internet stops working except torrents

koloss

New Member
Hi

My computer sometimes after watching a YouTube video or downloading a file the internet just stop working and how much I wait it doesn't open a page or download a file except one program that work after that which is BitTorrent ,I don't know what's wrong please I need help
 
What internet provider do you have? What is your internet setup at home? Modem and router or just modem? Have you scanned for malware?
 
i have modem and router (i tried once connecting it via LAN cable but no good and no other computer do that in my home), i have AVG internet security 2012
 
Do you have malwarebytes installed? I would suggest using it to scan your system for malware since you have bit torrent installed.

Please download Malwarebytes' Anti-Malware from here or here and save it to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to
    • Update Malwarebytes' Anti-Malware
    • and Launch Malwarebytes' Anti-Malware
  • then click Finish.
  • If an update is found, it will download and install the latest version. Please keep updating until it says you have the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • A log will be saved automatically which you can access by clicking on the Logs tab within Malwarebytes' Anti-Malware

If for some reason Malwarebytes will not install or run please download and run Rkill.scr, Rkill.exe, or Rkill.com. If you are still having issues running rkill then try downloading these renamed versions of the same program.

EXPLORER.EXE
IEXPLORE.EXE
USERINIT.EXE
WINLOGON.EXE

But DO NOT reboot the system and then try installing or running Malwarebytes. If Rkill (which is a black box) appears and then disappears right away or you get a message saying rkill is infected, keep trying to run rkill until it over powers the infection and temporarily kills it. Once a log appears on the screen, you can try running malwarebytes or downloading other programs.



Download the HijackThis installer from here.
Run the installer and choose Install, indicating that you accept the licence agreement. The installer will place a shortcut on your desktop and launch HijackThis.

Vista and Windows 7 users must right click on the hijackthis icon and click on run as. If the run as option doesn't appear then press and hold the shift key while right clicking on the icon to get it to appear.


Click Do a system scan and save a logfile

Most of what HijackThis lists will be harmless or even essential, don't fix anything yet.

When the hijackthis log appears in a notepad file, click on the edit menu, click select all, then click on the edit menu again and click on copy. Come back to your reply and right click on your mouse and click on paste.

Post the logfile that HijackThis produces along with the Malwarebytes Anti-Malware log
 
Malwarebytes Anti-Malware log:Malwarebytes Anti-Malware (Trial) 1.75.0.1300
www.malwarebytes.org

Database version: v2013.08.19.06

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 9.0.8112.16421
alaa :: ALAA-PC [administrator]

Protection: Enabled

8/20/2013 3:27:51 AM
mbam-log-2013-08-20 (03-27-51).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 377006
Time elapsed: 7 minute(s), 54 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 12
HKLM\SYSTEM\CurrentControlSet\Services\RelevantKnowledge (PUP.Adware.RelevantKnowledge) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110011341191} (PUP.GamePlayLab) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110011341191} (PUP.GamePlayLab) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{20241689-3AC3-226D-7C3E-401198C81BEA} (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2B2AAAD2-882B-A610-C139-EA77AB8CBE48} (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{67DD68E4-9EFB-B0EA-2659-CED3C5BE0B6D} (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F11FCAD5-AB73-43C7-A12C-E3512AFCE823} (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D9C78E75-CCF1-7B14-F147-EBA4083B046D} (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
HKCU\Software\DataMngr (PUP.Optional.DataMngr) -> Quarantined and deleted successfully.
HKCU\Software\Google\Chrome\Extensions\cjpglkicenollcignonpgiafdgfeehoj (PUP.FunMoods) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Google\Chrome\Extensions\cjpglkicenollcignonpgiafdgfeehoj (PUP.FunMoods) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Google\chrome\Extensions\fdloijijlkoblmigdofommgnheckmaki (PUP.Funmoods) -> Quarantined and deleted successfully.

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 14
C:\Users\alaa\AppData\Roaming\Babylon (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.
C:\Users\Guest\AppData\Roaming\Babylon (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.
C:\Users\Guest\AppData\Roaming\Babylon\Content (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.
C:\Users\Guest\AppData\Roaming\Babylon\Content\icons (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.
C:\Users\Guest\AppData\Roaming\Babylon\Content\manuals (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.
C:\Users\Guest\AppData\Roaming\Babylon\updates (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.
C:\PROGRAM FILES\RelevantKnowledge (PUP.Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\PROGRAM FILES\RelevantKnowledge\components (PUP.Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RelevantKnowledge (PUP.Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504} (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Cache (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B} (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Cache (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.

Files Detected: 67
C:\PROGRAM FILES\RelevantKnowledge\rlservice.exe (PUP.Adware.RelevantKnowledge) -> Quarantined and deleted successfully.
C:\ProgramData\InstallMate\{3D3602BE-68FD-449A-A671-20DFE6D52048}\Setup.exe (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\InstallMate\{3D3602BE-68FD-449A-A671-20DFE6D52048}\TsuDll.dll (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\InstallMate\{4FFD6466-8A12-4999-AB72-C230941E4690}\Setup.exe (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\InstallMate\{4FFD6466-8A12-4999-AB72-C230941E4690}\TsuDll.dll (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\InstallMate\{A77389E1-C494-4B60-A98B-8CB67C90AB17}\Setup.exe (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\InstallMate\{A77389E1-C494-4B60-A98B-8CB67C90AB17}\TsuDll.dll (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\InstallMate\{F11FCAD5-AB73-43C7-A12C-E3512AFCE823}\Setup.exe (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\InstallMate\{F11FCAD5-AB73-43C7-A12C-E3512AFCE823}\TsuDll.dll (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\InstallMate\{F467E946-8E22-436D-A186-C6002F84CBB0}\Setup.exe (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\InstallMate\{F467E946-8E22-436D-A186-C6002F84CBB0}\TsuDll.dll (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\PROGRAM FILES\COMMON FILES\ZugoInstaller.exe (PUP.Zugo) -> Quarantined and deleted successfully.
C:\Users\alaa\AppData\Local\Temp\PIPInstaller_PTV_.exe (PUP.Optional.BundledToolBar.A) -> Quarantined and deleted successfully.
C:\Users\alaa\Downloads\setup.exe (PUP.Optional.Installex) -> Quarantined and deleted successfully.
C:\Users\alaa\AppData\Local\funmoods.crx (PUP.Funmoods) -> Quarantined and deleted successfully.
C:\Users\alaa\Local Settings\Application Data\funmoods.crx (PUP.Funmoods) -> Quarantined and deleted successfully.
C:\Users\alaa\Local Settings\Application Data\Google\Chrome\User Data\Default\Local Storage\chrome-extension_cjpglkicenollcignonpgiafdgfeehoj_0.localstorage (PUP.FunMoods) -> Quarantined and deleted successfully.
C:\Users\alaa\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_cjpglkicenollcignonpgiafdgfeehoj_0.localstorage (PUP.FunMoods) -> Quarantined and deleted successfully.
C:\Users\alaa\AppData\Roaming\Babylon\log_file.txt (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.
C:\Users\Guest\AppData\Roaming\Babylon\log_file.txt (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.
C:\Users\Guest\AppData\Roaming\Babylon\FLStat.dat (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.
C:\Users\Guest\AppData\Roaming\Babylon\MyList.dat (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.
C:\Users\Guest\AppData\Roaming\Babylon\ocr_cache (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.
C:\Users\Guest\AppData\Roaming\Babylon\ocr_data (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.
C:\Users\Guest\AppData\Roaming\Babylon\Content\icons\09HMK27M2P_glossary_icon.ico (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.
C:\Users\Guest\AppData\Roaming\Babylon\Content\icons\36EZZ9HFKA_glossary_icon.ico (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.
C:\Users\Guest\AppData\Roaming\Babylon\Content\icons\3ZCCGQGCV2_glossary_icon.ico (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.
C:\Users\Guest\AppData\Roaming\Babylon\Content\icons\AC8T27QESJ_glossary_icon.ico (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.
C:\Users\Guest\AppData\Roaming\Babylon\Content\icons\BTMJWKZGYE_glossary_icon.ico (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.
C:\Users\Guest\AppData\Roaming\Babylon\Content\icons\S7HE5XG6JJ_glossary_icon.ico (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.
C:\Users\Guest\AppData\Roaming\Babylon\Content\manuals\36EZZ9HFKA_glossary_manual.pdf (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.
C:\Users\Guest\AppData\Roaming\Babylon\Content\manuals\3ZCCGQGCV2_glossary_manual.pdf (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.
C:\Users\Guest\AppData\Roaming\Babylon\Content\manuals\AC8T27QESJ_glossary_manual.pdf (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.
C:\Users\Guest\AppData\Roaming\Babylon\Content\manuals\S7HE5XG6JJ_glossary_manual.pdf (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.
C:\Users\Guest\AppData\Roaming\Babylon\updates\convert.dat (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.
C:\Users\Guest\AppData\Roaming\Babylon\updates\rates.dat (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.
C:\PROGRAM FILES\RelevantKnowledge\asmcf.dat (PUP.Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\PROGRAM FILES\RelevantKnowledge\chrome.manifest (PUP.Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\PROGRAM FILES\RelevantKnowledge\egdcf.dat (PUP.Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\PROGRAM FILES\RelevantKnowledge\install.rdf (PUP.Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\PROGRAM FILES\RelevantKnowledge\ncncf.dat (PUP.Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\PROGRAM FILES\RelevantKnowledge\nscf.dat (PUP.Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\PROGRAM FILES\RelevantKnowledge\rlcm.crx (PUP.Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\PROGRAM FILES\RelevantKnowledge\rlcm.txt (PUP.Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\PROGRAM FILES\RelevantKnowledge\rlls.dll (PUP.Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\PROGRAM FILES\RelevantKnowledge\rlls64.dll (PUP.Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\PROGRAM FILES\RelevantKnowledge\rloci.bin (PUP.Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\PROGRAM FILES\RelevantKnowledge\rlph.dll (PUP.Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\PROGRAM FILES\RelevantKnowledge\rlvknlg64.exe (PUP.Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\PROGRAM FILES\RelevantKnowledge\rlxf.dll (PUP.Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\PROGRAM FILES\RelevantKnowledge\components\rlxg.dll (PUP.Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\PROGRAM FILES\RelevantKnowledge\components\rlxh.dll (PUP.Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\PROGRAM FILES\RelevantKnowledge\components\rlxi.dll (PUP.Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\PROGRAM FILES\RelevantKnowledge\components\rlxj.dll (PUP.Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\PROGRAM FILES\RelevantKnowledge\components\rlxk.dll (PUP.Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RelevantKnowledge\About RelevantKnowledge.lnk (PUP.Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RelevantKnowledge\Privacy Policy and User License Agreement.lnk (PUP.Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RelevantKnowledge\Support.lnk (PUP.Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.dat (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.exe (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.ico (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setup.dll (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.dat (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.exe (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.ico (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setup.dll (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.

(end)


HijackThis log: when i open it (both ways normal and run as ) it says fatal error during installation
 
i have to add the recently i noticed that the problem only when using it too much(4 you tube videos and like 20 tabs) maybe that's the cause of the problem or its random
 
Please do the following.

Please download AdwCleaner by Xplode onto your Desktop.



•Please close all open programs and internet browsers.
•Double click on adwcleaner.exe to run the tool.
•Click on Delete.
•Confirm each time with OK
•Your computer will be rebooted automatically. A text file will open after the restart.
•Please post the content of that logfile in your reply.
•You can find the logfile at C:\AdwCleaner[Sn].txt as well - n is the order number.

After posting the log try installing hijackthis again.
 
# AdwCleaner v3.000 - Report created 24/08/2013 at 18:52:15
# Updated 20/08/2013 by Xplode
# Operating System : Windows 7 Ultimate Service Pack 1 (32 bits)
# Username : alaa - ALAA-PC
# Running from : D:\we will see you\adwcleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\APN
Folder Deleted : C:\ProgramData\Babylon
Folder Deleted : C:\ProgramData\continuetosave
Folder Deleted : C:\ProgramData\DeviceVM
Folder Deleted : C:\ProgramData\InstallMate
Folder Deleted : C:\ProgramData\Premium
Folder Deleted : C:\Program Files\1ClickDownload
[#] Folder Deleted : C:\Program Files\AskPartnerNetwork
Folder Deleted : C:\Program Files\Conduit
Folder Deleted : C:\Program Files\continuetosave
Folder Deleted : C:\Program Files\ExpressFiles
[#] Folder Deleted : C:\Program Files\iMesh Applications
Folder Deleted : C:\Program Files\MyPC Backup
Folder Deleted : C:\Program Files\SimpleSpeedy
Folder Deleted : C:\Program Files\Yontoo
Folder Deleted : C:\Users\alaa\AppData\Local\Bundled software uninstaller
Folder Deleted : C:\Users\alaa\AppData\Local\Conduit
Folder Deleted : C:\Users\alaa\AppData\Local\PackageAware
Folder Deleted : C:\Users\alaa\AppData\Local\SwvUpdater
Folder Deleted : C:\Users\alaa\AppData\Local\Temp\APN
Folder Deleted : C:\Users\alaa\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\alaa\AppData\LocalLow\continuetosave
Folder Deleted : C:\Users\alaa\AppData\Roaming\DeviceVM
Folder Deleted : C:\Users\the peoples computer\AppData\LocalLow\facemoods.com
Folder Deleted : C:\Users\the peoples computer\AppData\Roaming\ExpressFiles
Folder Deleted : C:\Program Files\Mozilla Firefox\Extensions\[email protected]
Folder Deleted : C:\Program Files\Mozilla Firefox\Extensions\[email protected]
Folder Deleted : C:\Users\alaa\AppData\Roaming\Mozilla\Firefox\Profiles\yyomd9ub.default\Extensions\[email protected]
Folder Deleted : C:\Users\alaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhkmmdeagpmijjmljdpaemdllheaaaig
File Deleted : C:\END
File Deleted : C:\Users\alaa\AppData\Local\funmoods-speeddial.crx
File Deleted : C:\Program Files\Mozilla Firefox\searchplugins\Babylon.xml
File Deleted : C:\Program Files\Mozilla Firefox\searchplugins\fcmdSrch.xml
File Deleted : C:\Users\alaa\AppData\Roaming\Mozilla\Firefox\Profiles\yyomd9ub.default\searchplugins\search.xml
File Deleted : C:\Users\alaa\AppData\Roaming\Mozilla\Firefox\Profiles\s74kbspm.default\user.js
File Deleted : C:\Users\alaa\AppData\Roaming\Mozilla\Firefox\Profiles\yyomd9ub.default\user.js
File Deleted : C:\Program Files\Mozilla Firefox\user.js

***** [ Shortcuts ] *****


***** [ Registry ] *****

Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{3C5F0F00-683D-4847-89C8-E7AF64FD1CFB}]
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dednnpigldgdbpgcdpfppmlcnnbjciel
Key Deleted : HKCU\Software\Google\Chrome\Extensions\fdloijijlkoblmigdofommgnheckmaki
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\lpmkgpnbiojfaoklbkpfneikocaobfai
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\mkndcbhcgphcfkkddanakjiepeknbgle
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\pmlghpafmmnmmkjdhacccolfgnkiboco
Key Deleted : HKLM\SOFTWARE\Classes\AppID\DiscoveryHelper.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\GIFAnimator.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\IMTrProgress.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\IMWeb.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL
Key Deleted : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr
Key Deleted : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1
Key Deleted : HKLM\SOFTWARE\Classes\DiscoveryHelper.iMesh6Discovery
Key Deleted : HKLM\SOFTWARE\Classes\DiscoveryHelper.iMesh6Discovery.1
Key Deleted : HKLM\SOFTWARE\Classes\imweb.imwebcontrol
Key Deleted : HKLM\SOFTWARE\Classes\oneclick
Key Deleted : HKLM\SOFTWARE\Classes\oneclickmg
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Api
Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Api.1
Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Layers
Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Layers.1
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [Backup.old.Start Page]
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\MenuExt\Translate this web page with Babylon
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\MenuExt\Translate with Babylon
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Babylon_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Babylon_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ContinueToSave_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ContinueToSave_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\facemoodssrv_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\facemoodssrv_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SweetIM_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SweetIM_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Vid-Saver_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Vid-Saver_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SP_09b71135
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SP_7699c875
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0003491.BHO
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0003491.BHO.1
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0003491.FBApi
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0003491.FBApi.1
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0003491.Sandbox
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0003491.Sandbox.1
Key Deleted : HKCU\Software\eed78abd35bf43
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_lightsaber_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_lightsaber_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_sniperspy_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_sniperspy_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_windows-password-cracker_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_windows-password-cracker_RASMANCS
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FC41815-FA4C-4F8B-B143-2C045C8EA2FC}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{21493C1F-D071-496A-9C27-450578888291}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{403A885F-CB00-40C1-BDC1-EB09053194F7}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{55C1727F-5535-4C2A-9601-8C2458608B48}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{2656B92B-0207-4AFB-BEBF-F5FD231ECD39}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{2C4BA31C-0C15-11E2-90C7-9BFCBEB168B3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{2EECD738-5844-4A99-B4B6-146BF802613B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{34CB0620-E343-4772-BBA8-D3074BC47516}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3BF72F68-72D8-461D-A884-329D936C5581}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{412CD209-DDA4-4275-8C79-55F1C93FBD47}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{59570C1F-B692-48C9-91B4-7809E6945287}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{63A0F7FA-2C95-4D7E-AF25-EFCC303D20A1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6559E502-6EE1-46B8-A83C-F3A45BDA23EE}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{69D3F709-9DE2-479F-980F-532D46895703}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{78E9D883-93CD-4072-BEF3-38EE581E2839}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7C3B01BC-53A5-48A0-A43B-0C67731134B9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E84186E-B5DE-4226-8A66-6E49C6B511B4}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{83AC1413-FCE4-4A46-9DD5-4F31F306E71F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{99066096-8989-4612-841F-621A01D54AD7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A2858A72-758F-4486-B6A1-7F1DCC0924FA}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B6F8DA9F-2696-419E-A8A3-19BE41EF51BD}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C63CA8A4-AB4E-49E5-A6C0-33FC86D80205}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C6A7847E-8931-4A9A-B4EF-72A91E3CCF4D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DD0F1D24-E250-4E93-966C-65615720AEFB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E46C8196-B634-44A1-AF6E-957C64278AB1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EC1277BB-1C71-4C0D-BA6D-BFEA16E773A6}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F42C7B47-5234-4BF5-8882-DAAC0D64870D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0BF91075-F457-4A8B-99EF-140B52D2F22A}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{431FB0E5-2CBB-4602-9FE6-F1D64488ADD7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5C9A230D-70A5-11D5-AFB0-0050DAC67890}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5E8CD073-21DF-4117-9BBD-D03C45D36CAE}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{69D3F709-9DE2-479F-980F-532D46895703}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8911483C-C00A-4183-9FBC-6C9C00946C15}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A9379648-F6EB-4F65-A624-1C10411A15D0}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C3F058A9-407D-4CD1-8F66-B75605B54B69}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{CA1CE38C-F04C-471F-B9F3-083C58165C10}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EFDCAF05-D29C-4D4D-9836-8CDCD606A6B2}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F16AB1DB-15C0-4456-A29E-4DF24FB9E3D2}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F42C7B47-5234-4BF5-8882-DAAC0D64870D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F7BEBBB1-7E6B-4561-9444-6F4866D60C7C}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{252C2315-CCE0-4446-8DA7-C00292A690BA}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{403A885F-CB00-40C1-BDC1-EB09053194F7}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{55C1727F-5535-4C2A-9601-8C2458608B48}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{5C9A2304-70A5-11D5-AFB0-0050DAC67890}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{EC96F516-51B2-4B46-8451-8665F5A6BA2B}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{F07FBD3E-2048-44A4-9065-71BF551E2672}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2C4BA31C-0C15-11E2-90C7-9BFCBEB168B3}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2C4BA31C-0C15-11E2-90C7-9BFCBEB168B3}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2C4BA31C-0C15-11E2-90C7-9BFCBEB168B3}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2EECD738-5844-4A99-B4B6-146BF802613B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{872F3C0B-4462-424C-BB9F-74C6899B9F92}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B6F8DA9F-2696-419E-A8A3-19BE41EF51BD}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0D7562AE-8EF6-416D-A838-AB665251703A}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{EEE6C35B-6118-11DC-9C72-001320C79847}]
Key Deleted : HKCU\Software\1ClickDownload
Key Deleted : HKCU\Software\BI
Key Deleted : HKCU\Software\Cr_Installer
Key Deleted : HKCU\Software\ExpressFiles
Key Deleted : HKCU\Software\Headlight
Key Deleted : HKCU\Software\IM
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKCU\Software\Zugo
Key Deleted : HKCU\Software\AppDataLow\SProtector
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKLM\Software\AVG Secure Search
Key Deleted : HKLM\Software\Babylon
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\DataMngr
Key Deleted : HKLM\Software\ExpressFiles
Key Deleted : HKLM\Software\Iminent
Key Deleted : HKLM\Software\SP Global
Key Deleted : HKLM\Software\SProtector
Key Deleted : HKLM\Software\systweak
Key Deleted : HKLM\Software\Tarma Installer
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\facemoods
Data Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - files\simple~1\sprote~1.dll,

***** [ Browsers ] *****

-\\ Internet Explorer v9.0.8112.16502

Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [SearchAssistant]

-\\ Mozilla Firefox v21.0 (en-US)

[ File : C:\Users\alaa\AppData\Roaming\Mozilla\Firefox\Profiles\s74kbspm.default\prefs.js ]

Line Deleted : user_pref("extensions.crossrider.bic", "13f1555fb2820afa4ab02326346f9a3a");

[ File : C:\Users\alaa\AppData\Roaming\Mozilla\Firefox\Profiles\yyomd9ub.default\prefs.js ]

Line Deleted : user_pref("extensions.funmoods.hmpg", true);
Line Deleted : user_pref("extensions.funmoods.hmpgUrl", "hxxp://start.funmoods.com/?f=1&a=nv1&chnl=nv1&cd=2XzutAtN2Y1L1QzutDtDtByDtBtBzzyC0DtD0AyCzyzy0CtBtN0D0TzutBtDtCtBtDyCtCyD&cr=929229447");
Line Deleted : user_pref("extensions.funmoods.dfltSrch", true);
Line Deleted : user_pref("extensions.funmoods.srchPrvdr", "Search");
Line Deleted : user_pref("extensions.funmoods.dnsErr", true);
Line Deleted : user_pref("extensions.funmoods_i.newTab", true);
Line Deleted : user_pref("extensions.funmoods.newTabUrl", "hxxp://start.funmoods.com/?f=2&a=nv1&chnl=nv1&cd=2XzutAtN2Y1L1QzutDtDtByDtBtBzzyC0DtD0AyCzyzy0CtBtN0D0TzutBtDtCtBtDyCtCyD&cr=929229447");
Line Deleted : user_pref("extensions.funmoods.tlbrSrchUrl", "");
Line Deleted : user_pref("extensions.funmoods.id", "");
Line Deleted : user_pref("extensions.funmoods.instlDay", "15506");
Line Deleted : user_pref("extensions.funmoods.vrsn", "1.5.23.22");
Line Deleted : user_pref("extensions.funmoods.vrsni", "1.5.23.22");
Line Deleted : user_pref("extensions.funmoods_i.vrsnTs", "1.5.23.2215:2:39");
Line Deleted : user_pref("extensions.funmoods.prtnrId", "funmoods");
Line Deleted : user_pref("extensions.funmoods.prdct", "funmoods");
Line Deleted : user_pref("extensions.funmoods.aflt", "nv1");
Line Deleted : user_pref("extensions.funmoods_i.smplGrp", "none");
Line Deleted : user_pref("extensions.funmoods.tlbrId", "base");
Line Deleted : user_pref("extensions.funmoods.instlRef", "nv1");
Line Deleted : user_pref("extensions.funmoods.dfltLng", "");
Line Deleted : user_pref("extensions.funmoods.excTlbr", false);
Line Deleted : user_pref("extensions.funmoods.autoRvrt", false);
Line Deleted : user_pref("extensions.funmoods.envrmnt", "production");
Line Deleted : user_pref("extensions.funmoods.isdcmntcmplt", true);
Line Deleted : user_pref("extensions.funmoods.mntrvrsn", "1.3.0");
Line Deleted : user_pref("extentions.y2layers.installId", "34243841-26c7-4155-8e3b-2ca005c0f9fb");
Line Deleted : user_pref("extentions.y2layers.defaultEnableAppsList", "bestvideodownloader,ezLooker,pagerage,buzzdock,toprelatedtopics,twittube");

[ File : C:\Users\the peoples computer\AppData\Roaming\Mozilla\Firefox\Profiles\ln7wq4zu.default\prefs.js ]

Line Deleted : user_pref("extensions.crossrider.bic", "13765515dc8268816367dce18355b560");
Line Deleted : user_pref("extensions.crossriderapp3491.3491.InstallationTime", 1361966408);
Line Deleted : user_pref("extensions.crossriderapp3491.3491.active", true);
Line Deleted : user_pref("extensions.crossriderapp3491.3491.addressbar", "");
Line Deleted : user_pref("extensions.crossriderapp3491.3491.affid", "0");
Line Deleted : user_pref("extensions.crossriderapp3491.3491.certdomaininstaller", "");
Line Deleted : user_pref("extensions.crossriderapp3491.3491.changeprevious", false);
Line Deleted : user_pref("extensions.crossriderapp3491.3491.cookie.InstallationTime.expiration", "Fri Feb 01 2030 00:00:00 GMT+0300 (Arab Standard Time)");
Line Deleted : user_pref("extensions.crossriderapp3491.3491.cookie.InstallationTime.value", "1361966408");
Line Deleted : user_pref("extensions.crossriderapp3491.3491.description", "Vid-Saver allows you to download your favorite streaming videos!");
Line Deleted : user_pref("extensions.crossriderapp3491.3491.domain", "");
Line Deleted : user_pref("extensions.crossriderapp3491.3491.emailsig", "");
Line Deleted : user_pref("extensions.crossriderapp3491.3491.enablesearch", false);
Line Deleted : user_pref("extensions.crossriderapp3491.3491.exposesites", "");
Line Deleted : user_pref("extensions.crossriderapp3491.3491.fbremoteurl", "");
Line Deleted : user_pref("extensions.crossriderapp3491.3491.group", 0);
Line Deleted : user_pref("extensions.crossriderapp3491.3491.homepage", "");
Line Deleted : user_pref("extensions.crossriderapp3491.3491.iframe", false);
Line Deleted : user_pref("extensions.crossriderapp3491.3491.manifesturl", "");
Line Deleted : user_pref("extensions.crossriderapp3491.3491.name", "Vid-Saver");
Line Deleted : user_pref("extensions.crossriderapp3491.3491.newtab", "");
Line Deleted : user_pref("extensions.crossriderapp3491.3491.opensearch", "");
Line Deleted : user_pref("extensions.crossriderapp3491.3491.pluginsurl", "hxxp://app-static.crossrider.com/plugin/apps/3491/plugins/081/ff/plugins.json");
Line Deleted : user_pref("extensions.crossriderapp3491.3491.premium", true);
Line Deleted : user_pref("extensions.crossriderapp3491.3491.publisher", "215 Apps");
Line Deleted : user_pref("extensions.crossriderapp3491.3491.searchstatus", 0);
Line Deleted : user_pref("extensions.crossriderapp3491.3491.setnewtab", false);
Line Deleted : user_pref("extensions.crossriderapp3491.3491.settingsurl", "");
Line Deleted : user_pref("extensions.crossriderapp3491.3491.thankyou", "hxxp://vid-saver.com/thankyou.html");
Line Deleted : user_pref("extensions.crossriderapp3491.3491.updateinterval", 360);
Line Deleted : user_pref("extensions.crossriderapp3491.3491.ver", 0);
Line Deleted : user_pref("extensions.crossriderapp3491.bic", "13765515dc8268816367dce18355b560");
Line Deleted : user_pref("extensions.crossriderapp3491.firstrun", false);
Line Deleted : user_pref("extensions.crossriderapp3491.installationdate", 1361966408);
Line Deleted : user_pref("extensions.crossriderapp3491.lastcheck", 22936267);
Line Deleted : user_pref("extensions.crossriderapp3491.lastcheckitem", 22936267);
Line Deleted : user_pref("extensions.crossriderapp3491.misc.lastBgWorkerTimer", "1361974447869");
Line Deleted : user_pref("extensions.crossriderapp3491.misc.lastDomWorkerTimer", "1361974447867");
Line Deleted : user_pref("extensions.crossriderapp3491.statsDailyCounter", 10);
Line Deleted : user_pref("extensions.enabledAddons", "%7BF53C93F1-07D5-430c-86D4-C9531B27DFAF%7D:12.0.0.2189,crossriderapp3491%40crossrider.com:0.91.110,afurladvisor%40anchorfree.com:3.11,%7B972ce4c6-7e08-4474-a285-[...]
Line Deleted : user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"{3C5F0F00-683D-4847-89C8-E7AF64FD1CFB}\":{\"descriptor\":\"C:\\\\Program Files\\\\RelevantKnowledge\",\"mtime\":134[...]

-\\ Google Chrome v

[ File : C:\Users\alaa\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Deleted : homepage

*************************

AdwCleaner[R0].txt - [23380 octets] - [24/08/2013 18:49:45]
AdwCleaner[S0].txt - [23676 octets] - [24/08/2013 18:52:15]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [23737 octets] ##########
 
Lets scan deeper then.

Download and Run ComboFix
If you already have Combofix, please delete this copy and download it again as it's being updated regularly.
  • Download this file here :

    Combofix

  • When the page loads click on the blue combofix download link next to the BleepingComputer Mirror.
  • Save the file to your windows desktop. The combofix icon will look like this when it has downloaded to your desktop.

    cf-icon.jpg
  • We are almost ready to start ComboFix, but before we do so, we need to take some preventative measures so that there are no conflicts with other programs when running ComboFix. At this point you should do the following:

  • Close all open Windows including this one.
  • Close or disable all running Antivirus, Antispyware, and Firewall programs as they may interfere with the proper running of ComboFix. Instructions on disabling these type of programs can be found here.
    Once these two steps have been completed, double-click on the ComboFix icon found on your desktop. Please note, that once you start ComboFix you should not click anywhere on the ComboFix window as it can cause the program to stall. In fact, when ComboFix is running, do not touch your computer at all. The scan could take a while, so please be patient.
  • Please click on I agree on the disclaimer window.
  • ComboFix will now install itself on to your computer. When it is done, a blue screen will appear as shown below.

    cf-preparing.jpg

  • ComboFix is now preparing to run. When it has finished ComboFix will automatically attempt to create a System Restore point so that if any problems occur while using the program you can restore back to your previous configuration. When ComboFix has finished creating the restore point, it will then backup your Windows Registry as shown in the image below.

    erunt.jpg

  • Once the Windows Registry has finished being backed up, ComboFix will attempt to detect if you have the Windows Recovery Console installed. If you already have it installed, you can skip to this section and continue reading. Otherwise you will see the following message as shown below:

    recovery-console-prompt.jpg

  • At the above message box, please click on the Yes button in order for ComboFix to continue. Please follow the steps and instructions given by ComboFix in order to finish the installation of the Recovery Console.
  • Please click on yes in the next window to continue scanning for malware.
  • ComboFix will now disconnect your computer from the Internet, so do not be surprised or concerned if you receive any warnings stating that you are no longer on the Internet. When ComboFix has finished it will automatically restore your Internet connection.
  • ComboFix will now start scanning your computer for known infections. This procedure can take some time, so please be patient.
  • While the program is scanning your computer, it will change your clock format, so do not be concerned when you see this happen. When ComboFix is finished it will restore your clock settings to their previous settings. You will also see the text in the ComboFix window being updated as it goes through the various stages of its scan. An example of this can be seen below.

    still-scanning-clockchanges.jpg

  • When ComboFix has finished running, you will see a screen stating that it is preparing the log report.
  • This can take a while, so please be patient. If you see your Windows desktop disappear, do not worry. This is normal and ComboFix will restore your desktop before it is finished. Eventually you will see a new screen that states the program is almost finished and telling you the programs log file, or report, will be located at C:\ComboFix.txt.
  • When ComboFix has finished, it will automatically close the program and change your clock back to its original format. It will then display the log file automatically for you.
  • Now you just click on the edit menu and click on select all, then click on the edit menu again and click on copy. Then come to the forum in your reply and right click on your mouse and click on paste.

If for some reason, if you try to run a program or open a file and you get an error message saying "illegal operation attempted on a registry key that has been marked for deletion", please just reboot your pc and you'll be fine.


In your next reply please post:
  • The ComboFix log
  • An update on how your computer is running

Also at this time, I would like for you to post a log that comofix produces but doesn't automatically show you. Please navigate to C:\Qoobox and in that folder will be a file named add-remove programs.txt. Open that file and copy and paste the contents back here.
 
sorry for taking ages to replay

ComboFix.exe:
ComboFix 13-09-26.03 - alaa 09/27/2013 21:31:15.2.2 - x86
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.3647.2564 [GMT 3:00]
Running from: d:\we will see you\ComboFix_2.exe
AV: AVG Internet Security 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
FW: AVG Internet Security 2012 *Disabled* {621CC794-9486-F902-D092-0484E8EA828B}
SP: AVG Internet Security 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
c:\program files\Your Product\Uninstall
c:\program files\Your Product\Uninstall\IRIMG1.JPG
c:\program files\Your Product\Uninstall\IRIMG2.JPG
c:\program files\Your Product\Uninstall\uninstall.dat
c:\program files\Your Product\Uninstall\uninstall.xml
c:\programdata\1338625323.2196.bin
c:\programdata\1338625323.2360.bin
c:\programdata\1338625323.3232.bin
c:\programdata\1338625323.3872.bin
c:\programdata\1338625323.4576.bin
c:\programdata\1338625323.4788.bin
c:\programdata\1338625323.5264.bin
c:\programdata\1338625323.5876.bin
c:\programdata\1338625323.5892.bin
c:\programdata\1338643477.bdinstall.bin
c:\programdata\1338713866.bdinstall.bin
c:\programdata\1338714000.bdinstall.bin
c:\programdata\1338718353.bdinstall.bin
c:\programdata\1338721512.bdinstall.bin
c:\programdata\1338722270.bdinstall.bin
c:\programdata\1341405866.bdinstall.bin
c:\programdata\1341777259.bdinstall.bin
C:\SVCHOST.EXE
c:\users\alaa\AppData\Roaming\Cashfiesta
c:\users\alaa\AppData\Roaming\Cashfiesta\Diag.log
c:\users\alaa\AppData\Roaming\Cashfiesta\rshamoon.dat
c:\windows\system32\nsx7977.tmp
c:\windows\system32\tmp3D88.tmp
c:\windows\system32\tmp4A3C.tmp
c:\windows\system32\tmp4A4C.tmp
D:\Autorun.inf
E:\autorun.inf
.
.
((((((((((((((((((((((((( Files Created from 2013-08-27 to 2013-09-27 )))))))))))))))))))))))))))))))
.
.
2013-09-27 18:38 . 2013-09-27 18:38 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-09-27 18:38 . 2013-09-27 18:38 -------- d-----w- c:\users\UpdatusUser.alaa-PC\AppData\Local\temp
2013-09-27 18:38 . 2013-09-27 18:38 -------- d-----w- c:\users\the peoples computer\AppData\Local\temp
2013-09-27 18:38 . 2013-09-27 18:38 -------- d-----w- c:\users\Guest\AppData\Local\temp
2013-09-27 18:38 . 2013-09-27 18:38 -------- d-----w- c:\users\fbwuser\AppData\Local\temp
2013-09-27 18:38 . 2013-09-27 18:38 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-09-27 17:39 . 2013-09-27 18:38 -------- d-----w- c:\users\alaa\AppData\Local\temp
2013-09-27 12:17 . 2013-09-27 12:17 -------- d-----w- c:\users\alaa\AppData\Local\SkinSoft
2013-09-16 09:30 . 2013-09-16 09:30 4806016 ----a-w- c:\program files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll
2013-09-16 09:30 . 2013-09-16 09:30 4806016 ----a-w- c:\program files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll
2013-09-15 18:42 . 2013-09-15 18:42 -------- d-----w- c:\users\alaa\AppData\Roaming\DAEMON Tools Ult
2013-09-15 18:42 . 2013-09-15 18:42 -------- d-----w- c:\programdata\DAEMON Tools Ult
2013-09-14 20:19 . 2013-08-05 01:56 133056 ----a-w- c:\windows\system32\drivers\ataport.sys
2013-09-14 20:19 . 2013-08-08 01:03 2348544 ----a-w- c:\windows\system32\win32k.sys
2013-09-12 13:55 . 2013-03-06 02:35 8950560 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2013-09-12 13:53 . 2013-03-04 14:14 3053030 ----a-w- c:\windows\system32\nvcoproc.bin
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-09-20 10:17 . 2012-02-08 18:58 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-09-20 10:17 . 2011-09-26 15:19 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-08-26 15:51 . 2013-08-26 15:51 466008 ----a-w- c:\windows\system32\drivers\sptd.sys
2013-08-24 16:02 . 2013-08-24 16:02 388096 ----a-r- c:\users\alaa\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2013-08-24 01:13 . 2013-08-24 01:09 24704 ----a-w- c:\windows\system32\drivers\dtscsibus.sys
2013-08-06 07:28 . 2013-08-27 18:03 7166848 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{64DC9D94-F46E-4B22-8610-567C07F3A8C5}\mpengine.dll
2013-07-25 08:57 . 2013-08-14 00:58 1620992 ----a-w- c:\windows\system32\WMVDECOD.DLL
2013-07-19 01:41 . 2013-08-14 00:51 2048 ----a-w- c:\windows\system32\tzres.dll
2013-07-17 21:46 . 2013-07-17 21:46 94632 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-07-17 21:46 . 2012-01-22 10:29 867240 ----a-w- c:\windows\system32\npdeployJava1.dll
2013-07-17 21:46 . 2011-12-11 18:48 789416 ----a-w- c:\windows\system32\deployJava1.dll
2013-07-09 05:03 . 2013-08-14 00:53 3968960 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-07-09 05:03 . 2013-08-14 00:53 3913664 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-07-09 04:53 . 2013-08-14 00:53 1289096 ----a-w- c:\windows\system32\ntdll.dll
2013-07-09 04:52 . 2013-08-14 00:59 175104 ----a-w- c:\windows\system32\wintrust.dll
2013-07-09 04:50 . 2013-08-14 00:51 652800 ----a-w- c:\windows\system32\rpcrt4.dll
2013-07-09 04:46 . 2013-08-14 00:59 140288 ----a-w- c:\windows\system32\cryptsvc.dll
2013-07-09 04:46 . 2013-08-14 00:59 1166848 ----a-w- c:\windows\system32\crypt32.dll
2013-07-09 04:46 . 2013-08-14 00:59 103936 ----a-w- c:\windows\system32\cryptnet.dll
2013-07-06 05:05 . 2013-08-14 00:51 1293760 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-12-20 18:10 235008 --shatr- c:\windows\System32\FltEng.dll
2011-12-20 18:12 61440 --shatr- c:\windows\System32\secpro.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\IDM Shell Extension]
@="{CDC95B92-E27C-4745-A8C5-64A52A78855D}"
[HKEY_CLASSES_ROOT\CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D}]
2012-11-15 23:07 21904 ----a-w- c:\program files\Internet Download Manager\IDMShellExt.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="e:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2013-01-31 3540416]
"Copernic Desktop Search - Home"="c:\program files\Copernic Desktop Search - Home\DesktopSearchService.exe" [2012-09-28 1691240]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
"BitTorrent"="c:\program files\BitTorrent\BitTorrent.exe" [2013-05-03 882520]
"Airytec Switch Off"="c:\program files\Airytec\Switch Off\swoff.exe" [2011-05-28 135168]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2013-06-21 19875432]
"DAEMON Tools Ultra Agent"="c:\program files\DAEMON Tools Ultra\DTAgent.exe" [2013-06-25 3128352]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PCTVOICE"="pctspk.exe" [2002-12-05 163840]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-02-11 172568]
"TV Card Remote Control Device Monitor"="c:\windows\713xRMT.exe" [2008-06-17 466944]
"AVG_TRAY"="d:\program files\AVG\AVG2012\avgtray.exe" [2012-11-19 2598520]
"nmapp"="d:\program files\Pure Networks\Network Magic\nmapp.exe" [2012-07-22 472112]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
"Nvtmru"="c:\program files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-07-27 1028896]
"HDAudDeck"="c:\program files\VIA\VIAudioi\VDeck\VDeck.exe" [2009-12-04 1728512]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2012-11-05 89184]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
TVMOBiLiArtworkManager.lnk - c:\program files\TVMOBiLi\bin\iTunesAlbumArtGenerator.exe "/path:c:\programdata\TVMOBiLi\cache" [2012-2-11 66048]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0d:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^TV Expert Schedule Agent.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\TV Expert Schedule Agent.lnk
backup=c:\windows\pss\TV Expert Schedule Agent.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^Users^alaa^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Serviio.lnk]
path=c:\users\alaa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Serviio.lnk
backup=c:\windows\pss\Serviio.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]
2012-11-05 12:27 89184 ----a-w- c:\program files\Microsoft Office\Office14\BCSSync.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
2013-05-03 11:12 882520 ----a-w- c:\program files\BitTorrent\BitTorrent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Ultra Agent]
2013-06-25 08:51 3128352 ----a-w- c:\program files\DAEMON Tools Ultra\DTAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update]
2012-07-12 16:52 138096 ----atw- c:\users\alaa\AppData\Local\Facebook\Update\FacebookUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FlyOnDesktopPro]
2011-07-12 10:32 976896 ----a-w- d:\program files\Fly on Desktop\FlyOnDesktop.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\googletalk]
2007-01-01 21:22 3739648 ----a-w- c:\users\alaa\AppData\Roaming\Google\Google Talk\googletalk.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDMan]
2013-01-31 08:20 3540416 ----a-w- c:\program files\Internet Download Manager\IDMan.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nmctxth]
2009-07-07 11:48 647216 ----a-w- c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2010-11-20 12:17 1174016 ----a-w- c:\program files\Windows Sidebar\sidebar.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2013-06-21 06:58 19875432 ----a-r- c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Speech Recognition]
2009-07-14 01:14 51712 ----a-w- c:\windows\Speech\Common\sapisvr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SRS Audio Sandbox]
2011-11-08 12:01 3215360 ----a-w- c:\program files\SRS Labs\Audio Sandbox\SRSSSC.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2013-03-12 04:32 253816 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2011-11-08 12:07 185896 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
.
R0 amdkmafd;AMD Audio Bus Lower Filter;c:\windows\system32\DRIVERS\amdkmafd.sys [2013-05-04 15968]
R2 AVGIDSAgent;AVGIDSAgent;d:\program files\AVG\AVG2012\avgidsagent.exe [2012-11-02 5174392]
R2 KMService;KMService;c:\windows\system32\srvany.exe [2010-05-31 8192]
R2 SecStore;Secure Storage;c:\windows\system32\secpro.exe [2011-12-20 61440]
R2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2013-09-16 3273088]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2013-06-21 162408]
R2 SwOffScheduler;Airytec Switch Off - Task Scheduler;c:\program files\Airytec\Switch Off\swoff.exe [2011-05-28 135168]
R2 SwOffWeb;Airytec Switch Off - Web Interface;c:\program files\Airytec\Switch Off\swoff.exe [2011-05-28 135168]
R2 tvMobiliService;tvMobiliService;c:\program files\TVMOBiLi\bin\tvMobiliService.exe [2012-02-11 1051648]
R3 3xHybrid;SAA713x TV Card Service;c:\windows\system32\DRIVERS\3xHybrid.sys [2010-12-01 1141888]
R3 athur;Atheros AR9271 Wireless Network Adapter Service;c:\windows\system32\DRIVERS\athur.sys [2013-03-05 1570816]
R3 BthAvrcp;Bluetooth AVRCP Profile;c:\windows\system32\DRIVERS\BthAvrcp.sys [2009-08-13 22528]
R3 CV2K1;CommView Network Monitor; [x]
R3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\DRIVERS\ew_hwusbdev.sys [x]
R3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys [x]
R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [2012-10-29 12400]
R3 huawei_enumerator;huawei_enumerator;c:\windows\system32\DRIVERS\ew_jubusenum.sys [x]
R3 hwusbdev;Huawei DataCard USB PNP Device; [x]
R3 NPF;WinPcap Packet Driver (NPF);c:\windows\system32\drivers\NPF.sys [2010-06-25 35088]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848]
R3 s1039bus;Sony Ericsson Device 1039 driver (WDM);c:\windows\system32\DRIVERS\s1039bus.sys [2010-03-15 98672]
R3 s1039mdfl;Sony Ericsson Device 1039 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s1039mdfl.sys [2010-03-15 14960]
R3 s1039mdm;Sony Ericsson Device 1039 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s1039mdm.sys [2010-03-15 124016]
R3 s1039mgmt;Sony Ericsson Device 1039 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s1039mgmt.sys [2010-03-15 117872]
R3 s1039nd5;Sony Ericsson Device 1039 USB Ethernet Emulation (NDIS);c:\windows\system32\DRIVERS\s1039nd5.sys [2010-03-15 25456]
R3 s1039obex;Sony Ericsson Device 1039 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s1039obex.sys [2010-03-15 113904]
R3 s1039unic;Sony Ericsson Device 1039 USB Ethernet Emulation (WDM);c:\windows\system32\DRIVERS\s1039unic.sys [2010-03-15 123504]
R3 Synth3dVsc;Synth3dVsc; [x]
R3 tapoas;TAP-Win32 Adapter OAS;c:\windows\system32\DRIVERS\tapoas.sys [2010-08-03 26112]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 49664]
R3 tsusbhub;tsusbhub; [x]
R3 VGPU;VGPU; [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-09-23 1343400]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 51040]
S0 AVGIDSHX;AVGIDSHX;c:\windows\system32\DRIVERS\avgidshx.sys [2012-04-19 24896]
S0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx86.sys [2012-01-31 31952]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 Avgfwfd;AVG network filter service;c:\windows\system32\DRIVERS\avgfwd6x.sys [2011-05-22 47968]
S1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx86.sys [2012-11-08 250080]
S1 Avgtdix;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdix.sys [2013-04-11 302368]
S1 HssDRV6;Hotspot Shield Routing Driver 6;c:\windows\system32\DRIVERS\hssdrv6.sys [2013-06-21 41160]
S1 TsLwWfF;WiFi Capture Driver;c:\windows\system32\DRIVERS\TsLwWfF.sys [2011-05-12 22632]
S2 avgfws;AVG Firewall;d:\program files\AVG\AVG2012\avgfws.exe [2012-12-05 2321560]
S2 avgwd;AVG WatchDog;d:\program files\AVG\AVG2012\avgwdsvc.exe [2012-02-14 193288]
S2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x32.sys [2011-09-21 21992]
S2 hshld;Hotspot Shield Service;c:\program files\Hotspot Shield\bin\cmw_srv.exe [2013-09-17 878888]
S2 HssWd;Hotspot Shield Monitoring Service;c:\program files\Hotspot Shield\bin\hsswd.exe [2013-09-17 556840]
S2 IDMWFP;IDMWFP;c:\windows\system32\DRIVERS\idmwfp.sys [2013-05-25 102344]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2013-07-27 14592288]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-03-05 383264]
S2 VIAKaraokeService;VIA Karaoke digital mixer Service;c:\windows\system32\viakaraokesrv.exe [2013-03-16 27768]
S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdriverx.sys [2012-12-10 142176]
S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\avgidsfilterx.sys [2011-12-23 24144]
S3 AVGIDSShim;AVGIDSShim;c:\windows\system32\DRIVERS\avgidsshimx.sys [2011-12-23 17232]
S3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\DRIVERS\clwvd.sys [2011-04-14 27760]
S3 Disc Soft Bus Service;Disc Soft Bus Service;c:\program files\DAEMON Tools Ultra\DiscSoftBusService.exe [2013-06-25 632352]
S3 dtscsibus;DAEMON Tools Virtual SCSI Bus;c:\windows\system32\DRIVERS\dtscsibus.sys [2013-08-24 24704]
S3 netr28u;RT2870 USB Extensible Wireless LAN Card Driver;c:\windows\system32\DRIVERS\netr28u.sys [2011-11-16 1270848]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad32v.sys [2013-05-14 34592]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2013-03-05 585872]
S3 taphss6;Anchorfree HSS VPN Adapter;c:\windows\system32\DRIVERS\taphss6.sys [2013-04-24 37064]
S3 VCSVADHWSer;Avnex Virtual Audio Device (WDM);c:\windows\system32\DRIVERS\vcsvad.sys [2008-12-26 17792]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2009-11-25 1108480]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
Contents of the 'Scheduled Tasks' folder
.
2013-09-27 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-02-08 10:17]
.
2013-09-27 c:\windows\Tasks\DriverScanner.job
- d:\program files\Uniblue\DriverScanner\dsmonitor.exe [2012-04-30 11:07]
.
2013-09-27 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3860670502-1900623974-4232932808-1000Core.job
- c:\users\alaa\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-06-15 16:52]
.
2013-09-27 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3860670502-1900623974-4232932808-1000UA.job
- c:\users\alaa\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-06-15 16:52]
.
2013-09-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-09-05 03:43]
.
2013-09-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-09-05 03:43]
.
2013-09-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3860670502-1900623974-4232932808-1000Core.job
- c:\users\alaa\AppData\Local\Google\Update\GoogleUpdate.exe [2012-05-12 18:47]
.
2013-09-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3860670502-1900623974-4232932808-1000UA.job
- c:\users\alaa\AppData\Local\Google\Update\GoogleUpdate.exe [2012-05-12 18:47]
.
2013-09-27 c:\windows\Tasks\RegistryBooster.job
- c:\program files\Uniblue\RegistryBooster\rbmonitor.exe [2012-01-05 08:26]
.
2013-01-31 c:\windows\Tasks\ROC_REG_JAN_DELETE.job
- c:\programdata\AVG January 2013 Campaign\ROC.exe [2013-01-30 21:16]
.
.
------- Supplementary Scan -------
.
uStart Page = https://www.google.com.qa/
IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: E&xport to Microsoft Excel - c:\program files\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\program files\MICROS~1\Office14\ONBttnIE.dll/105
IE: Search the Web
TCP: DhcpNameServer = 192.168.1.1 192.168.1.1
FF - ProfilePath - c:\users\alaa\AppData\Roaming\Mozilla\Firefox\Profiles\s74kbspm.default\
FF - prefs.js: network.proxy.ftp - 127.0.0.1
FF - prefs.js: network.proxy.ftp_port - 8555
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 8555
FF - prefs.js: network.proxy.socks - 127.0.0.1
FF - prefs.js: network.proxy.socks_port - 8555
FF - prefs.js: network.proxy.ssl - 127.0.0.1
FF - prefs.js: network.proxy.ssl_port - 8555
FF - prefs.js: network.proxy.type - 0
FF - ExtSQL: 2013-08-06 21:04; [email protected]; c:\users\alaa\AppData\Roaming\Mozilla\Firefox\Profiles\s74kbspm.default\extensions\[email protected]
FF - ExtSQL: 2013-08-23 04:40; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\users\alaa\AppData\Roaming\Mozilla\Firefox\Profiles\s74kbspm.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF - ExtSQL: 2013-08-24 05:21; [email protected]; c:\program files\Mozilla Firefox\browser\extensions\[email protected]
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{88c7f2aa-f93f-432c-8f0e-b7d85967a527} - (no file)
WebBrowser-{88C7F2AA-F93F-432C-8F0E-B7D85967A527} - (no file)
HKLM-Run-VIAAUD - c:\program files\VIA\VIAudioi\VDeck\VIAAUD.exe
MSConfigStartUp-APSDaemon - c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe
MSConfigStartUp-msnmsgr - c:\program files\Windows Live\Messenger\msnmsgr.exe
MSConfigStartUp-Sony Ericsson PC Companion - c:\program files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe
MSConfigStartUp-Sony PC Companion - c:\program files\Sony\Sony PC Companion\PCCompanion.exe
MSConfigStartUp-Steam - d:\program files\Steam\Steam.exe
MSConfigStartUp-YouCam Service - e:\program files\CyberLink\YouCam\YouCam\YouCamService.exe
AddRemove-ContinueToSave - c:\progra~1\INSTAL~2\CONTIN~1\Setup.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{98889811-442D-49DD-99D7-DC866BE87DBC}"=hex:51,66,7a,6c,4c,1d,38,12,7f,9b,9b,
9c,1f,0a,b3,0c,e6,c1,9f,c6,6e,b6,39,a8
"{0055C089-8582-441B-A0BF-17B458C2A3A8}"=hex:51,66,7a,6c,4c,1d,38,12,e7,c3,46,
04,b0,cb,75,01,df,a9,54,f4,5d,9c,e7,bc
"{2EECD738-5844-4A99-B4B6-146BF802613B}"=hex:51,66,7a,6c,4c,1d,38,12,56,d4,ff,
2a,76,16,f7,0f,cb,a0,57,2b,fd,5c,25,2f
"{72853161-30C5-4D22-B7F9-0BBC1D38A37E}"=hex:51,66,7a,6c,4c,1d,38,12,0f,32,96,
76,f7,7e,4c,08,c8,ef,48,fc,18,66,e7,6a
"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,
94,30,02,d1,0f,f1,da,12,24,73,56,27,d2
"{9CFACCB6-2F3F-4177-94EA-0D2B72D384C1}"=hex:51,66,7a,6c,4c,1d,38,12,d8,cf,e9,
98,0d,61,19,04,eb,fc,4e,6b,77,8d,c0,d5
"{9FDDE16B-836F-4806-AB1F-1455CBEFF289}"=hex:51,66,7a,6c,4c,1d,38,12,05,e2,ce,
9b,5d,cd,68,0d,d4,09,57,15,ce,b1,b6,9d
"{AD4DF010-E2FD-43CE-864A-6BD1EDC59AC2}"=hex:51,66,7a,6c,4c,1d,38,12,7e,f3,5e,
a9,cf,ac,a0,06,f9,5c,28,91,e8,9b,de,d6
"{B4F3A835-0E21-4959-BA22-42B3008E02FF}"=hex:51,66,7a,6c,4c,1d,38,12,5b,ab,e0,
b0,13,40,37,0c,c5,34,01,f3,05,d0,46,eb
"{CA4520F3-AE13-4FB1-A513-58E23991C86D}"=hex:51,66,7a,6c,4c,1d,38,12,9d,23,56,
ce,21,e0,df,0a,da,05,1b,a2,3c,cf,8c,79
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,
df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd
"{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}"=hex:51,66,7a,6c,4c,1d,38,12,8f,19,47,
2e,c4,15,0b,03,d7,b5,8c,e9,62,70,06,85
"{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}"=hex:51,66,7a,6c,4c,1d,38,12,35,fc,e1,
93,3e,68,a1,09,fc,5c,6e,9a,4b,77,a7,8a
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:8b,0e,80,c7,84,28,cd,01
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.032\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.032"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.abr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.abr"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ani\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.ani"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.arw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.arw"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bay\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.bay"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bmp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.bmp"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.bw"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cr2\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.cr2"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.crw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.crw"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cs1\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.cs1"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cur\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.cur"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.dcr"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.dcx"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dib\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.dib"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.djv\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.djv"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.djvu\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.djvu"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dng\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.dng"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.emf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.emf"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eps\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.eps"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.erf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.erf"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fff\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.fff"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fpx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.fpx"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.gif"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hdr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.hdr"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.icl\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.icl"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.icn\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.icn"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iff\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.iff"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ilbm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.ilbm"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.int\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.int"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.inta\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.inta"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iw4\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.iw4"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2c\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.j2c"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2k\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.j2k"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jbr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.jbr"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jfif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.jfif"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.jif"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jp2\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.jp2"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpc\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.jpc"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpe\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.jpe"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpeg\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.jpeg"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpg\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.jpg"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpk\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.jpk"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.jpx"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.kdc\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.kdc"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.lbm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.lbm"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mef\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.mef"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mos\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.mos"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mrw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.mrw"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nef\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.nef"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.orf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.orf"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pbm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.pbm"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pbr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.pbr"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcd\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.pcd"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pct\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.pct"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.pcx"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pef\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.pef"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pgm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.pgm"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pic\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.pic"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pict\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.pict"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pix\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.pix"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.png\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.png"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.ppm"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psd\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.psd"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.psp"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pspbrush\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.pspbrush"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pspimage\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.pspimage"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.raf"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ras\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.ras"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.raw"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rgb\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.rgb"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rgba\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.rgba"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rle\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.rle"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rsb\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.rsb"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sgi\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.sgi"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sr2\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.sr2"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.srf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.srf"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tga\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.tga"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.thm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.thm"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.tif"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tiff\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.tiff"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttc\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.ttc"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.ttf"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v25po\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.v25po"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v25pp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.v25pp"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v25ppf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.v25ppf"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.wbm"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbmp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.wbmp"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.wmf"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xbm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.xbm"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.xif"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xmp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.xmp"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xpm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.xpm"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:57,0d,f5,cf,09,ce,64,72,a1,a9,6a,38,fe,f1,13,20,6a,c5,d5,57,64,b4,6e,
99,ef,f0,78,b3,2e,cd,01,a5,c2,89,07,ec,3b,58,27,d1,3f,07,c6,44,a4,69,51,30,\
"??"=hex:11,01,07,25,28,34,44,2c,1e,78,48,f2,95,f6,67,0b
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000_Classes\CLSID\{01051598-dc7a-4e8e-9e06-921d50dce07f}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"Model"=dword:00000119
"Therad"=dword:0000001e
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
38,95,44,75,07,18,dd,fb,11,42,94,27,b7,99,0d,2a,ba,05,1a,a2,02,c9,3e,9b,f9,\
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000_Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"scansk"=hex(0):9e,23,e2,0c,58,1c,44,94,49,7d,c4,b4,e5,8c,c4,37,83,f6,09,9c,9e,
c0,1a,3b,ca,31,30,e0,7a,f6,13,cb,07,df,a2,a7,35,45,46,96,00,00,00,00,00,00,\
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000_Classes\CLSID\{67447f24-47b4-4b25-9aaa-8760a64e11cc}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"Model"=dword:00000155
"Therad"=dword:00000015
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a,
1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000_Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):b7,41,5c,c5,ed,31,db,5c,2e,ee,60,00,ff,91,6f,73,3d,f2,62,03,77,
71,e7,fe,8e,61,bf,e8,e4,37,f4,c2,5f,cb,9f,94,55,5a,d4,77,00,00,00,00,00,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'Explorer.exe'(436)
d:\program files\Pure Networks\Network Magic\nmrsrc.dll
c:\program files\Common Files\Pure Networks Shared\Platform\puresp4.dll
.
Completion time: 2013-09-27 21:39:42
ComboFix-quarantined-files.txt 2013-09-27 18:39
.
Pre-Run: 22,864,445,440 bytes free
Post-Run: 22,741,950,464 bytes free
.
- - End Of File - - DEEE172C6D60C5643077E399C07EC628
A36C5E4F47E84449FF07ED3517B43A31


Add-Remove Programs:

ACDSee Pro 2.5
Active@ UNDELETE 7
Adobe AIR
Adobe Audition 1.5
Adobe Download Assistant
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Advertising Center
aeon-flux.themepack
Airytec Switch Off
alicewonderland.themepack
alienware.themepack
Any Video Converter 3.3.7
Assassin's Creed III
Assassin's Creed(R) III v1.05
assassins-creed-revelations.themepack
AVG 2012
BioShock Infinite version 1.0.0.0
BitTorrent
Cain & Abel v2.5 beta44
Cain & Abel v4.9.42
CBR Reader
Cisco Network Magic
Command & Conquer Generals
Command & Conquer™ Red Alert™ 3
Command and ConquerTM Generals Zero Hour
CommView for WiFi
Company of Heroes 2 version 5.1
Copernic Desktop Search - Home
Counter-Strike 1.6
CPUID CPU-Z 1.59
D3DX10
DAEMON Tools Ultra
dark-knight-joker.themepack
Darksiders II
DarksidersInstaller
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition
DolbyFiles
Facebook Video Calling 1.2.0.287
Fly on Desktop 1.3
game-posters.themepack
Google Earth Plug-in
Google Talk (remove only)
Google Talk Plugin
Google Update Helper
HiJackThis
Hotspot Shield 3.17
HSF 2868 MicroModem Drivers
ImagXpress
Internet Download Manager
Internet TV for Windows Media Center
Java 7 Update 25
Java Auto Updater
JonDo
Junk Mail filter update
lightningwin7.themepack
Media Go
Media Go Video Playback Engine 1.120.107.05010
Menu Templates - Starter Kit
Mesh Runtime
Messenger Companion
Microsoft .NET Compact Framework 3.5
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Extended
Microsoft Application Error Reporting
Microsoft Office Access MUI (English) 2010
Microsoft Office Access Setup Metadata MUI (English) 2010
Microsoft Office Excel MUI (English) 2010
Microsoft Office Groove MUI (English) 2010
Microsoft Office InfoPath MUI (English) 2010
Microsoft Office OneNote MUI (English) 2010
Microsoft Office Outlook Connector
Microsoft Office Outlook MUI (English) 2010
Microsoft Office PowerPoint MUI (English) 2010
Microsoft Office Professional Plus 2010
Microsoft Office Proof (English) 2010
Microsoft Office Proof (French) 2010
Microsoft Office Proof (Spanish) 2010
Microsoft Office Proofing (English) 2010
Microsoft Office Publisher MUI (English) 2010
Microsoft Office Shared MUI (English) 2010
Microsoft Office Shared Setup Metadata MUI (English) 2010
Microsoft Office Word MUI (English) 2010
Microsoft Outlook Social Connector Provider for Windows Live Messenger 32-bit
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable - KB2467175
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Microsoft Visual C++ Run Time Lib Setup
Microsoft WSE 3.0 Runtime
Microsoft XNA Framework Redistributable 3.1
Microsoft_VC100_CRT_SP1_x86
Movie Templates - Starter Kit
Mozilla Firefox 21.0 (x86 en-US)
Mozilla Firefox 23.0.1 (x86 en-US)
Mozilla Maintenance Service
MP3 Cut 5.5.1
MPC-HC 1.6.8
MSVC80_x86_v2
MSVC90_x86
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MusicBrainz Picard
Nero BurnRights
Nero ControlCenter
Nero CoverDesigner
Nero DiscSpeed
Nero DriveSpeed
Nero InfoTool
Nero Installer
Nero Live
Nero PhotoSnap
Nero Recode
Nero Rescue Agent
Nero ShowTime
Nero StartSmart
Nero Vision
Nero WaveEditor
NeroBurningROM
NeroExpress
NeroLiveGadget
neroxml
Network Magic
Network Manager Setup
NVIDIA 3D Vision Controller Driver 314.16
NVIDIA 3D Vision Driver 314.16
NVIDIA Control Panel 314.16
NVIDIA GeForce Experience 1.6
NVIDIA Graphics Driver 314.16
NVIDIA HD Audio Driver 1.3.23.1
NVIDIA Install Application
NVIDIA PhysX
NVIDIA PhysX System Software 9.13.0604
NVIDIA Stereoscopic 3D Driver
NVIDIA Update 7.2.17
NVIDIA Update Components
NVIDIA Virtual Audio 1.2.1
ooVoo
PC Wizard 2012.2.12
Platform
PlayReady PC Runtime x86
PlayStation(R)Store
POD-Bot 2.5
popwarriortej.themepack
Pro Evolution Soccer
Pure Networks Platform
QuickTime
RAD Video Tools
Readiris Pro 10 Demo
RealPlayer
Red Alert 3 Uprising
Republic Heroes
RocketDock 1.3.5
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2835393)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628v2)
Security Update for Microsoft .NET Framework 4 Extended (KB2416472)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
Security Update for Microsoft .NET Framework 4 Extended (KB2736428)
Security Update for Microsoft .NET Framework 4 Extended (KB2742595)
Security Update for Microsoft Excel 2010 (KB2760597) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2687423) 32-Bit Edition
Security Update for Microsoft Outlook 2010 (KB2794707) 32-Bit Edition
Security Update for Microsoft Word 2010 (KB2760769) 32-Bit Edition
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition
SHIELD Streaming
Sierra Utilities
simpsons_0.themepack
Skype Click to Call
Skype™ 6.6
Sniper Ghost Warrior 2 version 5.1
sony-playstation.themepack
Sony Ericsson Update Engine
SoundTrax
SRS Audio Sandbox
Steam
swine-flu.themepack
System Requirements Lab CYRI
System Requirements Lab Detection
Team Fortress 2
Tenda Wireless LAN Card
terminatorsalvation.themepack
The Sims™ 3
thematrix.themepack
Tomb Raider version 5.1
TV Expert
TVMOBiLi
Ubuntu
Ultimate Reference Suite
Uniblue DriverScanner
Uniblue RegistryBooster
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2473228)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2600217)
Update for Microsoft .NET Framework 4 Extended (KB2836939)
Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition
Update for Microsoft Filter Pack 2.0 (KB2810071) 32-Bit Edition
Update for Microsoft Office 2010 (KB2494150)
Update for Microsoft Office 2010 (KB2553157) 32-Bit Edition
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition
Update for Microsoft Office 2010 (KB2589370) 32-Bit Edition
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition
Update for Microsoft Office 2010 (KB2760758) 32-Bit Edition
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition
Update for Microsoft Office 2010 (KB2825640) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2810072) 32-Bit Edition
Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition
Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition
Uplay
USB Storage Driver
vg-cities-art.themepack
VIA Platform Device Manager
VLC media player 1.0.1
WildPackets AiroPeek Demo
WildPackets OmniPeek Personal 4.1
Windows Live Communications Platform
Windows Live Essentials
Windows Live Family Safety
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Mail
Windows Live Mesh
Windows Live Messenger
Windows Live Messenger Companion Core
Windows Live MIME IFilter
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live Remote Client
Windows Live Remote Client Resources
Windows Live Remote Service
Windows Live Remote Service Resources
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
WinPcap 4.1.2
Wireshark 1.6.6
Word Reader 6.24
Yahoo! Messenger
Your Product
Yu-Gi-Oh! Power of Chaos LEGEND REBORN
 
I highly suggest uninstalling the following programs. Uniblue products are crap and not needed. If you are downloading and installing pirated copies of programs using torrent software then you could be getting yourself infected.

bitTorrent
Uniblue DriverScanner
Uniblue RegistryBooster

These two programs could be part of the cause of your issue.

WinPcap 4.1.2
Wireshark 1.6.6

You really have no use for those two programs unless you are a network admin or something like that.

Please also download and run junkware removal tool.

Please download Junkware Removal Tool to your desktop.

•Shutdown your antivirus to avoid any conflicts.

•Very important that you run the tool in this manner:
Right-mouse click JRT.exe and select Run as administrator
Do NOT just double-click it.

•The tool will open and start scanning your system.

•Please be patient as this can take a while to complete.

•On completion, a log (JRT.txt) is saved to your desktop and will automatically open.

•Post the contents of JRT.txt in your next message.
 
i uninstalled Uniblue Driver Scanner and Uniblue Registry Booster, about bit Torrent i tried uninstalling it before to fix the problem but it didn't work and about WinPcap and Wireshark i don't use them regularly but some times i need them
JRT.txt:(part one)
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.3 (09.27.2013:1)
OS: Windows 7 Ultimate x86
Ran by alaa on Sun 09/29/2013 at 14:49:49.75
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services

Failed to stop: [Service] hshld
Successfully stopped: [Service] hsstrayservice
Successfully deleted: [Service] hsstrayservice
Successfully stopped: [Service] hsswd
Successfully deleted: [Service] hsswd



~~~ Registry Values

Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\anchorfree
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\SweetIM
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\hotspotshield
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\driverscanner
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\speedupmypc
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\apnstub_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\apnstub_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\driverscanner_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\driverscanner_rasmancs
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{33333333-3333-3333-3333-330033343391}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110111251155}



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\ProgramData\hotspot shield"
Successfully deleted: [Folder] "C:\ProgramData\splashtop"
Successfully deleted: [Folder] "C:\ProgramData\starapp"
Successfully deleted: [Folder] "C:\Users\alaa\AppData\Roaming\hotspot shield"
Successfully deleted: [Folder] "C:\Users\alaa\appdata\local\downloadterms"
Successfully deleted: [Folder] "C:\Users\alaa\appdata\local\jollywallet"
Successfully deleted: [Folder] "C:\Users\alaa\appdata\local\updater12555"
Successfully deleted: [Folder] "C:\Users\alaa\appdata\locallow\mybabylon_english"
Successfully deleted: [Folder] "C:\Program Files\hotspot shield"
Successfully deleted: [Folder] "C:\Program Files\mybabylon_english"
Successfully deleted: [Folder] "C:\Program Files\splashtop"
Successfully deleted: [Folder] "C:\Program Files\your product"
Successfully deleted: [Folder] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\uniblue"
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{00A75CF0-CDBA-43C6-97AB-AE3EEA051661}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{00C42859-3064-432B-AA24-3CC17C438786}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{00D92063-113A-4926-9450-F28B70A4E422}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{01389EB0-D2B6-4A7D-AEEF-2E7D4803BE54}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{0244F65D-7083-4BF2-916D-8D51848C9099}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{028A7A59-9C3B-4C0A-9528-48EFA80D5ACE}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{02A2CFC4-7A3E-40FD-9C4A-1E5238BF79B3}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{02F34D42-C9BD-4277-AEA3-B4C945158647}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{04495F95-346F-4017-AE2C-FDBC13974E8A}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{04BEF6A0-7696-4DA9-86ED-B62F1F2FA454}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{053860C0-C562-45E4-A74B-86162A2390D4}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{05CF56AE-0DC8-4716-BA28-FD13847EF064}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{0615E0BB-C48A-4494-A3F1-2E9CA77966AC}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{06202CEB-1244-410D-B59E-5C7BD6E9E490}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{0657756A-5D28-41F1-8A64-6F1294D88EF0}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{075BCA38-7193-458D-9798-5F71B14BF491}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{082B6240-1C66-49DE-A59C-A7D811F709C9}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{087BDE4C-F932-4C4A-B293-808E1187AC5F}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{08D8BFF7-DCC3-4115-8A29-87701CFA138F}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{08FB2E43-32A0-4785-9A06-063AB681BB0A}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{094C4716-8273-41B9-9752-23F02A75F686}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{099BEA69-2C83-4434-9B7D-066F7EBCC894}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{0A716A6E-8EA5-4FC1-8E1D-D2ADAEC58C3D}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{0A9CDFD0-B0A3-4FFB-90BC-95EA16709FB7}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{0C57C140-E06F-4A5B-9EE2-EDC7DEF1079D}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{0C7549CC-4B4C-471A-A14C-D721DA887FAE}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{0C9B0F73-5C0A-4ADC-8AAA-04B4ED398E1A}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{0D7A3A23-05FD-4108-BC61-13FDACE097E9}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{0DD79863-A7CE-41D7-93E5-5B081CB62477}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{0E0839C1-236D-4892-9CB2-8AAB4B53D9CC}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{0EC86DD1-FB44-4A71-A954-2F6883497CBB}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{0ECB04CC-09A4-45A0-8872-928EB5EE7D69}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{0EED2356-0850-4A9A-BDE3-8AC480C98DA9}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{0F0351ED-15B1-4D2A-A823-19E3385CA544}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{0FAB538B-AA5C-43B9-9C0A-623D5EDBFFB3}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{10BBE841-5257-43E4-84FB-4A4071C25EFB}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{10DF52AD-C786-4971-A023-08F01AD41ED7}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{110B0A88-BDF6-413B-BD93-C9CC857BD576}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{113DBC91-7D70-41A4-9F3E-30059780EBC2}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{11B13D87-68E3-47E2-9D0A-C122AD9B20F5}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{12DCAB4C-BD47-43B5-BCDE-DE0923799F58}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{13040630-5BF7-4868-8AAD-E4FCEC922D78}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{1345680D-072E-4236-A409-95C22A196CEC}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{138745BD-D875-442D-97BD-249B97514307}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{13C37A46-8BCE-472D-9A59-E29EA9BCA233}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{13FD1394-C24E-4C10-B0AE-138ABEEDD5F6}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{1434EF58-1934-48C5-8069-152FF25A2F23}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{146C6A3A-D602-47F0-A25C-BEAD488D9776}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{146FEF05-6BC2-4384-B171-6ED44CA14B19}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{148D6CF7-E954-4A8F-AAE0-6AAEAD42645E}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{15A80D98-0554-45C5-AFC1-D30AB1B1A261}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{15AC02F5-D42E-485F-BB76-56289023809A}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{161929BA-2AFD-4EB8-883F-442206BEB578}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{1651CC94-29D4-4FA2-AE1F-3722A3B0885F}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{165A96A5-6E52-4119-8D8A-2F4092E79C62}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{16AFBFA9-48BF-42BD-8844-C55BFDC8B106}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{17AA07AC-886B-451F-8291-4F5AA6DD0BB4}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{17BCBAED-5499-4003-B427-137C261E76F7}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{17C0DF36-EF14-40FA-A5E0-ECC0307AAA1A}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{17F2F9C0-9E55-49C0-991A-9A43E49EF510}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{1816C39C-34A6-44F6-99B6-C1EDA6A1B47F}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{188071DB-ECF1-420C-BD08-A5CE9FAE8950}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{1958A829-00E5-46D6-AB1A-C899CAD7A324}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{19C59238-A952-4C32-92A9-AC1AD921B751}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{1AA21961-899F-408D-835C-7C4619B6DF06}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{1AAEAE9B-BFCA-4B7B-8A29-2F20DAA6CD4F}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{1B88D5C1-5725-4688-9433-A95D50849748}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{1BA0C2B2-4945-469C-BA50-735B3A0DADC2}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{1BE6A383-39DE-4DFF-ACE1-BD1F922D523B}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{1C3EA025-E12D-4B79-AC9D-E9515E2BD766}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{1D2D7873-F512-4EBD-85F4-B1D3459BA35D}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{1D2DEBB8-879B-47F1-ADEF-22DD4825FCB7}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{1D5CC82B-245C-4F4F-83FB-4596F99628B1}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{1D67C369-C48B-4465-A9BA-5B46FCD9799D}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{1DAD9519-5E3D-4DA3-BCA5-55F3D5146CF3}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{1DCC00F1-EB93-45C0-9E89-3581CD1DB033}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{1DD08969-77FA-4076-AEA2-3442842EEF19}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{1E3A5A88-79C6-4FB0-B68E-F8A4DEE9348C}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{1E7B5286-2649-4C61-A991-F6DC66F4867E}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{1F06CE6D-E81B-49E0-B11E-C871CDD67881}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{1F2C34F7-1CEF-4EF0-8E11-5F2A7003C004}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{2052B75B-BA92-410D-A2D1-BE267E5D4A94}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{205DE814-7E9A-44E7-8FEB-4D94286F2FDF}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{2066F817-1A64-466D-A63D-4818D3F00200}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{207D1E80-897A-4AE9-906C-6C8E404054BD}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{21209DA9-F2A8-4345-9FD8-359E711584FC}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{21264512-CD52-45F4-98DD-97B4A12F4AE2}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{22A5D6DA-F8DF-407A-86C0-98BD2FA7AB38}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{22CA64D3-4D93-43C4-8E1A-0C7B6F3F8424}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{22F3B97B-7B2A-4774-AC96-BD236F7B3744}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{23E9654A-A303-479F-A075-F68381446137}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{2403D1B6-7050-42BB-B7CE-558D76B62478}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{24A4AA67-6BBE-4DAF-9816-53D701DA0882}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{24FCFCB1-5BF6-4FB9-BFE4-40E917CB2AE3}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{2676D5E6-4337-4633-862D-2553BEB9DE54}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{26B80D37-141C-4EE3-A454-22BA4945D6B4}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{26CDFB78-5141-4746-8729-16E42C2E296F}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{276AD1D3-FE6A-4A04-B7AA-B1DBB5A3F4BE}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{28354BD4-29D0-4EB7-9E58-D61C32864905}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{2929CD66-3CC3-416D-9FAF-73179A49F24E}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{296450AB-577A-47B1-B19B-25FA4E9A2D05}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{2982108E-6C7D-40D4-B936-9CE06355F988}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{2A03AFED-D6FF-406F-BFD6-4997CE6457BE}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{2A989E32-248C-4968-B736-3178603EDD73}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{2B71AF4C-9A3D-4D96-B3B0-AE27F5CEB0D7}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{2B95D24E-E5E2-42F0-8B4A-C51A1C95AF79}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{2B9A4E54-288F-4D69-9AA5-471DF4679E54}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{2C5948CB-A1C4-4617-9167-3DD08A8BD967}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{2C5ADBD3-A97D-4A76-B0C9-29CE589604AF}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{2DE5043C-4D6D-4FAC-96DF-38E5056C3C9B}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{2EAE2BA6-E426-40CF-B2D3-24227DA0300E}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{2F9D095B-8A0A-4179-8084-BC7C0DFF60CD}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{30725F99-BFB8-48AF-B64A-CDD63A3AE1D3}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{319BEF8A-B355-4E22-8A8C-0F146615AE9A}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{31DE43F8-6DC0-4268-8364-D55E23E7D20E}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{31F6BDC1-0EB0-406E-B536-F04A2BB9F398}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{340B1E2A-01D0-4A78-940B-F8E3D9827F44}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{3681B928-0811-4720-BF4C-459B43C8A375}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{379B57FB-AE35-4B5B-BA15-550B28F62965}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{37B36C62-C94F-4E7F-B25C-C763863D3C65}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{381FDDA3-28F7-48B3-8073-D35AFA0869DD}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{38266985-0898-4353-8229-9FE99F311CBD}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{38A32FA7-E992-41D9-8550-8523197D3BAB}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{38DB4263-5299-4EFF-8F0E-771EA8C53086}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{38EF3EA0-9E9A-4392-9F1F-92044B703D67}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{390C9CFA-0EC9-4D9C-B208-1ED2A8482430}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{3A059832-893D-4A61-8C44-1FCEA9B997CB}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{3B599827-6D43-4E2A-B9A0-DFFC137BFBB6}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{3BC2DFD4-6630-4148-BC74-F48775898679}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{3BE26985-0E2A-4D5D-B599-84973A2981AA}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{3C15189B-5E36-496D-B015-EB9B01C679DD}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{3C1E83B8-E1FF-4EC2-8033-A51B508456C5}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{3C565174-A8B6-43BC-A34B-A40C8AB7890D}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{3C8052E7-65F6-430D-92C1-502DDD669351}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{3C9C8699-B409-43E0-A642-99550BADA8F4}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{3D0AA6C9-DE40-44B4-A867-92C6AC4FA10A}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{3D58A774-3419-4CCF-8745-79CAEBC63066}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{3E9C3FC3-6E29-467A-B064-143FF6086459}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{3EAC09FC-967F-4CCC-AD03-19B283516CAB}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{404E769F-41F2-441B-A8A1-7182585382D1}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{40952248-9C32-431C-ADED-B76FE33BF788}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{41222EF6-84C5-4DB2-937D-8213466A08EC}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{41465F6E-7A94-4185-9EDB-85967EC390EA}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{4230E550-2ECA-49E9-8299-B46DE2B46512}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{42388431-F6DB-4BDD-A644-8B83103F77B5}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{42BBB16D-EA98-4A8D-B6E1-8D98571292B6}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{42C06137-1AC0-4309-A6BE-304905E48DDE}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{4424818E-3CA2-49AB-86C5-E79CE1C4BFCB}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{444C59C5-E53A-4843-AEF7-CB6D66DA596D}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{44595053-E582-4FA1-9476-F64DADC7435B}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{454E2006-9699-4E2A-86EE-ABB21981B0E9}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{4561EFF2-B7F3-42B9-A3DC-166ACB0D6E4C}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{456EAC66-C2EC-4FFE-85E6-082E9872720D}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{45DC8DEE-6897-429A-92A9-40F07C201697}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{45E22962-509B-4141-97C2-FE12FF2641BD}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{45F49B3A-EBAD-462B-BF22-8C7CED9D417E}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{46180F4D-08A5-475C-8536-3C93CB945058}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{47F8E984-6564-4759-8F17-17ACB949AB1D}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{48AF017D-DB94-4E62-A9A9-347F7528E35E}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{48ECACE3-24A7-44F8-B298-619A4EA8BCF9}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{4910EE3C-DD93-4CDD-89F7-0F776C9D7400}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{498CD1B9-89F6-40BC-97E7-3D1EAD44260C}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{4A3F5C91-C35A-421C-A4A3-A66B638DC50D}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{4AA9F152-1CA6-4B27-B2F3-07C6A1BD2848}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{4AC11CA8-36EE-4DAF-BE1D-D74A8B6AA8F3}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{4B276A2C-3002-4AE8-9CA5-07CDAA91A190}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{4B82DB1F-93A4-4092-88AC-94F167C9A267}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{4BB67B7A-65C0-47D5-B565-DECD7E9EE981}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{4C8C3B4A-FDD4-41AE-BA2C-F0A0D0A0F2EF}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{4C8D6213-D436-4E14-8A13-D03D999BF0AA}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{4CB50C30-6760-4FF1-A06D-3CB45E42E424}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{4CB7DE9A-20BA-4474-A8DA-F13B9925F581}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{4D07A052-1BE5-4F91-805F-655999B2FCA3}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{4D497E1A-76A8-451A-A209-EE34B716FEDA}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{4D540D01-725C-4341-B7A4-D3FA5C426F4C}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{4DB72A51-7EDE-4C1A-9FE8-99134DDB5876}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{4E2DE294-BB58-4640-8750-6AF5BBA8F033}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{4F1A003D-FB7C-47EC-B557-942B33DD0BE5}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{4F560A1F-AA08-478F-A6DC-B11BB3CD1502}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{4FAC1F05-3CF0-4382-BE9E-8989CCEA4D4C}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{4FE22E0A-8E83-4EDD-A01C-ED33CF45174E}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{508C1EB5-4245-4173-A8D5-39FFBB40A275}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{509D8548-5C5F-4F1B-856A-7351AA3ED7F9}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{50D863AE-A424-44BD-B5BB-462AA975801E}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{523C9023-B6DD-4180-8046-6B745B91F0A6}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{52454978-4528-4D0A-B1F8-0587B036989A}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{540760B6-CB8A-4A25-AC28-2462D3796F04}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{5433D875-01F4-4726-A9FD-54A6C76BEBE4}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{54C2BA33-C46C-42FA-8716-F5654BFFFF69}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{54E38927-9B4A-4488-B1A2-296DFE085239}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{55C57E2E-5829-45D3-9AC9-9571BD181395}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{55E7DE18-B11A-475E-B5E7-62A670EF7F33}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{5694F476-E30D-488D-B9BB-DDCC73870176}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{56ABF12B-465C-4563-A457-ACEDDE2C729C}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{57802776-78E5-40DF-B571-824E73255E88}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{5780D17D-F417-4BF2-922B-D4A744AE6E8F}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{57E1EB2A-5CA3-47B9-B2C7-3DE6BFE6CDB3}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{57FB7043-6DBD-4695-A999-59CCEA1F1CAD}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{5883B239-304B-4A1B-82C1-B3C56882BA52}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{58DAB766-1D69-4B5E-BE1F-A0761A431C15}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{594432E9-CBE0-44AB-A712-B377B2B6DF37}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{59FBB455-0105-4547-8E53-935D162635F0}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{5A7AD40D-D221-40C8-AEAB-DCA07D860E6E}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{5ACC23B9-D37E-440B-8EDB-2D241F3A04F9}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{5B9A8A21-5323-485E-9F96-B09C83460D3D}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{5C8192FE-AFB8-4B36-B151-6775EC619980}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{5D4D4942-5005-4496-A899-57D97A12464B}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{5E21B896-A272-4874-ABCE-E1E5313D680A}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{5E62CA4E-C2F7-4FFC-B71B-CC5E7588C6BF}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{5EC84327-3D1C-4C2C-9220-3708487309FF}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{5ECB668B-0D87-44D3-9B1A-AD186C5FCC80}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{5F610562-4581-4394-896E-B2A4D2BF8F14}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{5F6C53CF-5315-49DB-A25E-E8419C8F05A5}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{60374E3A-CA11-483D-B624-B28A92279CA6}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{6081BBC9-2123-4C02-937B-044FACF1E06B}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{60E82E6C-906A-461F-9195-18495484A778}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{616120EA-E98B-4604-9340-E0C5D0350EDF}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{6269697B-58F0-4076-9675-8D19867260D9}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{62B92CC0-85A0-430E-9BD5-7B064EA0C0AA}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{6356A304-EF84-4BA1-BF8F-237C534C253F}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{63F04D48-A342-44F9-869F-2AB601A9FFB5}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{6463144B-ABF5-4075-805B-462D3E73C46A}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{652C3366-2626-4544-AF1A-461F2E648E2C}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{657C7D66-FAA5-45D3-B87B-DDA4CD34C4EC}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{65E9B07B-6E39-4E69-A74E-E074BB1608C0}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{65FF2787-B0D7-4637-821B-16816B331127}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{6624E89C-7AEB-4D85-9054-B738EE6B4CEB}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{667D8C95-6E65-4508-9587-AA11960DAB9C}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{66B2569E-7A4B-440B-9F60-FF416F512073}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{66B6C148-5F81-4FDE-9C9A-3E7578703434}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{672A4C43-9FED-4C7C-817B-559BB53653A4}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{687824DF-844A-410C-85E5-CF5CC0807757}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{6A34DABC-002D-4F30-950A-C28822D3008E}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{6AB5CA3B-1357-456E-AE93-B961DC4DF133}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{6AB7A852-1EBA-4EA7-90CE-EF7DA918CF14}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{6B592100-9C8B-410F-A76A-AA824F200D3F}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{6BBE71D7-26C0-4024-B663-76702AE0385F}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{6BC9CFE2-1606-4A51-9D0D-F679662AE5FA}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{6BF18F59-DDB0-4BB1-8439-C095B22F01B3}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{6BF8D63B-2821-4B7D-9EFE-E9FBB7D32462}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{6C42264E-7C96-419C-945E-275BBCDA0D40}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{6C555620-847A-4A06-9548-4B6F4CC85993}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{6DEF6416-1EBF-47F9-958A-E8D152B3E812}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{6EA6C500-7E60-4B90-B220-354448C68AA3}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{6ECE339D-79F5-4474-8027-F371CA21651A}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{6F9835B3-44FE-4447-B0D8-4B3B3643F20B}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{6FE0E88F-2A53-4F4E-8CC3-EE05FD4D6B50}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{6FEF4A3B-BFDE-4244-B585-CC8CD4A3F689}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{702B6037-CB3E-4F0E-9557-2566AC993E94}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{7054749E-7304-4D4B-80D4-74FAEDCE7044}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{70551334-4080-48D2-9F5F-06B565D4D92A}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{70C36E5F-43EB-43BC-84BA-6CE39C4C1F38}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{715F80DA-11D5-434C-ABD8-BF44A91D34E2}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{7161D0D5-F4FB-4658-A97A-19165E4FFC0A}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{726F7E28-BF0E-4343-BC05-06BB7B81986E}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{72F207DB-B578-457E-A51B-F87FD162574B}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{73B57F66-9D31-47AB-91EB-83DF6188627C}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{73D3C0D0-6254-46DB-B028-1F01B31D7B58}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{74075C13-64E2-4927-882A-0DD9CA74D5DF}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{743AFBB8-AF26-4069-A873-705B9BDF13BB}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{7532E163-7994-4B16-9526-3600C2165C8A}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{75FF68D5-C75B-40CD-A12F-50713AAD90ED}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{76BFE05C-7CC5-46E5-BA67-112E4519070C}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{7924877C-64D6-4A60-B75C-91C231FD857D}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{79B96E88-6886-402E-AE36-09C961D58E0C}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{79F990E6-D3DC-4A69-BF6D-9917673CDD18}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{7A5FD0F7-59D4-4066-B527-72CB1D690C94}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{7A75E14F-A040-4D6E-8D61-556BEC0DADD3}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{7A86CA2A-B80D-4077-92FC-31E30EE2F7A4}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{7C033FA4-7E45-47E9-B84E-9F71FF1B3873}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{7EC44A18-ED8D-446D-B6FC-58475C592264}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{7EFC7C9A-B143-4E22-B9E4-B6E1F24203FE}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{7F1BAECC-9911-4EE0-90AC-7BABC56B9948}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{808E7F01-A56F-4332-B0D7-51BCB55D5799}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{80A74BF2-53EF-4CA8-B22C-3EC5A308538B}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{810D3D27-48B9-4163-90CE-3BD3AD36C38C}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{81C217C6-4B7E-40FA-ADD3-8849D7D9D087}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{81ED3EF9-3336-4EF6-B992-00FDDDABA79B}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{820B5CEE-B98B-4864-AE7A-6E241D471663}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{82283534-076A-4ED4-B5B8-8F195F60756E}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{83C2D47E-C95C-4F98-B4E5-D65A7FF598F2}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{842751E9-21C8-4A4E-9A18-FA1DF5B6FB61}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{84A82A22-CE1C-4ACD-8FEA-CDED18C1C9DB}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{84B52D2D-CDD4-47F5-A11D-E2332009E80A}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{853BC8AB-A2CE-4EE5-A377-651E40592EEC}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{85785A6B-872D-4C51-904A-DDA8BC9C5288}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{86881DF0-8D4D-494D-AD97-891FCEC2FEBF}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{869A41C2-F689-4410-91A4-5D5EC6FA47B2}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{869C016C-CAF7-48B2-A63D-C8A4CDC41528}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{87D86642-CEE3-44F0-BF55-A4918EB9E413}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{87EFB616-6F51-4F45-85EE-407F1AFA4E70}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{887A291B-9EFE-4498-96C5-3320EAE9891D}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{8AC2DA06-F85B-46C3-97DF-B525C42908FA}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{8BBEF780-D35E-40B8-B63A-52F006D66EE4}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{8C80AFC2-8331-4E17-AAFF-6241349EC337}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{8D46A172-9B3C-4FED-86C8-7F413A8FA172}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{8E0CEB23-269D-48C0-A136-32EA342A4122}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{8EA097F1-9FB4-4706-AC16-A0F360C863B9}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{8F18ED18-9D47-47E1-BB27-6ECFCEA5138E}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{8F338E7D-A435-4E41-9481-018DBF1D4790}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{8FC03E5D-1EF3-4627-A6DF-0868600CDA71}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{9028B1CC-309E-4157-B487-2B9DD52890FE}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{90329CD5-1499-472A-A41C-6028CA07E626}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{90D2BE14-1AFD-4D8F-BF60-E116CCA16D53}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{9150223B-318F-41CE-BDF4-0778FA930ED7}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{91668A64-CF0E-4636-9451-D6907D78E8AB}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{91D170B1-ACD2-4B7E-A7E4-3465A827B28E}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{922DF02E-CD74-42A5-A048-44F6251A1958}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{9230F704-D500-4E26-8356-CCF1C2DDBD58}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{937BDAF1-930F-4F43-9580-B5EE4666A406}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{9422E05C-AB22-4797-A36F-2189C2ED7BA9}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{9592111B-2C49-4B93-8817-2B0611989408}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{95AD347E-3408-404C-9A69-63DDF67B4FD4}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{9617C625-D7B3-4C3B-9936-64C312232AC5}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{963EE2FD-A409-42AF-A763-D4E21D4E55D1}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{967D71AF-E07F-429B-ADF6-FA2F507DC166}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{969D3097-9ECA-418C-A948-004A3A1208D4}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{96A031A8-8C06-4F85-B808-01018A1B6018}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{96CD6A0C-9E6E-4A58-BD73-ADB712CEE09C}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{97B38006-A2DA-49E8-A4B2-56B26D1D1B0E}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{97EC159D-6C4D-43F8-8989-B256C3794B68}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{9884BB1F-B819-422E-9C6A-AF8057552DB1}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{9936C31B-B448-43C9-A18A-EA500C772E6C}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{9A735A6B-D86E-4E0D-9B3A-658DFF5190AC}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{9A99627B-00FC-44AC-A83D-AE9D0E7AAA46}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{9AD45966-587F-4D24-B77D-7C5941250ECF}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{9B012CFD-580E-44AD-BBE8-96BC21E99161}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{9B39A4A0-EF3D-4DB9-BE15-64AF99CCB27B}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{9B81261F-2731-4EA1-92C1-23E694ABEA49}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{9BAF2021-ED72-444E-9FD8-81E794B4CA14}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{9C29CDE5-83C6-4939-95C2-6E3BE06FB03F}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{9C972CAE-4ED2-4643-B1B2-90FF31FC4D09}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{9D377FAD-A6D1-4321-9A2B-20ABFCD27279}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{9D776C0E-1F13-423A-944D-AD5487BCC100}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{9E1B1D84-420F-4BA0-985D-44DF68C95F20}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{9E48EDD9-8BDB-4045-8616-4D5AE0E4298A}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{9E582937-1C37-4C57-9659-E7167EE36EE6}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{9E99538D-1E52-4998-B79D-707B516AF8A3}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{9EAFEA3B-465A-43E6-9A35-D3E6486B95F5}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{9F22B809-0B60-4EB6-84DD-33B4B59F1A14}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{9F374C0E-938F-4478-8096-F0825EA0224F}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{9F5B0FBE-DBCA-4F6D-917E-AE3180065B70}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{9F8825E5-6698-40DA-A9BE-4B0A306AC603}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{9F8EFE24-F630-401C-B1F8-41EA1C1BB6E8}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{9FF161C1-BC66-48CE-914E-B3F11F74BE32}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{9FF790DB-F9F9-468B-BC6E-3E3C0ABC8559}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{A026FC1F-66C6-4336-B0F7-93CF5B5124FC}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{A069A763-9BBF-4372-B00D-92EAAFD950F1}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{A0943441-DE11-4872-8A0A-C7373E06DB9F}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{A1053DB7-4EF8-47FF-9542-655F2DDB3B95}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{A12E9055-B07A-4BBA-9CAE-C8FA2FA73424}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{A1F8EB72-5E1B-4868-8C16-2AC835D6051F}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{A205E33B-E21C-4E28-A833-D1A80061891E}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{A2075B0D-55BB-412F-8F97-2D2C8F49A3A0}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{A221F589-FDF5-4092-A40E-3842AEC977D5}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{A3123FB8-7D3C-4410-894B-36470F43CD00}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{A338F5BD-3AFB-411C-9800-82A292A396BD}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{A408A71A-F2F3-4212-8E7A-6A0468AC7D4D}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{A4B3811B-CFF1-4E81-99EA-7CC1B204D8BD}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{A4DBE1CF-2D88-4F36-9CC5-2DE2B36360EE}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{A5611BF5-19FA-4696-88BF-B9D295A92821}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{A5C641FD-7AC8-4CAF-A034-B8E443AFF0BB}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{A5F94136-C942-4681-BB9F-BAB7DF212FB7}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{A76E72A4-732A-449F-87AF-43F5BFB77C91}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{A77459B5-4238-41AC-ABBC-BBB66177A952}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{A78D8DE3-5127-4503-9B61-4F54FAA64A5C}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{A891DEDE-1C75-480B-8B46-A29E480429D4}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{A8B960CE-49F7-4D72-B282-98DB1DE6445D}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{A8C6D745-C255-44B6-9F7D-BF97E2263838}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{A8F868F1-DB6E-4E5A-877F-D569ADE9AF7F}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{A975484F-FA68-4FD8-99A8-883ECB5A2902}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{AA06B955-8E75-459A-BBB0-BED1F2622DBB}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{AA3D8AEF-2E98-428E-B886-995A2D495FB5}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{ACC0EA40-BA42-476E-B5B9-CAF3E5CD8ABE}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{AD68AC83-FAD6-41BB-BE71-339973273607}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{AE88D20A-1B32-4D95-B7DD-535B6BFAB900}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{AEA16B15-1079-4586-B715-C5DF020D92AB}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{AF0A7792-B4A6-41E0-8934-41940DA8D6C8}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{AF9FCCCF-D691-44E7-A9DF-9A4AD750DE43}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{AFE9C6EF-764A-41C4-8108-0BE9054BDE87}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{AFEE04E5-5F0D-4F71-8313-E8F739C39A7B}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{AFFE8DB2-5920-41FE-A41E-68ECC35E62BC}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{B1EFB63E-CCE4-4B7C-9E1A-CD6B290F7761}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{B21523CA-7053-43B2-9C9D-A0222273C47E}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{B22DE8E0-C73A-4203-9583-7CA018FD9257}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{B270E99E-E664-4775-AA55-28A70FE3A89F}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{B27CC40A-5DC8-45AA-A4AC-3C11DB372471}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{B29A866E-41DD-4AC2-9A90-142D894032A4}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{B3F295ED-33D2-4096-B7F7-F7F108A8650D}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{B41F0F9D-3383-4AA4-A35F-4296BD5D7398}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{B48CC8E6-18B5-49AA-B2A9-F4354BB1EF66}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{B4A6896B-C1F8-4AC0-ACE6-0CCCD248CAAA}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{B4CE08C2-7D6D-4C3C-B48B-CD5DE9172A8C}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{B50CEDDD-5D11-439D-A5C2-3263A5A27345}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{B52C7E87-A854-453B-8382-9490B7284A4D}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{B537952F-2C59-4631-B8EA-D6CA9DADA2D5}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{B5385E1F-ADB9-40AE-A877-3CC5CC2FA916}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{B5E4BCC8-390C-4C7D-96F1-31A299B0F1D7}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{B6C40370-0F61-41AD-9FA5-01786FE32F8D}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{B9141A64-B0E9-4436-A441-CB9B0F140F7D}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{B969682F-7690-42B3-8BC1-2034BBF73B84}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{B9F5D910-9422-4B8D-A205-E16E59937F75}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{BAD29EFA-2591-482A-9711-28DB531C8A49}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{BAEB1470-A824-4F51-9E5B-ADF6829F7369}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{BB3786DE-4DCB-4FA2-B6A6-BD60D62E19C2}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{BB84273E-F471-4D22-8D47-A4D54BF700A5}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{BC48C511-A737-471A-98F3-27BB14A3832D}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{BC69ACA9-D0B1-4015-8101-974F3704EE4A}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{BCE0894B-8DC8-43CD-AE6A-D53B28E1CFAD}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{BD019C68-E9BE-4931-AAB2-0F7D383425F7}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{BD87C6B4-B8FB-4F48-94AF-4F448BD3A193}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{BDF89D4C-CAFF-47C4-9C44-4ACC9D597EED}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{BFBDB735-1329-4F2C-A144-FBF3F4B205CF}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{BFEC367E-BDF9-47AC-9BAD-60EA960087DD}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{C0379861-D148-4F92-A624-DCC3ED9E7CC9}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{C0894A54-6108-4C4F-91D4-471414FD0151}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{C0C0DC6C-6C62-427C-8D96-C158A64A6E5B}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{C108F94B-C579-4481-8F8C-BD6E650B69D3}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{C1A36D95-0B90-457D-8ED9-B8C4CAF43192}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{C287E2CA-55BA-426F-965C-7DF452C0CB64}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{C3D64483-D3CE-45E5-9BFF-512631C9A04A}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{C4148F28-42C0-4420-BD91-E742D1AE4CDF}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{C4A5558D-511D-4D79-BD98-0336ED9FB5A3}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{C4CBFECB-F1AE-41B2-9181-3161F2BAA0D5}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{C55C386C-96BB-455F-A53D-6FF85B75BA9F}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{C617D56A-1A3C-4B69-A0FD-57193DE22B82}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{C63DDD27-65C5-4ECD-B992-631DC672A4DC}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{C66DF8B0-26F9-4EFB-8BF3-4140138557F0}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{C752C34F-594A-4E4D-9968-2DEA336D6DCF}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{C78D474C-C0FD-4BEF-99EA-C6A4E4F15F5F}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{C81223E3-C7B1-4EEB-ACDF-3180BD6F605A}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{C88B49D1-44CD-480F-B9F4-0567735A313D}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{C9916B00-E89C-4AA0-85BA-A05B81FBF723}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{CAAE7F72-EAE0-4090-BF0C-7C8AD8DC8E5F}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{CAC3E855-6AF8-45DF-A85B-D169A572008E}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{CAFB55B1-30F1-4E61-B381-87F749270C22}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{CB867939-BAAE-4860-8953-2CDB618C44E5}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{CC8AE72A-11AA-4113-9DF9-5C1ED1F14575}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{CC8E0A97-24AC-49AA-A7CA-1955455D2A63}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{CD1AD76D-4FC1-4BCA-B3DC-E25E8C31396E}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{CD620425-BE0D-4B5B-A395-D6C3FE02FCA6}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{CD943256-F12E-402F-9813-EBD1EF786198}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{CF133699-8990-407F-8B0C-D3583E4A692D}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{CF22EE52-39CA-45B5-B67A-FC11D5B213AC}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{CF5932A9-5A38-4772-95FE-D35500BB68CB}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{CF9C53AE-6E55-408D-87CE-4DC7947C41D7}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{CFCD667C-B549-4B2B-B330-3662D5F66883}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{D00034DF-A074-4CAA-B8C3-037C7F447167}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{D04BA779-B98B-474A-9B21-33597BB7EE13}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{D04BAE1A-9B6A-4208-9574-5000F798E783}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{D07E16D6-FA0E-4395-84E6-F6596CD7FC13}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{D0858421-944E-4591-9B75-9C6BB64E40EC}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{D120B6D5-A210-4F66-98DF-B544463F7196}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{D17EDF24-C940-4F2D-AB9F-A632478ECE9F}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{D18A5552-3B0E-4057-902D-5CD70A9B25AC}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{D1917447-9F78-4FBD-8CDC-35FFC8D7C91F}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{D23CE6E5-4E04-40C4-B65C-3702569B61ED}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{D27FC467-3405-4418-96C3-5116E142785A}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{D3BE0650-6636-4385-8EB9-A47683153F4B}
 
JRT.txt:(part two)
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{D4D240B6-FFD1-47D2-BCA9-47BB65BB8566}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{D4F69E1F-591B-44E9-B9E7-4763A94C6398}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{D758011C-1F36-4745-B686-77270FEAAC42}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{D7EE25DB-F86B-4C77-9FD5-DD55B303F99B}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{D8A798B0-1F63-4F8E-A413-9D3D481DDCEA}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{D8F8E5A4-2704-48DD-BC4D-CF8654C1DA4A}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{DA2012C4-9D14-4C07-ADB0-6DBCE9746C3F}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{DA85A9AA-9D2C-4226-9775-08F4400569B3}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{DAB6080F-E6CF-43A4-9264-3EC46D55F2C6}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{DBB0A9F2-C27B-41B2-A0E5-0CCE20A869AF}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{DC29B6CA-C831-4508-A6EE-5C819FF6AF77}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{DC63E591-AB2C-4E0C-B092-6A982204D25C}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{DC8E916F-FD6A-4739-B9E1-478F95019E6B}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{DDABD34A-E446-41D9-BB28-69B01A3A0ECC}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{DE0FE320-9B7F-43C9-AF74-10FD21182445}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{DFAA8AA5-C838-4968-8D71-54C5107905C4}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{E00C706D-7FBB-4521-9D69-33848C2F59E7}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{E027D809-70AA-4515-B49E-04438C996A59}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{E03E4F48-0F73-44B2-A303-A003B2BBB913}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{E246189D-A13C-4A8C-A1A7-E37F90BAA893}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{E291B156-514F-49F2-AA7C-78AF98AC9D92}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{E2B6B9FB-FC2F-4689-B3CA-2F44C4590097}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{E2D82C56-3A0D-4054-BD74-94F59E51C3B5}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{E323403F-F4C6-4DA5-BB0A-F685F8821E14}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{E4168938-B511-4946-9F1A-4E362C9800B2}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{E441315B-1598-4FEA-BB6C-24DD025CAB53}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{E4C9E48C-8BE5-425E-B07C-A704D2CDA82D}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{E52BB2B4-999E-464B-8BF8-CBF313A3B390}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{E547C541-9A12-4DB4-86E7-1EEB0C99B3B8}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{E5B1ADFB-3867-47A9-8927-0BD39F3E62A7}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{E5B2BF13-F713-41D4-B613-113F03D75304}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{E617B8BB-F2DB-4523-BF45-9CD340FDC21A}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{E6917022-6878-4356-B1D9-C1420C655F08}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{E758C8F2-1B3D-4CBD-AB2E-5A3A6C9A6AF3}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{E75F0957-DE3E-4105-AE1D-E1554816AB4B}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{E7ABADCC-C92B-4E90-973E-916EC29B4503}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{E83DDDFA-F16E-4D6A-9435-63D0DD4A5589}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{E897C341-8111-4EC1-A5D0-E26DBC24579A}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{E8DC713A-1AA5-4728-99CC-5CA9AF9C6341}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{E90D350C-4174-492E-B559-BE8BF7425041}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{E94B3406-97DC-4C97-8A34-7E6AA3CEEE1F}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{EA324D38-6C72-4A68-907E-CF517FC64AD4}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{EAAF2153-BCC8-44D3-8356-4C69E6C162AB}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{EB2C06E5-8F60-4C4C-ADC0-2ED4C3D4A50B}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{EB43D66C-A787-4950-BF98-AF80737F6494}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{EBFCC913-4275-4373-9B81-EF093880C53A}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{EC2C7D7D-44C7-4039-AB79-C8FADE9DABE4}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{EC979F79-534D-4FD3-8BE5-ADAE5635CEE5}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{EC9B083B-352B-4C34-A06B-E483A0944831}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{ED5EAD87-CF96-4844-B8D6-4EF7B041F4FE}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{ED713EDC-CDA8-4CD8-ACF9-BBE333CB0F07}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{EE847A0C-2075-4FFB-BE3E-B7E810C0A848}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{EE87DDBA-377D-481B-8056-D1977DD90033}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{EF0F07D6-908D-4029-AFA6-559AE9755A9F}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{EF433C9C-5AB6-48DD-AC39-2938E39DD4BD}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{EF64D9A5-4C0D-44F3-9467-7ED07A9CA4E6}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{F044253C-0A5F-4058-9A2A-84E310FD16FE}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{F12E9C8B-E0BD-4ABC-8EE1-44419B2B67C1}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{F1B297EE-09A2-4F28-BD13-C01F6CCFCE5F}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{F1CBD3F1-2731-4025-A5AB-1A2144C658BA}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{F24B0AF8-DD98-443B-9D0F-9D97AF6410E3}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{F24E320F-2B70-452A-9B20-25100F4D2F8F}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{F2D88AE8-ADB5-4A17-AF76-032E5714EADE}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{F31D64EF-5294-4C4D-89BF-622C3A15F25D}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{F33F57CD-A421-470B-B7BD-017DC5FA5580}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{F3B5989D-23A9-472C-B259-FBD8EAAC0166}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{F41679AE-1634-425C-882F-D12B57561341}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{F42B35E8-4A29-44A2-9B31-6D597626353B}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{F43CE77D-68AE-4E7A-8F26-4B10E9F6ACDA}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{F44D254C-538D-4D19-83B3-C8323CCF2F55}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{F4FE431C-1562-4794-A419-7DD58F0024C4}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{F5484D12-6A19-472C-981B-D8C9D7D55465}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{F5C2501A-6E5B-452B-8FAF-3B23B3CCA745}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{F649E457-F1B6-488F-BE3D-12F85370DDBA}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{F770C2F8-2FA1-4C20-9E7C-E99B926B88A2}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{F777C599-59BE-4FC4-AA50-3DBB12C9EA81}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{F7A1224C-2ACA-491A-9412-8B7A45DDC16D}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{F7DB16B5-E963-454E-AD49-E8A5561634E5}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{F937B4D1-F944-4703-BEF2-EFF524B3D90A}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{F9D89174-9FBB-474C-A90D-B56AA25F2B43}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{FA426573-4B98-4407-85F0-CEB2A6E3C046}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{FAC19D11-23AE-46D7-9620-C571C92EBD5A}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{FACD8D68-B71A-433E-9B38-E7116B154725}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{FB4CFBBC-2B04-47E2-9233-398F951F1FC3}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{FB73C64A-EAA0-4635-BA7E-E0F107A181AE}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{FC465BD1-2DD6-4B72-AC74-6803EFE208F1}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{FD74C227-A888-4B44-9C9D-A4FB1B2D8D39}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{FE1740E2-71B8-4306-B24B-5FD47A7F03DB}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{FE231043-8866-4D89-A81B-B67AFDB02CCD}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{FE2D952C-4E69-42B3-AC64-387E4A27792C}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{FE366324-6A8E-47D5-B543-9D95B55E7D99}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{FE528487-629A-486E-8D1A-99BD9C332AF8}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{FE6FD4A5-93D5-4C53-85C9-2D0E6FE039F5}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{FE7C68A5-884A-48FF-A77D-09C2907EDBC8}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{FE9EA6AA-0375-4063-BDF0-B675D4D38F7B}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{FEDF5970-DB7D-4B76-A878-5486CD235F62}
Successfully deleted: [Empty Folder] C:\Users\alaa\appdata\local\{FFA3E71F-A70B-4268-B7C8-9AD66864D2B1}



