Danke für die Super-Unterstützung, hier die Files
mbam.txt: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 27.06.2014
Suchlauf-Zeit: 07:54:11
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.06.27.02
Rootkit Datenbank: v2014.06.23.02
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: TG
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 286946
Verstrichene Zeit: 21 Min, 45 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 2
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\updateToggleMark.exe, 2460, Löschen bei Neustart, [2d413e3f0d6e1e18087be0907190d828]
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\bin\utilToggleMark.exe, 2760, Löschen bei Neustart, [0d61eb920f6cc472097aa9c7d62bfd03]
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 20
PUP.Optional.ToggleMark.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Update ToggleMark, In Quarantäne, [2d413e3f0d6e1e18087be0907190d828],
PUP.Optional.ToggleMark.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Util ToggleMark, In Quarantäne, [0d61eb920f6cc472097aa9c7d62bfd03],
PUP.Optional.BrowseFox.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}, In Quarantäne, [fe70403dc3b8989efd062d531de50df3],
PUP.Optional.ToggleMark.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\ToggleMark, In Quarantäne, [bcb2502d8bf0c175f3608b38956dc53b],
PUP.Optional.ToggleMark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}, In Quarantäne, [bcb2502d8bf0c175f3608b38956dc53b],
PUP.Optional.ToggleMark.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}, In Quarantäne, [bcb2502d8bf0c175f3608b38956dc53b],
PUP.Optional.ToggleMark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}, In Quarantäne, [bcb2502d8bf0c175f3608b38956dc53b],
PUP.Optional.ToggleMark.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}, In Quarantäne, [bcb2502d8bf0c175f3608b38956dc53b],
PUP.Optional.ToggleMark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}, In Quarantäne, [bcb2502d8bf0c175f3608b38956dc53b],
PUP.Optional.ToggleMark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}, In Quarantäne, [bcb2502d8bf0c175f3608b38956dc53b],
PUP.Optional.ToggleMark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}, In Quarantäne, [bcb2502d8bf0c175f3608b38956dc53b],
PUP.Optional.ToggleMark.A, HKLM\SOFTWARE\WOW6432NODE\ToggleMark, In Quarantäne, [7bf3fb82afccef472d27319242c0db25],
PUP.Optional.IMGUpdater.A, HKLM\SOFTWARE\WOW6432NODE\IMGUPDATER, In Quarantäne, [a7c76a131a611c1a27dcd5db0df5748c],
PUP.Optional.ToggleMark.A, HKU\S-1-5-21-3212772127-1644909334-2868257101-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\ToggleMark, In Quarantäne, [c8a6abd24239df5798bd18ab5fa353ad],
PUP.Optional.Iminent.A, HKU\S-1-5-21-3212772127-1644909334-2868257101-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOWREGISTRY\Iminent, In Quarantäne, [cba304794833ff374369299241c1cd33],
PUP.Optional.ViewPassword.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{C27A6CC0-EC7F-6C40-D81C-C2C0E86CB95B}, In Quarantäne, [beb0750804773ef82f23b9d4937159a7],
PUP.Optional.ViewPassword.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{C27A6CC0-EC7F-6C40-D81C-C2C0E86CB95B}, In Quarantäne, [beb0750804773ef82f23b9d4937159a7],
PUP.Optional.ViewPassword.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{DD9AC078-326F-5AB1-57C3-3B8EFE00B05B}, In Quarantäne, [beb0750804773ef82f23b9d4937159a7],
PUP.Optional.ViewPassword.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{E3270255-EB96-FE1A-77AB-26BE249E1CFF}, In Quarantäne, [beb0750804773ef82f23b9d4937159a7],
PUP.Optional.ViewPassword.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{DD9AC078-326F-5AB1-57C3-3B8EFE00B05B}, In Quarantäne, [beb0750804773ef82f23b9d4937159a7],
