Ran AdwCleaner for first time with the following results. Concerned I'll remove something I should not. Would appreciate some advice on how to proceed. Thanks is advance for your help!

# AdwCleaner v5.201 - Logfile created 04/08/2016 at 07:28:02
# Updated 30/06/2016 by ToolsLib
# Database : 2016-08-04.1 [Server]
# Operating system : Windows 10 Home  (X64)
# Username : Ron - LENOVO-PC
# Running from : C:\Users\Ron\Downloads\adwcleaner_5.201.exe
# Option : Scan
# Support : https://toolslib.net/forum

***** [ Services ] *****

***** [ Folders ] *****

Folder Found : C:\ProgramData\pokki Folder Found : C:\ProgramData\Application Data\pokki Folder Found : C:\Program Files (x86)\Amazon\ABB Folder Found : C:\Users\Ron\AppData\Local\SweetLabs App Platform Folder Found : C:\Users\Default User\AppData\Local\Pokki Folder Found : C:\Users\Default\AppData\Local\Pokki

***** [ Files ] *****

File Found : C:\Users\Ron\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pokki Menu.lnk File Found : C:\Users\Ron\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk

***** [ DLL ] *****

***** [ WMI ] *****

***** [ Shortcuts ] *****

Shortcut Infected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk ( "hxxp://safesurfs.net/?ssid=1470245110&a=1031265&src=sh&uuid=d27e28a5-d48e-4005-af77-8e7623021619" ) Shortcut Infected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk ( "hxxp://safesurfs.net/?ssid=1470245110&a=1031265&src=sh&uuid=d27e28a5-d48e-4005-af77-8e7623021619" ) Shortcut Infected : C:\Users\Ron\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk ( "hxxp://safesurfs.net/?ssid=1470245110&a=1031265&src=sh&uuid=d27e28a5-d48e-4005-af77-8e7623021619" ) Shortcut Infected : C:\Users\Ron\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk ( "hxxp://safesurfs.net/?ssid=1470245110&a=1031265&src=sh&uuid=d27e28a5-d48e-4005-af77-8e7623021619" ) Shortcut Infected : C:\Users\Ron\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk ( "hxxp://safesurfs.net/?ssid=1470245110&a=1031265&src=sh&uuid=d27e28a5-d48e-4005-af77-8e7623021619" ) Shortcut Infected : C:\Users\Ron\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk ( "hxxp://safesurfs.net/?ssid=1470245110&a=1031265&src=sh&uuid=d27e28a5-d48e-4005-af77-8e7623021619" )

***** [ Scheduled tasks ] *****

Task Found : SweetLabs App Platform

***** [ Registry ] *****

Key Found : HKCU\Software\Classes\AllFileSystemObjects\shell\pokki Key Found : HKCU\Software\Classes\Directory\shell\pokki Key Found : HKCU\Software\Classes\Drive\shell\pokki Key Found : HKCU\Software\Classes\lnkfile\shell\pokki Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Pokki_04bb6df446330549a2cb8d67fbd1a745025b7bd1 Key Found : HKCU\Software\Classes\pokki Key Found : HKLM\SOFTWARE\Classes\PCSU.SysUtils Key Found : HKLM\SOFTWARE\Classes\PCSU.SysUtils.1 Key Found : HKU\S-1-5-21-4083000061-4242379254-3730415356-1001\Software\Classes\pokki Key Found : HKLM\SOFTWARE\Classes\CLSID\{B89F5C49-51DB-4974-AB5A-E25901AA339C} Key Found : HKLM\SOFTWARE\Classes\CLSID\{E9B5B0D2-D08A-49FC-8B5C-159B60BAA268} Key Found : HKLM\SOFTWARE\Classes\Interface\{6C42038D-817A-472C-8C2A-EF46F1DA576D} Key Found : HKLM\SOFTWARE\Classes\Interface\{873C7DA8-195D-4D5A-B830-C5E2831901EA} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{3157E247-2784-4028-BF0F-52D6DDC70E1B} Key Found : HKCU\Software\Pokki Key Found : HKCU\Software\SweetLabs App Platform Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\SweetLabs_AP Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\SweetLabs_Start_Menu Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0A7D6F3C-F2AB-48ED-BE23-99791BFF87D6} Key Found : HKU\S-1-5-21-4083000061-4242379254-3730415356-1001\Software\Pokki Key Found : HKU\S-1-5-21-4083000061-4242379254-3730415356-1001\Software\SweetLabs App Platform Key Found : HKU\S-1-5-21-4083000061-4242379254-3730415356-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\SweetLabs_AP Key Found : HKU\S-1-5-21-4083000061-4242379254-3730415356-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\SweetLabs_Start_Menu Key Found : HKLM\SOFTWARE\Classes\Installer\Features\C3F6D7A0BA2FDE84EB329997B1FF786D Key Found : HKLM\SOFTWARE\Classes\Installer\Products\C3F6D7A0BA2FDE84EB329997B1FF786D Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\C3F6D7A0BA2FDE84EB329997B1FF786D Key Found : [x64] HKLM\SOFTWARE\Classes\Installer\Products\C3F6D7A0BA2FDE84EB329997B1FF786D Value Found : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{D068D838-2833-43CD-92C4-1C3AEE820423}] Value Found : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{044F046E-A7BC-4002-A7F7-500A65D2DE3F}] Value Found : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{F3790947-15E9-42ED-ACBA-099749124C87}] Value Found : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{C2659D31-3181-4535-BC22-6C6AC8FA8F78}] Key Found : HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\SCService

***** [ Web browsers ] *****

[C:\Users\Ron\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : aol.com
[C:\Users\Ron\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : ask.com

*************************

C:\AdwCleaner\AdwCleaner[S1].txt - [5548 bytes] - [04/08/2016 07:28:02]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [5621 bytes] ##########

 

Re: Not sure if I should "clean" these

Hello,

I reviewed the logfile, you can click on "Clean" and share the generated logfile here.

