![]() |
FRST Logfile: FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-08-2013 --- --- --- --- --- --- FRST Additions Logfile: Code: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 04-08-2013 SystemLook 30.07.11 by jpshortstuff Log created at 19:08 on 06/08/2013 by PC Administrator - Elevation successful No Context: :filefind No Context: *systweak* No Context: *adawarebp* No Context: *datamngr* No Context: *lyrixeeker* No Context: *mypc backup* No Context: *speedupmypc* No Context: *sweetim* No Context: *distromatic* No Context: *BabSolution* No Context: *bProtector* No Context: *BrowserDefender* No Context: *iLivid* No Context: *holasearch* No Context: *DealPly* No Context: *Babylon* No Context: *Softonic* No Context: *delta LTD* No Context: *PriceGong* No Context: *OpenCandy* No Context: *PerformerSoft* No Context: *SoftSafe* No Context: *IBUpdater* ========== folderfind ========== Searching for "*systweak*" No folders found. Searching for "*adawarebp*" No folders found. Searching for "*datamngr*" No folders found. Searching for "*lyrixeeker*" No folders found. Searching for "*mypc backup*" No folders found. Searching for "*speedupmypc*" No folders found. Searching for "*sweetim*" No folders found. Searching for "*distromatic*" No folders found. Searching for "*BabSolution*" No folders found. Searching for "*bProtector*" No folders found. Searching for "*BrowserDefender*" No folders found. Searching for "*iLivid*" No folders found. Searching for "*holasearch*" No folders found. Searching for "*DealPly*" No folders found. Searching for "*Babylon*" No folders found. Searching for "*Softonic*" No folders found. Searching for "*delta LTD*" No folders found. Searching for "*PriceGong*" No folders found. Searching for "*OpenCandy*" No folders found. Searching for "*PerformerSoft*" No folders found. Searching for "*SoftSafe*" No folders found. Searching for "*IBUpdater*" No folders found. ========== regfind ========== Searching for "systweak" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\systweakasp_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\systweakasp_RASMANCS] Searching for "adawarebp" [HKEY_CURRENT_USER\Software\AppDataLow\Software\adawarebp] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Ad-Aware Browsing Protection] "command"=""C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe"" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\adawarebp_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\adawarebp_RASDLG] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\adawarebp_RASMANCS] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\AppDataLow\Software\adawarebp] Searching for "datamngr" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DATAMNGR] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DATAMNGR] "item"="DATAMNGR" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DATAMNGR] "command"="C:\PROGRA~2\SEARCH~1\Datamngr\DATAMN~1.EXE" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4E704E34-0FD7-4216-8B49-E4A8C853DB34}] "AppPath"="C:\PROGRA~2\SEARCH~1\Datamngr\SRTOOL~1" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0028FE51-2BFF-4A35-8266-0D10A6A4DF27}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe|Name=Search-Results Toolbar DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F8BD6963-EDBD-44DD-A5DA-038F96222E8A}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe|Name=Search-Results Toolbar DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0028FE51-2BFF-4A35-8266-0D10A6A4DF27}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe|Name=Search-Results Toolbar DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F8BD6963-EDBD-44DD-A5DA-038F96222E8A}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe|Name=Search-Results Toolbar DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0028FE51-2BFF-4A35-8266-0D10A6A4DF27}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe|Name=Search-Results Toolbar DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F8BD6963-EDBD-44DD-A5DA-038F96222E8A}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe|Name=Search-Results Toolbar DTX Broker|" Searching for "lyrixeeker" [HKEY_CURRENT_USER\Software\AppDataLow\Software\LyriXeeker] [HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions] "lyrix@lyrixeeker.co"="C:\Program Files (x86)\LyriXeeker\125.xpi" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\epojlgbehpaeekopencdagbdamnkppci] "Path"="C:\Program Files (x86)\LyriXeeker\125.crx" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\lyrix@lyrixeeker.co] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\lyrix@lyrixeeker.co] "Publisher"="LyriXeeker Tech" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\lyrix@lyrixeeker.co] "UninstallString"="C:\Program Files (x86)\LyriXeeker\uninstall.exe" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\AppDataLow\Software\LyriXeeker] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Mozilla\Firefox\Extensions] "lyrix@lyrixeeker.co"="C:\Program Files (x86)\LyriXeeker\125.xpi" Searching for "mypc backup" No data found. Searching for "speedupmypc" No data found. Searching for "sweetim" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3199093499-978631591-3148159529-1001\Software\SweetIM] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Sweetpacks Communicator] "command"="C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\02F47BF73B948514FAACADD8CBBDF37D] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\080D9F5E1E95FEE4794CE438E635239E] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgxml_wrapper.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\12BF94BD06C95F343A77631402B9556A] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1E264E0A5959A1C46BA9175A878B12EA] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgconfig.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2124D8A8CF720FD44866190AF560228E] "254796BF4AC84B64891B61C529A2E23F"="C:\ProgramData\SweetIM\Communicator\conf\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\27A325ACED8CA4743A30127638591ADB] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\mgsimcommon.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E6768B6932D112438F047C54D180635] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\ClearHist.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\350D17402BD84234EAF7D32F08172D7C] "254796BF4AC84B64891B61C529A2E23F"="C:\ProgramData\SweetIM\Communicator\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\351716A953E21214898904032EAE2E81] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\397C771A7BCAC904697C3EC629ED33ED] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgHelper.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3EE8C5F419057E1478A654868CEE60B5] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4735D908D66E1BA46B6C2D7185A12B2B] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\resources\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\69D6A6B2ED56AF24EA6335EAD6E91CA4] "16FE85B52F587794795A481CF9295697"="C?\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgHelperApp.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\76D8378E2DDAED3428720A631F6E3BF0] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\resources\sqlite\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7FFA128C2B0FF414D805FC5627883401] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mghooking.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86EDC790504E1834DBC20C9A04328FD2] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\green\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97C3D0F82E712E241A2F969F45E3351C] "16FE85B52F587794795A481CF9295697"="C?\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarProxy.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\98CC8BF5A4A6E6C4ABF7051DDAB8B058] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9A001B259DB7D694E818BE29B973992C] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9E7F556BF224D804D96A96F0F6344789] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\blue\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A189D17A469616C4688D23E192996267] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mglogger.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BAE2EC163C6A68A48921573E0E7E199D] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\mgcommunication.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BF4F885EDEE45644EB1E0C99E0162399] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\Microsoft.VC90.CRT\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C06C6662FA5B04646829E4A460857770] "254796BF4AC84B64891B61C529A2E23F"="C:\ProgramData\SweetIM\Communicator\Logs\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CE21F3FD57B244142880EF15A165A156] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\orange\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CEEB3E14ABE8270419B0FD762E18F7C6] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\mgcommon.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D15DAF33C220F91468A1D7D57C31ACD7] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\conf\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D3BA76A44C779424889063D5098ED2D6] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgcommon.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D6D0EB9FDBD90C04D92A7E729058F10D] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E4748F9A4181FCE46A23C13B517B9420] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgsimcommon.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ED1B5E9A3BDB51349BF96E842C062D98] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\Microsoft.VC90.CRT\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FECBC2BC14DA6CD459BD59A041709836] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\mgxml_wrapper.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\16FE85B52F587794795A481CF9295697\InstallProperties] "Contact"="SweetIM Technical Support Department" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\16FE85B52F587794795A481CF9295697\InstallProperties] "HelpLink"="hxxp://www.sweetim.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\16FE85B52F587794795A481CF9295697\InstallProperties] "InstallLocation"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\16FE85B52F587794795A481CF9295697\InstallProperties] "Publisher"="SweetIM Technologies Ltd." [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\16FE85B52F587794795A481CF9295697\InstallProperties] "URLInfoAbout"="hxxp://www.sweetim.