Posted 27 April 2023 - 07:48 AM
Posted 27 April 2023 - 08:07 AM
Posted 27 April 2023 - 09:17 AM
Edited by Calyxes, 27 April 2023 - 09:51 AM.
Posted 27 April 2023 - 10:04 AM
Posted 27 April 2023 - 07:17 PM
Web Companion WebAdvisor by McAfee
Start::
CreateRestorePoint:
CloseProcesses:
cmd: type "C:\WINDOWS\system32\drivers\etc\hosts"
C:\Program Files (x86)\Lavasoft
2023-04-27 19:06 - 2023-04-27 19:06 - 000001147 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoProc.lnk
2023-04-27 19:06 - 2023-04-27 19:06 - 000000000 ____D C:\Users\Windows10\AppData\Roaming\Digiarty
2023-04-27 19:04 - 2023-04-27 19:34 - 000000000 ____D C:\Program Files (x86)\VideoProc
2023-04-27 19:04 - 2023-04-27 19:04 - 000000000 ____D C:\ProgramData\CyberMania
C:\Program Files\Common Files\Wondershare
C:\Program Files (x86)\Common Files\Wondershare
2023-04-18 00:25 - 2023-04-18 00:27 - 000000000 ____D C:\ProgramData\GraphicsType14
2023-04-18 00:23 - 2023-04-18 00:38 - 000000000 ____D C:\Users\Windows10\AppData\Roaming\Wondershare
2023-04-18 00:20 - 2023-04-18 01:00 - 000000000 ____D C:\Program Files\Wondershare
2023-04-18 01:00 - 2020-08-24 00:42 - 000000000 ____D C:\ProgramData\Wondershare
2023-04-18 00:59 - 2022-02-05 21:59 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare
C:\Program Files\Common Files\AVG
HKLM\...\StartupApproved\Run32: => "Wondershare Helper Compact.exe"
HKU\S-1-5-21-1072221882-492732373-972231997-1001\...\Run: [Web Companion] => C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe [8160856 2020-06-24] (LAVASOFT SOFTWARE CANADA INC -> Lavasoft) <==== ATTENTION
HKU\S-1-5-21-1072221882-492732373-972231997-1001\...\Winlogon: [Shell] C:\Windows\explorer.exe [5249688 2023-04-13] (Microsoft Windows -> Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-21-1072221882-492732373-972231997-1001\...\Run: [QNPlus] => [X]
HKLM\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe (No File)
HKLM\...\Run: [UniConverterUpdateHelper] => C:\Program Files\Wondershare\UniConverter 14\WSVCUUpdateHelper.exe (No File)
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe (No File)
HKU\S-1-5-21-1072221882-492732373-972231997-1001\...\Run: [Discord] => C:\Users\Windows10\AppData\Local\Discord\app-0.0.307\Discord.exe (No File)
HKU\S-1-5-21-1072221882-492732373-972231997-1001\...\Run: [Adobe Reader Synchronizer] => "C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AdobeCollabSync.exe" (No File)
HKU\S-1-5-21-1072221882-492732373-972231997-1001\...\Run: [QMxNetworkSync] => C:\Program Files\Common Files\MAGIX Services\Update Notifier\QMxNetworkSync.exe (No File)
HKU\S-1-5-21-1072221882-492732373-972231997-1001\...\Run: [NoxMultiPlayer] => "D:\Program Files\Nox\bin\MultiPlayerManager.exe" -startSource:auto_start (No File)
HKU\S-1-5-21-1072221882-492732373-972231997-1001\...\Run: [Netmarble Launcher] => "D:\Games\Ni no Kuni Cross Worlds\Netmarble Launcher.exe" (No File)
HKU\S-1-5-21-1072221882-492732373-972231997-1001\...\Run: [com.messenger] => "C:\Users\Windows10\AppData\Local\Programs\Messenger\Messenger.exe" messenger://openAtLogin (No File)
HKU\S-1-5-21-1072221882-492732373-972231997-1001\...\StartupApproved\Run: => "Web Companion"
HKU\S-1-5-21-1072221882-492732373-972231997-1001\...\Policies\Explorer: [DisallowRun] 1
HKU\S-1-5-21-1072221882-492732373-972231997-1001\...\Policies\Explorer\DisallowRun: [1] irsetup.exe
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://ph.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_fs_16_34¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dph%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0DtDtCyB0CtBtBzz0E0D0D0AyCyE0C0EtN0D0Tzu0StCyCzyzytN1L2XzutAtFtByEtFyCtFyCtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2StDzztAyE0AtAyC0CtGyB0E0FtDtGtBtByBzztGyDtBtDtCtGtDyBzy0BtA0E0DtCzyyCtD0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StA0DtC0C0D0EyBzztG0EyByEtCtGyEzy0C0EtGzz0D0ByCtGtD0A0A0F0D0A0AtA0FtC0F0C2QtN0A0LzuyE%26cr%3D1993188331%26a%3Dwbf_fs_16_34%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome%2BSingle%2BLanguage
HKU\S-1-5-21-1072221882-492732373-972231997-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://securedsearch.lavasoft.com/?pr=vmn&id=webcompa&ent=hp_WCYID10440__180211
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://ph.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_fs_16_34¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dph%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0DtDtCyB0CtBtBzz0E0D0D0AyCyE0C0EtN0D0Tzu0StCyCzyzytN1L2XzutAtFtByEtFyCtFyCtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2StDzztAyE0AtAyC0CtGyB0E0FtDtGtBtByBzztGyDtBtDtCtGtDyBzy0BtA0E0DtCzyyCtD0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StA0DtC0C0D0EyBzztG0EyByEtCtGyEzy0C0EtGzz0D0ByCtGtD0A0A0F0D0A0AtA0FtC0F0C2QtN0A0LzuyE%26cr%3D1993188331%26a%3Dwbf_fs_16_34%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome%2BSingle%2BLanguage&p={searchTerms}
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://ph.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_fs_16_34¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dph%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0DtDtCyB0CtBtBzz0E0D0D0AyCyE0C0EtN0D0Tzu0StCyCzyzytN1L2XzutAtFtByEtFyCtFyCtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2StDzztAyE0AtAyC0CtGyB0E0FtDtGtBtByBzztGyDtBtDtCtGtDyBzy0BtA0E0DtCzyyCtD0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StA0DtC0C0D0EyBzztG0EyByEtCtGyEzy0C0EtGzz0D0ByCtGtD0A0A0F0D0A0AtA0FtC0F0C2QtN0A0LzuyE%26cr%3D1993188331%26a%3Dwbf_fs_16_34%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome%2BSingle%2BLanguage&p={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://ph.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_fs_16_34¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dph%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0DtDtCyB0CtBtBzz0E0D0D0AyCyE0C0EtN0D0Tzu0StCyCzyzytN1L2XzutAtFtByEtFyCtFyCtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2StDzztAyE0AtAyC0CtGyB0E0FtDtGtBtByBzztGyDtBtDtCtGtDyBzy0BtA0E0DtCzyyCtD0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StA0DtC0C0D0EyBzztG0EyByEtCtGyEzy0C0EtGzz0D0ByCtGtD0A0A0F0D0A0AtA0FtC0F0C2QtN0A0LzuyE%26cr%3D1993188331%26a%3Dwbf_fs_16_34%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome%2BSingle%2BLanguage&p={searchTerms}
