Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

have some bad malware, weird keys in ProgramData, Docs Folder "Empty"!


  • This topic is locked This topic is locked
36 replies to this topic

#1 ShadowMyst

ShadowMyst

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:New England
  • Local time:04:39 AM

Posted 08 April 2017 - 11:53 AM

Windows Vista 32-bit Home Premium, Compaq Presario - please edit if needbe.
Had downloaded Advanced System Care from a site that was NOT Iobit and was not CNET.. Still, ASC seemed to run all right; it removed some things, but didn't go as deep as I would have liked.
 
Then, I found some key entries in the ProgramData folder. When I googled those keys I got results that indicated that they may be malware.
 
My system starting slowing down. My taskmanager cpu was pretty high.
 
I had a few seconds where the computer would freeze on start up.
I also had a window that spoke about "personalized settings, RunDLL32.IEDKCS.32DLL.BrandIE4.SIGNUP.
I *think* I was able to get rid of that... after googling.
 
THEN, I got a repeat of "Personalized Settings:
1. C:\Windows\System32\Rundll32.exe
2. C:\Windows\system32\mscories.dll.Install
 
In the meantime, I'm trying to get Vista to update, as I need as many patches as is available.
 
 
I think I downloaded a bad adobe add-on.
 
I was worried about those keys, and if I might have a "baddie" in the works, so I started logging in using safe mode with networking. -- which worked very well until this morning when I logged in, noticed that my screen icons (I'd been using Vista Classic), were missing, including most of my "action" icons, anti virus apps, short cuts, etc.
 
When I went to my docs folder, I passed my mouse over it, and got, "This folder is empty."
 
I logged out of my main account and used my other profile, logged in,
 
If I'm in Safe mode with networking, I can get the documents under the other user profile
If I log in in regular mode, go through C:\Users\Regular profile, I get the indicator that the docs folder is empty.
 
I ran ComboFix, Adwcleaner, took notes in a txt, ran roguekiller -- Please see all attached.
 
Now, when I try to access documents I'm seeing those docs in Word (while I use Rich Text (rtf), and I'm looking at a couple of dialog boxes that I've been just closing. The docs open just fine.
 
Any help on solving this would be greatly appreciated.
I am open to suggestions, instructions, etc.
 
Thanks so much again in advance!
 
Shadow.
 
 
EDIT: And I think I just did an "Ooops." There is a specific section for logs, isn't there. Yikes. N00b here, trying to get to the correct department, just give me a nudge... :(

Edit: Moved topic from Windows Vista to the more appropriate forum. ~ Animal

 

:) Thanks, Animal :)

Attached Files


Edited by ShadowMyst, 09 April 2017 - 11:36 AM.


BC AdBot (Login to Remove)

 


#2 ShadowMyst

ShadowMyst
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:New England
  • Local time:04:39 AM

Posted 09 April 2017 - 11:38 AM

Shadow again.

Followed the instructions, and have two logs from FRST. Need to upload them.  Sorry, still figuring this site out.

 

:/



#3 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,179 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:01:39 AM

Posted 11 April 2017 - 08:20 PM

Greetings ShadowMyst and :welcome: to BleepingComputer's Virus/Trojan/Spyware/Malware Removal forum.

My name is Oh My! and I am here to help you! Now that we are "friends" please call me Gary.

If you would allow me to call you by your first name I would prefer to do that.

===================================================

Ground Rules:
  • First, I would like to inform you that most of us here at Bleeping Computer offer our expert assistance out of the goodness of our hearts. Please try to match our commitment to you with your patience toward us. If this was easy we would never have met.
  • Please do not run any tools or take any steps other than those I will provide for you while we work on your computer together. I need to be certain about the state of your computer in order to provide appropriate and effective steps for you to take. Most often "well intentioned" (and usually panic driven!) independent efforts can make things much worse for both of us. If at any point you would prefer to take your own steps please let me know, I will not be offended. I would be happy to focus on the many others who are waiting in line for assistance.
  • Please perform all steps in the order they are listed in each set of instructions. Some steps may be a bit complicated. If things are not clear, be sure to stop and let me know. We need to work on this together with confidence.
  • Please copy and paste all logs into your post unless directed otherwise. Please do not re-run any programs I suggest. If you encounter problems simply stop and tell me.
  • When you post your reply, use the Replytopic.jpg button instead.
  • In the upper right hand corner of the topic you will see the Followtopic.jpg button. Click on this then choose Immediate E-Mail notification and then Proceed and you will be sent an email once I have posted a response.
  • If you do not reply to your topic after 5 days we assume it has been abandoned and I will close it.
  • When your computer is clean I will alert you of such. I will also provide for you detailed information about how you can combat future infections.
  • I would like to remind you to make no further changes to your computer unless I direct you to do so.
===================================================

Now that I am assisting you, you can expect that I will be very responsive to your situation. If you are able, I would request you check this thread at least once per day so that we can try to resolve your issues effectively and efficiently. If you are going to be delayed please be considerate and post that information so that I know you are still with me. Unfortunately, there are many people waiting to be assisted and not enough of us at BleepingComputer to go around. I appreciate your understanding and diligence.

Thank you for your patience thus far.

Please copy and paste the contents of FRST.txt and Addition.txt in your reply. If the content is too long use one reply for each report.
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#4 ShadowMyst

ShadowMyst
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:New England
  • Local time:04:39 AM

Posted 12 April 2017 - 05:46 PM

Okay, Gary, per your request: FRST data:

 

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 15-03-2017
Ran by admin anticryptolock (administrator) on OWNER-PC (09-04-2017 03:03:40)
Running from C:\Users\admin anticryptolock\Downloads
Loaded Profiles: admin anticryptolock (Available Profiles: Owner & admin anticryptolock)
Platform: Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X86) Language: English (United States)
Internet Explorer Version 9 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(IObit) C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.32.7\GoogleCrashHandler.exe
(Hewlett-Packard Company) C:\hp\support\hpsysdrv.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe
(Microsoft Corporation) C:\Windows\System32\schtasks.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(OsdMaestro) C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Conexant Systems, Inc.) C:\Windows\System32\drivers\XAudio.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
(Microsoft Corporation) C:\Windows\System32\taskmgr.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
(AVAST Software s.r.o.) C:\Program Files\AVAST Software\Avast\aswidsagent.exe
(IObit) C:\Program Files\IObit\IObit Uninstaller\UninstallMonitor.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
(Hewlett-Packard) C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Windows\System32\sdclt.exe
(Microsoft Corporation) C:\Windows\System32\mobsync.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [hpsysdrv] => c:\hp\support\hpsysdrv.exe [65536 2007-04-18] (Hewlett-Packard Company)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [12205784 2015-05-04] (Realtek Semiconductor)
HKLM\...\Run: [SunJavaUpdateReg] => C:\Windows\system32\jureg.exe [54936 2007-04-07] (Sun Microsystems, Inc.)
HKLM\...\Run: [HP Software Update] => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49208 2011-05-10] (Hewlett-Packard)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [205512 2017-03-01] (AVAST Software)
HKLM\...\Run: [OsdMaestro] => C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe [118784 2007-02-15] (OsdMaestro)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [157456 2015-09-12] (Apple Inc.)
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2776528 2016-12-14] (Malwarebytes)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [587288 2016-12-12] (Oracle Corporation)
HKU\S-1-5-21-3222991852-3880959725-3339485959-1165\...\Run: [HPADVISOR] => C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe [1644088 2009-08-05] (Hewlett-Packard)
HKU\S-1-5-21-3222991852-3880959725-3339485959-1165\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-3222991852-3880959725-3339485959-1165\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-21-3222991852-3880959725-3339485959-1165\...\Policies\Explorer: [NoDesktopCleanupWizard] 1
HKU\S-1-5-21-3222991852-3880959725-3339485959-1165\...0c966feabec1\InprocServer32: [Default-shell32]  ATTENTION
HKU\S-1-5-18\...\Run: [Advanced SystemCare 9] => C:\Program Files\IObit\Advanced SystemCare\ASCTray.exe [3919136 2017-02-08] (IObit)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2017-03-01] (AVAST Software)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk [2013-12-27]
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hpqtra08.exe [2007-03-11] (Hewlett-Packard Co.)
GroupPolicyUsers\S-1-5-21-3222991852-3880959725-3339485959-1165\User: Restriction <======= ATTENTION
GroupPolicyUsers\S-1-5-21-3222991852-3880959725-3339485959-1000\User: Restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [122128 2015-08-12] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 208.59.247.45 208.59.247.46 192.168.1.1
Tcpip\..\Interfaces\{73B646CC-8C74-4151-84F9-23E4B03FD810}: [DhcpNameServer] 208.59.247.45 208.59.247.46 192.168.1.1

Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-3222991852-3880959725-3339485959-1165\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.yahoo.com?fr=hp-avast&type=avastbcl
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-3222991852-3880959725-3339485959-1165\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?ocid=EIE9HP&PC=UP50
HKU\S-1-5-21-3222991852-3880959725-3339485959-1165\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM -> ComcastSearch URL = hxxp://search.comcast.net/?q={searchTerms}&cat=Web&con=ie7
SearchScopes: HKLM -> {55C1D719-5274-4281-A484-D799AE2BA7E5} URL = hxxp://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=hp-psdt
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_121\bin\ssv.dll [2017-01-19] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-03-01] (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-01-19] (Oracle Corporation)
BHO: IObit Ads Removal -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\IObit\Advanced SystemCare\Surfing Protection\Adblock\Adblock.dll [2016-06-23] (IObit)
DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A} hxxp://h20364.www2.hp.com/CSMWeb/Customer/cabs/HPISDataManager.CAB
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0021-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll [2007-06-07] (Microsoft Corporation)

FireFox:
========
FF ProfilePath: C:\Users\admin anticryptolock\AppData\Roaming\Mozilla\Firefox\Profiles\jol1aryt.default [2017-04-09]
FF Homepage: Mozilla\Firefox\Profiles\jol1aryt.default -> hxxps://google.com
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: (Microsoft .NET Framework Assistant) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2010-03-18] [not signed]
FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: (RealDownloader) - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-09-27] [not signed]
FF HKLM\...\Firefox\Extensions: [{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF48
FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF48 [2017-03-01]
FF HKLM\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF48
FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF48 [2017-03-01]
FF HKU\.DEFAULT\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: (McAfee Security Scan Plus) - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04] [not signed]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_25_0_0_127.dll [2017-03-17] ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1228198.dll [2017-02-27] (Adobe Systems, Inc.)
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2015-09-04] ()
FF Plugin: @java.com/DTPlugin,version=11.121.2 -> C:\Program Files\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-01-19] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.121.2 -> C:\Program Files\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-01-19] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=16.0.3.51 -> c:\program files\real\realplayer\Netscape6\nppl3260.dll [2013-09-27] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin: @real.com/nprpchromebrowserrecordext;version=15.0.5.109 -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll [2012-06-29] (RealNetworks, Inc.)
FF Plugin: @real.com/nprphtml5videoshim;version=15.0.5.109 -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll [2012-06-29] (RealNetworks, Inc.)
FF Plugin: @real.com/nprpplugin;version=16.0.3.51 -> c:\program files\real\realplayer\Netscape6\nprpplugin.dll [2013-09-27] (RealPlayer)
FF Plugin: @realnetworks.com/npdlplugin;version=1 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll [2013-08-14] (RealDownloader)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=1.1.11 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppl3260.dll [2013-09-27] (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprpplugin.dll [2013-09-27] (RealPlayer)

Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR Profile: C:\Users\admin anticryptolock\AppData\Local\Google\Chrome\User Data\Default [2015-07-31]
CHR Extension: (Google Slides) - C:\Users\admin anticryptolock\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-07-15]
CHR Extension: (Google Docs) - C:\Users\admin anticryptolock\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-07-15]
CHR Extension: (Google Drive) - C:\Users\admin anticryptolock\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-07-15]
CHR Extension: (YouTube) - C:\Users\admin anticryptolock\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-07-15]
CHR Extension: (Google Search) - C:\Users\admin anticryptolock\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-07-15]
CHR Extension: (Google Sheets) - C:\Users\admin anticryptolock\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-07-15]
CHR Extension: (Avast Online Security) - C:\Users\admin anticryptolock\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-07-15]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\admin anticryptolock\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-07-15]
CHR Extension: (Google Wallet) - C:\Users\admin anticryptolock\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-15]
CHR Extension: (Gmail) - C:\Users\admin anticryptolock\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-07-15]
CHR HKLM\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2013-08-14]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [5545144 2017-03-01] (AVAST Software s.r.o.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [262736 2017-03-01] (AVAST Software)
R2 HP Health Check Service; c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [65536 2007-09-19] (Hewlett-Packard) [File not signed]
S4 hpqddsvc; C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [135168 2008-03-25] (Hewlett-Packard Co.) [File not signed]
R2 IMFservice; C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe [956192 2016-01-18] (IObit)
S2 LiveUpdateSvc; C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe [2960672 2016-07-20] (IObit)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [3381200 2016-12-14] (Malwarebytes)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.500\McCHSvc.exe [272136 2017-01-19] (McAfee, Inc.)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2010-08-06] (Hewlett-Packard) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2010-08-06] (Hewlett-Packard) [File not signed]
S2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] ()
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService.exe [254168 2015-05-04] (Realtek Semiconductor)
S3 RzKLService; C:\Program Files\Razer\Razer Game Booster\RzKLService.exe [105448 2013-11-22] (Razer Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-19] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 ASPI32; C:\Windows\system32\Drivers\ASPI32.sys [25244 2000-12-08] (Adaptec)
R1 aswbidsdriver; C:\Windows\system32\drivers\aswbidsdriverx.sys [257288 2017-03-01] (AVAST Software s.r.o.)
R0 aswbidsh; C:\Windows\system32\drivers\aswbidshx.sys [148720 2017-03-01] (AVAST Software s.r.o.)
R0 aswblog; C:\Windows\system32\drivers\aswblogx.sys [267016 2017-03-01] (AVAST Software s.r.o.)
R0 aswbuniv; C:\Windows\system32\drivers\aswbunivx.sys [41176 2017-03-01] (AVAST Software s.r.o.)
S3 aswHdsKe; C:\Windows\system32\drivers\aswHdsKe.sys [65344 2016-12-28] (AVAST Software)
S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [34136 2017-03-01] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [31064 2017-03-01] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [106392 2017-03-01] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr.sys [60632 2017-03-01] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [62152 2017-03-01] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [756200 2017-03-01] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [465024 2017-03-25] (AVAST Software)
R3 aswStmXP; C:\Windows\system32\drivers\aswStmXP.sys [184208 2017-03-01] (AVAST Software)
R0 aswVmm; C:\Windows\system32\drivers\aswVmm.sys [278776 2017-03-14] (AVAST Software)
S3 FileMonitor; C:\Program Files\IObit\IObit Malware Fighter\Drivers\wlh_x86\FileMonitor.sys [21184 2015-12-22] (IObit)
R0 FSProFilter; C:\Windows\System32\Drivers\FSPFltd.sys [41912 2010-07-22] (FSPro Labs)
R0 giveio; C:\Windows\System32\giveio.sys [5248 1996-04-03] () [File not signed]
R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO32.SYS [23840 2016-04-08] (REALiX™)
S3 MBAMProtection; C:\Windows\system32\drivers\mbam.sys [39360 2016-12-21] (Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [219584 2017-04-08] (Malwarebytes)
S3 rcmirror; C:\Windows\System32\DRIVERS\rcmirror.sys [3200 2010-01-18] (Windows ® Win 7 DDK provider)
S3 RegFilter; C:\Program Files\IObit\IObit Malware Fighter\drivers\wlh_x86\regfilter.sys [32288 2015-03-25] (IObit.com)
S3 Trufos; C:\Windows\System32\DRIVERS\TRUFOS.sys [408280 2014-10-15] (BitDefender S.R.L.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-19] (Microsoft Corporation)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 catchme; \??\C:\Users\ADMINA~1\AppData\Local\Temp\catchme.sys [X] <==== ATTENTION
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 motccgp; system32\DRIVERS\motccgp.sys [X]
S3 motccgpfl; system32\DRIVERS\motccgpfl.sys [X]
S3 motmodem; system32\DRIVERS\motmodem.sys [X]
S3 motport; system32\DRIVERS\motport.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S3 PcdrNdisuio; system32\DRIVERS\pcdrndisuio.sys [X]
S3 SymIM; system32\DRIVERS\SymIM.sys [X]
S3 SymIMMP; system32\DRIVERS\SymIM.sys [X]
S3 TMPassthruMP; system32\DRIVERS\TMPassthru.sys [X]
S2 VBoxAswDrv; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2099-02-24 15:15 - 2001-04-02 17:30 - 00000821 _____ C:\Windows\Lexmark_ICM.ini
2099-02-16 17:09 - 2001-02-16 16:37 - 00000062 _____ C:\Windows\system32\LXASUSCI.INI
2017-04-09 03:03 - 2017-04-09 03:05 - 00023531 _____ C:\Users\admin anticryptolock\Downloads\FRST.txt
2017-04-09 03:01 - 2017-04-09 03:03 - 00000000 ____D C:\FRST
2017-04-09 03:01 - 2017-04-09 03:01 - 01766912 _____ (Farbar) C:\Users\admin anticryptolock\Desktop\FRST.exe
2017-04-09 00:02 - 2017-04-09 00:28 - 3497946500 _____ C:\Users\admin anticryptolock\Documents\Drive_D.dat
2017-04-09 00:02 - 2017-04-09 00:28 - 03810457 _____ C:\Users\admin anticryptolock\Documents\Drive_D.xml
2017-04-08 14:47 - 2017-04-08 14:47 - 00000000 ____D C:\Users\admin anticryptolock\AppData\Local\CEF
2017-04-08 14:38 - 2017-04-08 21:57 - 92222293 _____ C:\Users\admin anticryptolock\Documents\Drive_C.xml
2017-04-08 14:38 - 2017-04-08 21:57 - 2449968548 _____ C:\Users\admin anticryptolock\Documents\Drive_C.dat
2017-04-08 14:34 - 2017-04-08 14:34 - 00000000 ____D C:\ProgramData\SWCUTemp
2017-04-08 14:24 - 2017-04-08 14:24 - 00000878 _____ C:\Users\Public\Desktop\DriveImage XML.lnk
2017-04-08 14:24 - 2017-04-08 14:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Runtime Software
2017-04-08 14:24 - 2017-04-08 14:24 - 00000000 ____D C:\Program Files\Runtime Software
2017-04-08 14:23 - 2017-04-08 14:23 - 02023440 _____ C:\Users\admin anticryptolock\Downloads\dixmlsetup.exe
2017-04-08 11:06 - 2017-04-08 11:06 - 00643281 _____ C:\Users\admin anticryptolock\AppData\Local\census.cache
2017-04-08 11:01 - 2017-04-08 11:01 - 00262570 _____ C:\Users\admin anticryptolock\AppData\Local\ars.cache
2017-04-08 10:24 - 2017-04-08 10:24 - 00000010 _____ C:\Users\admin anticryptolock\AppData\Local\sponge.last.runtime.cache
2017-04-08 10:13 - 2017-04-08 10:13 - 02105760 _____ (Trend Micro Inc.) C:\Users\admin anticryptolock\Downloads\HousecallLauncher.exe
2017-04-08 10:13 - 2017-04-08 10:13 - 00000036 _____ C:\Users\admin anticryptolock\AppData\Local\housecall.guid.cache
2017-04-08 10:07 - 2017-04-08 10:07 - 00000622 _____ C:\Users\admin anticryptolock\Desktop\Documents - Shortcut.lnk
2017-04-08 10:01 - 2017-04-08 10:01 - 00004462 _____ C:\Users\admin anticryptolock\AdwCleanerrpt apr8 2017 1001.txt
2017-04-08 09:13 - 2017-04-08 09:13 - 01196480 _____ (RaMMicHaeL) C:\Users\admin anticryptolock\Downloads\unchecky_setup.exe
2017-04-08 08:18 - 2017-04-08 08:19 - 04089296 _____ C:\Users\admin anticryptolock\Downloads\AdwCleaner.exe
2017-04-08 08:16 - 2017-04-09 03:04 - 00000000 ____D C:\Users\admin anticryptolock\AppData\LocalLow\Mozilla
2017-04-08 08:13 - 2017-04-08 11:59 - 00000679 _____ C:\Users\admin anticryptolock\computer hack apr 8 2017.txt
2017-04-08 08:13 - 2017-04-08 08:13 - 00013349 _____ C:\Users\admin anticryptolock\Documents\combofix log apr 8 2017 0812.txt
2017-04-08 08:12 - 2017-04-08 08:12 - 00013349 _____ C:\ComboFix.txt
2017-04-08 07:56 - 2011-06-26 02:45 - 00256000 _____ C:\Windows\PEV.exe
2017-04-08 07:56 - 2010-11-07 13:20 - 00208896 _____ C:\Windows\MBR.exe
2017-04-08 07:56 - 2009-04-20 00:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2017-04-08 07:56 - 2000-08-30 20:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2017-04-08 07:56 - 2000-08-30 20:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2017-04-08 07:56 - 2000-08-30 20:00 - 00098816 _____ C:\Windows\sed.exe
2017-04-08 07:56 - 2000-08-30 20:00 - 00080412 _____ C:\Windows\grep.exe
2017-04-08 07:56 - 2000-08-30 20:00 - 00068096 _____ C:\Windows\zip.exe
2017-04-08 07:44 - 2017-04-08 07:44 - 00534192 _____ C:\Windows\system32\FNTCACHE.DAT
2017-04-07 16:50 - 2017-04-07 16:50 - 00125896 _____ C:\Users\Owner\AppData\Local\GDIPFONTCACHEV1.DAT
2017-04-07 10:24 - 2017-04-07 10:24 - 35171128 _____ (Adlice Software ) C:\Users\Owner\Downloads\setup(4).exe
2017-04-03 12:44 - 2017-04-03 12:44 - 00096756 _____ C:\Users\Owner\Downloads\Walter Lob-3-20-2017 to 4-2-2017.pdf
2017-03-29 12:46 - 2017-03-29 12:46 - 35099168 _____ (Adlice Software ) C:\Users\Owner\Downloads\setup.exe
2017-03-29 11:29 - 2017-03-29 11:31 - 11005320 _____ (SurfRight B.V.) C:\Users\Owner\Downloads\hitmanpro(1).exe
2017-03-29 08:14 - 2017-03-29 08:18 - 11005320 _____ (SurfRight B.V.) C:\Users\Owner\Downloads\hitmanpro.exe
2017-03-29 07:56 - 2017-03-29 07:56 - 00000000 ____D C:\Users\Owner\AppData\Roaming\ProductData
2017-03-29 07:53 - 2017-04-07 10:11 - 00000000 ____D C:\ProgramData\ProductData
2017-03-29 07:41 - 2017-03-29 07:41 - 04089296 _____ C:\Users\Owner\Downloads\adwcleaner_6.045.exe
2017-03-24 20:30 - 2017-03-24 20:30 - 35109888 _____ (Adlice Software ) C:\Users\Owner\Downloads\setup(3).exe
2017-03-19 08:26 - 2017-03-19 08:27 - 20588120 _____ (Adobe Systems Incorporated) C:\Users\Owner\Downloads\install_flash_player_ppapi(1).exe
2017-03-19 08:26 - 2017-03-19 08:27 - 20119128 _____ (Adobe Systems Incorporated) C:\Users\Owner\Downloads\install_flash_player_ax.exe
2017-03-17 07:24 - 2017-03-17 07:24 - 00000000 ____D C:\cc5a674df9e1e1956315bf5ea6
2017-03-17 07:22 - 2017-03-17 07:24 - 154546261 _____ C:\Users\Owner\Downloads\Windows6.0-KB947821-v35-x86.msu
2017-03-17 07:07 - 2017-03-17 07:07 - 00000656 _____ C:\Users\Owner\Downloads\wu10.diagcab
2017-03-17 07:07 - 2017-03-17 07:07 - 00000636 _____ C:\Users\Owner\Downloads\WindowsMediaPlayerPlayDVD.diagcab
2017-03-17 07:03 - 2017-03-17 07:03 - 02349128 _____ C:\Users\Owner\Downloads\4a5dbe04-27dd-44c5-88e4-558ade5d6ca7_12375f2ee342acd3f34491a834337a2d8e5062e7(2).cab
2017-03-17 07:02 - 2017-03-17 07:02 - 02349128 _____ C:\Users\Owner\Downloads\4a5dbe04-27dd-44c5-88e4-558ade5d6ca7_12375f2ee342acd3f34491a834337a2d8e5062e7(1).cab
2017-03-17 07:02 - 2017-03-17 07:02 - 00774233 _____ C:\Users\Owner\Downloads\53248a5f-af4a-4e74-9171-3f9ad7a58431_bb2d6f9cf887be70954fb6e6caeb62febe4cd62b.cab
2017-03-17 07:01 - 2017-03-17 07:01 - 02349128 _____ C:\Users\Owner\Downloads\4a5dbe04-27dd-44c5-88e4-558ade5d6ca7_12375f2ee342acd3f34491a834337a2d8e5062e7.cab
2017-03-17 07:00 - 2017-03-17 07:01 - 88853882 _____ C:\Users\Owner\Downloads\829983c3-3688-4808-82e6-37b1f3589cbd_a577916d0d8f4cf52224f6277b5cd68eea36cbdc.cab
2017-03-17 06:59 - 2017-03-17 07:00 - 105181578 _____ C:\Users\Owner\Downloads\faf3c611-e236-4846-8efd-bbbf137cadc2_8915a05dedd5b345aeb6e312a977c2d3c2ac8afa.cab
2017-03-17 06:58 - 2017-03-17 06:58 - 10095856 _____ (Microsoft Corporation) C:\Users\Owner\Downloads\ndp45-kb3189039-x64_b968e2d55e5482d48f18338f2756da2786a44829.exe
2017-03-17 06:58 - 2017-03-17 06:58 - 09647768 _____ (Microsoft Corporation) C:\Users\Owner\Downloads\ndp46-kb3189040-x64_8a49fdc1aa5fd4ba858813b916cd27ce4c36e303.exe
2017-03-17 06:58 - 2017-03-17 06:58 - 08232287 _____ C:\Users\Owner\Downloads\windows6.0-kb3078601-x64_ef7d88846dbf568b534901f434c99274d7ef580f.msu
2017-03-17 06:58 - 2017-03-17 06:58 - 06427891 _____ C:\Users\Owner\Downloads\windows6.0-kb3188726-x64_dae2cde7e2d4a16f6ec510fe8964bb10048a02b6.msu
2017-03-17 06:56 - 2017-03-17 06:56 - 00000000 ____D C:\a0c5ad83fe016f346e
2017-03-17 06:55 - 2017-03-17 06:55 - 00425650 _____ C:\Users\Owner\Downloads\windows6.0-kb3073921-x86_582e5414c60ff7249c327d99cb9637718c6d542b.msu
2017-03-17 06:55 - 2017-03-17 06:55 - 00425650 _____ C:\Users\Owner\Downloads\windows6.0-kb3073921-x86_582e5414c60ff7249c327d99cb9637718c6d542b(1).msu
2017-03-17 06:54 - 2017-03-17 06:54 - 00432024 _____ C:\Users\Owner\Downloads\windows6.0-kb3073921-v2-x86_bec5fa1dbf93c2b552143deae5f954b7c0d86a64.msu
2017-03-17 01:40 - 2017-03-17 01:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2017-03-17 01:30 - 2017-03-17 01:39 - 00000000 ____D C:\Program Files\McAfee Security Scan
2017-03-16 00:15 - 2017-03-16 00:16 - 00000000 ____D C:\Users\Owner\Documents\Hiring home health aides
2017-03-15 23:44 - 2017-04-08 12:37 - 00429740 _____ C:\Windows\ntbtlog.txt
2017-03-14 10:34 - 2017-03-29 07:10 - 00000703 _____ C:\Users\Owner\Documents\STILL seeing personalized settings Mar 14 2017.txt
2017-03-14 10:04 - 2017-04-07 10:24 - 00000806 _____ C:\Users\Public\Desktop\RogueKiller.lnk
2017-03-14 10:03 - 2017-03-14 10:03 - 34977008 _____ (Adlice Software ) C:\Users\Owner\Downloads\setup(2).exe
2017-03-14 01:43 - 2017-03-14 01:43 - 00502524 _____ C:\Users\Owner\Documents\migratingfromapplets-2872444.pdf

