Ran by Traveller (23-02-2017 21:20:52) Run:1
Running from D:\FRST64
Loaded Profiles: Traveller (Available Profiles: Traveller & named)
Boot Mode: Normal
==============================================
fixlist content:
*****************
start
CloseProcesses:
CreateRestorePoint:
Emptytemp:
HKLM\...\StartupApproved\Run32: => "iTunesHelper"
HKLM\...\StartupApproved\Run32: => "QuickTime Task"
C:\Windows\system32\Drivers\etc\hosts
hosts:
HKU\.DEFAULT\Software\Classes\exefile: "%1" %* <===== ATTENTION
HKU\.DEFAULT\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRkrn => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRSVC => ""="Service"
AlternateDataStreams: C:\ProgramData\TEMP:41ADDB8A [131]
AlternateDataStreams: C:\ProgramData\TEMP:A064CECC [144]
AlternateDataStreams: C:\ProgramData\TEMP:B755D674 [194]
AlternateDataStreams: C:\ProgramData\TEMP
5FBE8F9 [157]
AlternateDataStreams: C:\Users\Public\DRM:احتضان [48]
AlternateDataStreams: C:\Users\Traveller\Desktop\Inner-Light.jpg:$CmdZnID [26]
AlternateDataStreams: C:\Users\Traveller\Downloads\Keygen-MESMERiZE.rar:$CmdTcID [64]
AlternateDataStreams: C:\Users\Traveller\Downloads\Keygen-MESMERiZE.rar:$CmdZnID [26]
AlternateDataStreams: C:\Users\Traveller\Downloads\pijano (mastered).mp3:$CmdTcID [64]
AlternateDataStreams: C:\Users\Traveller\Downloads\pijano (mastered).mp3:$CmdZnID [26]
AlternateDataStreams: C:\Users\Traveller\Downloads\pocket.crx:$CmdZnID [26]
AlternateDataStreams: C:\Users\Traveller\Downloads\Reset_antispam_0.3.1.7z:$CmdZnID [26]
AlternateDataStreams: C:\Users\Traveller\Downloads\rokcandy-2.0.1 (1).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Traveller\Downloads\root.crt:$CmdZnID [26]
AlternateDataStreams: C:\Users\Traveller\Downloads\root.der:$CmdZnID [26]
AlternateDataStreams: C:\Users\Traveller\Downloads\You Will Not Face This Alone.mp3:$CmdTcID [64]
AlternateDataStreams: C:\Users\Traveller\Downloads\You Will Not Face This Alone.mp3:$CmdZnID [26]
AlternateDataStreams: C:\Users\Traveller\Downloads\[kickass.so]hotline.miami.update.3.gog.torrent:$CmdZnID [26]
Shortcut: C:\Users\Traveller\Favorites\FileOptimizer Home Page.lnk -> hxxp://nikkhokkho.sourceforge.net/static.php?page=FileOptimize
Shortcut: C:\Users\Traveller\Favorites\NCH Software Download Site.lnk -> hxxp://
www.nch.com.au/index.htm
Shortcut: C:\Users\Traveller\Dropbox\Равиль\для меня.lnk -> C:\Users\
\Documents\для меня (No File) <===== Cyrillic
Shortcut: C:\Users\Traveller\Desktop\Домашняя бухгалтерия 5.lnk -> C:\Program Files (x86)\Keepsoft\HomeBuh5\HomeBuh5.exe (Keepsoft) <===== Cyrillic
Shortcut: C:\Users\Traveller\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Yamb 2.1.0.0 beta 2\Yamb - Website.lnk -> hxxp://yamb.unite-video.com
ShortcutWithArgument: C:\Users\Traveller\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\WorkFlowy.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=koegeopamaoljbmhnfjbclbocehhgmkm
ShortcutWithArgument: C:\Users\Traveller\AppData\Roaming\Microsoft\Internet Traveller\Quick Launch\User Pinned\ImplicitAppShortcuts\aeea6001c9fdcab9\Click&Clean.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=ghgabhipcejejjmhhchfonmamedcbeod
ShortcutWithArgument: C:\Users\Traveller\AppData\Roaming\Microsoft\Internet Traveller\Quick Launch\User Pinned\ImplicitAppShortcuts\a3a1d6b8109861c5\Hangouts.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=nckgahadagoaajjgafhacjanaoiihapd
ShortcutWithArgument: C:\Users\Traveller\AppData\Roaming\Microsoft\Internet Traveller\Quick Launch\User Pinned\ImplicitAppShortcuts\5a7f1fc1149619d6\Epic Privacy Browser.lnk -> C:\Users\Traveller\AppData\Local\Epic Privacy Browser\Application\epic.exe (Hidden Reflex) -> --profile-directory=Default
Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-925185676-1098965860-4220522822-1001UA.job => C:\Users\Traveller\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-925185676-1098965860-4220522822-1001Core.job => C:\Users\Traveller\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA1cf6986c118e050.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d0001d73c8b334.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-925185676-1098965860-4220522822-1001Core1cfd791cbe00d3.job => C:\Users\Traveller\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-925185676-1098965860-4220522822-1001Core1cfed3dadc0292f.job => C:\Users\Traveller\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-925185676-1098965860-4220522822-1001Core1cffedb14d73815.job => C:\Users\Traveller\AppData\Local\Google\Update\GoogleUpdate.exe
Task: {FCC01015-90D3-40BB-A7B7-FB8C342A9385} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-925185676-1098965860-4220522822-1001Core1d0411f110ceba0 => C:\Users\Traveller\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.)
Task: {CA479769-6B76-4C74-B358-67423E5E14AE} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2016-10-25] (NVIDIA Corporation)
Task: {D3E94B6F-E162-41ED-A78D-49068CC7ED23} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2016-10-25] (NVIDIA Corporation)
Task: {DAAEF8CA-94B0-46E6-94ED-FDC4B3E4AF4A} - System32\Tasks\{2F3CCF69-1646-4DB0-AFD2-72E35FF466E2} => Chrome.exe hxxp://ui.skype.com/ui/0/6.18.0.106/ru/abandoninstall?page=tsMain
Task: {DDB4C5BF-2FE1-41E1-8D6F-FE99673976A4} - System32\Tasks\{CA56EAE6-5E60-454F-8EE2-3825A791791D} => pcalua.exe -a C:\Users\Traveller\Downloads\Programs\CardReader_JMicron_W7_A01_TKH3F_ZPE.exe -d C:\Users\Traveller\AppData\Roaming\IDM
Task: {E050D551-CEF3-49EA-B469-70424D4A805A} - System32\Tasks\Opera scheduled Autoupdate 1408935599 => C:\Program Files (x86)\Opera\launcher.exe
Task: {E2DB1668-3E8B-457C-AF8E-95E39708C96A} - System32\Tasks\{2090741D-AF19-4C0D-987B-D5AD2CA171A4} => pcalua.exe -a "H:\Games\Teenage Mutant Ninja Turtles\TMNT.EXE" -d "H:\Games\Teenage Mutant Ninja Turtles"
Task: {91E9E3CA-F7D9-4D12-A30D-BB7ADA79C6DC} - System32\Tasks\Chameleon Startup Manager-Traveller => C:\Program Files (x86)\Chameleon Startup Manager\manager.exe [2015-02-10] (NeoSoft Tools)
Task: {92C88288-96C8-4FDF-A609-217497BFBEF9} - \Pointstone\System Cleaner\Log On Notice -> No File <==== ATTENTION
Task: {9822B3AD-B62E-42E8-8E38-EFEAEF22F1B2} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-925185676-1098965860-4220522822-1001UA => C:\Users\Traveller\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.)
Task: {9CBC36AC-65A1-4EE6-ADFE-AFF60472DD16} - System32\Tasks\Chameleon Monitor-startup-Traveller => c:\program files (x86)\common files\Chameleon Manager\monitor.exe [2015-02-10] (NeoSoft Tools)
Task: {A549169A-D962-4B64-81D2-C964B9449C9A} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2016-10-25] (NVIDIA Corporation)
Task: {4AC54D11-6DD2-4038-A5FF-94888CBDEE05} - System32\Tasks\Run RoboForm TaskBar Icon => D:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
Task: {5296151F-94E0-4363-BD38-3D32EB8820F6} - \{505A68B3-E825-4D29-AC08-B71CA2308CF5} -> No File <==== ATTENTION
Task: {5F4BF8A0-2FF1-467F-916B-CC2DAC8D72B1} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2016-10-25] (NVIDIA Corporation)
Task: {6A53FC7F-5F79-4FB4-8C68-579E7C847A2D} - System32\Tasks\{F5A09CDD-01AF-42BB-88BB-10471CCE6707} => pcalua.exe -a "C:\Program Files\ReviverSoft\Registry Reviver\Uninstall.exe"
Task: {7476B54B-CDB4-47A2-85FC-8F1BC37E7E33} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {7B81CF39-A304-40ED-B0FA-E97FCA106CC3} - System32\Tasks\Open URL by RoboForm => Rundll32.exe url.dll,FileProtocolHandler "hxxp://
www.roboform.com/uninstall.html?aaa=KICMHMKMJMPMGMNMNMKJCNMMNJNMOJCNLMOJGMOJCNGMLJKJMJCNJJJJOMJMKJLMGMJJLMJMOJMMJNJICMIMCNGMCNNMNMFMOMOMCNPMCNGMJMPMPMFMJMCNMMCNGMJMPMPMCNNMJNPICMHMFMFMOMPMJNHICMEKMICNJJCKJNBJCMLKNIOJJIKJDJDJKJNIJNKJCMJNNICMJNDJCMKJBJJNMJCMPMFMPMFM (the data entry has 35 more characters).
Task: {8033146A-54E7-453E-A3E9-FC0972A14F1A} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2016-10-25] (NVIDIA Corporation)
Task: {8D6A16C1-3BA2-4877-85C3-A3631C653532} - System32\Tasks\{A1D5D0E4-BB6C-4E3C-BD67-E5A8C0E74A2E} => pcalua.exe -a C:\Users\Traveller\Downloads\Programs\MDAC_TYP.EXE -d C:\Users\Traveller\AppData\Roaming\IDM
Task: {8EC5BF83-AC06-4190-A64A-4096E5BBCD19} - System32\Tasks\Nero\Nero Info => C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe [2015-06-04] (Nero AG)
Task: {3C7DF767-9E4B-4F3B-841D-95887E75AEFD} - \Pointstone\System Cleaner\Daily Notice -> No File <==== ATTENTION
Task: {43A17CBD-36AD-4BFB-B3C5-1FEF32E15681} - System32\Tasks\Red Giant Link => C:\Program Files\Red Giant Link\Red Giant Link.exe
Task: {4515A598-639B-489A-B22D-0FF6267D4734} - System32\Tasks\Norton AntiVirus\Norton Error Processor => C:\Program Files (x86)\Norton AntiVirus\Engine\22.6.0.142\SymErr.exe
Task: {00CE6CA9-7691-46ED-A32B-41B5D8052A0B} - System32\Tasks\Norton AntiVirus\Norton Error Analyzer => C:\Program Files (x86)\Norton AntiVirus\Engine\22.6.0.142\SymErr.exe
Task: {063A6DF0-D9DF-4D01-98C0-43B458DBC34F} - System32\Tasks\{36E7CDCE-3B01-4650-8948-AF254DEB073C} => pcalua.exe -a C:\Users\Traveller\Downloads\Programs\Shtrl4.exe -d C:\Users\Traveller\AppData\Roaming\IDM
Task: {0A4E987C-6912-497D-A2C5-DDC107B9467C} - System32\Tasks\AdobeAAMUpdater-1.0-MicrosoftAccount-ltwingtrust@hotmail.com => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2016-01-07] (Adobe Systems Incorporated)
Task: {0AC4904A-8372-4020-9BFF-55B687BCD936} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [2017-01-16] ()
Task: {0CB03F15-7BBF-4237-8FBB-FE6F3FA35FCD} - System32\Tasks\GoogleUpdateTaskMachineUA1cf6986c118e050 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {197671D1-207D-49D1-A944-E0D46AEF8027} - System32\Tasks\GoogleUpdateTaskMachineUA1d041918bdfa750 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {2409A78A-85F7-40FD-AD75-A78F381E4B62} - System32\Tasks\Chameleon Monitor-Traveller => c:\program files (x86)\common files\Chameleon Manager\monitor.exe [2015-02-10] (NeoSoft Tools)
Task: {2D04D24E-3525-4A26-A43D-33B1A0FF27BC} - System32\Tasks\GoogleUpdateTaskMachineUA1d0001d73c8b334 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
2017-01-25 21:59 - 2014-10-28 20:58 - 1040384 _____ (Microsoft Corporation) C:\Users\Traveller\AppData\Local\Temp\kernel32.dll
2017-02-02 03:56 - 2017-02-02 03:56 - 1066336 _____ (Microsoft Corporation) C:\Users\Traveller\AppData\Local\Temp\PidGenX.dll
C:\ProgramData\RegistryReviver.exe
2017-01-31 15:20 - 2017-01-31 15:20 - 0046951 _____ () C:\ProgramData\agent.1485894021.bdinstall.bin
2017-01-31 15:34 - 2017-01-31 15:34 - 0029177 _____ () C:\ProgramData\agent.1485894894.bdinstall.bin
2014-11-12 13:47 - 2017-01-07 23:48 - 0000043 _____ () C:\Users\Traveller\AppData\Local\~wmrg
2013-12-08 20:43 - 2015-02-18 03:30 - 0026624 _____ () C:\Users\Traveller\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-05-10 23:31 - 2015-03-01 20:06 - 0000010 _____ () C:\Users\Traveller\AppData\Local\.C3F2FH85-G3D2-2F02-D5CH-7D3D8C553E56
2015-03-20 13:48 - 2015-06-10 16:01 - 0000010 _____ () C:\Users\Traveller\AppData\Local\.DG212F11-EC8C-210D-DE1E-D9584D18D740
2015-09-13 17:11 - 2017-01-23 21:29 - 0000109 ___SH () C:\Users\Traveller\AppData\Local\00000128
2017-01-07 23:48 - 2014-11-12 13:47 - 00000043 _____ C:\Users\Traveller\AppData\Local\~wmrg
2017-01-12 20:06 - 2016-03-25 22:26 - 00000000 ____D C:\Users\Traveller\AppData\Roaming\qBittorrent
2017-01-18 02:51 - 2016-01-31 18:31 - 00003554 _____ C:\Windows\System32\Tasks\GarminUpdaterTask
2017-01-23 21:29 - 2015-09-13 17:11 - 00000109 ___SH C:\Users\Traveller\AppData\Local\00000128
2017-01-28 22:45 - 2016-07-06 10:47 - 00000000 ____D C:\ProgramData\WRData
2017-02-02 03:55 - 2013-12-09 02:12 - 00000000 ____D C:\Users\Traveller\AppData\Roaming\uTorrent
2017-02-02 17:25 - 2013-12-09 00:43 - 00000000 ____D C:\Windows\system32\MRT
2017-02-02 17:19 - 2013-12-09 00:43 - 135657872 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2017-02-03 16:17 - 2014-05-06 18:56 - 00000996 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA1cf6986c118e050.job
2017-02-03 15:40 - 2013-12-06 08:24 - 00003596 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-925185676-1098965860-4220522822-1001
2017-02-03 16:23 - 2013-12-22 10:56 - 00000000 ____D C:\ProgramData\TEMP
2017-02-03 16:22 - 2014-11-14 10:12 - 00000996 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d0001d73c8b334.job
2014-01-20 11:42 - 2015-11-25 00:49 - 0000132 _____ () C:\Users\Traveller\AppData\Roaming\Adobe BMP Format CC Prefs
2014-04-07 02:17 - 2014-04-07 02:17 - 0000132 _____ () C:\Users\Traveller\AppData\Roaming\Adobe GIF Format CC Prefs
2013-12-11 21:28 - 2015-11-03 00:53 - 0000132 _____ () C:\Users\Traveller\AppData\Roaming\Adobe PNG Format CC Prefs
2016-03-15 12:37 - 2017-01-24 14:30 - 0000034 _____ () C:\Users\Traveller\AppData\Roaming\AdobeWLCMCache.dat
2015-01-06 12:56 - 2013-07-22 03:59 - 0012005 _____ () C:\Users\Traveller\AppData\Roaming\alsoft.ini
2014-10-20 16:41 - 2014-10-31 23:06 - 0000268 ___RH () C:\Users\Traveller\AppData\Roaming\Ambience
2016-12-29 21:29 - 2016-12-29 21:29 - 0000003 _____ () C:\Users\Traveller\AppData\Roaming\CheckWinVer.log
2016-01-14 19:40 - 2016-04-02 10:04 - 0002044 _____ () C:\Users\Traveller\AppData\Roaming\droid4xinstaller.log
2016-04-28 15:56 - 2016-04-28 15:56 - 0347908 _____ () C:\Users\Traveller\AppData\Roaming\FontInfo.bin
2016-04-28 15:56 - 2016-04-28 15:56 - 0105744 _____ () C:\Users\Traveller\AppData\Roaming\GlyphInfo.bin
2015-03-20 14:21 - 2015-03-20 17:37 - 0576521 _____ () C:\Users\Traveller\AppData\Roaming\PS14_panel.log
2014-12-17 12:17 - 2014-12-17 12:17 - 0002114 _____ () C:\Users\Traveller\AppData\Roaming\SAS7_000.DAT
2013-12-09 08:33 - 2017-01-25 20:02 - 0000600 _____ () C:\Users\Traveller\AppData\Roaming\winscp.rnd
2015-08-10 11:58 - 2015-08-10 11:58 - 0038508 _____ () C:\Users\Traveller\AppData\Roaming\Значения, разделенные запятыми.ADR
2014-05-10 23:31 - 2015-03-01 20:06 - 0000010 _____ () C:\Users\Traveller\AppData\Local\.C3F2FH85-G3D2-2F02-D5CH-7D3D8C553E56
2015-03-20 13:48 - 2015-06-10 16:01 - 0000010 _____ () C:\Users\Traveller\AppData\Local\.DG212F11-EC8C-210D-DE1E-D9584D18D740
2015-09-13 17:11 - 2017-01-23 21:29 - 0000109 ___SH () C:\Users\Traveller\AppData\Local\00000128
2013-12-08 14:40 - 2013-12-12 18:22 - 144752885 _____ () C:\Users\Traveller\AppData\Local\ACCCx2_2_1_260.zip.aamdownload
2013-12-08 14:40 - 2013-12-12 18:22 - 0001817 _____ () C:\Users\Traveller\AppData\Local\ACCCx2_2_1_260.zip.aamdownload.aamd
2013-12-13 13:29 - 2017-01-30 22:00 - 0001456 _____ () C:\Users\Traveller\AppData\Local\Adobe Save for Web 13.0 Prefs
