It is possible - please don't worry!First stumblng block!
I ran the QTL : Run Fix Sript aa instructed.
It appears to have ``hung`. It ran for 2 hours and 17 minutes with the egg timer shown. Microsoft showed it as `program not responding`.
I will cancel it and retry hoping for better results. Will be back to you later!
Stay Tuned!
Let split OTL - Run Fix Script instruction to two parts:
Step 1. Part 1.
OTL - Run Fix Script
You should still have OTL.exe on your desktop.
Important! Close all applications and windows so that you have nothing open and are at your Desktop.
- Right click on OTL.exe, select "Run As Administrator..." to run it. If prompted by UAC, please allow it.
- Underneath Output at the top, make sure Standard Output is selected.
- Copy and Paste the following code into the text box. Do not include the word Code
- Code: Select all
:Commands [CREATERESTOREPOINT] :Files C:\Users\Luvfishn\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\KSFD0CVG\bar.utorrent[1].xml C:\Users\Luvfishn\AppData\Roaming\Microsoft\Windows\Cookies\Low\bob@utorrent[2].txt C:\Users\Luvfishn\AppData\Roaming\Microsoft\Windows\Recent\utorrent.lnk C:\Users\Luvfishn\AppData\Roaming\Mozilla\Firefox\Profiles\uldhlbwj.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\chrome\utorrentbar.jar C:\Users\Luvfishn\AppData\Roaming\Mozilla\Firefox\Profiles\uldhlbwj.default\extensions\{e9df9360-97f8-4690-afe6-996c80790da4}\chrome\utorrentcontrol.jar C:\Users\Luvfishn\AppData\Roaming\uTorrent\utorrent.lng C:\Users\Luvfishn\AppData\Local\Temp\Low\Temporary Internet Files\Content.IE5\1IDKEM6G\appsmetadata_toolbar_conduit-services_com[1].txt C:\Users\Luvfishn\AppData\Local\Temp\Low\Temporary Internet Files\Content.IE5\WLDF2BMN\conduit[1].htm C:\Users\Luvfishn\AppData\LocalLow\Conduit\Community Alerts\Feeds\http___alerts_conduit-services_com_root_1463703_1459357_US.xml C:\Users\Luvfishn\AppData\LocalLow\Conduit\Community Alerts\Feeds\http___alerts_conduit-services_com_root_997308_993027_CA.xml C:\Users\Luvfishn\AppData\Roaming\Mozilla\Firefox\Profiles\uldhlbwj.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\ConduitAutoCompleteSearch.js C:\Users\Luvfishn\AppData\Roaming\Mozilla\Firefox\Profiles\uldhlbwj.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\ConduitAutoCompleteSearch.xpt C:\Users\Luvfishn\AppData\Roaming\Mozilla\Firefox\Profiles\uldhlbwj.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\searchplugin\conduit.xml C:\Users\Luvfishn\AppData\Roaming\Mozilla\Firefox\Profiles\uldhlbwj.default\extensions\{e9df9360-97f8-4690-afe6-996c80790da4}\components\ConduitAutoCompleteSearch.js C:\Users\Luvfishn\AppData\Roaming\Mozilla\Firefox\Profiles\uldhlbwj.default\extensions\{e9df9360-97f8-4690-afe6-996c80790da4}\components\ConduitAutoCompleteSearch.xpt C:\Users\Luvfishn\AppData\Roaming\Mozilla\Firefox\Profiles\uldhlbwj.default\extensions\{e9df9360-97f8-4690-afe6-996c80790da4}\searchplugin\conduit.xml C:\Users\Luvfishn\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\W9FMZX7Q\mystart.incredibar[1].xml C:\Users\Luvfishn\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\W9FMZX7Q\search.incredibar[1].xml C:\Users\Luvfishn\AppData\Roaming\Mozilla\Firefox\Profiles\uldhlbwj.default\extensions\ffxtlbr@incredibar.com\content\incredibar.css C:\Users\Luvfishn\AppData\Roaming\Mozilla\Firefox\Profiles\uldhlbwj.default\extensions\ffxtlbr@incredibar.com\content\incredibar.xul