# AdwCleaner v6.
021 - Logfile created 14/10/2016 at 09:36:41
# Updated on 06/10/2016 by ToolsLib
# Database : 2016-10-13.2 [Server]
# Operating System : Windows 7 Ultimate Service Pack 1 (X86)
# Username : CRRPH Comanesti - STELI
# Running from : C:\Users\CRRPH Comanesti\Downloads\adwcleaner_6.021.exe
# Mode: Scan
# Support : https://toolslib.net/forum
***** [ Services ] *****
Service Found: BaiduHips
Service Found: bd0001
Service Found: bd0002
Service Found: BDMRTP
Service Found: BDMWrench
Service Found: QMUdisk
Service Found: TSSK
Service Found: softaal
Service Found: SRepairDrv
Service Found: tsnethlp
***** [ Folders ] *****
Folder Found: C:\Program Files\MTV20160128
Folder Found: C:\Users\CRRPH Comanesti\AppData\Local\VirtualStore\Program
Files\tencent
Folder Found: C:\Users\CRRPH Comanesti\AppData\Local\VirtualStore\Program
Files\Tencent
Folder Found: C:\Users\CRRPH Comanesti\AppData\Roaming\DriverCure
Folder Found: C:\Users\CRRPH Comanesti\AppData\Roaming\ParetoLogic
Folder Found: C:\Users\CRRPH Comanesti\AppData\Roaming\tencent
Folder Found: C:\Users\CRRPH Comanesti\AppData\Roaming\Tencent
Folder Found: C:\ProgramData\tencent
Folder Found: C:\ProgramData\TXQMPC
Folder Found: C:\ProgramData\Tencent
Folder Found: C:\ProgramData\Application Data\tencent
Folder Found: C:\ProgramData\Application Data\TXQMPC
Folder Found: C:\ProgramData\Application Data\Tencent
Folder Found: C:\Program Files\tencent
Folder Found: C:\Program Files\Tencent
Folder Found: C:\Program Files\Common Files\tencent
Folder Found: C:\Program Files\Common Files\Tencent
Folder Found: C:\Windows\GJFix
Folder Found: C:\Windows\system32\config\systemprofile\AppData\LocalLow\Yahoo!
Companion
Folder Found:
C:\Windows\system32\config\systemprofile\AppData\LocalLow\Yahoo!\Companion
***** [ Files ] *****
File Found: C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
File Found: C:\ProgramData\Application Data\{262E20B8-6E20-4CEF-B1FD-
D022AB1085F5}.dat
File Found: C:\Windows\system32\tssk.sys
***** [ DLL ] *****
No malicious DLLs found.
***** [ WMI ] *****
No malicious keys found.
***** [ Shortcuts ] *****
No infected shortcut found.
***** [ Scheduled Tasks ] *****
No malicious task found.
***** [ Registry ] *****
Key Found: HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\WdsManPro
Key Found: HKLM\SOFTWARE\Classes\BDDownloadProxy.Downloader
Key Found: HKLM\SOFTWARE\Classes\BDDownloadProxy.Downloader.1
Key Found: HKLM\SOFTWARE\Classes\Bolwt.WtBol
Key Found: HKLM\SOFTWARE\Classes\Bolwt.WtBol.1
Key Found: HKLM\SOFTWARE\Classes\metnsd
Key Found: HKLM\SOFTWARE\Classes\MTview.bmp
Key Found: HKLM\SOFTWARE\Classes\MTview.dib
Key Found: HKLM\SOFTWARE\Classes\MTview.emf
Key Found: HKLM\SOFTWARE\Classes\MTview.exif
Key Found: HKLM\SOFTWARE\Classes\MTview.gif
Key Found: HKLM\SOFTWARE\Classes\MTview.ico
Key Found: HKLM\SOFTWARE\Classes\MTview.jfif
Key Found: HKLM\SOFTWARE\Classes\MTview.jpe
Key Found: HKLM\SOFTWARE\Classes\MTview.jpeg
Key Found: HKLM\SOFTWARE\Classes\MTview.jpg
Key Found: HKLM\SOFTWARE\Classes\MTview.png
