# AdwCleaner v3.311 - Report created 06/10/2014 at 15:30:47 # Updated 30/09/2014 by Xplode # Operating System : Windows 7 Ultimate Service Pack 1 (32 bits) # Username : Luce - LUCE-PC # Running from : C:\Users\Luce\Downloads\adwcleaner_3.311.exe # Option : Scan ***** [ Services ] ***** Service Found : IePluginServices ***** [ Files / Folders ] ***** File Found : C:\Program Files\Mozilla Firefox\browser\searchplugins\default-search.xml File Found : C:\Program Files\Mozilla Firefox\user.js File Found : C:\Users\Bart & Leen\daemonprocess.txt File Found : C:\Users\Luce\AppData\Roaming\LiveSupport.exe_log.txt File Found : C:\Users\Luce\AppData\Roaming\Mozilla\Firefox\Profiles\ukec3ixn.default\searchplugins\default-search.xml File Found : C:\Users\Luce\AppData\Roaming\regsvr32.exe_log.txt File Found : C:\Users\Luce\daemonprocess.txt File Found : C:\Users\Luce\Desktop\Mobogenie.lnk File Found : C:\Users\Public\Desktop\EZDownloader.lnk File Found : C:\Windows\system32\roboot.exe Folder Found : C:\Program Files\BonanzaDeals Folder Found : C:\Program Files\BonanzaDealsLive Folder Found : C:\Program Files\EZDownloader Folder Found : C:\Program Files\FlvPlayer Folder Found : C:\Program Files\globalUpdate Folder Found : C:\Program Files\Mobogenie Folder Found : C:\Program Files\NCH Software Folder Found : C:\Program Files\SupTab Folder Found : C:\Program Files\TornTV.com Folder Found : C:\ProgramData\2308189059 Folder Found : C:\ProgramData\BonanzaDealsLive Folder Found : C:\ProgramData\IePluginServices Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EZDownloader Folder Found : C:\ProgramData\NCH Software Folder Found : C:\ProgramData\StarApp Folder Found : C:\ProgramData\WindowsMangerProtect Folder Found : C:\Users\Luce\AppData\Local\BonanzaDealsLive Folder Found : C:\Users\Luce\AppData\Local\genienext Folder Found : C:\Users\Luce\AppData\Local\globalUpdate Folder Found : C:\Users\Luce\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck Folder Found : C:\Users\Luce\AppData\Local\Mobogenie Folder Found : C:\Users\Luce\AppData\Local\playnowradio Folder Found : C:\Users\Luce\AppData\LocalLow\DataMngr Folder Found : C:\Users\Luce\AppData\Roaming\0F1F1C2Y1H1P1C0I0T Folder Found : C:\Users\Luce\AppData\Roaming\EZDownloader Folder Found : C:\Users\Luce\AppData\Roaming\FirefoxToolbar Folder Found : C:\Users\Luce\AppData\Roaming\istartsurf Folder Found : C:\Users\Luce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mobogenie Folder Found : C:\Users\Luce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TornTV.com Folder Found : C:\Users\Luce\AppData\Roaming\NCH Software Folder Found : C:\Users\Luce\AppData\Roaming\newnext.me Folder Found : C:\Users\Luce\AppData\Roaming\OpenCandy Folder Found : C:\Users\Luce\AppData\Roaming\Systweak Folder Found : C:\Users\Luce\AppData\Roaming\WebExtend Folder Found : C:\Users\Luce\Documents\Mobogenie Folder Found : C:\Users\Luce\Documents\Optimizer Pro Folder Found : C:\Users\Public\Documents\Goobzo Folder Found : C:\Users\Public\Documents\YTAHelper Folder Found : C:\Windows\system32\SearchProtect ***** [ Scheduled Tasks ] ***** Task Found : Express FilesUpdate ***** [ Shortcuts ] ***** ***** [ Registry ] ***** Key Found : HKCU\Software\1ClickDownload Key Found : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F} Key Found : HKCU\Software\AppDataLow\Software\Crossrider Key Found : HKCU\Software\AppDataLow\Software\lyricsspeaker Key Found : HKCU\Software\AppDataLow\Software\simplytech Key Found : HKCU\Software\BonanzaDealsLive Key Found : HKCU\Software\GlobalUpdate Key Found : HKCU\Software\Goobzo Key Found : HKCU\Software\InstallCore Key Found : HKCU\Software\Linkey Key Found : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\superfish.com Key Found : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.superfish.com Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{54739D49-AC03-4C57-9264-C5195596B3A1} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} Key Found : HKCU\Software\Optimizer Pro Key Found : HKCU\Software\Softonic Key Found : HKCU\Software\SupHpUISoft Key Found : HKCU\Software\systweak Key Found : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F} Key Found : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0} Key Found : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C} Key Found : HKLM\SOFTWARE\BonanzaDealsLive Key Found : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F} Key Found : HKLM\SOFTWARE\Classes\Interface\{6F43FA77-C18F-4D0C-9C7E-958876FE2061} Key Found : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5} Key Found : HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F} Key Found : HKLM\SOFTWARE\Classes\Interface\{DF948646-8BF4-450E-A059-CF8A4E0FE2BE} Key Found : HKLM\SOFTWARE\Classes\Interface\{E96B49B0-E11F-48FC-984A-EEC29A4F57E1} Key Found : HKLM\SOFTWARE\GlobalUpdate Key Found : HKLM\SOFTWARE\Goobzo Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\nbmafkdmkkckhggblphicnnhlgljnoje Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\ndgonipadfipmlmdfofnjnhhlgojnjdn Key Found : HKLM\SOFTWARE\istartsurfSoftware Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} Key Found : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS Key Found : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker_RASAPI32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker_RASMANCS Key Found : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker-1_RASAPI32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker-1_RASMANCS Key Found : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs Key Found : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs Key Found : HKLM\SOFTWARE\Microsoft\Tracing\avg-secure-search-installer_RASAPI32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\avg-secure-search-installer_RASMANCS Key Found : HKLM\SOFTWARE\Microsoft\Tracing\Searchqu Toolbar uninstall_RASAPI32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\Searchqu Toolbar uninstall_RASMANCS Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SearchSettings_RASAPI32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SearchSettings_RASMANCS Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_winrar_RASAPI32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_winrar_RASMANCS Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_voor_bittorrent_RASAPI32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_voor_bittorrent_RASMANCS Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_voor_freerip-mp3_RASAPI32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_voor_freerip-mp3_RASMANCS Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_voor_stickies_RASAPI32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_voor_stickies_RASMANCS Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_voor_vlc-media-player_RASAPI32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_voor_vlc-media-player_RASMANCS Key Found : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS Key Found : HKLM\SOFTWARE\Microsoft\Tracing\Torntv Downloader_RASAPI32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\Torntv Downloader_RASMANCS Key Found : HKLM\SOFTWARE\Microsoft\Tracing\YontooDesktop_RASAPI32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\YontooDesktop_RASMANCS Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\BonanzaDealsLive.exe Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Mobogenie.exe Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\00E944CB89111313EAF35A0553F547F9 Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\53F55AF3F4049ED3FA6EA6F88E414E24 Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\68E4BF4B11615E03C97732FD581AB607 Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8CE3DDAB2D152683FBCEB4866BCD2B0F Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AF6CE16AFEA5C9A39B766468A8B35C21 Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FB1E44269B58F433A8C8E671E37CFDCF Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0F44DC3A-6E62-4961-A14B-95323C512F9B}_is1 Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mobogenie Key Found : HKLM\SOFTWARE\SmdmF Key Found : HKLM\SOFTWARE\SupDp Key Found : HKLM\SOFTWARE\SupTab Key Found : HKLM\SOFTWARE\supWindowsMangerProtect Key Found : HKLM\SOFTWARE\supWPM Key Found : HKLM\SOFTWARE\systweak Key Found : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IePluginServices Key Found : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect Value Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [livesupport] Value Found : HKCU\Software\Mozilla\Firefox\Extensions [lspeaker@lyricsspeaker.net] Value Found : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x64] Value Found : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x64] Value Found : HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\AppCertDlls [x64] ***** [ Browsers ] ***** -\\ Internet Explorer v11.0.9600.17280 Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL] - hxxp://www.istartsurf.com/web/?type=ds&ts=1411983200&from=smt&uid=WDCXWD5000AADS-00L4B1_WD-WCAUK148038280382&q={searchTerms} Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] - hxxp://www.istartsurf.com/web/?type=ds&ts=1411983200&from=smt&uid=WDCXWD5000AADS-00L4B1_WD-WCAUK148038280382&q={searchTerms} -\\ Mozilla Firefox v32.0.3 (x86 nl) [ File : C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\sztsgv0g.default\prefs.js ] Line Found : user_pref("extensions.wrc.SearchRules.ask.com.style", ".WRCN {display:none} #yui-main .tsrc_vnru .title + .WRCN, #yui-main #teoma-results .title + .WRCN {display:inline !important; background: url(\"I[...] Line Found : user_pref("extensions.wrc.SearchRules.ask.com.url", "^hxxp(s)?