======= REPORT FROM AD-REMOVER 2.0.0.2,G | ONLY XP/VISTA/7 ======= Updated by TeamXscript on 12/04/11 Contact: AdRemover[DOT]contact[AT]gmail[DOT]com website: http://www.teamxscript.org C:\Program Files\Ad-Remover\main.exe (SCAN [1]) -> Launched at 13:45:13 on 18/09/2011, Normal boot Microsoft Windows XP Professional Dodatek Service Pack 3 (X86) Asia@SPEED2LITE ( ) ============== SEARCH ============== File found: C:\WINDOWS\system32\f3PSSavr.scr Folder found: C:\Documents and Settings\Asia\Ustawienia lokalne\Dane aplikacji\Conduit Folder found: C:\Documents and Settings\Asia\Ustawienia lokalne\Dane aplikacji\ConduitEngine Folder found: C:\Program Files\ConduitEngine Folder found: C:\Program Files\MyGlobalSearch Folder found: C:\Documents and Settings\Asia\Dane aplikacji\PriceGong File found: C:\Program Files\Internet Explorer\Msimg32.dll Key found: HKLM\Software\Classes\CLSID\{30F9B915-B755-4826-820B-08FBA6BD249D} Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D} Key found: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{30F9B915-B755-4826-820B-08FBA6BD249D} Key found: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{30F9B915-B755-4826-820B-08FBA6BD249D} Key found: HKLM\Software\Classes\TypeLib\{39CAFD20-BAFF-454D-A94C-7115710AE6E3} Key found: HKLM\Software\Classes\BHO.HelperObject Key found: HKLM\Software\Classes\BHO.HelperObject.1 Key found: HKLM\Software\Classes\Conduit.Engine Key found: HKLM\Software\Classes\Toolbar.CT1055551 Key found: HKLM\Software\Classes\Toolbar.CT2504091 Key found: HKLM\Software\Classes\Toolbar.CT2790392 Key found: HKLM\Software\Classes\AppID\BHO.dll Key found: HKLM\Software\Classes\AppID\{59AEAD8A-6822-4794-AF2E-8CC27312E26E} Key found: HKLM\Software\Conduit Key found: HKLM\Software\conduitEngine Key found: HKLM\Software\MyGlobalSearch Key found: HKCU\Software\conduitEngine Key found: HKCU\Software\PriceGong Key found: HKCU\Software\Toolbar Key found: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{1F096B29-E9DA-4D64-8D63-936BE7762CC5} Key found: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} Key found: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} Key found: HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} Key found: HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{66711601-36FD-4D94-A9E2-5FF8D001E93B} Key found: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF1-072E-44CF-8957-5838F569A31D} Key found: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA1-A523-4961-B6BB-170DE4475CCA} Key found: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA9-A523-4961-B6BB-170DE4475CCA} Key found: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EAB-A523-4961-B6BB-170DE4475CCA} Key found: HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45DD-9B68-D6A12C30E5D7} Key found: HKLM\Software\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll Key found: HKLM\Software\Microsoft\Multimedia\WMPlayer\Schemes\f3pss Key found: HKLM\Software\Microsoft\Office\Outlook\Addins\MyWebSearch.OutlookAddin Key found: HKLM\Software\Microsoft\Office\Word\Addins\MyWebSearch.OutlookAddin Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{07B18EAB-A523-4961-B6BB-170DE4475CCA} Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4D7B-9389-0F166788785A} Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{37B85A2B-692B-4205-9CAD-2626E4993404} Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8} Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3E720452-B472-4954-B7AA-33069EB53906} Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C} Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7473d294-b7bb-4f24-ae82-7e2ce94bb6a9} Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98D9753D-D73B-42D5-8C85-4469CDA897AB} Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9FF05104-B030-46FC-94B8-81276E4E27DF} Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E79DFBCA-5697-4FBD-94E5-5B2A9C7C1612} Value found: HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\post platform|FunWebProducts ============== ADDITIONNAL SCAN ============== **** Mozilla Firefox Version [3.6.22 (pl)] **** Plugins\npDivxPlayerPlugin.dll (DivX, Inc) HKLM_MozillaPlugins\@ngm.nexoneu.com/NxGame (x) HKLM_MozillaPlugins\Adobe