i have deleted the files in adwcleaner
this time the log file is
Code:
# AdwCleaner v3.023 - Report created 17/04/2014 at 19:49:06
# Updated 01/04/2014 by Xplode
# Operating System : Windows 7 Ultimate Service Pack 1 (32 bits)
# Username : Ahmad-A - AHMAD-PC
# Running from : C:\Users\Ahmad-A\Downloads\Programs\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
[#] Service Deleted : Update maucampo
[#] Service Deleted : Util maucampo
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\Babylon
Folder Deleted : C:\ProgramData\Tarma Installer
Folder Deleted : C:\Program Files\DAEMON Tools Toolbar
Folder Deleted : C:\Program Files\PutLockerDownloader
Folder Deleted : C:\Users\Ahmad-A\AppData\Local\genienext
Folder Deleted : C:\Users\Ahmad-A\AppData\Local\Mobogenie
Folder Deleted : C:\Users\Ahmad-A\AppData\Local\torch
Folder Deleted : C:\Users\Ahmad-A\AppData\LocalLow\Delta
Folder Deleted : C:\Users\Ahmad-A\AppData\Roaming\Babylon
Folder Deleted : C:\Users\Ahmad-A\AppData\Roaming\file scout
Folder Deleted : C:\Users\Ahmad-A\AppData\Roaming\newnext.me
Folder Deleted : C:\Users\Ahmad-A\AppData\Roaming\SimilarSites
Folder Deleted : C:\Users\Ahmad-A\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard
Folder Deleted : C:\Users\Ahmad-A\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PutLockerDownloader.com
Folder Deleted : C:\Users\Ahmad-A\AppData\Roaming\Mozilla\Firefox\Profiles\azdbg6xp.default-1374291711912\Extensions\WebSiteRecommendation@weliketheweb.com
File Deleted : C:\Users\Ahmad-A\AppData\Roaming\Mozilla\Firefox\Profiles\azdbg6xp.default-1374291711912\bprotector_extensions.sqlite
File Deleted : C:\Users\Ahmad-A\AppData\Roaming\Mozilla\Firefox\Profiles\azdbg6xp.default-1374291711912\bprotector_prefs.js
File Deleted : C:\Users\Ahmad-A\AppData\Roaming\Mozilla\Firefox\Profiles\azdbg6xp.default-1374291711912\invalidprefs.js
File Deleted : C:\Users\Ahmad-A\AppData\Roaming\Mozilla\Firefox\Profiles\13tk2e44.default\user.js
File Deleted : C:\Users\Ahmad-A\AppData\Roaming\Mozilla\Firefox\Profiles\azdbg6xp.default-1374291711912\user.js
File Deleted : C:\Users\Ahmad-A\AppData\Local\Google\Chrome\User Data\Default\bProtector Web Data
File Deleted : C:\Users\Ahmad-A\AppData\Local\Google\Chrome\User Data\Default\bprotectorpreferences
***** [ Shortcuts ] *****
***** [ Registry ] *****
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A33EAC2A-F603-49FE-8662-E4F2B3AD1A4A}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [bprotector start page]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope]
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings
Key Deleted : HKLM\SOFTWARE\Classes\*\shell\filescout
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Classes\PutLockerDownloader
Key Deleted : HKLM\SOFTWARE\Classes\S
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Key Deleted : HKCU\Software\5968adbbc69e844
Key Deleted : HKLM\SOFTWARE\5968adbbc69e844
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5D7D4FB9-ACA5-4013-8879-C58DCD4DF9F1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E49F0B41-3322-11D4-AEFE-00C04F61025C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{DCABB943-792E-44C4-9029-ECBEE6265AF9}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5D7D4FB9-ACA5-4013-8879-C58DCD4DF9F1}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5D7D4FB9-ACA5-4013-8879-C58DCD4DF9F1}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2A5A2A90-3B30-4E6E-A955-2F232C6EF517}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{5D7D4FB9-ACA5-4013-8879-C58DCD4DF9F1}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4B71-B0A3-3D82E62A6909}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4FC7-90CC-5EA0ABBE9EB8}
Key Deleted : HKCU\Software\1ClickDownload
Key Deleted : HKCU\Software\BabSolution
