You are on page 1of 5

#

#
#
#
#
#
#

AdwCleaner v4.206 - Logfile created 15/06/2015 at 09:16:20


Updated 01/06/2015 by Xplode
Database : 2015-05-31.5 [Local]
Operating system : Windows 7 Home Premium (x86)
Username : Gonalo - GONALO
Running from : C:\Users\Gonalo\Downloads\AdwCleaner.exe
Option : Scan

***** [ Services ] *****


Service Found : IHProtect Service
Service Found : ServiceEverything
***** [ Files / Folders ] *****
File Found : C:\Program Files\Mozilla Firefox\browser\searchplugins\delta-homes.
xml
File Found : C:\Program Files\Mozilla Firefox\defaults\pref\itms.js
File Found : C:\Users\Gonalo\AppData\Local\Google\Chrome\User Data\Default\Local
Storage\hxxp_websearch.relevantsearch.info_0.localstorage
File Found : C:\Users\Gonalo\AppData\Local\Google\Chrome\User Data\Default\Local
Storage\hxxp_websearch.relevantsearch.info_0.localstorage-journal
File Found : C:\Users\Gonalo\AppData\Local\Google\Chrome\User Data\Default\Local
Storage\hxxp_www.delta-homes.com_0.localstorage
File Found : C:\Users\Gonalo\AppData\Local\Google\Chrome\User Data\Default\Local
Storage\hxxp_www.delta-homes.com_0.localstorage-journal
File Found : C:\Users\Gonalo\AppData\Roaming\LiveSupport.exe_log.txt
File Found : C:\Users\Gonalo\AppData\Roaming\Mozilla\Firefox\Profiles\samkhsc6.de
fault\user.js
File Found : C:\Users\Gonalo\AppData\Roaming\PDFShaper.ini
File Found : C:\Users\Gonalo\AppData\Roaming\regsvr32.exe_log.txt
File Found : C:\Users\Gonalo\AppData\Roaming\VVZXSY
File Found : C:\Users\Gonalo\AppData\Roaming\VVZXSY.exe
File Found : C:\Users\Gonalo\AppData\Roaming\XOSCE
File Found : C:\Users\Gonalo\AppData\Roaming\XOSCE.exe
File Found : C:\Users\Gonalo\daemonprocess.txt
File Found : C:\Users\Me\AppData\Local\Google\Chrome\User Data\Default\Local Stor
age\hxxp_en.softonic.com_0.localstorage
File Found : C:\Users\Me\AppData\Local\Google\Chrome\User Data\Default\Local Stor
age\hxxp_en.softonic.com_0.localstorage-journal
File Found : C:\Users\Me\AppData\Local\Google\Chrome\User Data\Default\Local Stor
age\hxxp_websearch.relevantsearch.info_0.localstorage
File Found : C:\Users\Me\AppData\Local\Google\Chrome\User Data\Default\Local Stor
age\hxxp_websearch.relevantsearch.info_0.localstorage-journal
File Found : C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Local S
torage\hxxp_isearch.avg.com_0.localstorage
File Found : C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Local S
torage\hxxp_isearch.avg.com_0.localstorage-journal
File Found : C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Local S
torage\hxxp_websearch.relevantsearch.info_0.localstorage
File Found : C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Local S
torage\hxxp_websearch.relevantsearch.info_0.localstorage-journal
File Found : C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Local S
torage\hxxps_isearch.avg.com_0.localstorage
File Found : C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Local S
torage\hxxps_isearch.avg.com_0.localstorage-journal
File Found : C:\Users\Vasco\AppData\Local\funmoods-speeddial.crx
File Found : C:\Users\Vasco\AppData\Local\Google\Chrome\User Data\Default\Local
Storage\hxxp_en.softonic.com_0.localstorage
File Found : C:\Users\Vasco\AppData\Local\Google\Chrome\User Data\Default\Local