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\16FE85B52F587794795A481CF9295697\InstallProperties] "URLUpdateInfo"="hxxp://www.sweetim.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\254796BF4AC84B64891B61C529A2E23F\InstallProperties] "Contact"="SweetIM Technical Support Department" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\254796BF4AC84B64891B61C529A2E23F\InstallProperties] "HelpLink"="hxxp://www.sweetim.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\254796BF4AC84B64891B61C529A2E23F\InstallProperties] "InstallLocation"="C:\Program Files (x86)\SweetIM\Communicator\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\254796BF4AC84B64891B61C529A2E23F\InstallProperties] "Publisher"="SweetIM Technologies Ltd." [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\254796BF4AC84B64891B61C529A2E23F\InstallProperties] "URLInfoAbout"="hxxp://www.sweetim.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\254796BF4AC84B64891B61C529A2E23F\InstallProperties] "URLUpdateInfo"="hxxp://www.sweetim.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\toolbar_vit_sweetim_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\toolbar_vit_sweetim_RASMANCS] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{A21972B4-5118-42E3-B07B-3ABF8F630877}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe|Name=SweetPacksUpdateManager|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F0F839E5-89DE-4467-9E52-606055705D06}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe|Name=SweetPacksUpdateManager|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{A21972B4-5118-42E3-B07B-3ABF8F630877}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe|Name=SweetPacksUpdateManager|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F0F839E5-89DE-4467-9E52-606055705D06}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe|Name=SweetPacksUpdateManager|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{A21972B4-5118-42E3-B07B-3ABF8F630877}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe|Name=SweetPacksUpdateManager|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F0F839E5-89DE-4467-9E52-606055705D06}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe|Name=SweetPacksUpdateManager|" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3199093499-978631591-3148159529-1001\Software\SweetIM] Searching for "distromatic" No data found. Searching for "BabSolution" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\fagpjgjmoaccgkkpjeoinehnoaimnbla] "path"="C:\Users\PC\AppData\Roaming\BabSolution\CR\hola.crx" Searching for "bProtector" No data found. Searching for "BrowserDefender" [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\ProgramData\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe"="Application Manager" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{2A0F3D1B-0909-4FF4-B272-609CCE6054E7}] "DllName"="PCTBrowserDefender.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{472734EA-242A-422B-ADF8-83D1E48CC825}] "DllName"="PCTBrowserDefender.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{424202EF-76FA-4231-BF7A-5153EB49F987}] "Path"="\BrowserDefendert" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BrowserDefendert] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{2A0F3D1B-0909-4FF4-B272-609CCE6054E7}] "DllName"="PCTBrowserDefender.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{472734EA-242A-422B-ADF8-83D1E48CC825}] "DllName"="PCTBrowserDefender.dll" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\ProgramData\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe"="Application Manager" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\ProgramData\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe"="Application Manager" Searching for "iLivid" [HKEY_CURRENT_USER\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\C:\Users\PC\AppData\Local\iLivid] [HKEY_CURRENT_USER\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.8.false\C:\Users\PC\AppData\Local\iLivid] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\C:\Users\PC\AppData\Local\iLivid] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.8.false\C:\Users\PC\AppData\Local\iLivid] Searching for "holasearch" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "hp_url"="hxxp://www.holasearch.com/?babsrc=HP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "nt_url"="hxxp://www.holasearch.com/?babsrc=NT_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "dsFFX"="holasearch" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "uninstaller"="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\uninstall.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "sp_url"="hxxp://www.holasearch.com/?q={searchTerms}&babsrc=SP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "tb_url"="hxxp://www.holasearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "kw_url"="hxxp://www.holasearch.com/?babsrc=SP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927&q=" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\esrv.holasearchESrvc] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\esrv.holasearchESrvc\CurVer] @="esrv.holasearchESrvc.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\esrv.holasearchESrvc.1] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchappCore] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchappCore\CurVer] @="holasearch.holasearchappCore.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchappCore.1] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchdskBnd] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchdskBnd\CurVer] @="holasearch.holasearchdskBnd.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchdskBnd.1] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchHlpr] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchHlpr\CurVer] @="holasearch.holasearchHlpr.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchHlpr.1] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}\1.0\0\win32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchsrv.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}\1.0\HELPDIR] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0] @="holasearchCmn 1.0 Type Library" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0\0\win32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchEng.dll\2" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0\HELPDIR] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1E44819B-54E1-411B-9D9F-38D7B913BCF2}\InprocServer32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchEng.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}\LocalServer32] @=""C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchsrv.exe"" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}\ProgID] @="esrv.holasearchESrvc.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}\VersionIndependentProgID] @="esrv.holasearchESrvc" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}\InprocServer32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchApp.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}\ProgID] @="holasearch.holasearchappCore.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}\VersionIndependentProgID] @="holasearch.holasearchappCore" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C46EFEA4-B0F3-428B-9E77-650E3634EC56}\InprocServer32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\bh\holasearch.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "hp_url"="hxxp://www.holasearch.com/?babsrc=HP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "nt_url"="hxxp://www.holasearch.com/?babsrc=NT_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "dsFFX"="holasearch" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "uninstaller"="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\uninstall.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "sp_url"="hxxp://www.holasearch.com/?q={searchTerms}&babsrc=SP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "tb_url"="hxxp://www.holasearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "kw_url"="hxxp://www.holasearch.com/?babsrc=SP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927&q=" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}\1.0\0\win32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchsrv.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}\1.0\HELPDIR] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0] @="holasearchCmn 1.0 Type Library" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0\0\win32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchEng.dll\2" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0\HELPDIR] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5882DB3D-175D-4CDC-A030-1B7EC2BC8EC6}] "AppName"="holasearchsrv.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5882DB3D-175D-4CDC-A030-1B7EC2BC8EC6}] "AppPath"="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{1E44819B-54E1-411B-9D9F-38D7B913BCF2}\InprocServer32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchEng.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}\LocalServer32] @=""C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchsrv.exe"" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}\ProgID] @="esrv.holasearchESrvc.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}\VersionIndependentProgID] @="esrv.holasearchESrvc" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}\InprocServer32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchApp.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}\ProgID] @="holasearch.holasearchappCore.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}\VersionIndependentProgID] @="holasearch.holasearchappCore" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{C46EFEA4-B0F3-428B-9E77-650E3634EC56}\InprocServer32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\bh\holasearch.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "hp_url"="hxxp://www.holasearch.com/?babsrc=HP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "nt_url"="hxxp://www.holasearch.com/?babsrc=NT_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "dsFFX"="holasearch" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "uninstaller"="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\uninstall.