Hi
I ran Malwarebytes last month because my laptop was suddenly very slow. It found "Trojan.Dropper.MSIL" and quarantined it, but machine was still slow. After that I deleted the trojan from quarantine and I also ran AdwCleaner. Machine seems to be even slower now and is getting "Windows detected a hard disk problem" messages.
Full disclosure, I also dropped the machine shortly after finding the trojan which could not have helped.
Below are Malwarebytes and AdwCleaner logs from July when I first found the problem, and from today. I tried to follow a link from your site to Security check by screen317 but it says the account is suspended. Is there another source I can use for that?
Grateful for your help.
css
================================================
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 7/9/2016
Scan Time: 11:12 AM
Logfile:
Administrator: Yes
Version: 2.2.1.1043
Malware Database: v2016.07.09.07
Rootkit Database: v2016.05.27.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 10
CPU: x64
File System: NTFS
User: carol
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 430032
Time Elapsed: 2 hr, 21 min, 35 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 3
Trojan.Dropper.MSIL, C:\Users\carol\Downloads\freshland world trading stores ORDER#K331.01338 UK.zip, Quarantined, [f00b2af71882e94dc697d28993718a76],
PUP.Optional.HomePageHelper, C:\Users\carol\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences, Good: ("session":{"restore_on_startup":4,"startup_urls":["https://www.malwarebytes.org/restorebrowser/"]}}), Bad: ("session":{"restore_on_startup":4,"startup_urls":["https://homepage-web.com/?s=lenovo&m=start"]}}), Replaced,[6c8f4fd227739f970ca3bce21aea4db3]
PUP.Optional.HomePageHelper, C:\Users\carol\AppData\Roaming\Mozilla\Firefox\Profiles\nmbfgbfe.default\prefs.js, Good: (user_pref("browser.startup.homepage", "https://www.malwarebytes.org/restorebrowser/), Bad: (user_pref("browser.startup.homepage", "https://homepage-web.com), Replaced,[b9420e138c0e37ffb006485755af9070]
Physical Sectors: 0
(No malicious items detected)
(end)
===================================================================================
# AdwCleaner v5.201 - Logfile created 10/07/2016 at 23:46:31
# Updated 30/06/2016 by ToolsLib
# Database : 2016-07-10.3 [Server]
# Operating system : Windows 10 Home (X64)
# Username : carol - YOGASLUE
# Running from : C:\Users\carol\Desktop\adwcleaner_5.201.exe
# Option : Scan
# Support : https://toolslib.net/forum
***** [ Services ] *****
Service Found : Amazon 1Button App Service
***** [ Folders ] *****
Folder Found : C:\ProgramData\pokki
Folder Found : C:\ProgramData\Application Data\pokki
Folder Found : C:\Program Files (x86)\Amazon\Amazon1ButtonApp
Folder Found : C:\Users\carol\AppData\Local\SweetLabs App Platform
Folder Found : C:\Users\carol\AppData\Roaming\download Manager
Folder Found : C:\Users\QBDataServiceUser20\AppData\Local\pokki
Folder Found : C:\Users\QBDataServiceUser26\AppData\Local\pokki
Folder Found : C:\Users\Administrator\AppData\Local\pokki
Folder Found : C:\Users\Default User\AppData\Local\Pokki
Folder Found : C:\Users\Default\AppData\Local\Pokki
***** [ Files ] *****
File Found : C:\Users\carol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk
File Found : C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\PC App Store.lnk
File Found : C:\Users\carol\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_homepage-web.com_0.localstorage
File Found : C:\Users\carol\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_homepage-web.com_0.localstorage-journal
