======= REPORT FROM AD-REMOVER 2.0.0.2,G | ONLY XP/VISTA/7 ======= Updated by TeamXscript on 12/04/11 Contact: AdRemover[DOT]contact[AT]gmail[DOT]com website: http://www.teamxscript.org H:\Program Files\Ad-Remover\main.exe (SCAN [1]) -> Launched at 13:11:37 on 12/08/2011, Normal boot Microsoft Windows XP Home Edition Dodatek Service Pack 3 (X86) user@Q-415FDE6457B64 ( ) ============== SEARCH ============== Folder found: H:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Conduit Folder found: H:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\ConduitEngine Folder found: H:\Program Files\ConduitEngine Key found: HKLM\Software\Classes\CLSID\{0974BA1E-64EC-11DE-B2A5-E43756D89593} Key found: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0974BA1E-64EC-11DE-B2A5-E43756D89593} Key found: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0974BA1E-64EC-11DE-B2A5-E43756D89593} Key found: HKLM\Software\Classes\CLSID\{27549B12-7597-435B-B353-B8F5BE30C565} Key found: HKLM\Software\Classes\CLSID\{27F69C85-64E1-43CE-98B5-3C9F22FB408E} Key found: HKLM\Software\Classes\AppID\{1301A8A5-3DFB-4731-A162-B357D00C9644} Key found: HKLM\Software\Classes\CLSID\{30F9B915-B755-4826-820B-08FBA6BD249D} Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D} Key found: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{30F9B915-B755-4826-820B-08FBA6BD249D} Key found: HKLM\Software\Classes\CLSID\{7FF99715-3016-4381-84CE-E4E4C9673020} Key found: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7FF99715-3016-4381-84CE-E4E4C9673020} Key found: HKLM\Software\Classes\CLSID\{8A27C370-9E3E-4CB0-A789-07600C282884} Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8A27C370-9E3E-4CB0-A789-07600C282884} Key found: HKLM\Software\Classes\CLSID\{B543EF05-9758-464E-9F37-4C28525B4A4C} Key found: HKLM\Software\Classes\CLSID\{BB76A90B-2B4C-4378-8506-9A2B6E16943C} Key found: HKLM\Software\Classes\CLSID\{C3AB94A4-BFD0-4BBA-A331-DE504F07D2DB} Key found: HKLM\Software\Classes\Interface\{477F210A-2A86-4666-9C4B-1189634D2C84} Key found: HKLM\Software\Classes\CLSID\{F42C7B47-5234-4BF5-8882-DAAC0D64870E} Key found: HKLM\Software\Classes\Interface\{F42C7B47-5234-4BF5-8882-DAAC0D64870E} Key found: HKLM\Software\Classes\Interface\{F7BEBBB1-7E6B-4561-9444-6F4866D60C7D} Key found: HKLM\Software\Classes\Interface\{FF871E51-2655-4D06-AED5-745962A96B32} Key found: HKLM\Software\Classes\TypeLib\{8F5F1CB6-EA9E-40AF-A5CA-C7FD63CC1971} Key found: HKLM\Software\Classes\BandooCore.BandooCore Key found: HKLM\Software\Classes\BandooCore.BandooCore.1 Key found: HKLM\Software\Classes\BandooCore.ResourcesMngr Key found: HKLM\Software\Classes\BandooCore.ResourcesMngr.1 Key found: HKLM\Software\Classes\BandooCore.SettingsMngr Key found: HKLM\Software\Classes\BandooCore.SettingsMngr.1 Key found: HKLM\Software\Classes\BandooCore.StatisticMngr Key found: HKLM\Software\Classes\BandooCore.StatisticMngr.1 Key found: HKLM\Software\Classes\Conduit.Engine Key found: HKLM\Software\Classes\DiscoveryHelper.iMesh6Discovery Key found: HKLM\Software\Classes\DiscoveryHelper.iMesh6Discovery.1 Key found: HKLM\Software\Classes\Toolbar.CT1708250 Key found: HKLM\Software\Classes\Toolbar.CT2786678 Key found: HKLM\Software\Classes\AppID\BandooCore.EXE Key found: HKLM\Software\bandoo Key found: HKLM\Software\Conduit Key found: HKLM\Software\conduitEngine Key found: HKCU\Software\Conduit Key found: HKCU\Software\conduitEngine Key found: HKCU\Software\SearchquMediabarTb Key found: HKCU\Software\Zugo Key found: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Bandoo Key found: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{043C5167-00BB-4324-AF7E-62013FAEDACF} Key found: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{42168F92-DA71-42E6-BC7F-132EAC1F1899} Key found: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} Key found: HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{424624F4-C5DD-4e1d-BDD0-1E9C9B7799CC} Key found: HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7f000001-db8e-f89c-2fec-49bf726f8c12} Key found: HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8A62CB42-055E-45EF-AA7E-8BF6F3AB6E65} Key found: HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9C8A3CA5-889E-4554-BEEC-EC0876E4E96A} Key found: HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F9189560-573A-4fde-B055-AE7B0F4CF080} Value found: HKLM\Software\Microsoft\Internet Explorer\Toolbar|{30F9B915-B755-4826-820B-08FBA6BD249D} Value