======= REPORT FROM AD-REMOVER 2.0.0.2,G | ONLY XP/VISTA/7 ======= Updated by TeamXscript on 12/04/11 Contact: AdRemover[DOT]contact[AT]gmail[DOT]com website: http://www.teamxscript.org C:\Program Files\Ad-Remover\main.exe (SCAN [3]) -> Launched at 20:38:38 on 01/08/2011, Normal boot Microsoft Windows 7 Ultimate Service Pack 1 (X86) Admin@ADMIN-PC (ACTION ACT SIERRA) ============== SEARCH ============== Folder found: C:\Users\Admin\AppData\LocalLow\Conduit Folder found: C:\Program Files\Conduit Key found: HKLM\Software\Classes\Toolbar.CT1750559 Key found: HKLM\Software\Conduit Key found: HKCU\Software\Conduit Key found: HKCU\Software\AppDataLow\Software\Conduit Key found: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{42168F92-DA71-42E6-BC7F-132EAC1F1899} Key found: HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} Key found: HKLM\Software\Microsoft\Internet Explorer\Extensions\{3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} ============== ADDITIONNAL SCAN ============== **** Mozilla Firefox Version [5.0 (pl)] **** HKLM_MozillaPlugins\@nvidia.com/3DVision (x) HKLM_MozillaPlugins\@nvidia.com/3DVisionStreaming (x) HKLM_MozillaPlugins\Adobe Reader (x) HKCU_MozillaPlugins\@octoshape.com/Octoshape Streaming Services,version=1.0 (x) Searchplugins\allegro-pl.xml (hxxp://www.allegro.pl/search.php?string={searchTerms}&sourceid=Mozilla-search) Searchplugins\fbc-pl.xml (hxxp://fbc.pionier.net.pl/owoc/results) Searchplugins\merlin-pl.xml (hxxp://www.merlin.com.pl/frontend/search?sourceid=Mozilla-search&fraza={searchTerms}&skad=crhhxmkohb) Searchplugins\pwn-pl.xml (hxxp://encyklopedia.pwn.pl/szukaj.php?co={searchTerms}) Searchplugins\wikipedia-pl.xml (hxxp://pl.wikipedia.org/wiki/Specjalna:Szukaj) Searchplugins\wp-pl.xml (hxxp://szukaj.wp.pl/szukaj.html?z=T&r=T&szukaj={searchTerms}) Components\browsercomps.dll (Mozilla Foundation) Extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1} (Skype extension for Firefox ) -- C:\Users\Admin\AppData\Roaming\Mozilla\FireFox\Profiles\rwahbrm1.default -- Prefs.js - browser.search.selectedEngine, Prefs.js - browser.startup.homepage_override.mstone, false ======================================== **** Google Chrome Version [12.0.742.122] **** Extension - jfmjfhklogoienhpfnppmbcbjfjnkonk (x) -- C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default -- Preferences - default_search_provider: "Google" (Enabled: true) (hxxp://www.google.com/cse?cx=partner-pub-5462406484424654%3A8q0sn8-w2ss&ie=ISO-8859-1&q={searchTerms}&sa=Search&siteurl=qooqlle.com%2F) Preferences - homepage: hxxp://www.google.com/ Preferences - homepage_is_newtabpage: false Plugin - Chrome NaCl (Enabled: false) (C:\Users\Admin\AppData\Local\Google\Chrome\Application\12.0.742.122\ppGoogleNaClPluginChrome.dll) Plugin - Octoshape Streaming Services (Enabled: true) (C:\Users\Admin\AppData\Roaming\Mozilla\plugins\npoctoshape.dll) Plugin - Octoshape Streaming Services (Enabled: true) (C:\Users\Admin\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-1010120-0-npoctoshape.dll) Plugin - NVIDIA 3D Vision (Enabled: true) (C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll) Plugin - NVIDIA 3D VISION (Enabled: true) (C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll) Plugin - "Java" (Enabled: true) Plugin - "Silverlight" (Enabled: true) Plugin - "Chrome NaCl" (Enabled: false) Plugin - "Octoshape Streaming Services" (Enabled: true) Plugin - "NVIDIA 3D Vision" (Enabled: true) Plugin - "NVIDIA 3D VISION" (Enabled: true) ======================================== **** Internet Explorer Version [8.0.7601.17514] **** HKCU_Main|Search Page - hxxp://go.microsoft.com/fwlink/?LinkId=54896 HKLM_Main|Default_Page_URL - hxxp://go.microsoft.com/fwlink/?LinkId=69157 HKLM_Main|Default_Search_URL - hxxp://go.microsoft.com/fwlink/?LinkId=54896 HKLM_Main|Search Page - hxxp://go.microsoft.com/fwlink/?LinkId=54896 HKLM_Main|Start Page - hxxp://go.microsoft.com/fwlink/?LinkId=69157 HKLM_SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} - "BS Player Customized Web Search" (hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT...) HKCU_Toolbar\WebBrowser|{32099AAC-C132-4136-9E9A-4E364A424E17} (x) HKLM_ElevationPolicy\97b92c98-21fa-4371-b59b-f5fd45a00528 - C:\Program Files\BS_Player\BS_PlayerToolbarHelper.exe (x) HKLM_ElevationPolicy\{07d873dc-b9b9-44f5-af0b-fb59fa54fb7a} - C:\Windows\System32\wpcer.exe (x) HKLM_ElevationPolicy\{0a402d70-1f10-4ae7-bec9-286a98240695} - C:\Windows\System32\winfxdocobj.exe (x) HKLM_ElevationPolicy\{70f641fd-9ffc-4d5b-a4dc-962af4ed7999} - C:\Program Files\Internet Explorer\iedw.exe (x) HKLM_Extensions\{3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - "PokerStars" (D:\Program Files\PokerStars\main.ico) BHO\{DF925EF3-7A87-44E4-9CAF-8D7B280BF616} - "IplexToALLPlayer" (C:\PROGRA~1\ALLPLA~1\Iplex\IplexToALLPlayer.dll) ======================================== C:\Program Files\Ad-Remover\Quarantine: 0 File(s) C:\Program Files\Ad-Remover\Backup: 3 File(s) C:\Ad-Report-SCAN[1].txt - 01/08/2011 20:33:25 (5291 Byte(s)) C:\Ad-Report-SCAN[2].txt - 01/08/2011 20:34:56 (5355 Byte(s)) C:\Ad-Report-SCAN[3].txt - 01/08/2011 20:38:41 (5281 Byte(s)) End at: 20:39:39, 01/08/2011 ============== E.O.F ==============