Voila le rapport de Ad-R:
======= REPORT FROM AD-REMOVER 2.0.0.2,G | ONLY XP/VISTA/7 =======
Updated by TeamXscript on 12/04/11
Contact: AdRemover[DOT]contact[AT]gmail[DOT]com
website:
http://www.teamxscript.org
C:\Program Files\Ad-Remover\main.exe (CLEAN [3]) -> Launched at 22:09:58 on 24/05/2011, Safeboot mode
Microsoft® Windows Vista™ Édition Intégrale Service Pack 2 (X86)
OMER@OMER-PC (HP Pavilion 06 D5468AT-ABA ALONPAV)
============== ACTION(S) ==============
(!) -- Temporary files deleted.
-- File opened: C:\Users\OMER\AppData\Roaming\Mozilla\FireFox\Profiles\gn6mscey.default\Prefs.js --
Line deleted: user_pref("CT2542115.SearchEngine", "Recherche||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_...
Line deleted: user_pref("CT2542115.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT254...
Line deleted: user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1061742/1057446/FR", "\"0\"...
Line deleted: user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1066/1066/FR", "\"0\"");
Line deleted: user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1112915/1108619/FR", "\"0\"...
Line deleted: user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1172363/1168048/FR", "\"0\"...
Line deleted: user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1336967/1332636/FR", "\"0\"...
Line deleted: user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/666152/662013/FR", "\"0\"")...
Line deleted: user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/708285/704145/FR", "\"0\"")...
Line deleted: user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/825605/821413/FR", "\"0\"")...
Line deleted: user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/863916/859718/FR", "\"0\"")...
Line deleted: user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/FR", "\"0\"")...
Line deleted: user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/986190/981911/FR", "\"0\"")...
Line deleted: user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\...
Line deleted: user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.engine.conduit-services.com/DLG.pkg?ver=3.3.3...
Line deleted: user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "63...
Line deleted: user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=1/11/20...
Line deleted: user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=12/30/2...
Line deleted: user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=2/17/20...
Line deleted: user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=2/22/20...
Line deleted: user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=3/13/20...
Line deleted: user_pref("CommunityToolbar.EngineOwner", "ConduitEngine");
Line deleted: user_pref("CommunityToolbar.EngineOwnerGuid", "
engine@conduit.com");
Line deleted: user_pref("CommunityToolbar.EngineOwnerToolbarId", "conduitengine");
Line deleted: user_pref("CommunityToolbar.IsEngineShown", true);
Line deleted: user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true);
Line deleted: user_pref("CommunityToolbar.OriginalEngineOwner", "ConduitEngine");
Line deleted: user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "
engine@conduit.com");
Line deleted: user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "conduitengine");
Line deleted: user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "chrome://browser-region/locale/region.pr...
Line deleted: user_pref("CommunityToolbar.ToolbarsList", "CT2542115,ConduitEngine");
Line deleted: user_pref("CommunityToolbar.ToolbarsList2", "CT2542115");
Line deleted: user_pref("CommunityToolbar.alert.alertDialogsGetterLastCheckTime", "Thu Mar 24 2011 11:53:19 GMT+01...
