# AdwCleaner v3.010 - Report created 03/11/2013 at 13:03:08 # Updated 20/10/2013 by Xplode # Operating System : Microsoft Windows XP Service Pack 3 (32 bits) # Username : Andy - NEW1 # Running from : D:\My Documents\Downloads\AdwCleaner.exe # Option : Scan ***** [ Services ] ***** Service Found : vToolbarUpdater17.0.12 ***** [ Files / Folders ] ***** File Found : C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\q67gg1dl.default\searchplugins\Web Search.xml File Found : C:\WINDOWS\Tasks\paretologic registration3.job Folder Found : C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\q67gg1dl.default\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} Folder Found : C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\q67gg1dl.default\Extensions\{AD9A41D2-9A49-4FA6-A79E-71A0785364C8} Folder Found : C:\Documents and Settings\Andy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof Folder Found C:\DOCUME~1\Andy\LOCALS~1\Temp\Smartbar Folder Found C:\Documents and Settings\All Users\Application Data\AVG Secure Search Folder Found C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar Folder Found C:\Documents and Settings\All Users\Application Data\ParetoLogic Folder Found C:\Documents and Settings\All Users\Application Data\Tarma Installer Folder Found C:\Documents and Settings\Andy\Application Data\AVG Secure Search Folder Found C:\Documents and Settings\Andy\Application Data\Mysearchdial Folder Found C:\Documents and Settings\Andy\Application Data\Toolbar4 Folder Found C:\Documents and Settings\Andy\Local Settings\Application Data\AVG Secure Search Folder Found C:\Documents and Settings\Andy\Local Settings\Application Data\AVG Security Toolbar Folder Found C:\Documents and Settings\Andy\Local Settings\Application Data\PackageAware Folder Found C:\Documents and Settings\Andy\Local Settings\Application Data\Smartbar Folder Found C:\Program Files\AVG Secure Search Folder Found C:\Program Files\Common Files\AVG Secure Search Folder Found C:\Program Files\Common Files\ParetoLogic Folder Found C:\Program Files\MyPC Backup Folder Found C:\Program Files\MyPC Backup Folder Found C:\Program Files\ParetoLogic ***** [ Shortcuts ] ***** ***** [ Registry ] ***** Key Found : HKCU\Software\AVG Secure Search Key Found : HKCU\Software\AVG Security Toolbar Key Found : HKCU\Software\Google\Chrome\Extensions\pflphaooapbgpeakohlggbpidpppgdff Key Found : HKCU\Software\InstallCore Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8} Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{96BD48DD-741B-41AE-AC4A-AFF96BA00F7E} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{338B4DFE-2E2C-4338-9E41-E176D497299E} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{338B4DFE-2E2C-4338-9E41-E176D497299E} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FCBCCB87-9224-4B8D-B117-F56D924BEB18} Key Found : HKCU\Software\mysearchdial Key Found : HKCU\Software\mysearchdial.com Key Found : HKCU\Software\YahooPartnerToolbar Key Found : HKLM\Software\AVG Secure Search Key Found : HKLM\Software\AVG Security Toolbar Key Found : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2} Key Found : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB} Key Found : HKLM\SOFTWARE\Classes\AppID\esrv.EXE Key Found : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE Key Found : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL Key Found : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI Key Found : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI.1 Key Found : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj Key Found : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj.1 Key Found : HKLM\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} Key Found : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Key Found : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3} Key Found : HKLM\SOFTWARE\Classes\CLSID\{94496571-6AC5-4836-82D5-D46260C44B17} Key Found : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Found : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9} Key Found : HKLM\SOFTWARE\Classes\CLSID\{BC9FD17D-30F6-4464-9E53-596A90AFF023} Key Found : HKLM\SOFTWARE\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3} Key Found : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468} Key Found : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Key Found : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Found : HKLM\SOFTWARE\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC} Key Found : HKLM\SOFTWARE\Classes\esrv.mysearchdialESrvc Key Found : HKLM\SOFTWARE\Classes\esrv.mysearchdialESrvc.1 Key Found : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Key Found : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Key Found : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Key Found : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6} Key Found : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1 Key Found : HKLM\SOFTWARE\Classes\TypeLib\{13ABD093-D46F-40DF-A608-47E162EC799D} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94} Key Found : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE Key Found : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1 Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\pflphaooapbgpeakohlggbpidpppgdff Key Found : HKLM\Software\InstallCore Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{219046AE-358F-4CF1-B1FD-2B4DE83642A8} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\AVG Secure Search Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG Secure Search Key Found : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin Key Found : HKLM\Software\Tarma