Storage\hxxp_en.softonic.com_0.localstorage-journal
File Found : C:\Users\Vasco\AppData\Local\Google\Chrome\User Data\Default\Local
Storage\hxxp_websearch.relevantsearch.info_0.localstorage
File Found : C:\Users\Vasco\AppData\Local\Google\Chrome\User Data\Default\Local
Storage\hxxp_websearch.relevantsearch.info_0.localstorage-journal
File Found : C:\Users\Vasco\AppData\Roaming\Microsoft\Windows\Start Menu\Program
s\jZip.lnk
File Found : C:\Windows\system32\RegistryHelperLM.ocx
Folder Found : C:\Program Files\SupTab
Folder Found : C:\ProgramData\{72725c86-aad7-02b9-7272-25c86aad721a}
Folder Found : C:\ProgramData\Avg_Update_0814tb
Folder Found : C:\ProgramData\IePluginService
Folder Found : C:\ProgramData\IHProtectUpDate
Folder Found : C:\ProgramData\Registry Helper
Folder Found : C:\ProgramData\SoftWarehouse
Folder Found : C:\ProgramData\StarApp
Folder Found : C:\ProgramData\Tarma Installer
Folder Found : C:\ProgramData\WPM
Folder Found : C:\Users\GONALO~1\AppData\Local\Temp\BrowseMark
Folder Found : C:\Users\GONALO~1\AppData\Local\Temp\jZip
Folder Found : C:\Users\GONALO~1\AppData\Local\Temp\NetCrawl
Folder Found : C:\Users\Gonalo\AppData\Local\genienext
Folder Found : C:\Users\Gonalo\AppData\Local\globalUpdate
Folder Found : C:\Users\Gonalo\AppData\Local\jZip
Folder Found : C:\Users\Gonalo\AppData\Local\Mobogenie
Folder Found : C:\Users\Gonalo\AppData\LocalLow\AVG Secure Search
Folder Found : C:\Users\Gonalo\AppData\Roaming\goforfiles
Folder Found : C:\Users\Gonalo\AppData\Roaming\newnext.me
Folder Found : C:\Users\Gonalo\AppData\Roaming\Solvusoft
Folder Found : C:\Users\Gonalo\AppData\Roaming\SupTab
Folder Found : C:\Users\Gonalo\AppData\Roaming\sweet-page
Folder Found : C:\Users\Joana.GONALO\AppData\Local\jZip
Folder Found : C:\Users\Me\AppData\Local\jZip
Folder Found : C:\Users\Me\AppData\LocalLow\AVG Secure Search
Folder Found : C:\Users\Vasco\AppData\Local\Funmoods
Folder Found : C:\Users\Vasco\AppData\Local\jZip
Folder Found : C:\Users\Vasco\AppData\LocalLow\AVG Secure Search
Folder Found : C:\Users\Vasco\AppData\Roaming\Funmoods
Folder Found : C:\Users\Vasco\Funmoods
***** [ Scheduled tasks ] *****
Task
Task
Task
Task
Task
Task
Task
Task

Found
Found
Found
Found
Found
Found
Found
Found

:
:
:
:
:
:
:
:

Funmoods
GoforFilesUpdate
VVZXSY
VVZXSY
XOSCE
XOSCE
0814tbUpdateInfo
0814tbUpdateInfo

***** [ Shortcuts ] *****


Shortcut Infected : C:\Users\Gonalo\AppData\Roaming\Microsoft\Windows\Start Menu\
Programs\Internet Explorer.lnk
Shortcut Infected : C:\Users\Gonalo\AppData\Roaming\Microsoft\Windows\Start Menu\
Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
Shortcut Infected : C:\Users\Gonalo\AppData\Roaming\Microsoft\Internet Explorer\Q
uick Launch\Google Chrome.lnk
Shortcut Infected : C:\Users\Gonalo\AppData\Roaming\Microsoft\Internet Explorer\Q