Line deleted: user_pref("CommunityToolbar.alert.alertInfoInterval", 60);
Line deleted: user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Tue May 17 2011 17:41:06 GMT+0200");
Line deleted: user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com");
Line deleted: user_pref("CommunityToolbar.alert.firstTimeAlertShown", true);
Line deleted: user_pref("CommunityToolbar.alert.locale", "en");
Line deleted: user_pref("CommunityToolbar.alert.loginIntervalMin", 1440);
Line deleted: user_pref("CommunityToolbar.alert.loginLastCheckTime", "Mon May 16 2011 21:36:08 GMT+0200");
Line deleted: user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1303303927");
Line deleted: user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);
Line deleted: user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com");
Line deleted: user_pref("CommunityToolbar.alert.showTrayIcon", false);
Line deleted: user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);
Line deleted: user_pref("CommunityToolbar.alert.userId", "33ed5ac0-3176-4913-b0f4-0e6852c03c4f");
Line deleted: user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Line deleted: user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Line deleted: user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2542115");
Line deleted: user_pref("ConduitEngine.AppTrackingLastCheckTime", "Sat Apr 16 2011 11:22:49 GMT+0200");
Line deleted: user_pref("ConduitEngine.BrowserCompStateIsOpen_3287235895595217780", true);
Line deleted: user_pref("ConduitEngine.BrowserCompStateIsOpen_3604955317306971232", true);
Line deleted: user_pref("ConduitEngine.BrowserCompStateIsOpen_3976808699496931956", true);
Line deleted: user_pref("ConduitEngine.BrowserCompStateIsOpen_8556964412163870795", true);
Line deleted: user_pref("ConduitEngine.CTID", "ConduitEngine");
Line deleted: user_pref("ConduitEngine.DialogsGetterLastCheckTime", "Sun May 15 2011 13:46:11 GMT+0200");
Line deleted: user_pref("ConduitEngine.FirstServerDate", "01/07/2011 20");
Line deleted: user_pref("ConduitEngine.FirstTime", true);
Line deleted: user_pref("ConduitEngine.FirstTimeFF3", true);
Line deleted: user_pref("ConduitEngine.HasUserGlobalKeys", true);
Line deleted: user_pref("ConduitEngine.Initialize", true);
Line deleted: user_pref("ConduitEngine.InitializeCommonPrefs", true);
Line deleted: user_pref("ConduitEngine.InstalledDate", "Fri Jan 07 2011 18:44:58 GMT+0100");
Line deleted: user_pref("ConduitEngine.IsMulticommunity", false);
Line deleted: user_pref("ConduitEngine.IsOpenThankYouPage", false);
Line deleted: user_pref("ConduitEngine.IsOpenUninstallPage", true);
Line deleted: user_pref("ConduitEngine.LanguagePackLastCheckTime", "Mon May 16 2011 21:36:17 GMT+0200");
Line deleted: user_pref("ConduitEngine.LastLogin_3.2.5.2", "Thu Mar 24 2011 11:09:52 GMT+0100");
Line deleted: user_pref("ConduitEngine.LastLogin_3.3.3.2", "Tue May 17 2011 21:18:47 GMT+0200");
Line deleted: user_pref("ConduitEngine.SearchFromAddressBarIsInit", true);
Line deleted: user_pref("ConduitEngine.SettingsLastCheckTime", "Tue May 17 2011 21:18:45 GMT+0200");
Line deleted: user_pref("ConduitEngine.UserID", "UN57650431449928899");
Line deleted: user_pref("ConduitEngine.backendstorage._fb_dailyactivity", "31333032343432343935343538");
Line deleted: user_pref("ConduitEngine.backendstorage._fb_lifetimesent", "54525545");
Line deleted: user_pref("ConduitEngine.backendstorage.ad5c3ba0a4b741e3a263c08dd3251e6aparamsgk", "7B22757064617465...
Line deleted: user_pref("ConduitEngine.backendstorage.appbuttondisablenull", "30");
Line deleted: user_pref("ConduitEngine.backendstorage.eb_dailyactivity", "31333035353734353737343037");
Line deleted: user_pref("ConduitEngine.backendstorage.eb_lifetimesent", "54525545");
Line deleted: user_pref("ConduitEngine.backendstorage.facebook_ctid_connect_send", "73656E646564");
Line deleted: user_pref("ConduitEngine.backendstorage.facebook_ctid_connect_send_new", "73656E646564");
Line deleted: user_pref("ConduitEngine.backendstorage.facebook_mode", "32");
Line deleted: user_pref("ConduitEngine.backendstorage.facebook_user_locale", "6672");
Line deleted: user_pref("ConduitEngine.backendstorage.fb_dailyactivity", "31333033383133303332383338");
Line deleted: user_pref("ConduitEngine.backendstorage.fb_lifetimesent", "54525545");
Line deleted: user_pref("ConduitEngine.backendstorage.youtube_user_first_login_date", "30342F31392F32303131");
Line deleted: user_pref("ConduitEngine.backendstorage.youtube_user_survey_visit", "4E4F545F56495349544544");
Line deleted: user_pref("ConduitEngine.backendstorage.youtubelang", "4652");
Line deleted: user_pref("ConduitEngine.backendstorage.ytapp_dailyactivity", "31333035353734353737333131");
Line deleted: user_pref("ConduitEngine.backendstorage.ytapp_lifetimesent", "54525545");
Line deleted: user_pref("ConduitEngine.componentAlertEnabled", true);
Line deleted: user_pref("ConduitEngine.counterAppsAdded", 10);
Line deleted: user_pref("ConduitEngine.engineLocale", "fr");
Line deleted: user_pref("ConduitEngine.enngineContextMenuLastCheckTime", "Mon May 16 2011 21:36:27 GMT+0200");
Line deleted: user_pref("ConduitEngine.globalFirstTimeInfoLastCheckTime", "Tue May 17 2011 17:41:06 GMT+0200");
Line deleted: user_pref("ConduitEngine.initDone", true);
Line deleted: user_pref("ConduitEngine.isAppTrackingManagerOn", true);
Line deleted: user_pref("ConduitEngine.usagesFlag", 2);
Line deleted: user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2542115&Sea...
