# AdwCleaner v5.105 - Logfile created 26/03/2016 at 06:27:41 # Updated 21/03/2016 by Xplode # Database : 2016-03-25.2 [Server] # Operating system : Windows 7 Ultimate Service Pack 1 (x64) # Username : sama office - SAMAOFFICE-PC # Running from : C:\Users\sama office\Downloads\adwcleaner_5.105.exe # Option : Scan # Support : http://toolslib.net/forum ***** [ Services ] ***** ***** [ Folders ] ***** Folder Found : C:\ProgramData\SuperEasy Software Folder Found : C:\ProgramData\systemk Folder Found : C:\ProgramData\VideoDownloaderUltimateWinApp Folder Found : C:\Users\sama office\AppData\Local\torch Folder Found : C:\Users\sama office\AppData\Roaming\FirefoxToolbar Folder Found : C:\Users\sama office\AppData\Roaming\RHEng Folder Found : C:\Users\sama office\AppData\Roaming\SuperEasy Software Folder Found : C:\Users\sama office\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MediaGet2 Folder Found : C:\Users\sama office\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\torch Folder Found : C:\Users\SAMAOF~1\AppData\Local\Temp\thirteen degrees ***** [ Files ] ***** File Found : C:\Users\sama office\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_foxi69.tlscdn.com_0.localstorage File Found : C:\Users\sama office\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_foxi69.tlscdn.com_0.localstorage-journal File Found : C:\Users\sama office\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_hdapp1008-a.akamaihd.net_0.localstorage File Found : C:\Users\sama office\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_hdapp1008-a.akamaihd.net_0.localstorage-journal File Found : C:\Users\sama office\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_ar.hao123.com_0.localstorage File Found : C:\Users\sama office\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_ar.hao123.com_0.localstorage-journal File Found : C:\Users\sama office\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_primeshare.tv_0.localstorage File Found : C:\Users\sama office\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_primeshare.tv_0.localstorage-journal File Found : C:\Users\sama office\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.newtabtvplussearch.com_0.localstorage File Found : C:\Users\sama office\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.newtabtvplussearch.com_0.localstorage-journal File Found : C:\Windows\SysNative\LavasoftTcpService64.dll File Found : C:\Windows\SysWOW64\lavasofttcpservice.dll ***** [ DLL ] ***** ***** [ Shortcuts ] ***** ***** [ Scheduled tasks ] ***** Task Found : RunAsStdUser Task ***** [ Registry ] ***** Key Found : HKCU\Software\MozillaPlugins\TorchVLC Key Found : HKLM\SOFTWARE\Classes\Applications\Torch.exe Key Found : HKLM\SOFTWARE\Clients\StartMenuInternet\Torch Value Found : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x64] Value Found : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x86] Value Found : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x64] Value Found : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x86] Value Found : HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\AppCertDlls [x64] Value Found : HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\AppCertDlls [x86] Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip Key Found : HKCU\Software\Classes\pokki Key Found : HKLM\SOFTWARE\Classes\SettingsManagerIEHelper.DNSGuard Key Found : HKLM\SOFTWARE\Classes\SettingsManagerIEHelper.DNSGuard.1 Key Found : HKU\S-1-5-21-3855221253-3299819671-4228833451-1000\Software\Classes\pokki Key Found : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F} Key Found : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} Key Found : HKLM\SOFTWARE\Classes\CLSID\{54739D49-AC03-4C57-9264-C5195596B3A1} Key Found : HKLM\SOFTWARE\Classes\CLSID\{6E993643-8FBC-44FE-BC85-D318495C4D96} Key Found : HKLM\SOFTWARE\Classes\CLSID\{E1842850-FB16-4471-B327-7343FBAED55C} Key Found : HKLM\SOFTWARE\Classes\Interface\{AA760BA8-5862-4BC5-9263-4452CBC0B264} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{93D511B5-143B-4A99-ABFC-B5B78AD0AE1B} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47} Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{54739D49-AC03-4C57-9264-C5195596B3A1} Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{E1842850-FB16-4471-B327-7343FBAED55C} Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2} Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792} Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{2D9DB233-DC4B-4677-946C-5FA5ABCF506B} Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{3AE76A17-C344-4A83-81CE-65EFEE41E42D} Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{4C0A69B0-CE97-42B7-86FC-08280C99C74D} Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24} Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{8FAF962C-3EDE-405E-B1D0-62B8235C6044} Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{C1F5E799-B218-4C32-B189-3C389BA140BB} Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{F60C9408-3110-4C98-A139-ABE1EE1111DD} Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{AA760BA8-5862-4BC5-9263-4452CBC0B264} Key