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "sp_url"="hxxp://www.holasearch.com/?q={searchTerms}&babsrc=SP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "tb_url"="hxxp://www.holasearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "kw_url"="hxxp://www.holasearch.com/?babsrc=SP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927&q=" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}\1.0\0\win32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchsrv.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}\1.0\HELPDIR] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0] @="holasearchCmn 1.0 Type Library" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0\0\win32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchEng.dll\2" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0\HELPDIR] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" Searching for "DealPly" [HKEY_CURRENT_USER\Software\Wow6432Node\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje] "path"="C:\Program Files (x86)\DealPly\DealPly.crx" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{296BED8D-8F7A-40EE-AFDD-642839AC7E7F}] "Path"="\DealPlyUpdate" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AC019BF5-2EB9-4103-AEE1-09CD370F4CBB}] "Path"="\DealPly" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPly] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPlyUpdate] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Wow6432Node\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje] "path"="C:\Program Files (x86)\DealPly\DealPly.crx" Searching for "Babylon" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{2EECD738-5844-4A99-B4B6-146BF802613B}] "DllName"="BabylonToolbar.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}] "DllName"="BabylonToolbar.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{98889811-442D-49DD-99D7-DC866BE87DBC}] "DllName"="BabylonToolbarTlbr.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{2EECD738-5844-4A99-B4B6-146BF802613B}] "DllName"="BabylonToolbar.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}] "DllName"="BabylonToolbar.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{98889811-442D-49DD-99D7-DC866BE87DBC}] "DllName"="BabylonToolbarTlbr.dll" Searching for "Softonic" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\1e40ca8e_0] @="{0.0.0.00000000}.{f8047516-971f-40ba-85de-843482a8264a}|\Device\HarddiskVolume2\Users\PC\Downloads\SoftonicDownloader_fuer_mp3directcut.exe%b{00000000-0000-0000-0000-000000000000}" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\29629339_0] @="{0.0.0.00000000}.{f8047516-971f-40ba-85de-843482a8264a}|\Device\HarddiskVolume2\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe%b{00000000-0000-0000-0000-000000000000}" [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe"="Softonic Downloader " [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_mp3directcut_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_mp3directcut_RASMANCS] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_trustport-internet-security_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_trustport-internet-security_RASMANCS] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\1e40ca8e_0] @="{0.0.0.00000000}.{f8047516-971f-40ba-85de-843482a8264a}|\Device\HarddiskVolume2\Users\PC\Downloads\SoftonicDownloader_fuer_mp3directcut.exe%b{00000000-0000-0000-0000-000000000000}" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\29629339_0] @="{0.0.0.00000000}.{f8047516-971f-40ba-85de-843482a8264a}|\Device\HarddiskVolume2\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe%b{00000000-0000-0000-0000-000000000000}" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe"="Softonic Downloader " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe"="Softonic Downloader " Searching for "delta LTD" No data found. Searching for "PriceGong" [HKEY_CURRENT_USER\Software\PowerPack\225\13] "c"="hxxp://www.powerpackdl.com/downloads/pricegong.exe" [HKEY_CURRENT_USER\Software\PowerPack\225\13] "i"="hxxp://www.pricegong.com/TermsofUse.aspx" [HKEY_CURRENT_USER\Software\PowerPack\225\13] "j"="PriceGong" [HKEY_CURRENT_USER\Software\PowerPack\225\13] "n"="rv:HKCR,AppID\\PriceGongIE.DLL,AppID,{835315FC-1BF6-4CA9-80CD-F6C158D40692}" [HKEY_CURRENT_USER\Software\PowerPack\225\13] "x"="hxxp://www.pricegong.com/favicon.ico" [HKEY_CURRENT_USER\Software\PowerPack\225\13] "y"="hxxp://www.pricegong.com/" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\PriceGong_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\PriceGong_RASMANCS] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\PowerPack\225\13] "c"="hxxp://www.powerpackdl.com/downloads/pricegong.exe" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\PowerPack\225\13] "i"="hxxp://www.pricegong.com/TermsofUse.aspx" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\PowerPack\225\13] "j"="PriceGong" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\PowerPack\225\13] "n"="rv:HKCR,AppID\\PriceGongIE.DLL,AppID,{835315FC-1BF6-4CA9-80CD-F6C158D40692}" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\PowerPack\225\13] "x"="hxxp://www.pricegong.com/favicon.ico" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\PowerPack\225\13] "y"="hxxp://www.pricegong.com/" Searching for "OpenCandy" No data found. Searching for "PerformerSoft" No data found. Searching for "SoftSafe" No data found. Searching for "IBUpdater" No data found. Searching for " " [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\PhotoPrintingWizard\Laser Pro LL2] "PrintTicket"="<?xml version="1.0"?> <psf:PrintTicket version="1" xmlns:xsd="hxxp://www.w3.org/2001/XMLSchema" xmlns:xsi="hxxp://www.w3.org/2001/XMLSchema-instance" xmlns:psf="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemaframework" xmlns:psk="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemakeywords" xmlns:mti="hxxp://schemas.monotypeimaging.com/ptpc/2006/1" xmlns:oem="hxxp://schemas.monotypeimaging.com/ptpc/oem/2006/1"><psf:Feature name="psk:PageOrientation"><psf:Option name="psk:Landscape"/></psf:Feature><!-- --><!-- Monotype Imaging print ticket --><!-- --><!-- --><!-- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\PhotoPrintingWizard\Laser Pro LL2] "PrintCapabilites"="<?xml version="1.0"?> <psf:PrintCapabilities version="1" xmlns:xsd="hxxp://www.w3.org/2001/XMLSchema" xmlns:xsi="hxxp://www.w3.org/2001/XMLSchema-instance" xmlns:psf="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemaframework" xmlns:psk="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemakeywords" xmlns:mti="hxxp://schemas.monotypeimaging.com/ptpc/2006/1" xmlns:oem="hxxp://schemas.monotypeimaging.com/ptpc/oem/2006/1"><!-- --><!-- Monotype Imaging print capabilities --><!-- --><!-- --><!-- JobComment --><!-- [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "G:\Menu.exe"="CnMemory Software " [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe"="Softonic Downloader " [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Desktop\TrustPort_Internet_Security_12.0.0.4788.exe"="TrustPort Internet Security " [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WSMAN\Plugin\Microsoft.PowerShell] "ConfigXML"=" <PlugInConfiguration xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Name="microsoft.powershell" Filename="%windir%\system32\pwrshplugin.dll" SDKVersion="1" XmlRenderingType="text" > <InitializationParameters> <Param Name="PSVersion" Value="2.0"/> </InitializationParameters> <Resources> <Resource ResourceUri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell" SupportsOptions="true" ExactMatch="true"> <Security xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Uri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell" ExactMatch="true" Sddl="O:NSG:BAD:P(A;;GA;;;BA)S:P(AU;FA;GA;;;WD)(AU;SA;GXGW;;;WD)"/> <Capability Type="Shell"/> </Resource> </Res [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\WSMAN\Plugin\Microsoft.PowerShell32] "ConfigXML"="<PlugInConfiguration xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Name="microsoft.powershell32" Filename="%windir%\system32\pwrshplugin.dll" SDKVersion="1" XmlRenderingType="text" Architecture="32" > <InitializationParameters> <Param Name="PSVersion" Value="2.0"/> </InitializationParameters> <Resources> <Resource ResourceUri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell32" SupportsOptions="true" ExactMatch="true"> <Security xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Uri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell32" ExactMatch="true" Sddl="O:NSG:BAD:P(A;;GA;;;BA)S:P(AU;FA;GA;;;WD)(AU;SA;GXGW;;;WD)"/> [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&10D4990&0&__ ______&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&10D4990&0&__ ______&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&11AC6715&0&_ _______&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&11AC6715&0&_ _______&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&2706475&0&__ ______&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&2706475&0&__ ______&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&10D4990&0&__ ______&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&10D4990&0&__ ______&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&11AC6715&0&_ _______&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&11AC6715&0&_ _______&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&2706475&0&__ ______&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&2706475&0&__ ______&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&10D4990& 0&________&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&10D4990& 0&________&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&11AC6715 &0&________&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&11AC6715 &0&________&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&2706475& 0&________&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&2706475& 0&________&1#] "DeviceDesc"="NERO " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\PhotoPrintingWizard\Laser Pro LL2] "PrintTicket"="<?xml version="1.0"?> <psf:PrintTicket version="1" xmlns:xsd="hxxp://www.w3.org/2001/XMLSchema" xmlns:xsi="hxxp://www.w3.org/2001/XMLSchema-instance" xmlns:psf="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemaframework" xmlns:psk="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemakeywords" xmlns:mti="hxxp://schemas.monotypeimaging.com/ptpc/2006/1" xmlns:oem="hxxp://schemas.monotypeimaging.com/ptpc/oem/2006/1"><psf:Feature name="psk:PageOrientation"><psf:Option name="psk:Landscape"/></psf:Feature><!-- --><!-- Monotype Imaging print ticket --><!-- --><!-- --><!-- [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\PhotoPrintingWizard\Laser Pro LL2] "PrintCapabilites"="<?xml version="1.0"?> <psf:PrintCapabilities version="1" xmlns:xsd="hxxp://www.w3.org/2001/XMLSchema" xmlns:xsi="hxxp://www.w3.org/2001/XMLSchema-instance" xmlns:psf="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemaframework" xmlns:psk="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemakeywords" xmlns:mti="hxxp://schemas.monotypeimaging.com/ptpc/2006/1" xmlns:oem="hxxp://schemas.monotypeimaging.com/ptpc/oem/2006/1"><!-- --><!-- Monotype Imaging print capabilities --><!-- --><!-- --><!-- JobComment --><!-- [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "G:\Menu.exe"="CnMemory Software " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe"="Softonic Downloader " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Desktop\TrustPort_Internet_Security_12.0.0.4788.exe"="TrustPort Internet Security " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "G:\Menu.exe"="CnMemory Software " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe"="Softonic Downloader " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Desktop\TrustPort_Internet_Security_12.0.0.4788.exe"="TrustPort Internet Security " -= EOF =- |