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-04-09 02:33 - 2006-11-02 08:47 - 00003696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2017-04-09 02:33 - 2006-11-02 08:47 - 00003696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2017-04-08 14:36 - 2016-12-21 13:29 - 00219584 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2017-04-08 14:33 - 2010-01-06 02:37 - 00000880 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2017-04-08 14:32 - 2006-11-02 09:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-04-08 11:59 - 2013-12-13 20:09 - 00000000 ____D C:\Users\admin anticryptolock
2017-04-08 10:07 - 2008-02-07 14:02 - 00000000 ____D C:\Users\Owner
2017-04-08 10:04 - 2006-11-02 09:01 - 00032560 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2017-04-08 09:59 - 2015-07-15 07:00 - 00000000 ____D C:\Users\admin anticryptolock\AppData\Roaming\ProductData
2017-04-08 08:30 - 2016-10-26 03:01 - 00000000 ____D C:\AdwCleaner
2017-04-08 08:30 - 2012-04-26 23:00 - 00000000 ____D C:\ProgramData\IObit
2017-04-08 08:28 - 2014-04-26 06:30 - 00125896 _____ C:\Users\admin anticryptolock\AppData\Local\GDIPFONTCACHEV1.DAT
2017-04-08 08:28 - 2013-12-13 22:15 - 00000000 ____D C:\Users\admin anticryptolock\AppData\LocalLow\IObit
2017-04-08 08:28 - 2013-12-13 20:10 - 00000000 ____D C:\Users\admin anticryptolock\AppData\Roaming\IObit
2017-04-08 08:12 - 2012-08-14 01:37 - 00000000 ____D C:\Qoobox
2017-04-08 08:10 - 2006-11-02 06:23 - 00000215 _____ C:\Windows\system.ini
2017-04-08 08:09 - 2008-02-09 22:28 - 00000000 ____D C:\Users\Owner\AppData\Local\Adobe
2017-04-08 07:54 - 2017-01-09 19:20 - 00000000 ____D C:\Users\Owner\anti virus apps
2017-04-08 07:52 - 2017-01-09 19:21 - 00001189 _____ C:\Users\Owner\Desktop\anti virus apps.lnk
2017-04-07 16:58 - 2013-06-09 10:38 - 64684032 _____ C:\Windows\system32\config\software.iobit
2017-04-07 16:58 - 2013-06-09 10:38 - 50229248 _____ C:\Windows\system32\config\components.iobit
2017-04-07 16:58 - 2013-06-09 10:38 - 02220032 _____ C:\Windows\system32\config\default.iobit
2017-04-07 16:58 - 2013-06-09 10:38 - 00094208 _____ C:\Windows\system32\config\sam.iobit
2017-04-07 16:58 - 2013-06-09 10:38 - 00024576 _____ C:\Windows\system32\config\security.iobit
2017-04-07 16:49 - 2016-11-16 04:57 - 00000000 ____D C:\Users\Owner\AppData\LocalLow\Mozilla
2017-04-07 10:25 - 2017-01-24 06:55 - 00024688 _____ C:\Windows\system32\Drivers\TrueSight.sys
2017-04-07 10:24 - 2017-01-24 06:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2017-04-07 10:24 - 2017-01-24 06:53 - 00000000 ____D C:\Program Files\RogueKiller
2017-04-07 10:11 - 2012-03-18 15:51 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2017-04-03 12:58 - 2016-05-10 07:41 - 00000000 ____D C:\Program Files\Mozilla Firefox
2017-04-03 12:34 - 2008-02-07 17:26 - 00001356 _____ C:\Users\Owner\AppData\Local\d3d9caps.dat
2017-03-30 15:52 - 2016-10-16 01:12 - 00000000 ____D C:\Users\Owner\Documents\Registry of Motor Vehicles
2017-03-29 09:10 - 2011-10-25 19:58 - 00000000 ____D C:\Program Files\IObit
2017-03-29 07:31 - 2016-02-20 18:31 - 00000000 ____D C:\Users\Owner\Documents\JRT scans
2017-03-29 07:02 - 2006-11-02 07:18 - 00000000 ____D C:\Windows\inf
2017-03-27 10:35 - 2017-02-13 19:45 - 00000000 ____D C:\Users\Owner\AppData\Local\CrashDumps
2017-03-25 09:48 - 2015-03-11 13:13 - 00465024 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2017-03-24 22:22 - 2015-09-18 01:04 - 00000000 ____D C:\Users\Owner\Documents\Unique Homecare Services
2017-03-19 08:37 - 2017-01-04 21:29 - 00802904 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2017-03-19 08:37 - 2017-01-04 21:29 - 00144472 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2017-03-19 08:37 - 2007-11-18 22:48 - 00000000 ____D C:\Windows\system32\Macromed
2017-03-17 01:23 - 2008-02-11 17:47 - 00000000 ____D C:\Users\Owner\Documents\Susannah's Stuff
2017-03-16 00:12 - 2008-02-11 18:07 - 00000000 ____D C:\Users\Owner\Documents\Walter
2017-03-14 07:51 - 2015-03-11 13:13 - 00278776 _____ (AVAST Software) C:\Windows\system32\Drivers\aswvmm.sys
2017-03-14 07:50 - 2006-11-02 06:33 - 00758862 _____ C:\Windows\system32\PerfStringBackup.INI
2017-03-10 20:09 - 2016-12-21 13:29 - 00059968 _____ C:\Windows\system32\Drivers\mbae.sys

==================== Files in the root of some directories =======

2012-07-30 22:34 - 2012-07-30 22:35 - 89340632 _____ () C:\Program Files\avast_free_antivirus_setup.exe
2012-08-08 02:02 - 2012-08-08 02:02 - 19620864 _____ (Luis Cobian, CobianSoft) C:\Program Files\cbSetup.exe
2012-09-03 16:03 - 2012-09-03 16:03 - 0894952 _____ (Oracle Corporation) C:\Program Files\jre-7u7-windows-i586-iftw.exe
2012-08-08 07:38 - 2012-08-08 07:39 - 3186402 _____ () C:\Program Files\mylockbox_setup.zip
2017-04-08 11:01 - 2017-04-08 11:01 - 0262570 _____ () C:\Users\admin anticryptolock\AppData\Local\ars.cache
2017-04-08 11:06 - 2017-04-08 11:06 - 0643281 _____ () C:\Users\admin anticryptolock\AppData\Local\census.cache
2014-03-10 18:52 - 2014-06-17 01:56 - 0000680 _____ () C:\Users\admin anticryptolock\AppData\Local\d3d9caps.dat
2014-06-17 01:35 - 2014-06-17 01:40 - 0011776 _____ () C:\Users\admin anticryptolock\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2017-04-08 10:13 - 2017-04-08 10:13 - 0000036 _____ () C:\Users\admin anticryptolock\AppData\Local\housecall.guid.cache
2017-04-08 10:24 - 2017-04-08 10:24 - 0000010 _____ () C:\Users\admin anticryptolock\AppData\Local\sponge.last.runtime.cache
2008-07-18 16:20 - 2008-07-18 16:20 - 0005099 _____ () C:\ProgramData\amjmwaey.gaf
2007-11-18 22:48 - 2013-12-27 22:08 - 0023126 _____ () C:\ProgramData\hpzinstall.log

Files to move or delete:
====================
C:\Users\Owner\AdbeRdr1014_en_US.exe
C:\Users\Owner\backup.reg
C:\Users\Owner\Firefox Setup 11.0b3.exe
C:\Users\Owner\Firefox Setup 6.0.exe
C:\Users\Owner\HPPSdr hp print and scan doctor Dec 3 2013.exe
C:\Users\Owner\iTunesSetup.exe
C:\Users\Owner\mseinstall.exe
C:\Users\Owner\NP2k9WinDemo.exe
C:\Users\Owner\QuickTimeInstaller.exe
C:\Users\Owner\RealPlayer11GOLD(2).exe
C:\Users\Owner\RealPlayer11GOLD.exe
C:\Users\Owner\scanjet_vista_tablet_patch Dec 3 2013.exe
C:\Users\Owner\SeFilm.exe
C:\Users\Owner\slp_dd_hathi_110_017   dec 3 2013.exe
C:\Users\Owner\vlc-1.1.11-win32.exe
C:\Users\Owner\windows-kb890830-v2.8.exe


==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2017-04-08 14:40

==================== End of FRST.txt ============================

 

Lesseee if it will let me post it, or if it's too long... ~`???



#5 ShadowMyst

ShadowMyst
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:New England
  • Local time:04:39 AM

Posted 12 April 2017 - 05:51 PM

Okay, now, the ADDITION text -- Gary - I am IMPRESSED that you can read **and understand** all of this!

 

Additional scan result of Farbar Recovery Scan Tool (x86) Version: 15-03-2017
Ran by admin anticryptolock (09-04-2017 03:06:28)
Running from C:\Users\admin anticryptolock\Downloads
Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X86) (2007-11-22 07:45:16)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

admin anticryptolock (S-1-5-21-3222991852-3880959725-3339485959-1165 - Administrator - Enabled) => C:\Users\admin anticryptolock
Administrator (S-1-5-21-3222991852-3880959725-3339485959-500 - Administrator - Disabled)
Guest (S-1-5-21-3222991852-3880959725-3339485959-501 - Limited - Disabled)
Owner (S-1-5-21-3222991852-3880959725-3339485959-1000 - Administrator - Enabled) => C:\Users\Owner

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AV: IObit Malware Fighter (Disabled - Out of date) {4D381C57-3C7A-6F22-07EB-639F49E836D4}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: IObit Malware Fighter (Enabled - Up to date) {A751AC20-3B48-5237-898A-78C4436BB78D}
AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

. . . (Version: 2.6.2.4 - Intel) Hidden
32 Bit HP CIO Components Installer (Version: 7.1.8 - Hewlett-Packard) Hidden
AccelerateTab (HKLM\...\AccelerateTab_is1) (Version: 1.0 - AccelerateTab)
Adobe Digital Editions 2.0 (HKLM\...\Adobe Digital Editions 2.0) (Version: 2.0 - Adobe Systems Incorporated)
Adobe Flash Player 25 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 25.0.0.127 - Adobe Systems Incorporated)
Adobe Flash Player 25 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 25.0.0.127 - Adobe Systems Incorporated)
Adobe Flash Player 25 PPAPI (HKLM\...\Adobe Flash Player PPAPI) (Version: 25.0.0.127 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) (HKLM\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.2 (HKLM\...\Adobe Shockwave Player) (Version: 12.2.8.198 - Adobe Systems, Inc.)
ADSRemoval (HKLM\...\ADSRemoval_is1) (Version: 1.0 - ADSRemoval)
AIO_Scan (Version: 90.0.222.000 - Hewlett-Packard) Hidden
AnswerWorks 5.0 English Runtime (HKLM\...\{DBCC73BA-C69A-4BF5-B4BF-F07501EE7039}) (Version: 5.0.7 - Vantage Software Technologies)
Apple Application Support (32-bit) (HKLM\...\{AFA1153A-F547-409B-B837-3A0D6C5A3FEC}) (Version: 3.1.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{D9F3D66A-9885-4DDD-A800-9DDF488359A1}) (Version: 10.0.1.3 - Apple Inc.)
Apple Software Update (HKLM\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
Avanquest update (HKLM\...\{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}) (Version: 1.29 - Avanquest Software)
Avast Free Antivirus (HKLM\...\Avast Antivirus) (Version: 17.2.2288 - AVAST Software)
Bonjour (HKLM\...\{D168AAD0-6686-47C1-B599-CDD4888B9D1A}) (Version: 3.1.0.1 - Apple Inc.)
BufferChm (Version: 140.0.212.000 - Hewlett-Packard) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 3.26 - Piriform)
CDBurnerXP (HKLM\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.2.4291 - CDBurnerXP)
Compatibility Pack for the 2007 Office system (HKLM\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Copy (Version: 90.0.146.000 - Hewlett-Packard) Hidden
CustomerResearchQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
CyberLink DVD Suite Deluxe (HKLM\...\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 5.5.1019 - CyberLink Corp.)
D3DX10 (Version: 15.4.2368.0902 - Microsoft) Hidden
Destination Component (Version: 090.000.091.086 - Hewlett-Packard) Hidden
DeviceDiscovery (Version: 110.0.180.000 - Hewlett-Packard) Hidden
DeviceManagementQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
DJ_AIO_ProductContext (Version: 90.0.236.000 - Hewlett-Packard) Hidden
DJ_AIO_Software (Version: 90.0.222.000 - Hewlett-Packard) Hidden
DJ_AIO_Software_min (Version: 90.0.222.000 - Hewlett-Packard) Hidden
DriveImage XML (Private Edition) (HKLM\...\{F7E1CA14-B39D-452A-960B-39423DDDD933}) (Version: 2.60.000 - Runtime Software)
Driver Booster 3.2 (HKLM\...\Driver Booster_is1) (Version: 3.2 - IObit)
ESET Online Scanner v3 (HKLM\...\ESET Online Scanner) (Version:  - )
eSupportQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
F4100 (Version: 90.0.222.000 - Hewlett-Packard) Hidden
F4100_doccd (Version: 90.0.222.000 - Hewlett-Packard) Hidden
F4100_Help (Version: 90.0.222.000 - Hewlett-Packard) Hidden
Finale NotePad 2012 (HKLM\...\Finale NotePad 2012) (Version: 2012..r1.5 - MakeMusic)
FinePix Studio (HKLM\...\{E3B3AB03-8ABC-46CF-8CA9-DB5581E1F368}) (Version:  - )
FinePixViewer Resource (HKLM\...\{B44529FF-501E-47CD-A06D-223C161BE058}) (Version: 1.2 - FUJIFILM Corporation)
FinePixViewer Ver.5.4 (HKLM\...\{24ED4D80-8294-11D5-96CD-0040266301AD}) (Version: 5.4 - FUJIFILM Corporation)
FontSelector (HKLM\...\{2D9F25E4-E4A6-439E-86E4-25782BA161EF}) (Version: 1.0.1 - Font Marketplace)
Google Chrome (HKLM\...\Google Chrome) (Version: 50.0.2661.75 - Google Inc.)
Google Earth (HKLM\...\{F6430171-B86B-4639-839E-374913E7911D}) (Version: 7.1.8.3036 - Google)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.32.7 - Google Inc.) Hidden
GPBaseService2 (Version: 140.0.211.000 - Hewlett-Packard) Hidden
Hardware Diagnostic Tools (HKLM\...\PC-Doctor 5 for Windows) (Version: 5.00.4589.14 - PC-Doctor, Inc.)
Hewlett-Packard Active Check (Version: 1.1.11.0 - Hewlett-Packard) Hidden
Hewlett-Packard Asset Agent for Health Check (Version: 2.0.62.5 - HP) Hidden
HP Active Support Library (HKLM\...\{11BB336F-0E58-4977-B866-F24FA334616B}) (Version: 2.3.0.2 - Hewlett-Packard)
HP Advisor (HKLM\...\{73A43E42-3658-4DD9-8551-FACDA3632538}) (Version: 3.1.9152.3107 - Hewlett-Packard)
HP Customer Experience Enhancements (HKLM\...\{AFAD41A9-9687-48A3-848F-693C11451433}) (Version: 5.4.0.2360 - Hewlett-Packard)
HP Customer Participation Program 9.0 (HKLM\...\HPExtendedCapabilities) (Version: 9.0 - HP)
HP Deskjet 3050A J611 series Basic Device Software (HKLM\...\{AE47EB5B-1789-4480-AD6D-7753473E9DDE}) (Version: 25.0.571.0 - Hewlett-Packard Co.)
HP Deskjet 3050A J611 series Help (HKLM\...\{97DDCAB8-B770-4089-A10F-67568069D78A}) (Version: 140.0.2.2 - Hewlett Packard)
HP Deskjet 3050A J611 series Product Improvement Study (HKLM\...\{E9652A2B-6547-4CA7-A06B-1365FE264B7D}) (Version: 25.0.571.0 - Hewlett-Packard Co.)
HP Deskjet All-In-One Software 9.0 (HKLM\...\{FA8A44D7-3E8A-4034-9C4F-088FA6B72BC4}) (Version: 9.0 - HP)
HP Easy Setup - Frontend (HKLM\...\{9885A11E-60E4-417C-B58B-8B31B21C0B8A}) (Version: 5.4.0.2430 - Hewlett-Packard)
HP Imaging Device Functions 9.0 (HKLM\...\HP Imaging Device Functions) (Version: 9.0 - HP)
HP On-Screen Cap/Num/Scroll Lock Indicator (HKLM\...\OsdMaestro) (Version:  - Hewlett-Packard)
HP Photo Creations (HKLM\...\HP Photo Creations) (Version: 1.0.0.2024 - HP Photo Creations Powered by RocketLife)
HP Photosmart Essential 2.01 (HKLM\...\HP Photosmart Essential) (Version: 2.01 - HP)
HP Solution Center 14.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 14.0 - HP)
HP Update (HKLM\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HPDiagnosticAlert (Version: 1.00.0000 - Microsoft) Hidden
HPProductAssistant (Version: 140.0.212.000 - Hewlett-Packard) Hidden
HPSSupply (HKLM\...\{487B0B9B-DCD4-440D-89A0-A6EDE1A545A3}) (Version: 2.2.0.0000 - Hewlett Packard Development Company L.P.)
Intel® Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version:  - )
Intel® Driver Update Utility (HKLM\...\{66e8e99a-eb6f-4403-9fc2-0ddd4d6f353e}) (Version: 2.6.2.4 - Intel)
IObit Apps Toolbar v7.1 (HKLM\...\{EA0F950C-D926-4366-A60C-9E7B71DB1FF2}) (Version: 7.1 - Spigot, Inc.) <==== ATTENTION
IObit Malware Fighter 4 (HKLM\...\IObit Malware Fighter_is1) (Version: 4.0 - IObit)
IObit Uninstaller (HKLM\...\IObitUninstall) (Version: 5.4.0.125 - IObit)
iTunes (HKLM\...\{868B9974-4F23-494D-B6BC-4FAB92B2755D}) (Version: 12.1.3.6 - Apple Inc.)
Java 8 Update 121 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F32180121F0}) (Version: 8.0.1210.13 - Oracle Corporation)
Junk Mail filter update (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
LabelPrint (HKLM\...\{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.2.2209 - CyberLink Corp.)
LightScribe System Software  1.10.16.1 (HKLM\...\{E6CFBFB5-9232-410C-B353-AF6E614B2681}) (Version: 1.10.16.1 - hxxp://www.lightscribe.com)
LightScribe Template Labeler (HKLM\...\{3EBA6E7C-3DF6-48AE-B87B-4CAFB2C1C3F7}) (Version: 1.10.13.1 - LightScribe)
Malwarebytes version 3.0.5.1299 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.0.5.1299 - Malwarebytes)
MarketResearch (Version: 90.0.146.000 - Hewlett-Packard) Hidden
McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.11.500.3 - McAfee, Inc.)
Mesh Runtime (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office File Validation Add-In (HKLM\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (HKLM\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office PowerPoint Viewer 2007 (English) (HKLM\...\{95120000-00AF-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50428.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319 (HKLM\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Works (HKLM\...\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}) (Version: 9.7.0621 - Microsoft Corporation)
MotoHelper MergeModules (Version: 1.2.0 - Motorola) Hidden
Motorola Mobile Drivers Installation 5.2.0 (Version: 5.2.0 - Motorola Inc.) Hidden
Mozilla Firefox 52.0.2 ESR (x86 en-US) (HKLM\...\Mozilla Firefox 52.0.2 ESR (x86 en-US)) (Version: 52.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 52.0.2.6291 - Mozilla)
MSXML 4.0 SP2 (KB936181) (HKLM\...\{C04E32E0-0416-434D-AFB9-6969D703A9EF}) (Version: 4.20.9848.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB941833) (HKLM\...\{C523D256-313D-4866-B36A-F3DE528246EF}) (Version: 4.20.9849.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
muvee autoProducer 6.1 (HKLM\...\{E8C2622C-9FF1-4F60-8008-A0208154F9F3}) (Version: 6.10.050 - muvee Technologies)
My HP Games (HKLM\...\WildTangent hp Master Uninstall) (Version: HPCMPQ1902 - WildTangent)
My Lockbox 2.8.7 (HKLM\...\My Lockbox_is1) (Version: 2.8.7 - )
OGA Notifier 2.0.0048.0 (Version: 2.0.0048.0 - Microsoft Corporation) Hidden
Power2Go (HKLM\...\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 5.6.3417 - CyberLink Corp.)
PowerDirector (HKLM\...\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 6.5.2209 - CyberLink Corp.)
PowerDirector (Version: 6.5.2209 - CyberLink Corp.) Hidden
PSSWCORE (Version: 2.01.0000 - Hewlett-Packard) Hidden
Python 2.5 (HKLM\...\{0A2C5854-557E-48C8-835A-3B9F074BDCAA}) (Version: 2.5.150 - Martin v. Löwis)
Quicken 2008 (HKLM\...\{3B0F52AC-EF5C-4831-B221-06C782E41280}) (Version: 17.1.1.24 - Intuit)
QuickTime 7 (HKLM\...\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.)
Razer Game Booster (HKLM\...\Razer Game Booster_is1) (Version: 4.1.59.0 - Razer Inc.)
RealDownloader (Version: 1.3.3 - RealNetworks, Inc.) Hidden
RealNetworks - Microsoft Visual C++ 2008 Runtime (Version: 9.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) Hidden
RealPlayer (HKLM\...\RealPlayer 16.0) (Version: 16.0.3 - RealNetworks)
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7487 - Realtek Semiconductor Corp.)
RealUpgrade 1.1 (Version: 1.1.0 - RealNetworks, Inc.) Hidden
RogueKiller version 12.10.3.0 (HKLM\...\8B3D7924-ED89-486B-8322-E8594065D5CB_is1) (Version: 12.10.3.0 - Adlice Software)
SafeZone Stable 1.48.2066.120 (Version: 1.48.2066.120 - Avast Software) Hidden
Scan (Version: 9.0.0.0 - Hewlett-Packard) Hidden
Segoe UI (Version: 15.4.2271.0615 - Microsoft Corp) Hidden
Smart Defrag 5 (HKLM\...\Smart Defrag_is1) (Version: 5.0.2 - IObit)
Snapfish Picture Mover (HKLM\...\{029B5901-1F27-4347-9923-E8ACC8F54E15}) (Version: 1.9.0.16 - HP Snapfish)
Soft Data Fax Modem with SmartCP (HKLM\...\CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200C14F1) (Version: 7.74.00 - Conexant Systems)
SolutionCenter (Version: 140.0.214.000 - Hewlett-Packard) Hidden
Status (Version: 110.0.180.000 - Hewlett-Packard) Hidden
Strongvault Online Backup (Version: 5.0.2.34 - Strongvault Online Backup) Hidden <==== ATTENTION
swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Toolbox (Version: 90.0.146.000 - Hewlett-Packard) Hidden
TrayApp (Version: 110.0.180.000 - Hewlett-Packard) Hidden
Tweaking.com - Windows Repair (HKLM\...\Tweaking.com - Windows Repair) (Version: 3.9.19 - Tweaking.com)
UnloadSupport (Version: 9.0.0 - Hewlett-Packard) Hidden
Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
VideoToolkit01 (Version: 90.0.146.000 - Hewlett-Packard) Hidden
VLC media player (HKLM\...\VLC media player) (Version: 2.2.4 - VideoLAN)
WeatherBug Gadget (Version: 1.0.0.6 - AWS Convergence Technologies) Hidden
WebReg (Version: 90.0.146.000 - Hewlett-Packard) Hidden
Windows Live Essentials (HKLM\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live OneCare safety scanner (HKLM\...\Windows Live OneCare safety scanner) (Version:  - Microsoft Corporation)
Yahoo! Detect (HKLM\...\YTdetect) (Version:  - )

