======= REPORT FROM AD-REMOVER 2.0.0.2,G | ONLY XP/VISTA/7 ======= Updated by TeamXscript on 12/04/11 Contact: AdRemover[DOT]contact[AT]gmail[DOT]com website: http://www.teamxscript.org C:\Program Files\Ad-Remover\main.exe (CLEAN [1]) -> Launched at 15:07:26 on 31/08/2011, Normal boot Microsoft Windows 7 Ultimate Service Pack 1 (X86) mama@MAMA-PC ( ) ============== ACTION(S) ============== File deleted: C:\Users\macirk\AppData\Roaming\Readar_sl.exe Folder deleted: C:\Users\mama\AppData\Local\Conduit Folder deleted: C:\Users\mama\AppData\LocalLow\Conduit (!) -- Temporary files deleted. -- File opened: C:\Users\macirk\AppData\Roaming\Mozilla\FireFox\Profiles\zse0afx0.default\Prefs.js -- Line deleted: user_pref("browser.search.selectedEngine", "qooqlle"); Line deleted: user_pref("browser.startup.homepage", "hxxp://www.qooqlle.com/"); -- File closed -- Key deleted: HKLM\Software\Classes\Toolbar.CT2612669 Key deleted: HKLM\Software\Conduit Key deleted: HKCU\Software\AppDataLow\Software\Toolbar Key deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{42168F92-DA71-42E6-BC7F-132EAC1F1899} Key deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Key deleted: HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} ============== ADDITIONNAL SCAN ============== **** Mozilla Firefox Version [5.0.1 (pl)] **** HKLM_MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf (x) Searchplugins\allegro-pl.xml (hxxp://www.allegro.pl/search.php?string={searchTerms}&sourceid=Mozilla-search) Searchplugins\fbc-pl.xml (hxxp://fbc.pionier.net.pl/owoc/results) Searchplugins\merlin-pl.xml (hxxp://www.merlin.com.pl/frontend/search?sourceid=Mozilla-search&fraza={searchTerms}&skad=crhhxmkohb) Searchplugins\pwn-pl.xml (hxxp://encyklopedia.pwn.pl/szukaj.php?co={searchTerms}) Searchplugins\wikipedia-pl.xml (hxxp://pl.wikipedia.org/wiki/Specjalna:Szukaj) Searchplugins\wp-pl.xml (hxxp://szukaj.wp.pl/szukaj.html?z=T&r=T&szukaj={searchTerms}) Components\browsercomps.dll (Mozilla Foundation) HKLM_Extensions|smartwebprinting@hp.com - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 HKCU_Extensions|smartwebprinting@hp.com - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 -- C:\Users\mama\AppData\Roaming\Mozilla\FireFox\Profiles\22fl6dgw.default -- Prefs.js - browser.search.selectedEngine, Prefs.js - browser.startup.homepage, Prefs.js - browser.startup.homepage_override.mstone, false -- C:\Users\macirk\AppData\Roaming\Mozilla\FireFox\Profiles\zse0afx0.default -- Searchplugins\search.xml (?) Prefs.js - browser.startup.homepage_override.mstone, false ======================================== **** Google Chrome Version [13.0.782.218] **** Extension\icmlaeflemplmjndnaapfdbbnpncnbda (C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx) (?) -- C:\Users\mama\AppData\Local\Google\Chrome\User Data\Default -- Preferences - default_search_provider: "qooqlle" (Enabled: ) (hxxp://www.google.com/cse?cx=partner-pub-5462406484424654%3A8q0sn8-w2ss&ie=ISO-8859-1&q={searchTerms}&sa=Search&siteurl=qooqlle.com%2F) Preferences - homepage: hxxp://www.qooqlle.com/ Preferences - homepage_is_newtabpage: false ======================================== **** Internet Explorer Version [9.0.8112.16421] **** HKCU_Main|Default_Page_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome HKCU_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU_Main|Search bar - hxxp://go.microsoft.com/fwlink/?linkid=54896 HKCU_Main|Start Page - hxxp://fr.msn.com/ HKLM_Main|Default_Page_URL - hxxp://go.microsoft.com/fwlink/?LinkId=54896 HKLM_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM_Main|Search bar - hxxp://search.msn.com/spbasic.htm HKLM_Main|Search Page - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM_Main|Start Page - hxxp://fr.msn.com/ HKCU_URLSearchHooks|{90b49673-5506-483e-b92b-ca0265bd9ca8} (x) HKCU_Toolbar\WebBrowser|{90B49673-5506-483E-B92B-CA0265BD9CA8} (x) HKLM_Toolbar|{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} (C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll) HKLM_ElevationPolicy\{07d873dc-b9b9-44f5-af0b-fb59fa54fb7a} - C:\Windows\System32\wpcer.exe (x) HKLM_ElevationPolicy\{0a402d70-1f10-4ae7-bec9-286a98240695} - C:\Windows\System32\winfxdocobj.exe (x) HKLM_ElevationPolicy\{70f641fd-9ffc-4d5b-a4dc-962af4ed7999} - C:\Program Files\Internet Explorer\iedw.exe (x) BHO\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - "avast! WebRep" (C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll) ======================================== C:\Program Files\Ad-Remover\Quarantine: 22 File(s) C:\Program Files\Ad-Remover\Backup: 15 File(s) C:\Ad-Report-CLEAN[1].txt - 31/08/2011 15:07:30 (4976 Byte(s)) C:\Ad-Report-SCAN[1].txt - 30/08/2011 17:45:00 (5268 Byte(s)) End at: 15:08:45, 31/08/2011 ============== E.O.F ==============