SystemLook 30.07.11 by jpshortstuff Log created at 19:08 on 06/08/2013 by PC Administrator - Elevation successful No Context: :filefind No Context: *systweak* No Context: *adawarebp* No Context: *datamngr* No Context: *lyrixeeker* No Context: *mypc backup* No Context: *speedupmypc* No Context: *sweetim* No Context: *distromatic* No Context: *BabSolution* No Context: *bProtector* No Context: *BrowserDefender* No Context: *iLivid* No Context: *holasearch* No Context: *DealPly* No Context: *Babylon* No Context: *Softonic* No Context: *delta LTD* No Context: *PriceGong* No Context: *OpenCandy* No Context: *PerformerSoft* No Context: *SoftSafe* No Context: *IBUpdater* ========== folderfind ========== Searching for "*systweak*" No folders found. Searching for "*adawarebp*" No folders found. Searching for "*datamngr*" No folders found. Searching for "*lyrixeeker*" No folders found. Searching for "*mypc backup*" No folders found. Searching for "*speedupmypc*" No folders found. Searching for "*sweetim*" No folders found. Searching for "*distromatic*" No folders found. Searching for "*BabSolution*" No folders found. Searching for "*bProtector*" No folders found. Searching for "*BrowserDefender*" No folders found. Searching for "*iLivid*" No folders found. Searching for "*holasearch*" No folders found. Searching for "*DealPly*" No folders found. Searching for "*Babylon*" No folders found. Searching for "*Softonic*" No folders found. Searching for "*delta LTD*" No folders found. Searching for "*PriceGong*" No folders found. Searching for "*OpenCandy*" No folders found. Searching for "*PerformerSoft*" No folders found. Searching for "*SoftSafe*" No folders found. Searching for "*IBUpdater*" No folders found. ========== regfind ========== Searching for "systweak" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\systweakasp_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\systweakasp_RASMANCS] Searching for "adawarebp" [HKEY_CURRENT_USER\Software\AppDataLow\Software\adawarebp] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Ad-Aware Browsing Protection] "command"=""C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe"" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\adawarebp_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\adawarebp_RASDLG] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\adawarebp_RASMANCS] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\AppDataLow\Software\adawarebp] Searching for "datamngr" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DATAMNGR] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DATAMNGR] "item"="DATAMNGR" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DATAMNGR] "command"="C:\PROGRA~2\SEARCH~1\Datamngr\DATAMN~1.EXE" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4E704E34-0FD7-4216-8B49-E4A8C853DB34}] "AppPath"="C:\PROGRA~2\SEARCH~1\Datamngr\SRTOOL~1" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0028FE51-2BFF-4A35-8266-0D10A6A4DF27}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe|Name=Search-Results Toolbar DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F8BD6963-EDBD-44DD-A5DA-038F96222E8A}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe|Name=Search-Results Toolbar DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0028FE51-2BFF-4A35-8266-0D10A6A4DF27}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe|Name=Search-Results Toolbar DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F8BD6963-EDBD-44DD-A5DA-038F96222E8A}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe|Name=Search-Results Toolbar DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0028FE51-2BFF-4A35-8266-0D10A6A4DF27}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe|Name=Search-Results Toolbar DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F8BD6963-EDBD-44DD-A5DA-038F96222E8A}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe|Name=Search-Results Toolbar DTX Broker|" Searching for "lyrixeeker" [HKEY_CURRENT_USER\Software\AppDataLow\Software\LyriXeeker] [HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions] "lyrix@lyrixeeker.co"="C:\Program Files (x86)\LyriXeeker\125.xpi" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\epojlgbehpaeekopencdagbdamnkppci] "Path"="C:\Program Files (x86)\LyriXeeker\125.crx" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\lyrix@lyrixeeker.co] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\lyrix@lyrixeeker.co] "Publisher"="LyriXeeker Tech" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\lyrix@lyrixeeker.co] "UninstallString"="C:\Program Files (x86)\LyriXeeker\uninstall.exe" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\AppDataLow\Software\LyriXeeker] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Mozilla\Firefox\Extensions] "lyrix@lyrixeeker.co"="C:\Program Files (x86)\LyriXeeker\125.xpi" Searching for "mypc backup" No data found. Searching for "speedupmypc" No data found. Searching for "sweetim" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3199093499-978631591-3148159529-1001\Software\SweetIM] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Sweetpacks Communicator] "command"="C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\02F47BF73B948514FAACADD8CBBDF37D] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\080D9F5E1E95FEE4794CE438E635239E] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgxml_wrapper.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\12BF94BD06C95F343A77631402B9556A] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1E264E0A5959A1C46BA9175A878B12EA] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgconfig.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2124D8A8CF720FD44866190AF560228E] "254796BF4AC84B64891B61C529A2E23F"="C:\ProgramData\SweetIM\Communicator\conf\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\27A325ACED8CA4743A30127638591ADB] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\mgsimcommon.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E6768B6932D112438F047C54D180635] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\ClearHist.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\350D17402BD84234EAF7D32F08172D7C] "254796BF4AC84B64891B61C529A2E23F"="C:\ProgramData\SweetIM\Communicator\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\351716A953E21214898904032EAE2E81] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\397C771A7BCAC904697C3EC629ED33ED] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgHelper.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3EE8C5F419057E1478A654868CEE60B5] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4735D908D66E1BA46B6C2D7185A12B2B] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\resources\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\69D6A6B2ED56AF24EA6335EAD6E91CA4] "16FE85B52F587794795A481CF9295697"="C?\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgHelperApp.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\76D8378E2DDAED3428720A631F6E3BF0] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\resources\sqlite\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7FFA128C2B0FF414D805FC5627883401] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mghooking.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86EDC790504E1834DBC20C9A04328FD2] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\green\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97C3D0F82E712E241A2F969F45E3351C] "16FE85B52F587794795A481CF9295697"="C?\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarProxy.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\98CC8BF5A4A6E6C4ABF7051DDAB8B058] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9A001B259DB7D694E818BE29B973992C] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9E7F556BF224D804D96A96F0F6344789] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\blue\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A189D17A469616C4688D23E192996267] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mglogger.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BAE2EC163C6A68A48921573E0E7E199D] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\mgcommunication.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BF4F885EDEE45644EB1E0C99E0162399] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\Microsoft.VC90.CRT\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C06C6662FA5B04646829E4A460857770] "254796BF4AC84B64891B61C529A2E23F"="C:\ProgramData\SweetIM\Communicator\Logs\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CE21F3FD57B244142880EF15A165A156] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\orange\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CEEB3E14ABE8270419B0FD762E18F7C6] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\mgcommon.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D15DAF33C220F91468A1D7D57C31ACD7] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\conf\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D3BA76A44C779424889063D5098ED2D6] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgcommon.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D6D0EB9FDBD90C04D92A7E729058F10D] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E4748F9A4181FCE46A23C13B517B9420] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgsimcommon.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ED1B5E9A3BDB51349BF96E842C062D98] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\Microsoft.VC90.CRT\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FECBC2BC14DA6CD459BD59A041709836] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\mgxml_wrapper.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\16FE85B52F587794795A481CF9295697\InstallProperties] "Contact"="SweetIM Technical Support Department" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\16FE85B52F587794795A481CF9295697\InstallProperties] "HelpLink"="hxxp://www.sweetim.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\16FE85B52F587794795A481CF9295697\InstallProperties] "InstallLocation"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\16FE85B52F587794795A481CF9295697\InstallProperties] "Publisher"="SweetIM Technologies Ltd." [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\16FE85B52F587794795A481CF9295697\InstallProperties] "URLInfoAbout"="hxxp://www.sweetim.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\16FE85B52F587794795A481CF9295697\InstallProperties] "URLUpdateInfo"="hxxp://www.sweetim.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\254796BF4AC84B64891B61C529A2E23F\InstallProperties] "Contact"="SweetIM Technical Support Department" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\254796BF4AC84B64891B61C529A2E23F\InstallProperties] "HelpLink"="hxxp://www.sweetim.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\254796BF4AC84B64891B61C529A2E23F\InstallProperties] "InstallLocation"="C:\Program Files (x86)\SweetIM\Communicator\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\254796BF4AC84B64891B61C529A2E23F\InstallProperties] "Publisher"="SweetIM Technologies Ltd." [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\254796BF4AC84B64891B61C529A2E23F\InstallProperties] "URLInfoAbout"="hxxp://www.sweetim.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\254796BF4AC84B64891B61C529A2E23F\InstallProperties] "URLUpdateInfo"="hxxp://www.sweetim.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\toolbar_vit_sweetim_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\toolbar_vit_sweetim_RASMANCS] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{A21972B4-5118-42E3-B07B-3ABF8F630877}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe|Name=SweetPacksUpdateManager|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F0F839E5-89DE-4467-9E52-606055705D06}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe|Name=SweetPacksUpdateManager|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{A21972B4-5118-42E3-B07B-3ABF8F630877}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe|Name=SweetPacksUpdateManager|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F0F839E5-89DE-4467-9E52-606055705D06}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe|Name=SweetPacksUpdateManager|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{A21972B4-5118-42E3-B07B-3ABF8F630877}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe|Name=SweetPacksUpdateManager|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F0F839E5-89DE-4467-9E52-606055705D06}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe|Name=SweetPacksUpdateManager|" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3199093499-978631591-3148159529-1001\Software\SweetIM] Searching for "distromatic" No data found. Searching for "BabSolution" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\fagpjgjmoaccgkkpjeoinehnoaimnbla] "path"="C:\Users\PC\AppData\Roaming\BabSolution\CR\hola.crx" Searching for "bProtector" No data found. Searching for "BrowserDefender" [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\ProgramData\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe"="Application Manager" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{2A0F3D1B-0909-4FF4-B272-609CCE6054E7}] "DllName"="PCTBrowserDefender.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{472734EA-242A-422B-ADF8-83D1E48CC825}] "DllName"="PCTBrowserDefender.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{424202EF-76FA-4231-BF7A-5153EB49F987}] "Path"="\BrowserDefendert" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BrowserDefendert] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{2A0F3D1B-0909-4FF4-B272-609CCE6054E7}] "DllName"="PCTBrowserDefender.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{472734EA-242A-422B-ADF8-83D1E48CC825}] "DllName"="PCTBrowserDefender.dll" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\ProgramData\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe"="Application Manager" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\ProgramData\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe"="Application Manager" Searching for "iLivid" [HKEY_CURRENT_USER\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\C:\Users\PC\AppData\Local\iLivid] [HKEY_CURRENT_USER\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.8.false\C:\Users\PC\AppData\Local\iLivid] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\C:\Users\PC\AppData\Local\iLivid] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.8.false\C:\Users\PC\AppData\Local\iLivid] Searching for "holasearch" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "hp_url"="hxxp://www.holasearch.com/?babsrc=HP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "nt_url"="hxxp://www.holasearch.com/?babsrc=NT_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "dsFFX"="holasearch" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "uninstaller"="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\uninstall.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "sp_url"="hxxp://www.holasearch.com/?q={searchTerms}&babsrc=SP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "tb_url"="hxxp://www.holasearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "kw_url"="hxxp://www.holasearch.com/?babsrc=SP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927&q=" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\esrv.holasearchESrvc] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\esrv.holasearchESrvc\CurVer] @="esrv.holasearchESrvc.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\esrv.holasearchESrvc.1] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchappCore] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchappCore\CurVer] @="holasearch.holasearchappCore.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchappCore.1] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchdskBnd] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchdskBnd\CurVer] @="holasearch.holasearchdskBnd.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchdskBnd.1] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchHlpr] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchHlpr\CurVer] @="holasearch.holasearchHlpr.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchHlpr.1] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}\1.0\0\win32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchsrv.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}\1.0\HELPDIR] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0] @="holasearchCmn 1.0 Type Library" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0\0\win32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchEng.dll\2" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0\HELPDIR] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1E44819B-54E1-411B-9D9F-38D7B913BCF2}\InprocServer32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchEng.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}\LocalServer32] @=""C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchsrv.exe"" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}\ProgID] @="esrv.holasearchESrvc.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}\VersionIndependentProgID] @="esrv.holasearchESrvc" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}\InprocServer32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchApp.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}\ProgID] @="holasearch.holasearchappCore.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}\VersionIndependentProgID] @="holasearch.holasearchappCore" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C46EFEA4-B0F3-428B-9E77-650E3634EC56}\InprocServer32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\bh\holasearch.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "hp_url"="hxxp://www.holasearch.com/?babsrc=HP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "nt_url"="hxxp://www.holasearch.com/?babsrc=NT_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "dsFFX"="holasearch" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "uninstaller"="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\uninstall.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "sp_url"="hxxp://www.holasearch.com/?q={searchTerms}&babsrc=SP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "tb_url"="hxxp://www.holasearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "kw_url"="hxxp://www.holasearch.com/?babsrc=SP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927&q=" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}\1.0\0\win32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchsrv.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}\1.0\HELPDIR] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0] @="holasearchCmn 1.0 Type Library" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0\0\win32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchEng.dll\2" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0\HELPDIR] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5882DB3D-175D-4CDC-A030-1B7EC2BC8EC6}] "AppName"="holasearchsrv.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5882DB3D-175D-4CDC-A030-1B7EC2BC8EC6}] "AppPath"="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{1E44819B-54E1-411B-9D9F-38D7B913BCF2}\InprocServer32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchEng.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}\LocalServer32] @=""C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchsrv.exe"" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}\ProgID] @="esrv.holasearchESrvc.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}\VersionIndependentProgID] @="esrv.holasearchESrvc" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}\InprocServer32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchApp.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}\ProgID] @="holasearch.holasearchappCore.