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0D9A6676-E7E9-4379-ACD7-9E235B2E247F} - System32\Tasks\{9E824D69-F1D8-4FA9-957C-1BD52949E79B} => pcalua.exe -a C:\Users\Owner\Desktop\wmvfirefoxpluginsetup-0.1.675.1923.exe -d C:\Users\Owner\Desktop
Task: {0F8492ED-9B20-420C-AFE1-2597B2536A69} - System32\Tasks\{96CB999D-D56A-44B8-88CE-B263635281B5} => pcalua.exe -a C:\Users\Owner\AppData\Roaming\Dropbox\bin\Uninstall.exe
Task: {12F2FB58-482B-45CE-91FE-469AD3BA03B9} - System32\Tasks\GoogleUpdateTaskMachineCore1d0f83723728dc0 => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.)
Task: {210A3F62-32F4-44F8-A4EE-876DD9F9A952} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.)
Task: {2193D548-5087-48A8-BA78-11A55EDF0CF0} - \Uninstaller_SkipUac_Owner -> No File <==== ATTENTION
Task: {325903FB-FC15-4C35-BD33-3520B1E4A5D7} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\system32\Macromed\Flash\FlashUtil32_25_0_0_127_pepper.exe [2017-03-19] (Adobe Systems Incorporated)
Task: {4085288C-157A-4EA3-BD23-34AAE8753537} - System32\Tasks\{81D36BAA-037E-4C63-8F5E-03972E26A209} => pcalua.exe -a C:\Windows\unvise32.exe -d C:\Windows -c C:\PROGRA~1\SSREMO~1\WINFIX~1\uninstal.log
Task: {57BAA3C9-9BAF-4B80-B1BB-7DA0D20CE677} - System32\Tasks\{0AA30D52-82F0-481F-B5DB-B925ADAAEC64} => pcalua.exe -a C:\Users\Owner\AppData\Local\Temp\InstallFlashPlayer.exe -d "C:\Program Files\Mozilla Firefox" <==== ATTENTION
Task: {58699313-6F1B-45C9-824B-5DCB284930C4} - System32\Tasks\{7B448623-2896-42C7-8A7F-399EFB8B3265} => pcalua.exe -a C:\Windows\system32\igfxcpl.cpl -c Intel® GMA Driver
Task: {5E1E8F24-239D-4794-8230-36C181661661} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-3222991852-3880959725-3339485959-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.)
Task: {65807845-679A-4597-81D0-C9951DE3E8A9} - \Driver Booster SkipUAC (SYSTEM) -> No File <==== ATTENTION
Task: {6BB5649B-BCBF-456E-A198-8769E01E3C35} - \Driver Booster SkipUAC (Owner) -> No File <==== ATTENTION
Task: {7146F999-EB42-4096-A93B-A8857EA82DB9} - System32\Tasks\SmartDefrag_Update => C:\Program Files\IObit\Smart Defrag\AutoUpdate.exe [2016-03-23] (IObit)
Task: {812CB87A-0074-4BFA-B916-D224E4E8FC07} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.)
Task: {8848D97C-CCC7-4A9E-A72A-52EBC3975C96} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2017-03-01] (AVAST Software)
Task: {9257BE66-66E2-4833-AA67-25A9F002AE49} - System32\Tasks\{31826C7C-60C7-4D54-B6DE-CB183CFFA0CF} => pcalua.exe -a "C:\Program Files\Quicken\PDFDrv\Install.exe" -d "C:\Program Files\Quicken\PDFDrv"
Task: {9D40B1E4-827C-4B59-AA0F-D8AAE0FFE33F} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-3222991852-3880959725-3339485959-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.)
Task: {9ECEBC6C-204C-4C03-94D9-1826E6517B00} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-3222991852-3880959725-3339485959-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.)
Task: {A0364B18-9C67-4642-A27D-19F8E1364E9D} - System32\Tasks\PC-Doctor\Scheduled Maintanence => C:\Program Files\PC-Doctor 5 for Windows\RunProfiler.exe [2007-06-25] (PC-Doctor, Inc.)
Task: {AE475C41-32C1-4C5D-9687-89129EC93985} - System32\Tasks\ASC10_SkipUac_Owner => C:\Program Files\IObit\Advanced SystemCare\ASC.exe
Task: {B061D5FB-62BC-4FEA-8698-B1700F281104} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2012-12-19] (Piriform Ltd)
Task: {BAABEAE4-981F-4CBA-8274-DD80EE9EF683} - \Driver Booster Scan -> No File <==== ATTENTION
Task: {C152B96C-F219-4470-BCD9-D8DDDE410F55} - \Driver Booster Update -> No File <==== ATTENTION
Task: {C2F55971-AE96-4C8C-ACDE-9F21C0E768CE} - System32\Tasks\HPCustParticipation HP Deskjet 3050A J611 series => C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\HPCustPartic.exe [2011-06-08] (Hewlett-Packard Co.)
Task: {C340B0B0-AA83-4BBB-8F86-2A2B87CFF1D5} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-12-14] (Adobe Systems Incorporated)
Task: {D03C2AFD-DC8D-4E46-A94C-7841CD7155A9} - System32\Tasks\{F89EA742-8EFB-412E-9212-EC63809D42CB} => pcalua.exe -a "C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CS9B81CY\GetGnuWin32-0.6.21[1].exe" -d C:\Users\Owner\Desktop
Task: {E634DC68-C231-42F1-97CB-9910521D8541} - \Uninstaller_SkipUac_Administrator -> No File <==== ATTENTION
Task: {EAC1E61E-5365-44DE-BBCD-8F4DE830E2DA} - System32\Tasks\SafeZone scheduled Autoupdate 1458676906 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2016-08-12] (Avast Software)
Task: {EC75A2DA-8E83-4C9B-80C9-F516AC646223} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)
Task: {F5353FA7-2075-44EC-90FF-216CABB5F64E} - System32\Tasks\JavaUpdateadmin anticryptolock => C:\Windows\system32\jusched.exe
Task: {FFFD62AD-17D4-4C36-A0FC-2292C1629B07} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-3222991852-3880959725-3339485959-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\Tweaking.com - Windows Repair Tray Icon.job => C:\Program Files\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe C:\Program Files\Tweaking.com\Windows Repair (All in One) Tweaking.com - Windows Repair )Created By Tweaking.com

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

==================== Loaded Modules (Whitelisted) ==============

2017-03-01 21:43 - 2017-03-01 21:43 - 00170216 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2017-04-08 10:01 - 2017-04-08 10:01 - 06022832 _____ () C:\Program Files\AVAST Software\Avast\defs\17040800\algo.dll
2017-03-01 21:44 - 2017-03-01 21:44 - 00655056 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
2014-02-12 20:58 - 2014-02-12 20:58 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-03-20 18:12 - 2015-03-20 18:12 - 01044776 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2016-12-21 13:29 - 2017-03-10 20:09 - 01732896 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\PoliciesControllerImpl.dll
2009-08-05 12:26 - 2009-08-05 12:26 - 00061440 _____ () C:\Program Files\Hewlett-Packard\HP Advisor\Pillars\PCAlerts\PCAlertsPillar.dll
2009-08-05 12:26 - 2009-08-05 12:26 - 00131072 _____ () C:\Program Files\Hewlett-Packard\HP Advisor\Pillars\ECenter\ECLibrary.dll
2009-08-05 12:25 - 2009-08-05 12:25 - 00028672 _____ () C:\Program Files\Hewlett-Packard\HP Advisor\Microsoft.Practices.EnterpriseLibrary.ExceptionHandling.Logging.dll
2009-08-05 12:26 - 2009-08-05 12:26 - 00040960 _____ () C:\Program Files\Hewlett-Packard\HP Advisor\MessagingServer.dll
2009-08-05 12:26 - 2009-08-05 12:26 - 00005632 _____ () C:\Program Files\Hewlett-Packard\HP Advisor\MessagingInterface.dll
2009-08-05 12:26 - 2009-08-05 12:26 - 00028672 _____ () C:\Program Files\Hewlett-Packard\HP Advisor\MessagingMessages.dll
2009-08-05 12:26 - 2009-08-05 12:26 - 00036864 _____ () C:\Program Files\Hewlett-Packard\HP Advisor\MessagingClients.dll
2009-08-05 12:26 - 2009-08-05 12:26 - 00007680 _____ () C:\Program Files\Hewlett-Packard\HP Advisor\RemotingClient.dll
2017-03-01 21:42 - 2017-03-01 21:42 - 00134920 _____ () c:\Program Files\AVAST Software\Avast\vaarclient.dll
2016-10-17 15:15 - 2015-12-23 18:32 - 00190240 _____ () C:\Program Files\IObit\IObit Uninstaller\madBasic_.bpl
2016-10-17 15:15 - 2015-12-23 18:32 - 00057632 _____ () C:\Program Files\IObit\IObit Uninstaller\madDisAsm_.bpl
2016-09-28 05:46 - 2016-09-28 05:47 - 48936448 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2017-03-01 21:42 - 2017-03-01 21:42 - 00290352 _____ () C:\Program Files\AVAST Software\Avast\gaming_mode_ui.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData\TEMP:303528AB [131]
AlternateDataStreams: C:\ProgramData\TEMP:DFC5A2B2 [212]
AlternateDataStreams: C:\ProgramData\TEMP:FC2E567F [104]

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BFE => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BITS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MpsSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\msiserver => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SharedAccess => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vss => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BITS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\msiserver => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SamSs => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\srv => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\srv2 => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\srvnet => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vss => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

HKLM\...\cmdfile\DefaultIcon: %SystemRoot%\System32\imageres.dll,-68 <===== ATTENTION

==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE restricted site: HKU\.DEFAULT\...\008i.com -> 008i.com
IE restricted site: HKU\.DEFAULT\...\008k.com -> 008k.com
IE restricted site: HKU\.DEFAULT\...\00hq.com -> 00hq.com
IE restricted site: HKU\.DEFAULT\...\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\.DEFAULT\...\01i.info -> 01i.info
IE restricted site: HKU\.DEFAULT\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\.DEFAULT\...\05p.com -> 05p.com
IE restricted site: HKU\.DEFAULT\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\.DEFAULT\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\.DEFAULT\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\.DEFAULT\...\0calories.net -> 0calories.net
IE restricted site: HKU\.DEFAULT\...\0cj.net -> 0cj.net
IE restricted site: HKU\.DEFAULT\...\0scan.com -> 0scan.com
IE restricted site: HKU\.DEFAULT\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\.DEFAULT\...\1-domains-registrations.com -> 1-domains-registrations.com
IE restricted site: HKU\.DEFAULT\...\1-se.com -> 1-se.com
IE restricted site: HKU\.DEFAULT\...\1001movie.com -> 1001movie.com
IE restricted site: HKU\.DEFAULT\...\1001night.biz -> 1001night.biz
IE restricted site: HKU\.DEFAULT\...\100gal.net -> 100gal.net
IE restricted site: HKU\.DEFAULT\...\100sexlinks.com -> 100sexlinks.com

There are 4788 more sites.


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2006-11-02 06:23 - 2017-04-08 08:10 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts

127.0.0.1       localhost

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3222991852-3880959725-3339485959-1165\Control Panel\Desktop\\Wallpaper -> C:\Users\Public\Pictures\Sample Pictures\Cabo.JPG
DNS Servers: 208.59.247.45 - 208.59.247.46
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 1) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

MSCONFIG\Services: SfCtlCom => 2
MSCONFIG\Services: TMBMServer => 2
MSCONFIG\Services: TmProxy => 2
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: mylbx => C:\Program Files\My Lockbox\mylbx.exe /a
MSCONFIG\startupreg: PrinTray => C:\Windows\system32\spool\DRIVERS\W32X86\3\printray.exe

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{2B060F2A-01D9-49F4-8B59-05798FDEA000}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
FirewallRules: [TCP Query User{9EFC9B42-1D3C-423C-AD8B-5A1D52F40669}C:\program files\videolan\vlc\vlc.exe] => (Block) C:\program files\videolan\vlc\vlc.exe
FirewallRules: [UDP Query User{2A411DE8-F6F2-44FC-AE92-359EEF2C8E80}C:\program files\videolan\vlc\vlc.exe] => (Block) C:\program files\videolan\vlc\vlc.exe
FirewallRules: [{AEA10DAC-019B-4BCF-848E-60DFE4F73A26}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{A445DDCC-45AD-42A2-A2B0-55B0A173A456}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [WinCollab-DFSR-In-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [WinCollab-DFSR-Out-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [WinCollab-In-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-Out-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-In-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-Out-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [{C7FE593A-698F-4050-8DEB-7A46CDBD4A60}] => (Allow) LPort=139
FirewallRules: [{9845CFB1-F7CC-44AC-B4F8-7EE89F427CFB}] => (Allow) LPort=138
FirewallRules: [{825686B5-7686-4C5D-8371-3B53F2C94065}] => (Allow) LPort=137
FirewallRules: [{997C09BD-78F2-4B73-9638-52126042CEEC}] => (Allow) LPort=137
FirewallRules: [{41051A13-5975-4482-A415-7645BDACF1A5}] => (Allow) LPort=138
FirewallRules: [{C0F54608-91F0-4E4D-B381-F8FC8BA2D67D}] => (Allow) LPort=139
FirewallRules: [TCP Query User{A141030F-7A5E-436E-AC12-60B4C72FCE4F}C:\program files\real\realplayer\realplay.exe] => (Allow) C:\program files\real\realplayer\realplay.exe
FirewallRules: [UDP Query User{A1DB684F-B214-4989-B364-489EF8333D08}C:\program files\real\realplayer\realplay.exe] => (Allow) C:\program files\real\realplayer\realplay.exe
FirewallRules: [{4E6BCE39-F3EA-461A-B669-6B6DCA024E8A}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{3A07DF7E-EF3B-4E59-BEA2-E0AC3DE2B9BB}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{5A23A0BD-D279-4AF7-9CB4-FA8E629F1F48}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{A8D6B8B1-9696-4894-9B65-2AE682EE40F6}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe
FirewallRules: [{44670F9B-1D96-4ECB-BA60-71038AA85165}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{54CBFDAD-0604-4D91-A5BF-062363E0D7C8}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{5F7637A9-8BBD-4121-B649-042AD60D132B}] => (Allow) C:\Program Files\IObit\Advanced SystemCare\Surfing Protection\FFNativeMessage.exe
FirewallRules: [{202339DA-E648-4C49-9F9D-17A057562985}] => (Allow) C:\Program Files\IObit\Advanced SystemCare\Surfing Protection\FFNativeMessage.exe
FirewallRules: [{3C9100F6-5D66-43F1-BD8A-51D3D0F193DE}] => (Allow) C:\Users\ADMINA~1\AppData\Local\Temp\HouseCall\tmase\nmap\nmap.exe
FirewallRules: [TCP Query User{3BB2BEF5-1A9F-4935-BA30-020A5E8BDB63}C:\users\admin anticryptolock\appdata\local\temp\housecall\tmase\nmap\bonjour.exe] => (Block) C:\users\admin anticryptolock\appdata\local\temp\housecall\tmase\nmap\bonjour.exe
FirewallRules: [UDP Query User{D51F845D-4CAF-40A4-8126-88AF543496A1}C:\users\admin anticryptolock\appdata\local\temp\housecall\tmase\nmap\bonjour.exe] => (Block) C:\users\admin anticryptolock\appdata\local\temp\housecall\tmase\nmap\bonjour.exe

==================== Restore Points =========================


==================== Faulty Device Manager Devices =============

Name: isatap.cable.rcn.com
Description: Microsoft ISATAP Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver


==================== Event log errors: =========================

Application errors:
==================
Error: (04/08/2017 02:37:03 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Windows\Installer\{C8E8D2E3-EF6A-4B1D-A09E-7B27EBE2F3CE}\recordingmanager.exe".
Dependent Assembly rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (04/08/2017 02:37:03 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Windows\Installer\{C8E8D2E3-EF6A-4B1D-A09E-7B27EBE2F3CE}\recordingmanager.exe".
Dependent Assembly rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (04/08/2017 02:34:09 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Activation context generation failed for "C:\Program Files\Windows Live\Messenger\msnmsgr.exe".Error in manifest or policy file "" on line .
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4148_none_5090ab56bcba71c2.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_e163563597edeada.manifest.

Error: (04/08/2017 02:33:50 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application rndlresolversvc.exe, version 0.0.0.0, time stamp 0x520c0269, faulting module rndlresolversvc.exe, version 0.0.0.0, time stamp 0x520c0269, exception code 0xc0000005, fault offset 0x00003035,
process id 0xd40, application start time 0x01d2b096a61531cf.

Error: (04/08/2017 02:31:28 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 512) (User: )
Description: The Cryptographic Services service failed to initialize the VSS backup "System Writer" object.

Details:
Could not query the status of the EventSystem service.

System Error:
A system shutdown is in progress.
.

Error: (04/08/2017 12:00:55 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Windows\Installer\{C8E8D2E3-EF6A-4B1D-A09E-7B27EBE2F3CE}\recordingmanager.exe".
Dependent Assembly rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (04/08/2017 12:00:28 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Activation context generation failed for "C:\Program Files\Windows Live\Messenger\msnmsgr.exe".Error in manifest or policy file "" on line .
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4148_none_5090ab56bcba71c2.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_e163563597edeada.manifest.

Error: (04/08/2017 10:07:22 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Windows\Installer\{C8E8D2E3-EF6A-4B1D-A09E-7B27EBE2F3CE}\recordingmanager.exe".
Dependent Assembly rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (04/08/2017 10:07:22 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Windows\Installer\{C8E8D2E3-EF6A-4B1D-A09E-7B27EBE2F3CE}\recordingmanager.exe".
Dependent Assembly rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (04/08/2017 10:06:37 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Activation context generation failed for "C:\Program Files\Windows Live\Messenger\msnmsgr.exe".Error in manifest or policy file "" on line .
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4148_none_5090ab56bcba71c2.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_e163563597edeada.manifest.


System errors:
=============
Error: (04/08/2017 02:34:09 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The VBoxAsw Support Driver service failed to start due to the following error:
The system cannot find the path specified.

Error: (04/08/2017 02:33:53 PM) (Source: Print) (EventID: 19) (User: NT AUTHORITY)
Description: The print spooler failed to share printer Amyuni Document Converter with shared resource name Amyuni Document Converter. Error 2114. The printer cannot be used by others on the network.

Error: (04/08/2017 02:33:53 PM) (Source: Print) (EventID: 19) (User: NT AUTHORITY)
Description: The print spooler failed to share printer HP Deskjet 3050A J611 series with shared resource name HP Deskjet 3050A J611 series. Error 2114. The printer cannot be used by others on the network.

Error: (04/08/2017 02:33:53 PM) (Source: Print) (EventID: 19) (User: NT AUTHORITY)
Description: The print spooler failed to share printer HP Deskjet F4100 series with shared resource name HP Deskjet F4100 series. Error 2114. The printer cannot be used by others on the network.

Error: (04/08/2017 02:33:53 PM) (Source: Print) (EventID: 19) (User: NT AUTHORITY)
Description: The print spooler failed to share printer HP Deskjet F4100 series (Copy 4) with shared resource name HP Deskjet F4100 series (Copy 4). Error 2114. The printer cannot be used by others on the network.

Error: (04/08/2017 02:33:53 PM) (Source: Print) (EventID: 19) (User: NT AUTHORITY)
Description: The print spooler failed to share printer Quicken PDF Printer with shared resource name Quicken PDF Printer. Error 2114. The printer cannot be used by others on the network.

Error: (04/08/2017 02:33:53 PM) (Source: Print) (EventID: 19) (User: NT AUTHORITY)
Description: The print spooler failed to share printer Send To OneNote 2007 with shared resource name Send To OneNote 2007. Error 2114. The printer cannot be used by others on the network.

Error: (04/08/2017 12:37:41 PM) (Source: DCOM) (EventID: 10005) (User: )
Description: DCOM got error "1068" attempting to start the service stisvc with arguments "" in order to run the server:
{A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error: (04/08/2017 12:01:12 PM) (Source: DCOM) (EventID: 10005) (User: )
Description: DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server:
{9E175B68-F52A-11D8-B9A5-505054503030}

Error: (04/08/2017 10:07:48 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The PnP-X IP Bus Enumerator service depends on the Function Discovery Provider Host service which failed to start because of the following error:
The dependency service or group failed to start.


CodeIntegrity:
===================================
  Date: 2017-04-08 10:36:55.005
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\MBAMChameleon.sys because the set of per-page image hashes could not be found on the system.

  Date: 2017-04-08 10:36:53.664
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\MBAMChameleon.sys because the set of per-page image hashes could not be found on the system.

  Date: 2017-04-08 10:36:52.322
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\MBAMChameleon.sys because the set of per-page image hashes could not be found on the system.

  Date: 2017-04-08 10:36:50.996
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\MBAMChameleon.sys because the set of per-page image hashes could not be found on the system.

  Date: 2017-04-08 10:34:18.054
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

  Date: 2017-04-08 10:34:16.712
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

  Date: 2017-04-08 10:34:15.370
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

  Date: 2017-04-08 10:34:14.013
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

  Date: 2017-04-08 08:02:13.827
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

  Date: 2017-04-08 08:02:12.501
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.


==================== Memory info ===========================

Processor: Intel® Pentium® Dual CPU E2180 @ 2.00GHz
Percentage of memory in use: 49%
Total physical RAM: 2038.64 MB
Available physical RAM: 1027.27 MB
Total Virtual: 4314.55 MB
Available Virtual: 2508.14 MB

==================== Drives ================================

Drive c: (COMPAQ) (Fixed) (Total:326.01 GB) (Free:82.69 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (FACTORY_IMAGE) (Fixed) (Total:9.34 GB) (Free:0.87 GB) NTFS ==>[system with boot components (obtained from drive)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 335.4 GB) (Disk ID: 1549F232)
Partition 1: (Active) - (Size=326 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=9.3 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================

 

 

Um, an fyi, I had sent an email with an attachment from a laptop to my desktop machine. The attachment seemed to work fine, but a "baddie" might have stowed away in there (I have a zwatom thingie trojan horsing with Odysseus around in the laptop :(  ) When I attempted to log onto THIS machine, desktop vista, I got a looong wait with the words "windows is preparing your desktop."  Anyway, Whatever you need, I'll do the best I can.

 

Thanks so much in advance,  um, you could call me "Shadow", or "Susannah"  your choice.  Sorry 'bout the reference to the Trojan War -- but, in a pinch.... ;)  :devil: user profile corrupted ?  eek!



#6 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,179 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:01:39 AM

Posted 12 April 2017 - 08:46 PM

Greetings Susannah.

Let's start with this.

===================================================

Uninstalling a Program using Add/Remove Program

--------------------

I recommend the uninstalling of the below listed program(s).
  • Press windows key Windows_Logo_key.gif + r on your keyboard at the same time
  • Type appwiz.cpl and press Enter
  • A list of installed programs will be displayed
  • Uninstall the following by clicking on the program(s) below (and any other similar names) and selecting Remove or Uninstall

IObit Apps Toolbar v7.1
IObit Malware Fighter 4
IObit Uninstaller
Strongvault Online Backup

  • Reboot your computer
===================================================

Farbar's Recovery Scan Tool - Run Fix in Normal or Safe Mode

--------------------
  • Press the Windows Key + R on your keyboard at the same time. Type in notepad and press Enter
  • Please copy and paste the contents of the below code box into the open notepad and save it as fixlist.txt in the same location/folder as FRST.exe (<<<Important)
CreateRestorePoint:
CloseProcesses:
HKU\S-1-5-21-3222991852-3880959725-3339485959-1165\...0c966feabec1\InprocServer32: [Default-shell32]  ATTENTION
GroupPolicyUsers\S-1-5-21-3222991852-3880959725-3339485959-1165\User: Restriction <======= ATTENTION
GroupPolicyUsers\S-1-5-21-3222991852-3880959725-3339485959-1000\User: Restriction <======= ATTENTION
2099-02-24 15:15 - 2001-04-02 17:30 - 00000821 _____ C:\Windows\Lexmark_ICM.ini
2099-02-16 17:09 - 2001-02-16 16:37 - 00000062 _____ C:\Windows\system32\LXASUSCI.INI
2008-07-18 16:20 - 2008-07-18 16:20 - 0005099 _____ () C:\ProgramData\amjmwaey.gaf
C:\Users\Owner\AdbeRdr1014_en_US.exe
C:\Users\Owner\backup.reg
C:\Users\Owner\Firefox Setup 11.0b3.exe
C:\Users\Owner\Firefox Setup 6.0.exe
C:\Users\Owner\HPPSdr hp print and scan doctor Dec 3 2013.exe
C:\Users\Owner\iTunesSetup.exe
C:\Users\Owner\mseinstall.exe
C:\Users\Owner\NP2k9WinDemo.exe
C:\Users\Owner\QuickTimeInstaller.exe
C:\Users\Owner\RealPlayer11GOLD(2).exe
C:\Users\Owner\RealPlayer11GOLD.exe
C:\Users\Owner\scanjet_vista_tablet_patch Dec 3 2013.exe
C:\Users\Owner\SeFilm.exe
C:\Users\Owner\slp_dd_hathi_110_017   dec 3 2013.exe
C:\Users\Owner\vlc-1.1.11-win32.exe
C:\Users\Owner\windows-kb890830-v2.8.exe
Task: {2193D548-5087-48A8-BA78-11A55EDF0CF0} - \Uninstaller_SkipUac_Owner -> No File <==== ATTENTION
Task: {57BAA3C9-9BAF-4B80-B1BB-7DA0D20CE677} - System32\Tasks\{0AA30D52-82F0-481F-B5DB-B925ADAAEC64} => pcalua.exe -a C:\Users\Owner\AppData\Local\Temp\InstallFlashPlayer.exe -d "C:\Program Files\Mozilla Firefox" <==== ATTENTION
Task: {65807845-679A-4597-81D0-C9951DE3E8A9} - \Driver Booster SkipUAC (SYSTEM) -> No File <==== ATTENTION
Task: {6BB5649B-BCBF-456E-A198-8769E01E3C35} - \Driver Booster SkipUAC (Owner) -> No File <==== ATTENTION
Task: {BAABEAE4-981F-4CBA-8274-DD80EE9EF683} - \Driver Booster Scan -> No File <==== ATTENTION
Task: {C152B96C-F219-4470-BCD9-D8DDDE410F55} - \Driver Booster Update -> No File <==== ATTENTION
Task: {E634DC68-C231-42F1-97CB-9910521D8541} - \Uninstaller_SkipUac_Administrator -> No File <==== ATTENTION
AlternateDataStreams: C:\ProgramData\TEMP:303528AB [131]
AlternateDataStreams: C:\ProgramData\TEMP:DFC5A2B2 [212]
AlternateDataStreams: C:\ProgramData\TEMP:FC2E567F [104]
Folder: C:\cc5a674df9e1e1956315bf5ea6
emptytemp:
  • Right click on FRST.exe, select Run as administrator then press the Fix button
  • When completed he tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • Programs uninstall?
  • Fixlog
  • Update on computer behavior

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#7 ShadowMyst

ShadowMyst
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:New England
  • Local time:04:39 AM

Posted 15 April 2017 - 01:33 AM

Okay, gettin' into it. With respect, I might have to make this into two parts,as the requirements of Uncle Sam and the 15th of this month are holding their hands out.

 

some notes:  couple of things:

1. There is another toolbar -- Iobit v6.6, when I clicked on it, it didn't have an "uninstall" feature."

2. when I went to uninstall Iobit apps toolbar v7.1 I got both a dialog box saying "windows installer"
  The feature you are trying to use is on a network resource that is unavailable.

click OK To try again, or enter an alternate path to a folder containing the installation package Iobitapps Toolbar.msi in the box below.

Use Source:  C:\Users\owner\appData\Local\Temp\{88D524B6-AF1A-4B3E-A80B-12AACB91EDEE}
 etc.,etc.

And, when I clicked okay on the above, I then got a dialog box

    -- Interactive Services Dialog Detection:

A program can't display a message on your desktop.
The program may need information or permission to complete a task.

then, a dialog box: the installation source for this product is not available. Verify that the source exists and that you can access it.

As there IS a path to spigot's IObit v7.7 toolbar, do you think I could uninstall it that way?

Additionally, I take it I need to uninstall the Iobit folder? out of C:\Programs?


https://www.bleepingcomputer.com/forums/t/526131/cpu-usage-soaring/
Per Google Search: "CPU usage soaring - Virus, Trojan, Spyware, and Malware Removal ...
https://www.bleepingcomputer.com/forums/t/526131/cpu-usage-soaring/
Mar 1, 2014 - URLSearchHook: HKCU - IObit Apps Toolbar - {03EB0E9C-7A91-4381-A220-9B52B641CDB1} - C:\Program Files\IObit Apps Toolbar\IE\8.8\iobitappsToolbarIE.dll (Spigot, Inc.) ..... FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 ..... CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\Mozilla ..."


re: Strongvault, it seems as if that is a PUP, has its' own removal game.  Should I continue, e.g. instructions in Malwaretips, etc.
could not find source of Strongvault.

https://answers.microsoft.com/en-us/windows/forum/windows_10-security/unable-to-uninstall-strongvault/5406bb52-1841-47ad-8e2f-20de08ac12ec?tab=question&status=AllReplies&status=AllReplies%2CAllReplies#tabs -- followed this to try to get rid of strongvault.

The Registry entries of the program may be preventing you from completely uninstalling it from the system. Follow these steps to delete the entries:

    Press the Windows key + R on your keyboard.
    Type regedit then press Enter.
    Navigate to these locations in the Registry:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Run\random.exe
    HKEY_CURRENT_USER\Software\Microsoft\CurrentVersion\Run\”MSN” = “%Temp%\34542.exe
    HKEY_CURRENT_USER\AppEvents\Schemes\Apps\Explorer\Navigating
HKEY_CURRENT_USER\AppEvents\Schemes\Apps\Explorer\Navigating -- found this one. deleting.

went to regedit. typed in strongvault. got a key or two. Was too much of a sissy to delete. two values. Also, I didn't know whether you wanted this done, and felt caution was best.

