSvcHost.exe - (3216) not killed - whitelisted 2016-09-22 22:57:28 : [main] - svchost.exe - (3216) not killed - whitelisted 2016-09-22 22:57:28 : [main] - SMSvcHost.exe - (3216) not killed - whitelisted 2016-09-22 22:57:28 : [main] - Killing NisSrv.exe(4660) 2016-09-22 22:57:28 : [main] - sihost.exe - (4660) not killed - whitelisted 2016-09-22 22:57:28 : [main] - svchost.exe - (4660) not killed - whitelisted 2016-09-22 22:57:28 : [main] - Killing PresentationFontCache.exe(5980) 2016-09-22 22:57:28 : [main] - Killing SynTPEnh.exe(5260) 2016-09-22 22:57:28 : [main] - Killing hmpalert.exe(1640) 2016-09-22 22:57:28 : [main] - Killing taskhostw.exe(5488) 2016-09-22 22:57:28 : [main] - Killing mbamgui.exe(5220) 2016-09-22 22:57:28 : [main] - Killing GoogleCrashHandler.exe(740) 2016-09-22 22:57:29 : [main] - Killing GoogleCrashHandler64.exe(5136) 2016-09-22 22:57:29 : [main] - Killing MagicPlus_helper.exe(5976) 2016-09-22 22:57:29 : [main] - Killing igfxEM.exe(5868) 2016-09-22 22:57:29 : [main] - Killing igfxHK.exe(6072) 2016-09-22 22:57:29 : [main] - Killing igfxTray.exe(6052) 2016-09-22 22:57:29 : [main] - Killing RuntimeBroker.exe(6712) 2016-09-22 22:57:29 : [main] - Killing ServiceHostAppUpdater.exe(6812) 2016-09-22 22:57:29 : [main] - explorer.exe - (6812) not killed - whitelisted 2016-09-22 22:57:29 : [main] - Killing PDVD10Serv.exe(6916) 2016-09-22 22:57:29 : [main] - Killing ShellExperienceHost.exe(6976) 2016-09-22 22:57:29 : [main] - Killing SynTPHelper.exe(3552) 2016-09-22 22:57:29 : [main] - Killing SearchIndexer.exe(5456) 2016-09-22 22:57:29 : [main] - SearchUI.exe - (5456) not killed - whitelisted 2016-09-22 22:57:29 : [main] - Killing SettingSyncHost.exe(8184) 2016-09-22 22:57:29 : [main] - smartscreen.exe - (8184) not killed - whitelisted 2016-09-22 22:57:29 : [main] - Killing CAudioFilterAgent64.exe(7176) 2016-09-22 22:57:29 : [main] - Killing RTFTrack.exe(7800) 2016-09-22 22:57:29 : [main] - Killing Energy Manager.exe(7852) 2016-09-22 22:57:29 : [main] - Killing HPSupportSolutionsFrameworkService.exe(7848) 2016-09-22 22:57:29 : [main] - Killing CDASrv.exe(7712) 2016-09-22 22:57:29 : [main] - Killing MSASCuiL.exe(7124) 2016-09-22 22:57:30 : [main] - Killing LSCNotify.exe(7512) 2016-09-22 22:57:30 : [main] - WmiPrvSE.exe - (7512) not killed - whitelisted 2016-09-22 22:57:30 : [main] - Killing FAHWindow32.exe(7480) 2016-09-22 22:57:30 : [main] - Killing FAHWindow64.exe(2116) 2016-09-22 22:57:30 : [main] - Killing WZUpdateNotifier.exe(8436) 2016-09-22 22:57:30 : [main] - Killing PWRISOVM.EXE(8544) 2016-09-22 22:57:30 : [main] - javaw.exe - (8544) not killed - whitelisted 2016-09-22 22:57:30 : [main] - Killing wfc.exe(8868) 2016-09-22 22:57:30 : [main] - Killing WzPreloader.exe(7192) 2016-09-22 22:57:30 : [main] - Killing SDTray.exe(8092) 2016-09-22 22:57:30 : [main] - Killing IAStorDataMgrSvc.exe(9140) 2016-09-22 22:57:30 : [main] - Killing SkypeHost.exe(9192) 2016-09-22 22:57:30 : [main] - Killing jhi_service.exe(8324) 2016-09-22 22:57:30 : [main] - Killing IAStorIcon.exe(7468) 2016-09-22 22:57:30 : [main] - Killing ServiceHostApp.exe(6728) 2016-09-22 22:57:30 : [main] - Killing audiodg.exe(3992) 2016-09-22 22:57:31 : [main] - Killing ServiceHostApp.exe(0) 2016-09-22 22:57:31 : [main] - ServiceStartMenuIndexer.exe - (0) not killed - whitelisted 2016-09-23 08:01:46 : INFO [main] - >>>> STARTING <<<< 2016-09-23 08:01:46 : INFO [main] - RAM Usage: 49 2016-09-23 08:01:46 : INFO [main] - OS: WIN_10 X64 2016-09-23 08:01:46 : [main.language] - Checking the language 2016-09-23 08:01:46 : [main.language] - Language found: en 2016-09-23 08:01:46 : [main.network] - Checking the network connectivity 2016-09-23 08:01:46 : [main.network] - Network connectivity status: True 2016-09-23 08:01:46 : [main.eula] - Checking for EULA agreement 2016-09-23 08:01:46 : [main.network] - Check for updates 2016-09-23 08:01:46 : [main.network] - Requesting the last release number 2016-09-23 08:01:50 : [main.network] - The current version is up-to-date 2016-09-23 08:01:50 : [main.gui] - GUI setup 2016-09-23 08:01:50 : [main.gui] - Languages setup 2016-09-23 08:01:51 : [main] - Chrome is installed: True 2016-09-23 08:01:51 : [main] - Firefox is installed: True 2016-09-23 08:01:51 : [main.gui] - Showing the gui 2016-09-23 08:18:56 : [main.gui] - Scan requested 2016-09-23 08:18:56 : [scan] - Running from: C:\AdwCleaner 2016-09-23 08:18:56 : [scan] - Progress: 0% 2016-09-23 08:18:56 : [database] - Checking for database updates 2016-09-23 08:18:56 : [main.network] - Updating definitions 2016-09-23 08:19:05 : [main.network] - Saving the updated definitions 2016-09-23 08:19:05 : [main.network] - Requesting the lastest database release number 2016-09-23 08:19:05 : [main.network] - Latest definitions: 473226c94043f2b9b71cd5a080c4bf6f 2016-09-23 08:19:05 : [database] - Database update succeeded: 473226C94043F2B9B71CD5A080C4BF6F 2016-09-23 08:19:05 : [scan] - Progress: 5% 2016-09-23 08:19:05 : [database] - Initialize the database 2016-09-23 08:19:05 : [database] - Loading sqlite3.dll 2016-09-23 08:19:06 : [database] - Opening the database 2016-09-23 08:19:06 : [database] - Querying database's version 2016-09-23 08:19:06 : [database] - Loading internal data 2016-09-23 08:19:06 : [database] - Loading detections 2016-09-23 08:19:09 : [database] - Loading generics 2016-09-23 08:19:09 : [database] - Closing the database 2016-09-23 08:19:09 : [database] - Closing database 2016-09-23 08:19:09 : [database] - Unloading sqlite3.dll 2016-09-23 08:19:09 : [scan] - Progress: 15% 2016-09-23 08:19:09 : [scan.generic] - Generating generic detections 2016-09-23 08:19:09 : [scan.generic] - Generating generic detections [1] 2016-09-23 08:19:09 : [scan.generic] - Generating generic detections [2] 2016-09-23 08:19:09 : [scan.generic] - Generating generic detections [3] 2016-09-23 08:19:09 : [scan.generic] - Generating generic detections [4] 2016-09-23 08:19:09 : [scan.generic] - Generating generic detections [5] 2016-09-23 08:19:09 : [scan.generic] - Generating generic detections [6] 2016-09-23 08:19:09 : [scan.generic] - Generating generic detections [7] 2016-09-23 08:19:09 : [scan.generic] - Generating generic detections [8] 2016-09-23 08:19:09 : [scan.generic] - Generating generic detections [9] 2016-09-23 08:19:09 : [scan.generic] - Generating generic detections [10] 2016-09-23 08:19:09 : [scan.generic] - Generating generic detections [11] 2016-09-23 08:19:09 : [scan.generic] - Generating generic detections [12] 2016-09-23 08:19:09 : [scan.generic] - Generating generic detections [13] 2016-09-23 08:19:09 : [scan.generic] - Generating generic detections [14] 2016-09-23 08:19:09 : [scan.generic] - Generating generic detections [15] 2016-09-23 08:19:09 : [scan.generic] - Generating generic detections [16] 2016-09-23 08:19:09 : [scan.generic] - Generating generic detections [17] 2016-09-23 08:19:09 : [scan.generic] - Generating generic detections [18] 2016-09-23 08:19:09 : [scan.generic] - Generating generic detections [19] 2016-09-23 08:19:09 : [scan.generic] - Generating generic detections [20] 2016-09-23 08:19:09 : [scan.generic] - Generating generic detections [21] 2016-09-23 08:19:09 : [scan.generic] - Generating generic detections [22] 2016-09-23 08:19:09 : [scan.generic] - Generating generic detections [23] 2016-09-23 08:19:09 : [scan.generic] - Generating generic detections [24] 2016-09-23 08:19:09 : [scan.generic] - Generating generic detections [25] 2016-09-23 08:19:09 : [scan.generic] - Generating generic detections [26] 2016-09-23 08:19:09 : [scan.generic] - Generating generic detections [27] 2016-09-23 08:19:09 : [scan.generic] - Generating generic detections [28] 2016-09-23 08:19:09 : [scan.generic] - Generating generic detections [29] 2016-09-23 08:19:09 : [scan.generic] - Generating generic detections [30] 2016-09-23 08:19:09 : [scan.generic] - Generating generic detections [31] 2016-09-23 08:19:09 : [scan.generic] - Generating generic detections [32] 2016-09-23 08:19:09 : [scan.generic] - Generating generic detections [33] 2016-09-23 08:19:09 : [scan.generic] - Generating generic detections [34] 2016-09-23 08:19:09 : [scan.generic] - Generating generic detections [35] 2016-09-23 08:19:09 : [scan.generic] - Generating generic detections [36] 2016-09-23 08:19:09 : [scan.generic] - Generating generic detections [37] 2016-09-23 08:19:09 : [scan.generic] - Generating generic detections [38] 2016-09-23 08:19:09 : [scan.generic] - Generating generic detections [39] 2016-09-23 08:19:09 : [scan.generic] - Generating generic detections [40] 2016-09-23 08:19:09 : [scan.generic] - Generating generic detections [41] 2016-09-23 08:19:09 : [scan.generic] - Generating generic detections [42] 2016-09-23 08:19:09 : [scan.generic] - Generating generic detections [43] 2016-09-23 08:19:10 : [scan.generic] - Generating generic detections [44] 2016-09-23 08:19:10 : [scan.generic] - Generating generic detections [45] 2016-09-23 08:19:10 : [scan.generic] - Generic