C:\Boot\BCD.iobit C:\Program Files (x86)\IObit Toolbar\IE\6.6\iobitToolbarIE.dll C:\Program Files (x86)\IObit Toolbar\Res\iobit_logo.gif C:\Program Files (x86)\IObit Toolbar\Res\iobit_logo_hover.gif C:\Users\Luvfishn\ntuser.dat.iobit C:\Users\Luvfishn\AppData\Local\Microsoft\Windows\UsrClass.dat.iobit C:\Users\Luvfishn\AppData\Roaming\Microsoft\Windows\Cookies\bob@iobit[2].txt C:\Users\Luvfishn\AppData\Roaming\Microsoft\Windows\Cookies\bob@www.iobit[1].txt C:\Users\Luvfishn\AppData\Roaming\Microsoft\Windows\Cookies\bob@www.iobit[2].txt C:\Users\Luvfishn\AppData\Roaming\Microsoft\Windows\Cookies\Low\bob@www.iobit[1].txt C:\Users\Luvfishn\AppData\Roaming\Mozilla\Firefox\Profiles\uldhlbwj.default\{F0B1CEAC-7C0D-407c-B25E-623D7CBECCCB}\iobit.lock C:\Users\Luvfishn\Desktop\Desktop Icons\Security & Maintenance Tools\IObit Malware Fighter.lnk C:\Users\Luvfishn\Favorites\IObit Freeware (1).url C:\Users\Luvfishn\Favorites\IObit Freeware.URL C:\Users\Luvfishn\Favorites\From Internet Explorer\IObit Freeware.URL C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT.iobit C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT.iobit C:\Windows\System32\config\DEFAULT.iobit C:\Windows\System32\config\SAM.iobit C:\Windows\System32\config\SECURITY.iobit C:\Windows\System32\config\SOFTWARE.iobit C:\Windows\System32\config\SYSTEM.iobit C:\Users\Luvfishn\AppData\Roaming\uTorrent C:\Program Files (x86)\Conduit C:\Users\Luvfishn\AppData\Local\Conduit C:\Users\Luvfishn\AppData\LocalLow\Conduit C:\Users\Luvfishn\AppData\Roaming\Mozilla\Firefox\Profiles\uldhlbwj.default\conduitCommon C:\Users\Luvfishn\AppData\Local\Temp\mt_ffx\Incredibar.com C:\Users\Luvfishn\AppData\Local\Temp\mt_ffx\Incredibar.com\incredibar C:\Users\Luvfishn\AppData\Roaming\Mozilla\Firefox\Profiles\uldhlbwj.default\extensions\ffxtlbr@incredibar.com C:\IObit C:\Program Files (x86)\IObit C:\Program Files (x86)\IObit Toolbar C:\Program Files (x86)\IObit\IObit Malware Fighter C:\ProgramData\IObit C:\Users\All Users\IObit C:\Users\Default\AppData\Roaming\IObit C:\Users\Default\AppData\Roaming\IObit\IObit Malware Fighter C:\Users\Luvfishn\AppData\LocalLow\IObit C:\Users\Luvfishn\AppData\Roaming\IObit C:\Users\Luvfishn\AppData\Roaming\IObit\IObit Malware Fighter C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\IObit C:\ProgramData\Trusteer C:\Users\All Users\Trusteer C:\Users\Default\AppData\Local\Trusteer C:\Users\Luvfishn\AppData\Local\Trusteer
- Click under the Custom Scan/Fixes box and paste the copied text.
- Click the Run Fix button. If prompted... click OK.
- OTL may ask to reboot the machine. Please do so if asked.
- Let the program run unhindered and reboot the PC when it is done.
When the computer reboots, and you start your usual account, a Notepad text file will appear. - Copy the contents of that file and post it in your next reply. The log can also be found, based on the date/time it was created, as C:\_OTL\MovedFiles\MMDDYYYY_HHMMSS.log
Step 1. Part 2.
OTL - Run Fix Script
You should still have OTL.exe on your desktop.
Important! Close all applications and windows so that you have nothing open and are at your Desktop.
- Right click on OTL.exe, select "Run As Administrator..." to run it. If prompted by UAC, please allow it.
- Underneath Output at the top, make sure Standard Output is selected.