-- File closed --
Key deleted: HKLM\Software\Classes\CLSID\{A7E8C343-7860-4A95-9AA8-AAF30D0F6D1E}
Key deleted: HKLM\Software\Classes\CLSID\{AA06A60A-87EA-43EA-8D76-E17396443F92}
Key deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{AA06A60A-87EA-43EA-8D76-E17396443F92}
Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AA06A60A-87EA-43EA-8D76-E17396443F92}
Key deleted: HKLM\Software\Classes\CLSID\{FC0D62C2-9640-4AEB-A5D5-CF25DF11FA8C}
Key deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FC0D62C2-9640-4AEB-A5D5-CF25DF11FA8C}
Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FC0D62C2-9640-4AEB-A5D5-CF25DF11FA8C}
Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FC0D62C2-9640-4AEB-A5D5-CF25DF11FA8C}
Key deleted: HKLM\Software\Classes\Interface\{6612AFDD-34AD-4B89-A236-7E6D07C3FDCD}
Key deleted: HKLM\Software\Classes\TypeLib\{ED85AEBE-F834-4088-B5D3-97EB2478A6CD}
Key deleted: HKLM\Software\Classes\Conduit.Engine
Key deleted: HKLM\Software\Classes\OfferBox.OfferBoxServer
Key deleted: HKLM\Software\Classes\OfferBox.OfferBoxServer.1
Key deleted: HKLM\Software\Classes\Toolbar.CT2442941
Key deleted: HKLM\Software\Classes\Toolbar.CT2542115
Key deleted: HKLM\Software\Classes\Toolbar.CT2738886
Key deleted: HKLM\Software\Conduit
Key deleted: HKLM\Software\conduitEngine
Key deleted: HKLM\Software\OfferBox
Key deleted: HKLM\Software\Trymedia Systems
Key deleted: HKCU\Software\Conduit
Key deleted: HKCU\Software\OfferBox
Key deleted: HKCU\Software\AppDataLow\Toolbar
Key deleted: HKCU\Software\AppDataLow\Software\Conduit
Key deleted: HKCU\Software\AppDataLow\Software\conduitEngine
Key deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Key deleted: HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Key deleted: HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{37F4A335-D085-423e-A425-0370799166FB}
Key deleted: HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ABF15D30-62B8-4A1E-93FC-58F2AE60575C}
Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\conduitEngine
Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\OfferBox
Key deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\conduitEngine
Key deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\OfferBox
Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key deleted: HKLM\Software\Google\Chrome\Extensions\bjeikeheijdjdfjbmknpefojickbkmom
Value deleted: HKLM\Software\Mozilla\Firefox\Extensions|
offerboxffx@offerbox.com
Value deleted: HKLM\Software\Microsoft\Internet Explorer\Toolbar|{30F9B915-B755-4826-820B-08FBA6BD249D}
Value deleted: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser|{D4027C7F-154A-4066-A1AD-4243D8127440}
Value deleted: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser|{4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33}
============== ADDITIONNAL SCAN ==============
-- C:\Users\OMER\AppData\Roaming\Mozilla\FireFox\Profiles\gn6mscey.default --
Extensions\{00352F14-3F76-4e4d-ACFF-9972D7E4B3B9} (MacOSX Theme)
Extensions\{de5809e0-2b07-11dd-bd0b-0800200c9a66} (Gradient iCool)
Prefs.js - browser.download.dir, C:\\Users\\OMER\\Desktop\\Téléchargements
Prefs.js - browser.download.lastDir, C:\\Users\\OMER\\Desktop
Prefs.js - browser.startup.homepage, hxxp://
www.google.fr/
Prefs.js - browser.startup.homepage_override.buildID, 20110413222027
Prefs.js - browser.startup.homepage_override.mstone, rv:2.0.1
Prefs.js - keyword.URL, hxxp://home.speedbit.com/search.aspx?aff=206&q=
========================================
**** Google Chrome Version [11.0.696.68] ****
-- C:\Users\OMER\AppData\Local\Google\Chrome\User Data\Default --
Preferences - default_search_provider: "Google" (Enabled: true) (?)
