Hier die Logfiles    Code:  
 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 
Junkware Removal Tool (JRT) by Thisisu 
Version: 4.8.9 (04.22.2013:1) 
OS: Windows 7 Professional x86 
Ran by afshin3 on 24.04.2013 at 18:17:44,32 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~         
~~~ Services   
Successfully stopped: [Service] wajamupdater  
Successfully deleted: [Service] wajamupdater        
~~~ Registry Values       
~~~ Registry Keys   
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\babylon 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\babylontoolbar 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\freeze.com 
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\ilivid 
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\softonic 
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\surf canyon 
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\wajam 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\wajam 
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\Software\pricegong 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\appid\escort.dll 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\appid\priam_bho.dll 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\applications\ilividsetup.exe 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\prod.cap 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\wajam.wajambho 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\wajam.wajambho.1 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\wajam.wajamdownloader 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\wajam.wajamdownloader.1 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\babylontoolbarsrv_rasapi32 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\babylontoolbarsrv_rasmancs 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\datamngrui_rasapi32 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\datamngrui_rasmancs 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\facemoods_rasapi32 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\facemoods_rasmancs 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\ilivid_rasapi32 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\ilivid_rasmancs 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\ilividmediabar_rasapi32 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\ilividmediabar_rasmancs 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\ilividsetup_rasapi32 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\ilividsetup_rasmancs 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\mybabylontb_rasapi32 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\mybabylontb_rasmancs 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\setupdatamngr_searchqu_rasapi32 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\setupdatamngr_searchqu_rasmancs 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\wajam_install_rasapi32 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\wajam_install_rasmancs 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\wajamupdater_rasapi32 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\wajamupdater_rasmancs 
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A} 
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} 
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} 
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{1F096B29-E9DA-4D64-8D63-936BE7762CC5} 
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} 
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8} 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}       
~~~ Files   
Successfully deleted: [File] "C:\end"       
~~~ Folders   
Successfully deleted: [Folder] "C:\ProgramData\boost_interprocess" 
Successfully deleted: [Folder] "C:\Users\afshin3\AppData\Roaming\dealply" 
Successfully deleted: [Folder] "C:\Users\afshin3\appdata\local\wajam" 
Successfully deleted: [Folder] "C:\Users\afshin3\appdata\locallow\boost_interprocess" 
Successfully deleted: [Folder] "C:\Users\afshin3\appdata\locallow\pricegong" 
Successfully deleted: [Folder] "C:\Program Files\daemon tools toolbar" 
Successfully deleted: [Folder] "C:\Program Files\wajam" 
Successfully deleted: [Folder] "C:\Users\afshin3\AppData\Roaming\microsoft\windows\start menu\programs\wajam"       
~~~ Event Viewer Logs were cleared           
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 
Scan was completed on 24.04.2013 at 18:20:07,10 
End of JRT log 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~    Code:  
 # AdwCleaner v2.202 - Logfile created 04/24/2013 at 18:34:45 
# Updated 23/04/2013 by Xplode 
# Operating system : Windows 7 Professional Service Pack 1 (32 bits) 
# User : afshin3 - AFSHIN3-PC 
# Boot Mode : Normal 
# Running from : C:\Users\afshin3\Desktop\adwcleaner.exe 
# Option [Delete]     
***** [Services] *****     
***** [Files / Folders] *****   
File Deleted : C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml 
File Deleted : C:\Program Files\Mozilla FireFox\searchplugins\Search_Results.xml 
File Deleted : C:\Users\afshin3\AppData\Roaming\Mozilla\Firefox\Profiles\6vvjwyse.default\extensions\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}.xpi 
File Deleted : C:\Users\afshin3\AppData\Roaming\Mozilla\Firefox\Profiles\6vvjwyse.default\searchplugins\Search_Results.xml 
Folder Deleted : C:\Users\afshin3\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb 
Folder Deleted : C:\Users\afshin3\AppData\Local\PackageAware 
Folder Deleted : C:\Users\afshin3\AppData\LocalLow\BabylonToolbar 
Folder Deleted : C:\Users\afshin3\AppData\LocalLow\facemoods.com   
***** [Registry] *****   
Key Deleted : HKCU\Software\InstallCore 
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} 
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} 
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FAEE6D5-34F4-42AA-8025-3FD8F3EC4634} 
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0} 
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB} 
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17} 
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2} 
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5D64294B-1341-4FE7-B6D8-7C36828D4DD5} 
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} 
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2} 
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{095BFD3C-4602-4FE1-96F1-AEFAFBFD067D} 
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dhkplhfnhceodhffomolpfigojocbpcb 
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp 
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670} 
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88} 
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Wajam 
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WajamUpdater 
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{32099AAC-C132-4136-9E9A-4E364A424E17}]   
***** [Internet Browsers] *****   
-\\ Internet Explorer v10.0.9200.16537   
[OK] Registry is clean.   
-\\ Mozilla Firefox v20.0.1 (en-US)   
File : C:\Users\afshin3\AppData\Roaming\Mozilla\Firefox\Profiles\6vvjwyse.default\prefs.js   
C:\Users\afshin3\AppData\Roaming\Mozilla\Firefox\Profiles\6vvjwyse.default\user.js ... Deleted !   
Deleted : user_pref("browser.newtab.url", "hxxp://search.babylon.com/?affID=110824&tt=4812_3&babsrc=NT_ss&mntr[...] 
Deleted : user_pref("browser.search.defaultenginename", "Search the web (Babylon)"); 
Deleted : user_pref("browser.startup.homepage", "hxxp://search.babylon.com/?affID=110824&tt=4812_3&babsrc=HP_s[...] 
Deleted : user_pref("extensions.BabylonToolbar_i.newTab", true); 
Deleted : user_pref("extensions.BabylonToolbar_i.newTabUrl", "hxxp://search.babylon.com/?affID=110824&tt=4812_[...] 
Deleted : user_pref("extensions.wajam.affiliate_id", "6447"); 
Deleted : user_pref("extensions.wajam.firstrun", "false"); 
Deleted : user_pref("extensions.wajam.log_send_info", "false"); 
Deleted : user_pref("extensions.wajam.mappingListJsonString", "{\"version\":\"0.21086\",\"supported_sites\":{\[...] 
Deleted : user_pref("extensions.wajam.no_trace", "false"); 
Deleted : user_pref("extensions.wajam.server_current_mapping_version", "0.21086"); 
Deleted : user_pref("extensions.wajam.supported_sites.amazon_product.priam_se_js", "try {window['APP_LABEL_NAM[...] 
Deleted : user_pref("extensions.wajam.supported_sites.amazon_v2.wajam_se_js", "try {window['APP_LABEL_NAME'] =[...] 
Deleted : user_pref("extensions.wajam.supported_sites.ebay_product.wajam_se_js", "try {window['APP_LABEL_NAME'[...] 
Deleted : user_pref("extensions.wajam.supported_sites.ebay_v2.wajam_se_js", "try {window['APP_LABEL_NAME'] = '[...] 
Deleted : user_pref("extensions.wajam.supported_sites.encryptedgoogle.wajam_google_js", "try {window['APP_LABE[...] 
Deleted : user_pref("extensions.wajam.supported_sites.google.wajam_google_se_js", "try {window['APP_LABEL_NAME[...] 
Deleted : user_pref("extensions.wajam.supported_sites.wikipedia.wajam_se_js", "try {window['APP_LABEL_NAME'] =[...] 
Deleted : user_pref("extensions.wajam.supported_sites.yahoo.wajam_se_js", "try {window['APP_LABEL_NAME'] = 'wa[...] 
Deleted : user_pref("extensions.wajam.supported_sites.youtubesearch.wajam_se_js", "try {window['APP_LABEL_NAME[...] 
Deleted : user_pref("extensions.wajam.trace_log", "1356976618717 - onFlagInfoReceived - Server mapping version[...] 
Deleted : user_pref("extensions.wajam.unique_id", "D6FE8B73C8A3F2F8DE3960D9267BB3BF"); 
Deleted : user_pref("extensions.wajam.user_current_mapping_version", "0"); 
Deleted : user_pref("extensions.wajam.version", "1.26"); 
Deleted : user_pref("extensions.wajam.website_version", "1.00266.0"); 
Deleted : user_pref("keyword.URL", "hxxp://search.babylon.com/?affID=110824&tt=4812_3&babsrc=KW_ss&mntrId=16c9[...]   
-\\ Google Chrome v [Unable to get version]   
File : C:\Users\afshin3\AppData\Local\Google\Chrome\User Data\Default\Preferences   
Deleted [l.7] : search_url = "hxxp://search.babylon.com/?babsrc=SP_ss&q={searchTerms}&mntrId=16c9c05100000000[...] 
Deleted [l.92] : homepage = "hxxp://search.babylon.com/?babsrc=HP_ss&mntrId=16c9c051000000000000001377649987&tlve[...]   
*************************   
AdwCleaner[R1].txt - [6088 octets] - [24/04/2013 18:34:17] 
AdwCleaner[S1].txt - [6168 octets] - [24/04/2013 18:34:45]   
########## EOF - C:\AdwCleaner[S1].txt - [6228 octets] ##########    Code:  
 OTL logfile created on: 24.04.2013 19:26:14 - Run 3 
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\afshin3\Desktop 
 Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation 
Internet Explorer (Version = 9.10.9200.16540) 
Locale: 00000407 | Country: Germany | Language: DEU | Date Format: dd.MM.yyyy 
  
