# AdwCleaner v3.007 - Report created 10/10/2013 at 15:09:34 # Updated 09/10/2013 by Xplode # Operating System : Windows Vista (TM) Business Service Pack 2 (32 bits) # Username : ldv - PC_VAN_LDV # Running from : D:\Users\ldv\Downloads\adwcleaner.exe # Option : Clean ***** [ Services ] ***** Service Deleted : winzipersvc ***** [ Files / Folders ] ***** Folder Deleted : C:\ProgramData\apn Folder Deleted : C:\ProgramData\Babylon Folder Deleted : C:\ProgramData\BetterSoft Folder Deleted : C:\ProgramData\StarApp Folder Deleted : C:\ProgramData\cuontinuyetoysauve Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SearchNewTab Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZipper Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\cuontinuyetoysauve Folder Deleted : C:\Program Files\continuetosave Folder Deleted : C:\Program Files\MyPC Backup Folder Deleted : C:\Program Files\Omiga Plus Folder Deleted : C:\Program Files\optimizer pro Folder Deleted : C:\Program Files\SweetIM Folder Deleted : C:\Program Files\WebSearch Folder Deleted : C:\Program Files\WinZipper Folder Deleted : C:\Program Files\Common Files\337 Folder Deleted : C:\Windows\system32\WNLT Folder Deleted : C:\Users\ldv\AppData\Local\cool_mirage Folder Deleted : C:\Users\ldv\AppData\Local\PutLockerDownloader Folder Deleted : C:\Users\ldv\AppData\LocalLow\SearchNewTab Folder Deleted : C:\Users\ldv\AppData\LocalLow\cuontinuyetoysauve Folder Deleted : C:\Users\ldv\AppData\Roaming\337 Folder Deleted : C:\Users\ldv\AppData\Roaming\goforfiles Folder Deleted : C:\Users\ldv\AppData\Roaming\NCdownloader Folder Deleted : C:\Users\ldv\AppData\Roaming\Omiga Plus Folder Deleted : C:\Users\ldv\AppData\Roaming\Systweak Folder Deleted : C:\Users\ldv\AppData\Roaming\WinZipper Folder Deleted : C:\Users\ldv\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FTDownloader.com Folder Deleted : C:\Users\ldv\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PutLockerDownloader.com Folder Deleted : C:\Users\ldv\AppData\Roaming\Mozilla\Firefox\Profiles\wiqftbrl.default\jetpack Folder Deleted : C:\Users\ldv\AppData\Local\Google\Chrome\User Data\Default\Extensions\figfnoieeipddlnhkkcmpobaimcfhjam File Deleted : C:\Users\ldv\AppData\Roaming\Mozilla\Firefox\Profiles\wiqftbrl.default\Extensions\firefox@browsefox.com.xpi File Deleted : C:\Users\ldv\AppData\Roaming\Mozilla\Firefox\Profiles\wiqftbrl.default\invalidprefs.js File Deleted : C:\Program Files\Mozilla Firefox\searchplugins\Babylon.xml File Deleted : C:\Users\ldv\AppData\Roaming\Mozilla\Firefox\Profiles\wiqftbrl.default\searchplugins\delta.xml File Deleted : C:\Program Files\Mozilla Firefox\searchplugins\qvo6.xml File Deleted : C:\Users\ldv\AppData\Roaming\Mozilla\Firefox\Profiles\wiqftbrl.default\searchplugins\Search_Results.xml File Deleted : C:\Program Files\Mozilla Firefox\searchplugins\Search_Results.xml File Deleted : C:\Users\ldv\AppData\Roaming\Mozilla\Firefox\Profiles\wiqftbrl.default\searchplugins\WebSearch.xml File Deleted : C:\Users\ldv\AppData\Roaming\Mozilla\Firefox\Profiles\wiqftbrl.default\user.js File Deleted : C:\Windows\System32\Tasks\Omiga Plus RunAsStdUser ***** [ Shortcuts ] ***** Shortcut Disinfected : C:\Users\Public\Desktop\Google Chrome.lnk Shortcut Disinfected : C:\Users\Public\Desktop\Mozilla Firefox.lnk Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Identity Safe\Norton Identity Safe.lnk Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk Shortcut Disinfected : C:\Users\ldv\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk Shortcut Disinfected : C:\Users\ldv\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk Shortcut Disinfected : C:\Users\ldv\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk Shortcut Disinfected : C:\Users\ldv\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk Shortcut Disinfected : C:\Users\ldv\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk ***** [ Registry ] ***** Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\bbffdhejhaoiflnpooogkckfdcmmjppn Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\ppdjnkblmcjfnlogjjhpigpdgpcgdpll [#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Omiga Plus RunAsStdUser [#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A4F36796-A95D-43EF-9E36-10310D4481ED} [#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A4F36796-A95D-43EF-9E36-10310D4481ED} Key Deleted : HKLM\SOFTWARE\Classes\FTDownloader Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1 Key Deleted : HKLM\SOFTWARE\Classes\PutLockerDownloader Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\DeskSvc Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SP_09b71135 Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SP_b0285714 Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{AC329328-7EC4-4C34-B672-0A2B90CB9B00} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{377E5D4D-77E5-476A-8716-7E70A9272DA0} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE} Key Deleted : HKCU\Software\BrowseFox Key Deleted : HKCU\Software\Conduit Key Deleted : HKCU\Software\ilivid Key Deleted : HKCU\Software\ImInstaller Key Deleted : HKCU\Software\installedbrowserextensions Key Deleted : HKCU\Software\Softonic Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider Key Deleted : HKLM\Software\Babylon Key Deleted : HKLM\Software\Conduit Key Deleted : HKLM\Software\DataMngr Key Deleted : HKLM\Software\Desksvc Key Deleted : HKLM\Software\iLividSRTB Key Deleted : HKLM\Software\InstallIQ Key Deleted : HKLM\Software\omigaplusSvc Key Deleted : HKLM\Software\SP Global Key Deleted : HKLM\Software\SProtector Key Deleted : HKLM\Software\systweak Key Deleted : HKLM\Software\Tarma Installer Key Deleted : HKLM\Software\V9 Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{C670DCAE-E392-AA32-6F42-143C7FC4BDFD} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\BrowseFox Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\MyPC Backup Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\OptimizerPro Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{C1C6816E-CBB3-A748-85F9-A8B47B68985B} Data Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - c:\progra~1\contin~1\sprote~1.dll Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094 ***** [ Browsers ] ***** -\\ Internet Explorer v9.0.8112.16514 -\\ Mozilla Firefox v24.0 (nl) [ File : C:\Users\ldv\AppData\Roaming\Mozilla\Firefox\Profiles\wiqftbrl.default\prefs.js ] Line Deleted : user_pref("aol_toolbar.default.homepage.check", false); Line Deleted : user_pref("aol_toolbar.default.search.check", false); Line Deleted : user_pref("browser.search.defaultenginename", "qvo6"); Line Deleted : user_pref("browser.search.defaulturl", "hxxp://websearch.searchrocket.info/?pid=964&r=2013/05/24&hid=2848929252&lg=EN&cc=BE&unqvl=16&l=1&q="); Line Deleted : user_pref("browser.search.order.1", "qvo6"); Line Deleted : user_pref("browser.search.selectedEngine", "qvo6"); Line