uick Launch\Launch Internet Explorer Browser.lnk


***** [ Registry ] *****
Data Found : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\s
hell\open\command [(Default)] - "C:\Program Files\Mozilla Firefox\firefox.exe" h
xxp://www.delta-homes.com/?type=sc&ts=1434056033&z=a8fc50012d6f09becfd6c80gcz7cc
z1ebw3q7e3c6z&from=ient06110&uid=WDCXWD3200AAKX-001CA0_WD-WMAYUE28959289592
Data Found : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome
\shell\open\command [(Default)] - "C:\Program Files\Google\Chrome\Application\ch
rome.exe" hxxp://www.delta-homes.com/?type=sc&ts=1434056033&z=a8fc50012d6f09becf
d6c80gcz7ccz1ebw3q7e3c6z&from=ient06110&uid=WDCXWD3200AAKX-001CA0_WD-WMAYUE28959
289592
Data Found : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\
shell\open\command [(Default)] - C:\Program Files\Internet Explorer\iexplore.exe
hxxp://www.delta-homes.com/?type=sc&ts=1434056033&z=a8fc50012d6f09becfd6c80gcz7
ccz1ebw3q7e3c6z&from=ient06110&uid=WDCXWD3200AAKX-001CA0_WD-WMAYUE28959289592
Data Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_
DLLs] - C:\PROGRA~1\SupTab\SEARCH~1.DLL
Key Found : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Found : HKCU\Software\AppDataLow\Software\Crossrider
Key Found : HKCU\Software\AppDataLow\SProtector
Key Found : HKCU\Software\Appscion
Key Found : HKCU\Software\BI
Key Found : HKCU\Software\Conduit_Search_Protect
Key Found : HKCU\Software\GlobalUpdate
Key Found : HKCU\Software\GoforFiles
Key Found : HKCU\Software\InstallCore
Key Found : HKCU\Software\jZip
Key Found : HKCU\Software\LiveSupport
Key Found : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\del
ta-homes.com
Key Found : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\sup
erfish.com
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D77
6-472f-A0FF-E1416B8B2E3A}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06
A-4372-A1C7-0B49F9E0FFF0}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99A
F-4226-BDF6-49120163DE86}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4
C-4172-9AC4-73315F71CFFE}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{BF81DC48-60C
0-40E8-BD6D-F97A743C6F33}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBC
F-4FDA-883E-ADEF965B476C}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{51D26BB
4-4D2C-4AE4-9873-5FF41B6DED1F}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2A5A2A90-3
B30-4E6E-A955-2F232C6EF517}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{51D26BB4-4
D2C-4AE4-9873-5FF41B6DED1F}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AF6B0594-6
008-4327-93E5-608AD710A6FA}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\jZip
Key Found : HKCU\Software\Softonic
Key Found : HKCU\Software\Webplayer
Key Found : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Found : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Found : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}

Key Found : HKLM\SOFTWARE\Avg Secure Update


Key Found : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Key Found : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Key Found : HKLM\SOFTWARE\Classes\CLSID\{00B11DA2-75ED-4364-ABA5-9A95B1F5E946}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{408CFAD9-8F13-4747-8EC7-770A339C7237}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{6D4506CE-F855-4657-AA38-DB6B1F733982}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{6E993643-8FBC-44FE-BC85-D318495C4D96}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
Key Found : HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0
F}
Key Found : HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F8853
4}
Key Found : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B
8}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016
F}
Key Found : HKLM\SOFTWARE\Classes\jZip.file
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{03771AEF-400D-4A13-B712-25878EC4A3F5}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{07CAC314-E962-4F78-89AB-DD002F2490EE}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{DCABB943-792E-44C4-9029-ECBEE6265AF9}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Key Found : HKLM\SOFTWARE\delta-homesSoftware
Key Found : HKLM\SOFTWARE\GlobalUpdate
Key Found : HKLM\SOFTWARE\GoforFiles
Key Found : HKLM\SOFTWARE\IHProtect
Key Found : HKLM\SOFTWARE\jZip
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4
C-4172-9AC4-73315F71CFFE}
Key Found : HKLM\SOFTWARE\microsoft\shared tools\msconfig\startupreg\mobilegeni
daemon
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAd
d
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppPath\jZip.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Help
er Objects\{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Help
er Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C670DCAE-E
392-AA32-6F42-143C7FC4BDFD}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\S-480333868
Key Found : HKLM\SOFTWARE\Registry Helper
Key Found : HKLM\SOFTWARE\SP Global
Key Found : HKLM\SOFTWARE\SProtector
Key Found : HKLM\SOFTWARE\SupDp
Key Found : HKLM\SOFTWARE\SupTab
Key Found : HKLM\SOFTWARE\supWPM
Key Found : HKLM\SOFTWARE\sweet-pageSoftware
Key Found : HKLM\SOFTWARE\Tarma Installer
Key Found : HKLM\SOFTWARE\Vittalia
Key Found : HKLM\SOFTWARE\Wpm
Key Found : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IePlugin
Service
Key Found : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\webcakeu
pdater
Key Found : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Wpm
Key Found : HKU\.DEFAULT\Software\Avg Secure Update