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://ph.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_fs_16_34¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dph%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0DtDtCyB0CtBtBzz0E0D0D0AyCyE0C0EtN0D0Tzu0StCyCzyzytN1L2XzutAtFtByEtFyCtFyCtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2StDzztAyE0AtAyC0CtGyB0E0FtDtGtBtByBzztGyDtBtDtCtGtDyBzy0BtA0E0DtCzyyCtD0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StA0DtC0C0D0EyBzztG0EyByEtCtGyEzy0C0EtGzz0D0ByCtGtD0A0A0F0D0A0AtA0FtC0F0C2QtN0A0LzuyE%26cr%3D1993188331%26a%3Dwbf_fs_16_34%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome%2BSingle%2BLanguage&p={searchTerms}
SearchScopes: HKU\S-1-5-21-1072221882-492732373-972231997-1001 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={039FF48C-87C2-4779-954B-EF24CDC6A062}&mid=b25a0edfa7e647cfb2ad19b66e041c4c-2d2237a3295f9b6422042bf98b8cf02e4f3fbdf6&lang=en&ds=AVG&coid=avgtbavg&cmpid=0516pii&pr=fr&d=2016-09-07 12:52:04&v=4.3.6.255&pid=wtu&sg=&sap=dsp&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1072221882-492732373-972231997-1001 -> {C0C3A6C6-03BC-4195-8FCB-AEA091301353} URL = hxxps://ph.search.yahoo.com/yhs/search?hspart=lvs&hsimp=yhs-awc&type=lvs__webcompa__1_0__ya__ch_WCYID10440__180211__yaie&p={searchTerms}
IFEO\LogTransport2.exe: [Debugger] 0
S2 rsAssistant; C:\Program Files\RAVAntivirus\rsAssistant.exe [X]
S3 MpKsl72edc48c; \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F5BFF280-4238-4A22-86A6-51970BBD54E1}\MpKslDrv.sys [X]
Task: {6FC00065-4A94-4AAE-8F09-5B1FAB981F1F} - System32\Tasks\Apple Diagnostics => C:\Program Files (x86)\Common Files\Apple\Internet Services\EReporter.exe (No File)
Task: {B1F3D2C2-9991-4161-97F6-5684DCFD3140} - System32\Tasks\Opera scheduled Autoupdate 1644079984 => C:\Users\Windows10\AppData\Local\Programs\Opera\launcher.exe --scheduledautoupdate $(Arg0) (No File)
Task: {DD1C90BC-1C3B-40BA-862E-2C69771F77C7} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {6FC00065-4A94-4AAE-8F09-5B1FAB981F1F} - System32\Tasks\Apple Diagnostics => C:\Program Files (x86)\Common Files\Apple\Internet Services\EReporter.exe (No File)
Task: {B1F3D2C2-9991-4161-97F6-5684DCFD3140} - System32\Tasks\Opera scheduled Autoupdate 1644079984 => C:\Users\Windows10\AppData\Local\Programs\Opera\launcher.exe --scheduledautoupdate $(Arg0) (No File)
Task: {0B0DDDB6-E65E-47F8-8208-D5E92F405AB3} - System32\Tasks\AVG\Overseer => C:\Program Files\Common Files\AVG\Overseer\overseer.exe [2172344 2023-04-12] (AVG Technologies USA, LLC -> AVG Technologies)
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
AlternateDataStreams: C:\Users\Windows10\Application Data:955d2a2f697b1c9b40c63a2dd2b7d393 [394]
AlternateDataStreams: C:\Users\Windows10\AppData\Roaming:955d2a2f697b1c9b40c63a2dd2b7d393 [394]
C:\Users\Windows10\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpih
FF Plugin: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.adobe.xfdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [No File]
FF Plugin: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [No File]
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [No File]
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [No File]
FF Plugin-x32: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.adobe.xfdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x86.dll [No File]
FF Plugin-x32: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x86.dll [No File]
FF Plugin HKU\.DEFAULT: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [No File]
FF Plugin HKU\.DEFAULT: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.adobe.xfdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [No File]
FF Plugin HKU\.DEFAULT: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [No File]
FF Plugin HKU\S-1-5-21-1072221882-492732373-972231997-1001: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [No File]
FF Plugin HKU\S-1-5-21-1072221882-492732373-972231997-1001: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.adobe.xfdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [No File]
FF Plugin HKU\S-1-5-21-1072221882-492732373-972231997-1001: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [No File]
CustomCLSID: HKU\S-1-5-21-1072221882-492732373-972231997-1001_Classes\CLSID\{14100442-9664-1407-2647-000000000000}\localserver32 -> "C:\Users\Windows10\AppData\Local\Wondershare\Wondershare NativePush\WsToastNotification.exe" -ToastActivated => No File
ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers1: [BtSendToMenuEx] -> {CF24E6B8-F148-4BCB-9108-ADF313966E80} => -> No File
BHO: No Name -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> No File
cmd: netsh winsock reset catalog
cmd: netsh int ip reset resetlog.txt
cmd: netsh advfirewall reset
cmd: netsh advfirewall set allprofiles state ON
cmd: bitsadmin /reset /allusers
cmd: ipconfig /flushdns
Removeproxy:
hosts:
Emptytemp:
End::
SearchAll: VideoProc;McAfee;Wondershare;Lavasoft
Edited by Oh My!, 28 April 2023 - 08:34 AM.