2013-12-08 20:43 - 2015-02-18 03:30 - 0026624 _____ () C:\Users\Traveller\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-01-30 19:03 - 2015-01-31 08:24 - 0342476 _____ () C:\Users\Traveller\AppData\Local\helpman.imc
2017-01-31 16:08 - 2017-01-31 16:08 - 0000036 _____ () C:\Users\Traveller\AppData\Local\housecall.guid.cache
2016-07-30 16:39 - 2016-07-30 16:39 - 0000001 _____ () C:\Users\Traveller\AppData\Local\llftool.4.40.agreement
2016-07-05 09:20 - 2017-01-31 18:38 - 0000600 _____ () C:\Users\Traveller\AppData\Local\PUTTY.RND
2015-12-04 08:42 - 2015-12-04 08:42 - 0000847 _____ () C:\Users\Traveller\AppData\Local\recently-used.xbel
2014-06-22 23:21 - 2016-10-13 13:36 - 0007583 _____ () C:\Users\Traveller\AppData\Local\Resmon.ResmonCfg
2017-01-31 17:31 - 2017-02-01 19:13 - 0000010 _____ () C:\Users\Traveller\AppData\Local\sponge.last.runtime.cache
2014-11-12 13:47 - 2017-01-07 23:48 - 0000043 _____ () C:\Users\Traveller\AppData\Local\~wmrg
2017-01-31 15:20 - 2017-01-31 15:20 - 0046951 _____ () C:\ProgramData\agent.1485894021.bdinstall.bin
2017-01-31 15:34 - 2017-01-31 15:34 - 0029177 _____ () C:\ProgramData\agent.1485894894.bdinstall.bin
2017-01-18 22:06 - 2017-01-18 22:06 - 00002652 _____ C:\Users\Traveller\AppData\LocalLow\wbkD99A.tmp
2017-01-31 16:26 - 2017-02-01 08:25 - 00407608 _____ (Trend Micro Inc.) C:\Windows\RegBootClean64.exe
2017-01-31 16:09 - 2017-02-01 21:18 - 00000000 ____D C:\ProgramData\Trend Micro
2017-01-31 16:08 - 2017-01-31 16:08 - 00000036 _____ C:\Users\Traveller\AppData\Local\housecall.guid.cache
2017-01-31 16:03 - 2017-01-31 16:06 - 145050392 _____ (Trend Micro Inc.) C:\Users\Public\Desktop\Trend_Micro.exe
2017-01-31 15:34 - 2017-01-31 15:34 - 00029177 _____ C:\ProgramData\agent.1485894894.bdinstall.bin
2017-01-31 15:20 - 2017-01-31 15:20 - 00046951 _____ C:\ProgramData\agent.1485894021.bdinstall.bin
2017-02-01 17:12 - 2017-02-01 21:18 - 00000000 ____D C:\Users\Traveller\AppData\Local\Trend Micro
U3 DfSdkS; no ImagePath
S4 nvvad_WaveExtensible; \SystemRoot\system32\drivers\nvvad64v.sys [X]
U0 SR; no ImagePath
U2 srservice; no ImagePath
S3 vpnva; \SystemRoot\system32\DRIVERS\vpnva64-6.sys [X]
S3 RTCore64; no ImagePath
S3 NAVENG; no ImagePath
S3 NAVEX15; no ImagePath
S3 DIRECTIO; no ImagePath
CHR HKLM-x32\...\Chrome\Extension: [pkijdmeepjhpenmighhaodgfoogncnlk] - <no Path/update_url>
CHR HKLM-x32\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ngkhgikojglcgnckopipfdajaifmmnnc] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx
CHR Extension: (YSlow) - C:\Users\Traveller\AppData\Local\Google\Chrome\User Data\Default\Extensions\ninejjcohidippngpapiilnmkgllmakh [2016-10-18]
CHR Extension: (Autofill) - C:\Users\Traveller\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlmmgnhgdeffjkdckmikfpnddkbbfkkk [2017-01-04]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Traveller\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-01-18]
CHR Extension: (COPY URL) - C:\Users\Traveller\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkhnbhdofgaendegcgbmndipmijhbili [2016-03-29]
CHR Extension: (YouTube) - C:\Users\Traveller\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-24]
CHR Extension: (Google Search) - C:\Users\Traveller\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-28]
FF Plugin ProgramFiles/Appdata: C:\Users\Traveller\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\Traveller\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-12-08] (Google)
FF Plugin HKU\S-1-5-21-925185676-1098965860-4220522822-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Traveller\AppData\Local\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin HKU\S-1-5-21-925185676-1098965860-4220522822-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Traveller\AppData\Local\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin HKU\S-1-5-21-925185676-1098965860-4220522822-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Traveller\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-02-24] (Unity Technologies ApS)
FF Plugin-x32: @wacom.com/wtPlugin,version=2.1.0.7 -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2016-02-12] (Adobe Systems)
FF Plugin-x32: wacom.com/WacomTabletPlugin -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin HKU\S-1-5-21-925185676-1098965860-4220522822-1001: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Traveller\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll
FF NetworkProxy: Mozilla\Firefox\Profiles\sxpbrh0x.default -> autoconfig_url", "data:text/javascript,function FindProxyForURL(url, host) {if ((host == \"
www.abc.net.au\")
(host == \"iview.abc.net.au\")
(host == \"iviewmetered-vh.akamaihd.net\")
(url.indexOf(\"proxmate=au\") != -1)
(host == \"livestream.com\")
(host == \"
www.livestream.com\")
(host == \"api.new.livestream.com\")
(host == \"player.ooyala.com\")
(host == \"xnewsvidhd-vh.akamaihd.net\")
(host == \"
www.animelab.com\")
(host == \"dcgm6i50yfgtk.cloudfront.net\")) { return 'PROXY au-node.proxmate.me:8008' } else if ((url.indexOf(\"proxmate=ca\") != -1)
(host == \"ici.tou.tv\")
(host == \"toutvuniver1-vh.akamaihd.net\")
(host == \"geoip.radio-canada.ca\")
(host == \"api.radio-canada.ca\")
(host == \"images.tou.tv\")
(host == \"player.siriusxm.ca\")
(host == \"primary.hls-streaming.production.streaming.siriusxm.ca\")
(host == \"now.sportsnet.ca\")
(host == \"watch.sportsnet.ca\")
(host == \"player.9c9media.com\")
(host == \"metrics.ctv.ca\")
(host == \"capi.9c9media.com\")
(host == \"
www.ctv.ca\")
(host == \"
www.willow.tv\")
(host == \"willowtv.live-s.cdn.bitgravity.com\")) { return 'PROXY ca-node.proxmate.me:8008' } else if ((host == \"arte.tv\")
(host == \"
www.arte.tv\")
(host == \"geoftv-a.akamaihd.net\")
(host == \"hdfauthftv-a.akamaihd.net\")
(host == \"replayftv-vh.akamaihd.net\")
(host == \"ftvingest-vh.akamaihd.net\")
(host == \"live.francetv.fr\")
(host == \"d8.tv\")
(host == \"
www.d8.tv\")
(host == \"us-cplus-aka.canal-plus.com\")
(host == \"hds_live_d8_aka-lh.akamaihd.net\")
(host == \"d17.tv\")
(host == \"
www.d17.tv\")
(host == \"hds_live_d17_aka-lh.akamaihd.net\")
(url.indexOf(\"proxmate=fr\") != -1)
(host == \"
www.6play.fr\")
(host == \"geo.6cloud.fr\")
(host == \"proxy-021.dc3.dailymotion.com\")
(host == \"proxy-67.dailymotion.com\")
(host == \"prof.estat.com\")
(host == \"metrics.dailymotion.com\")
(host == \"
www.dailymotion.com\")
(host == \"vmap.snappytv.com\")) { return 'PROXY fr-node.proxmate.me:8008' } else if ((host == \"vod-akamai-psd-hds.p7s1digital.de\")
(host == \"vas.sim-technik.de\")
(url.indexOf(\"proxmate=de\") != -1)
(host == \"nightclub.de\")
(host == \"zdf.de\")
(host == \"
www.zdf.de\")
(host == \"zdf_hds_de-f.akamaihd.net\")
(host == \"api.nowtv.de\")
(host == \"delivestream-lh.akamaihd.net\")
(host == \"cdnapi.kaltura.com\")
(host == \"disneychannel.de\")
(host == \"
www.southpark.de\")) { return 'PROXY de-node.proxmate.me:8008' } else if ((host == \"
www.tg4.ie\")
(url.indexOf(\"proxmate=ie\") != -1)) { return 'PROXY ie-node.proxmate.me:8008' } else if ((host == \"rai.tv\")
(host == \"
www.rai.tv\")
(host == \"mediapolis.rai.it\")
(host == \"
www.rai.it\")
(host == \"stream5.rai.it\")
(host == \"stream6.rai.it\")
(host == \"stream7.rai.it\")
(host == \"sspushrai1-s.akamaihd.net\")
(host == \"sspushrai2-s.akamaihd.net\")
(host == \"sspushraisport2-s.akamaihd.net\")
(host == \"sspushrai3-s.akamaihd.net\")
(host == \"secondary.adaptiveedge.rai.it\")
(host == \"rai-italia01.wt-eu02.net\")
(host == \"download.rai.tv\")
(host == \"mediapolisvod.rai.it\")
(host == \"ww.rai.tv\")
(host == \".xuniplay.fdnames.com\")
(url.indexOf(\"xuniplay.fdnames.com\") != -1)
(host == \"se-to1-8.se.live3.msf.ticdn.it\")
(host == \"live.shinystat.com\")
(host == \"lic.mediaset.net\")
(host == \"cssr.video.mediaset.it\")
(url.indexOf(\"proxmate=it\") != -1)
(host == \"
www.vvvvid.it\")) { return 'PROXY it-node.proxmate.me:8008' } else if ((host == \"telecinco.es\")
(host == \"telecinco1-vh.akamaihd.net\")
(host == \"
www.telecinco.es\")
(url.indexOf(\"proxmate=es\") != -1)
(host == \"antena3.com\")
(host == \"
www.antena3.com\")
(host == \"geodesprogresiva.antena3.com\")
(host == \"rtve.es\")
(host == \"
www.rtve.es\")
(host == \"ztnr.rtve.es\")
(host == \"mvodt.lvlt.rtve.es\")
(host == \"swf.rtve.es\")
(host == \"cuatro.com\")
(host == \"
www.cuatro.com\")
(host == \"cuatro1-vh.akamaihd.net\")
(host == \"peliculas-online.atresplayer.com\")
(host == \"servicios.atresplayer.com\")
(host == \"atresplayer.com\")
(host == \"
www.atresplayer.com\")
(host == \"k.uecdn.es\")
(host == \"v.uecdn.es\")
(host == \"as.com\")
(host == \"ep00.epimg.net\")
(host == \"futbol.as.com\")) { return 'PROXY es-node.proxmate.me:8008' } else if ((host == \"prosieben.ch\")
(host == \"
www.prosieben.ch\")
(host == \"s1tv.ch\")
(host == \"
www.s1tv.ch\")
(host == \"zba2-0-hds-live.zahs.tv\")
(host == \"embed-zattoo.com\")
(host == \"chtv.ch\")
(host == \"
www.chtv.ch\")
(host == \"zba2-1-hds-live.zahs.tv\")
(host == \"sat1.ch\")
(host == \"
www.sat1.ch\")
(host == \"rsi.ch\")
(host == \"
www.rsi.ch\")
(host == \"codch-vh.akamaihd.net\")
(host == \"il.srgssr.ch\")
(host == \"ch.viva.tv\")
(host == \"intl.esperanto.mtvi.com\")
(url.indexOf(\"proxmate=ch\") != -1)
(host == \"zattoo.com\")
(host == \"
www.srf.ch\")
(host == \"srgssruni1ch-lh.akamaihd.net\")
(host == \"srgssruni2ch-lh.akamaihd.net\")
(host == \"srgssruni3ch-lh.akamaihd.net\")
(host == \"
www.teleboy.ch\")
(host == \"aka-cdn-ns.adtech.de\")
(host == \"teleboy.customers.cdn.iptv.ch\")) { return 'PROXY ch-node.proxmate.me:8008' } else if ((host == \"c.brightcove.com\")
(host == \"secure.brightcove.com\")
(host == \"metrics.brightcove.com\")
(host == \"stv-ak.cds1.yospace.com\")
(host == \"core.stvfiles.com\")
(host == \"player.stv.tv\")
(host == \"stv.brightcove.com.edgesuite.net\")
(host == \"uk-dev-stv.cdn.videoplaza.tv\")
(host == \"mercury.itv.com\")
(host == \"
www.itv.com\")
(host == \"itv.com\")
(host == \"llnw.live.btv.simplestream.com\")
(host == \"players.simplestream.com\")
(host == \"uapi.simplestream.com\")
(host == \"channel5.com\")
(host == \"wwwcdn.channel5.com\")
(host == \"cassie.channel5.com\")
(host == \"player.channel5.com\")
(host == \"deliver-hls.channel5.com\")
(host == \"akahls.channel5.com\")
(host == \"llnwhls.channel5.com\")
(host == \"milkshake.tv\")
(host == \"
www.milkshake.tv\")
(host == \"trk-euwest.tidaltv.com\")
(host == \"mp.adverts.itv.com\")
(host == \"req.tidaltv.com\")
(host == \"s1.2mdn.net\")
(host == \"pes.itv.com\")
(host == \"ned.itv.com\")
(host == \"itvdotcom.2cnt.net\")
(host == \"tom.itv.com\")
(host == \"dave.uktv.co.uk\")
(host == \"uktvplay.uktv.co.uk\")
(host == \"uktvhdse.brightcove.com.edgesuite.net\")
(host == \"admin.brightcove.com\")
(host == \"really.uktv.co.uk\")
(host == \"yesterday.uktv.co.uk\")
(host == \"drama.uktv.co.uk\")
(host == \"live.tvplayer.com\")
(host == \"tvplayer.com\")
(host == \"sapi.tvplayer.com\")
(host == \"api.tvplayer.com\")
(host == \"
www.gamefront.com\")
(url.indexOf(\"proxmate=uk\") != -1)
(host == \"channel4.com\")
(host == \"ais.channel4.com\")
(host == \"pandr.my.channel4.com\")
(host == \"all4nav.channel4.com\")
(host == \"4id.channel4.com\")) { return 'PROXY uk-node.proxmate.me:8008' } else if ((host == \"link.theplatform.com\")
(host == \"discidevflash-f.akamaihd.net\")
(host == \"api.geoip.dp.discovery.com\")
(host == \"vidtech.cbsinteractive.com\")
(host == \"vidtech.cbsima.com\")
(host == \"om.cbsi.com\")
(host == \"media.mtvnservices.com\")
(host == \"api-manga.crunchyroll.com\")
(host == \"crunchyroll.com\")
(host == \"
www.crunchyroll.com\")
(host == \"cdn.wwtv.warnerbros.com\")
(host == \"hlsioscwtv.warnerbros.com\")
(host == \"media.cwtv.com\")
(host == \"servicesaetn-a.akamaihd.net\")
(host == \"live.mlssoccer.com\")
(host == \"tvewnbc-i.akamaihd.net\")
(host == \"tvenbceast-i.akamaihd.net\")
(host == \"nbcmpx-vh.akamaihd.net\")
(host == \"
www.pandora.com\")
(host == \"video.pbs.org\")
(host == \"ga.video.cdn.pbs.org\")
(host == \"urs.pbs.org\")
(host == \"play.spotify.com\")
(host == \"
www.spotify.com\")
(host == \"play.spotify.edgekey.net\")
(host == \"
www.iheart.com\")
(host == \"api2.iheart.com\")
(host == \"api.iheart.com\")
(host == \"iheart.com\")
(host == \"nick.mtvnimages.com\")
(host == \"sni-vh.akamaihd.net\")
(url.indexOf(\"proxmate=us\") != -1)
(url.indexOf(\".googlevideo.com\") != -1)
(host == \"api.segment.io\")
(host == \"
www.vevo.com\")
(host == \"vevo.com\")
(host == \"apiv2.vevo.com\")
(host == \"songza.com\")
(host == \"new.songza.com\")
(host == \"
www.daisuki.net\")
(host == \"bngn-vh.akamaihd.net\")
(host == \"bngnwww.b-ch.com\")
(host == \"
www.hbogo.com\")
(host == \"catalog.lv3.hbogo.com\")
(host == \"profile.lv3.hbogo.com\")
(host == \"profile.hbogo.com\")
(url.indexOf(\".lv3.hbogo.com\") != -1)
(host == \"register.hbogo.com\")
(host == \"play.hbogo.com\")
(host == \"smetrics.hbogo.com\")
(url.indexOf(\".lv3.cdn.hbo.com\") != -1)
(host == \"comet.api.hbo.com\")
(host == \"play.google.com\")
(host == \"checkout.google.com\")
(host == \"store.google.com\")
(host == \"apis.google.com\")
(host == \"amc350888def-vh.akamaihd.net\")
(host == \"a564avoddashnsus-a.akamaihd.net\")
(host == \"atv-ps.amazon.com\")
(host == \"
www.amazon.com\")
(host == \"amazon.com\")
(host == \"fls-na.amazon.com\")
(host == \"phds-vod.cdn.turner.com\")
(host == \"token.vgtf.net\")
(host == \"
www.ondemandkorea.com\")
(host == \"
www.fxnetworks.com\")
(host == \"fxvcms-f.akamaihd.net\")
(host == \"tvetelemundo-vh.akamaihd.net\")
(host == \"feed.theplatform.com\")
(host == \"fsvideohds-vh.akamaihd.net\")
(host == \"watchable.com\")
(host == \"cilhlsvod-f.akamaihd.net\")
(host == \"oxygenvod-vh.akamaihd.net\")
(host == \"tvesyfy-vh.akamaihd.net\")
(host == \"
www.smithsonianchannel.com\")
(host == \"c.brightcove.com\")
(host == \"brightcove01.brightcove.com\")
(host == \"edge.api.brightcove.com\")
(host == \"
www.eonline.com\")
(host == \"link.theplatform.com\")
(host == \"api.listenlive.co\")
(host == \"playerservices.streamtheworld.com\")
(host == \"player.listenlive.co\")
(url.indexOf(\"live.streamtheworld.com\") != -1)
(host == \"
www.cartoonnetwork.com\")
(host == \"
www.viki.com\")
(host == \"\\\"
www.viki.com\")
(host == \"
www.origin.com\")
(host == \"ht.cdn.turner.com\")
(host == \"aolvideoshd-vh.akamaihd.net\")
(host == \"syn.5min.com\")
(host == \"stvideos.5min.com\")
(host == \"
www.showtime.com\")
(host == \"secure.showtime.com\")