***** [ DLL ] *****
***** [ WMI ] *****
***** [ Shortcuts ] *****
***** [ Scheduled tasks ] *****
Task Found : SweetLabs App Platform
***** [ Registry ] *****
Key Found : HKCU\Software\Classes\AllFileSystemObjects\shell\pokki
Key Found : HKCU\Software\Classes\Directory\shell\pokki
Key Found : HKCU\Software\Classes\Drive\shell\pokki
Key Found : HKCU\Software\Classes\lnkfile\shell\pokki
Key Found : HKLM\SOFTWARE\Classes\Amazon1ButtonRuntime.Amazon1ButtonRuntime
Key Found : HKLM\SOFTWARE\Classes\Amazon1ButtonRuntime.AmazonRuntimeServer
Key Found : HKLM\SOFTWARE\Classes\AppID\{7F46C358-270D-4791-A579-AD1DDA1A3F7B}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{BD6ECB00-7C4A-4F97-B425-44117F2A7AAE}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BD6ECB00-7C4A-4F97-B425-44117F2A7AAE}
Key Found : HKCU\Software\SweetLabs App Platform
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\SweetLabs_AP
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\SweetLabs_Start_Menu
Key Found : HKU\S-1-5-21-153808505-2681921322-2986878879-1001\Software\SweetLabs App Platform
Key Found : HKU\S-1-5-21-153808505-2681921322-2986878879-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\SweetLabs_AP
Key Found : HKU\S-1-5-21-153808505-2681921322-2986878879-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\SweetLabs_Start_Menu
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3DCCCD6BD02558446B24CF1C63EC213C
Data Found : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Secondary_Page_URL] - hxxp://mystart.lenovo.com
Data Found : HKCU\Software\Microsoft\Internet Explorer\Main [Secondary Start Pages] - hxxp://mystart.lenovo.com
Data Found : HKU\S-1-5-21-153808505-2681921322-2986878879-1001\Software\Microsoft\Internet Explorer\Main [Default_Secondary_Page_URL] - hxxp://mystart.lenovo.com
Data Found : HKU\S-1-5-21-153808505-2681921322-2986878879-1001\Software\Microsoft\Internet Explorer\Main [Secondary Start Pages] - hxxp://mystart.lenovo.com
Value Found : HKU\S-1-5-21-153808505-2681921322-2986878879-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run [Pokki]
***** [ Web browsers ] *****
[C:\Users\carol\AppData\Roaming\Mozilla\Firefox\Profiles\nmbfgbfe.default\prefs.js] Found : user_pref("browser.search.defaultenginename", "Web Search");
[C:\Users\carol\AppData\Roaming\Mozilla\Firefox\Profiles\nmbfgbfe.default\prefs.js] Found : user_pref("browser.search.defaultenginename.US", "Web Search");
[C:\Users\carol\AppData\Roaming\Mozilla\Firefox\Profiles\nmbfgbfe.default\prefs.js] Found : user_pref("browser.search.hiddenOneOffs", "Yahoo,Bing,Amazon.com,eBay,Twitter,Web Search,Wikipedia (en)");
[C:\Users\carol\AppData\Roaming\Mozilla\Firefox\Profiles\nmbfgbfe.default\prefs.js] Found : user_pref("browser.search.selectedEngine", "Web Search");
[C:\Users\carol\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : aol.com
[C:\Users\carol\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : ask.com
[C:\Users\carol\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : search.homepage-web.com
[C:\Users\carol\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Homepage] Found : hxxps://homepage-web.com/?s=lenovo&m=home
*************************
C:\AdwCleaner\AdwCleaner[S1].txt - [4995 bytes] - [10/07/2016 23:46:31]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [5068 bytes] ##########
====================================================================================
SCANS FROM AUGUST 13
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 8/13/2016
Scan Time: 9:09 AM
Logfile: malwarebytes 8-13-16.txt
Administrator: Yes
Version: 2.2.1.1043