Posted 27 April 2023 - 08:13 PM
Hi. I dont remember using Cryptolocker. And the link for revouninstaller doesn't work. I'm getting "this site can't be reached"...is there another way of downloading it?
Posted 27 April 2023 - 08:21 PM
Posted 28 April 2023 - 02:53 AM
I was able to download the Revo uninstaller, but I clicked mistakenly on finish, instead of the SELECT ALL DELETE ... is there a way to delete the left overs of what I uninstalled?
Posted 28 April 2023 - 08:36 AM
Edited by Oh My!, 28 April 2023 - 08:36 AM.
Posted 29 April 2023 - 01:04 AM
Programs Uninstalled:
1. Web Companion
2. Web Advisor by McAfee
3. Battle.net
4. Can't remember the other one
Posted 29 April 2023 - 01:11 AM
Attached here is the search.txt
Thank you
Posted 29 April 2023 - 03:29 PM
Start::
CloseProcesses:
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\CLR_v2.0\UsageLogs\Lavasoft.WCAssistant.WinService.exe.log
C:\Windows\Prefetch\WINXVIDEOPROCCONVERTER5.5.0.E-1E8421BC.pf
C:\Windows\Prefetch\WONDERSHARE HELPER COMPACT.TM-01761C6D.pf
C:\Windows\Prefetch\WONDERSHARE NATIVEPUSH_14416_-B6140321.pf
C:\Windows\Prefetch\WONDERSHARE UNICONVERTER UPDA-5CF44B5D.pf
C:\Windows\Prefetch\WONDERSHARE UNICONVERTER UPDA-8CFA6282.pf
C:\Users\Windows10\AppData\Roaming\WebStorage\Logs\AWS-Wondershare Filmora9.txt
C:\Users\Windows10\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{6D809377-6AF0-444B-8957-A3773F02200E}_Wondershare_Wondershare Filmora Update_Wondershare Filmora Update_exe
C:\Users\Windows10\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}_VideoProc_VideoProcConverter_exe
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Profile 9\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.2609_0\mcafee_wa_crypto_learn.js
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Profile 9\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.2609_0\images\web_advisor\mcafee_brand.svg
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Profile 9\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.2609_0\images\web_advisor\mcafee_logo.svg
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Profile 9\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.2609_0\images\web_advisor\mcafee_slogan_white.svg
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Profile 9\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.2609_0\images\web_advisor\mcafee_webadvisor_logo.svg
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Profile 9\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.2609_0\images\web_advisor\white_mcafee_icon.svg
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Profile 9\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.2609_0\images\settings\mcafee-shield-pattern.svg
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Profile 9\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.2609_0\images\crypto\mcafee-white.png
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Profile 9\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.2609_0\images\advanced_protection_signals\mcafee-logo.svg
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Profile 9\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.2609_0\html\mcafee_wa_crypto_learn.html
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Profile 9\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.2609_0\css\mcafee_wa_crypto_learn.css
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Profile 18\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.3111_0\mcafee_wa_crypto_learn.js
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Profile 18\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.3111_0\sourceMap\mcafee_wa_crypto_learn.js.map
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Profile 18\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.3111_0\sourceMap\css\mcafee_wa_crypto_learn.css.map
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Profile 18\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.3111_0\images\web_advisor\mcafee_brand.svg
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Profile 18\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.3111_0\images\web_advisor\mcafee_logo.svg
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Profile 18\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.3111_0\images\web_advisor\mcafee_slogan_white.svg
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Profile 18\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.3111_0\images\web_advisor\mcafee_webadvisor_logo.svg
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Profile 18\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.3111_0\images\web_advisor\white_mcafee_icon.svg
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Profile 18\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.3111_0\images\settings\mcafee-shield-pattern.svg
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Profile 18\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.3111_0\images\crypto\mcafee-white.png
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Profile 18\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.3111_0\images\advanced_protection_signals\mcafee-logo.svg
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Profile 18\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.3111_0\html\mcafee_wa_crypto_learn.html
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Profile 18\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.3111_0\css\mcafee_wa_crypto_learn.css
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Profile 14\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.2647_0\mcafee_wa_crypto_learn.js
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Profile 14\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.2647_0\images\web_advisor\mcafee_brand.svg
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Profile 14\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.2647_0\images\web_advisor\mcafee_logo.svg
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Profile 14\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.2647_0\images\web_advisor\mcafee_slogan_white.svg
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Profile 14\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.2647_0\images\web_advisor\mcafee_webadvisor_logo.svg
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Profile 14\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.2647_0\images\web_advisor\white_mcafee_icon.svg
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Profile 14\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.2647_0\images\settings\mcafee-shield-pattern.svg
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Profile 14\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.2647_0\images\crypto\mcafee-white.png
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Profile 14\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.2647_0\images\advanced_protection_signals\mcafee-logo.svg
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Profile 14\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.2647_0\html\mcafee_wa_crypto_learn.html
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Profile 14\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.2647_0\css\mcafee_wa_crypto_learn.css
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Profile 13\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.2609_0\mcafee_wa_crypto_learn.js
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Profile 13\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.2609_0\images\web_advisor\mcafee_brand.svg