1,75 Gb Total Physical Memory | 0,95 Gb Available Physical Memory | 54,21% Memory free 
3,50 Gb Paging File | 2,56 Gb Available in Paging File | 73,16% Paging File free 
Paging file location(s): ?:\pagefile.sys [binary data] 
  
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files 
Drive C: | 50,79 Gb Total Space | 27,89 Gb Free Space | 54,91% Space Free | Partition Type: NTFS 
Drive D: | 51,00 Gb Total Space | 21,51 Gb Free Space | 42,17% Space Free | Partition Type: NTFS 
  
Computer Name: AFSHIN3-PC | User Name: afshin3 | Logged in as Administrator. 
Boot Mode: Normal | Scan Mode: All users 
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days 
   ========== Processes (SafeList) ========== 
  
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) 
PRC - C:\Users\afshin3\Desktop\OTL.exe (OldTimer Tools) 
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated) 
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation) 
PRC - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO) 
PRC - C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO) 
PRC - C:\Program Files\Kodak\AiO\Center\EKAiOHostService.exe (Eastman Kodak Company) 
PRC - C:\Program Files\Kodak\AiO\StatusMonitor\EKPrinterSDK.exe (Eastman Kodak Company) 
PRC - C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe (Eastman Kodak Company) 
PRC - C:\Windows\explorer.exe (Microsoft Corporation) 
PRC - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom) 
PRC - C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (TomTom) 
PRC - C:\Program Files\Intense Language Office\Common\OffMan.exe () 
  
   ========== Modules (No Company Name) ========== 
  
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll () 
MOD - C:\Program Files\Intense Language Office\Common\OffMan.exe () 
  
   ========== Services (SafeList) ========== 
  
SRV - (MozillaMaintenance) -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation) 
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated) 
SRV - (AdobeARMservice) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated) 
SRV - (cmdAgent) -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO) 
SRV - (Kodak AiO Network Discovery Service) -- C:\Program Files\Kodak\AiO\Center\EKAiOHostService.exe (Eastman Kodak Company) 
SRV - (Kodak AiO Status Monitor Service) -- C:\Program Files\Kodak\AiO\StatusMonitor\EKPrinterSDK.exe (Eastman Kodak Company) 
SRV - (SkypeUpdate) -- C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies) 
SRV - (WatAdminSvc) -- C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation) 
SRV - (TomTomHOMEService) -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom) 
SRV - (StorSvc) -- C:\Windows\System32\StorSvc.dll (Microsoft Corporation) 
SRV - (SensrSvc) -- C:\Windows\System32\sensrsvc.dll (Microsoft Corporation) 
SRV - (PeerDistSvc) -- C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation) 
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation) 
  