Preferences - homepage:
Preferences - homepage_is_newtabpage: true
Plugin - Pando Web Plugin (Enabled: true) (C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll)
Plugin - D'Fusion @Home Web Plug-In (2.30.11563.AR23) (Enabled: true) (C:\Program Files\Total Immersion\DFusionHomeWebPlugIn\NPDFusionWebFirefox.dll)
Plugin - 3DVIA player (Enabled: true) (C:\Program Files\Virtools\3D Life Player\npvirtools.dll)
Plugin - "D'Fusion @Home Web Plug-In (2.30.11563.AR23)" (Enabled: true)
Plugin - "OfferboxChromePlugin Dynamic Link Library" (Enabled: true)
Plugin - "DivX Player" (Enabled: true)
Plugin - "Nexon Game Controller" (Enabled: true)
Plugin - "Pando Web Plugin" (Enabled: true)
Plugin - "3DVIA player" (Enabled: true)
========================================
**** Internet Explorer Version [8.0.6001.19048] ****
HKCU_Main|Default_Page_URL - hxxp://
www.microsoft.com/isapi/redir.dll?prd=i ... ar=msnhome
HKCU_Main|Default_Search_URL - hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU_Main|Search bar - hxxp://go.microsoft.com/fwlink/?linkid=54896
HKCU_Main|Start Page - hxxp://fr.msn.com/
HKLM_Main|Default_Page_URL - hxxp://go.microsoft.com/fwlink/?LinkId=54896
HKLM_Main|Default_Search_URL - hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM_Main|Search bar - hxxp://search.msn.com/spbasic.htm
HKLM_Main|Search Page - hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM_Main|Start Page - hxxp://fr.msn.com/
HKCU_URLSearchHooks|{c31212e2-a150-4036-985a-f55e14037b94} (x)
HKLM_URLSearchHooks|{c31212e2-a150-4036-985a-f55e14037b94} (x)
HKCU_SearchScopes\{672F00A9-11D6-426c-8C2B-9D4222BBBC85} - "SpeedBit Search" (hxxp://home.speedbit.com/search.aspx?aff=206&q={searchTerms})
HKCU_Toolbar\WebBrowser|{C31212E2-A150-4036-985A-F55E14037B94} (x)
HKLM_Toolbar|{c31212e2-a150-4036-985a-f55e14037b94} (x)
HKLM_Toolbar|{381FFDE8-2394-4F90-B10D-FC6124A40F8C} (C:\Program Files\BitDefender\BitDefender 2011\IEToolbar.dll)
HKLM_ElevationPolicy\50c64575-38e0-4f7a-8069-04789c1d91e5 - C:\Program Files\Soft-Search\Soft-SearchToolbarHelper.exe (x)
HKLM_ElevationPolicy\{569591D2-F221-4115-9A89-762956BEB3C0} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\SmartWebPrintExe.exe (?)
HKLM_ElevationPolicy\{6D7F17B9-FD2B-48C7-A1CC-2355C7AB4D44} - C:\Program Files\FRgaming\FRgamingToolbarHelper.exe (?)
HKLM_ElevationPolicy\{70f641fd-9ffc-4d5b-a4dc-962af4ed7999} - C:\Program Files\Internet Explorer\iedw.exe (x)
HKLM_ElevationPolicy\{80B84A0A-EDA4-47FD-8BE1-6B49F4197BE6} - C:\Program Files\BitDefender\BitDefender 2011\about.exe\about.ex (x)
HKLM_ElevationPolicy\{CDF23FF1-D4CC-4BA4-9D6D-629661527960} - C:\Users\OMER\AppData\Local\Conduit\CT2738886\FRgamingAutoUpdateHelper.exe (x)
BHO\{5C255C8A-E604-49b4-9D64-90988571CECB} (?)
========================================
PS: Désolé pour le retard :/