detections generated 2016-09-23 08:19:10 : [scan] - Progress: 20% 2016-09-23 08:19:10 : [scan.generic] - Starting generic analysis 2016-09-23 08:20:26 : [scan] - Progress: 30% 2016-09-23 08:20:26 : [scan.services] - Starting services scan [1] 2016-09-23 08:20:26 : [scan.services] - Stopping services scan [1] 2016-09-23 08:20:26 : [scan.services] - Starting services scan [2] 2016-09-23 08:20:26 : [scan.services] - Stopping services scan [2] 2016-09-23 08:20:26 : [scan.services] - 0 malicious services found 2016-09-23 08:20:26 : [scan] - Progress: 40% 2016-09-23 08:20:26 : [scan.folders] - Starting folders scan 2016-09-23 08:20:27 : [scan.folders] - Found C:\Users\Admin\AppData\Local\SweetLabs App Platform 2016-09-23 08:20:27 : [scan.folders] - Found C:\Users\Admin\AppData\Local\torch 2016-09-23 08:20:45 : [scan.folders] - Found C:\ProgramData\torchcrashhandler 2016-09-23 08:20:46 : [scan.folders] - Found C:\ProgramData\Application Data\torchcrashhandler 2016-09-23 08:20:59 : [scan.folders] - Found C:\Users\Default User\AppData\Local\Pokki 2016-09-23 08:20:59 : [scan.folders] - Found C:\Users\Default\AppData\Local\Pokki 2016-09-23 08:20:59 : [scan.folders] - Stopping folders scan 2016-09-23 08:20:59 : [scan.folders] - 6 malicious folders found 2016-09-23 08:20:59 : [scan] - Progress: 50% 2016-09-23 08:20:59 : [scan.files] - Starting files scan 2016-09-23 08:21:02 : [scan.files] - Found C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Torch.lnk 2016-09-23 08:21:02 : [scan.files] - Found C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk 2016-09-23 08:21:09 : [scan.files] - Stopping files scan 2016-09-23 08:21:09 : [scan.files] - 2 malicious files found 2016-09-23 08:21:09 : [scan] - Progress: 55% 2016-09-23 08:21:09 : [scan.dll] - Starting DLL scan 2016-09-23 08:21:09 : [scan.dll] - Stopping DLL scan 2016-09-23 08:21:09 : [scan.dll] - 0 malicious DLL found 2016-09-23 08:21:09 : [scan] - Progress: 60% 2016-09-23 08:21:09 : [scan.wmi] - Starting WMI scan 2016-09-23 08:21:10 : [scan.wmi] - Stopping WMI scan 2016-09-23 08:21:10 : [scan.wmi] - 0 malicious WMI found 2016-09-23 08:21:10 : [scan] - Progress: 65% 2016-09-23 08:21:10 : [scan.shortcuts] - Starting shortcuts scan 2016-09-23 08:21:37 : [scan.shortcuts] - Stopping shortcuts scan 2016-09-23 08:21:37 : [scan.shortcuts] - 0 malicious shortcuts found 2016-09-23 08:21:37 : [scan] - Progress: 70% 2016-09-23 08:21:37 : [scan.tasks] - Starting tasks scan 2016-09-23 08:21:38 : [scan.tasks] - Found SweetLabs App Platform 2016-09-23 08:21:38 : [scan.tasks] - Stopping tasks scan 2016-09-23 08:21:38 : [scan.tasks] - 1 malicious tasks found 2016-09-23 08:21:38 : [scan] - Progress: 75% 2016-09-23 08:21:38 : [scan.registry] - Starting registry scan [1] 2016-09-23 08:21:39 : [scan.registry] - Found Microsoft.IIsScriptHelper 2016-09-23 08:21:39 : [scan.registry] - Found Microsoft.IIsScriptHelper.1.0 2016-09-23 08:21:40 : [scan.registry] - Found Microsoft.IIsScriptHelper 2016-09-23 08:21:40 : [scan.registry] - Found Microsoft.IIsScriptHelper.1.0 2016-09-23 08:21:40 : [scan.registry] - Stopping registry scan [1] 2016-09-23 08:21:40 : [scan.registry] - Starting registry scan [2] 2016-09-23 08:21:42 : [scan.registry] - Found {6E993643-8FBC-44FE-BC85-D318495C4D96} 2016-09-23 08:21:42 : [scan.registry] - Found {A43DE495-3D00-47D4-9D2C-303115707939} 2016-09-23 08:21:51 : [scan.registry] - Stopping registry scan [2] 2016-09-23 08:21:51 : [scan.registry] - Starting registry scan [3] 2016-09-23 08:21:53 : [scan.registry] - Found SweetLabs App Platform 2016-09-23 08:21:53 : [scan.registry] - Found torch 2016-09-23 08:21:53 : [scan.registry] - Found SweetLabs_AP 2016-09-23 08:21:53 : [scan.registry] - Found SweetLabs_Start_Menu 2016-09-23 08:21:53 : [scan.registry] - Found torch 2016-09-23 08:21:54 : [scan.registry] - Found SweetLabs App Platform 2016-09-23 08:21:54 : [scan.registry] - Found torch 2016-09-23 08:21:54 : [scan.registry] - Found torch 2016-09-23 08:21:54 : [scan.registry] - Found SweetLabs_AP 2016-09-23 08:21:54 : [scan.registry] - Found SweetLabs_Start_Menu 2016-09-23 08:21:54 : [scan.registry] - Found torch 2016-09-23 08:21:55 : [scan.registry] - Found SweetLabs App Platform 2016-09-23 08:21:55 : [scan.registry] - Found torch 2016-09-23 08:21:56 : [scan.registry] - Found SweetLabs_AP 2016-09-23 08:21:56 : [scan.registry] - Found SweetLabs_Start_Menu 2016-09-23 08:21:56 : [scan.registry] - Found torch 2016-09-23 08:21:56 : [scan.registry] - Stopping registry scan [3] 2016-09-23 08:21:56 : [scan] - Progress: 80% 2016-09-23 08:21:56 : [scan.registry] - Starting registry scan [4] 2016-09-23 08:21:56 : [scan.registry] - Stopping registry scan [4] 2016-09-23 08:21:56 : [scan.registry] - Starting registry scan [5] 2016-09-23 08:21:56 : [scan.registry] - Stopping registry scan [5] 2016-09-23 08:21:56 : [scan] - Progress: 82% 2016-09-23 08:21:56 : [scan.registry] - Starting registry scan [6] 2016-09-23 08:21:56 : [scan.registry] - Stopping registry scan [6] 2016-09-23 08:21:56 : [scan.registry] - Starting registry scan [7] 2016-09-23 08:21:56 : [scan.registry] - Stopping registry scan [7] 2016-09-23 08:21:56 : [scan.registry] - Starting registry scan [8] 2016-09-23 08:21:56 : [scan.registry] - Stopping registry scan [8] 2016-09-23 08:21:56 : [scan] - Progress: 84% 2016-09-23 08:21:56 : [scan.registry] - Starting registry scan [9] 2016-09-23 08:21:56 : [scan.registry] - Stopping registry scan [9] 2016-09-23 08:21:56 : [scan.registry] - Starting registry scan [10] 2016-09-23 08:21:56 : [scan.registry] - Stopping registry scan [10] 2016-09-23 08:21:56 : [scan.registry] - Starting registry scan [11] 2016-09-23 08:21:56 : [scan.registry] - Stopping registry scan [11] 2016-09-23 08:21:56 : [scan.registry] - Starting registry scan [12] 2016-09-23 08:21:56 : [scan.registry] - Stopping registry scan [12] 2016-09-23 08:21:56 : [scan.registry] - Starting registry scan [13] 2016-09-23 08:21:56 : [scan.registry] - Stopping registry scan [13] 2016-09-23 08:21:56 : [scan.registry] - Starting registry scan [14] 2016-09-23 08:21:56 : [scan.registry] - Stopping registry scan [14] 2016-09-23 08:21:56 : [scan.registry] - Starting registry scan [15] 2016-09-23 08:21:56 : [scan.registry] - Stopping registry scan [15] 2016-09-23 08:21:56 : [scan.registry] - Starting registry scan [16] 2016-09-23 08:21:56 : [scan.registry] - Stopping registry scan [16] 2016-09-23 08:21:57 : [scan.registry] - Starting registry scan [17] 2016-09-23 08:21:57 : [scan.registry] - Stopping registry scan [17] 2016-09-23 08:21:57 : [scan.registry] - Starting registry scan [18] 2016-09-23 08:21:57 : [scan.registry] - Stopping registry scan [18] 2016-09-23 08:21:57 : [scan] - Progress: 86% 2016-09-23 08:21:57 : [scan.registry] - Starting registry scan [19] 2016-09-23 08:21:57 : [scan.registry] - Found HKCU\Software\Classes\AllFileSystemObjects\shell\pokki 2016-09-23 08:21:57 : [scan.registry] - Found HKCU\Software\Classes\Directory\shell\pokki 2016-09-23 08:21:57 : [scan.registry] - Found HKCU\Software\Classes\Drive\shell\pokki 2016-09-23 08:21:57 : [scan.registry] - Found HKCU\Software\Classes\lnkfile\shell\pokki 2016-09-23 08:21:57 : [scan.registry] - Found HKCU\Software\MozillaPlugins\TorchVLC 2016-09-23 08:21:57 : [scan.registry] - Found HKLM\SOFTWARE\Classes\Applications\Torch.exe 2016-09-23 08:21:57 : [scan.registry] - Found HKLM\SOFTWARE\Clients\StartMenuInternet\Torch 2016-09-23 08:21:57 : [scan.registry] - Found HKLM\SOFTWARE\Classes\f 2016-09-23 08:21:57 : [scan.registry] - Stopping registry scan [19] 2016-09-23 08:21:57 : [scan] - Progress: 88% 2016-09-23 08:21:57 : [scan.registry] - 30 malicious registry element found 2016-09-23 08:21:57 : [scan] - Progress: 90% 2016-09-23 08:21:57 : [main] - Firefox is installed: True 2016-09-23 08:21:57 : [scan.firefox] - Starting Firefox based browsers scan [1] 2016-09-23 08:22:14 : [scan.firefox] - Stopping Firefox based browsers scan [1] 2016-09-23 08:22:14 : [scan.firefox] - Starting Firefox based browsers scan [2] 2016-09-23 08:22:16 : [scan.firefox] - Stopping Firefox based browsers scan [2] 2016-09-23 08:22:16 : [scan] - Progress: 92% 2016-09-23 08:22:16 : [scan.firefox] - Starting Firefox based browsers scan [3] 2016-09-23 08:22:16 : [scan.firefox] - Reading C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\ij40lcbc.default\prefs.js 2016-09-23 08:22:16 : [scan.firefox] - Reading C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\ij40lcbc.default\user.js 2016-09-23 08:22:16 : [scan.firefox] - No profile to scan, skipping 2016-09-23 08:22:16 : [scan.firefox] - No profile to scan, skipping 2016-09-23 08:22:16 : [scan.firefox] - No profile to scan, skipping 2016-09-23 08:22:16 : [scan] - Progress: 94% 2016-09-23 08:22:16 : [scan.firefox] - Stopping Firefox based browsers scan [3] 2016-09-23 08:22:16 : [scan.firefox] - 0 malicious Firefox preferences found 2016-09-23 08:22:16 : [scan] - Progress: 95% 2016-09-23 08:22:16 : [main] - Chrome