 

 

FIXLOG: Fix result of Farbar Recovery Scan Tool (x86) Version: 15-03-2017
Ran by admin anticryptolock (15-04-2017 02:01:59) Run:1
Running from C:\Users\admin anticryptolock\Desktop
Loaded Profiles: admin anticryptolock (Available Profiles: Owner & admin anticryptolock)
Boot Mode: Normal

==============================================

fixlist content:
*****************
CreateRestorePoint:
CloseProcesses:
HKU\S-1-5-21-3222991852-3880959725-3339485959-1165\...0c966feabec1\InprocServer32: [Default-shell32]  ATTENTION
GroupPolicyUsers\S-1-5-21-3222991852-3880959725-3339485959-1165\User: Restriction <======= ATTENTION
GroupPolicyUsers\S-1-5-21-3222991852-3880959725-3339485959-1000\User: Restriction <======= ATTENTION
2099-02-24 15:15 - 2001-04-02 17:30 - 00000821 _____ C:\Windows\Lexmark_ICM.ini
2099-02-16 17:09 - 2001-02-16 16:37 - 00000062 _____ C:\Windows\system32\LXASUSCI.INI
2008-07-18 16:20 - 2008-07-18 16:20 - 0005099 _____ () C:\ProgramData\amjmwaey.gaf
C:\Users\Owner\AdbeRdr1014_en_US.exe
C:\Users\Owner\backup.reg
C:\Users\Owner\Firefox Setup 11.0b3.exe
C:\Users\Owner\Firefox Setup 6.0.exe
C:\Users\Owner\HPPSdr hp print and scan doctor Dec 3 2013.exe
C:\Users\Owner\iTunesSetup.exe
C:\Users\Owner\mseinstall.exe
C:\Users\Owner\NP2k9WinDemo.exe
C:\Users\Owner\QuickTimeInstaller.exe
C:\Users\Owner\RealPlayer11GOLD(2).exe
C:\Users\Owner\RealPlayer11GOLD.exe
C:\Users\Owner\scanjet_vista_tablet_patch Dec 3 2013.exe
C:\Users\Owner\SeFilm.exe
C:\Users\Owner\slp_dd_hathi_110_017   dec 3 2013.exe
C:\Users\Owner\vlc-1.1.11-win32.exe
C:\Users\Owner\windows-kb890830-v2.8.exe
Task: {2193D548-5087-48A8-BA78-11A55EDF0CF0} - \Uninstaller_SkipUac_Owner -> No File <==== ATTENTION
Task: {57BAA3C9-9BAF-4B80-B1BB-7DA0D20CE677} - System32\Tasks\{0AA30D52-82F0-481F-B5DB-B925ADAAEC64} => pcalua.exe -a C:\Users\Owner\AppData\Local\Temp\InstallFlashPlayer.exe -d "C:\Program Files\Mozilla Firefox" <==== ATTENTION
Task: {65807845-679A-4597-81D0-C9951DE3E8A9} - \Driver Booster SkipUAC (SYSTEM) -> No File <==== ATTENTION
Task: {6BB5649B-BCBF-456E-A198-8769E01E3C35} - \Driver Booster SkipUAC (Owner) -> No File <==== ATTENTION
Task: {BAABEAE4-981F-4CBA-8274-DD80EE9EF683} - \Driver Booster Scan -> No File <==== ATTENTION
Task: {C152B96C-F219-4470-BCD9-D8DDDE410F55} - \Driver Booster Update -> No File <==== ATTENTION
Task: {E634DC68-C231-42F1-97CB-9910521D8541} - \Uninstaller_SkipUac_Administrator -> No File <==== ATTENTION
AlternateDataStreams: C:\ProgramData\TEMP:303528AB [131]
AlternateDataStreams: C:\ProgramData\TEMP:DFC5A2B2 [212]
AlternateDataStreams: C:\ProgramData\TEMP:FC2E567F [104]
Folder: C:\cc5a674df9e1e1956315bf5ea6
emptytemp:
*****************

Restore point was successfully created.
Processes closed successfully.
HKU\S-1-5-21-3222991852-3880959725-3339485959-1165\Software\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1} => key removed successfully.
C:\Windows\system32\GroupPolicyUsers\S-1-5-21-3222991852-3880959725-3339485959-1165\User => moved successfully
C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully
C:\Windows\system32\GroupPolicyUsers\S-1-5-21-3222991852-3880959725-3339485959-1000\User => moved successfully
C:\Windows\Lexmark_ICM.ini => moved successfully
C:\Windows\system32\LXASUSCI.INI => moved successfully
C:\ProgramData\amjmwaey.gaf => moved successfully
C:\Users\Owner\AdbeRdr1014_en_US.exe => moved successfully
C:\Users\Owner\backup.reg => moved successfully
C:\Users\Owner\Firefox Setup 11.0b3.exe => moved successfully
C:\Users\Owner\Firefox Setup 6.0.exe => moved successfully
C:\Users\Owner\HPPSdr hp print and scan doctor Dec 3 2013.exe => moved successfully
C:\Users\Owner\iTunesSetup.exe => moved successfully
C:\Users\Owner\mseinstall.exe => moved successfully
C:\Users\Owner\NP2k9WinDemo.exe => moved successfully
C:\Users\Owner\QuickTimeInstaller.exe => moved successfully
C:\Users\Owner\RealPlayer11GOLD(2).exe => moved successfully
C:\Users\Owner\RealPlayer11GOLD.exe => moved successfully
C:\Users\Owner\scanjet_vista_tablet_patch Dec 3 2013.exe => moved successfully
C:\Users\Owner\SeFilm.exe => moved successfully
C:\Users\Owner\slp_dd_hathi_110_017   dec 3 2013.exe => moved successfully
C:\Users\Owner\vlc-1.1.11-win32.exe => moved successfully
C:\Users\Owner\windows-kb890830-v2.8.exe => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2193D548-5087-48A8-BA78-11A55EDF0CF0} => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2193D548-5087-48A8-BA78-11A55EDF0CF0} => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Uninstaller_SkipUac_Owner => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{57BAA3C9-9BAF-4B80-B1BB-7DA0D20CE677} => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{57BAA3C9-9BAF-4B80-B1BB-7DA0D20CE677} => key removed successfully.
C:\Windows\System32\Tasks\{0AA30D52-82F0-481F-B5DB-B925ADAAEC64} => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{0AA30D52-82F0-481F-B5DB-B925ADAAEC64} => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{65807845-679A-4597-81D0-C9951DE3E8A9} => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{65807845-679A-4597-81D0-C9951DE3E8A9} => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster SkipUAC (SYSTEM) => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6BB5649B-BCBF-456E-A198-8769E01E3C35} => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6BB5649B-BCBF-456E-A198-8769E01E3C35} => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster SkipUAC (Owner) => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{BAABEAE4-981F-4CBA-8274-DD80EE9EF683} => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BAABEAE4-981F-4CBA-8274-DD80EE9EF683} => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster Scan => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C152B96C-F219-4470-BCD9-D8DDDE410F55} => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C152B96C-F219-4470-BCD9-D8DDDE410F55} => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster Update => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E634DC68-C231-42F1-97CB-9910521D8541} => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E634DC68-C231-42F1-97CB-9910521D8541} => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Uninstaller_SkipUac_Administrator => key removed successfully.
C:\ProgramData\TEMP => ":303528AB" ADS removed successfully..
C:\ProgramData\TEMP => ":DFC5A2B2" ADS removed successfully..
C:\ProgramData\TEMP => ":FC2E567F" ADS removed successfully..

========================= Folder: C:\cc5a674df9e1e1956315bf5ea6 ========================

2017-03-17 07:24 - 2014-09-19 00:00 - 0346888 _____ (Microsoft Corporation) C:\cc5a674df9e1e1956315bf5ea6\CheckSURPackage.EXE
2017-03-17 07:24 - 2014-09-19 04:01 - 0000695 _____ () C:\cc5a674df9e1e1956315bf5ea6\PkgInstallOrder.txt
2017-03-17 07:24 - 2014-09-18 20:52 - 5844752 _____ (Microsoft Corporation) C:\cc5a674df9e1e1956315bf5ea6\Windows6.0-6001-Client-Wave0-X86.EXE
2017-03-17 07:24 - 2014-09-18 21:03 - 29385992 _____ (Microsoft Corporation) C:\cc5a674df9e1e1956315bf5ea6\Windows6.0-6001-Client-Wave1-X86.EXE
2017-03-17 07:24 - 2014-09-18 20:45 - 7720720 _____ (Microsoft Corporation) C:\cc5a674df9e1e1956315bf5ea6\Windows6.0-6001-Client-X86.EXE
2017-03-17 07:24 - 2014-09-18 21:56 - 4441360 _____ (Microsoft Corporation) C:\cc5a674df9e1e1956315bf5ea6\Windows6.0-6001-Server-Wave0-X86.EXE
2017-03-17 07:24 - 2014-09-18 22:04 - 12744464 _____ (Microsoft Corporation) C:\cc5a674df9e1e1956315bf5ea6\Windows6.0-6001-Server-Wave1-X86.EXE
2017-03-17 07:24 - 2014-09-18 21:51 - 4581640 _____ (Microsoft Corporation) C:\cc5a674df9e1e1956315bf5ea6\Windows6.0-6001-Server-X86.EXE
2017-03-17 07:24 - 2014-09-18 23:07 - 23656200 _____ (Microsoft Corporation) C:\cc5a674df9e1e1956315bf5ea6\Windows6.0-6001-ServicingCAB2-X86.EXE
2017-03-17 07:24 - 2014-09-18 22:37 - 34001160 _____ (Microsoft Corporation) C:\cc5a674df9e1e1956315bf5ea6\Windows6.0-6001-Servicing-X86.EXE
2017-03-17 07:24 - 2014-09-18 23:28 - 3115272 _____ (Microsoft Corporation) C:\cc5a674df9e1e1956315bf5ea6\Windows6.0-6001-Servicing-X86-1Apr13.EXE
2017-03-17 07:24 - 2014-09-18 22:25 - 12678408 _____ (Microsoft Corporation) C:\cc5a674df9e1e1956315bf5ea6\Windows6.0-6002-Shared-X86.EXE
2017-03-17 07:24 - 2014-09-18 19:44 - 0029189 _____ () C:\cc5a674df9e1e1956315bf5ea6\Windows6.0-KB947821-v35-x86.cab
2017-03-17 07:24 - 2014-09-18 19:45 - 0000447 _____ () C:\cc5a674df9e1e1956315bf5ea6\Windows6.0-KB947821-v35-x86.xml
2017-03-17 07:24 - 2014-09-18 19:45 - 0000461 _____ () C:\cc5a674df9e1e1956315bf5ea6\Windows6.0-KB947821-v35-x86-pkgProperties.txt
2017-03-17 07:24 - 2014-09-18 23:43 - 3094792 _____ (Microsoft Corporation) C:\cc5a674df9e1e1956315bf5ea6\Windows6.0-servicing-x86-19Dec13.exe
2017-03-17 07:24 - 2014-09-18 23:38 - 4869384 _____ (Microsoft Corporation) C:\cc5a674df9e1e1956315bf5ea6\Windows6.0-servicing-x86-20Sep13.exe
2017-03-17 07:24 - 2014-09-18 23:53 - 1382664 _____ (Microsoft Corporation) C:\cc5a674df9e1e1956315bf5ea6\Windows6.0-servicing-x86-26Mar14.exe
2017-03-17 07:24 - 2014-09-18 23:55 - 2689296 _____ (Microsoft Corporation) C:\cc5a674df9e1e1956315bf5ea6\Windows6.0-servicing-x86-5Sep14.exe
2017-03-17 07:24 - 2014-09-18 23:32 - 3962120 _____ (Microsoft Corporation) C:\cc5a674df9e1e1956315bf5ea6\windows6.0-servicing-x86-7jul13.exe
2017-03-17 07:24 - 2014-09-18 23:58 - 0181520 _____ (Microsoft Corporation) C:\cc5a674df9e1e1956315bf5ea6\Windows6.0-SSCab-X86.EXE
2017-03-17 07:24 - 2014-09-19 04:02 - 0172682 _____ () C:\cc5a674df9e1e1956315bf5ea6\WSUSSCAN.cab

====== End of Folder: ======


=========== EmptyTemp: ==========

BITS transfer queue => 0 B
DOMStoree, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 18475990 B
Java, Flash, Steam htmlcache => 592 B
Windows/system/drivers => 69902369 B
Edge => 0 B
Chrome => 7090758 B
Firefox => 35947213 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 33125 B
Public => 0 B
ProgramData => 0 B
systemprofile => 426843 B
LocalService => 132244 B
NetworkService => 168764 B
Owner => 947028 B
admin anticryptolock => 209099159 B

RecycleBin => 273309911 B
EmptyTemp: => 587 MB temporary data Removed.

================================
The system needed a reboot.    ==== End of Fixlog 02:10:17 ====

 

 

Behavior: Haven't ventured into "Owner" yet. Apparently smart defrag (IObit/) is still present. I need to uninstall, yes?  Start up has some lag.  Will add more once Uncle Sam is placated ;)

 

Hey, thanks so much for going through this with me.

 

Will post more when I can.

 

~S~


Edited by ShadowMyst, 15 April 2017 - 01:35 AM.


#8 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,179 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:01:39 AM

Posted 15 April 2017 - 01:52 PM

Thank you for the information and reports. When you are able, please do this.

===================================================

Farbar's Recovery Scan Tool Search

--------------------
  • Launch FRST
  • Copy/paste the following in the Search Field
*iobit*;*Strongvault*
  • Click Search File(s) button
  • When completed click OK and a Search.txt document will open on your desktop
  • Copy and paste the contents of that document your reply
  • Copy/paste the following in the Search Field
*iobit*;*Strongvault*
  • Click Search Registry button
  • When completed click OK and a Searchreg.txt document will open on your desktop
  • Copy and paste the contents of that document your reply
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • Search.txt
  • Searchreg.txt

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#9 ShadowMyst

ShadowMyst
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:New England
  • Local time:04:39 AM

Posted 16 April 2017 - 11:37 PM

Hokay. Ole Sammy took placation pretty well!

 

Per your request

 

1.Search.txt: Farbar Recovery Scan Tool (x86) Version: 15-03-2017
Ran by admin anticryptolock (17-04-2017 00:16:52)
Running from C:\Users\admin anticryptolock
Boot Mode: Safe Mode (with Networking)

================== Search Files: "*iobit*;*Strongvault*" =============

C:\Windows\System32\IObitSmartDefragExtension.dll
[2016-05-27 00:10][2016-03-25 14:33] 0111392 ____A (IObit) B911C3510EE818D47018DCF9F2BF7D68 [File is digitally signed]

C:\Windows\System32\SMI\Store\Machine\schema.dat.iobit
[2012-07-25 04:07][2016-08-23 11:41] 6643712 ____A () 5D9676EB2248E1FB31E37964F1BF0C45 [File not signed]

C:\Windows\System32\config\components.iobit
[2013-06-09 10:38][2017-04-07 16:58] 50229248 ____A ()  [File not signed]

C:\Windows\System32\config\default.iobit
[2013-06-09 10:38][2017-04-07 16:58] 2220032 ____A () F0890E901D815A569B18E6E695C9EC4A [File not signed]

C:\Windows\System32\config\sam.iobit
[2013-06-09 10:38][2017-04-07 16:58] 0094208 ____A () AFB5F4633DF0A1D32EAED929C740D3B5 [File not signed]

C:\Windows\System32\config\security.iobit
[2013-06-09 10:38][2017-04-07 16:58] 0024576 ____A () CF197C763E526F13C238DFE519204DAD [File not signed]

C:\Windows\System32\config\software.iobit
[2013-06-09 10:38][2017-04-07 16:58] 64684032 ____A ()  [File not signed]

C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.iobit
[2013-06-09 10:38][2017-04-07 16:58] 0172032 ____A () E11FABFFBDF3FF25CB400E841FE76B13 [File not signed]

C:\Windows\ServiceProfiles\LocalService\ntuser.dat.iobit
[2013-06-09 10:38][2017-04-07 16:58] 0159744 ____A () ABB850C35FC921895F977056E3A3EF7B [File not signed]

C:\Windows\Prefetch\IOBITUNINSTALER.EXE-D03E1084.pf
[2017-04-09 13:56][2017-04-09 14:06] 0373118 ____A () B812448A2EAE66D5F83BBC7526FE4070 [File not signed]

C:\Users\Owner\Favorites\Download IObit Freeware.url
[2012-11-08 07:57][2017-03-07 16:05] 0000103 ____A () 1CC05D805C3A8DF2CFAE8C93767B051C [File not signed]

C:\Users\Owner\Favorites\IObit Malware Fighter Help Center.url
[2013-07-27 19:36][2017-03-07 16:05] 0000837 ____A () 238BBB3207D6E40DCC1B0DDB3FEE7478 [File not signed]

C:\Users\Owner\Documents\Iobit Advanced System Care Update History July 25 2012.txt
[2012-07-25 03:59][2012-07-25 03:59] 0002071 ____A () AFE534A27F5F07A0581F0F7C7659C763 [File not signed]

C:\Users\Owner\Documents\IOBIT and advanced system care notes and FAQ.rtf
[2013-07-27 21:10][2013-07-27 21:24] 5280818 ____A () 137C811A58020B890E6A931FEBD167C0 [File not signed]

C:\Users\Owner\Documents\Iobit error report Dec 16 2011.txt
[2011-12-16 20:19][2011-12-16 20:19] 0000327 ____A () CA5560481188CA26DDB6165D2837A41F [File not signed]

C:\Users\Owner\Documents\strongvault still there after running 2 avast scans and adwcleaner 12 29 2012.jpg
[2012-12-29 22:25][2012-12-29 22:25] 0528481 ____A () 86013CC013669585091C2B8AB2B31D30 [File not signed]

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\u4l6dqze.default-1355119460502\extensions\ascsurfingprotectionnew@iobit.com.xpi
[2017-02-18 12:26][2016-10-18 11:27] 0153926 ____A () 7DBA155B1ED45AE45EA2CD80FF6E4601 [File not signed]

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\mdquwntd.default-1475852303466\extensions\ascsurfingprotectionnew@iobit.com.xpi
[2017-03-07 16:14][2016-10-18 11:27] 0153926 ____A () 7DBA155B1ED45AE45EA2CD80FF6E4601 [File not signed]

C:\Users\Owner\AppData\Local\Microsoft\Windows\UsrClass.dat.iobit
[2013-06-09 10:38][2017-04-07 16:58] 9003008 ____A () 5212D4919EB0D9183C052F3DE10619B6 [File not signed]

C:\Users\admin anticryptolock\Documents\FRST program and rpts\per Gary of BleepComp, problems when trying to remove Iobit.txt
[2017-04-15 00:38][2017-04-15 01:45] 0002824 ____A () D9208BB5E93BD42B3ACBAD7D84EF4286 [File not signed]

C:\Users\admin anticryptolock\AppData\Roaming\Microsoft\Windows\Recent\per Gary of BleepComp, problems when trying to remove Iobit.lnk
[2017-04-15 02:24][2017-04-15 02:24] 0000780 ____A () C54B7C9F32A1655C4BE764F91A71082E [File not signed]

C:\ProgramData\IObit\iobitpromotion.ini
[2015-12-17 15:35][2017-02-18 12:25] 0000154 ____A () 2A0BA083592DEE6497DCAF1A601A2837 [File not signed]

C:\Program Files\My Lockbox\files to be saved\Documents\6 Apr 12 recent docs from start button.. as iobit will clear them.jpg
[2012-08-09 04:28][2012-04-06 13:43] 0073770 ____A () 4334388A9ED5800F3416C166CDCAAA39 [File not signed]

C:\Program Files\My Lockbox\files to be saved\Documents\Iobit Advanced System Care Update History July 25 2012.txt
[2012-08-09 04:29][2012-07-25 03:59] 0002071 ____A () AFE534A27F5F07A0581F0F7C7659C763 [File not signed]

C:\Program Files\My Lockbox\files to be saved\Documents\Iobit error report Dec 16 2011.txt
[2012-08-09 04:29][2011-12-16 20:19] 0000327 ____A () CA5560481188CA26DDB6165D2837A41F [File not signed]

C:\Old Firefox Data\{F0B1CEAC-7C0D-407c-B25E-623D7CBECCCB}\iobit.lock
[2012-12-10 02:04][2012-07-25 04:13] 0000001 ____A () 7215EE9C7D9DC229D2921A40E899EC5F [File not signed]

C:\Old Firefox Data\extensions\iobit@mybrowserbar.com
[2012-12-10 02:04][2012-12-05 08:46] 0000034 ____A () 624463A1DBA77C1D1A89C2FC32D48255 [File not signed]

C:\GREAT44_SHARED\New Folder\Pictures\Jan 1 2013 strongvault installation complete.jpg
[2013-01-01 14:11][2013-01-01 14:11] 0561289 ____A () BD69E1418DFEE1208953D76A9B6328A0 [File not signed]

C:\GREAT44_SHARED\New Folder\Pictures\computer screen shots\after 2 AdwCleaner scans malware and AVast strongvault still there 12 29 2012.jpg
[2012-12-29 23:21][2012-12-29 23:21] 0533254 ____A () 38244DFB56F7506C0B944B0E79764719 [File not signed]

C:\Boot\BCD.iobit
[2013-06-09 10:38][2017-04-03 14:29] 0032768 ____A () 6B85BF115BE949F9BFCB40C642CD65B6 [File not signed]

C:\AdwCleaner\quarantine\files\fiufazuytmkiqlnzosmxcvkadinrnczc\IObit Malware Fighter.exe.dat
[2017-04-08 08:29][2013-02-13 19:01] 0000687 ____A () 7AE1FF9FC9C223E49D73E1E78E8BDD20 [File not signed]

====== End of Search ======

 

 

2 of 2: searchreg:Farbar Recovery Scan Tool (x86) Version: 15-03-2017
Ran by admin anticryptolock (17-04-2017 00:28:18)
Running from C:\Users\admin anticryptolock
Boot Mode: Safe Mode (with Networking)

================== Search Registry: "iobit;Strongvault" ===========


===================== Search result for "iobit" ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\ADSRemoval]
"UninstallString"="C:\Program Files\IObit\IObit Malware Fighter\adsremoval\unins000.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\ADSRemoval]
"InstallLocation"="C:\Program Files\IObit\IObit Malware Fighter\adsremoval"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\IObit Malware Fighter]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\//\//\IObit Cloud Anti-Malwre]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AdblockPlus.AdblockPlus]
""="IObit Ads Removal"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AdblockPlus.AdblockPlus.1]
""="IObit Ads Removal"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0BB81440-5F42-4480-A5F7-770A6F439FC8}\InprocServer32]
""="C:\Program Files\IObit\IObit Malware Fighter\IMFShellExt.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{189F1E63-33A7-404B-B2F6-8C76A452CC54}\InprocServer32]
""="C:\Windows\System32\IObitSmartDefragExtension.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2803063F-4B8D-4dc6-8874-D1802487FE2D}\InprocServer32]
""="C:\Program Files\IObit\Advanced SystemCare\ASCExtMenu.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8DE189EC-C9C8-4D31-9F18-E0B7407019A9}]
""="IObit Uninstaller"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8DE189EC-C9C8-4D31-9F18-E0B7407019A9}\DefaultIcon]
""="C:\Program Files\IObit\IObit Uninstaller\IObitUninstaler.exe,0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8DE189EC-C9C8-4D31-9F18-E0B7407019A9}\Shell\Open\command]
""=""C:\Program Files\IObit\IObit Uninstaller\Uninstaler_SkipUac.exe" control_statistics"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FFCB3198-32F3-4E8B-9539-4324694ED664}]
""="IObit Ads Removal"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FFCB3198-32F3-4E8B-9539-4324694ED664}\InprocServer32]
""="C:\Program Files\IObit\Advanced SystemCare\Surfing Protection\Adblock\Adblock.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\IObit Malware Fighter]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\IObit Malware Fighter]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\C059F0AE629D66346AC0E9B717BDF12F]
"ProductName"="IObit Apps Toolbar v7.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\C059F0AE629D66346AC0E9B717BDF12F\SourceList]
"PackageName"="iobitappsToolbar.msi"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\E5D7A28B1734BBF4793EA1C766649A33]
"ProductName"="IObit Toolbar v6.6"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\E5D7A28B1734BBF4793EA1C766649A33\SourceList]
"PackageName"="iobitToolbar.msi"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\lnkfile\shellex\ContextMenuHandlers\IObit Malware Fighter]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0B80B6D2-246B-4A6B-AEA1-66F1DF0F4211}\1.0]
""="IObitSmartDefragExtensionLib"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0B80B6D2-246B-4A6B-AEA1-66F1DF0F4211}\1.0\0\win32]
""="C:\Windows\system32\IObitSmartDefragExtension.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{60AD0991-ECD4-49DC-B170-8B7E7C60F51B}\1.0\0\win32]
""="C:\Program Files\IObit\Advanced SystemCare\ASCExtMenu.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{60AD0991-ECD4-49DC-B170-8B7E7C60F51B}\1.0\HELPDIR]
""="C:\Program Files\IObit\Advanced SystemCare"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{7CD37F36-0BEF-11DC-8314-0800200C9A67}\1.0\0\win32]
""="C:\Program Files\IObit\Advanced SystemCare\Surfing Protection\Adblock\Adblock.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{7CD37F36-0BEF-11DC-8314-0800200C9A67}\1.0\HELPDIR]
""="C:\Program Files\IObit\Advanced SystemCare\Surfing Protection\Adblock"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{ACB9DC96-D7BB-430F-AE6B-97F0DFDEAFCC}\1.0\0\win32]
""="C:\Program Files\IObit\IObit Malware Fighter\IMFShellExt.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{ACB9DC96-D7BB-430F-AE6B-97F0DFDEAFCC}\1.0\HELPDIR]
""="C:\Program Files\IObit\IObit Malware Fighter"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F03CE6C6-4F7F-4E36-92EF-DE5ACFA9E429}\1.0\0\win32]
""="C:\Program Files\IObit\IObit Malware Fighter\adsremoval\IE\Adblock.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F03CE6C6-4F7F-4E36-92EF-DE5ACFA9E429}\1.0\HELPDIR]
""="C:\Program Files\IObit\IObit Malware Fighter\adsremoval\IE"

[HKEY_LOCAL_MACHINE\SOFTWARE\IObit]

[HKEY_LOCAL_MACHINE\SOFTWARE\IObit]
"serverURL"="http://iobit.mybrowserbar.com/"

[HKEY_LOCAL_MACHINE\SOFTWARE\IObit]
"partnerName"="IObit"

[HKEY_LOCAL_MACHINE\SOFTWARE\IObit]
"partnerNameSafe"="iobit"

[HKEY_LOCAL_MACHINE\SOFTWARE\IObit]
"ffext_path"="C:\Program Files\IObit Toolbar\FF\"

[HKEY_LOCAL_MACHINE\SOFTWARE\IObit]
"installDir"="C:\Program Files\IObit Toolbar\"

[HKEY_LOCAL_MACHINE\SOFTWARE\IObit\Advanced SystemCare]
"apppath"="C:\Program Files\IObit\Advanced SystemCare\"

[HKEY_LOCAL_MACHINE\SOFTWARE\IObit\Advanced SystemCare]
"installpath"="C:\Program Files\IObit\Surfing Protection"

[HKEY_LOCAL_MACHINE\SOFTWARE\IObit\Advanced SystemCare 6]
"installpath"="C:\Program Files\IObit\Advanced SystemCare 6"

[HKEY_LOCAL_MACHINE\SOFTWARE\IObit\Advanced SystemCare 7]
"installpath"="C:\Program Files\IObit\Surfing Protection"

