Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 28-01-2015 Ran by rwi at 2015-01-29 10:26:56 Run:1 Running from C:\Users\rwi\Desktop\FRST-OlderVersion Loaded Profiles: rwi (Available profiles: rwi) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: (Microsoft Corporation) C:\Windows\explorer.exe CreateRestorePoint: Task: {73684B5E-055F-47A2-9682-240E1AFEE85F} - System32\Tasks\Windows Update Check - 0x696D087B => C:\ProgramData\anjdfkhm.ru\bjrwzmzis.exe <==== ATTENTION Task: {80B38D87-718E-4764-AC60-7B8AFE1CE745} - System32\Tasks\Windows Update Check - 0x5FF907D6 => C:\ProgramData\Winrar_Update\xegiwezhr.exe [] () <==== ATTENTION HKU\S-1-5-21-2094431546-3998815993-849199213-6484\...\Run: [dXEFj.exe] => C:\Users\rwi\AppData\Local\Temp\dXEFj.exe <===== ATTENTION HKU\S-1-5-21-2094431546-3998815993-849199213-6484\...\Run: [msqilyra.com] => C:\ProgramData\Local Settings\Temp\msqilyra.com [1469440 2009-07-14] () <===== ATTENTION HKU\S-1-5-21-2094431546-3998815993-849199213-6484\...\Run: [000262c7.exe] => C:\Users\rwi\AppData\Local\Temp\000262c7.exe <===== ATTENTION HKU\S-1-5-21-2094431546-3998815993-849199213-6484\...\Run: [00014a0a.exe] => C:\Users\rwi\AppData\Local\Temp\00014a0a.exe <===== ATTENTION HKU\S-1-5-21-2094431546-3998815993-849199213-6484\...\Run: [msvuti.cmd] => C:\ProgramData\Local Settings\Temp\msvuti.cmd [1469440 2009-07-14] () <===== ATTENTION HKU\S-1-5-21-2094431546-3998815993-849199213-6484\...\Run: [0111bf1f.exe] => C:\Users\rwi\AppData\Local\Temp\0111bf1f.exe <===== ATTENTION HKU\S-1-5-21-2094431546-3998815993-849199213-6484\...\Run: [0009c6a8.exe] => C:\Users\rwi\AppData\Local\Temp\0009c6a8.exe <===== ATTENTION HKU\S-1-5-21-2094431546-3998815993-849199213-6484\...\Run: [msvaawe.bat] => C:\ProgramData\Local Settings\Temp\msvaawe.bat [1468928 2009-07-14] () <===== ATTENTION HKU\S-1-5-21-2094431546-3998815993-849199213-6484\...\Run: [0011dcd7.exe] => C:\Users\rwi\AppData\Local\Temp\0011dcd7.exe <===== ATTENTION HKU\S-1-5-21-2094431546-3998815993-849199213-6484\...\Run: [Aktualizacja Przegladarki] => "C:\Users\rwi\AppData\Roaming\Microsoft\ICyq3HsaMLgxgfJrXq.exe" HKU\S-1-5-21-2094431546-3998815993-849199213-6484\...\Run: [000216da.exe] => C:\Users\rwi\AppData\Local\Temp\000216da.exe <===== ATTENTION HKU\S-1-5-21-2094431546-3998815993-849199213-6484\...\Run: [Winrar_Update] => C:\ProgramData\Winrar_Update\xegiwezhr.exe [0 ] () HKU\S-1-5-21-2094431546-3998815993-849199213-6484\...\Run: [eafpajiogfiowgqa.exe] => C:\Users\rwi\AppData\Roaming\eafpajiogfiowgqa.exe [1156608 2015-01-22] () HKLM\...\Run: [] => [X] HKLM\...\Policies\Explorer\Run: [15388] => C:\ProgramData\Local Settings\Temp\msobywg.bat [360448 2009-07-14] ( (Microsoft Corporation)) HKLM\...\Policies\Explorer: [NoFolderOptions] 0 HKLM\...\Policies\Explorer: [NoControlPanel] 0 IFEO\2.ini: [Debugger] wuauclt.exe IFEO\20150122141436608779000000D14.xml: [Debugger] wuauclt.exe IFEO\20150122141436610494300000D14.xml: [Debugger] wuauclt.exe IFEO\20150122141436644745100000D14.xml: [Debugger] wuauclt.exe IFEO\20150122141436659748100000D14.xml: [Debugger] wuauclt.exe IFEO\20150122141436675069800000D14.xml: [Debugger] wuauclt.exe IFEO\20150122141436691848700000D14.xml: [Debugger] wuauclt.exe IFEO\20150122141436706132400000D14.xml: [Debugger] wuauclt.exe IFEO\20150122141436722844600000D14.xml: [Debugger] wuauclt.exe IFEO\20150122141436724077300000D14.xml: [Debugger] wuauclt.exe IFEO\20150122141436755545600000D14.xml: [Debugger] wuauclt.exe IFEO\20150122141436771818200000D14.xml: [Debugger] wuauclt.exe IFEO\20150122141436787883900000D14.xml: [Debugger] wuauclt.exe IFEO\20150122141436802925100000D14.xml: [Debugger] wuauclt.exe IFEO\20150122141436818884900000D14.xml: [Debugger] wuauclt.exe IFEO\20150122141436820082200000D14.xml: [Debugger] wuauclt.exe IFEO\20150122141436852371300000D14.xml: [Debugger] wuauclt.exe IFEO\20150122141436867827900000D14.xml: [Debugger] wuauclt.exe IFEO\20150122141436883057100000D14.xml: [Debugger] wuauclt.exe IFEO\20150122141436898937200000D14.xml: [Debugger] wuauclt.exe IFEO\20150122141436914025100000D14.xml: [Debugger] wuauclt.exe IFEO\20150122141436930620500000D14.xml: [Debugger] wuauclt.exe IFEO\20150122141436945453300000D14.xml: [Debugger] wuauclt.exe IFEO\20150122141436948464300000D14.xml: [Debugger] wuauclt.exe IFEO\20150122141436979595400000D14.xml: [Debugger] wuauclt.exe IFEO\20150122141436994272000000D14.xml: [Debugger] wuauclt.exe IFEO\20150122141437010619800000D14.xml: [Debugger] wuauclt.exe IFEO\20150122141437041487100000D14.xml: [Debugger] wuauclt.exe IFEO\20150122141437044776900000D14.xml: [Debugger] wuauclt.exe IFEO\20150122141437075983900000D14.xml: [Debugger] wuauclt.exe IFEO\20150122141437091065700000D14.xml: [Debugger] wuauclt.exe IFEO\20150122141437106696600000D14.xml: [Debugger] wuauclt.exe IFEO\20150122141437122941400000D14.xml: [Debugger] wuauclt.exe IFEO\20150122141437124017800000D14.xml: [Debugger] wuauclt.exe IFEO\20150122141437155460700000D14.xml: [Debugger] wuauclt.exe IFEO\3.ini: [Debugger] wuauclt.exe IFEO\4.ini: [Debugger] wuauclt.exe IFEO\advisory_dlg.ini: [Debugger] wuauclt.exe IFEO\advisory_dlg.png: [Debugger] wuauclt.exe IFEO\Agent.dll: [Debugger] wuauclt.exe IFEO\Agent.ini: [Debugger] wuauclt.exe IFEO\agentDefault.ini: [Debugger] wuauclt.exe IFEO\AgentEvents: [Debugger] wuauclt.exe IFEO\AgentPlugin.dll: [Debugger] wuauclt.exe IFEO\agentprvkey.bin: [Debugger] wuauclt.exe IFEO\agentpubkey.bin: [Debugger] wuauclt.exe IFEO\AgentRes.Dll: [Debugger] wuauclt.exe IFEO\Agent_FG-MSZ-FIN-RW.log: [Debugger] wuauclt.exe IFEO\Agent_FG-MSZ-FIN-RW.xml: [Debugger] wuauclt.exe IFEO\Agent_FG-MSZ-FIN-RW_backup.log: [Debugger] wuauclt.exe IFEO\Agent_FG-MSZ-FIN-RW_error.log: [Debugger] wuauclt.exe IFEO\Agent_W530-THINK.log: [Debugger] wuauclt.exe IFEO\Agent_W530-THINK.xml: [Debugger] wuauclt.exe IFEO\Agent_W530-THINK_error.log: [Debugger] wuauclt.exe IFEO\allow.png: [Debugger] wuauclt.exe IFEO\AppLib.dll: [Debugger] wuauclt.exe IFEO\aslicense.bin: [Debugger] wuauclt.exe IFEO\avvclean.dat: [Debugger] wuauclt.exe IFEO\avvnames.dat: [Debugger] wuauclt.exe IFEO\avvscan.dat: [Debugger] wuauclt.exe IFEO\BBCpl.dll: [Debugger] wuauclt.exe IFEO\bidirectional.png: [Debugger] wuauclt.exe IFEO\BocDet_VSE.McS: [Debugger] wuauclt.exe IFEO\boost_thread-vc100-mt-1_39.dll: [Debugger] wuauclt.exe IFEO\button_disabled.png: [Debugger] wuauclt.exe IFEO\button_down.png: [Debugger] wuauclt.exe IFEO\button_hover.png: [Debugger] wuauclt.exe IFEO\button_up.png: [Debugger] wuauclt.exe IFEO\cabundle.cer: [Debugger] wuauclt.exe IFEO\catalog.z: [Debugger] wuauclt.exe IFEO\ccme_base.dll: [Debugger] wuauclt.exe IFEO\checked.png: [Debugger] wuauclt.exe IFEO\checkmark.png: [Debugger] wuauclt.exe IFEO\ClientUI.dll: [Debugger] wuauclt.exe IFEO\CMALib.dll: [Debugger] wuauclt.exe IFEO\CMAUIRes.dll: [Debugger] wuauclt.exe IFEO\CmdAgent.exe: [Debugger] wuauclt.exe IFEO\cmdagent.sig: [Debugger] wuauclt.exe IFEO\Common Framework: [Debugger] wuauclt.exe IFEO\ComponentSubsystem.dll: [Debugger] wuauclt.exe IFEO\ComponentUserInterface.dll: [Debugger] wuauclt.exe IFEO\condl.dll: [Debugger] wuauclt.exe IFEO\config.dat: [Debugger] wuauclt.exe IFEO\consl.dll: [Debugger] wuauclt.exe IFEO\coptcpl.dll: [Debugger] wuauclt.exe IFEO\cryptocme2.dll: [Debugger] wuauclt.exe IFEO\cryptocme2.sig: [Debugger] wuauclt.exe