| Ellyamara |  19.03.2013 23:59 |         Code:  
 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 
Junkware Removal Tool (JRT) by Thisisu 
Version: 4.7.2 (03.15.2013:1) 
OS: Windows 7 Ultimate x64 
Ran by majdi ameni elvira on 19.03.2013 at 23:21:52,82 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~         
~~~ Services       
~~~ Registry Values   
Successfully deleted: [Registry Value] hkey_local_machine\software\microsoft\windows\currentversion\run\\sweetim 
Successfully deleted: [Registry Value] hkey_local_machine\software\microsoft\windows\currentversion\run\\sweetpacks communicator 
Successfully deleted: [Registry Value] hkey_local_machine\software\microsoft\internet explorer\toolbar\\{c98d5b61-b0ea-4d48-9839-1079d352d880}  
Successfully repaired: [Registry Value] hkey_current_user\software\microsoft\internet explorer\main\\Start Page 
Successfully repaired: [Registry Value] hkey_users\.default\software\microsoft\internet explorer\main\\Start Page 
Successfully repaired: [Registry Value] hkey_users\s-1-5-18\software\microsoft\internet explorer\main\\Start Page 
Successfully repaired: [Registry Value] hkey_users\s-1-5-19\software\microsoft\internet explorer\main\\Start Page 
Successfully repaired: [Registry Value] hkey_users\s-1-5-20\software\microsoft\internet explorer\main\\Start Page 
Successfully repaired: [Registry Value] hkey_users\S-1-5-21-3828282979-3244811858-1549132693-1000\software\microsoft\internet explorer\main\\Start Page 
Successfully repaired: [Registry Value] hkey_local_machine\software\microsoft\internet explorer\main\\Start Page 
Successfully repaired: [Registry Value] hkey_current_user\software\microsoft\internet explorer\searchscopes\\DefaultScope 
Successfully repaired: [Registry Value] hkey_local_machine\software\microsoft\internet explorer\searchscopes\\DefaultScope 
Successfully repaired: [Registry Value] hkey_users\.default\software\microsoft\internet explorer\searchscopes\\DefaultScope 
Successfully repaired: [Registry Value] hkey_users\s-1-5-18\software\microsoft\internet explorer\searchscopes\\DefaultScope 
Successfully repaired: [Registry Value] hkey_users\s-1-5-19\software\microsoft\internet explorer\searchscopes\\DefaultScope 
Successfully repaired: [Registry Value] hkey_users\s-1-5-20\software\microsoft\internet explorer\searchscopes\\DefaultScope 
Successfully repaired: [Registry Value] hkey_users\S-1-5-21-3828282979-3244811858-1549132693-1000\software\microsoft\internet explorer\searchscopes\\DefaultScope       
~~~ Registry Keys   
Successfully deleted: [Registry Key] hkey_local_machine\software\babylon 
Failed to delete: [Registry Key] hkey_local_machine\software\datamngr 
Failed to delete: [Registry Key] hkey_current_user\software\datamngr_toolbar 
Successfully deleted: [Registry Key] hkey_local_machine\software\ib updater 
Successfully deleted: [Registry Key] hkey_current_user\software\im 
Successfully deleted: [Registry Key] hkey_current_user\software\iminstaller 
Successfully deleted: [Registry Key] hkey_current_user\software\sweetim 
Successfully deleted: [Registry Key] hkey_local_machine\software\sweetim 
Successfully deleted: [Registry Key] hkey_current_user\software\appdatalow\software\crossrider 
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\mediaplayer.graphicsutils 
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\mediaplayer.graphicsutils.1 
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\mgmediaplayer.gifanimator 
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\mgmediaplayer.gifanimator.1 
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\prod.cap 
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\sim-packages 
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\tracing\bundlesweetimsetup_rasapi32 
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\tracing\bundlesweetimsetup_rasmancs 
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\tracing\giant savings-internalinstaller_rasapi32 
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\tracing\giant savings-internalinstaller_rasmancs 
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\tracing\giant savings_rasapi32 
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\tracing\giant savings_rasmancs 
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\tracing\incredibar_installer_rasapi32 
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\tracing\incredibar_installer_rasmancs 
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\tracing\incredibartoolbar_rasapi32 
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\tracing\incredibartoolbar_rasmancs 
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\tracing\mybabylontb_rasapi32 
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\tracing\mybabylontb_rasmancs 
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\tracing\sweetim_rasapi32 
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\tracing\sweetim_rasmancs 
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\tracing\sweetpacksupdatemanager_rasapi32 
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\tracing\sweetpacksupdatemanager_rasmancs 
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\windows\currentversion\app paths\sweetim.exe 
Failed to delete: [Registry Key] hkey_local_machine\software\wow6432node\datamngr 
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{0696f815-a3a9-490a-bb14-9ec3350b1276} 
Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\searchscopes\{0ecdf796-c2dc-4d79-a620-cce0c0a66cc9} 
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{147a976f-eee1-4377-8ea7-4716e4cdd239} 
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{5d79f641-c168-40df-a32f-bacea7509e75} 
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser helper objects\{5d79f641-c168-40df-a32f-bacea7509e75} 
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{9afb8248-617f-460d-9366-d71cdeda3179} 
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{c98d5b61-b0ea-4d48-9839-1079d352d880} 
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{cb41fc95-f1b3-4797-8bb6-1012ff62abba} 
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser helper objects\{cb41fc95-f1b3-4797-8bb6-1012ff62abba} 
Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\searchscopes\{cff4db9b-135f-47c0-9269-b4c6572fd61a} 
Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\searchscopes\{eee6c360-6118-11dc-9c72-001320c79847} 
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\internet explorer\searchscopes\{eee6c360-6118-11dc-9c72-001320c79847} 
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{fe063db1-4ec0-403e-8dd8-394c54984b2c}  
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser helper objects\{fe063db1-4ec0-403e-8dd8-394c54984b2c}        
~~~ Files       
~~~ Folders   
Successfully deleted: [Folder] "C:\ProgramData\babylon" 
Successfully deleted: [Folder] "C:\ProgramData\sweetim" 
Successfully deleted: [Folder] "C:\ProgramData\tarma installer" 
Successfully deleted: [Folder] "C:\Users\majdi ameni elvira\AppData\Roaming\babylon" 
Successfully deleted: [Folder] "C:\Users\majdi ameni elvira\AppData\Roaming\goforfiles" 
Successfully deleted: [Folder] "C:\Users\majdi ameni elvira\AppData\Roaming\opencandy" 
Successfully deleted: [Folder] "C:\Users\majdi ameni elvira\appdata\local\televisionfanatic" 
Successfully deleted: [Folder] "C:\Users\majdi ameni elvira\appdata\locallow\babylontoolbar" 
Successfully deleted: [Folder] "C:\Users\majdi ameni elvira\appdata\locallow\televisionfanatic" 
Successfully deleted: [Folder] "C:\Program Files (x86)\goforfiles" 
Successfully deleted: [Folder] "C:\Program Files (x86)\optimizer pro" 
Successfully deleted: [Folder] "C:\Program Files (x86)\perion" 
Successfully deleted: [Folder] "C:\Program Files (x86)\sweetim"       
~~~ FireFox   
Successfully deleted: [File] C:\user.js 
Successfully deleted: [File] "C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml" 
Successfully deleted: [File] C:\Users\majdi ameni elvira\AppData\Roaming\mozilla\firefox\profiles\bo9166oc.default\user.js 