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Profile 13\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.2609_0\images\web_advisor\mcafee_logo.svg
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Profile 13\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.2609_0\images\web_advisor\mcafee_slogan_white.svg
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Profile 13\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.2609_0\images\web_advisor\mcafee_webadvisor_logo.svg
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Profile 13\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.2609_0\images\web_advisor\white_mcafee_icon.svg
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Profile 13\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.2609_0\images\settings\mcafee-shield-pattern.svg
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Profile 13\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.2609_0\images\crypto\mcafee-white.png
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Profile 13\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.2609_0\images\advanced_protection_signals\mcafee-logo.svg
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Profile 13\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.2609_0\html\mcafee_wa_crypto_learn.html
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Profile 13\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.2609_0\css\mcafee_wa_crypto_learn.css
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.3218_0\mcafee_wa_crypto_learn.js
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.3218_0\images\web_advisor\mcafee_brand.svg
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.3218_0\images\web_advisor\mcafee_logo.svg
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.3218_0\images\web_advisor\mcafee_slogan_white.svg
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.3218_0\images\web_advisor\mcafee_webadvisor_logo.svg
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.3218_0\images\web_advisor\white_mcafee_icon.svg
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.3218_0\images\settings\mcafee-shield-pattern.svg
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.3218_0\images\crypto\mcafee-white.png
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.3218_0\images\advanced_protection_signals\mcafee-logo.svg
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.3218_0\html\mcafee_wa_crypto_learn.html
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.3218_0\css\mcafee_wa_crypto_learn.css
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.3168_0\mcafee_wa_crypto_learn.js
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.3168_0\images\web_advisor\mcafee_brand.svg
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.3168_0\images\web_advisor\mcafee_logo.svg
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.3168_0\images\web_advisor\mcafee_slogan_white.svg
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.3168_0\images\web_advisor\mcafee_webadvisor_logo.svg
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.3168_0\images\web_advisor\white_mcafee_icon.svg
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.3168_0\images\settings\mcafee-shield-pattern.svg
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.3168_0\images\crypto\mcafee-white.png
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.3168_0\images\advanced_protection_signals\mcafee-logo.svg
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.3168_0\html\mcafee_wa_crypto_learn.html
C:\Users\Windows10\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\8.1.0.3168_0\css\mcafee_wa_crypto_learn.css
C:\ProgramData\Intel\ShaderCache\Wondershare Filmora X_0
C:\ProgramData\Intel\ShaderCache\Wondershare Filmora X_1
C:\ProgramData\Intel\ShaderCache\Wondershare Filmora9_0
C:\ProgramData\Intel\ShaderCache\Wondershare Filmora9_1
2016-04-20 10:50 - 2016-04-20 10:50 ____A C:\Windows\ASUS\oobeEula\Mcafee
2023-04-27 19:17 - 2023-04-27 19:18 _____ C:\Users\Windows10\Videos\VideoProc Converter
2023-04-27 19:17 - 2023-04-27 19:31 _____ C:\Users\Windows10\Pictures\VideoProc Converter
2023-04-27 19:17 - 2023-04-27 19:18 _____ C:\Users\Windows10\Music\VideoProc Converter
2016-08-26 14:19 - 2016-08-26 14:19 _____ C:\Users\Windows10\AppData\Roaming\Macromedia
2020-08-24 00:40 - 2023-04-18 01:02 _____ C:\Users\Windows10\AppData\Local\Wondershare
2022-01-29 16:03 - 2022-02-05 22:12 _____ C:\Users\Public\Documents\Wondershare
2016-04-20 10:47 - 2023-04-28 15:31 _____ C:\ProgramData\McAfee
2016-11-01 14:14 - 2016-11-01 14:14 _____ C:\Program Files (x86)\McAfee
2016-11-01 14:14 - 2016-11-01 14:14 _____ C:\Program Files (x86)\Common Files\McAfee
2016-11-01 14:14 - 2016-11-01 14:14 _____ C:\Program Files\Common Files\McAfee
2016-11-01 14:14 - 2016-11-01 14:14 _____ C:\Program Files\Common Files\AV\McAfee Anti-Virus And Anti-Spyware
2023-04-18 00:23 - 2023-04-18 00:38 _____ C:\FRST\Quarantine\C\Users\Windows10\AppData\Roaming\Wondershare
2023-04-27 19:06 - 2023-04-27 19:31 _____ C:\FRST\Quarantine\C\Users\Windows10\AppData\Roaming\Digiarty\VideoProc Converter
2020-08-24 00:42 - 2023-04-18 01:00 _____ C:\FRST\Quarantine\C\ProgramData\Wondershare
2022-02-05 21:59 - 2023-04-18 00:59 _____ C:\FRST\Quarantine\C\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare
2022-02-05 22:09 - 2022-02-05 22:09 _____ C:\FRST\Quarantine\C\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare\Wondershare Filmora Update
2023-04-27 19:04 - 2023-04-27 19:34 _____ C:\FRST\Quarantine\C\Program Files (x86)\VideoProc
2023-04-18 00:20 - 2023-04-18 01:00 _____ C:\FRST\Quarantine\C\Program Files\Wondershare
2016-04-20 10:00 - 2016-04-20 10:00 _____ C:\eSupport\eDriver\Software\McAFee
2016-04-20 10:00 - 2016-04-20 10:00 _____ C:\eSupport\eDriver\Software\McAFee\McAfee Internet Security
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{291EE2A7-BFA5-4e9e-A358-C93655556A6C}|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71F96464-78F3-11D0-A18C-00A0C9118956}|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C6E13360-30AC-11D0-A18C-00A0C9118956}|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AB0000C-FECE-4D1F-A2AC-A9573530656E}|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{291EE2A7-BFA5-4e9e-A358-C93655556A6C}|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{71F96464-78F3-11D0-A18C-00A0C9118956}|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{C6E13360-30AC-11D0-A18C-00A0C9118956}|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{6AB0000C-FECE-4D1F-A2AC-A9573530656E}|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{a4112d1a-6dfa-476e-bb75-e350d24934e1}\ChannelReferences\0|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{a4112d1a-6dfa-476e-bb75-e350d24934e1}\ChannelReferences\1|""
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\ExternalResources\BackgroundAudioPlayer|MultimediaVideoProcessor
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\ExternalResources\EmCreateProcess|MultimediaVideoProcessor
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\ExternalResources\ExtendedExecution|MultimediaVideoProcessor
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\ExternalResources\FileProviderTarget|MultimediaVideoProcessor
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\ExternalResources\Pausing|MultimediaVideoProcessor
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\ExternalResources\PPLE|MultimediaVideoProcessor