IFEO\cryptshim.dll: [Debugger] wuauclt.exe IFEO\csscan.exe: [Debugger] wuauclt.exe IFEO\dainstall.exe: [Debugger] wuauclt.exe IFEO\DataStore.bin: [Debugger] wuauclt.exe IFEO\DesktopProtection: [Debugger] wuauclt.exe IFEO\details_close_normal.png: [Debugger] wuauclt.exe IFEO\details_close_pressed.png: [Debugger] wuauclt.exe IFEO\details_open_normal.png: [Debugger] wuauclt.exe IFEO\details_open_pressed.png: [Debugger] wuauclt.exe IFEO\disallow.png: [Debugger] wuauclt.exe IFEO\Dispatcher.dll: [Debugger] wuauclt.exe IFEO\document.png: [Debugger] wuauclt.exe IFEO\Emabout.dll: [Debugger] wuauclt.exe IFEO\EmailOnDeliveryLog.txt: [Debugger] wuauclt.exe IFEO\EmCfgCpl.dll: [Debugger] wuauclt.exe IFEO\EmHelp.dll: [Debugger] wuauclt.exe IFEO\Engine: [Debugger] wuauclt.exe IFEO\engmin.zip: [Debugger] wuauclt.exe IFEO\engmin64.zip: [Debugger] wuauclt.exe IFEO\EvtFiltr.ini: [Debugger] wuauclt.exe IFEO\folder_closed.png: [Debugger] wuauclt.exe IFEO\folder_open.png: [Debugger] wuauclt.exe IFEO\FrameworkLog.html: [Debugger] wuauclt.exe IFEO\FrameworkLog.js: [Debugger] wuauclt.exe IFEO\FrameworkLog.xsl: [Debugger] wuauclt.exe IFEO\FrameworkLogFirefox.xsl: [Debugger] wuauclt.exe IFEO\FrameworkManifest.xml: [Debugger] wuauclt.exe IFEO\FrameworkService.exe: [Debugger] wuauclt.exe IFEO\FrameworkService.sig: [Debugger] wuauclt.exe IFEO\FrmInst.exe: [Debugger] wuauclt.exe IFEO\ftcfg.dll: [Debugger] wuauclt.exe IFEO\ftl.dll: [Debugger] wuauclt.exe IFEO\Genevtinf3.dll: [Debugger] wuauclt.exe IFEO\GenEvtInf3_64.dll: [Debugger] wuauclt.exe IFEO\gradated_background.png: [Debugger] wuauclt.exe IFEO\gradated_background_with_mcafee_logo.png: [Debugger] wuauclt.exe IFEO\graphics.dll: [Debugger] wuauclt.exe IFEO\gray_checked.png: [Debugger] wuauclt.exe IFEO\grip.png: [Debugger] wuauclt.exe IFEO\group_folder_closed.png: [Debugger] wuauclt.exe IFEO\gui_redirect.ini: [Debugger] wuauclt.exe IFEO\Images: [Debugger] wuauclt.exe IFEO\inbound.png: [Debugger] wuauclt.exe IFEO\inetmgr.dll: [Debugger] wuauclt.exe IFEO\InstallMain.McS: [Debugger] wuauclt.exe IFEO\ipcchannel.dll: [Debugger] wuauclt.exe IFEO\LastProp.xml: [Debugger] wuauclt.exe IFEO\LastPropsSentToServer.xml: [Debugger] wuauclt.exe IFEO\LazyCache.dll: [Debugger] wuauclt.exe IFEO\license.bin: [Debugger] wuauclt.exe IFEO\license.dat: [Debugger] wuauclt.exe IFEO\license.txt: [Debugger] wuauclt.exe IFEO\ListenServer.dll: [Debugger] wuauclt.exe IFEO\lockdown.dll: [Debugger] wuauclt.exe IFEO\Logging.dll: [Debugger] wuauclt.exe IFEO\logparser.exe: [Debugger] wuauclt.exe IFEO\main_window.ini: [Debugger] wuauclt.exe IFEO\Management.dll: [Debugger] wuauclt.exe IFEO\mcadmin.exe: [Debugger] wuauclt.exe IFEO\McAfee: [Debugger] wuauclt.exe IFEO\McAfeeCommonUpdaterPlugin.dll: [Debugger] wuauclt.exe IFEO\McAfeeWin32GUISupportDLL.dll: [Debugger] wuauclt.exe IFEO\mcafee_m_small.png: [Debugger] wuauclt.exe IFEO\McAVDetect.DLL: [Debugger] wuauclt.exe IFEO\McAVSCV.DLL: [Debugger] wuauclt.exe IFEO\mcconsol.exe: [Debugger] wuauclt.exe IFEO\McScan32.dll: [Debugger] wuauclt.exe IFEO\McScanCheck.exe: [Debugger] wuauclt.exe IFEO\McScript.log: [Debugger] wuauclt.exe IFEO\McScript_backup.log: [Debugger] wuauclt.exe IFEO\McScript_error.log: [Debugger] wuauclt.exe IFEO\McScript_error_backup.log: [Debugger] wuauclt.exe IFEO\McScript_InUse.exe: [Debugger] wuauclt.exe IFEO\McShield.dll: [Debugger] wuauclt.exe IFEO\McTray: [Debugger] wuauclt.exe IFEO\McTray.exe: [Debugger] wuauclt.exe IFEO\McTrayErrorLoggingPlugin.dll: [Debugger] wuauclt.exe IFEO\McTrayEventLog.dll: [Debugger] wuauclt.exe IFEO\McTrayInstSupp.dll: [Debugger] wuauclt.exe IFEO\McTrayInterfaceLib.dll: [Debugger] wuauclt.exe IFEO\McTrayLegacySupportPlugin32.dll: [Debugger] wuauclt.exe IFEO\McTrayRes.dll: [Debugger] wuauclt.exe IFEO\mcupdate.exe: [Debugger] wuauclt.exe IFEO\Mcurial.Dll: [Debugger] wuauclt.exe IFEO\mcvssnmp.dll: [Debugger] wuauclt.exe IFEO\MERTool.url: [Debugger] wuauclt.exe IFEO\Messages.dat: [Debugger] wuauclt.exe IFEO\mfeagent.cat: [Debugger] wuauclt.exe IFEO\MFEagent.msi: [Debugger] wuauclt.exe IFEO\mfeann.exe: [Debugger] wuauclt.exe IFEO\mfeapconfig.dll: [Debugger] wuauclt.exe IFEO\mfeavfa.dll: [Debugger] wuauclt.exe IFEO\mfeCmnLib71.dll: [Debugger] wuauclt.exe IFEO\mfecryptc.dll: [Debugger] wuauclt.exe IFEO\mfecryptc.sig: [Debugger] wuauclt.exe IFEO\mfecurl.dll: [Debugger] wuauclt.exe IFEO\mfediscovery.dll: [Debugger] wuauclt.exe IFEO\mfehida.dll: [Debugger] wuauclt.exe IFEO\mfehidin.exe: [Debugger] wuauclt.exe IFEO\mfelpc.dll: [Debugger] wuauclt.exe IFEO\mferuntime20150119092906965.dat: [Debugger] wuauclt.exe IFEO\MfeServiceMgr.exe: [Debugger] wuauclt.exe IFEO\MfeServiceMgr.sig: [Debugger] wuauclt.exe IFEO\mfevtpa.dll: [Debugger] wuauclt.exe IFEO\mfezlib.dll: [Debugger] wuauclt.exe IFEO\Microsoft.VC100.CRT.manifest: [Debugger] wuauclt.exe IFEO\Microsoft.VC80.CRT.manifest: [Debugger] wuauclt.exe IFEO\midutil.dll: [Debugger] wuauclt.exe IFEO\minus_sign.png: [Debugger] wuauclt.exe IFEO\msaconfig.exe: [Debugger] wuauclt.exe IFEO\msaconfig.sig: [Debugger] wuauclt.exe IFEO\Mscan64a.dll: [Debugger] wuauclt.exe IFEO\msvcm80.dll: [Debugger] wuauclt.exe IFEO\msvcp100.dll: [Debugger] wuauclt.exe IFEO\msvcp71.dll: [Debugger] wuauclt.exe IFEO\msvcp80.dll: [Debugger] wuauclt.exe IFEO\msvcr100.dll: [Debugger] wuauclt.exe IFEO\msvcr71.dll: [Debugger] wuauclt.exe IFEO\msvcr80.dll: [Debugger] wuauclt.exe IFEO\Mue.exe: [Debugger] wuauclt.exe IFEO\Mue.sig: [Debugger] wuauclt.exe IFEO\MueRes.dll: [Debugger] wuauclt.exe IFEO\MueRes_InUse.dll: [Debugger] wuauclt.exe IFEO\mytilus3.dll: [Debugger] wuauclt.exe IFEO\mytilus3_worker.dll: [Debugger] wuauclt.exe IFEO\naCmnLib3_71.dll: [Debugger] wuauclt.exe IFEO\naevent.dll: [Debugger] wuauclt.exe IFEO\nagshr32.dll: [Debugger] wuauclt.exe IFEO\naiann.dll: [Debugger] wuauclt.exe IFEO\nailite.dll: [Debugger] wuauclt.exe IFEO\nailog3.dll: [Debugger] wuauclt.exe IFEO\Nainet.dll: [Debugger] wuauclt.exe IFEO\naitcpp.inf: [Debugger] wuauclt.exe IFEO\naPolicyManager.dll: [Debugger] wuauclt.exe IFEO\naPrdMgr.exe: [Debugger] wuauclt.exe IFEO\naPrdMgr.sig: [Debugger] wuauclt.exe IFEO\naSPIPE.dll: [Debugger] wuauclt.exe IFEO\naxml3_71.dll: [Debugger] wuauclt.exe IFEO\naziplib.dll: [Debugger] wuauclt.exe IFEO\NextProp.xml: [Debugger] wuauclt.exe IFEO\no_symbol.png: [Debugger] wuauclt.exe IFEO\nvpcpl.dll: [Debugger] wuauclt.exe IFEO\OASCpl.dll: [Debugger] wuauclt.exe IFEO\OtlkScan.dll: [Debugger] wuauclt.exe IFEO\OtlkUI.20130924155504.dll: [Debugger] wuauclt.exe IFEO\outbound.png: [Debugger] wuauclt.exe IFEO\Patchw32.dll: [Debugger] wuauclt.exe IFEO\PcrPlug.dll: [Debugger] wuauclt.exe IFEO\pireg.exe: [Debugger] wuauclt.exe IFEO\pkg00130283738398530000_3823725180.spkg: [Debugger] wuauclt.exe IFEO\pkg00130283738402590000_141706860.spkg: [Debugger] wuauclt.exe IFEO\pkg00130486978620150000_905842077.spkg: [Debugger] wuauclt.exe IFEO\pkg00130486981276420000_3922522066.spkg: [Debugger] wuauclt.exe IFEO\pkg00130486993533310000_2427086521.spkg: [Debugger] wuauclt.exe IFEO\pkg00130487016472650000_2437068241.spkg: [Debugger] wuauclt.exe IFEO\pkg00130487026266050000_104983657.spkg: [Debugger] wuauclt.exe IFEO\pkg00130487037854760000_2400459517.spkg: [Debugger] wuauclt.exe IFEO\pkg00130487545952870000_3180744114.spkg: [Debugger] wuauclt.exe IFEO\pkg00130487575498580000_1637079096.spkg: [Debugger] wuauclt.exe