Installer Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{CCC7A320-B3CA-4199-B1A6-9F516DD69829}] Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}] Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}] Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{CCC7A320-B3CA-4199-B1A6-9F516DD69829}] Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt] Value Found : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar] ***** [ Browsers ] ***** -\\ Internet Explorer v7.0.6000.21357 Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] - hxxp://start.mysearchdial.com/?f=1&a=dnldmsd&cd=2XzuyEtN2Y1L1QzutDtDtByEtC0DtB0FyCyE0C0D0C0B0B0EtN0D0Tzu0CyDyDyCtN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1Q1G1I1Q1H1B1Q&cr=200542007&ir= -\\ Mozilla Firefox v24.0 (en-US) [ File : C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\q67gg1dl.default\prefs.js ] Line Found : user_pref("avg.install.installDirPath", "C:\\Documents and Settings\\All Users\\Application Data\\AVG Secure Search\\FireFoxExt\\17.0.1.12"); Line Found : user_pref("avg.userPreferences.URLBarFocus.whiteList", "bing\\.com|google\\.\\w+|yahoo\\.\\w+|gmail\\.\\w+|hotmail\\.\\w+|live\\.\\w+|isearch\\.avg\\.com|mysearch\\.avg\\.com"); Line Found : user_pref("browser.search.defaultenginename", "Web Search"); Line Found : user_pref("browser.search.order.1", "Mysearchdial"); Line Found : user_pref("browser.search.selectedEngine", "Web Search"); Line Found : user_pref("extensions.helperbar.DockingPositionDown", false); Line Found : user_pref("extensions.helperbar.LastHiddenTime", 23058047); Line Found : user_pref("extensions.helperbar.SmartbarDisabled", true); Line Found : user_pref("extensions.helperbar.SmartbarStateMinimaized", false); Line Found : user_pref("extensions.helperbar.Visibility", true); Line Found : user_pref("extensions.helperbar.countryiso", "gb"); Line Found : user_pref("extensions.helperbar.downloadprovider", "shoppinghelper"); Line Found : user_pref("extensions.helperbar.installationid", "4f2319f9-64f2-112a-1fba-c21e3a74fdf7"); Line Found : user_pref("extensions.helperbar.installdate", "03/11/2013"); Line Found : user_pref("extensions.helperbar.publisher", "shoppinghelper"); Line Found : user_pref("extensions.mysearchdial.aflt", "dnldmsd"); Line Found : user_pref("extensions.mysearchdial.appId", "{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}"); Line Found : user_pref("extensions.mysearchdial.cd", "2XzuyEtN2Y1L1QzutDtDtByEtC0DtB0FyCyE0C0D0C0B0B0EtN0D0Tzu0CyDyDyCtN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1Q1G1I1Q1H1B1Q"); Line Found : user_pref("extensions.mysearchdial.cntry", "GB"); Line Found : user_pref("extensions.mysearchdial.cr", "200542007"); Line Found : user_pref("extensions.mysearchdial.dfltLng", ""); Line Found : user_pref("extensions.mysearchdial.dfltSrch", true); Line Found : user_pref("extensions.mysearchdial.dnsErr", true); Line Found : user_pref("extensions.mysearchdial.dpkLst", "3654782829,1334533236,1121012847,231756876,1895130307,603719297,4288797614,3754950497,426401714,3046281807,752626116,1657571787,3224935090,2597085128,18285[...] Line Found : user_pref("extensions.mysearchdial.excTlbr", false); Line Found : user_pref("extensions.mysearchdial.hdrMd5", "4DD0788152D996584C6B5A3905CC5F70"); Line Found : user_pref("extensions.mysearchdial.hmpg", true); Line Found : user_pref("extensions.mysearchdial.hmpgUrl", "hxxp://start.mysearchdial.com/?f=1&a=dnldmsd&cd=2XzuyEtN2Y1L1QzutDtDtByEtC0DtB0FyCyE0C0D0C0B0B0EtN0D0Tzu0CyDyDyCtN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1Q1G1I1Q[...] Line Found : user_pref("extensions.mysearchdial.id", "00241D2F64CDCBBE"); Line Found : user_pref("extensions.mysearchdial.instlDay", "15896"); Line Found : user_pref("extensions.mysearchdial.instlRef", ""); Line Found : user_pref("extensions.mysearchdial.lastB", "hxxp://start.mysearchdial.com/?f=1&a=dnldmsd&cd=2XzuyEtN2Y1L1QzutDtDtByEtC0DtB0FyCyE0C0D0C0B0B0EtN0D0Tzu0CyDyDyCtN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1Q1G1I1Q1H[...] Line Found : user_pref("extensions.mysearchdial.lastVrsnTs", "0:23:25"); Line Found : user_pref("extensions.mysearchdial.newTabUrl", "hxxp://start.mysearchdial.com/?f=2&a=dnldmsd&cd=2XzuyEtN2Y1L1QzutDtDtByEtC0DtB0FyCyE0C0D0C0B0B0EtN0D0Tzu0CyDyDyCtN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1Q1G1I[...] Line Found : user_pref("extensions.mysearchdial.pnu_base", "{\"newVrsn\":\"44\",\"lastVrsn\":\"44\",\"vrsnLoad\":\"\",\"showMsg\":\"false\",\"showSilent\":\"false\",\"msgTs\":0,\"lstMsgTs\":\"0\"}"); Line Found : user_pref("extensions.mysearchdial.prdct", "mysearchdial"); Line Found : user_pref("extensions.mysearchdial.prtnrId", "mysearchdial"); Line Found : user_pref("extensions.mysearchdial.sg", "none"); Line Found : user_pref("extensions.mysearchdial.srchPrvdr", "Mysearchdial"); Line Found : user_pref("extensions.mysearchdial.tlbrId", "base"); Line Found : user_pref("extensions.mysearchdial.tlbrSrchUrl", "hxxp://start.mysearchdial.com/?f=3&a=dnldmsd&cd=2XzuyEtN2Y1L1QzutDtDtByEtC0DtB0FyCyE0C0D0C0B0B0EtN0D0Tzu0CyDyDyCtN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1Q1G[...] Line Found : user_pref("extensions.mysearchdial.vrsn", ""); Line Found : user_pref("extensions.mysearchdial.vrsni", ""); Line Found : user_pref("extensions.mysearchdial_i.hmpg", true); Line Found : user_pref("extensions.mysearchdial_i.newTab", false); Line Found : user_pref("extensions.mysearchdial_i.smplGrp", "none"); Line Found : user_pref("extensions.mysearchdial_i.vrsnTs", "0:23:25"); -\\ Google Chrome v [ File : C:\Documents and Settings\Andy\Local Settings\Application Data\Google\Chrome\User Data\Default\preferences ] Found : search_url ************************* AdwCleaner[R0].txt - [14016 octets] - [03/11/2013 13:03:08] ########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [14077 octets] ##########