# AdwCleaner v5.101 - Logfile created 12/03/2016 at 16:29:55 # Updated 07/03/2016 by Xplode # Database : 2016-03-08.1 [Server] # Operating system : Windows 7 Ultimate Service Pack 1 (x64) # Username : Thibault - THIBAULT-PC # Running from : A:\Downloads A\adwcleaner_5.101.exe # Option : Scan # Support : http://toolslib.net/forum ***** [ Services ] ***** ***** [ Folders ] ***** Folder Found : C:\Program Files (x86)\GetPrivate Folder Found : C:\ProgramData\SoftSafe Folder Found : C:\ProgramData\StarApp Folder Found : C:\ProgramData\Tarma Installer Folder Found : C:\ProgramData\Trymedia Folder Found : C:\Users\Thibault\AppData\Local\28050 Folder Found : C:\Users\Thibault\AppData\Local\Google\Chrome\User Data\Default\Extensions\bohapeiooecafommnlaiccilacgmkaoc Folder Found : C:\Users\Thibault\AppData\Roaming\BitLord Folder Found : C:\Users\Thibault\AppData\Roaming\OpenCandy Folder Found : C:\Users\Thibault\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GetPrivate Folder Found : C:\Users\Thibault\Documents\BitLord Folder Found : C:\Windows\SysWOW64\SearchProtect ***** [ Files ] ***** File Found : C:\END File Found : C:\Users\Thibault\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage File Found : C:\Users\Thibault\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage-journal File Found : C:\Users\Thibault\AppData\Roaming\Mozilla\Firefox\Profiles\k29xqsqf.default\searchplugins\trovi-search.xml File Found : C:\Users\Thibault\AppData\Roaming\Mozilla\Firefox\Profiles\k29xqsqf.default\searchplugins\WebSearch.xml ***** [ DLL ] ***** ***** [ Shortcuts ] ***** ***** [ Scheduled tasks ] ***** ***** [ Registry ] ***** Key Found : HKLM\SOFTWARE\Classes\Applications\Torch.exe Key Found : HKLM\SOFTWARE\Clients\StartMenuInternet\Torch Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\jbpkiefagocgkmemidfngdkamloieekf Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\kiplfnciaokpcennlkldkdaeaaomamof Key Found : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826} Key Found : HKCU\Software\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D} Key Found : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761} Key Found : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D} Key Found : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401} Key Found : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5} Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{58124A0B-DC32-4180-9BFF-E0E21AE34026}] Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{977AE9CC-AF83-45E8-9E03-E2798216E2D5}] Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}] Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08} Key Found : HKCU\Software\1ClickDownload Key Found : HKCU\Software\Conduit Key Found : HKCU\Software\GetPrivate Key Found : HKCU\Software\PrivitizeVPNInstallDates Key Found : HKCU\Software\StartSearch Key Found : HKCU\Software\SweetIM Key Found : HKCU\Software\torch Key Found : HKCU\Software\AppDataLow\SProtector Key Found : HKLM\SOFTWARE\GetPrivate Key Found : HKLM\SOFTWARE\Iminent Key Found : HKLM\SOFTWARE\SP Global Key Found : HKLM\SOFTWARE\SProtector Key Found : HKLM\SOFTWARE\SweetIM Key Found : HKLM\SOFTWARE\torch Key Found : HKLM\SOFTWARE\Uniblue Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GetPrivate Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP Key Found : [x64] HKLM\SOFTWARE\Tarma Installer Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5 Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375 Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\43C098337DB065A49B665D4EA7F16D1C Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\18C9E3869A16248439FE3FF9EB02207A Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5D8011310B2622942868A458964FFDC5 Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6C63F7979DCC2154CB9591969A5CB89D Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6DD31E6C1A73B334383DF186676F4D20 Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AB3204F747B20694B8D49EF92D8DC94B Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C81E33A400B6F814E90C7A3354E2A3A5 Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EDBF68C5F16790341B7C6FD7C7F8E4FC Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FFA531D0F3A71504DA7AC6A11CE33739 Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} Data Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope] - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE} Key Found : [x64] HKLM\SOFTWARE\Microsoft\Shared Tools\MsConfig\StartupReg\GetPrivate ***** [ Web browsers ] ***** [C:\Users\Thibault\AppData\Roaming\Mozilla\Firefox\Profiles\k29xqsqf.default\prefs.js] [Preference] Found : user_pref("browser.newtab.url", "hxxp://search.conduit.com/?ctid=CT3312375&octid=EB_ORIGINAL_CTID&SearchSource=69&CUI=&SSPV=&Lay=1&UM=2&UP=SPB976F527-7117-4DA1-B412-E44A3396F84E"); [C:\Users\Thibault\AppData\Roaming\Mozilla\Firefox\Profiles\k29xqsqf.default\prefs.js] [Preference] Found : user_pref("browser.search.defaultenginename,S", "WebSearch"); [C:\Users\Thibault\AppData\Roaming\Mozilla\Firefox\Profiles\k29xqsqf.default\prefs.js] [Preference] Found : user_pref("browser.search.defaulturl", "hxxp://websearch.searchrocket.info/?pid=940&r=2013/05/23&hid=334668425&lg=EN&cc=FR&unqvl=16&l=1&q="); [C:\Users\Thibault\AppData\Roaming\Mozilla\Firefox\Profiles\k29xqsqf.default\prefs.js] [Preference] Found : user_pref("browser.search.order.1", "WebSearch"); [C:\Users\Thibault\AppData\Roaming\Mozilla\Firefox\Profiles\k29xqsqf.default\prefs.js] [Preference] Found : user_pref("browser.search.order.1,S", "WebSearch"); [C:\Users\Thibault\AppData\Roaming\Mozilla\Firefox\Profiles\k29xqsqf.default\prefs.js] [Preference] Found : user_pref("browser.search.selectedEngine,S", "WebSearch"); [C:\Users\Thibault\AppData\Roaming\Mozilla\Firefox\Profiles\k29xqsqf.default\prefs.js] [Preference] Found : user_pref("browser.startup.homepage", "hxxp://search.conduit.com/?ctid=CT3312375&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SPB976F527-7117-4DA1-B412-E44A3396F84E&SSPV="); [C:\Users\Thibault\AppData\Roaming\Mozilla\Firefox\Profiles\k29xqsqf.default\prefs.js] [Preference] Found : user_pref("keyword.URL", "hxxp://websearch.searchrocket.info/?pid=940&r=2013/05/23&hid=334668425&lg=EN&cc=FR&unqvl=16&l=1&q="); [C:\Users\Thibault\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Startup_URLs] Found : hxxp://www.delta-homes.com/?type=hp&ts=1433264775&z=38d34a61e15b191c64412d4g8zccac0o2q6zdm6qco&from=wpm06023&uid=WDCXWD1600BEVS-08VAT2_WD-WXF0E79SC763SC763 [C:\Users\Thibault\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : bohapeiooecafommnlaiccilacgmkaoc [C:\Users\Thibault\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : booedmolknjekdopkepjjeckmjkdpfgl [C:\Users\Thibault\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : flpcjncodpafbgdpnkljologafpionhb [C:\Users\Thibault\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : lfmhcpmkbdkbgbmkjoiopeeegenkdikp [C:\Users\Thibault\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : niapdbllcanepiiimjjndipklodoedlc ************************* C:\Program Files (x86)\AdwCleaner\AdwCleaner[S1].txt - [9183 bytes] - [12/03/2016 16:28:34] C:\Program Files (x86)\AdwCleaner\AdwCleaner[S2].txt - [9032 bytes] - [12/03/2016 16:29:55] ########## EOF - C:\Program Files (x86)\AdwCleaner\AdwCleaner[S2].txt - [9125 bytes] ##########