Successfully deleted: [File] C:\Users\majdi ameni elvira\AppData\Roaming\mozilla\firefox\profiles\bo9166oc.default\extensions\{eee6c361-6118-11dc-9c72-001320c79847}.xpi 
Successfully deleted: [File] C:\Users\majdi ameni elvira\AppData\Roaming\mozilla\firefox\profiles\bo9166oc.default\searchplugins\mngr.xml 
Successfully deleted: [File] C:\Users\majdi ameni elvira\AppData\Roaming\mozilla\firefox\profiles\bo9166oc.default\searchplugins\my-web-search.xml 
Successfully deleted: [File] C:\Users\majdi ameni elvira\AppData\Roaming\mozilla\firefox\profiles\bo9166oc.default\searchplugins\mystart search.xml 
Successfully deleted: [File] C:\Users\majdi ameni elvira\AppData\Roaming\mozilla\firefox\profiles\bo9166oc.default\searchplugins\sweetim.xml 
Successfully deleted: [Folder] C:\Users\majdi ameni elvira\AppData\Roaming\mozilla\firefox\profiles\bo9166oc.default\extensions\ffxtlbr@incredibar.com 
Successfully deleted: [Registry Value] hkey_local_machine\software\mozilla\firefox\extensions\\64ffxtbr@televisionfanatic.com 
Successfully deleted: [Registry Value] hkey_local_machine\software\mozilla\firefox\extensions\\{336d0c35-8a85-403a-b9d2-65c292c39087} 
Successfully deleted the following from C:\Users\majdi ameni elvira\AppData\Roaming\mozilla\firefox\profiles\bo9166oc.default\prefs.js   
user_pref("avg.install.userHPSettings", "hxxp://search.babylon.com/?affID=110824&tt=4712_1&babsrc=HP_ss_cr&mntrId=1839a315000000000000062737ac3dfd"); 
user_pref("avg.install.userSPSettings", "Search the web (Babylon)"); 
user_pref("browser.newtab.url", "hxxp://home.sweetim.com/?src=97&barid={258AC3B4-38E1-11E2-8D52-802D4622B6AB}"); 
user_pref("browser.search.defaultenginename", "My Web Search"); 
user_pref("browser.search.selectedEngine", "My Web Search"); 
user_pref("browser.startup.homepage", "hxxp://home.mywebsearch.com/index.jhtml?ptb=9793F69C-12AB-4040-8A21-21C370963563&n=77fc20f8&p2=^XP^xdm284^YY^de&si=CMWkj4Ce_LQCFUmN3godw 
user_pref("extensions.BabylonToolbar.admin", false); 
user_pref("extensions.BabylonToolbar.aflt", "babsst"); 
user_pref("extensions.BabylonToolbar.appId", "{BDB69379-802F-4eaf-B541-F8DE92DD98DB}"); 
user_pref("extensions.BabylonToolbar.dfltLng", "en"); 
user_pref("extensions.BabylonToolbar.excTlbr", false); 
user_pref("extensions.BabylonToolbar.id", "1839a315000000000000062737ac3dfd"); 
user_pref("extensions.BabylonToolbar.instlDay", "15667"); 
user_pref("extensions.BabylonToolbar.instlRef", "sst"); 
user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar"); 
user_pref("extensions.BabylonToolbar.prtnrId", "babylon"); 
user_pref("extensions.BabylonToolbar.tlbrId", "irhnew"); 
user_pref("extensions.BabylonToolbar.tlbrSrchUrl", "hxxp://search.babylon.com/?babsrc=TB_def&mntrId=1839a315000000000000062737ac3dfd&q="); 
user_pref("extensions.BabylonToolbar.vrsn", "1.8.3.8"); 
user_pref("extensions.BabylonToolbar.vrsni", "1.8.3.8"); 
user_pref("extensions.BabylonToolbar_i.smplGrp", "none"); 
user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.8.3.822:01:50"); 
user_pref("extensions.crossrider.bic", "13b2f136ebd157307c2c9e06c780d584"); 
user_pref("extensions.incredibar.actvtyRptTime", "1363178958927"); 
user_pref("extensions.incredibar.admin", false); 
user_pref("extensions.incredibar.aflt", "orgnl"); 
user_pref("extensions.incredibar.afterInstallRpt", "sent"); 
user_pref("extensions.incredibar.cntry", "DE"); 
user_pref("extensions.incredibar.dfltLng", "EN"); 
user_pref("extensions.incredibar.dfltSrch", false); 
user_pref("extensions.incredibar.dfltlng", "en"); 
user_pref("extensions.incredibar.dfltsrch", "false"); 
user_pref("extensions.incredibar.did", "10643"); 
user_pref("extensions.incredibar.envrmnt", "production"); 
user_pref("extensions.incredibar.excTlbr", false); 
user_pref("extensions.incredibar.hdrMd5", "D25AD09ED0BB33979A04FA38701C4EB0"); 
user_pref("extensions.incredibar.hmpg", false); 
user_pref("extensions.incredibar.hrdid", "1839a315000000000000062737ac3dfd"); 
user_pref("extensions.incredibar.id", "1839a315000000000000062737ac3dfd"); 
user_pref("extensions.incredibar.installerproductid", "26"); 
user_pref("extensions.incredibar.instlDay", "15671"); 
user_pref("extensions.incredibar.instlRef", ""); 
user_pref("extensions.incredibar.instlday", "15671"); 
user_pref("extensions.incredibar.instlref", ""); 
user_pref("extensions.incredibar.isDcmntCmplt", false); 
user_pref("extensions.incredibar.isdcmntcmplt", "false"); 
user_pref("extensions.incredibar.keywordurl", ""); 
user_pref("extensions.incredibar.lastVrsnTs", "1.5.11.141:15:19"); 
user_pref("extensions.incredibar.mntrvrsn", "1.2.0"); 
user_pref("extensions.incredibar.newTab", false); 
user_pref("extensions.incredibar.newtab", "false"); 
user_pref("extensions.incredibar.newtaburl", ""); 
user_pref("extensions.incredibar.noFFXTlbr", false); 
user_pref("extensions.incredibar.ppd", "6666660837"); 
user_pref("extensions.incredibar.prdct", "incredibar"); 
user_pref("extensions.incredibar.productid", "26"); 
user_pref("extensions.incredibar.prtnrId", "Incredibar"); 
user_pref("extensions.incredibar.prtnrid", "Incredibar"); 
user_pref("extensions.incredibar.sg", "none"); 
user_pref("extensions.incredibar.smplGrp", "none"); 
user_pref("extensions.incredibar.smplgrp", "none"); 
user_pref("extensions.incredibar.srch", ""); 
user_pref("extensions.incredibar.srchprvdr", ""); 
user_pref("extensions.incredibar.tlbrId", "base"); 
user_pref("extensions.incredibar.tlbrSrchUrl", "hxxp://mystart.Incredibar.com/?a=6PQQWpXjtr&loc=IB_TB&i=26&search="); 
user_pref("extensions.incredibar.tlbrid", "base"); 
user_pref("extensions.incredibar.tlbrsrchurl", "hxxp://mystart.Incredibar.com/?a=6PQQWpXjtr&loc=IB_TB&i=26&search="); 
user_pref("extensions.incredibar.upn2", "6PQQWpXjtr"); 
user_pref("extensions.incredibar.upn2n", "92543995753433061"); 
user_pref("extensions.incredibar.vrsn", "1.5.11.14"); 
user_pref("extensions.incredibar.vrsnTs", "1.5.11.141:15:19"); 
user_pref("extensions.incredibar.vrsni", "1.5.11.14"); 
user_pref("extensions.incredibar.vrsnts", "1.5.11.141:15:19"); 
user_pref("extensions.incredibar_i.aflt", "orgnl"); 
user_pref("extensions.incredibar_i.dfltLng", ""); 
user_pref("extensions.incredibar_i.did", "10643"); 
user_pref("extensions.incredibar_i.excTlbr", false); 
user_pref("extensions.incredibar_i.id", "1839a315000000000000062737ac3dfd"); 
user_pref("extensions.incredibar_i.installerproductid", "26"); 
user_pref("extensions.incredibar_i.instlDay", "15671"); 
user_pref("extensions.incredibar_i.instlRef", ""); 
user_pref("extensions.incredibar_i.ms_url_id", ""); 
user_pref("extensions.incredibar_i.newTab", false); 
user_pref("extensions.incredibar_i.ppd", "6666660837"); 
user_pref("extensions.incredibar_i.prdct", "incredibar"); 
user_pref("extensions.incredibar_i.productid", "26"); 
user_pref("extensions.incredibar_i.prtnrId", "Incredibar"); 
user_pref("extensions.incredibar_i.smplGrp", "none"); 
user_pref("extensions.incredibar_i.tlbrId", "base"); 
user_pref("extensions.incredibar_i.tlbrSrchUrl", "hxxp://mystart.Incredibar.com/?a=6PQQWpXjtr&loc=IB_TB&i=26&search="); 
user_pref("extensions.incredibar_i.upn2", "6PQQWpXjtr"); 
user_pref("extensions.incredibar_i.upn2n", "92543995753433061"); 
user_pref("extensions.incredibar_i.vrsn", "1.5.11.14"); 
user_pref("extensions.incredibar_i.vrsnTs", "1.5.11.141:15:19"); 
user_pref("extensions.incredibar_i.vrsni", "1.5.11.14"); 
user_pref("extensions.kango.storage.minibar.config", "{\"name\":\"Layouts Express\",\"description\":\"Change facebook to look just the way you want it, with hundreds of unique 
user_pref("extensions.mywebsearch.prevDefaultEngine", "Search the web (Babylon)"); 
user_pref("extensions.mywebsearch.prevKwdEnabled", true); 
user_pref("extensions.mywebsearch.prevKwdURL", "hxxp://search.sweetim.com/search.asp?barid={258AC3B4-38E1-11E2-8D52-802D4622B6AB}&src=2&crg=3.1010000.10007&q="); 
user_pref("extensions.mywebsearch.prevSelectedEngine", "Search the web (Babylon)"); 
user_pref("extensions.toolbar.mindspark._64Members_.homepage", "hxxp://home.mywebsearch.com/index.jhtml?ptb=9793F69C-12AB-4040-8A21-21C370963563&n=77fc20f8&p2=^XP^xdm284^YY^de 
user_pref("extensions.toolbar.mindspark._64Members_.hp.enabled", true); 
user_pref("extensions.toolbar.mindspark._64Members_.initialized", true); 
user_pref("extensions.toolbar.mindspark._64Members_.installation.contextKey", ""); 
user_pref("extensions.toolbar.mindspark._64Members_.installation.installDate", "2013012216"); 
user_pref("extensions.toolbar.mindspark._64Members_.installation.partnerId", "^XP^xdm284^YY^de"); 
user_pref("extensions.toolbar.mindspark._64Members_.installation.partnerSubId", "CMWkj4Ce_LQCFUmN3godwloAZQ"); 
user_pref("extensions.toolbar.mindspark._64Members_.installation.success", true); 
user_pref("extensions.toolbar.mindspark._64Members_.installation.toolbarId", "9793F69C-12AB-4040-8A21-21C370963563"); 
user_pref("extensions.toolbar.mindspark._64Members_.lastActivePing", "1363610046353"); 
user_pref("extensions.toolbar.mindspark._64Members_.options.defaultSearch", true); 
user_pref("extensions.toolbar.mindspark._64Members_.options.homePageEnabled", true); 
user_pref("extensions.toolbar.mindspark._64Members_.options.keywordEnabled", true); 
user_pref("extensions.toolbar.mindspark._64Members_.options.tabEnabled", true); 
user_pref("extensions.toolbar.mindspark._64Members_.searchHistory", "facebook.com"); 
user_pref("extensions.toolbar.mindspark._64Members_.weather.location", "10001"); 
user_pref("extensions.toolbar.mindspark.hp.enabled", true); 
user_pref("extensions.toolbar.mindspark.hp.enabled.guid", "televisionfanatic@mindspark.com"); 
user_pref("extensions.toolbar.mindspark.lastInstalled", "televisionfanatic@mindspark.com"); 
user_pref("keyword.URL", "hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?st=kwd&ptb=9793F69C-12AB-4040-8A21-21C370963563&n=77fc20f8&ind=2013012216&p2=^XP^xdm284^YY^de& 
user_pref("sweetim.toolbar.RevertDialog.enable", "false"); 
user_pref("sweetim.toolbar.UserSelectedSaveSettings", "true"); 
user_pref("sweetim.toolbar.Visibility.VisibilityGuardLastUnHide", "0"); 
user_pref("sweetim.toolbar.Visibility.enable", "true"); 
user_pref("sweetim.toolbar.Visibility.intervaldays", "7"); 
user_pref("sweetim.toolbar.cargo", "3.1010000.10007"); 
user_pref("sweetim.toolbar.cda.DisableOveride.enable", "true"); 
user_pref("sweetim.toolbar.cda.HideOveride.enable", "true"); 
user_pref("sweetim.toolbar.cda.RemoveOveride.enable", "true"); 
user_pref("sweetim.toolbar.cda.returnValue", "none"); 
user_pref("sweetim.toolbar.dialogs.0.enable", "true"); 
user_pref("sweetim.toolbar.dialogs.0.handler", "chrome://sim_toolbar_package/content/optionsdialog-handler.js"); 
user_pref("sweetim.toolbar.dialogs.0.height", "335"); 
user_pref("sweetim.toolbar.dialogs.0.id", "id_options_dialog"); 
user_pref("sweetim.toolbar.dialogs.0.title", "$string.config.label;"); 
user_pref("sweetim.toolbar.dialogs.0.url", "hxxp://www.sweetim.com/simffbar/options_remote_ff.asp?lang=$locale_id;&toolbar_version=$ITEM_VERSION;&crg=$cargo;"); 
user_pref("sweetim.toolbar.dialogs.0.width", "761"); 
user_pref("sweetim.toolbar.dialogs.1.enable", "true"); 
user_pref("sweetim.toolbar.dialogs.1.handler", "chrome://sim_toolbar_package/content/exampledialog-handler.js"); 
user_pref("sweetim.toolbar.dialogs.1.height", "300"); 
user_pref("sweetim.toolbar.dialogs.1.id", "id_example_dialog"); 
user_pref("sweetim.toolbar.dialogs.1.title", "Example (unit-test) dialog"); 
user_pref("sweetim.toolbar.dialogs.1.url", "chrome://sim_toolbar_package/content/exampledialog.html"); 
user_pref("sweetim.toolbar.dialogs.1.width", "500"); 
user_pref("sweetim.toolbar.dialogs.2.enable", "true"); 
user_pref("sweetim.toolbar.dialogs.2.handler", "chrome://sim_toolbar_package/content/cdadialog-handler.js"); 
user_pref("sweetim.toolbar.dialogs.2.height", "150"); 
user_pref("sweetim.toolbar.dialogs.2.id", "id_dialog_hide_disable_remove"); 
user_pref("sweetim.toolbar.dialogs.2.title", "Option Dialog"); 
user_pref("sweetim.toolbar.dialogs.2.url", "hxxp://www.sweetim.com/simffbar/simcdadialog.asp"); 
user_pref("sweetim.toolbar.dialogs.2.width", "530"); 
user_pref("sweetim.toolbar.dnscatch.domain-blacklist", ".*.sweetim.com/.*|.*.facebook.com/.*|.*.google.com/.*|.*.google.co.in/.*|.*.google.com.br/.*|.*.google.es/.*|.*.youtube 
user_pref("sweetim.toolbar.highlight.colors", "#FFFF00,#00FFE4,#5AFF00,#0087FF,#FFCC00,#FF00F0"); 
user_pref("sweetim.toolbar.keywordUrlGuard.enable", "false"); 
user_pref("sweetim.toolbar.logger.ConsoleHandler.MinReportLevel", "7"); 
user_pref("sweetim.toolbar.logger.FileHandler.FileName", "ff-toolbar.log"); 
user_pref("sweetim.toolbar.logger.FileHandler.MaxFileSize", "200000"); 
user_pref("sweetim.toolbar.logger.FileHandler.MinReportLevel", "7"); 
user_pref("sweetim.toolbar.mode.debug", "false"); 
user_pref("sweetim.toolbar.newtab.created", "true"); 
user_pref("sweetim.toolbar.newtab.enable", "true"); 
user_pref("sweetim.toolbar.previous.browser.search.defaultenginename", "Search the web (Babylon)"); 
user_pref("sweetim.toolbar.previous.browser.search.selectedEngine", "Search the web (Babylon)"); 
user_pref("sweetim.toolbar.previous.browser.startup.homepage", "hxxp://search.babylon.com/?affID=110824&tt=4712_1&babsrc=HP_ss_cr&mntrId=1839a315000000000000062737ac3dfd"); 
user_pref("sweetim.toolbar.previous.keyword.URL", ""); 
user_pref("sweetim.toolbar.rc.url", "hxxp://www.sweetim.com/simffbar/rc.html?toolbar_version=$ITEM_VERSION;&crg=$cargo;"); 
user_pref("sweetim.toolbar.scripts.0.addcontextdiv", "true"); 
user_pref("sweetim.toolbar.scripts.0.callback", "simVerification"); 
user_pref("sweetim.toolbar.scripts.0.domain-blacklist", ""); 
user_pref("sweetim.toolbar.scripts.0.domain-whitelist", "hxxp://(www.|apps.)?facebook\\.com.*"); 
user_pref("sweetim.toolbar.scripts.0.elementid", "id_script_sim_fb"); 
user_pref("sweetim.toolbar.scripts.0.enable", "false"); 
user_pref("sweetim.toolbar.scripts.0.id", "id_script_fb"); 
user_pref("sweetim.toolbar.scripts.0.url", "hxxp://sc.sweetim.com/apps/in/fb/infb.js"); 
user_pref("sweetim.toolbar.scripts.1.addcontextdiv", "true"); 
user_pref("sweetim.toolbar.scripts.1.callback", "simVerification"); 
user_pref("sweetim.toolbar.scripts.1.domain-blacklist", ""); 
user_pref("sweetim.toolbar.scripts.1.domain-whitelist", "hxxps://(www.|apps.)?facebook\\.com.*"); 
user_pref("sweetim.toolbar.scripts.1.elementid", "id_script_sim_fb"); 
user_pref("sweetim.toolbar.scripts.1.enable", "false"); 
user_pref("sweetim.toolbar.scripts.1.id", "id_script_fb_hxxpS"); 
user_pref("sweetim.toolbar.scripts.1.url", "hxxps://sc.sweetim.com/apps/in/fb/infb.js"); 
user_pref("sweetim.toolbar.scripts.2.addcontextdiv", "false"); 
user_pref("sweetim.toolbar.scripts.2.callback", ""); 
user_pref("sweetim.toolbar.scripts.2.domain-blacklist", ".*.google..*|.*.bing..*|.*.live..*|.*.msn..*|.*.yahoo..*|.*.youtube.com.*|.*ask.com.*|.*.sweetim.com.*"); 
user_pref("sweetim.toolbar.scripts.2.domain-whitelist", ""); 
user_pref("sweetim.toolbar.scripts.2.elementid", "id_predict_include_script"); 
user_pref("sweetim.toolbar.scripts.2.enable", "false"); 
user_pref("sweetim.toolbar.scripts.2.id", "id_script_prad"); 
user_pref("sweetim.toolbar.scripts.2.url", "hxxp://cdn1.certified-apps.com/scripts/shared/enable.js?si=3104&tid=chff1"); 
user_pref("sweetim.toolbar.search.external", "<?xml version=\"1.0\"?><TOOLBAR><EXTERNAL_SEARCH engine=\"hxxp://*google.*\" param=\"q=\" /><EXTERNAL_SEARCH engine=\"hxxp://sear 
user_pref("sweetim.toolbar.search.history.capacity", "10"); 
user_pref("sweetim.toolbar.searchguard.enable", "false"); 
user_pref("sweetim.toolbar.searchguard.initialized_by_rc", "true"); 
user_pref("sweetim.toolbar.simapp_id", "{258AC3B4-38E1-11E2-8D52-802D4622B6AB}"); 
user_pref("sweetim.toolbar.urls.homepage", "hxxp://home.sweetim.com/?st=6&barid={258AC3B4-38E1-11E2-8D52-802D4622B6AB}"); 
user_pref("sweetim.toolbar.version", "1.9.0.0"); 
user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_blackList", "form=CONTLB|babsrc=toolbar|babsrc=tb_ss|invocationType=tb50-ie-aolsoftonic-tbsbox-en-us|invocatio 
user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_referrer", "hxxp://us.yhs4.search.yahoo.com/yhs/search?fr=altavista&itag=ody&q=hxxp://nonexistent.yontoo.com/| 
user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_temp_referer", "hxxp://us.yhs4.search.yahoo.com/yhs/search?fr=altavista&itag=ody&q=hxxp://nonexistent.yontoo.c 
user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_whiteList", "{\"search.babylon.com\":\"q\",\"search.sweetim.com\":\"q\",\"search.imesh.net\":\"q\",\"www.searc 
Emptied folder: C:\Users\majdi ameni elvira\AppData\Roaming\mozilla\firefox\profiles\bo9166oc.default\minidumps [168 files]       
~~~ Chrome   
Successfully deleted: [Folder] C:\Users\majdi ameni elvira\appdata\local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn 
Successfully deleted: [Registry Key] hkey_local_machine\software\google\chrome\extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd 
Successfully deleted: [Registry Key] hkey_local_machine\software\google\chrome\extensions\jcdgjdiieiljkfkdcloehkohchhpekkn 
Successfully deleted: [Registry Key] hkey_local_machine\software\google\chrome\extensions\pgafcinpmmpklohkojmllohdhomoefph       
~~~ Event Viewer Logs were cleared           
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 
Scan was completed on 19.03.2013 at 23:30:36,29 
End of JRT log 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~    Code:  
 # AdwCleaner v2.115 - Logfile created 03/20/2013 at 00:14:17 
# Updated 17/03/2013 by Xplode 
# Operating system : Windows 7 Ultimate  (64 bits) 
# User : majdi ameni elvira - MAJDIAMENIELVIR 
# Boot Mode : Normal 
# Running from : C:\Users\majdi ameni elvira\Downloads\adwcleaner.exe 
# Option [Delete]     
***** [Services] *****     
***** [Files / Folders] *****   
Folder Deleted : C:\Program Files (x86)\AskTBar 
Folder Deleted : C:\Users\majdi ameni elvira\AppData\Local\Google\Chrome\User Data\Default\Extensions\jifflliplgeajjdhmkcfnngfpgbjonjg 
Folder Deleted : C:\Users\majdi ameni elvira\AppData\Local\Google\Chrome\User Data\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj 
Folder Deleted : C:\Users\majdi ameni elvira\AppData\Roaming\Mozilla\Firefox\Profiles\bo9166oc.default\SweetPacksToolbarData 
Folder Deleted : C:\Windows\Installer\{7683B745-6060-41FD-AA75-0BBB383FEAD4}   
***** [Registry] *****   
Key Deleted : HKCU\Software\DataMngr_Toolbar 
Key Deleted : HKCU\Software\InstallCore 
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9CB65201-89C4-402C-BA80-02D8C59F9B1D} 
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FE063DB1-4EC0-403E-8DD8-394C54984B2C} 
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FE063DB9-4EC0-403E-8DD8-394C54984B2C} 
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9CB65201-89C4-402C-BA80-02D8C59F9B1D} 
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} 
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FE063DB1-4EC0-403E-8DD8-394C54984B2C} 
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FE063DB9-4EC0-403E-8DD8-394C54984B2C} 
Key Deleted : HKCU\Software\5aeddd0e53fed44 
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826} 
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB} 
Key Deleted : HKLM\Software\Classes\Installer\Features\547B38670606DF14AA57B0BB83F3AE4D 
Key Deleted : HKLM\Software\Classes\Installer\Features\EB6AF8AEEB922FA4392548F13812E50B 
Key Deleted : HKLM\Software\Classes\Installer\Products\547B38670606DF14AA57B0BB83F3AE4D 
Key Deleted : HKLM\Software\Classes\Installer\Products\EB6AF8AEEB922FA4392548F13812E50B 
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{03119103-0854-469D-807A-171568457991} 
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4D3B167E-5FD8-4276-8FD7-9DF19C1E4D19} 
Key Deleted : HKLM\Software\DataMngr 
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{04D2B915-19FF-41E9-994D-95DC898BEA43} 
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F02C0832-C85C-4B93-8C6F-9DF20121A10D} 
Key Deleted : HKLM\SOFTWARE\Wow6432Node\5aeddd0e53fed44 
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{04D2B915-19FF-41E9-994D-95DC898BEA43} 
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{13119113-0854-469D-807A-171568457991} 
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{33119133-0854-469D-807A-171568457991} 
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D} 
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{82AC53B4-164C-4B07-A016-437A8388B81A} 
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{9CB65201-89C4-402C-BA80-02D8C59F9B1D} 
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{9CB65206-89C4-402C-BA80-02D8C59F9B1D} 
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{A4A0CB15-8465-4F58-A7E5-73084EA2A064} 
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{F02C0832-C85C-4B93-8C6F-9DF20121A10D} 
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{FE063DB9-4EC0-403E-8DD8-394C54984B2C} 
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401} 
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5} 
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{23119123-0854-469D-807A-171568457991} 
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A439801C-961D-452C-AB42-7848E9CBD289} 
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{F4EBB1E2-21F3-4786-8CF4-16EC5925867F} 
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\jifflliplgeajjdhmkcfnngfpgbjonjg 
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj 
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9CB65201-89C4-402C-BA80-02D8C59F9B1D} 
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{7683B745-6060-41FD-AA75-0BBB383FEAD4} 
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{EA8FA6BE-29BE-4AF2-9352-841F83215EB0} 
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{23119123-0854-469D-807A-171568457991} 
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd 
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{9CB65206-89C4-402C-BA80-02D8C59F9B1D}] 
Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{FE063DB9-4EC0-403E-8DD8-394C54984B2C}]   
***** [Internet Browsers] *****   
-\\ Internet Explorer v9.0.8112.16470   
[OK] Registry is clean.   
-\\ Mozilla Firefox v19.0.2 (fr)   
File : C:\Users\majdi ameni elvira\AppData\Roaming\Mozilla\Firefox\Profiles\bo9166oc.default\prefs.js   
Deleted : user_pref("extensions.kango.storage.minibar.config", "{\"name\":\"Layouts Express\",\"description\":[...] 
Deleted : user_pref("extensions.kango.storage.ui.button.iconCache", "\"data:image/png;base64,iVBORw0KGgoAAAANS[...] 
Deleted : user_pref("sweetim.toolbar.scripts.0.domain-whitelist", "hxxp://(www.|apps.)?facebook\\.com.*"); 
Deleted : user_pref("sweetim.toolbar.scripts.1.domain-whitelist", "hxxps://(www.|apps.)?facebook\\.com.*"); 
Deleted : user_pref("sweetim.toolbar.search.external", "<?xml version=\"1.0\"?><TOOLBAR><EXTERNAL_SEARCH engin[...] 
Deleted : user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_whiteList", "{\"search.babylon.com\[...]   
-\\ Google Chrome v25.0.1364.172   
File : C:\Users\majdi ameni elvira\AppData\Local\Google\Chrome\User Data\Default\Preferences   
Deleted [l.38] : keyword = "search.sweetim.com", 
Deleted [l.41] : search_url = "hxxp://search.sweetim.com/search.asp?src=6&q={searchTerms}&st=6&barid={258AC3B4[...] 
Deleted [l.1920] : homepage = "hxxp://home.sweetim.com/?st=6&barid={258AC3B4-38E1-11E2-8D52-802D4622B6AB}", 
Deleted [l.2240] : urls_to_restore_on_startup = [ "hxxp://home.sweetim.com/?st=6&barid={258AC3B4-38E1-11E2-8D52-[...]   
*************************   
AdwCleaner[S1].txt - [6782 octets] - [20/03/2013 00:14:17]   
########## EOF - C:\AdwCleaner[S1].txt - [6842 octets] ##########    Code:  
 OTL logfile created on: 20.03.2013 00:20:12 - Run 3 
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\majdi ameni elvira\Downloads 
64bit- Ultimate Edition  (Version = 6.1.7600) - Type = NTWorkstation 
Internet Explorer (Version = 9.0.8112.16421) 
Locale: 00000407 | Country: Germany | Language: DEU | Date Format: dd.MM.yyyy 
  
3,98 Gb Total Physical Memory | 2,81 Gb Available Physical Memory | 70,68% Memory free 
7,96 Gb Paging File | 6,88 Gb Available in Paging File | 86,35% Paging File free 
Paging file location(s): ?:\pagefile.sys [binary data] 
  
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) 
Drive C: | 97,56 Gb Total Space | 56,89 Gb Free Space | 58,32% Space Free | Partition Type: NTFS 
Drive D: | 368,10 Gb Total Space | 368,00 Gb Free Space | 99,97% Space Free | Partition Type: NTFS 
  
Computer Name: MAJDIAMENIELVIR | User Name: majdi ameni elvira | Logged in as Administrator. 
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans 
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days 
   ========== Processes (SafeList) ========== 
  
PRC - C:\Users\majdi ameni elvira\Downloads\OTL.exe (OldTimer Tools) 
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) 
PRC - C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe (McAfee, Inc.) 
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation) 
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation) 
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) 
PRC - C:\Program Files (x86)\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated) 
  
   ========== Modules (No Company Name) ========== 
  
MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll () 
  
   ========== Services (SafeList) ========== 
  
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation) 
SRV:64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation) 
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated) 
SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation) 
SRV - (McComponentHostService) -- C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe (McAfee, Inc.) 
SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation) 
SRV - (MBAMScheduler) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) 
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation) 
  
   ========== Driver Services (SafeList) ========== 
  
DRV:64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation) 
DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.) 
DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.) 
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation) 
DRV:64bit: - (athr) -- C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.) 
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices) 
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices) 
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.) 
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation) 
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company) 
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology) 
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation) 
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation) 
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation) 
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.) 
DRV:64bit: - (SFEP) -- C:\Windows\SysNative\drivers\SFEP.sys (Sony Corporation) 
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation) 
  
   ========== Standard Registry (SafeList) ========== 
  
   ========== Internet Explorer ========== 
  
IE:64bit: - HKLM\..\SearchScopes,DefaultScope =  
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com 
IE - HKLM\..\SearchScopes,DefaultScope =  
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC 
  
  
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com 
IE - HKU\.DEFAULT\..\SearchScopes,defaultscope =  
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 
  
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com 
IE - HKU\S-1-5-18\..\SearchScopes,defaultscope =  
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 
  
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com 
IE - HKU\S-1-5-19\..\SearchScopes,defaultscope =  
  
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com 
IE - HKU\S-1-5-20\..\SearchScopes,defaultscope =  
  
IE - HKU\S-1-5-21-3828282979-3244811858-1549132693-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com 
IE - HKU\S-1-5-21-3828282979-3244811858-1549132693-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE 
IE - HKU\S-1-5-21-3828282979-3244811858-1549132693-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 74 BB A3 4F 92 BA CD 01  [binary data] 
IE - HKU\S-1-5-21-3828282979-3244811858-1549132693-1000\..\SearchScopes,DefaultScope =  
IE - HKU\S-1-5-21-3828282979-3244811858-1549132693-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC 
IE - HKU\S-1-5-21-3828282979-3244811858-1549132693-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 
   ========== FireFox ========== 
  
FF - prefs.js..browser.search.defaulturl: "" 
FF - prefs.js..browser.search.useDBForOrder: true 
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2 
FF - user.js - File not found 
  
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_6_602_180.dll File not found 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll () 
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found 
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () 
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) 
FF - HKLM\Software\MozillaPlugins\@mcafee.com/McAfeeMssPlugin: C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.) 
FF - HKLM\Software\MozillaPlugins\@TelevisionFanatic.com/Plugin: C:\Program Files (x86)\TelevisionFanatic\bar\1.bin\NP64Stub.dll File not found 
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.) 
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.) 
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.2: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) 
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\majdi ameni elvira\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) 
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\majdi ameni elvira\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.) 
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\majdi ameni elvira\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.) 
  
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\PROGRAM FILES\IB UPDATER\FIREFOX 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013.03.08 16:02:30 | 000,000,000 | ---D | M] 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins 
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013.03.08 16:02:30 | 000,000,000 | ---D | M] 
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins 
  
[2012.10.04 04:58:12 | 000,000,000 | ---D | M] (No name found) -- C:\Users\majdi ameni elvira\AppData\Roaming\mozilla\Extensions 
[2013.03.19 23:30:03 | 000,000,000 | ---D | M] (No name found) -- C:\Users\majdi ameni elvira\AppData\Roaming\mozilla\Firefox\Profiles\bo9166oc.default\extensions 
[2012.10.21 12:46:43 | 000,000,000 | ---D | M] (Gutscheinrausch.de) -- C:\Users\majdi ameni elvira\AppData\Roaming\mozilla\Firefox\Profiles\bo9166oc.default\extensions\mail@gutscheinrausch.de 
[2013.03.08 16:02:28 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions 
[2013.03.08 16:02:30 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll 
[2013.01.22 17:52:09 | 000,001,609 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazon-france.xml 
[2012.09.06 02:54:26 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml 
[2012.12.05 23:23:43 | 000,002,035 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\cnrtl-tlfi-fr.xml 
[2013.02.19 21:24:29 | 000,001,472 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-france.xml 
[2013.01.22 17:52:09 | 000,001,399 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-fr.xml 
[2012.12.05 23:23:43 | 000,001,169 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-france.xml 
   ========== Chrome  ========== 
  
CHR - default_search_provider: SweetIM Search (Enabled) 
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding} 
CHR - default_search_provider: suggest_url =  
CHR - homepage: hxxp://www.google.com/ 
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\majdi ameni elvira\AppData\Local\Google\Chrome\Application\22.0.1229.79\PepperFlash\pepflashplayer.dll 
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer 
CHR - plugin: Native Client (Enabled) = C:\Users\majdi ameni elvira\AppData\Local\Google\Chrome\Application\25.0.1364.172\ppGoogleNaClPluginChrome.dll 
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\majdi ameni elvira\AppData\Local\Google\Chrome\Application\25.0.1364.172\pdf.dll 
CHR - plugin: Google Update (Enabled) = C:\Users\majdi ameni elvira\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll 
CHR - Extension: YouTube = C:\Users\majdi ameni elvira\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\ 
CHR - Extension: Google-Suche = C:\Users\majdi ameni elvira\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1\ 
CHR - Extension: IncrediBar for Chrome = C:\Users\majdi ameni elvira\AppData\Local\Google\Chrome\User Data\Default\Extensions\niogeckbkdcabhnapjbkeiklablhjoca\1.0.5_0\ 
CHR - Extension: Google Mail = C:\Users\majdi ameni elvira\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\ 
CHR - Extension: YouTube = C:\Users\majdi ameni elvira\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\ 
CHR - Extension: Google-Suche = C:\Users\majdi ameni elvira\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1\ 
CHR - Extension: IncrediBar for Chrome = C:\Users\majdi ameni elvira\AppData\Local\Google\Chrome\User Data\Default\Extensions\niogeckbkdcabhnapjbkeiklablhjoca\1.0.5_0\ 
CHR - Extension: Google Mail = C:\Users\majdi ameni elvira\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\ 
  
O1 HOSTS File: ([2013.03.18 19:25:13 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts 
O1 - Hosts: 127.0.0.1       localhost 
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) 
O2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.) 
O4 - HKU\S-1-5-21-3828282979-3244811858-1549132693-1000..\Run: [Facebook Update] C:\Users\majdi ameni elvira\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.) 
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present 
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present 
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present 
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present 
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present 
O7 - HKU\S-1-5-21-3828282979-3244811858-1549132693-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present 
O7 - HKU\S-1-5-21-3828282979-3244811858-1549132693-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 
O13 - gopher Prefix: missing 
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E1F1FCF9-F9FF-4066-90F7-CD9D1F1AD570}: DhcpNameServer = 192.168.1.1 
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) 
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) 
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) 
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation) 
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. 
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. 
O32 - HKLM CDRom: AutoRun - 1 
O34 - HKLM BootExecute: (autocheck autochk *) 
O35:64bit: - HKLM\..comfile [open] -- "%1" %* 
O35:64bit: - HKLM\..exefile [open] -- "%1" %* 
O35 - HKLM\..comfile [open] -- "%1" %* 
O35 - HKLM\..exefile [open] -- "%1" %* 
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %* 
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* 
O37 - HKLM\...com [@ = ComFile] -- "%1" %* 
O37 - HKLM\...exe [@ = exefile] -- "%1" %* 
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) 
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) 
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) 
   ========== Files/Folders - Created Within 30 Days ========== 
  
[2013.03.19 23:21:50 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT 
[2013.03.19 23:21:42 | 000,000,000 | ---D | C] -- C:\JRT 
[2013.03.18 19:29:51 | 000,000,000 | ---D | C] -- C:\Windows\temp 
[2013.03.18 19:25:26 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN 
[2013.03.18 19:17:39 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe 
[2013.03.18 19:17:39 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe 
[2013.03.18 19:17:39 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe 
[2013.03.18 19:17:33 | 000,000,000 | ---D | C] -- C:\Qoobox 
[2013.03.18 19:17:19 | 000,000,000 | ---D | C] -- C:\Windows\erdnt 
[2013.03.16 17:18:28 | 000,000,000 | ---D | C] -- C:\Users\majdi ameni elvira\Desktop\mbar 
[2013.03.13 15:35:06 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll 
[2013.03.13 15:35:06 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll 
[2013.03.13 15:35:06 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll 
[2013.03.13 15:35:05 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl 
[2013.03.13 15:35:05 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl 
[2013.03.13 15:35:05 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll 
[2013.03.13 15:35:05 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll 
[2013.03.13 15:35:05 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll 
[2013.03.13 15:35:05 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe 
[2013.03.13 15:35:05 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe 
[2013.03.13 15:35:04 | 002,312,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll 
[2013.03.13 15:35:04 | 000,729,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll 
[2013.03.13 15:35:02 | 000,816,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll 
[2013.03.13 15:35:02 | 000,717,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll 
[2013.03.13 15:35:02 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll 
[2013.03.13 00:28:56 | 000,000,000 | ---D | C] -- C:\Users\majdi ameni elvira\AppData\Roaming\Malwarebytes 
[2013.03.13 00:28:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware 
[2013.03.13 00:28:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes 
[2013.03.13 00:28:33 | 000,024,176 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys 
[2013.03.13 00:28:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware 
[2013.03.13 00:28:12 | 000,000,000 | ---D | C] -- C:\Users\majdi ameni elvira\AppData\Local\Programs 
[2013.03.12 23:51:33 | 000,000,000 | -H-D | C] -- C:\Users\majdi ameni elvira\AppData\Roaming\3EE0BCD6 
[2013.03.12 23:50:02 | 000,000,000 | ---D | C] -- C:\Users\majdi ameni elvira\Sbblisr 
[2013.03.12 12:35:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSXML 4.0 
[2013.03.12 12:32:36 | 000,000,000 | ---D | C] -- C:\Users\majdi ameni elvira\AppData\Roaming\U3 
[2013.03.12 11:51:26 | 000,000,000 | ---D | C] -- C:\Users\majdi ameni elvira\Desktop\musik neu 
[2013.03.08 16:02:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox 
[2013.03.01 20:53:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth 
   ========== Files - Modified Within 30 Days ========== 
  
[2013.03.20 00:20:11 | 000,010,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 
[2013.03.20 00:20:11 | 000,010,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 
[2013.03.20 00:19:26 | 001,472,002 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI 
[2013.03.20 00:19:26 | 000,641,706 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat 
[2013.03.20 00:19:26 | 000,607,190 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat 
[2013.03.20 00:19:26 | 000,126,062 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat 
[2013.03.20 00:19:26 | 000,103,568 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat 
[2013.03.20 00:15:09 | 000,000,918 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job 
[2013.03.20 00:15:00 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat 
[2013.03.20 00:14:56 | 3206,959,104 | -HS- | M] () -- C:\hiberfil.sys 
[2013.03.20 00:00:00 | 000,001,172 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3828282979-3244811858-1549132693-1000UA.job 
[2013.03.19 23:50:01 | 000,000,922 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job 
[2013.03.19 23:38:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job 
[2013.03.19 22:56:01 | 000,000,980 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3828282979-3244811858-1549132693-1000UA.job 
[2013.03.19 22:56:00 | 000,000,958 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3828282979-3244811858-1549132693-1000Core.job 
[2013.03.18 19:25:13 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts 
[2013.03.17 23:48:31 | 000,000,512 | ---- | M] () -- C:\Users\majdi ameni elvira\Desktop\MBR.dat 
[2013.03.17 01:00:00 | 000,001,120 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3828282979-3244811858-1549132693-1000Core.job 
[2013.03.16 22:33:30 | 000,214,374 | ---- | M] () -- C:\Users\majdi ameni elvira\Desktop\888951_617600784933108_956178932_o.jpg 
[2013.03.16 22:32:13 | 000,137,609 | ---- | M] () -- C:\Users\majdi ameni elvira\Desktop\862389_617088378317682_1757131080_n.jpg 
[2013.03.16 22:32:03 | 000,055,333 | ---- | M] () -- C:\Users\majdi ameni elvira\Desktop\804300_617195524973634_123515814_n.jpg 
[2013.03.16 22:31:51 | 000,064,652 | ---- | M] () -- C:\Users\majdi ameni elvira\Desktop\862185_617195691640284_854219262_n.jpg 
[2013.03.16 22:31:38 | 000,173,307 | ---- | M] () -- C:\Users\majdi ameni elvira\Desktop\888810_617600941599759_392689594_o.jpg 
[2013.03.14 20:01:49 | 000,002,395 | ---- | M] () -- C:\Users\majdi ameni elvira\Desktop\Google Chrome.lnk 
[2013.03.13 14:38:22 | 000,693,976 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe 
[2013.03.13 14:38:22 | 000,073,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 
[2013.03.11 22:32:35 | 000,095,176 | ---- | M] () -- C:\Users\majdi ameni elvira\Desktop\602166_574832465874756_198468293_n.jpg 
[2013.03.10 01:01:37 | 000,934,836 | ---- | M] () -- C:\Users\majdi ameni elvira\Desktop\attachment.php.jpg 
[2013.03.09 10:18:49 | 000,091,328 | ---- | M] () -- C:\Users\majdi ameni elvira\Desktop\702889_571393502887170_527173581_n.jpg 
[2013.03.09 10:18:31 | 000,139,126 | ---- | M] () -- C:\Users\majdi ameni elvira\Desktop\702923_571393476220506_597571333_n.jpg 
[2013.03.08 18:10:22 | 000,017,927 | ---- | M] () -- C:\Users\majdi ameni elvira\Desktop\601592_570957746249165_1027927645_n.jpg 
[2013.03.08 18:09:49 | 000,040,828 | ---- | M] () -- C:\Users\majdi ameni elvira\Desktop\734632_571303722881234_1523163912_n.jpg 
[2013.03.08 16:01:13 | 000,031,133 | ---- | M] () -- C:\Users\majdi ameni elvira\Desktop\577996_10151559285256614_1219465472_n.jpg 
[2013.03.07 16:29:46 | 000,057,079 | ---- | M] () -- C:\Users\majdi ameni elvira\Desktop\65547_346293635492142_879126177_n.jpg 
[2013.02.28 23:03:42 | 000,071,558 | ---- | M] () -- C:\Users\majdi ameni elvira\Desktop\803380_608383912521462_350012141_n.jpg 
[2013.02.28 23:02:57 | 000,067,753 | ---- | M] () -- C:\Users\majdi ameni elvira\Desktop\730621_609338392426014_1849945632_n.jpg 
[2013.02.28 23:02:46 | 000,024,753 | ---- | M] () -- C:\Users\majdi ameni elvira\Desktop\730599_609328659093654_2139714039_n.jpg 
[2013.02.28 13:11:10 | 000,306,636 | ---- | M] () -- C:\Users\majdi ameni elvira\Desktop\859076_316425691793924_261292111_o.jpg 
[2013.02.26 19:13:19 | 000,096,306 | ---- | M] () -- C:\Users\majdi ameni elvira\Desktop\480151_610010319025863_232090152_n.jpg 
[2013.02.26 19:12:50 | 000,074,640 | ---- | M] () -- C:\Users\majdi ameni elvira\Desktop\524955_610019829024912_1986722450_n.jpg 
[2013.02.26 19:10:46 | 000,034,721 | ---- | M] () -- C:\Users\majdi ameni elvira\Desktop\485047_611786715514890_1200217643_n.jpg 
[2013.02.26 15:28:23 | 000,037,588 | ---- | M] () -- C:\Users\majdi ameni elvira\Desktop\285260_10151585540105209_864790281_n.jpg 
[2013.02.26 15:09:38 | 000,011,837 | ---- | M] () -- C:\Users\majdi ameni elvira\Desktop\430935_315873545195684_1097459838_n.jpg 
[2013.02.25 19:59:10 | 000,017,239 | ---- | M] () -- C:\Users\majdi ameni elvira\Desktop\317977_521838064503053_417561600_n.jpg 
[2013.02.22 16:28:23 | 000,031,910 | ---- | M] () -- C:\Users\majdi ameni elvira\Desktop\559878_339374372850735_142926935_n.jpg 
   ========== Files Created - No Company Name ========== 
  
[2013.03.18 19:17:39 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe 
[2013.03.18 19:17:39 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe 
[2013.03.18 19:17:39 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe 
[2013.03.18 19:17:39 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe 
[2013.03.18 19:17:39 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe 
[2013.03.17 23:48:31 | 000,000,512 | ---- | C] () -- C:\Users\majdi ameni elvira\Desktop\MBR.dat 
[2013.03.16 22:33:29 | 000,214,374 | ---- | C] () -- C:\Users\majdi ameni elvira\Desktop\888951_617600784933108_956178932_o.jpg 
[2013.03.16 22:32:13 | 000,137,609 | ---- | C] () -- C:\Users\majdi ameni elvira\Desktop\862389_617088378317682_1757131080_n.jpg 
[2013.03.16 22:32:03 | 000,055,333 | ---- | C] () -- C:\Users\majdi ameni elvira\Desktop\804300_617195524973634_123515814_n.jpg 
[2013.03.16 22:31:50 | 000,064,652 | ---- | C] () -- C:\Users\majdi ameni elvira\Desktop\862185_617195691640284_854219262_n.jpg 
[2013.03.16 22:31:37 | 000,173,307 | ---- | C] () -- C:\Users\majdi ameni elvira\Desktop\888810_617600941599759_392689594_o.jpg 
[2013.03.11 22:32:33 | 000,095,176 | ---- | C] () -- C:\Users\majdi ameni elvira\Desktop\602166_574832465874756_198468293_n.jpg 
[2013.03.10 01:01:34 | 000,934,836 | ---- | C] () -- C:\Users\majdi ameni elvira\Desktop\attachment.php.jpg 
[2013.03.09 10:18:48 | 000,091,328 | ---- | C] () -- C:\Users\majdi ameni elvira\Desktop\702889_571393502887170_527173581_n.jpg 
[2013.03.09 10:18:30 | 000,139,126 | ---- | C] () -- C:\Users\majdi ameni elvira\Desktop\702923_571393476220506_597571333_n.jpg 
[2013.03.08 18:10:21 | 000,017,927 | ---- | C] () -- C:\Users\majdi ameni elvira\Desktop\601592_570957746249165_1027927645_n.jpg 
[2013.03.08 18:09:47 | 000,040,828 | ---- | C] () -- C:\Users\majdi ameni elvira\Desktop\734632_571303722881234_1523163912_n.jpg 
[2013.03.08 15:59:57 | 000,031,133 | ---- | C] () -- C:\Users\majdi ameni elvira\Desktop\577996_10151559285256614_1219465472_n.jpg 
[2013.03.07 16:29:44 | 000,057,079 | ---- | C] () -- C:\Users\majdi ameni elvira\Desktop\65547_346293635492142_879126177_n.jpg 
[2013.02.28 23:03:41 | 000,071,558 | ---- | C] () -- C:\Users\majdi ameni elvira\Desktop\803380_608383912521462_350012141_n.jpg 
[2013.02.28 23:02:56 | 000,067,753 | ---- | C] () -- C:\Users\majdi ameni elvira\Desktop\730621_609338392426014_1849945632_n.jpg 
[2013.02.28 23:02:45 | 000,024,753 | ---- | C] () -- C:\Users\majdi ameni elvira\Desktop\730599_609328659093654_2139714039_n.jpg 
[2013.02.28 13:11:09 | 000,306,636 | ---- | C] () -- C:\Users\majdi ameni elvira\Desktop\859076_316425691793924_261292111_o.jpg 
[2013.02.26 19:13:17 | 000,096,306 | ---- | C] () -- C:\Users\majdi ameni elvira\Desktop\480151_610010319025863_232090152_n.jpg 
[2013.02.26 19:12:49 | 000,074,640 | ---- | C] () -- C:\Users\majdi ameni elvira\Desktop\524955_610019829024912_1986722450_n.jpg 
[2013.02.26 19:10:46 | 000,034,721 | ---- | C] () -- C:\Users\majdi ameni elvira\Desktop\485047_611786715514890_1200217643_n.jpg 
[2013.02.26 15:28:22 | 000,037,588 | ---- | C] () -- C:\Users\majdi ameni elvira\Desktop\285260_10151585540105209_864790281_n.jpg 
[2013.02.26 15:09:36 | 000,011,837 | ---- | C] () -- C:\Users\majdi ameni elvira\Desktop\430935_315873545195684_1097459838_n.jpg 
[2013.02.25 19:59:09 | 000,017,239 | ---- | C] () -- C:\Users\majdi ameni elvira\Desktop\317977_521838064503053_417561600_n.jpg 
[2013.02.22 16:28:22 | 000,031,910 | ---- | C] () -- C:\Users\majdi ameni elvira\Desktop\559878_339374372850735_142926935_n.jpg 
[2012.10.29 18:23:43 | 000,003,584 | ---- | C] () -- C:\Users\majdi ameni elvira\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 
   ========== ZeroAccess Check ========== 
  
[2009.07.14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini 
  
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 
  
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] 
  
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 
  
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] 
  
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 
"" = C:\Windows\SysNative\shell32.dll -- [2012.06.09 06:30:56 | 014,165,504 | ---- | M] (Microsoft Corporation) 
"ThreadingModel" = Apartment 
  
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] 
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 05:46:56 | 012,868,608 | ---- | M] (Microsoft Corporation) 
"ThreadingModel" = Apartment 
  
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation) 
"ThreadingModel" = Free 
  
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] 
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.07.14 02:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation) 
"ThreadingModel" = Free 
  