is installed: True 2016-09-23 08:22:16 : [scan.chromium] - Starting Chromium based browsers scan [1] 2016-09-23 08:22:20 : [scan.chromium] - Stopping Chromium based browsers scan [1] 2016-09-23 08:22:20 : [scan] - Progress: 97% 2016-09-23 08:22:20 : [scan.chromium] - Starting Chromium based browsers scan [2] 2016-09-23 08:22:20 : [scan.chromium] - No profile to scan, skipping 2016-09-23 08:22:20 : [scan.chromium] - Opening C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Web Data 2016-09-23 08:22:20 : [scan.chromium] - Closing C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Web Data 2016-09-23 08:22:20 : [scan.chromium] - Opening C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences 2016-09-23 08:22:21 : [scan.chromium] - No profile to scan, skipping 2016-09-23 08:22:21 : [scan.chromium] - No profile to scan, skipping 2016-09-23 08:22:21 : [scan.chromium] - No profile to scan, skipping 2016-09-23 08:22:21 : [scan.chromium] - No profile to scan, skipping 2016-09-23 08:22:21 : [scan.chromium] - No profile to scan, skipping 2016-09-23 08:22:21 : [scan.chromium] - Stopping Chromium based browsers scan [2] 2016-09-23 08:22:21 : [scan] - Progress: 99% 2016-09-23 08:22:21 : [scan.chromium] - Starting Chromium based browsers scan [3] 2016-09-23 08:22:21 : [scan.chromium] - Stopping Chromium based browsers scan [3] 2016-09-23 08:22:21 : [scan.chromium] - 0 malicious Chromium preferences elements found 2016-09-23 08:22:21 : [scan] - Progress: 100% 2016-09-23 08:22:21 : [scan] - Stopping scan 2016-09-23 09:05:28 : [main.gui] - Deleting temporary files before exiting 2016-09-23 09:05:29 : [main.gui] - >>>> EXITING <<<< 2016-09-23 09:05:49 : INFO [main] - >>>> STARTING <<<< 2016-09-23 09:05:49 : INFO [main] - RAM Usage: 47 2016-09-23 09:05:49 : INFO [main] - OS: WIN_10 X64 2016-09-23 09:05:49 : [main.language] - Checking the language 2016-09-23 09:05:49 : [main.language] - Language found: en 2016-09-23 09:05:49 : [main.network] - Checking the network connectivity 2016-09-23 09:05:49 : [main.network] - Network connectivity status: True 2016-09-23 09:05:49 : [main.eula] - Checking for EULA agreement 2016-09-23 09:05:49 : [main.network] - Check for updates 2016-09-23 09:05:49 : [main.network] - Requesting the last release number 2016-09-23 09:05:54 : [main.network] - The current version is up-to-date 2016-09-23 09:05:54 : [main.gui] - GUI setup 2016-09-23 09:05:54 : [main.gui] - Languages setup 2016-09-23 09:05:54 : [main] - Chrome is installed: True 2016-09-23 09:05:54 : [main] - Firefox is installed: True 2016-09-23 09:05:54 : [main.gui] - Showing the gui 2016-09-23 09:06:31 : [main.gui] - Scan requested 2016-09-23 09:06:31 : [scan] - Running from: C:\AdwCleaner 2016-09-23 09:06:31 : [scan] - Progress: 0% 2016-09-23 09:06:31 : [database] - Checking for database updates 2016-09-23 09:06:31 : [main.network] - Updating definitions 2016-09-23 09:07:01 : [main.network] - Saving the updated definitions 2016-09-23 09:07:01 : [main.network] - Requesting the lastest database release number 2016-09-23 09:07:02 : [main.network] - Latest definitions: 473226c94043f2b9b71cd5a080c4bf6f 2016-09-23 09:07:02 : [database] - Database update succeeded: 473226C94043F2B9B71CD5A080C4BF6F 2016-09-23 09:07:02 : [scan] - Progress: 5% 2016-09-23 09:07:02 : [database] - Initialize the database 2016-09-23 09:07:02 : [database] - Loading sqlite3.dll 2016-09-23 09:07:02 : [database] - Opening the database 2016-09-23 09:07:02 : [database] - Querying database's version 2016-09-23 09:07:02 : [database] - Loading internal data 2016-09-23 09:07:02 : [database] - Loading detections 2016-09-23 09:07:05 : [database] - Loading generics 2016-09-23 09:07:05 : [database] - Closing the database 2016-09-23 09:07:05 : [database] - Closing database 2016-09-23 09:07:05 : [database] - Unloading sqlite3.dll 2016-09-23 09:07:05 : [scan] - Progress: 15% 2016-09-23 09:07:05 : [scan.generic] - Generating generic detections 2016-09-23 09:07:05 : [scan.generic] - Generating generic detections [1] 2016-09-23 09:07:05 : [scan.generic] - Generating generic detections [2] 2016-09-23 09:07:05 : [scan.generic] - Generating generic detections [3] 2016-09-23 09:07:05 : [scan.generic] - Generating generic detections [4] 2016-09-23 09:07:05 : [scan.generic] - Generating generic detections [5] 2016-09-23 09:07:05 : [scan.generic] - Generating generic detections [6] 2016-09-23 09:07:05 : [scan.generic] - Generating generic detections [7] 2016-09-23 09:07:05 : [scan.generic] - Generating generic detections [8] 2016-09-23 09:07:05 : [scan.generic] - Generating generic detections [9] 2016-09-23 09:07:05 : [scan.generic] - Generating generic detections [10] 2016-09-23 09:07:05 : [scan.generic] - Generating generic detections [11] 2016-09-23 09:07:05 : [scan.generic] - Generating generic detections [12] 2016-09-23 09:07:05 : [scan.generic] - Generating generic detections [13] 2016-09-23 09:07:05 : [scan.generic] - Generating generic detections [14] 2016-09-23 09:07:05 : [scan.generic] - Generating generic detections [15] 2016-09-23 09:07:05 : [scan.generic] - Generating generic detections [16] 2016-09-23 09:07:05 : [scan.generic] - Generating generic detections [17] 2016-09-23 09:07:05 : [scan.generic] - Generating generic detections [18] 2016-09-23 09:07:05 : [scan.generic] - Generating generic detections [19] 2016-09-23 09:07:05 : [scan.generic] - Generating generic detections [20] 2016-09-23 09:07:05 : [scan.generic] - Generating generic detections [21] 2016-09-23 09:07:05 : [scan.generic] - Generating generic detections [22] 2016-09-23 09:07:05 : [scan.generic] - Generating generic detections [23] 2016-09-23 09:07:05 : [scan.generic] - Generating generic detections [24] 2016-09-23 09:07:05 : [scan.generic] - Generating generic detections [25] 2016-09-23 09:07:05 : [scan.generic] - Generating generic detections [26] 2016-09-23 09:07:05 : [scan.generic] - Generating generic detections [27] 2016-09-23 09:07:05 : [scan.generic] - Generating generic detections [28] 2016-09-23 09:07:05 : [scan.generic] - Generating generic detections [29] 2016-09-23 09:07:05 : [scan.generic] - Generating generic detections [30] 2016-09-23 09:07:05 : [scan.generic] - Generating generic detections [31] 2016-09-23 09:07:05 : [scan.generic] - Generating generic detections [32] 2016-09-23 09:07:05 : [scan.generic] - Generating generic detections [33] 2016-09-23 09:07:05 : [scan.generic] - Generating generic detections [34] 2016-09-23 09:07:05 : [scan.generic] - Generating generic detections [35] 2016-09-23 09:07:05 : [scan.generic] - Generating generic detections [36] 2016-09-23 09:07:05 : [scan.generic] - Generating generic detections [37] 2016-09-23 09:07:05 : [scan.generic] - Generating generic detections [38] 2016-09-23 09:07:05 : [scan.generic] - Generating generic detections [39] 2016-09-23 09:07:05 : [scan.generic] - Generating generic detections [40] 2016-09-23 09:07:05 : [scan.generic] - Generating generic detections [41] 2016-09-23 09:07:05 : [scan.generic] - Generating generic detections [42] 2016-09-23 09:07:05 : [scan.generic] - Generating generic detections [43] 2016-09-23 09:07:06 : [scan.generic] - Generating generic detections [44] 2016-09-23 09:07:06 : [scan.generic] - Generating generic detections [45] 2016-09-23 09:07:06 : [scan.generic] - Generic detections generated 2016-09-23 09:07:06 : [scan] - Progress: 20% 2016-09-23 09:07:06 : [scan.generic] - Starting generic analysis 2016-09-23 09:07:37 : [scan] - Progress: 30% 2016-09-23 09:07:37 : [scan.services] - Starting services scan [1] 2016-09-23 09:07:37 : [scan.services] - Stopping services scan [1] 2016-09-23 09:07:37 : [scan.services] - Starting services scan [2] 2016-09-23 09:07:37 : [scan.services] - Stopping services scan [2] 2016-09-23 09:07:37 : [scan.services] - 0 malicious services found 2016-09-23 09:07:37 : [scan] - Progress: 40% 2016-09-23 09:07:37 : [scan.folders] - Starting folders scan 2016-09-23 09:07:38 : [scan.folders] - Found C:\Users\Admin\AppData\Local\SweetLabs App Platform 2016-09-23 09:07:43 : [scan.folders] - Found C:\Users\Admin\AppData\Local\torch 2016-09-23 09:08:01 : [scan.folders] - Found C:\ProgramData\torchcrashhandler 2016-09-23 09:08:02 : [scan.folders] - Found C:\ProgramData\Application Data\torchcrashhandler 2016-09-23 09:08:14 : [scan.folders] - Found C:\Users\Default User\AppData\Local\Pokki 2016-09-23 09:08:14 : [scan.folders] - Found C:\Users\Default\AppData\Local\Pokki 2016-09-23 09:08:14 : [scan.folders] - Stopping folders scan 2016-09-23 09:08:14 : [scan.folders] - 6 malicious folders found 2016-09-23 09:08:14 : [scan] - Progress: 50% 2016-09-23 09:08:14 : [scan.files] - Starting files scan 2016-09-23 09:08:17 : [scan.files] - Found C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Torch.lnk 2016-09-23 09:08:17 : [scan.files] - Found C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk 2016-09-23 09:08:25 : [scan.files] - Stopping files scan 2016-09-23 