# AdwCleaner v4.208 - Logfile created 14/08/2015 at 12:37:42 # Updated 09/07/2015 by Xplode # Database : 2015-08-14.2 [Server] # Operating system : Microsoft Windows XP Service Pack 3 (x86) # Username : koko - KOKO-91428864AB # Running from : C:\Documents and Settings\koko\Desktop\adwcleaner_4.208.exe # Option : Scan ***** [ Services ] ***** ***** [ Files / Folders ] ***** File Found : C:\Documents and Settings\koko\Local Settings\Application Data\Google\Chrome\User Data\Default\Local Storage\hxxp_ar.hao123.com_0.localstorage File Found : C:\Documents and Settings\koko\Local Settings\Application Data\Google\Chrome\User Data\Default\Local Storage\hxxp_ar.hao123.com_0.localstorage-journal File Found : C:\Documents and Settings\koko\Local Settings\Application Data\Google\Chrome\User Data\Default\Local Storage\hxxp_search.hao123.com.eg_0.localstorage File Found : C:\Documents and Settings\koko\Local Settings\Application Data\Google\Chrome\User Data\Default\Local Storage\hxxp_search.hao123.com.eg_0.localstorage-journal File Found : C:\Program Files\Mozilla Firefox\searchplugins\yahoo.xml ***** [ Scheduled tasks ] ***** ***** [ Shortcuts ] ***** ***** [ Registry ] ***** Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9AD09901-06DD-4DDD-A62D-6D2243B771AB} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0E5680D1-BF44-4929-94AF-FD30D784AD1D} Key Found : HKLM\SOFTWARE\Classes\AddressBarSearch.SearchHook Key Found : HKLM\SOFTWARE\Classes\AddressBarSearch.SearchHook.1 Key Found : HKLM\SOFTWARE\Classes\AppID\{82A5CE4D-AF0C-45B6-8AF8-75625BE6A08D} Key Found : HKLM\SOFTWARE\Classes\AppID\{B2B7E0CD-E169-43B3-A233-E129610EE314} Key Found : HKLM\SOFTWARE\Classes\CLSID\{0DEC13F0-5C8C-4147-8329-6CDFAD9755B7} Key Found : HKLM\SOFTWARE\Classes\CLSID\{0F3DC9E0-C459-4A40-BCF8-747BD9322E10} Key Found : HKLM\SOFTWARE\Classes\CLSID\{5E97F0FA-3B44-4634-A87E-8B0D5CFD6365} Key Found : HKLM\SOFTWARE\Classes\CLSID\{951F5841-FD1E-4F1D-8607-67B174DBD753} Key Found : HKLM\SOFTWARE\Classes\CLSID\{D1CCB0CC-DA45-4797-93D3-DEE7A13F8177} Key Found : HKLM\SOFTWARE\Classes\CLSID\{DCE24E28-D8EF-49BE-BC01-A1DD3B58FCE3} Key Found : HKLM\SOFTWARE\Classes\CLSID\{E4F7F1A5-490E-4884-A9E3-CBD6A25749E1} Key Found : HKLM\SOFTWARE\Classes\STC.FBServiceAPPEventsSink Key Found : HKLM\SOFTWARE\Classes\STC.FBServiceAPPEventsSink.1 Key Found : HKLM\SOFTWARE\Classes\STC.OptionMenu Key Found : HKLM\SOFTWARE\Classes\STC.OptionMenu.1 Key Found : HKLM\SOFTWARE\Classes\STC.Protocol Key Found : HKLM\SOFTWARE\Classes\STC.Protocol.1 Key Found : HKLM\SOFTWARE\Classes\STC.VisualBookmark Key Found : HKLM\SOFTWARE\Classes\STC.VisualBookmark.1 Key Found : HKLM\SOFTWARE\Classes\STC.WebObject Key Found : HKLM\SOFTWARE\Classes\STC.WebObject.1 Key Found : HKLM\SOFTWARE\Classes\STCHelper.BHOHelper Key Found : HKLM\SOFTWARE\Classes\STCHelper.BHOHelper.1 Key Found : HKLM\SOFTWARE\Classes\STCHelper.FBServiceAPP Key Found : HKLM\SOFTWARE\Classes\STCHelper.FBServiceAPP.1 Key Found : HKLM\SOFTWARE\Classes\STCHelper.Protocol Key Found : HKLM\SOFTWARE\Classes\STCHelper.Protocol.1 Key Found : HKLM\SOFTWARE\Classes\TypeLib\{4E8E0178-00EF-413D-9324-E7B3E31572E3} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{A1A533A8-E106-422B-AE29-D0025269AF83} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{B1759D04-0EF9-472A-B5C3-C774997B5321} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{80ED3EBC-CC05-4336-ABCC-295798855718} Value Found : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{91c612bf-2a7a-48b8-8c8c-6de28589b7a0}] Value Found : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{d9284e50-81fc-11da-a72b-0800200c9a66}] ***** [ Web browsers ] ***** -\\ Internet Explorer v8.0.6001.18702 Setting Found : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxp://start.myplaycity.com/ Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] - hxxp://start.myplaycity.com/ -\\ Mozilla Firefox v8.0 (en-US) -\\ Google Chrome v44.0.2403.155 [C:\Documents and Settings\koko\Local Settings\Application Data\Google\Chrome\User Data\Default\Secure Preferences] - Found [Homepage] : 351A9603A717DD0E365D3D042EA301E21F4398B6062C84C8D2755BA4D131A4FB","homepage_is_newtabpage":"2ED97EA0B46A19AC7B8AA3E45D6F513D2735FD96E8C02450D4FEFDC4DDA92B40","pinned_tabs":"24A39DE5685F05C9D0ADE5F4782F71FBE8B38F79CF5096FDA4444D868D1FA0AC","prefs":{"preference_reset_time":"3F4A3652FA77C5B0A07AB21CE33ED1EC1F0255CE53B8979826F8C4691524DCE6"},"profile":{"reset_prompt_memento":"5DE6CC02D3DFAD19E57BD0724B4A8F395055771EEB54BCE9D488B5716E8103B2"},"safebrowsing":{"incidents_sent":"6E647F9CDA0969EAB878E05B5050C5703EA831A2770386D674425E7E2788B826"},"search_provider_overrides":"0F9B12662CC98B265AD21918151DD761540A9863CADBF875BEEC903F66AE53CA","session":{"restore_on_startup":"C3EBF975989F8CC79750C37347744C7F927A1B52EC881D9749F3AE47044E1247","startup_urls":"2971BCA7478DD9131CFCD08FB68D0903970E0AACDD58B4647C061E162B44DEBD"},"software_reporter":{"prompt_reason":"0DE7A104CE24617E602DAA43C373CD5EC14746BD43A53EB77106ABF77CFD72C5","prompt_seed":"BE2508BB5F128AA1D00AB198566D3A34550EF5D761347E865717C794357BF4D4","prompt_version":"451CD6F155982CEA5ECB0C39657256048CD71F737FB1A8A6EA41BBDF830BF28A"},"sync":{"remaining_rollback_tries":"2654A09F4D8CCF3B6379097238A2D0324178CAA0EAB44029AB383A5902C36A60"}},"super_mac":"1A90A7A98C799C80DD5EE080FCB7B662BBB0EDEDAD68FD07DE0A1746CB6B4E06"},"session":{"restore_on_startup":4,"startup_urls":["hxxp://ar.hao123.com/?tn=hp_hp_8387_hao123_ar [C:\Documents and Settings\koko\Local Settings\Application Data\Google\Chrome\User Data\Default\Secure Preferences] - Found [Startup_URLs] : 2971BCA7478DD9131CFCD08FB68D0903970E0AACDD58B4647C061E162B44DEBD"},"software_reporter":{"prompt_reason":"0DE7A104CE24617E602DAA43C373CD5EC14746BD43A53EB77106ABF77CFD72C5","prompt_seed":"BE2508BB5F128AA1D00AB198566D3A34550EF5D761347E865717C794357BF4D4","prompt_version":"451CD6F155982CEA5ECB0C39657256048CD71F737FB1A8A6EA41BBDF830BF28A"},"sync":{"remaining_rollback_tries":"2654A09F4D8CCF3B6379097238A2D0324178CAA0EAB44029AB383A5902C36A60"}},"super_mac":"1A90A7A98C799C80DD5EE080FCB7B662BBB0EDEDAD68FD07DE0A1746CB6B4E06"},"session":{"restore_on_startup":4,"startup_urls":["hxxp://ar.hao123.com/?tn=hp_hp_8387_hao123_ar ************************* AdwCleaner[R0].txt - [6388 bytes] - [14/08/2015 12:37:42] ########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [6447 bytes] ##########