Found : HKCU\Software\1ClickDownload Key Found : HKCU\Software\Conduit Key Found : HKCU\Software\Linkey Key Found : HKCU\Software\Media Get LLC Key Found : HKCU\Software\Mozilla\Extends Key Found : HKCU\Software\Softonic Key Found : HKCU\Software\SuperEasy Software Key Found : HKCU\Software\SystemK Key Found : HKCU\Software\torch Key Found : HKLM\SOFTWARE\Conduit Key Found : HKLM\SOFTWARE\omiga-plusSoftware Key Found : HKLM\SOFTWARE\SystemK Key Found : HKLM\SOFTWARE\torch Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\torch Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D08D9F98-1C78-4704-87E6-368B0023D831} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Settings Manager Key Found : [x64] HKLM\SOFTWARE\SuperEasy Software Key Found : HKU\S-1-5-21-3855221253-3299819671-4228833451-1000\Software\1ClickDownload Key Found : HKU\S-1-5-21-3855221253-3299819671-4228833451-1000\Software\Conduit Key Found : HKU\S-1-5-21-3855221253-3299819671-4228833451-1000\Software\Linkey Key Found : HKU\S-1-5-21-3855221253-3299819671-4228833451-1000\Software\Media Get LLC Key Found : HKU\S-1-5-21-3855221253-3299819671-4228833451-1000\Software\Mozilla\Extends Key Found : HKU\S-1-5-21-3855221253-3299819671-4228833451-1000\Software\Softonic Key Found : HKU\S-1-5-21-3855221253-3299819671-4228833451-1000\Software\SuperEasy Software Key Found : HKU\S-1-5-21-3855221253-3299819671-4228833451-1000\Software\SystemK Key Found : HKU\S-1-5-21-3855221253-3299819671-4228833451-1000\Software\torch Key Found : HKU\S-1-5-21-3855221253-3299819671-4228833451-1000\Software\Microsoft\Windows\CurrentVersion\Uninstall\torch Data Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL] - hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1403963136&from=ild&uid=TOSHIBAXMQ01ABD100_X3S5P8QZTXXX3S5P8QZT&q={searchTerms} Data Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL] - hxxp://isearch.omiga-plus.com/?type=hp&ts=1403963136&from=ild&uid=TOSHIBAXMQ01ABD100_X3S5P8QZTXXX3S5P8QZT Data Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] - hxxp://isearch.omiga-plus.com/?type=hp&ts=1403963136&from=ild&uid=TOSHIBAXMQ01ABD100_X3S5P8QZTXXX3S5P8QZT Data Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] - hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1403963136&from=ild&uid=TOSHIBAXMQ01ABD100_X3S5P8QZTXXX3S5P8QZT&q={searchTerms} Value Found : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{A709AFF2-02E6-4C51-8A5D-8A1D994DF10B}] Value Found : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{92172234-FAFF-42D4-AAFB-B1FC80282AEE}] Value Found : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{4E4CF274-F0A9-4B11-92AA-7606C7E9BCBF}] Value Found : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{7546F332-0554-4766-9FA6-875933DF576E}] Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} Data Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes [DefaultScope] - {33BB0A4E-99AF-4226-BDF6-49120163DE86} Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2503} Data Found : HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command [] - C:\Program Files (x86)\Internet Explorer\iexplore.exe hxxp://isearch.omiga-plus.com/?type=sc&ts=1403963136&from=ild&uid=TOSHIBAXMQ01ABD100_X3S5P8QZTXXX3S5P8QZT Key Found : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\default-search.net Value Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [VideoDownloaderUltimate] Value Found : HKU\S-1-5-21-3855221253-3299819671-4228833451-1000\Software\Microsoft\Windows\CurrentVersion\Run [VideoDownloaderUltimate] ***** [ Web browsers ] ***** [C:\Users\sama office\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : isearch.omiga-plus.com [C:\Users\sama office\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : omiga-plus [C:\Users\sama office\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : default-search.net [C:\Users\sama office\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : subtitle-edit.en.softonic.com [C:\Users\sama office\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : blufftitler.en.softonic.com ************************* C:\AdwCleaner\AdwCleaner[S1].txt - [11788 bytes] - [26/03/2016 05:04:31] C:\AdwCleaner\AdwCleaner[S3].txt - [11862 bytes] - [26/03/2016 05:22:54] C:\AdwCleaner\AdwCleaner[S4].txt - [12236 bytes] - [26/03/2016 06:27:41] ########## EOF - C:\AdwCleaner\AdwCleaner[S4].txt - [12310 bytes] ##########