Best regards,

Re: Not sure if I should "clean" these

Thanks very much. I ran the clean and here is the log.

Appreciate your help!

# AdwCleaner v5.201 - Logfile created 04/08/2016 at 17:24:50 # Updated 30/06/2016 by ToolsLib # Database : 2016-08-04.1 [Server] # Operating system : Windows 10 Home  (X64) # Username : Ron - LENOVO-PC # Running from : C:\Users\Ron\Downloads\adwcleaner_5.201.exe # Option : Clean # Support : https://toolslib.net/forum

***** [ Services ] *****

***** [ Folders ] *****

[-] Folder Deleted : C:\ProgramData\pokki [#] Folder Deleted : C:\ProgramData\Application Data\pokki [-] Folder Deleted : C:\Program Files (x86)\Amazon\ABB [-] Folder Deleted : C:\Users\Ron\AppData\Local\SweetLabs App Platform [-] Folder Deleted : C:\Users\Default User\AppData\Local\Pokki [#] Folder Deleted : C:\Users\Default\AppData\Local\Pokki

***** [ Files ] *****

[-] File Deleted : C:\Users\Ron\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pokki Menu.lnk [-] File Deleted : C:\Users\Ron\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk

***** [ DLLs ] *****

***** [ WMI ] *****

***** [ Shortcuts ] *****

[-] Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk [-] Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk [-] Shortcut Disinfected : C:\Users\Ron\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk [-] Shortcut Disinfected : C:\Users\Ron\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk [-] Shortcut Disinfected : C:\Users\Ron\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk [-] Shortcut Disinfected : C:\Users\Ron\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk

***** [ Scheduled tasks ] *****

[-] Task Deleted : SweetLabs App Platform

***** [ Registry ] *****

[-] Key Deleted : HKCU\Software\Classes\AllFileSystemObjects\shell\pokki [-] Key Deleted : HKCU\Software\Classes\Directory\shell\pokki [-] Key Deleted : HKCU\Software\Classes\Drive\shell\pokki [-] Key Deleted : HKCU\Software\Classes\lnkfile\shell\pokki [-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Pokki_04bb6df446330549a2cb8d67fbd1a745025b7bd1 [-] Key Deleted : HKCU\Software\Classes\pokki [-] Key Deleted : HKLM\SOFTWARE\Classes\PCSU.SysUtils [-] Key Deleted : HKLM\SOFTWARE\Classes\PCSU.SysUtils.1 [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B89F5C49-51DB-4974-AB5A-E25901AA339C} [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E9B5B0D2-D08A-49FC-8B5C-159B60BAA268} [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6C42038D-817A-472C-8C2A-EF46F1DA576D} [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{873C7DA8-195D-4D5A-B830-C5E2831901EA} [-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{3157E247-2784-4028-BF0F-52D6DDC70E1B} [-] Key Deleted : HKCU\Software\Pokki [-] Key Deleted : HKCU\Software\SweetLabs App Platform [-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\SweetLabs_AP [-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\SweetLabs_Start_Menu [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0A7D6F3C-F2AB-48ED-BE23-99791BFF87D6} [-] Key Deleted : HKLM\SOFTWARE\Classes\Installer\Features\C3F6D7A0BA2FDE84EB329997B1FF786D [-] Key Deleted : HKLM\SOFTWARE\Classes\Installer\Products\C3F6D7A0BA2FDE84EB329997B1FF786D [-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\C3F6D7A0BA2FDE84EB329997B1FF786D [-] Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{D068D838-2833-43CD-92C4-1C3AEE820423}] [-] Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{044F046E-A7BC-4002-A7F7-500A65D2DE3F}] [-] Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{F3790947-15E9-42ED-ACBA-099749124C87}] [-] Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{C2659D31-3181-4535-BC22-6C6AC8FA8F78}] [-] Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\SCService

***** [ Web browsers ] *****

[-] [C:\Users\Ron\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : aol.com [-] [C:\Users\Ron\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : ask.com

*************************

:: "Tracing" keys deleted :: Winsock settings cleared

*************************

C:\AdwCleaner\AdwCleaner[C1].txt - [4666 bytes] - [04/08/2016 18:24:50] C:\AdwCleaner\AdwCleaner[S1].txt - [5708 bytes] - [04/08/2016 08:28:02]

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [4812 bytes] ##########

 

Re: Not sure if I should "clean" these

Hello,

Great !

So if you don't have anymore issues, you can just relaunch AdwCleaner and click on "Uninstall".

Best regards,

Re: Not sure if I should "clean" these

Thanks very much for your time, effort and expertise!

Re: Not sure if I should "clean" these

You're welcome :)