- Copy and Paste the following code into the text box. Do not include the word Code
- Code: Select all
:Commands [CREATERESTOREPOINT] :Reg [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\utorrent.com] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-941371534-4025170946-3007303680-1000\Software\Web Assistant\script_storage] "WSG_whiteList"=- [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\utorrent.com] [-HKEY_CURRENT_USER\Software\SpeedMaxPc\SpeedMaxPc\ScanSettings\File Sharing History\uTorrent 1.x] [-HKEY_CURRENT_USER\Software\SpeedyPC Software\SpeedyPC Pro\ScanSettings\File Sharing History\uTorrent 1.x] [-HKEY_CURRENT_USER\Software\Classes\Applications\uTorrent.exe] [HKEY_CURRENT_USER\Software\Classes\Applications\uTorrent.exe\shell\open\command] @="" [HKEY_CURRENT_USER\Software\Classes\btdna\DefaultIcon] @="" [HKEY_CURRENT_USER\Software\Classes\btdna\shell\open\command] @="" [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Program Files (x86)\uTorrent\uTorrent.exe"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Conduit\AppPaths\client] "AppPath"=- [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\uTorrent_RASAPI32] [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\uTorrent_RASMANCS] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "TCP Query User{6E9C0B30-12D4-4AF0-8371-F3350B23E7B1}C:\users\luvfishn\desktop\utorrent.exe"=- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "UDP Query User{9E12A92F-779B-4E65-BFD6-D57A9B6EF229}C:\users\luvfishn\desktop\utorrent.exe"=- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "TCP Query User{6E9C0B30-12D4-4AF0-8371-F3350B23E7B1}C:\users\luvfishn\desktop\utorrent.exe"=- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "UDP Query User{9E12A92F-779B-4E65-BFD6-D57A9B6EF229}C:\users\luvfishn\desktop\utorrent.exe"=- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "TCP Query User{6E9C0B30-12D4-4AF0-8371-F3350B23E7B1}C:\users\luvfishn\desktop\utorrent.exe"=- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "UDP Query User{9E12A92F-779B-4E65-BFD6-D57A9B6EF229}C:\users\luvfishn\desktop\utorrent.exe"=- [-HKEY_USERS\S-1-5-21-941371534-4025170946-3007303680-1000\Software\Microsoft\Internet Explorer\DOMStorage\utorrent.com] [HKEY_USERS\S-1-5-21-941371534-4025170946-3007303680-1000\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-941371534-4025170946-3007303680-1000\Software\Web Assistant\script_storage] "WSG_whiteList"=- [-HKEY_USERS\S-1-5-21-941371534-4025170946-3007303680-1000\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\utorrent.com] [-HKEY_USERS\S-1-5-21-941371534-4025170946-3007303680-1000\Software\SpeedMaxPc\SpeedMaxPc\ScanSettings\File Sharing History\uTorrent 1.x] [-HKEY_USERS\S-1-5-21-941371534-4025170946-3007303680-1000\Software\SpeedyPC Software\SpeedyPC Pro\ScanSettings\File Sharing History\uTorrent 1.x] [-HKEY_USERS\S-1-5-21-941371534-4025170946-3007303680-1000\Software\Classes\Applications\uTorrent.exe] [HKEY_USERS\S-1-5-21-941371534-4025170946-3007303680-1000\Software\Classes\Applications\uTorrent.exe\shell\open\command] @="" [HKEY_USERS\S-1-5-21-941371534-4025170946-3007303680-1000\Software\Classes\btdna\DefaultIcon] @="" [HKEY_USERS\S-1-5-21-941371534-4025170946-3007303680-1000\Software\Classes\btdna\shell\open\command] @="" [HKEY_USERS\S-1-5-21-941371534-4025170946-3007303680-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Program Files (x86)\uTorrent\uTorrent.exe"=- [HKEY_USERS\S-1-5-21-941371534-4025170946-3007303680-1000_Classes\Applications\uTorrent.exe] [HKEY_USERS\S-1-5-21-941371534-4025170946-3007303680-1000_Classes\Applications\uTorrent.exe\shell\open\command] @="" [HKEY_USERS\S-1-5-21-941371534-4025170946-3007303680-1000_Classes\btdna\DefaultIcon] @="" [HKEY_USERS\S-1-5-21-941371534-4025170946-3007303680-1000_Classes\btdna\shell\open\command] @="" [HKEY_USERS\S-1-5-21-941371534-4025170946-3007303680-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Program Files (x86)\uTorrent\uTorrent.exe"=- [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-941371534-4025170946-3007303680-1000\Software\Web Assistant\script_storage] "WSG_whiteList"=- [HKEY_USERS\S-1-5-21-941371534-4025170946-3007303680-1000\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-941371534-4025170946-3007303680-1000\Software\Web Assistant\script_storage] "WSG_whiteList"=- [-HKEY_CURRENT_USER\Software\AppDataLow\Software\Conduit] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-941371534-4025170946-3007303680-1000\Software\Web Assistant\script_storage] "WSG_whiteList"=- [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-941371534-4025170946-3007303680-1000\Software\Web Assistant\script_storage] "WSG_temp_referer"=- [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-941371534-4025170946-3007303680-1000\Software\Web Assistant\script_storage] "WSG_referrer"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3c471948-f874-49f5-b338-4f214a2ee0b1}] @="" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3c471948-f874-49f5-b338-4f214a2ee0b1}\InprocServer32] @="" [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Conduit] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Conduit\Community Alerts] "Path"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{3c471948-f874-49f5-b338-4f214a2ee0b1}] @="" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{3c471948-f874-49f5-b338-4f214a2ee0b1}\InprocServer32] @="" [HKEY_USERS\S-1-5-21-941371534-4025170946-3007303680-1000\Software\AppDataLow\Software\Conduit] [HKEY_USERS\S-1-5-21-941371534-4025170946-3007303680-1000\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-941371534-4025170946-3007303680-1000\Software\Web