![]() |
TrojansHunter kann gefundenen Trojaner leider nicht löschen Hallo Liebe Leute, ich hoffe, es kann mir jemand helfen. Ich habe das Programm TrojanHunter runtergeladen, da ich das Gefühl hatte, dass mein PC ein Trojaner hat. Beim Scannen hat das Programm Folgendes herausgefunden: Found malware file: C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFdetect.exe (Vobfus.432) Found malware file: C:\Users\All Users\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFdetect.exe (Vobfus.432) Found malware file: C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\acrobatupdater.exe (AgentZ.2056) Found malware file: C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\readerupdater.exe (AgentZ.2056) Doch leider kann ich das nicht löschen, da ich eine trial version habe.. Was muss ich tun? Vielen Dank im Voraus und LG U-C |
:hallo: Mein Name ist Matthias und ich werde dir bei der Bereinigung deines Computers helfen. Bitte beachte folgende Hinweise:
Ich habe dein Thema in Arbeit und melde mich so schnell wie möglich mit weiteren Anweisungen. |
Servus, Zitat:
Was ist passiert? Gibt es Auffälligkeiten? Gibt es Probleme mit deinem Rechner? Wenn ja, welche? Zitat:
Zitat:
|
Servus, vielen Dank für die schnelle Antwort! :) Da bin ich schonmal beruhigt... Während ich z.B. etwas google oder nur so im Internet surfe z.B. Youtube, Mails checken, kommen ständig Warnungen von dubiosen Programm, dass mein Computer in Gefahr ist. Oder, dass mein Laufwerk C bereinigt werden müsste " Klicken Sie auf bereinigen"- was ich natürlich nicht gemacht habe. Des Weiteren schließt sich mein Browser öfters von ganz alleine und die Internetverbindung ist wird immer langsamer. Ich hoffe, ich könnte deine Fragen einigermaßen verständlich beantworten.. :) |
Servus, Zitat:
Ich würde deinen Rechner gerne mal etwas näher inspizieren, nur um sicher zu gehen. :) So geht es los: Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: ![]() (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
|
So ich habe jetzt alles gemacht was du gesagt hast :) Das sind jetzt so 4 Sachen, die ich angezeigt bekommen habe: FRST Logfile: FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-08-2013 --- --- --- --- --- --- FRST Additions Logfile: Code: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 04-08-2013 FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-08-2013 --- --- --- |
FRST Additions Logfile: Code: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 04-08-2013 Habe ich alles richtig gemacht, oder fehlt da noch was? |
Servus, Zitat:
Du hast dir jede Menge Adware eingefangen. :) Dann starten wir mal die Bereinigung: AdwCleaner bitte zweimal direkt hintereinander genau so ausführen und beide Logdateien davon posten! Schritt 1 Downloade Dir bitte ![]()
Schritt 2 Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Schritt 3 Downloade Dir bitte ![]()
Bitte poste mit deiner nächsten Antwort
|
Hey habe schritt 1 und 2 schon mal fertig. Die poste ich dann schon mal Also die beiden LogdateienAdwCleaner Logfile: Code: # AdwCleaner v2.306 - Datei am 05/08/2013 um 17:20:38 erstellt adw cleaner (S2)AdwCleaner Logfile: Code: # AdwCleaner v2.306 - Datei am 05/08/2013 um 17:26:11 erstellt Code: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Malwarebytes Anti-Malware (Test) 1.75.0.1300 Malwarebytes : Free anti-malware download Datenbank Version: v2013.08.05.05 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 PC :: PC-HP [Administrator] Schutz: Aktiviert 05.08.2013 17:58:43 mbam-log-2013-08-05 (17-58-43).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 214006 Laufzeit: 11 Minute(n), 23 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 6 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{17E58097-6CA5-448B-830F-2A19678248FB} (PUP.Optional.LyricXeeker.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{17E58097-6CA5-448B-830F-2A19678248FB} (PUP.Optional.LyricXeeker.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2f7ea55-9ec3-4993-a1e9-62bdb904fd6d} (PUP.Optional.LyricXeeker.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\CLSID\{d2f7ea55-9ec3-4993-a1e9-62bdb904fd6d} (PUP.Optional.LyricXeeker.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\TypeLib\{32db519c-98a8-4129-828a-368cd8cf25a0} (PUP.Optional.LyricXeeker.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\Interface\{F9CF2BCB-2794-4E8B-A570-38B96572C2BE} (PUP.Optional.LyricXeeker.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Registrierungswerte: 1 HKCU\Software\Microsoft\Windows\CurrentVersion\Run|NTRedirect (PUP.Optional.A.BabSolution) -> Daten: C:\Windows\SysWOW64\rundll32.exe "C:\Users\PC\AppData\Roaming\BabSolution\Shared\NTRedirect.dll",Run -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 4 C:\Users\PC\Downloads\setup.exe (PUP.Optional.InstallCore) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Windows\Installer\1372f5c.msi (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Windows\Installer\1372f63.msi (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Windows\Tasks\LyricXeeker Update.job (PUP.Optional.Lyrixeeker) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) Und fertig :) |
Servus, sieht schon gut aus. :) Wir spüren die letzten Reste auf, damit wie sie später entfernen können: Schritt 1 Kontrollscan mit FRST Führe wie zuvor beschrieben einen Scan mit FRST aus. Setze dazu eine Haken bei Addition.txt rechts unten und klicke auf Scan. Es werden wieder zwei Logdateien erzeugt. Poste mir diese. Schritt 2 Lade SystemLook von jpshortstuff vom folgenden Spiegel herunter und speichere das Tool auf dem Desktop. SystemLook (64 bit)
Gibt es noch Probleme mit Malware? Wenn ja, welche? Wie läuft der Rechner derzeit? Bitte poste mit deiner nächsten Antwort
|
hey, anbei die Daten: FRST Logfile: FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-08-2013 --- --- --- --- --- --- FRST Additions Logfile: Code: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 04-08-2013 LSystemLook 30.07.11 by jpshortstuff Log created at 22:24 on 05/08/2013 by PC Administrator - Elevation successful ========== filefind ========== Searching for "*systweak*" No files found. Searching for "*adawarebp*" C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.dll --a---- 318872 bytes [23:20 11/12/2012] [23:20 11/12/2012] C55D73BF01BEB9C25516FA519174CC9C C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe --a---- 542104 bytes [23:20 11/12/2012] [23:20 11/12/2012] DF7AEEC25E5C006EEC61206476F48629 C:\Users\All Users\Ad-Aware Browsing Protection\adawarebp.dll --a---- 318872 bytes [23:20 11/12/2012] [23:20 11/12/2012] C55D73BF01BEB9C25516FA519174CC9C C:\Users\All Users\Ad-Aware Browsing Protection\adawarebp.exe --a---- 542104 bytes [23:20 11/12/2012] [23:20 11/12/2012] DF7AEEC25E5C006EEC61206476F48629 Searching for "*datamngr*" No files found. Searching for "*lyrixeeker*" No files found. Searching for "*mypc backup*" No files found. Searching for "*speedupmypc*" No files found. Searching for "*sweetim*" No files found. Searching for "*distromatic*" No files found. Searching for "*BabSolution*" No files found. Searching for "*bProtector*" No files found. Searching for "*BrowserDefender*" C:\Windows\Prefetch\BROWSERDEFENDER.EXE-62524200.pf --a---- 30700 bytes [00:24 05/08/2013] [14:50 05/08/2013] A660DF35F2F003AAABD99C1581C9AF85 C:\Windows\System32\Tasks\BrowserDefendert --a---- 3436 bytes [14:50 05/08/2013] [14:50 05/08/2013] 8444D519E7504D38BE49BC3FAE167689 Searching for "*iLivid*" C:\Users\PC\Downloads\iLividSetupV1.exe --a---- 1302424 bytes [18:57 27/11/2012] [18:57 27/11/2012] A572625DB335FCCA490C909C373FB81C Searching for "*holasearch*" No files found. Searching for "*DealPly*" C:\Windows\System32\Tasks\DealPly --a---- 3482 bytes [08:07 07/02/2013] [18:11 16/03/2013] FD52B70225C0B2F3FCE040C2C359D1A8 C:\Windows\System32\Tasks\DealPlyUpdate --a---- 3304 bytes [18:11 25/11/2012] [18:11 25/11/2012] 3F89962238E95558E6CF05D47AE0D32B Searching for "*Babylon*" C:\Users\PC\AppData\Local\Temp\8DD1A082-BAB0-7891-8C74-BC4EED533129\Latest\Babylon.dat --a---- 12384 bytes [14:49 05/08/2013] [12:17 19/02/2013] 825E5733974586A0A1229A53361ED13E Searching for "*Softonic*" No files found. Searching for "*delta LTD*" No files found. Searching for "*PriceGong*" No files found. Searching for "*OpenCandy*" No files found. Searching for "*PerformerSoft*" No files found. Searching for "*SoftSafe*" C:\Program Files\Common Files\Bitdefender\SetupInformation\downloader\extern\kingsoftSafeguard.xml --a---- 618 bytes [10:56 09/02/2013] [14:28 24/04/2012] E7BE97006F2213266A33D726FDBBE913 C:\Program Files\Common Files\Bitdefender\SetupInformation\downloader\extern\kingsoftSafeguard.xml.md5 --a---- 32 bytes [10:56 09/02/2013] [17:44 29/06/2012] D885CA3A040A7350B1CB313C9DC264ED Searching for "*IBUpdater*" No files found. ========== folderfind ========== Searching for "*systweak*" No folders found. Searching for "*adawarebp*" No folders found. Searching for "*datamngr*" No folders found. Searching for "*lyrixeeker*" C:\Program Files (x86)\LyriXeeker d------ [14:49 05/08/2013] Searching for "*mypc backup*" No folders found. Searching for "*speedupmypc*" No folders found. Searching for "*sweetim*" No folders found. Searching for "*distromatic*" No folders found. Searching for "*BabSolution*" No folders found. Searching for "*bProtector*" No folders found. Searching for "*BrowserDefender*" No folders found. Searching for "*iLivid*" No folders found. Searching for "*holasearch*" No folders found. Searching for "*DealPly*" C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\NS6RQ2XF\static.dealply.com d------ [22:51 12/02/2013] C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\NS6RQ2XF\macromedia.com\support\flashplayer\sys\#static.dealply.com d------ [22:51 12/02/2013] C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\NS6RQ2XF\static.dealply.com\flash\dealply_swf_engine.swf d------ [22:51 12/02/2013] Searching for "*Babylon*" No folders found. Searching for "*Softonic*" No folders found. Searching for "*delta LTD*" No folders found. Searching for "*PriceGong*" No folders found. Searching for "*OpenCandy*" No folders found. Searching for "*PerformerSoft*" No folders found. Searching for "*SoftSafe*" No folders found. Searching for "*IBUpdater*" No folders found. ========== regfind ========== Searching for "systweak" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\systweakasp_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\systweakasp_RASMANCS] Searching for "adawarebp" [HKEY_CURRENT_USER\Software\AppDataLow\Software\adawarebp] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Ad-Aware Browsing Protection] "command"=""C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe"" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\adawarebp_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\adawarebp_RASDLG] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\adawarebp_RASMANCS] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\AppDataLow\Software\adawarebp] Searching for "datamngr" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DATAMNGR] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DATAMNGR] "item"="DATAMNGR" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DATAMNGR] "command"="C:\PROGRA~2\SEARCH~1\Datamngr\DATAMN~1.EXE" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4E704E34-0FD7-4216-8B49-E4A8C853DB34}] "AppPath"="C:\PROGRA~2\SEARCH~1\Datamngr\SRTOOL~1" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0028FE51-2BFF-4A35-8266-0D10A6A4DF27}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe|Name=Search-Results Toolbar DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F8BD6963-EDBD-44DD-A5DA-038F96222E8A}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe|Name=Search-Results Toolbar DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0028FE51-2BFF-4A35-8266-0D10A6A4DF27}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe|Name=Search-Results Toolbar DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F8BD6963-EDBD-44DD-A5DA-038F96222E8A}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe|Name=Search-Results Toolbar DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0028FE51-2BFF-4A35-8266-0D10A6A4DF27}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe|Name=Search-Results Toolbar DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F8BD6963-EDBD-44DD-A5DA-038F96222E8A}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe|Name=Search-Results Toolbar DTX Broker|" Searching for "lyrixeeker" [HKEY_CURRENT_USER\Software\AppDataLow\Software\LyriXeeker] [HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions] "lyrix@lyrixeeker.co"="C:\Program Files (x86)\LyriXeeker\125.xpi" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\epojlgbehpaeekopencdagbdamnkppci] "Path"="C:\Program Files (x86)\LyriXeeker\125.crx" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\lyrix@lyrixeeker.co] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\lyrix@lyrixeeker.co] "Publisher"="LyriXeeker Tech" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\lyrix@lyrixeeker.co] "UninstallString"="C:\Program Files (x86)\LyriXeeker\uninstall.exe" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\AppDataLow\Software\LyriXeeker] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Mozilla\Firefox\Extensions] "lyrix@lyrixeeker.co"="C:\Program Files (x86)\LyriXeeker\125.xpi" Searching for "mypc backup" No data found. Searching for "speedupmypc" No data found. Searching for "sweetim" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3199093499-978631591-3148159529-1001\Software\SweetIM] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Sweetpacks Communicator] "command"="C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\02F47BF73B948514FAACADD8CBBDF37D] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\080D9F5E1E95FEE4794CE438E635239E] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgxml_wrapper.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\12BF94BD06C95F343A77631402B9556A] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1E264E0A5959A1C46BA9175A878B12EA] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgconfig.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2124D8A8CF720FD44866190AF560228E] "254796BF4AC84B64891B61C529A2E23F"="C:\ProgramData\SweetIM\Communicator\conf\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\27A325ACED8CA4743A30127638591ADB] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\mgsimcommon.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E6768B6932D112438F047C54D180635] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\ClearHist.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\350D17402BD84234EAF7D32F08172D7C] "254796BF4AC84B64891B61C529A2E23F"="C:\ProgramData\SweetIM\Communicator\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\351716A953E21214898904032EAE2E81] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\397C771A7BCAC904697C3EC629ED33ED] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgHelper.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3EE8C5F419057E1478A654868CEE60B5] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4735D908D66E1BA46B6C2D7185A12B2B] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\resources\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\69D6A6B2ED56AF24EA6335EAD6E91CA4] "16FE85B52F587794795A481CF9295697"="C?\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgHelperApp.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\76D8378E2DDAED3428720A631F6E3BF0] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\resources\sqlite\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7FFA128C2B0FF414D805FC5627883401] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mghooking.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86EDC790504E1834DBC20C9A04328FD2] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\green\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97C3D0F82E712E241A2F969F45E3351C] "16FE85B52F587794795A481CF9295697"="C?\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarProxy.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\98CC8BF5A4A6E6C4ABF7051DDAB8B058] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9A001B259DB7D694E818BE29B973992C] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9E7F556BF224D804D96A96F0F6344789] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\blue\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A189D17A469616C4688D23E192996267] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mglogger.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BAE2EC163C6A68A48921573E0E7E199D] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\mgcommunication.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BF4F885EDEE45644EB1E0C99E0162399] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\Microsoft.VC90.CRT\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C06C6662FA5B04646829E4A460857770] "254796BF4AC84B64891B61C529A2E23F"="C:\ProgramData\SweetIM\Communicator\Logs\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CE21F3FD57B244142880EF15A165A156] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\orange\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CEEB3E14ABE8270419B0FD762E18F7C6] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\mgcommon.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D15DAF33C220F91468A1D7D57C31ACD7] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\conf\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D3BA76A44C779424889063D5098ED2D6] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgcommon.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D6D0EB9FDBD90C04D92A7E729058F10D] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E4748F9A4181FCE46A23C13B517B9420] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgsimcommon.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ED1B5E9A3BDB51349BF96E842C062D98] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\Microsoft.VC90.CRT\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FECBC2BC14DA6CD459BD59A041709836] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\mgxml_wrapper.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\16FE85B52F587794795A481CF9295697\InstallProperties] "Contact"="SweetIM Technical Support Department" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\16FE85B52F587794795A481CF9295697\InstallProperties] "HelpLink"="hxxp://www.sweetim.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\16FE85B52F587794795A481CF9295697\InstallProperties] "InstallLocation"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\16FE85B52F587794795A481CF9295697\InstallProperties] "Publisher"="SweetIM Technologies Ltd." [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\16FE85B52F587794795A481CF9295697\InstallProperties] "URLInfoAbout"="hxxp://www.sweetim.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\16FE85B52F587794795A481CF9295697\InstallProperties] "URLUpdateInfo"="hxxp://www.sweetim.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\254796BF4AC84B64891B61C529A2E23F\InstallProperties] "Contact"="SweetIM Technical Support Department" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\254796BF4AC84B64891B61C529A2E23F\InstallProperties] "HelpLink"="hxxp://www.sweetim.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\254796BF4AC84B64891B61C529A2E23F\InstallProperties] "InstallLocation"="C:\Program Files (x86)\SweetIM\Communicator\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\254796BF4AC84B64891B61C529A2E23F\InstallProperties] "Publisher"="SweetIM Technologies Ltd." [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\254796BF4AC84B64891B61C529A2E23F\InstallProperties] "URLInfoAbout"="hxxp://www.sweetim.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\254796BF4AC84B64891B61C529A2E23F\InstallProperties] "URLUpdateInfo"="hxxp://www.sweetim.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\toolbar_vit_sweetim_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\toolbar_vit_sweetim_RASMANCS] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{A21972B4-5118-42E3-B07B-3ABF8F630877}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe|Name=SweetPacksUpdateManager|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F0F839E5-89DE-4467-9E52-606055705D06}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe|Name=SweetPacksUpdateManager|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{A21972B4-5118-42E3-B07B-3ABF8F630877}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe|Name=SweetPacksUpdateManager|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F0F839E5-89DE-4467-9E52-606055705D06}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe|Name=SweetPacksUpdateManager|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{A21972B4-5118-42E3-B07B-3ABF8F630877}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe|Name=SweetPacksUpdateManager|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F0F839E5-89DE-4467-9E52-606055705D06}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe|Name=SweetPacksUpdateManager|" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3199093499-978631591-3148159529-1001\Software\SweetIM] Searching for "distromatic" No data found. Searching for "BabSolution" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\fagpjgjmoaccgkkpjeoinehnoaimnbla] "path"="C:\Users\PC\AppData\Roaming\BabSolution\CR\hola.crx" Searching for "bProtector" No data found. Searching for "BrowserDefender" [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\ProgramData\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe"="Application Manager" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{2A0F3D1B-0909-4FF4-B272-609CCE6054E7}] "DllName"="PCTBrowserDefender.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{472734EA-242A-422B-ADF8-83D1E48CC825}] "DllName"="PCTBrowserDefender.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{424202EF-76FA-4231-BF7A-5153EB49F987}] "Path"="\BrowserDefendert" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BrowserDefendert] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{2A0F3D1B-0909-4FF4-B272-609CCE6054E7}] "DllName"="PCTBrowserDefender.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{472734EA-242A-422B-ADF8-83D1E48CC825}] "DllName"="PCTBrowserDefender.dll" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\ProgramData\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe"="Application Manager" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\ProgramData\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe"="Application Manager" Searching for "iLivid" [HKEY_CURRENT_USER\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\C:\Users\PC\AppData\Local\iLivid] [HKEY_CURRENT_USER\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.8.false\C:\Users\PC\AppData\Local\iLivid] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\C:\Users\PC\AppData\Local\iLivid] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.8.false\C:\Users\PC\AppData\Local\iLivid] Searching for "holasearch" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "hp_url"="hxxp://www.holasearch.com/?babsrc=HP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "nt_url"="hxxp://www.holasearch.com/?babsrc=NT_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "dsFFX"="holasearch" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "uninstaller"="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\uninstall.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "sp_url"="hxxp://www.holasearch.com/?q={searchTerms}&babsrc=SP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "tb_url"="hxxp://www.holasearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "kw_url"="hxxp://www.holasearch.com/?babsrc=SP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927&q=" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\esrv.holasearchESrvc] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\esrv.holasearchESrvc\CurVer] @="esrv.holasearchESrvc.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\esrv.holasearchESrvc.1] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchappCore] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchappCore\CurVer] @="holasearch.holasearchappCore.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchappCore.1] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchdskBnd] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchdskBnd\CurVer] @="holasearch.holasearchdskBnd.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchdskBnd.1] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchHlpr] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchHlpr\CurVer] @="holasearch.holasearchHlpr.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchHlpr.1] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}\1.0\0\win32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchsrv.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}\1.0\HELPDIR] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0] @="holasearchCmn 1.0 Type Library" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0\0\win32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchEng.dll\2" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0\HELPDIR] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1E44819B-54E1-411B-9D9F-38D7B913BCF2}\InprocServer32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchEng.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}\LocalServer32] @=""C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchsrv.exe"" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}\ProgID] @="esrv.holasearchESrvc.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}\VersionIndependentProgID] @="esrv.holasearchESrvc" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}\InprocServer32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchApp.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}\ProgID] @="holasearch.holasearchappCore.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}\VersionIndependentProgID] @="holasearch.holasearchappCore" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C46EFEA4-B0F3-428B-9E77-650E3634EC56}\InprocServer32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\bh\holasearch.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "hp_url"="hxxp://www.holasearch.com/?babsrc=HP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "nt_url"="hxxp://www.holasearch.com/?babsrc=NT_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "dsFFX"="holasearch" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "uninstaller"="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\uninstall.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "sp_url"="hxxp://www.holasearch.com/?q={searchTerms}&babsrc=SP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "tb_url"="hxxp://www.holasearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "kw_url"="hxxp://www.holasearch.com/?babsrc=SP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927&q=" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}\1.0\0\win32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchsrv.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}\1.0\HELPDIR] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0] @="holasearchCmn 1.0 Type Library" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0\0\win32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchEng.dll\2" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0\HELPDIR] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5882DB3D-175D-4CDC-A030-1B7EC2BC8EC6}] "AppName"="holasearchsrv.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5882DB3D-175D-4CDC-A030-1B7EC2BC8EC6}] "AppPath"="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{1E44819B-54E1-411B-9D9F-38D7B913BCF2}\InprocServer32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchEng.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}\LocalServer32] @=""C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchsrv.exe"" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}\ProgID] @="esrv.holasearchESrvc.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}\VersionIndependentProgID] @="esrv.holasearchESrvc" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}\InprocServer32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchApp.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}\ProgID] @="holasearch.holasearchappCore.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}\VersionIndependentProgID] @="holasearch.holasearchappCore" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{C46EFEA4-B0F3-428B-9E77-650E3634EC56}\InprocServer32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\bh\holasearch.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "hp_url"="hxxp://www.holasearch.com/?babsrc=HP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "nt_url"="hxxp://www.holasearch.com/?babsrc=NT_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "dsFFX"="holasearch" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "uninstaller"="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\uninstall.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "sp_url"="hxxp://www.holasearch.com/?q={searchTerms}&babsrc=SP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "tb_url"="hxxp://www.holasearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "kw_url"="hxxp://www.holasearch.com/?babsrc=SP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927&q=" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}\1.0\0\win32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchsrv.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}\1.0\HELPDIR] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0] @="holasearchCmn 1.0 Type Library" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0\0\win32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchEng.dll\2" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0\HELPDIR] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" Searching for "DealPly" [HKEY_CURRENT_USER\Software\Wow6432Node\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje] "path"="C:\Program Files (x86)\DealPly\DealPly.crx" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{296BED8D-8F7A-40EE-AFDD-642839AC7E7F}] "Path"="\DealPlyUpdate" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AC019BF5-2EB9-4103-AEE1-09CD370F4CBB}] "Path"="\DealPly" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPly] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPlyUpdate] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Wow6432Node\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje] "path"="C:\Program Files (x86)\DealPly\DealPly.crx" Searching for "Babylon" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{2EECD738-5844-4A99-B4B6-146BF802613B}] "DllName"="BabylonToolbar.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}] "DllName"="BabylonToolbar.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{98889811-442D-49DD-99D7-DC866BE87DBC}] "DllName"="BabylonToolbarTlbr.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{2EECD738-5844-4A99-B4B6-146BF802613B}] "DllName"="BabylonToolbar.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}] "DllName"="BabylonToolbar.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{98889811-442D-49DD-99D7-DC866BE87DBC}] "DllName"="BabylonToolbarTlbr.dll" Searching for "Softonic" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\1e40ca8e_0] @="{0.0.0.00000000}.{f8047516-971f-40ba-85de-843482a8264a}|\Device\HarddiskVolume2\Users\PC\Downloads\SoftonicDownloader_fuer_mp3directcut.exe%b{00000000-0000-0000-0000-000000000000}" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\29629339_0] @="{0.0.0.00000000}.{f8047516-971f-40ba-85de-843482a8264a}|\Device\HarddiskVolume2\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe%b{00000000-0000-0000-0000-000000000000}" [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe"="Softonic Downloader " [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_mp3directcut_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_mp3directcut_RASMANCS] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_trustport-internet-security_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_trustport-internet-security_RASMANCS] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\1e40ca8e_0] @="{0.0.0.00000000}.{f8047516-971f-40ba-85de-843482a8264a}|\Device\HarddiskVolume2\Users\PC\Downloads\SoftonicDownloader_fuer_mp3directcut.exe%b{00000000-0000-0000-0000-000000000000}" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\29629339_0] @="{0.0.0.00000000}.{f8047516-971f-40ba-85de-843482a8264a}|\Device\HarddiskVolume2\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe%b{00000000-0000-0000-0000-000000000000}" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe"="Softonic Downloader " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe"="Softonic Downloader " Searching for "delta LTD" No data found. Searching for "PriceGong" [HKEY_CURRENT_USER\Software\PowerPack\225\13] "c"="hxxp://www.powerpackdl.com/downloads/pricegong.exe" [HKEY_CURRENT_USER\Software\PowerPack\225\13] "i"="hxxp://www.pricegong.com/TermsofUse.aspx" [HKEY_CURRENT_USER\Software\PowerPack\225\13] "j"="PriceGong" [HKEY_CURRENT_USER\Software\PowerPack\225\13] "n"="rv:HKCR,AppID\\PriceGongIE.DLL,AppID,{835315FC-1BF6-4CA9-80CD-F6C158D40692}" [HKEY_CURRENT_USER\Software\PowerPack\225\13] "x"="hxxp://www.pricegong.com/favicon.ico" [HKEY_CURRENT_USER\Software\PowerPack\225\13] "y"="hxxp://www.pricegong.com/" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\PriceGong_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\PriceGong_RASMANCS] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\PowerPack\225\13] "c"="hxxp://www.powerpackdl.com/downloads/pricegong.exe" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\PowerPack\225\13] "i"="hxxp://www.pricegong.com/TermsofUse.aspx" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\PowerPack\225\13] "j"="PriceGong" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\PowerPack\225\13] "n"="rv:HKCR,AppID\\PriceGongIE.DLL,AppID,{835315FC-1BF6-4CA9-80CD-F6C158D40692}" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\PowerPack\225\13] "x"="hxxp://www.pricegong.com/favicon.ico" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\PowerPack\225\13] "y"="hxxp://www.pricegong.com/" Searching for "OpenCandy" No data found. Searching for "PerformerSoft" No data found. Searching for "SoftSafe" No data found. Searching for "IBUpdater" No data found. Searching for " " [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\PhotoPrintingWizard\Laser Pro LL2] "PrintTicket"="<?xml version="1.0"?> <psf:PrintTicket version="1" xmlns:xsd="hxxp://www.w3.org/2001/XMLSchema" xmlns:xsi="hxxp://www.w3.org/2001/XMLSchema-instance" xmlns:psf="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemaframework" xmlns:psk="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemakeywords" xmlns:mti="hxxp://schemas.monotypeimaging.com/ptpc/2006/1" xmlns:oem="hxxp://schemas.monotypeimaging.com/ptpc/oem/2006/1"><psf:Feature name="psk:PageOrientation"><psf:Option name="psk:Landscape"/></psf:Feature><!-- --><!-- Monotype Imaging print ticket --><!-- --><!-- --><!-- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\PhotoPrintingWizard\Laser Pro LL2] "PrintCapabilites"="<?xml version="1.0"?> <psf:PrintCapabilities version="1" xmlns:xsd="hxxp://www.w3.org/2001/XMLSchema" xmlns:xsi="hxxp://www.w3.org/2001/XMLSchema-instance" xmlns:psf="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemaframework" xmlns:psk="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemakeywords" xmlns:mti="hxxp://schemas.monotypeimaging.com/ptpc/2006/1" xmlns:oem="hxxp://schemas.monotypeimaging.com/ptpc/oem/2006/1"><!-- --><!-- Monotype Imaging print capabilities --><!-- --><!-- --><!-- JobComment --><!-- [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "G:\Menu.exe"="CnMemory Software " [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe"="Softonic Downloader " [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Desktop\TrustPort_Internet_Security_12.0.0.4788.exe"="TrustPort Internet Security " [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WSMAN\Plugin\Microsoft.PowerShell] "ConfigXML"=" <PlugInConfiguration xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Name="microsoft.powershell" Filename="%windir%\system32\pwrshplugin.dll" SDKVersion="1" XmlRenderingType="text" > <InitializationParameters> <Param Name="PSVersion" Value="2.0"/> </InitializationParameters> <Resources> <Resource ResourceUri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell" SupportsOptions="true" ExactMatch="true"> <Security xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Uri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell" ExactMatch="true" Sddl="O:NSG:BAD:P(A;;GA;;;BA)S:P(AU;FA;GA;;;WD)(AU;SA;GXGW;;;WD)"/> <Capability Type="Shell"/> </Resource> </Res [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\WSMAN\Plugin\Microsoft.PowerShell32] "ConfigXML"="<PlugInConfiguration xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Name="microsoft.powershell32" Filename="%windir%\system32\pwrshplugin.dll" SDKVersion="1" XmlRenderingType="text" Architecture="32" > <InitializationParameters> <Param Name="PSVersion" Value="2.0"/> </InitializationParameters> <Resources> <Resource ResourceUri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell32" SupportsOptions="true" ExactMatch="true"> <Security xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Uri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell32" ExactMatch="true" Sddl="O:NSG:BAD:P(A;;GA;;;BA)S:P(AU;FA;GA;;;WD)(AU;SA;GXGW;;;WD)"/> [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&10D4990&0&__ ______&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&10D4990&0&__ ______&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&11AC6715&0&_ _______&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&11AC6715&0&_ _______&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&2706475&0&__ ______&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&2706475&0&__ ______&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&10D4990&0&__ ______&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&10D4990&0&__ ______&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&11AC6715&0&_ _______&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&11AC6715&0&_ _______&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&2706475&0&__ ______&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&2706475&0&__ ______&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&10D4990& 0&________&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&10D4990& 0&________&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&11AC6715 &0&________&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&11AC6715 &0&________&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&2706475& 0&________&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&2706475& 0&________&1#] "DeviceDesc"="NERO " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\PhotoPrintingWizard\Laser Pro LL2] "PrintTicket"="<?xml version="1.0"?> <psf:PrintTicket version="1" xmlns:xsd="hxxp://www.w3.org/2001/XMLSchema" xmlns:xsi="hxxp://www.w3.org/2001/XMLSchema-instance" xmlns:psf="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemaframework" xmlns:psk="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemakeywords" xmlns:mti="hxxp://schemas.monotypeimaging.com/ptpc/2006/1" xmlns:oem="hxxp://schemas.monotypeimaging.com/ptpc/oem/2006/1"><psf:Feature name="psk:PageOrientation"><psf:Option name="psk:Landscape"/></psf:Feature><!-- --><!-- Monotype Imaging print ticket --><!-- --><!-- --><!-- [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\PhotoPrintingWizard\Laser Pro LL2] "PrintCapabilites"="<?xml version="1.0"?> <psf:PrintCapabilities version="1" xmlns:xsd="hxxp://www.w3.org/2001/XMLSchema" xmlns:xsi="hxxp://www.w3.org/2001/XMLSchema-instance" xmlns:psf="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemaframework" xmlns:psk="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemakeywords" xmlns:mti="hxxp://schemas.monotypeimaging.com/ptpc/2006/1" xmlns:oem="hxxp://schemas.monotypeimaging.com/ptpc/oem/2006/1"><!-- --><!-- Monotype Imaging print capabilities --><!-- --><!-- --><!-- JobComment --><!-- [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "G:\Menu.exe"="CnMemory Software " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe"="Softonic Downloader " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Desktop\TrustPort_Internet_Security_12.0.0.4788.exe"="TrustPort Internet Security " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "G:\Menu.exe"="CnMemory Software " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe"="Softonic Downloader " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Desktop\TrustPort_Internet_Security_12.0.0.4788.exe"="TrustPort Internet Security " -= EOF =- |
LSystemLook 30.07.11 by jpshortstuff Log created at 22:24 on 05/08/2013 by PC Administrator - Elevation successful ========== filefind ========== Searching for "*systweak*" No files found. Searching for "*adawarebp*" C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.dll --a---- 318872 bytes [23:20 11/12/2012] [23:20 11/12/2012] C55D73BF01BEB9C25516FA519174CC9C C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe --a---- 542104 bytes [23:20 11/12/2012] [23:20 11/12/2012] DF7AEEC25E5C006EEC61206476F48629 C:\Users\All Users\Ad-Aware Browsing Protection\adawarebp.dll --a---- 318872 bytes [23:20 11/12/2012] [23:20 11/12/2012] C55D73BF01BEB9C25516FA519174CC9C C:\Users\All Users\Ad-Aware Browsing Protection\adawarebp.exe --a---- 542104 bytes [23:20 11/12/2012] [23:20 11/12/2012] DF7AEEC25E5C006EEC61206476F48629 Searching for "*datamngr*" No files found. Searching for "*lyrixeeker*" No files found. Searching for "*mypc backup*" No files found. Searching for "*speedupmypc*" No files found. Searching for "*sweetim*" No files found. Searching for "*distromatic*" No files found. Searching for "*BabSolution*" No files found. Searching for "*bProtector*" No files found. Searching for "*BrowserDefender*" C:\Windows\Prefetch\BROWSERDEFENDER.EXE-62524200.pf --a---- 30700 bytes [00:24 05/08/2013] [14:50 05/08/2013] A660DF35F2F003AAABD99C1581C9AF85 C:\Windows\System32\Tasks\BrowserDefendert --a---- 3436 bytes [14:50 05/08/2013] [14:50 05/08/2013] 8444D519E7504D38BE49BC3FAE167689 Searching for "*iLivid*" C:\Users\PC\Downloads\iLividSetupV1.exe --a---- 1302424 bytes [18:57 27/11/2012] [18:57 27/11/2012] A572625DB335FCCA490C909C373FB81C Searching for "*holasearch*" No files found. Searching for "*DealPly*" C:\Windows\System32\Tasks\DealPly --a---- 3482 bytes [08:07 07/02/2013] [18:11 16/03/2013] FD52B70225C0B2F3FCE040C2C359D1A8 C:\Windows\System32\Tasks\DealPlyUpdate --a---- 3304 bytes [18:11 25/11/2012] [18:11 25/11/2012] 3F89962238E95558E6CF05D47AE0D32B Searching for "*Babylon*" C:\Users\PC\AppData\Local\Temp\8DD1A082-BAB0-7891-8C74-BC4EED533129\Latest\Babylon.dat --a---- 12384 bytes [14:49 05/08/2013] [12:17 19/02/2013] 825E5733974586A0A1229A53361ED13E Searching for "*Softonic*" No files found. Searching for "*delta LTD*" No files found. Searching for "*PriceGong*" No files found. Searching for "*OpenCandy*" No files found. Searching for "*PerformerSoft*" No files found. Searching for "*SoftSafe*" C:\Program Files\Common Files\Bitdefender\SetupInformation\downloader\extern\kingsoftSafeguard.xml --a---- 618 bytes [10:56 09/02/2013] [14:28 24/04/2012] E7BE97006F2213266A33D726FDBBE913 C:\Program Files\Common Files\Bitdefender\SetupInformation\downloader\extern\kingsoftSafeguard.xml.md5 --a---- 32 bytes [10:56 09/02/2013] [17:44 29/06/2012] D885CA3A040A7350B1CB313C9DC264ED Searching for "*IBUpdater*" No files found. ========== folderfind ========== Searching for "*systweak*" No folders found. Searching for "*adawarebp*" No folders found. Searching for "*datamngr*" No folders found. Searching for "*lyrixeeker*" C:\Program Files (x86)\LyriXeeker d------ [14:49 05/08/2013] Searching for "*mypc backup*" No folders found. Searching for "*speedupmypc*" No folders found. Searching for "*sweetim*" No folders found. Searching for "*distromatic*" No folders found. Searching for "*BabSolution*" No folders found. Searching for "*bProtector*" No folders found. Searching for "*BrowserDefender*" No folders found. Searching for "*iLivid*" No folders found. Searching for "*holasearch*" No folders found. Searching for "*DealPly*" C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\NS6RQ2XF\static.dealply.com d------ [22:51 12/02/2013] C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\NS6RQ2XF\macromedia.com\support\flashplayer\sys\#static.dealply.com d------ [22:51 12/02/2013] C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\NS6RQ2XF\static.dealply.com\flash\dealply_swf_engine.swf d------ [22:51 12/02/2013] Searching for "*Babylon*" No folders found. Searching for "*Softonic*" No folders found. Searching for "*delta LTD*" No folders found. Searching for "*PriceGong*" No folders found. Searching for "*OpenCandy*" No folders found. Searching for "*PerformerSoft*" No folders found. Searching for "*SoftSafe*" No folders found. Searching for "*IBUpdater*" No folders found. ========== regfind ========== Searching for "systweak" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\systweakasp_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\systweakasp_RASMANCS] Searching for "adawarebp" [HKEY_CURRENT_USER\Software\AppDataLow\Software\adawarebp] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Ad-Aware Browsing Protection] "command"=""C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe"" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\adawarebp_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\adawarebp_RASDLG] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\adawarebp_RASMANCS] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\AppDataLow\Software\adawarebp] Searching for "datamngr" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DATAMNGR] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DATAMNGR] "item"="DATAMNGR" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DATAMNGR] "command"="C:\PROGRA~2\SEARCH~1\Datamngr\DATAMN~1.EXE" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4E704E34-0FD7-4216-8B49-E4A8C853DB34}] "AppPath"="C:\PROGRA~2\SEARCH~1\Datamngr\SRTOOL~1" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0028FE51-2BFF-4A35-8266-0D10A6A4DF27}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe|Name=Search-Results Toolbar DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F8BD6963-EDBD-44DD-A5DA-038F96222E8A}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe|Name=Search-Results Toolbar DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0028FE51-2BFF-4A35-8266-0D10A6A4DF27}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe|Name=Search-Results Toolbar DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F8BD6963-EDBD-44DD-A5DA-038F96222E8A}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe|Name=Search-Results Toolbar DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0028FE51-2BFF-4A35-8266-0D10A6A4DF27}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe|Name=Search-Results Toolbar DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F8BD6963-EDBD-44DD-A5DA-038F96222E8A}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe|Name=Search-Results Toolbar DTX Broker|" Searching for "lyrixeeker" [HKEY_CURRENT_USER\Software\AppDataLow\Software\LyriXeeker] [HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions] "lyrix@lyrixeeker.co"="C:\Program Files (x86)\LyriXeeker\125.xpi" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\epojlgbehpaeekopencdagbdamnkppci] "Path"="C:\Program Files (x86)\LyriXeeker\125.crx" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\lyrix@lyrixeeker.co] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\lyrix@lyrixeeker.co] "Publisher"="LyriXeeker Tech" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\lyrix@lyrixeeker.co] "UninstallString"="C:\Program Files (x86)\LyriXeeker\uninstall.exe" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\AppDataLow\Software\LyriXeeker] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Mozilla\Firefox\Extensions] "lyrix@lyrixeeker.co"="C:\Program Files (x86)\LyriXeeker\125.xpi" Searching for "mypc backup" No data found. Searching for "speedupmypc" No data found. Searching for "sweetim" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3199093499-978631591-3148159529-1001\Software\SweetIM] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Sweetpacks Communicator] "command"="C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\02F47BF73B948514FAACADD8CBBDF37D] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\080D9F5E1E95FEE4794CE438E635239E] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgxml_wrapper.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\12BF94BD06C95F343A77631402B9556A] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1E264E0A5959A1C46BA9175A878B12EA] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgconfig.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2124D8A8CF720FD44866190AF560228E] "254796BF4AC84B64891B61C529A2E23F"="C:\ProgramData\SweetIM\Communicator\conf\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\27A325ACED8CA4743A30127638591ADB] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\mgsimcommon.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E6768B6932D112438F047C54D180635] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\ClearHist.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\350D17402BD84234EAF7D32F08172D7C] "254796BF4AC84B64891B61C529A2E23F"="C:\ProgramData\SweetIM\Communicator\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\351716A953E21214898904032EAE2E81] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\397C771A7BCAC904697C3EC629ED33ED] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgHelper.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3EE8C5F419057E1478A654868CEE60B5] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4735D908D66E1BA46B6C2D7185A12B2B] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\resources\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\69D6A6B2ED56AF24EA6335EAD6E91CA4] "16FE85B52F587794795A481CF9295697"="C?\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgHelperApp.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\76D8378E2DDAED3428720A631F6E3BF0] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\resources\sqlite\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7FFA128C2B0FF414D805FC5627883401] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mghooking.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86EDC790504E1834DBC20C9A04328FD2] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\green\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97C3D0F82E712E241A2F969F45E3351C] "16FE85B52F587794795A481CF9295697"="C?\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarProxy.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\98CC8BF5A4A6E6C4ABF7051DDAB8B058] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9A001B259DB7D694E818BE29B973992C] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9E7F556BF224D804D96A96F0F6344789] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\blue\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A189D17A469616C4688D23E192996267] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mglogger.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BAE2EC163C6A68A48921573E0E7E199D] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\mgcommunication.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BF4F885EDEE45644EB1E0C99E0162399] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\Microsoft.VC90.CRT\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C06C6662FA5B04646829E4A460857770] "254796BF4AC84B64891B61C529A2E23F"="C:\ProgramData\SweetIM\Communicator\Logs\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CE21F3FD57B244142880EF15A165A156] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\orange\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CEEB3E14ABE8270419B0FD762E18F7C6] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\mgcommon.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D15DAF33C220F91468A1D7D57C31ACD7] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\conf\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D3BA76A44C779424889063D5098ED2D6] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgcommon.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D6D0EB9FDBD90C04D92A7E729058F10D] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E4748F9A4181FCE46A23C13B517B9420] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgsimcommon.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ED1B5E9A3BDB51349BF96E842C062D98] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\Microsoft.VC90.CRT\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FECBC2BC14DA6CD459BD59A041709836] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\mgxml_wrapper.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\16FE85B52F587794795A481CF9295697\InstallProperties] "Contact"="SweetIM Technical Support Department" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\16FE85B52F587794795A481CF9295697\InstallProperties] "HelpLink"="hxxp://www.sweetim.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\16FE85B52F587794795A481CF9295697\InstallProperties] "InstallLocation"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\16FE85B52F587794795A481CF9295697\InstallProperties] "Publisher"="SweetIM Technologies Ltd." [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\16FE85B52F587794795A481CF9295697\InstallProperties] "URLInfoAbout"="hxxp://www.sweetim.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\16FE85B52F587794795A481CF9295697\InstallProperties] "URLUpdateInfo"="hxxp://www.sweetim.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\254796BF4AC84B64891B61C529A2E23F\InstallProperties] "Contact"="SweetIM Technical Support Department" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\254796BF4AC84B64891B61C529A2E23F\InstallProperties] "HelpLink"="hxxp://www.sweetim.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\254796BF4AC84B64891B61C529A2E23F\InstallProperties] "InstallLocation"="C:\Program Files (x86)\SweetIM\Communicator\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\254796BF4AC84B64891B61C529A2E23F\InstallProperties] "Publisher"="SweetIM Technologies Ltd." [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\254796BF4AC84B64891B61C529A2E23F\InstallProperties] "URLInfoAbout"="hxxp://www.sweetim.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\254796BF4AC84B64891B61C529A2E23F\InstallProperties] "URLUpdateInfo"="hxxp://www.sweetim.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\toolbar_vit_sweetim_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\toolbar_vit_sweetim_RASMANCS] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{A21972B4-5118-42E3-B07B-3ABF8F630877}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe|Name=SweetPacksUpdateManager|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F0F839E5-89DE-4467-9E52-606055705D06}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe|Name=SweetPacksUpdateManager|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{A21972B4-5118-42E3-B07B-3ABF8F630877}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe|Name=SweetPacksUpdateManager|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F0F839E5-89DE-4467-9E52-606055705D06}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe|Name=SweetPacksUpdateManager|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{A21972B4-5118-42E3-B07B-3ABF8F630877}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe|Name=SweetPacksUpdateManager|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F0F839E5-89DE-4467-9E52-606055705D06}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe|Name=SweetPacksUpdateManager|" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3199093499-978631591-3148159529-1001\Software\SweetIM] Searching for "distromatic" No data found. Searching for "BabSolution" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\fagpjgjmoaccgkkpjeoinehnoaimnbla] "path"="C:\Users\PC\AppData\Roaming\BabSolution\CR\hola.crx" Searching for "bProtector" No data found. Searching for "BrowserDefender" [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\ProgramData\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe"="Application Manager" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{2A0F3D1B-0909-4FF4-B272-609CCE6054E7}] "DllName"="PCTBrowserDefender.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{472734EA-242A-422B-ADF8-83D1E48CC825}] "DllName"="PCTBrowserDefender.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{424202EF-76FA-4231-BF7A-5153EB49F987}] "Path"="\BrowserDefendert" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BrowserDefendert] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{2A0F3D1B-0909-4FF4-B272-609CCE6054E7}] "DllName"="PCTBrowserDefender.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{472734EA-242A-422B-ADF8-83D1E48CC825}] "DllName"="PCTBrowserDefender.dll" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\ProgramData\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe"="Application Manager" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\ProgramData\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe"="Application Manager" Searching for "iLivid" [HKEY_CURRENT_USER\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\C:\Users\PC\AppData\Local\iLivid] [HKEY_CURRENT_USER\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.8.false\C:\Users\PC\AppData\Local\iLivid] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\C:\Users\PC\AppData\Local\iLivid] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.8.false\C:\Users\PC\AppData\Local\iLivid] Searching for "holasearch" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "hp_url"="hxxp://www.holasearch.com/?babsrc=HP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "nt_url"="hxxp://www.holasearch.com/?babsrc=NT_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "dsFFX"="holasearch" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "uninstaller"="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\uninstall.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "sp_url"="hxxp://www.holasearch.com/?q={searchTerms}&babsrc=SP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "tb_url"="hxxp://www.holasearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "kw_url"="hxxp://www.holasearch.com/?babsrc=SP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927&q=" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\esrv.holasearchESrvc] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\esrv.holasearchESrvc\CurVer] @="esrv.holasearchESrvc.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\esrv.holasearchESrvc.1] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchappCore] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchappCore\CurVer] @="holasearch.holasearchappCore.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchappCore.1] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchdskBnd] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchdskBnd\CurVer] @="holasearch.holasearchdskBnd.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchdskBnd.1] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchHlpr] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchHlpr\CurVer] @="holasearch.holasearchHlpr.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchHlpr.1] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}\1.0\0\win32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchsrv.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}\1.0\HELPDIR] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0] @="holasearchCmn 1.0 Type Library" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0\0\win32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchEng.dll\2" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0\HELPDIR] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1E44819B-54E1-411B-9D9F-38D7B913BCF2}\InprocServer32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchEng.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}\LocalServer32] @=""C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchsrv.exe"" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}\ProgID] @="esrv.holasearchESrvc.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}\VersionIndependentProgID] @="esrv.holasearchESrvc" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}\InprocServer32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchApp.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}\ProgID] @="holasearch.holasearchappCore.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}\VersionIndependentProgID] @="holasearch.holasearchappCore" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C46EFEA4-B0F3-428B-9E77-650E3634EC56}\InprocServer32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\bh\holasearch.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "hp_url"="hxxp://www.holasearch.com/?babsrc=HP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "nt_url"="hxxp://www.holasearch.com/?babsrc=NT_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "dsFFX"="holasearch" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "uninstaller"="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\uninstall.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "sp_url"="hxxp://www.holasearch.com/?q={searchTerms}&babsrc=SP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "tb_url"="hxxp://www.holasearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "kw_url"="hxxp://www.holasearch.com/?babsrc=SP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927&q=" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}\1.0\0\win32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchsrv.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}\1.0\HELPDIR] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0] @="holasearchCmn 1.0 Type Library" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0\0\win32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchEng.dll\2" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0\HELPDIR] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5882DB3D-175D-4CDC-A030-1B7EC2BC8EC6}] "AppName"="holasearchsrv.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5882DB3D-175D-4CDC-A030-1B7EC2BC8EC6}] "AppPath"="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{1E44819B-54E1-411B-9D9F-38D7B913BCF2}\InprocServer32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchEng.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}\LocalServer32] @=""C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchsrv.exe"" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}\ProgID] @="esrv.holasearchESrvc.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}\VersionIndependentProgID] @="esrv.holasearchESrvc" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}\InprocServer32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchApp.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}\ProgID] @="holasearch.holasearchappCore.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}\VersionIndependentProgID] @="holasearch.holasearchappCore" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{C46EFEA4-B0F3-428B-9E77-650E3634EC56}\InprocServer32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\bh\holasearch.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "hp_url"="hxxp://www.holasearch.com/?babsrc=HP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "nt_url"="hxxp://www.holasearch.com/?babsrc=NT_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "dsFFX"="holasearch" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "uninstaller"="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\uninstall.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "sp_url"="hxxp://www.holasearch.com/?q={searchTerms}&babsrc=SP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "tb_url"="hxxp://www.holasearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "kw_url"="hxxp://www.holasearch.com/?babsrc=SP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927&q=" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}\1.0\0\win32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchsrv.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}\1.0\HELPDIR] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0] @="holasearchCmn 1.0 Type Library" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0\0\win32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchEng.dll\2" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0\HELPDIR] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" Searching for "DealPly" [HKEY_CURRENT_USER\Software\Wow6432Node\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje] "path"="C:\Program Files (x86)\DealPly\DealPly.crx" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{296BED8D-8F7A-40EE-AFDD-642839AC7E7F}] "Path"="\DealPlyUpdate" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AC019BF5-2EB9-4103-AEE1-09CD370F4CBB}] "Path"="\DealPly" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPly] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPlyUpdate] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Wow6432Node\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje] "path"="C:\Program Files (x86)\DealPly\DealPly.crx" Searching for "Babylon" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{2EECD738-5844-4A99-B4B6-146BF802613B}] "DllName"="BabylonToolbar.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}] "DllName"="BabylonToolbar.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{98889811-442D-49DD-99D7-DC866BE87DBC}] "DllName"="BabylonToolbarTlbr.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{2EECD738-5844-4A99-B4B6-146BF802613B}] "DllName"="BabylonToolbar.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}] "DllName"="BabylonToolbar.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{98889811-442D-49DD-99D7-DC866BE87DBC}] "DllName"="BabylonToolbarTlbr.dll" Searching for "Softonic" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\1e40ca8e_0] @="{0.0.0.00000000}.{f8047516-971f-40ba-85de-843482a8264a}|\Device\HarddiskVolume2\Users\PC\Downloads\SoftonicDownloader_fuer_mp3directcut.exe%b{00000000-0000-0000-0000-000000000000}" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\29629339_0] @="{0.0.0.00000000}.{f8047516-971f-40ba-85de-843482a8264a}|\Device\HarddiskVolume2\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe%b{00000000-0000-0000-0000-000000000000}" [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe"="Softonic Downloader " [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_mp3directcut_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_mp3directcut_RASMANCS] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_trustport-internet-security_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_trustport-internet-security_RASMANCS] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\1e40ca8e_0] @="{0.0.0.00000000}.{f8047516-971f-40ba-85de-843482a8264a}|\Device\HarddiskVolume2\Users\PC\Downloads\SoftonicDownloader_fuer_mp3directcut.exe%b{00000000-0000-0000-0000-000000000000}" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\29629339_0] @="{0.0.0.00000000}.{f8047516-971f-40ba-85de-843482a8264a}|\Device\HarddiskVolume2\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe%b{00000000-0000-0000-0000-000000000000}" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe"="Softonic Downloader " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe"="Softonic Downloader " Searching for "delta LTD" No data found. Searching for "PriceGong" [HKEY_CURRENT_USER\Software\PowerPack\225\13] "c"="hxxp://www.powerpackdl.com/downloads/pricegong.exe" [HKEY_CURRENT_USER\Software\PowerPack\225\13] "i"="hxxp://www.pricegong.com/TermsofUse.aspx" [HKEY_CURRENT_USER\Software\PowerPack\225\13] "j"="PriceGong" [HKEY_CURRENT_USER\Software\PowerPack\225\13] "n"="rv:HKCR,AppID\\PriceGongIE.DLL,AppID,{835315FC-1BF6-4CA9-80CD-F6C158D40692}" [HKEY_CURRENT_USER\Software\PowerPack\225\13] "x"="hxxp://www.pricegong.com/favicon.ico" [HKEY_CURRENT_USER\Software\PowerPack\225\13] "y"="hxxp://www.pricegong.com/" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\PriceGong_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\PriceGong_RASMANCS] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\PowerPack\225\13] "c"="hxxp://www.powerpackdl.com/downloads/pricegong.exe" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\PowerPack\225\13] "i"="hxxp://www.pricegong.com/TermsofUse.aspx" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\PowerPack\225\13] "j"="PriceGong" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\PowerPack\225\13] "n"="rv:HKCR,AppID\\PriceGongIE.DLL,AppID,{835315FC-1BF6-4CA9-80CD-F6C158D40692}" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\PowerPack\225\13] "x"="hxxp://www.pricegong.com/favicon.ico" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\PowerPack\225\13] "y"="hxxp://www.pricegong.com/" Searching for "OpenCandy" No data found. Searching for "PerformerSoft" No data found. Searching for "SoftSafe" No data found. Searching for "IBUpdater" No data found. Searching for " " [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\PhotoPrintingWizard\Laser Pro LL2] "PrintTicket"="<?xml version="1.0"?> <psf:PrintTicket version="1" xmlns:xsd="hxxp://www.w3.org/2001/XMLSchema" xmlns:xsi="hxxp://www.w3.org/2001/XMLSchema-instance" xmlns:psf="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemaframework" xmlns:psk="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemakeywords" xmlns:mti="hxxp://schemas.monotypeimaging.com/ptpc/2006/1" xmlns:oem="hxxp://schemas.monotypeimaging.com/ptpc/oem/2006/1"><psf:Feature name="psk:PageOrientation"><psf:Option name="psk:Landscape"/></psf:Feature><!-- --><!-- Monotype Imaging print ticket --><!-- --><!-- --><!-- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\PhotoPrintingWizard\Laser Pro LL2] "PrintCapabilites"="<?xml version="1.0"?> <psf:PrintCapabilities version="1" xmlns:xsd="hxxp://www.w3.org/2001/XMLSchema" xmlns:xsi="hxxp://www.w3.org/2001/XMLSchema-instance" xmlns:psf="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemaframework" xmlns:psk="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemakeywords" xmlns:mti="hxxp://schemas.monotypeimaging.com/ptpc/2006/1" xmlns:oem="hxxp://schemas.monotypeimaging.com/ptpc/oem/2006/1"><!-- --><!-- Monotype Imaging print capabilities --><!-- --><!-- --><!-- JobComment --><!-- [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "G:\Menu.exe"="CnMemory Software " [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe"="Softonic Downloader " [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Desktop\TrustPort_Internet_Security_12.0.0.4788.exe"="TrustPort Internet Security " [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WSMAN\Plugin\Microsoft.PowerShell] "ConfigXML"=" <PlugInConfiguration xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Name="microsoft.powershell" Filename="%windir%\system32\pwrshplugin.dll" SDKVersion="1" XmlRenderingType="text" > <InitializationParameters> <Param Name="PSVersion" Value="2.0"/> </InitializationParameters> <Resources> <Resource ResourceUri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell" SupportsOptions="true" ExactMatch="true"> <Security xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Uri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell" ExactMatch="true" Sddl="O:NSG:BAD:P(A;;GA;;;BA)S:P(AU;FA;GA;;;WD)(AU;SA;GXGW;;;WD)"/> <Capability Type="Shell"/> </Resource> </Res [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\WSMAN\Plugin\Microsoft.PowerShell32] "ConfigXML"="<PlugInConfiguration xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Name="microsoft.powershell32" Filename="%windir%\system32\pwrshplugin.dll" SDKVersion="1" XmlRenderingType="text" Architecture="32" > <InitializationParameters> <Param Name="PSVersion" Value="2.0"/> </InitializationParameters> <Resources> <Resource ResourceUri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell32" SupportsOptions="true" ExactMatch="true"> <Security xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Uri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell32" ExactMatch="true" Sddl="O:NSG:BAD:P(A;;GA;;;BA)S:P(AU;FA;GA;;;WD)(AU;SA;GXGW;;;WD)"/> [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&10D4990&0&__ ______&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&10D4990&0&__ ______&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&11AC6715&0&_ _______&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&11AC6715&0&_ _______&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&2706475&0&__ ______&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&2706475&0&__ ______&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&10D4990&0&__ ______&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&10D4990&0&__ ______&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&11AC6715&0&_ _______&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&11AC6715&0&_ _______&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&2706475&0&__ ______&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&2706475&0&__ ______&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&10D4990& 0&________&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&10D4990& 0&________&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&11AC6715 &0&________&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&11AC6715 &0&________&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&2706475& 0&________&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&2706475& 0&________&1#] "DeviceDesc"="NERO " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\PhotoPrintingWizard\Laser Pro LL2] "PrintTicket"="<?xml version="1.0"?> <psf:PrintTicket version="1" xmlns:xsd="hxxp://www.w3.org/2001/XMLSchema" xmlns:xsi="hxxp://www.w3.org/2001/XMLSchema-instance" xmlns:psf="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemaframework" xmlns:psk="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemakeywords" xmlns:mti="hxxp://schemas.monotypeimaging.com/ptpc/2006/1" xmlns:oem="hxxp://schemas.monotypeimaging.com/ptpc/oem/2006/1"><psf:Feature name="psk:PageOrientation"><psf:Option name="psk:Landscape"/></psf:Feature><!-- --><!-- Monotype Imaging print ticket --><!-- --><!-- --><!-- [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\PhotoPrintingWizard\Laser Pro LL2] "PrintCapabilites"="<?xml version="1.0"?> <psf:PrintCapabilities version="1" xmlns:xsd="hxxp://www.w3.org/2001/XMLSchema" xmlns:xsi="hxxp://www.w3.org/2001/XMLSchema-instance" xmlns:psf="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemaframework" xmlns:psk="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemakeywords" xmlns:mti="hxxp://schemas.monotypeimaging.com/ptpc/2006/1" xmlns:oem="hxxp://schemas.monotypeimaging.com/ptpc/oem/2006/1"><!-- --><!-- Monotype Imaging print capabilities --><!-- --><!-- --><!-- JobComment --><!-- [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "G:\Menu.exe"="CnMemory Software " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe"="Softonic Downloader " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Desktop\TrustPort_Internet_Security_12.0.0.4788.exe"="TrustPort Internet Security " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "G:\Menu.exe"="CnMemory Software " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe"="Softonic Downloader " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Desktop\TrustPort_Internet_Security_12.0.0.4788.exe"="TrustPort Internet Security " -= EOF =- Sooo, der PC läuft wieder ganz gut- dafür erstmal sehr herzlichen Dank! Der hat nur noch beim Hochfahren einige Schwierigkeiten z.B. wenn man sein PW eingegeben hat, dann braucht der einige Zeit bis sich der PC öffnet. Und beim Hochfahren bleibt es zunächst lange Zeit schwarz, bis ich beim Benutzerkonto meinen PW eingeben kann. Wie kann ich mich in Zukunft vor Viren etc. schützen? Was könntest du mir empfehlen? :=) |
Servus, Zitat:
Zitat:
Zitat:
Du hast dich schon wieder mit Adware infiziert: Zitat:
Jetzt können wir wieder von vorne anfangen... :balla: Schritt 1 Downloade Dir bitte ![]()
Schritt 2 Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Schritt 3 Downloade Dir bitte ![]()
Bitte poste mit deiner nächsten Antwort
|
Zitat:
Zitat:
Code: # AdwCleaner v2.306 - Datei am 06/08/2013 um 14:37:07 erstellt Code: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Malwarebytes Anti-Malware (Test) 1.75.0.1300 Malwarebytes : Free anti-malware download Datenbank Version: v2013.08.06.03 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 PC :: PC-HP [Administrator] Schutz: Aktiviert 06.08.2013 14:56:43 mbam-log-2013-08-06 (14-56-43).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 214077 Laufzeit: 8 Minute(n), 31 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) |
Servus, ok, und jetzt nochmal das hier: Schritt 1 Kontrollscan mit FRST Führe wie zuvor beschrieben einen Scan mit FRST aus. Setze dazu eine Haken bei Addition.txt rechts unten und klicke auf Scan. Es werden wieder zwei Logdateien erzeugt. Poste mir diese. Schritt 2 Lade SystemLook von jpshortstuff vom folgenden Spiegel herunter und speichere das Tool auf dem Desktop. SystemLook (64 bit)
Bitte poste mit deiner nächsten Antwort
|
FRST Logfile: FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-08-2013 --- --- --- --- --- --- FRST Additions Logfile: Code: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 04-08-2013 SystemLook 30.07.11 by jpshortstuff Log created at 19:08 on 06/08/2013 by PC Administrator - Elevation successful No Context: :filefind No Context: *systweak* No Context: *adawarebp* No Context: *datamngr* No Context: *lyrixeeker* No Context: *mypc backup* No Context: *speedupmypc* No Context: *sweetim* No Context: *distromatic* No Context: *BabSolution* No Context: *bProtector* No Context: *BrowserDefender* No Context: *iLivid* No Context: *holasearch* No Context: *DealPly* No Context: *Babylon* No Context: *Softonic* No Context: *delta LTD* No Context: *PriceGong* No Context: *OpenCandy* No Context: *PerformerSoft* No Context: *SoftSafe* No Context: *IBUpdater* ========== folderfind ========== Searching for "*systweak*" No folders found. Searching for "*adawarebp*" No folders found. Searching for "*datamngr*" No folders found. Searching for "*lyrixeeker*" No folders found. Searching for "*mypc backup*" No folders found. Searching for "*speedupmypc*" No folders found. Searching for "*sweetim*" No folders found. Searching for "*distromatic*" No folders found. Searching for "*BabSolution*" No folders found. Searching for "*bProtector*" No folders found. Searching for "*BrowserDefender*" No folders found. Searching for "*iLivid*" No folders found. Searching for "*holasearch*" No folders found. Searching for "*DealPly*" No folders found. Searching for "*Babylon*" No folders found. Searching for "*Softonic*" No folders found. Searching for "*delta LTD*" No folders found. Searching for "*PriceGong*" No folders found. Searching for "*OpenCandy*" No folders found. Searching for "*PerformerSoft*" No folders found. Searching for "*SoftSafe*" No folders found. Searching for "*IBUpdater*" No folders found. ========== regfind ========== Searching for "systweak" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\systweakasp_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\systweakasp_RASMANCS] Searching for "adawarebp" [HKEY_CURRENT_USER\Software\AppDataLow\Software\adawarebp] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Ad-Aware Browsing Protection] "command"=""C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe"" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\adawarebp_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\adawarebp_RASDLG] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\adawarebp_RASMANCS] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\AppDataLow\Software\adawarebp] Searching for "datamngr" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DATAMNGR] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DATAMNGR] "item"="DATAMNGR" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DATAMNGR] "command"="C:\PROGRA~2\SEARCH~1\Datamngr\DATAMN~1.EXE" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4E704E34-0FD7-4216-8B49-E4A8C853DB34}] "AppPath"="C:\PROGRA~2\SEARCH~1\Datamngr\SRTOOL~1" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0028FE51-2BFF-4A35-8266-0D10A6A4DF27}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe|Name=Search-Results Toolbar DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F8BD6963-EDBD-44DD-A5DA-038F96222E8A}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe|Name=Search-Results Toolbar DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0028FE51-2BFF-4A35-8266-0D10A6A4DF27}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe|Name=Search-Results Toolbar DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F8BD6963-EDBD-44DD-A5DA-038F96222E8A}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe|Name=Search-Results Toolbar DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0028FE51-2BFF-4A35-8266-0D10A6A4DF27}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe|Name=Search-Results Toolbar DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F8BD6963-EDBD-44DD-A5DA-038F96222E8A}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe|Name=Search-Results Toolbar DTX Broker|" Searching for "lyrixeeker" [HKEY_CURRENT_USER\Software\AppDataLow\Software\LyriXeeker] [HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions] "lyrix@lyrixeeker.co"="C:\Program Files (x86)\LyriXeeker\125.xpi" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\epojlgbehpaeekopencdagbdamnkppci] "Path"="C:\Program Files (x86)\LyriXeeker\125.crx" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\lyrix@lyrixeeker.co] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\lyrix@lyrixeeker.co] "Publisher"="LyriXeeker Tech" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\lyrix@lyrixeeker.co] "UninstallString"="C:\Program Files (x86)\LyriXeeker\uninstall.exe" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\AppDataLow\Software\LyriXeeker] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Mozilla\Firefox\Extensions] "lyrix@lyrixeeker.co"="C:\Program Files (x86)\LyriXeeker\125.xpi" Searching for "mypc backup" No data found. Searching for "speedupmypc" No data found. Searching for "sweetim" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3199093499-978631591-3148159529-1001\Software\SweetIM] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Sweetpacks Communicator] "command"="C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\02F47BF73B948514FAACADD8CBBDF37D] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\080D9F5E1E95FEE4794CE438E635239E] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgxml_wrapper.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\12BF94BD06C95F343A77631402B9556A] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1E264E0A5959A1C46BA9175A878B12EA] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgconfig.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2124D8A8CF720FD44866190AF560228E] "254796BF4AC84B64891B61C529A2E23F"="C:\ProgramData\SweetIM\Communicator\conf\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\27A325ACED8CA4743A30127638591ADB] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\mgsimcommon.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E6768B6932D112438F047C54D180635] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\ClearHist.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\350D17402BD84234EAF7D32F08172D7C] "254796BF4AC84B64891B61C529A2E23F"="C:\ProgramData\SweetIM\Communicator\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\351716A953E21214898904032EAE2E81] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\397C771A7BCAC904697C3EC629ED33ED] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgHelper.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3EE8C5F419057E1478A654868CEE60B5] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4735D908D66E1BA46B6C2D7185A12B2B] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\resources\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\69D6A6B2ED56AF24EA6335EAD6E91CA4] "16FE85B52F587794795A481CF9295697"="C?\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgHelperApp.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\76D8378E2DDAED3428720A631F6E3BF0] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\resources\sqlite\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7FFA128C2B0FF414D805FC5627883401] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mghooking.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86EDC790504E1834DBC20C9A04328FD2] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\green\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97C3D0F82E712E241A2F969F45E3351C] "16FE85B52F587794795A481CF9295697"="C?\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarProxy.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\98CC8BF5A4A6E6C4ABF7051DDAB8B058] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9A001B259DB7D694E818BE29B973992C] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9E7F556BF224D804D96A96F0F6344789] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\blue\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A189D17A469616C4688D23E192996267] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mglogger.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BAE2EC163C6A68A48921573E0E7E199D] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\mgcommunication.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BF4F885EDEE45644EB1E0C99E0162399] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\Microsoft.VC90.CRT\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C06C6662FA5B04646829E4A460857770] "254796BF4AC84B64891B61C529A2E23F"="C:\ProgramData\SweetIM\Communicator\Logs\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CE21F3FD57B244142880EF15A165A156] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\orange\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CEEB3E14ABE8270419B0FD762E18F7C6] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\mgcommon.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D15DAF33C220F91468A1D7D57C31ACD7] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\conf\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D3BA76A44C779424889063D5098ED2D6] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgcommon.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D6D0EB9FDBD90C04D92A7E729058F10D] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E4748F9A4181FCE46A23C13B517B9420] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgsimcommon.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ED1B5E9A3BDB51349BF96E842C062D98] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\Microsoft.VC90.CRT\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FECBC2BC14DA6CD459BD59A041709836] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\mgxml_wrapper.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\16FE85B52F587794795A481CF9295697\InstallProperties] "Contact"="SweetIM Technical Support Department" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\16FE85B52F587794795A481CF9295697\InstallProperties] "HelpLink"="hxxp://www.sweetim.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\16FE85B52F587794795A481CF9295697\InstallProperties] "InstallLocation"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\16FE85B52F587794795A481CF9295697\InstallProperties] "Publisher"="SweetIM Technologies Ltd." [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\16FE85B52F587794795A481CF9295697\InstallProperties] "URLInfoAbout"="hxxp://www.sweetim.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\16FE85B52F587794795A481CF9295697\InstallProperties] "URLUpdateInfo"="hxxp://www.sweetim.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\254796BF4AC84B64891B61C529A2E23F\InstallProperties] "Contact"="SweetIM Technical Support Department" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\254796BF4AC84B64891B61C529A2E23F\InstallProperties] "HelpLink"="hxxp://www.sweetim.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\254796BF4AC84B64891B61C529A2E23F\InstallProperties] "InstallLocation"="C:\Program Files (x86)\SweetIM\Communicator\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\254796BF4AC84B64891B61C529A2E23F\InstallProperties] "Publisher"="SweetIM Technologies Ltd." [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\254796BF4AC84B64891B61C529A2E23F\InstallProperties] "URLInfoAbout"="hxxp://www.sweetim.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\254796BF4AC84B64891B61C529A2E23F\InstallProperties] "URLUpdateInfo"="hxxp://www.sweetim.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\toolbar_vit_sweetim_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\toolbar_vit_sweetim_RASMANCS] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{A21972B4-5118-42E3-B07B-3ABF8F630877}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe|Name=SweetPacksUpdateManager|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F0F839E5-89DE-4467-9E52-606055705D06}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe|Name=SweetPacksUpdateManager|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{A21972B4-5118-42E3-B07B-3ABF8F630877}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe|Name=SweetPacksUpdateManager|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F0F839E5-89DE-4467-9E52-606055705D06}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe|Name=SweetPacksUpdateManager|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{A21972B4-5118-42E3-B07B-3ABF8F630877}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe|Name=SweetPacksUpdateManager|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F0F839E5-89DE-4467-9E52-606055705D06}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe|Name=SweetPacksUpdateManager|" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3199093499-978631591-3148159529-1001\Software\SweetIM] Searching for "distromatic" No data found. Searching for "BabSolution" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\fagpjgjmoaccgkkpjeoinehnoaimnbla] "path"="C:\Users\PC\AppData\Roaming\BabSolution\CR\hola.crx" Searching for "bProtector" No data found. Searching for "BrowserDefender" [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\ProgramData\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe"="Application Manager" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{2A0F3D1B-0909-4FF4-B272-609CCE6054E7}] "DllName"="PCTBrowserDefender.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{472734EA-242A-422B-ADF8-83D1E48CC825}] "DllName"="PCTBrowserDefender.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{424202EF-76FA-4231-BF7A-5153EB49F987}] "Path"="\BrowserDefendert" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BrowserDefendert] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{2A0F3D1B-0909-4FF4-B272-609CCE6054E7}] "DllName"="PCTBrowserDefender.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{472734EA-242A-422B-ADF8-83D1E48CC825}] "DllName"="PCTBrowserDefender.dll" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\ProgramData\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe"="Application Manager" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\ProgramData\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe"="Application Manager" Searching for "iLivid" [HKEY_CURRENT_USER\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\C:\Users\PC\AppData\Local\iLivid] [HKEY_CURRENT_USER\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.8.false\C:\Users\PC\AppData\Local\iLivid] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\C:\Users\PC\AppData\Local\iLivid] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.8.false\C:\Users\PC\AppData\Local\iLivid] Searching for "holasearch" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "hp_url"="hxxp://www.holasearch.com/?babsrc=HP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "nt_url"="hxxp://www.holasearch.com/?babsrc=NT_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "dsFFX"="holasearch" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "uninstaller"="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\uninstall.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "sp_url"="hxxp://www.holasearch.com/?q={searchTerms}&babsrc=SP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "tb_url"="hxxp://www.holasearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "kw_url"="hxxp://www.holasearch.com/?babsrc=SP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927&q=" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\esrv.holasearchESrvc] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\esrv.holasearchESrvc\CurVer] @="esrv.holasearchESrvc.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\esrv.holasearchESrvc.1] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchappCore] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchappCore\CurVer] @="holasearch.holasearchappCore.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchappCore.1] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchdskBnd] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchdskBnd\CurVer] @="holasearch.holasearchdskBnd.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchdskBnd.1] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchHlpr] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchHlpr\CurVer] @="holasearch.holasearchHlpr.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchHlpr.1] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}\1.0\0\win32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchsrv.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}\1.0\HELPDIR] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0] @="holasearchCmn 1.0 Type Library" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0\0\win32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchEng.dll\2" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0\HELPDIR] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1E44819B-54E1-411B-9D9F-38D7B913BCF2}\InprocServer32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchEng.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}\LocalServer32] @=""C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchsrv.exe"" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}\ProgID] @="esrv.holasearchESrvc.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}\VersionIndependentProgID] @="esrv.holasearchESrvc" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}\InprocServer32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchApp.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}\ProgID] @="holasearch.holasearchappCore.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}\VersionIndependentProgID] @="holasearch.holasearchappCore" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C46EFEA4-B0F3-428B-9E77-650E3634EC56}\InprocServer32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\bh\holasearch.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "hp_url"="hxxp://www.holasearch.com/?babsrc=HP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "nt_url"="hxxp://www.holasearch.com/?babsrc=NT_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "dsFFX"="holasearch" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "uninstaller"="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\uninstall.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "sp_url"="hxxp://www.holasearch.com/?q={searchTerms}&babsrc=SP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "tb_url"="hxxp://www.holasearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "kw_url"="hxxp://www.holasearch.com/?babsrc=SP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927&q=" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}\1.0\0\win32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchsrv.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}\1.0\HELPDIR] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0] @="holasearchCmn 1.0 Type Library" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0\0\win32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchEng.dll\2" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0\HELPDIR] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5882DB3D-175D-4CDC-A030-1B7EC2BC8EC6}] "AppName"="holasearchsrv.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5882DB3D-175D-4CDC-A030-1B7EC2BC8EC6}] "AppPath"="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{1E44819B-54E1-411B-9D9F-38D7B913BCF2}\InprocServer32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchEng.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}\LocalServer32] @=""C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchsrv.exe"" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}\ProgID] @="esrv.holasearchESrvc.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}\VersionIndependentProgID] @="esrv.holasearchESrvc" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}\InprocServer32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchApp.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}\ProgID] @="holasearch.holasearchappCore.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}\VersionIndependentProgID] @="holasearch.holasearchappCore" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{C46EFEA4-B0F3-428B-9E77-650E3634EC56}\InprocServer32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\bh\holasearch.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "hp_url"="hxxp://www.holasearch.com/?babsrc=HP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "nt_url"="hxxp://www.holasearch.com/?babsrc=NT_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "dsFFX"="holasearch" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "uninstaller"="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\uninstall.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "sp_url"="hxxp://www.holasearch.com/?q={searchTerms}&babsrc=SP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "tb_url"="hxxp://www.holasearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "kw_url"="hxxp://www.holasearch.com/?babsrc=SP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927&q=" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}\1.0\0\win32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchsrv.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}\1.0\HELPDIR] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0] @="holasearchCmn 1.0 Type Library" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0\0\win32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchEng.dll\2" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0\HELPDIR] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" Searching for "DealPly" [HKEY_CURRENT_USER\Software\Wow6432Node\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje] "path"="C:\Program Files (x86)\DealPly\DealPly.crx" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{296BED8D-8F7A-40EE-AFDD-642839AC7E7F}] "Path"="\DealPlyUpdate" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AC019BF5-2EB9-4103-AEE1-09CD370F4CBB}] "Path"="\DealPly" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPly] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPlyUpdate] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Wow6432Node\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje] "path"="C:\Program Files (x86)\DealPly\DealPly.crx" Searching for "Babylon" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{2EECD738-5844-4A99-B4B6-146BF802613B}] "DllName"="BabylonToolbar.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}] "DllName"="BabylonToolbar.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{98889811-442D-49DD-99D7-DC866BE87DBC}] "DllName"="BabylonToolbarTlbr.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{2EECD738-5844-4A99-B4B6-146BF802613B}] "DllName"="BabylonToolbar.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}] "DllName"="BabylonToolbar.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{98889811-442D-49DD-99D7-DC866BE87DBC}] "DllName"="BabylonToolbarTlbr.dll" Searching for "Softonic" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\1e40ca8e_0] @="{0.0.0.00000000}.{f8047516-971f-40ba-85de-843482a8264a}|\Device\HarddiskVolume2\Users\PC\Downloads\SoftonicDownloader_fuer_mp3directcut.exe%b{00000000-0000-0000-0000-000000000000}" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\29629339_0] @="{0.0.0.00000000}.{f8047516-971f-40ba-85de-843482a8264a}|\Device\HarddiskVolume2\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe%b{00000000-0000-0000-0000-000000000000}" [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe"="Softonic Downloader " [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_mp3directcut_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_mp3directcut_RASMANCS] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_trustport-internet-security_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_trustport-internet-security_RASMANCS] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\1e40ca8e_0] @="{0.0.0.00000000}.{f8047516-971f-40ba-85de-843482a8264a}|\Device\HarddiskVolume2\Users\PC\Downloads\SoftonicDownloader_fuer_mp3directcut.exe%b{00000000-0000-0000-0000-000000000000}" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\29629339_0] @="{0.0.0.00000000}.{f8047516-971f-40ba-85de-843482a8264a}|\Device\HarddiskVolume2\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe%b{00000000-0000-0000-0000-000000000000}" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe"="Softonic Downloader " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe"="Softonic Downloader " Searching for "delta LTD" No data found. Searching for "PriceGong" [HKEY_CURRENT_USER\Software\PowerPack\225\13] "c"="hxxp://www.powerpackdl.com/downloads/pricegong.exe" [HKEY_CURRENT_USER\Software\PowerPack\225\13] "i"="hxxp://www.pricegong.com/TermsofUse.aspx" [HKEY_CURRENT_USER\Software\PowerPack\225\13] "j"="PriceGong" [HKEY_CURRENT_USER\Software\PowerPack\225\13] "n"="rv:HKCR,AppID\\PriceGongIE.DLL,AppID,{835315FC-1BF6-4CA9-80CD-F6C158D40692}" [HKEY_CURRENT_USER\Software\PowerPack\225\13] "x"="hxxp://www.pricegong.com/favicon.ico" [HKEY_CURRENT_USER\Software\PowerPack\225\13] "y"="hxxp://www.pricegong.com/" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\PriceGong_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\PriceGong_RASMANCS] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\PowerPack\225\13] "c"="hxxp://www.powerpackdl.com/downloads/pricegong.exe" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\PowerPack\225\13] "i"="hxxp://www.pricegong.com/TermsofUse.aspx" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\PowerPack\225\13] "j"="PriceGong" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\PowerPack\225\13] "n"="rv:HKCR,AppID\\PriceGongIE.DLL,AppID,{835315FC-1BF6-4CA9-80CD-F6C158D40692}" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\PowerPack\225\13] "x"="hxxp://www.pricegong.com/favicon.ico" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\PowerPack\225\13] "y"="hxxp://www.pricegong.com/" Searching for "OpenCandy" No data found. Searching for "PerformerSoft" No data found. Searching for "SoftSafe" No data found. Searching for "IBUpdater" No data found. Searching for " " [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\PhotoPrintingWizard\Laser Pro LL2] "PrintTicket"="<?xml version="1.0"?> <psf:PrintTicket version="1" xmlns:xsd="hxxp://www.w3.org/2001/XMLSchema" xmlns:xsi="hxxp://www.w3.org/2001/XMLSchema-instance" xmlns:psf="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemaframework" xmlns:psk="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemakeywords" xmlns:mti="hxxp://schemas.monotypeimaging.com/ptpc/2006/1" xmlns:oem="hxxp://schemas.monotypeimaging.com/ptpc/oem/2006/1"><psf:Feature name="psk:PageOrientation"><psf:Option name="psk:Landscape"/></psf:Feature><!-- --><!-- Monotype Imaging print ticket --><!-- --><!-- --><!-- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\PhotoPrintingWizard\Laser Pro LL2] "PrintCapabilites"="<?xml version="1.0"?> <psf:PrintCapabilities version="1" xmlns:xsd="hxxp://www.w3.org/2001/XMLSchema" xmlns:xsi="hxxp://www.w3.org/2001/XMLSchema-instance" xmlns:psf="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemaframework" xmlns:psk="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemakeywords" xmlns:mti="hxxp://schemas.monotypeimaging.com/ptpc/2006/1" xmlns:oem="hxxp://schemas.monotypeimaging.com/ptpc/oem/2006/1"><!-- --><!-- Monotype Imaging print capabilities --><!-- --><!-- --><!-- JobComment --><!-- [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "G:\Menu.exe"="CnMemory Software " [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe"="Softonic Downloader " [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Desktop\TrustPort_Internet_Security_12.0.0.4788.exe"="TrustPort Internet Security " [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WSMAN\Plugin\Microsoft.PowerShell] "ConfigXML"=" <PlugInConfiguration xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Name="microsoft.powershell" Filename="%windir%\system32\pwrshplugin.dll" SDKVersion="1" XmlRenderingType="text" > <InitializationParameters> <Param Name="PSVersion" Value="2.0"/> </InitializationParameters> <Resources> <Resource ResourceUri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell" SupportsOptions="true" ExactMatch="true"> <Security xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Uri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell" ExactMatch="true" Sddl="O:NSG:BAD:P(A;;GA;;;BA)S:P(AU;FA;GA;;;WD)(AU;SA;GXGW;;;WD)"/> <Capability Type="Shell"/> </Resource> </Res [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\WSMAN\Plugin\Microsoft.PowerShell32] "ConfigXML"="<PlugInConfiguration xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Name="microsoft.powershell32" Filename="%windir%\system32\pwrshplugin.dll" SDKVersion="1" XmlRenderingType="text" Architecture="32" > <InitializationParameters> <Param Name="PSVersion" Value="2.0"/> </InitializationParameters> <Resources> <Resource ResourceUri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell32" SupportsOptions="true" ExactMatch="true"> <Security xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Uri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell32" ExactMatch="true" Sddl="O:NSG:BAD:P(A;;GA;;;BA)S:P(AU;FA;GA;;;WD)(AU;SA;GXGW;;;WD)"/> [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&10D4990&0&__ ______&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&10D4990&0&__ ______&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&11AC6715&0&_ _______&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&11AC6715&0&_ _______&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&2706475&0&__ ______&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&2706475&0&__ ______&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&10D4990&0&__ ______&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&10D4990&0&__ ______&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&11AC6715&0&_ _______&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&11AC6715&0&_ _______&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&2706475&0&__ ______&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&2706475&0&__ ______&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&10D4990& 0&________&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&10D4990& 0&________&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&11AC6715 &0&________&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&11AC6715 &0&________&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&2706475& 0&________&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&2706475& 0&________&1#] "DeviceDesc"="NERO " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\PhotoPrintingWizard\Laser Pro LL2] "PrintTicket"="<?xml version="1.0"?> <psf:PrintTicket version="1" xmlns:xsd="hxxp://www.w3.org/2001/XMLSchema" xmlns:xsi="hxxp://www.w3.org/2001/XMLSchema-instance" xmlns:psf="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemaframework" xmlns:psk="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemakeywords" xmlns:mti="hxxp://schemas.monotypeimaging.com/ptpc/2006/1" xmlns:oem="hxxp://schemas.monotypeimaging.com/ptpc/oem/2006/1"><psf:Feature name="psk:PageOrientation"><psf:Option name="psk:Landscape"/></psf:Feature><!-- --><!-- Monotype Imaging print ticket --><!-- --><!-- --><!-- [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\PhotoPrintingWizard\Laser Pro LL2] "PrintCapabilites"="<?xml version="1.0"?> <psf:PrintCapabilities version="1" xmlns:xsd="hxxp://www.w3.org/2001/XMLSchema" xmlns:xsi="hxxp://www.w3.org/2001/XMLSchema-instance" xmlns:psf="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemaframework" xmlns:psk="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemakeywords" xmlns:mti="hxxp://schemas.monotypeimaging.com/ptpc/2006/1" xmlns:oem="hxxp://schemas.monotypeimaging.com/ptpc/oem/2006/1"><!-- --><!-- Monotype Imaging print capabilities --><!-- --><!-- --><!-- JobComment --><!-- [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "G:\Menu.exe"="CnMemory Software " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe"="Softonic Downloader " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Desktop\TrustPort_Internet_Security_12.0.0.4788.exe"="TrustPort Internet Security " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "G:\Menu.exe"="CnMemory Software " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe"="Softonic Downloader " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Desktop\TrustPort_Internet_Security_12.0.0.4788.exe"="TrustPort Internet Security " -= EOF =- |
SystemLook 30.07.11 by jpshortstuff Log created at 19:08 on 06/08/2013 by PC Administrator - Elevation successful No Context: :filefind No Context: *systweak* No Context: *adawarebp* No Context: *datamngr* No Context: *lyrixeeker* No Context: *mypc backup* No Context: *speedupmypc* No Context: *sweetim* No Context: *distromatic* No Context: *BabSolution* No Context: *bProtector* No Context: *BrowserDefender* No Context: *iLivid* No Context: *holasearch* No Context: *DealPly* No Context: *Babylon* No Context: *Softonic* No Context: *delta LTD* No Context: *PriceGong* No Context: *OpenCandy* No Context: *PerformerSoft* No Context: *SoftSafe* No Context: *IBUpdater* ========== folderfind ========== Searching for "*systweak*" No folders found. Searching for "*adawarebp*" No folders found. Searching for "*datamngr*" No folders found. Searching for "*lyrixeeker*" No folders found. Searching for "*mypc backup*" No folders found. Searching for "*speedupmypc*" No folders found. Searching for "*sweetim*" No folders found. Searching for "*distromatic*" No folders found. Searching for "*BabSolution*" No folders found. Searching for "*bProtector*" No folders found. Searching for "*BrowserDefender*" No folders found. Searching for "*iLivid*" No folders found. Searching for "*holasearch*" No folders found. Searching for "*DealPly*" No folders found. Searching for "*Babylon*" No folders found. Searching for "*Softonic*" No folders found. Searching for "*delta LTD*" No folders found. Searching for "*PriceGong*" No folders found. Searching for "*OpenCandy*" No folders found. Searching for "*PerformerSoft*" No folders found. Searching for "*SoftSafe*" No folders found. Searching for "*IBUpdater*" No folders found. ========== regfind ========== Searching for "systweak" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\systweakasp_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\systweakasp_RASMANCS] Searching for "adawarebp" [HKEY_CURRENT_USER\Software\AppDataLow\Software\adawarebp] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Ad-Aware Browsing Protection] "command"=""C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe"" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\adawarebp_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\adawarebp_RASDLG] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\adawarebp_RASMANCS] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\AppDataLow\Software\adawarebp] Searching for "datamngr" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DATAMNGR] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DATAMNGR] "item"="DATAMNGR" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DATAMNGR] "command"="C:\PROGRA~2\SEARCH~1\Datamngr\DATAMN~1.EXE" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4E704E34-0FD7-4216-8B49-E4A8C853DB34}] "AppPath"="C:\PROGRA~2\SEARCH~1\Datamngr\SRTOOL~1" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0028FE51-2BFF-4A35-8266-0D10A6A4DF27}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe|Name=Search-Results Toolbar DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F8BD6963-EDBD-44DD-A5DA-038F96222E8A}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe|Name=Search-Results Toolbar DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0028FE51-2BFF-4A35-8266-0D10A6A4DF27}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe|Name=Search-Results Toolbar DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F8BD6963-EDBD-44DD-A5DA-038F96222E8A}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe|Name=Search-Results Toolbar DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0028FE51-2BFF-4A35-8266-0D10A6A4DF27}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe|Name=Search-Results Toolbar DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F8BD6963-EDBD-44DD-A5DA-038F96222E8A}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe|Name=Search-Results Toolbar DTX Broker|" Searching for "lyrixeeker" [HKEY_CURRENT_USER\Software\AppDataLow\Software\LyriXeeker] [HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions] "lyrix@lyrixeeker.co"="C:\Program Files (x86)\LyriXeeker\125.xpi" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\epojlgbehpaeekopencdagbdamnkppci] "Path"="C:\Program Files (x86)\LyriXeeker\125.crx" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\lyrix@lyrixeeker.co] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\lyrix@lyrixeeker.co] "Publisher"="LyriXeeker Tech" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\lyrix@lyrixeeker.co] "UninstallString"="C:\Program Files (x86)\LyriXeeker\uninstall.exe" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\AppDataLow\Software\LyriXeeker] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Mozilla\Firefox\Extensions] "lyrix@lyrixeeker.co"="C:\Program Files (x86)\LyriXeeker\125.xpi" Searching for "mypc backup" No data found. Searching for "speedupmypc" No data found. Searching for "sweetim" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3199093499-978631591-3148159529-1001\Software\SweetIM] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Sweetpacks Communicator] "command"="C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\02F47BF73B948514FAACADD8CBBDF37D] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\080D9F5E1E95FEE4794CE438E635239E] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgxml_wrapper.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\12BF94BD06C95F343A77631402B9556A] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1E264E0A5959A1C46BA9175A878B12EA] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgconfig.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2124D8A8CF720FD44866190AF560228E] "254796BF4AC84B64891B61C529A2E23F"="C:\ProgramData\SweetIM\Communicator\conf\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\27A325ACED8CA4743A30127638591ADB] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\mgsimcommon.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E6768B6932D112438F047C54D180635] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\ClearHist.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\350D17402BD84234EAF7D32F08172D7C] "254796BF4AC84B64891B61C529A2E23F"="C:\ProgramData\SweetIM\Communicator\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\351716A953E21214898904032EAE2E81] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\397C771A7BCAC904697C3EC629ED33ED] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgHelper.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3EE8C5F419057E1478A654868CEE60B5] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4735D908D66E1BA46B6C2D7185A12B2B] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\resources\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\69D6A6B2ED56AF24EA6335EAD6E91CA4] "16FE85B52F587794795A481CF9295697"="C?\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgHelperApp.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\76D8378E2DDAED3428720A631F6E3BF0] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\resources\sqlite\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7FFA128C2B0FF414D805FC5627883401] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mghooking.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86EDC790504E1834DBC20C9A04328FD2] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\green\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97C3D0F82E712E241A2F969F45E3351C] "16FE85B52F587794795A481CF9295697"="C?\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarProxy.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\98CC8BF5A4A6E6C4ABF7051DDAB8B058] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9A001B259DB7D694E818BE29B973992C] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9E7F556BF224D804D96A96F0F6344789] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\blue\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A189D17A469616C4688D23E192996267] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mglogger.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BAE2EC163C6A68A48921573E0E7E199D] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\mgcommunication.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BF4F885EDEE45644EB1E0C99E0162399] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\Microsoft.VC90.CRT\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C06C6662FA5B04646829E4A460857770] "254796BF4AC84B64891B61C529A2E23F"="C:\ProgramData\SweetIM\Communicator\Logs\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CE21F3FD57B244142880EF15A165A156] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\orange\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CEEB3E14ABE8270419B0FD762E18F7C6] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\mgcommon.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D15DAF33C220F91468A1D7D57C31ACD7] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\conf\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D3BA76A44C779424889063D5098ED2D6] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgcommon.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D6D0EB9FDBD90C04D92A7E729058F10D] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E4748F9A4181FCE46A23C13B517B9420] "16FE85B52F587794795A481CF9295697"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgsimcommon.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ED1B5E9A3BDB51349BF96E842C062D98] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\Microsoft.VC90.CRT\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FECBC2BC14DA6CD459BD59A041709836] "254796BF4AC84B64891B61C529A2E23F"="C:\Program Files (x86)\SweetIM\Communicator\mgxml_wrapper.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\16FE85B52F587794795A481CF9295697\InstallProperties] "Contact"="SweetIM Technical Support Department" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\16FE85B52F587794795A481CF9295697\InstallProperties] "HelpLink"="hxxp://www.sweetim.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\16FE85B52F587794795A481CF9295697\InstallProperties] "InstallLocation"="C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\16FE85B52F587794795A481CF9295697\InstallProperties] "Publisher"="SweetIM Technologies Ltd." [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\16FE85B52F587794795A481CF9295697\InstallProperties] "URLInfoAbout"="hxxp://www.sweetim.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\16FE85B52F587794795A481CF9295697\InstallProperties] "URLUpdateInfo"="hxxp://www.sweetim.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\254796BF4AC84B64891B61C529A2E23F\InstallProperties] "Contact"="SweetIM Technical Support Department" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\254796BF4AC84B64891B61C529A2E23F\InstallProperties] "HelpLink"="hxxp://www.sweetim.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\254796BF4AC84B64891B61C529A2E23F\InstallProperties] "InstallLocation"="C:\Program Files (x86)\SweetIM\Communicator\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\254796BF4AC84B64891B61C529A2E23F\InstallProperties] "Publisher"="SweetIM Technologies Ltd." [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\254796BF4AC84B64891B61C529A2E23F\InstallProperties] "URLInfoAbout"="hxxp://www.sweetim.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\254796BF4AC84B64891B61C529A2E23F\InstallProperties] "URLUpdateInfo"="hxxp://www.sweetim.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\toolbar_vit_sweetim_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\toolbar_vit_sweetim_RASMANCS] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{A21972B4-5118-42E3-B07B-3ABF8F630877}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe|Name=SweetPacksUpdateManager|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F0F839E5-89DE-4467-9E52-606055705D06}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe|Name=SweetPacksUpdateManager|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{A21972B4-5118-42E3-B07B-3ABF8F630877}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe|Name=SweetPacksUpdateManager|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F0F839E5-89DE-4467-9E52-606055705D06}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe|Name=SweetPacksUpdateManager|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{A21972B4-5118-42E3-B07B-3ABF8F630877}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe|Name=SweetPacksUpdateManager|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{F0F839E5-89DE-4467-9E52-606055705D06}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe|Name=SweetPacksUpdateManager|" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3199093499-978631591-3148159529-1001\Software\SweetIM] Searching for "distromatic" No data found. Searching for "BabSolution" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\fagpjgjmoaccgkkpjeoinehnoaimnbla] "path"="C:\Users\PC\AppData\Roaming\BabSolution\CR\hola.crx" Searching for "bProtector" No data found. Searching for "BrowserDefender" [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\ProgramData\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe"="Application Manager" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{2A0F3D1B-0909-4FF4-B272-609CCE6054E7}] "DllName"="PCTBrowserDefender.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{472734EA-242A-422B-ADF8-83D1E48CC825}] "DllName"="PCTBrowserDefender.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{424202EF-76FA-4231-BF7A-5153EB49F987}] "Path"="\BrowserDefendert" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BrowserDefendert] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{2A0F3D1B-0909-4FF4-B272-609CCE6054E7}] "DllName"="PCTBrowserDefender.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{472734EA-242A-422B-ADF8-83D1E48CC825}] "DllName"="PCTBrowserDefender.dll" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\ProgramData\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe"="Application Manager" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\ProgramData\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe"="Application Manager" Searching for "iLivid" [HKEY_CURRENT_USER\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\C:\Users\PC\AppData\Local\iLivid] [HKEY_CURRENT_USER\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.8.false\C:\Users\PC\AppData\Local\iLivid] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Trolltech\OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QImageIOHandlerFactoryInterface:\C:\Users\PC\AppData\Local\iLivid] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Trolltech\OrganizationDefaults\Qt Plugin Cache 4.8.false\C:\Users\PC\AppData\Local\iLivid] Searching for "holasearch" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "hp_url"="hxxp://www.holasearch.com/?babsrc=HP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "nt_url"="hxxp://www.holasearch.com/?babsrc=NT_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "dsFFX"="holasearch" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "uninstaller"="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\uninstall.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "sp_url"="hxxp://www.holasearch.com/?q={searchTerms}&babsrc=SP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "tb_url"="hxxp://www.holasearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "kw_url"="hxxp://www.holasearch.com/?babsrc=SP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927&q=" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\esrv.holasearchESrvc] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\esrv.holasearchESrvc\CurVer] @="esrv.holasearchESrvc.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\esrv.holasearchESrvc.1] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchappCore] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchappCore\CurVer] @="holasearch.holasearchappCore.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchappCore.1] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchdskBnd] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchdskBnd\CurVer] @="holasearch.holasearchdskBnd.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchdskBnd.1] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchHlpr] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchHlpr\CurVer] @="holasearch.holasearchHlpr.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchHlpr.1] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}\1.0\0\win32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchsrv.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}\1.0\HELPDIR] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0] @="holasearchCmn 1.0 Type Library" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0\0\win32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchEng.dll\2" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0\HELPDIR] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1E44819B-54E1-411B-9D9F-38D7B913BCF2}\InprocServer32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchEng.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}\LocalServer32] @=""C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchsrv.exe"" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}\ProgID] @="esrv.holasearchESrvc.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}\VersionIndependentProgID] @="esrv.holasearchESrvc" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}\InprocServer32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchApp.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}\ProgID] @="holasearch.holasearchappCore.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}\VersionIndependentProgID] @="holasearch.holasearchappCore" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C46EFEA4-B0F3-428B-9E77-650E3634EC56}\InprocServer32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\bh\holasearch.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "hp_url"="hxxp://www.holasearch.com/?babsrc=HP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "nt_url"="hxxp://www.holasearch.com/?babsrc=NT_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "dsFFX"="holasearch" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "uninstaller"="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\uninstall.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "sp_url"="hxxp://www.holasearch.com/?q={searchTerms}&babsrc=SP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "tb_url"="hxxp://www.holasearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "kw_url"="hxxp://www.holasearch.com/?babsrc=SP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927&q=" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}\1.0\0\win32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchsrv.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}\1.0\HELPDIR] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0] @="holasearchCmn 1.0 Type Library" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0\0\win32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchEng.dll\2" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0\HELPDIR] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5882DB3D-175D-4CDC-A030-1B7EC2BC8EC6}] "AppName"="holasearchsrv.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5882DB3D-175D-4CDC-A030-1B7EC2BC8EC6}] "AppPath"="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{1E44819B-54E1-411B-9D9F-38D7B913BCF2}\InprocServer32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchEng.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}\LocalServer32] @=""C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchsrv.exe"" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}\ProgID] @="esrv.holasearchESrvc.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}\VersionIndependentProgID] @="esrv.holasearchESrvc" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}\InprocServer32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchApp.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}\ProgID] @="holasearch.holasearchappCore.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}\VersionIndependentProgID] @="holasearch.holasearchappCore" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{C46EFEA4-B0F3-428B-9E77-650E3634EC56}\InprocServer32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\bh\holasearch.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "hp_url"="hxxp://www.holasearch.com/?babsrc=HP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "nt_url"="hxxp://www.holasearch.com/?babsrc=NT_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "dsFFX"="holasearch" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "uninstaller"="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\uninstall.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "sp_url"="hxxp://www.holasearch.com/?q={searchTerms}&babsrc=SP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "tb_url"="hxxp://www.holasearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}\instl\data] "kw_url"="hxxp://www.holasearch.com/?babsrc=SP_ss&mntrId=A0157CE9D3626F22&affID=121962&tsp=4927&q=" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}\1.0\0\win32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchsrv.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}\1.0\HELPDIR] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0] @="holasearchCmn 1.0 Type Library" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0\0\win32] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchEng.dll\2" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}\1.0\HELPDIR] @="C:\Program Files (x86)\holasearch\holasearch\1.8.16.16" Searching for "DealPly" [HKEY_CURRENT_USER\Software\Wow6432Node\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje] "path"="C:\Program Files (x86)\DealPly\DealPly.crx" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{296BED8D-8F7A-40EE-AFDD-642839AC7E7F}] "Path"="\DealPlyUpdate" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AC019BF5-2EB9-4103-AEE1-09CD370F4CBB}] "Path"="\DealPly" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPly] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPlyUpdate] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Wow6432Node\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje] "path"="C:\Program Files (x86)\DealPly\DealPly.crx" Searching for "Babylon" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{2EECD738-5844-4A99-B4B6-146BF802613B}] "DllName"="BabylonToolbar.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}] "DllName"="BabylonToolbar.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{98889811-442D-49DD-99D7-DC866BE87DBC}] "DllName"="BabylonToolbarTlbr.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{2EECD738-5844-4A99-B4B6-146BF802613B}] "DllName"="BabylonToolbar.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}] "DllName"="BabylonToolbar.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{98889811-442D-49DD-99D7-DC866BE87DBC}] "DllName"="BabylonToolbarTlbr.dll" Searching for "Softonic" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\1e40ca8e_0] @="{0.0.0.00000000}.{f8047516-971f-40ba-85de-843482a8264a}|\Device\HarddiskVolume2\Users\PC\Downloads\SoftonicDownloader_fuer_mp3directcut.exe%b{00000000-0000-0000-0000-000000000000}" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\29629339_0] @="{0.0.0.00000000}.{f8047516-971f-40ba-85de-843482a8264a}|\Device\HarddiskVolume2\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe%b{00000000-0000-0000-0000-000000000000}" [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe"="Softonic Downloader " [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_mp3directcut_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_mp3directcut_RASMANCS] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_trustport-internet-security_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_trustport-internet-security_RASMANCS] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\1e40ca8e_0] @="{0.0.0.00000000}.{f8047516-971f-40ba-85de-843482a8264a}|\Device\HarddiskVolume2\Users\PC\Downloads\SoftonicDownloader_fuer_mp3directcut.exe%b{00000000-0000-0000-0000-000000000000}" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\29629339_0] @="{0.0.0.00000000}.{f8047516-971f-40ba-85de-843482a8264a}|\Device\HarddiskVolume2\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe%b{00000000-0000-0000-0000-000000000000}" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe"="Softonic Downloader " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe"="Softonic Downloader " Searching for "delta LTD" No data found. Searching for "PriceGong" [HKEY_CURRENT_USER\Software\PowerPack\225\13] "c"="hxxp://www.powerpackdl.com/downloads/pricegong.exe" [HKEY_CURRENT_USER\Software\PowerPack\225\13] "i"="hxxp://www.pricegong.com/TermsofUse.aspx" [HKEY_CURRENT_USER\Software\PowerPack\225\13] "j"="PriceGong" [HKEY_CURRENT_USER\Software\PowerPack\225\13] "n"="rv:HKCR,AppID\\PriceGongIE.DLL,AppID,{835315FC-1BF6-4CA9-80CD-F6C158D40692}" [HKEY_CURRENT_USER\Software\PowerPack\225\13] "x"="hxxp://www.pricegong.com/favicon.ico" [HKEY_CURRENT_USER\Software\PowerPack\225\13] "y"="hxxp://www.pricegong.com/" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\PriceGong_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\PriceGong_RASMANCS] [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\PowerPack\225\13] "c"="hxxp://www.powerpackdl.com/downloads/pricegong.exe" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\PowerPack\225\13] "i"="hxxp://www.pricegong.com/TermsofUse.aspx" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\PowerPack\225\13] "j"="PriceGong" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\PowerPack\225\13] "n"="rv:HKCR,AppID\\PriceGongIE.DLL,AppID,{835315FC-1BF6-4CA9-80CD-F6C158D40692}" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\PowerPack\225\13] "x"="hxxp://www.pricegong.com/favicon.ico" [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\PowerPack\225\13] "y"="hxxp://www.pricegong.com/" Searching for "OpenCandy" No data found. Searching for "PerformerSoft" No data found. Searching for "SoftSafe" No data found. Searching for "IBUpdater" No data found. Searching for " " [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\PhotoPrintingWizard\Laser Pro LL2] "PrintTicket"="<?xml version="1.0"?> <psf:PrintTicket version="1" xmlns:xsd="hxxp://www.w3.org/2001/XMLSchema" xmlns:xsi="hxxp://www.w3.org/2001/XMLSchema-instance" xmlns:psf="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemaframework" xmlns:psk="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemakeywords" xmlns:mti="hxxp://schemas.monotypeimaging.com/ptpc/2006/1" xmlns:oem="hxxp://schemas.monotypeimaging.com/ptpc/oem/2006/1"><psf:Feature name="psk:PageOrientation"><psf:Option name="psk:Landscape"/></psf:Feature><!-- --><!-- Monotype Imaging print ticket --><!-- --><!-- --><!-- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\PhotoPrintingWizard\Laser Pro LL2] "PrintCapabilites"="<?xml version="1.0"?> <psf:PrintCapabilities version="1" xmlns:xsd="hxxp://www.w3.org/2001/XMLSchema" xmlns:xsi="hxxp://www.w3.org/2001/XMLSchema-instance" xmlns:psf="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemaframework" xmlns:psk="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemakeywords" xmlns:mti="hxxp://schemas.monotypeimaging.com/ptpc/2006/1" xmlns:oem="hxxp://schemas.monotypeimaging.com/ptpc/oem/2006/1"><!-- --><!-- Monotype Imaging print capabilities --><!-- --><!-- --><!-- JobComment --><!-- [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "G:\Menu.exe"="CnMemory Software " [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe"="Softonic Downloader " [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Desktop\TrustPort_Internet_Security_12.0.0.4788.exe"="TrustPort Internet Security " [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WSMAN\Plugin\Microsoft.PowerShell] "ConfigXML"=" <PlugInConfiguration xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Name="microsoft.powershell" Filename="%windir%\system32\pwrshplugin.dll" SDKVersion="1" XmlRenderingType="text" > <InitializationParameters> <Param Name="PSVersion" Value="2.0"/> </InitializationParameters> <Resources> <Resource ResourceUri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell" SupportsOptions="true" ExactMatch="true"> <Security xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Uri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell" ExactMatch="true" Sddl="O:NSG:BAD:P(A;;GA;;;BA)S:P(AU;FA;GA;;;WD)(AU;SA;GXGW;;;WD)"/> <Capability Type="Shell"/> </Resource> </Res [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\WSMAN\Plugin\Microsoft.PowerShell32] "ConfigXML"="<PlugInConfiguration xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Name="microsoft.powershell32" Filename="%windir%\system32\pwrshplugin.dll" SDKVersion="1" XmlRenderingType="text" Architecture="32" > <InitializationParameters> <Param Name="PSVersion" Value="2.0"/> </InitializationParameters> <Resources> <Resource ResourceUri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell32" SupportsOptions="true" ExactMatch="true"> <Security xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Uri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell32" ExactMatch="true" Sddl="O:NSG:BAD:P(A;;GA;;;BA)S:P(AU;FA;GA;;;WD)(AU;SA;GXGW;;;WD)"/> [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&10D4990&0&__ ______&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&10D4990&0&__ ______&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&11AC6715&0&_ _______&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&11AC6715&0&_ _______&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&2706475&0&__ ______&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&2706475&0&__ ______&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&10D4990&0&__ ______&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&10D4990&0&__ ______&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&11AC6715&0&_ _______&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&11AC6715&0&_ _______&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&2706475&0&__ ______&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&2706475&0&__ ______&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&10D4990& 0&________&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&10D4990& 0&________&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&11AC6715 &0&________&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&11AC6715 &0&________&1#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&2706475& 0&________&0#] "DeviceDesc"="NERO " [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_ODYS&PROD_NERO&REV_2.00#7&2706475& 0&________&1#] "DeviceDesc"="NERO " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\PhotoPrintingWizard\Laser Pro LL2] "PrintTicket"="<?xml version="1.0"?> <psf:PrintTicket version="1" xmlns:xsd="hxxp://www.w3.org/2001/XMLSchema" xmlns:xsi="hxxp://www.w3.org/2001/XMLSchema-instance" xmlns:psf="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemaframework" xmlns:psk="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemakeywords" xmlns:mti="hxxp://schemas.monotypeimaging.com/ptpc/2006/1" xmlns:oem="hxxp://schemas.monotypeimaging.com/ptpc/oem/2006/1"><psf:Feature name="psk:PageOrientation"><psf:Option name="psk:Landscape"/></psf:Feature><!-- --><!-- Monotype Imaging print ticket --><!-- --><!-- --><!-- [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\PhotoPrintingWizard\Laser Pro LL2] "PrintCapabilites"="<?xml version="1.0"?> <psf:PrintCapabilities version="1" xmlns:xsd="hxxp://www.w3.org/2001/XMLSchema" xmlns:xsi="hxxp://www.w3.org/2001/XMLSchema-instance" xmlns:psf="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemaframework" xmlns:psk="hxxp://schemas.microsoft.com/windows/2003/08/printing/printschemakeywords" xmlns:mti="hxxp://schemas.monotypeimaging.com/ptpc/2006/1" xmlns:oem="hxxp://schemas.monotypeimaging.com/ptpc/oem/2006/1"><!-- --><!-- Monotype Imaging print capabilities --><!-- --><!-- --><!-- JobComment --><!-- [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "G:\Menu.exe"="CnMemory Software " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe"="Softonic Downloader " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Desktop\TrustPort_Internet_Security_12.0.0.4788.exe"="TrustPort Internet Security " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "G:\Menu.exe"="CnMemory Software " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Downloads\SoftonicDownloader_fuer_trustport-internet-security.exe"="Softonic Downloader " [HKEY_USERS\S-1-5-21-3199093499-978631591-3148159529-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Users\PC\Desktop\TrustPort_Internet_Security_12.0.0.4788.exe"="TrustPort Internet Security " -= EOF =- |
Servus, Schritt 1
Schritt 2 Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code: start Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Schritt 3 ESET Online Scanner
Schritt 4 Downloade Dir bitte ![]()
Bitte poste mit deiner nächsten Antwort
|
start HKCU\...\Run: [QtraxNotification] - C:\Users\PC\Qtrax\Player\Notification.exe [118568 2013-08-05] () C:\Users\PC\Qtrax BHO-x32: LyricsContainer - {83a2ad96-138f-4a98-b9db-4f65368dba9d} - C:\Program Files (x86)\LyricsContainer\125.dll C:\Program Files (x86)\LyricsContainer Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File FF Extension: LyricXeeker - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\oxamfp2j.default\Extensions\125 FF HKCU\...\Firefox\Extensions: [lyrix@lyrixeeker.co] C:\Program Files (x86)\LyriXeeker\125.xpi CHR HKLM-x32\...\Chrome\Extension: [epojlgbehpaeekopencdagbdamnkppci] - C:\Program Files (x86)\LyriXeeker\125.crx CHR HKLM-x32\...\Chrome\Extension: [fagpjgjmoaccgkkpjeoinehnoaimnbla] - C:\Users\PC\AppData\Roaming\BabSolution\CR\hola.crx CHR HKLM-x32\...\Chrome\Extension: [keaillmajpeodnbelalgeffidfcdgiem] - C:\Program Files (x86)\LyricsContainer\125.crx C:\Program Files (x86)\LyriXeeker 2013-08-05 16:50 - 2013-08-05 16:50 - 00003436 _____ C:\Windows\System32\Tasks\BrowserDefendert 2013-08-05 16:50 - 2013-08-05 16:50 - 00002377 _____ C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Qtrax Player.lnk 2013-08-05 16:50 - 2013-08-05 16:50 - 00000000 ____D C:\Users\PC\AppData\Roaming\Zip Opener Packages 2013-08-05 16:50 - 2013-08-05 16:50 - 00000000 ____D C:\Program Files (x86)\OpenIt 2013-08-05 16:48 - 2013-08-05 16:48 - 00717160 _____ C:\Users\PC\Downloads\ZipOpenerSetup(1).exe 2013-08-04 16:17 - 2013-08-04 16:17 - 04653592 _____ (Systweak Inc ) C:\Users\PC\Downloads\rcpsetupdsnr_ds367212.exe 2013-08-03 02:44 - 2013-08-03 02:44 - 00000000 ____D C:\Users\PC\Qtrax 2013-08-03 02:40 - 2013-08-05 16:50 - 00003782 _____ C:\Windows\System32\Tasks\QtraxPlayer 2013-08-03 02:39 - 2013-08-06 18:49 - 00000280 _____ C:\Windows\Tasks\DigitalSite.job 2013-08-03 02:39 - 2013-08-05 16:49 - 00003208 _____ C:\Windows\System32\Tasks\DigitalSite 2013-08-03 02:39 - 2013-08-03 02:39 - 00717160 _____ C:\Users\PC\Downloads\ZipOpenerSetup.exe 2013-08-03 02:39 - 2013-08-03 02:39 - 00000000 ____D C:\Users\PC\AppData\Roaming\DigitalSite 2013-08-05 16:50 - 2013-07-01 14:20 - 00003370 _____ C:\Windows\System32\Tasks\EPUpdater 2013-08-03 02:39 - 2013-08-03 02:39 - 00717160 _____ C:\Users\PC\Downloads\ZipOpenerSetup.exe Task: {296BED8D-8F7A-40EE-AFDD-642839AC7E7F} - System32\Tasks\DealPlyUpdate => C:\Program Files (x86)\DealPly\DealPlyUpdate.exe Task: {424202EF-76FA-4231-BF7A-5153EB49F987} - System32\Tasks\BrowserDefendert Task: {58A24A98-E7CB-4B24-8C1F-1A8963D3C8B7} - System32\Tasks\DigitalSite => C:\Users\PC\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE Task: {69EBF01E-16AF-43A1-BF6C-0AACD9FCDD08} - System32\Tasks\EPUpdater => C:\Users\PC\AppData\Roaming\BABSOL~1 Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\systweakasp_RASAPI32" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\systweakasp_RASMANCS" /f Reg: reg delete "HKEY_CURRENT_USER\Software\AppDataLow\Software\adawarebp" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\adawarebp_RASAPI32" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\adawarebp_RASDLG" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\adawarebp_RASMANCS" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DATAMNGR" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules" /v "{0028FE51-2BFF-4A35-8266-0D10A6A4DF27}" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules" /v "{F8BD6963-EDBD-44DD-A5DA-038F96222E8A}" /f Reg: reg delete "HKEY_CURRENT_USER\Software\AppDataLow\Software\LyriXeeker" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\epojlgbehpaeekopencdagbdamnkppci" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\lyrix@lyrixeeker.co" /f Reg: reg delete "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3199093499-978631591-3148159529-1001\Software\SweetIM" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\toolbar_vit_sweetim_RASAPI32" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\toolbar_vit_sweetim_RASMANCS" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\fagpjgjmoaccgkkpjeoinehnoaimnbla" /f Reg: reg delete "HKEY_CURRENT_USER\Software\Trolltech" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\esrv.holasearchESrvc" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\esrv.holasearchESrvc.1" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchappCore" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchappCore.1" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchdskBnd" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchdskBnd.1" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchHlpr" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchHlpr.1" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1E44819B-54E1-411B-9D9F-38D7B913BCF2}" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C46EFEA4-B0F3-428B-9E77-650E3634EC56}" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5882DB3D-175D-4CDC-A030-1B7EC2BC8EC6}" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{1E44819B-54E1-411B-9D9F-38D7B913BCF2}" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{C46EFEA4-B0F3-428B-9E77-650E3634EC56}" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_mp3directcut_RASAPI32" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_mp3directcut_RASMANCS" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_trustport-internet-security_RASAPI32" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_trustport-internet-security_RASMANCS" /f Reg: reg delete "HKEY_CURRENT_USER\Software\PowerPack" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\PriceGong_RASAPI32" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\PriceGong_RASMANCS" /f end ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=ba732d7a34e01f4a976b2d198e665265 # engine=14686 # end=stopped # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-08-07 01:57:49 # local_time=2013-08-07 03:57:49 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1023 16777215 0 0 0 0 0 0 # compatibility_mode=5893 16776574 100 94 0 127513719 0 0 # scanned=18394 # found=0 # cleaned=0 # scan_time=1288 Results of screen317's Security Check version 0.99.71 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 10 ``````````````Antivirus/Firewall Check:`````````````` Microsoft Security Essentials Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Ad-Aware Malwarebytes Anti-Malware Version 1.75.0.1300 Adobe Flash Player 11.8.800.94 Adobe Reader 10.1.7 Adobe Reader out of Date! Mozilla Firefox (22.0) ````````Process Check: objlist.exe by Laurent```````` Microsoft Security Essentials MSMpEng.exe Microsoft Security Essentials msseces.exe Ad-Aware AAWService.exe is disabled! Ad-Aware AAWTray.exe is disabled! Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbamgui.exe Malwarebytes' Anti-Malware mbamscheduler.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` |
Servus, lies dir meinen Schritt zum FRST-Fix nochmal durch und poste die Logdatei des Fixes von FRST, nicht die Code-Box von mir... :blabla: ;) |
Ups sry :D Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 07-08-2013 Ran by PC at 2013-08-07 17:58:13 Run:1 Running from C:\Users\PC\Desktop Boot Mode: Normal ============================================== HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\QtraxNotification => Value not found. C:\Users\PC\Qtrax => Moved successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83a2ad96-138f-4a98-b9db-4f65368dba9d} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{83a2ad96-138f-4a98-b9db-4f65368dba9d} => Key deleted successfully. "C:\Program Files (x86)\LyricsContainer" => File/Directory not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => Value deleted successfully. HKCR\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => Key not found. C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\oxamfp2j.default\Extensions\125 => Moved successfully. HKCU\Software\Mozilla\Firefox\Extensions\\lyrix@lyrixeeker.co => Value deleted successfully. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\epojlgbehpaeekopencdagbdamnkppci => Key deleted successfully. "C:\Program Files (x86)\LyriXeeker\125.crx" => File/Directory not found. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\fagpjgjmoaccgkkpjeoinehnoaimnbla => Key deleted successfully. "C:\Users\PC\AppData\Roaming\BabSolution\CR\hola.crx" => File/Directory not found. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\keaillmajpeodnbelalgeffidfcdgiem => Key deleted successfully. "C:\Program Files (x86)\LyricsContainer\125.crx" => File/Directory not found. "C:\Program Files (x86)\LyriXeeker" => File/Directory not found. C:\Windows\System32\Tasks\BrowserDefendert => Moved successfully. "C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Qtrax Player.lnk" => File/Directory not found. "C:\Users\PC\AppData\Roaming\Zip Opener Packages" => File/Directory not found. "C:\Program Files (x86)\OpenIt" => File/Directory not found. C:\Users\PC\Downloads\ZipOpenerSetup(1).exe => Moved successfully. C:\Users\PC\Downloads\rcpsetupdsnr_ds367212.exe => Moved successfully. "C:\Users\PC\Qtrax" => File/Directory not found. C:\Windows\System32\Tasks\QtraxPlayer => Moved successfully. C:\Windows\Tasks\DigitalSite.job => Moved successfully. C:\Windows\System32\Tasks\DigitalSite => Moved successfully. C:\Users\PC\Downloads\ZipOpenerSetup.exe => Moved successfully. "C:\Users\PC\AppData\Roaming\DigitalSite" directory move: C:\Users\PC\AppData\Roaming\DigitalSite\UpdateProc\config.dat => Moved successfully. C:\Users\PC\AppData\Roaming\DigitalSite\UpdateProc\prod.dat => Moved successfully. C:\Users\PC\AppData\Roaming\DigitalSite\UpdateProc\STTL.DAT => Moved successfully. C:\Users\PC\AppData\Roaming\DigitalSite\UpdateProc\TTL.DAT => Moved successfully. C:\Users\PC\AppData\Roaming\DigitalSite\UpdateProc\UpdateTask.exe => Moved successfully. Could not move "C:\Users\PC\AppData\Roaming\DigitalSite" directory. => Scheduled to move on reboot. C:\Windows\System32\Tasks\EPUpdater => Moved successfully. "C:\Users\PC\Downloads\ZipOpenerSetup.exe" => File/Directory not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{296BED8D-8F7A-40EE-AFDD-642839AC7E7F} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{296BED8D-8F7A-40EE-AFDD-642839AC7E7F} => Key deleted successfully. C:\Windows\System32\Tasks\DealPlyUpdate => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPlyUpdate => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{424202EF-76FA-4231-BF7A-5153EB49F987} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{424202EF-76FA-4231-BF7A-5153EB49F987} => Key deleted successfully. C:\Windows\System32\Tasks\BrowserDefendert not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BrowserDefendert => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{58A24A98-E7CB-4B24-8C1F-1A8963D3C8B7} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{58A24A98-E7CB-4B24-8C1F-1A8963D3C8B7} => Key deleted successfully. C:\Windows\System32\Tasks\DigitalSite not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DigitalSite => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{69EBF01E-16AF-43A1-BF6C-0AACD9FCDD08} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{69EBF01E-16AF-43A1-BF6C-0AACD9FCDD08} => Key deleted successfully. C:\Windows\System32\Tasks\EPUpdater not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EPUpdater => Key deleted successfully. ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\systweakasp_RASAPI32" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\systweakasp_RASMANCS" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_CURRENT_USER\Software\AppDataLow\Software\adawarebp" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\adawarebp_RASAPI32" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\adawarebp_RASDLG" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\adawarebp_RASMANCS" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DATAMNGR" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules" /v "{0028FE51-2BFF-4A35-8266-0D10A6A4DF27}" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules" /v "{F8BD6963-EDBD-44DD-A5DA-038F96222E8A}" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_CURRENT_USER\Software\AppDataLow\Software\LyriXeeker" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\epojlgbehpaeekopencdagbdamnkppci" /f ========= FEHLER: Der angegebene Registrierungsschlssel bzw. Wert wurde nicht gefunden. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\lyrix@lyrixeeker.co" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3199093499-978631591-3148159529-1001\Software\SweetIM" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\toolbar_vit_sweetim_RASAPI32" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\toolbar_vit_sweetim_RASMANCS" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\fagpjgjmoaccgkkpjeoinehnoaimnbla" /f ========= FEHLER: Der angegebene Registrierungsschlssel bzw. Wert wurde nicht gefunden. ========= End of Reg: ========= ========= reg delete "HKEY_CURRENT_USER\Software\Trolltech" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\esrv.holasearchESrvc" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\esrv.holasearchESrvc.1" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchappCore" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchappCore.1" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchdskBnd" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchdskBnd.1" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchHlpr" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\holasearch.holasearchHlpr.1" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1E44819B-54E1-411B-9D9F-38D7B913BCF2}" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{C46EFEA4-B0F3-428B-9E77-650E3634EC56}" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}" /f ========= FEHLER: Der angegebene Registrierungsschlssel bzw. Wert wurde nicht gefunden. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}" /f ========= FEHLER: Der angegebene Registrierungsschlssel bzw. Wert wurde nicht gefunden. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}" /f ========= FEHLER: Der angegebene Registrierungsschlssel bzw. Wert wurde nicht gefunden. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5882DB3D-175D-4CDC-A030-1B7EC2BC8EC6}" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{1E44819B-54E1-411B-9D9F-38D7B913BCF2}" /f ========= FEHLER: Der angegebene Registrierungsschlssel bzw. Wert wurde nicht gefunden. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{A1EC45B2-B5F7-4B87-955E-E97F778ACAE8}" /f ========= FEHLER: Der angegebene Registrierungsschlssel bzw. Wert wurde nicht gefunden. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{B71E4FEB-89F8-4ACB-A60F-A7DE399119AE}" /f ========= FEHLER: Der angegebene Registrierungsschlssel bzw. Wert wurde nicht gefunden. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{C46EFEA4-B0F3-428B-9E77-650E3634EC56}" /f ========= FEHLER: Der angegebene Registrierungsschlssel bzw. Wert wurde nicht gefunden. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\AppID\{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}" /f ========= FEHLER: Der angegebene Registrierungsschlssel bzw. Wert wurde nicht gefunden. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{58B41DCD-55B2-48EB-A55A-E330070FFC00}" /f ========= FEHLER: Der angegebene Registrierungsschlssel bzw. Wert wurde nicht gefunden. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{9BA19DB8-5C5A-4C13-AEEB-A1336113333E}" /f ========= FEHLER: Der angegebene Registrierungsschlssel bzw. Wert wurde nicht gefunden. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_mp3directcut_RASAPI32" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_mp3directcut_RASMANCS" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_trustport-internet-security_RASAPI32" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_trustport-internet-security_RASMANCS" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_CURRENT_USER\Software\PowerPack" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\PriceGong_RASAPI32" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\PriceGong_RASMANCS" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= =========== Result of Scheduled Files to move =========== "C:\Users\PC\AppData\Roaming\DigitalSite" => Directory could not move. ==== End of Fixlog ==== |
Servus, sieht schon mal gut aus. Noch eine letzte Kontrolle: Kontrollscan mit FRST Führe wie zuvor beschrieben einen Scan mit FRST aus. Setze dazu eine Haken bei Addition.txt rechts unten und klicke auf Scan. Es werden wieder zwei Logdateien erzeugt. Poste mir diese. |
Hey, sry dass ich mich erst jetzt melde. Muss ich bei dem FRST einen neuen Scan machen? Da er diese Fixlist.txt nicht findet.. LG |
Servus, lies dir bitte meinen letzten Post nochmal durch, dort steht alles drinnen. ;) |
Oh ja :D habs jetzt verstanden :D FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-08-2013 FRST Additions Logfile: Code: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 09-08-2013 |
Servus, Wenn du keine Probleme mehr hast, dann sind wir hier fertig. Deine Logdateien sind sauber. :daumenhoc Zum Schluss müssen wir noch ein paar abschließende Schritte unternehmen, um deinen Pc aufzuräumen und abzusichern. Schritt 1 Deinstalliere bitte deine aktuelle Version von Adobe Reader Start--> Systemsteuerung--> Software / Programme deinstallieren--> Adobe Reader und lade dir die neue Version von Hier herunter- Entferne den Hacken für den McAfee SecurityScan bzw. Google Chrome. Schritt 2
Prüfe bitte auch (regelmässig) ob folgende Links fehlende Updates bei deinen Plugins zeigen: Schritt 3 Die Reihenfolge ist hier entscheidend.
Schritt 4 Abschließend habe ich noch ein paar Tipps zur Absicherung deines Systems. Ich kann gar nicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von Registry Cleanern. Diese Schaden deinem System mehr als dass sie helfen. Hier ein englischer Link: Miekemoes Blogspot ( MVP ) Was du vermeiden solltest:
Nun bleibt mir nur noch dir viel Spaß beim sicheren Surfen zu wünschen... ... und vielleicht möchtest du ja das Trojaner-Board unterstützen? Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so dass ich dieses Thema aus meinen Abos löschen kann. |
Ich habe alles gemacht! Vielen vielen Dank für alles! Läuft alles super! :) |
Ich bin froh, dass wir helfen konnten :abklatsch: In diesem Forum kannst du eine kurze Rückmeldung zur Bereinigung abgeben, sofern du das möchtest: Lob, Kritik und Wünsche Klicke dazu auf den Button "NEUES THEMA" und poste ein kleines Feedback. Vielen Dank! :) Dieses Thema scheint erledigt und wird aus meinen Abos gelöscht. Solltest Du das Thema erneut brauchen, schicke mir bitte eine PM. Jeder andere bitte hier klicken und einen eigenen Thread erstellen. |
Alle Zeitangaben in WEZ +1. Es ist jetzt 11:32 Uhr. |
Copyright ©2000-2025, Trojaner-Board