(url.indexOf(\".vgtf.net\") != -1)
(host == \"phds-live.cdn.turner.com\")
(host == \"api.amplitude.com\")
(host == \"order.rhapsody.com\")
(host == \"payment.rhapsody.com\")
(host == \"
www.pivot.tv\")
(host == \"js.maxmind.com\")
(host == \"shonenjump.viz.com\")) { return 'PROXY us-node.proxmate.me:8008' } else if ((host == \"livestreams.omroep.nl\")
(host == \".npostreaming.nl\")
(host == \"ida.omroep.nl\")
(host == \"npoplayer.omroep.nl\")
(host == \"
www.zapp.nl\")
(host == \"tellerapi.omroep.nl\")
(host == \"e.omroep.nl\")
(url.indexOf(\"proxmate=nl\") != -1)) { return 'PROXY nl-node.proxmate.me:8008' } else if ((host == \"tvthek.orf.at\")
(host == \"apasfiisl.apa.at\")
(host == \"orf.oewabox.at\")
(host == \"194.232.200.58\")
(host == \"185.85.28.1\")
(host == \"atvplus.oewabox.at\")
(host == \"cdn.atv.at\")
(url.indexOf(\"proxmate=at\") != -1)
(host == \"hdsvodsportsman-vh.akamaihd.net\")
(host == \"streamaccess.unas.tv\")
(host == \"
www.laola1.tv\")
(host == \"
www.livestation.com\")
(host == \"livestation.com\")
(url.indexOf(\".emigrantas.tv\") != -1)) { return 'PROXY at-node.proxmate.me:8008' } else if ((host == \"netflix.com\")
(host == \"
www.netflix.com\")
(host == \"cbp-us.nccp.netflix.com\")
(host == \"secure.netflix.com\")
(host == \"api-global.netflix.com\")
(host == \"ichnaea.netflix.com\")
(host == \"customerevents.netflix.com\")
(host == \"s.thebrighttag.com\")) { return 'PROXY usnet-node.proxmate.me:8008' } else if ((host == \"s.hulu.com\")
(host == \"
www.funimation.com\")
(host == \"wpc.8c48.edgecastcdn.net\")
(host == \"southpark.cc.com\")
(host == \"api.utils.watchabc.go.com\")
(host == \"
www.dramafever.com\")
(host == \"
www.logotv.com\")
(host == \"api.watchabc.go.com\")
(host == \"theanimenetwork.com\")
(host == \"huluim.com\")
(host == \"
www.hulu.com\")
(host == \"t2.hulu.com\")
(host == \"urlcheck.hulu.com\")
(host == \"t.hulu.com\")
(host == \"s.hulu.com\")
(host == \"play.hulu.com\")
(host == \"t2.huluim.com\")) { return 'PROXY ush-node.proxmate.me:8008' } else if ((host == \"player.ooyala.com\")
(host == \"l.ooyala.com\")) { return 'PROXY auv-node.proxmate.me:8008' } else if ((host == \"web-api-us.crackle.com\")
(host == \"legacyweb-us.crackle.com\")) { return 'PROXY us2-node.proxmate.me:8008' } else if ((host == \"counter.yadro.ru\")
(host == \"turbik.tv\")
(host == \"player.rutv.ru\")
(host == \"api.rutv.ru\")
(host == \"cdnng.v.rtr-vesti.ru\")
(host == \"player.vgtrk.com\")
(url.indexOf(\"proxmate=ru\") != -1)
(host == \"stream.1tv.ru\")
(host == \"mobdrm.1tv.ru\")) { return 'PROXY ru-node.proxmate.me:8008' } else if ((host == \"security.video.globo.com\")
(host == \"api.globovideos.com\")
(host == \"s.videos.globo.com\")
(host == \"gshow.globo.com\")
(host == \"voddownload02.video.globo.com\")
(host == \"secure.nuuvem.com\")
(host == \"webportal.nowonline.com.br\")) { return 'PROXY br-node.proxmate.me:8008' } else if ((host == \"
www.bbc.co.uk\")
(host == \"open.live.bbc.co.uk\")
(host == \"fig.bbc.co.uk\")
(host == \"vod-hds-uk-live.edgesuite.net\")
(host == \"vod-hds-uk-live.bbcfmt.vo.llnwd.net\")
(host == \"vs-hds-uk-live.bbcfmt.vo.llnwd.net\")
(host == \"vs-hds-uk-live.edgesuite.net\")
(host == \"bbc.co.uk\")) { return 'PROXY ukb-node.proxmate.me:8008' } else { return 'DIRECT'; }}"
FF NetworkProxy: Mozilla\Firefox\Profiles\sxpbrh0x.default -> backup.ftp", "120.203.162.87"
FF NetworkProxy: Mozilla\Firefox\Profiles\sxpbrh0x.default -> backup.ftp_port", 8123
FF NetworkProxy: Mozilla\Firefox\Profiles\sxpbrh0x.default -> backup.socks", "120.203.162.87"
FF NetworkProxy: Mozilla\Firefox\Profiles\sxpbrh0x.default -> backup.socks_port", 8123
FF NetworkProxy: Mozilla\Firefox\Profiles\sxpbrh0x.default -> backup.ssl", "120.203.162.87"
FF NetworkProxy: Mozilla\Firefox\Profiles\sxpbrh0x.default -> backup.ssl_port", 8123
FF NetworkProxy: Mozilla\Firefox\Profiles\sxpbrh0x.default -> ftp", "185.127.164.20"
FF NetworkProxy: Mozilla\Firefox\Profiles\sxpbrh0x.default -> ftp_port", 443
FF NetworkProxy: Mozilla\Firefox\Profiles\sxpbrh0x.default -> http", "185.127.164.20"
FF NetworkProxy: Mozilla\Firefox\Profiles\sxpbrh0x.default -> http_port", 443
FF NetworkProxy: Mozilla\Firefox\Profiles\sxpbrh0x.default -> network.proxy.socks_remote_dns", 1
FF NetworkProxy: Mozilla\Firefox\Profiles\sxpbrh0x.default -> share_proxy_settings", true
FF NetworkProxy: Mozilla\Firefox\Profiles\sxpbrh0x.default -> socks", "185.127.164.20"
FF NetworkProxy: Mozilla\Firefox\Profiles\sxpbrh0x.default -> socks_port", 443
FF NetworkProxy: Mozilla\Firefox\Profiles\sxpbrh0x.default -> ssl", "185.127.164.20"
FF NetworkProxy: Mozilla\Firefox\Profiles\sxpbrh0x.default -> ssl_port", 443
FF NetworkProxy: Mozilla\Firefox\Profiles\sxpbrh0x.default -> type", 1
Handler: tmtbim - {0B37915C-8B98-4B9E-80D4-464D2C830D10} - D:\Program Files\Trend Micro\Titanium\UIFramework\ProToolbarIMRatingActiveX.dll No File
Toolbar: HKLM - Webroot Toolbar - {97ab88ef-346b-4179-a0b1-7445896547a5} - No File
Toolbar: HKLM-x32 - PDFXChange 2012 IE Plugin - {42DFA04F-0F16-418e-B80C-AB97A5AFAD3A} - C:\Program Files\Tracker Software\PDF-XChange 5\PXCIEAddin5.dll [2013-11-08] (Tracker Software Products (Canada) Ltd.)
Toolbar: HKLM-x32 - Webroot Toolbar - {97ab88ef-346b-4179-a0b1-7445896547a5} - No File
BHO-x32: Webroot Vault -> {c8d5d964-2be8-4c5b-8cf5-6e975aa88504} -> No File
HKLM\SOFTWARE\Policies\Microsoft\Internet Traveller: Restriction <======= ATTENTION
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\SOFTWARE\Policies\Microsoft\Internet Traveller: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Traveller\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Traveller\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Traveller\Main,Search Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Traveller\Main,Search Page =
HKLM\Software\Microsoft\Internet Traveller\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Traveller\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Traveller\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Traveller\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Traveller\Main,Local Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Traveller\Main,Local Page =
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\Software\Microsoft\Internet Traveller\Main,Start Page = about:blank
SearchScopes: HKU\S-1-5-21-925185676-1098965860-4220522822-1001 -> DefaultScope {56B90406-7F40-474C-AC73-88B4F2C484EF} URL = hxxps://encrypted.google.com/search?hl={language}&q={searchTerms}
SearchScopes: HKU\S-1-5-21-925185676-1098965860-4220522822-1001 -> {56B90406-7F40-474C-AC73-88B4F2C484EF} URL = hxxps://encrypted.google.com/search?hl={language}&q={searchTerms}
Tcpip\..\Interfaces\{54997AEA-6BE5-4B1D-AA3A-01377EAF9D27}: [DhcpNameServer] 8.8.8.8
Tcpip\..\Interfaces\{7B4C56F8-54B9-49AE-AC24-2E617300C9FC}: [DhcpNameServer] 200.48.225.130 200.48.225.146
Tcpip\..\Interfaces\{98FE26F2-9E79-4C35-8D23-4F5B94D8526A}: [DhcpNameServer] 200.48.225.130 200.48.225.146
HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local: [ActivePolicy] SOFTWARE\Policies\Microsoft\Windows\IPSEC\Policy\Local\ipsecPolicy{be0e178f-2e50-4541-804c-a34f7db55587} <======= ATTENTION (Restriction - IP)
GroupPolicy: Restriction <======= ATTENTION
GroupPolicy\User: Restriction <======= ATTENTION
GroupPolicyScripts: Restriction <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
ShortcutTarget: Install LastPass FF RunOnce.lnk -> C:\Program Files (x86)\Common Files\wruninstall.exe (No File)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install LastPass IE RunOnce.lnk [2016-07-06]
ShortcutTarget: Install LastPass IE RunOnce.lnk -> C:\Program Files (x86)\Common Files\wruninstall.exe (No File)
ShellIconOverlayIdentifiers-x32: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => -> No File
ShellIconOverlayIdentifiers-x32: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => -> No File
ShellIconOverlayIdentifiers-x32: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => -> No File
ShellIconOverlayIdentifiers-x32: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => -> No File
ShellIconOverlayIdentifiers-x32: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => -> No File
ShellIconOverlayIdentifiers-x32: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => -> No File
ShellIconOverlayIdentifiers-x32: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => -> No File
ShellIconOverlayIdentifiers-x32: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => -> No File
ShellIconOverlayIdentifiers: [1aCopyShExtError] -> {83BEA36E-7680-4598-A4DF-994426F6E78D} => -> No File
ShellIconOverlayIdentifiers: [2aCopyShExtSynced] -> {845B7388-6F85-4F32-9FD5-F02DC7882B89} => -> No File
ShellIconOverlayIdentifiers: [3aCopyShExtSyncing] -> {F6378A7A-F753-449B-AE1B-997A96132E61} => -> No File
ShellIconOverlayIdentifiers: [4aCopyShExtSyncingProg1] -> {3A511828-777D-46F8-82F4-5B530C1B3D9E} => -> No File
ShellIconOverlayIdentifiers: [5aCopyShExtSyncingProg2] -> {C8C88204-5B14-40EC-BA72-8AEBC762047E} => -> No File
ShellIconOverlayIdentifiers: [6aCopyShExtSyncingProg3] -> {ACFF45C3-3EEB-4351-86C2-6696BA264239} => -> No File
ShellIconOverlayIdentifiers: [7aCopyShExtSyncingProg4] -> {29AF997F-488B-46F0-AE78-7146F1B89CC3} => -> No File
ShellIconOverlayIdentifiers: [8aCopyShExtSyncingProg5] -> {03F9AD29-1C78-4B66-8890-B177B5430C53} => -> No File
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => -> No File
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => -> No File
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => -> No File
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => -> No File
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => -> No File
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => -> No File
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => -> No File
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => -> No File
HKU\S-1-5-18\...\Run: [Copy] => "C:\Users\Traveller\AppData\Roaming\Copy\CopyAgent.exe"
HKU\S-1-5-18\...\Run: [ooVoo.exe] => C:\Program Files (x86)\ooVoo\oovoo.exe [36592672 2015-08-20] (ooVoo LLC)
HKU\S-1-5-18\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1407912 2017-01-16] (Garmin Ltd. or its subsidiaries)
HKU\S-1-5-18\...\Policies\system: [DisableCMD] 0
HKU\S-1-5-18\...\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-18\...\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-18\...\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-18\...\Policies\Traveller: [NoViewOnDrive] 0
HKU\S-1-5-18\...\Policies\Traveller: [DisableLocalMachineRun] 0
HKU\S-1-5-18\...\Policies\Traveller: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-18\...\Policies\Traveller: [DisableCurrentUserRun] 0
HKU\S-1-5-18\...\Policies\Traveller: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-18\...\Policies\Traveller: [NoViewContextMenu] 0
HKU\S-1-5-18\...\Policies\Traveller: [NoShellSearchButton] 0
HKU\S-1-5-18\...\Policies\Traveller: [NoFind] 0
HKU\S-1-5-18\...\Policies\Traveller: [NoFile] 0
HKU\S-1-5-18\...\Policies\Traveller: [HideClock] 0
HKU\S-1-5-18\...\Policies\Traveller: [NoTrayContextMenu] 0
HKU\S-1-5-18\...\Policies\Traveller: [NoTrayItemsDisplay] 0
HKU\S-1-5-18\...\Policies\Traveller: [NoSetFolders] 0
HKU\S-1-5-18\...\Policies\Traveller: [NoDevMgrUpdate] 0
HKU\S-1-5-18\...\Policies\Traveller: [NoSetTaskbar] 0
HKU\S-1-5-18\...\Policies\Traveller: [NoDeletePrinter] 0
HKU\S-1-5-18\...\Policies\Traveller: [NoDFSTab] 0
HKU\S-1-5-18\...\Policies\Traveller: [NoChangeStartMenu] 0
HKU\S-1-5-18\...\Policies\Traveller: [NoLogoff] 0
HKU\S-1-5-18\...\Policies\Traveller: [NoWindowsUpdate] 0
HKU\S-1-5-18\...\Policies\Traveller: [NoEncryptOnMove] 0
HKU\S-1-5-18\...\Policies\Traveller: [NoRunasInstallPrompt] 0
HKU\S-1-5-18\...\Policies\Traveller: [NoResolveSearch] 0
HKU\S-1-5-18\...\Policies\Traveller: [NoSaveSettings] 0
HKU\S-1-5-18\...\Policies\Traveller: [NoHardwareTab] 0
HKU\S-1-5-18\...\Policies\Traveller: [NoStartMenuSubFolders] 0
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\...\Policies\system: [DisableCMD] 0
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\...\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\...\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\...\Policies\Traveller: [DisableLocalMachineRun] 0
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\...\Policies\Traveller: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\...\Policies\Traveller: [DisableCurrentUserRun] 0
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\...\Policies\Traveller: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\...\Policies\Traveller: [NoViewContextMenu] 0
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\...\Policies\Traveller: [NoShellSearchButton] 0
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\...\Policies\Traveller: [HideClock] 0
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\...\Policies\Traveller: [NoTrayItemsDisplay] 0
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\...\Policies\Traveller: [NoDevMgrUpdate] 0
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\...\Policies\Traveller: [NoDeletePrinter] 0
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\...\Policies\Traveller: [NoDFSTab] 0
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\...\Policies\Traveller: [NoWindowsUpdate] 0
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\...\Policies\Traveller: [NoEncryptOnMove] 0
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\...\Policies\Traveller: [NoRunasInstallPrompt] 0
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\...\Policies\Traveller: [NoResolveSearch] 0
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\...\Policies\Traveller: [NoSaveSettings] 0
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\...\Policies\Traveller: [NoHardwareTab] 0
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\...\Policies\Traveller: [NoStartMenuSubFolders] 0
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\...\MountPoints2: {8185036d-bf50-11e5-82f9-14feb5c3027f} - "E:\LGAutoRun.exe"
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\...\MountPoints2: {b491a930-679a-11e3-825e-00dbdf2de1f9} - "E:\AutoRun.exe"
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\...\MountPoints2: {e5212153-5f05-11e3-8251-806e6f6e6963} - "Q:\autorun.exe"
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\...\Run: [Google Update] => C:\Users\Traveller\AppData\Local\Google\Update\1.3.32.7\GoogleUpdateCore.exe [601752 2016-12-16] (Google Inc.)
