santaniy | 29.08.2013 21:38 | Code:
# AdwCleaner v3.001 - Report created 29/08/2013 at 22:25:22
# Updated 24/08/2013 by Xplode
# Operating System : Windows 8 Pro (32 bits)
# Username : AndiY - FRANZ
# Running from : C:\Users\AndiY\Desktop\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
Service Deleted : BrowserDefendert
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\Babylon
Folder Deleted : C:\ProgramData\BrowserDefender
Folder Deleted : C:\ProgramData\IBUpdaterService
Folder Deleted : C:\Program Files\Browser Updater
Folder Deleted : C:\Program Files\Protected Search
Folder Deleted : C:\Users\AndiY\AppData\Local\DownloadGuide
Folder Deleted : C:\Users\AndiY\AppData\Local\Temp\OCS
Folder Deleted : C:\Users\AndiY\AppData\LocalLow\SimplyTech
Folder Deleted : C:\Users\AndiY\AppData\Roaming\Babylon
Folder Deleted : C:\Users\AndiY\AppData\Roaming\OpenCandy
Folder Deleted : C:\Users\AndiY\AppData\Roaming\PerformerSoft
Folder Deleted : C:\Users\AndiY\AppData\Roaming\SimplyTech
File Deleted : C:\WINDOWS\system32\roboot.exe
File Deleted : C:\Users\AndiY\AppData\Roaming\Mozilla\Firefox\Profiles\tf6bddtv.default\searchplugins\holasearch.xml
File Deleted : C:\Users\AndiY\AppData\Roaming\Mozilla\Firefox\Profiles\mData\searchplugins\Web Search.xml
File Deleted : C:\Program Files\Mozilla Firefox\searchplugins\Web Search.xml
File Deleted : C:\Users\AndiY\AppData\Roaming\Mozilla\Firefox\Profiles\tf6bddtv.default\bprotector_extensions.sqlite
File Deleted : C:\Users\AndiY\AppData\Roaming\Mozilla\Firefox\Profiles\tf6bddtv.default\user.js
File Deleted : C:\WINDOWS\System32\Tasks\BrowserDefendert
***** [ Shortcuts ] *****
***** [ Registry ] *****
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BrowserDefendert
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EA0B1608-A239-43CB-902E-394063688FA0}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EA0B1608-A239-43CB-902E-394063688FA0}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [bprotector start page]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope]
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKCU\Software\5f48d88e039ba14
Key Deleted : HKLM\SOFTWARE\5f48d88e039ba14
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CFD485F0-96BD-47CD-BB6D-CD7DDA95F102}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKCU\Software\BabylonToolbar
Key Deleted : HKCU\Software\DataMngr
[#] Key Deleted : HKCU\Software\DataMngr_Toolbar
Key Deleted : HKCU\Software\OCS
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKLM\Software\Babylon
Key Deleted : HKLM\Software\DataMngr
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}
***** [ Browsers ] *****
-\\ Internet Explorer v10.0.9200.16660
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Search Page]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Search Bar]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Default_Page_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Default_Page_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Bar]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Search [Default_Search_URL]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Search [Start Page]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Search [Start Default_Page_URL]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Search [Search Bar]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Search [Search Page]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [Tabs]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Start Page]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Start Default_Page_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Default_Search_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Search Bar]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Search Page]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\SearchUrl [(Default)]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl [(Default)]
-\\ Mozilla Firefox v23.0.1 (de)
[ File : C:\Users\AndiY\AppData\Roaming\Mozilla\Firefox\Profiles\mData\prefs.js ]
Line Deleted : user_pref("browser.search.defaultenginename", "Web Search");
Line Deleted : user_pref("browser.search.defaultengine", "Web Search");
Line Deleted : user_pref("browser.search.selectedEngine", "Web Search");
Line Deleted : user_pref("browser.search.order.1", "Web Search");
