Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # AdwCleaner v5.001 - Logfile created 04/09/2015 at 19:05:05
- # Updated 17/08/2015 by Xplode
- # Database : 2015-08-31.2 [Server]
- # Operating system : Microsoft Windows XP Service Pack 3 (x86)
- # Username : User - X-TEAM
- # Running from : C:\Documents and Settings\User\Мои документы\модели\adwcleaner-5-001-multi-win.exe
- # Option : Scan
- ***** [ Services ] *****
- Service Found : QQPCRTP
- Service Found : TS888
- Service Found : TAOAccelerator
- Service Found : TSDefenseBt
- Service Found : TSSysKit
- Service Found : QMUdisk
- Service Found : TSCPM
- Service Found : TFsFlt
- Service Found : TAOFrame
- Service Found : tsksp
- Service Found : QQSysMon
- Service Found : TsFltMgr
- Service Found : TAOKernelDriver
- Service Found : TSSK
- Service Found : QMIEProtect
- ***** [ Folders ] *****
- Folder Found : C:\Documents and Settings\All Users\Application Data\Mail.Ru
- Folder Found : C:\Documents and Settings\All Users\Application Data\tencent
- Folder Found : C:\Documents and Settings\User\Application Data\AnyProtectEx
- Folder Found : C:\Documents and Settings\User\Application Data\SmartWeb
- Folder Found : C:\Documents and Settings\User\Application Data\tencent
- Folder Found : C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\ibq1ct9d.default\Extensions\{a38384b3-2d1d-4f36-bc22-0f7ae402bcd7}
- Folder Found : C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\ibq1ct9d.default\Extensions\defsearchp@gmail.com
- Folder Found : C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\ibq1ct9d.default\Extensions\{6E727987-C8EA-44DA-8749-310C0FBE3C3E}
- Folder Found : C:\Documents and Settings\User\Local Settings\Application Data\globalUpdate
- Folder Found : C:\Documents and Settings\User\Local Settings\Application Data\Mail.Ru
- Folder Found : C:\Documents and Settings\User\Local Settings\Application Data\MailRu
- Folder Found : C:\Documents and Settings\User\Local Settings\Application Data\MediaGet2
- Folder Found : C:\Documents and Settings\User\Local Settings\Application Data\SmartWeb
- Folder Found : C:\Documents and Settings\User\Local Settings\Application Data\Kometa
- Folder Found : C:\Documents and Settings\User\Local Settings\Application Data\Crossbrowse
- Folder Found : C:\Documents and Settings\User\Local Settings\Application Data\Amigo
- Folder Found : C:\Documents and Settings\User\Local Settings\Application Data\promoskiki
- Folder Found : C:\Documents and Settings\User\Local Settings\Application Data\Host installer
- Folder Found : C:\Documents and Settings\User\Local Settings\Application Data\5E978D00-1438204158-81DF-29A9-485B395BBDB6
- Folder Found : C:\Documents and Settings\User\Главное меню\Программы\promoskiki
- Folder Found : C:\Program Files\Mail.Ru
- Folder Found : C:\Program Files\Crossbrowse
- Folder Found : C:\Program Files\tencent
- Folder Found : C:\Program Files\Torrent Search
- Folder Found : C:\Program Files\Application Assistance
- Folder Found : C:\Program Files\skinapp
- Folder Found : C:\Program Files\Common Files\tencent
- ***** [ Files ] *****
- File Found : C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\crossbrowse.lnk
- File Found : C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\ibq1ct9d.default\Extensions\vb@yandex.ru.xpi
- File Found : C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\ibq1ct9d.default\searchplugins\mystartsearch.xml
- File Found : C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\ibq1ct9d.default\user.js
- File Found : C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\ibq1ct9d.default\searchplugins\mailru.xml
- File Found : C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Local Storage\hxxp_pstatic.bestpriceninja.com_0.localstorage
- File Found : C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Local Storage\hxxp_pstatic.bestpriceninja.com_0.localstorage-journal
- File Found : C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Local Storage\hxxps_pstatic.bestpriceninja.com_0.localstorage
- File Found : C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Local Storage\hxxps_pstatic.bestpriceninja.com_0.localstorage-journal
- File Found : C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Local Storage\hxxp_searches.vi-view.com_0.localstorage
- File Found : C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Local Storage\hxxp_searches.vi-view.com_0.localstorage-journal
- File Found : C:\WINDOWS\QMNetworkMgr.ini