found: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser|{30F9B915-B755-4826-820B-08FBA6BD249D} ============== ADDITIONNAL SCAN ============== **** Mozilla Firefox Version [5.0.1 (pl)] **** HKLM_MozillaPlugins\Adobe Reader (x) Searchplugins\allegro-pl.xml (hxxp://www.allegro.pl/search.php?string={searchTerms}&sourceid=Mozilla-search) Searchplugins\fbc-pl.xml (hxxp://fbc.pionier.net.pl/owoc/results) Searchplugins\merlin-pl.xml (hxxp://www.merlin.com.pl/frontend/search?sourceid=Mozilla-search&fraza={searchTerms}&skad=crhhxmkohb) Searchplugins\pwn-pl.xml (hxxp://encyklopedia.pwn.pl/szukaj.php?co={searchTerms}) Searchplugins\wikipedia-pl.xml (hxxp://pl.wikipedia.org/wiki/Specjalna:Szukaj) Searchplugins\wp-pl.xml (hxxp://szukaj.wp.pl/szukaj.html?z=T&r=T&szukaj={searchTerms}) Components\browsercomps.dll (Mozilla Foundation) -- H:\Documents and Settings\user\Dane aplikacji\Mozilla\FireFox\Profiles\pam208xz.default -- Extensions\ChoiceGuard@Microsoft (Microsoft Choice Guard) Extensions\pl@dictionaries.addons.mozilla.org (Polski slownik poprawnej pisowni) Extensions\staged (?) Prefs.js - browser.search.selectedEngine, Prefs.js - browser.startup.homepage_override.mstone, false ======================================== **** Internet Explorer Version [6.0.2900.5512] **** HKLM_Main|Default_Page_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome HKLM_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM_Main|Search Page - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU_URLSearchHooks|{0063BF63-BFFF-4B8F-9D26-4267DF7F17DD} - "DeviceVM Url Search Hook" (H:\WINDOWS\system32\dvmurl.dll) HKCU_SearchScopes\{043C5167-00BB-4324-AF7E-62013FAEDACF} - "Web Search..." (hxxp://vshare.toolbarhome.com/search.aspx?q={searchTerms}&srch=dsp) HKCU_SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e} - "Search" (hxxp://www.bigseekpro.com/search/browser/layoutsexpress/{E6A04B1C-D6CF-46B3-AA6C...) HKCU_SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} - " " (hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT...) HKCU_Toolbar\WebBrowser|{30F9B915-B755-4826-820B-08FBA6BD249D} (H:\Program Files\ConduitEngine\prxConduitEngine.dll) HKLM_Toolbar|{30F9B915-B755-4826-820B-08FBA6BD249D} (H:\Program Files\ConduitEngine\prxConduitEngine.dll) HKLM_ElevationPolicy\41feb28f-ebcf-4922-b58d-dffcccac74fc - H:\Program Files\Free_Lunch_Design\Free_Lunch_DesignToolbarHelper.exe (x) HKLM_ElevationPolicy\a5cab7a5-2849-4387-bbc9-0dce1ae88d6c - H:\Program Files\Free_Lunch_Design\Free_Lunch_DesignToolbarHelper.exe (x) HKLM_ElevationPolicy\d992aefb-7fe2-4277-b94e-41b110af4c50 - H:\Program Files\Free_Lunch_Design\Free_Lunch_DesignToolbarHelper.exe (x) HKLM_ElevationPolicy\{424624F4-C5DD-4e1d-BDD0-1E9C9B7799CC} - H:\Program Files\Bandoo\BndCore.exe (x) HKLM_ElevationPolicy\{438214DB-BB3C-4813-89F3-B3757D52B28E} - H:\Program Files\BearShare Applications\BearShare\BearShare.exe (MusicLab, LLC) HKLM_ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291} - H:\Program Files\LayoutsExpress Toolbar\TbHelper2.exe (x) HKLM_ElevationPolicy\{7f000001-db8e-f89c-2fec-49bf726f8c12} - H:\Program Files\Bandoo\ExtensionsManager.exe (x) HKLM_ElevationPolicy\{887A57CE-0492-4A28-86BB-0BDED2CD0F4A} - H:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Conduit\CT1708250\Free_Lunch_DesignAutoUpdaterHelper.exe (?) HKLM_ElevationPolicy\{8A62CB42-055E-45EF-AA7E-8BF6F3AB6E65} - H:\Program Files\ConduitEngine\ConduitEngineHelper.exe (?) HKLM_ElevationPolicy\{9C8A3CA5-889E-4554-BEEC-EC0876E4E96A} - H:\Program Files\Bandoo\Bandoo.exe (x) HKLM_ElevationPolicy\{ECD44919-CD7F-4303-B07F-EC1EBB40F608} - H:\Program Files\Free_Lunch_Design\Free_Lunch_DesignToolbarHelper.exe (x) HKLM_ElevationPolicy\{F9189560-573A-4fde-B055-AE7B0F4CF080} - H:\Program Files\Bandoo\BandooUI.exe (x) HKLM_Extensions\{40525A66-DB98-480D-BCF9-7AF88C1AF438} - "ArcaVir >>" (H:\Program Files\ArcaBit\WebExtensions\ie\ArcaIEExt.dll,203) HKLM_Extensions\{e2e2dd38-d088-4134-82b7-f2ba38496583} - "?" (?) BHO\{30F9B915-B755-4826-820B-08FBA6BD249D} - "Conduit Engine " (H:\Program Files\ConduitEngine\prxConduitEngine.dll) BHO\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - "Search Helper" (h:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll) ======================================== H:\Program Files\Ad-Remover\Quarantine: 0 File(s) H:\Program Files\Ad-Remover\Backup: 0 File(s) H:\Ad-Report-SCAN[1].txt - 12/08/2011 13:11:43 (8132 Byte(s)) End at: 13:12:05, 12/08/2011 ============== E.O.F ==============