Key Found: HKLM\SOFTWARE\Classes\MTview.tif
Key Found: HKLM\SOFTWARE\Classes\MTview.tiff
Key Found: HKLM\SOFTWARE\Classes\MTview.wmf
Key Found: HKLM\SOFTWARE\Classes\PCSuiteContactsView
Key Found: HKLM\SOFTWARE\Classes\PCSuiteMessagesView
Key Found: HKLM\SOFTWARE\Classes\qmgcfiles
Key Found: HKLM\SOFTWARE\Classes\Sample.BrowserHandler
Key Found: HKLM\SOFTWARE\Classes\Sample.BrowserHandler.1
Key Found: HKLM\SOFTWARE\Classes\Sample.YTBPartnerSample
Key Found: HKLM\SOFTWARE\Classes\Sample.YTBPartnerSample.1
Key Found: HKLM\SOFTWARE\Classes\YBrowserToolbar.YBrowserToolbar
Key Found: HKLM\SOFTWARE\Classes\YBrowserToolbar.YBrowserToolbar.1
Key Found: HKU\S-1-5-21-466879663-47384589-4096548802-
1000\Software\Classes\TypeLib\{157B1AA6-3E5C-404A-9118-C1D91F537040}
Key Found: HKLM\SOFTWARE\Classes\AppID\{51BEE30D-EEC8-4BA3-930B-298B8E759EB1}
Key Found: HKLM\SOFTWARE\Classes\AppID\{7375D127-3955-4654-8E7D-1949A7A9C902}
Key Found: HKLM\SOFTWARE\Classes\CLSID\{70DE12EA-79F4-46BC-9812-86DB50A2FD64}
Key Found: HKLM\SOFTWARE\Classes\CLSID\{15DEE173-1BE9-4424-81E0-58A87076E9B1}
Key Found: HKLM\SOFTWARE\Classes\CLSID\{91B5E4DE-4C97-41CD-9F94-84BFAABB7371}
Key Found: HKLM\SOFTWARE\Classes\CLSID\{920D873D-05AB-4574-AD3A-872DD173658A}
Key Found: HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Key Found: HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Key Found: HKLM\SOFTWARE\Classes\Interface\{6B3732AA-F6D4-4F16-9E22-49EDC52C9514}
Key Found: HKLM\SOFTWARE\Classes\Interface\{E7270EC6-0113-4A78-B610-E501D0A9E48E}
Key Found: HKLM\SOFTWARE\Classes\Interface\{371AD4A5-1520-4AA2-A8A4-F9AD3BAC6957}
Key Found: HKLM\SOFTWARE\Classes\Interface\{7F124846-5453-4BB8-A41D-E11481FFC9DF}
Key Found: HKLM\SOFTWARE\Classes\Interface\{8FD65019-BF09-45DA-AD81-E95AE911F1FD}
Key Found: HKCU\Software\Classes\TypeLib\{157B1AA6-3E5C-404A-9118-C1D91F537040}
Key Found: HKLM\SOFTWARE\Classes\TypeLib\{F6C2BABA-9E4C-425F-9AEC-24AB8F2B640D}
Key Found: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects\{15DEE173-1BE9-4424-81E0-58A87076E9B1}
Key Found: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{15DEE173-
1BE9-4424-81E0-58A87076E9B1}
Key Found: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{29B6CFD5-
0064-411A-8C42-9890C83F9921}
Key Found: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{15DEE173-
1BE9-4424-81E0-58A87076E9B1}
Key Found: HKU\.DEFAULT\Software\Yahoo\Companion
Key Found: HKU\.DEFAULT\Software\SavePass 1.1-nv-ie
Key Found: HKU\S-1-5-21-466879663-47384589-4096548802-1000\Software\Conduit
Key Found: HKU\S-1-5-21-466879663-47384589-4096548802-
1000\Software\InstalledBrowserExtensions
Key Found: HKU\S-1-5-21-466879663-47384589-4096548802-1000\Software\Myfree Codec
Key Found: HKU\S-1-5-21-466879663-47384589-4096548802-1000\Software\OB
Key Found: HKU\S-1-5-21-466879663-47384589-4096548802-1000\Software\ParetoLogic
Key Found: HKU\S-1-5-21-466879663-47384589-4096548802-1000\Software\WEBAPP
Key Found: HKU\S-1-5-21-466879663-47384589-4096548802-
1000\Software\Yahoo\Companion
Key Found: HKU\S-1-5-21-466879663-47384589-4096548802-