   ========== Driver Services (SafeList) ========== 
  
DRV - (hwdatacard) -- system32\DRIVERS\ewusbmdm.sys File not found 
DRV - (huawei_enumerator) -- system32\DRIVERS\ew_jubusenum.sys File not found 
DRV - (ewusbnet) -- system32\DRIVERS\ewusbnet.sys File not found 
DRV - (ew_hwusbdev) -- system32\DRIVERS\ew_hwusbdev.sys File not found 
DRV - (catchme) -- C:\Users\afshin3\AppData\Local\Temp\catchme.sys File not found 
DRV - (inspect) -- C:\Windows\System32\drivers\inspect.sys (COMODO) 
DRV - (cmdHlp) -- C:\Windows\System32\drivers\cmdhlp.sys (COMODO) 
DRV - (cmdGuard) -- C:\Windows\System32\drivers\cmdGuard.sys (COMODO) 
DRV - (cmderd) -- C:\Windows\System32\drivers\cmderd.sys (COMODO) 
DRV - (AF15BDA) -- C:\Windows\System32\drivers\AF15BDA.sys (ITETech                  ) 
DRV - (vmbus) -- C:\Windows\System32\drivers\vmbus.sys (Microsoft Corporation) 
DRV - (storflt) -- C:\Windows\System32\drivers\vmstorfl.sys (Microsoft Corporation) 
DRV - (storvsc) -- C:\Windows\System32\drivers\storvsc.sys (Microsoft Corporation) 
DRV - (TsUsbFlt) -- C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation) 
DRV - (WinUsb) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation) 
DRV - (VMBusHID) -- C:\Windows\System32\drivers\VMBusHID.sys (Microsoft Corporation) 
DRV - (s3cap) -- C:\Windows\System32\drivers\vms3cap.sys (Microsoft Corporation) 
DRV - (vwifimp) -- C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation) 
DRV - (AgereSoftModem) -- C:\Windows\System32\drivers\AGRSM.sys (LSI Corp) 
DRV - (yukonw7) -- C:\Windows\System32\drivers\yk62x86.sys (Marvell) 
DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.) 
DRV - (hxctlflt) -- C:\Windows\System32\drivers\hxctlflt.sys (Guillemot Corporation) 
DRV - (atikmdag) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.) 
DRV - (WDC_SAM) -- C:\Windows\System32\drivers\wdcsam.sys (Western Digital Technologies) 
DRV - (SNPSTD3) -- C:\Windows\System32\drivers\snpstd3.sys (Sonix Co. Ltd.) 
DRV - (Afc) -- C:\Windows\System32\drivers\afc.sys (Arcsoft, Inc.) 
  
   ========== Standard Registry (SafeList) ========== 
  
   ========== Internet Explorer ========== 
  
IE - HKLM\..\SearchScopes,DefaultScope =  
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC 
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 
  
  
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =  
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 
  
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =  
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 
  
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =  
  
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =  
  
IE - HKU\S-1-5-21-2499919780-2418098726-987346099-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank 
IE - HKU\S-1-5-21-2499919780-2418098726-987346099-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us 
IE - HKU\S-1-5-21-2499919780-2418098726-987346099-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 02 5B 68 E9 1A F2 CB 01  [binary data] 
IE - HKU\S-1-5-21-2499919780-2418098726-987346099-1000\..\SearchScopes,DefaultScope =  
IE - HKU\S-1-5-21-2499919780-2418098726-987346099-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR 
IE - HKU\S-1-5-21-2499919780-2418098726-987346099-1000\..\SearchScopes\{26ED5B98-2585-48BC-9A12-50E2336F61D6}: "URL" = hxxp://de.search.yahoo.com/search?p={searchterms}&ei=UTF-8&fr=w3i&type=W3i_DS,136,0_0,Search,20110415,16987,0,8,0 
IE - HKU\S-1-5-21-2499919780-2418098726-987346099-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC 
IE - HKU\S-1-5-21-2499919780-2418098726-987346099-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 
IE - HKU\S-1-5-21-2499919780-2418098726-987346099-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:60444 
   ========== FireFox ========== 
  
FF - prefs.js..extensions.enabledAddons: %7B635abd67-4fe9-1b23-4f01-e679fa7484c1%7D:2.5.9.20130409112616 
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:20.0.1 
FF - user.js - File not found 
  
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_6_602_180.dll () 
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found 
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.0.61118.0\npctrl.dll ( Microsoft Corporation) 
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.633: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) 
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.633: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.) 
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.633: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) 
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.633: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.) 
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=:  File not found 
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) 
  
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011.04.04 04:46:56 | 000,000,000 | -H-D | M] 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.04.21 11:21:54 | 000,000,000 | ---D | M] 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013.04.21 11:21:48 | 000,000,000 | ---D | M] 
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.04.21 11:21:54 | 000,000,000 | ---D | M] 
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013.04.21 11:21:48 | 000,000,000 | ---D | M] 
  
[2012.11.13 20:31:05 | 000,000,000 | -H-D | M] (No name found) -- C:\Users\afshin3\AppData\Roaming\Mozilla\Extensions 
[2012.10.03 17:59:34 | 000,000,000 | ---D | M] (No name found) -- C:\Users\afshin3\AppData\Roaming\Mozilla\Extensions\home2@tomtom.com 
[2013.04.24 18:35:07 | 000,000,000 | ---D | M] (No name found) -- C:\Users\afshin3\AppData\Roaming\Mozilla\Firefox\Profiles\6vvjwyse.default\extensions 
[2013.04.21 13:51:31 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\afshin3\AppData\Roaming\Mozilla\Firefox\Profiles\6vvjwyse.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} 
[2013.04.21 11:21:48 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions 
[2013.04.21 11:21:54 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll 
[2012.09.24 09:56:39 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml 
[2013.02.19 20:38:50 | 000,002,086 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml 
   ========== Chrome  ========== 
  
CHR - default_search_provider: Search the web (Babylon) () 
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding} 
CHR - default_search_provider: suggest_url =  
CHR - homepage: hxxp://www.google.com/ 
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Users\afshin3\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.3_0\ 
  
