# AdwCleaner v5.027 - Logfile created 30/12/2015 at 20:25:24 # Updated 30/12/2015 by Xplode # Database : 2015-12-30.1 [Server] # Operating system : Windows 7 Professional Service Pack 1 (x64) # Username : hp - HP-PC # Running from : C:\Users\hp\Downloads\adwcleaner_5.027.exe # Option : Cleaning # Support : http://toolslib.net/forum ***** [ Services ] ***** [-] Service Deleted : InternetUpdater [-] Service Deleted : PirritUpdater [-] Service Deleted : RegFltrX64 [-] Service Deleted : rgfltx64 ***** [ Folders ] ***** [-] Folder Deleted : C:\Program Files\Conduit [-] Folder Deleted : C:\Program Files (x86)\Bench [-] Folder Deleted : C:\Program Files (x86)\Conduit [-] Folder Deleted : C:\Program Files (x86)\Discount Dragon [-] Folder Deleted : C:\Program Files (x86)\eDealsPop [-] Folder Deleted : C:\Program Files (x86)\Linkey [-] Folder Deleted : C:\Program Files (x86)\Pirrit [-] Folder Deleted : C:\Program Files (x86)\predm [-] Folder Deleted : C:\Program Files (x86)\SearchProtect [-] Folder Deleted : C:\Program Files (x86)\Settings Manager [-] Folder Deleted : C:\Program Files (x86)\WinRST [-] Folder Deleted : C:\Program Files (x86)\edealpop [-] Folder Deleted : C:\ProgramData\Conduit [-] Folder Deleted : C:\ProgramData\InternetUpdater [-] Folder Deleted : C:\ProgramData\RHelpers [-] Folder Deleted : C:\ProgramData\systemk [-] Folder Deleted : C:\ProgramData\Updater [-] Folder Deleted : C:\ProgramData\Websteroids [-] Folder Deleted : C:\ProgramData\{aa72e467-1a4d-d67c-aa72-2e4671a4919c} [-] Folder Deleted : C:\ProgramData\{cac07911-0443-1ffd-cac0-07911044e444} [-] Folder Deleted : C:\Users\hp\AppData\Local\BenchUpdater [-] Folder Deleted : C:\Users\hp\AppData\Local\Conduit [-] Folder Deleted : C:\Users\hp\AppData\Local\Discount Dragon [-] Folder Deleted : C:\Users\hp\AppData\Local\Pirrit Suggestor [-] Folder Deleted : C:\Users\hp\AppData\Local\SearchProtect [-] Folder Deleted : C:\Users\hp\AppData\Local\WinRST [-] Folder Deleted : C:\Users\hp\AppData\Local\CheckCode [-] Folder Deleted : C:\Users\hp\AppData\Local\HelperApp [-] Folder Deleted : C:\Users\hp\AppData\Local\tuto4pc_fr_13 [-] Folder Deleted : C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl [-] Folder Deleted : C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\nafaimnnclfjfedmmabolbppcngeolgf [-] Folder Deleted : C:\Users\hp\AppData\LocalLow\Conduit [-] Folder Deleted : C:\Users\hp\AppData\LocalLow\PriceGong [-] Folder Deleted : C:\Users\hp\AppData\Roaming\Pirrit [-] Folder Deleted : C:\Users\hp\AppData\Roaming\Systweak [-] Folder Deleted : C:\Users\hp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Discount Dragon [#] Folder Deleted : C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\Extensions\suggestor@suggestor.pirrit.com.xpi [-] Folder Deleted : C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\xiqve2pr.default\astrmndant [#] Folder Deleted : C:\Windows\SysNative\Tasks\wse_astromenda [-] Folder Deleted : C:\Windows\SysWOW64\SearchProtect ***** [ Files ] ***** [-] File Deleted : C:\END [-] File Deleted : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\default-search.xml [-] File Deleted : C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_mppnoffgpafgpgbaigljliadgbnhljfl_0.localstorage [-] File Deleted : C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_nafaimnnclfjfedmmabolbppcngeolgf_0.localstorage [-] File Deleted : C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\searchplugins\astromenda.xml [-] File Deleted : C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\user.js [-] File Deleted : C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\xiqve2pr.default\invalidprefs.js [-] File Deleted : C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\xiqve2pr.default\searchplugins\astromenda.xml [-] File Deleted : C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\xiqve2pr.default\searchplugins\default-search.xml [-] File Deleted : C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\xiqve2pr.default\searchplugins\trovi-search.xml [-] File Deleted : C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\xiqve2pr.default\user.js [-] File Deleted : C:\Windows\AppPatch\Custom\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb [-] File Deleted : C:\Windows\AppPatch\Custom\Custom64\{cf2797aa-b7ec-e311-8ed9-005056c00008}.sdb [-] File Deleted : C:\Windows\SysNative\roboot64.exe ***** [ DLLs ] ***** ***** [ Shortcuts ] ***** ***** [ Scheduled tasks ] ***** [-] Task Deleted : bench-sys [-] Task Deleted : WSE_Astromenda [-] Task Deleted : bench-S-1-5-21-1902466115-555383110-2771929642-1000 [-] Task Deleted : bench-sys [-] Task Deleted : bench-S-1-5-21-1902466115-555383110-2771929642-1000 [-] Task Deleted : bench-sys ***** [ Registry ] ***** [-] Key Deleted : HKLM\SOFTWARE\Classes\speedupmypc [-] Key Deleted : HKLM\SOFTWARE\Google\Chrome\NativeMessagingHosts\com.bench.nmhost [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe [-] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [eDealsPop] [-] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [Wd] [-] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [eDealPop] [-] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [BService64] [-] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [fst_ca_9] [-] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3294791 [-] Key Deleted : HKCU\Software\Classes\CLSID\{DB40EAF2-2025-4F74-B9EF-7C0782F26C84} [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C} [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E993643-8FBC-44FE-BC85-D318495C4D96} [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D40C654D-7C51-4EB3-95B2-1E23905C2A2D} [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6} [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EA34C851-D481-49F5-A356-3A8B0A8F3B7E} [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{BE496A80-8F51-461F-B3D7-88A258A60541} [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762} [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DB40EAF2-2025-4F74-B9EF-7C0782F26C84} [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D40C654D-7C51-4EB3-95B2-1E23905C2A2D} [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA34C851-D481-49F5-A356-3A8B0A8F3B7E} [-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D40C654D-7C51-4EB3-95B2-1E23905C2A2D} [-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EA34C851-D481-49F5-A356-3A8B0A8F3B7E} [-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47} [-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{54739D49-AC03-4C57-9264-C5195596B3A1} [-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D40C654D-7C51-4EB3-95B2-1E23905C2A2D} [-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EA34C851-D481-49F5-A356-3A8B0A8F3B7E} [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{93DBF2BB-A2B3-4683-A92E-57E60751F346} [-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C} [-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6} [-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{BE496A80-8F51-461F-B3D7-88A258A60541} [-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47} [-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{93DBF2BB-A2B3-4683-A92E-57E60751F346} [-] Key Deleted : HKCU\Software\Conduit [-] Key Deleted : HKCU\Software\IM [-] Key Deleted : HKCU\Software\InstallCore [-] Key Deleted : HKCU\Software\Softonic [-] Key Deleted : HKCU\Software\SweetIM [-] Key Deleted : HKCU\Software\SystemK [-] Key Deleted : HKCU\Software\Tune [-] Key Deleted : HKCU\Software\Tutorials [-] Key Deleted : HKCU\Software\TutoTag [-] Key Deleted : HKCU\Software\Linkey [-] Key Deleted : HKCU\Software\AppDataLow\Software\Conduit [-] Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes [-] Key Deleted : HKCU\Software\AppDataLow\Software\DynConIE [-] Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong [-] Key Deleted : HKLM\SOFTWARE\AdvertisingSupport [-] Key Deleted : HKLM\SOFTWARE\Bench [-] Key Deleted : HKLM\SOFTWARE\Conduit [-] Key Deleted : HKLM\SOFTWARE\Discount Dragon [-] Key Deleted : HKLM\SOFTWARE\FreeSoftToday [-] Key Deleted : HKLM\SOFTWARE\Pirrit [-] Key Deleted : HKLM\SOFTWARE\SearchProtect [-] Key Deleted : HKLM\SOFTWARE\SweetIM [-] Key Deleted : HKLM\SOFTWARE\SystemK [-] Key Deleted : HKLM\SOFTWARE\Tune [-] Key Deleted : HKLM\SOFTWARE\Tutorials [-] Key Deleted : HKLM\SOFTWARE\Uniblue [!] Key Not Deleted : HKLM\SOFTWARE\Uniblue\DriverScanner [-] Key Deleted : HKLM\SOFTWARE\Upt [-] Key Deleted : HKLM\SOFTWARE\WinUpd [-] Key Deleted : HKLM\SOFTWARE\SI-App [-] Key Deleted : HKLM\SOFTWARE\RST [-] Key Deleted : HKLM\SOFTWARE\SPPDCOM [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\eDealsPop_is1 [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\eDeals_is1 [-] Key Deleted : [x64] HKLM\SOFTWARE\Discount Dragon [-] Key Deleted : [x64] HKLM\SOFTWARE\DomaIQ [-] Key Deleted : [x64] HKLM\SOFTWARE\Pirrit [-] Key Deleted : [x64] HKLM\SOFTWARE\Upt [-] Key Deleted : [x64] HKLM\SOFTWARE\WinUpd [-] Key Deleted : [x64] HKLM\SOFTWARE\SI-App [-] Key Deleted : [x64] HKLM\SOFTWARE\RST [-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C168639F-5810-4EC8-B1E8-0251AA8A771C} [!] Key Not Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe [!] Key Not Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe [!] Key Not Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip [!] Key Not Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe [-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} [-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9} [-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{632F07F3-19A1-4d16-A23F-E6CE9486BAB5} [-] Data Restored : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope] [-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} [-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{F2078CDC-2089-4B98-A801-ADAC600A3D50} [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} ***** [ Web browsers ] ***** [-] [C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\prefs.js] [Preference] Deleted : user_pref("browser.startup.homepage", "hxxp://ca.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_wnzp_15_19¶m1=1¶m2=f%3D1%26b%3DFirefox%26cc%3Dca%26pa%3DWinYahoo%26[...] [-] [C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\xiqve2pr.default\prefs.js] [Preference] Deleted : user_pref("browser.newtab.url", "hxxp://search.conduit.com/?ctid=CT3314958&octid=EB_ORIGINAL_CTID&SearchSource=69&CUI=&SSPV=&Lay=1&UM=2&UP=SP5E34F31C-C7EF-4A86-81F6-0BC2FAFEDC3C"); [-] [C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\xiqve2pr.default\prefs.js] [Preference] Deleted : user_pref("browser.search.order.1", "default-search.net"); [-] [C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\xiqve2pr.default\prefs.js] [Preference] Deleted : user_pref("extensions.astrmndasr.hmpgUrl", "hxxp://astromenda.com/?f=1&a=ast_wnzp01_14_42_ff&cd=2XzuyEtN2Y1L1Qzu0Dzzzy0DyCyBzyzytCyD0EtByDyEtCyDtN0D0Tzu0StCtDtBtAtN1L2XzutAtFyDtFtCtFyEtN1L1CzutCyEtBzy[...] [-] [C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\xiqve2pr.default\prefs.js] [Preference] Deleted : user_pref("extensions.astrmndasr.newTabUrl", "hxxp://astromenda.com/?f=2&a=ast_wnzp01_14_42_ff&cd=2XzuyEtN2Y1L1Qzu0Dzzzy0DyCyBzyzytCyD0EtByDyEtCyDtN0D0Tzu0StCtDtBtAtN1L2XzutAtFyDtFtCtFyEtN1L1CzutCyEtB[...] [-] [C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\xiqve2pr.default\prefs.js] [Preference] Deleted : user_pref("extensions.astrmndasr.prtnrId", "WSE_Astromenda"); [-] [C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\xiqve2pr.default\prefs.js] [Preference] Deleted : user_pref("extensions.astrmndasr.srchPrvdr", "Astromenda"); [-] [C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\xiqve2pr.default\prefs.js] [Preference] Deleted : user_pref("extensions.astrmndasr.tlbrSrchUrl", "hxxp://astromenda.com/?f=3&a=ast_wnzp01_14_42_ff&cd=2XzuyEtN2Y1L1Qzu0Dzzzy0DyCyBzyzytCyD0EtByDyEtCyDtN0D0Tzu0StCtDtBtAtN1L2XzutAtFyDtFtCtFyEtN1L1CzutCyE[...] [-] [C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\xiqve2pr.default\prefs.js] [Preference] Deleted : user_pref("extensions.dynconff.cache.diaporama-photo-pratic.softonic.fr.content", "\r\n "); [-] [C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\xiqve2pr.default\prefs.js] [Preference] Deleted : user_pref("extensions.dynconff.cache.search.conduit.com.expires", "1390104382486"); [-] [C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\xiqve2pr.default\prefs.js] [Preference] Deleted : user_pref("extensions.dynconff.cache.www.softonic.fr.content", "\r\n