IFEO\pkg00130487587802080000_505750469.spkg: [Debugger] wuauclt.exe IFEO\pkg00130487610670040000_218874406.spkg: [Debugger] wuauclt.exe IFEO\pkg00130487645271680000_1186786167.spkg: [Debugger] wuauclt.exe IFEO\pkg00130487672523070000_1049954230.spkg: [Debugger] wuauclt.exe IFEO\pkg00130487683475170000_2917543291.spkg: [Debugger] wuauclt.exe IFEO\pkg00130487705485430000_3177136656.spkg: [Debugger] wuauclt.exe IFEO\pkg00130487739705730000_3770996762.spkg: [Debugger] wuauclt.exe IFEO\pkg00130487769326820000_3176360642.spkg: [Debugger] wuauclt.exe IFEO\pkg00130487781808500000_2016455484.spkg: [Debugger] wuauclt.exe IFEO\pkg00130487804240070000_709036342.spkg: [Debugger] wuauclt.exe IFEO\pkg00130487840052670000_1136986743.spkg: [Debugger] wuauclt.exe IFEO\pkg00130487856184430000_3399027147.spkg: [Debugger] wuauclt.exe IFEO\pkg00130487867676080000_660593062.spkg: [Debugger] wuauclt.exe IFEO\pkg00130488472348410000_1609362892.spkg: [Debugger] wuauclt.exe IFEO\pkg00130488484738450000_2777886704.spkg: [Debugger] wuauclt.exe IFEO\pkg00130488505740290000_3665425022.spkg: [Debugger] wuauclt.exe IFEO\pkg00130488538686540000_1510983857.spkg: [Debugger] wuauclt.exe IFEO\pkg00130488572528190000_1720763739.spkg: [Debugger] wuauclt.exe IFEO\pkg00130488583410500000_751044111.spkg: [Debugger] wuauclt.exe IFEO\pkg00130488610516290000_3335329728.spkg: [Debugger] wuauclt.exe IFEO\pkg00130488644282870000_3692162735.spkg: [Debugger] wuauclt.exe IFEO\pkg00130488668007880000_2077638625.spkg: [Debugger] wuauclt.exe IFEO\pkg00130488678374570000_516215274.spkg: [Debugger] wuauclt.exe IFEO\pkg00130488701563330000_195051264.spkg: [Debugger] wuauclt.exe IFEO\pkg00130488732852500000_590295132.spkg: [Debugger] wuauclt.exe IFEO\pkg00130489304600020000_3585717127.spkg: [Debugger] wuauclt.exe IFEO\pkg00130489460265300000_443515461.spkg: [Debugger] wuauclt.exe IFEO\pkg00130489460367170000_3859414461.spkg: [Debugger] wuauclt.exe IFEO\pkg00130489483567930000_1100563953.spkg: [Debugger] wuauclt.exe IFEO\pkg00130489525328520000_2271446734.spkg: [Debugger] wuauclt.exe IFEO\pkg00130489539788930000_2410246629.spkg: [Debugger] wuauclt.exe IFEO\pkg00130489570908150000_3380911397.spkg: [Debugger] wuauclt.exe IFEO\pkg00130489596888100000_538301776.spkg: [Debugger] wuauclt.exe IFEO\pkg00130493626822070000_3758387281.spkg: [Debugger] wuauclt.exe IFEO\pkg00130493645766480000_1204911931.spkg: [Debugger] wuauclt.exe IFEO\pkg00130493680537200000_3191195673.spkg: [Debugger] wuauclt.exe IFEO\pkg00130493695915330000_855238066.spkg: [Debugger] wuauclt.exe IFEO\pkg00130493719116360000_284180699.spkg: [Debugger] wuauclt.exe IFEO\pkg00130493760697140000_1623165773.spkg: [Debugger] wuauclt.exe IFEO\pkg00130493774207620000_3513265569.spkg: [Debugger] wuauclt.exe IFEO\pkg00130493807668300000_174765869.spkg: [Debugger] wuauclt.exe IFEO\pkg00130493834569110000_1155875258.spkg: [Debugger] wuauclt.exe IFEO\pkg00130493853059510000_3822309134.spkg: [Debugger] wuauclt.exe IFEO\pkg00130493888943110000_3891416026.spkg: [Debugger] wuauclt.exe IFEO\pkg00130493898750880000_2888344145.spkg: [Debugger] wuauclt.exe IFEO\pkg00130493922991100000_2224162039.spkg: [Debugger] wuauclt.exe IFEO\pkg00130494541665580000_2147771041.spkg: [Debugger] wuauclt.exe IFEO\pkg00130494542448000000_2064125646.spkg: [Debugger] wuauclt.exe IFEO\pkg00130494566415960000_4051398629.spkg: [Debugger] wuauclt.exe IFEO\pkg00130494608677100000_1713622191.spkg: [Debugger] wuauclt.exe IFEO\pkg00130628477543890000_1178998994.spkg: [Debugger] wuauclt.exe IFEO\pkg00130628477544040000_3663141724.spkg: [Debugger] wuauclt.exe IFEO\pkg00130628477549180000_4282010264.spkg: [Debugger] wuauclt.exe IFEO\pkg00130628477549960000_298415004.spkg: [Debugger] wuauclt.exe IFEO\plus_sign.png: [Debugger] wuauclt.exe IFEO\PoEvtInf.dll: [Debugger] wuauclt.exe IFEO\PrdMgr_FG-MSZ-FIN-RW.log: [Debugger] wuauclt.exe IFEO\PrdMgr_FG-MSZ-FIN-RW_error.log: [Debugger] wuauclt.exe IFEO\PrdMgr_W530-THINK.log: [Debugger] wuauclt.exe IFEO\PrdMgr_W530-THINK_error.log: [Debugger] wuauclt.exe IFEO\QuarCpl.dll: [Debugger] wuauclt.exe IFEO\readme.html: [Debugger] wuauclt.exe IFEO\RepoKeys.ini: [Debugger] wuauclt.exe IFEO\restartvse.exe: [Debugger] wuauclt.exe IFEO\rule_folder_closed.png: [Debugger] wuauclt.exe IFEO\scan32.exe: [Debugger] wuauclt.exe IFEO\Scan64.Exe: [Debugger] wuauclt.exe IFEO\Scheduler.dll: [Debugger] wuauclt.exe IFEO\ScnCfg32.Exe: [Debugger] wuauclt.exe IFEO\scriptff.dll: [Debugger] wuauclt.exe IFEO\ScriptSn.20130924155504.dll: [Debugger] wuauclt.exe IFEO\scriptsn.dll: [Debugger] wuauclt.exe IFEO\SecureFrameworkFactory3.dll: [Debugger] wuauclt.exe IFEO\Server.bin: [Debugger] wuauclt.exe IFEO\serverDefault.xml: [Debugger] wuauclt.exe IFEO\serverpubkey.bin: [Debugger] wuauclt.exe IFEO\serverreqseckey.bin: [Debugger] wuauclt.exe IFEO\ServerSiteList.xml: [Debugger] wuauclt.exe IFEO\shcfg32.exe: [Debugger] wuauclt.exe IFEO\shext.dll: [Debugger] wuauclt.exe IFEO\shstat.dll: [Debugger] wuauclt.exe IFEO\shstat.exe: [Debugger] wuauclt.exe IFEO\shutil.dll: [Debugger] wuauclt.exe IFEO\SignLic.Txt: [Debugger] wuauclt.exe IFEO\sitecache.bin: [Debugger] wuauclt.exe IFEO\SiteList.xml: [Debugger] wuauclt.exe IFEO\SiteStat.xml: [Debugger] wuauclt.exe IFEO\splashscreen.png: [Debugger] wuauclt.exe IFEO\strings.bin: [Debugger] wuauclt.exe IFEO\Subscriptions.txt: [Debugger] wuauclt.exe IFEO\SvcMgr_FG-MSZ-FIN-RW.log: [Debugger] wuauclt.exe IFEO\SvcMgr_FG-MSZ-FIN-RW_error.log: [Debugger] wuauclt.exe IFEO\SystemCore: [Debugger] wuauclt.exe IFEO\system_status_error_medium.png: [Debugger] wuauclt.exe IFEO\system_status_ok_medium.png: [Debugger] wuauclt.exe IFEO\system_status_warning_medium.png: [Debugger] wuauclt.exe IFEO\Task: [Debugger] wuauclt.exe IFEO\trailer.png: [Debugger] wuauclt.exe IFEO\tray_menu_issue.png: [Debugger] wuauclt.exe IFEO\tray_menu_okay.png: [Debugger] wuauclt.exe IFEO\UdaterUI.exe: [Debugger] wuauclt.exe IFEO\UdaterUI.sig: [Debugger] wuauclt.exe IFEO\unchecked.png: [Debugger] wuauclt.exe IFEO\UpdateHistory.ini: [Debugger] wuauclt.exe IFEO\UpdateMain.McS: [Debugger] wuauclt.exe IFEO\updater.Dll: [Debugger] wuauclt.exe IFEO\UpdateSubSys.Dll: [Debugger] wuauclt.exe IFEO\UpdPlug.Dll: [Debugger] wuauclt.exe IFEO\UpdRes.Dll: [Debugger] wuauclt.exe IFEO\UserSpace.Dll: [Debugger] wuauclt.exe IFEO\V2datdet.mcs: [Debugger] wuauclt.exe IFEO\V2engdet.mcs: [Debugger] wuauclt.exe IFEO\V2enginstall.mcs: [Debugger] wuauclt.exe IFEO\VirusScan Enterprise: [Debugger] wuauclt.exe IFEO\vse880.msi: [Debugger] wuauclt.exe IFEO\VSE880Det.McS: [Debugger] wuauclt.exe IFEO\VsEvntUI.DLL: [Debugger] wuauclt.exe IFEO\vsodscpl.dll: [Debugger] wuauclt.exe IFEO\vsplugin.dll: [Debugger] wuauclt.exe IFEO\VsTskMgr.exe: [Debugger] wuauclt.exe IFEO\vsupdate.dll: [Debugger] wuauclt.exe IFEO\vsupdcpl.dll: [Debugger] wuauclt.exe IFEO\wmain.dll: [Debugger] wuauclt.exe IFEO\WscAv.dll: [Debugger] wuauclt.exe IFEO\wscavexe.exe: [Debugger] wuauclt.exe IFEO\XMLWrap.Dll: [Debugger] wuauclt.exe IFEO\{A14CD6FC-3BA8-4703-87BF-E3247CE382F5}.ini: [Debugger] wuauclt.exe ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File ShellIconOverlayIdentifiers: [SugarSyncBackedUp] -> {0C4A258A-3F3B-4FFF-80A7-9B3BEC139472} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll No File ShellIconOverlayIdentifiers: [SugarSyncPending] -> {62CCD8E3-9C21-41E1-B55E-1E26DFC68511} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll No File ShellIconOverlayIdentifiers: [SugarSyncRoot] -> {A759AFF6-5851-457D-A540-F4ECED148351} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll No File ShellIconOverlayIdentifiers: [SugarSyncShared] -> {1574C9EF-7D58-488F-B358-8B78C1538F51} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll No File ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File CustomCLSID: HKU\S-1-5-21-2094431546-3998815993-849199213-6484_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\rwi\AppData\Roaming\Dropbox\bin\Dropbox.exe /autoplay No File HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank BHO-x32: scriptproxy -> {7DB2D5A0-7241-4E79-B68D-6309F01C5231} -> C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20130924155504.dll No File S2 smihlp2; \??