Malware Database: v2016.08.13.03
Rootkit Database: v2016.08.09.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 10
CPU: x64
File System: NTFS
User: carol
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 436807
Time Elapsed: 6 hr, 39 min, 20 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 0
(No malicious items detected)
Physical Sectors: 0
(No malicious items detected)
(end)
# AdwCleaner v6.000 - Logfile created 13/08/2016 at 16:46:49
# Updated on 12/08/2016 by ToolsLib
# Database : 2016-08-13.2 [Server]
# Operating System : Windows 10 Home (X64)
# Username : carol - YOGASLUE
# Running from : C:\Users\carol\Downloads\adwcleaner_6.000.exe
# Mode: Clean
# Support : https://toolslib.net/forum
***** [ Services ] *****
***** [ Folders ] *****
***** [ Files ] *****
***** [ DLL ] *****
***** [ WMI ] *****
***** [ Shortcuts ] *****
***** [ Scheduled Tasks ] *****
***** [ Registry ] *****
[-] Key deleted: [x64] HKLM\SOFTWARE\Classes\CLSID\{BD6ECB00-7C4A-4F97-B425-44117F2A7AAE}
***** [ Web browsers ] *****
[-] [aol.com] [Search Provider] Deleted: aol.com
[-] [ask.com] [Search Provider] Deleted: ask.com
*************************
:: "Tracing" keys deleted
:: Winsock settings cleared
*************************
C:\AdwCleaner\AdwCleaner[C1].txt - [5098 Bytes] - [10/07/2016 23:54:45]
C:\AdwCleaner\AdwCleaner[C1]1.txt - [5098 Bytes] - [11/07/2016 00:25:01]
C:\AdwCleaner\AdwCleaner[C2].txt - [1215 Bytes] - [09/08/2016 08:31:41]
C:\AdwCleaner\AdwCleaner[C3].txt - [1145 Bytes] - [13/08/2016 16:46:49]
C:\AdwCleaner\AdwCleaner[S1].txt - [5151 Bytes] - [10/07/2016 23:46:31]
C:\AdwCleaner\AdwCleaner[S2].txt - [1142 Bytes] - [09/08/2016 08:19:37]
C:\AdwCleaner\AdwCleaner[S3].txt - [1700 Bytes] - [13/08/2016 16:42:39]
########## EOF - C:\AdwCleaner\AdwCleaner[C3].txt - [1437 Bytes] ##########
I ran Malwarebytes last month because my laptop was suddenly very slow. It found "Trojan.Dropper.MSIL" and quarantined it, but machine was still slow. After that I deleted the trojan from quarantine and I also ran AdwCleaner. Machine seems to be even slower now and is getting "Windows detected a hard disk problem" messages.
Full disclosure, I also dropped the machine shortly after finding the trojan which could not have helped.
Below are Malwarebytes and AdwCleaner logs from July when I first found the problem, and from today. I tried to follow a link from your site to Security check by screen317 but it says the account is suspended. Is there another source I can use for that?
Grateful for your help.
css
================================================
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 7/9/2016
Scan Time: 11:12 AM
Logfile:
Administrator: Yes
Version: 2.2.1.1043
Malware Database: v2016.07.09.07
Rootkit Database: v2016.05.27.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 10
CPU: x64
File System: NTFS
User: carol
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 430032
Time Elapsed: 2 hr, 21 min, 35 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 3
Trojan.Dropper.MSIL, C:\Users\carol\Downloads\freshland world trading stores ORDER#K331.01338 UK.zip, Quarantined, [f00b2af71882e94dc697d28993718a76],
PUP.Optional.HomePageHelper, C:\Users\carol\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences, Good: ("session":{"restore_on_startup":4,"startup_urls":["https://www.malwarebytes.org/restorebrowser/"]}}), Bad: ("session":{"restore_on_startup":4,"startup_urls":["https://homepage-web.com/?s=lenovo&m=start"]}}), Replaced,[6c8f4fd227739f970ca3bce21aea4db3]