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) 
"ThreadingModel" = Both 
  
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] 
   ========== Files - Unicode (All) ========== 
[2013.03.16 19:45:01 | 019,652,117 | ---- | M] ()(C:\Users\majdi ameni elvira\Desktop\???? ??????? ?????? hadhra jaret achwaki - YouTube.FLV) -- C:\Users\majdi ameni elvira\Desktop\جارت الاشواق الحضرة hadhra jaret achwaki - YouTube.FLV 
[2013.03.16 19:31:45 | 019,652,117 | ---- | C] ()(C:\Users\majdi ameni elvira\Desktop\???? ??????? ?????? hadhra jaret achwaki - YouTube.FLV) -- C:\Users\majdi ameni elvira\Desktop\جارت الاشواق الحضرة hadhra jaret achwaki - YouTube.FLV   
< End of report >   bei OTL war es nur eine logfile..hab ichs falsch gemacht??  
tut mir leid hab die 2te logfile doch noch gefunden   Code:  
 OTL Extras logfile created on: 20.03.2013 00:20:12 - Run 3 
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\majdi ameni elvira\Downloads 
64bit- Ultimate Edition  (Version = 6.1.7600) - Type = NTWorkstation 
Internet Explorer (Version = 9.0.8112.16421) 
Locale: 00000407 | Country: Germany | Language: DEU | Date Format: dd.MM.yyyy 
  
3,98 Gb Total Physical Memory | 2,81 Gb Available Physical Memory | 70,68% Memory free 
7,96 Gb Paging File | 6,88 Gb Available in Paging File | 86,35% Paging File free 
Paging file location(s): ?:\pagefile.sys [binary data] 
  
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) 
Drive C: | 97,56 Gb Total Space | 56,89 Gb Free Space | 58,32% Space Free | Partition Type: NTFS 
Drive D: | 368,10 Gb Total Space | 368,00 Gb Free Space | 99,97% Space Free | Partition Type: NTFS 
  
Computer Name: MAJDIAMENIELVIR | User Name: majdi ameni elvira | Logged in as Administrator. 
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans 
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days 
   ========== Extra Registry (SafeList) ========== 
  
   ========== File Associations ========== 
   64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] 
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) 
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] 
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) 
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) 
  
[HKEY_USERS\S-1-5-21-3828282979-3244811858-1549132693-1000\SOFTWARE\Classes\<extension>] 
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) 
   ========== Shell Spawning ========== 
   64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] 
batfile [open] -- "%1" %* 
cmdfile [open] -- "%1" %* 
comfile [open] -- "%1" %* 
exefile [open] -- "%1" %* 
helpfile [open] -- Reg Error: Key error. 
htmlfile [edit] -- Reg Error: Key error. 
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) 
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) 
htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation) 
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) 
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) 
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) 
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) 
piffile [open] -- "%1" %* 
regfile [merge] -- Reg Error: Key error. 
scrfile [config] -- "%1" 
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l 
scrfile [open] -- "%1" /S 
txtfile [edit] -- Reg Error: Key error. 
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () 
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) 
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () 
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
Folder [explore] -- Reg Error: Value error. 
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] 
batfile [open] -- "%1" %* 
cmdfile [open] -- "%1" %* 
comfile [open] -- "%1" %* 
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) 
exefile [open] -- "%1" %* 
helpfile [open] -- Reg Error: Key error. 
htmlfile [edit] -- Reg Error: Key error. 
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) 
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) 
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) 
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) 
piffile [open] -- "%1" %* 
regfile [merge] -- Reg Error: Key error. 
scrfile [config] -- "%1" 
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l 
scrfile [open] -- "%1" /S 
txtfile [edit] -- Reg Error: Key error. 
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () 
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) 
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () 
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
Folder [explore] -- Reg Error: Value error. 
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) 
   ========== Security Center Settings ========== 
   64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] 
"cval" = 1 
"FirewallDisableNotify" = 0 
"AntiVirusDisableNotify" = 0 
"UpdatesDisableNotify" = 0 
   64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 
   64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] 
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data] 
"AntiVirusOverride" = 0 
"AntiSpywareOverride" = 0 
"FirewallOverride" = 0 
   64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] 
   ========== System Restore Settings ========== 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] 
"DisableSR" = 0 
   ========== Firewall Settings ========== 
   64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall] 
   64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile] 
   64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile] 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile] 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] 
"DisableNotifications" = 0 
"EnableFirewall" = 1 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 
"DisableNotifications" = 0 
"EnableFirewall" = 1 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] 
"DisableNotifications" = 0 
"EnableFirewall" = 1 
   ========== Authorized Applications List ========== 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] 
  
   ========== Vista Active Open Ports Exception List ========== 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] 
   ========== Vista Active Application Exception List ========== 
  
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] 
"{1D6BD56B-541C-4D5D-9C61-14D0370DFB64}" = protocol=6 | dir=in | app=c:\program files (x86)\goforfiles\goforfilesdl.exe |  
"{28EB52E5-F894-40AE-9BCA-471099896575}" = protocol=6 | dir=in | app=c:\windows\syswow64\msiexec.exe |  
"{349FBD90-4322-4D18-963E-D4DF001EFA2C}" = protocol=6 | dir=in | app=c:\windows\system32\dmwu.exe |  
"{38A045C7-ADA3-4C12-9504-8F141A7026BF}" = dir=in | app=c:\users\majdi ameni elvira\appdata\local\facebook\video\skype\facebookvideocalling.exe |  
"{5BC526C7-B5DB-432B-A739-ABEDBCFF334E}" = protocol=6 | dir=in | app=c:\program files (x86)\goforfiles\goforfiles.exe |  
"{606A77EF-0CA3-4289-A55B-B788A6F25DC8}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |  
"{76AEAD72-3658-446A-A037-30FD44B96620}" = protocol=17 | dir=in | app=c:\program files (x86)\sweetim\communicator\sweetpacksupdatemanager.exe |  
"{7A301976-C47F-46CF-B435-9B8CFC6D618D}" = protocol=17 | dir=in | app=c:\windows\syswow64\msiexec.exe |  
"{82A7328E-9E33-4F50-814E-53D66BB6BA0B}" = protocol=17 | dir=in | app=c:\windows\system32\dmwu.exe |  
"{96DD81E1-F78D-4D0E-86F7-BB011A5A5E3D}" = protocol=17 | dir=in | app=c:\program files (x86)\goforfiles\goforfilesdl.exe |  
"{9815E4D5-1CBF-4579-A788-6514EDC1717F}" = protocol=17 | dir=in | app=c:\windows\system32\arfc\wrtc.exe |  
"{CA7AF6D9-D4CE-4DE9-8F84-2CC704E7033C}" = protocol=17 | dir=in | app=c:\program files (x86)\goforfiles\goforfiles.exe |  
"{CAA89A70-CF66-45D7-A00A-42650BCD620E}" = protocol=6 | dir=in | app=c:\program files (x86)\sweetim\communicator\sweetpacksupdatemanager.exe |  
"{D8C28A7B-7284-411C-AEBB-DD48052AAAFF}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |  
"{F18B3906-C0D2-4096-987D-C0D88A3177F4}" = protocol=6 | dir=in | app=c:\windows\system32\arfc\wrtc.exe |  
   ========== HKEY_LOCAL_MACHINE Uninstall List ========== 
  
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] 
"{1493B2AE-0261-47D2-B1AA-F4DAD0F6C48B}" = iTunes 
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 
  
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] 
"{34B32B70-8081-11E2-89AF-B8AC6F98CCE3}" = Google Earth Plug-in 
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml 
"{5C474A83-A45F-470C-9AC8-2BD1C251BF9A}" = Skype™ 4.2 
"{7D916FA5-DAE9-4A25-B089-655C70EAF607}" = Atheros WiFi Driver Installation 
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper 
"{AC76BA86-7AD7-1031-7B44-A70800000002}" = Adobe Reader 7.0.8 - Deutsch 
"{B92C5909-1D37-4C51-8397-A28BB28E5DC3}" = Facebook Video Calling 1.2.0.287 
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin 
"AskTBar Uninstall" = Ask Toolbar 
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.70.0.1100 
"McAfee Security Scan" = McAfee Security Scan Plus 
"Mozilla Firefox 19.0.2 (x86 fr)" = Mozilla Firefox 19.0.2 (x86 fr) 
"MozillaMaintenanceService" = Mozilla Maintenance Service 
"TelevisionFanaticbar Uninstall" = TelevisionFanatic Toolbar 
"VLC media player" = VLC media player 2.0.2 
   ========== HKEY_USERS Uninstall List ========== 
  
[HKEY_USERS\S-1-5-21-3828282979-3244811858-1549132693-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] 
"Google Chrome" = Google Chrome 
   ========== Last 20 Event Log Errors ========== 
  
[ System Events ] 
Error - 19.03.2013 19:15:07 | Computer Name = majdiamenielvir | Source = BTHUSB | ID = 327697 
Description = Der lokale Bluetooth-Adapter ist aus einem unbekannten Grund fehlgeschlagen 
 und wird nicht verwendet. Der Treiber wurde entladen. 
  
  
< End of report >      |