======= REPORT FROM AD-REMOVER 2.0.0.2,G | ONLY XP/VISTA/7 ======= Updated by TeamXscript on 12/04/11 Contact: AdRemover[DOT]contact[AT]gmail[DOT]com website: http://www.teamxscript.org C:\Program Files (x86)\Ad-Remover\main.exe (SCAN [1]) -> Launched at 12:15:16 on 04/09/2011, Normal boot Microsoft Windows 7 Ultimate (X64) Marcin@MARCIN-KOMPUTER (System manufacturer System Product Name) ============== SEARCH ============== Folder found: C:\Users\Marcin\AppData\LocalLow\Conduit Folder found: C:\Program Files (x86)\AutocompletePro Folder found: C:\Users\Marcin\AppData\Local\OpenCandy Folder found: C:\ProgramData\PopCap Games Folder found: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PopCap Games Folder found: C:\Program Files (x86)\PopCap Games Folder found: C:\Users\Marcin\AppData\LocalLow\PriceGong Folder found: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RelevantKnowledge Folder found: C:\Program Files (x86)\RelevantKnowledge Folder found: C:\ProgramData\Trymedia Key found: HKLM\Software\Classes\Conduit.Engine Key found: HKLM\Software\Classes\Toolbar.CT2504091 Key found: HKLM\Software\Classes\Toolbar.CT2786678 Key found: HKLM\Software\Conduit Key found: HKLM\Software\PopCap Key found: HKCU\Software\AutocompleteProBHO Key found: HKCU\Software\Conduit Key found: HKCU\Software\PopCap Key found: HKCU\Software\AppDataLow\Software\PriceGong Key found: HKCU\Software\AppDataLow\Software\Toolbar Key found: HKLM\Software\eRightSoft\OpenCandy Key found: HKLM\Software\Wow6432Node\eRightSoft\OpenCandy Key found: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{42168F92-DA71-42E6-BC7F-132EAC1F1899} Key found: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} Key found: HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{D08D9F98-1C78-4704-87E6-368B0023D831} Value found: HKLM\Software\Mozilla\Firefox\Extensions|{6E19037A-12E3-4295-8915-ED48BC341614} Value found: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser|{30F9B915-B755-4826-820B-08FBA6BD249D} ============== ADDITIONNAL SCAN ============== **** Internet Explorer Version [8.0.7600.16385] **** HKCU_Main|Start Page - hxxp://search.conduit.com?SearchSource=10&ctid=CT2504091 HKLM_Main|Default_Page_URL - hxxp://go.microsoft.com/fwlink/?LinkId=69157 HKLM_Main|Default_Search_URL - hxxp://go.microsoft.com/fwlink/?LinkId=54896 HKLM_Main|Search Page - hxxp://go.microsoft.com/fwlink/?LinkId=54896 HKCU_URLSearchHooks|{ba14329e-9550-4989-b3f2-9732e92d17cc} (x) HKCU_SearchScopes\{4994317B-A5CA-4E48-AB03-3215B4B95643} - "AVG Secure Search" (hxxp://search.avg.com/route/?d=4d0a661e&v=6.10.6.4&i=26&tp=chrome&q={searchTerms...) HKCU_SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} - "Web Search" (hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT...) HKLM_SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} - "Web Search" (hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT...) HKCU_Toolbar\WebBrowser|{32099AAC-C132-4136-9E9A-4E364A424E17} (x) HKCU_Toolbar\WebBrowser|{30F9B915-B755-4826-820B-08FBA6BD249D} (x) HKCU_Toolbar\WebBrowser|{BA14329E-9550-4989-B3F2-9732E92D17CC} (x) HKLM_Toolbar|{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} (C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll) HKCU_ElevationPolicy\{E0A900DF-9611-4446-86BD-4B1D47E7DB2A} - C:\Users\Marcin\AppData\Local\Google\Chrome\Application\13.0.782.220\chrome_launcher.exe (x) HKLM_ElevationPolicy\{07d873dc-b9b9-44f5-af0b-fb59fa54fb7a} - C:\Windows\SysWOW64\wpcer.exe (x) HKLM_ElevationPolicy\{0a402d70-1f10-4ae7-bec9-286a98240695} - C:\Windows\SysWOW64\winfxdocobj.exe (x) HKLM_ElevationPolicy\{70f641fd-9ffc-4d5b-a4dc-962af4ed7999} - C:\Program Files (x86)\Internet Explorer\iedw.exe (x) HKLM_ElevationPolicy\{7BD9A644-9DC6-42be-8872-CBF5524276BD} - C:\Program Files (x86)\Common Files\Software Update Utility\dnu.exe (AOL LLC) HKLM_ElevationPolicy\{B43A0C1E-B63F-4691-B68F-CD807A45DA01} - C:\Windows\system32\TSWbPrxy.exe (x) BHO\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - "avast! WebRep" (C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll) BHO\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - "Skype Browser Helper" (C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll) BHO\{DF925EF3-7A87-44E4-9CAF-8D7B280BF616} - "IplexToALLPlayer" (C:\PROGRA~2\ALLPLA~1\Iplex\IPLEXT~1.DLL) BHO\{F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - "IEPluginBHO Class" (C:\Users\Marcin\AppData\Roaming\Nowe Gadu-Gadu\_userdata\ggbho.1.dll) (x) ======================================== C:\Program Files (x86)\Ad-Remover\Quarantine: 0 File(s) C:\Program Files (x86)\Ad-Remover\Backup: 0 File(s) C:\Ad-Report-SCAN[1].txt - 04/09/2011 12:16:49 (4875 Byte(s)) End at: 12:17:47, 04/09/2011 ============== E.O.F ==============