[HKEY_LOCAL_MACHINE\SOFTWARE\IObit\Advanced SystemCare 7]
"apppath"="C:\Program Files\IObit\Advanced SystemCare 7\"

[HKEY_LOCAL_MACHINE\SOFTWARE\IObit\Advanced SystemCare 8]
"apppath"="C:\Program Files\IObit\Advanced SystemCare 8\"

[HKEY_LOCAL_MACHINE\SOFTWARE\IObit\Advanced SystemCare 8]
"installpath"="C:\Program Files\IObit\Surfing Protection"

[HKEY_LOCAL_MACHINE\SOFTWARE\IObit\Advanced SystemCare Ultimate]
"ASCV7"="C:\Program Files\IObit\Advanced SystemCare 7\"

[HKEY_LOCAL_MACHINE\SOFTWARE\IObit\Advanced SystemCare Ultimate]
"ascuv7uninstallpath"="C:\Program Files\IObit\Advanced SystemCare Ultimate 7\unins000.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\IObit\IObit Malware Fighter]

[HKEY_LOCAL_MACHINE\SOFTWARE\IObit\LiveUpdate]
"AppPath"="C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\IObit\LiveUpdate]
"config"="C:\ProgramData\IObit\IObitLiveUpdate\update.ept"

[HKEY_LOCAL_MACHINE\SOFTWARE\IObit\RealTimeProtector]
"InstallLocation"="C:\Program Files\IObit\Advanced SystemCare\"

[HKEY_LOCAL_MACHINE\SOFTWARE\IObit\RegistryDefragBoot]
"LogPath"="\??\C:\Program Files\IObit\Advanced SystemCare 7\BootTimeLog\"

[HKEY_LOCAL_MACHINE\SOFTWARE\IObit\Uninstaller]
"UninstallerFree"="C:\Program Files\IObit\IObit Uninstaller\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_1_for_KB2964358~31bf3856ad364e35~x86~~9.1.1.0]
"InstallLocation"="\\?\C:\Program Files\IObit\Advanced SystemCare 7\KB2964358.cab_Temp\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_1_for_KB3065979~31bf3856ad364e35~x86~~6.0.1.0]
"InstallLocation"="\\?\C:\Program Files\IObit\Advanced SystemCare 8\KB3065979.cab_Temp\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_1_for_KB3118401~31bf3856ad364e35~x86~~6.0.1.1]
"InstallLocation"="\\?\C:\Program Files\IObit\Advanced SystemCare\KB3118401.cab_Temp\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_for_KB2964358_RTM~31bf3856ad364e35~x86~~9.1.1.0]
"InstallLocation"="\\?\C:\Program Files\IObit\Advanced SystemCare 7\KB2964358.cab_Temp\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_for_KB2964358~31bf3856ad364e35~x86~~9.1.1.0]
"InstallLocation"="\\?\C:\Program Files\IObit\Advanced SystemCare 7\KB2964358.cab_Temp\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_for_KB3065979_client_2~31bf3856ad364e35~x86~~6.0.1.0]
"InstallLocation"="\\?\C:\Program Files\IObit\Advanced SystemCare 8\KB3065979.cab_Temp\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_for_KB3065979_client~31bf3856ad364e35~x86~~6.0.1.0]
"InstallLocation"="\\?\C:\Program Files\IObit\Advanced SystemCare 8\KB3065979.cab_Temp\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_for_KB3065979~31bf3856ad364e35~x86~~6.0.1.0]
"InstallLocation"="\\?\C:\Program Files\IObit\Advanced SystemCare 8\KB3065979.cab_Temp\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_for_KB3118401_client_2~31bf3856ad364e35~x86~~6.0.1.1]
"InstallLocation"="\\?\C:\Program Files\IObit\Advanced SystemCare\KB3118401.cab_Temp\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_for_KB3118401_client~31bf3856ad364e35~x86~~6.0.1.1]
"InstallLocation"="\\?\C:\Program Files\IObit\Advanced SystemCare\KB3118401.cab_Temp\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_for_KB3118401~31bf3856ad364e35~x86~~6.0.1.1]
"InstallLocation"="\\?\C:\Program Files\IObit\Advanced SystemCare\KB3118401.cab_Temp\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{020FA22C-3547-4244-9C64-C11CB32D9C44}]
"Path"="C:\Program Files\IObit\Smart Defrag 2\drivers\wnet_x64\SmartDefragBootTime.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{0521AE79-9B22-4C30-819D-0701061ECA24}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\SendBugReport.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{078F4E71-DA56-4195-B2E5-A87503A05B51}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 5\SecurityHole_Backup\KB2636927.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{086D4DA4-BA8F-49C9-B508-0083D6ACDBEF}]
"Path"="C:\Program Files\IObit\IObit Malware Fighter\UninstallPromote.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{0A63117E-7302-4D99-B85C-507669F66E11}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\Report.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{0AB65B47-2FE6-4AA1-9533-D786CA99552D}]
"Path"="C:\Program Files\IObit\Smart Defrag 2\drivers\wxp_x64\SmartDefragBootTime.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{0B385D8E-F37C-430F-B8AB-357A02FD7994}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\ASCService.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{107A0070-2598-4B13-AFD2-E380338B957A}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\ErrorReport.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{13B1F917-645B-423E-9FD9-6C8AC21EFC68}]
"Path"="C:\Program Files\IObit\Driver Booster\DrvInstall\DrvInstall.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{14F2C49D-B138-4EB1-8A21-D452F4FC7E6E}]
"Path"="C:\Program Files\IObit\IObit Malware Fighter\BlueBirdInit.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{183059F9-B0D0-4D8A-9DFA-A1A818B54301}]
"Path"="C:\Program Files\IObit\Smart Defrag 2\drivers\win8_x64\SmartDefragBootTime.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{1B3674B1-84C1-42E0-9627-B99453F295F8}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\drivers\wlh_x86\RegistryDefragBootTime.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{1C40FA7B-C9B6-496B-9D91-D851D9A83E11}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\Monitor.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{1F07C09C-65D5-47AF-B48E-69A737E2E831}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\amc-remind.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{1F27D45E-CF18-429A-9B89-6EA2807BBC18}]
"Path"="C:\Program Files\IObit\IObit Malware Fighter\SendBugReport.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{209D3D30-E2A2-4C6E-80A0-673F4CC478AA}]
"Path"="C:\Program Files\IObit\Smart Defrag 2\drivers\win7_x86\SmartDefragBootTime.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{21883BA0-3B8D-486C-8DFD-08523407C246}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\drivers\wlh_amd64\RegistryDefragBootTime.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{2207A69B-6B77-4068-B5D4-8B2C0CBF865E}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\Nfeatures.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{245CC750-E872-445F-BF6F-AF8BB0925726}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\InternetBooster.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{267B474C-FB0E-4FB5-AD64-6C96CAAB59D9}]
"Path"="C:\Program Files\IObit\Smart Defrag 2\Freeware\ASC_FreeSoftwareDownloader.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{2864DD1B-935C-480E-AEE4-32429864B8FB}]
"Path"="C:\Program Files\IObit\Driver Booster\Scheduler.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{286806EE-EFF7-49E0-80E2-2D263805E9D9}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\drivers\win7_x86\RegistryDefragBootTime.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{28AFDDC2-3871-433E-B97E-6574FB1D7A85}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\Sur11_ShortcutFixer.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{2CF991D2-AB2C-458D-A1A0-F95E65DEC70A}]
"Path"="C:\Program Files\IObit\Driver Booster\DrvInstall\DpInstX64.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{305C68A7-841C-4361-B145-BDB3FD6CE8D6}]
"Path"="C:\Program Files\IObit\Smart Defrag 2\drivers\wxp_x86\SmartDefragBootTime.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{32AA54BF-D0E5-45C8-97D5-592DD075F792}]
"Path"="C:\Program Files\IObit\Smart Defrag 2\drivers\win7_x64\SmartDefragBootTime.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{34D9CB50-974B-4E01-8150-67249D61571F}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\drivers\wnet_x86\RegistryDefragBootTime.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{35955A05-7038-48FA-B934-8EEDB4A416E6}]
"Path"="C:\Program Files\IObit\Smart Defrag 2\drivers\wnet_x86\SmartDefragBootTime.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{3F760F3D-FC1B-4A16-A346-277E0413056E}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\ASCDownload.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{41BB69C5-1512-487B-8829-B5B1E09AE231}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\Register.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{42524A82-D0A1-47B1-9E94-493C7D2422B7}]
"Path"="C:\Program Files\IObit\Smart Defrag 2\AutoUpdate.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{44530D40-F018-4F03-BEAF-60D00FA68F4F}]
"Path"="C:\Program Files\IObit\Driver Booster\Promote.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{448D1FCC-6AB1-4065-A98D-B6F4B291C27A}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\ProTip.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{476A98E9-4450-4797-8457-4CDE563942B9}]
"Path"="C:\Program Files\IObit\Driver Booster\DriverBooster.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{534824A9-9BE7-44B8-AB46-7C7D05628BBF}]
"Path"="C:\Program Files\IObit\Smart Defrag 2\drivers\wlh_x86\SmartDefragBootTime.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{5409ABCE-5236-4B9C-A7E2-01285F0FF3C0}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\Sua12_ClonedFilesScanner.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{569F1FF6-C0BA-43D0-AAF7-7F5C009F044B}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\ASCInit.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{579605EA-7884-4AA7-A432-415469929121}]
"Path"="C:\Program Files\IObit\Driver Booster\DrvInstall\DpInstX32.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{5D8B7533-8D84-4FC1-9A27-6682A1CF78BD}]
"Path"="C:\Program Files\IObit\IObit Malware Fighter\IMF_ActionCenterDownloader.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{65508EC2-27B0-4FB9-B506-FFF6E8F0214A}]
"Path"="C:\Program Files\IObit\IObit Malware Fighter\IWsIMF.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{65646C1D-85FC-4F00-A59D-BC78A3C44685}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\RescueCenter.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{6C9D20CF-0EA9-4A58-9235-5BC929FD60B1}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\drivers\win7_amd64\RegistryDefragBootTime.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{727E1A24-EB26-4893-BAD6-FA04B5943BEB}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\drivers\wxp_amd64\RegistryDefragBootTime.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{72F60D25-8D06-44DF-BD07-D27FE47B52AF}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\ASCUpgrade.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{77E3B67C-6965-4888-9D67-0543D80295C9}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\Suc11_RegistryCleaner.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{78C0511C-F50B-45B4-839A-66B998C0B5CB}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\SecurityHole_Backup\KB915597.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{79E09A72-F891-4FFB-8D74-A9F941E5D91C}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\Wizard.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{7AE61FE3-5580-4A17-8442-1E1DD11639B7}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\Reminder.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{7C5C06A2-4A85-4ED3-9EDA-BFD872C83A42}]
"Path"="C:\Program Files\IObit\IObit Malware Fighter\unins000.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{7E2AF306-BE7A-4C70-B381-D684F754AC5B}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\AutoCare.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{8182D514-E413-4D50-A9F1-CA9A8023B074}]
"Path"="C:\Program Files\IObit\IObit Malware Fighter\Freeware\IMF_FreeSoftwareDownloader.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{87C456EB-EAF7-4D3B-BFF0-E0BED9977763}]
"Path"="C:\Program Files\IObit\Smart Defrag 2\ActionCenterDownloader.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{883008C2-DB5A-4591-B60D-30BD874E8EED}]
"Path"="C:\Program Files\IObit\Driver Booster\Deployer.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{8958F620-8584-4001-91BA-9DA9C068C001}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\UpgradeTip.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{8BE08235-79BE-4774-85C6-FC04155C2440}]
"Path"="C:\Program Files\IObit\Smart Defrag 2\unins000.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{8D046828-F10D-450F-889A-3D721D493445}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\unins000.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{8F224F34-C4F3-4CE1-AA0B-BD70033154D9}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\Sua11_DiskExplorer.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{952A9ACE-8D88-4788-8982-BBD58DB050E4}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\DiskScan.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{98CA1FDA-7072-4102-9DC1-E19C89869CAF}]
"Path"="C:\Program Files\IObit\Smart Defrag 2\Freeware\SD_FreeSoftwareDownloader.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{9EAC015D-F712-4825-8EE2-2DAAE7905D22}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\PerformUpdate.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{A03D70B0-5189-45AA-BE6E-E896C875D18C}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\DelayLoad.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{A316A072-BE31-4953-8889-5ADBE7F1FE67}]
"Path"="C:\Program Files\IObit\Smart Defrag 2\SmartDefrag.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{A71757D8-D971-4056-AD8B-B81985086CC2}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\Freeware\ASC_FreeSoftwareDownloader.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{A7F40756-B1B8-463C-B627-995F022054AB}]
"Path"="C:\Program Files\IObit\Smart Defrag 2\drivers\wlh_x64\SmartDefragBootTime.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{AA8C3320-A9E6-40C7-B2D2-4DEA16E2C311}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\Suo12_StartupManager.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{B3D01F97-E195-458A-87F9-C45E1AB2A241}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\Suo11_InternetBooster.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{B66494CD-4E40-4743-8E44-AF6E70738EA4}]
"Path"="C:\Program Files\IObit\Driver Booster\UpdateDB.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{BCCC5684-AF1E-479E-8F60-612B2DBF4ECA}]
"Path"="C:\Program Files\IObit\Driver Booster\unins000.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{BE176D14-CC2E-4190-875A-8714A9FD9721}]
"Path"="C:\Program Files\IObit\Smart Defrag 2\UninstallPromote.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{C6055D53-B858-49FC-B676-7C57CD89030B}]
"Path"="C:\Program Files\IObit\IObit Malware Fighter\IMF.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{C6A5867A-5BC8-4C83-8942-A31E14783133}]
"Path"="C:\Program Files\IObit\Smart Defrag 2\drivers\win8_x86\SmartDefragBootTime.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{CAF8FF43-5043-449E-B3D9-2B58FE49347C}]
"Path"="C:\Program Files\IObit\Smart Defrag 2\SDInit.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{CE21BBB5-34CD-4B39-8B77-FE9AE8DD9FDA}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\ProInstallTip.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{D24C09CE-C6AA-4708-8851-39EE3CC9F06A}]
"Path"="C:\Program Files\IObit\Driver Booster\AutoUpdate.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{D3F19A3F-27F7-4FDA-8732-19BED2973C25}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\TbAppCaller.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{DCADD14F-1F26-4E26-8A33-BB0F9EDFFDB6}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\Suc10_Uninstal.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{DCE3D6AE-8EA8-4DF0-8483-B09942E56018}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\AutoUpdate.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{DDAD7EF2-1982-4AE3-9DF6-F130EDE088B4}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\newyear.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{DE89804C-8A77-45C8-87C9-424976A52AA5}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\AutoSweep.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{E03C5CBC-A311-4565-839C-28536B3B7BE9}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\UninstallPromote.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{E0E3EDDE-1497-4C69-82E9-FFE835D1578C}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\christmas.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{E316FB34-DE6E-49D5-89E8-E58B88976BF3}]
"Path"="C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{E4B65AE1-5911-4424-BCDE-DC1E8BC9A053}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\ASCTooltips.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{E5C02470-160E-4739-9BCE-709FDF413D9E}]
"Path"="C:\Program Files\IObit Toolbar\WidgiHelper.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{E64F9DEA-4397-4643-ABBA-B5A9B8A144B7}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\QuickSettings.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{E65A5C4A-4D16-4335-8F60-F2548CED4550}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\ASCTray.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{E830E645-8952-4C40-A689-87AFE7953690}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\ASC.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{EA1166EB-4421-4FB5-8BE4-16F56C35269F}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 4\free-software-downloader.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{EB6D4B9B-67AE-4DAD-A200-A286EDE91FB1}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\Sur12_DiskDoctor.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{F2206154-EF80-4111-86EC-93F5694DA515}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\drivers\wxp_x86\RegistryDefragBootTime.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{F308B143-6DA7-465D-9383-07CC58B3CC99}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\ActionCenterDownloader.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{F488AC55-FAEC-4841-9C30-1FB71BB3D8D0}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\drivers\wnet_amd64\RegistryDefragBootTime.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{FB0B687D-E57F-4C5A-B760-A7A72D5C1EB8}]
"Path"="C:\Program Files\IObit\IObit Malware Fighter\TaskSchedule.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{FC15A5C0-80A3-4BC7-BB42-62EECC06441A}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\Suo10_SmartRAM.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{189F1E63-33A7-404B-B2F6-8C76A452CC54}"="IObitSmartDefrag Extension"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ADSRemoval_is1]
"Inno Setup: App Path"="C:\Program Files\IObit\IObit Malware Fighter\adsremoval"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ADSRemoval_is1]
"InstallLocation"="C:\Program Files\IObit\IObit Malware Fighter\adsremoval\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ADSRemoval_is1]
"UninstallString"=""C:\Program Files\IObit\IObit Malware Fighter\adsremoval\unins000.exe""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ADSRemoval_is1]
"QuietUninstallString"=""C:\Program Files\IObit\IObit Malware Fighter\adsremoval\unins000.exe" /SILENT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Driver Booster_is1]
"Publisher"="IObit"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Smart Defrag_is1]
"Inno Setup: App Path"="C:\Program Files\IObit\Smart Defrag"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Smart Defrag_is1]
"InstallLocation"="C:\Program Files\IObit\Smart Defrag\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Smart Defrag_is1]
"DisplayIcon"="C:\Program Files\IObit\Smart Defrag\SmartDefrag.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Smart Defrag_is1]
"UninstallString"=""C:\Program Files\IObit\Smart Defrag\unins000.exe""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Smart Defrag_is1]
"QuietUninstallString"=""C:\Program Files\IObit\Smart Defrag\unins000.exe" /SILENT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Smart Defrag_is1]
"Publisher"="IObit"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Smart Defrag_is1]
"URLInfoAbout"="http://www.iobit.com/"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Smart Defrag_is1]
"HelpLink"="http://www.iobit.com/"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Smart Defrag_is1]
"URLUpdateInfo"="http://www.iobit.com/"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EA0F950C-D926-4366-A60C-9E7B71DB1FF2}]
"DisplayName"="IObit Apps Toolbar v7.1"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LiveUpdateSvc]
"ImagePath"="C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe"

[HKEY_USERS\.DEFAULT\Software\AppDataLow\Software\IObit]

[HKEY_USERS\.DEFAULT\Software\IObit]

[HKEY_USERS\.DEFAULT\Software\IObit\Advanced SystemCare]
"OldPath"="C:\Program Files\IObit\Advanced SystemCare 8\unins000.exe"

[HKEY_USERS\.DEFAULT\Software\IObit\Advanced SystemCare 6]
"OldPath"="C:\Program Files\IObit\Advanced SystemCare 5\unins000.exe"

[HKEY_USERS\.DEFAULT\Software\IObit\Advanced SystemCare 8]
"OldPath"="C:\Program Files\IObit\Advanced SystemCare 7\unins000.exe"

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 9"=""C:\Program Files\IObit\Advanced SystemCare\ASCTray.exe" /Auto"

[HKEY_USERS\S-1-5-21-3222991852-3880959725-3339485959-1165\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\IObit Surfing Protection_is1]

[HKEY_USERS\S-1-5-21-3222991852-3880959725-3339485959-1165\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\IObit Malware Fighter]

[HKEY_USERS\S-1-5-21-3222991852-3880959725-3339485959-1165\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\IObit Uninstaller]

[HKEY_USERS\S-1-5-21-3222991852-3880959725-3339485959-1165\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Program Files\IObit\IObit Uninstaller\Uninstall_Mitor.exe"="Uninstall_Mitor"

[HKEY_USERS\S-1-5-21-3222991852-3880959725-3339485959-1165\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Program Files\IObit\IObit Uninstaller\IObitUninstaler.exe"="Uninstall Programs"

[HKEY_USERS\S-1-5-21-3222991852-3880959725-3339485959-1165\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Program Files\IObit\IObit Malware Fighter\AutoUpdate.exe"="IObit Malware Fighter Autoupdate"

[HKEY_USERS\S-1-5-21-3222991852-3880959725-3339485959-1165\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Program Files\IObit\IObit Uninstaller\unins000.exe"="Setup/Uninstall"

[HKEY_USERS\S-1-5-21-3222991852-3880959725-3339485959-1165\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Program Files\IObit\IObit Malware Fighter\unins000.exe"="Setup/Uninstall"


===================== Search result for "Strongvault" ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:
Users
Owner
AppData
Local
Strongvault Online Backup
AxInterop.LocalBackupLib.dll]
ClientApi.dll]
Common.dll]
Integration.Ace.dll]
Integration.Radialpoint.dll]
Integration.Scheduler.dll]
Integration.UploadAgent.dll]
Integration.ZipLib.dll]
Interop.ADODB.dll]
Interop.ADOX.dll]
Interop.LocalBackupLib.dll]
Interop.Shell32.dll]
Interop.VSBackupVista.dll]
Interop.VSS.dll]
Interop.VSS2003.dll]
Interop.XceedEncryptionLib.dll]
SMessaging.exe]
SOS.Contracts.BackupServer.dll]
SOS.Contracts.Infiniscale.dll]
SOS.Contracts.Shared.dll]
SOSLibrary.dll]
SOSLiveProtect.exe]
SStorage.exe]
VSBackupNet.dll]
Xceed.Compression.dll]
Xceed.Compression.Formats.dll]
XFileNet.dll]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\D03D33E5698D29D40B33F55418B99273]
"ProductName"="Strongvault Online Backup"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\D03D33E5698D29D40B33F55418B99273\SourceList]
"PackageName"="Setup_Strongvault.msi"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\D03D33E5698D29D40B33F55418B99273\SourceList]
"LastUsedSource"="n;1;C:\Program Files\Strongvault Online Backup\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\D03D33E5698D29D40B33F55418B99273\SourceList\Net]
"1"="C:\Program Files\Strongvault Online Backup\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000051B-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000051C-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000051D-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000051E-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000051F-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000520-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000521-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000523-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000524-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000525-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000526-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000527-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000528-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000529-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000052A-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000052B-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000052C-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000052E-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000052F-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000530-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000531-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000532-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000533-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000540-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000541-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000542-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000543-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000544-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000545-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000546-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000547-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000548-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000549-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000054A-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000054B-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000552-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000553-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000554-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000570-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000571-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000573-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000574-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000576-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000577-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000057A-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000057B-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000057C-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000057D-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000057E-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{2AC1B0DF-D478-3140-999B-BEB56A4AA112}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{43EA8D11-CE4A-355B-83DB-A414D5D3A431}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{49735749-147A-300B-8986-004FC837C083}\5.0.2.34]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\XFileNet.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{4CDEE1C3-5A1B-350E-A3F9-F9F7F7C95CAC}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADOX.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{63033C5B-3DD7-3B07-ADF8-15EEE68AA14F}\5.0.2.34]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\VSBackupNet.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{793FC64C-92D4-36C2-8D76-29ADE5ACC998}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADOX.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{7E632ADF-9D4A-374C-AD52-25A9213987EE}\5.0.2.34]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\VSBackupNet.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{7F564B7C-5B6C-3AB9-B8FD-109554AE454B}\5.0.2.34]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\ClientApi.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{898CF1A5-06A2-30B5-8088-F9E7A66A4143}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADOX.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{9080C45E-594C-3768-A294-C1B261ECD5F9}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADOX.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{9558E2B7-51E3-315A-A409-2F1E30A23EFA}\5.0.2.34]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\ClientApi.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{9B09BB39-AEDE-3F55-AAF4-804064565E97}\5.0.2.34]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\ClientApi.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{A56187C5-D690-4037-AE32-A00EDC376AC3}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{A700FB12-17FC-3877-A874-00C31AFED422}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADOX.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{A9BA0EB6-3DA2-3A7A-B296-7FF4F611FD80}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADOX.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{BFBCF6E9-EE8C-366E-8DD2-34AFB7637D06}\5.0.2.34]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\XFileNet.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{C0CAD8CE-F322-3633-865B-FE9CF09B81BA}\5.0.2.34]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\ClientApi.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{D3BDD942-66D3-3156-B238-DE8B9720F37F}\5.0.2.34]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\ClientApi.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{D95DA0A3-AB54-356D-9050-B986DBD6A11A}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADOX.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{DD4CB1CF-E6F7-3A03-A77E-ED44939DD4CF}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADOX.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{DFF05178-341C-396F-A898-50DDBC699024}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADOX.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{E221116A-32CE-36C4-990E-4E731DF815F5}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADOX.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{E8F7B742-5831-3A24-8C7F-30A77C99DA9B}\5.0.2.34]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\ClientApi.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{F757B661-E287-3E2F-AF82-74FD2DF87F46}\5.0.2.34]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\ClientApi.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{FFC6D718-C67D-34B7-A64F-5B2235F83C11}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5E33D30D-D896-4D92-B033-5F45819B2937}]
"HelpLink"="http://www.strongvaultfree.com"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5E33D30D-D896-4D92-B033-5F45819B2937}]
"Publisher"="Strongvault Online Backup"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5E33D30D-D896-4D92-B033-5F45819B2937}]
"URLInfoAbout"="http://www.strongvaultfree.com"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5E33D30D-D896-4D92-B033-5F45819B2937}]
"DisplayName"="Strongvault Online Backup"

====== End of Search ======

 

tryin' something....

e1iGkA.gif

 

woo woo woo woo! malware malware!  woo woo woo woo!

giphy.gif

 

;)  Lesseee if THAT works! ;)



#10 ShadowMyst

ShadowMyst
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:New England
  • Local time:04:39 AM

Posted 16 April 2017 - 11:45 PM

Hokay. Ole Sammy took placation pretty well!
 
Per your request
 
1.Search.txt: Farbar Recovery Scan Tool (x86) Version: 15-03-2017
Ran by admin anticryptolock (17-04-2017 00:16:52)
Running from C:\Users\admin anticryptolock
Boot Mode: Safe Mode (with Networking)

================== Search Files: "*iobit*;*Strongvault*" =============

C:\Windows\System32\IObitSmartDefragExtension.dll
[2016-05-27 00:10][2016-03-25 14:33] 0111392 ____A (IObit) B911C3510EE818D47018DCF9F2BF7D68 [File is digitally signed]

C:\Windows\System32\SMI\Store\Machine\schema.dat.iobit
[2012-07-25 04:07][2016-08-23 11:41] 6643712 ____A () 5D9676EB2248E1FB31E37964F1BF0C45 [File not signed]

C:\Windows\System32\config\components.iobit
[2013-06-09 10:38][2017-04-07 16:58] 50229248 ____A ()  [File not signed]

C:\Windows\System32\config\default.iobit
[2013-06-09 10:38][2017-04-07 16:58] 2220032 ____A () F0890E901D815A569B18E6E695C9EC4A [File not signed]

C:\Windows\System32\config\sam.iobit
[2013-06-09 10:38][2017-04-07 16:58] 0094208 ____A () AFB5F4633DF0A1D32EAED929C740D3B5 [File not signed]

C:\Windows\System32\config\security.iobit
[2013-06-09 10:38][2017-04-07 16:58] 0024576 ____A () CF197C763E526F13C238DFE519204DAD [File not signed]

C:\Windows\System32\config\software.iobit
[2013-06-09 10:38][2017-04-07 16:58] 64684032 ____A ()  [File not signed]

C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.iobit
[2013-06-09 10:38][2017-04-07 16:58] 0172032 ____A () E11FABFFBDF3FF25CB400E841FE76B13 [File not signed]

C:\Windows\ServiceProfiles\LocalService\ntuser.dat.iobit
[2013-06-09 10:38][2017-04-07 16:58] 0159744 ____A () ABB850C35FC921895F977056E3A3EF7B [File not signed]

C:\Windows\Prefetch\IOBITUNINSTALER.EXE-D03E1084.pf
[2017-04-09 13:56][2017-04-09 14:06] 0373118 ____A () B812448A2EAE66D5F83BBC7526FE4070 [File not signed]

C:\Users\Owner\Favorites\Download IObit Freeware.url
[2012-11-08 07:57][2017-03-07 16:05] 0000103 ____A () 1CC05D805C3A8DF2CFAE8C93767B051C [File not signed]

C:\Users\Owner\Favorites\IObit Malware Fighter Help Center.url
[2013-07-27 19:36][2017-03-07 16:05] 0000837 ____A () 238BBB3207D6E40DCC1B0DDB3FEE7478 [File not signed]

C:\Users\Owner\Documents\Iobit Advanced System Care Update History July 25 2012.txt
[2012-07-25 03:59][2012-07-25 03:59] 0002071 ____A () AFE534A27F5F07A0581F0F7C7659C763 [File not signed]

C:\Users\Owner\Documents\IOBIT and advanced system care notes and FAQ.rtf
[2013-07-27 21:10][2013-07-27 21:24] 5280818 ____A () 137C811A58020B890E6A931FEBD167C0 [File not signed]

C:\Users\Owner\Documents\Iobit error report Dec 16 2011.txt
[2011-12-16 20:19][2011-12-16 20:19] 0000327 ____A () CA5560481188CA26DDB6165D2837A41F [File not signed]

C:\Users\Owner\Documents\strongvault still there after running 2 avast scans and adwcleaner 12 29 2012.jpg
[2012-12-29 22:25][2012-12-29 22:25] 0528481 ____A () 86013CC013669585091C2B8AB2B31D30 [File not signed]

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\u4l6dqze.default-1355119460502\extensions\ascsurfingprotectionnew@iobit.com.xpi
[2017-02-18 12:26][2016-10-18 11:27] 0153926 ____A () 7DBA155B1ED45AE45EA2CD80FF6E4601 [File not signed]

C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\mdquwntd.default-1475852303466\extensions\ascsurfingprotectionnew@iobit.com.xpi
[2017-03-07 16:14][2016-10-18 11:27] 0153926 ____A () 7DBA155B1ED45AE45EA2CD80FF6E4601 [File not signed]

C:\Users\Owner\AppData\Local\Microsoft\Windows\UsrClass.dat.iobit
[2013-06-09 10:38][2017-04-07 16:58] 9003008 ____A () 5212D4919EB0D9183C052F3DE10619B6 [File not signed]

C:\Users\admin anticryptolock\Documents\FRST program and rpts\per Gary of BleepComp, problems when trying to remove Iobit.txt
[2017-04-15 00:38][2017-04-15 01:45] 0002824 ____A () D9208BB5E93BD42B3ACBAD7D84EF4286 [File not signed]

C:\Users\admin anticryptolock\AppData\Roaming\Microsoft\Windows\Recent\per Gary of BleepComp, problems when trying to remove Iobit.lnk
[2017-04-15 02:24][2017-04-15 02:24] 0000780 ____A () C54B7C9F32A1655C4BE764F91A71082E [File not signed]

C:\ProgramData\IObit\iobitpromotion.ini
[2015-12-17 15:35][2017-02-18 12:25] 0000154 ____A () 2A0BA083592DEE6497DCAF1A601A2837 [File not signed]

C:\Program Files\My Lockbox\files to be saved\Documents\6 Apr 12 recent docs from start button.. as iobit will clear them.jpg
[2012-08-09 04:28][2012-04-06 13:43] 0073770 ____A () 4334388A9ED5800F3416C166CDCAAA39 [File not signed]

C:\Program Files\My Lockbox\files to be saved\Documents\Iobit Advanced System Care Update History July 25 2012.txt
[2012-08-09 04:29][2012-07-25 03:59] 0002071 ____A () AFE534A27F5F07A0581F0F7C7659C763 [File not signed]

C:\Program Files\My Lockbox\files to be saved\Documents\Iobit error report Dec 16 2011.txt
[2012-08-09 04:29][2011-12-16 20:19] 0000327 ____A () CA5560481188CA26DDB6165D2837A41F [File not signed]

C:\Old Firefox Data\{F0B1CEAC-7C0D-407c-B25E-623D7CBECCCB}\iobit.lock
[2012-12-10 02:04][2012-07-25 04:13] 0000001 ____A () 7215EE9C7D9DC229D2921A40E899EC5F [File not signed]

C:\Old Firefox Data\extensions\iobit@mybrowserbar.com
[2012-12-10 02:04][2012-12-05 08:46] 0000034 ____A () 624463A1DBA77C1D1A89C2FC32D48255 [File not signed]

C:\GREAT44_SHARED\New Folder\Pictures\Jan 1 2013 strongvault installation complete.jpg
[2013-01-01 14:11][2013-01-01 14:11] 0561289 ____A () BD69E1418DFEE1208953D76A9B6328A0 [File not signed]

C:\GREAT44_SHARED\New Folder\Pictures\computer screen shots\after 2 AdwCleaner scans malware and AVast strongvault still there 12 29 2012.jpg
[2012-12-29 23:21][2012-12-29 23:21] 0533254 ____A () 38244DFB56F7506C0B944B0E79764719 [File not signed]

C:\Boot\BCD.iobit
[2013-06-09 10:38][2017-04-03 14:29] 0032768 ____A () 6B85BF115BE949F9BFCB40C642CD65B6 [File not signed]

C:\AdwCleaner\quarantine\files\fiufazuytmkiqlnzosmxcvkadinrnczc\IObit Malware Fighter.exe.dat
[2017-04-08 08:29][2013-02-13 19:01] 0000687 ____A () 7AE1FF9FC9C223E49D73E1E78E8BDD20 [File not signed]

====== End of Search ======
 
 
2 of 2: searchreg:Farbar Recovery Scan Tool (x86) Version: 15-03-2017
Ran by admin anticryptolock (17-04-2017 00:28:18)
Running from C:\Users\admin anticryptolock
Boot Mode: Safe Mode (with Networking)

================== Search Registry: "iobit;Strongvault" ===========


===================== Search result for "iobit" ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\ADSRemoval]
"UninstallString"="C:\Program Files\IObit\IObit Malware Fighter\adsremoval\unins000.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\ADSRemoval]
"InstallLocation"="C:\Program Files\IObit\IObit Malware Fighter\adsremoval"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\IObit Malware Fighter]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\//\//\IObit Cloud Anti-Malwre]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AdblockPlus.AdblockPlus]
""="IObit Ads Removal"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AdblockPlus.AdblockPlus.1]
""="IObit Ads Removal"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0BB81440-5F42-4480-A5F7-770A6F439FC8}\InprocServer32]
""="C:\Program Files\IObit\IObit Malware Fighter\IMFShellExt.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{189F1E63-33A7-404B-B2F6-8C76A452CC54}\InprocServer32]
""="C:\Windows\System32\IObitSmartDefragExtension.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2803063F-4B8D-4dc6-8874-D1802487FE2D}\InprocServer32]
""="C:\Program Files\IObit\Advanced SystemCare\ASCExtMenu.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8DE189EC-C9C8-4D31-9F18-E0B7407019A9}]
""="IObit Uninstaller"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8DE189EC-C9C8-4D31-9F18-E0B7407019A9}\DefaultIcon]
""="C:\Program Files\IObit\IObit Uninstaller\IObitUninstaler.exe,0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8DE189EC-C9C8-4D31-9F18-E0B7407019A9}\Shell\Open\command]
""=""C:\Program Files\IObit\IObit Uninstaller\Uninstaler_SkipUac.exe" control_statistics"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FFCB3198-32F3-4E8B-9539-4324694ED664}]
""="IObit Ads Removal"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FFCB3198-32F3-4E8B-9539-4324694ED664}\InprocServer32]
""="C:\Program Files\IObit\Advanced SystemCare\Surfing Protection\Adblock\Adblock.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\IObit Malware Fighter]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\IObit Malware Fighter]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\C059F0AE629D66346AC0E9B717BDF12F]
"ProductName"="IObit Apps Toolbar v7.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\C059F0AE629D66346AC0E9B717BDF12F\SourceList]
"PackageName"="iobitappsToolbar.msi"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\E5D7A28B1734BBF4793EA1C766649A33]
"ProductName"="IObit Toolbar v6.6"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\E5D7A28B1734BBF4793EA1C766649A33\SourceList]
"PackageName"="iobitToolbar.msi"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\lnkfile\shellex\ContextMenuHandlers\IObit Malware Fighter]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0B80B6D2-246B-4A6B-AEA1-66F1DF0F4211}\1.0]
""="IObitSmartDefragExtensionLib"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0B80B6D2-246B-4A6B-AEA1-66F1DF0F4211}\1.0\0\win32]
""="C:\Windows\system32\IObitSmartDefragExtension.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{60AD0991-ECD4-49DC-B170-8B7E7C60F51B}\1.0\0\win32]
""="C:\Program Files\IObit\Advanced SystemCare\ASCExtMenu.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{60AD0991-ECD4-49DC-B170-8B7E7C60F51B}\1.0\HELPDIR]
""="C:\Program Files\IObit\Advanced SystemCare"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{7CD37F36-0BEF-11DC-8314-0800200C9A67}\1.0\0\win32]
""="C:\Program Files\IObit\Advanced SystemCare\Surfing Protection\Adblock\Adblock.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{7CD37F36-0BEF-11DC-8314-0800200C9A67}\1.0\HELPDIR]
""="C:\Program Files\IObit\Advanced SystemCare\Surfing Protection\Adblock"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{ACB9DC96-D7BB-430F-AE6B-97F0DFDEAFCC}\1.0\0\win32]
""="C:\Program Files\IObit\IObit Malware Fighter\IMFShellExt.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{ACB9DC96-D7BB-430F-AE6B-97F0DFDEAFCC}\1.0\HELPDIR]
""="C:\Program Files\IObit\IObit Malware Fighter"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F03CE6C6-4F7F-4E36-92EF-DE5ACFA9E429}\1.0\0\win32]
""="C:\Program Files\IObit\IObit Malware Fighter\adsremoval\IE\Adblock.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F03CE6C6-4F7F-4E36-92EF-DE5ACFA9E429}\1.0\HELPDIR]
""="C:\Program Files\IObit\IObit Malware Fighter\adsremoval\IE"

[HKEY_LOCAL_MACHINE\SOFTWARE\IObit]

[HKEY_LOCAL_MACHINE\SOFTWARE\IObit]
"serverURL"="http://iobit.mybrowserbar.com/"

[HKEY_LOCAL_MACHINE\SOFTWARE\IObit]
"partnerName"="IObit"

[HKEY_LOCAL_MACHINE\SOFTWARE\IObit]
"partnerNameSafe"="iobit"

[HKEY_LOCAL_MACHINE\SOFTWARE\IObit]
"ffext_path"="C:\Program Files\IObit Toolbar\FF\"

[HKEY_LOCAL_MACHINE\SOFTWARE\IObit]
"installDir"="C:\Program Files\IObit Toolbar\"

[HKEY_LOCAL_MACHINE\SOFTWARE\IObit\Advanced SystemCare]
"apppath"="C:\Program Files\IObit\Advanced SystemCare\"

[HKEY_LOCAL_MACHINE\SOFTWARE\IObit\Advanced SystemCare]
"installpath"="C:\Program Files\IObit\Surfing Protection"

[HKEY_LOCAL_MACHINE\SOFTWARE\IObit\Advanced SystemCare 6]
"installpath"="C:\Program Files\IObit\Advanced SystemCare 6"

[HKEY_LOCAL_MACHINE\SOFTWARE\IObit\Advanced SystemCare 7]
"installpath"="C:\Program Files\IObit\Surfing Protection"

[HKEY_LOCAL_MACHINE\SOFTWARE\IObit\Advanced SystemCare 7]
"apppath"="C:\Program Files\IObit\Advanced SystemCare 7\"

[HKEY_LOCAL_MACHINE\SOFTWARE\IObit\Advanced SystemCare 8]
"apppath"="C:\Program Files\IObit\Advanced SystemCare 8\"

[HKEY_LOCAL_MACHINE\SOFTWARE\IObit\Advanced SystemCare 8]
"installpath"="C:\Program Files\IObit\Surfing Protection"

[HKEY_LOCAL_MACHINE\SOFTWARE\IObit\Advanced SystemCare Ultimate]
"ASCV7"="C:\Program Files\IObit\Advanced SystemCare 7\"

[HKEY_LOCAL_MACHINE\SOFTWARE\IObit\Advanced SystemCare Ultimate]
"ascuv7uninstallpath"="C:\Program Files\IObit\Advanced SystemCare Ultimate 7\unins000.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\IObit\IObit Malware Fighter]

[HKEY_LOCAL_MACHINE\SOFTWARE\IObit\LiveUpdate]
"AppPath"="C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\IObit\LiveUpdate]
"config"="C:\ProgramData\IObit\IObitLiveUpdate\update.ept"

[HKEY_LOCAL_MACHINE\SOFTWARE\IObit\RealTimeProtector]
"InstallLocation"="C:\Program Files\IObit\Advanced SystemCare\"

[HKEY_LOCAL_MACHINE\SOFTWARE\IObit\RegistryDefragBoot]
"LogPath"="\??\C:\Program Files\IObit\Advanced SystemCare 7\BootTimeLog\"

[HKEY_LOCAL_MACHINE\SOFTWARE\IObit\Uninstaller]
"UninstallerFree"="C:\Program Files\IObit\IObit Uninstaller\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_1_for_KB2964358~31bf3856ad364e35~x86~~9.1.1.0]
"InstallLocation"="\\?\C:\Program Files\IObit\Advanced SystemCare 7\KB2964358.cab_Temp\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_1_for_KB3065979~31bf3856ad364e35~x86~~6.0.1.0]
"InstallLocation"="\\?\C:\Program Files\IObit\Advanced SystemCare 8\KB3065979.cab_Temp\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_1_for_KB3118401~31bf3856ad364e35~x86~~6.0.1.1]
"InstallLocation"="\\?\C:\Program Files\IObit\Advanced SystemCare\KB3118401.cab_Temp\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_for_KB2964358_RTM~31bf3856ad364e35~x86~~9.1.1.0]
"InstallLocation"="\\?\C:\Program Files\IObit\Advanced SystemCare 7\KB2964358.cab_Temp\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_for_KB2964358~31bf3856ad364e35~x86~~9.1.1.0]
"InstallLocation"="\\?\C:\Program Files\IObit\Advanced SystemCare 7\KB2964358.cab_Temp\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_for_KB3065979_client_2~31bf3856ad364e35~x86~~6.0.1.0]
"InstallLocation"="\\?\C:\Program Files\IObit\Advanced SystemCare 8\KB3065979.cab_Temp\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_for_KB3065979_client~31bf3856ad364e35~x86~~6.0.1.0]
"InstallLocation"="\\?\C:\Program Files\IObit\Advanced SystemCare 8\KB3065979.cab_Temp\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_for_KB3065979~31bf3856ad364e35~x86~~6.0.1.0]
"InstallLocation"="\\?\C:\Program Files\IObit\Advanced SystemCare 8\KB3065979.cab_Temp\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_for_KB3118401_client_2~31bf3856ad364e35~x86~~6.0.1.1]
"InstallLocation"="\\?\C:\Program Files\IObit\Advanced SystemCare\KB3118401.cab_Temp\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_for_KB3118401_client~31bf3856ad364e35~x86~~6.0.1.1]
"InstallLocation"="\\?\C:\Program Files\IObit\Advanced SystemCare\KB3118401.cab_Temp\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_for_KB3118401~31bf3856ad364e35~x86~~6.0.1.1]
"InstallLocation"="\\?\C:\Program Files\IObit\Advanced SystemCare\KB3118401.cab_Temp\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{020FA22C-3547-4244-9C64-C11CB32D9C44}]
"Path"="C:\Program Files\IObit\Smart Defrag 2\drivers\wnet_x64\SmartDefragBootTime.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{0521AE79-9B22-4C30-819D-0701061ECA24}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\SendBugReport.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{078F4E71-DA56-4195-B2E5-A87503A05B51}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 5\SecurityHole_Backup\KB2636927.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{086D4DA4-BA8F-49C9-B508-0083D6ACDBEF}]
"Path"="C:\Program Files\IObit\IObit Malware Fighter\UninstallPromote.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{0A63117E-7302-4D99-B85C-507669F66E11}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\Report.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{0AB65B47-2FE6-4AA1-9533-D786CA99552D}]
"Path"="C:\Program Files\IObit\Smart Defrag 2\drivers\wxp_x64\SmartDefragBootTime.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{0B385D8E-F37C-430F-B8AB-357A02FD7994}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\ASCService.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{107A0070-2598-4B13-AFD2-E380338B957A}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\ErrorReport.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{13B1F917-645B-423E-9FD9-6C8AC21EFC68}]
"Path"="C:\Program Files\IObit\Driver Booster\DrvInstall\DrvInstall.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{14F2C49D-B138-4EB1-8A21-D452F4FC7E6E}]
"Path"="C:\Program Files\IObit\IObit Malware Fighter\BlueBirdInit.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{183059F9-B0D0-4D8A-9DFA-A1A818B54301}]
"Path"="C:\Program Files\IObit\Smart Defrag 2\drivers\win8_x64\SmartDefragBootTime.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{1B3674B1-84C1-42E0-9627-B99453F295F8}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\drivers\wlh_x86\RegistryDefragBootTime.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{1C40FA7B-C9B6-496B-9D91-D851D9A83E11}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\Monitor.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{1F07C09C-65D5-47AF-B48E-69A737E2E831}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\amc-remind.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{1F27D45E-CF18-429A-9B89-6EA2807BBC18}]
"Path"="C:\Program Files\IObit\IObit Malware Fighter\SendBugReport.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{209D3D30-E2A2-4C6E-80A0-673F4CC478AA}]
"Path"="C:\Program Files\IObit\Smart Defrag 2\drivers\win7_x86\SmartDefragBootTime.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{21883BA0-3B8D-486C-8DFD-08523407C246}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\drivers\wlh_amd64\RegistryDefragBootTime.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{2207A69B-6B77-4068-B5D4-8B2C0CBF865E}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\Nfeatures.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{245CC750-E872-445F-BF6F-AF8BB0925726}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\InternetBooster.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{267B474C-FB0E-4FB5-AD64-6C96CAAB59D9}]
"Path"="C:\Program Files\IObit\Smart Defrag 2\Freeware\ASC_FreeSoftwareDownloader.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{2864DD1B-935C-480E-AEE4-32429864B8FB}]
"Path"="C:\Program Files\IObit\Driver Booster\Scheduler.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{286806EE-EFF7-49E0-80E2-2D263805E9D9}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\drivers\win7_x86\RegistryDefragBootTime.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{28AFDDC2-3871-433E-B97E-6574FB1D7A85}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\Sur11_ShortcutFixer.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{2CF991D2-AB2C-458D-A1A0-F95E65DEC70A}]
"Path"="C:\Program Files\IObit\Driver Booster\DrvInstall\DpInstX64.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{305C68A7-841C-4361-B145-BDB3FD6CE8D6}]
"Path"="C:\Program Files\IObit\Smart Defrag 2\drivers\wxp_x86\SmartDefragBootTime.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{32AA54BF-D0E5-45C8-97D5-592DD075F792}]
"Path"="C:\Program Files\IObit\Smart Defrag 2\drivers\win7_x64\SmartDefragBootTime.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{34D9CB50-974B-4E01-8150-67249D61571F}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\drivers\wnet_x86\RegistryDefragBootTime.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{35955A05-7038-48FA-B934-8EEDB4A416E6}]
"Path"="C:\Program Files\IObit\Smart Defrag 2\drivers\wnet_x86\SmartDefragBootTime.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{3F760F3D-FC1B-4A16-A346-277E0413056E}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\ASCDownload.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{41BB69C5-1512-487B-8829-B5B1E09AE231}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\Register.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{42524A82-D0A1-47B1-9E94-493C7D2422B7}]
"Path"="C:\Program Files\IObit\Smart Defrag 2\AutoUpdate.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{44530D40-F018-4F03-BEAF-60D00FA68F4F}]
"Path"="C:\Program Files\IObit\Driver Booster\Promote.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{448D1FCC-6AB1-4065-A98D-B6F4B291C27A}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\ProTip.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{476A98E9-4450-4797-8457-4CDE563942B9}]
"Path"="C:\Program Files\IObit\Driver Booster\DriverBooster.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{534824A9-9BE7-44B8-AB46-7C7D05628BBF}]
"Path"="C:\Program Files\IObit\Smart Defrag 2\drivers\wlh_x86\SmartDefragBootTime.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{5409ABCE-5236-4B9C-A7E2-01285F0FF3C0}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\Sua12_ClonedFilesScanner.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{569F1FF6-C0BA-43D0-AAF7-7F5C009F044B}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\ASCInit.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{579605EA-7884-4AA7-A432-415469929121}]
"Path"="C:\Program Files\IObit\Driver Booster\DrvInstall\DpInstX32.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{5D8B7533-8D84-4FC1-9A27-6682A1CF78BD}]
"Path"="C:\Program Files\IObit\IObit Malware Fighter\IMF_ActionCenterDownloader.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{65508EC2-27B0-4FB9-B506-FFF6E8F0214A}]
"Path"="C:\Program Files\IObit\IObit Malware Fighter\IWsIMF.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{65646C1D-85FC-4F00-A59D-BC78A3C44685}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\RescueCenter.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{6C9D20CF-0EA9-4A58-9235-5BC929FD60B1}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\drivers\win7_amd64\RegistryDefragBootTime.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{727E1A24-EB26-4893-BAD6-FA04B5943BEB}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\drivers\wxp_amd64\RegistryDefragBootTime.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{72F60D25-8D06-44DF-BD07-D27FE47B52AF}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\ASCUpgrade.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{77E3B67C-6965-4888-9D67-0543D80295C9}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\Suc11_RegistryCleaner.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{78C0511C-F50B-45B4-839A-66B998C0B5CB}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\SecurityHole_Backup\KB915597.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{79E09A72-F891-4FFB-8D74-A9F941E5D91C}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\Wizard.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{7AE61FE3-5580-4A17-8442-1E1DD11639B7}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\Reminder.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{7C5C06A2-4A85-4ED3-9EDA-BFD872C83A42}]
"Path"="C:\Program Files\IObit\IObit Malware Fighter\unins000.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{7E2AF306-BE7A-4C70-B381-D684F754AC5B}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\AutoCare.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{8182D514-E413-4D50-A9F1-CA9A8023B074}]
"Path"="C:\Program Files\IObit\IObit Malware Fighter\Freeware\IMF_FreeSoftwareDownloader.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{87C456EB-EAF7-4D3B-BFF0-E0BED9977763}]
"Path"="C:\Program Files\IObit\Smart Defrag 2\ActionCenterDownloader.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{883008C2-DB5A-4591-B60D-30BD874E8EED}]
"Path"="C:\Program Files\IObit\Driver Booster\Deployer.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{8958F620-8584-4001-91BA-9DA9C068C001}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\UpgradeTip.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{8BE08235-79BE-4774-85C6-FC04155C2440}]
"Path"="C:\Program Files\IObit\Smart Defrag 2\unins000.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{8D046828-F10D-450F-889A-3D721D493445}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\unins000.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{8F224F34-C4F3-4CE1-AA0B-BD70033154D9}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\Sua11_DiskExplorer.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{952A9ACE-8D88-4788-8982-BBD58DB050E4}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\DiskScan.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{98CA1FDA-7072-4102-9DC1-E19C89869CAF}]
"Path"="C:\Program Files\IObit\Smart Defrag 2\Freeware\SD_FreeSoftwareDownloader.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{9EAC015D-F712-4825-8EE2-2DAAE7905D22}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\PerformUpdate.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{A03D70B0-5189-45AA-BE6E-E896C875D18C}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\DelayLoad.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{A316A072-BE31-4953-8889-5ADBE7F1FE67}]
"Path"="C:\Program Files\IObit\Smart Defrag 2\SmartDefrag.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{A71757D8-D971-4056-AD8B-B81985086CC2}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\Freeware\ASC_FreeSoftwareDownloader.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{A7F40756-B1B8-463C-B627-995F022054AB}]
"Path"="C:\Program Files\IObit\Smart Defrag 2\drivers\wlh_x64\SmartDefragBootTime.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{AA8C3320-A9E6-40C7-B2D2-4DEA16E2C311}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\Suo12_StartupManager.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{B3D01F97-E195-458A-87F9-C45E1AB2A241}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\Suo11_InternetBooster.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{B66494CD-4E40-4743-8E44-AF6E70738EA4}]
"Path"="C:\Program Files\IObit\Driver Booster\UpdateDB.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{BCCC5684-AF1E-479E-8F60-612B2DBF4ECA}]
"Path"="C:\Program Files\IObit\Driver Booster\unins000.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{BE176D14-CC2E-4190-875A-8714A9FD9721}]
"Path"="C:\Program Files\IObit\Smart Defrag 2\UninstallPromote.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{C6055D53-B858-49FC-B676-7C57CD89030B}]
"Path"="C:\Program Files\IObit\IObit Malware Fighter\IMF.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{C6A5867A-5BC8-4C83-8942-A31E14783133}]
"Path"="C:\Program Files\IObit\Smart Defrag 2\drivers\win8_x86\SmartDefragBootTime.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{CAF8FF43-5043-449E-B3D9-2B58FE49347C}]
"Path"="C:\Program Files\IObit\Smart Defrag 2\SDInit.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{CE21BBB5-34CD-4B39-8B77-FE9AE8DD9FDA}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\ProInstallTip.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{D24C09CE-C6AA-4708-8851-39EE3CC9F06A}]
"Path"="C:\Program Files\IObit\Driver Booster\AutoUpdate.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{D3F19A3F-27F7-4FDA-8732-19BED2973C25}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\TbAppCaller.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{DCADD14F-1F26-4E26-8A33-BB0F9EDFFDB6}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\Suc10_Uninstal.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{DCE3D6AE-8EA8-4DF0-8483-B09942E56018}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\AutoUpdate.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{DDAD7EF2-1982-4AE3-9DF6-F130EDE088B4}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\newyear.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{DE89804C-8A77-45C8-87C9-424976A52AA5}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\AutoSweep.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{E03C5CBC-A311-4565-839C-28536B3B7BE9}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\UninstallPromote.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{E0E3EDDE-1497-4C69-82E9-FFE835D1578C}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\christmas.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{E316FB34-DE6E-49D5-89E8-E58B88976BF3}]
"Path"="C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{E4B65AE1-5911-4424-BCDE-DC1E8BC9A053}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\ASCTooltips.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{E5C02470-160E-4739-9BCE-709FDF413D9E}]
"Path"="C:\Program Files\IObit Toolbar\WidgiHelper.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{E64F9DEA-4397-4643-ABBA-B5A9B8A144B7}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\QuickSettings.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{E65A5C4A-4D16-4335-8F60-F2548CED4550}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\ASCTray.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{E830E645-8952-4C40-A689-87AFE7953690}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\ASC.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{EA1166EB-4421-4FB5-8BE4-16F56C35269F}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 4\free-software-downloader.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{EB6D4B9B-67AE-4DAD-A200-A286EDE91FB1}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\Sur12_DiskDoctor.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{F2206154-EF80-4111-86EC-93F5694DA515}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\drivers\wxp_x86\RegistryDefragBootTime.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{F308B143-6DA7-465D-9383-07CC58B3CC99}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\ActionCenterDownloader.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{F488AC55-FAEC-4841-9C30-1FB71BB3D8D0}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\drivers\wnet_amd64\RegistryDefragBootTime.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{FB0B687D-E57F-4C5A-B760-A7A72D5C1EB8}]
"Path"="C:\Program Files\IObit\IObit Malware Fighter\TaskSchedule.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{FC15A5C0-80A3-4BC7-BB42-62EECC06441A}]
"Path"="C:\Program Files\IObit\Advanced SystemCare 6\Suo10_SmartRAM.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{189F1E63-33A7-404B-B2F6-8C76A452CC54}"="IObitSmartDefrag Extension"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ADSRemoval_is1]
"Inno Setup: App Path"="C:\Program Files\IObit\IObit Malware Fighter\adsremoval"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ADSRemoval_is1]
"InstallLocation"="C:\Program Files\IObit\IObit Malware Fighter\adsremoval\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ADSRemoval_is1]
"UninstallString"=""C:\Program Files\IObit\IObit Malware Fighter\adsremoval\unins000.exe""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ADSRemoval_is1]
"QuietUninstallString"=""C:\Program Files\IObit\IObit Malware Fighter\adsremoval\unins000.exe" /SILENT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Driver Booster_is1]
"Publisher"="IObit"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Smart Defrag_is1]
"Inno Setup: App Path"="C:\Program Files\IObit\Smart Defrag"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Smart Defrag_is1]
"InstallLocation"="C:\Program Files\IObit\Smart Defrag\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Smart Defrag_is1]
"DisplayIcon"="C:\Program Files\IObit\Smart Defrag\SmartDefrag.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Smart Defrag_is1]
"UninstallString"=""C:\Program Files\IObit\Smart Defrag\unins000.exe""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Smart Defrag_is1]
"QuietUninstallString"=""C:\Program Files\IObit\Smart Defrag\unins000.exe" /SILENT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Smart Defrag_is1]
"Publisher"="IObit"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Smart Defrag_is1]
"URLInfoAbout"="http://www.iobit.com/"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Smart Defrag_is1]
"HelpLink"="http://www.iobit.com/"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Smart Defrag_is1]
"URLUpdateInfo"="http://www.iobit.com/"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EA0F950C-D926-4366-A60C-9E7B71DB1FF2}]
"DisplayName"="IObit Apps Toolbar v7.1"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LiveUpdateSvc]
"ImagePath"="C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe"