O1 HOSTS File: ([2013.04.23 19:43:21 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts 
O1 - Hosts: 127.0.0.1       localhost 
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer) 
O3 - HKU\S-1-5-21-2499919780-2418098726-987346099-1000\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found. 
O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO) 
O4 - HKLM..\Run: [Conime] %windir%\system32\conime.exe File not found 
O4 - HKLM..\Run: [EKIJ5000StatusMonitor] C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe (Eastman Kodak Company) 
O4 - HKLM..\Run: [EKStatusMonitor] C:\Program Files\Kodak\AiO\StatusMonitor\EKStatusMonitor.exe (Eastman Kodak Company) 
O4 - HKU\S-1-5-21-2499919780-2418098726-987346099-1000..\Run: [ILO_Office_Manager] C:\Windows\System32\intedreg.exe () 
O4 - HKU\S-1-5-21-2499919780-2418098726-987346099-1000..\Run: [TomTomHOME.exe] C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (TomTom) 
O4 - HKU\.DEFAULT..\RunOnce: [KodakHomeCenter] C:\Program Files\Kodak\AiO\Center\AiOHomeCenter.exe (Eastman Kodak Company) 
O4 - HKU\S-1-5-18..\RunOnce: [KodakHomeCenter] C:\Program Files\Kodak\AiO\Center\AiOHomeCenter.exe (Eastman Kodak Company) 
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present 
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present 
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\control panel present 
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\control panel present 
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\control panel present 
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\control panel present 
O7 - HKU\S-1-5-21-2499919780-2418098726-987346099-1000\Software\Policies\Microsoft\Internet Explorer\control panel present 
O7 - HKU\S-1-5-21-2499919780-2418098726-987346099-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html File not found 
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{49DA8658-2237-452F-8942-D2F2235D4E29}: DhcpNameServer = 192.168.2.1 
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{49DA8658-2237-452F-8942-D2F2235D4E29}: NameServer = 8.26.56.26,156.154.70.22 
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F35B6E81-FB01-421F-BBF3-52D02468DC4B}: NameServer = 8.26.56.26,156.154.70.22 
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) 
O20 - AppInit_DLLs: (C:\Windows\System32\guard32.dll) - C:\Windows\System32\guard32.dll (COMODO) 
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) 
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) 
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) 
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. 
O32 - HKLM CDRom: AutoRun - 1 
O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] 
O34 - HKLM BootExecute: (autocheck autochk *) 
O35 - HKLM\..comfile [open] -- "%1" %* 
O35 - HKLM\..exefile [open] -- "%1" %* 
O37 - HKLM\...com [@ = ComFile] -- "%1" %* 
O37 - HKLM\...exe [@ = exefile] -- "%1" %* 
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) 
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) 
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) 
   ========== Files/Folders - Created Within 30 Days ========== 
  
[2013.04.24 18:17:39 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT 
[2013.04.24 18:17:21 | 000,000,000 | ---D | C] -- C:\JRT 
[2013.04.24 17:59:29 | 000,535,764 | ---- | C] (Oleg N. Scherbakov) -- C:\Users\afshin3\Desktop\JRT.exe 
[2013.04.23 19:46:03 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN 
[2013.04.23 19:46:00 | 000,000,000 | ---D | C] -- C:\Windows\temp 
[2013.04.23 19:46:00 | 000,000,000 | ---D | C] -- C:\Users\afshin3\AppData\Local\temp 
[2013.04.23 19:31:04 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe 
[2013.04.23 19:31:04 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe 
[2013.04.23 19:31:04 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe 
[2013.04.23 19:18:33 | 000,000,000 | ---D | C] -- C:\Qoobox 
[2013.04.23 19:18:12 | 000,000,000 | ---D | C] -- C:\Windows\erdnt 
[2013.04.23 19:14:30 | 005,059,674 | R--- | C] (Swearware) -- C:\Users\afshin3\Desktop\ComboFix.exe 
[2013.04.21 14:10:00 | 002,706,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb 
[2013.04.21 14:09:58 | 002,877,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll 
[2013.04.21 14:09:58 | 000,061,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll 
[2013.04.21 14:09:58 | 000,039,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll 
[2013.04.21 14:09:57 | 000,493,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll 
[2013.04.21 14:09:57 | 000,391,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll 
[2013.04.21 14:09:56 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll 
[2013.04.21 14:09:56 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe 
[2013.04.21 14:09:56 | 000,042,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe 
[2013.04.21 14:09:56 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll 
[2013.04.21 14:02:30 | 002,237,968 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\afshin3\Desktop\tdsskiller.exe 
[2013.04.21 13:53:33 | 004,745,728 | ---- | C] (AVAST Software) -- C:\Users\afshin3\Desktop\aswMBR.exe 
[2013.04.21 12:41:28 | 000,000,000 | ---D | C] -- C:\Avenger 
[2013.04.21 11:48:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes 
[2013.04.21 11:44:42 | 000,000,000 | ---D | C] -- C:\Users\afshin3\Desktop\mbar 
[2013.04.21 11:21:48 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox 
[2013.04.21 10:46:23 | 002,347,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys 
[2013.04.21 10:46:19 | 003,913,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe 
[2013.04.21 10:46:18 | 003,968,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe 
[2013.04.21 10:46:16 | 000,038,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\csrsrv.dll 
[2013.04.21 10:46:03 | 000,131,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\aaclient.dll 
[2013.04.21 10:46:03 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tsgqec.dll 
[2013.04.07 18:04:15 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\afshin3\Desktop\OTL.exe 
[2013.04.07 17:05:01 | 000,000,000 | ---D | C] -- C:\Users\afshin3\AppData\Local\Eraser 6 
[2013.04.06 22:24:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy 
[2013.04.06 22:23:45 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy 2 
[2013.04.06 22:18:37 | 000,000,000 | ---D | C] -- C:\Users\afshin3\AppData\Local\Programs 
[2013.04.06 22:04:39 | 000,000,000 | ---D | C] -- C:\Program Files\HashTab Shell Extension 
[2013.04.02 20:37:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PrintProjects 
[2013.04.02 20:37:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Visan 
[2013.04.02 20:37:23 | 000,000,000 | ---D | C] -- C:\ProgramData\PrintProjects 
[2013.04.02 20:37:23 | 000,000,000 | ---D | C] -- C:\Program Files\PrintProjects 
[2013.03.30 18:19:38 | 000,745,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MsSpellCheckingFacility.exe 
[2013.03.30 18:19:38 | 000,185,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\elshyph.dll 
[2013.03.30 18:19:27 | 000,158,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll 
[2013.03.30 18:19:25 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll 
[2013.03.30 18:19:24 | 000,082,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll 
[2013.03.30 18:19:23 | 000,150,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe 
[2013.03.30 18:19:23 | 000,138,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe 
[2013.03.30 18:19:21 | 000,137,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe 
[2013.03.30 18:19:19 | 000,057,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll 
[2013.03.30 18:19:18 | 000,038,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll 
[2013.03.30 18:19:17 | 000,117,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll 
[2013.03.30 18:19:17 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll 
[2013.03.30 18:19:16 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll 
[2013.03.30 18:19:16 | 000,011,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe 
[2013.03.30 18:19:14 | 000,073,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe 
[2013.03.30 18:19:14 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll 
[2013.03.30 18:19:10 | 000,361,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec 
[2013.03.30 18:19:10 | 000,226,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll 
[2013.03.30 18:19:09 | 000,357,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll 
[2013.03.30 18:19:08 | 001,400,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat 
[2013.03.30 18:19:08 | 000,629,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll 
[2013.03.30 18:19:07 | 000,232,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll 
[2013.03.30 18:19:06 | 000,719,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmlmedia.dll 
[2013.03.30 18:19:06 | 000,242,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll 
[2013.03.30 18:19:05 | 001,441,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl 
[2013.03.30 18:19:04 | 000,023,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll 
[2011.10.23 11:50:41 | 000,227,328 | ---- | C] (Microsoft Corporation) -- C:\Users\afshin3\taskmgr.exe 
[2011.04.04 05:09:21 | 011,193,664 | ---- | C] (DT Soft Ltd.) -- C:\Users\afshin3\DTLite4402-0131.exe 
[2011.04.04 04:45:15 | 000,606,560 | ---- | C] (RealNetworks, Inc.) -- C:\Users\afshin3\RealPlayer_de.exe 
[2006.07.28 13:33:26 | 000,212,992 | ---- | C] (OXY Solution) -- C:\Program Files\CardBurner.exe 
[2003.03.18 21:20:00 | 001,060,864 | ---- | C] (Microsoft Corporation) -- C:\Program Files\mfc71.dll 
[2003.03.18 21:12:12 | 001,047,552 | ---- | C] (Microsoft Corporation) -- C:\Program Files\mfc71u.dll 
[2003.02.21 04:42:22 | 000,348,160 | ---- | C] (Microsoft Corporation) -- C:\Program Files\msvcr71.dll 
   ========== Files - Modified Within 30 Days ========== 
  