HKLM\...\Policies\Traveller: [DisableLocalMachineRun] 0
HKLM\...\Policies\Traveller: [DisableLocalMachineRunOnce] 0
HKLM\...\Policies\Traveller: [DisableCurrentUserRun] 0
HKLM\...\Policies\Traveller: [DisableCurrentUserRunOnce] 0
HKLM\...\Policies\Traveller: [NoViewContextMenu] 0
HKLM\...\Policies\Traveller: [NoShellSearchButton] 0
HKLM\...\Policies\Traveller: [HideClock] 0
HKLM\...\Policies\Traveller: [NoTrayItemsDisplay] 0
HKLM\...\Policies\Traveller: [NoDevMgrUpdate] 0
HKLM\...\Policies\Traveller: [NoDeletePrinter] 0
HKLM\...\Policies\Traveller: [NoDFSTab] 0
HKLM\...\Policies\Traveller: [NoWindowsUpdate] 0
HKLM\...\Policies\Traveller: [NoEncryptOnMove] 0
HKLM\...\Policies\Traveller: [NoRunasInstallPrompt] 0
HKLM\...\Policies\Traveller: [NoResolveSearch] 0
HKLM\...\Policies\Traveller: [NoSaveSettings] 0
HKLM\...\Policies\Traveller: [NoHardwareTab] 0
HKLM\...\Policies\Traveller: [NoStartMenuSubFolders] 0
HKU\S-1-5-19\...\Policies\system: [DisableCMD] 0
HKU\S-1-5-19\...\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-19\...\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-19\...\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-19\...\Policies\Traveller: [NoViewOnDrive] 0
HKU\S-1-5-19\...\Policies\Traveller: [DisableLocalMachineRun] 0
HKU\S-1-5-19\...\Policies\Traveller: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-19\...\Policies\Traveller: [DisableCurrentUserRun] 0
HKU\S-1-5-19\...\Policies\Traveller: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-19\...\Policies\Traveller: [NoViewContextMenu] 0
HKU\S-1-5-19\...\Policies\Traveller: [NoShellSearchButton] 0
HKU\S-1-5-19\...\Policies\Traveller: [NoFind] 0
HKU\S-1-5-19\...\Policies\Traveller: [NoFile] 0
HKU\S-1-5-19\...\Policies\Traveller: [HideClock] 0
HKU\S-1-5-19\...\Policies\Traveller: [NoTrayContextMenu] 0
HKU\S-1-5-19\...\Policies\Traveller: [NoTrayItemsDisplay] 0
HKU\S-1-5-19\...\Policies\Traveller: [NoSetFolders] 0
HKU\S-1-5-19\...\Policies\Traveller: [NoDevMgrUpdate] 0
HKU\S-1-5-19\...\Policies\Traveller: [NoSetTaskbar] 0
HKU\S-1-5-19\...\Policies\Traveller: [NoDeletePrinter] 0
HKU\S-1-5-19\...\Policies\Traveller: [NoDFSTab] 0
HKU\S-1-5-19\...\Policies\Traveller: [NoChangeStartMenu] 0
HKU\S-1-5-19\...\Policies\Traveller: [NoLogoff] 0
HKU\S-1-5-19\...\Policies\Traveller: [NoWindowsUpdate] 0
HKU\S-1-5-19\...\Policies\Traveller: [NoEncryptOnMove] 0
HKU\S-1-5-19\...\Policies\Traveller: [NoRunasInstallPrompt] 0
HKU\S-1-5-19\...\Policies\Traveller: [NoResolveSearch] 0
HKU\S-1-5-19\...\Policies\Traveller: [NoSaveSettings] 0
HKU\S-1-5-19\...\Policies\Traveller: [NoHardwareTab] 0
HKU\S-1-5-19\...\Policies\Traveller: [NoStartMenuSubFolders] 0
HKU\S-1-5-20\...\Policies\system: [DisableCMD] 0
HKU\S-1-5-20\...\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-20\...\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-20\...\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-20\...\Policies\Traveller: [NoViewOnDrive] 0
HKU\S-1-5-20\...\Policies\Traveller: [DisableLocalMachineRun] 0
HKU\S-1-5-20\...\Policies\Traveller: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-20\...\Policies\Traveller: [DisableCurrentUserRun] 0
HKU\S-1-5-20\...\Policies\Traveller: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-20\...\Policies\Traveller: [NoViewContextMenu] 0
HKU\S-1-5-20\...\Policies\Traveller: [NoShellSearchButton] 0
HKU\S-1-5-20\...\Policies\Traveller: [NoFind] 0
HKU\S-1-5-20\...\Policies\Traveller: [NoFile] 0
HKU\S-1-5-20\...\Policies\Traveller: [HideClock] 0
HKU\S-1-5-20\...\Policies\Traveller: [NoTrayContextMenu] 0
HKU\S-1-5-20\...\Policies\Traveller: [NoTrayItemsDisplay] 0
HKU\S-1-5-20\...\Policies\Traveller: [NoSetFolders] 0
HKU\S-1-5-20\...\Policies\Traveller: [NoDevMgrUpdate] 0
HKU\S-1-5-20\...\Policies\Traveller: [NoSetTaskbar] 0
HKU\S-1-5-20\...\Policies\Traveller: [NoDeletePrinter] 0
HKU\S-1-5-20\...\Policies\Traveller: [NoDFSTab] 0
HKU\S-1-5-20\...\Policies\Traveller: [NoChangeStartMenu] 0
HKU\S-1-5-20\...\Policies\Traveller: [NoLogoff] 0
HKU\S-1-5-20\...\Policies\Traveller: [NoWindowsUpdate] 0
HKU\S-1-5-20\...\Policies\Traveller: [NoEncryptOnMove] 0
HKU\S-1-5-20\...\Policies\Traveller: [NoRunasInstallPrompt] 0
HKU\S-1-5-20\...\Policies\Traveller: [NoResolveSearch] 0
HKU\S-1-5-20\...\Policies\Traveller: [NoSaveSettings] 0
HKU\S-1-5-20\...\Policies\Traveller: [NoHardwareTab] 0
HKU\S-1-5-20\...\Policies\Traveller: [NoStartMenuSubFolders] 0
HKLM Group Policy restriction on software: cipher.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.js <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.js <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: syskey.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.js <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.pub*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.pub*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.js <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.exe <====== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.js <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.pub*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.com <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.jse <====== ATTENTION
HKLM Group Policy restriction on software: lsassw86s.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.pub*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.js <====== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.js <====== ATTENTION
HKLM Group Policy restriction on software: %programfiles(x86)%\*\svchost.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.com <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.pub*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.pub*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.js <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.com <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.exe <====== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.js <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.scr <====== ATTENTION
HKLM Group Policy restriction on software: ** <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.scr <====== ATTENTION
HKLM Group Policy restriction on software: scsvserv.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.pub*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Appdata\Roaming\Microsoft\Windows\IEUpdate\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.com <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*\svchost.exe <====== ATTENTION
HKLM Group Policy restriction on software: vssadmin.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.pub*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.com <====== ATTENTION
HKLM Group Policy restriction on software: *:\$Recycle.Bin <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.com <====== ATTENTION
HKLM Group Policy restriction on software: %systemdrive%\*\svchost.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.js <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.bat <====== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.com <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.com <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.js <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: lsassvrtdbks.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.js <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.js <====== ATTENTION
HKLM Group Policy restriction on software: %programfiles%\*\svchost.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.exe <====== ATTENTION
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-09-22] (Oracle Corporation)
CMD: RD /S /Q %WinDir%\System32\GroupPolicyUsers
CMD: RD /S /Q %WinDir%\System32\GroupPolicy
CMD: RD /S /Q %WinDir%\SysWOW64\GroupPolicyUsers
CMD: RD /S /Q %WinDir%\SysWOW64\GroupPolicy
CMD: RD /S /Q %WinDir%\SysNative\GroupPolicyUsers
CMD: RD /S /Q %WinDir%\SysNative\GroupPolicy
CMD: gpupdate /force
CMD: bitsadmin /reset /allusers
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: ipconfig /flushdns
EmptyTemp:
end
*****************
Processes closed successfully.
Restore point was successfully created.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32\\iTunesHelper => value removed successfully
HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\iTunesHelper => value not found.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32\\QuickTime Task => value removed successfully
HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\QuickTime Task => value not found.
Could not move "C:\Windows\system32\Drivers\etc\hosts" => Scheduled to move on reboot.
Could not move "C:\Windows\System32\Drivers\etc\hosts" => Scheduled to move on reboot.
HKU\.DEFAULT\Software\Classes\exefile => key removed successfully
HKU\.DEFAULT\Software\Classes\.exe => key removed successfully
HKLM\System\CurrentControlSet\Control\SafeBoot\Network\WRkrn => key removed successfully
HKLM\System\CurrentControlSet\Control\SafeBoot\Network\WRSVC => key removed successfully
C:\ProgramData\TEMP => ":41ADDB8A" ADS removed successfully.
C:\ProgramData\TEMP => ":A064CECC" ADS removed successfully.
C:\ProgramData\TEMP => ":B755D674" ADS removed successfully.
C:\ProgramData\TEMP => "
5FBE8F9" ADS removed successfully.
C:\Users\Public\DRM => ":احتضان" ADS removed successfully.
C:\Users\Traveller\Desktop\Inner-Light.jpg => ":$CmdZnID" ADS removed successfully.
C:\Users\Traveller\Downloads\Keygen-MESMERiZE.rar => ":$CmdTcID" ADS removed successfully.
C:\Users\Traveller\Downloads\Keygen-MESMERiZE.rar => ":$CmdZnID" ADS removed successfully.
C:\Users\Traveller\Downloads\pijano (mastered).mp3 => ":$CmdTcID" ADS removed successfully.
C:\Users\Traveller\Downloads\pijano (mastered).mp3 => ":$CmdZnID" ADS removed successfully.
C:\Users\Traveller\Downloads\pocket.crx => ":$CmdZnID" ADS removed successfully.
C:\Users\Traveller\Downloads\Reset_antispam_0.3.1.7z => ":$CmdZnID" ADS removed successfully.
C:\Users\Traveller\Downloads\rokcandy-2.0.1 (1).zip => ":$CmdZnID" ADS removed successfully.
C:\Users\Traveller\Downloads\root.crt => ":$CmdZnID" ADS removed successfully.
C:\Users\Traveller\Downloads\root.der => ":$CmdZnID" ADS removed successfully.
C:\Users\Traveller\Downloads\You Will Not Face This Alone.mp3 => ":$CmdTcID" ADS removed successfully.
C:\Users\Traveller\Downloads\You Will Not Face This Alone.mp3 => ":$CmdZnID" ADS removed successfully.
C:\Users\Traveller\Downloads\[kickass.so]hotline.miami.update.3.gog.torrent => ":$CmdZnID" ADS removed successfully.
C:\Users\Traveller\Favorites\FileOptimizer Home Page.lnk => moved successfully
C:\Users\Traveller\Favorites\NCH Software Download Site.lnk => moved successfully
C:\Users\Traveller\Dropbox\Равиль\для меня.lnk => moved successfully
C:\Users\Traveller\Desktop\Домашняя бухгалтерия 5.lnk => moved successfully
C:\Users\Traveller\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Yamb 2.1.0.0 beta 2\Yamb - Website.lnk => moved successfully
C:\Users\Traveller\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\WorkFlowy.lnk => Shortcut argument removed successfully.
C:\Users\Traveller\AppData\Roaming\Microsoft\Internet Traveller\Quick Launch\User Pinned\ImplicitAppShortcuts\aeea6001c9fdcab9\Click&Clean.lnk => not found.
C:\Users\Traveller\AppData\Roaming\Microsoft\Internet Traveller\Quick Launch\User Pinned\ImplicitAppShortcuts\a3a1d6b8109861c5\Hangouts.lnk => not found.
C:\Users\Traveller\AppData\Roaming\Microsoft\Internet Traveller\Quick Launch\User Pinned\ImplicitAppShortcuts\5a7f1fc1149619d6\Epic Privacy Browser.lnk => not found.