[HKEY_USERS\.DEFAULT\Software\AppDataLow\Software\IObit]

[HKEY_USERS\.DEFAULT\Software\IObit]

[HKEY_USERS\.DEFAULT\Software\IObit\Advanced SystemCare]
"OldPath"="C:\Program Files\IObit\Advanced SystemCare 8\unins000.exe"

[HKEY_USERS\.DEFAULT\Software\IObit\Advanced SystemCare 6]
"OldPath"="C:\Program Files\IObit\Advanced SystemCare 5\unins000.exe"

[HKEY_USERS\.DEFAULT\Software\IObit\Advanced SystemCare 8]
"OldPath"="C:\Program Files\IObit\Advanced SystemCare 7\unins000.exe"

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 9"=""C:\Program Files\IObit\Advanced SystemCare\ASCTray.exe" /Auto"

[HKEY_USERS\S-1-5-21-3222991852-3880959725-3339485959-1165\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\IObit Surfing Protection_is1]

[HKEY_USERS\S-1-5-21-3222991852-3880959725-3339485959-1165\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\IObit Malware Fighter]

[HKEY_USERS\S-1-5-21-3222991852-3880959725-3339485959-1165\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\IObit Uninstaller]

[HKEY_USERS\S-1-5-21-3222991852-3880959725-3339485959-1165\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Program Files\IObit\IObit Uninstaller\Uninstall_Mitor.exe"="Uninstall_Mitor"

[HKEY_USERS\S-1-5-21-3222991852-3880959725-3339485959-1165\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Program Files\IObit\IObit Uninstaller\IObitUninstaler.exe"="Uninstall Programs"

[HKEY_USERS\S-1-5-21-3222991852-3880959725-3339485959-1165\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Program Files\IObit\IObit Malware Fighter\AutoUpdate.exe"="IObit Malware Fighter Autoupdate"

[HKEY_USERS\S-1-5-21-3222991852-3880959725-3339485959-1165\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Program Files\IObit\IObit Uninstaller\unins000.exe"="Setup/Uninstall"

[HKEY_USERS\S-1-5-21-3222991852-3880959725-3339485959-1165\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Program Files\IObit\IObit Malware Fighter\unins000.exe"="Setup/Uninstall"


===================== Search result for "Strongvault" ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:
Users
Owner
AppData
Local
Strongvault Online Backup
AxInterop.LocalBackupLib.dll]
ClientApi.dll]
Common.dll]
Integration.Ace.dll]
Integration.Radialpoint.dll]
Integration.Scheduler.dll]
Integration.UploadAgent.dll]
Integration.ZipLib.dll]
Interop.ADODB.dll]
Interop.ADOX.dll]
Interop.LocalBackupLib.dll]
Interop.Shell32.dll]
Interop.VSBackupVista.dll]
Interop.VSS.dll]
Interop.VSS2003.dll]
Interop.XceedEncryptionLib.dll]
SMessaging.exe]
SOS.Contracts.BackupServer.dll]
SOS.Contracts.Infiniscale.dll]
SOS.Contracts.Shared.dll]
SOSLibrary.dll]
SOSLiveProtect.exe]
SStorage.exe]
VSBackupNet.dll]
Xceed.Compression.dll]
Xceed.Compression.Formats.dll]
XFileNet.dll]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\D03D33E5698D29D40B33F55418B99273]
"ProductName"="Strongvault Online Backup"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\D03D33E5698D29D40B33F55418B99273\SourceList]
"PackageName"="Setup_Strongvault.msi"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\D03D33E5698D29D40B33F55418B99273\SourceList]
"LastUsedSource"="n;1;C:\Program Files\Strongvault Online Backup\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\D03D33E5698D29D40B33F55418B99273\SourceList\Net]
"1"="C:\Program Files\Strongvault Online Backup\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000051B-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000051C-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000051D-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000051E-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000051F-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000520-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000521-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000523-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000524-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000525-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000526-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000527-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000528-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000529-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000052A-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000052B-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000052C-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000052E-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000052F-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000530-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000531-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000532-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000533-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000540-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000541-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000542-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000543-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000544-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000545-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000546-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000547-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000548-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000549-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000054A-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000054B-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000552-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000553-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000554-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000570-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000571-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000573-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000574-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000576-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000577-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000057A-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000057B-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000057C-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000057D-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000057E-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{2AC1B0DF-D478-3140-999B-BEB56A4AA112}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{43EA8D11-CE4A-355B-83DB-A414D5D3A431}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{49735749-147A-300B-8986-004FC837C083}\5.0.2.34]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\XFileNet.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{4CDEE1C3-5A1B-350E-A3F9-F9F7F7C95CAC}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADOX.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{63033C5B-3DD7-3B07-ADF8-15EEE68AA14F}\5.0.2.34]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\VSBackupNet.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{793FC64C-92D4-36C2-8D76-29ADE5ACC998}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADOX.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{7E632ADF-9D4A-374C-AD52-25A9213987EE}\5.0.2.34]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\VSBackupNet.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{7F564B7C-5B6C-3AB9-B8FD-109554AE454B}\5.0.2.34]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\ClientApi.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{898CF1A5-06A2-30B5-8088-F9E7A66A4143}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADOX.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{9080C45E-594C-3768-A294-C1B261ECD5F9}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADOX.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{9558E2B7-51E3-315A-A409-2F1E30A23EFA}\5.0.2.34]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\ClientApi.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{9B09BB39-AEDE-3F55-AAF4-804064565E97}\5.0.2.34]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\ClientApi.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{A56187C5-D690-4037-AE32-A00EDC376AC3}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{A700FB12-17FC-3877-A874-00C31AFED422}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADOX.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{A9BA0EB6-3DA2-3A7A-B296-7FF4F611FD80}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADOX.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{BFBCF6E9-EE8C-366E-8DD2-34AFB7637D06}\5.0.2.34]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\XFileNet.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{C0CAD8CE-F322-3633-865B-FE9CF09B81BA}\5.0.2.34]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\ClientApi.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{D3BDD942-66D3-3156-B238-DE8B9720F37F}\5.0.2.34]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\ClientApi.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{D95DA0A3-AB54-356D-9050-B986DBD6A11A}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADOX.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{DD4CB1CF-E6F7-3A03-A77E-ED44939DD4CF}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADOX.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{DFF05178-341C-396F-A898-50DDBC699024}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADOX.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{E221116A-32CE-36C4-990E-4E731DF815F5}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADOX.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{E8F7B742-5831-3A24-8C7F-30A77C99DA9B}\5.0.2.34]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\ClientApi.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{F757B661-E287-3E2F-AF82-74FD2DF87F46}\5.0.2.34]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\ClientApi.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{FFC6D718-C67D-34B7-A64F-5B2235F83C11}\2.8.0.0]
"CodeBase"="file:///C:\Users\Owner\AppData\Local\Strongvault Online Backup\Interop.ADODB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5E33D30D-D896-4D92-B033-5F45819B2937}]
"HelpLink"="http://www.strongvaultfree.com"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5E33D30D-D896-4D92-B033-5F45819B2937}]
"Publisher"="Strongvault Online Backup"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5E33D30D-D896-4D92-B033-5F45819B2937}]
"URLInfoAbout"="http://www.strongvaultfree.com"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5E33D30D-D896-4D92-B033-5F45819B2937}]
"DisplayName"="Strongvault Online Backup"

====== End of Search ======
 
I wonder how many incarnations of Strongvault are in here?

Maybe it's disguised.  :?
 
 
woo woo woo woo! so many!  so many!  woo woo woo woo!
Wow! Strongvault! The program that gets in EVERYWHERE!  Nyaaaah!
 
 
Yikes!
 
~S.~

Edited by Oh My!, 24 April 2017 - 08:03 AM.


#11 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,179 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:01:39 AM

Posted 17 April 2017 - 10:44 AM

Thank you for the information. Let's try this first.

===================================================

Uninstalling Programs Using Revo Uninstaller Free

--------------------

I recommend uninstalling the below listed program(s) from your computer.

Revo Uninstaller is more thorough in deleting programs on your computer than using the Add/Remove option in Windows. Since it is a more powerful tool, please be sure to follow the instructions carefully.

Please note there is a chance when you look for this program to uninstall through Revo it might not be listed because of a previous uninstall. If that is the case simply stop and let me know.
  • Please download and install Revo Uninstaller Free
  • Double click the Revo Uninstaller icon
  • From the list of programs double click on the listed program(s), or anything similar, to remove it (if it exists)
IObit Apps Toolbar v7.1
IObit Malware Fighter 4
IObit Uninstaller
Strongvault Online Backup
  • If presented with the program uninstall option click Uninstall
  • If asked to reboot select Reboot later
  • Under Scanning Modes select Advanced then select Scan
  • On the Found leftover Registry items window check the items in bold only then click Delete. You may have to expand some folders by clicking the "+" mark.
  • When prompted click on Next then Yes
  • On the Found leftover files and folders window click on Select all, click Finish, then click Yes
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • Results?

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#12 ShadowMyst

ShadowMyst
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:New England
  • Local time:04:39 AM

Posted 17 April 2017 - 09:13 PM

found iobit apps toolbar v7.1  uninstalling.
got a dialog box with "windows installer" the feature you are trying to use is on a network resource that is unavailable.  click ok to try again or enter an alternate path to a folder containing the installation package 'iobitapps Toolbar.msi' in the box below.use source:
c:\users\owner\appdata\local\temp\{88D524B6-AF1A-4B3E-A80B-12AACB91EDEE}\
Aha! realized that I had NOT switched parameters, went to "advanced" search, and items WERE found!
Clearing out remainders.

have 16 icons with "local[j0005]-[p03, etc.] images, but....photo gallery loads.
could not find or get to source.


went for iobit toolbar v6.6 got dialog box -- windows installer -- the installation source for this product is not available. Verify that the source exists and that you can access it.

Note: I WAS able to click on "scan."  was able to uninstall IObit toolbar v6.6 -- yippee!
got rid of residue, then, refreshed Revo.

 

was unable to find the other two

 

However... followed the path from the FRST report that I'd given you in my previous post, did a "regedit", looked in C:\Users\Owner\AppData\Local\Strongvault Online Backup\AxInterop.LocalBackupLib.dll

??

 

Also, went into Revo\Options\Uninstaller\Exclude, and I was looking at a bunch of registry keys. Guess I need to take a second look at the user guide :/

 

googled to see if there were alternate "strongvault" names. Found some and entered same into the search parameters. I must have done something incorrectly, as Revo didn't see any.


Edited by ShadowMyst, 17 April 2017 - 10:02 PM.


#13 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,179 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:01:39 AM

Posted 17 April 2017 - 09:20 PM

Please do this.

===================================================

Farbar's Recovery Scan Tool - Run Fix in Normal or Safe Mode Using Attached File

--------------------
  • Please download and save it in the same location as FRST.exe (example, Desktop, USB device) <<< Important
  • Launch FRST and press the Fix button just once and wait, the program will automatically launch fixlist.txt.
  • The tool will create a log on the desktop called Fixlog.txt. Please attach the file in your reply.
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • Attached Fixlog file

Edited by Oh My!, 17 April 2017 - 10:01 PM.

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#14 ShadowMyst

ShadowMyst
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:New England
  • Local time:04:39 AM

Posted 18 April 2017 - 12:53 PM

Hi, Gary:

 

Did that thing. Got FRST dialog box that computer needs to restart -- "you...[won't] get any ntoification from the tool after restart."

So, here are the scan results. I'll then restart.

 

Fix result of Farbar Recovery Scan Tool (x86) Version: 15-03-2017
Ran by admin anticryptolock (18-04-2017 13:31:45) Run:2
Running from C:\Users\admin anticryptolock
Loaded Profiles: admin anticryptolock (Available Profiles: Owner & admin anticryptolock)
Boot Mode: Normal

==============================================

fixlist content:
*****************
CreateRestorePoint:
CloseProcesses:
C:\Windows\System32\IObitSmartDefragExtension.dll
C:\Windows\System32\SMI\Store\Machine\schema.dat.iobit
C:\Windows\System32\config\components.iobit
C:\Windows\System32\config\default.iobit
C:\Windows\System32\config\sam.iobit
C:\Windows\System32\config\security.iobit
C:\Windows\System32\config\software.iobit
C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.iobit
C:\Windows\ServiceProfiles\LocalService\ntuser.dat.iobit
C:\Windows\Prefetch\IOBITUNINSTALER.EXE-D03E1084.pf
C:\Users\Owner\Favorites\Download IObit Freeware.url
C:\Users\Owner\Favorites\IObit Malware Fighter Help Center.url
C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\u4l6dqze.default-1355119460502\extensions\ascsurfingprotectionnew@iobit.com.xpi
C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\mdquwntd.default-1475852303466\extensions\ascsurfingprotectionnew@iobit.com.xpi
C:\Users\Owner\AppData\Local\Microsoft\Windows\UsrClass.dat.iobit
C:\Users\admin anticryptolock\AppData\Roaming\Microsoft\Windows\Recent\per Gary of BleepComp, problems when trying to remove Iobit.lnk
C:\ProgramData\IObit\iobitpromotion.ini
C:\Old Firefox Data\{F0B1CEAC-7C0D-407c-B25E-623D7CBECCCB}\iobit.lock
C:\Old Firefox Data\extensions\iobit@mybrowserbar.com
C:\Boot\BCD.iobit
C:\AdwCleaner\quarantine\files\fiufazuytmkiqlnzosmxcvkadinrnczc\IObit Malware Fighter.exe.dat
C:\Program Files\IObit
C:\Program Files\Strongvault Online Backup
StartRegdit:
[HKEY_LOCAL_MACHINE\SOFTWARE\ADSRemoval]
"UninstallString"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\ADSRemoval]
"InstallLocation"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\IObit Malware Fighter]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\//\//\IObit Cloud Anti-Malwre]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AdblockPlus.AdblockPlus]
""=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AdblockPlus.AdblockPlus.1]
""=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0BB81440-5F42-4480-A5F7-770A6F439FC8}\InprocServer32]
""=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{189F1E63-33A7-404B-B2F6-8C76A452CC54}\InprocServer32]
""=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2803063F-4B8D-4dc6-8874-D1802487FE2D}\InprocServer32]
""=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8DE189EC-C9C8-4D31-9F18-E0B7407019A9}]
""=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8DE189EC-C9C8-4D31-9F18-E0B7407019A9}\DefaultIcon]
""=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8DE189EC-C9C8-4D31-9F18-E0B7407019A9}\Shell\Open\command]
""==
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FFCB3198-32F3-4E8B-9539-4324694ED664}]
""==
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FFCB3198-32F3-4E8B-9539-4324694ED664}\InprocServer32]
""==
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\IObit Malware Fighter]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\IObit Malware Fighter]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\C059F0AE629D66346AC0E9B717BDF12F]
"ProductName"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\C059F0AE629D66346AC0E9B717BDF12F\SourceList]
"PackageName"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\E5D7A28B1734BBF4793EA1C766649A33]
"ProductName"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\E5D7A28B1734BBF4793EA1C766649A33\SourceList]
"PackageName"=-
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\lnkfile\shellex\ContextMenuHandlers\IObit Malware Fighter]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0B80B6D2-246B-4A6B-AEA1-66F1DF0F4211}\1.0]
""=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0B80B6D2-246B-4A6B-AEA1-66F1DF0F4211}\1.0\0\win32]
""=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{60AD0991-ECD4-49DC-B170-8B7E7C60F51B}\1.0\0\win32]
""=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{60AD0991-ECD4-49DC-B170-8B7E7C60F51B}\1.0\HELPDIR]
""=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{7CD37F36-0BEF-11DC-8314-0800200C9A67}\1.0\0\win32]
""=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{7CD37F36-0BEF-11DC-8314-0800200C9A67}\1.0\HELPDIR]
""=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{ACB9DC96-D7BB-430F-AE6B-97F0DFDEAFCC}\1.0\0\win32]
""=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{ACB9DC96-D7BB-430F-AE6B-97F0DFDEAFCC}\1.0\HELPDIR]
""=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F03CE6C6-4F7F-4E36-92EF-DE5ACFA9E429}\1.0\0\win32]
""=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F03CE6C6-4F7F-4E36-92EF-DE5ACFA9E429}\1.0\HELPDIR]
""=-
[-HKEY_LOCAL_MACHINE\SOFTWARE\IObit]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_1_for_KB2964358~31bf3856ad364e35~x86~~9.1.1.0]
"InstallLocation"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_1_for_KB3065979~31bf3856ad364e35~x86~~6.0.1.0]
"InstallLocation"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_1_for_KB3118401~31bf3856ad364e35~x86~~6.0.1.1]
"InstallLocation"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_for_KB2964358_RTM~31bf3856ad364e35~x86~~9.1.1.0]
"InstallLocation"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_for_KB2964358~31bf3856ad364e35~x86~~9.1.1.0]
"InstallLocation"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_for_KB3065979_client_2~31bf3856ad364e35~x86~~6.0.1.0]
"InstallLocation"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_for_KB3065979_client~31bf3856ad364e35~x86~~6.0.1.0]
"InstallLocation"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_for_KB3065979~31bf3856ad364e35~x86~~6.0.1.0]
"InstallLocation"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_for_KB3118401_client_2~31bf3856ad364e35~x86~~6.0.1.1]
"InstallLocation"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_for_KB3118401_client~31bf3856ad364e35~x86~~6.0.1.1]
"InstallLocation"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_for_KB3118401~31bf3856ad364e35~x86~~6.0.1.1]
"InstallLocation"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{020FA22C-3547-4244-9C64-C11CB32D9C44}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{0521AE79-9B22-4C30-819D-0701061ECA24}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{078F4E71-DA56-4195-B2E5-A87503A05B51}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{086D4DA4-BA8F-49C9-B508-0083D6ACDBEF}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{0A63117E-7302-4D99-B85C-507669F66E11}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{0AB65B47-2FE6-4AA1-9533-D786CA99552D}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{0B385D8E-F37C-430F-B8AB-357A02FD7994}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{107A0070-2598-4B13-AFD2-E380338B957A}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{13B1F917-645B-423E-9FD9-6C8AC21EFC68}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{14F2C49D-B138-4EB1-8A21-D452F4FC7E6E}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{183059F9-B0D0-4D8A-9DFA-A1A818B54301}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{1B3674B1-84C1-42E0-9627-B99453F295F8}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{1C40FA7B-C9B6-496B-9D91-D851D9A83E11}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{1F07C09C-65D5-47AF-B48E-69A737E2E831}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{1F27D45E-CF18-429A-9B89-6EA2807BBC18}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{209D3D30-E2A2-4C6E-80A0-673F4CC478AA}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{21883BA0-3B8D-486C-8DFD-08523407C246}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{2207A69B-6B77-4068-B5D4-8B2C0CBF865E}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{245CC750-E872-445F-BF6F-AF8BB0925726}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{267B474C-FB0E-4FB5-AD64-6C96CAAB59D9}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{2864DD1B-935C-480E-AEE4-32429864B8FB}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{286806EE-EFF7-49E0-80E2-2D263805E9D9}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{28AFDDC2-3871-433E-B97E-6574FB1D7A85}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{2CF991D2-AB2C-458D-A1A0-F95E65DEC70A}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{305C68A7-841C-4361-B145-BDB3FD6CE8D6}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{32AA54BF-D0E5-45C8-97D5-592DD075F792}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{34D9CB50-974B-4E01-8150-67249D61571F}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{35955A05-7038-48FA-B934-8EEDB4A416E6}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{3F760F3D-FC1B-4A16-A346-277E0413056E}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{41BB69C5-1512-487B-8829-B5B1E09AE231}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{42524A82-D0A1-47B1-9E94-493C7D2422B7}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{44530D40-F018-4F03-BEAF-60D00FA68F4F}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{448D1FCC-6AB1-4065-A98D-B6F4B291C27A}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{476A98E9-4450-4797-8457-4CDE563942B9}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{534824A9-9BE7-44B8-AB46-7C7D05628BBF}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{5409ABCE-5236-4B9C-A7E2-01285F0FF3C0}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{569F1FF6-C0BA-43D0-AAF7-7F5C009F044B}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{579605EA-7884-4AA7-A432-415469929121}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{5D8B7533-8D84-4FC1-9A27-6682A1CF78BD}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{65508EC2-27B0-4FB9-B506-FFF6E8F0214A}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{65646C1D-85FC-4F00-A59D-BC78A3C44685}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{6C9D20CF-0EA9-4A58-9235-5BC929FD60B1}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{727E1A24-EB26-4893-BAD6-FA04B5943BEB}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{72F60D25-8D06-44DF-BD07-D27FE47B52AF}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{77E3B67C-6965-4888-9D67-0543D80295C9}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{78C0511C-F50B-45B4-839A-66B998C0B5CB}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{79E09A72-F891-4FFB-8D74-A9F941E5D91C}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{7AE61FE3-5580-4A17-8442-1E1DD11639B7}]
"Path"=--
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{7C5C06A2-4A85-4ED3-9EDA-BFD872C83A42}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{7E2AF306-BE7A-4C70-B381-D684F754AC5B}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{8182D514-E413-4D50-A9F1-CA9A8023B074}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{87C456EB-EAF7-4D3B-BFF0-E0BED9977763}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{883008C2-DB5A-4591-B60D-30BD874E8EED}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{8958F620-8584-4001-91BA-9DA9C068C001}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{8BE08235-79BE-4774-85C6-FC04155C2440}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{8D046828-F10D-450F-889A-3D721D493445}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{8F224F34-C4F3-4CE1-AA0B-BD70033154D9}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{952A9ACE-8D88-4788-8982-BBD58DB050E4}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{98CA1FDA-7072-4102-9DC1-E19C89869CAF}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{9EAC015D-F712-4825-8EE2-2DAAE7905D22}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{A03D70B0-5189-45AA-BE6E-E896C875D18C}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{A316A072-BE31-4953-8889-5ADBE7F1FE67}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{A71757D8-D971-4056-AD8B-B81985086CC2}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{A7F40756-B1B8-463C-B627-995F022054AB}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{AA8C3320-A9E6-40C7-B2D2-4DEA16E2C311}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{B3D01F97-E195-458A-87F9-C45E1AB2A241}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{B66494CD-4E40-4743-8E44-AF6E70738EA4}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{BCCC5684-AF1E-479E-8F60-612B2DBF4ECA}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{BE176D14-CC2E-4190-875A-8714A9FD9721}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{C6055D53-B858-49FC-B676-7C57CD89030B}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{C6A5867A-5BC8-4C83-8942-A31E14783133}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{CAF8FF43-5043-449E-B3D9-2B58FE49347C}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{CE21BBB5-34CD-4B39-8B77-FE9AE8DD9FDA}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{D24C09CE-C6AA-4708-8851-39EE3CC9F06A}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{D3F19A3F-27F7-4FDA-8732-19BED2973C25}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{DCADD14F-1F26-4E26-8A33-BB0F9EDFFDB6}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{DCE3D6AE-8EA8-4DF0-8483-B09942E56018}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{DDAD7EF2-1982-4AE3-9DF6-F130EDE088B4}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{DE89804C-8A77-45C8-87C9-424976A52AA5}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{E03C5CBC-A311-4565-839C-28536B3B7BE9}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{E0E3EDDE-1497-4C69-82E9-FFE835D1578C}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{E316FB34-DE6E-49D5-89E8-E58B88976BF3}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{E4B65AE1-5911-4424-BCDE-DC1E8BC9A053}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{E5C02470-160E-4739-9BCE-709FDF413D9E}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{E64F9DEA-4397-4643-ABBA-B5A9B8A144B7}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{E65A5C4A-4D16-4335-8F60-F2548CED4550}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{E830E645-8952-4C40-A689-87AFE7953690}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{EA1166EB-4421-4FB5-8BE4-16F56C35269F}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{EB6D4B9B-67AE-4DAD-A200-A286EDE91FB1}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{F2206154-EF80-4111-86EC-93F5694DA515}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{F308B143-6DA7-465D-9383-07CC58B3CC99}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{F488AC55-FAEC-4841-9C30-1FB71BB3D8D0}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{FB0B687D-E57F-4C5A-B760-A7A72D5C1EB8}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{FC15A5C0-80A3-4BC7-BB42-62EECC06441A}]
"Path"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{189F1E63-33A7-404B-B2F6-8C76A452CC54}"=-
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ADSRemoval_is1]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Driver Booster_is1]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EA0F950C-D926-4366-A60C-9E7B71DB1FF2}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LiveUpdateSvc]
"ImagePath"=-
[-HKEY_USERS\.DEFAULT\Software\AppDataLow\Software\IObit]
[-HKEY_USERS\.DEFAULT\Software\IObit]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 9"=-
[-HKEY_USERS\S-1-5-21-3222991852-3880959725-3339485959-1165\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\IObit Surfing Protection_is1]
[-HKEY_USERS\S-1-5-21-3222991852-3880959725-3339485959-1165\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\IObit Malware Fighter]
[-HKEY_USERS\S-1-5-21-3222991852-3880959725-3339485959-1165\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\IObit Uninstaller]
[HKEY_USERS\S-1-5-21-3222991852-3880959725-3339485959-1165\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Program Files\IObit\IObit Uninstaller\Uninstall_Mitor.exe"=-
[HKEY_USERS\S-1-5-21-3222991852-3880959725-3339485959-1165\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Program Files\IObit\IObit Uninstaller\IObitUninstaler.exe"=-
[HKEY_USERS\S-1-5-21-3222991852-3880959725-3339485959-1165\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Program Files\IObit\IObit Malware Fighter\AutoUpdate.exe"=-
[HKEY_USERS\S-1-5-21-3222991852-3880959725-3339485959-1165\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Program Files\IObit\IObit Uninstaller\unins000.exe"=-
[HKEY_USERS\S-1-5-21-3222991852-3880959725-3339485959-1165\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Program Files\IObit\IObit Malware Fighter\unins000.exe"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\D03D33E5698D29D40B33F55418B99273]
"ProductName"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\D03D33E5698D29D40B33F55418B99273\SourceList]
"PackageName"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\D03D33E5698D29D40B33F55418B99273\SourceList]
"LastUsedSource"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\D03D33E5698D29D40B33F55418B99273\SourceList\Net]
"1"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000051B-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000051C-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000051D-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000051E-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000051F-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000520-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000521-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000523-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000524-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000525-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000526-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000527-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000528-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000529-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000052A-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000052B-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000052C-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000052E-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000052F-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000530-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000531-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000532-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000533-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000540-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000541-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000542-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000543-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000544-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000545-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000546-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000547-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000548-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000549-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000054A-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000054B-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000552-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000553-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000554-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000570-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000571-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000573-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000574-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000576-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000577-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000057A-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000057B-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000057C-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000057D-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000057E-0000-0010-8000-00AA006D2EA4}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{2AC1B0DF-D478-3140-999B-BEB56A4AA112}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{43EA8D11-CE4A-355B-83DB-A414D5D3A431}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{49735749-147A-300B-8986-004FC837C083}\5.0.2.34]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{4CDEE1C3-5A1B-350E-A3F9-F9F7F7C95CAC}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{63033C5B-3DD7-3B07-ADF8-15EEE68AA14F}\5.0.2.34]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{793FC64C-92D4-36C2-8D76-29ADE5ACC998}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{7E632ADF-9D4A-374C-AD52-25A9213987EE}\5.0.2.34]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{7F564B7C-5B6C-3AB9-B8FD-109554AE454B}\5.0.2.34]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{898CF1A5-06A2-30B5-8088-F9E7A66A4143}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{9080C45E-594C-3768-A294-C1B261ECD5F9}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{9558E2B7-51E3-315A-A409-2F1E30A23EFA}\5.0.2.34]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{9B09BB39-AEDE-3F55-AAF4-804064565E97}\5.0.2.34]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{A56187C5-D690-4037-AE32-A00EDC376AC3}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{A700FB12-17FC-3877-A874-00C31AFED422}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{A9BA0EB6-3DA2-3A7A-B296-7FF4F611FD80}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{BFBCF6E9-EE8C-366E-8DD2-34AFB7637D06}\5.0.2.34]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{C0CAD8CE-F322-3633-865B-FE9CF09B81BA}\5.0.2.34]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{D3BDD942-66D3-3156-B238-DE8B9720F37F}\5.0.2.34]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{D95DA0A3-AB54-356D-9050-B986DBD6A11A}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{DD4CB1CF-E6F7-3A03-A77E-ED44939DD4CF}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{DFF05178-341C-396F-A898-50DDBC699024}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{E221116A-32CE-36C4-990E-4E731DF815F5}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{E8F7B742-5831-3A24-8C7F-30A77C99DA9B}\5.0.2.34]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{F757B661-E287-3E2F-AF82-74FD2DF87F46}\5.0.2.34]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{FFC6D718-C67D-34B7-A64F-5B2235F83C11}\2.8.0.0]
"CodeBase"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5E33D30D-D896-4D92-B033-5F45819B2937}]
"HelpLink"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5E33D30D-D896-4D92-B033-5F45819B2937}]
"Publisher"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5E33D30D-D896-4D92-B033-5F45819B2937}]
"URLInfoAbout"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5E33D30D-D896-4D92-B033-5F45819B2937}]
"DisplayName"=-
EndRegedit:
*****************