Line Deleted : user_pref("browser.startup.homepage", "hxxp://search.certified-toolbar.com?si=43169&st=home&tid=3580&ver=4.5&ts=1377681541522.000009&tguid=43169-3580-1377681541522-C08AC0157E114C69D47ED11EB8646D12");
Line Deleted : user_pref("browser.newtab.url", "hxxp://search.certified-toolbar.com?si=43169&st=newtab&tid=3580&ver=4.5&ts=1377681541522.000009&tguid=43169-3580-1377681541522-C08AC0157E114C69D47ED11EB8646D12");
Line Deleted : user_pref("keyword.URL", "hxxp://search.certified-toolbar.com?si=43169&st=chrome&tid=3580&ver=4.5&ts=1377681541522.000009&tguid=43169-3580-1377681541522-C08AC0157E114C69D47ED11EB8646D12&q=");
Line Deleted : user_pref("wtb3580.homepage", "hxxp://search.certified-toolbar.com?si=43169&st=home&tid=3580&ver=4.5&ts=1377681541522.000009&tguid=43169-3580-1377681541522-C08AC0157E114C69D47ED11EB8646D12");
Line Deleted : user_pref("wtb3580.newtab", "hxxp://search.certified-toolbar.com?si=43169&st=home&tid=3580&ver=4.5&ts=1377681541522.000009&tguid=43169-3580-1377681541522-C08AC0157E114C69D47ED11EB8646D12");
[ File : C:\Users\AndiY\AppData\Roaming\Mozilla\Firefox\Profiles\tf6bddtv.default\prefs.js ]
Line Deleted : user_pref("browser.newtab.url", "hxxp://search.certified-toolbar.com?si=43169&st=newtab&tid=3580&ver=4.5&ts=1377681541522.000009&tguid=43169-3580-1377681541522-C08AC0157E114C69D47ED11EB8646D12");
Line Deleted : user_pref("browser.search.defaultengine", "Web Search");
Line Deleted : user_pref("browser.search.order.1", "Web Search");
Line Deleted : user_pref("extensions.holasearch.admin", false);
Line Deleted : user_pref("extensions.holasearch.aflt", "babsst");
Line Deleted : user_pref("extensions.holasearch.appId", "{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}");
Line Deleted : user_pref("extensions.holasearch.autoRvrt", "false");
Line Deleted : user_pref("extensions.holasearch.dfltLng", "en");
Line Deleted : user_pref("extensions.holasearch.excTlbr", false);
Line Deleted : user_pref("extensions.holasearch.ffxUnstlRst", false);
Line Deleted : user_pref("extensions.holasearch.id", "42cad5fe000000000000827bcb8809ff");
Line Deleted : user_pref("extensions.holasearch.instlDay", "15854");
Line Deleted : user_pref("extensions.holasearch.instlRef", "sst");
Line Deleted : user_pref("extensions.holasearch.newTab", false);
Line Deleted : user_pref("extensions.holasearch.prdct", "holasearch");
Line Deleted : user_pref("extensions.holasearch.prtnrId", "holasearch");
Line Deleted : user_pref("extensions.holasearch.rvrt", "false");
Line Deleted : user_pref("extensions.holasearch.smplGrp", "none");
Line Deleted : user_pref("extensions.holasearch.tlbrId", "base");
Line Deleted : user_pref("extensions.holasearch.tlbrSrchUrl", "");
Line Deleted : user_pref("extensions.holasearch.vrsn", "1.8.16.16");
Line Deleted : user_pref("extensions.holasearch.vrsnTs", "1.8.16.1618:15:27");
Line Deleted : user_pref("extensions.holasearch.vrsni", "1.8.16.16");
Line Deleted : user_pref("keyword.URL", "hxxp://search.certified-toolbar.com?si=43169&st=chrome&tid=3580&ver=4.5&ts=1377681541522.000009&tguid=43169-3580-1377681541522-C08AC0157E114C69D47ED11EB8646D12&q=");
Line Deleted : user_pref("wtb3580.homepage", "hxxp://search.certified-toolbar.com?si=43169&st=home&tid=3580&ver=4.5&ts=1377681541522.000009&tguid=43169-3580-1377681541522-C08AC0157E114C69D47ED11EB8646D12");
Line Deleted : user_pref("wtb3580.newtab", "hxxp://search.certified-toolbar.com?si=43169&st=home&tid=3580&ver=4.5&ts=1377681541522.000009&tguid=43169-3580-1377681541522-C08AC0157E114C69D47ED11EB8646D12");
*************************
AdwCleaner[R0].txt - [13218 octets] - [29/08/2013 22:24:42]
AdwCleaner[S0].txt - [9621 octets] - [29/08/2013 22:25:22]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [9681 octets] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.5.5 (08.28.2013:1)
OS: Windows 8 Pro x86
Ran by AndiY on 29.08.2013 at 22:34:20,92
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\simplytech
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\simplytech
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\hometab_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\hometab_rasmancs
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{17A81D31-1AAA-4BBE-A3D9-4122E3DCBC19}
~~~ Files
~~~ Folders
~~~ FireFox
Emptied folder: C:\Users\AndiY\AppData\Roaming\mozilla\firefox\profiles\tf6bddtv.default\minidumps [21 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 29.08.2013 at 22:36:36,11
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |