# AdwCleaner v3.017 - Report created 16/01/2014 at 18:14:42 # Updated 12/01/2014 by Xplode # Operating System : Windows 7 Home Premium Service Pack 1 (64 bits) # Username : Jeremy - JEREMY-PC # Running from : C:\Users\Jeremy\Downloads\adwcleaner.exe # Option : Scan ***** [ Services ] ***** Service Found : vToolbarUpdater17.3.0 ***** [ Files / Folders ] ***** File Found : C:\END File Found : C:\Program Files (x86)\Mozilla Firefox\browser\nsprotector.js File Found : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\safeguard-secure-search.xml File Found : C:\Users\Jeremy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_app.mam.conduit.com_0.localstorage File Found : C:\Users\Jeremy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_app.mam.conduit.com_0.localstorage-journal File Found : C:\Users\Jeremy\AppData\Local\Google\Chrome\user data\default\local storage\hxxp_pricegong.conduitapps.com_0.localstorage File Found : C:\Users\Jeremy\AppData\Local\Google\Chrome\user data\default\local storage\hxxp_pricegong.conduitapps.com_0.localstorage-journal File Found : C:\Users\Jeremy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_storage.conduit.com_0.localstorage File Found : C:\Users\Jeremy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_storage.conduit.com_0.localstorage-journal File Found : C:\Users\Jeremy\AppData\Roaming\Mozilla\Firefox\Profiles\02yon0iv.default\searchplugins\Conduit.xml File Found : C:\Users\Jeremy\AppData\Roaming\Mozilla\Firefox\Profiles\02yon0iv.default\searchplugins\safeguard-secure-search.xml File Found : C:\Users\Public\Desktop\eBay.lnk Folder Found : C:\Users\Jeremy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ieiiggnfmhgcolbimglmfjfpkjildjdd Folder Found : C:\Users\Jeremy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof Folder Found : C:\Users\Jeremy\AppData\Roaming\Mozilla\Firefox\Profiles\02yon0iv.default\Extensions\{bf9194c2-b86d-4ebc-9b53-1c08b6ff779e} Folder Found C:\Program Files (x86)\AVG SafeGuard toolbar Folder Found C:\Program Files (x86)\Common Files\AVG Secure Search Folder Found C:\Program Files (x86)\Conduit Folder Found C:\Program Files (x86)\Searchprotect Folder Found C:\Program Files\Level Quality Watcher Folder Found C:\ProgramData\AVG SafeGuard toolbar Folder Found C:\ProgramData\Conduit Folder Found C:\ProgramData\VisualBee Folder Found C:\Users\Jeremy\AppData\Local\AVG SafeGuard toolbar Folder Found C:\Users\Jeremy\AppData\Local\Conduit Folder Found C:\Users\Jeremy\AppData\Local\NativeMessaging Folder Found C:\Users\Jeremy\AppData\Local\Temp\NativeMessaging Folder Found C:\Users\Jeremy\AppData\LocalLow\AVG SafeGuard toolbar Folder Found C:\Users\Jeremy\AppData\LocalLow\Conduit Folder Found C:\Users\Jeremy\AppData\Roaming\Mozilla\Firefox\Profiles\02yon0iv.default\CT3287802 Folder Found C:\Users\Jeremy\AppData\Roaming\Searchprotect ***** [ Shortcuts ] ***** ***** [ Registry ] ***** Key Found : HKCU\Software\AppDataLow\Software\Conduit Key Found : HKCU\Software\AppDataLow\Software\ConduitSearchScopes Key Found : HKCU\Software\AppDataLow\Software\SmartBar Key Found : HKCU\Software\AVG SafeGuard toolbar Key Found : HKCU\Software\Conduit Key Found : HKCU\Software\Google\Chrome\Extensions\ieiiggnfmhgcolbimglmfjfpkjildjdd Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Found : HKCU\Software\SearchProtect Key Found : HKCU\Software\Softonic Key Found : HKCU\Software\visualbee Key Found : HKCU\Software\WEDLMNGR Key Found : [x64] HKCU\Software\AVG SafeGuard toolbar Key Found : [x64] HKCU\Software\Conduit Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Found : [x64] HKCU\Software\SearchProtect Key Found : [x64] HKCU\Software\Softonic Key Found : [x64] HKCU\Software\visualbee Key Found : [x64] HKCU\Software\WEDLMNGR Key Found : HKLM\Software\AVG SafeGuard toolbar Key Found : HKLM\Software\AVG Security Toolbar Key Found : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323} Key Found : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2} Key Found : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB} Key Found : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE Key Found : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL Key Found : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.BrowserWndAPI Key Found : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.BrowserWndAPI.1 Key Found : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.PugiObj Key Found : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.PugiObj.1 Key Found : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777} Key Found : HKLM\SOFTWARE\Classes\CLSID\{408CFAD9-8F13-4747-8EC7-770A339C7237} Key Found : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Key Found : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3} Key Found : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Found : HKLM\SOFTWARE\Classes\CLSID\{AE91F9CE-0900-4E2A-B673-F3F6E4FC54D9} Key