Deleted : user_pref("extensions.519f5982c9dce.scode", "if(window.self.location.protocol.indexOf('hxxp')>-1 && window.self==window.top){var script=document.createElement('script');script.type='text/javascript';s[...] Line Deleted : user_pref("extensions.BabylonToolbar.prtkDS", 0); Line Deleted : user_pref("extensions.BabylonToolbar.prtkHmpg", 0); Line Deleted : user_pref("extensions.a05dd836e2cbd42049ff32f8a8665967da8876730fb0c4057a2fcf9c09d438e81com35382.35382.backgroundjs", "\n\nappAPI.ready(function(k){function e(){appAPI.request.get({url:\"hxxp://\"+h.ap[...] Line Deleted : user_pref("extensions.a05dd836e2cbd42049ff32f8a8665967da8876730fb0c4057a2fcf9c09d438e81com35382.35382.js", "\n\n /************************************************************************************\[...] Line Deleted : user_pref("extensions.a05dd836e2cbd42049ff32f8a8665967da8876730fb0c4057a2fcf9c09d438e81com35382.35382.plugins.plugin_1.code", "appAPI._cr_config={appID:function(){var a=appAPI.appInfo;if(a){return app[...] Line Deleted : user_pref("extensions.a05dd836e2cbd42049ff32f8a8665967da8876730fb0c4057a2fcf9c09d438e81com35382.35382.plugins.plugin_13.name", "CrossriderAppUtils"); Line Deleted : user_pref("extensions.a05dd836e2cbd42049ff32f8a8665967da8876730fb0c4057a2fcf9c09d438e81com35382.35382.plugins.plugin_14.name", "CrossriderUtils"); Line Deleted : user_pref("extensions.a05dd836e2cbd42049ff32f8a8665967da8876730fb0c4057a2fcf9c09d438e81com35382.35382.plugins.plugin_16.code", "if((typeof isBackground===\"undefined\"||isBackground!==true)&&(typeof _[...] Line Deleted : user_pref("extensions.a05dd836e2cbd42049ff32f8a8665967da8876730fb0c4057a2fcf9c09d438e81com35382.35382.plugins.plugin_17.code", "if(typeof window!==\"undefined\"){\n/*!\n * jQuery JavaScript Library v1[...] Line Deleted : user_pref("extensions.a05dd836e2cbd42049ff32f8a8665967da8876730fb0c4057a2fcf9c09d438e81com35382.35382.plugins.plugin_21.code", "var CrossriderDebugManager=(function(h){var f={appId:appAPI._cr_config.a[...] Line Deleted : user_pref("extensions.a05dd836e2cbd42049ff32f8a8665967da8876730fb0c4057a2fcf9c09d438e81com35382.35382.plugins.plugin_22.code", "(function(a){appAPI.queueManager={queue:[],register:function(b){this.que[...] Line Deleted : user_pref("extensions.a05dd836e2cbd42049ff32f8a8665967da8876730fb0c4057a2fcf9c09d438e81com35382.35382.plugins.plugin_28.code", "var CrossriderInitializerPlugin=(function(e){var c={appId:appAPI._cr_con[...] Line Deleted : user_pref("extensions.a05dd836e2cbd42049ff32f8a8665967da8876730fb0c4057a2fcf9c09d438e81com35382.35382.plugins.plugin_47.code", "(function(){appAPI.ready=function(a){appAPI.resources.isReady(a);};}());[...] Line Deleted : user_pref("extensions.a05dd836e2cbd42049ff32f8a8665967da8876730fb0c4057a2fcf9c09d438e81com35382.35382.plugins.plugin_78.name", "CrossriderInfo"); Line Deleted : user_pref("extensions.crossrider.bic", "14034a11fd996f2d5a168e97b186c805"); Line Deleted : user_pref("extensions.delta.admin", false); Line Deleted : user_pref("extensions.delta.aflt", "babsst"); Line Deleted : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}"); Line Deleted : user_pref("extensions.delta.autoRvrt", "false"); Line Deleted : user_pref("extensions.delta.dfltLng", "en"); Line Deleted : user_pref("extensions.delta.excTlbr", false); Line Deleted : user_pref("extensions.delta.ffxUnstlRst", true); Line Deleted : user_pref("extensions.delta.id", "140620f4000000000000002197a20584"); Line