09:08:25 : [scan.files] - 2 malicious files found 2016-09-23 09:08:25 : [scan] - Progress: 55% 2016-09-23 09:08:25 : [scan.dll] - Starting DLL scan 2016-09-23 09:08:25 : [scan.dll] - Stopping DLL scan 2016-09-23 09:08:25 : [scan.dll] - 0 malicious DLL found 2016-09-23 09:08:25 : [scan] - Progress: 60% 2016-09-23 09:08:25 : [scan.wmi] - Starting WMI scan 2016-09-23 09:08:26 : [scan.wmi] - Stopping WMI scan 2016-09-23 09:08:26 : [scan.wmi] - 0 malicious WMI found 2016-09-23 09:08:26 : [scan] - Progress: 65% 2016-09-23 09:08:26 : [scan.shortcuts] - Starting shortcuts scan 2016-09-23 09:08:57 : [scan.shortcuts] - Stopping shortcuts scan 2016-09-23 09:08:57 : [scan.shortcuts] - 0 malicious shortcuts found 2016-09-23 09:08:57 : [scan] - Progress: 70% 2016-09-23 09:08:57 : [scan.tasks] - Starting tasks scan 2016-09-23 09:08:57 : [scan.tasks] - Found SweetLabs App Platform 2016-09-23 09:08:58 : [scan.tasks] - Stopping tasks scan 2016-09-23 09:08:58 : [scan.tasks] - 1 malicious tasks found 2016-09-23 09:08:58 : [scan] - Progress: 75% 2016-09-23 09:08:58 : [scan.registry] - Starting registry scan [1] 2016-09-23 09:08:59 : [scan.registry] - Found Microsoft.IIsScriptHelper 2016-09-23 09:08:59 : [scan.registry] - Found Microsoft.IIsScriptHelper.1.0 2016-09-23 09:09:00 : [scan.registry] - Found Microsoft.IIsScriptHelper 2016-09-23 09:09:00 : [scan.registry] - Found Microsoft.IIsScriptHelper.1.0 2016-09-23 09:09:00 : [scan.registry] - Stopping registry scan [1] 2016-09-23 09:09:00 : [scan.registry] - Starting registry scan [2] 2016-09-23 09:09:05 : [scan.registry] - Found {6E993643-8FBC-44FE-BC85-D318495C4D96} 2016-09-23 09:09:05 : [scan.registry] - Found {A43DE495-3D00-47D4-9D2C-303115707939} 2016-09-23 09:09:14 : [scan.registry] - Stopping registry scan [2] 2016-09-23 09:09:14 : [scan.registry] - Starting registry scan [3] 2016-09-23 09:09:15 : [scan.registry] - Found SweetLabs App Platform 2016-09-23 09:09:15 : [scan.registry] - Found torch 2016-09-23 09:09:16 : [scan.registry] - Found SweetLabs_AP 2016-09-23 09:09:16 : [scan.registry] - Found SweetLabs_Start_Menu 2016-09-23 09:09:16 : [scan.registry] - Found torch 2016-09-23 09:09:21 : [scan.registry] - Found SweetLabs App Platform 2016-09-23 09:09:21 : [scan.registry] - Found torch 2016-09-23 09:09:22 : [scan.registry] - Found torch 2016-09-23 09:09:22 : [scan.registry] - Found SweetLabs_AP 2016-09-23 09:09:22 : [scan.registry] - Found SweetLabs_Start_Menu 2016-09-23 09:09:22 : [scan.registry] - Found torch 2016-09-23 09:09:23 : [scan.registry] - Found SweetLabs App Platform 2016-09-23 09:09:23 : [scan.registry] - Found torch 2016-09-23 09:09:23 : [scan.registry] - Found SweetLabs_AP 2016-09-23 09:09:23 : [scan.registry] - Found SweetLabs_Start_Menu 2016-09-23 09:09:23 : [scan.registry] - Found torch 2016-09-23 09:09:23 : [scan.registry] - Stopping registry scan [3] 2016-09-23 09:09:23 : [scan] - Progress: 80% 2016-09-23 09:09:23 : [scan.registry] - Starting registry scan [4] 2016-09-23 09:09:24 : [scan.registry] - Stopping registry scan [4] 2016-09-23 09:09:24 : [scan.registry] - Starting registry scan [5] 2016-09-23 09:09:24 : [scan.registry] - Stopping registry scan [5] 2016-09-23 09:09:24 : [scan] - Progress: 82% 2016-09-23 09:09:24 : [scan.registry] - Starting registry scan [6] 2016-09-23 09:09:24 : [scan.registry] - Stopping registry scan [6] 2016-09-23 09:09:24 : [scan.registry] - Starting registry scan [7] 2016-09-23 09:09:24 : [scan.registry] - Stopping registry scan [7] 2016-09-23 09:09:24 : [scan.registry] - Starting registry scan [8] 2016-09-23 09:09:24 : [scan.registry] - Stopping registry scan [8] 2016-09-23 09:09:24 : [scan] - Progress: 84% 2016-09-23 09:09:24 : [scan.registry] - Starting registry scan [9] 2016-09-23 09:09:24 : [scan.registry] - Stopping registry scan [9] 2016-09-23 09:09:24 : [scan.registry] - Starting registry scan [10] 2016-09-23 09:09:24 : [scan.registry] - Stopping registry scan [10] 2016-09-23 09:09:24 : [scan.registry] - Starting registry scan [11] 2016-09-23 09:09:24 : [scan.registry] - Stopping registry scan [11] 2016-09-23 09:09:24 : [scan.registry] - Starting registry scan [12] 2016-09-23 09:09:24 : [scan.registry] - Stopping registry scan [12] 2016-09-23 09:09:24 : [scan.registry] - Starting registry scan [13] 2016-09-23 09:09:24 : [scan.registry] - Stopping registry scan [13] 2016-09-23 09:09:24 : [scan.registry] - Starting registry scan [14] 2016-09-23 09:09:24 : [scan.registry] - Stopping registry scan [14] 2016-09-23 09:09:24 : [scan.registry] - Starting registry scan [15] 2016-09-23 09:09:24 : [scan.registry] - Stopping registry scan [15] 2016-09-23 09:09:24 : [scan.registry] - Starting registry scan [16] 2016-09-23 09:09:24 : [scan.registry] - Stopping registry scan [16] 2016-09-23 09:09:24 : [scan.registry] - Starting registry scan [17] 2016-09-23 09:09:24 : [scan.registry] - Stopping registry scan [17] 2016-09-23 09:09:24 : [scan.registry] - Starting registry scan [18] 2016-09-23 09:09:25 : [scan.registry] - Stopping registry scan [18] 2016-09-23 09:09:25 : [scan] - Progress: 86% 2016-09-23 09:09:25 : [scan.registry] - Starting registry scan [19] 2016-09-23 09:09:25 : [scan.registry] - Found HKCU\Software\Classes\AllFileSystemObjects\shell\pokki 2016-09-23 09:09:25 : [scan.registry] - Found HKCU\Software\Classes\Directory\shell\pokki 2016-09-23 09:09:25 : [scan.registry] - Found HKCU\Software\Classes\Drive\shell\pokki 2016-09-23 09:09:25 : [scan.registry] - Found HKCU\Software\Classes\lnkfile\shell\pokki 2016-09-23 09:09:25 : [scan.registry] - Found HKCU\Software\MozillaPlugins\TorchVLC 2016-09-23 09:09:25 : [scan.registry] - Found HKLM\SOFTWARE\Classes\Applications\Torch.exe 2016-09-23 09:09:25 : [scan.registry] - Found HKLM\SOFTWARE\Clients\StartMenuInternet\Torch 2016-09-23 09:09:25 : [scan.registry] - Found HKLM\SOFTWARE\Classes\f 2016-09-23 09:09:25 : [scan.registry] - Stopping registry scan [19] 2016-09-23 09:09:25 : [scan] - Progress: 88% 2016-09-23 09:09:25 : [scan.registry] - 30 malicious registry element found 2016-09-23 09:09:25 : [scan] - Progress: 90% 2016-09-23 09:09:26 : [main] - Firefox is installed: True 2016-09-23 09:09:26 : [scan.firefox] - Starting Firefox based browsers scan [1] 2016-09-23 09:09:42 : [scan.firefox] - Stopping Firefox based browsers scan [1] 2016-09-23 09:09:42 : [scan.firefox] - Starting Firefox based browsers scan [2] 2016-09-23 09:09:44 : [scan.firefox] - Stopping Firefox based browsers scan [2] 2016-09-23 09:09:44 : [scan] - Progress: 92% 2016-09-23 09:09:44 : [scan.firefox] - Starting Firefox based browsers scan [3] 2016-09-23 09:09:44 : [scan.firefox] - Reading C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\ij40lcbc.default\prefs.js 2016-09-23 09:09:44 : [scan.firefox] - Reading C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\ij40lcbc.default\user.js 2016-09-23 09:09:44 : [scan.firefox] - No profile to scan, skipping 2016-09-23 09:09:44 : [scan.firefox] - No profile to scan, skipping 2016-09-23 09:09:44 : [scan.firefox] - No profile to scan, skipping 2016-09-23 09:09:44 : [scan] - Progress: 94% 2016-09-23 09:09:44 : [scan.firefox] - Stopping Firefox based browsers scan [3] 2016-09-23 09:09:44 : [scan.firefox] - 0 malicious Firefox preferences found 2016-09-23 09:09:44 : [scan] - Progress: 95% 2016-09-23 09:09:44 : [main] - Chrome is installed: True 2016-09-23 09:09:44 : [scan.chromium] - Starting Chromium based browsers scan [1] 2016-09-23 09:09:47 : [scan.chromium] - Stopping Chromium based browsers scan [1] 2016-09-23 09:09:47 : [scan] - Progress: 97% 2016-09-23 09:09:47 : [scan.chromium] - Starting Chromium based browsers scan [2] 2016-09-23 09:09:48 : [scan.chromium] - No profile to scan, skipping 2016-09-23 09:09:48 : [scan.chromium] - Opening C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Web Data 2016-09-23 09:09:48 : [scan.chromium] - Found C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] uk.ask.com 2016-09-23 09:09:48 : [scan.chromium] - Found C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] vlc-media-player.en.softonic.com 2016-09-23 09:09:48 : [scan.chromium] - Found C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] blackberry-desktop-software.en.softonic.com 2016-09-23 09:09:48 : [scan.chromium] - Closing C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Web Data 2016-09-23 09:09:48 : [scan.chromium] - Opening C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences 2016-09-23 09:09:49 : [scan.chromium] - No profile to scan, skipping 2016-09-23 09:09:49 : [scan.chromium] - No profile to scan, skipping 2016-09-23 09:09:49 : [scan.chromium] - No profile to scan, skipping 2016-09-23 09:09:49 : [scan.chromium] - No profile to scan, skipping 2016-09-23 09:09:49 : [scan.chromium] - No profile to scan, skipping 2016-09-23 09:09:49 : [scan.chromium] - Stopping Chromium based browsers scan [2] 2016-09-23 09:09:49 : [scan] - Progress: 99% 2016-09-23 09:09:49 : [scan.chromium] - Starting Chromium based