Assistant\script_storage] "WSG_whiteList"=- [HKEY_USERS\S-1-5-21-941371534-4025170946-3007303680-1000\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-941371534-4025170946-3007303680-1000\Software\Web Assistant\script_storage] "WSG_temp_referer"=- [HKEY_USERS\S-1-5-21-941371534-4025170946-3007303680-1000\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-941371534-4025170946-3007303680-1000\Software\Web Assistant\script_storage] "WSG_referrer"=- [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-941371534-4025170946-3007303680-1000\Software\Web Assistant\script_storage] "WSG_whiteList"=- [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes] "DoNotAskAgain"=- [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\FunmoodsSetup_RASAPI32] [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\FunmoodsSetup_RASMANCS] [HKEY_USERS\S-1-5-21-941371534-4025170946-3007303680-1000\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-941371534-4025170946-3007303680-1000\Software\Web Assistant\script_storage] "WSG_whiteList"=- [HKEY_USERS\S-1-5-21-941371534-4025170946-3007303680-1000\Software\Microsoft\Internet Explorer\SearchScopes] "DoNotAskAgain"=- [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-941371534-4025170946-3007303680-1000\Software\Web Assistant\script_storage] "WSG_whiteList"=- [HKEY_USERS\S-1-5-21-941371534-4025170946-3007303680-1000\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-941371534-4025170946-3007303680-1000\Software\Web Assistant\script_storage] "WSG_whiteList"=- [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\incredibar.com] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}] "URL"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{336D0C35-8A85-403a-B9D2-65C292C39087}_is1] "Publisher"=- [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\IncredibarToolbar_RASAPI32] [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\IncredibarToolbar_RASMANCS] [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\incredibar_install_RASAPI32] [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\incredibar_install_RASMANCS] [-HKEY_USERS\S-1-5-21-941371534-4025170946-3007303680-1000\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\incredibar.com] [HKEY_USERS\S-1-5-21-941371534-4025170946-3007303680-1000\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}] "URL"=- [-HKEY_CURRENT_USER\Software\AppDataLow\Software\IObit] [-HKEY_CURRENT_USER\Software\IObit] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-941371534-4025170946-3007303680-1000\Software\Web Assistant\script_storage] "WSG_whiteList"=- [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Program Files (x86)\IObit\Advanced SystemCare 6\Suc10_Uninstal.exe"=- [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Program Files (x86)\IObit\Advanced SystemCare 6\unins000.exe"=- [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\IObit Malware Fighter] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\//\//\IObit Cloud Anti-Malwre] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0BB81440-5F42-4480-A5F7-770A6F439FC8}\InprocServer32] @="" [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\IObit Malware Fighter] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\ShellEx\ContextMenuHandlers\IObit Malware Fighter] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\E5D7A28B1734BBF4793EA1C766649A33] "ProductName"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\E5D7A28B1734BBF4793EA1C766649A33\SourceList] "PackageName"=- [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\lnkfile\shellex\ContextMenuHandlers\IObit Malware Fighter] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{ACB9DC96-D7BB-430F-AE6B-97F0DFDEAFCC}\1.0\0\win64] @="" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{ACB9DC96-D7BB-430F-AE6B-97F0DFDEAFCC}\1.0\HELPDIR] @="" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{ACB9DC96-D7BB-430F-AE6B-97F0DFDEAFCC}\1.0\0\win64] @="" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{ACB9DC96-D7BB-430F-AE6B-97F0DFDEAFCC}\1.0\HELPDIR] @="" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0BDA0769-FD72-49F4-9266-E1FB004F4D8F}] "AppPath"="C:\Program Files (x86)\IObit Toolbar\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Microsoft-Windows-RDP-WinIP-Package-MiniLP~31bf3856ad364e35~amd64~en-US~7.1.7601.16398] "InstallLocation"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Microsoft-Windows-RDP-WinIP-Package-TopLevel~31bf3856ad364e35~amd64~~7.1.7601.16398] "InstallLocation"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Microsoft-Windows-RDP-WinIP-Package~31bf3856ad364e35~amd64~en-US~7.1.7601.16398] "InstallLocation"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Microsoft-Windows-RDP-WinIP-Package~31bf3856ad364e35~amd64~~7.1.7601.16398] "InstallLocation"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Microsoft-Windows-RemoteDesktopClient-WinIP-Package~31bf3856ad364e35~amd64~en-US~7.1.7601.16398] "InstallLocation"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Microsoft-Windows-RemoteDesktopClient-WinIP-Package~31bf3856ad364e35~amd64~~7.1.7601.16398] "InstallLocation"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Microsoft-Windows-RemoteDesktopService-WinIP-Package~31bf3856ad364e35~amd64~en-US~7.1.7601.16398] "InstallLocation"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Microsoft-Windows-RemoteDesktopService-WinIP-Package~31bf3856ad364e35~amd64~~7.1.7601.16398] "InstallLocation"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_1_for_KB2675157~31bf3856ad364e35~amd64~~9.4.1.0] "InstallLocation"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_1_for_KB2709981~31bf3856ad364e35~amd64~~6.1.2.0] "InstallLocation"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_26_for_KB2574819~31bf3856ad364e35~amd64~~6.1.1.