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\ExternalResources\ResourceIntensive|MultimediaVideoProcessor
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\ExternalResources\StandardExternalResources|MultimediaVideoProcessor
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\ExternalResources\UiExtended|MultimediaVideoProcessor
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\ExternalResources\VoipBackground|MultimediaVideoProcessor
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\ExternalResources\VoipCall|MultimediaVideoProcessor
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\ExternalResources\VoipLegacy|MultimediaVideoProcessor
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\ExternalResources\WebAuthSignIn|MultimediaVideoProcessor
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MediaInterfaces\{C6E13360-30AC-11d0-A18C-00A0C9118956}|""
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MediaSets\{C6E13360-30AC-11d0-A18C-00A0C9118956}\PropertyPages\{71F96464-78F3-11d0-A18C-00A0C9118956}|""
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-1072221882-492732373-972231997-1001|\Device\HarddiskVolume3\Program Files (x86)\VideoProc\VideoProcConverter.exe
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\702ca3b4_0|""
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppSwitched|{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\VideoProc\VideoProcConverter.exe
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\UFH\SHC|1
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|D:\Downloads\DeleteValue: FTUApps.com] - VideoProc Converter v5.5.0 Multilingual Pre-Activated\WinXVideoProcConverter5.5.0.exe
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Program Files (x86)\VideoProc\VideoProcConverter.exe
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{15AF52F6-E83C-4228-95FE-4407687CEFBF}\InprocServer32|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3C1CD4CD-9359-4A9D-A0FA-9E809E873CA6}\InprocServer32|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{590AB12E-F706-4BA8-9D08-A1EEC69A687D}\InProcServer32|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{84D248DA-52CD-442c-B6AE-28F143DB1E33}\InprocServer32|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D905F5A4-15B0-4B47-99D8-CE0230557148}\LocalServer32|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D905F5A4-15B0-4B47-99D8-CE0230557148}\LocalServer32|ServerExecutable
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DA32C9C5-1147-402A-A127-E0E169E9E9B4}\InprocServer32|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E782BE15-9936-4A7F-8DF9-9AB95D229DF1}\LocalServer32|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E782BE15-9936-4A7F-8DF9-9AB95D229DF1}\LocalServer32|ServerExecutable
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{309437E9-DE9F-4005-8C66-B1A74D6A23C2}\1.0\0\win64|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{309437E9-DE9F-4005-8C66-B1A74D6A23C2}\1.0\HELPDIR|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{75C34846-0EA8-41F7-90FD-55B2EC33C97F}\1.0|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{75C34846-0EA8-41F7-90FD-55B2EC33C97F}\1.0\0\win64|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{75C34846-0EA8-41F7-90FD-55B2EC33C97F}\1.0\HELPDIR|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{DCAEB2CC-5FB4-4BDA-A835-A7707130400C}\1.0\0\win64|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{DCAEB2CC-5FB4-4BDA-A835-A7707130400C}\1.0\HELPDIR|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{DDFB9D95-CC5A-455F-9800-361B7C9D1E7E}\1.0\0\win64|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{DDFB9D95-CC5A-455F-9800-361B7C9D1E7E}\1.0\HELPDIR|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{E3E78E39-3EA4-4E98-A185-999797E3EA0A}\1.0\0\win64|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{E3E78E39-3EA4-4E98-A185-999797E3EA0A}\1.0\HELPDIR|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{A95B959F-64A9-43E4-A874-C8A77905854A}\InprocServer32|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\NativeMessagingHosts\webadvisor.mcafee.chrome.extension|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McInst\InstallSettings|Install Dir
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\UPDMGR\InstallSettings|Install Dir
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Edge\NativeMessagingHosts\webadvisor.mcafee.chrome.extension|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DAABE21E-DB8C-49b8-9511-9E6547ECBC6F}|AppPath
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\StartupFolder|McAfee Security Scan Plus.lnk
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\NativeMessagingHosts\webadvisor.mcafee.chrome.extension|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Chrome\NativeMessagingHosts\webadvisor.mcafee.chrome.extension|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\McAfee\McInst\InstallSettings|Install Dir
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\McAfee\SharedModules\c:%progra~2%common~1%mcafee%instal~1%mcinst.exe|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\McAfee\UPDMGR\InstallSettings|Install Dir
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Edge\NativeMessagingHosts\webadvisor.mcafee.chrome.extension|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DAABE21E-DB8C-49b8-9511-9E6547ECBC6F}|AppPath
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Mozilla\NativeMessagingHosts\webadvisor.mcafee.chrome.extension|""
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\UserSettings\S-1-5-21-1072221882-492732373-972231997-1001|\Device\HarddiskVolume3\Program Files\McAfee Security Scan\3.11.1137\McUICnt.exe
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\DownloadManager\1235|owWPage
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\DownloadManager\499|owWPage
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppSwitched|{6D809377-6AF0-444B-8957-A3773F02200E}\McAfee\WebAdvisor\uihost.exe
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\ShowJumpView|{6D809377-6AF0-444B-8957-A3773F02200E}\McAfee\WebAdvisor\uihost.exe
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Search\RecentApps\{E563CFF8-2873-448B-956E-483A6CCDC71E}|AppPath
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Program Files\mcafee\msc\mcuihost.exe
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Program Files\McAfee Security Scan\3.11.681\McUICnt.exe
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Program Files\McAfee Security Scan\uninstall.exe
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Program Files\McAfee\WebAdvisor\uninstaller.exe
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Program Files\McAfee\WebAdvisor\uihost.exe.FriendlyAppName
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Program Files\McAfee\WebAdvisor\uihost.exe.ApplicationCompany
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4E962A61-DFC4-49B1-B7AE-91FBAFB7191C}\InprocServer32|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{564F2F1E-E001-41D2-8459-9C9B865CC6B0}\InprocServer32|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A43DE495-3D00-47d4-9D2C-303115707939}\LocalServer32|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AD83011E-01D1-4623-91FD-6B75F183C5A9}\InprocServer32|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{05C2CB2D-A42E-3709-81D5-67C9E7E1C1CF}\1.0.0.0|Class
