# AdwCleaner v3.020 - Report created 09/03/2014 at 10:44:03 # Updated 27/02/2014 by Xplode # Operating System : Windows 7 Professional Service Pack 1 (64 bits) # Username : ssharma - DL15-4GYQFS1 # Running from : C:\Users\ssharma\Desktop\tools\AdwCleaner.exe # Option : Scan ***** [ Services ] ***** ***** [ Files / Folders ] ***** File Found : C:\Users\ssharma\AppData\Local\Temp\Uninstall.exe Folder Found : C:\Users\ssharma\AppData\Roaming\Mozilla\Firefox\Profiles\m1tixxl2.default\Extensions\support@lastpass.com Folder Found : C:\Users\ssharma\AppData\Roaming\Mozilla\Firefox\Profiles\m1tixxl2.default\Extensions\support@lastpass.com Folder Found : C:\Users\ssharma\AppData\Roaming\Mozilla\Firefox\Profiles\m1tixxl2.default\Extensions\support@lastpass.com Folder Found : C:\Users\ssharma\AppData\Roaming\Mozilla\Firefox\Profiles\m1tixxl2.default\Extensions\support@lastpass.com Folder Found : C:\Users\ssharma\AppData\Roaming\Mozilla\Firefox\Profiles\m1tixxl2.default\Extensions\support@lastpass.com Folder Found C:\Program Files (x86)\BitLord 2 Folder Found C:\ProgramData\sAAvensehaure a Folder Found C:\ProgramData\saivoenSoHaree Folder Found C:\ProgramData\savensshare Folder Found C:\ProgramData\savensshuaRe Folder Found C:\ProgramData\ssavenshaaree! Folder Found C:\Users\ssharma\AppData\Local\Bundled software uninstaller Folder Found C:\Users\ssharma\AppData\Local\Oxy Folder Found C:\Users\ssharma\AppData\Local\Temp\AirInstaller Folder Found C:\Users\ssharma\AppData\Roaming\BitLord Folder Found C:\Users\ssharma\AppData\Roaming\EZDownloader Folder Found C:\Users\ssharma\AppData\Roaming\Oxy ***** [ Shortcuts ] ***** ***** [ Registry ] ***** Key Found : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F} Key Found : HKCU\Software\caphyon Key Found : HKCU\Software\Escolade Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8C1C9F18-8B7F-D87E-727D-20C15D9CE4A3} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B431EF29-3A3D-2CF4-A102-B13B7ECE90B9} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BC7CB95B-8C6F-35D5-FF43-66DCCF01844E} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{E547610F-2B54-FBC3-01AE-66D8CA2F2B5B} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8C1C9F18-8B7F-D87E-727D-20C15D9CE4A3} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B431EF29-3A3D-2CF4-A102-B13B7ECE90B9} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BC7CB95B-8C6F-35D5-FF43-66DCCF01844E} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E547610F-2B54-FBC3-01AE-66D8CA2F2B5B} Key Found : [x64] HKCU\Software\caphyon Key Found : [x64] HKCU\Software\Escolade Key Found : HKLM\Software\{1146AC44-2F03-4431-B4FD-889BC837521F} Key Found : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0} Key Found : HKLM\Software\{6791A2F3-FC80-475C-A002-C014AF797E9C} Key Found : HKLM\SOFTWARE\Classes\CLSID\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA} Key Found : HKLM\SOFTWARE\Classes\CLSID\{4C836512-BB70-11D2-A5A7-00105A9C91C6} Key Found : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Found : HKLM\SOFTWARE\Classes\CLSID\{DB797690-40E0-11D2-9BD5-0060082AE372} Key Found : HKLM\SOFTWARE\Classes\CLSID\{E547610F-2B54-FBC3-01AE-66D8CA2F2B5B} Key Found : HKLM\SOFTWARE\Classes\Interface\{1F8EDE97-36D5-422A-B8F0-9406E2D87C60} Key Found : HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{DB797681-40E0-11D2-9BD5-0060082AE372} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{DCABB943-792E-44C4-9029-ECBEE6265AF9} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{FEB62B15-CC00-4736-AAEC-BA046C9DFF73} Key Found : HKLM\Software\dosearchessoftware Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E547610F-2B54-FBC3-01AE-66D8CA2F2B5B} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E547610F-2B54-FBC3-01AE-66D8CA2F2B5B} Key Found : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WsysSvc Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{1B97A696-5576-43AC-A73B-E1D2C78F21E8} Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{1F8EDE97-36D5-422A-B8F0-9406E2D87C60} Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F} Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534} Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5} Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{75BF416E-4326-45B5-8A2D-AE32D05B930B} Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6} Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F} Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{D54C859C-6066-4F31-8FE0-2AAEDCAE67D7} Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90} Key Found : [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\bbjciahceamgodcoidkjpchnokgfpphh Key Found : [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\cjpglkicenollcignonpgiafdgfeehoj Key Found : [x64] HKLM\SOFTWARE\Tarma Installer Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}] Value Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Jing] ***** [ Browsers ] ***** -\\ Internet Explorer v11.0.9600.16518 Setting Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] - hxxp://www.dosearches.com/?utm_source=b&utm_medium=mp3&utm_campaign=rg&utm_content=hp&from=mp3&uid=WDCXWD3200BEKT-75PVMT1_WD-WXC1C22T1883T1883&ts=1384135935 -\\ Mozilla Firefox v27.0.1 (en-US) [ File : C:\Users\ssharma\AppData\Roaming\Mozilla\Firefox\Profiles\m1tixxl2.default\prefs.js ] Line Found : user_pref("CT3284668_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1366120455921,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}]"); Line Found : user_pref("CT3305605_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1383595749835,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}]"); Line Found : user_pref("browser.search.defaultengine", "Ask.com"); Line Found : user_pref("browser.search.order.1", "Ask.com"); Line Found : user_pref("extensions.WvX8.scode", "(function(){if(window.self.location.hostname.indexOf(\"acebook.co\")>-1){return};new function(){var a=this;a.domain_storage=\"hxxp://xls.searchfun.in\";a.prefix=\"i[...] Line Found : user_pref("extensions.cMh7q1dYNt63.scode", "(function(){if(window.self.location.hostname.indexOf(\"acebook.co\")>-1){return};new function(){var a=this;a.domain_storage=\"hxxp://xls.searchfun.in\";a.pr[...] Line Found : user_pref("extensions.gmwKG8nuSgcn.scode", "(function(){if(window.self.location.hostname.indexOf(\"acebook.co\")>-1){return};new function(){var a=this;a.domain_storage=\"hxxp://xls.searchfun.in\";a.pr[...] Line Found : user_pref("extensions.tnYY4t8Ys3x.scode", "(function(){if(window.self.location.hostname.indexOf(\"acebook.co\")>-1){return};new function(){var a=this;a.domain_storage=\"hxxp://xls.searchfun.in\";a.pre[...] Line Found : user_pref("extensions.xe0wphXXprb7.scode", "(function(){if(window.self.location.hostname.indexOf(\"acebook.co\")>-1){return};new function(){var a=this;a.domain_storage=\"hxxp://xls.searchfun.in\";a.pr[...] -\\ Google Chrome v33.0.1750.146 [ File : C:\Users\ssharma\AppData\Local\Google\Chrome\User Data\Default\preferences ] Found : homepage Found : urls_to_restore_on_startup ************************* AdwCleaner[R0].txt - [8458 octets] - [09/03/2014 10:44:03] ########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [8518 octets] ##########