7] "InstallLocation"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_27_for_KB2574819~31bf3856ad364e35~amd64~~6.1.1.7] "InstallLocation"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_29_for_KB2574819~31bf3856ad364e35~amd64~~6.1.1.7] "InstallLocation"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_2_for_KB2653956~31bf3856ad364e35~amd64~~6.1.1.5] "InstallLocation"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_2_for_KB2679255~31bf3856ad364e35~amd64~~6.1.2.0] "InstallLocation"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_3_for_KB2653956~31bf3856ad364e35~amd64~~6.1.1.5] "InstallLocation"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_3_for_KB2679255~31bf3856ad364e35~amd64~~6.1.2.0] "InstallLocation"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_9_for_KB2679255~31bf3856ad364e35~amd64~~6.1.2.0] "InstallLocation"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_for_KB2574819_SP1~31bf3856ad364e35~amd64~~6.1.1.7] "InstallLocation"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_for_KB2574819~31bf3856ad364e35~amd64~~6.1.1.7] "InstallLocation"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_for_KB2653956_SP1~31bf3856ad364e35~amd64~~6.1.1.5] "InstallLocation"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_for_KB2653956~31bf3856ad364e35~amd64~~6.1.1.5] "InstallLocation"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_for_KB2675157_RTM~31bf3856ad364e35~amd64~~9.4.1.0] "InstallLocation"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_for_KB2675157~31bf3856ad364e35~amd64~~9.4.1.0] "InstallLocation"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_for_KB2679255_RTM~31bf3856ad364e35~amd64~~6.1.2.0] "InstallLocation"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_for_KB2679255_SP1~31bf3856ad364e35~amd64~~6.1.2.0] "InstallLocation"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_for_KB2679255~31bf3856ad364e35~amd64~~6.1.2.0] "InstallLocation"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_for_KB2709981_SP1~31bf3856ad364e35~amd64~~6.1.2.0] "InstallLocation"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_for_KB2709981~31bf3856ad364e35~amd64~~6.1.2.0] "InstallLocation"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\Program Files (x86)\IObit Toolbar\"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\Program Files (x86)\IObit Toolbar\Res\"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\Program Files (x86)\IObit Toolbar\Res\Lang\"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\Program Files (x86)\IObit Toolbar\FF\"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\Program Files (x86)\IObit Toolbar\FF\chrome\"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\Program Files (x86)\IObit Toolbar\IE\6.6\"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\Program Files (x86)\IObit Toolbar\IE\"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\227891B259797954E88A157FD9F260A0] "E5D7A28B1734BBF4793EA1C766649A33"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\23B4B261A2ECC1943BE70631F436E48A] "E5D7A28B1734BBF4793EA1C766649A33"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\31DCED2B089CF994E8AE06ACC68A5EE9] "E5D7A28B1734BBF4793EA1C766649A33"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49EFEF44F9F9E174D88D2367B8D09298] "E5D7A28B1734BBF4793EA1C766649A33"="- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7F690F9F1CABCA34A98316B70CEF929B] "E5D7A28B1734BBF4793EA1C766649A33"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8AA3AE5B29805BA45936E77BE5D17854] "E5D7A28B1734BBF4793EA1C766649A33"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\98726D23C6BC87F4FAC2D95AE4948E72] "E5D7A28B1734BBF4793EA1C766649A33"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A2A9776E1D82C384AAF9A1C74B6EFF03] "E5D7A28B1734BBF4793EA1C766649A33"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C8B34D3806072054880CD17980F94CCF] "E5D7A28B1734BBF4793EA1C766649A33"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\E5D7A28B1734BBF4793EA1C766649A33\InstallProperties] "InstallLocation"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\E5D7A28B1734BBF4793EA1C766649A33\InstallProperties] "DisplayName"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Application Updater\Subscriptions\41] "regpath"=- [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\IObit] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\IObit] "serverURL"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\IObit] "partnerName"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\IObit] "partnerNameSafe"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\IObit] "ffext_path"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\IObit] "installDir"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\IObit\Advanced SystemCare 6] "installpath"=- [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\IObit\IObit Malware Fighter] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\IObit\RegistryDefragBoot] "LogPath"=- [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\iobitappsToolbar-stub-1_RASAPI32] [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\iobitappsToolbar-stub-1_RASMANCS] [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\IObitToolbar-stub-1_RASAPI32] [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\IObitToolbar-stub-1_RASMANCS] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{ACB9DC96-D7BB-430F-AE6B-97F0DFDEAFCC}\1.0\0\win64] @="" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{ACB9DC96-D7BB-430F-AE6B-97F0DFDEAFCC}\1.0\HELPDIR] @="" [-HKEY_USERS\.DEFAULT\Software\IObit] [HKEY_USERS\.DEFAULT\Software\IObit\Advanced SystemCare 