~~~ FireFox

Successfully deleted: [File] C:\user.js
Emptied folder: C:\Users\alaa\AppData\Roaming\mozilla\firefox\profiles\s74kbspm.default\minidumps [156 files]



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Sun 09/29/2013 at 14:51:20.92
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
Ok. Lets do some more.

1.

Please download and run TDSSkiller

When the program opens, click on the start scan button.

tdssstartscan_zps32a151cd.jpg


TDSSKiller will now scan your computer for the TDSS infection. When the scan has finished it will display a result screen stating whether or not the infection was found on your computer. If it was found it will display a screen similar to the one below.

2663-2-eng.png


To remove the infections simply click on the Continue button and TDSSKiller will attempt to clean them or remove them.

After trying to clean them it will pop up with the results of the scan and its actions.

2663_3_en.png


Please reboot the system if asked to do so.

After running there will be a log that will be located at the root of your c:\ drive labeled tdsskiller with a series of numbers after it example, C:\TDSSKiller.2.4.7_23.07.2010_15.31.43_log.txt

Please open the log and copy and paste it back here.

2.

1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
It must be Notepad, not Wordpad.
2. Copy the text in the below code box

Code:
Reglock::

[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000_Classes\CLSID\{01051598-dc7a-4e8e-9e06-921d50dce07f}]
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000_Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000_Classes\CLSID\{67447f24-47b4-4b25-9aaa-8760a64e11cc}]
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000_Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]


3. Go to the Notepad window and click Edit > Paste
4. Then click File > Save
5. Name the file CFScript.txt - Save the file to your Desktop
6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!


CFScript-1.gif


ComboFix will begin to execute, just follow the prompts.
After reboot (in case it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply.
 
