# AdwCleaner v3.007 - Report created 16/10/2013 at 19:16:36 # Updated 09/10/2013 by Xplode # Operating System : Microsoft Windows XP Dodatek Service Pack 3 (32 bits) # Username : Mariush - MARIUSZ-5152694 # Running from : C:\Documents and Settings\Mariush\Moje dokumenty\Pobieranie\AdwCleaner.exe # Option : Scan ***** [ Services ] ***** Service Found : WsysSvc ***** [ Files / Folders ] ***** Folder Found C:\DOCUME~1\Mariush\USTAWI~1\Temp\eIntaller Folder Found C:\Documents and Settings\All Users\Dane aplikacji\eSafe ***** [ Shortcuts ] ***** Shortcut Found : C:\Documents and Settings\All Users\Pulpit\Mozilla Firefox.lnk ( hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=sc&from=cor&uid=WDCXWD5000AAKX-001CA0_WD-WCAYU858803488034&ts=1381942033 ) Shortcut Found : C:\Documents and Settings\All Users\Menu Start\Programy\Mozilla Firefox.lnk ( hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=sc&from=cor&uid=WDCXWD5000AAKX-001CA0_WD-WCAYU858803488034&ts=1381942033 ) Shortcut Found : C:\Documents and Settings\Mariush\Menu Start\Programy\Internet Explorer.lnk ( hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=sc&from=cor&uid=WDCXWD5000AAKX-001CA0_WD-WCAYU858803488034&ts=1381942033 ) Shortcut Found : C:\Documents and Settings\Mariush\Menu Start\Programy\Akcesoria\Narzędzia systemowe\Internet Explorer (bez dodatków).lnk ( hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=sc&from=cor&uid=WDCXWD5000AAKX-001CA0_WD-WCAYU858803488034&ts=1381942033 ) Shortcut Found : C:\Documents and Settings\Mariush\Dane aplikacji\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk ( hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=sc&from=cor&uid=WDCXWD5000AAKX-001CA0_WD-WCAYU858803488034&ts=1381942033 ) Shortcut Found : C:\Documents and Settings\Mariush\Dane aplikacji\Microsoft\Internet Explorer\Quick Launch\Uruchom przeglądarkę Internet Explorer.lnk ( hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=sc&from=cor&uid=WDCXWD5000AAKX-001CA0_WD-WCAYU858803488034&ts=1381942033 ) ***** [ Registry ] ***** Data Found : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command [(Default)] - "C:\Program Files\Mozilla Firefox\firefox.exe" hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=sc&from=cor&uid=WDCXWD5000AAKX-001CA0_WD-WCAYU858803488034&ts=1381942033 Data Found : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command [(Default)] - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=sc&from=cor&uid=WDCXWD5000AAKX-001CA0_WD-WCAYU858803488034&ts=1381942033 Key Found : HKCU\Software\InstallCore Key Found : HKLM\Software\eSafeSecControl Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WSysControl Key Found : HKLM\Software\qvo6Software Key Found : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WsysSvc Value Found : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Documents and Settings\All Users\Dane aplikacji\eSafe\eGdpSvc.exe] ***** [ Browsers ] ***** -\\ Internet Explorer v8.0.6001.18702 Setting Found : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=WDCXWD5000AAKX-001CA0_WD-WCAYU858803488034&ts=1381942033 Setting Found : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL] - hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=WDCXWD5000AAKX-001CA0_WD-WCAYU858803488034&ts=1381942033 Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL] - hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=WDCXWD5000AAKX-001CA0_WD-WCAYU858803488034&ts=1381942033 Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] - hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=WDCXWD5000AAKX-001CA0_WD-WCAYU858803488034&ts=1381942033 Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [SearchAssistant] - hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=WDCXWD5000AAKX-001CA0_WD-WCAYU858803488034&ts=1381942033&type=default&q={searchTerms} Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [CustomizeSearch] - hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=WDCXWD5000AAKX-001CA0_WD-WCAYU858803488034&ts=1381942033&type=default&q={searchTerms} -\\ Mozilla Firefox v24.0 (pl) [ File : C:\Documents and Settings\Mariush\Dane aplikacji\Mozilla\Firefox\Profiles\4iym9x7j.default\prefs.js ] Line Found : user_pref("browser.newtab.url", "hxxp://www.qvo6.com/newtab/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=nt&from=cor&uid=WDCXWD5000AAKX-001CA0_WD-WCAYU858803488034&ts=1381942033"); Line Found : user_pref("browser.search.defaultenginename", "qvo6"); Line Found : user_pref("browser.search.selectedEngine", "qvo6"); Line Found : user_pref("browser.startup.homepage", "hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=WDCXWD5000AAKX-001CA0_WD-WCAYU858803488034&ts=1381942033"); ************************* AdwCleaner[R0].txt - [15826 octets] - [14/10/2013 19:18:42] AdwCleaner[R1].txt - [5892 octets] - [16/10/2013 19:16:36] AdwCleaner[S0].txt - [14685 octets] - [14/10/2013 19:19:19] ########## EOF - C:\AdwCleaner\AdwCleaner[R1].txt - [6013 octets] ##########