browsers scan [3] 2016-09-23 09:09:50 : [scan.chromium] - Stopping Chromium based browsers scan [3] 2016-09-23 09:09:50 : [scan.chromium] - 3 malicious Chromium preferences elements found 2016-09-23 09:09:50 : [scan] - Progress: 100% 2016-09-23 09:09:50 : [scan] - Stopping scan 2016-09-23 09:11:19 : [main.gui] - Clean requested 2016-09-23 09:11:25 : [main.gui] - Killing all processes 2016-09-23 09:11:25 : [main] - Killing [System Process](0) 2016-09-23 09:11:25 : [main] - Killing System(4) 2016-09-23 09:11:25 : [main] - smss.exe - (4) not killed - whitelisted 2016-09-23 09:11:25 : [main] - csrss.exe - (4) not killed - whitelisted 2016-09-23 09:11:25 : [main] - wininit.exe - (4) not killed - whitelisted 2016-09-23 09:11:25 : [main] - services.exe - (4) not killed - whitelisted 2016-09-23 09:11:25 : [main] - lsass.exe - (4) not killed - whitelisted 2016-09-23 09:11:25 : [main] - svchost.exe - (4) not killed - whitelisted 2016-09-23 09:11:25 : [main] - svchost.exe - (4) not killed - whitelisted 2016-09-23 09:11:25 : [main] - svchost.exe - (4) not killed - whitelisted 2016-09-23 09:11:25 : [main] - Killing WUDFHost.exe(1028) 2016-09-23 09:11:25 : [main] - Killing hmpalert.exe(1160) 2016-09-23 09:11:25 : [main] - svchost.exe - (1160) not killed - whitelisted 2016-09-23 09:11:25 : [main] - svchost.exe - (1160) not killed - whitelisted 2016-09-23 09:11:25 : [main] - svchost.exe - (1160) not killed - whitelisted 2016-09-23 09:11:25 : [main] - svchost.exe - (1160) not killed - whitelisted 2016-09-23 09:11:25 : [main] - Killing igfxCUIService.exe(1632) 2016-09-23 09:11:25 : [main] - svchost.exe - (1632) not killed - whitelisted 2016-09-23 09:11:25 : [main] - svchost.exe - (1632) not killed - whitelisted 2016-09-23 09:11:25 : [main] - svchost.exe - (1632) not killed - whitelisted 2016-09-23 09:11:25 : [main] - dasHost.exe - (1632) not killed - whitelisted 2016-09-23 09:11:25 : [main] - svchost.exe - (1632) not killed - whitelisted 2016-09-23 09:11:25 : [main] - Killing spoolsv.exe(2036) 2016-09-23 09:11:26 : [main] - svchost.exe - (2036) not killed - whitelisted 2016-09-23 09:11:26 : [main] - Killing OfficeClickToRun.exe(2368) 2016-09-23 09:11:26 : [main] - Killing BtwRSupportService.exe(2376) 2016-09-23 09:11:26 : [main] - Killing mqsvc.exe(2404) 2016-09-23 09:11:26 : [main] - Killing HuaweiHiSuiteService64.exe(2412) 2016-09-23 09:11:26 : [main] - Killing CxAudMsg64.exe(2420) 2016-09-23 09:11:26 : [main] - svchost.exe - (2420) not killed - whitelisted 2016-09-23 09:11:26 : [main] - Killing NLSSRV32.EXE(2452) 2016-09-23 09:11:26 : [main] - Killing HeciServer.exe(2484) 2016-09-23 09:11:26 : [main] - svchost.exe - (2484) not killed - whitelisted 2016-09-23 09:11:26 : [main] - Killing mbamscheduler.exe(2516) 2016-09-23 09:11:27 : [main] - Killing RichVideo64.exe(2524) 2016-09-23 09:11:27 : [main] - svchost.exe - (2524) not killed - whitelisted 2016-09-23 09:11:27 : [main] - Killing SynTPEnhService.exe(2548) 2016-09-23 09:11:27 : [main] - Killing sqlwriter.exe(2556) 2016-09-23 09:11:27 : [main] - Killing MsMpEng.exe(2572) 2016-09-23 09:11:27 : [main] - Killing webservd.exe(2580) 2016-09-23 09:11:27 : [main] - Killing NitroPDFDriverService8x64.exe(2588) 2016-09-23 09:11:28 : [main] - Killing SDUpdSvc.exe(2628) 2016-09-23 09:11:28 : [main] - Killing inetinfo.exe(2636) 2016-09-23 09:11:28 : [main] - svchost.exe - (2636) not killed - whitelisted 2016-09-23 09:11:28 : [main] - Killing mbamservice.exe(2684) 2016-09-23 09:11:28 : [main] - Killing SDWSCSvc.exe(2792) 2016-09-23 09:11:28 : [main] - Killing Memory Compression(2808) 2016-09-23 09:11:28 : [main] - Killing webcategory.exe(3184) 2016-09-23 09:11:28 : [main] - conhost.exe - (3184) not killed - whitelisted 2016-09-23 09:11:28 : [main] - svchost.exe - (3184) not killed - whitelisted 2016-09-23 09:11:28 : [main] - SMSvcHost.exe - (3184) not killed - whitelisted 2016-09-23 09:11:28 : [main] - SMSvcHost.exe - (3184) not killed - whitelisted 2016-09-23 09:11:28 : [main] - Killing NisSrv.exe(4000) 2016-09-23 09:11:28 : [main] - Killing HPSupportSolutionsFrameworkService.exe(2476) 2016-09-23 09:11:28 : [main] - Killing GoogleCrashHandler.exe(5128) 2016-09-23 09:11:29 : [main] - Killing GoogleCrashHandler64.exe(5304) 2016-09-23 09:11:29 : [main] - Killing IAStorDataMgrSvc.exe(5172) 2016-09-23 09:11:29 : [main] - WmiPrvSE.exe - (5172) not killed - whitelisted 2016-09-23 09:11:29 : [main] - Killing jhi_service.exe(812) 2016-09-23 09:11:29 : [main] - Killing SearchIndexer.exe(2880) 2016-09-23 09:11:29 : [main] - csrss.exe - (2880) not killed - whitelisted 2016-09-23 09:11:29 : [main] - winlogon.exe - (2880) not killed - whitelisted 2016-09-23 09:11:29 : [main] - dwm.exe - (2880) not killed - whitelisted 2016-09-23 09:11:29 : [main] - userAgent.exe - (2880) not killed - whitelisted 2016-09-23 09:11:29 : [main] - conhost.exe - (2880) not killed - whitelisted 2016-09-23 09:11:29 : [main] - Killing hmpalert.exe(5488) 2016-09-23 09:11:29 : [main] - Killing mbamgui.exe(552) 2016-09-23 09:11:29 : [main] - svchost.exe - (552) not killed - whitelisted 2016-09-23 09:11:29 : [main] - sihost.exe - (552) not killed - whitelisted 2016-09-23 09:11:29 : [main] - Killing taskhostw.exe(4248) 2016-09-23 09:11:29 : [main] - Killing PresentationFontCache.exe(4500) 2016-09-23 09:11:29 : [main] - Killing SynTPEnh.exe(3092) 2016-09-23 09:11:29 : [main] - Killing RuntimeBroker.exe(6364) 2016-09-23 09:11:29 : [main] - Killing ServiceHostAppUpdater.exe(5084) 2016-09-23 09:11:29 : [main] - explorer.exe - (5084) not killed - whitelisted 2016-09-23 09:11:29 : [main] - Killing igfxEM.exe(6156) 2016-09-23 09:11:29 : [main] - Killing igfxHK.exe(4888) 2016-09-23 09:11:30 : [main] - Killing MagicPlus_helper.exe(5568) 2016-09-23 09:11:30 : [main] - Killing igfxTray.exe(4640) 2016-09-23 09:11:30 : [main] - Killing PDVD10Serv.exe(8072) 2016-09-23 09:11:30 : [main] - Killing SynTPHelper.exe(6704) 2016-09-23 09:11:30 : [main] - Killing ShellExperienceHost.exe(3852) 2016-09-23 09:11:31 : [main] - SearchUI.exe - (3852) not killed - whitelisted 2016-09-23 09:11:31 : [main] - Killing SettingSyncHost.exe(8884) 2016-09-23 09:11:31 : [main] - Killing CAudioFilterAgent64.exe(9204) 2016-09-23 09:11:31 : [main] - Killing RTFTrack.exe(8984) 2016-09-23 09:11:31 : [main] - Killing Energy Manager.exe(8948) 2016-09-23 09:11:31 : [main] - Killing CDASrv.exe(8280) 2016-09-23 09:11:31 : [main] - Killing MSASCuiL.exe(8800) 2016-09-23 09:11:31 : [main] - Killing WZUpdateNotifier.exe(8676) 2016-09-23 09:11:32 : [main] - Killing wfc.exe(6944) 2016-09-23 09:11:32 : [main] - Killing FAHWindow32.exe(8316) 2016-09-23 09:11:32 : [main] - Killing FAHWindow64.exe(4192) 2016-09-23 09:11:32 : [main] - Killing PWRISOVM.EXE(8228) 2016-09-23 09:11:32 : [main] - Killing WzPreloader.exe(5896) 2016-09-23 09:11:32 : [main] - javaw.exe - (5896) not killed - whitelisted 2016-09-23 09:11:32 : [main] - Killing SDTray.exe(9004) 2016-09-23 09:11:32 : [main] - InstallAgent.exe - (9004) not killed - whitelisted 2016-09-23 09:11:32 : [main] - Killing LSCNotify.exe(7600) 2016-09-23 09:11:32 : [main] - Killing InstallAgentUserBroker.exe(5592) 2016-09-23 09:11:32 : [main] - Killing IAStorIcon.exe(8212) 2016-09-23 09:11:33 : [main] - Killing SkypeHost.exe(9276) 2016-09-23 09:11:33 : [main] - Killing ServiceHostApp.exe(9340) 2016-09-23 09:11:33 : [main] - Killing ServiceHostApp.exe(9340) 2016-09-23 09:11:34 : [main] - ServiceStartMenuIndexer.exe - (9340) not killed - whitelisted 2016-09-23 09:11:34 : [main] - Killing IDMan.exe(9516) 2016-09-23 09:11:34 : [main] - Killing IEMonitor.exe(1236) 2016-09-23 09:11:34 : [main] - explorer.exe - (1236) not killed - whitelisted 2016-09-23 09:11:34 : [main] - Killing dllhost.exe(6080) 2016-09-23 09:11:34 : [main] - explorer.exe - (6080) not killed - whitelisted 2016-09-23 09:11:34 : [main] - Killing SDUpdate.exe(4036) 2016-09-23 09:11:35 : [main] - Killing OfficeC2RClient.exe(2960) 2016-09-23 09:11:35 : [main] - Killing VSSVC.exe(12448) 2016-09-23 09:11:35 : [main] - svchost.exe - (12448) not killed - whitelisted 2016-09-23 09:11:35 : [main] - Killing SearchProtocolHost.exe(5584) 2016-09-23 09:11:35 : [main] - Killing startsys.exe(7236) 2016-09-23 09:11:35 : [main] - Killing SearchFilterHost.exe(12336) 2016-09-23 09:11:35 : [main] - conhost.exe - (12336) not killed - whitelisted 2016-09-23 09:11:35 : [main] - Killing rundll32.exe(11156) 2016-09-23 09:11:35 : [main] - Killing GoogleUpdate.exe(12960) 2016-09-23 09:11:35 : [main] - Killing GoogleUpdate.exe(4408) 2016-09-23 09:11:36 : [main] - Killing rundll32.exe(7792) 2016-09-23 09:11:36 : [main] - smartscreen.exe - (7792) not killed - whitelisted 2016-09-23 09:11:36 : [main] - Killing audiodg.exe(4208) 2016-09-23 09:11:36 : [main] - Killing GoogleUpdate.exe(4408) 2016-09-23 09:11:36 : [main] - Killing GoogleCrashHandler.exe(4292) 2016-09-23 09:11:37 : [main] - Killing GoogleCrashHandler64.exe(6888) 2016-09-23 09:11:37 : [main] - Killing 54.0.2840.34_54.0.2840.27_chrome_updater.exe(10944) 