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{05C2CB2D-A42E-3709-81D5-67C9E7E1C1CF}\1.0.0.0|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{123AFA2B-32E6-34D9-A628-601053277318}\1.0.0.0|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{28E2D8EC-DED8-3EEF-AEAF-3F3749C4F0E5}\1.0.0.0|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{2D424708-228B-37A1-9AAE-BE8A14A8D87F}\1.0.0.0|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{45698A01-851C-3937-B3FA-54E6EF05C89A}\1.0.0.0|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{48FB197F-66B3-33FA-9B2F-8E25240818B0}\1.0.0.0|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{4B904E63-C9F3-3725-8E1F-58B5BFE13A4E}\1.0.0.0|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{541FB261-F7D3-3C91-BAC9-49CE3F635D6A}\1.0.0.0|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{7625870B-CC1B-31E0-9DB2-60DB1E5BCB08}\1.0.0.0|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{8BB41A4A-C64C-328A-A80F-159BFE391EB4}\1.0.0.0|Class
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{8BB41A4A-C64C-328A-A80F-159BFE391EB4}\1.0.0.0|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{9181627E-CBB5-3401-8A57-163CF4276253}\1.0.0.0|Class
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{9181627E-CBB5-3401-8A57-163CF4276253}\1.0.0.0|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{9C49D7A2-5D77-39D3-ABF4-6772690D6A71}\1.0.0.0|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{9D314338-013A-3679-B7F9-D6FD2C1AD5A8}\1.0.0.0|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{A6E61D83-DC0F-3F2E-9AA1-BACC7CD056CF}\1.0.0.0|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{A8299CF1-2427-302E-9FC2-CF921D2216FE}\1.0.0.0|Class
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{A8299CF1-2427-302E-9FC2-CF921D2216FE}\1.0.0.0|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{AB80A9AC-684E-334C-A4D4-C1FDA22AFA40}\1.0.0.0|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{B171F5B4-0B1D-3EAC-ACB7-665F326E3652}\1.0.0.0|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{BD0A682A-3D52-3CBC-BC08-5F253F5A4CCE}\1.0.0.0|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{ECB43121-D1E0-30FF-9EED-684B265CD7A7}\1.0.0.0|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{F0C6C8C5-1048-3565-B31B-B7D0072CF745}\1.0.0.0|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{4171D4F1-18BA-4CF9-AFDA-AAC12C91BB44}\1.0\0\win32|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{4171D4F1-18BA-4CF9-AFDA-AAC12C91BB44}\1.0\HELPDIR|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{BA975139-E81E-415B-81E0-4F0A129172FC}\1.0\0\win64|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{BA975139-E81E-415B-81E0-4F0A129172FC}\1.0\HELPDIR|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C564F43A-83E2-41A9-8655-905AC1E13193}\1.0\0\win32|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C564F43A-83E2-41A9-8655-905AC1E13193}\1.0\HELPDIR|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C91DBF93-5FEB-4761-8E72-936C6118C6F6}\3.0\0\win32|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C91DBF93-5FEB-4761-8E72-936C6118C6F6}\3.0\HELPDIR|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D7C57A97-4CC2-439C-8D0B-D4700309225D}\1.0\0\win64|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D7C57A97-4CC2-439C-8D0B-D4700309225D}\1.0\HELPDIR|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D85C6069-D628-4276-93C3-9A94E5338D8B}\1.1\0\win32|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D85C6069-D628-4276-93C3-9A94E5338D8B}\1.1\HELPDIR|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\UniConverter14.AssocFile.USE\DefaultIcon|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\UniConverter14.AssocFile.USE\shell\open\command|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wondershare.Burner.BurnProgress|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wondershare.Burner.BurnProgressData|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wondershare.Burner.BurnSourceList|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wondershare.Burner.CDBurnCore|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wondershare.Burner.ConvertProgress|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wondershare.Burner.EraseProgress|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wondershare.Burner.RemoteMediaBurner|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{1CB5C1BD-2E68-3CD5-AD84-93D626300220}|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{1CB5C1BD-2E68-3CD5-AD84-93D626300220}\InprocServer32|Class
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{1CB5C1BD-2E68-3CD5-AD84-93D626300220}\InprocServer32|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{1CB5C1BD-2E68-3CD5-AD84-93D626300220}\InprocServer32\1.0.0.0|Class
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{1CB5C1BD-2E68-3CD5-AD84-93D626300220}\InprocServer32\1.0.0.0|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{1CB5C1BD-2E68-3CD5-AD84-93D626300220}\ProgId|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{27354123-7F64-5B0F-8F00-5D77AFBE261E}\InprocServer32|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{27354123-7F64-5B0F-8F00-5D77AFBE261E}\InprocServer32\1.0.0.0|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{2C941FC6-975B-59BE-A960-9A2A262853A5}\InprocServer32|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{2C941FC6-975B-59BE-A960-9A2A262853A5}\InprocServer32\1.0.0.0|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{2C941FC7-975B-59BE-A960-9A2A262853A5}\InprocServer32|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{2C941FC7-975B-59BE-A960-9A2A262853A5}\InprocServer32\1.0.0.0|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{2C941FC8-975B-59BE-A960-9A2A262853A5}\InprocServer32|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{2C941FC8-975B-59BE-A960-9A2A262853A5}\InprocServer32\1.0.0.0|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{2C941FC9-975B-59BE-A960-9A2A262853A5}\InprocServer32|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{2C941FC9-975B-59BE-A960-9A2A262853A5}\InprocServer32\1.0.0.0|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{2C941FCA-975B-59BE-A960-9A2A262853A5}\InprocServer32|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{2C941FCA-975B-59BE-A960-9A2A262853A5}\InprocServer32\1.0.0.0|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{2C941FCB-975B-59BE-A960-9A2A262853A5}\InprocServer32|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{2C941FCB-975B-59BE-A960-9A2A262853A5}\InprocServer32\1.0.0.0|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{2C941FCC-975B-59BE-A960-9A2A262853A5}\InprocServer32|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{2C941FCC-975B-59BE-A960-9A2A262853A5}\InprocServer32\1.0.0.0|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{476D46AF-0DCE-3362-B51B-98197FDCDBA9}|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{476D46AF-0DCE-3362-B51B-98197FDCDBA9}\InprocServer32|Class
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{476D46AF-0DCE-3362-B51B-98197FDCDBA9}\InprocServer32|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{476D46AF-0DCE-3362-B51B-98197FDCDBA9}\InprocServer32\1.0.0.0|Class
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{476D46AF-0DCE-3362-B51B-98197FDCDBA9}\InprocServer32\1.0.0.0|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{476D46AF-0DCE-3362-B51B-98197FDCDBA9}\ProgId|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{67F088BB-F178-3693-A443-130A0659EA3E}|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{67F088BB-F178-3693-A443-130A0659EA3E}\InprocServer32|Class
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{67F088BB-F178-3693-A443-130A0659EA3E}\InprocServer32|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{67F088BB-F178-3693-A443-130A0659EA3E}\InprocServer32\1.0.0.0|Class