PUP.Optional.HomePageHelper, C:\Users\carol\AppData\Roaming\Mozilla\Firefox\Profiles\nmbfgbfe.default\prefs.js, Good: (user_pref("browser.startup.homepage", "https://www.malwarebytes.org/restorebrowser/), Bad: (user_pref("browser.startup.homepage", "https://homepage-web.com), Replaced,[b9420e138c0e37ffb006485755af9070]
Physical Sectors: 0
(No malicious items detected)
(end)
===================================================================================
# AdwCleaner v5.201 - Logfile created 10/07/2016 at 23:46:31
# Updated 30/06/2016 by ToolsLib
# Database : 2016-07-10.3 [Server]
# Operating system : Windows 10 Home (X64)
# Username : carol - YOGASLUE
# Running from : C:\Users\carol\Desktop\adwcleaner_5.201.exe
# Option : Scan
# Support : https://toolslib.net/forum
***** [ Services ] *****
Service Found : Amazon 1Button App Service
***** [ Folders ] *****
Folder Found : C:\ProgramData\pokki
Folder Found : C:\ProgramData\Application Data\pokki
Folder Found : C:\Program Files (x86)\Amazon\Amazon1ButtonApp
Folder Found : C:\Users\carol\AppData\Local\SweetLabs App Platform
Folder Found : C:\Users\carol\AppData\Roaming\download Manager
Folder Found : C:\Users\QBDataServiceUser20\AppData\Local\pokki
Folder Found : C:\Users\QBDataServiceUser26\AppData\Local\pokki
Folder Found : C:\Users\Administrator\AppData\Local\pokki
Folder Found : C:\Users\Default User\AppData\Local\Pokki
Folder Found : C:\Users\Default\AppData\Local\Pokki
***** [ Files ] *****
File Found : C:\Users\carol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk
File Found : C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\PC App Store.lnk
File Found : C:\Users\carol\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_homepage-web.com_0.localstorage
File Found : C:\Users\carol\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_homepage-web.com_0.localstorage-journal
***** [ DLL ] *****
***** [ WMI ] *****
***** [ Shortcuts ] *****
***** [ Scheduled tasks ] *****
Task Found : SweetLabs App Platform
***** [ Registry ] *****
Key Found : HKCU\Software\Classes\AllFileSystemObjects\shell\pokki
Key Found : HKCU\Software\Classes\Directory\shell\pokki
Key Found : HKCU\Software\Classes\Drive\shell\pokki
Key Found : HKCU\Software\Classes\lnkfile\shell\pokki
Key Found : HKLM\SOFTWARE\Classes\Amazon1ButtonRuntime.Amazon1ButtonRuntime
Key Found : HKLM\SOFTWARE\Classes\Amazon1ButtonRuntime.AmazonRuntimeServer
Key Found : HKLM\SOFTWARE\Classes\AppID\{7F46C358-270D-4791-A579-AD1DDA1A3F7B}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{BD6ECB00-7C4A-4F97-B425-44117F2A7AAE}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BD6ECB00-7C4A-4F97-B425-44117F2A7AAE}
Key Found : HKCU\Software\SweetLabs App Platform
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\SweetLabs_AP
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\SweetLabs_Start_Menu
Key Found : HKU\S-1-5-21-153808505-2681921322-2986878879-1001\Software\SweetLabs App Platform
Key Found : HKU\S-1-5-21-153808505-2681921322-2986878879-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\SweetLabs_AP
Key Found : HKU\S-1-5-21-153808505-2681921322-2986878879-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\SweetLabs_Start_Menu
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3DCCCD6BD02558446B24CF1C63EC213C
Data Found : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Secondary_Page_URL] - hxxp://mystart.lenovo.com
Data Found : HKCU\Software\Microsoft\Internet Explorer\Main [Secondary Start Pages] - hxxp://mystart.lenovo.com
Data Found : HKU\S-1-5-21-153808505-2681921322-2986878879-1001\Software\Microsoft\Internet Explorer\Main [Default_Secondary_Page_URL] - hxxp://mystart.lenovo.com