C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-925185676-1098965860-4220522822-1001UA.job => moved successfully
C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-925185676-1098965860-4220522822-1001Core.job => moved successfully
C:\Windows\Tasks\GoogleUpdateTaskMachineUA1cf6986c118e050.job => moved successfully
C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d0001d73c8b334.job => moved successfully
C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-925185676-1098965860-4220522822-1001Core1cfd791cbe00d3.job => moved successfully
C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-925185676-1098965860-4220522822-1001Core1cfed3dadc0292f.job => moved successfully
C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-925185676-1098965860-4220522822-1001Core1cffedb14d73815.job => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FCC01015-90D3-40BB-A7B7-FB8C342A9385} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FCC01015-90D3-40BB-A7B7-FB8C342A9385} => key removed successfully
C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-925185676-1098965860-4220522822-1001Core1d0411f110ceba0 => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskUserS-1-5-21-925185676-1098965860-4220522822-1001Core1d0411f110ceba0 => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CA479769-6B76-4C74-B358-67423E5E14AE} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CA479769-6B76-4C74-B358-67423E5E14AE} => key removed successfully
C:\Windows\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D3E94B6F-E162-41ED-A78D-49068CC7ED23} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D3E94B6F-E162-41ED-A78D-49068CC7ED23} => key removed successfully
C:\Windows\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DAAEF8CA-94B0-46E6-94ED-FDC4B3E4AF4A} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DAAEF8CA-94B0-46E6-94ED-FDC4B3E4AF4A} => key removed successfully
C:\Windows\System32\Tasks\{2F3CCF69-1646-4DB0-AFD2-72E35FF466E2} => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{2F3CCF69-1646-4DB0-AFD2-72E35FF466E2} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DDB4C5BF-2FE1-41E1-8D6F-FE99673976A4} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DDB4C5BF-2FE1-41E1-8D6F-FE99673976A4} => key removed successfully
C:\Windows\System32\Tasks\{CA56EAE6-5E60-454F-8EE2-3825A791791D} => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{CA56EAE6-5E60-454F-8EE2-3825A791791D} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{E050D551-CEF3-49EA-B469-70424D4A805A} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E050D551-CEF3-49EA-B469-70424D4A805A} => key removed successfully
C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1408935599 => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Opera scheduled Autoupdate 1408935599 => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E2DB1668-3E8B-457C-AF8E-95E39708C96A} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E2DB1668-3E8B-457C-AF8E-95E39708C96A} => key removed successfully
C:\Windows\System32\Tasks\{2090741D-AF19-4C0D-987B-D5AD2CA171A4} => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{2090741D-AF19-4C0D-987B-D5AD2CA171A4} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{91E9E3CA-F7D9-4D12-A30D-BB7ADA79C6DC} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{91E9E3CA-F7D9-4D12-A30D-BB7ADA79C6DC} => key removed successfully
C:\Windows\System32\Tasks\Chameleon Startup Manager-Traveller => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Chameleon Startup Manager-Traveller => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{92C88288-96C8-4FDF-A609-217497BFBEF9} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{92C88288-96C8-4FDF-A609-217497BFBEF9} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Pointstone\System Cleaner\Log On Notice => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9822B3AD-B62E-42E8-8E38-EFEAEF22F1B2} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9822B3AD-B62E-42E8-8E38-EFEAEF22F1B2} => key removed successfully
C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-925185676-1098965860-4220522822-1001UA => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskUserS-1-5-21-925185676-1098965860-4220522822-1001UA => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9CBC36AC-65A1-4EE6-ADFE-AFF60472DD16} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9CBC36AC-65A1-4EE6-ADFE-AFF60472DD16} => key removed successfully
C:\Windows\System32\Tasks\Chameleon Monitor-startup-Traveller => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Chameleon Monitor-startup-Traveller => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{A549169A-D962-4B64-81D2-C964B9449C9A} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A549169A-D962-4B64-81D2-C964B9449C9A} => key removed successfully
C:\Windows\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4AC54D11-6DD2-4038-A5FF-94888CBDEE05} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4AC54D11-6DD2-4038-A5FF-94888CBDEE05} => key removed successfully
C:\Windows\System32\Tasks\Run RoboForm TaskBar Icon => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Run RoboForm TaskBar Icon => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5296151F-94E0-4363-BD38-3D32EB8820F6} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5296151F-94E0-4363-BD38-3D32EB8820F6} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{505A68B3-E825-4D29-AC08-B71CA2308CF5} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{5F4BF8A0-2FF1-467F-916B-CC2DAC8D72B1} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5F4BF8A0-2FF1-467F-916B-CC2DAC8D72B1} => key removed successfully
C:\Windows\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6A53FC7F-5F79-4FB4-8C68-579E7C847A2D} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6A53FC7F-5F79-4FB4-8C68-579E7C847A2D} => key removed successfully
C:\Windows\System32\Tasks\{F5A09CDD-01AF-42BB-88BB-10471CCE6707} => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{F5A09CDD-01AF-42BB-88BB-10471CCE6707} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{7476B54B-CDB4-47A2-85FC-8F1BC37E7E33} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7476B54B-CDB4-47A2-85FC-8F1BC37E7E33} => key removed successfully
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7B81CF39-A304-40ED-B0FA-E97FCA106CC3} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7B81CF39-A304-40ED-B0FA-E97FCA106CC3} => key removed successfully
C:\Windows\System32\Tasks\Open URL by RoboForm => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Open URL by RoboForm => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8033146A-54E7-453E-A3E9-FC0972A14F1A} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8033146A-54E7-453E-A3E9-FC0972A14F1A} => key removed successfully
C:\Windows\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8D6A16C1-3BA2-4877-85C3-A3631C653532} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8D6A16C1-3BA2-4877-85C3-A3631C653532} => key removed successfully
C:\Windows\System32\Tasks\{A1D5D0E4-BB6C-4E3C-BD67-E5A8C0E74A2E} => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{A1D5D0E4-BB6C-4E3C-BD67-E5A8C0E74A2E} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8EC5BF83-AC06-4190-A64A-4096E5BBCD19} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8EC5BF83-AC06-4190-A64A-4096E5BBCD19} => key removed successfully
C:\Windows\System32\Tasks\Nero\Nero Info => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Nero\Nero Info => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3C7DF767-9E4B-4F3B-841D-95887E75AEFD} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3C7DF767-9E4B-4F3B-841D-95887E75AEFD} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Pointstone\System Cleaner\Daily Notice => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{43A17CBD-36AD-4BFB-B3C5-1FEF32E15681} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{43A17CBD-36AD-4BFB-B3C5-1FEF32E15681} => key removed successfully
C:\Windows\System32\Tasks\Red Giant Link => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Red Giant Link => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4515A598-639B-489A-B22D-0FF6267D4734} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4515A598-639B-489A-B22D-0FF6267D4734} => key removed successfully
C:\Windows\System32\Tasks\Norton AntiVirus\Norton Error Processor => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Norton AntiVirus\Norton Error Processor => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{00CE6CA9-7691-46ED-A32B-41B5D8052A0B} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{00CE6CA9-7691-46ED-A32B-41B5D8052A0B} => key removed successfully
C:\Windows\System32\Tasks\Norton AntiVirus\Norton Error Analyzer => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Norton AntiVirus\Norton Error Analyzer => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{063A6DF0-D9DF-4D01-98C0-43B458DBC34F} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{063A6DF0-D9DF-4D01-98C0-43B458DBC34F} => key removed successfully
C:\Windows\System32\Tasks\{36E7CDCE-3B01-4650-8948-AF254DEB073C} => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{36E7CDCE-3B01-4650-8948-AF254DEB073C} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0A4E987C-6912-497D-A2C5-DDC107B9467C} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0A4E987C-6912-497D-A2C5-DDC107B9467C} => key removed successfully
C:\Windows\System32\Tasks\AdobeAAMUpdater-1.0-MicrosoftAccount-ltwingtrust@hotmail.com => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AdobeAAMUpdater-1.0-MicrosoftAccount-ltwingtrust@hotmail.com => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0AC4904A-8372-4020-9BFF-55B687BCD936} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0AC4904A-8372-4020-9BFF-55B687BCD936} => key removed successfully
C:\Windows\System32\Tasks\GarminUpdaterTask => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GarminUpdaterTask => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0CB03F15-7BBF-4237-8FBB-FE6F3FA35FCD} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0CB03F15-7BBF-4237-8FBB-FE6F3FA35FCD} => key removed successfully
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA1cf6986c118e050 => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA1cf6986c118e050 => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{197671D1-207D-49D1-A944-E0D46AEF8027} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{197671D1-207D-49D1-A944-E0D46AEF8027} => key removed successfully
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA1d041918bdfa750 => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA1d041918bdfa750 => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2409A78A-85F7-40FD-AD75-A78F381E4B62} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2409A78A-85F7-40FD-AD75-A78F381E4B62} => key removed successfully
C:\Windows\System32\Tasks\Chameleon Monitor-Traveller => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Chameleon Monitor-Traveller => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2D04D24E-3525-4A26-A43D-33B1A0FF27BC} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2D04D24E-3525-4A26-A43D-33B1A0FF27BC} => key removed successfully
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA1d0001d73c8b334 => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA1d0001d73c8b334 => key removed successfully
C:\Users\Traveller\AppData\Local\Temp\kernel32.dll => moved successfully
C:\Users\Traveller\AppData\Local\Temp\PidGenX.dll => moved successfully
C:\ProgramData\RegistryReviver.exe => moved successfully
C:\ProgramData\agent.1485894021.bdinstall.bin => moved successfully
C:\ProgramData\agent.1485894894.bdinstall.bin => moved successfully
C:\Users\Traveller\AppData\Local\~wmrg => moved successfully
C:\Users\Traveller\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini => moved successfully
C:\Users\Traveller\AppData\Local\.C3F2FH85-G3D2-2F02-D5CH-7D3D8C553E56 => moved successfully
C:\Users\Traveller\AppData\Local\.DG212F11-EC8C-210D-DE1E-D9584D18D740 => moved successfully
C:\Users\Traveller\AppData\Local\00000128 => moved successfully
"C:\Users\Traveller\AppData\Local\~wmrg" => not found.
C:\Users\Traveller\AppData\Roaming\qBittorrent => moved successfully
"C:\Windows\System32\Tasks\GarminUpdaterTask" => not found.
"C:\Users\Traveller\AppData\Local\00000128" => not found.
"C:\ProgramData\WRData" folder move:
Could not move "C:\ProgramData\WRData" => Scheduled to move on reboot.
C:\Users\Traveller\AppData\Roaming\uTorrent => moved successfully
C:\Windows\system32\MRT => moved successfully
C:\Windows\system32\MRT.exe => moved successfully
"C:\Windows\Tasks\GoogleUpdateTaskMachineUA1cf6986c118e050.job" => not found.
C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-925185676-1098965860-4220522822-1001 => moved successfully
C:\ProgramData\TEMP => moved successfully
"C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d0001d73c8b334.job" => not found.
C:\Users\Traveller\AppData\Roaming\Adobe BMP Format CC Prefs => moved successfully
C:\Users\Traveller\AppData\Roaming\Adobe GIF Format CC Prefs => moved successfully
C:\Users\Traveller\AppData\Roaming\Adobe PNG Format CC Prefs => moved successfully
C:\Users\Traveller\AppData\Roaming\AdobeWLCMCache.dat => moved successfully
C:\Users\Traveller\AppData\Roaming\alsoft.ini => moved successfully
C:\Users\Traveller\AppData\Roaming\Ambience => moved successfully
C:\Users\Traveller\AppData\Roaming\CheckWinVer.log => moved successfully
C:\Users\Traveller\AppData\Roaming\droid4xinstaller.log => moved successfully
C:\Users\Traveller\AppData\Roaming\FontInfo.bin => moved successfully
C:\Users\Traveller\AppData\Roaming\GlyphInfo.bin => moved successfully
C:\Users\Traveller\AppData\Roaming\PS14_panel.log => moved successfully
C:\Users\Traveller\AppData\Roaming\SAS7_000.DAT => moved successfully
C:\Users\Traveller\AppData\Roaming\winscp.rnd => moved successfully
C:\Users\Traveller\AppData\Roaming\Значения, разделенные запятыми.ADR => moved successfully
"C:\Users\Traveller\AppData\Local\.C3F2FH85-G3D2-2F02-D5CH-7D3D8C553E56" => not found.
"C:\Users\Traveller\AppData\Local\.DG212F11-EC8C-210D-DE1E-D9584D18D740" => not found.
"C:\Users\Traveller\AppData\Local\00000128" => not found.
C:\Users\Traveller\AppData\Local\ACCCx2_2_1_260.zip.aamdownload => moved successfully
C:\Users\Traveller\AppData\Local\ACCCx2_2_1_260.zip.aamdownload.aamd => moved successfully
C:\Users\Traveller\AppData\Local\Adobe Save for Web 13.0 Prefs => moved successfully
"C:\Users\Traveller\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini" => not found.
C:\Users\Traveller\AppData\Local\helpman.imc => moved successfully
C:\Users\Traveller\AppData\Local\housecall.guid.cache => moved successfully
C:\Users\Traveller\AppData\Local\llftool.4.40.agreement => moved successfully
C:\Users\Traveller\AppData\Local\PUTTY.RND => moved successfully
C:\Users\Traveller\AppData\Local\recently-used.xbel => moved successfully
C:\Users\Traveller\AppData\Local\Resmon.ResmonCfg => moved successfully
C:\Users\Traveller\AppData\Local\sponge.last.runtime.cache => moved successfully
"C:\Users\Traveller\AppData\Local\~wmrg" => not found.
"C:\ProgramData\agent.1485894021.bdinstall.bin" => not found.
"C:\ProgramData\agent.1485894894.bdinstall.bin" => not found.
C:\Users\Traveller\AppData\LocalLow\wbkD99A.tmp => moved successfully
C:\Windows\RegBootClean64.exe => moved successfully
C:\ProgramData\Trend Micro => moved successfully
"C:\Users\Traveller\AppData\Local\housecall.guid.cache" => not found.
C:\Users\Public\Desktop\Trend_Micro.exe => moved successfully
"C:\ProgramData\agent.1485894894.bdinstall.bin" => not found.
"C:\ProgramData\agent.1485894021.bdinstall.bin" => not found.
C:\Users\Traveller\AppData\Local\Trend Micro => moved successfully
HKLM\System\CurrentControlSet\Services\DfSdkS => key removed successfully
DfSdkS => service removed successfully
HKLM\System\CurrentControlSet\Services\nvvad_WaveExtensible => key removed successfully
nvvad_WaveExtensible => service removed successfully
HKLM\System\CurrentControlSet\Services\SR => key removed successfully
SR => service removed successfully
HKLM\System\CurrentControlSet\Services\srservice => key removed successfully
srservice => service removed successfully
HKLM\System\CurrentControlSet\Services\vpnva => key removed successfully
vpnva => service removed successfully
HKLM\System\CurrentControlSet\Services\RTCore64 => key removed successfully
RTCore64 => service removed successfully
HKLM\System\CurrentControlSet\Services\NAVENG => key removed successfully
NAVENG => service removed successfully
HKLM\System\CurrentControlSet\Services\NAVEX15 => key removed successfully
NAVEX15 => service removed successfully
HKLM\System\CurrentControlSet\Services\DIRECTIO => key removed successfully
DIRECTIO => service removed successfully
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\pkijdmeepjhpenmighhaodgfoogncnlk => key removed successfully
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\iikflkcanblccfahdhdonehdalibjnif => key removed successfully
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ngkhgikojglcgnckopipfdajaifmmnnc => key removed successfully
HKLM\SOFTWARE\Google\Chrome\Extensions\iikflkcanblccfahdhdonehdalibjnif => key removed successfully
C:\Users\Traveller\AppData\Local\Google\Chrome\User Data\Default\Extensions\ninejjcohidippngpapiilnmkgllmakh => moved successfully
C:\Users\Traveller\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlmmgnhgdeffjkdckmikfpnddkbbfkkk => moved successfully
C:\Users\Traveller\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda => moved successfully
C:\Users\Traveller\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkhnbhdofgaendegcgbmndipmijhbili => moved successfully
C:\Users\Traveller\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo => moved successfully
C:\Users\Traveller\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf => moved successfully
C:\Users\Traveller\AppData\Roaming\mozilla\plugins\npgoogletalk.dll => moved successfully
C:\Users\Traveller\AppData\Roaming\mozilla\plugins\npo1d.dll => moved successfully
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\Software\MozillaPlugins\@tools.google.com/Google Update;version=3 => key removed successfully
C:\Users\Traveller\AppData\Local\Google\Update\1.3.32.7\npGoogleUpdate3.dll => moved successfully
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\Software\MozillaPlugins\@tools.google.com/Google Update;version=9 => key removed successfully
C:\Users\Traveller\AppData\Local\Google\Update\1.3.32.7\npGoogleUpdate3.dll => not found.
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0 => key removed successfully
C:\Users\Traveller\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll => moved successfully
HKLM\Software\Wow6432Node\MozillaPlugins\@wacom.com/wtPlugin,version=2.1.0.7 => key removed successfully
C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll => moved successfully
HKLM\Software\Wow6432Node\MozillaPlugins\adobe.com/AdobeAAMDetect => key removed successfully
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll => moved successfully
HKLM\Software\Wow6432Node\MozillaPlugins\wacom.com/WacomTabletPlugin => key removed successfully
C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll => not found.
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin => key not found.
C:\Users\Traveller\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll => not found.
HKLM\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3 => key removed successfully
C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll => moved successfully
HKLM\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9 => key removed successfully
C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll => not found.
"C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll" => not found.
Firefox Proxy settings were reset.
(host == \"iview.abc.net.au\") => Error: No automatic fix found for this entry.
(host == \"iviewmetered-vh.akamaihd.net\") => Error: No automatic fix found for this entry.
(url.indexOf(\"proxmate=au\") != -1) => Error: No automatic fix found for this entry.
(host == \"livestream.com\") => Error: No automatic fix found for this entry.
(host == \"
www.livestream.com\") => Error: No automatic fix found for this entry.
(host == \"api.new.livestream.com\") => Error: No automatic fix found for this entry.
(host == \"player.ooyala.com\") => Error: No automatic fix found for this entry.
(host == \"xnewsvidhd-vh.akamaihd.net\") => Error: No automatic fix found for this entry.
(host == \"
www.animelab.com\") => Error: No automatic fix found for this entry.
{ return 'PROXY au-node.proxmate.me:8008' } else if ((url.indexOf(\"proxmate=ca\") != -1) => No running process found
(host == \"ici.tou.tv\") => Error: No automatic fix found for this entry.
(host == \"toutvuniver1-vh.akamaihd.net\") => Error: No automatic fix found for this entry.
(host == \"geoip.radio-canada.ca\") => Error: No automatic fix found for this entry.
(host == \"api.radio-canada.ca\") => Error: No automatic fix found for this entry.
(host == \"images.tou.tv\") => Error: No automatic fix found for this entry.
(host == \"player.siriusxm.ca\") => Error: No automatic fix found for this entry.
(host == \"primary.hls-streaming.production.streaming.siriusxm.ca\") => Error: No automatic fix found for this entry.
(host == \"now.sportsnet.ca\") => Error: No automatic fix found for this entry.
(host == \"watch.sportsnet.ca\") => Error: No automatic fix found for this entry.
(host == \"player.9c9media.com\") => Error: No automatic fix found for this entry.
(host == \"metrics.ctv.ca\") => Error: No automatic fix found for this entry.
(host == \"capi.9c9media.com\") => Error: No automatic fix found for this entry.
(host == \"
www.ctv.ca\") => Error: No automatic fix found for this entry.
(host == \"
www.willow.tv\") => Error: No automatic fix found for this entry.
{ return 'PROXY ca-node.proxmate.me:8008' } else if ((host == \"arte.tv\") => No running process found
(host == \"
www.arte.tv\") => Error: No automatic fix found for this entry.
(host == \"geoftv-a.akamaihd.net\") => Error: No automatic fix found for this entry.
(host == \"hdfauthftv-a.akamaihd.net\") => Error: No automatic fix found for this entry.
(host == \"replayftv-vh.akamaihd.net\") => Error: No automatic fix found for this entry.
(host == \"ftvingest-vh.akamaihd.net\") => Error: No automatic fix found for this entry.
(host == \"live.francetv.fr\") => Error: No automatic fix found for this entry.
(host == \"d8.tv\") => Error: No automatic fix found for this entry.
(host == \"
www.d8.tv\") => Error: No automatic fix found for this entry.
(host == \"us-cplus-aka.canal-plus.com\") => Error: No automatic fix found for this entry.
(host == \"hds_live_d8_aka-lh.akamaihd.net\") => Error: No automatic fix found for this entry.
(host == \"d17.tv\") => Error: No automatic fix found for this entry.
(host == \"
www.d17.tv\") => Error: No automatic fix found for this entry.
(host == \"hds_live_d17_aka-lh.akamaihd.net\") => Error: No automatic fix found for this entry.
(url.indexOf(\"proxmate=fr\") != -1) => Error: No automatic fix found for this entry.
(host == \"
www.6play.fr\") => Error: No automatic fix found for this entry.
(host == \"geo.6cloud.fr\") => Error: No automatic fix found for this entry.
(host == \"proxy-021.dc3.dailymotion.com\") => Error: No automatic fix found for this entry.
(host == \"proxy-67.dailymotion.com\") => Error: No automatic fix found for this entry.
(host == \"prof.estat.com\") => Error: No automatic fix found for this entry.
(host == \"metrics.dailymotion.com\") => Error: No automatic fix found for this entry.
(host == \"
www.dailymotion.com\") => Error: No automatic fix found for this entry.
{ return 'PROXY fr-node.proxmate.me:8008' } else if ((host == \"vod-akamai-psd-hds.p7s1digital.de\") => No running process found
(host == \"vas.sim-technik.de\") => Error: No automatic fix found for this entry.
(url.indexOf(\"proxmate=de\") != -1) => Error: No automatic fix found for this entry.
(host == \"nightclub.de\") => Error: No automatic fix found for this entry.
(host == \"zdf.de\") => Error: No automatic fix found for this entry.
(host == \"
www.zdf.de\") => Error: No automatic fix found for this entry.
(host == \"zdf_hds_de-f.akamaihd.net\") => Error: No automatic fix found for this entry.
(host == \"api.nowtv.de\") => Error: No automatic fix found for this entry.
(host == \"delivestream-lh.akamaihd.net\") => Error: No automatic fix found for this entry.
(host == \"cdnapi.kaltura.com\") => Error: No automatic fix found for this entry.
(host == \"disneychannel.de\") => Error: No automatic fix found for this entry.
{ return 'PROXY de-node.proxmate.me:8008' } else if ((host == \"
www.tg4.ie\") => No running process found
(url.indexOf(\"proxmate=ie\") != -1)) { return 'PROXY ie-node.proxmate.me:8008' } else if ((host == \"rai.tv\") => Error: No automatic fix found for this entry.
(host == \"
www.rai.tv\") => Error: No automatic fix found for this entry.
(host == \"mediapolis.rai.it\") => Error: No automatic fix found for this entry.
(host == \"
www.rai.it\") => Error: No automatic fix found for this entry.
(host == \"stream5.rai.it\") => Error: No automatic fix found for this entry.
(host == \"stream6.rai.it\") => Error: No automatic fix found for this entry.
(host == \"stream7.rai.it\") => Error: No automatic fix found for this entry.
(host == \"sspushrai1-s.akamaihd.net\") => Error: No automatic fix found for this entry.
(host == \"sspushrai2-s.akamaihd.net\") => Error: No automatic fix found for this entry.
(host == \"sspushraisport2-s.akamaihd.net\") => Error: No automatic fix found for this entry.
(host == \"sspushrai3-s.akamaihd.net\") => Error: No automatic fix found for this entry.
(host == \"secondary.adaptiveedge.rai.it\") => Error: No automatic fix found for this entry.
(host == \"rai-italia01.wt-eu02.net\") => Error: No automatic fix found for this entry.
(host == \"download.rai.tv\") => Error: No automatic fix found for this entry.
(host == \"mediapolisvod.rai.it\") => Error: No automatic fix found for this entry.
(host == \"ww.rai.tv\") => Error: No automatic fix found for this entry.
(host == \".xuniplay.fdnames.com\") => Error: No automatic fix found for this entry.
(url.indexOf(\"xuniplay.fdnames.com\") != -1) => Error: No automatic fix found for this entry.
(host == \"se-to1-8.se.live3.msf.ticdn.it\") => Error: No automatic fix found for this entry.
(host == \"live.shinystat.com\") => Error: No automatic fix found for this entry.
(host == \"lic.mediaset.net\") => Error: No automatic fix found for this entry.
(host == \"cssr.video.mediaset.it\") => Error: No automatic fix found for this entry.
(url.indexOf(\"proxmate=it\") != -1) => Error: No automatic fix found for this entry.
{ return 'PROXY it-node.proxmate.me:8008' } else if ((host == \"telecinco.es\") => No running process found
(host == \"telecinco1-vh.akamaihd.net\") => Error: No automatic fix found for this entry.
(host == \"
www.telecinco.es\") => Error: No automatic fix found for this entry.
(url.indexOf(\"proxmate=es\") != -1) => Error: No automatic fix found for this entry.
(host == \"antena3.com\") => Error: No automatic fix found for this entry.
(host == \"
www.antena3.com\") => Error: No automatic fix found for this entry.
(host == \"geodesprogresiva.antena3.com\") => Error: No automatic fix found for this entry.
(host == \"rtve.es\") => Error: No automatic fix found for this entry.
(host == \"
www.rtve.es\") => Error: No automatic fix found for this entry.
(host == \"ztnr.rtve.es\") => Error: No automatic fix found for this entry.
(host == \"mvodt.lvlt.rtve.es\") => Error: No automatic fix found for this entry.
(host == \"swf.rtve.es\") => Error: No automatic fix found for this entry.
(host == \"cuatro.com\") => Error: No automatic fix found for this entry.
(host == \"
www.cuatro.com\") => Error: No automatic fix found for this entry.
(host == \"cuatro1-vh.akamaihd.net\") => Error: No automatic fix found for this entry.
(host == \"peliculas-online.atresplayer.com\") => Error: No automatic fix found for this entry.
(host == \"servicios.atresplayer.com\") => Error: No automatic fix found for this entry.
(host == \"atresplayer.com\") => Error: No automatic fix found for this entry.
(host == \"
www.atresplayer.com\") => Error: No automatic fix found for this entry.
(host == \"k.uecdn.es\") => Error: No automatic fix found for this entry.
(host == \"v.uecdn.es\") => Error: No automatic fix found for this entry.
(host == \"as.com\") => Error: No automatic fix found for this entry.
(host == \"ep00.epimg.net\") => Error: No automatic fix found for this entry.
{ return 'PROXY es-node.proxmate.me:8008' } else if ((host == \"prosieben.ch\") => No running process found
(host == \"
www.prosieben.ch\") => Error: No automatic fix found for this entry.
(host == \"s1tv.ch\") => Error: No automatic fix found for this entry.
(host == \"
www.s1tv.ch\") => Error: No automatic fix found for this entry.
(host == \"zba2-0-hds-live.zahs.tv\") => Error: No automatic fix found for this entry.
(host == \"embed-zattoo.com\") => Error: No automatic fix found for this entry.
(host == \"chtv.ch\") => Error: No automatic fix found for this entry.
(host == \"
www.chtv.ch\") => Error: No automatic fix found for this entry.
(host == \"zba2-1-hds-live.zahs.tv\") => Error: No automatic fix found for this entry.
(host == \"sat1.ch\") => Error: No automatic fix found for this entry.
(host == \"
www.sat1.ch\") => Error: No automatic fix found for this entry.
(host == \"rsi.ch\") => Error: No automatic fix found for this entry.
(host == \"
www.rsi.ch\") => Error: No automatic fix found for this entry.
(host == \"codch-vh.akamaihd.net\") => Error: No automatic fix found for this entry.
(host == \"il.srgssr.ch\") => Error: No automatic fix found for this entry.
(host == \"ch.viva.tv\") => Error: No automatic fix found for this entry.
(host == \"intl.esperanto.mtvi.com\") => Error: No automatic fix found for this entry.
(url.indexOf(\"proxmate=ch\") != -1) => Error: No automatic fix found for this entry.
(host == \"zattoo.com\") => Error: No automatic fix found for this entry.
(host == \"
www.srf.ch\") => Error: No automatic fix found for this entry.
(host == \"srgssruni1ch-lh.akamaihd.net\") => Error: No automatic fix found for this entry.
(host == \"srgssruni2ch-lh.akamaihd.net\") => Error: No automatic fix found for this entry.
(host == \"srgssruni3ch-lh.akamaihd.net\") => Error: No automatic fix found for this entry.
(host == \"
www.teleboy.ch\") => Error: No automatic fix found for this entry.
(host == \"aka-cdn-ns.adtech.de\") => Error: No automatic fix found for this entry.
{ return 'PROXY ch-node.proxmate.me:8008' } else if ((host == \"c.brightcove.com\") => No running process found
(host == \"secure.brightcove.com\") => Error: No automatic fix found for this entry.
(host == \"metrics.brightcove.com\") => Error: No automatic fix found for this entry.
(host == \"stv-ak.cds1.yospace.com\") => Error: No automatic fix found for this entry.
(host == \"core.stvfiles.com\") => Error: No automatic fix found for this entry.
(host == \"player.stv.tv\") => Error: No automatic fix found for this entry.
(host == \"stv.brightcove.com.edgesuite.net\") => Error: No automatic fix found for this entry.
(host == \"uk-dev-stv.cdn.videoplaza.tv\") => Error: No automatic fix found for this entry.
(host == \"mercury.itv.com\") => Error: No automatic fix found for this entry.
(host == \"
www.itv.com\") => Error: No automatic fix found for this entry.
(host == \"itv.com\") => Error: No automatic fix found for this entry.
(host == \"llnw.live.btv.simplestream.com\") => Error: No automatic fix found for this entry.
(host == \"players.simplestream.com\") => Error: No automatic fix found for this entry.
(host == \"uapi.simplestream.com\") => Error: No automatic fix found for this entry.
(host == \"channel5.com\") => Error: No automatic fix found for this entry.
(host == \"wwwcdn.channel5.com\") => Error: No automatic fix found for this entry.
(host == \"cassie.channel5.com\") => Error: No automatic fix found for this entry.
(host == \"player.channel5.com\") => Error: No automatic fix found for this entry.
(host == \"deliver-hls.channel5.com\") => Error: No automatic fix found for this entry.
(host == \"akahls.channel5.com\") => Error: No automatic fix found for this entry.
(host == \"llnwhls.channel5.com\") => Error: No automatic fix found for this entry.
(host == \"milkshake.tv\") => Error: No automatic fix found for this entry.
(host == \"
www.milkshake.tv\") => Error: No automatic fix found for this entry.
(host == \"trk-euwest.tidaltv.com\") => Error: No automatic fix found for this entry.
(host == \"mp.adverts.itv.com\") => Error: No automatic fix found for this entry.
(host == \"req.tidaltv.com\") => Error: No automatic fix found for this entry.
(host == \"s1.2mdn.net\") => Error: No automatic fix found for this entry.
(host == \"pes.itv.com\") => Error: No automatic fix found for this entry.
(host == \"ned.itv.com\") => Error: No automatic fix found for this entry.
(host == \"itvdotcom.2cnt.net\") => Error: No automatic fix found for this entry.
(host == \"tom.itv.com\") => Error: No automatic fix found for this entry.
(host == \"dave.uktv.co.uk\") => Error: No automatic fix found for this entry.
(host == \"uktvplay.uktv.co.uk\") => Error: No automatic fix found for this entry.
(host == \"uktvhdse.brightcove.com.edgesuite.net\") => Error: No automatic fix found for this entry.
(host == \"admin.brightcove.com\") => Error: No automatic fix found for this entry.
(host == \"really.uktv.co.uk\") => Error: No automatic fix found for this entry.
(host == \"yesterday.uktv.co.uk\") => Error: No automatic fix found for this entry.
(host == \"drama.uktv.co.uk\") => Error: No automatic fix found for this entry.
(host == \"live.tvplayer.com\") => Error: No automatic fix found for this entry.
(host == \"tvplayer.com\") => Error: No automatic fix found for this entry.
(host == \"sapi.tvplayer.com\") => Error: No automatic fix found for this entry.
(host == \"api.tvplayer.com\") => Error: No automatic fix found for this entry.
(host == \"
www.gamefront.com\") => Error: No automatic fix found for this entry.
(url.indexOf(\"proxmate=uk\") != -1) => Error: No automatic fix found for this entry.
(host == \"channel4.com\") => Error: No automatic fix found for this entry.
(host == \"ais.channel4.com\") => Error: No automatic fix found for this entry.
(host == \"pandr.my.channel4.com\") => Error: No automatic fix found for this entry.
(host == \"all4nav.channel4.com\") => Error: No automatic fix found for this entry.
{ return 'PROXY uk-node.proxmate.me:8008' } else if ((host == \"link.theplatform.com\") => No running process found
(host == \"discidevflash-f.akamaihd.net\") => Error: No automatic fix found for this entry.
(host == \"api.geoip.dp.discovery.com\") => Error: No automatic fix found for this entry.
(host == \"vidtech.cbsinteractive.com\") => Error: No automatic fix found for this entry.
(host == \"vidtech.cbsima.com\") => Error: No automatic fix found for this entry.
(host == \"om.cbsi.com\") => Error: No automatic fix found for this entry.
(host == \"media.mtvnservices.com\") => Error: No automatic fix found for this entry.
(host == \"api-manga.crunchyroll.com\") => Error: No automatic fix found for this entry.
(host == \"crunchyroll.com\") => Error: No automatic fix found for this entry.
(host == \"
www.crunchyroll.com\") => Error: No automatic fix found for this entry.
(host == \"cdn.wwtv.warnerbros.com\") => Error: No automatic fix found for this entry.
(host == \"hlsioscwtv.warnerbros.com\") => Error: No automatic fix found for this entry.
(host == \"media.cwtv.com\") => Error: No automatic fix found for this entry.
(host == \"servicesaetn-a.akamaihd.net\") => Error: No automatic fix found for this entry.
(host == \"live.mlssoccer.com\") => Error: No automatic fix found for this entry.
(host == \"tvewnbc-i.akamaihd.net\") => Error: No automatic fix found for this entry.
(host == \"tvenbceast-i.akamaihd.net\") => Error: No automatic fix found for this entry.
(host == \"nbcmpx-vh.akamaihd.net\") => Error: No automatic fix found for this entry.
(host == \"
www.pandora.com\") => Error: No automatic fix found for this entry.
(host == \"video.pbs.org\") => Error: No automatic fix found for this entry.
(host == \"ga.video.cdn.pbs.org\") => Error: No automatic fix found for this entry.
(host == \"urs.pbs.org\") => Error: No automatic fix found for this entry.
(host == \"play.spotify.com\") => Error: No automatic fix found for this entry.
(host == \"
www.spotify.com\") => Error: No automatic fix found for this entry.
(host == \"play.spotify.edgekey.net\") => Error: No automatic fix found for this entry.
(host == \"
www.iheart.com\") => Error: No automatic fix found for this entry.
(host == \"api2.iheart.com\") => Error: No automatic fix found for this entry.
(host == \"api.iheart.com\") => Error: No automatic fix found for this entry.
(host == \"iheart.com\") => Error: No automatic fix found for this entry.
(host == \"nick.mtvnimages.com\") => Error: No automatic fix found for this entry.
(host == \"sni-vh.akamaihd.net\") => Error: No automatic fix found for this entry.
(url.indexOf(\"proxmate=us\") != -1) => Error: No automatic fix found for this entry.
(url.indexOf(\".googlevideo.com\") != -1) => Error: No automatic fix found for this entry.
(host == \"api.segment.io\") => Error: No automatic fix found for this entry.
(host == \"
www.vevo.com\") => Error: No automatic fix found for this entry.
(host == \"vevo.com\") => Error: No automatic fix found for this entry.
(host == \"apiv2.vevo.com\") => Error: No automatic fix found for this entry.
(host == \"songza.com\") => Error: No automatic fix found for this entry.
(host == \"new.songza.com\") => Error: No automatic fix found for this entry.
(host == \"
www.daisuki.net\") => Error: No automatic fix found for this entry.
(host == \"bngn-vh.akamaihd.net\") => Error: No automatic fix found for this entry.
(host == \"bngnwww.b-ch.com\") => Error: No automatic fix found for this entry.
(host == \"
www.hbogo.com\") => Error: No automatic fix found for this entry.
(host == \"catalog.lv3.hbogo.com\") => Error: No automatic fix found for this entry.
(host == \"profile.lv3.hbogo.com\") => Error: No automatic fix found for this entry.
(host == \"profile.hbogo.com\") => Error: No automatic fix found for this entry.
(url.indexOf(\".lv3.hbogo.com\") != -1) => Error: No automatic fix found for this entry.
(host == \"register.hbogo.com\") => Error: No automatic fix found for this entry.
(host == \"play.hbogo.com\") => Error: No automatic fix found for this entry.
(host == \"smetrics.hbogo.com\") => Error: No automatic fix found for this entry.
(url.indexOf(\".lv3.cdn.hbo.com\") != -1) => Error: No automatic fix found for this entry.
(host == \"comet.api.hbo.com\") => Error: No automatic fix found for this entry.
(host == \"play.google.com\") => Error: No automatic fix found for this entry.
(host == \"checkout.google.com\") => Error: No automatic fix found for this entry.
(host == \"store.google.com\") => Error: No automatic fix found for this entry.
(host == \"apis.google.com\") => Error: No automatic fix found for this entry.
(host == \"amc350888def-vh.akamaihd.net\") => Error: No automatic fix found for this entry.
(host == \"a564avoddashnsus-a.akamaihd.net\") => Error: No automatic fix found for this entry.
(host == \"atv-ps.amazon.com\") => Error: No automatic fix found for this entry.
(host == \"
www.amazon.com\") => Error: No automatic fix found for this entry.
(host == \"amazon.com\") => Error: No automatic fix found for this entry.
(host == \"fls-na.amazon.com\") => Error: No automatic fix found for this entry.
(host == \"phds-vod.cdn.turner.com\") => Error: No automatic fix found for this entry.
(host == \"token.vgtf.net\") => Error: No automatic fix found for this entry.
(host == \"
www.ondemandkorea.com\") => Error: No automatic fix found for this entry.
(host == \"
www.fxnetworks.com\") => Error: No automatic fix found for this entry.
(host == \"fxvcms-f.akamaihd.net\") => Error: No automatic fix found for this entry.
(host == \"tvetelemundo-vh.akamaihd.net\") => Error: No automatic fix found for this entry.
(host == \"feed.theplatform.com\") => Error: No automatic fix found for this entry.
(host == \"fsvideohds-vh.akamaihd.net\") => Error: No automatic fix found for this entry.
(host == \"watchable.com\") => Error: No automatic fix found for this entry.