[2013.04.24 20:06:49 | 001,474,832 | ---- | M] () -- C:\Windows\System32\drivers\sfi.dat 
[2013.04.24 19:58:02 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job 
[2013.04.24 18:44:21 | 000,014,976 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 
[2013.04.24 18:44:21 | 000,014,976 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 
[2013.04.24 18:37:24 | 000,000,316 | ---- | M] () -- C:\Windows\tasks\GlaryInitialize.job 
[2013.04.24 18:36:56 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat 
[2013.04.24 18:36:53 | 1407,848,448 | -HS- | M] () -- C:\hiberfil.sys 
[2013.04.24 18:00:37 | 000,619,461 | ---- | M] () -- C:\Users\afshin3\Desktop\adwcleaner.exe 
[2013.04.24 17:59:35 | 000,535,764 | ---- | M] (Oleg N. Scherbakov) -- C:\Users\afshin3\Desktop\JRT.exe 
[2013.04.23 19:43:21 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts 
[2013.04.23 19:14:36 | 005,059,674 | R--- | M] (Swearware) -- C:\Users\afshin3\Desktop\ComboFix.exe 
[2013.04.22 20:14:14 | 000,624,412 | ---- | M] () -- C:\Windows\System32\perfh009.dat 
[2013.04.22 20:14:14 | 000,106,756 | ---- | M] () -- C:\Windows\System32\perfc009.dat 
[2013.04.21 19:45:47 | 000,286,344 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT 
[2013.04.21 14:02:31 | 002,237,968 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\afshin3\Desktop\tdsskiller.exe 
[2013.04.21 14:00:17 | 000,000,512 | ---- | M] () -- C:\Users\afshin3\Desktop\MBR.dat 
[2013.04.21 13:54:54 | 004,745,728 | ---- | M] (AVAST Software) -- C:\Users\afshin3\Desktop\aswMBR.exe 
[2013.04.08 17:52:52 | 000,044,848 | ---- | M] () -- C:\Users\afshin3\Desktop\Comodo Log 08.04.2013.htm 
[2013.04.07 19:10:56 | 000,377,856 | ---- | M] () -- C:\Users\afshin3\Desktop\gmer_2.1.19163.exe 
[2013.04.07 18:04:16 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\afshin3\Desktop\OTL.exe 
[2013.04.07 18:03:29 | 000,000,000 | ---- | M] () -- C:\Users\afshin3\defogger_reenable 
[2013.04.02 20:33:39 | 000,002,114 | ---- | M] () -- C:\Users\Public\Desktop\KODAK AiO Home Center.lnk 
[2013.04.02 20:30:58 | 000,002,045 | ---- | M] () -- C:\Users\Public\Desktop\Get CleanPrint.lnk 
[2013.03.30 18:19:38 | 000,745,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MsSpellCheckingFacility.exe 
[2013.03.30 18:19:38 | 000,185,344 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\elshyph.dll 
[2013.03.30 18:19:27 | 000,158,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll 
[2013.03.30 18:19:25 | 000,163,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll 
[2013.03.30 18:19:25 | 000,082,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll 
[2013.03.30 18:19:23 | 000,150,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe 
[2013.03.30 18:19:23 | 000,138,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe 
[2013.03.30 18:19:21 | 000,137,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe 
[2013.03.30 18:19:19 | 000,057,344 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll 
[2013.03.30 18:19:18 | 000,038,400 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll 
[2013.03.30 18:19:17 | 000,117,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll 
[2013.03.30 18:19:17 | 000,041,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll 
[2013.03.30 18:19:16 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll 
[2013.03.30 18:19:16 | 000,011,776 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe 
[2013.03.30 18:19:14 | 000,073,728 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe 
[2013.03.30 18:19:14 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll 
[2013.03.30 18:19:10 | 000,361,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\html.iec 
[2013.03.30 18:19:10 | 000,226,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll 
[2013.03.30 18:19:09 | 000,357,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll 
[2013.03.30 18:19:08 | 001,400,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat 
[2013.03.30 18:19:08 | 000,629,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll 
[2013.03.30 18:19:07 | 000,232,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\url.dll 
[2013.03.30 18:19:07 | 000,025,185 | ---- | M] () -- C:\Windows\System32\ieuinit.inf 
[2013.03.30 18:19:06 | 000,719,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtmlmedia.dll 
[2013.03.30 18:19:06 | 000,242,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll 
[2013.03.30 18:19:05 | 001,441,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl 
[2013.03.30 18:19:04 | 000,023,040 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll 
   ========== Files Created - No Company Name ========== 
  