i didn't have any problems with the first scan
the second:
ComboFix 13-10-01.03 - alaa 10/02/2013 17:23:58.3.2 - x86
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.3647.2524 [GMT 3:00]
Running from: c:\users\alaa\Desktop\ComboFix_2.exe
Command switches used :: c:\users\alaa\Desktop\CFScript.txt
AV: AVG Internet Security 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
FW: AVG Internet Security 2012 *Enabled* {621CC794-9486-F902-D092-0484E8EA828B}
SP: AVG Internet Security 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((( Files Created from 2013-09-02 to 2013-10-02 )))))))))))))))))))))))))))))))
.
.
2013-10-02 14:31 . 2013-10-02 14:31 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-10-02 14:31 . 2013-10-02 14:31 -------- d-----w- c:\users\UpdatusUser.alaa-PC\AppData\Local\temp
2013-10-02 14:31 . 2013-10-02 14:31 -------- d-----w- c:\users\the peoples computer\AppData\Local\temp
2013-10-02 14:31 . 2013-10-02 14:31 -------- d-----w- c:\users\Guest\AppData\Local\temp
2013-10-02 14:31 . 2013-10-02 14:31 -------- d-----w- c:\users\fbwuser\AppData\Local\temp
2013-10-02 14:31 . 2013-10-02 14:31 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-10-02 14:20 . 2013-10-02 14:21 -------- d-----w- C:\ComboFix_2
2013-09-30 20:24 . 2013-09-30 20:24 -------- d-----w- c:\program files\Beautifun Games
2013-09-29 13:40 . 2013-09-29 13:40 -------- d-----w- c:\programdata\Hotspot Shield
2013-09-29 13:40 . 2013-09-29 13:40 -------- d-----w- c:\program files\Hotspot Shield
2013-09-29 13:40 . 2013-09-29 13:40 -------- d-----w- c:\users\alaa\AppData\Roaming\Hotspot Shield
2013-09-29 11:49 . 2013-09-29 11:49 -------- d-----w- c:\windows\ERUNT
2013-09-29 11:44 . 2013-09-29 11:44 -------- d-----w- c:\programdata\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1}
2013-09-29 11:44 . 2013-09-29 11:44 -------- d-----w- c:\users\alaa\AppData\Local\PackageAware
2013-09-27 17:39 . 2013-10-02 14:31 -------- d-----w- c:\users\alaa\AppData\Local\temp
2013-09-27 12:17 . 2013-09-27 12:17 -------- d-----w- c:\users\alaa\AppData\Local\SkinSoft
2013-09-16 09:30 . 2013-09-16 09:30 4806016 ----a-w- c:\program files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll
2013-09-16 09:30 . 2013-09-16 09:30 4806016 ----a-w- c:\program files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll
2013-09-15 18:42 . 2013-09-15 18:42 -------- d-----w- c:\users\alaa\AppData\Roaming\DAEMON Tools Ult
2013-09-15 18:42 . 2013-09-15 18:42 -------- d-----w- c:\programdata\DAEMON Tools Ult
2013-09-14 20:19 . 2013-08-05 01:56 133056 ----a-w- c:\windows\system32\drivers\ataport.sys
2013-09-14 20:19 . 2013-08-08 01:03 2348544 ----a-w- c:\windows\system32\win32k.sys
2013-09-12 13:55 . 2013-03-06 02:35 8950560 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2013-09-12 13:53 . 2013-03-04 14:14 3053030 ----a-w- c:\windows\system32\nvcoproc.bin
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-09-20 10:17 . 2012-02-08 18:58 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-09-20 10:17 . 2011-09-26 15:19 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-08-26 15:51 . 2013-08-26 15:51 466008 ----a-w- c:\windows\system32\drivers\sptd.sys
2013-08-24 16:02 . 2013-08-24 16:02 388096 ----a-r- c:\users\alaa\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2013-08-24 01:13 . 2013-08-24 01:09 24704 ----a-w- c:\windows\system32\drivers\dtscsibus.sys
2013-08-06 07:28 . 2013-08-27 18:03 7166848 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{64DC9D94-F46E-4B22-8610-567C07F3A8C5}\mpengine.dll
2013-07-25 08:57 . 2013-08-14 00:58 1620992 ----a-w- c:\windows\system32\WMVDECOD.DLL
2013-07-19 01:41 . 2013-08-14 00:51 2048 ----a-w- c:\windows\system32\tzres.dll
2013-07-17 21:46 . 2013-07-17 21:46 94632 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-07-17 21:46 . 2012-01-22 10:29 867240 ----a-w- c:\windows\system32\npdeployJava1.dll
2013-07-17 21:46 . 2011-12-11 18:48 789416 ----a-w- c:\windows\system32\deployJava1.dll
2013-07-09 05:03 . 2013-08-14 00:53 3968960 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-07-09 05:03 . 2013-08-14 00:53 3913664 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-07-09 04:53 . 2013-08-14 00:53 1289096 ----a-w- c:\windows\system32\ntdll.dll
2013-07-09 04:52 . 2013-08-14 00:59 175104 ----a-w- c:\windows\system32\wintrust.dll
2013-07-09 04:50 . 2013-08-14 00:51 652800 ----a-w- c:\windows\system32\rpcrt4.dll
2013-07-09 04:46 . 2013-08-14 00:59 140288 ----a-w- c:\windows\system32\cryptsvc.dll
2013-07-09 04:46 . 2013-08-14 00:59 1166848 ----a-w- c:\windows\system32\crypt32.dll
2013-07-09 04:46 . 2013-08-14 00:59 103936 ----a-w- c:\windows\system32\cryptnet.dll
2013-07-06 05:05 . 2013-08-14 00:51 1293760 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-12-20 18:10 235008 --shatr- c:\windows\System32\FltEng.dll
2011-12-20 18:12 61440 --shatr- c:\windows\System32\secpro.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\IDM Shell Extension]
@="{CDC95B92-E27C-4745-A8C5-64A52A78855D}"
[HKEY_CLASSES_ROOT\CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D}]
2012-11-15 23:07 21904 ----a-w- c:\program files\Internet Download Manager\IDMShellExt.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="e:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2013-01-31 3540416]
"Copernic Desktop Search - Home"="c:\program files\Copernic Desktop Search - Home\DesktopSearchService.exe" [2012-09-28 1691240]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
"BitTorrent"="c:\program files\BitTorrent\BitTorrent.exe" [2013-05-03 882520]
"Airytec Switch Off"="c:\program files\Airytec\Switch Off\swoff.exe" [2011-05-28 135168]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2013-06-21 19875432]
"DAEMON Tools Ultra Agent"="c:\program files\DAEMON Tools Ultra\DTAgent.exe" [2013-06-25 3128352]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PCTVOICE"="pctspk.exe" [2002-12-05 163840]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-02-11 172568]
"TV Card Remote Control Device Monitor"="c:\windows\713xRMT.exe" [2008-06-17 466944]
"AVG_TRAY"="d:\program files\AVG\AVG2012\avgtray.exe" [2012-11-19 2598520]
"nmapp"="d:\program files\Pure Networks\Network Magic\nmapp.exe" [2012-07-22 472112]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
"Nvtmru"="c:\program files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-07-27 1028896]
"HDAudDeck"="c:\program files\VIA\VIAudioi\VDeck\VDeck.exe" [2009-12-04 1728512]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2012-11-05 89184]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
TVMOBiLiArtworkManager.lnk - c:\program files\TVMOBiLi\bin\iTunesAlbumArtGenerator.exe "/path:c:\programdata\TVMOBiLi\cache" [2012-2-11 66048]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0d:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^TV Expert Schedule Agent.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\TV Expert Schedule Agent.lnk
backup=c:\windows\pss\TV Expert Schedule Agent.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^Users^alaa^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Serviio.lnk]
path=c:\users\alaa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Serviio.lnk
backup=c:\windows\pss\Serviio.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]
2012-11-05 12:27 89184 ----a-w- c:\program files\Microsoft Office\Office14\BCSSync.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
2013-05-03 11:12 882520 ----a-w- c:\program files\BitTorrent\BitTorrent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Ultra Agent]
2013-06-25 08:51 3128352 ----a-w- c:\program files\DAEMON Tools Ultra\DTAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update]
2012-07-12 16:52 138096 ----atw- c:\users\alaa\AppData\Local\Facebook\Update\FacebookUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FlyOnDesktopPro]
2011-07-12 10:32 976896 ----a-w- d:\program files\Fly on Desktop\FlyOnDesktop.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\googletalk]
2007-01-01 21:22 3739648 ----a-w- c:\users\alaa\AppData\Roaming\Google\Google Talk\googletalk.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDMan]
2013-01-31 08:20 3540416 ----a-w- c:\program files\Internet Download Manager\IDMan.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nmctxth]
2009-07-07 11:48 647216 ----a-w- c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2010-11-20 12:17 1174016 ----a-w- c:\program files\Windows Sidebar\sidebar.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2013-06-21 06:58 19875432 ----a-r- c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Speech Recognition]
2009-07-14 01:14 51712 ----a-w- c:\windows\Speech\Common\sapisvr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SRS Audio Sandbox]
2011-11-08 12:01 3215360 ----a-w- c:\program files\SRS Labs\Audio Sandbox\SRSSSC.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2013-03-12 04:32 253816 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2011-11-08 12:07 185896 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
.
R0 amdkmafd;AMD Audio Bus Lower Filter;c:\windows\system32\DRIVERS\amdkmafd.sys [2013-05-04 15968]
R2 AVGIDSAgent;AVGIDSAgent;d:\program files\AVG\AVG2012\avgidsagent.exe [2012-11-02 5174392]
R2 KMService;KMService;c:\windows\system32\srvany.exe [2010-05-31 8192]
R2 SecStore;Secure Storage;c:\windows\system32\secpro.exe [2011-12-20 61440]
R2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2013-09-16 3273088]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2013-06-21 162408]
R2 SwOffScheduler;Airytec Switch Off - Task Scheduler;c:\program files\Airytec\Switch Off\swoff.exe [2011-05-28 135168]
R2 SwOffWeb;Airytec Switch Off - Web Interface;c:\program files\Airytec\Switch Off\swoff.exe [2011-05-28 135168]
R2 tvMobiliService;tvMobiliService;c:\program files\TVMOBiLi\bin\tvMobiliService.exe [2012-02-11 1051648]
R3 3xHybrid;SAA713x TV Card Service;c:\windows\system32\DRIVERS\3xHybrid.sys [2010-12-01 1141888]
R3 athur;Atheros AR9271 Wireless Network Adapter Service;c:\windows\system32\DRIVERS\athur.sys [2013-03-05 1570816]
R3 BthAvrcp;Bluetooth AVRCP Profile;c:\windows\system32\DRIVERS\BthAvrcp.sys [2009-08-13 22528]
R3 CV2K1;CommView Network Monitor; [x]
R3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\DRIVERS\ew_hwusbdev.sys [x]
R3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys [x]
R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [2012-10-29 12400]
R3 huawei_enumerator;huawei_enumerator;c:\windows\system32\DRIVERS\ew_jubusenum.sys [x]
R3 hwusbdev;Huawei DataCard USB PNP Device; [x]
R3 NPF;WinPcap Packet Driver (NPF);c:\windows\system32\drivers\NPF.sys [2010-06-25 35088]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848]
R3 s1039bus;Sony Ericsson Device 1039 driver (WDM);c:\windows\system32\DRIVERS\s1039bus.sys [2010-03-15 98672]
R3 s1039mdfl;Sony Ericsson Device 1039 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s1039mdfl.sys [2010-03-15 14960]
R3 s1039mdm;Sony Ericsson Device 1039 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s1039mdm.sys [2010-03-15 124016]
R3 s1039mgmt;Sony Ericsson Device 1039 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s1039mgmt.sys [2010-03-15 117872]
R3 s1039nd5;Sony Ericsson Device 1039 USB Ethernet Emulation (NDIS);c:\windows\system32\DRIVERS\s1039nd5.sys [2010-03-15 25456]
R3 s1039obex;Sony Ericsson Device 1039 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s1039obex.sys [2010-03-15 113904]
R3 s1039unic;Sony Ericsson Device 1039 USB Ethernet Emulation (WDM);c:\windows\system32\DRIVERS\s1039unic.sys [2010-03-15 123504]
R3 Synth3dVsc;Synth3dVsc; [x]
R3 tapoas;TAP-Win32 Adapter OAS;c:\windows\system32\DRIVERS\tapoas.sys [2010-08-03 26112]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 49664]
R3 tsusbhub;tsusbhub; [x]
R3 VGPU;VGPU; [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-09-23 1343400]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 51040]
S0 AVGIDSHX;AVGIDSHX;c:\windows\system32\DRIVERS\avgidshx.sys [2012-04-19 24896]
S0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx86.sys [2012-01-31 31952]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 Avgfwfd;AVG network filter service;c:\windows\system32\DRIVERS\avgfwd6x.sys [2011-05-22 47968]
S1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx86.sys [2012-11-08 250080]
S1 Avgtdix;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdix.sys [2013-04-11 302368]
S1 HssDRV6;Hotspot Shield Routing Driver 6;c:\windows\system32\DRIVERS\hssdrv6.sys [2013-06-21 41160]
S1 TsLwWfF;WiFi Capture Driver;c:\windows\system32\DRIVERS\TsLwWfF.sys [2011-05-12 22632]
S2 avgfws;AVG Firewall;d:\program files\AVG\AVG2012\avgfws.exe [2012-12-05 2321560]
S2 avgwd;AVG WatchDog;d:\program files\AVG\AVG2012\avgwdsvc.exe [2012-02-14 193288]
S2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x32.sys [2011-09-21 21992]
S2 hshld;Hotspot Shield Service;c:\program files\Hotspot Shield\bin\cmw_srv.exe [2013-09-17 878888]
S2 HssWd;Hotspot Shield Monitoring Service;c:\program files\Hotspot Shield\bin\hsswd.exe [2013-09-17 556840]
S2 IDMWFP;IDMWFP;c:\windows\system32\DRIVERS\idmwfp.sys [2013-05-25 102344]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2013-07-27 14592288]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-03-05 383264]
S2 VIAKaraokeService;VIA Karaoke digital mixer Service;c:\windows\system32\viakaraokesrv.exe [2013-03-16 27768]
S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdriverx.sys [2012-12-10 142176]
S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\avgidsfilterx.sys [2011-12-23 24144]
S3 AVGIDSShim;AVGIDSShim;c:\windows\system32\DRIVERS\avgidsshimx.sys [2011-12-23 17232]
S3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\DRIVERS\clwvd.sys [2011-04-14 27760]
S3 Disc Soft Bus Service;Disc Soft Bus Service;c:\program files\DAEMON Tools Ultra\DiscSoftBusService.exe [2013-06-25 632352]
S3 dtscsibus;DAEMON Tools Virtual SCSI Bus;c:\windows\system32\DRIVERS\dtscsibus.sys [2013-08-24 24704]
S3 netr28u;RT2870 USB Extensible Wireless LAN Card Driver;c:\windows\system32\DRIVERS\netr28u.sys [2011-11-16 1270848]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad32v.sys [2013-05-14 34592]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2013-03-05 585872]
S3 taphss6;Anchorfree HSS VPN Adapter;c:\windows\system32\DRIVERS\taphss6.sys [2013-04-24 37064]
S3 VCSVADHWSer;Avnex Virtual Audio Device (WDM);c:\windows\system32\DRIVERS\vcsvad.sys [2008-12-26 17792]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2009-11-25 1108480]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - 13807636
*Deregistered* - 13807636
.
Contents of the 'Scheduled Tasks' folder
.
2013-10-02 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-02-08 10:17]
.
2013-10-01 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3860670502-1900623974-4232932808-1000Core.job
- c:\users\alaa\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-06-15 16:52]
.
2013-10-02 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3860670502-1900623974-4232932808-1000UA.job
- c:\users\alaa\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-06-15 16:52]
.
2013-10-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-09-05 03:43]
.
2013-10-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-09-05 03:43]
.
2013-10-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3860670502-1900623974-4232932808-1000Core.job
- c:\users\alaa\AppData\Local\Google\Update\GoogleUpdate.exe [2012-05-12 18:47]
.
2013-10-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3860670502-1900623974-4232932808-1000UA.job
- c:\users\alaa\AppData\Local\Google\Update\GoogleUpdate.exe [2012-05-12 18:47]
.
2013-01-31 c:\windows\Tasks\ROC_REG_JAN_DELETE.job
- c:\programdata\AVG January 2013 Campaign\ROC.exe [2013-01-30 21:16]
.
.
------- Supplementary Scan -------
.
uStart Page = https://www.google.com.qa/
IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: E&xport to Microsoft Excel - c:\program files\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\program files\MICROS~1\Office14\ONBttnIE.dll/105
IE: Search the Web
TCP: DhcpNameServer = 192.168.100.1
FF - ProfilePath - c:\users\alaa\AppData\Roaming\Mozilla\Firefox\Profiles\s74kbspm.default\
FF - prefs.js: network.proxy.ftp - 127.0.0.1
FF - prefs.js: network.proxy.ftp_port - 8555
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 8555
FF - prefs.js: network.proxy.socks - 127.0.0.1
FF - prefs.js: network.proxy.socks_port - 8555
FF - prefs.js: network.proxy.ssl - 127.0.0.1
FF - prefs.js: network.proxy.ssl_port - 8555
FF - prefs.js: network.proxy.type - 2
FF - ExtSQL: 2013-08-06 21:04; [email protected]; c:\users\alaa\AppData\Roaming\Mozilla\Firefox\Profiles\s74kbspm.default\extensions\[email protected]
FF - ExtSQL: 2013-08-23 04:40; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\users\alaa\AppData\Roaming\Mozilla\Firefox\Profiles\s74kbspm.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF - ExtSQL: 2013-08-24 05:21; [email protected]; c:\program files\Mozilla Firefox\browser\extensions\[email protected]
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-Your Product1.0 - c:\program files\Your Product\uninstall.exe
AddRemove-{09FF4DB8-7DE9-4D47-B7DB-915DB7D9A8CA} - c:\programdata\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1}\bm_installer.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{98889811-442D-49DD-99D7-DC866BE87DBC}"=hex:51,66,7a,6c,4c,1d,38,12,7f,9b,9b,
9c,1f,0a,b3,0c,e6,c1,9f,c6,6e,b6,39,a8
"{0055C089-8582-441B-A0BF-17B458C2A3A8}"=hex:51,66,7a,6c,4c,1d,38,12,e7,c3,46,
04,b0,cb,75,01,df,a9,54,f4,5d,9c,e7,bc
"{2EECD738-5844-4A99-B4B6-146BF802613B}"=hex:51,66,7a,6c,4c,1d,38,12,56,d4,ff,
2a,76,16,f7,0f,cb,a0,57,2b,fd,5c,25,2f
"{72853161-30C5-4D22-B7F9-0BBC1D38A37E}"=hex:51,66,7a,6c,4c,1d,38,12,0f,32,96,
76,f7,7e,4c,08,c8,ef,48,fc,18,66,e7,6a
"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,
94,30,02,d1,0f,f1,da,12,24,73,56,27,d2
"{9CFACCB6-2F3F-4177-94EA-0D2B72D384C1}"=hex:51,66,7a,6c,4c,1d,38,12,d8,cf,e9,
98,0d,61,19,04,eb,fc,4e,6b,77,8d,c0,d5
"{9FDDE16B-836F-4806-AB1F-1455CBEFF289}"=hex:51,66,7a,6c,4c,1d,38,12,05,e2,ce,
9b,5d,cd,68,0d,d4,09,57,15,ce,b1,b6,9d
"{AD4DF010-E2FD-43CE-864A-6BD1EDC59AC2}"=hex:51,66,7a,6c,4c,1d,38,12,7e,f3,5e,
a9,cf,ac,a0,06,f9,5c,28,91,e8,9b,de,d6
"{B4F3A835-0E21-4959-BA22-42B3008E02FF}"=hex:51,66,7a,6c,4c,1d,38,12,5b,ab,e0,
b0,13,40,37,0c,c5,34,01,f3,05,d0,46,eb
"{CA4520F3-AE13-4FB1-A513-58E23991C86D}"=hex:51,66,7a,6c,4c,1d,38,12,9d,23,56,
ce,21,e0,df,0a,da,05,1b,a2,3c,cf,8c,79
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,
df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd
"{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}"=hex:51,66,7a,6c,4c,1d,38,12,8f,19,47,
2e,c4,15,0b,03,d7,b5,8c,e9,62,70,06,85
"{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}"=hex:51,66,7a,6c,4c,1d,38,12,35,fc,e1,
93,3e,68,a1,09,fc,5c,6e,9a,4b,77,a7,8a
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:8b,0e,80,c7,84,28,cd,01
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.032\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.032"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.abr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.abr"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ani\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.ani"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.arw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.arw"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bay\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.bay"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bmp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.bmp"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.bw"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cr2\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.cr2"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.crw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.crw"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cs1\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.cs1"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cur\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.cur"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.dcr"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.dcx"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dib\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.dib"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.djv\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.djv"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.djvu\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.djvu"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dng\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.dng"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.emf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.emf"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eps\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.eps"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.erf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.erf"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fff\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.fff"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fpx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.fpx"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.gif"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hdr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.hdr"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.icl\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.icl"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.icn\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.icn"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iff\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.iff"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ilbm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.ilbm"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.int\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.int"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.inta\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.inta"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iw4\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.iw4"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2c\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.j2c"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2k\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.j2k"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jbr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.jbr"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jfif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.jfif"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.jif"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jp2\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.jp2"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpc\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.jpc"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpe\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.jpe"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpeg\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.jpeg"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpg\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.jpg"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpk\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.jpk"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.jpx"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.kdc\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.kdc"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.lbm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.lbm"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mef\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.mef"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mos\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.mos"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mrw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.mrw"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nef\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.nef"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.orf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.orf"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pbm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.pbm"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pbr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.pbr"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcd\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.pcd"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pct\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.pct"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.pcx"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pef\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.pef"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pgm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.pgm"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pic\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.pic"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pict\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.pict"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pix\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.pix"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.png\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.png"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.ppm"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psd\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.psd"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.psp"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pspbrush\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.pspbrush"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pspimage\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.pspimage"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.raf"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ras\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.ras"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.raw"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rgb\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.rgb"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rgba\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.rgba"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rle\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.rle"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rsb\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.rsb"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sgi\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.sgi"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sr2\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.sr2"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.srf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.srf"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tga\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.tga"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.thm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.thm"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.tif"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tiff\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.tiff"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttc\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.ttc"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.ttf"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v25po\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.v25po"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v25pp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.v25pp"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v25ppf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.v25ppf"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.wbm"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbmp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.wbmp"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.wmf"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xbm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.xbm"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.xif"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xmp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.xmp"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xpm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 2.5.xpm"
.
[HKEY_USERS\S-1-5-21-3860670502-1900623974-4232932808-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:57,0d,f5,cf,09,ce,64,72,a1,a9,6a,38,fe,f1,13,20,6a,c5,d5,57,64,b4,6e,
99,ef,f0,78,b3,2e,cd,01,a5,c2,89,07,ec,3b,58,27,d1,3f,07,c6,44,a4,69,51,30,\
"??"=hex:11,01,07,25,28,34,44,2c,1e,78,48,f2,95,f6,67,0b
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'Explorer.exe'(4528)
d:\program files\Pure Networks\Network Magic\nmrsrc.dll
c:\program files\Common Files\Pure Networks Shared\Platform\puresp4.dll
.
Completion time: 2013-10-02 17:32:35
ComboFix-quarantined-files.txt 2013-10-02 14:32
ComboFix2.txt 2013-09-27 18:39
.
Pre-Run: 21,697,277,952 bytes free
Post-Run: 21,624,360,960 bytes free
.
- - End Of File - - 8D3443B9BA10DE7EC462D3DE51782418
A36C5E4F47E84449FF07ED3517B43A31
 
Are you still having issues with the internet not working? If so, it may be AVG related. Can you temporarily uninstall it and see what happens?
 
Back
Top