======= REPORT FROM AD-REMOVER 2.0.0.2,G | ONLY XP/VISTA/7 ======= Updated by TeamXscript on 12/04/11 Contact: AdRemover[DOT]contact[AT]gmail[DOT]com website: http://www.teamxscript.org C:\Program Files\Ad-Remover\main.exe (SCAN [2]) -> Launched at 18:08:41 on 17/06/2011, Normal boot Microsoft® Windows Vista™ Home Basic (X86) Marcin@SNOTF (FUJITSU SIEMENS AMILO Pi 1505) ============== SEARCH ============== ============== ADDITIONNAL SCAN ============== **** Mozilla Firefox Version [3.6.17 (pl)] **** FIREFOX.EXE\Shell\Open\Command - "C:\Users\Marcin\AppData\Local\ghh.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe" Searchplugins\allegro-pl.xml (hxxp://www.allegro.pl/search.php?string={searchTerms}&sourceid=Mozilla-search) Searchplugins\fbc-pl.xml (hxxp://fbc.pionier.net.pl/owoc/results) Searchplugins\merlin-pl.xml (hxxp://www.merlin.com.pl/frontend/search?sourceid=Mozilla-search&fraza={searchTerms}&skad=crhhxmkohb) Searchplugins\pwn-pl.xml (hxxp://encyklopedia.pwn.pl/szukaj.php?co={searchTerms}) Searchplugins\wikipedia-pl.xml (hxxp://pl.wikipedia.org/wiki/Specjalna:Szukaj) Searchplugins\wp-pl.xml (hxxp://szukaj.wp.pl/szukaj.html?z=T&r=T&szukaj={searchTerms}) -- C:\Users\Marcin\AppData\Roaming\Mozilla\FireFox\Profiles\u4cyky9y.default -- Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} (TV.wrzuc.to) Prefs.js - browser.download.dir, C:\\Users\\Marcin\\Downloads Prefs.js - browser.download.lastDir, C:\\Users\\Marcin\\Desktop Prefs.js - browser.search.defaultenginename, Prefs.js - browser.search.selectedEngine, Google Prefs.js - browser.startup.homepage, hxxp://www.pajacyk.pl/ Prefs.js - browser.startup.homepage_override.mstone, rv:1.9.2.17 ======================================== **** Internet Explorer Version [7.0.6000.17037] **** IEXPLORE.EXE\Shell\Open\Command - C:\Users\Marcin\AppData\Local\ghh.exe -a C:\Program Files\Internet Explorer\iexplore.exe HKCU_Main|Default_Page_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome HKCU_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU_Main|Search bar - hxxp://go.microsoft.com/fwlink/?linkid=54896 HKCU_Main|Start Page - hxxp://fr.msn.com/ HKLM_Main|Default_Page_URL - hxxp://go.microsoft.com/fwlink/?LinkId=54896 HKLM_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM_Main|Search bar - hxxp://search.msn.com/spbasic.htm HKLM_Main|Search Page - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM_Main|Start Page - hxxp://fr.msn.com/ HKCU_ElevationPolicy\{47C53625-D229-4C8F-82E2-1ED363AE0D78} - C:\Program Files\BitComet\BitComet.exe (x) HKCU_ElevationPolicy\{48DE111E-A07F-4393-8FED-2B1E8C6EF6F6} - C:\Windows\System32\Macromed\Flash\FlashUtil9f.exe (x) HKCU_ElevationPolicy\{60767602-F8EF-456B-A695-9D6548166565} - C:\Program Files\NOL3\Notowania OnLine 3.0 DM BOS S.A\NOL3.exe (x) HKCU_ElevationPolicy\{8C93AA65-25EC-4377-B278-250F68A2DE8E} - C:\Windows\System32\Macromed\Flash\FlashUtil9d.exe (x) HKCU_ElevationPolicy\{BBDA703C-0E74-45C7-86F9-1A56F716C42C} - C:\Program Files\IrfanView\i_view32.exe (Irfan Skiljan) HKLM_ElevationPolicy\{4181C878-6A35-406d-8D1B-030C80F8DDAE} - C:\Program Files\Virgin Broadband\advisor\BroadbandadvisorComHandler.exe (Radialpoint Inc.) HKLM_ElevationPolicy\{6354B1ED-3B82-405a-87F7-B278EF054B96} - C:\Program Files\Photodex Presenter\pxplay.exe (Photodex Corporation) BHO\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - "AcroIEHlprObj Class" (C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll) ======================================== C:\Program Files\Ad-Remover\Quarantine: 8 File(s) C:\Program Files\Ad-Remover\Backup: 18 File(s) C:\Ad-Report-CLEAN[1].txt - 17/06/2011 17:46:23 (6726 Byte(s)) C:\Ad-Report-SCAN[1].txt - 17/06/2011 16:39:50 (6775 Byte(s)) C:\Ad-Report-SCAN[2].txt - 17/06/2011 18:08:48 (3910 Byte(s)) End at: 18:10:42, 17/06/2011 ============== E.O.F ==============