[2013.04.24 18:00:35 | 000,619,461 | ---- | C] () -- C:\Users\afshin3\Desktop\adwcleaner.exe 
[2013.04.23 19:31:04 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe 
[2013.04.23 19:31:04 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe 
[2013.04.23 19:31:04 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe 
[2013.04.23 19:31:04 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe 
[2013.04.23 19:31:04 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe 
[2013.04.21 14:00:17 | 000,000,512 | ---- | C] () -- C:\Users\afshin3\Desktop\MBR.dat 
[2013.04.08 17:52:52 | 000,044,848 | ---- | C] () -- C:\Users\afshin3\Desktop\Comodo Log 08.04.2013.htm 
[2013.04.07 19:10:54 | 000,377,856 | ---- | C] () -- C:\Users\afshin3\Desktop\gmer_2.1.19163.exe 
[2013.04.07 18:03:29 | 000,000,000 | ---- | C] () -- C:\Users\afshin3\defogger_reenable 
[2013.04.02 20:33:39 | 000,002,114 | ---- | C] () -- C:\Users\Public\Desktop\KODAK AiO Home Center.lnk 
[2013.04.02 20:30:58 | 000,002,045 | ---- | C] () -- C:\Users\Public\Desktop\Get CleanPrint.lnk 
[2013.03.30 18:19:07 | 000,025,185 | ---- | C] () -- C:\Windows\System32\ieuinit.inf 
[2013.03.14 20:49:47 | 000,000,118 | ---- | C] () -- C:\Windows\System32\MRT.INI 
[2011.08.24 08:22:21 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin 
[2011.08.11 17:08:52 | 001,474,832 | ---- | C] () -- C:\Windows\System32\drivers\sfi.dat 
[2011.07.26 17:22:00 | 000,015,428 | ---- | C] () -- C:\Users\afshin3\RefEdit.exd 
[2011.07.15 09:42:53 | 000,000,000 | ---- | C] () -- C:\Users\afshin3\AppData\Local\{ED8D64B9-37E5-435F-A739-1A5B063B4035} 
[2011.06.15 21:11:34 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe 
[2011.05.28 02:54:09 | 000,000,136 | -H-- | C] () -- C:\ProgramData\~37673988 
[2011.05.21 19:33:54 | 000,000,000 | ---- | C] () -- C:\Users\afshin3\AppData\Local\{BB9D2246-53EC-47D6-B18C-E16A21D48890} 
[2011.04.05 21:34:18 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat 
[2011.04.05 20:12:03 | 000,005,115 | -H-- | C] () -- C:\ProgramData\mtbjfghn.xbe 
[2006.07.28 13:29:14 | 000,000,367 | ---- | C] () -- C:\Program Files\MyList.mft 
[2006.05.30 16:03:32 | 000,025,893 | ---- | C] () -- C:\Program Files\Card Burner upotreba.xml 
[2005.11.15 11:25:50 | 005,823,050 | ---- | C] () -- C:\Program Files\Salif Keita - 03 - Madan.mp3 
[2005.11.01 15:46:06 | 002,753,515 | ---- | C] () -- C:\Program Files\La_Flaca.mp3 
[2003.10.18 06:37:10 | 004,006,266 | ---- | C] () -- C:\Program Files\ABBA - Super Trooper.mp3 
[2003.10.18 06:36:58 | 003,658,106 | ---- | C] () -- C:\Program Files\Blonde - Atomic.mp3 
   ========== ZeroAccess Check ========== 
  
[2009.07.14 06:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini 
  
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] 
  
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] 
  
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] 
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 06:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation) 
"ThreadingModel" = Apartment 
  
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] 
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 14:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation) 
"ThreadingModel" = Free 
  
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] 
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.07.14 03:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation) 
"ThreadingModel" = Both   
< End of report >    Code:  
 OTL Extras logfile created on: 24.04.2013 19:26:14 - Run 3 
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\afshin3\Desktop 
 Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation 
Internet Explorer (Version = 9.10.9200.16540) 
Locale: 00000407 | Country: Germany | Language: DEU | Date Format: dd.MM.yyyy 
  
1,75 Gb Total Physical Memory | 0,95 Gb Available Physical Memory | 54,21% Memory free 
3,50 Gb Paging File | 2,56 Gb Available in Paging File | 73,16% Paging File free 
Paging file location(s): ?:\pagefile.sys [binary data] 
  
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files 
Drive C: | 50,79 Gb Total Space | 27,89 Gb Free Space | 54,91% Space Free | Partition Type: NTFS 
Drive D: | 51,00 Gb Total Space | 21,51 Gb Free Space | 42,17% Space Free | Partition Type: NTFS 
  