6] "OldPath"=- [-HKEY_USERS\S-1-5-21-941371534-4025170946-3007303680-1000\Software\AppDataLow\Software\IObit] [-HKEY_USERS\S-1-5-21-941371534-4025170946-3007303680-1000\Software\IObit] [HKEY_USERS\S-1-5-21-941371534-4025170946-3007303680-1000\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-941371534-4025170946-3007303680-1000\Software\Web Assistant\script_storage] "WSG_whiteList"=- [HKEY_USERS\S-1-5-21-941371534-4025170946-3007303680-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Program Files (x86)\IObit\Advanced SystemCare 6\Suc10_Uninstal.exe"=- [HKEY_USERS\S-1-5-21-941371534-4025170946-3007303680-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Program Files (x86)\IObit\Advanced SystemCare 6\unins000.exe"=- [HKEY_USERS\S-1-5-21-941371534-4025170946-3007303680-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Program Files (x86)\IObit\Advanced SystemCare 6\Suc10_Uninstal.exe"=- [HKEY_USERS\S-1-5-21-941371534-4025170946-3007303680-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\Program Files (x86)\IObit\Advanced SystemCare 6\unins000.exe"=- [-HKEY_USERS\S-1-5-18\Software\IObit] [HKEY_USERS\S-1-5-18\Software\IObit\Advanced SystemCare 6] "OldPath"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\Program Files (x86)\Trusteer\Rapport\"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\Program Files (x86)\Trusteer\Rapport\bin\"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\Program Files (x86)\Trusteer\Rapport\bin\x64\"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\ProgramData\Trusteer\Rapport\store\exts\"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\ProgramData\Trusteer\Rapport\store\"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\ProgramData\Trusteer\Rapport\store\exts\RapportMS\baseline\"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\ProgramData\Trusteer\Rapport\store\exts\RapportMS\"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\ProgramData\Trusteer\Rapport\store\exts\RapportGP\baseline\"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\ProgramData\Trusteer\Rapport\store\exts\RapportGP\"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\ProgramData\Trusteer\Rapport\store\exts\KoanLight\baseline\"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\ProgramData\Trusteer\Rapport\store\exts\KoanLight\"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\ProgramData\Trusteer\Rapport\store\exts\TanzanLight\baseline\"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\ProgramData\Trusteer\Rapport\store\exts\TanzanLight\"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\ProgramData\Trusteer\Rapport\store\exts\NikkoLight\baseline\"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\ProgramData\Trusteer\Rapport\store\exts\NikkoLight\"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\ProgramData\Trusteer\Rapport\store\exts\RapportVB\baseline\"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\ProgramData\Trusteer\Rapport\store\exts\RapportVB\"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\184F97B0114E2454F945388651600D21] "00000000000000000000000000000000"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\30B6297A103051A4EA88586B82CF8953] "00000000000000000000000000000000"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3AF252B42455C054A8C5D582418D33E4] "00000000000000000000000000000000"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4998D4CAFB29ED2429752DD6A2EBC7C2] "00000000000000000000000000000000"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4998D4CAFB29ED2429752DD6A2EBC7C2] "10000000000000000000000000000000"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4DAA008A16873814EB34949637601218] "00000000000000000000000000000000"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4DAA008A16873814EB34949637601218] "10000000000000000000000000000000"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6406074B7A68DFE4A9D05C641274D19C] "00000000000000000000000000000000"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\69EC7AEB378309D4484447304851332C] "00000000000000000000000000000000"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7D8ED67F246AE484AAC5070B6D19A1E1] "00000000000000000000000000000000"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\94F383FCE0103DB45AAF8A9C449ADBCA] "00000000000000000000000000000000"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9D2261D0CC4D1694DB1EC5877F83BA85] "00000000000000000000000000000000"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9D2261D0CC4D1694DB1EC5877F83BA85] "10000000000000000000000000000000"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B1A14715CD5BFDF43B0DE6BCAF4E5728] "10000000000000000000000000000000"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B1A14715CD5BFDF43B0DE6BCAF4E5728] "00000000000000000000000000000000"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BF61A5397EF5DEE48A8DD633E51DC755] "00000000000000000000000000000000"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BF61A5397EF5DEE48A8DD633E51DC755] "10000000000000000000000000000000"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E568096D548215947887D41B47F21743] "00000000000000000000000000000000"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E568096D548215947887D41B47F21743] "10000000000000000000000000000000"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E69EE9F6EBC26FD4CAB2AD12D31485A9] "00000000000000000000000000000000"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1DD81E7D-0D28-4CEB-87B2-C041A4FCB215}] "DisplayName"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Compatibility