\\:\\/\\/(.+\\.)?ask\\.com\\/.*"); Line Found : user_pref("extensions.wrc.SearchRules.rambler.ru.style", ".WRCN {display:none} .search-results .title + .WRCN {display:inline !important; background: url(\"IMAGE\") right no-repeat}"); [ File : C:\Users\Bart & Leen\AppData\Roaming\Mozilla\Firefox\Profiles\96kg30ij.default\prefs.js ] [ File : C:\Users\Luce\AppData\Roaming\Mozilla\Firefox\Profiles\i56pb4nz.default\prefs.js ] [ File : C:\Users\Luce\AppData\Roaming\Mozilla\Firefox\Profiles\ukec3ixn.default\prefs.js ] Line Found : user_pref("browser.search.order.1", "default-search.net"); Line Found : user_pref("extensions.crossrider.bic", "148c1196c30db918acd248f0f83af954"); Line Found : user_pref("extensions.quick_start.enable_search1", false); Line Found : user_pref("extensions.quick_start.sd.closeWindowWithLastTab_prev_state", false); Line Found : user_pref("extensions.toolbar.mindspark._12Members_.hp.user.defined", true); Line Found : user_pref("extensions.toolbar.mindspark._12Members_.initialized", true); Line Found : user_pref("extensions.toolbar.mindspark._12Members_.installation.contextKey", ""); Line Found : user_pref("extensions.toolbar.mindspark._12Members_.installation.installDate", "2012090213"); Line Found : user_pref("extensions.toolbar.mindspark._12Members_.installation.partnerId", "9Nxdm080YYbe"); Line Found : user_pref("extensions.toolbar.mindspark._12Members_.installation.partnerSubId", "CKeUtNvBlrICFUZN3goduyAAvA"); Line Found : user_pref("extensions.toolbar.mindspark._12Members_.installation.success", true); Line Found : user_pref("extensions.toolbar.mindspark._12Members_.installation.toolbarId", "CCBB0A76-1D18-425B-B436-9A71C1D88A31"); Line Found : user_pref("extensions.toolbar.mindspark._12Members_.lastActivePing", "1358345998217"); Line Found : user_pref("extensions.toolbar.mindspark._12Members_.options.defaultSearch", false); Line Found : user_pref("extensions.toolbar.mindspark._12Members_.options.homePageEnabled", false); Line Found : user_pref("extensions.toolbar.mindspark._12Members_.options.keywordEnabled", false); Line Found : user_pref("extensions.toolbar.mindspark._12Members_.options.tabEnabled", false); Line Found : user_pref("extensions.toolbar.mindspark._12Members_.searchHistory", "poppemie.blogspot.be"); Line Found : user_pref("extensions.toolbar.mindspark._12Members_.weather.location", "10001"); Line Found : user_pref("extensions.toolbar.mindspark.lastInstalled", "myscrapnook@mindspark.com"); Line Found : user_pref("keyword.URL", "hxxp://www.default-search.net/search?sid=476&aid=135&itype=n&ver=13892&tm=485&src=ds&p="); -\\ Google Chrome v37.0.2062.124 [ File : C:\Users\Bart & Leen\AppData\Local\Google\Chrome\User Data\Default\preferences ] Found [Search Provider] : hxxp://isearch.avg.com/search?cid={454A055D-E4ED-45CA-97E4-41BEE91918FB}&mid=960d4fd5a40e47d09e74d16f5ecf7883-84a3e1f3113ef6b838d7ef7e88777c55baf5023c&lang=en&ds=gm011&pr=sa&d=2013-01-11 18:50:31&v=13.2.0.5&sap=dsp&q={searchTerms} Found [Search Provider] : hxxp://search.certified-toolbar.com?si=44393&st=bs&tid=3786&ver=2.9&ts=1368279163388&tguid=44393-3786-1368279163388-FA3C67FF12B1D19CCD43F32DDA905E96&q={searchTerms} Found [Homepage] : hxxp://search.certified-toolbar.com?si=44393&st=home&tid=3786&ver=2.9&ts=1368279163388&tguid=44393-3786-1368279163388-FA3C67FF12B1D19CCD43F32DDA905E96 [ File : C:\Users\Luce\AppData\Local\Google\Chrome\User Data\Default\preferences ] Found [Search Provider] : hxxp://websearch.pu-results.info/?l=1&q={searchTerms}&pid=708&r=2013/05/18&hid=588773379&lg=EN&cc=BE Found [Search Provider] : hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3325585&octid=EB_ORIGINAL_CTID&ISID=MBB36BE54-17CF-4C02-966D-67E9E4217EB2&SearchSource=58&CUI=&UM=6&UP=SPD79A0ADF-A9E9-4B7D-9622-C6DEC36B2889&q={searchTerms}&SSPV= Found [Startup_urls] : hxxp://www.istartsurf.com/?type=hp&ts=1411983200&from=smt&uid=WDCXWD5000AADS-00L4B1_WD-WCAUK148038280382 Found [Homepage] : hxxp://www.trovi.com/?gd=&ctid=CT3325585&octid=EB_ORIGINAL_CTID&ISID=MBB36BE54-17CF-4C02-966D-67E9E4217EB2&SearchSource=55&CUI=&UM=6&UP=SPD79A0ADF-A9E9-4B7D-9622-C6DEC36B2889&SSPV= Found [Extension] : abepbblpkilpjohncjbccmdjhdhbnhdj Found [Extension] : booedmolknjekdopkepjjeckmjkdpfgl Found [Extension] : eofcbnmajmjmplflapaojjnihcjkigck Found [Extension] : flpcjncodpafbgdpnkljologafpionhb Found [Extension] : ndgonipadfipmlmdfofnjnhhlgojnjdn ************************* AdwCleaner[R0].txt - [16104 octets] - [06/10/2014 15:30:47] ########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [16165 octets] ##########