.
======= RAPPORT D'AD-REMOVER 2.0.0.0,C | UNIQUEMENT XP/VISTA/7 =======
.
Mis à jour par C_XX le 22/04/10 à 19:00
Contact:
AdRemover.contact@gmail.comSite web:
http://pagesperso-orange.fr/NosTools/ad_remover.html.
Lancé à: 11:18:42 le 23/04/2010 | Mode normal | Option: CLEAN
Exécuté de: C:\Ad-Remover\ADR.exe
SE: Microsoft® Windows Vista™ HomePremium - X86
Nom du PC: PC-DE-DAVID (Packard Bell BV EasyNote SB85)
Utilisateur actuel: david (Administrateur)
.
============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
.
Service: *Application Updater*
.
C:\Program Files\Application Updater
C:\Program Files\Dealio Toolbar
C:\Program Files\Mozilla FireFox\extensions\dealio@mybrowserbar.com
C:\Program Files\Mozilla Firefox\extensions\searchsettings@spigot.com
C:\Program Files\Search Settings
C:\Users\david\AppData\LocalLow\Dealio
C:\Users\david\AppData\LocalLow\Search Settings
(!) -- Fichiers temporaires supprimés.
.
HKCU\Software\AppDataLow\Software\Dealio
HKCU\Software\Microsoft\Internet Explorer\LowRegistry\Search Settings
HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
HKLM\Software\Application Updater
HKLM\Software\Classes\CLSID\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}
HKLM\Software\Classes\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
HKLM\Software\Classes\Installer\Products\96DC878CBD58B624183A7E1157AABE19
HKLM\Software\Classes\Interface\{D5A1EF9A-7948-435D-8B87-D6A598317288}
HKLM\Software\Classes\Interface\{DB885111-F39F-4D88-9EE5-C88460B6DF7B}
HKLM\Software\Classes\SearchSettings.BHO
HKLM\Software\Classes\SearchSettings.BHO.1
HKLM\Software\Classes\TypeLib\{CD082CCA-086F-4FD8-8FD7-247A0DBBD1CC}
HKLM\Software\Dealio
HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}
HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Products\96DC878CBD58B624183A7E1157AABE19
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{C878CD69-85DB-426B-81A3-E71175AAEB91}
HKLM\Software\Search Settings
HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks|{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
HKLM\Software\Microsoft\Internet Explorer\Toolbar|{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}
HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\Program Files\Application Updater\ApplicationUpdater.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\Program Files\Dealio Toolbar\FF\chrome.manifest
HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\Program Files\Dealio Toolbar\FF\chrome\locale\EN-US\widgitoolbarplugin.properties
HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\Program Files\Dealio Toolbar\FF\components\dealioToolbarFF.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\Program Files\Dealio Toolbar\FF\install.rdf
HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\Program Files\Search Settings\FF\chrome\locale\en-US\searchsettingsplugin.dtd
HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\Program Files\Search Settings\FF\components\SearchSettingsFF.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\Program Files\Search Settings\FF\install.rdf
HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\Program Files\Search Settings\SearchSettingsRes409.dll
.
(Orpheline) BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} (CLSID manquant)
(Orpheline) HKLM,Uninstall - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\uninst.exe (Fichier manquant)
(Orpheline) HKLM,Uninstall - Shin Megami Tensei - C:\AeriaGames\MegaTen-FR\Uninst.exe (Fichier manquant)
(Orpheline) HKLM,Uninstall - {3EE33958-7381-4E7B-A4F3-6E43098E9E9C} - regsvr32 /u /s C:\Program Files\Google\Google_BAE\BAE.dll (Fichier manquant)
.
============== SCAN ADDITIONNEL ==============
.
* Mozilla FireFox Version 3.6.3 (fr) *
.
C:\Users\david\..\ku1perj5.default\prefs.js - browser.download.lastDir: C:\\Users\\david\\Desktop
C:\Users\david\..\ku1perj5.default\prefs.js - browser.search.defaultenginename: Google
C:\Users\david\..\ku1perj5.default\prefs.js - browser.search.defaulturl:
hxxp://search.conduit.com/ResultsExt.as ... ource=3&q={searchTerms}
C:\Users\david\..\ku1perj5.default\prefs.js - browser.search.selectedEngine: Messenger Plus Live France Customized Web Search
C:\Users\david\..\ku1perj5.default\prefs.js - browser.startup.homepage:
hxxp://www.google.frC:\Users\david\..\ku1perj5.default\prefs.js - browser.startup.homepage_override.mstone: rv:1.9.2.3
C:\Users\david\..\ku1perj5.default\prefs.js - keyword.URL:
hxxp://search.conduit.com/ResultsExt.as ... 2567681&q=.
.
* Internet Explorer Version 7.0.6000.17037 *
.
[HKCU\Software\Microsoft\Internet Explorer\Main]
.
AutoHide: yes
Default_Page_URL:
hxxp://www.microsoft.com/isapi/redir.dl ... ar=msnhomeDefault_Search_URL:
hxxp://www.microsoft.com/isapi/redir.dl ... r=iesearchDo404Search: 0x01000000
Enable Browser Extensions: yes
Local Page: C:\Windows\system32\blank.htm
Search bar:
hxxp://go.microsoft.com/fwlink/?linkid=54896Show_ToolBar: yes
Start Page:
hxxp://fr.msn.com/.
[HKLM\Software\Microsoft\Internet Explorer\Main]
.
AutoHide: yes
Default_Page_URL:
hxxp://www.microsoft.com/isapi/redir.dl ... ar=msnhomeDefault_Search_URL:
hxxp://www.microsoft.com/isapi/redir.dl ... r=iesearchDelete_Temp_Files_On_Exit: yes
Local Page: %SystemRoot%\system32\blank.htm
Search bar:
hxxp://search.msn.com/spbasic.htmSearch Page:
hxxp://www.microsoft.com/isapi/redir.dl ... r=iesearchStart Page:
hxxp://fr.msn.com/.
[HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS]
.
Tabs:
res://ieframe.dll/tabswelcome.htmBlank:
res://mshtml.dll/blank.htm.
============== SUSPECT(S) ==============
.
C:\Users\david\Desktop\Crack\iw4mp.exe
C:\Users\david\Desktop\Crack\iw4sp.exe
C:\Users\david\Desktop\divers\Crack\godfather2.exe
C:\Users\david\Desktop\divers\Crack\KeYgen.exe
C:\Users\david\Documents\Mes fichiers reçus\Keygen Core multilogiciels Adobe V1.04.exe
.
========================================
.
C:\Users\david\AppData\Local\Temp: 4 Fichier(s), 100 Dossier(s)
C:\Windows\temp: 2 Fichier(s), 12 Dossier(s)
C:\Users\david\AppData\Roaming\Microsoft\Windows\Cookies: 2 Fichier(s), 2 Dossier(s)
Temporary Internet Files: 2 Fichier(s), 36 Dossier(s)
.
C:\Ad-Remover\Quarantine: 95 Fichier(s)
C:\Ad-Remover\Backup: 16 Fichier(s)
.
C:\Ad-Report-CLEAN[1].txt - 6910 Octet(s)
.
Fin à: 11:24:33, 23/04/2010
.
============== E.O.F - CLEAN[1] ==============