======= REPORT FROM AD-REMOVER 2.0.0.2,G | ONLY XP/VISTA/7 ======= Updated by TeamXscript on 12/04/11 Contact: AdRemover[DOT]contact[AT]gmail[DOT]com website: http://www.teamxscript.org C:\Program Files\Ad-Remover\main.exe (SCAN [1]) -> Launched at 11:05:45 on 28/07/2011, Normal boot Microsoft Windows XP Home Edition Dodatek Service Pack 3 (X86) XP User@OEM-D26BC91C2B3 ( ) ============== SEARCH ============== Folder found: C:\Documents and Settings\XP User\Dane aplikacji\Mozilla\FireFox\Profiles\sbbomf0a.default\conduit File found: C:\Documents and Settings\XP User\Dane aplikacji\Mozilla\FireFox\Profiles\sbbomf0a.default\searchplugins\conduit.xml Folder found: C:\Documents and Settings\XP User\Ustawienia lokalne\Dane aplikacji\Conduit Folder found: C:\Program Files\Conduit -- File opened: C:\Documents and Settings\XP User\Dane aplikacji\Mozilla\FireFox\Profiles\sbbomf0a.default\Prefs.js -- Line found: user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1708250&Sea... -- File closed -- Key found: HKLM\Software\Classes\Toolbar.CT1708250 Key found: HKLM\Software\Conduit Key found: HKCU\Software\Conduit Key found: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} Key found: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440} Value found: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser|{D4027C7F-154A-4066-A1AD-4243D8127440} ============== ADDITIONNAL SCAN ============== **** Mozilla Firefox Version [3.6.13 (pl)] **** Plugins\npganymedenet.dll ( ) Plugins\npVividasPlayer.dll ( ) HKLM_MozillaPlugins\Adobe Reader (x) Searchplugins\allegro-pl.xml (hxxp://www.allegro.pl/search.php?string={searchTerms}&sourceid=Mozilla-search) Searchplugins\fbc-pl.xml (hxxp://fbc.pionier.net.pl/owoc/results) Searchplugins\merlin-pl.xml (hxxp://www.merlin.com.pl/frontend/search?sourceid=Mozilla-search&fraza={searchTerms}&skad=crhhxmkohb) Searchplugins\pwn-pl.xml (hxxp://encyklopedia.pwn.pl/szukaj.php?co={searchTerms}) Searchplugins\wikipedia-pl.xml (hxxp://pl.wikipedia.org/wiki/Specjalna:Szukaj) Searchplugins\wp-pl.xml (hxxp://szukaj.wp.pl/szukaj.html?z=T&r=T&szukaj={searchTerms}) -- C:\Documents and Settings\XP User\Dane aplikacji\Mozilla\FireFox\Profiles\sbbomf0a.default -- Extensions\player@vividas.com (Vividas player plugin) Extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8} (Stylish) Searchplugins\conduit.xml (hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1708250&SearchSource=3&q={searchTerms} /) Prefs.js - browser.download.lastDir, C:\\Documents and Settings\\XP User\\Pulpit\\100dniówka Prefs.js - browser.search.defaulturl, hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1708250&SearchSource=3&q={searchTerms} Prefs.js - browser.startup.homepage, www.google.pl Prefs.js - browser.startup.homepage_override.mstone, rv:1.9.2.13 ======================================== **** Google Chrome Version [12.0.742.122] **** -- C:\Documents and Settings\XP User\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default -- Preferences - default_search_provider: "Google" (Enabled: true) (?) Preferences - homepage: hxxp://www.google.pl/ Preferences - homepage_is_newtabpage: false Plugin - "My Global Search Plugin Stub" (Enabled: true) Plugin - "Picasa" (Enabled: true) Plugin - "Vividas Player Plugin" (Enabled: true) Plugin - "GanymedeNet.Detector" (Enabled: true) ======================================== **** Internet Explorer Version [6.0.2900.5512] **** HKCU_Main|Search Page - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM_Main|Default_Page_URL - hxxp://go.microsoft.com/fwlink/?LinkId=69157 HKLM_Main|Default_Search_URL - hxxp://go.microsoft.com/fwlink/?LinkId=54896 HKLM_Main|Search Page - hxxp://go.microsoft.com/fwlink/?LinkId=54896 HKLM_Main|Start Page - hxxp://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home HKCU_URLSearchHooks|{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} - "Free Lunch Design Toolbar" (C:\Program Files\Free_Lunch_Design\tbFre1.dll) HKCU_SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} - "Free Lunch Design Customized Web Search" (hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT...) HKCU_Toolbar\WebBrowser|{D4027C7F-154A-4066-A1AD-4243D8127440} (x) HKCU_Toolbar\WebBrowser|{57CC715D-37CA-44E4-9EC2-8C2CBDDB25EC} (C:\Program Files\Free_Lunch_Design\tbFre1.dll) HKLM_Toolbar|{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} (C:\Program Files\Free_Lunch_Design\tbFre1.dll) HKCU_ElevationPolicy\{1902485B-CE75-42C1-BA2D-57E660793D9A} - C:\Documents and Settings\XP User\Pulpit\IEMonitor.exe (x) HKCU_ElevationPolicy\{E0DACC63-037F-46EE-AC02-E4C7B0FBFEB4} - C:\Documents and Settings\XP User\Pulpit\IDMan.exe (x) HKLM_ElevationPolicy\b8d94348-3ed8-4661-9583-9200f6bec6ec - C:\Program Files\Free_Lunch_Design\Free_Lunch_DesignToolbarHelper.exe (?) HKLM_ElevationPolicy\d72ae168-5eb2-4e9a-a3de-7069527f4ac6 - C:\Program Files\Free_Lunch_Design\Free_Lunch_DesignToolbarHelper.exe (?) HKLM_ElevationPolicy\da7d6475-76a3-4f2c-95c0-2dc8caf10c25 - C:\Program Files\Free_Lunch_Design\Free_Lunch_DesignToolbarHelper.exe (?) HKLM_ElevationPolicy\{E0DACC63-037F-46EE-AC02-E4C7B0FBFEB4} - C:\Documents and Settings\XP User\Pulpit\IDMan.exe (x) HKLM_Extensions\{e2e2dd38-d088-4134-82b7-f2ba38496583} - "?" (?) BHO\{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} - "Free Lunch Design Toolbar" (C:\Program Files\Free_Lunch_Design\tbFre1.dll) BHO\{F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - "IEPluginBHO Class" (C:\Documents and Settings\XP User\Dane aplikacji\Nowe Gadu-Gadu\_userdata\ggbho.1.dll) ======================================== C:\Program Files\Ad-Remover\Quarantine: 0 File(s) C:\Program Files\Ad-Remover\Backup: 1 File(s) C:\Ad-Report-SCAN[1].txt - 28/07/2011 11:06:20 (3551 Byte(s)) End at: 11:06:50, 28/07/2011 ============== E.O.F ==============