\C:\Program Files\ThinkVantage Fingerprint Software\smihlp.sys [X] U4 srservice; No ImagePath AlternateDataStreams: C:\Users\rwi:id C:\ProgramData\anjdfkhm.ru C:\ProgramData\Local Settings\Temp C:\ProgramData\WinMediaManager00 C:\ProgramData\Winrar_Update C:\Users\rwi\AppData\OICE_15_974FA576_32C1D314_B79 C:\Users\rwi\AppData\Roaming\browserup32.exe C:\Users\rwi\AppData\Roaming\eafpajiogfiowgqa.exe C:\Users\rwi\AppData\Roaming\pid.txt C:\Users\rwi\AppData\Roaming\pidloc.txt C:\Users\rwi\AppData\Roaming\WinMediaManager00 C:\Users\rwi\Desktop\hs_err_pid*.log Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f Reg: reg delete HKCU\Software\Mozilla /f Reg: reg delete HKCU\Software\MozillaPlugins /f Reg: reg delete HKLM\SOFTWARE\Mozilla /f Reg: reg delete HKLM\SOFTWARE\MozillaPlugins /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Mozilla /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\mozilla.org /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\MozillaPlugins /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f CMD: for /d %f in (C:\Users\rwi\AppData\Local\{*}) do rd /s /q "%f" CMD: dir /a C:\ProgramData CMD: dir /a C:\Users\rwi\AppData\Roaming\Microsoft Folder: C:\Program Files\Windows Defender Folder: C:\Program Files (x86)\Windows Defender EmptyTemp: ***************** Processes closed successfully. [1676] C:\Windows\explorer.exe => Process closed successfully. Restore point was successfully created. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{73684B5E-055F-47A2-9682-240E1AFEE85F}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{73684B5E-055F-47A2-9682-240E1AFEE85F}" => Key deleted successfully. C:\Windows\System32\Tasks\Windows Update Check - 0x696D087B => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Windows Update Check - 0x696D087B" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{80B38D87-718E-4764-AC60-7B8AFE1CE745}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{80B38D87-718E-4764-AC60-7B8AFE1CE745}" => Key deleted successfully. C:\Windows\System32\Tasks\Windows Update Check - 0x5FF907D6 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Windows Update Check - 0x5FF907D6" => Key deleted successfully. HKU\S-1-5-21-2094431546-3998815993-849199213-6484\Software\Microsoft\Windows\CurrentVersion\Run\\dXEFj.exe => value deleted successfully. HKU\S-1-5-21-2094431546-3998815993-849199213-6484\Software\Microsoft\Windows\CurrentVersion\Run\\msqilyra.com => value deleted successfully. HKU\S-1-5-21-2094431546-3998815993-849199213-6484\Software\Microsoft\Windows\CurrentVersion\Run\\000262c7.exe => value deleted successfully. HKU\S-1-5-21-2094431546-3998815993-849199213-6484\Software\Microsoft\Windows\CurrentVersion\Run\\00014a0a.exe => value deleted successfully. HKU\S-1-5-21-2094431546-3998815993-849199213-6484\Software\Microsoft\Windows\CurrentVersion\Run\\msvuti.cmd => value deleted successfully. HKU\S-1-5-21-2094431546-3998815993-849199213-6484\Software\Microsoft\Windows\CurrentVersion\Run\\0111bf1f.exe => value deleted successfully. HKU\S-1-5-21-2094431546-3998815993-849199213-6484\Software\Microsoft\Windows\CurrentVersion\Run\\0009c6a8.exe => value deleted successfully. HKU\S-1-5-21-2094431546-3998815993-849199213-6484\Software\Microsoft\Windows\CurrentVersion\Run\\msvaawe.bat => value deleted successfully. HKU\S-1-5-21-2094431546-3998815993-849199213-6484\Software\Microsoft\Windows\CurrentVersion\Run\\0011dcd7.exe => value deleted successfully. HKU\S-1-5-21-2094431546-3998815993-849199213-6484\Software\Microsoft\Windows\CurrentVersion\Run\\Aktualizacja Przegladarki => value deleted successfully. HKU\S-1-5-21-2094431546-3998815993-849199213-6484\Software\Microsoft\Windows\CurrentVersion\Run\\000216da.exe => value deleted successfully. HKU\S-1-5-21-2094431546-3998815993-849199213-6484\Software\Microsoft\Windows\CurrentVersion\Run\\Winrar_Update => value deleted successfully. HKU\S-1-5-21-2094431546-3998815993-849199213-6484\Software\Microsoft\Windows\CurrentVersion\Run\\eafpajiogfiowgqa.exe => value deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\\15388 => Value not found. HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFolderOptions => value deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoControlPanel => value deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\2.ini" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\20150122141436608779000000D14.xml" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\20150122141436610494300000D14.xml" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\20150122141436644745100000D14.xml" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\20150122141436659748100000D14.xml" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\20150122141436675069800000D14.xml" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\20150122141436691848700000D14.xml" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\20150122141436706132400000D14.xml" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\20150122141436722844600000D14.xml" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\20150122141436724077300000D14.xml" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\20150122141436755545600000D14.xml" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\20150122141436771818200000D14.xml" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\20150122141436787883900000D14.xml" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\20150122141436802925100000D14.xml" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\20150122141436818884900000D14.xml" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\20150122141436820082200000D14.xml" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\20150122141436852371300000D14.xml" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\20150122141436867827900000D14.xml" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\20150122141436883057100000D14.xml" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\20150122141436898937200000D14.xml" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\20150122141436914025100000D14.xml" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\20150122141436930620500000D14.xml" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\20150122141436945453300000D14.xml" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\20150122141436948464300000D14.xml" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\20150122141436979595400000D14.xml" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