Registrierungswerte: 1
PUP.Optional.IMGUpdater.A, HKLM\SOFTWARE\WOW6432NODE\IMGUPDATER|ConfigBlockJSN, {
"MAIN_SWITCH" : true,
"UPDATABLE" : {
"064A36CC-4404-42F9-B26E-3BFD515F2447" : {
"lastupdated" : 0,
"mindeltatime" : 259200
},
"2C200CBA-D536-40C8-902D-9C34FD10AD85" : {
"lastupdated" : 0,
"localversion" : "0",
"mindeltatime" : 259200
},
"4C973056-22D8-488C-A358-AEA00CC2EC7D" : {
"lastupdated" : 0,
"mindeltatime" : 259200
}
}
}
, In Quarantäne, [a7c76a131a611c1a27dcd5db0df5748c]
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 4
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark, Löschen bei Neustart, [bcb2502d8bf0c175f3608b38956dc53b],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\bin, Löschen bei Neustart, [bcb2502d8bf0c175f3608b38956dc53b],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\bin\plugins, In Quarantäne, [bcb2502d8bf0c175f3608b38956dc53b],
PUP.Optional.Conduit.A, C:\Users\TG\AppData\Local\Temp\CT3323737, In Quarantäne, [8de16617186338fe0268f2a1b949d828],
Dateien: 26
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\updateToggleMark.exe, Löschen bei Neustart, [2d413e3f0d6e1e18087be0907190d828],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\bin\utilToggleMark.exe, Löschen bei Neustart, [0d61eb920f6cc472097aa9c7d62bfd03],
PUP.Optional.Conduit.A, C:\Users\TG\Downloads\MyPhoneExplorer_TSV21YHIN.exe, In Quarantäne, [620cfc81e09b0f273a576de2d8293cc4],
PUP.Optional.Softonic.A, C:\Users\TG\Downloads\SoftonicDownloader_fuer_anki.exe, In Quarantäne, [35396815285386b086aa28fd6e9334cc],
PUP.Optional.Iminent.A, C:\Windows\System32\Tasks\FinishInstall igdhbblpcellaljokkpfhcjlagemhgjl, In Quarantäne, [9fcffd80c3b8a393b5549715b44edb25],
PUP.Optional.ToggleMark.A, C:\Users\TG\AppData\Roaming\Mozilla\Firefox\Profiles\oqsg4t4l.default\extensions\{af16abf4-eac1-49b4-93fc-58f6ca799135}.xpi, In Quarantäne, [3d31dca15f1c290df0d103aa5da548b8],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\ToggleMark.ico, In Quarantäne, [bcb2502d8bf0c175f3608b38956dc53b],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\0, In Quarantäne, [bcb2502d8bf0c175f3608b38956dc53b],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\7za.exe, In Quarantäne, [bcb2502d8bf0c175f3608b38956dc53b],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\ToggleMarkUninstall.exe, In Quarantäne, [bcb2502d8bf0c175f3608b38956dc53b],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\updateToggleMark.InstallState, In Quarantäne, [bcb2502d8bf0c175f3608b38956dc53b],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\bin\7za.exe, In Quarantäne, [bcb2502d8bf0c175f3608b38956dc53b],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\bin\BrowserAdapterS.7z, In Quarantäne, [bcb2502d8bf0c175f3608b38956dc53b],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\bin\sqlite3.dll, In Quarantäne, [bcb2502d8bf0c175f3608b38956dc53b],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\bin\ToggleMark.BrowserAdapter.exe, In Quarantäne, [bcb2502d8bf0c175f3608b38956dc53b],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\bin\ToggleMark.PurBrowse64.exe, In Quarantäne, [bcb2502d8bf0c175f3608b38956dc53b],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\bin\ToggleMark.PurBrowseG.zip, In Quarantäne, [bcb2502d8bf0c175f3608b38956dc53b],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\bin\utilToggleMark.InstallState, In Quarantäne, [bcb2502d8bf0c175f3608b38956dc53b],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\bin\{af16abf4-eac1-49b4-93fc-58f6ca799135}.dll, In Quarantäne, [bcb2502d8bf0c175f3608b38956dc53b],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\bin\plugins\ToggleMark.Bromon.dll, In Quarantäne, [bcb2502d8bf0c175f3608b38956dc53b],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\bin\plugins\ToggleMark.BroStats.dll, In Quarantäne, [bcb2502d8bf0c175f3608b38956dc53b],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\bin\plugins\ToggleMark.BrowserAdapterS.dll, In Quarantäne, [bcb2502d8bf0c175f3608b38956dc53b],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\bin\plugins\ToggleMark.CompatibilityChecker.dll, In Quarantäne, [bcb2502d8bf0c175f3608b38956dc53b],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\bin\plugins\ToggleMark.FFUpdate.dll, In Quarantäne, [bcb2502d8bf0c175f3608b38956dc53b],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\bin\plugins\ToggleMark.IEUpdate.dll, In Quarantäne, [bcb2502d8bf0c175f3608b38956dc53b],
PUP.Optional.ToggleMark.A, C:\Program Files (x86)\ToggleMark\bin\plugins\ToggleMark.PurBrowseG.dll, In Quarantäne, [bcb2502d8bf0c175f3608b38956dc53b],
Physische Sektoren: 0
(No malicious items detected)
(end)
ESET log.txt Code:
ESETSmartInstaller@High as downloader log:
all ok
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7587
# api_version=3.0.2
# EOSSerial=82612d0e74126c478223b63a20b4595d
# engine=18911
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-06-27 10:36:58
# local_time=2014-06-27 12:36:58 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1='Avira Desktop'
# compatibility_mode=1810 16777213 100 99 21676 850260 0 0
# compatibility_mode_1=''
# compatibility_mode=5893 16776574 100 94 95957 155495268 0 0
# scanned=259514
# found=29
# cleaned=0
# scan_time=11814
sh=103A2F97E88142DBC3A02536C9D6B0555DD8437C ft=1 fh=c71c0011389f51a3 vn="Variante von Win32/AdWare.EoRezo.AU Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\fst_de_64\freeSoftToday_widget.exe.vir"
sh=21414F593C1EB6166307C94CAB88771DD7E1A93D ft=1 fh=648870a43ff7a269 vn="Variante von Win32/AdWare.EoRezo.AU Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\fst_de_64\fst_de_64.exe.vir"
sh=5B54E24892C8E7F424AF273E0F051B89858C89AE ft=1 fh=570f49fa3b076b35 vn="Win32/Adware.EoRezo.AS Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\fst_de_64\predm.exe.vir"
sh=91C45E16A830548CC423AA01C18E456844DBB6B6 ft=1 fh=0d441bdf7e3fb258 vn="Win32/Toolbar.Iminent.C evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Iminent\inst\Bootstrapper\IminentUninstall.exe.vir"
sh=DEF85D609AF52A0F878CA80F53264C1524E48A4A ft=1 fh=c41213f667b13f46 vn="Variante von Win32/Adware.EoRezo.AJ Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\TG\AppData\Local\fst_de_64\upfst_de_64.exe.vir"
sh=7A2589020E1532105EA0B3845BAEDA0271AA2F42 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\TG\AppData\Roaming\Mozilla\Firefox\Profiles\oqsg4t4l.default\Extensions\a54e453c-130a-4769-9333-c5ec2aa914c5@9bd7cc89-9c7c-44e9-a03b-042b92d363f0.com\extensionData\plugins\91.js.vir"
sh=EF4C3D5EB1BE1CE32E78F93BFF98BE1F01229DF2 ft=1 fh=c71c0011f85d84c1 vn="Variante von Win32/AdWare.AddLyrics.AQ Anwendung" ac=I fn="C:\FRST\Quarantine\C\Program Files (x86)\-ViewPassword-soft\-ViewPassword-soft\ViewPasswordon174.exe"
sh=D5226170F67ECC3C885DB42A6AEA025B02B26F29 ft=1 fh=e2c3ceef38f4554c vn="Variante von Win32/Adware.EoRezo.AJ Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\TG\AppData\Local\t4pc_en_7\upt4pc_en_7.exe"
sh=E6087C460ACDF7239A62125C067B883112D4616F ft=1 fh=1da6c5dcda1c8a45 vn="Win32/InstallMonetizer.AX evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\TG\AppData\Local\t4pc_en_7\Download\majt4pc.exe"
sh=320E06DF666307CFF4637F6204F0572C12E032DB ft=1 fh=709a833c8f49e980 vn="Variante von Win32/DownloadGuide.A evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\TG\Downloads\soft32_IrfanView_1.0.exe.xBAD"