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}\VersionIndependentProgID] @="holasearch.holasearchappCore" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{C46EFEA4-B0F3-428B-9E77-650E3634EC56}\InprocServer32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\bh\holasearch.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "hp_url"="hxxp://www.holasearch.com/?babsrc=HP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "nt_url"="hxxp://www.holasearch.com/?babsrc=NT_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "dsFFX"="holasearch" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "uninstaller"="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\uninstall.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "sp_url"="hxxp://www.holasearch.com/?q={searchTerms}&babsrc=SP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "tb_url"="hxxp://www.holasearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "kw_url"="hxxp://www.holasearch.com/?babsrc=SP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927&q=" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}\1.0\0\win32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchsrv.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}\1.0\HELPDIR] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0] @="holasearchCmn 1.0 Type Library" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0\0\win32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchEng.dll\2" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0\HELPDIR] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" Searching for "DealPly" [HKEY_CURRENT_USER\Software\Wow6432Node\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje] "path"="C:\Program Files (x86)\DealPly\DealPly.crx" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{296BED8D-8F7A-40EE-AFDD-642839AC7E7F}] "Path"="\DealPlyUpdate" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AC019BF5-2EB9-4103-AEE1-09CD370F4CBB}] "Path"="\DealPly" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPly] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPlyUpdate] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Wow6432Node\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje] "path"="C:\Program Files (x86)\DealPly\DealPly.crx" Searching for "Babylon" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{2EECD738-5844-4A99-B4B6-146BF802613B}] "DllName"="BabylonToolbar.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}] "DllName"="BabylonToolbar.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{98889811-442D-49DD-99D7-DC866BE87DBC}] "DllName"="BabylonToolbarTlbr.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{2EECD738-5844-4A99-B4B6-146BF802613B}] "DllName"="BabylonToolbar.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}] "DllName"="BabylonToolbar.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{98889811-442D-49DD-99D7-DC866BE87DBC}] "DllName"="BabylonToolbarTlbr.dll" Searching for "Softonic" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\1e40ca8e_0] @="{0.0.0.00000000}.{f8047516-971f-40ba-85de-843482a8264a}|\Device\HarddiskVolume2\Users\PC\Downloads\SoftonicDownloader_fuer_mp3directcut.exe%b{00000000-0000-0000-0000-000000000000}" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\29629339_0] @="{0.0.0.00000000}.{f8047516-971f-40ba-85de-843482a8264a}|\Device\HarddiskVolume2\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe%b{00000000-0000-0000-0000-000000000000}" [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe"="Softonic Downloader " [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_mp3directcut_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_mp3directcut_RASMANCS] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_trustport-internet-security_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_trustport-internet-security_RASMANCS] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\1e40ca8e_0] @="{0.0.0.00000000}.{f8047516-971f-40ba-85de-843482a8264a}|\Device\HarddiskVolume2\Users\PC\Downloads\SoftonicDownloader_fuer_mp3directcut.exe%b{00000000-0000-0000-0000-000000000000}" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\29629339_0] @="{0.0.0.00000000}.{f8047516-971f-40ba-85de-843482a8264a}|\Device\HarddiskVolume2\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe%b{00000000-0000-0000-0000-000000000000}" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe"="Softonic Downloader " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe"="Softonic Downloader " Searching for "delta LTD" No data found. Searching for "PriceGong" [HKEY_CURRENT_USER\Software\PowerPack\225\13] "c"="hxxp://www.powerpackdl.com/downloads/pricegong.exe" [HKEY_CURRENT_USER\Software\PowerPack\225\13] "i"="hxxp://www.pricegong.com/TermsofUse.aspx" [HKEY_CURRENT_USER\Software\PowerPack\225\13] "j"="PriceGong" [HKEY_CURRENT_USER\Software\PowerPack\225\13] "n"="rv:HKCR,AppID\\PriceGongIE.DLL,AppID,{835315FC-1BF6-4CA9-80CD-F6C158D40692}" [HKEY_CURRENT_USER\Software\PowerPack\225\13] "x"="hxxp://www.pricegong.com/favicon.ico" [HKEY_CURRENT_USER\Software\PowerPack\225\13] "y"="hxxp://www.pricegong.com/" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\PriceGong_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\PriceGong_RASMANCS] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\PowerPack\225\13] "c"="hxxp://www.powerpackdl.com/downloads/pricegong.exe" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\PowerPack\225\13] "i"="hxxp://www.pricegong.com/TermsofUse.aspx" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\PowerPack\225\13] "j"="PriceGong" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\PowerPack\225\13] "n"="rv:HKCR,AppID\\PriceGongIE.DLL,AppID,{835315FC-1BF6-4CA9-80CD-F6C158D40692}" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\PowerPack\225\13] "x"="hxxp://www.pricegong.com/favicon.ico" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\PowerPack\225\13] "y"="hxxp://www.pricegong.com/" Searching for "OpenCandy" No data found. Searching for "PerformerSoft" No data found. Searching for "SoftSafe" No data found. Searching for "IBUpdater" No data found. Searching for " " [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\PhotoPrintingWizard\Laser Pro LL2] "PrintTicket"="<?xml version="1.0"?> <psf:PrintTicket version="1" xmlns:xsd="hxxp://www.w3.org/2001/XMLSchema" xmlns:xsi="hxxp://www.w3.org/2001/XMLSchema-instance" xmlns:psf="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemaframework" xmlns:psk="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemakeywords" xmlns:mti="hxxp://schemas.monotypeimaging.com/ptpc/2006/1" xmlns:oem="hxxp://schemas.monotypeimaging.com/ptpc/oem/2006/1"><psf:Feature name="psk:PageOrientation"><psf:Option name="psk:Landscape"/></psf:Feature><!-- --><!-- Monotype Imaging print ticket --><!-- --><!-- --><!-- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\PhotoPrintingWizard\Laser Pro LL2] "PrintCapabilites"="<?xml version="1.0"?> <psf:PrintCapabilities version="1" xmlns:xsd="hxxp://www.w3.org/2001/XMLSchema" xmlns:xsi="hxxp://www.w3.org/2001/XMLSchema-instance" xmlns:psf="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemaframework" xmlns:psk="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemakeywords" xmlns:mti="hxxp://schemas.monotypeimaging.com/ptpc/2006/1" xmlns:oem="hxxp://schemas.monotypeimaging.com/ptpc/oem/2006/1"><!-- --><!-- Monotype Imaging print capabilities --><!-- --><!-- --><!-- JobComment --><!-- [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "G:\Menu.exe"="CnMemory Software " [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe"="Softonic Downloader " [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Desktop\TrustPort_Internet_Security_12.0.0.4788.exe"="TrustPort Internet Security " [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WSMAN\Plugin\Microsoft.PowerShell] "ConfigXML"=" <PlugInConfiguration xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Name="microsoft.powershell" Filename="%windir%\system32\pwrshplugin.dll" SDKVersion="1" XmlRenderingType="text" > <InitializationParameters> <Param Name="PSVersion" Value="2.0"/> </InitializationParameters> <Resources> <Resource ResourceUri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell" SupportsOptions="true" ExactMatch="true"> <Security xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Uri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell" ExactMatch="true" Sddl="O:NSG:BAD:P(A;;GA;;;BA)S:P(AU;FA;GA;;;WD)(AU;SA;GXGW;;;WD)"/> <Capability Type="Shell"/> </Resource> </Res [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\WSMAN\Plugin\Microsoft.PowerShell32] "ConfigXML"="<PlugInConfiguration xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Name="microsoft.powershell32" Filename="%windir%\system32\pwrshplugin.dll" SDKVersion="1" XmlRenderingType="text" Architecture="32" > <InitializationParameters> <Param Name="PSVersion" Value="2.0"/> </InitializationParameters> <Resources> <Resource ResourceUri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell32" SupportsOptions="true" ExactMatch="true"> <Security xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Uri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell32" ExactMatch="true" Sddl="O:NSG:BAD:P(A;;GA;;;BA)S:P(AU;FA;GA;;;WD)(AU;SA;GXGW;;;WD)"/> [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&10D4990&0&__ ______&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&10D4990&0&__ ______&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&11AC6715&0&_ _______&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&11AC6715&0&_ _______&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&2706475&0&__ ______&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&2706475&0&__ ______&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&10D4990&0&__ ______&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&10D4990&0&__ ______&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&11AC6715&0&_ _______&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&11AC6715&0&_ _______&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&2706475&0&__ ______&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&2706475&0&__ ______&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&10D4990& 0&________&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&10D4990& 0&________&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&11AC6715 &0&________&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&11AC6715 &0&________&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&2706475& 0&________&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&2706475& 0&________&1#] "DeviceDesc"="NERO " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\PhotoPrintingWizard\Laser Pro LL2] "PrintTicket"="<?xml version="1.0"?