\20150122141436994272000000D14.xml" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\20150122141437010619800000D14.xml" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\20150122141437041487100000D14.xml" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\20150122141437044776900000D14.xml" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\20150122141437075983900000D14.xml" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\20150122141437091065700000D14.xml" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\20150122141437106696600000D14.xml" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\20150122141437122941400000D14.xml" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\20150122141437124017800000D14.xml" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\20150122141437155460700000D14.xml" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\3.ini" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\4.ini" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\advisory_dlg.ini" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\advisory_dlg.png" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\Agent.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\Agent.ini" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\agentDefault.ini" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\AgentEvents" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\AgentPlugin.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\agentprvkey.bin" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\agentpubkey.bin" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\AgentRes.Dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\Agent_FG-MSZ-FIN-RW.log" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\Agent_FG-MSZ-FIN-RW.xml" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\Agent_FG-MSZ-FIN-RW_backup.log" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\Agent_FG-MSZ-FIN-RW_error.log" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\Agent_W530-THINK.log" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\Agent_W530-THINK.xml" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\Agent_W530-THINK_error.log" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\allow.png" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\AppLib.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\aslicense.bin" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\avvclean.dat" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\avvnames.dat" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\avvscan.dat" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\BBCpl.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\bidirectional.png" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\BocDet_VSE.McS" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\boost_thread-vc100-mt-1_39.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\button_disabled.png" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\button_down.png" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\button_hover.png" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\button_up.png" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\cabundle.cer" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\catalog.z" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\ccme_base.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\checked.png" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\checkmark.png" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\ClientUI.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\CMALib.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\CMAUIRes.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\CmdAgent.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\cmdagent.sig" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\Common Framework" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\ComponentSubsystem.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\ComponentUserInterface.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\condl.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\config.dat" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\consl.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\coptcpl.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\cryptocme2.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\cryptocme2.sig" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\cryptshim.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\csscan.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\dainstall.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\DataStore.bin" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\DesktopProtection" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\details_close_normal.png" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\details_close_pressed.png" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\details_open_normal.png" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\details_open_pressed.png" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\disallow.png" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\Dispatcher.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\document.png" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\Emabout.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\EmailOnDeliveryLog.txt" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\EmCfgCpl.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\EmHelp.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\Engine" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\engmin.zip" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\engmin64.zip" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\EvtFiltr.ini" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\folder_closed.png" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\folder_open.png" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\FrameworkLog.html" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\FrameworkLog.js" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\FrameworkLog.xsl" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\FrameworkLogFirefox.xsl" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\FrameworkManifest.xml" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\FrameworkService.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\FrameworkService.sig" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\FrmInst.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\ftcfg.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\ftl.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\Genevtinf3.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\GenEvtInf3_64.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\gradated_background.png" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\gradated_background_with_mcafee_logo.png" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\graphics.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\gray_checked.png" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\grip.png" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\group_folder_closed.png" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\gui_redirect.ini" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\Images" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\inbound.png" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\inetmgr.