Reader (x) Searchplugins\allegro-pl.xml (hxxp://www.allegro.pl/search.php?string={searchTerms}&sourceid=Mozilla-search) Searchplugins\fbc-pl.xml (hxxp://fbc.pionier.net.pl/owoc/results) Searchplugins\merlin-pl.xml (hxxp://www.merlin.com.pl/frontend/search?sourceid=Mozilla-search&fraza={searchTerms}&skad=crhhxmkohb) Searchplugins\pwn-pl.xml (hxxp://encyklopedia.pwn.pl/szukaj.php?co={searchTerms}) Searchplugins\wikipedia-pl.xml (hxxp://pl.wikipedia.org/wiki/Specjalna:Szukaj) Searchplugins\wp-pl.xml (hxxp://szukaj.wp.pl/szukaj.html?z=T&r=T&szukaj={searchTerms}) HKLM_Extensions|{23fcfd51-4958-4f00-80a3-ae97e717ed8b} - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 -- C:\Documents and Settings\Asia\Dane aplikacji\Mozilla\FireFox\Profiles\olulnl1z.default -- Extensions\{241aae70-0022-11de-87af-0800200c9a66} (?) Extensions\{aab35b56-0206-4472-9993-9cb5c09bb722} (?) Prefs.js - browser.download.lastDir, C:\\Documents and Settings\\Asia\\Pulpit Prefs.js - browser.startup.homepage, hxxp://www.dziennik.pl/ Prefs.js - browser.startup.homepage_override.mstone, rv:1.9.1.2 Prefs.js - privacy.popups.showBrowserMessage, false Prefs.js - browser.startup.homepage, ======================================== **** Internet Explorer Version [8.0.6001.18702] **** HKCU_Main|Search Page - hxxp://go.microsoft.com/fwlink/?LinkId=54896 HKLM_Main|Default_Page_URL - hxxp://go.microsoft.com/fwlink/?LinkId=69157 HKLM_Main|Default_Search_URL - hxxp://go.microsoft.com/fwlink/?LinkId=54896 HKLM_Main|Search Page - hxxp://go.microsoft.com/fwlink/?LinkId=54896 HKLM_Main|Start Page - hxxp://go.microsoft.com/fwlink/?LinkId=69157 HKCU_SearchScopes\{06CD7211-BCA4-4113-BBB3-CA411E958A74} - "SpeedBit Search" (hxxp://search.speedbit.com/searchresults.asp?src=default&q={searchTerms}) HKCU_SearchScopes\{1F096B29-E9DA-4D64-8D63-936BE7762CC5} - "Search the web (Babylon)" (hxxp://search.babylon.com/?babsrc=SP_ss&q={searchTerms}&mntrId=bc2ad139000000000...) HKCU_SearchScopes\{35065594-9169-4a34-B167-FC4865038E53} - "Easy Gif Animator Toolbar" (hxxp://search.easygifanimator-toolbar.com/search?p=Q&ts=ne&w={searchTerms}&csrc=...) HKCU_SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} - "My Web Search" (hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZNfox000&fl=0&ptb=Irwm30BIEpyG5...) HKCU_SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} - "Best Security Tips Customized Web Search" (hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT...) HKLM_SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} - "My Web Search" (hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZNfox000&fl=0&ptb=Irwm30BIEpyG5...) HKLM_ElevationPolicy\37989cdc-8c2e-4069-93ed-598038015e86 - C:\Program Files\Vuze_Remote\Vuze_RemoteToolbarHelper.exe (x) HKLM_ElevationPolicy\41ab7c43-6626-4eeb-880a-72ecf9036d38 - C:\Program Files\Vuze_Remote\Vuze_RemoteToolbarHelper.exe (x) HKLM_ElevationPolicy\6e56fc51-dda7-4b41-9bd1-0ca574588106 - C:\Program Files\Best_Security_Tips\Best_Security_TipsToolbarHelper.exe (x) HKLM_ElevationPolicy\{5F17E524-3447-4c7d-8E5F-4EFF31CDE3B7} - C:\Program Files\Common Files\DivX Shared\DesktopService\DDMService.exe (DivX, LLC) HKLM_ElevationPolicy\{64903E32-AE0B-408D-909C-09A08791F28D} - C:\Program Files\DivX\DivX Plus Web Player\dwpBroker.exe (?) HKLM_ElevationPolicy\{66711601-36FD-4D94-A9E2-5FF8D001E93B} - C:\Program Files\ConduitEngine\ConduitEngineHelper.exe (?) HKLM_ElevationPolicy\{68AF847F-6E91-45dd-9B68-D6A12C30E5D7} - C:\WINDOWS\system32\f3PSSavr.scr (FunWebProducts.com) HKLM_ElevationPolicy\{76E2369A-75BA-41F9-8B9E-16059E5CF9A6} - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (MadrasAddison Orestes FrenchSophia AmmanBeijing) HKLM_ElevationPolicy\{D802E3EF-2513-4661-972E-BAD737EFBA88} - C:\Program Files\DivX\DivX OVS Helper\OVSHelperBroker.exe (DivX, LLC.) HKLM_Extensions\{e2e2dd38-d088-4134-82b7-f2ba38496583} - "?" (?) BHO\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - "Adobe PDF Reader Link Helper" (C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll) BHO\{30F9B915-B755-4826-820B-08FBA6BD249D} - "Conduit Engine " (C:\Program Files\ConduitEngine\prxConduitEngine.dll) BHO\{326E768D-4182-46FD-9C16-1449A49795F4} - "DivX Plus Web Player HTML5