Assistant] "ExecutablestoExclude"=- [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\RapportMgmtService_RASAPI32] [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\RapportMgmtService_RASMANCS] [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\RapportService_RASAPI32] [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\RapportService_RASMANCS] [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\RapportSetup_RASAPI32] [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\RapportSetup_RASMANCS] [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Trusteer\Rapport] [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_RAPPORTCERBERUS_34302] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_RAPPORTCERBERUS_34302\0000] "Service"=- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_RAPPORTCERBERUS_34302\0000] "DeviceDesc"=- [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_RAPPORTCERBERUS_42020] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_RAPPORTCERBERUS_42020\0000] "Service"=- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_RAPPORTCERBERUS_42020\0000] "DeviceDesc"=- [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_RAPPORTCERBERUS_43926] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_RAPPORTCERBERUS_43926\0000] "Service"=- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_RAPPORTCERBERUS_43926\0000] "DeviceDesc"=- [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_RAPPORTCERBERUS_44365] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_RAPPORTCERBERUS_44365\0000] "Service"=- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_RAPPORTCERBERUS_44365\0000] "DeviceDesc"=- [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_RAPPORTEI64] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_RAPPORTEI64\0000] "Service"=- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_RAPPORTEI64\0000] "DeviceDesc"=- [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_RAPPORTKE64] [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_RAPPORTPG64] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_RAPPORTPG64\0000] "Service"=- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_RAPPORTPG64\0000] "DeviceDesc"=- [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_RAPPORTCERBERUS_34302] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_RAPPORTCERBERUS_34302\0000] "Service"=- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_RAPPORTCERBERUS_34302\0000] "DeviceDesc"=- [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_RAPPORTCERBERUS_42020] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_RAPPORTCERBERUS_42020\0000] "Service"=- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_RAPPORTCERBERUS_42020\0000] "DeviceDesc"=- [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_RAPPORTCERBERUS_43926] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_RAPPORTCERBERUS_43926\0000] "Service"=- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_RAPPORTCERBERUS_43926\0000] "DeviceDesc"=- [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_RAPPORTCERBERUS_44365] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_RAPPORTCERBERUS_44365\0000] "Service"=- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_RAPPORTCERBERUS_44365\0000] "DeviceDesc"=- [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_RAPPORTEI64] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_RAPPORTEI64\0000] "Service"=- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_RAPPORTEI64\0000] "DeviceDesc"=- [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_RAPPORTKE64] [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_RAPPORTPG64] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_RAPPORTPG64\0000] "Service"=- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_RAPPORTPG64\0000] "DeviceDesc"=- [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_RAPPORTCERBERUS_34302] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_RAPPORTCERBERUS_34302\0000] "Service"=- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_RAPPORTCERBERUS_34302\0000] "DeviceDesc"=- [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_RAPPORTCERBERUS_42020] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_RAPPORTCERBERUS_42020\0000] "Service"=- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_RAPPORTCERBERUS_42020\0000] "DeviceDesc"=- [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_RAPPORTCERBERUS_43926] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_RAPPORTCERBERUS_43926\0000] "Service"=- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_RAPPORTCERBERUS_43926\0000] "DeviceDesc"=- [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_RAPPORTCERBERUS_44365] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_RAPPORTCERBERUS_44365\0000] "Service"=- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_RAPPORTCERBERUS_44365\0000] "DeviceDesc"=- [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_RAPPORTEI64] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_RAPPORTEI64\0000] "Service"=- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_RAPPORTEI64\0000] "DeviceDesc"=- [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_RAPPORTKE64] [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_RAPPORTPG64] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_RAPPORTPG64\0000] "Service"=- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_RAPPORTPG64\0000] "DeviceDesc"=- [-HKEY_USERS\.DEFAULT\Software\Trusteer\Rapport] [-HKEY_USERS\S-1-5-18\Software\Trusteer\Rapport] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\Program Files (x86)\Trusteer\Rapport\"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\Program Files (x86)\Trusteer\"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\Program Files (x86)\Trusteer\Rapport\bin\"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\Program Files (x86)\Trusteer\Rapport\bin\x64\"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\ProgramData\Trusteer\Rapport\store\exts\"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\ProgramData\Trusteer\Rapport\store\"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\ProgramData\Trusteer\Rapport\store\exts\RapportMS\baseline\"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\ProgramData\Trusteer\Rapport\store\exts\RapportMS\"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\ProgramData\Trusteer\Rapport\store\exts\RapportGP\baseline\"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\ProgramData\Trusteer\Rapport\store\exts\RapportGP\"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\ProgramData\Trusteer\Rapport\store\exts\KoanLight\baseline\"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\ProgramData\Trusteer\Rapport\store\exts\KoanLight\"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\ProgramData\Trusteer\Rapport\store\exts\TanzanLight\baseline\"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\ProgramData\Trusteer\Rapport\store\exts\TanzanLight\"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\ProgramData\Trusteer\Rapport\store\exts\NikkoLight\baseline\"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\ProgramData\Trusteer\Rapport\store\exts\NikkoLight\"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\ProgramData\Trusteer\Rapport\store\exts\RapportVB\baseline\"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\ProgramData\Trusteer\Rapport\store\exts\RapportVB\"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\184F97B0114E2454F945388651600D21] "00000000000000000000000000000000"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\30B6297A103051A4EA88586B82CF8953] "00000000000000000000000000000000"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3AF252B42455C054A8C5D582418D33E4] "00000000000000000000000000000000"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4998D4CAFB29ED2429752DD6A2EBC7C2] "00000000000000000000000000000000"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4998D4CAFB29ED2429752DD6A2EBC7C2] "10000000000000000000000000000000"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4DAA008A16873814EB34949637601218] "00000000000000000000000000000000"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Micros-oft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4DAA008A16873814EB34949637601218] "10000000000000000000000000000000"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6406074B7A68DFE4A9D05C641274D19C] "00000000000000000000000000000000"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\69EC7AEB378309D4484447304851332C] "00000000000000000000000000000000"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7D8ED67F246AE484AAC5070B6D19A1E1] "00000000000000000000000000000000"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\94F383FCE0103DB45AAF8A9C449ADBCA] "00000000000000000000000000000000"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9D2261D0CC4D1694DB1EC5877F83BA85] "00000000000000000000000000000000"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9D2261D0CC4D1694DB1EC5877F83BA85] "10000000000000000000000000000000"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B1A14715CD5BFDF43B0DE6BCAF4E5728] "10000000000000000000000000000000"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B1A14715CD5BFDF43B0DE6BCAF4E5728] "00000000000000000000000000000000"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BF61A5397EF5DEE48A8DD633E51DC755] "00000000000000000000000000000000"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BF61A5397EF5DEE48A8DD633E51DC755] "10000000000000000000000000000000"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E568096D548215947887D41B47F21743] "00000000000000000000000000000000"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E568096D548215947887D41B47F21743] "10000000000000000000000000000000"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E69EE9F6EBC26FD4CAB2AD12D31485A9] "00000000000000000000000000000000"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1DD81E7D-0D28-4CEB-87B2-C041A4FCB215}] "Publisher"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Compatibility Assistant] "ExecutablestoExclude"=- [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Trusteer] [-HKEY_USERS\.DEFAULT\Software\Trusteer] [-HKEY_USERS\S-1-5-18\Software\Trusteer] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-941371534-4025170946-3007303680-1000\Software\Web Assistant\script_storage] "WSG_whiteList"=- [HKEY_USERS\S-1-5-21-941371534-4025170946-3007303680-1000\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-941371534-4025170946-3007303680-1000\Software\Web Assistant\script_storage] "WSG_whiteList"=-
- Click under the Custom Scan/Fixes box and paste the copied text.
- Click the Run Fix button. If prompted... click OK.
- OTL may ask to reboot the machine. Please do so if asked.
- Let the program run unhindered and reboot the PC when it is done.
When the computer reboots, and you start your usual account, a Notepad text file will appear. - Copy the contents of that file and post it in your next reply. The log can also be found, based on the date/time it was created, as C:\_OTL\MovedFiles\MMDDYYYY_HHMMSS.log
Then please run Steps 2 and 3 from my previous post...
Please include in your next reply:
- Do you have any problems executing the instructions?
- Contents of the C:\_OTL\MovedFiles\MMDDYYYY_HHMMSS.log log file after OTL FixScript - Part 1 run
- Contents of the C:\_OTL\MovedFiles\MMDDYYYY_HHMMSS.log log file after OTL FixScript - Part 2 run
- Contents of the SystemLook.txt log file
- Contents of a OTL.txt log file
- Do you see any changes in computer behavior?
Please do not hesitate to divide the post into multiple if it is too long...
Thanks,
pgmigg
Failure to post replies within 72 hours will result in this thread being closed