***** [ Web browsers ] *****


-\\ Internet Explorer v9.0.8112.16476
Setting Found : HKCU\Software\Microsoft\Internet Explorer\Main [Search Page] - h
xxp://search.delta-homes.com/web/?type=ds&ts=1434056033&z=a8fc50012d6f09becfd6c8
0gcz7ccz1ebw3q7e3c6z&from=ient06110&uid=WDCXWD3200AAKX-001CA0_WD-WMAYUE289592895
92&q={searchTerms}
Setting Found : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL
] - hxxp://www.delta-homes.com/?type=hp&ts=1434056033&z=a8fc50012d6f09becfd6c80g
cz7ccz1ebw3q7e3c6z&from=ient06110&uid=WDCXWD3200AAKX-001CA0_WD-WMAYUE28959289592
Setting Found : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Search_U
RL] - hxxp://search.delta-homes.com/web/?type=ds&ts=1434056033&z=a8fc50012d6f09b
ecfd6c80gcz7ccz1ebw3q7e3c6z&from=ient06110&uid=WDCXWD3200AAKX-001CA0_WD-WMAYUE28
959289592&q={searchTerms}
Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_U
RL] - hxxp://www.sweet-page.com/web/?type=ds&ts=1397490980&from=cor&uid=WDCXWD32
00AAKX-001CA0_WD-WMAYUE28959289592&q={searchTerms}
Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL
] - hxxp://www.delta-homes.com/?type=hp&ts=1434056033&z=a8fc50012d6f09becfd6c80g
cz7ccz1ebw3q7e3c6z&from=ient06110&uid=WDCXWD3200AAKX-001CA0_WD-WMAYUE28959289592
Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] - h
xxp://www.sweet-page.com/web/?type=ds&ts=1397490980&from=cor&uid=WDCXWD3200AAKX001CA0_WD-WMAYUE28959289592&q={searchTerms}
-\\ Mozilla Firefox v38.0.5 (x86 pt-PT)
-\\ Google Chrome v43.0.2357.124
[C:\Users\Gonalo\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found
[Search Provider] : hxxp://en.softonic.com/s/{searchTerms}
[C:\Users\Gonalo\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found
[Search Provider] : hxxp://en.softonic.com/s/{searchTerms}
[C:\Users\Joana.GONALO\AppData\Local\Google\Chrome\User Data\Default\Web data] Found [Search Provider] : hxxp://www.softonic.com.br/s/{searchTerms}
[C:\Users\Me\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] Found [Extension] : ndibdjnfmopecpmkdieinmbadjfpblof
[C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [
Search Provider] : hxxp://isearch.avg.com/search?cid={B7D183AF-CCD4-4E46-908F-DF
E2C6E5F935}&mid=41310532646242b88aec138cbb106f63-ad1491be2ce6c122f6b66faa90e70c2
decf7d34c&lang=pt-br&ds=hk015&pr=sa&d=2013-04-27 14:53:52&v=15.5.0.2&pid=avg&sg=
0&sap=dsp&q={searchTerms}
*************************
AdwCleaner[R0].txt - [15302 bytes] - [15/06/2015 09:16:20]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [15362 bytes] ##########

You might also like