1000\Software\Yahoo\YFriendsBar
Key Found: HKU\S-1-5-21-466879663-47384589-4096548802-1000\Software\SavePass 1.1-
nv-ie
Key Found: HKU\S-1-5-21-466879663-47384589-4096548802-
1000\Software\AppDataLow\Software\Yahoo\Companion
Key Found: HKCU\Software\Microsoft\Internet
Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-466879663-47384589-4096548802-
1000\Software\Yahoo\YFriendsBar
Key Found: HKU\S-1-5-18\Software\Yahoo\Companion
Key Found: HKU\S-1-5-18\Software\SavePass 1.1-nv-ie
Key Found: HKCU\Software\Conduit
Key Found: HKCU\Software\InstalledBrowserExtensions
Key Found: HKCU\Software\Myfree Codec
Key Found: HKCU\Software\OB
Key Found: HKCU\Software\ParetoLogic
Key Found: HKCU\Software\WEBAPP
Key Found: HKCU\Software\Yahoo\Companion
Key Found: HKCU\Software\Yahoo\YFriendsBar
Key Found: HKCU\Software\SavePass 1.1-nv-ie
Key Found: HKCU\Software\AppDataLow\Software\Yahoo\Companion
Key Found: HKLM\SOFTWARE\AppDataLow\SOFTWARE\_CrossriderRegNamePlaceHolder_
Key Found: HKLM\SOFTWARE\AppDataLow\SOFTWARE\Crossrider
Key Found: HKLM\SOFTWARE\GlobalUpdate
Key Found: HKLM\SOFTWARE\InstalledBrowserExtensions
Key Found: HKLM\SOFTWARE\istartsurfSoftware
Key Found: HKLM\SOFTWARE\Myfree Codec
Key Found: HKLM\SOFTWARE\ParetoLogic
Key Found: HKLM\SOFTWARE\Yahoo\Companion
Key Found: HKLM\SOFTWARE\SavePass 1.1-nv-ie
Data Found: HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] -
hxxp://www.hao123.com/?tn=29065018_243_hao_pg
Key Found: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\bestpriceninja.com
Key Found: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\foxi69.tlscdn.com
Key Found: HKCU\Software\Microsoft\Internet
Explorer\DOMStorage\pstatic.bestpriceninja.com
Key Found: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\qq.com
Key Found: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\tlscdn.com
Key Found: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\v.qq.com
Key Found: HKCU\Software\Microsoft\Internet
Explorer\LowRegistry\DOMStorage\hao123.com
Key Found: HKCU\Software\Microsoft\Internet
Explorer\LowRegistry\DOMStorage\www.hao123.com
Value Found: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [baiduAnTray]
Value Found: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [MTView]
Value Found: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [un]
Key Found: HKLM\SOFTWARE\Classes\AppID\DownloadProxy.EXE
Key Found: HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\QQPCRTP
Key Found: HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\QQPCRTP
Key Found: HKCU\Software\Classes\VirtualStore\MACHINE\SOFTWARE\Tencent
Key Found: HKEY_CLASSES_ROOT\.qmgc
***** [ Web browsers ] *****
No malicious Firefox based browser items found.
No malicious Chromium based browser items found.
*************************
C:\AdwCleaner\AdwCleaner[R0].txt - [3956 Bytes] - [10/06/2015 15:35:09]
C:\AdwCleaner\AdwCleaner[S0].txt - [3939 Bytes] - [10/06/2015 15:36:37]
C:\AdwCleaner\AdwCleaner[S1].txt - [9447 Bytes] - [14/10/2016 09:36:41]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [9520 Bytes] ##########