sh=5B54E24892C8E7F424AF273E0F051B89858C89AE ft=1 fh=570f49fa3b076b35 vn="Win32/Adware.EoRezo.AS Anwendung" ac=I fn="C:\Program Files (x86)\t4pc_en_7\predm.exe"
sh=1B0CF29B09D476117F5C2806196FBB62A5E4E10E ft=1 fh=4d87c7c4203bf4eb vn="Variante von Win32/Toolbar.CrossRider.AK evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\V-9.1HD\099c6c9e-8fbb-4604-9a19-02127ec36095-11.exe"
sh=564C07690513A7BAE3D6127FA50234EEB9E1F778 ft=1 fh=77937b4620ea03ac vn="Variante von Win32/Toolbar.CrossRider.AJ evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\V-9.1HD\099c6c9e-8fbb-4604-9a19-02127ec36095-2.exe"
sh=1B0CF29B09D476117F5C2806196FBB62A5E4E10E ft=1 fh=4d87c7c4203bf4eb vn="Variante von Win32/Toolbar.CrossRider.AK evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\V-9.1HD\099c6c9e-8fbb-4604-9a19-02127ec36095-3.exe"
sh=F63655DD6FA7B9D8D142D3C94B4FA89AF9DEC743 ft=1 fh=3a5fee453a8f2280 vn="Variante von Win32/Toolbar.CrossRider.AK evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\V-9.1HD\099c6c9e-8fbb-4604-9a19-02127ec36095-4.exe"
sh=C6F52C51DA33D21D3F39AE6DEC649643820EB810 ft=1 fh=dbd212c17bdfbf54 vn="Variante von Win32/Toolbar.CrossRider.AH evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\V-9.1HD\099c6c9e-8fbb-4604-9a19-02127ec36095-5.exe"
sh=9BCA94138A2F2C00C904A8F2387C84983E2432E5 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\V-9.1HD\099c6c9e-8fbb-4604-9a19-02127ec36095.crx"
sh=F98677D17197080AD61E60F348F174B8AF278D19 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\V-9.1HD\360-52916.crx"
sh=9BCA94138A2F2C00C904A8F2387C84983E2432E5 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\V-9.1HD\52916.crx"
sh=21215683BBF89A50CDA5EF6DBFE178F265F462BC ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\V-9.1HD\52916.xpi"
sh=9B7D74F7390B1772BD8BFC477E2F3FE26DE68858 ft=1 fh=faa8610cb87cb02a vn="Variante von Win32/Packed.VMDetector.E evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\V-9.1HD\utils.exe"
sh=9D70B64C507D4C0A7C34FF9761945F7935335DAB ft=1 fh=a8f287a81dddaadf vn="Variante von Win32/Toolbar.CrossRider.AL evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\V-9.1HD\V-9.1HD-bg.exe"
sh=ED358E82A61C731E5457D98E00D097248E691EE7 ft=1 fh=9602663caef5aa15 vn="Variante von Win32/Toolbar.CrossRider.AF evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\V-9.1HD\V-9.1HD-bho.dll"
sh=C369B82EDAB6AFE203A8A508F846083E547A40E9 ft=1 fh=a1daa6089797bc27 vn="Variante von Win64/Toolbar.Crossrider.F evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\V-9.1HD\V-9.1HD-bho64.dll"
sh=56ED1444A872906F39D62A83410FD3706F2F53B7 ft=1 fh=061b25ba32c75145 vn="Variante von Win32/Toolbar.CrossRider.AJ evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\V-9.1HD\V-9.1HD-codedownloader.exe"
sh=534ED9D4A175A415E49E53E063A7A55B015CF229 ft=1 fh=d2172c34719c6886 vn="Variante von Win32/InstallCore.PK evtl. unerwünschte Anwendung" ac=I fn="C:\Users\TG\AppData\Local\Temp\ICReinstall_nsmDD48.tmp"
sh=13287F94C77CE22E0C11855F6DD07512CC74C105 ft=1 fh=080273d70ec48dd3 vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\Users\TG\Downloads\FreeStudio590.exe"
sh=B9623FD3460649E450A80DB5FA1FB013B93307BB ft=1 fh=c71c00112871741b vn="Variante von Win32/InstallCore.OZ evtl. unerwünschte Anwendung" ac=I fn="C:\Users\TG\Downloads\FreeYouTubeToMP3Converter.exe"
sh=76C19267783B1C3FBE78C7EDFB19EEE1CA020E5B ft=1 fh=24f1c525cd32bc9c vn="Win32/DownWare.L evtl. unerwünschte Anwendung" ac=I fn="C:\Users\TG\Downloads\MyPhoneExplorer_TSV21YHIN\0e8a8fc29a4f3fa38247ff96cc95e649_MyPhoneExplorer_Setup_1.8.5.exe" |