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\InstallMain.McS" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\ipcchannel.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\LastProp.xml" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\LastPropsSentToServer.xml" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\LazyCache.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\license.bin" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\license.dat" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\license.txt" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\ListenServer.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\lockdown.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\Logging.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\logparser.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\main_window.ini" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\Management.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\mcadmin.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\McAfee" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\McAfeeCommonUpdaterPlugin.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\McAfeeWin32GUISupportDLL.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\mcafee_m_small.png" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\McAVDetect.DLL" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\McAVSCV.DLL" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\mcconsol.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\McScan32.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\McScanCheck.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\McScript.log" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\McScript_backup.log" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\McScript_error.log" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\McScript_error_backup.log" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\McScript_InUse.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\McShield.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\McTray" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\McTray.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\McTrayErrorLoggingPlugin.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\McTrayEventLog.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\McTrayInstSupp.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\McTrayInterfaceLib.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\McTrayLegacySupportPlugin32.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\McTrayRes.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\mcupdate.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\Mcurial.Dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\mcvssnmp.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\MERTool.url" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\Messages.dat" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\mfeagent.cat" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\MFEagent.msi" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\mfeann.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\mfeapconfig.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\mfeavfa.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\mfeCmnLib71.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\mfecryptc.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\mfecryptc.sig" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\mfecurl.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\mfediscovery.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\mfehida.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\mfehidin.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\mfelpc.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\mferuntime20150119092906965.dat" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\MfeServiceMgr.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\MfeServiceMgr.sig" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\mfevtpa.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\mfezlib.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\Microsoft.VC100.CRT.manifest" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\Microsoft.VC80.CRT.manifest" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\midutil.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\minus_sign.png" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\msaconfig.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\msaconfig.sig" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\Mscan64a.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\msvcm80.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\msvcp100.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\msvcp71.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\msvcp80.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\msvcr100.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\msvcr71.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\msvcr80.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\Mue.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\Mue.sig" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\MueRes.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\MueRes_InUse.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\mytilus3.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\mytilus3_worker.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\naCmnLib3_71.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\naevent.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\nagshr32.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\naiann.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\nailite.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\nailog3.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\Nainet.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\naitcpp.inf" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\naPolicyManager.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\naPrdMgr.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\naPrdMgr.sig" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\naSPIPE.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\naxml3_71.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\naziplib.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\NextProp.xml" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\no_symbol.png" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\nvpcpl.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\OASCpl.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\OtlkScan.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\OtlkUI.20130924155504.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\outbound.png" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\Patchw32.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\PcrPlug.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pireg.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130283738398530000_3823725180.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130283738402590000_141706860.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130486978620150000_905842077.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130486981276420000_3922522066.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130486993533310000_2427086521.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130487016472650000_2437068241.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130487026266050000_104983657.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130487037854760000_2400459517.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130487545952870000_3180744114.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130487575498580000_1637079096.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130487587802080000_505750469.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130487610670040000_218874406.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130487645271680000_1186786167.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130487672523070000_1049954230.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130487683475170000_2917543291.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130487705485430000_3177136656.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130487739705730000_3770996762.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130487769326820000_3176360642.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130487781808500000_2016455484.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130487804240070000_709036342.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130487840052670000_1136986743.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130487856184430000_3399027147.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130487867676080000_660593062.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130488472348410000_1609362892.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130488484738450000_2777886704.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130488505740290000_3665425022.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130488538686540000_1510983857.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130488572528190000_1720763739.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130488583410500000_751044111.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130488610516290000_3335329728.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130488644282870000_3692162735.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130488668007880000_2077638625.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130488678374570000_516215274.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130488701563330000_195051264.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130488732852500000_590295132.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130489304600020000_3585717127.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130489460265300000_443515461.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130489460367170000_3859414461.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130489483567930000_1100563953.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130489525328520000_2271446734.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130489539788930000_2410246629.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130489570908150000_3380911397.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130489596888100000_538301776.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130493626822070000_3758387281.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130493645766480000_1204911931.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130493680537200000_3191195673.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130493695915330000_855238066.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130493719116360000_284180699.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130493760697140000_1623165773.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130493774207620000_3513265569.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130493807668300000_174765869.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130493834569110000_1155875258.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130493853059510000_3822309134.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130493888943110000_3891416026.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130493898750880000_2888344145.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130493922991100000_2224162039.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130494541665580000_2147771041.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130494542448000000_2064125646.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130494566415960000_4051398629.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130494608677100000_1713622191.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130628477543890000_1178998994.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130628477544040000_3663141724.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130628477549180000_4282010264.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pkg00130628477549960000_298415004.spkg" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\plus_sign.png" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\PoEvtInf.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\PrdMgr_FG-MSZ-FIN-RW.log" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\PrdMgr_FG-MSZ-FIN-RW_error.log" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\PrdMgr_W530-THINK.log" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\PrdMgr_W530-THINK_error.log" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\QuarCpl.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\readme.html" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\RepoKeys.ini" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\restartvse.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\rule_folder_closed.png" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\scan32.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\Scan64.Exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\Scheduler.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\ScnCfg32.Exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\scriptff.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\ScriptSn.20130924155504.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\scriptsn.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\SecureFrameworkFactory3.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\Server.bin" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\serverDefault.xml" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\serverpubkey.bin" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\serverreqseckey.bin" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\ServerSiteList.xml" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\shcfg32.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\shext.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\shstat.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\shstat.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\shutil.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\SignLic.Txt" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\sitecache.bin" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\SiteList.xml" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\SiteStat.xml" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\splashscreen.png" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\strings.bin" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\Subscriptions.txt" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\SvcMgr_FG-MSZ-FIN-RW.log" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\SvcMgr_FG-MSZ-FIN-RW_error.log" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\SystemCore" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\system_status_error_medium.png" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\system_status_ok_medium.png" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\system_status_warning_medium.png" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\Task" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\trailer.png" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\tray_menu_issue.png" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\tray_menu_okay.png" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\UdaterUI.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\UdaterUI.sig" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\unchecked.png" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\UpdateHistory.ini" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\UpdateMain.McS" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\updater.Dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\UpdateSubSys.Dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\UpdPlug.Dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\UpdRes.Dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\UserSpace.Dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\V2datdet.mcs" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\V2engdet.mcs" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\V2enginstall.mcs" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\VirusScan Enterprise" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\vse880.msi" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\VSE880Det.McS" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\VsEvntUI.DLL" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\vsodscpl.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\vsplugin.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\VsTskMgr.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\vsupdate.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\vsupdcpl.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\wmain.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\WscAv.dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\wscavexe.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\XMLWrap.Dll" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\{A14CD6FC-3BA8-4703-87BF-E3247CE382F5}.ini" => Key deleted successfully. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive1" => Key deleted successfully. HKCR\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A} => Key not found. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive2" => Key deleted successfully. HKCR\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => Key not found. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive3" => Key deleted successfully. HKCR\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524} => Key not found. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => Key deleted successfully. HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => Key not found. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\SugarSyncBackedUp" => Key deleted successfully. "HKCR\CLSID\{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472}" => Key deleted successfully. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\SugarSyncPending" => Key deleted successfully. "HKCR\CLSID\{62CCD8E3-9C21-41E1-B55E-1E26DFC68511}" => Key deleted successfully. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\SugarSyncRoot" => Key deleted successfully. "HKCR\CLSID\{A759AFF6-5851-457D-A540-F4ECED148351}" => Key deleted successfully. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\SugarSyncShared" => Key deleted successfully. "HKCR\CLSID\{1574C9EF-7D58-488F-B358-8B78C1538F51}" => Key deleted successfully. "HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive1" => Key deleted successfully. HKCR\Wow6432Node\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A} => Key not found. "HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive2" => Key deleted successfully. HKCR\Wow6432Node\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => Key not found. "HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive3" => Key deleted successfully. HKCR\Wow6432Node\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524} => Key not found. "HKU\S-1-5-21-2094431546-3998815993-849199213-6484_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}" => Key deleted successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7DB2D5A0-7241-4E79-B68D-6309F01C5231}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{7DB2D5A0-7241-4E79-B68D-6309F01C5231}" => Key deleted successfully. smihlp2 => Service deleted successfully. srservice => Service deleted successfully. C:\Users\rwi => ":id" ADS removed successfully. C:\ProgramData\anjdfkhm.ru => Moved successfully. C:\ProgramData\Local Settings\Temp => Moved successfully. C:\ProgramData\WinMediaManager00 => Moved successfully. "C:\ProgramData\Winrar_Update" directory move: Could not move "C:\ProgramData\Winrar_Update" directory. => Scheduled to move on reboot. C:\Users\rwi\AppData\OICE_15_974FA576_32C1D314_B79 => Moved successfully. C:\Users\rwi\AppData\Roaming\browserup32.exe => Moved successfully. C:\Users\rwi\AppData\Roaming\eafpajiogfiowgqa.exe => Moved successfully. C:\Users\rwi\AppData\Roaming\pid.txt => Moved successfully. C:\Users\rwi\AppData\Roaming\pidloc.txt => Moved successfully. C:\Users\rwi\AppData\Roaming\WinMediaManager00 => Moved successfully. C:\Users\rwi\Desktop\hs_err_pid*.log => Moved successfully. ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= Operacja ukoäczona pomylnie. ========= End of Reg: ========= ========= reg delete HKCU\Software\Mozilla /f ========= Operacja ukoäczona pomylnie. ========= End of Reg: ========= ========= reg delete HKCU\Software\MozillaPlugins /f ========= Operacja ukoäczona pomylnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Mozilla /f ========= Operacja ukoäczona pomylnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\MozillaPlugins /f ========= Operacja ukoäczona pomylnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\Mozilla /f ========= Operacja ukoäczona pomylnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\mozilla.org /f ========= Operacja ukoäczona pomylnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\MozillaPlugins /f ========= Operacja ukoäczona pomylnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomylnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomylnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomylnie. ========= End of Reg: ========= ========= for /d %f in (C:\Users\rwi\AppData\Local\{*}) do rd /s /q "%f" ========= ========= End of CMD: ========= ========= dir /a C:\ProgramData ========= Wolumin w stacji C to Windows7_OS Numer seryjny woluminu: F917-3C1C Katalog: C:\ProgramData 2015-01-29 10:27