(host == \"cilhlsvod-f.akamaihd.net\") => Error: No automatic fix found for this entry.
(host == \"oxygenvod-vh.akamaihd.net\") => Error: No automatic fix found for this entry.
(host == \"tvesyfy-vh.akamaihd.net\") => Error: No automatic fix found for this entry.
(host == \"
www.smithsonianchannel.com\") => Error: No automatic fix found for this entry.
(host == \"c.brightcove.com\") => Error: No automatic fix found for this entry.
(host == \"brightcove01.brightcove.com\") => Error: No automatic fix found for this entry.
(host == \"edge.api.brightcove.com\") => Error: No automatic fix found for this entry.
(host == \"
www.eonline.com\") => Error: No automatic fix found for this entry.
(host == \"link.theplatform.com\") => Error: No automatic fix found for this entry.
(host == \"api.listenlive.co\") => Error: No automatic fix found for this entry.
(host == \"playerservices.streamtheworld.com\") => Error: No automatic fix found for this entry.
(host == \"player.listenlive.co\") => Error: No automatic fix found for this entry.
(url.indexOf(\"live.streamtheworld.com\") != -1) => Error: No automatic fix found for this entry.
(host == \"
www.cartoonnetwork.com\") => Error: No automatic fix found for this entry.
(host == \"
www.viki.com\") => Error: No automatic fix found for this entry.
(host == \"\\\"
www.viki.com\") => Error: No automatic fix found for this entry.
(host == \"
www.origin.com\") => Error: No automatic fix found for this entry.
(host == \"ht.cdn.turner.com\") => Error: No automatic fix found for this entry.
(host == \"aolvideoshd-vh.akamaihd.net\") => Error: No automatic fix found for this entry.
(host == \"syn.5min.com\") => Error: No automatic fix found for this entry.
(host == \"stvideos.5min.com\") => Error: No automatic fix found for this entry.
(host == \"
www.showtime.com\") => Error: No automatic fix found for this entry.
(host == \"secure.showtime.com\") => Error: No automatic fix found for this entry.
(url.indexOf(\".vgtf.net\") != -1) => Error: No automatic fix found for this entry.
(host == \"phds-live.cdn.turner.com\") => Error: No automatic fix found for this entry.
(host == \"api.amplitude.com\") => Error: No automatic fix found for this entry.
(host == \"order.rhapsody.com\") => Error: No automatic fix found for this entry.
(host == \"payment.rhapsody.com\") => Error: No automatic fix found for this entry.
(host == \"
www.pivot.tv\") => Error: No automatic fix found for this entry.
(host == \"js.maxmind.com\") => Error: No automatic fix found for this entry.
{ return 'PROXY us-node.proxmate.me:8008' } else if ((host == \"livestreams.omroep.nl\") => No running process found
(host == \".npostreaming.nl\") => Error: No automatic fix found for this entry.
(host == \"ida.omroep.nl\") => Error: No automatic fix found for this entry.
(host == \"npoplayer.omroep.nl\") => Error: No automatic fix found for this entry.
(host == \"
www.zapp.nl\") => Error: No automatic fix found for this entry.
(host == \"tellerapi.omroep.nl\") => Error: No automatic fix found for this entry.
(host == \"e.omroep.nl\") => Error: No automatic fix found for this entry.
(url.indexOf(\"proxmate=nl\") != -1)) { return 'PROXY nl-node.proxmate.me:8008' } else if ((host == \"tvthek.orf.at\") => Error: No automatic fix found for this entry.
(host == \"apasfiisl.apa.at\") => Error: No automatic fix found for this entry.
(host == \"orf.oewabox.at\") => Error: No automatic fix found for this entry.
(host == \"194.232.200.58\") => Error: No automatic fix found for this entry.
(host == \"185.85.28.1\") => Error: No automatic fix found for this entry.
(host == \"atvplus.oewabox.at\") => Error: No automatic fix found for this entry.
(host == \"cdn.atv.at\") => Error: No automatic fix found for this entry.
(url.indexOf(\"proxmate=at\") != -1) => Error: No automatic fix found for this entry.
(host == \"hdsvodsportsman-vh.akamaihd.net\") => Error: No automatic fix found for this entry.
(host == \"streamaccess.unas.tv\") => Error: No automatic fix found for this entry.
(host == \"
www.laola1.tv\") => Error: No automatic fix found for this entry.
(host == \"
www.livestation.com\") => Error: No automatic fix found for this entry.
(host == \"livestation.com\") => Error: No automatic fix found for this entry.
(url.indexOf(\".emigrantas.tv\") != -1)) { return 'PROXY at-node.proxmate.me:8008' } else if ((host == \"netflix.com\") => Error: No automatic fix found for this entry.
(host == \"
www.netflix.com\") => Error: No automatic fix found for this entry.
(host == \"cbp-us.nccp.netflix.com\") => Error: No automatic fix found for this entry.
(host == \"secure.netflix.com\") => Error: No automatic fix found for this entry.
(host == \"api-global.netflix.com\") => Error: No automatic fix found for this entry.
(host == \"ichnaea.netflix.com\") => Error: No automatic fix found for this entry.
(host == \"customerevents.netflix.com\") => Error: No automatic fix found for this entry.
{ return 'PROXY usnet-node.proxmate.me:8008' } else if ((host == \"s.hulu.com\") => No running process found
(host == \"
www.funimation.com\") => Error: No automatic fix found for this entry.
(host == \"wpc.8c48.edgecastcdn.net\") => Error: No automatic fix found for this entry.
(host == \"southpark.cc.com\") => Error: No automatic fix found for this entry.
(host == \"api.utils.watchabc.go.com\") => Error: No automatic fix found for this entry.
(host == \"
www.dramafever.com\") => Error: No automatic fix found for this entry.
(host == \"
www.logotv.com\") => Error: No automatic fix found for this entry.
(host == \"api.watchabc.go.com\") => Error: No automatic fix found for this entry.
(host == \"theanimenetwork.com\") => Error: No automatic fix found for this entry.
(host == \"huluim.com\") => Error: No automatic fix found for this entry.
(host == \"
www.hulu.com\") => Error: No automatic fix found for this entry.
(host == \"t2.hulu.com\") => Error: No automatic fix found for this entry.
(host == \"urlcheck.hulu.com\") => Error: No automatic fix found for this entry.
(host == \"t.hulu.com\") => Error: No automatic fix found for this entry.
(host == \"s.hulu.com\") => Error: No automatic fix found for this entry.
(host == \"play.hulu.com\") => Error: No automatic fix found for this entry.
{ return 'PROXY ush-node.proxmate.me:8008' } else if ((host == \"player.ooyala.com\") => No running process found
{ return 'PROXY auv-node.proxmate.me:8008' } else if ((host == \"web-api-us.crackle.com\") => No running process found
{ return 'PROXY us2-node.proxmate.me:8008' } else if ((host == \"counter.yadro.ru\") => No running process found
(host == \"turbik.tv\") => Error: No automatic fix found for this entry.
(host == \"player.rutv.ru\") => Error: No automatic fix found for this entry.
(host == \"api.rutv.ru\") => Error: No automatic fix found for this entry.
(host == \"cdnng.v.rtr-vesti.ru\") => Error: No automatic fix found for this entry.
(host == \"player.vgtrk.com\") => Error: No automatic fix found for this entry.
(url.indexOf(\"proxmate=ru\") != -1) => Error: No automatic fix found for this entry.
(host == \"stream.1tv.ru\") => Error: No automatic fix found for this entry.
{ return 'PROXY ru-node.proxmate.me:8008' } else if ((host == \"security.video.globo.com\") => No running process found
(host == \"api.globovideos.com\") => Error: No automatic fix found for this entry.
(host == \"s.videos.globo.com\") => Error: No automatic fix found for this entry.
(host == \"gshow.globo.com\") => Error: No automatic fix found for this entry.
(host == \"voddownload02.video.globo.com\") => Error: No automatic fix found for this entry.
(host == \"secure.nuuvem.com\") => Error: No automatic fix found for this entry.
{ return 'PROXY br-node.proxmate.me:8008' } else if ((host == \"
www.bbc.co.uk\") => No running process found
(host == \"open.live.bbc.co.uk\") => Error: No automatic fix found for this entry.
(host == \"fig.bbc.co.uk\") => Error: No automatic fix found for this entry.
(host == \"vod-hds-uk-live.edgesuite.net\") => Error: No automatic fix found for this entry.
(host == \"vod-hds-uk-live.bbcfmt.vo.llnwd.net\") => Error: No automatic fix found for this entry.
(host == \"vs-hds-uk-live.bbcfmt.vo.llnwd.net\") => Error: No automatic fix found for this entry.
(host == \"vs-hds-uk-live.edgesuite.net\") => Error: No automatic fix found for this entry.
{ return 'PROXY ukb-node.proxmate.me:8008' } else { return 'DIRECT'; }}" => No running process found
Firefox Proxy settings were reset.
Firefox Proxy settings were reset.
Firefox Proxy settings were reset.
Firefox Proxy settings were reset.
Firefox Proxy settings were reset.
Firefox Proxy settings were reset.
Firefox Proxy settings were reset.
Firefox Proxy settings were reset.
Firefox Proxy settings were reset.
Firefox Proxy settings were reset.
Firefox Proxy settings were reset.
Firefox Proxy settings were reset.
Firefox Proxy settings were reset.
Firefox Proxy settings were reset.
Firefox Proxy settings were reset.
Firefox Proxy settings were reset.
Firefox Proxy settings were reset.
HKCR\PROTOCOLS\Handler\tmtbim => key not found.
HKCR\CLSID\{0B37915C-8B98-4B9E-80D4-464D2C830D10} => key not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{97ab88ef-346b-4179-a0b1-7445896547a5} => value removed successfully
HKCR\CLSID\{97ab88ef-346b-4179-a0b1-7445896547a5} => key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{42DFA04F-0F16-418e-B80C-AB97A5AFAD3A} => value removed successfully
HKCR\Wow6432Node\CLSID\{42DFA04F-0F16-418e-B80C-AB97A5AFAD3A} => key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{97ab88ef-346b-4179-a0b1-7445896547a5} => value removed successfully
HKCR\Wow6432Node\CLSID\{97ab88ef-346b-4179-a0b1-7445896547a5} => key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c8d5d964-2be8-4c5b-8cf5-6e975aa88504} => key removed successfully
HKCR\Wow6432Node\CLSID\{c8d5d964-2be8-4c5b-8cf5-6e975aa88504} => key not found.
HKLM\SOFTWARE\Policies\Microsoft\Internet Traveller: Restriction <======= ATTENTION => Error: No automatic fix found for this entry.
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\SOFTWARE\Policies\Microsoft\Internet Traveller: Restriction <======= ATTENTION => Error: No automatic fix found for this entry.
HKLM\Software\Microsoft\Internet Traveller\Main,Start Page = about:blank => Error: No automatic fix found for this entry.
HKLM\Software\Wow6432Node\Microsoft\Internet Traveller\Main,Start Page = about:blank => Error: No automatic fix found for this entry.
HKLM\Software\Microsoft\Internet Traveller\Main,Search Page = => Error: No automatic fix found for this entry.
HKLM\Software\Wow6432Node\Microsoft\Internet Traveller\Main,Search Page = => Error: No automatic fix found for this entry.
HKLM\Software\Microsoft\Internet Traveller\Main,Default_Page_URL = => Error: No automatic fix found for this entry.
HKLM\Software\Wow6432Node\Microsoft\Internet Traveller\Main,Default_Page_URL = => Error: No automatic fix found for this entry.
HKLM\Software\Microsoft\Internet Traveller\Main,Default_Search_URL = => Error: No automatic fix found for this entry.
HKLM\Software\Wow6432Node\Microsoft\Internet Traveller\Main,Default_Search_URL = => Error: No automatic fix found for this entry.
HKLM\Software\Microsoft\Internet Traveller\Main,Local Page = => Error: No automatic fix found for this entry.
HKLM\Software\Wow6432Node\Microsoft\Internet Traveller\Main,Local Page = => Error: No automatic fix found for this entry.
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\Software\Microsoft\Internet Traveller\Main,Start Page = about:blank => Error: No automatic fix found for this entry.
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56B90406-7F40-474C-AC73-88B4F2C484EF} => key removed successfully
HKCR\CLSID\{56B90406-7F40-474C-AC73-88B4F2C484EF} => key not found.
HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{54997AEA-6BE5-4B1D-AA3A-01377EAF9D27}\\DhcpNameServer => value removed successfully
HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{7B4C56F8-54B9-49AE-AC24-2E617300C9FC}\\DhcpNameServer => value removed successfully
HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{98FE26F2-9E79-4C35-8D23-4F5B94D8526A}\\DhcpNameServer => value removed successfully
HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local\\ActivePolicy => value removed successfully
C:\Windows\system32\GroupPolicy\Machine => moved successfully
C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully
C:\Windows\SysWOW64\GroupPolicy\GPT.ini => moved successfully
C:\Windows\system32\GroupPolicy\User => moved successfully
"C:\Windows\system32\GroupPolicy\Machine" => not found.
HKLM\SOFTWARE\Policies\Google => key removed successfully
C:\Program Files (x86)\Common Files\wruninstall.exe => not found.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install LastPass IE RunOnce.lnk => moved successfully
C:\Program Files (x86)\Common Files\wruninstall.exe => not found.
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\"DropboxExt1" => key removed successfully
HKCR\Wow6432Node\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => key not found.
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\"DropboxExt2" => key removed successfully
HKCR\Wow6432Node\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => key not found.
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\"DropboxExt3" => key removed successfully
HKCR\Wow6432Node\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => key not found.
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\"DropboxExt4" => key removed successfully
HKCR\Wow6432Node\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => key not found.
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\"DropboxExt5" => key removed successfully
HKCR\Wow6432Node\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => key not found.
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\"DropboxExt6" => key removed successfully
HKCR\Wow6432Node\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => key not found.
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\"DropboxExt7" => key removed successfully
HKCR\Wow6432Node\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => key not found.
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\"DropboxExt8" => key removed successfully
HKCR\Wow6432Node\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => key not found.
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\1aCopyShExtError => key removed successfully
HKCR\CLSID\{83BEA36E-7680-4598-A4DF-994426F6E78D} => key not found.
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\2aCopyShExtSynced => key removed successfully
HKCR\CLSID\{845B7388-6F85-4F32-9FD5-F02DC7882B89} => key not found.
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\3aCopyShExtSyncing => key removed successfully
HKCR\CLSID\{F6378A7A-F753-449B-AE1B-997A96132E61} => key not found.
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\4aCopyShExtSyncingProg1 => key removed successfully
HKCR\CLSID\{3A511828-777D-46F8-82F4-5B530C1B3D9E} => key not found.
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\5aCopyShExtSyncingProg2 => key removed successfully
HKCR\CLSID\{C8C88204-5B14-40EC-BA72-8AEBC762047E} => key not found.
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\6aCopyShExtSyncingProg3 => key removed successfully
HKCR\CLSID\{ACFF45C3-3EEB-4351-86C2-6696BA264239} => key not found.
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\7aCopyShExtSyncingProg4 => key removed successfully
HKCR\CLSID\{29AF997F-488B-46F0-AE78-7146F1B89CC3} => key not found.
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\8aCopyShExtSyncingProg5 => key removed successfully
HKCR\CLSID\{03F9AD29-1C78-4B66-8890-B177B5430C53} => key not found.
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\"DropboxExt1" => key removed successfully
HKCR\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => key not found.
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\"DropboxExt2" => key removed successfully
HKCR\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => key not found.
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\"DropboxExt3" => key removed successfully
HKCR\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => key not found.
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\"DropboxExt4" => key removed successfully
HKCR\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => key not found.
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\"DropboxExt5" => key removed successfully
HKCR\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => key not found.
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\"DropboxExt6" => key removed successfully
HKCR\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => key not found.
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\"DropboxExt7" => key removed successfully
HKCR\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => key not found.
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\"DropboxExt8" => key removed successfully
HKCR\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => key not found.