Restore point was successfully created.
Processes closed successfully.
C:\Windows\System32\IObitSmartDefragExtension.dll => moved successfully
C:\Windows\System32\SMI\Store\Machine\schema.dat.iobit => moved successfully
C:\Windows\System32\config\components.iobit => moved successfully
C:\Windows\System32\config\default.iobit => moved successfully
C:\Windows\System32\config\sam.iobit => moved successfully
C:\Windows\System32\config\security.iobit => moved successfully
C:\Windows\System32\config\software.iobit => moved successfully
C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.iobit => moved successfully
C:\Windows\ServiceProfiles\LocalService\ntuser.dat.iobit => moved successfully
C:\Windows\Prefetch\IOBITUNINSTALER.EXE-D03E1084.pf => moved successfully
C:\Users\Owner\Favorites\Download IObit Freeware.url => moved successfully
C:\Users\Owner\Favorites\IObit Malware Fighter Help Center.url => moved successfully
C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\u4l6dqze.default-1355119460502\extensions\ascsurfingprotectionnew@iobit.com.xpi => moved successfully
C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\mdquwntd.default-1475852303466\extensions\ascsurfingprotectionnew@iobit.com.xpi => moved successfully
C:\Users\Owner\AppData\Local\Microsoft\Windows\UsrClass.dat.iobit => moved successfully
C:\Users\admin anticryptolock\AppData\Roaming\Microsoft\Windows\Recent\per Gary of BleepComp, problems when trying to remove Iobit.lnk => moved successfully
C:\ProgramData\IObit\iobitpromotion.ini => moved successfully
C:\Old Firefox Data\{F0B1CEAC-7C0D-407c-B25E-623D7CBECCCB}\iobit.lock => moved successfully
C:\Old Firefox Data\extensions\iobit@mybrowserbar.com => moved successfully
C:\Boot\BCD.iobit => moved successfully
C:\AdwCleaner\quarantine\files\fiufazuytmkiqlnzosmxcvkadinrnczc\IObit Malware Fighter.exe.dat => moved successfully
"C:\Program Files\IObit" => not found.
"C:\Program Files\Strongvault Online Backup" => not found.
StartRegdit: => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\ADSRemoval] => Error: No automatic fix found for this entry.
"UninstallString"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\ADSRemoval] => Error: No automatic fix found for this entry.
"InstallLocation"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\IObit Malware Fighter] => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\//\//\IObit Cloud Anti-Malwre] => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AdblockPlus.AdblockPlus] => Error: No automatic fix found for this entry.
""=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AdblockPlus.AdblockPlus.1] => Error: No automatic fix found for this entry.
""=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0BB81440-5F42-4480-A5F7-770A6F439FC8}\InprocServer32] => Error: No automatic fix found for this entry.
""=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{189F1E63-33A7-404B-B2F6-8C76A452CC54}\InprocServer32] => Error: No automatic fix found for this entry.
""=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2803063F-4B8D-4dc6-8874-D1802487FE2D}\InprocServer32] => Error: No automatic fix found for this entry.
""=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8DE189EC-C9C8-4D31-9F18-E0B7407019A9}] => Error: No automatic fix found for this entry.
""=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8DE189EC-C9C8-4D31-9F18-E0B7407019A9}\DefaultIcon] => Error: No automatic fix found for this entry.
""=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8DE189EC-C9C8-4D31-9F18-E0B7407019A9}\Shell\Open\command] => Error: No automatic fix found for this entry.
""== => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FFCB3198-32F3-4E8B-9539-4324694ED664}] => Error: No automatic fix found for this entry.
""== => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FFCB3198-32F3-4E8B-9539-4324694ED664}\InprocServer32] => Error: No automatic fix found for this entry.
""== => Error: No automatic fix found for this entry.
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\IObit Malware Fighter => key removed successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\IObit Malware Fighter => key removed successfully.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\C059F0AE629D66346AC0E9B717BDF12F] => Error: No automatic fix found for this entry.
"ProductName"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\C059F0AE629D66346AC0E9B717BDF12F\SourceList] => Error: No automatic fix found for this entry.
"PackageName"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\E5D7A28B1734BBF4793EA1C766649A33] => Error: No automatic fix found for this entry.
"ProductName"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\E5D7A28B1734BBF4793EA1C766649A33\SourceList] => Error: No automatic fix found for this entry.
"PackageName"=- => Error: No automatic fix found for this entry.
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\lnkfile\shellex\ContextMenuHandlers\IObit Malware Fighter => key removed successfully.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0B80B6D2-246B-4A6B-AEA1-66F1DF0F4211}\1.0] => Error: No automatic fix found for this entry.
""=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0B80B6D2-246B-4A6B-AEA1-66F1DF0F4211}\1.0\0\win32] => Error: No automatic fix found for this entry.
""=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{60AD0991-ECD4-49DC-B170-8B7E7C60F51B}\1.0\0\win32] => Error: No automatic fix found for this entry.
""=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{60AD0991-ECD4-49DC-B170-8B7E7C60F51B}\1.0\HELPDIR] => Error: No automatic fix found for this entry.
""=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{7CD37F36-0BEF-11DC-8314-0800200C9A67}\1.0\0\win32] => Error: No automatic fix found for this entry.
""=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{7CD37F36-0BEF-11DC-8314-0800200C9A67}\1.0\HELPDIR] => Error: No automatic fix found for this entry.
""=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{ACB9DC96-D7BB-430F-AE6B-97F0DFDEAFCC}\1.0\0\win32] => Error: No automatic fix found for this entry.
""=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{ACB9DC96-D7BB-430F-AE6B-97F0DFDEAFCC}\1.0\HELPDIR] => Error: No automatic fix found for this entry.
""=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F03CE6C6-4F7F-4E36-92EF-DE5ACFA9E429}\1.0\0\win32] => Error: No automatic fix found for this entry.
""=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F03CE6C6-4F7F-4E36-92EF-DE5ACFA9E429}\1.0\HELPDIR] => Error: No automatic fix found for this entry.
""=- => Error: No automatic fix found for this entry.
HKEY_LOCAL_MACHINE\SOFTWARE\IObit => key removed successfully.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_1_for_KB2964358~31bf3856ad364e35~x86~~9.1.1.0] => Error: No automatic fix found for this entry.
"InstallLocation"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_1_for_KB3065979~31bf3856ad364e35~x86~~6.0.1.0] => Error: No automatic fix found for this entry.
"InstallLocation"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_1_for_KB3118401~31bf3856ad364e35~x86~~6.0.1.1] => Error: No automatic fix found for this entry.
"InstallLocation"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_for_KB2964358_RTM~31bf3856ad364e35~x86~~9.1.1.0] => Error: No automatic fix found for this entry.
"InstallLocation"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_for_KB2964358~31bf3856ad364e35~x86~~9.1.1.0] => Error: No automatic fix found for this entry.
"InstallLocation"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_for_KB3065979_client_2~31bf3856ad364e35~x86~~6.0.1.0] => Error: No automatic fix found for this entry.
"InstallLocation"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_for_KB3065979_client~31bf3856ad364e35~x86~~6.0.1.0] => Error: No automatic fix found for this entry.
"InstallLocation"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_for_KB3065979~31bf3856ad364e35~x86~~6.0.1.0] => Error: No automatic fix found for this entry.
"InstallLocation"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_for_KB3118401_client_2~31bf3856ad364e35~x86~~6.0.1.1] => Error: No automatic fix found for this entry.
"InstallLocation"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_for_KB3118401_client~31bf3856ad364e35~x86~~6.0.1.1] => Error: No automatic fix found for this entry.
"InstallLocation"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_for_KB3118401~31bf3856ad364e35~x86~~6.0.1.1] => Error: No automatic fix found for this entry.
"InstallLocation"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{020FA22C-3547-4244-9C64-C11CB32D9C44}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{0521AE79-9B22-4C30-819D-0701061ECA24}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{078F4E71-DA56-4195-B2E5-A87503A05B51}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{086D4DA4-BA8F-49C9-B508-0083D6ACDBEF}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{0A63117E-7302-4D99-B85C-507669F66E11}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{0AB65B47-2FE6-4AA1-9533-D786CA99552D}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{0B385D8E-F37C-430F-B8AB-357A02FD7994}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{107A0070-2598-4B13-AFD2-E380338B957A}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{13B1F917-645B-423E-9FD9-6C8AC21EFC68}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{14F2C49D-B138-4EB1-8A21-D452F4FC7E6E}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{183059F9-B0D0-4D8A-9DFA-A1A818B54301}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{1B3674B1-84C1-42E0-9627-B99453F295F8}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{1C40FA7B-C9B6-496B-9D91-D851D9A83E11}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{1F07C09C-65D5-47AF-B48E-69A737E2E831}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{1F27D45E-CF18-429A-9B89-6EA2807BBC18}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{209D3D30-E2A2-4C6E-80A0-673F4CC478AA}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{21883BA0-3B8D-486C-8DFD-08523407C246}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{2207A69B-6B77-4068-B5D4-8B2C0CBF865E}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{245CC750-E872-445F-BF6F-AF8BB0925726}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{267B474C-FB0E-4FB5-AD64-6C96CAAB59D9}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{2864DD1B-935C-480E-AEE4-32429864B8FB}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{286806EE-EFF7-49E0-80E2-2D263805E9D9}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{28AFDDC2-3871-433E-B97E-6574FB1D7A85}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{2CF991D2-AB2C-458D-A1A0-F95E65DEC70A}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{305C68A7-841C-4361-B145-BDB3FD6CE8D6}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{32AA54BF-D0E5-45C8-97D5-592DD075F792}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{34D9CB50-974B-4E01-8150-67249D61571F}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{35955A05-7038-48FA-B934-8EEDB4A416E6}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{3F760F3D-FC1B-4A16-A346-277E0413056E}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{41BB69C5-1512-487B-8829-B5B1E09AE231}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{42524A82-D0A1-47B1-9E94-493C7D2422B7}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{44530D40-F018-4F03-BEAF-60D00FA68F4F}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{448D1FCC-6AB1-4065-A98D-B6F4B291C27A}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{476A98E9-4450-4797-8457-4CDE563942B9}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{534824A9-9BE7-44B8-AB46-7C7D05628BBF}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{5409ABCE-5236-4B9C-A7E2-01285F0FF3C0}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{569F1FF6-C0BA-43D0-AAF7-7F5C009F044B}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{579605EA-7884-4AA7-A432-415469929121}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{5D8B7533-8D84-4FC1-9A27-6682A1CF78BD}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{65508EC2-27B0-4FB9-B506-FFF6E8F0214A}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{65646C1D-85FC-4F00-A59D-BC78A3C44685}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{6C9D20CF-0EA9-4A58-9235-5BC929FD60B1}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{727E1A24-EB26-4893-BAD6-FA04B5943BEB}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{72F60D25-8D06-44DF-BD07-D27FE47B52AF}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{77E3B67C-6965-4888-9D67-0543D80295C9}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{78C0511C-F50B-45B4-839A-66B998C0B5CB}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{79E09A72-F891-4FFB-8D74-A9F941E5D91C}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{7AE61FE3-5580-4A17-8442-1E1DD11639B7}] => Error: No automatic fix found for this entry.
"Path"=-- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{7C5C06A2-4A85-4ED3-9EDA-BFD872C83A42}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{7E2AF306-BE7A-4C70-B381-D684F754AC5B}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{8182D514-E413-4D50-A9F1-CA9A8023B074}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{87C456EB-EAF7-4D3B-BFF0-E0BED9977763}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{883008C2-DB5A-4591-B60D-30BD874E8EED}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{8958F620-8584-4001-91BA-9DA9C068C001}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{8BE08235-79BE-4774-85C6-FC04155C2440}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{8D046828-F10D-450F-889A-3D721D493445}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{8F224F34-C4F3-4CE1-AA0B-BD70033154D9}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{952A9ACE-8D88-4788-8982-BBD58DB050E4}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{98CA1FDA-7072-4102-9DC1-E19C89869CAF}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{9EAC015D-F712-4825-8EE2-2DAAE7905D22}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{A03D70B0-5189-45AA-BE6E-E896C875D18C}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{A316A072-BE31-4953-8889-5ADBE7F1FE67}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{A71757D8-D971-4056-AD8B-B81985086CC2}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{A7F40756-B1B8-463C-B627-995F022054AB}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{AA8C3320-A9E6-40C7-B2D2-4DEA16E2C311}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{B3D01F97-E195-458A-87F9-C45E1AB2A241}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{B66494CD-4E40-4743-8E44-AF6E70738EA4}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{BCCC5684-AF1E-479E-8F60-612B2DBF4ECA}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{BE176D14-CC2E-4190-875A-8714A9FD9721}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{C6055D53-B858-49FC-B676-7C57CD89030B}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{C6A5867A-5BC8-4C83-8942-A31E14783133}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{CAF8FF43-5043-449E-B3D9-2B58FE49347C}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{CE21BBB5-34CD-4B39-8B77-FE9AE8DD9FDA}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{D24C09CE-C6AA-4708-8851-39EE3CC9F06A}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{D3F19A3F-27F7-4FDA-8732-19BED2973C25}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{DCADD14F-1F26-4E26-8A33-BB0F9EDFFDB6}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{DCE3D6AE-8EA8-4DF0-8483-B09942E56018}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{DDAD7EF2-1982-4AE3-9DF6-F130EDE088B4}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{DE89804C-8A77-45C8-87C9-424976A52AA5}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{E03C5CBC-A311-4565-839C-28536B3B7BE9}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{E0E3EDDE-1497-4C69-82E9-FFE835D1578C}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{E316FB34-DE6E-49D5-89E8-E58B88976BF3}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{E4B65AE1-5911-4424-BCDE-DC1E8BC9A053}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{E5C02470-160E-4739-9BCE-709FDF413D9E}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{E64F9DEA-4397-4643-ABBA-B5A9B8A144B7}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{E65A5C4A-4D16-4335-8F60-F2548CED4550}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{E830E645-8952-4C40-A689-87AFE7953690}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{EA1166EB-4421-4FB5-8BE4-16F56C35269F}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{EB6D4B9B-67AE-4DAD-A200-A286EDE91FB1}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{F2206154-EF80-4111-86EC-93F5694DA515}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{F308B143-6DA7-465D-9383-07CC58B3CC99}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{F488AC55-FAEC-4841-9C30-1FB71BB3D8D0}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{FB0B687D-E57F-4C5A-B760-A7A72D5C1EB8}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Parental Controls\Users\S-1-5-21-3222991852-3880959725-3339485959-1000\App Restrictions\{FC15A5C0-80A3-4BC7-BB42-62EECC06441A}] => Error: No automatic fix found for this entry.
"Path"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved] => Error: No automatic fix found for this entry.
"{189F1E63-33A7-404B-B2F6-8C76A452CC54}"=- => Error: No automatic fix found for this entry.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ADSRemoval_is1 => key removed successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Driver Booster_is1 => key removed successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EA0F950C-D926-4366-A60C-9E7B71DB1FF2} => key not found.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LiveUpdateSvc] => Error: No automatic fix found for this entry.
"ImagePath"=- => Error: No automatic fix found for this entry.
HKEY_USERS\.DEFAULT\Software\AppDataLow\Software\IObit => key removed successfully.
HKEY_USERS\.DEFAULT\Software\IObit => key removed successfully.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] => Error: No automatic fix found for this entry.
"Advanced SystemCare 9"=- => Error: No automatic fix found for this entry.
HKEY_USERS\S-1-5-21-3222991852-3880959725-3339485959-1165\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\IObit Surfing Protection_is1 => key removed successfully.
HKEY_USERS\S-1-5-21-3222991852-3880959725-3339485959-1165\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\IObit Malware Fighter => key removed successfully.
HKEY_USERS\S-1-5-21-3222991852-3880959725-3339485959-1165\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\IObit Uninstaller => key removed successfully.
[HKEY_USERS\S-1-5-21-3222991852-3880959725-3339485959-1165\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] => Error: No automatic fix found for this entry.
"C:\Program Files\IObit\IObit Uninstaller\Uninstall_Mitor.exe=-" => not found.
[HKEY_USERS\S-1-5-21-3222991852-3880959725-3339485959-1165\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] => Error: No automatic fix found for this entry.
"C:\Program Files\IObit\IObit Uninstaller\IObitUninstaler.exe=-" => not found.
[HKEY_USERS\S-1-5-21-3222991852-3880959725-3339485959-1165\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] => Error: No automatic fix found for this entry.
"C:\Program Files\IObit\IObit Malware Fighter\AutoUpdate.exe=-" => not found.
[HKEY_USERS\S-1-5-21-3222991852-3880959725-3339485959-1165\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] => Error: No automatic fix found for this entry.
"C:\Program Files\IObit\IObit Uninstaller\unins000.exe=-" => not found.
[HKEY_USERS\S-1-5-21-3222991852-3880959725-3339485959-1165\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] => Error: No automatic fix found for this entry.
"C:\Program Files\IObit\IObit Malware Fighter\unins000.exe=-" => not found.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\D03D33E5698D29D40B33F55418B99273] => Error: No automatic fix found for this entry.
"ProductName"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\D03D33E5698D29D40B33F55418B99273\SourceList] => Error: No automatic fix found for this entry.
"PackageName"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\D03D33E5698D29D40B33F55418B99273\SourceList] => Error: No automatic fix found for this entry.
"LastUsedSource"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\D03D33E5698D29D40B33F55418B99273\SourceList\Net] => Error: No automatic fix found for this entry.
"1"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000051B-0000-0010-8000-00AA006D2EA4}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000051C-0000-0010-8000-00AA006D2EA4}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000051D-0000-0010-8000-00AA006D2EA4}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000051E-0000-0010-8000-00AA006D2EA4}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000051F-0000-0010-8000-00AA006D2EA4}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000520-0000-0010-8000-00AA006D2EA4}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000521-0000-0010-8000-00AA006D2EA4}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000523-0000-0010-8000-00AA006D2EA4}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000524-0000-0010-8000-00AA006D2EA4}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000525-0000-0010-8000-00AA006D2EA4}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000526-0000-0010-8000-00AA006D2EA4}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000527-0000-0010-8000-00AA006D2EA4}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000528-0000-0010-8000-00AA006D2EA4}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000529-0000-0010-8000-00AA006D2EA4}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000052A-0000-0010-8000-00AA006D2EA4}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000052B-0000-0010-8000-00AA006D2EA4}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000052C-0000-0010-8000-00AA006D2EA4}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000052E-0000-0010-8000-00AA006D2EA4}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000052F-0000-0010-8000-00AA006D2EA4}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000530-0000-0010-8000-00AA006D2EA4}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000531-0000-0010-8000-00AA006D2EA4}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000532-0000-0010-8000-00AA006D2EA4}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000533-0000-0010-8000-00AA006D2EA4}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000540-0000-0010-8000-00AA006D2EA4}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000541-0000-0010-8000-00AA006D2EA4}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000542-0000-0010-8000-00AA006D2EA4}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000543-0000-0010-8000-00AA006D2EA4}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000544-0000-0010-8000-00AA006D2EA4}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000545-0000-0010-8000-00AA006D2EA4}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000546-0000-0010-8000-00AA006D2EA4}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000547-0000-0010-8000-00AA006D2EA4}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000548-0000-0010-8000-00AA006D2EA4}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000549-0000-0010-8000-00AA006D2EA4}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000054A-0000-0010-8000-00AA006D2EA4}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000054B-0000-0010-8000-00AA006D2EA4}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000552-0000-0010-8000-00AA006D2EA4}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000553-0000-0010-8000-00AA006D2EA4}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000554-0000-0010-8000-00AA006D2EA4}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000570-0000-0010-8000-00AA006D2EA4}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000571-0000-0010-8000-00AA006D2EA4}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000573-0000-0010-8000-00AA006D2EA4}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000574-0000-0010-8000-00AA006D2EA4}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000576-0000-0010-8000-00AA006D2EA4}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{00000577-0000-0010-8000-00AA006D2EA4}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000057A-0000-0010-8000-00AA006D2EA4}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000057B-0000-0010-8000-00AA006D2EA4}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000057C-0000-0010-8000-00AA006D2EA4}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000057D-0000-0010-8000-00AA006D2EA4}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{0000057E-0000-0010-8000-00AA006D2EA4}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{2AC1B0DF-D478-3140-999B-BEB56A4AA112}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{43EA8D11-CE4A-355B-83DB-A414D5D3A431}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{49735749-147A-300B-8986-004FC837C083}\5.0.2.34] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{4CDEE1C3-5A1B-350E-A3F9-F9F7F7C95CAC}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{63033C5B-3DD7-3B07-ADF8-15EEE68AA14F}\5.0.2.34] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{793FC64C-92D4-36C2-8D76-29ADE5ACC998}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{7E632ADF-9D4A-374C-AD52-25A9213987EE}\5.0.2.34] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{7F564B7C-5B6C-3AB9-B8FD-109554AE454B}\5.0.2.34] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{898CF1A5-06A2-30B5-8088-F9E7A66A4143}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{9080C45E-594C-3768-A294-C1B261ECD5F9}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{9558E2B7-51E3-315A-A409-2F1E30A23EFA}\5.0.2.34] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{9B09BB39-AEDE-3F55-AAF4-804064565E97}\5.0.2.34] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{A56187C5-D690-4037-AE32-A00EDC376AC3}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{A700FB12-17FC-3877-A874-00C31AFED422}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{A9BA0EB6-3DA2-3A7A-B296-7FF4F611FD80}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{BFBCF6E9-EE8C-366E-8DD2-34AFB7637D06}\5.0.2.34] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{C0CAD8CE-F322-3633-865B-FE9CF09B81BA}\5.0.2.34] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{D3BDD942-66D3-3156-B238-DE8B9720F37F}\5.0.2.34] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{D95DA0A3-AB54-356D-9050-B986DBD6A11A}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{DD4CB1CF-E6F7-3A03-A77E-ED44939DD4CF}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{DFF05178-341C-396F-A898-50DDBC699024}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{E221116A-32CE-36C4-990E-4E731DF815F5}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{E8F7B742-5831-3A24-8C7F-30A77C99DA9B}\5.0.2.34] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{F757B661-E287-3E2F-AF82-74FD2DF87F46}\5.0.2.34] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{FFC6D718-C67D-34B7-A64F-5B2235F83C11}\2.8.0.0] => Error: No automatic fix found for this entry.
"CodeBase"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5E33D30D-D896-4D92-B033-5F45819B2937}] => Error: No automatic fix found for this entry.
"HelpLink"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5E33D30D-D896-4D92-B033-5F45819B2937}] => Error: No automatic fix found for this entry.
"Publisher"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5E33D30D-D896-4D92-B033-5F45819B2937}] => Error: No automatic fix found for this entry.
"URLInfoAbout"=- => Error: No automatic fix found for this entry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5E33D30D-D896-4D92-B033-5F45819B2937}] => Error: No automatic fix found for this entry.
"DisplayName"=- => Error: No automatic fix found for this entry.
EndRegedit: => Error: No automatic fix found for this entry.


The system needed a reboot.

==== End of Fixlog 13:34:25 ====



#15 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,179 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:01:39 AM

Posted 18 April 2017 - 03:21 PM

Greetings,

One little typo caused an error in deleting all the registry keys. Let's try it again. Please do this.

===================================================

Farbar's Recovery Scan Tool - Run Fix in Normal or Safe Mode Using Attached File

--------------------
  • Please download and save it in the same location as FRST.exe (example, Desktop, USB device) <<< Important
  • Launch FRST and press the Fix button just once and wait, the program will automatically launch fixlist.txt.
  • The tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • Fixlog

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users