Computer Name: AFSHIN3-PC | User Name: afshin3 | Logged in as Administrator. 
Boot Mode: Normal | Scan Mode: All users 
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days 
   ========== Extra Registry (SafeList) ========== 
  
   ========== File Associations ========== 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] 
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) 
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) 
.html [@ = Reg Error: Value error.] -- Reg Error: Key error. File not found 
.jse [@ = JSEFile] -- C:\Windows\System32\CScript.exe (Microsoft Corporation) 
.wsf [@ = WSFFile] -- C:\Windows\System32\CScript.exe (Microsoft Corporation) 
  
[HKEY_USERS\S-1-5-21-2499919780-2418098726-987346099-1000\SOFTWARE\Classes\<extension>] 
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) 
   ========== Shell Spawning ========== 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] 
batfile [open] -- "%1" %* 
cmdfile [open] -- "%1" %* 
comfile [open] -- "%1" %* 
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) 
exefile [open] -- "%1" %* 
helpfile [open] -- Reg Error: Key error. 
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) 
htmlfile [edit] -- Reg Error: Key error. 
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) 
jsefile [open] -- %SystemRoot%\System32\CScript.exe "%1" %* (Microsoft Corporation) 
piffile [open] -- "%1" %* 
regfile [merge] -- Reg Error: Key error. 
scrfile [config] -- "%1" 
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l 
scrfile [open] -- "%1" /S 
txtfile [edit] -- Reg Error: Key error. 
wsffile [open] -- %SystemRoot%\System32\CScript.exe "%1" %* (Microsoft Corporation) 
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) 
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
Folder [explore] -- Reg Error: Value error. 
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
   ========== Security Center Settings ========== 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] 
"cval" = 1 
"FirewallDisableNotify" = 0 
"AntiVirusDisableNotify" = 0 
"UpdatesDisableNotify" = 0 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] 
"VistaSp1" = Reg Error: Unknown registry data type -- File not found 
"AntiVirusOverride" = 0 
"AntiSpywareOverride" = 0 
"FirewallOverride" = 0 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] 
   ========== System Restore Settings ========== 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] 
"DisableSR" = 0 
   ========== Firewall Settings ========== 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile] 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] 
"DisableNotifications" = 0 
"EnableFirewall" = 0 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 
"DisableNotifications" = 0 
"EnableFirewall" = 0 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] 
"DisableNotifications" = 0 
"EnableFirewall" = 0 
   ========== Authorized Applications List ========== 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] 
  