Key Deleted : HKCU\Software\DataMngr
[#] Key Deleted : HKCU\Software\DataMngr_Toolbar
Key Deleted : HKCU\Software\dt soft\daemon tools toolbar
Key Deleted : HKCU\Software\filescout
Key Deleted : HKCU\Software\maucampo
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKLM\Software\DataMngr
Key Deleted : HKLM\Software\Description
Key Deleted : HKLM\Software\maucampo
Key Deleted : HKLM\Software\Tarma Installer
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.16521
-\\ Mozilla Firefox v28.0 (en-US)
[ File : C:\Users\Ahmad-A\AppData\Roaming\Mozilla\Firefox\Profiles\13tk2e44.default\prefs.js ]
Line Deleted : user_pref("browser.newtab.url", "hxxp://www1.delta-search.com/?babsrc=NT_ss&mntrId=20D2E4D53DF20BB1&affID=119776&tsp=4949");
Line Deleted : user_pref("browser.search.order.1", "Delta Search");
Line Deleted : user_pref("extensions.delta.admin", false);
Line Deleted : user_pref("extensions.delta.aflt", "babsst");
Line Deleted : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
Line Deleted : user_pref("extensions.delta.autoRvrt", "false");
Line Deleted : user_pref("extensions.delta.dfltLng", "en");
Line Deleted : user_pref("extensions.delta.excTlbr", false);
Line Deleted : user_pref("extensions.delta.ffxUnstlRst", true);
Line Deleted : user_pref("extensions.delta.id", "20d28e45000000000000e4d53df20bb1");
Line Deleted : user_pref("extensions.delta.instlDay", "15906");
Line Deleted : user_pref("extensions.delta.instlRef", "sst");
Line Deleted : user_pref("extensions.delta.newTab", false);
Line Deleted : user_pref("extensions.delta.prdct", "delta");
Line Deleted : user_pref("extensions.delta.prtnrId", "delta");
Line Deleted : user_pref("extensions.delta.rvrt", "false");
Line Deleted : user_pref("extensions.delta.smplGrp", "none");
Line Deleted : user_pref("extensions.delta.tlbrId", "base");
Line Deleted : user_pref("extensions.delta.tlbrSrchUrl", "");
Line Deleted : user_pref("extensions.delta.vrsn", "1.8.21.5");
Line Deleted : user_pref("extensions.delta.vrsni", "1.8.21.5");
Line Deleted : user_pref("extensions.delta.vrsnTs", "1.8.21.58:35:19");
Line Deleted : user_pref("extensions.delta_i.babExt", "");
Line Deleted : user_pref("extensions.delta_i.babTrack", "affID=119776&tsp=4949");
Line Deleted : user_pref("extensions.delta_i.srcExt", "ss");
[ File : C:\Users\Ahmad-A\AppData\Roaming\Mozilla\Firefox\Profiles\azdbg6xp.default-1374291711912\prefs.js ]
Line Deleted : user_pref("extensions._aNxKBB.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"txtlnkusaolp00000800\")>-1||url.match(/ressba[...]
-\\ Google Chrome v34.0.1847.116
[ File : C:\Users\Ahmad-A\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [7815 octets] - [17/04/2014 16:11:00]
AdwCleaner[R1].txt - [7875 octets] - [17/04/2014 19:47:39]
AdwCleaner[S0].txt - [7946 octets] - [17/04/2014 19:49:06]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [8006 octets] ##########
i have also used junk remover tool and rogue killer.
the log file of jrt is
Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Ultimate x86
Ran by Ahmad-A on Thu 04/17/2014 at 20:55:52.19
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-4208122127-1762691292-62734005-1000\Software\Microsoft\Internet Explorer\Main\\Start Page
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-4208122127-1762691292-62734005-1000\Software\sweetim
~~~ Files
~~~ Folders
~~~ FireFox
Successfully deleted: [Folder] C:\Users\Ahmad-A\AppData\Roaming\mozilla\firefox\profiles\azdbg6xp.default-1374291711912\extensions\staged
Emptied folder: C:\Users\Ahmad-A\AppData\Roaming\mozilla\firefox\profiles\azdbg6xp.default-1374291711912\minidumps [191 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Thu 04/17/2014 at 20:58:43.63
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Thanks for help.