Data Found : HKU\S-1-5-21-153808505-2681921322-2986878879-1001\Software\Microsoft\Internet Explorer\Main [Secondary Start Pages] - hxxp://mystart.lenovo.com
Value Found : HKU\S-1-5-21-153808505-2681921322-2986878879-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run [Pokki]
***** [ Web browsers ] *****
[C:\Users\carol\AppData\Roaming\Mozilla\Firefox\Profiles\nmbfgbfe.default\prefs.js] Found : user_pref("browser.search.defaultenginename", "Web Search");
[C:\Users\carol\AppData\Roaming\Mozilla\Firefox\Profiles\nmbfgbfe.default\prefs.js] Found : user_pref("browser.search.defaultenginename.US", "Web Search");
[C:\Users\carol\AppData\Roaming\Mozilla\Firefox\Profiles\nmbfgbfe.default\prefs.js] Found : user_pref("browser.search.hiddenOneOffs", "Yahoo,Bing,Amazon.com,eBay,Twitter,Web Search,Wikipedia (en)");
[C:\Users\carol\AppData\Roaming\Mozilla\Firefox\Profiles\nmbfgbfe.default\prefs.js] Found : user_pref("browser.search.selectedEngine", "Web Search");
[C:\Users\carol\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : aol.com
[C:\Users\carol\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : ask.com
[C:\Users\carol\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : search.homepage-web.com
[C:\Users\carol\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Homepage] Found : hxxps://homepage-web.com/?s=lenovo&m=home
*************************
C:\AdwCleaner\AdwCleaner[S1].txt - [4995 bytes] - [10/07/2016 23:46:31]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [5068 bytes] ##########
====================================================================================
SCANS FROM AUGUST 13
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 8/13/2016
Scan Time: 9:09 AM
Logfile: malwarebytes 8-13-16.txt
Administrator: Yes
Version: 2.2.1.1043
Malware Database: v2016.08.13.03
Rootkit Database: v2016.08.09.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 10
CPU: x64
File System: NTFS
User: carol
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 436807
Time Elapsed: 6 hr, 39 min, 20 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 0
(No malicious items detected)
Physical Sectors: 0
(No malicious items detected)
(end)
# AdwCleaner v6.000 - Logfile created 13/08/2016 at 16:46:49
# Updated on 12/08/2016 by ToolsLib
# Database : 2016-08-13.2 [Server]
# Operating System : Windows 10 Home (X64)
# Username : carol - YOGASLUE
# Running from : C:\Users\carol\Downloads\adwcleaner_6.000.exe
# Mode: Clean
# Support : https://toolslib.net/forum
***** [ Services ] *****
***** [ Folders ] *****
***** [ Files ] *****
***** [ DLL ] *****
***** [ WMI ] *****
***** [ Shortcuts ] *****
***** [ Scheduled Tasks ] *****
***** [ Registry ] *****
[-] Key deleted: [x64] HKLM\SOFTWARE\Classes\CLSID\{BD6ECB00-7C4A-4F97-B425-44117F2A7AAE}
***** [ Web browsers ] *****
[-] [aol.com] [Search Provider] Deleted: aol.com
[-] [ask.com] [Search Provider] Deleted: ask.com
*************************
:: "Tracing" keys deleted
:: Winsock settings cleared
*************************
C:\AdwCleaner\AdwCleaner[C1].txt - [5098 Bytes] - [10/07/2016 23:54:45]
C:\AdwCleaner\AdwCleaner[C1]1.txt - [5098 Bytes] - [11/07/2016 00:25:01]
C:\AdwCleaner\AdwCleaner[C2].txt - [1215 Bytes] - [09/08/2016 08:31:41]
C:\AdwCleaner\AdwCleaner[C3].txt - [1145 Bytes] - [13/08/2016 16:46:49]
C:\AdwCleaner\AdwCleaner[S1].txt - [5151 Bytes] - [10/07/2016 23:46:31]
C:\AdwCleaner\AdwCleaner[S2].txt - [1142 Bytes] - [09/08/2016 08:19:37]
C:\AdwCleaner\AdwCleaner[S3].txt - [1700 Bytes] - [13/08/2016 16:42:39]
########## EOF - C:\AdwCleaner\AdwCleaner[C3].txt - [1437 Bytes] ##########