# AdwCleaner v3.005 - Report created 24/09/2013 at 12:17:07 # Updated 22/09/2013 by Xplode # Operating System : Windows 7 Ultimate (32 bits) # Username : Keleth - KELETH-KOMPUTER # Running from : C:\Users\Keleth\Downloads\AdwCleaner.exe # Option : Scan ***** [ Services ] ***** Service Found : WsysSvc ***** [ Files / Folders ] ***** File Found : C:\Program Files\Mozilla Firefox\searchplugins\qvo6.xml File Found : C:\Users\Keleth\AppData\Roaming\Mozilla\Firefox\Profiles\4fl6zdln.default-1380017284166\user.js Folder Found C:\ProgramData\Babylon Folder Found C:\ProgramData\eSafe Folder Found C:\Users\Keleth\AppData\Local\DProtect Folder Found C:\Users\Keleth\AppData\Local\lollipop Folder Found C:\Users\Keleth\AppData\Local\Temp\DProtect Folder Found C:\Users\Keleth\AppData\Local\Temp\eIntaller Folder Found C:\Users\Keleth\AppData\LocalLow\SimplyTech Folder Found C:\Users\Keleth\AppData\Roaming\0D0S1L2Z1P1B0T1P1B2Z Folder Found C:\Users\Keleth\AppData\Roaming\digitalsite ***** [ Shortcuts ] ***** Shortcut Found : C:\Users\Public\Desktop\Google Chrome.lnk ( hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=sc&from=cor&uid=WDCXWD5000AAKS-00D2B0_WD-WCASY567551075510&ts=1380017520 ) Shortcut Found : C:\Users\Public\Desktop\Mozilla Firefox.lnk ( hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=sc&from=cor&uid=WDCXWD5000AAKS-00D2B0_WD-WCASY567551075510&ts=1380017520 ) Shortcut Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk ( hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=sc&from=cor&uid=WDCXWD5000AAKS-00D2B0_WD-WCASY567551075510&ts=1380017520 ) Shortcut Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk ( hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=sc&from=cor&uid=WDCXWD5000AAKS-00D2B0_WD-WCASY567551075510&ts=1380017520 ) Shortcut Found : C:\Users\Keleth\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk ( hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=sc&from=cor&uid=WDCXWD5000AAKS-00D2B0_WD-WCASY567551075510&ts=1380017520 ) Shortcut Found : C:\Users\Keleth\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk ( hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=sc&from=cor&uid=WDCXWD5000AAKS-00D2B0_WD-WCASY567551075510&ts=1380017520 ) Shortcut Found : C:\Users\Keleth\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk ( hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=sc&from=cor&uid=WDCXWD5000AAKS-00D2B0_WD-WCASY567551075510&ts=1380017520 ) Shortcut Found : C:\Users\Keleth\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk ( hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=sc&from=cor&uid=WDCXWD5000AAKS-00D2B0_WD-WCASY567551075510&ts=1380017520 ) Shortcut Found : C:\Users\Keleth\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk ( hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=sc&from=cor&uid=WDCXWD5000AAKS-00D2B0_WD-WCASY567551075510&ts=1380017520 ) Shortcut Found : C:\Users\Keleth\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk ( hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=sc&from=cor&uid=WDCXWD5000AAKS-00D2B0_WD-WCASY567551075510&ts=1380017520 ) ***** [ Registry ] ***** Data Found : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command [(Default)] - "C:\Program Files\Mozilla Firefox\firefox.exe" hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=sc&from=cor&uid=WDCXWD5000AAKS-00D2B0_WD-WCASY567551075510&ts=1380017520 Data Found : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command [(Default)] - "C:\Program Files\Google\Chrome\Application\chrome.exe" hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=sc&from=cor&uid=WDCXWD5000AAKS-00D2B0_WD-WCASY567551075510&ts=1380017520 Data Found : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command [(Default)] - "C:\Program Files\Internet Explorer\iexplore.exe" hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=sc&from=cor&uid=WDCXWD5000AAKS-00D2B0_WD-WCASY567551075510&ts=1380017520 Key Found : HKCU\Software\AppDataLow\Software\simplytech Key Found : HKCU\Software\AppDataLow\SProtector Key Found : HKCU\Software\BabSolution Key Found : HKCU\Software\BI Key Found : HKCU\Software\dsiteproducts Key Found : HKCU\Software\InstallCore Key Found : HKCU\Software\lollipop Key Found : HKCU\Software\simplytech Key Found : HKCU\Software\Softonic Key Found : HKLM\Software\Babylon Key Found : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56} Key Found : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3} Key Found : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3} Key Found : HKLM\SOFTWARE\Classes\AppID\secman.DLL Key Found : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} Key Found : HKLM\SOFTWARE\Classes\Prod.cap