> <psf:PrintTicket version="1" xmlns:xsd="hxxp://www.w3.org/2001/XMLSchema" xmlns:xsi="hxxp://www.w3.org/2001/XMLSchema-instance" xmlns:psf="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemaframework" xmlns:psk="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemakeywords" xmlns:mti="hxxp://schemas.monotypeimaging.com/ptpc/2006/1" xmlns:oem="hxxp://schemas.monotypeimaging.com/ptpc/oem/2006/1"><psf:Feature name="psk:PageOrientation"><psf:Option name="psk:Landscape"/></psf:Feature><!-- --><!-- Monotype Imaging print ticket --><!-- --><!-- --><!-- [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\PhotoPrintingWizard\Laser Pro LL2] "PrintCapabilites"="<?xml version="1.0"?> <psf:PrintCapabilities version="1" xmlns:xsd="hxxp://www.w3.org/2001/XMLSchema" xmlns:xsi="hxxp://www.w3.org/2001/XMLSchema-instance" xmlns:psf="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemaframework" xmlns:psk="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemakeywords" xmlns:mti="hxxp://schemas.monotypeimaging.com/ptpc/2006/1" xmlns:oem="hxxp://schemas.monotypeimaging.com/ptpc/oem/2006/1"><!-- --><!-- Monotype Imaging print capabilities --><!-- --><!-- --><!-- JobComment --><!-- [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "G:\Menu.exe"="CnMemory Software " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe"="Softonic Downloader " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Desktop\TrustPort_Internet_Security_12.0.0.4788.exe"="TrustPort Internet Security " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "G:\Menu.exe"="CnMemory Software " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe"="Softonic Downloader " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Desktop\TrustPort_Internet_Security_12.0.0.4788.exe"="TrustPort Internet Security " -= EOF =- |
Servus, Schritt 1
Schritt 2 Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code: start Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Schritt 3 ESET Online Scanner
Schritt 4 Downloade Dir bitte ![]()
Bitte poste mit deiner nächsten Antwort
|
start HKCU\...\Run: [QtraxNotification] - C:\Users\PC\Qtrax\Player\Notification.exe [118568 2013-08-05] () C:\Users\PC\Qtrax BHO-x32: LyricsContainer - {83a2ad96-138f-4a98-b9db-4f65368dba9d} - C:\Program Files (x86)\LyricsContainer\125.dll C:\Program Files (x86)\LyricsContainer Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File FF Extension: LyricXeeker - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\oxamfp2j.default\Extensions\125 FF HKCU\...\Firefox\Extensions: [lyrix@lyrixeeker.co] C:\Program Files (x86)\LyriXeeker\125.xpi CHR HKLM-x32\...\Chrome\Extension: [epojlgbehpaeekopencdagbdamnkppci] - C:\Program Files (x86)\LyriXeeker\125.crx CHR HKLM-x32\...\Chrome\Extension: [fagpjgjmoaccgkkpjeoinehnoaimnbla] - C:\Users\PC\AppData\Roaming\BabSolution\CR\hola.crx CHR HKLM-x32\...\Chrome\Extension: [keaillmajpeodnbelalgeffidfcdgiem] - C:\Program Files (x86)\LyricsContainer\125.crx C:\Program Files (x86)\LyriXeeker 2013-08-05 16:50 - 2013-08-05 16:50 - 00003436 _____ C:\Windows\System32\Tasks\BrowserDefendert 2013-08-05 16:50 - 2013-08-05 16:50 - 00002377 _____ C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Qtrax Player.lnk 2013-08-05 16:50 - 2013-08-05 16:50 - 00000000 ____D C:\Users\PC\AppData\Roaming\Zip Opener Packages 2013-08-05 16:50 - 2013-08-05 16:50 - 00000000 ____D C:\Program Files (x86)\OpenIt 2013-08-05 16:48 - 2013-08-05 16:48 - 00717160 _____ C:\Users\PC\Downloads\ZipOpenerSetup(1).exe 2013-08-04 16:17 - 2013-08-04 16:17 - 04653592 _____ (Systweak Inc ) C:\Users\PC\Downloads\rcpsetupdsnr_ds367212.exe 2013-08-03 02:44 - 2013-08-03 02:44 - 00000000 ____D C:\Users\PC\Qtrax 2013-08-03 02:40 - 2013-08-05 16:50 - 00003782 _____ C:\Windows\System32\Tasks\QtraxPlayer 2013-08-03 02:39 - 2013-08-06 18:49 - 00000280 _____ C:\Windows\Tasks\DigitalSite.job 2013-08-03 02:39 - 2013-08-05 16:49 - 00003208 _____ C:\Windows\System32\Tasks\DigitalSite 2013-08-03 02:39 - 2013-08-03 02:39 - 00717160 _____ C:\Users\PC\Downloads\ZipOpenerSetup.exe 2013-08-03 02:39 - 2013-08-03 02:39 - 00000000 ____D C:\Users\PC\AppData\Roaming\DigitalSite 2013-08-05 16:50 - 2013-07-01 14:20 - 00003370 _____ C:\Windows\System32\Tasks\EPUpdater 2013-08-03 02:39 - 2013-08-03 02:39 - 00717160 _____ C:\Users\PC\Downloads\ZipOpenerSetup.exe Task: {296BED8D-8F7A-40EE-AFDD-642839AC7E7F} - System32\Tasks\DealPlyUpdate => C:\Program Files (x86)\DealPly\DealPlyUpdate.exe Task: {424202EF-76FA-4231-BF7A-5153EB49F987} - System32\Tasks\BrowserDefendert Task: {58A24A98-E7CB-4B24-8C1F-1A8963D3C8B7} - System32\Tasks\DigitalSite => C:\Users\PC\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE Task: {69EBF01E-16AF-43A1-BF6C-0AACD9FCDD08} - System32\Tasks\EPUpdater => C:\Users\PC\AppData\Roaming\BABSOL~1 Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\systweakasp_RASAPI32" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\systweakasp_RASMANCS" /f Reg: reg delete "HKEY_CURRENT_USER\Software\AppDataLow\Software\adawarebp" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\adawarebp_RASAPI32" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\adawarebp_RASDLG" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\adawarebp_RASMANCS" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DATAMNGR" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules" /v "{0028FE51-2BFF-4A35-8266-0D10A6A4DF27}" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules" /v "{F8BD6963-EDBD-44DD-A5DA-038F96222E8A}" /f Reg: reg delete "HKEY_CURRENT_USER\Software\AppDataLow\Software\LyriXeeker" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\epojlgbehpaeekopencdagbdamnkppci" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\lyrix@lyrixeeker.co" /f Reg: reg delete "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3199093499-978631591-3148159529-1001\Software\SweetIM" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\toolbar_vit_sweetim_RASAPI32" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\toolbar_vit_sweetim_RASMANCS" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\fagpjgjmoaccgkkpjeoinehnoaimnbla" /f Reg: reg delete "HKEY_CURRENT_USER\Software\Trolltech" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\esrv.holasearchESrvc" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\esrv.holasearchESrvc.1" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchappCore" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchappCore.1" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchdskBnd" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchdskBnd.1" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchHlpr" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchHlpr.1" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1E44819B-54E1-411B-9D9F-38D7B913BCF2}" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C46EFEA4-B0F3-428B-9E77-650E3634EC56}" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5882DB3D-175D-4CDC-A030-1B7EC2BC8EC6}" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{1E44819B-54E1-411B-9D9F-38D7B913BCF2}" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{C46EFEA4-B0F3-428B-9E77-650E3634EC56}" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_mp3directcut_RASAPI32" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_mp3directcut_RASMANCS" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_trustport-internet-security_RASAPI32" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_trustport-internet-security_RASMANCS" /f Reg: reg delete "HKEY_CURRENT_USER\Software\PowerPack" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\PriceGong_RASAPI32" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\PriceGong_RASMANCS" /f end ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=ba732d7a34e01f4a976b2d198e665265 # engine=14686 # end=stopped # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-08-07 01:57:49 # local_time=2013-08-07 03:57:49 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1023 16777215 0 0 0 0 0 0 # compatibility_mode=5893 16776574 100 94 0 127513719 0 0 # scanned=18394 # found=0 # cleaned=0 # scan_time=1288 Results of screen317's Security Check version 0.99.71 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 10 ``````````````Antivirus/Firewall Check:`````````````` Microsoft Security Essentials Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Ad-Aware Malwarebytes Anti-Malware Version 1.75.0.1300 Adobe Flash Player 11.8.800.94 Adobe Reader 10.1.7 Adobe Reader out of Date! Mozilla Firefox (22.0) ````````Process Check: objlist.exe by Laurent```````` Microsoft Security Essentials MSMpEng.exe Microsoft Security Essentials msseces.exe Ad-Aware AAWService.exe is disabled! Ad-Aware AAWTray.exe is disabled! Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbamgui.exe Malwarebytes' Anti-Malware mbamscheduler.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` |
Servus, lies dir meinen Schritt zum FRST-Fix nochmal durch und poste die Logdatei des Fixes von FRST, nicht die Code-Box von mir... :blabla: ;) |