Found : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9} Key Found : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468} Key Found : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Key Found : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Found : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Key Found : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Key Found : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Key Found : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6} Key Found : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol Key Found : HKLM\SOFTWARE\Classes\S Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1 Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT3287802 Key Found : HKLM\SOFTWARE\Classes\TypeLib\{07CAC314-E962-4F78-89AB-DD002F2490EE} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94} Key Found : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE Key Found : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1 Key Found : HKLM\Software\Conduit Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\ieiiggnfmhgcolbimglmfjfpkjildjdd Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Found : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG SafeGuard toolbar Key Found : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin Key Found : HKLM\Software\SearchProtect Key Found : HKLM\Software\visualbee Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6} Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Found : [x64] HKLM\SOFTWARE\Scorpion Saver Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}] Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt] Value Found : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar] ***** [ Browsers ] ***** -\\ Internet Explorer v11.0.9600.16428 -\\ Mozilla Firefox v26.0 (en-US) [ File : C:\Users\Jeremy\AppData\Roaming\Mozilla\Firefox\Profiles\02yon0iv.default\prefs.js ] Line Found : user_pref("CT3287802.FF19Solved", "true"); Line Found : user_pref("CT3287802.UserID", "UN31794089652907720"); Line Found : user_pref("CT3287802.browser.search.defaultthis.engineName", "true"); Line Found : user_pref("CT3287802.fullUserID", "UN31794089652907720.IN.20131129214940"); Line Found : user_pref("CT3287802.installDate", "29/11/2013 21:49:48"); Line Found : user_pref("CT3287802.installSessionId", "{206458D2-E6FF-43BE-B790-6375371437BD}"); Line Found : user_pref("CT3287802.installSp", "TRUE"); Line Found : user_pref("CT3287802.installerVersion", "1.8.1.4"); Line Found : user_pref("CT3287802.keyword", "true"); Line Found : user_pref("CT3287802.originalSearchAddressUrl", ""); Line Found : user_pref("CT3287802.originalSearchEngine", "AVG Secure Search"); Line Found : user_pref("CT3287802.originalSearchEngineName", "AVG Secure Search"); Line Found : user_pref("CT3287802.searchRevert", "false"); Line Found : user_pref("CT3287802.searchUninstallUserMode", "2"); Line Found : user_pref("CT3287802.searchUserMode", "2"); Line Found : user_pref("CT3287802.smartbar.homepage", "true"); Line Found : user_pref("CT3287802.toolbarInstallDate", "29-11-2013 21:49:40"); Line Found : user_pref("CT3287802.versionFromInstaller", "10.22.5.10"); Line Found : user_pref("CT3287802.xpeMode", "0"); Line Found : user_pref("Smartbar.SearchFromAddressBarSavedUrl", ""); Line Found : user_pref("browser.search.defaultenginename", "VisualBee V.3 Customized Web Search"); Line Found : user_pref("browser.search.defaultthis.engineName", "VisualBee V.3 Customized Web Search"); Line Found : user_pref("browser.search.selectedEngine", "VisualBee V.3 Customized Web Search"); Line Found : user_pref("smartbar.addressBarOwnerCTID", "CT3287802"); Line Found : user_pref("smartbar.defaultSearchOwnerCTID", "CT3287802"); Line Found : user_pref("smartbar.homePageOwnerCTID", "CT3287802"); Line Found : user_pref("smartbar.machineId", "XV88LDKBO8GIOSFFY3Z1DQYXSP15QURSUUJW6TL+ZCAJC0CMRFIDVARWOZBCV3OTHUJJMPXDRGFZ4BILFPVHIG"); -\\ Google Chrome v32.0.1700.76 [ File : C:\Users\Jeremy\AppData\Local\Google\Chrome\User Data\Default\preferences ] Found : icon_url Found : search_url Found : suggest_url Found : keyword Found : search_url Found : icon_url Found : search_url Found : suggest_url Found : keyword ************************* AdwCleaner[R0].txt - [12994 octets] - [16/01/2014 18:14:42] ########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [13055 octets] ########## ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.0 (01.07.2014:1) OS: Windows 7 Home Premium x64 Ran by Jeremy on Thu 01/16/2014 at 20:40:40.61 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{D10D9E44-7750-43AC-B4C4-F6ECC28463D8} ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\Users\Jeremy\appdata\local\cre" ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on Thu 01/16/2014 at 20:45:40.81 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~