Key Found : HKLM\Software\Conduit Key Found : HKLM\Software\eSafeSecControl Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CFD485F0-96BD-47CD-BB6D-CD7DDA95F102} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} Key Found : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_dla_gadu-gadu-10_RASAPI32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_dla_gadu-gadu-10_RASMANCS Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_dla_minecraft(1)_RASAPI32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_dla_minecraft(1)_RASMANCS Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_dla_minecraft_RASAPI32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_dla_minecraft_RASMANCS Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_dla_mp3-cut_RASAPI32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_dla_mp3-cut_RASMANCS Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_dla_mumble_RASAPI32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_dla_mumble_RASMANCS Key Found : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASAPI32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASMANCS Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WSysControl Key Found : HKLM\Software\qvo6Software Key Found : HKLM\Software\SP Global Key Found : HKLM\Software\SProtector Key Found : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WsysSvc ***** [ Browsers ] ***** -\\ Internet Explorer v8.0.7600.16385 Setting Found : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=WDCXWD5000AAKS-00D2B0_WD-WCASY567551075510&ts=1380017504 Setting Found : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL] - hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=WDCXWD5000AAKS-00D2B0_WD-WCASY567551075510&ts=1380017504 Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL] - hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=WDCXWD5000AAKS-00D2B0_WD-WCASY567551075510&ts=1380017504 Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] - hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=WDCXWD5000AAKS-00D2B0_WD-WCASY567551075510&ts=1380017504 Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [Tabs] - hxxp://www.qvo6.com/newtab/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=nt&from=cor&uid=WDCXWD5000AAKS-00D2B0_WD-WCASY567551075510&ts=1380017504 Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [bProtectTabs] - hxxp://www1.delta-search.com/?affID=119816&tt=gc_170513_18210&babsrc=NT_ss&mntrId=E02D00241D2E6EDF Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Start Page] - hxxp://search.certified-toolbar.com?si=41460&st=home&tid=2938&ver=3.2&ts=1370286447047&tguid=41460-2938-1370286447047-EB99EA4BA3DCB0021135EB0BC28542BD Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Start Default_Page_URL] - hxxp://search.certified-toolbar.com?si=41460&st=home&tid=2938&ver=3.2&ts=1370286447047&tguid=41460-2938-1370286447047-EB99EA4BA3DCB0021135EB0BC28542BD Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Default_Search_URL] - hxxp://search.certified-toolbar.com?si=41460&tid=2938&ver=3.2&ts=1370286447047&tguid=41460-2938-1370286447047-EB99EA4BA3DCB0021135EB0BC28542BD&st=chrome&q= Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Search Bar] - hxxp://search.certified-toolbar.com?si=41460&tid=2938&ver=3.2&ts=1370286447047&tguid=41460-2938-1370286447047-EB99EA4BA3DCB0021135EB0BC28542BD&st=chrome&q= Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Search Page] - hxxp://search.certified-toolbar.com?si=41460&tid=2938&ver=3.2&ts=1370286447047&tguid=41460-2938-1370286447047-EB99EA4BA3DCB0021135EB0BC28542BD&st=chrome&q= Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [CustomizeSearch] - hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=WDCXWD5000AAKS-00D2B0_WD-WCASY567551075510&ts=1380017504&type=default&q={searchTerms} Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [SearchAssistant] - hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=WDCXWD5000AAKS-00D2B0_WD-WCASY567551075510&ts=1380017504&type=default&q={searchTerms} -\\ Mozilla Firefox v23.0.1 (pl) [ File : C:\Users\Keleth\AppData\Roaming\Mozilla\Firefox\Profiles\4fl6zdln.default-1380017284166\prefs.js ] Line Found : user_pref("browser.search.defaultenginename", "qvo6"); Line Found : user_pref("browser.search.order.1", "qvo6"); -\\ Google Chrome v29.0.1547.76 [ File : C:\Users\Keleth\AppData\Local\Google\Chrome\User Data\Default\preferences ] Found : homepage Found : search_url Found : keyword Found : urls_to_restore_on_startup ************************* AdwCleaner[R0].txt - [11059 octets] - [24/09/2013 12:17:07] ########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [11120 octets] ##########