Ups sry :D Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 07-08-2013 Ran by PC at 2013-08-07 17:58:13 Run:1 Running from C:\Users\PC\Desktop Boot Mode: Normal ============================================== HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\QtraxNotification => Value not found. C:\Users\PC\Qtrax => Moved successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83a2ad96-138f-4a98-b9db-4f65368dba9d} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{83a2ad96-138f-4a98-b9db-4f65368dba9d} => Key deleted successfully. "C:\Program Files (x86)\LyricsContainer" => File/Directory not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => Value deleted successfully. HKCR\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => Key not found. C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\oxamfp2j.default\Extensions\125 => Moved successfully. HKCU\Software\Mozilla\Firefox\Extensions\\lyrix@lyrixeeker.co => Value deleted successfully. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\epojlgbehpaeekopencdagbdamnkppci => Key deleted successfully. "C:\Program Files (x86)\LyriXeeker\125.crx" => File/Directory not found. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\fagpjgjmoaccgkkpjeoinehnoaimnbla => Key deleted successfully. "C:\Users\PC\AppData\Roaming\BabSolution\CR\hola.crx" => File/Directory not found. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\keaillmajpeodnbelalgeffidfcdgiem => Key deleted successfully. "C:\Program Files (x86)\LyricsContainer\125.crx" => File/Directory not found. "C:\Program Files (x86)\LyriXeeker" => File/Directory not found. C:\Windows\System32\Tasks\BrowserDefendert => Moved successfully. "C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Qtrax Player.lnk" => File/Directory not found. "C:\Users\PC\AppData\Roaming\Zip Opener Packages" => File/Directory not found. "C:\Program Files (x86)\OpenIt" => File/Directory not found. C:\Users\PC\Downloads\ZipOpenerSetup(1).exe => Moved successfully. C:\Users\PC\Downloads\rcpsetupdsnr_ds367212.exe => Moved successfully. "C:\Users\PC\Qtrax" => File/Directory not found. C:\Windows\System32\Tasks\QtraxPlayer => Moved successfully. C:\Windows\Tasks\DigitalSite.job => Moved successfully. C:\Windows\System32\Tasks\DigitalSite => Moved successfully. C:\Users\PC\Downloads\ZipOpenerSetup.exe => Moved successfully. "C:\Users\PC\AppData\Roaming\DigitalSite" directory move: C:\Users\PC\AppData\Roaming\DigitalSite\UpdateProc\config.dat => Moved successfully. C:\Users\PC\AppData\Roaming\DigitalSite\UpdateProc\prod.dat => Moved successfully. C:\Users\PC\AppData\Roaming\DigitalSite\UpdateProc\STTL.DAT => Moved successfully. C:\Users\PC\AppData\Roaming\DigitalSite\UpdateProc\TTL.DAT => Moved successfully. C:\Users\PC\AppData\Roaming\DigitalSite\UpdateProc\UpdateTask.exe => Moved successfully. Could not move "C:\Users\PC\AppData\Roaming\DigitalSite" directory. => Scheduled to move on reboot. C:\Windows\System32\Tasks\EPUpdater => Moved successfully. "C:\Users\PC\Downloads\ZipOpenerSetup.exe" => File/Directory not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{296BED8D-8F7A-40EE-AFDD-642839AC7E7F} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{296BED8D-8F7A-40EE-AFDD-642839AC7E7F} => Key deleted successfully. C:\Windows\System32\Tasks\DealPlyUpdate => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPlyUpdate => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{424202EF-76FA-4231-BF7A-5153EB49F987} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{424202EF-76FA-4231-BF7A-5153EB49F987} => Key deleted successfully. C:\Windows\System32\Tasks\BrowserDefendert not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BrowserDefendert => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{58A24A98-E7CB-4B24-8C1F-1A8963D3C8B7} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{58A24A98-E7CB-4B24-8C1F-1A8963D3C8B7} => Key deleted successfully. C:\Windows\System32\Tasks\DigitalSite not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DigitalSite => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{69EBF01E-16AF-43A1-BF6C-0AACD9FCDD08} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{69EBF01E-16AF-43A1-BF6C-0AACD9FCDD08} => Key deleted successfully. C:\Windows\System32\Tasks\EPUpdater not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EPUpdater => Key deleted successfully. ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\systweakasp_RASAPI32" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\systweakasp_RASMANCS" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_CURRENT_USER\Software\AppDataLow\Software\adawarebp" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\adawarebp_RASAPI32" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\adawarebp_RASDLG" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\adawarebp_RASMANCS" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DATAMNGR" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules" /v "{0028FE51-2BFF-4A35-8266-0D10A6A4DF27}" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules" /v "{F8BD6963-EDBD-44DD-A5DA-038F96222E8A}" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_CURRENT_USER\Software\AppDataLow\Software\LyriXeeker" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\epojlgbehpaeekopencdagbdamnkppci" /f ========= FEHLER: Der angegebene Registrierungsschlssel bzw. Wert wurde nicht gefunden. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\lyrix@lyrixeeker.co" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3199093499-978631591-3148159529-1001\Software\SweetIM" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\toolbar_vit_sweetim_RASAPI32" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\toolbar_vit_sweetim_RASMANCS" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\fagpjgjmoaccgkkpjeoinehnoaimnbla" /f ========= FEHLER: Der angegebene Registrierungsschlssel bzw. Wert wurde nicht gefunden. ========= End of Reg: ========= ========= reg delete "HKEY_CURRENT_USER\Software\Trolltech" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\esrv.holasearchESrvc" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\esrv.holasearchESrvc.1" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchappCore" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchappCore.1" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchdskBnd" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchdskBnd.1" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchHlpr" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchHlpr.1" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1E44819B-54E1-411B-9D9F-38D7B913BCF2}" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C46EFEA4-B0F3-428B-9E77-650E3634EC56}" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}" /f ========= FEHLER: Der angegebene Registrierungsschlssel bzw. Wert wurde nicht gefunden. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}" /f ========= FEHLER: Der angegebene Registrierungsschlssel bzw. Wert wurde nicht gefunden. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}" /f ========= FEHLER: Der angegebene Registrierungsschlssel bzw. Wert wurde nicht gefunden. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5882DB3D-175D-4CDC-A030-1B7EC2BC8EC6}" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{1E44819B-54E1-411B-9D9F-38D7B913BCF2}" /f ========= FEHLER: Der angegebene Registrierungsschlssel bzw. Wert wurde nicht gefunden. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}" /f ========= FEHLER: Der angegebene Registrierungsschlssel bzw. Wert wurde nicht gefunden. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}" /f ========= FEHLER: Der angegebene Registrierungsschlssel bzw. Wert wurde nicht gefunden. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{C46EFEA4-B0F3-428B-9E77-650E3634EC56}" /f ========= FEHLER: Der angegebene Registrierungsschlssel bzw. Wert wurde nicht gefunden. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}" /f ========= FEHLER: Der angegebene Registrierungsschlssel bzw. Wert wurde nicht gefunden. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}" /f ========= FEHLER: Der angegebene Registrierungsschlssel bzw. Wert wurde nicht gefunden. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}" /f ========= FEHLER: Der angegebene Registrierungsschlssel bzw. Wert wurde nicht gefunden. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_mp3directcut_RASAPI32" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_mp3directcut_RASMANCS" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_trustport-internet-security_RASAPI32" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_trustport-internet-security_RASMANCS" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_CURRENT_USER\Software\PowerPack" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\PriceGong_RASAPI32" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\PriceGong_RASMANCS" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= =========== Result of Scheduled Files to move =========== "C:\Users\PC\AppData\Roaming\DigitalSite" => Directory could not move. ==== End of Fixlog ==== |
Servus, sieht schon mal gut aus. Noch eine letzte Kontrolle: Kontrollscan mit FRST Führe wie zuvor beschrieben einen Scan mit FRST aus. Setze dazu eine Haken bei Addition.txt rechts unten und klicke auf Scan. Es werden wieder zwei Logdateien erzeugt. Poste mir diese. |
Hey, sry dass ich mich erst jetzt melde. Muss ich bei dem FRST einen neuen Scan machen? Da er diese Fixlist.txt nicht findet.. LG |
Servus, lies dir bitte meinen letzten Post nochmal durch, dort steht alles drinnen. ;) |
Oh ja :D habs jetzt verstanden :D FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-08-2013 FRST Additions Logfile: Code: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 09-08-2013 |
Servus, Wenn du keine Probleme mehr hast, dann sind wir hier fertig. Deine Logdateien sind sauber. :daumenhoc Zum Schluss müssen wir noch ein paar abschließende Schritte unternehmen, um deinen Pc aufzuräumen und abzusichern. Schritt 1 Deinstalliere bitte deine aktuelle Version von Adobe Reader Start--> Systemsteuerung--> Software / Programme deinstallieren--> Adobe Reader und lade dir die neue Version von Hier herunter- Entferne den Hacken für den McAfee SecurityScan bzw. Google Chrome. Schritt 2
Prüfe bitte auch (regelmässig) ob folgende Links fehlende Updates bei deinen Plugins zeigen: Schritt 3 Die Reihenfolge ist hier entscheidend.
Schritt 4 Abschließend habe ich noch ein paar Tipps zur Absicherung deines Systems. Ich kann gar nicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von Registry Cleanern. Diese Schaden deinem System mehr als dass sie helfen. Hier ein englischer Link: Miekemoes Blogspot ( MVP ) Was du vermeiden solltest:
Nun bleibt mir nur noch dir viel Spaß beim sicheren Surfen zu wünschen... ... und vielleicht möchtest du ja das Trojaner-Board unterstützen? Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so dass ich dieses Thema aus meinen Abos löschen kann. |
Ich habe alles gemacht! Vielen vielen Dank für alles! Läuft alles super! :) |
Ich bin froh, dass wir helfen konnten :abklatsch: In diesem Forum kannst du eine kurze Rückmeldung zur Bereinigung abgeben, sofern du das möchtest: Lob, Kritik und Wünsche Klicke dazu auf den Button "NEUES THEMA" und poste ein kleines Feedback. Vielen Dank! :) Dieses Thema scheint erledigt und wird aus meinen Abos gelöscht. Solltest Du das Thema erneut brauchen, schicke mir bitte eine PM. Jeder andere bitte hier klicken und einen eigenen Thread erstellen. |
Alle Zeitangaben in WEZ +1. Es ist jetzt 11:26 Uhr. |
Copyright ©2000-2025, Trojaner-Board