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run\\Copy => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run\\ooVoo.exe => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run\\GarminExpressTrayApp => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DisableCMD => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispAppearancePage => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispBackgroundPage => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispSettingsPage => value removed successfully
HKU\S-1-5-18\...\Policies\Traveller: [NoViewOnDrive] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-18\...\Policies\Traveller: [DisableLocalMachineRun] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-18\...\Policies\Traveller: [DisableLocalMachineRunOnce] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-18\...\Policies\Traveller: [DisableCurrentUserRun] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-18\...\Policies\Traveller: [DisableCurrentUserRunOnce] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-18\...\Policies\Traveller: [NoViewContextMenu] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-18\...\Policies\Traveller: [NoShellSearchButton] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-18\...\Policies\Traveller: [NoFind] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-18\...\Policies\Traveller: [NoFile] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-18\...\Policies\Traveller: [HideClock] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-18\...\Policies\Traveller: [NoTrayContextMenu] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-18\...\Policies\Traveller: [NoTrayItemsDisplay] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-18\...\Policies\Traveller: [NoSetFolders] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-18\...\Policies\Traveller: [NoDevMgrUpdate] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-18\...\Policies\Traveller: [NoSetTaskbar] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-18\...\Policies\Traveller: [NoDeletePrinter] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-18\...\Policies\Traveller: [NoDFSTab] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-18\...\Policies\Traveller: [NoChangeStartMenu] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-18\...\Policies\Traveller: [NoLogoff] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-18\...\Policies\Traveller: [NoWindowsUpdate] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-18\...\Policies\Traveller: [NoEncryptOnMove] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-18\...\Policies\Traveller: [NoRunasInstallPrompt] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-18\...\Policies\Traveller: [NoResolveSearch] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-18\...\Policies\Traveller: [NoSaveSettings] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-18\...\Policies\Traveller: [NoHardwareTab] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-18\...\Policies\Traveller: [NoStartMenuSubFolders] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DisableCMD => value removed successfully
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispAppearancePage => value removed successfully
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispSettingsPage => value removed successfully
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\...\Policies\Traveller: [DisableLocalMachineRun] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\...\Policies\Traveller: [DisableLocalMachineRunOnce] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\...\Policies\Traveller: [DisableCurrentUserRun] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\...\Policies\Traveller: [DisableCurrentUserRunOnce] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\...\Policies\Traveller: [NoViewContextMenu] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\...\Policies\Traveller: [NoShellSearchButton] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\...\Policies\Traveller: [HideClock] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\...\Policies\Traveller: [NoTrayItemsDisplay] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\...\Policies\Traveller: [NoDevMgrUpdate] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\...\Policies\Traveller: [NoDeletePrinter] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\...\Policies\Traveller: [NoDFSTab] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\...\Policies\Traveller: [NoWindowsUpdate] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\...\Policies\Traveller: [NoEncryptOnMove] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\...\Policies\Traveller: [NoRunasInstallPrompt] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\...\Policies\Traveller: [NoResolveSearch] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\...\Policies\Traveller: [NoSaveSettings] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\...\Policies\Traveller: [NoHardwareTab] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\...\Policies\Traveller: [NoStartMenuSubFolders] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8185036d-bf50-11e5-82f9-14feb5c3027f} => key removed successfully
HKCR\CLSID\{8185036d-bf50-11e5-82f9-14feb5c3027f} => key not found.
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b491a930-679a-11e3-825e-00dbdf2de1f9} => key removed successfully
HKCR\CLSID\{b491a930-679a-11e3-825e-00dbdf2de1f9} => key not found.
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e5212153-5f05-11e3-8251-806e6f6e6963} => key removed successfully
HKCR\CLSID\{e5212153-5f05-11e3-8251-806e6f6e6963} => key not found.
HKU\S-1-5-21-925185676-1098965860-4220522822-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Google Update => value removed successfully
HKLM\...\Policies\Traveller: [DisableLocalMachineRun] 0 => Error: No automatic fix found for this entry.
HKLM\...\Policies\Traveller: [DisableLocalMachineRunOnce] 0 => Error: No automatic fix found for this entry.
HKLM\...\Policies\Traveller: [DisableCurrentUserRun] 0 => Error: No automatic fix found for this entry.
HKLM\...\Policies\Traveller: [DisableCurrentUserRunOnce] 0 => Error: No automatic fix found for this entry.
HKLM\...\Policies\Traveller: [NoViewContextMenu] 0 => Error: No automatic fix found for this entry.
HKLM\...\Policies\Traveller: [NoShellSearchButton] 0 => Error: No automatic fix found for this entry.
HKLM\...\Policies\Traveller: [HideClock] 0 => Error: No automatic fix found for this entry.
HKLM\...\Policies\Traveller: [NoTrayItemsDisplay] 0 => Error: No automatic fix found for this entry.
HKLM\...\Policies\Traveller: [NoDevMgrUpdate] 0 => Error: No automatic fix found for this entry.
HKLM\...\Policies\Traveller: [NoDeletePrinter] 0 => Error: No automatic fix found for this entry.
HKLM\...\Policies\Traveller: [NoDFSTab] 0 => Error: No automatic fix found for this entry.
HKLM\...\Policies\Traveller: [NoWindowsUpdate] 0 => Error: No automatic fix found for this entry.
HKLM\...\Policies\Traveller: [NoEncryptOnMove] 0 => Error: No automatic fix found for this entry.
HKLM\...\Policies\Traveller: [NoRunasInstallPrompt] 0 => Error: No automatic fix found for this entry.
HKLM\...\Policies\Traveller: [NoResolveSearch] 0 => Error: No automatic fix found for this entry.
HKLM\...\Policies\Traveller: [NoSaveSettings] 0 => Error: No automatic fix found for this entry.
HKLM\...\Policies\Traveller: [NoHardwareTab] 0 => Error: No automatic fix found for this entry.
HKLM\...\Policies\Traveller: [NoStartMenuSubFolders] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DisableCMD => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispAppearancePage => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispBackgroundPage => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispSettingsPage => value removed successfully
HKU\S-1-5-19\...\Policies\Traveller: [NoViewOnDrive] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-19\...\Policies\Traveller: [DisableLocalMachineRun] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-19\...\Policies\Traveller: [DisableLocalMachineRunOnce] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-19\...\Policies\Traveller: [DisableCurrentUserRun] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-19\...\Policies\Traveller: [DisableCurrentUserRunOnce] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-19\...\Policies\Traveller: [NoViewContextMenu] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-19\...\Policies\Traveller: [NoShellSearchButton] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-19\...\Policies\Traveller: [NoFind] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-19\...\Policies\Traveller: [NoFile] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-19\...\Policies\Traveller: [HideClock] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-19\...\Policies\Traveller: [NoTrayContextMenu] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-19\...\Policies\Traveller: [NoTrayItemsDisplay] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-19\...\Policies\Traveller: [NoSetFolders] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-19\...\Policies\Traveller: [NoDevMgrUpdate] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-19\...\Policies\Traveller: [NoSetTaskbar] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-19\...\Policies\Traveller: [NoDeletePrinter] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-19\...\Policies\Traveller: [NoDFSTab] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-19\...\Policies\Traveller: [NoChangeStartMenu] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-19\...\Policies\Traveller: [NoLogoff] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-19\...\Policies\Traveller: [NoWindowsUpdate] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-19\...\Policies\Traveller: [NoEncryptOnMove] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-19\...\Policies\Traveller: [NoRunasInstallPrompt] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-19\...\Policies\Traveller: [NoResolveSearch] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-19\...\Policies\Traveller: [NoSaveSettings] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-19\...\Policies\Traveller: [NoHardwareTab] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-19\...\Policies\Traveller: [NoStartMenuSubFolders] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DisableCMD => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispAppearancePage => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispBackgroundPage => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispSettingsPage => value removed successfully
HKU\S-1-5-20\...\Policies\Traveller: [NoViewOnDrive] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-20\...\Policies\Traveller: [DisableLocalMachineRun] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-20\...\Policies\Traveller: [DisableLocalMachineRunOnce] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-20\...\Policies\Traveller: [DisableCurrentUserRun] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-20\...\Policies\Traveller: [DisableCurrentUserRunOnce] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-20\...\Policies\Traveller: [NoViewContextMenu] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-20\...\Policies\Traveller: [NoShellSearchButton] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-20\...\Policies\Traveller: [NoFind] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-20\...\Policies\Traveller: [NoFile] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-20\...\Policies\Traveller: [HideClock] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-20\...\Policies\Traveller: [NoTrayContextMenu] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-20\...\Policies\Traveller: [NoTrayItemsDisplay] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-20\...\Policies\Traveller: [NoSetFolders] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-20\...\Policies\Traveller: [NoDevMgrUpdate] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-20\...\Policies\Traveller: [NoSetTaskbar] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-20\...\Policies\Traveller: [NoDeletePrinter] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-20\...\Policies\Traveller: [NoDFSTab] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-20\...\Policies\Traveller: [NoChangeStartMenu] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-20\...\Policies\Traveller: [NoLogoff] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-20\...\Policies\Traveller: [NoWindowsUpdate] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-20\...\Policies\Traveller: [NoEncryptOnMove] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-20\...\Policies\Traveller: [NoRunasInstallPrompt] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-20\...\Policies\Traveller: [NoResolveSearch] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-20\...\Policies\Traveller: [NoSaveSettings] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-20\...\Policies\Traveller: [NoHardwareTab] 0 => Error: No automatic fix found for this entry.
HKU\S-1-5-20\...\Policies\Traveller: [NoStartMenuSubFolders] 0 => Error: No automatic fix found for this entry.
HKLM Group Policy restriction on software: cipher.exe <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.txt*.js <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.avi*.jse <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %appdata%\*\*.exe <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.mp3*.scr <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\*.jse <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.xlsx*.js <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.bmp*.pif <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.mp3*.pif <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wma*.exe <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.scr <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.xlsx*.exe <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.docx*.js <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.js <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.jpg*.scr <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.cmd <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wmv*.scr <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %appdata%\*\*.js <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.cmd <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: syskey.exe <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.scr <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.jse <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %appdata%\*\*.pif <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.rar*.js <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.rar*.cmd <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.txt*.cmd <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.doc*.jse <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.js <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.com <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.avi*.pif <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.mp4*.pif <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.jpg*.pif <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pub*.com <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.mp3*.jse <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wma*.pif <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\*.js <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pptx*.scr <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pub*.cmd <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pdf*.pif <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.mp3*.bat <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.xls*.jse <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.png*.pif <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pptx*.js <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.js <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.ppt*.cmd <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.png*.cmd <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.docx*.exe <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.doc*.exe <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: C:\Users\*.jse <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.xlsx*.scr <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.gif*.com <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pdf*.cmd <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\*.scr <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wmv*.com <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.doc*.pif <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\*.pif <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.rtf*.exe <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wav*.exe <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.png*.jse <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wma*.cmd <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.mp3*.js <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.pif <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.7z*.com <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.scr <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pdf*.bat <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %appdata%\*\*.scr <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.exe <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.docx*.bat <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pub*.jse <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\*.com <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %appdata%\*.js <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.gif*.exe <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.jpg*.jse <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: lsassw86s.exe <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.xls*.exe <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\*.jse <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.jpeg*.pif <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\*.bat <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.scr <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pub*.bat <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.rtf*.js <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.ppt*.exe <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.mp4*.jse <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\*.jse <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.jpg*.com <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.docx*.jse <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.avi*.scr <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.rtf*.jse <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wma*.com <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.jpeg*.jse <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wma*.bat <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.zip*.cmd <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.avi*.js <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: C:\Users\*.bat <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.avi*.bat <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.cmd <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %allusersprofile%\*.com <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.bmp*.scr <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.cmd <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.ppt*.pif <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.mp3*.cmd <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.xls*.com <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.txt*.exe <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pdf*.exe <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\*.bat <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\*.js <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programfiles(x86)%\*\svchost.exe <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.rtf*.com <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %appdata%\*\*.bat <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.bat <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.bat <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.rar*.pif <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.zip*.jse <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.mp4*.exe <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.jpeg*.exe <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %allusersprofile%\*.scr <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: C:\Users\*.pif <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pub*.exe <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.jpeg*.scr <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pub*.js <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.rtf*.scr <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wmv*.jse <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.exe <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.avi*.exe <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.png*.com <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wav*.js <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.gif*.js <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.pif <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.jpg*.cmd <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.exe <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: C:\Users\*.exe <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.jpeg*.bat <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.zip*.exe <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %appdata%\*.com <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.jse <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pptx*.exe <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: C:\Users\*.cmd <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.jpeg*.cmd <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\*.bat <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.js <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.exe <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.bat <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.bat <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.divx*.jse <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.divx*.com <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.exe <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.rar*.scr <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: ** <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wma*.scr <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.scr <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.pif <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.bmp*.cmd <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.doc*.scr <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %appdata%\*.pif <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pdf*.jse <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.jse <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wav*.com <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\*.pif <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\*.scr <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\*.cmd <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pdf*.com <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.pif <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.txt*.com <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.rtf*.pif <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wmv*.bat <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.rtf*.cmd <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.xls*.js <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.docx*.pif <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.txt*.scr <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wav*.jse <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.divx*.scr <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.rar*.exe <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.exe <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.xlsx*.cmd <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wma*.jse <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.mp4*.scr <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.doc*.cmd <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.7z*.cmd <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.exe <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %appdata%\*.exe <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\*.js <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wav*.pif <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.jpeg*.com <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.7z*.scr <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.png*.scr <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: scsvserv.exe <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.bmp*.js <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.xlsx*.jse <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pub*.pif <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.png*.bat <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wmv*.exe <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.txt*.jse <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %appdata%\*\*.com <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\*.exe <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.bat <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.gif*.cmd <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\*.exe <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pptx*.jse <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.gif*.jse <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.xls*.cmd <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.rar*.com <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wav*.scr <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.xlsx*.com <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.bmp*.bat <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.cmd <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.rar*.bat <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.scr <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.xls*.pif <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.ppt*.bat <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\Appdata\Roaming\Microsoft\Windows\IEUpdate\*.exe <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.jse <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\*.cmd <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.com <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %allusersprofile%\*.cmd <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\*\svchost.exe <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: vssadmin.exe <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pub*.scr <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pptx*.com <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wmv*.pif <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.doc*.bat <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.txt*.bat <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.zip*.com <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *:\$Recycle.Bin <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pptx*.pif <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.com <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.docx*.com <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.js <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wmv*.cmd <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: C:\Users\*.scr <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.avi*.cmd <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.zip*.bat <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\*.cmd <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.com <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %systemdrive%\*\svchost.exe <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.txt*.pif <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.pif <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.gif*.bat <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %appdata%\*\*.cmd <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %appdata%\*.jse <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.bat <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %allusersprofile%\*.jse <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.mp4*.bat <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.com <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.pif <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.7z*.pif <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.mp4*.js <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wmv*.js <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %allusersprofile%\*.exe <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %allusersprofile%\*.js <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.xlsx*.bat <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.png*.js <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pptx*.bat <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: C:\Users\*.js <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.divx*.exe <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wma*.js <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.divx*.bat <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.avi*.com <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wav*.cmd <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.bmp*.com <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %appdata%\*\*.jse <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.ppt*.com <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %appdata%\*.scr <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\*.pif <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wav*.bat <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.zip*.pif <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.jpeg*.js <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\*.com <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.docx*.cmd <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.mp4*.com <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.7z*.js <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.xlsx*.pif <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pptx*.cmd <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.zip*.js <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.zip*.scr <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.jpg*.exe <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.7z*.bat <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pdf*.scr <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.xls*.bat <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.mp4*.cmd <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\*.exe <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: lsassvrtdbks.exe <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.docx*.scr <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.js <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.rtf*.bat <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.rar*.jse <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.7z*.jse <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.cmd <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.xls*.scr <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.doc*.js <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\*.scr <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.gif*.scr <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.pif <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %allusersprofile%\*.bat <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.js <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.jpg*.js <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.divx*.pif <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.mp3*.exe <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.ppt*.js <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programfiles%\*\svchost.exe <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.cmd <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.ppt*.scr <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %allusersprofile%\*.pif <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.com <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.jse <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.divx*.cmd <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.bmp*.exe <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %appdata%\*.bat <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.mp3*.com <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.bat <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.scr <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.bmp*.jse <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.ppt*.jse <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.gif*.pif <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %appdata%\*.cmd <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.jse <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\*.com <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.jse <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.jpg*.bat <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.divx*.js <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pdf*.js <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.doc*.com <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.com <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.7z*.exe <====== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.png*.exe <====== ATTENTION => restored successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => value not found.
========= RD /S /Q %WinDir%\System32\GroupPolicyUsers =========
========= End of CMD: =========
========= RD /S /Q %WinDir%\System32\GroupPolicy =========
========= End of CMD: =========
========= RD /S /Q %WinDir%\SysWOW64\GroupPolicyUsers =========
========= End of CMD: =========
========= RD /S /Q %WinDir%\SysWOW64\GroupPolicy =========
========= End of CMD: =========
========= RD /S /Q %WinDir%\SysNative\GroupPolicyUsers =========
The system cannot find the path specified.
========= End of CMD: =========
========= RD /S /Q %WinDir%\SysNative\GroupPolicy =========
The system cannot find the path specified.
========= End of CMD: =========
========= gpupdate /force =========
Updating policy...
Computer Policy update has completed successfully.
User Policy update has completed successfully.
========= End of CMD: =========
========= bitsadmin /reset /allusers =========
BITSADMIN version 3.0 [ 7.7.9600 ]
BITS administration utility.
(C) Copyright 2000-2006 Microsoft Corp.
BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.
Unable to cancel {46BD48A5-CD80-45E0-B4AD-B14688AD27BE}.
0 out of 1 jobs canceled.
========= End of CMD: =========
========= reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f =========
The operation completed successfully.
========= End of Reg: =========
========= reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f =========
The operation completed successfully.
========= End of Reg: =========
========= netsh advfirewall reset =========
Ok.
========= End of CMD: =========
========= netsh advfirewall set allprofiles state ON =========
Ok.
========= End of CMD: =========
========= ipconfig /flushdns =========
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
========= End of CMD: =========
=========== EmptyTemp: ==========
BITS transfer queue => 16777216 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 6564754 B
Java, Flash, Steam htmlcache => 914 B
Windows/system/drivers => 209458152 B
Edge => 0 B
Chrome => 543675531 B
Firefox => 212319627 B
Opera => 131743379 B
Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 330231 B
systemprofile32 => 216009 B
LocalService => 4808 B
NetworkService => 63926146 B
Traveller => 1381725440 B
UpdatusUser => 0 B
UpdatusUser => 0 B
named => 0 B
RecycleBin => 0 B
EmptyTemp: => 2.4 GB temporary data Removed.
================================
Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 23-02-2017 21:34:37)
C:\Windows\system32\Drivers\etc\hosts => Is moved successfully
Hosts restored successfully.
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
"C:\ProgramData\WRData" => Could not move
==== End of Fixlog 21:34:41 ====