======= REPORT FROM AD-REMOVER 2.0.0.2,G | ONLY XP/VISTA/7 ======= Updated by TeamXscript on 12/04/11 Contact: AdRemover[DOT]contact[AT]gmail[DOT]com website: http://www.teamxscript.org C:\Program Files\Ad-Remover\main.exe (CLEAN [1]) -> Launched at 18:42:45 on 13/02/2012, Normal boot Microsoft Windows 7 Home Premium Service Pack 1 (X86) Piotrek@PT88IAT89 (SAMSUNG ELECTRONICS CO., LTD. R530/R730) ============== ACTION(S) ============== Folder deleted: C:\Users\Piotrek\Documents\Imesh Folder deleted: C:\Users\Piotrek\Music\Imesh Folder deleted: C:\Users\Piotrek\AppData\LocalLow\Conduit Folder deleted: C:\Program Files\Conduit Folder deleted: C:\Users\Piotrek\AppData\LocalLow\ConduitEngine Folder deleted: C:\Program Files\ConduitEngine Folder deleted: C:\Users\Piotrek\AppData\Local\iMesh (!) -- Temporary files deleted. Key deleted: HKLM\Software\Classes\CLSID\{EA74C8FC-4D9D-4C8C-B751-09D28C06C7F9} Key deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EA74C8FC-4D9D-4C8C-B751-09D28C06C7F9} Key deleted: HKLM\Software\Classes\Conduit.Engine Key deleted: HKLM\Software\Classes\Toolbar.CT2680812 Key deleted: HKLM\Software\Conduit Key deleted: HKLM\Software\conduitEngine Key deleted: HKCU\Software\DataMngr Key deleted: HKCU\Software\iMesh Key deleted: HKCU\Software\PartyGaming Key deleted: HKCU\Software\Titan Poker Key deleted: HKCU\Software\AppDataLow\Toolbar Key deleted: HKCU\Software\AppDataLow\Software\Conduit Key deleted: HKCU\Software\AppDataLow\Software\conduitEngine Key deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{8A96AF9E-4074-43b7-BEA3-87217BDA7406} Key deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} Key deleted: HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{8A96AF9E-4074-43b7-BEA3-87217BDA7406} Key deleted: HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} Key deleted: HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2BC1FFA7-5274-4034-9B45-6660324A3E58} Key deleted: HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B68C20AC-7BFD-4595-8458-63FA91E7C104} Key deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\conduitEngine Key deleted: HKLM\Software\Microsoft\Internet Explorer\Extensions\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} Value deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Run|DataMngr ============== ADDITIONNAL SCAN ============== **** Internet Explorer Version [8.0.7601.17514] **** HKCU_Main|Default_Page_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome HKCU_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU_Main|Search bar - hxxp://go.microsoft.com/fwlink/?linkid=54896 HKCU_Main|Start Page - hxxp://fr.msn.com/ HKLM_Main|Default_Page_URL - hxxp://go.microsoft.com/fwlink/?LinkId=54896 HKLM_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM_Main|Search bar - hxxp://search.msn.com/spbasic.htm HKLM_Main|Search Page - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM_Main|Start Page - hxxp://fr.msn.com/ HKCU_SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21} - "Search Results" (hxxp://dts.search-results.com/sr?src=ieb&appid=434&systemid=1&q={searchTerms}) HKCU_SearchScopes\{E88E0043-C9D4-4e33-8555-FEE4F5B63060} - "mail.ru: ????? ? ?????????" (hxxp://go.mail.ru/search?q={searchTerms}&utf8in=1&fr=ietb) HKCU_SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847} - "SweetIM Search" (hxxp://search.sweetim.com/search.asp?src=6&q={searchTerms}&barid={25CC7286-2F14-...) HKLM_SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21} - "Search Results" (hxxp://dts.search-results.com/sr?src=ieb&appid=434&systemid=1&q={searchTerms}) HKLM_SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847} - "?" (hxxp://search.sweetim.com/search.asp?src=6&q={searchTerms}&barid={25CC7286-2F14-...) HKCU_Toolbar\WebBrowser|{32099AAC-C132-4136-9E9A-4E364A424E17} (x) HKLM_ElevationPolicy\{70f641fd-9ffc-4d5b-a4dc-962af4ed7999} - C:\Program Files\Internet Explorer\iedw.exe (x) HKLM_ElevationPolicy\{8B2CE5D8-02C3-47B3-83E6-E4579F92F9B6} - C:\Program Files\Utubebario\UtubebarioToolbarHelper.exe (?) HKLM_ElevationPolicy\{99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~1\WI3C8A~1\ToolBar\uninstall.exe (?) HKLM_ElevationPolicy\{A2D14993-7315-4f91-AD76-20605495ED6C} - C:\Program Files\ESTsoft\ALUpdate\ALUpExt.exe (x) HKLM_ElevationPolicy\{A6E2003F-95C5-4591-BA9A-0093080FDB5C} - C:\Program Files\Common Files\Oberon Media\OberonBroker\1.0.0.63\OberonBroker.exe (?) HKLM_ElevationPolicy\{BEB6D896-42FA-4A66-BD76-5B2486210A45} - C:\PROGRA~1\WI3C8A~1\ToolBar\dtUser.exe (Visicom Media Inc.) HKLM_ElevationPolicy\{F2632B95-A2AD-4283-B49A-34D4802BA647} - C:\Program Files\ESTsoft\ALUpdate\ALUpdate.exe (x) BHO\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - "Skype Browser Helper" (C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll) ======================================== C:\Program Files\Ad-Remover\Quarantine: 111 File(s) C:\Program Files\Ad-Remover\Backup: 15 File(s) C:\Ad-Report-CLEAN[1].txt - 13/02/2012 18:42:50 (5243 Byte(s)) C:\Ad-Report-SCAN[1].txt - 13/02/2012 10:15:15 (5888 Byte(s)) End at: 18:43:44, 13/02/2012 ============== E.O.F ==============