2016-09-23 09:11:37 : [main] - Killing setup.exe(9572) 2016-09-23 09:11:37 : [main] - Killing setup.exe(0) 2016-09-23 09:11:37 : [main] - Killing backgroundTaskHost.exe(9452) 2016-09-23 11:40:20 : INFO [main] - >>>> STARTING <<<< 2016-09-23 11:40:20 : INFO [main] - RAM Usage: 54 2016-09-23 11:40:20 : INFO [main] - OS: WIN_10 X64 2016-09-23 11:40:20 : [main.language] - Checking the language 2016-09-23 11:40:20 : [main.language] - Language found: en 2016-09-23 11:40:20 : [main.network] - Checking the network connectivity 2016-09-23 11:40:20 : [main.network] - Network connectivity status: True 2016-09-23 11:40:20 : [main.eula] - Checking for EULA agreement 2016-09-23 11:40:20 : [main.network] - Check for updates 2016-09-23 11:40:20 : [main.network] - Requesting the last release number 2016-09-23 11:40:25 : [main.network] - The current version is up-to-date 2016-09-23 11:40:25 : [main.gui] - GUI setup 2016-09-23 11:40:25 : [main.gui] - Languages setup 2016-09-23 11:40:25 : [main] - Chrome is installed: True 2016-09-23 11:40:25 : [main] - Firefox is installed: True 2016-09-23 11:40:25 : [main.gui] - Showing the gui 2016-09-23 11:40:28 : [main.gui] - Scan requested 2016-09-23 11:40:28 : [scan] - Running from: C:\AdwCleaner 2016-09-23 11:40:28 : [scan] - Progress: 0% 2016-09-23 11:40:28 : [database] - Checking for database updates 2016-09-23 11:40:28 : [main.network] - Updating definitions 2016-09-23 11:40:43 : [main.network] - Saving the updated definitions 2016-09-23 11:40:43 : [main.network] - Requesting the lastest database release number 2016-09-23 11:40:43 : [main.network] - Latest definitions: 473226c94043f2b9b71cd5a080c4bf6f 2016-09-23 11:40:43 : [database] - Database update succeeded: 473226C94043F2B9B71CD5A080C4BF6F 2016-09-23 11:40:43 : [scan] - Progress: 5% 2016-09-23 11:40:43 : [database] - Initialize the database 2016-09-23 11:40:43 : [database] - Loading sqlite3.dll 2016-09-23 11:40:43 : [database] - Opening the database 2016-09-23 11:40:43 : [database] - Querying database's version 2016-09-23 11:40:43 : [database] - Loading internal data 2016-09-23 11:40:43 : [database] - Loading detections 2016-09-23 11:40:47 : [database] - Loading generics 2016-09-23 11:40:47 : [database] - Closing the database 2016-09-23 11:40:47 : [database] - Closing database 2016-09-23 11:40:47 : [database] - Unloading sqlite3.dll 2016-09-23 11:40:47 : [scan] - Progress: 15% 2016-09-23 11:40:47 : [scan.generic] - Generating generic detections 2016-09-23 11:40:47 : [scan.generic] - Generating generic detections [1] 2016-09-23 11:40:47 : [scan.generic] - Generating generic detections [2] 2016-09-23 11:40:47 : [scan.generic] - Generating generic detections [3] 2016-09-23 11:40:47 : [scan.generic] - Generating generic detections [4] 2016-09-23 11:40:47 : [scan.generic] - Generating generic detections [5] 2016-09-23 11:40:47 : [scan.generic] - Generating generic detections [6] 2016-09-23 11:40:47 : [scan.generic] - Generating generic detections [7] 2016-09-23 11:40:47 : [scan.generic] - Generating generic detections [8] 2016-09-23 11:40:47 : [scan.generic] - Generating generic detections [9] 2016-09-23 11:40:47 : [scan.generic] - Generating generic detections [10] 2016-09-23 11:40:47 : [scan.generic] - Generating generic detections [11] 2016-09-23 11:40:47 : [scan.generic] - Generating generic detections [12] 2016-09-23 11:40:47 : [scan.generic] - Generating generic detections [13] 2016-09-23 11:40:47 : [scan.generic] - Generating generic detections [14] 2016-09-23 11:40:47 : [scan.generic] - Generating generic detections [15] 2016-09-23 11:40:47 : [scan.generic] - Generating generic detections [16] 2016-09-23 11:40:47 : [scan.generic] - Generating generic detections [17] 2016-09-23 11:40:47 : [scan.generic] - Generating generic detections [18] 2016-09-23 11:40:47 : [scan.generic] - Generating generic detections [19] 2016-09-23 11:40:47 : [scan.generic] - Generating generic detections [20] 2016-09-23 11:40:47 : [scan.generic] - Generating generic detections [21] 2016-09-23 11:40:47 : [scan.generic] - Generating generic detections [22] 2016-09-23 11:40:47 : [scan.generic] - Generating generic detections [23] 2016-09-23 11:40:47 : [scan.generic] - Generating generic detections [24] 2016-09-23 11:40:47 : [scan.generic] - Generating generic detections [25] 2016-09-23 11:40:47 : [scan.generic] - Generating generic detections [26] 2016-09-23 11:40:47 : [scan.generic] - Generating generic detections [27] 2016-09-23 11:40:47 : [scan.generic] - Generating generic detections [28] 2016-09-23 11:40:47 : [scan.generic] - Generating generic detections [29] 2016-09-23 11:40:47 : [scan.generic] - Generating generic detections [30] 2016-09-23 11:40:47 : [scan.generic] - Generating generic detections [31] 2016-09-23 11:40:47 : [scan.generic] - Generating generic detections [32] 2016-09-23 11:40:47 : [scan.generic] - Generating generic detections [33] 2016-09-23 11:40:47 : [scan.generic] - Generating generic detections [34] 2016-09-23 11:40:47 : [scan.generic] - Generating generic detections [35] 2016-09-23 11:40:47 : [scan.generic] - Generating generic detections [36] 2016-09-23 11:40:47 : [scan.generic] - Generating generic detections [37] 2016-09-23 11:40:47 : [scan.generic] - Generating generic detections [38] 2016-09-23 11:40:47 : [scan.generic] - Generating generic detections [39] 2016-09-23 11:40:47 : [scan.generic] - Generating generic detections [40] 2016-09-23 11:40:47 : [scan.generic] - Generating generic detections [41] 2016-09-23 11:40:47 : [scan.generic] - Generating generic detections [42] 2016-09-23 11:40:47 : [scan.generic] - Generating generic detections [43] 2016-09-23 11:40:47 : [scan.generic] - Generating generic detections [44] 2016-09-23 11:40:47 : [scan.generic] - Generating generic detections [45] 2016-09-23 11:40:47 : [scan.generic] - Generic detections generated 2016-09-23 11:40:47 : [scan] - Progress: 20% 2016-09-23 11:40:47 : [scan.generic] - Starting generic analysis 2016-09-23 11:40:58 : [scan] - Progress: 30% 2016-09-23 11:40:58 : [scan.services] - Starting services scan [1] 2016-09-23 11:40:58 : [scan.services] - Stopping services scan [1] 2016-09-23 11:40:58 : [scan.services] - Starting services scan [2] 2016-09-23 11:40:59 : [scan.services] - Stopping services scan [2] 2016-09-23 11:40:59 : [scan.services] - 0 malicious services found 2016-09-23 11:40:59 : [scan] - Progress: 40% 2016-09-23 11:40:59 : [scan.folders] - Starting folders scan 2016-09-23 11:41:00 : [scan.folders] - Found C:\Users\Admin\AppData\Local\SweetLabs App Platform 2016-09-23 11:41:00 : [scan.folders] - Found C:\Users\Admin\AppData\Local\torch 2016-09-23 11:41:19 : [scan.folders] - Found C:\ProgramData\torchcrashhandler 2016-09-23 11:41:20 : [scan.folders] - Found C:\ProgramData\Application Data\torchcrashhandler 2016-09-23 11:41:33 : [scan.folders] - Found C:\Users\Default User\AppData\Local\Pokki 2016-09-23 11:41:33 : [scan.folders] - Found C:\Users\Default\AppData\Local\Pokki 2016-09-23 11:41:33 : [scan.folders] - Stopping folders scan 2016-09-23 11:41:33 : [scan.folders] - 6 malicious folders found 2016-09-23 11:41:33 : [scan] - Progress: 50% 2016-09-23 11:41:33 : [scan.files] - Starting files scan 2016-09-23 11:41:36 : [scan.files] - Found C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Torch.lnk 2016-09-23 11:41:36 : [scan.files] - Found C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk 2016-09-23 11:41:43 : [scan.files] - Stopping files scan 2016-09-23 11:41:43 : [scan.files] - 2 malicious files found 2016-09-23 11:41:43 : [scan] - Progress: 55% 2016-09-23 11:41:43 : [scan.dll] - Starting DLL scan 2016-09-23 11:41:43 : [scan.dll] - Stopping DLL scan 2016-09-23 11:41:43 : [scan.dll] - 0 malicious DLL found 2016-09-23 11:41:43 : [scan] - Progress: 60% 2016-09-23 11:41:43 : [scan.wmi] - Starting WMI scan 2016-09-23 11:41:43 : [scan.wmi] - Stopping WMI scan 2016-09-23 11:41:43 : [scan.wmi] - 0 malicious WMI found 2016-09-23 11:41:43 : [scan] - Progress: 65% 2016-09-23 11:41:43 : [scan.shortcuts] - Starting shortcuts scan 2016-09-23 11:41:45 : [scan.shortcuts] - Stopping shortcuts scan 2016-09-23 11:41:45 : [scan.shortcuts] - 0 malicious shortcuts found 2016-09-23 11:41:45 : [scan] - Progress: 70% 2016-09-23 11:41:45 : [scan.tasks] - Starting tasks scan 2016-09-23 11:41:46 : [scan.tasks] - Stopping tasks scan 2016-09-23 11:41:46 : [scan.tasks] - 0 malicious tasks found 2016-09-23 11:41:46 : [scan] - Progress: 75% 2016-09-23 11:41:46 : [scan.registry] - Starting registry scan [1] 2016-09-23 11:41:47 : [scan.registry] - Found Microsoft.IIsScriptHelper 2016-09-23 11:41:47 : [scan.registry] - Found Microsoft.IIsScriptHelper.1.0 2016-09-23 11:41:48 : [scan.registry] - Found Microsoft.IIsScriptHelper 2016-09-23 11:41:48 : [scan.registry] - Found Microsoft.IIsScriptHelper.1.0 2016-09-23 11:41:49 : [scan.registry] - Stopping registry scan [1] 2016-09-23 11:41:49 : [scan.registry] - Starting registry scan [2] 2016-09-23 11:41:51 : [scan.registry] - Found {6E993643-8FBC-44FE-BC85-D318495C4D96} 2016-09-23 11:41:51 : [scan.registry] - Found {A43DE495-3D00-47D4-9D2C-303115707939} 2016-09-23 11:42:01 : [scan.registry] - Stopping registry scan [2] 2016-09-23 11:42:01 : [scan.registry] - Starting registry scan [3] 2016-09-23 11:42:02 : [scan.registry] - Found SweetLabs App Platform 2016-09-23 11:42:02 : [scan.registry] - Found torch 2016-09-23 11:42:03 : [scan.registry] - Found SweetLabs_AP 2016-09-23 11:42:03 : [scan.registry] - Found SweetLabs_Start_Menu 2016-09-23 11:42:03 : [scan.registry] - Found torch 2016-09-23 11:42:04 : [scan.registry] - Found SweetLabs App Platform 2016-09-23 11:42:04 : [scan.registry] - Found torch 2016-09-23 11:42:04 : [scan.registry] - Found torch 2016-09-23 11:42:04 : [scan.registry] - Found SweetLabs_AP 2016-09-23 11:42:04 : [scan.registry] - Found SweetLabs_Start_Menu 2016-09-23 11:42:04 : [scan.registry] - Found torch 2016-09-23 11:42:05 : [scan.registry] - Found SweetLabs App Platform 2016-09-23 11:42:05 : [scan.registry] - Found torch 2016-09-23 11:42:05 : [scan.registry] - Found SweetLabs_AP 2016-09-23 11:42:06 : [scan.registry] - Found SweetLabs_Start_Menu 2016-09-23 11:42:06 : [scan.registry] - Found torch 2016-09-23 11:42:06 : [scan.registry] - Stopping registry scan [3] 2016-09-23 11:42:06 : [scan] - Progress: 80% 2016-09-23 11:42:06 : [scan.registry] - Starting registry scan [4] 2016-09-23 11:42:06 : [scan.registry] - Stopping registry scan [4] 2016-09-23 11:42:06 : [scan.registry] - Starting registry scan [5] 2016-09-23 11:42:06 : [scan.registry] - Stopping registry scan [5] 2016-09-23 11:42:06 : [scan] - Progress: 82% 2016-09-23 11:42:06 : [scan.registry] - Starting registry scan [6] 2016-09-23 11:42:06 : [scan.registry] - Stopping registry scan [6] 2016-09-23 11:42:06 : [scan.registry] - Starting registry scan [7] 2016-09-23 11:42:06 : [scan.registry] - Stopping registry scan [7] 2016-09-23 11:42:06 : [scan.registry] - Starting registry scan [8] 2016-09-23 11:42:06 : [scan.registry] - Stopping registry scan [8] 2016-09-23 11:42:06 : [scan] - Progress: 84% 2016-09-23 11:42:06 : [scan.registry] - Starting registry scan [9] 2016-09-23 11:42:06 : [scan.registry] - Stopping registry scan [9] 2016-09-23 11:42:06 : [scan.registry] - Starting registry scan [10] 2016-09-23 11:42:06 : [scan.registry] - Stopping registry scan [10] 2016-09-23 11:42:06 : [scan.registry] - Starting registry scan [11] 2016-09-23 11:42:06 : [scan.registry] - Stopping registry scan [11] 2016-09-23 11:42:06 : [scan.registry] - Starting registry scan [12] 2016-09-23 11:42:06 : [scan.registry] - Stopping registry scan [12] 2016-09-23 11:42:06 : [scan.registry] - Starting registry scan [13] 2016-09-23 11:42:06 : [scan.registry] - Stopping registry scan [13] 2016-09-23 11:42:06 : [scan.registry] - Starting registry scan [14] 2016-09-23 11:42:06 : [scan.registry] - Stopping registry scan [14] 2016-09-23 11:42:06 : [scan.registry] - Starting registry scan [15] 2016-09-23 11:42:06 : [scan.registry] - Stopping registry scan [15] 2016-09-23 11:42:06 : [scan.registry] - Starting registry scan [16] 2016-09-23 11:42:06 : [scan.registry] - Stopping registry scan [16] 2016-09-23 11:42:06 : [scan.registry] - Starting registry scan [17] 2016-09-23 11:42:07 : [scan.registry] - Stopping registry scan [17] 2016-09-23 11:42:07 : [scan.registry] - Starting registry scan [18] 2016-09-23 11:42:07 : [scan.registry] - Stopping registry scan [18] 2016-09-23 11:42:07 : [scan] - Progress: 86% 2016-09-23 11:42:07 : [scan.registry] - Starting registry scan [19] 2016-09-23 11:42:07 : [scan.registry] - Found HKCU\Software\Classes\AllFileSystemObjects\shell\pokki 2016-09-23 11:42:07 : [scan.registry] - Found HKCU\Software\Classes\Directory\shell\pokki 2016-09-23 11:42:07 : [scan.registry] - Found HKCU\Software\Classes\Drive\shell\pokki 2016-09-23 11:42:07 : [scan.registry] - Found HKCU\Software\Classes\lnkfile\shell\pokki 2016-09-23 11:42:07 : [scan.registry] - Found HKCU\Software\MozillaPlugins\TorchVLC 2016-09-23 11:42:07 : [scan.registry] - Found HKLM\SOFTWARE\Classes\Applications\Torch.exe 2016-09-23 11:42:07 : [scan.registry] - Found HKLM\SOFTWARE\Clients\StartMenuInternet\Torch 2016-09-23 11:42:07 : [scan.registry] - Found HKLM\SOFTWARE\Classes\f 2016-09-23 11:42:07 : [scan.registry] - Stopping registry scan [19] 2016-09-23 11:42:07 : [scan] - Progress: 88% 2016-09-23 11:42:07 : [scan.registry] - 30 malicious registry element found 2016-09-23 11:42:07 : [scan] - Progress: 90% 2016-09-23 11:42:07 : [main] - Firefox is installed: True 2016-09-23 11:42:07 : [scan.firefox] - Starting Firefox based browsers scan [1] 2016-09-23 11:42:23 : [scan.firefox] - Stopping Firefox based browsers scan [1] 2016-09-23 11:42:23 : [scan.firefox] - Starting Firefox based browsers scan [2] 2016-09-23 11:42:25 : [scan.firefox] - Stopping Firefox based browsers scan [2] 2016-09-23 11:42:25 : [scan] - Progress: 92% 2016-09-23 11:42:25 : [scan.firefox] - Starting Firefox based browsers scan [3] 2016-09-23 11:42:25 : [scan.firefox] - Reading C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\ij40lcbc.default\prefs.js 2016-09-23 11:42:25 : [scan.firefox] - Reading C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\ij40lcbc.default\user.js 2016-09-23 11:42:25 : [scan.firefox] - Found "network.http.request.max-start-delay" - 0 2016-09-23 11:42:25 : [scan.firefox] - No profile to scan, skipping 2016-09-23 11:42:25 : [scan.firefox] - No profile to scan, skipping 2016-09-23 11:42:25 : [scan.firefox] - No profile to scan, skipping 2016-09-23 11:42:25 : [scan] - Progress: 94% 2016-09-23 11:42:25 : [scan.firefox] - Stopping Firefox based browsers scan [3] 2016-09-23 11:42:25 : [scan.firefox] - 1 malicious Firefox preferences found 2016-09-23 11:42:25 : [scan] - Progress: 95% 2016-09-23 11:42:25 : [main] - Chrome is installed: True 2016-09-23 11:42:25 : [scan.chromium] - Starting Chromium based browsers scan [1] 2016-09-23 11:42:28 : [scan.chromium] - Stopping Chromium based browsers scan [1] 2016-09-23 11:42:28 : [scan] - Progress: 97% 2016-09-23 11:42:28 : [scan.chromium] - Starting Chromium based browsers scan [2] 2016-09-23 11:42:28 : [scan.chromium] - No profile to scan, skipping 2016-09-23 11:42:28 : [scan.chromium] - Opening C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Web Data 2016-09-23 11:42:28 : [scan.chromium] - Closing C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Web Data 2016-09-23 11:42:28 : [scan.chromium] - Opening C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences 2016-09-23 11:42:30 : [scan.chromium] - No profile to scan, skipping 2016-09-23 11:42:30 : [scan.chromium] - No profile to scan, skipping 2016-09-23 11:42:30 : [scan.chromium] - No profile to scan, skipping 2016-09-23 11:42:30 : [scan.chromium] - No profile to scan, skipping 2016-09-23 11:42:30 : [scan.chromium] - No profile to scan, skipping 2016-09-23 11:42:30 : [scan.chromium] - Stopping Chromium based browsers scan [2] 2016-09-23 11:42:30 : [scan] - Progress: 99% 2016-09-23 11:42:30 : [scan.chromium] - Starting Chromium based browsers scan [3] 2016-09-23 11:42:30 : [scan.chromium] - Stopping Chromium based browsers scan [3] 2016-09-23 11:42:30 : [scan.chromium] - 0 malicious Chromium preferences elements found 2016-09-23 11:42:30 : [scan] - Progress: 100% 2016-09-23 11:42:30 : [scan] - Stopping scan 2016-09-23 11:44:20 : [main.gui] - Clean requested 2016-09-23 11:44:22 : [main.gui] - Killing all processes 2016-09-23 11:44:22 : [main] - Killing [System Process](0) 2016-09-23 11:44:22 : [main] - Killing System(4) 2016-09-23 11:44:22 : [main] - smss.exe - (4) not killed - whitelisted 2016-09-23 11:44:22 : [main] - csrss.exe - (4) not killed - whitelisted 2016-09-23 11:44:22 : [main] - wininit.exe - (4) not killed - whitelisted 2016-09-23 11:44:22 : [main] - csrss.exe - (4) not killed - whitelisted 2016-09-23 11:44:22 : [main] - winlogon.exe - (4) not killed - whitelisted 2016-09-23 11:44:22 : [main] - services.exe - (4) not killed - whitelisted 2016-09-23 11:44:22 : [main] - lsass.exe - (4) not killed - whitelisted 2016-09-23 11:44:22 : [main] - svchost.exe - (4) not killed - whitelisted 2016-09-23 11:44:22 : [main] - svchost.exe - (4) not killed - whitelisted 2016-09-23 11:44:22 : [main] - dwm.exe - (4) not killed - whitelisted 2016-09-23 11:44:22 : [main] - svchost.exe - (4) not killed - whitelisted 2016-09-23 11:44:22 : [main] - svchost.exe - (4) not killed - whitelisted 2016-09-23 11:44:22 : [main] - Killing hmpalert.exe(1252) 2016-09-23 11:44:23 : [main] - svchost.exe - (1252) not killed - whitelisted 2016-09-23 11:44:23 : [main] - svchost.exe - (1252) not killed - whitelisted 2016-09-23 11:44:23 : [main] - svchost.exe - (1252) not killed - whitelisted 2016-09-23 11:44:23 : [main] - svchost.exe - (1252) not killed - whitelisted 2016-09-23 11:44:23 : [main] - Killing igfxCUIService.exe(1852) 2016-09-23 11:44:23 : [main] - svchost.exe - (1852) not killed - whitelisted 2016-09-23 11:44:23 : [main] - svchost.exe - (1852) not killed - whitelisted 2016-09-23 11:44:23 : [main] - svchost.exe - (1852) not killed - whitelisted 2016-09-23 11:44:23 : [main] - Killing spoolsv.exe(1488) 2016-09-23 11:44:23 : [main] - Killing WUDFHost.exe(2064) 2016-09-23 11:44:23 : [main] - Killing SearchIndexer.exe(2212) 2016-09-23 11:44:23 : [main] - svchost.exe - (2212) not killed - whitelisted 2016-09-23 11:44:23 : [main] - Killing BtwRSupportService.exe(2452) 2016-09-23 11:44:23 : [main] - Killing OfficeClickToRun.exe(2460) 2016-09-23 11:44:24 : [main] - Killing wfcs.exe(2476) 2016-09-23 11:44:24 : [main] - Killing webservd.exe(2484) 2016-09-23 11:44:24 : [main] - svchost.exe - (2484) not killed - whitelisted 2016-09-23 11:44:24 : [main] - Killing CxAudMsg64.exe(2500) 2016-09-23 11:44:24 : [main] - svchost.exe - (2500) not killed - whitelisted 2016-09-23 11:44:24 : [main] - svchost.exe - (2500) not killed - whitelisted 2016-09-23 11:44:24 : [main] - svchost.exe - (2500) not killed - whitelisted 2016-09-23 11:44:24 : [main] - Killing SDUpdSvc.exe(2564) 2016-09-23 11:44:24 : [main] - Killing SynTPEnhService.exe(2576) 2016-09-23 11:44:24 : [main] - Killing mbamscheduler.exe(2596) 2016-09-23 11:44:24 : [main] - svchost.exe - (2596) not killed - whitelisted 2016-09-23 11:44:24 : [main] - Killing sqlwriter.exe(2628) 2016-09-23 11:44:24 : [main] - Killing RichVideo64.exe(2636) 2016-09-23 11:44:24 : [main] - Killing NLSSRV32.EXE(2660) 2016-09-23 11:44:24 : [main] - Killing HuaweiHiSuiteService64.exe(2668) 2016-09-23 11:44:24 : [main] - Killing mbamservice.exe(2676) 2016-09-23 11:44:24 : [main] - Killing inetinfo.exe(2684) 2016-09-23 11:44:25 : [main] - SDFSSvc.exe - (2684) not killed - whitelisted 2016-09-23 11:44:25 : [main] - Killing HeciServer.exe(2704) 2016-09-23 11:44:25 : [main] - Killing NitroPDFDriverService8x64.exe(2732) 2016-09-23 11:44:25 : [main] - svchost.exe - (2732) not killed - whitelisted 2016-09-23 11:44:25 : [main] - Killing Memory Compression(2756) 2016-09-23 11:44:25 : [main] - Killing mqsvc.exe(2776) 2016-09-23 11:44:25 : [main] - SMSvcHost.exe - (2776) not killed - whitelisted 2016-09-23 11:44:25 : [main] - Killing SDWSCSvc.exe(2816) 2016-09-23 11:44:25 : [main] - Killing startsys.exe(3516) 2016-09-23 11:44:25 : [main] - conhost.exe - (3516) not killed - whitelisted 2016-09-23 11:44:25 : [main] - userAgent.exe - (3516) not killed - whitelisted 2016-09-23 11:44:25 : [main] - conhost.exe - (3516) not killed - whitelisted 2016-09-23 11:44:25 : [main] - Killing webcategory.exe(3608) 2016-09-23 11:44:25 : [main] - conhost.exe - (3608) not killed - whitelisted 2016-09-23 11:44:25 : [main] - SMSvcHost.exe - (3608) not killed - whitelisted 2016-09-23 11:44:25 : [main] - svchost.exe - (3608) not killed - whitelisted 2016-09-23 11:44:25 : [main] - WmiPrvSE.exe - (3608) not killed - whitelisted 2016-09-23 11:44:25 : [main] - Killing HPSupportSolutionsFrameworkService.exe(3184) 2016-09-23 11:44:25 : [main] - Killing GoogleCrashHandler.exe(256) 2016-09-23 11:44:25 : [main] - Killing GoogleCrashHandler64.exe(4800) 2016-09-23 11:44:25 : [main] - Killing IAStorDataMgrSvc.exe(5740) 2016-09-23 11:44:26 : [main] - Killing jhi_service.exe(5912) 2016-09-23 11:44:26 : [main] - Killing hmpalert.exe(3452) 2016-09-23 11:44:26 : [main] - Killing mbamgui.exe(220) 2016-09-23 11:44:26 : [main] - sihost.exe - (220) not killed - whitelisted 2016-09-23 11:44:26 : [main] - svchost.exe - (220) not killed - whitelisted 2016-09-23 11:44:26 : [main] - Killing PresentationFontCache.exe(5272) 2016-09-23 11:44:26 : [main] - Killing SynTPEnh.exe(5268) 2016-09-23 11:44:26 : [main] - Killing taskhostw.exe(5516) 2016-09-23 11:44:26 : [main] - Killing ServiceHostAppUpdater.exe(4104) 2016-09-23 11:44:26 : [main] - Killing RuntimeBroker.exe(2320) 2016-09-23 11:44:26 : [main] - Killing igfxEM.exe(940) 2016-09-23 11:44:26 : [main] - Killing igfxHK.exe(2656) 2016-09-23 11:44:26 : [main] - Killing igfxTray.exe(5424) 2016-09-23 11:44:26 : [main] - explorer.exe - (5424) not killed - whitelisted 2016-09-23 11:44:26 : [main] - Killing SynTPHelper.exe(1952) 2016-09-23 11:44:26 : [main] - Killing ShellExperienceHost.exe(1044) 2016-09-23 11:44:26 : [main] - SearchUI.exe - (1044) not killed - whitelisted 2016-09-23 11:44:26 : [main] - Killing SkypeHost.exe(6248) 2016-09-23 11:44:27 : [main] - Killing ServiceHostApp.exe(6356) 2016-09-23 11:44:27 : [main] - Killing SettingSyncHost.exe(564) 2016-09-23 11:44:27 : [main] - Killing CAudioFilterAgent64.exe(7020) 2016-09-23 11:44:28 : [main] - Killing RTFTrack.exe(7036) 2016-09-23 11:44:28 : [main] - Killing Energy Manager.exe(7936) 2016-09-23 11:44:28 : [main] - Killing CDASrv.exe(7172) 2016-09-23 11:44:28 : [main] - Killing FAHWindow32.exe(7680) 2016-09-23 11:44:28 : [main] - Killing FAHWindow64.exe(7756) 2016-09-23 11:44:28 : [main] - Killing WZUpdateNotifier.exe(7776) 2016-09-23 11:44:28 : [main] - Killing PWRISOVM.EXE(7392) 2016-09-23 11:44:28 : [main] - Killing wfc.exe(7560) 2016-09-23 11:44:28 : [main] - javaw.exe - (7560) not killed - whitelisted 2016-09-23 11:44:28 : [main] - Killing SDTray.exe(7732) 2016-09-23 11:44:28 : [main] - Killing WzPreloader.exe(7744) 2016-09-23 11:44:28 : [main] - Killing ServiceHostApp.exe(0) 2016-09-23 11:44:28 : [main] - Killing IAStorIcon.exe(6496) 2016-09-23 11:44:29 : [main] - Killing dllhost.exe(8688) 2016-09-23 11:44:29 : [main] - Killing LSCNotify.exe(8760) 2016-09-23 11:44:29 : [main] - ServiceStartMenuIndexer.exe - (8760) not killed - whitelisted 2016-09-23 11:44:29 : [main] - Killing torch.exe(8376) 2016-09-23 11:44:29 : [main] - Killing torch.exe(8212) 2016-09-23 11:44:29 : [main] - Killing torch.exe(0) 2016-09-23 11:44:29 : [main] - Killing TorchUpdate.exe(0) 2016-09-23 11:44:29 : [main] - Killing torch.exe(0) 2016-09-23 11:44:29 : [main] - Killing torch.exe(0) 2016-09-23 11:44:29 : [main] - Killing torch.exe(0) 2016-09-23 11:44:29 : [main] - Killing torch.exe(0) 2016-09-23 11:44:29 : [main] - Killing torch.exe(0) 2016-09-23 11:44:29 : [main] - Killing torch.exe(0) 2016-09-23 11:44:29 : [main] - Killing torch.exe(0) 2016-09-23 11:44:29 : [main] - Killing torch.exe(0) 2016-09-23 11:44:29 : [main] - Killing torch.exe(0) 2016-09-23 11:44:29 : [main] - Killing fontdrvhost.exe(584) 2016-09-23 11:44:29 : [main] - Killing notepad.exe(1876) 2016-09-23 11:44:29 : [main] - Killing LiveUpdate.exe(8956) 2016-09-23 11:44:29 : [main] - Killing ASCService.exe(4336) 2016-09-23 11:44:29 : [main] - Killing UninstallMonitor.exe(5280) 2016-09-23 11:44:29 : [main] - Killing ASC.exe(10304) 2016-09-23 11:44:29 : [main] - Killing Monitor.exe(10284) 2016-09-23 11:44:29 : [main] - Killing ASCTray.exe(1872) 2016-09-23 11:44:29 : [main] - Killing notepad.exe(12216) 2016-09-23 11:44:29 : [main] - Killing RealTimeProtector.exe(12072) 2016-09-23 11:44:29 : [main] - dasHost.exe - (12072) not killed - whitelisted 2016-09-23 11:44:29 : [main] - Killing chrome.exe(9556) 2016-09-23 11:44:30 : [main] - Killing chrome.exe(648) 2016-09-23 11:44:30 : [main] - Killing chrome.exe(9336) 2016-09-23 11:44:30 : [main] - Killing chrome.exe(6212) 2016-09-23 11:44:30 : [main] - Killing chrome.exe(0) 2016-09-23 11:44:30 : [main] - Killing chrome.exe(0) 2016-09-23 11:44:30 : [main] - Killing Dashlane.exe(11960) 2016-09-23 11:44:30 : [main] - Killing DashlanePlugin.exe(11752) 2016-09-23 11:44:30 : [main] - Killing MagicPlus_helper.exe(5040) 2016-09-23 11:44:30 : [main] - Killing chrome.exe(0) 2016-09-23 11:44:30 : [main] - Killing chrome.exe(0) 2016-09-23 11:44:30 : [main] - Killing chrome.exe(0) 2016-09-23 11:44:30 : [main] - Killing chrome.exe(0) 2016-09-23 11:44:30 : [main] - Killing chrome.exe(0) 2016-09-23 11:44:30 : [main] - Killing chrome.exe(0) 2016-09-23 11:44:30 : [main] - Killing audiodg.exe(12176) 2016-09-23 11:44:30 : [main] - Killing chrome.exe(0) 2016-09-23 11:44:30 : [main] - smartscreen.exe - (0) not killed - whitelisted 2016-09-23 12:19:13 : INFO [main] - >>>> STARTING <<<< 2016-09-23 12:19:13 : INFO [main] - RAM Usage: 61 2016-09-23 12:19:13 : INFO [main] - OS: WIN_10 X64 2016-09-23 12:19:13 : [main.language] - Checking the language 2016-09-23 12:19:13 : [main.language] - Language found: en 2016-09-23 12:19:13 : [main.network] - Checking the network connectivity 2016-09-23 12:19:13 : [main.network] - Network connectivity status: True 2016-09-23 12:19:13 : [main.eula] - Checking for EULA agreement 2016-09-23 12:19:13 : [main.network] - Check for updates 2016-09-23 12:19:13 : [main.network] - Requesting the last release number 2016-09-23 12:19:13 : [main.network] - Failure when requesting the release number (13) 2016-09-23 12:19:13 : [main.gui] - GUI setup 2016-09-23 12:19:13 : [main.gui] - Languages setup 2016-09-23 12:19:13 : [main] - Chrome is installed: True 2016-09-23 12:19:13 : [main] - Firefox is installed: True 2016-09-23 12:19:14 : [main.gui] - Showing the gui 2016-09-23 12:19:27 : [main.gui] - Showing Report window