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{67F088BB-F178-3693-A443-130A0659EA3E}\InprocServer32\1.0.0.0|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{67F088BB-F178-3693-A443-130A0659EA3E}\ProgId|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{B47D9895-FCDB-3B49-AEA9-76D3266605DF}|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{B47D9895-FCDB-3B49-AEA9-76D3266605DF}\InprocServer32|Class
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{B47D9895-FCDB-3B49-AEA9-76D3266605DF}\InprocServer32|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{B47D9895-FCDB-3B49-AEA9-76D3266605DF}\InprocServer32\1.0.0.0|Class
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{B47D9895-FCDB-3B49-AEA9-76D3266605DF}\InprocServer32\1.0.0.0|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{B47D9895-FCDB-3B49-AEA9-76D3266605DF}\ProgId|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{C3E5A776-669A-32B8-A8AE-651A059516DE}|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{C3E5A776-669A-32B8-A8AE-651A059516DE}\InprocServer32|Class
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{C3E5A776-669A-32B8-A8AE-651A059516DE}\InprocServer32|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{C3E5A776-669A-32B8-A8AE-651A059516DE}\InprocServer32\1.0.0.0|Class
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{C3E5A776-669A-32B8-A8AE-651A059516DE}\InprocServer32\1.0.0.0|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{C3E5A776-669A-32B8-A8AE-651A059516DE}\ProgId|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{D9026FCF-C95F-4445-A97E-C1846A7174AC}\LocalServer32|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{D9026FCF-C95F-4445-A97E-C1846A7174AC}\LocalServer32|ServerExecutable
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{DEF255FE-288E-48DE-ADA8-9B60D7ED7A38}|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{DEF255FE-288E-48DE-ADA8-9B60D7ED7A38}|LocalizedString
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{DEF255FE-288E-48DE-ADA8-9B60D7ED7A38}\LocalServer32|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{DEF255FE-288E-48DE-ADA8-9B60D7ED7A38}\ProgId|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{EE1B1EFE-DFEA-3FA2-AA4F-08D1BAE8BE84}|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{EE1B1EFE-DFEA-3FA2-AA4F-08D1BAE8BE84}\InprocServer32|Class
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{EE1B1EFE-DFEA-3FA2-AA4F-08D1BAE8BE84}\InprocServer32|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{EE1B1EFE-DFEA-3FA2-AA4F-08D1BAE8BE84}\InprocServer32\1.0.0.0|Class
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{EE1B1EFE-DFEA-3FA2-AA4F-08D1BAE8BE84}\InprocServer32\1.0.0.0|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{EE1B1EFE-DFEA-3FA2-AA4F-08D1BAE8BE84}\ProgId|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION|Wondershare Filmora9.exe
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION|Wondershare Filmora X.exe
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Wondershare|ExePath
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Wondershare\846|UninstallJumpPage
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Volatile\00\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{27354128-7F64-5B0F-8F00-5D77AFBE261E}\InprocServer32\1.0.0.0|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Volatile\00\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{27354129-7F64-5B0F-8F00-5D77AFBE261E}\InprocServer32\1.0.0.0|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Volatile\00\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{2735412A-7F64-5B0F-8F00-5D77AFBE261E}\InprocServer32\1.0.0.0|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Volatile\00\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{2735412B-7F64-5B0F-8F00-5D77AFBE261E}\InprocServer32\1.0.0.0|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Volatile\00\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{2735412C-7F64-5B0F-8F00-5D77AFBE261E}\InprocServer32\1.0.0.0|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Volatile\00\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{2735412D-7F64-5B0F-8F00-5D77AFBE261E}\InprocServer32\1.0.0.0|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Volatile\00\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{2735412E-7F64-5B0F-8F00-5D77AFBE261E}\InprocServer32\1.0.0.0|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Volatile\00\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{2C941FC5-975B-59BE-A960-9A2A262853A5}\InprocServer32\1.0.0.0|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Volatile\00\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{2C941FCE-975B-59BE-A960-9A2A262853A5}\InprocServer32\1.0.0.0|CodeBase
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Wondershare\Wondershare Helper Compact|DataLastRoom
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Wondershare\Wondershare Helper Compact|DataCurrentRoom
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\DirectInput\MostRecentApplication|Name
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\DirectInput\MostRecentApplication|Id
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\DirectInput\WONDERSHARE FILMORA X.EXE61A4CF40001B3920|Name
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\DirectInput\WONDERSHARE FILMORA X.EXE61AF0B25001B7520|Name
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\bb5841dc_0|""
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\f810f5d5_0|""
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppSwitched|{6D809377-6AF0-444B-8957-A3773F02200E}\Wondershare\Filmora9\Wondershare Filmora9.exe
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppSwitched|{6D809377-6AF0-444B-8957-A3773F02200E}\Wondershare\Filmora9\EffectsInstaller.exe
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppSwitched|C:\Users\Windows10\Downloads\Data\Wondershare Filmora\local\stubexe\0xC7FBA366B8307207\Wondershare Filmora X.exe
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppSwitched|{6D809377-6AF0-444B-8957-A3773F02200E}\Wondershare\Wondershare Filmora\Wondershare Filmora X.exe
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppSwitched|{6D809377-6AF0-444B-8957-A3773F02200E}\Wondershare\UniConverter 14\VCPlayer.exe
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\ShowJumpView|{6D809377-6AF0-444B-8957-A3773F02200E}\Wondershare\Filmora9\Wondershare Filmora9.exe
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4a\OpenWithList|e
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3\OpenWithList|i
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4\OpenWithList|c
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.webm\OpenWithList|c
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wfp\OpenWithList|a
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmv\OpenWithList|b
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|D:\Downloads\Wondershare Filmora 9.1.2.7 (x64) Multilingual Pre-Activated\Filmora.9.1.2.7\Filmora.v9.1.2.7.exe
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Program Files\Wondershare\Filmora9\Wondershare Filmora9.exe
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\unins000.exe
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Program Files\Wondershare\Filmora9\unins001.exe
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\Windows10\Downloads\Wondershare Filmora X 10.7.10.0 Portable\Filmora\Filmora\Wondershare Filmora X.exe