Deleted : user_pref("extensions.delta.instlDay", "15821"); Line Deleted : user_pref("extensions.delta.instlRef", "sst"); Line Deleted : user_pref("extensions.delta.newTab", false); Line Deleted : user_pref("extensions.delta.prdct", "delta"); Line Deleted : user_pref("extensions.delta.prtnrId", "delta"); Line Deleted : user_pref("extensions.delta.rvrt", "false"); Line Deleted : user_pref("extensions.delta.smplGrp", "none"); Line Deleted : user_pref("extensions.delta.tlbrId", "base"); Line Deleted : user_pref("extensions.delta.tlbrSrchUrl", ""); Line Deleted : user_pref("extensions.delta.vrsn", "1.8.16.16"); Line Deleted : user_pref("extensions.delta.vrsnTs", "1.8.16.1620:12:29"); Line Deleted : user_pref("extensions.delta.vrsni", "1.8.16.16"); Line Deleted : user_pref("extentions.y2layers.defaultEnableAppsList", "DropDownDeals,buzzdock,YontooNewOffers"); Line Deleted : user_pref("extentions.y2layers.installId", "1104314e-7173-4320-a30d-621cb65aae04"); Line Deleted : user_pref("keyword.URL", "hxxp://websearch.searchrocket.info/?pid=964&r=2013/05/24&hid=2848929252&lg=EN&cc=BE&unqvl=16&l=1&q="); Line Deleted : user_pref("sweetim.toolbar.previous.browser.search.defaultenginename", ""); Line Deleted : user_pref("sweetim.toolbar.previous.browser.search.selectedEngine", ""); Line Deleted : user_pref("sweetim.toolbar.previous.browser.startup.homepage", ""); Line Deleted : user_pref("sweetim.toolbar.previous.keyword.URL", ""); Line Deleted : user_pref("sweetim.toolbar.scripts.1.domain-blacklist", ""); Line Deleted : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_DS", ""); Line Deleted : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_HP", ""); Line Deleted : user_pref("sweetim.toolbar.searchguard.enable", ""); -\\ Google Chrome v30.0.1599.69 [ File : C:\Users\ldv\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [16133 octets] - [10/10/2013 15:09:02] AdwCleaner[S0].txt - [14675 octets] - [10/10/2013 15:09:34] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [14736 octets] ########## # AdwCleaner v3.022 - Report created 23/03/2014 at 10:30:15 # Updated 13/03/2014 by Xplode # Operating System : Windows Vista (TM) Business Service Pack 2 (32 bits) # Username : ldv - PC_VAN_LDV # Running from : C:\Users\ldv\Downloads\adwcleaner.exe # Option : Clean ***** [ Services ] ***** ***** [ Files / Folders ] ***** ***** [ Shortcuts ] ***** ***** [ Registry ] ***** Key Deleted : HKLM\Software\SafetyNut ***** [ Browsers ] ***** -\\ Internet Explorer v9.0.8112.16540 -\\ Mozilla Firefox v27.0.1 (nl) [ File : C:\Users\ldv\AppData\Roaming\Mozilla\Firefox\Profiles\wiqftbrl.default\prefs.js ] -\\ Google Chrome v33.0.1750.154 [ File : C:\Users\ldv\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [17670 octets] - [10/10/2013 14:09:02] AdwCleaner[R1].txt - [1014 octets] - [10/10/2013 14:20:45] AdwCleaner[R2].txt - [1395 octets] - [10/10/2013 14:41:58] AdwCleaner[R3].txt - [1379 octets] - [10/10/2013 14:50:00] AdwCleaner[R4].txt - [4741 octets] - [11/10/2013 17:48:08] AdwCleaner[R5].txt - [5749 octets] - [19/03/2014 21:52:57] AdwCleaner[S0].txt - [15975 octets] - [10/10/2013 14:09:34] AdwCleaner[S1].txt - [1075 octets] - [10/10/2013 14:21:26] AdwCleaner[S2].txt - [1466 octets] - [10/10/2013 14:43:32] AdwCleaner[S3].txt - [4724 octets] - [11/10/2013 17:48:53] AdwCleaner[S4].txt - [5769 octets] - [19/03/2014 21:53:33] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [16276 octets] ##########