   ========== Vista Active Open Ports Exception List ========== 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] 
"{1D5B3B02-B9EA-4261-AC8F-57CC13F3CCE8}" = lport=2869 | protocol=6 | dir=in | app=system |  
"{24A73305-7487-4D37-81FB-C561EAB47B6C}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |  
"{52443A2A-29EF-4CBE-B331-EF35E18CB1BC}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |  
"{585FFDE5-E5A4-4F80-95D3-19430175BB2A}" = lport=10243 | protocol=6 | dir=in | app=system |  
"{5FC414DF-7217-40CE-B4EE-5090CB7ED6A8}" = rport=10243 | protocol=6 | dir=out | app=system |  
"{6DAD194B-864A-4AB7-87B4-8B4CE340B683}" = lport=5353 | protocol=17 | dir=in | name=bonjour port 5353 |  
"{6EE563F1-2273-422B-BCB2-0C8BCF87AFDC}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |  
"{70EEB091-2935-463F-94F2-FE589F288ED1}" = lport=9322 | protocol=6 | dir=in | name=ekdiscovery |  
"{7D4F7821-1A14-4EAC-A26C-0AD0824D4E5D}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |  
"{B178C977-397F-4768-B556-3E47BF33BF4E}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |  
"{B6EC3B30-BBB6-44E5-AACE-47CD0F303260}" = lport=9322 | protocol=6 | dir=in | name=ekdiscovery |  
"{CAAE12F8-AF9A-4F6E-9112-ED74115B11DF}" = lport=5353 | protocol=17 | dir=in | name=bonjour port 5353 |  
"{ECB3E4FF-B004-4B32-86B6-2EEE599B0943}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |  
   ========== Vista Active Application Exception List ========== 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] 
"{0AAE40B3-B02F-4D2C-931A-80F82027ED01}" = protocol=6 | dir=in | app=c:\program files\msi\arcsoft\totalmedia\totalmedia.exe |  
"{0CD39F31-2967-4791-896E-450D7B2F3A90}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |  
"{1045495B-BCA2-4FCE-B902-5EEC2D0FB210}" = protocol=17 | dir=in | app=c:\program files\kodak\aio\center\networkprinterdiscovery.exe |  
"{10A6A2B1-0522-46BF-96E1-E9F891A716D8}" = protocol=6 | dir=in | app=c:\program files\kodak\aio\center\kodak.statistics.exe |  
"{18F82BF0-B855-41D8-89F8-DD354F59C23E}" = dir=in | app=c:\program files\skype\phone\skype.exe |  
"{1C9EAC22-707C-430C-885B-4FD64EA6F422}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |  
"{1E8061EB-A0E6-4449-ABDC-335386A88E77}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |  
"{2C942CBE-7A47-4AC9-94FE-47ABB3860C28}" = protocol=17 | dir=in | app=c:\program files\kodak\aio\center\networkprinterdiscovery.exe |  
"{314C04AA-2DD2-4E58-9603-1994027C2945}" = protocol=17 | dir=in | app=c:\program files\msi\arcsoft\totalmedia\totalmedia.exe |  
"{410DF6CD-5162-4864-BEBE-422F30B63648}" = protocol=6 | dir=out | app=system |  
"{49CC08C6-A875-403B-9300-B5F394738ED8}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |  
"{4C8978BF-DDAD-4778-B02A-3ACF01F2FABE}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |  
"{50FBDCB5-AF22-4266-B8F4-5EBE335F3AC8}" = protocol=6 | dir=in | app=c:\program files\kodak\aio\firmware\kodakaioupdater.exe |  
"{575009AE-140A-42EF-887F-BA645B75D044}" = protocol=6 | dir=in | app=c:\program files\kodak\aio\center\aiohomecenter.exe |  
"{6046089B-C609-4B12-9119-E87429D9F276}" = protocol=17 | dir=in | app=c:\program files\kodak\aio\firmware\kodakaioupdater.exe |  
"{6E7226CD-5C1F-4FBC-B8C7-81EBD3085198}" = protocol=6 | dir=in | app=c:\programdata\kodak\installer\setup.exe |  
"{6FD34CB4-E4B2-4062-BE08-C08823FA15AD}" = protocol=6 | dir=in | app=c:\program files\kodak\aio\center\networkprinterdiscovery.exe |  
"{70AA399A-697C-4531-9800-0CFFCE4BC10D}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |  
"{8B76BC7B-9DB1-4A2F-9C18-F46DBC393120}" = protocol=17 | dir=in | app=c:\program files\kodak\aio\center\aiohomecenter.exe |  
"{9DFE6763-E414-42B4-B7A8-65376C154C7E}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |  
"{A30858AB-FECF-42B8-9625-EDE00FC6249F}" = protocol=17 | dir=in | app=c:\programdata\kodak\installer\setup.exe |  
"{A6DFB519-CA89-40F9-A0E0-C4A9BF6A6878}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |  
"{A80B1371-3858-402B-837E-917477B071E7}" = protocol=6 | dir=in | app=c:\program files\kodak\aio\center\networkprinterdiscovery.exe |  
"{B7B2B037-F638-4057-974E-9BE0B38C6AB2}" = protocol=17 | dir=in | app=c:\program files\kodak\aio\center\kodak.statistics.exe |  
"{BAFCEDA9-D32C-48BD-A55A-A1CA725F2232}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |  
"{D2A5B77E-25E4-4C7E-A384-CD56BCE17CA2}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |  
"{F89ABEEB-87E6-4E2C-A64A-AE8753B88211}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |  
"TCP Query User{524D615B-881E-406A-A2E0-D62F500F58E2}C:\program files\voipcheapcom.com\voipcheapcom\voipcheapcom.exe" = protocol=6 | dir=in | app=c:\program files\voipcheapcom.com\voipcheapcom\voipcheapcom.exe |  
"TCP Query User{79F2F4D8-5D30-48E0-85EB-77F13F0BAD05}C:\program files\voipcheapcom.com\voipcheapcom\voipcheapcom.exe" = protocol=6 | dir=in | app=c:\program files\voipcheapcom.com\voipcheapcom\voipcheapcom.exe |  
"TCP Query User{FA8F0533-7F43-4C38-BFB0-61000A7EE68D}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |  
"UDP Query User{102C492B-D110-4DC9-8CF9-D24DE3141D71}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |  
"UDP Query User{840598D4-427D-44E3-99B9-F8D347D4C76B}C:\program files\voipcheapcom.com\voipcheapcom\voipcheapcom.exe" = protocol=17 | dir=in | app=c:\program files\voipcheapcom.com\voipcheapcom\voipcheapcom.exe |  
"UDP Query User{9C34D2E7-0ED3-4614-9D4F-8823A6F45056}C:\program files\voipcheapcom.com\voipcheapcom\voipcheapcom.exe" = protocol=17 | dir=in | app=c:\program files\voipcheapcom.com\voipcheapcom\voipcheapcom.exe |  
   ========== HKEY_LOCAL_MACHINE Uninstall List ========== 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] 
"{0645A454-AD44-4F0D-99CF-6B762735AD1F}" = aioprnt 
"{1686816B-367A-4EA6-9C20-F694A5511C13}" = AS Lernen 
"{27EF8E7F-88D1-4ec5-ADE2-7E447FDF114E}" = Kodak AIO Printer 
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1 
"{376348C2-E372-48BC-A138-E896757BD86A}" = aioscnnr 
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile 
"{48B41C3A-9A92-4B81-B653-C97FEB85C910}" = C4USelfUpdater 
"{56BA241F-580C-43D2-8403-947241AAE633}" = center 
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin 
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable 
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime 
"{8678BD65-D66E-48BB-8531-91D0EF8998A1}" = Hercules Classic Silver 
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight 
"{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}" = TomTom HOME Visual Studio Merge Modules 
"{90280407-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional mit FrontPage 
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.6) 
"{AFF7E080-1974-45BF-9310-10DE1A1F5ED0}" = Adobe AIR 
"{BE94C681-68E2-4561-8ABC-8D2E799168B4}" = essentials 
"{BFBCF96F-7361-486A-965C-54B17AC35421}" = ocr 
"{CC5825C2-2F59-459B-84ED-D0D1958101FA}" = CardBurner 
"{DA5BDB2A-12F0-4343-8351-21AAEB293990}" = PreReq 
"{E0F274B7-592B-4669-8FB8-8D9825A09858}" = KODAK AiO Software 
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.8 
"{EF53BFAB-4C10-40DB-A82D-9B07111715C6}" = aioscnnr 
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 
"{FD8E178D-8B4E-42DA-B434-EFF270329B1C}" = COMODO Internet Security 
"{FF68083C-E11E-4A91-B54B-CD72AB5A0CF5}" = ArcSoft TotalMedia 3 
"Adobe AIR" = Adobe AIR 
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX 
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin 
"doPDF 7 printer_is1" = doPDF 7.2 printer 
"Glary Utilities_is1" = Glary Utilities 2.42.0.1389 
"HashTab" = HashTab 5.1.0.23 
"Intense Language Office" = Intense Language Office 
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile 
"Mozilla Firefox 20.0.1 (x86 en-US)" = Mozilla Firefox 20.0.1 (x86 en-US) 
"MozillaMaintenanceService" = Mozilla Maintenance Service 
"Nano" = Nano 1.1.1 
"PrintProjects" = PrintProjects 
"RealPlayer 12.0" = RealPlayer 
"TIPP10_is1" = TIPP10 Version 2.1.0 
"TomTom HOME" = TomTom HOME 2.7.3.1894 
   ========== HKEY_USERS Uninstall List ========== 
  
[HKEY_USERS\S-1-5-21-2499919780-2418098726-987346099-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] 
  
< End of report >      |