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\Windows10\Downloads\Wondershare Filmora X 10.7.10.0 Portable\Filmora\Filmora.exe
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\Windows10\Documents\Wondershare\Wondershare Filmora\Filmora.exe
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\Windows10\Downloads\Wondershare Filmora X 10.7.10.0 Portable\Filmora\Filmora\Filmora.exe
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\Windows10\Downloads\Wondershare Filmora X.exe
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|D:\Downloads\Wondershare Filmora X 10.1.21.0 incl activator DeleteValue: CrackingPatching]\filmora_64bit_full846.exe
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Program Files\Wondershare\Wondershare Filmora\unins000.exe
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|D:\Downloads\Wondershare UniConverter v14.1.15.171 (x64) + Fix {CracksHash}\Setup\uniconverter14_64bit_full14204.exe
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Program Files\Wondershare\UniConverter 14\VCPlayer.exe
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Program Files\Wondershare\UniConverter 14\unins000.exe
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\Windows10\AppData\Local\Wondershare\Wondershare NativePush\unins000.exe
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers|C:\Users\Windows10\Downloads\Wondershare Filmora X.exe
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Spoon\SandboxCache\3D407BEB9C5C172A\roaming\modified\@HKLM@\Software\Wondershare\846|UninstallJumpPage
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Wondershare\Wondershare Helper Compact|InstallPath
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Classes\AppUserModelId\Wondershare.NotificationApp|DisplayName
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Classes\AppUserModelId\Wondershare.NotificationApp|IconUri
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Program Files\Wondershare\Filmora9\Wondershare Filmora9.exe.FriendlyAppName
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Program Files\Wondershare\Filmora9\Wondershare Filmora9.exe.ApplicationCompany
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Program Files\Wondershare\UniConverter 14\VCPlayer.exe.FriendlyAppName
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Program Files\Wondershare\UniConverter 14\VCPlayer.exe.ApplicationCompany
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\UserSettings\S-1-5-21-1072221882-492732373-972231997-1001|\Device\HarddiskVolume3\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\DownloadManager\1579|FileName
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\DownloadManager\1579|Cookie
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\DownloadManager\1579|Url0
DeleteValue: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\DownloadManager\1579|U0_c
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications\VideoProcConverter.exe
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\MedaFoundationVideoProc
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\MedaFoundationVideoProcD3D
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\NativeMessagingHosts\webadvisor.mcafee.chrome.extension
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\mcafeeupdater
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Edge\NativeMessagingHosts\webadvisor.mcafee.chrome.extension
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\McAfee Trust
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\NativeMessagingHosts\webadvisor.mcafee.chrome.extension
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Chrome\NativeMessagingHosts\webadvisor.mcafee.chrome.extension
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\McAfee
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\McAfee\SharedModules\c:%progra~2%common~1%mcafee%instal~1%mcinst.exe
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\McAfee.com
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\mcafeeupdater
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Edge\NativeMessagingHosts\webadvisor.mcafee.chrome.extension
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\SystemCertificates\McAfee Trust
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Mozilla\NativeMessagingHosts\webadvisor.mcafee.chrome.extension
DeleteKey: HKEY_USERS\.DEFAULT\Software\McAfee
DeleteKey: HKEY_USERS\.DEFAULT\Software\Microsoft\SystemCertificates\McAfee Trust
DeleteKey: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\SystemCertificates\McAfee Trust
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wondershare.Burner.BurnProgress
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wondershare.Burner.BurnProgressData
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wondershare.Burner.BurnSourceList
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wondershare.Burner.CDBurnCore
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wondershare.Burner.ConvertProgress
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wondershare.Burner.EraseProgress
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wondershare.Burner.RemoteMediaBurner
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications\Wondershare Filmora X.exe
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications\Wondershare Filmora9.exe
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Wondershare
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Wondershare\Wondershare Helper Compact
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Wondershare
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Wondershare\Wondershare Filmora
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Wondershare\Wondershare Helper Compact
DeleteKey: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\BugSplat\wondershare_filmora_9_0_win
DeleteKey: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\BugSplat\wondershare_filmora_9_0_win\Wondershare Filmora 9.0
DeleteKey: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\BugSplat\wondershare_filmora_x_win
DeleteKey: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\BugSplat\wondershare_filmora_x_win\Wondershare Filmora X
DeleteKey: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\DirectInput\WONDERSHARE FILMORA X.EXE61A4CF40001B3920
DeleteKey: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\DirectInput\WONDERSHARE FILMORA X.EXE61AF0B25001B7520
DeleteKey: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\ConsentStore\microphone\NonPackaged\C:#Program Files#Wondershare#Filmora9#Wondershare Filmora9.exe
DeleteKey: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Spoon\SandboxCache\3D407BEB9C5C172A\roaming\modified\@HKLM@\Software\Wondershare
DeleteKey: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Wondershare
DeleteKey: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Wondershare\Wondershare Helper Compact
DeleteKey: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Classes\AppUserModelId\Wondershare.NotificationApp
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Lavasoft
DeleteKey: HKEY_USERS\S-1-5-21-1072221882-492732373-972231997-1001\SOFTWARE\Lavasoft
cmd: net stop bits
Move: C:\ProgramData\Microsoft\Network\Downloader\qmgr*.db C:\ProgramData\Microsoft\Network\Downloader\qmgr*.db.old
cmd: net start bits
cmd: bitsadmin /list /allusers
End::
Posted 29 April 2023 - 06:37 PM
Posted 29 April 2023 - 08:17 PM
Posted 30 April 2023 - 12:08 AM
i tried downloading eset unfortunately it crashes, it opens and closes after few seconds
0 members, 1 guests, 0 anonymous users