- File Found : C:\WINDOWS\system32\tssk.sys
- File Found : C:\WINDOWS\system32\drivers\TsFltMgr.sys
- File Found : C:\WINDOWS\system32\drivers\TSDefenseBt.sys
- File Found : C:\WINDOWS\system32\drivers\TFsFlt.sys
- File Found : C:\WINDOWS\system32\drivers\TAOKernelXP.sys
- File Found : C:\WINDOWS\system32\drivers\TS888.sys
- File Found : C:\WINDOWS\system32\drivers\TAOAccelerator.sys
- ***** [ Shortcuts ] *****
- Shortcut Infected : C:\Documents and Settings\User\Главное меню\Программы\WarThunder\WаrТhundеr.lnk ( hxxp://www.mystartsearch.com/?type=sc&ts=1438419521&z=9335ce5bdec3f5143f5938fg9z1c0b9z5o5c3bee1z&from=cmi&uid=395049983_1052514_847ECE53 )
- ***** [ Scheduled tasks ] *****
- Task Found : Update Service for Torrent Search
- Task Found : Update Service for Torrent Search2
- Task Found : WordSurfer Auto Updater 1.10.0.19 Pending Update
- Task Found : WordSurfer Auto Updater 1.10.0.19 Core
- Task Found : WordSurfer Auto Updater 1.10.0.19 Core
- Task Found : WordSurfer Auto Updater 1.10.0.19 Pending Update
- ***** [ Registry ] *****
- Key Found : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
- Key Found : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
- Key Found : HKCU\Software\Mozilla\Extends
- Key Found : HKLM\SOFTWARE\Classes\AppID\DownloadProxy.EXE
- Key Found : HKLM\SOFTWARE\Microsoft\Mediaplayer\Shiminclusionlist\crossbrowse.exe
- Key Found : HKLM\SOFTWARE\Clients\StartMenuInternet\crossbrowse.exe
- Key Found : HKLM\SOFTWARE\Classes\CRSBRWSHTML
- Key Found : HKLM\SOFTWARE\Clients\StartMenuInternet\Crossbrowse
- Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\crossbrowse.exe
- Value Found : HKLM\SOFTWARE\Classes\.htm\OpenWithProgids [CRSBRWSHTML]
- Value Found : HKLM\SOFTWARE\Classes\.html\OpenWithProgids [CRSBRWSHTML]
- Value Found : HKLM\SOFTWARE\RegisteredApplications [Crossbrowse]
- Key Found : HKLM\SOFTWARE\Classes\AppID\globalupdate.exe
- Key Found : HKLM\SOFTWARE\CLASSES\METNSD
- Key Found : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\QQPCRTP
- Key Found : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\QQPCRTP
- Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\.QMDeskTopGCIcon
- Value Found : HKLM\SOFTWARE\Classes\.xht\OpenWithProgIDs [CRSBRWSHTML]
- Value Found : HKLM\SOFTWARE\Classes\.webp\OpenWithProgIDs [CRSBRWSHTML]
- Value Found : HKLM\SOFTWARE\Classes\.shtml\OpenWithProgIDs [CRSBRWSHTML]
- Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\browser.exe
- Key Found : HKLM\SOFTWARE\MozillaPlugins\@qq.com/QQPCMgr
- Key Found : HKLM\SOFTWARE\Clients\StartMenuInternet\amigo.exe
- Value Found : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [defsearchp@gmail.com]
- Key Found : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
- Key Found : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
- Key Found : HKLM\SOFTWARE\Classes\AppID\{51BEE30D-EEC8-4BA3-930B-298B8E759EB1}
- Key Found : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
- Key Found : HKLM\SOFTWARE\Classes\CLSID\{70DE12EA-79F4-46BC-9812-86DB50A2FD64}
- Key Found : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
- Key Found : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
- Key Found : HKLM\SOFTWARE\Classes\CLSID\{C379EAD1-CB34-4B09-AF6B-7E587F8BCD80}
- Key Found : HKLM\SOFTWARE\Classes\CLSID\{6EDBF8C0-C94C-4A13-956F-E393BCA5BA4B}
- Key Found : HKLM\SOFTWARE\Classes\CLSID\{1F91A9A1-01BA-4C81-863D-3BA0751E1419}
- Key Found : HKLM\SOFTWARE\Classes\CLSID\{6E727987-C8EA-44DA-8749-310C0FBE3C3E}
- Key Found : HKLM\SOFTWARE\Classes\Interface\{E7270EC6-0113-4A78-B610-E501D0A9E48E}
- Key Found : HKLM\SOFTWARE\Classes\Interface\{EAC7DE5C-9520-435D-91AA-4A02E4773CEA}
- Key Found : HKLM\SOFTWARE\Classes\Interface\{357D32FC-F0AE-4B37-B36F-D44AA31496F5}
- Key Found : HKLM\SOFTWARE\Classes\Interface\{80B3B43F-7508-4627-BE66-00FB9AE5EE72}
- Key Found : HKLM\SOFTWARE\Classes\TypeLib\{B0660298-91AA-421F-BF0D-BFF6BB8BF3AE}
- Key Found : HKLM\SOFTWARE\Classes\TypeLib\{5A83D7C9-4A14-4000-BC05-389268238753}
- Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1F91A9A1-01BA-4C81-863D-3BA0751E1419}
- Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6E727987-C8EA-44DA-8749-310C0FBE3C3E}
- Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1F91A9A1-01BA-4C81-863D-3BA0751E1419}
- Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6E727987-C8EA-44DA-8749-310C0FBE3C3E}
- Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1F91A9A1-01BA-4C81-863D-3BA0751E1419}
- Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
- Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
- Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser [{10921475-03CE-4E04-90CE-E2E7EF20C814}]
- Key Found : HKU\.DEFAULT\Software\Torrent Search
- Key Found : HKCU\Software\AnyProtect
- Key Found : HKCU\Software\APN PIP
- Key Found : HKCU\Software\IM
- Key Found : HKCU\Software\InstalledBrowserExtensions
- Key Found : HKCU\Software\SmartWeb
- Key Found : HKCU\Software\Crossbrowse
- Key Found : HKCU\Software\YorkNewCin
- Key Found : HKCU\Software\Torrent Search
- Key Found : HKCU\Software\Kromtech
- Key Found : HKLM\SOFTWARE\InstalledBrowserExtensions
- Key Found : HKLM\SOFTWARE\Crossbrowse
- Key Found : HKLM\SOFTWARE\SpeedBit
- Key Found : HKLM\SOFTWARE\Torrent Search
- Key Found : HKLM\SOFTWARE\searchult
- Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AnyProtect
- Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdater
- Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ASPackage
- Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Linkey
- Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7ADF667E-E14D-4D2C-827C-B0108F0D93BC}
- Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2AEF02C3-5159-4C81-A688-8D954F0DEE56}_NewSearch
- Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\MailRuUpdater
- Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\SoftwareUpdater
- Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ASPackage
- Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Torrent Search
- Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{2AEF02C3-5159-4C81-A688-8D954F0DEE56}_NewSearch
- Data Found : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxp://www.hao123.com/?tn=95751091_hao_pg
- Data Found : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Search_URL] - hxxps://safesearch.avira.com/#web/result?source=art&q=
- Data Found : HKCU\Software\Microsoft\Internet Explorer\Main [Search Page] - hxxps://safesearch.avira.com/#web/result?source=art&q=
- Data Found : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL] - hxxps://safesearch.avira.com/#web/result?source=art&q=
- Data Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] - hxxp://www.hao123.com/?tn=95751091_hao_pg
- Data Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL] - hxxp://www.mystartsearch.com/?type=hppp&ts=1438435050&z=c560da6ca3ebd8ae1f18efagdz2c3b1z7c3t0cccbw&from=cmi&uid=395049983_1052514_847ECE53
- Data Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [SearchAssistant] - hxxp://www.mystartsearch.com/web/?type=dspp&ts=1438435050&z=c560da6ca3ebd8ae1f18efagdz2c3b1z7c3t0cccbw&from=cmi&uid=395049983_1052514_847ECE53&q={searchTerms}
- Data Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [CustomizeSearch] - hxxp://www.mystartsearch.com/web/?type=dspp&ts=1438435050&z=c560da6ca3ebd8ae1f18efagdz2c3b1z7c3t0cccbw&from=cmi&uid=395049983_1052514_847ECE53&q={searchTerms}
- Data Found : HKU\S-1-5-21-484763869-448539723-1801674531-1004\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxp://www.hao123.com/?tn=95751091_hao_pg
- Data Found : HKU\S-1-5-21-484763869-448539723-1801674531-1004\Software\Microsoft\Internet Explorer\Main [Default_Search_URL] - hxxps://safesearch.avira.com/#web/result?source=art&q=
- Data Found : HKU\S-1-5-21-484763869-448539723-1801674531-1004\Software\Microsoft\Internet Explorer\Main [Search Page] - hxxps://safesearch.avira.com/#web/result?source=art&q=
- Data Found : HKU\S-1-5-21-484763869-448539723-1801674531-1004\Software\Microsoft\Internet Explorer\Main [Default_Page_URL] - hxxps://safesearch.avira.com/#web/result?source=art&q=
- Data Found : HKLM\SOFTWARE\Clients\StartMenuInternet\chrome.exe\shell\open\command [] - "C:\Program Files\Google\Chrome\Application\chrome.exe" hxxp://www.mystartsearch.com/?type=sc&ts=1438616943&z=8a5e2a2a41a47f5037b671bgcz8c3bdq0odgeofo2c&from=cmi&uid=395049983_1052514_847ECE53
- ***** [ Web browsers ] *****
- [C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : gosearch
- [C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : istartsurf
- [C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : mystartsearch.com
- [C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : mystartsearch
- *************************
- C:\AdwCleaner[S8].txt - [14514 bytes] - [04/09/2015 19:05:05]
- ########## EOF - C:\AdwCleaner[S8].txt - [14577 bytes] ##########
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement