![]() |
TrojansHunter kann gefundenen Trojaner leider nicht löschen Hallo Liebe Leute, ich hoffe, es kann mir jemand helfen. Ich habe das Programm TrojanHunter runtergeladen, da ich das Gefühl hatte, dass mein PC ein Trojaner hat. Beim Scannen hat das Programm Folgendes herausgefunden: Found malware file: C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFdetect.exe (Vobfus.432) Found malware file: C:\Users\All Users\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFdetect.exe (Vobfus.432) Found malware file: C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\acrobatupdater.exe (AgentZ.2056) Found malware file: C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\readerupdater.exe (AgentZ.2056) Doch leider kann ich das nicht löschen, da ich eine trial version habe.. Was muss ich tun? Vielen Dank im Voraus und LG U-C |
:hallo: Mein Name ist Matthias und ich werde dir bei der Bereinigung deines Computers helfen. Bitte beachte folgende Hinweise:
Ich habe dein Thema in Arbeit und melde mich so schnell wie möglich mit weiteren Anweisungen. |
Servus, Zitat:
Was ist passiert? Gibt es Auffälligkeiten? Gibt es Probleme mit deinem Rechner? Wenn ja, welche? Zitat:
Zitat:
|
Servus, vielen Dank für die schnelle Antwort! :) Da bin ich schonmal beruhigt... Während ich z.B. etwas google oder nur so im Internet surfe z.B. Youtube, Mails checken, kommen ständig Warnungen von dubiosen Programm, dass mein Computer in Gefahr ist. Oder, dass mein Laufwerk C bereinigt werden müsste " Klicken Sie auf bereinigen"- was ich natürlich nicht gemacht habe. Des Weiteren schließt sich mein Browser öfters von ganz alleine und die Internetverbindung ist wird immer langsamer. Ich hoffe, ich könnte deine Fragen einigermaßen verständlich beantworten.. :) |
Servus, Zitat:
Ich würde deinen Rechner gerne mal etwas näher inspizieren, nur um sicher zu gehen. :) So geht es los: Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: ![]() (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
|
So ich habe jetzt alles gemacht was du gesagt hast :) Das sind jetzt so 4 Sachen, die ich angezeigt bekommen habe: FRST Logfile: FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-08-2013 --- --- --- --- --- --- FRST Additions Logfile: Code: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 04-08-2013 FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-08-2013 --- --- --- |
FRST Additions Logfile: Code: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 04-08-2013 Habe ich alles richtig gemacht, oder fehlt da noch was? |
Servus, Zitat:
Du hast dir jede Menge Adware eingefangen. :) Dann starten wir mal die Bereinigung: AdwCleaner bitte zweimal direkt hintereinander genau so ausführen und beide Logdateien davon posten! Schritt 1 Downloade Dir bitte ![]()
Schritt 2 Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Schritt 3 Downloade Dir bitte ![]()
Bitte poste mit deiner nächsten Antwort
|
Hey habe schritt 1 und 2 schon mal fertig. Die poste ich dann schon mal Also die beiden LogdateienAdwCleaner Logfile: Code: # AdwCleaner v2.306 - Datei am 05/08/2013 um 17:20:38 erstellt adw cleaner (S2)AdwCleaner Logfile: Code: # AdwCleaner v2.306 - Datei am 05/08/2013 um 17:26:11 erstellt Code: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Malwarebytes Anti-Malware (Test) 1.75.0.1300 Malwarebytes : Free anti-malware download Datenbank Version: v2013.08.05.05 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 PC :: PC-HP [Administrator] Schutz: Aktiviert 05.08.2013 17:58:43 mbam-log-2013-08-05 (17-58-43).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 214006 Laufzeit: 11 Minute(n), 23 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 6 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{17E58097-6CA5-448B-830F-2A19678248FB} (PUP.Optional.LyricXeeker.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{17E58097-6CA5-448B-830F-2A19678248FB} (PUP.Optional.LyricXeeker.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2f7ea55-9ec3-4993-a1e9-62bdb904fd6d} (PUP.Optional.LyricXeeker.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\CLSID\{d2f7ea55-9ec3-4993-a1e9-62bdb904fd6d} (PUP.Optional.LyricXeeker.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\TypeLib\{32db519c-98a8-4129-828a-368cd8cf25a0} (PUP.Optional.LyricXeeker.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\Interface\{F9CF2BCB-2794-4E8B-A570-38B96572C2BE} (PUP.Optional.LyricXeeker.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Registrierungswerte: 1 HKCU\Software\Microsoft\Windows\CurrentVersion\Run|NTRedirect (PUP.Optional.A.BabSolution) -> Daten: C:\Windows\SysWOW64\rundll32.exe "C:\Users\PC\AppData\Roaming\BabSolution\Shared\NTRedirect.dll",Run -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 4 C:\Users\PC\Downloads\setup.exe (PUP.Optional.InstallCore) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Windows\Installer\1372f5c.msi (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Windows\Installer\1372f63.msi (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Windows\Tasks\LyricXeeker Update.job (PUP.Optional.Lyrixeeker) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) Und fertig :) |
Servus, sieht schon gut aus. :) Wir spüren die letzten Reste auf, damit wie sie später entfernen können: Schritt 1 Kontrollscan mit FRST Führe wie zuvor beschrieben einen Scan mit FRST aus. Setze dazu eine Haken bei Addition.txt rechts unten und klicke auf Scan. Es werden wieder zwei Logdateien erzeugt. Poste mir diese. Schritt 2 Lade SystemLook von jpshortstuff vom folgenden Spiegel herunter und speichere das Tool auf dem Desktop. SystemLook (64 bit)
Gibt es noch Probleme mit Malware? Wenn ja, welche? Wie läuft der Rechner derzeit? Bitte poste mit deiner nächsten Antwort
|
hey, anbei die Daten: FRST Logfile: FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-08-2013 --- --- --- --- --- --- FRST Additions Logfile: Code: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 04-08-2013 LSystemLook 30.07.11 by jpshortstuff Log created at 22:24 on 05/08/2013 by PC Administrator - Elevation successful ========== filefind ========== Searching for "*systweak*" No files found. Searching for "*adawarebp*" C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.dll --a---- 318872 bytes [23:20 11/12/2012] [23:20 11/12/2012] C55D73BF01BEB9C25516FA519174CC9C C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe --a---- 542104 bytes [23:20 11/12/2012] [23:20 11/12/2012] DF7AEEC25E5C006EEC61206476F48629 C:\Users\All Users\Ad-Aware Browsing Protection\adawarebp.dll --a---- 318872 bytes [23:20 11/12/2012] [23:20 11/12/2012] C55D73BF01BEB9C25516FA519174CC9C C:\Users\All Users\Ad-Aware Browsing Protection\adawarebp.exe --a---- 542104 bytes [23:20 11/12/2012] [23:20 11/12/2012] DF7AEEC25E5C006EEC61206476F48629 Searching for "*datamngr*" No files found. Searching for "*lyrixeeker*" No files found. Searching for "*mypc backup*" No files found. Searching for "*speedupmypc*" No files found. Searching for "*sweetim*" No files found. Searching for "*distromatic*" No files found. Searching for "*BabSolution*" No files found. Searching for "*bProtector*" No files found. Searching for "*BrowserDefender*" C:\Windows\Prefetch\BROWSERDEFENDER.EXE-62524200.pf --a---- 30700 bytes [00:24 05/08/2013] [14:50 05/08/2013] A660DF35F2F003AAABD99C1581C9AF85 C:\Windows\System32\Tasks\BrowserDefendert --a---- 3436 bytes [14:50 05/08/2013] [14:50 05/08/2013] 8444D519E7504D38BE49BC3FAE167689 Searching for "*iLivid*" C:\Users\PC\Downloads\iLividSetupV1.exe --a---- 1302424 bytes [18:57 27/11/2012] [18:57 27/11/2012] A572625DB335FCCA490C909C373FB81C Searching for "*holasearch*" No files found. Searching for "*DealPly*" C:\Windows\System32\Tasks\DealPly --a---- 3482 bytes [08:07 07/02/2013] [18:11 16/03/2013] FD52B70225C0B2F3FCE040C2C359D1A8 C:\Windows\System32\Tasks\DealPlyUpdate --a---- 3304 bytes [18:11 25/11/2012] [18:11 25/11/2012] 3F89962238E95558E6CF05D47AE0D32B Searching for "*Babylon*" C:\Users\PC\AppData\Local\Temp\8DD1A082-BAB0-7891-8C74-BC4EED533129\Latest\Babylon.dat --a---- 12384 bytes [14:49 05/08/2013] [12:17 19/02/2013] 825E5733974586A0A1229A53361ED13E Searching for "*Softonic*" No files found. Searching for "*delta LTD*" No files found. Searching for "*PriceGong*" No files found. Searching for "*OpenCandy*" No files found. Searching for "*PerformerSoft*" No files found. Searching for "*SoftSafe*" C:\Program Files\Common Files\Bitdefender\SetupInformation\downloader\extern\kingsoftSafeguard.xml --a---- 618 bytes [10:56 09/02/2013] [14:28 24/04/2012] E7BE97006F2213266A33D726FDBBE913 C:\Program Files\Common Files\Bitdefender\SetupInformation\downloader\extern\kingsoftSafeguard.xml.md5 --a---- 32 bytes [10:56 09/02/2013] [17:44 29/06/2012] D885CA3A040A7350B1CB313C9DC264ED Searching for "*IBUpdater*" No files found. ========== folderfind ========== Searching for "*systweak*" No folders found. Searching for "*adawarebp*" No folders found. Searching for "*datamngr*" No folders found. Searching for "*lyrixeeker*" C:\Program Files (x86)\LyriXeeker d------ [14:49 05/08/2013] Searching for "*mypc backup*" No folders found. Searching for "*speedupmypc*" No folders found. Searching for "*sweetim*" No folders found. Searching for "*distromatic*" No folders found. Searching for "*BabSolution*" No folders found. Searching for "*bProtector*" No folders found. Searching for "*BrowserDefender*" No folders found. Searching for "*iLivid*" No folders found. Searching for "*holasearch*" No folders found. Searching for "*DealPly*" C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\NS6RQ2XF\static.dealply.com d------ [22:51 12/02/2013] C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\NS6RQ2XF\macromedia.com\support\flashplayer\sys\#static.dealply.com d------ [22:51 12/02/2013] C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\NS6RQ2XF\static.dealply.com\flash\dealply_swf_engine.swf d------ [22:51 12/02/2013] Searching for "*Babylon*" No folders found. Searching for "*Softonic*" No folders found. Searching for "*delta LTD*" No folders found. Searching for "*PriceGong*" No folders found. Searching for "*OpenCandy*" No folders found. Searching for "*PerformerSoft*" No folders found. Searching for "*SoftSafe*" No folders found. Searching for "*IBUpdater*" No folders found. ========== regfind ========== Searching for "systweak" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\systweakasp_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\systweakasp_RASMANCS] Searching for "adawarebp" [HKEY_CURRENT_USER\Software\AppDataLow\Software\adawarebp] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Ad-Aware Browsing Protection] "command"=""C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe"" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\adawarebp_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\adawarebp_RASDLG] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\adawarebp_RASMANCS] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\AppDataLow\Software\adawarebp] Searching for "datamngr" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DATAMNGR] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DATAMNGR] "item"="DATAMNGR" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DATAMNGR] "command"="C:\PROGRA~2\SEARCH~1\Datamngr\DATAMN~1.EXE" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4E704E34-0FD7-4216-8B49-E4A8C853DB34}] "AppPath"="C:\PROGRA~2\SEARCH~1\Datamngr\SRTOOL~1" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0028FE51-2BFF-4A35-8266-0D10A6A4DF27}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe|Name=Search-Results Toolbar DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F8BD6963-EDBD-44DD-A5DA-038F96222E8A}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe|Name=Search-Results Toolbar DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0028FE51-2BFF-4A35-8266-0D10A6A4DF27}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe|Name=Search-Results Toolbar DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F8BD6963-EDBD-44DD-A5DA-038F96222E8A}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe|Name=Search-Results Toolbar DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0028FE51-2BFF-4A35-8266-0D10A6A4DF27}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe|Name=Search-Results Toolbar DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F8BD6963-EDBD-44DD-A5DA-038F96222E8A}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe|Name=Search-Results Toolbar DTX Broker|" Searching for "lyrixeeker" [HKEY_CURRENT_USER\Software\AppDataLow\Software\LyriXeeker] [HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions] "lyrix@lyrixeeker.co"="C:\Program Files (x86)\LyriXeeker\125.xpi" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\epojlgbehpaeekopencdagbdamnkppci] "Path"="C:\Program Files (x86)\LyriXeeker\125.crx" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\lyrix@lyrixeeker.co] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\lyrix@lyrixeeker.co] "Publisher"="LyriXeeker Tech" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\lyrix@lyrixeeker.co] "UninstallString"="C:\Program Files (x86)\LyriXeeker\uninstall.exe" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\AppDataLow\Software\LyriXeeker] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Mozilla\Firefox\Extensions] "lyrix@lyrixeeker.co"="C:\Program Files (x86)\LyriXeeker\125.xpi" Searching for "mypc backup" No data found. Searching for "speedupmypc" No data found. Searching for "sweetim" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3199093499-978631591-3148159529-1001\Software\SweetIM] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Sweetpacks Communicator] "command"="C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\02F47BF73B948514FAACADD8CBBDF37D] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\080D9F5E1E95FEE4794CE438E635239E] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgxml_wrapper.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\12BF94BD06C95F343A77631402B9556A] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1E264E0A5959A1C46BA9175A878B12EA] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgconfig.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2124D8A8CF720FD44866190AF560228E] "254796BF4AC84B64891B61C529A2E23F"="C:\ProgramData\SweetIM\Communicator\conf\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\27A325ACED8CA4743A30127638591ADB] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\mgsimcommon.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E6768B6932D112438F047C54D180635] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\ClearHist.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\350D17402BD84234EAF7D32F08172D7C] "254796BF4AC84B64891B61C529A2E23F"="C:\ProgramData\SweetIM\Communicator\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\351716A953E21214898904032EAE2E81] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\397C771A7BCAC904697C3EC629ED33ED] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgHelper.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3EE8C5F419057E1478A654868CEE60B5] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4735D908D66E1BA46B6C2D7185A12B2B] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\resources\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\69D6A6B2ED56AF24EA6335EAD6E91CA4] "16FE85B52F587794795A481CF9295697"="C?\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgHelperApp.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\76D8378E2DDAED3428720A631F6E3BF0] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\resources\sqlite\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7FFA128C2B0FF414D805FC5627883401] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mghooking.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86EDC790504E1834DBC20C9A04328FD2] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\green\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97C3D0F82E712E241A2F969F45E3351C] "16FE85B52F587794795A481CF9295697"="C?\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarProxy.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\98CC8BF5A4A6E6C4ABF7051DDAB8B058] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9A001B259DB7D694E818BE29B973992C] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9E7F556BF224D804D96A96F0F6344789] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\blue\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A189D17A469616C4688D23E192996267] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mglogger.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BAE2EC163C6A68A48921573E0E7E199D] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\mgcommunication.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BF4F885EDEE45644EB1E0C99E0162399] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\Microsoft.VC90.CRT\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C06C6662FA5B04646829E4A460857770] "254796BF4AC84B64891B61C529A2E23F"="C:\ProgramData\SweetIM\Communicator\Logs\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CE21F3FD57B244142880EF15A165A156] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\orange\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CEEB3E14ABE8270419B0FD762E18F7C6] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\mgcommon.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D15DAF33C220F91468A1D7D57C31ACD7] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\conf\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D3BA76A44C779424889063D5098ED2D6] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgcommon.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D6D0EB9FDBD90C04D92A7E729058F10D] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E4748F9A4181FCE46A23C13B517B9420] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgsimcommon.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ED1B5E9A3BDB51349BF96E842C062D98] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\Microsoft.VC90.CRT\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FECBC2BC14DA6CD459BD59A041709836] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\mgxml_wrapper.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\16FE85B52F587794795A481CF9295697\InstallProperties] "Contact"="SweetIM Technical Support Department" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\16FE85B52F587794795A481CF9295697\InstallProperties] "HelpLink"="hxxp://www.sweetim.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\16FE85B52F587794795A481CF9295697\InstallProperties] "InstallLocation"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\16FE85B52F587794795A481CF9295697\InstallProperties] "Publisher"="SweetIM Technologies Ltd." [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\16FE85B52F587794795A481CF9295697\InstallProperties] "URLInfoAbout"="hxxp://www.sweetim.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\16FE85B52F587794795A481CF9295697\InstallProperties] "URLUpdateInfo"="hxxp://www.sweetim.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\254796BF4AC84B64891B61C529A2E23F\InstallProperties] "Contact"="SweetIM Technical Support Department" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\254796BF4AC84B64891B61C529A2E23F\InstallProperties] "HelpLink"="hxxp://www.sweetim.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\254796BF4AC84B64891B61C529A2E23F\InstallProperties] "InstallLocation"="C:\Program Files (x86)\SweetIM\Communicator\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\254796BF4AC84B64891B61C529A2E23F\InstallProperties] "Publisher"="SweetIM Technologies Ltd." [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\254796BF4AC84B64891B61C529A2E23F\InstallProperties] "URLInfoAbout"="hxxp://www.sweetim.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\254796BF4AC84B64891B61C529A2E23F\InstallProperties] "URLUpdateInfo"="hxxp://www.sweetim.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\toolbar_vit_sweetim_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\toolbar_vit_sweetim_RASMANCS] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{A21972B4-5118-42E3-B07B-3ABF8F630877}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe|Name=SweetPacksUpdateManager|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F0F839E5-89DE-4467-9E52-606055705D06}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe|Name=SweetPacksUpdateManager|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{A21972B4-5118-42E3-B07B-3ABF8F630877}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe|Name=SweetPacksUpdateManager|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F0F839E5-89DE-4467-9E52-606055705D06}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe|Name=SweetPacksUpdateManager|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{A21972B4-5118-42E3-B07B-3ABF8F630877}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe|Name=SweetPacksUpdateManager|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F0F839E5-89DE-4467-9E52-606055705D06}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe|Name=SweetPacksUpdateManager|" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3199093499-978631591-3148159529-1001\Software\SweetIM] Searching for "distromatic" No data found. Searching for "BabSolution" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\fagpjgjmoaccgkkpjeoinehnoaimnbla] "path"="C:\Users\PC\AppData\Roaming\BabSolution\CR\hola.crx" Searching for "bProtector" No data found. Searching for "BrowserDefender" [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\ProgramData\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe"="Application Manager" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{2A0F3D1B-0909-4FF4-B272-609CCE6054E7}] "DllName"="PCTBrowserDefender.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{472734EA-242A-422B-ADF8-83D1E48CC825}] "DllName"="PCTBrowserDefender.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{424202EF-76FA-4231-BF7A-5153EB49F987}] "Path"="\BrowserDefendert" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BrowserDefendert] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{2A0F3D1B-0909-4FF4-B272-609CCE6054E7}] "DllName"="PCTBrowserDefender.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{472734EA-242A-422B-ADF8-83D1E48CC825}] "DllName"="PCTBrowserDefender.dll" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\ProgramData\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe"="Application Manager" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\ProgramData\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe"="Application Manager" Searching for "iLivid" [HKEY_CURRENT_USER\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\C:\Users\PC\AppData\Local\iLivid] [HKEY_CURRENT_USER\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.8.false\C:\Users\PC\AppData\Local\iLivid] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\C:\Users\PC\AppData\Local\iLivid] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.8.false\C:\Users\PC\AppData\Local\iLivid] Searching for "holasearch" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "hp_url"="hxxp://www.holasearch.com/?babsrc=HP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "nt_url"="hxxp://www.holasearch.com/?babsrc=NT_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "dsFFX"="holasearch" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "uninstaller"="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\uninstall.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "sp_url"="hxxp://www.holasearch.com/?q={searchTerms}&babsrc=SP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "tb_url"="hxxp://www.holasearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "kw_url"="hxxp://www.holasearch.com/?babsrc=SP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927&q=" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\esrv.holasearchESrvc] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\esrv.holasearchESrvc\CurVer] @="esrv.holasearchESrvc.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\esrv.holasearchESrvc.1] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchappCore] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchappCore\CurVer] @="holasearch.holasearchappCore.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchappCore.1] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchdskBnd] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchdskBnd\CurVer] @="holasearch.holasearchdskBnd.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchdskBnd.1] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchHlpr] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchHlpr\CurVer] @="holasearch.holasearchHlpr.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchHlpr.1] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}\1.0\0\win32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchsrv.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}\1.0\HELPDIR] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0] @="holasearchCmn 1.0 Type Library" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0\0\win32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchEng.dll\2" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0\HELPDIR] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1E44819B-54E1-411B-9D9F-38D7B913BCF2}\InprocServer32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchEng.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}\LocalServer32] @=""C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchsrv.exe"" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}\ProgID] @="esrv.holasearchESrvc.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}\VersionIndependentProgID] @="esrv.holasearchESrvc" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}\InprocServer32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchApp.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}\ProgID] @="holasearch.holasearchappCore.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}\VersionIndependentProgID] @="holasearch.holasearchappCore" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C46EFEA4-B0F3-428B-9E77-650E3634EC56}\InprocServer32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\bh\holasearch.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "hp_url"="hxxp://www.holasearch.com/?babsrc=HP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "nt_url"="hxxp://www.holasearch.com/?babsrc=NT_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "dsFFX"="holasearch" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "uninstaller"="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\uninstall.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "sp_url"="hxxp://www.holasearch.com/?q={searchTerms}&babsrc=SP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "tb_url"="hxxp://www.holasearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "kw_url"="hxxp://www.holasearch.com/?babsrc=SP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927&q=" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}\1.0\0\win32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchsrv.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}\1.0\HELPDIR] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0] @="holasearchCmn 1.0 Type Library" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0\0\win32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchEng.dll\2" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0\HELPDIR] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5882DB3D-175D-4CDC-A030-1B7EC2BC8EC6}] "AppName"="holasearchsrv.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5882DB3D-175D-4CDC-A030-1B7EC2BC8EC6}] "AppPath"="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{1E44819B-54E1-411B-9D9F-38D7B913BCF2}\InprocServer32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchEng.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}\LocalServer32] @=""C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchsrv.exe"" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}\ProgID] @="esrv.holasearchESrvc.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}\VersionIndependentProgID] @="esrv.holasearchESrvc" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}\InprocServer32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchApp.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}\ProgID] @="holasearch.holasearchappCore.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}\VersionIndependentProgID] @="holasearch.holasearchappCore" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{C46EFEA4-B0F3-428B-9E77-650E3634EC56}\InprocServer32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\bh\holasearch.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "hp_url"="hxxp://www.holasearch.com/?babsrc=HP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "nt_url"="hxxp://www.holasearch.com/?babsrc=NT_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "dsFFX"="holasearch" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "uninstaller"="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\uninstall.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "sp_url"="hxxp://www.holasearch.com/?q={searchTerms}&babsrc=SP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "tb_url"="hxxp://www.holasearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "kw_url"="hxxp://www.holasearch.com/?babsrc=SP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927&q=" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}\1.0\0\win32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchsrv.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}\1.0\HELPDIR] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0] @="holasearchCmn 1.0 Type Library" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0\0\win32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchEng.dll\2" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0\HELPDIR] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" Searching for "DealPly" [HKEY_CURRENT_USER\Software\Wow6432Node\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje] "path"="C:\Program Files (x86)\DealPly\DealPly.crx" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{296BED8D-8F7A-40EE-AFDD-642839AC7E7F}] "Path"="\DealPlyUpdate" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AC019BF5-2EB9-4103-AEE1-09CD370F4CBB}] "Path"="\DealPly" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPly] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPlyUpdate] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Wow6432Node\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje] "path"="C:\Program Files (x86)\DealPly\DealPly.crx" Searching for "Babylon" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{2EECD738-5844-4A99-B4B6-146BF802613B}] "DllName"="BabylonToolbar.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}] "DllName"="BabylonToolbar.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{98889811-442D-49DD-99D7-DC866BE87DBC}] "DllName"="BabylonToolbarTlbr.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{2EECD738-5844-4A99-B4B6-146BF802613B}] "DllName"="BabylonToolbar.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}] "DllName"="BabylonToolbar.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{98889811-442D-49DD-99D7-DC866BE87DBC}] "DllName"="BabylonToolbarTlbr.dll" Searching for "Softonic" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\1e40ca8e_0] @="{0.0.0.00000000}.{f8047516-971f-40ba-85de-843482a8264a}|\Device\HarddiskVolume2\Users\PC\Downloads\SoftonicDownloader_fuer_mp3directcut.exe%b{00000000-0000-0000-0000-000000000000}" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\29629339_0] @="{0.0.0.00000000}.{f8047516-971f-40ba-85de-843482a8264a}|\Device\HarddiskVolume2\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe%b{00000000-0000-0000-0000-000000000000}" [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe"="Softonic Downloader " [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_mp3directcut_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_mp3directcut_RASMANCS] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_trustport-internet-security_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_trustport-internet-security_RASMANCS] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\1e40ca8e_0] @="{0.0.0.00000000}.{f8047516-971f-40ba-85de-843482a8264a}|\Device\HarddiskVolume2\Users\PC\Downloads\SoftonicDownloader_fuer_mp3directcut.exe%b{00000000-0000-0000-0000-000000000000}" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\29629339_0] @="{0.0.0.00000000}.{f8047516-971f-40ba-85de-843482a8264a}|\Device\HarddiskVolume2\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe%b{00000000-0000-0000-0000-000000000000}" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe"="Softonic Downloader " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe"="Softonic Downloader " Searching for "delta LTD" No data found. Searching for "PriceGong" [HKEY_CURRENT_USER\Software\PowerPack\225\13] "c"="hxxp://www.powerpackdl.com/downloads/pricegong.exe" [HKEY_CURRENT_USER\Software\PowerPack\225\13] "i"="hxxp://www.pricegong.com/TermsofUse.aspx" [HKEY_CURRENT_USER\Software\PowerPack\225\13] "j"="PriceGong" [HKEY_CURRENT_USER\Software\PowerPack\225\13] "n"="rv:HKCR,AppID\\PriceGongIE.DLL,AppID,{835315FC-1BF6-4CA9-80CD-F6C158D40692}" [HKEY_CURRENT_USER\Software\PowerPack\225\13] "x"="hxxp://www.pricegong.com/favicon.ico" [HKEY_CURRENT_USER\Software\PowerPack\225\13] "y"="hxxp://www.pricegong.com/" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\PriceGong_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\PriceGong_RASMANCS] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\PowerPack\225\13] "c"="hxxp://www.powerpackdl.com/downloads/pricegong.exe" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\PowerPack\225\13] "i"="hxxp://www.pricegong.com/TermsofUse.aspx" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\PowerPack\225\13] "j"="PriceGong" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\PowerPack\225\13] "n"="rv:HKCR,AppID\\PriceGongIE.DLL,AppID,{835315FC-1BF6-4CA9-80CD-F6C158D40692}" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\PowerPack\225\13] "x"="hxxp://www.pricegong.com/favicon.ico" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\PowerPack\225\13] "y"="hxxp://www.pricegong.com/" Searching for "OpenCandy" No data found. Searching for "PerformerSoft" No data found. Searching for "SoftSafe" No data found. Searching for "IBUpdater" No data found. Searching for " " [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\PhotoPrintingWizard\Laser Pro LL2] "PrintTicket"="<?xml version="1.0"?> <psf:PrintTicket version="1" xmlns:xsd="hxxp://www.w3.org/2001/XMLSchema" xmlns:xsi="hxxp://www.w3.org/2001/XMLSchema-instance" xmlns:psf="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemaframework" xmlns:psk="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemakeywords" xmlns:mti="hxxp://schemas.monotypeimaging.com/ptpc/2006/1" xmlns:oem="hxxp://schemas.monotypeimaging.com/ptpc/oem/2006/1"><psf:Feature name="psk:PageOrientation"><psf:Option name="psk:Landscape"/></psf:Feature><!-- --><!-- Monotype Imaging print ticket --><!-- --><!-- --><!-- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\PhotoPrintingWizard\Laser Pro LL2] "PrintCapabilites"="<?xml version="1.0"?> <psf:PrintCapabilities version="1" xmlns:xsd="hxxp://www.w3.org/2001/XMLSchema" xmlns:xsi="hxxp://www.w3.org/2001/XMLSchema-instance" xmlns:psf="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemaframework" xmlns:psk="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemakeywords" xmlns:mti="hxxp://schemas.monotypeimaging.com/ptpc/2006/1" xmlns:oem="hxxp://schemas.monotypeimaging.com/ptpc/oem/2006/1"><!-- --><!-- Monotype Imaging print capabilities --><!-- --><!-- --><!-- JobComment --><!-- [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "G:\Menu.exe"="CnMemory Software " [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe"="Softonic Downloader " [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Desktop\TrustPort_Internet_Security_12.0.0.4788.exe"="TrustPort Internet Security " [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WSMAN\Plugin\Microsoft.PowerShell] "ConfigXML"=" <PlugInConfiguration xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Name="microsoft.powershell" Filename="%windir%\system32\pwrshplugin.dll" SDKVersion="1" XmlRenderingType="text" > <InitializationParameters> <Param Name="PSVersion" Value="2.0"/> </InitializationParameters> <Resources> <Resource ResourceUri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell" SupportsOptions="true" ExactMatch="true"> <Security xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Uri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell" ExactMatch="true" Sddl="O:NSG:BAD:P(A;;GA;;;BA)S:P(AU;FA;GA;;;WD)(AU;SA;GXGW;;;WD)"/> <Capability Type="Shell"/> </Resource> </Res [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\WSMAN\Plugin\Microsoft.PowerShell32] "ConfigXML"="<PlugInConfiguration xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Name="microsoft.powershell32" Filename="%windir%\system32\pwrshplugin.dll" SDKVersion="1" XmlRenderingType="text" Architecture="32" > <InitializationParameters> <Param Name="PSVersion" Value="2.0"/> </InitializationParameters> <Resources> <Resource ResourceUri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell32" SupportsOptions="true" ExactMatch="true"> <Security xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Uri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell32" ExactMatch="true" Sddl="O:NSG:BAD:P(A;;GA;;;BA)S:P(AU;FA;GA;;;WD)(AU;SA;GXGW;;;WD)"/> [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&10D4990&0&__ ______&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&10D4990&0&__ ______&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&11AC6715&0&_ _______&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&11AC6715&0&_ _______&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&2706475&0&__ ______&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&2706475&0&__ ______&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&10D4990&0&__ ______&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&10D4990&0&__ ______&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&11AC6715&0&_ _______&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&11AC6715&0&_ _______&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&2706475&0&__ ______&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&2706475&0&__ ______&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&10D4990& 0&________&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&10D4990& 0&________&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&11AC6715 &0&________&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&11AC6715 &0&________&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&2706475& 0&________&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&2706475& 0&________&1#] "DeviceDesc"="NERO " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\PhotoPrintingWizard\Laser Pro LL2] "PrintTicket"="<?xml version="1.0"?> <psf:PrintTicket version="1" xmlns:xsd="hxxp://www.w3.org/2001/XMLSchema" xmlns:xsi="hxxp://www.w3.org/2001/XMLSchema-instance" xmlns:psf="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemaframework" xmlns:psk="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemakeywords" xmlns:mti="hxxp://schemas.monotypeimaging.com/ptpc/2006/1" xmlns:oem="hxxp://schemas.monotypeimaging.com/ptpc/oem/2006/1"><psf:Feature name="psk:PageOrientation"><psf:Option name="psk:Landscape"/></psf:Feature><!-- --><!-- Monotype Imaging print ticket --><!-- --><!-- --><!-- [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\PhotoPrintingWizard\Laser Pro LL2] "PrintCapabilites"="<?xml version="1.0"?> <psf:PrintCapabilities version="1" xmlns:xsd="hxxp://www.w3.org/2001/XMLSchema" xmlns:xsi="hxxp://www.w3.org/2001/XMLSchema-instance" xmlns:psf="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemaframework" xmlns:psk="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemakeywords" xmlns:mti="hxxp://schemas.monotypeimaging.com/ptpc/2006/1" xmlns:oem="hxxp://schemas.monotypeimaging.com/ptpc/oem/2006/1"><!-- --><!-- Monotype Imaging print capabilities --><!-- --><!-- --><!-- JobComment --><!-- [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "G:\Menu.exe"="CnMemory Software " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe"="Softonic Downloader " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Desktop\TrustPort_Internet_Security_12.0.0.4788.exe"="TrustPort Internet Security " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "G:\Menu.exe"="CnMemory Software " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe"="Softonic Downloader " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Desktop\TrustPort_Internet_Security_12.0.0.4788.exe"="TrustPort Internet Security " -= EOF =- |
LSystemLook 30.07.11 by jpshortstuff Log created at 22:24 on 05/08/2013 by PC Administrator - Elevation successful ========== filefind ========== Searching for "*systweak*" No files found. Searching for "*adawarebp*" C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.dll --a---- 318872 bytes [23:20 11/12/2012] [23:20 11/12/2012] C55D73BF01BEB9C25516FA519174CC9C C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe --a---- 542104 bytes [23:20 11/12/2012] [23:20 11/12/2012] DF7AEEC25E5C006EEC61206476F48629 C:\Users\All Users\Ad-Aware Browsing Protection\adawarebp.dll --a---- 318872 bytes [23:20 11/12/2012] [23:20 11/12/2012] C55D73BF01BEB9C25516FA519174CC9C C:\Users\All Users\Ad-Aware Browsing Protection\adawarebp.exe --a---- 542104 bytes [23:20 11/12/2012] [23:20 11/12/2012] DF7AEEC25E5C006EEC61206476F48629 Searching for "*datamngr*" No files found. Searching for "*lyrixeeker*" No files found. Searching for "*mypc backup*" No files found. Searching for "*speedupmypc*" No files found. Searching for "*sweetim*" No files found. Searching for "*distromatic*" No files found. Searching for "*BabSolution*" No files found. Searching for "*bProtector*" No files found. Searching for "*BrowserDefender*" C:\Windows\Prefetch\BROWSERDEFENDER.EXE-62524200.pf --a---- 30700 bytes [00:24 05/08/2013] [14:50 05/08/2013] A660DF35F2F003AAABD99C1581C9AF85 C:\Windows\System32\Tasks\BrowserDefendert --a---- 3436 bytes [14:50 05/08/2013] [14:50 05/08/2013] 8444D519E7504D38BE49BC3FAE167689 Searching for "*iLivid*" C:\Users\PC\Downloads\iLividSetupV1.exe --a---- 1302424 bytes [18:57 27/11/2012] [18:57 27/11/2012] A572625DB335FCCA490C909C373FB81C Searching for "*holasearch*" No files found. Searching for "*DealPly*" C:\Windows\System32\Tasks\DealPly --a---- 3482 bytes [08:07 07/02/2013] [18:11 16/03/2013] FD52B70225C0B2F3FCE040C2C359D1A8 C:\Windows\System32\Tasks\DealPlyUpdate --a---- 3304 bytes [18:11 25/11/2012] [18:11 25/11/2012] 3F89962238E95558E6CF05D47AE0D32B Searching for "*Babylon*" C:\Users\PC\AppData\Local\Temp\8DD1A082-BAB0-7891-8C74-BC4EED533129\Latest\Babylon.dat --a---- 12384 bytes [14:49 05/08/2013] [12:17 19/02/2013] 825E5733974586A0A1229A53361ED13E Searching for "*Softonic*" No files found. Searching for "*delta LTD*" No files found. Searching for "*PriceGong*" No files found. Searching for "*OpenCandy*" No files found. Searching for "*PerformerSoft*" No files found. Searching for "*SoftSafe*" C:\Program Files\Common Files\Bitdefender\SetupInformation\downloader\extern\kingsoftSafeguard.xml --a---- 618 bytes [10:56 09/02/2013] [14:28 24/04/2012] E7BE97006F2213266A33D726FDBBE913 C:\Program Files\Common Files\Bitdefender\SetupInformation\downloader\extern\kingsoftSafeguard.xml.md5 --a---- 32 bytes [10:56 09/02/2013] [17:44 29/06/2012] D885CA3A040A7350B1CB313C9DC264ED Searching for "*IBUpdater*" No files found. ========== folderfind ========== Searching for "*systweak*" No folders found. Searching for "*adawarebp*" No folders found. Searching for "*datamngr*" No folders found. Searching for "*lyrixeeker*" C:\Program Files (x86)\LyriXeeker d------ [14:49 05/08/2013] Searching for "*mypc backup*" No folders found. Searching for "*speedupmypc*" No folders found. Searching for "*sweetim*" No folders found. Searching for "*distromatic*" No folders found. Searching for "*BabSolution*" No folders found. Searching for "*bProtector*" No folders found. Searching for "*BrowserDefender*" No folders found. Searching for "*iLivid*" No folders found. Searching for "*holasearch*" No folders found. Searching for "*DealPly*" C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\NS6RQ2XF\static.dealply.com d------ [22:51 12/02/2013] C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\NS6RQ2XF\macromedia.com\support\flashplayer\sys\#static.dealply.com d------ [22:51 12/02/2013] C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\NS6RQ2XF\static.dealply.com\flash\dealply_swf_engine.swf d------ [22:51 12/02/2013] Searching for "*Babylon*" No folders found. Searching for "*Softonic*" No folders found. Searching for "*delta LTD*" No folders found. Searching for "*PriceGong*" No folders found. Searching for "*OpenCandy*" No folders found. Searching for "*PerformerSoft*" No folders found. Searching for "*SoftSafe*" No folders found. Searching for "*IBUpdater*" No folders found. ========== regfind ========== Searching for "systweak" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\systweakasp_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\systweakasp_RASMANCS] Searching for "adawarebp" [HKEY_CURRENT_USER\Software\AppDataLow\Software\adawarebp] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Ad-Aware Browsing Protection] "command"=""C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe"" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\adawarebp_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\adawarebp_RASDLG] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\adawarebp_RASMANCS] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\AppDataLow\Software\adawarebp] Searching for "datamngr" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DATAMNGR] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DATAMNGR] "item"="DATAMNGR" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DATAMNGR] "command"="C:\PROGRA~2\SEARCH~1\Datamngr\DATAMN~1.EXE" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4E704E34-0FD7-4216-8B49-E4A8C853DB34}] "AppPath"="C:\PROGRA~2\SEARCH~1\Datamngr\SRTOOL~1" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0028FE51-2BFF-4A35-8266-0D10A6A4DF27}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe|Name=Search-Results Toolbar DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F8BD6963-EDBD-44DD-A5DA-038F96222E8A}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe|Name=Search-Results Toolbar DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0028FE51-2BFF-4A35-8266-0D10A6A4DF27}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe|Name=Search-Results Toolbar DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F8BD6963-EDBD-44DD-A5DA-038F96222E8A}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe|Name=Search-Results Toolbar DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0028FE51-2BFF-4A35-8266-0D10A6A4DF27}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe|Name=Search-Results Toolbar DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F8BD6963-EDBD-44DD-A5DA-038F96222E8A}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe|Name=Search-Results Toolbar DTX Broker|" Searching for "lyrixeeker" [HKEY_CURRENT_USER\Software\AppDataLow\Software\LyriXeeker] [HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions] "lyrix@lyrixeeker.co"="C:\Program Files (x86)\LyriXeeker\125.xpi" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\epojlgbehpaeekopencdagbdamnkppci] "Path"="C:\Program Files (x86)\LyriXeeker\125.crx" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\lyrix@lyrixeeker.co] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\lyrix@lyrixeeker.co] "Publisher"="LyriXeeker Tech" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\lyrix@lyrixeeker.co] "UninstallString"="C:\Program Files (x86)\LyriXeeker\uninstall.exe" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\AppDataLow\Software\LyriXeeker] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Mozilla\Firefox\Extensions] "lyrix@lyrixeeker.co"="C:\Program Files (x86)\LyriXeeker\125.xpi" Searching for "mypc backup" No data found. Searching for "speedupmypc" No data found. Searching for "sweetim" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3199093499-978631591-3148159529-1001\Software\SweetIM] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Sweetpacks Communicator] "command"="C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\02F47BF73B948514FAACADD8CBBDF37D] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\080D9F5E1E95FEE4794CE438E635239E] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgxml_wrapper.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\12BF94BD06C95F343A77631402B9556A] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1E264E0A5959A1C46BA9175A878B12EA] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgconfig.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2124D8A8CF720FD44866190AF560228E] "254796BF4AC84B64891B61C529A2E23F"="C:\ProgramData\SweetIM\Communicator\conf\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\27A325ACED8CA4743A30127638591ADB] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\mgsimcommon.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E6768B6932D112438F047C54D180635] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\ClearHist.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\350D17402BD84234EAF7D32F08172D7C] "254796BF4AC84B64891B61C529A2E23F"="C:\ProgramData\SweetIM\Communicator\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\351716A953E21214898904032EAE2E81] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\397C771A7BCAC904697C3EC629ED33ED] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgHelper.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3EE8C5F419057E1478A654868CEE60B5] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4735D908D66E1BA46B6C2D7185A12B2B] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\resources\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\69D6A6B2ED56AF24EA6335EAD6E91CA4] "16FE85B52F587794795A481CF9295697"="C?\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgHelperApp.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\76D8378E2DDAED3428720A631F6E3BF0] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\resources\sqlite\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7FFA128C2B0FF414D805FC5627883401] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mghooking.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86EDC790504E1834DBC20C9A04328FD2] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\green\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97C3D0F82E712E241A2F969F45E3351C] "16FE85B52F587794795A481CF9295697"="C?\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarProxy.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\98CC8BF5A4A6E6C4ABF7051DDAB8B058] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9A001B259DB7D694E818BE29B973992C] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9E7F556BF224D804D96A96F0F6344789] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\blue\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A189D17A469616C4688D23E192996267] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mglogger.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BAE2EC163C6A68A48921573E0E7E199D] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\mgcommunication.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BF4F885EDEE45644EB1E0C99E0162399] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\Microsoft.VC90.CRT\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C06C6662FA5B04646829E4A460857770] "254796BF4AC84B64891B61C529A2E23F"="C:\ProgramData\SweetIM\Communicator\Logs\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CE21F3FD57B244142880EF15A165A156] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\orange\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CEEB3E14ABE8270419B0FD762E18F7C6] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\mgcommon.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D15DAF33C220F91468A1D7D57C31ACD7] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\conf\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D3BA76A44C779424889063D5098ED2D6] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgcommon.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D6D0EB9FDBD90C04D92A7E729058F10D] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E4748F9A4181FCE46A23C13B517B9420] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgsimcommon.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ED1B5E9A3BDB51349BF96E842C062D98] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\Microsoft.VC90.CRT\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FECBC2BC14DA6CD459BD59A041709836] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\mgxml_wrapper.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\16FE85B52F587794795A481CF9295697\InstallProperties] "Contact"="SweetIM Technical Support Department" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\16FE85B52F587794795A481CF9295697\InstallProperties] "HelpLink"="hxxp://www.sweetim.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\16FE85B52F587794795A481CF9295697\InstallProperties] "InstallLocation"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\16FE85B52F587794795A481CF9295697\InstallProperties] "Publisher"="SweetIM Technologies Ltd." [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\16FE85B52F587794795A481CF9295697\InstallProperties] "URLInfoAbout"="hxxp://www.sweetim.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\16FE85B52F587794795A481CF9295697\InstallProperties] "URLUpdateInfo"="hxxp://www.sweetim.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\254796BF4AC84B64891B61C529A2E23F\InstallProperties] "Contact"="SweetIM Technical Support Department" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\254796BF4AC84B64891B61C529A2E23F\InstallProperties] "HelpLink"="hxxp://www.sweetim.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\254796BF4AC84B64891B61C529A2E23F\InstallProperties] "InstallLocation"="C:\Program Files (x86)\SweetIM\Communicator\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\254796BF4AC84B64891B61C529A2E23F\InstallProperties] "Publisher"="SweetIM Technologies Ltd." [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\254796BF4AC84B64891B61C529A2E23F\InstallProperties] "URLInfoAbout"="hxxp://www.sweetim.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\254796BF4AC84B64891B61C529A2E23F\InstallProperties] "URLUpdateInfo"="hxxp://www.sweetim.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\toolbar_vit_sweetim_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\toolbar_vit_sweetim_RASMANCS] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{A21972B4-5118-42E3-B07B-3ABF8F630877}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe|Name=SweetPacksUpdateManager|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F0F839E5-89DE-4467-9E52-606055705D06}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe|Name=SweetPacksUpdateManager|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{A21972B4-5118-42E3-B07B-3ABF8F630877}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe|Name=SweetPacksUpdateManager|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F0F839E5-89DE-4467-9E52-606055705D06}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe|Name=SweetPacksUpdateManager|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{A21972B4-5118-42E3-B07B-3ABF8F630877}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe|Name=SweetPacksUpdateManager|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F0F839E5-89DE-4467-9E52-606055705D06}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe|Name=SweetPacksUpdateManager|" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3199093499-978631591-3148159529-1001\Software\SweetIM] Searching for "distromatic" No data found. Searching for "BabSolution" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\fagpjgjmoaccgkkpjeoinehnoaimnbla] "path"="C:\Users\PC\AppData\Roaming\BabSolution\CR\hola.crx" Searching for "bProtector" No data found. Searching for "BrowserDefender" [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\ProgramData\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe"="Application Manager" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{2A0F3D1B-0909-4FF4-B272-609CCE6054E7}] "DllName"="PCTBrowserDefender.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{472734EA-242A-422B-ADF8-83D1E48CC825}] "DllName"="PCTBrowserDefender.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{424202EF-76FA-4231-BF7A-5153EB49F987}] "Path"="\BrowserDefendert" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BrowserDefendert] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{2A0F3D1B-0909-4FF4-B272-609CCE6054E7}] "DllName"="PCTBrowserDefender.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{472734EA-242A-422B-ADF8-83D1E48CC825}] "DllName"="PCTBrowserDefender.dll" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\ProgramData\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe"="Application Manager" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\ProgramData\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe"="Application Manager" Searching for "iLivid" [HKEY_CURRENT_USER\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\C:\Users\PC\AppData\Local\iLivid] [HKEY_CURRENT_USER\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.8.false\C:\Users\PC\AppData\Local\iLivid] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\C:\Users\PC\AppData\Local\iLivid] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.8.false\C:\Users\PC\AppData\Local\iLivid] Searching for "holasearch" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "hp_url"="hxxp://www.holasearch.com/?babsrc=HP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "nt_url"="hxxp://www.holasearch.com/?babsrc=NT_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "dsFFX"="holasearch" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "uninstaller"="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\uninstall.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "sp_url"="hxxp://www.holasearch.com/?q={searchTerms}&babsrc=SP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "tb_url"="hxxp://www.holasearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "kw_url"="hxxp://www.holasearch.com/?babsrc=SP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927&q=" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\esrv.holasearchESrvc] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\esrv.holasearchESrvc\CurVer] @="esrv.holasearchESrvc.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\esrv.holasearchESrvc.1] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchappCore] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchappCore\CurVer] @="holasearch.holasearchappCore.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchappCore.1] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchdskBnd] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchdskBnd\CurVer] @="holasearch.holasearchdskBnd.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchdskBnd.1] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchHlpr] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchHlpr\CurVer] @="holasearch.holasearchHlpr.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchHlpr.1] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}\1.0\0\win32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchsrv.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}\1.0\HELPDIR] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0] @="holasearchCmn 1.0 Type Library" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0\0\win32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchEng.dll\2" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0\HELPDIR] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1E44819B-54E1-411B-9D9F-38D7B913BCF2}\InprocServer32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchEng.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}\LocalServer32] @=""C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchsrv.exe"" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}\ProgID] @="esrv.holasearchESrvc.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}\VersionIndependentProgID] @="esrv.holasearchESrvc" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}\InprocServer32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchApp.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}\ProgID] @="holasearch.holasearchappCore.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}\VersionIndependentProgID] @="holasearch.holasearchappCore" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C46EFEA4-B0F3-428B-9E77-650E3634EC56}\InprocServer32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\bh\holasearch.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "hp_url"="hxxp://www.holasearch.com/?babsrc=HP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "nt_url"="hxxp://www.holasearch.com/?babsrc=NT_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "dsFFX"="holasearch" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "uninstaller"="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\uninstall.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "sp_url"="hxxp://www.holasearch.com/?q={searchTerms}&babsrc=SP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "tb_url"="hxxp://www.holasearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "kw_url"="hxxp://www.holasearch.com/?babsrc=SP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927&q=" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}\1.0\0\win32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchsrv.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}\1.0\HELPDIR] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0] @="holasearchCmn 1.0 Type Library" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0\0\win32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchEng.dll\2" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0\HELPDIR] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5882DB3D-175D-4CDC-A030-1B7EC2BC8EC6}] "AppName"="holasearchsrv.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5882DB3D-175D-4CDC-A030-1B7EC2BC8EC6}] "AppPath"="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{1E44819B-54E1-411B-9D9F-38D7B913BCF2}\InprocServer32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchEng.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}\LocalServer32] @=""C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchsrv.exe"" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}\ProgID] @="esrv.holasearchESrvc.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}\VersionIndependentProgID] @="esrv.holasearchESrvc" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}\InprocServer32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchApp.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}\ProgID] @="holasearch.holasearchappCore.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}\VersionIndependentProgID] @="holasearch.holasearchappCore" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{C46EFEA4-B0F3-428B-9E77-650E3634EC56}\InprocServer32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\bh\holasearch.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "hp_url"="hxxp://www.holasearch.com/?babsrc=HP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "nt_url"="hxxp://www.holasearch.com/?babsrc=NT_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "dsFFX"="holasearch" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "uninstaller"="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\uninstall.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "sp_url"="hxxp://www.holasearch.com/?q={searchTerms}&babsrc=SP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "tb_url"="hxxp://www.holasearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "kw_url"="hxxp://www.holasearch.com/?babsrc=SP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927&q=" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}\1.0\0\win32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchsrv.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}\1.0\HELPDIR] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0] @="holasearchCmn 1.0 Type Library" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0\0\win32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchEng.dll\2" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0\HELPDIR] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" Searching for "DealPly" [HKEY_CURRENT_USER\Software\Wow6432Node\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje] "path"="C:\Program Files (x86)\DealPly\DealPly.crx" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{296BED8D-8F7A-40EE-AFDD-642839AC7E7F}] "Path"="\DealPlyUpdate" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AC019BF5-2EB9-4103-AEE1-09CD370F4CBB}] "Path"="\DealPly" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPly] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPlyUpdate] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Wow6432Node\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje] "path"="C:\Program Files (x86)\DealPly\DealPly.crx" Searching for "Babylon" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{2EECD738-5844-4A99-B4B6-146BF802613B}] "DllName"="BabylonToolbar.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}] "DllName"="BabylonToolbar.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{98889811-442D-49DD-99D7-DC866BE87DBC}] "DllName"="BabylonToolbarTlbr.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{2EECD738-5844-4A99-B4B6-146BF802613B}] "DllName"="BabylonToolbar.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}] "DllName"="BabylonToolbar.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{98889811-442D-49DD-99D7-DC866BE87DBC}] "DllName"="BabylonToolbarTlbr.dll" Searching for "Softonic" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\1e40ca8e_0] @="{0.0.0.00000000}.{f8047516-971f-40ba-85de-843482a8264a}|\Device\HarddiskVolume2\Users\PC\Downloads\SoftonicDownloader_fuer_mp3directcut.exe%b{00000000-0000-0000-0000-000000000000}" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\29629339_0] @="{0.0.0.00000000}.{f8047516-971f-40ba-85de-843482a8264a}|\Device\HarddiskVolume2\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe%b{00000000-0000-0000-0000-000000000000}" [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe"="Softonic Downloader " [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_mp3directcut_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_mp3directcut_RASMANCS] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_trustport-internet-security_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_trustport-internet-security_RASMANCS] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\1e40ca8e_0] @="{0.0.0.00000000}.{f8047516-971f-40ba-85de-843482a8264a}|\Device\HarddiskVolume2\Users\PC\Downloads\SoftonicDownloader_fuer_mp3directcut.exe%b{00000000-0000-0000-0000-000000000000}" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\29629339_0] @="{0.0.0.00000000}.{f8047516-971f-40ba-85de-843482a8264a}|\Device\HarddiskVolume2\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe%b{00000000-0000-0000-0000-000000000000}" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe"="Softonic Downloader " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe"="Softonic Downloader " Searching for "delta LTD" No data found. Searching for "PriceGong" [HKEY_CURRENT_USER\Software\PowerPack\225\13] "c"="hxxp://www.powerpackdl.com/downloads/pricegong.exe" [HKEY_CURRENT_USER\Software\PowerPack\225\13] "i"="hxxp://www.pricegong.com/TermsofUse.aspx" [HKEY_CURRENT_USER\Software\PowerPack\225\13] "j"="PriceGong" [HKEY_CURRENT_USER\Software\PowerPack\225\13] "n"="rv:HKCR,AppID\\PriceGongIE.DLL,AppID,{835315FC-1BF6-4CA9-80CD-F6C158D40692}" [HKEY_CURRENT_USER\Software\PowerPack\225\13] "x"="hxxp://www.pricegong.com/favicon.ico" [HKEY_CURRENT_USER\Software\PowerPack\225\13] "y"="hxxp://www.pricegong.com/" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\PriceGong_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\PriceGong_RASMANCS] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\PowerPack\225\13] "c"="hxxp://www.powerpackdl.com/downloads/pricegong.exe" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\PowerPack\225\13] "i"="hxxp://www.pricegong.com/TermsofUse.aspx" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\PowerPack\225\13] "j"="PriceGong" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\PowerPack\225\13] "n"="rv:HKCR,AppID\\PriceGongIE.DLL,AppID,{835315FC-1BF6-4CA9-80CD-F6C158D40692}" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\PowerPack\225\13] "x"="hxxp://www.pricegong.com/favicon.ico" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\PowerPack\225\13] "y"="hxxp://www.pricegong.com/" Searching for "OpenCandy" No data found. Searching for "PerformerSoft" No data found. Searching for "SoftSafe" No data found. Searching for "IBUpdater" No data found. Searching for " " [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\PhotoPrintingWizard\Laser Pro LL2] "PrintTicket"="<?xml version="1.0"?> <psf:PrintTicket version="1" xmlns:xsd="hxxp://www.w3.org/2001/XMLSchema" xmlns:xsi="hxxp://www.w3.org/2001/XMLSchema-instance" xmlns:psf="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemaframework" xmlns:psk="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemakeywords" xmlns:mti="hxxp://schemas.monotypeimaging.com/ptpc/2006/1" xmlns:oem="hxxp://schemas.monotypeimaging.com/ptpc/oem/2006/1"><psf:Feature name="psk:PageOrientation"><psf:Option name="psk:Landscape"/></psf:Feature><!-- --><!-- Monotype Imaging print ticket --><!-- --><!-- --><!-- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\PhotoPrintingWizard\Laser Pro LL2] "PrintCapabilites"="<?xml version="1.0"?> <psf:PrintCapabilities version="1" xmlns:xsd="hxxp://www.w3.org/2001/XMLSchema" xmlns:xsi="hxxp://www.w3.org/2001/XMLSchema-instance" xmlns:psf="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemaframework" xmlns:psk="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemakeywords" xmlns:mti="hxxp://schemas.monotypeimaging.com/ptpc/2006/1" xmlns:oem="hxxp://schemas.monotypeimaging.com/ptpc/oem/2006/1"><!-- --><!-- Monotype Imaging print capabilities --><!-- --><!-- --><!-- JobComment --><!-- [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "G:\Menu.exe"="CnMemory Software " [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe"="Softonic Downloader " [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Desktop\TrustPort_Internet_Security_12.0.0.4788.exe"="TrustPort Internet Security " [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WSMAN\Plugin\Microsoft.PowerShell] "ConfigXML"=" <PlugInConfiguration xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Name="microsoft.powershell" Filename="%windir%\system32\pwrshplugin.dll" SDKVersion="1" XmlRenderingType="text" > <InitializationParameters> <Param Name="PSVersion" Value="2.0"/> </InitializationParameters> <Resources> <Resource ResourceUri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell" SupportsOptions="true" ExactMatch="true"> <Security xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Uri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell" ExactMatch="true" Sddl="O:NSG:BAD:P(A;;GA;;;BA)S:P(AU;FA;GA;;;WD)(AU;SA;GXGW;;;WD)"/> <Capability Type="Shell"/> </Resource> </Res [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\WSMAN\Plugin\Microsoft.PowerShell32] "ConfigXML"="<PlugInConfiguration xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Name="microsoft.powershell32" Filename="%windir%\system32\pwrshplugin.dll" SDKVersion="1" XmlRenderingType="text" Architecture="32" > <InitializationParameters> <Param Name="PSVersion" Value="2.0"/> </InitializationParameters> <Resources> <Resource ResourceUri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell32" SupportsOptions="true" ExactMatch="true"> <Security xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Uri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell32" ExactMatch="true" Sddl="O:NSG:BAD:P(A;;GA;;;BA)S:P(AU;FA;GA;;;WD)(AU;SA;GXGW;;;WD)"/> [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&10D4990&0&__ ______&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&10D4990&0&__ ______&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&11AC6715&0&_ _______&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&11AC6715&0&_ _______&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&2706475&0&__ ______&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&2706475&0&__ ______&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&10D4990&0&__ ______&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&10D4990&0&__ ______&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&11AC6715&0&_ _______&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&11AC6715&0&_ _______&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&2706475&0&__ ______&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&2706475&0&__ ______&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&10D4990& 0&________&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&10D4990& 0&________&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&11AC6715 &0&________&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&11AC6715 &0&________&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&2706475& 0&________&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&2706475& 0&________&1#] "DeviceDesc"="NERO " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\PhotoPrintingWizard\Laser Pro LL2] "PrintTicket"="<?xml version="1.0"?> <psf:PrintTicket version="1" xmlns:xsd="hxxp://www.w3.org/2001/XMLSchema" xmlns:xsi="hxxp://www.w3.org/2001/XMLSchema-instance" xmlns:psf="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemaframework" xmlns:psk="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemakeywords" xmlns:mti="hxxp://schemas.monotypeimaging.com/ptpc/2006/1" xmlns:oem="hxxp://schemas.monotypeimaging.com/ptpc/oem/2006/1"><psf:Feature name="psk:PageOrientation"><psf:Option name="psk:Landscape"/></psf:Feature><!-- --><!-- Monotype Imaging print ticket --><!-- --><!-- --><!-- [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\PhotoPrintingWizard\Laser Pro LL2] "PrintCapabilites"="<?xml version="1.0"?> <psf:PrintCapabilities version="1" xmlns:xsd="hxxp://www.w3.org/2001/XMLSchema" xmlns:xsi="hxxp://www.w3.org/2001/XMLSchema-instance" xmlns:psf="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemaframework" xmlns:psk="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemakeywords" xmlns:mti="hxxp://schemas.monotypeimaging.com/ptpc/2006/1" xmlns:oem="hxxp://schemas.monotypeimaging.com/ptpc/oem/2006/1"><!-- --><!-- Monotype Imaging print capabilities --><!-- --><!-- --><!-- JobComment --><!-- [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "G:\Menu.exe"="CnMemory Software " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe"="Softonic Downloader " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Desktop\TrustPort_Internet_Security_12.0.0.4788.exe"="TrustPort Internet Security " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "G:\Menu.exe"="CnMemory Software " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe"="Softonic Downloader " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Desktop\TrustPort_Internet_Security_12.0.0.4788.exe"="TrustPort Internet Security " -= EOF =- Sooo, der PC läuft wieder ganz gut- dafür erstmal sehr herzlichen Dank! Der hat nur noch beim Hochfahren einige Schwierigkeiten z.B. wenn man sein PW eingegeben hat, dann braucht der einige Zeit bis sich der PC öffnet. Und beim Hochfahren bleibt es zunächst lange Zeit schwarz, bis ich beim Benutzerkonto meinen PW eingeben kann. Wie kann ich mich in Zukunft vor Viren etc. schützen? Was könntest du mir empfehlen? :=) |
Servus, Zitat:
Zitat:
Zitat:
Du hast dich schon wieder mit Adware infiziert: Zitat:
Jetzt können wir wieder von vorne anfangen... :balla: Schritt 1 Downloade Dir bitte ![]()
Schritt 2 Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Schritt 3 Downloade Dir bitte ![]()
Bitte poste mit deiner nächsten Antwort
|
Zitat:
Zitat:
Code: # AdwCleaner v2.306 - Datei am 06/08/2013 um 14:37:07 erstellt Code: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Malwarebytes Anti-Malware (Test) 1.75.0.1300 Malwarebytes : Free anti-malware download Datenbank Version: v2013.08.06.03 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 PC :: PC-HP [Administrator] Schutz: Aktiviert 06.08.2013 14:56:43 mbam-log-2013-08-06 (14-56-43).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 214077 Laufzeit: 8 Minute(n), 31 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) |
Servus, ok, und jetzt nochmal das hier: Schritt 1 Kontrollscan mit FRST Führe wie zuvor beschrieben einen Scan mit FRST aus. Setze dazu eine Haken bei Addition.txt rechts unten und klicke auf Scan. Es werden wieder zwei Logdateien erzeugt. Poste mir diese. Schritt 2 Lade SystemLook von jpshortstuff vom folgenden Spiegel herunter und speichere das Tool auf dem Desktop. SystemLook (64 bit)
Bitte poste mit deiner nächsten Antwort
|
Alle Zeitangaben in WEZ +1. Es ist jetzt 08:33 Uhr. |
Copyright ©2000-2025, Trojaner-Board