Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

my antivirus and window defender cannot active [Solved]


  • This topic is locked This topic is locked

#1
fandy

fandy

    Member

  • Member
  • PipPip
  • 12 posts

i have a windows 8.1 64bit

and my antivirus is avast, i dont really remerber when it happen but my antivirus can't do any scan or actived.
I have try re-install it but still can't scan

sorry for my bad english btw

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:15-09-2015
Ran by Rifandi (administrator) on RIP (19-09-2015 04:32:07)
Running from C:\Users\Rifandi\Desktop
Loaded Profiles: Rifandi (Available Profiles: Rifandi)
Platform: Windows 8.1 Pro (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Atheros Commnucations) C:\Windows\System32\AdminService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\Windows\SysWOW64\ChgService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
() C:\Program Files (x86)\Join Air\AssistantServices.exe
(Microsoft Corporation) C:\Users\Rifandi\AppData\Roaming\Microsoft\SystemCertificates\VSSVC.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Integrated Clock Controller Service\ICCProxy.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMan.exe
() C:\Program Files\Rainmeter\Rainmeter.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.Reader_6.4.9926.17994_x64__8wekyb3d8bbwe\glcnd.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(FileProperties_CompanyName) C:\Program Files (x86)\help4u\help4u_notification_service.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [17111056 2013-12-20] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [193008 2013-12-20] (Lenovo(beijing) Limited)
HKLM\...\Run: [Nvtmru] => "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2531472 2014-12-13] (NVIDIA Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13647576 2013-08-27] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1321688 2013-08-07] (Realtek Semiconductor)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [UIExec] => C:\Program Files (x86)\Join Air\UIExec.exe [713728 2010-12-16] ()
HKLM-x32\...\Run: [WinampAgent] => C:\Program Files (x86)\Winamp\winampa.exe [85600 2013-12-13] (Nullsoft, Inc.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [937920 2011-09-06] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [36760 2011-09-06] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [2904984 2011-09-06] (Adobe Systems Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [TaskbarNoNotification] 1
HKLM\...\Policies\Explorer: [HideSCAHealth] 1
HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\Run: [TornTv Downloader] => C:\Users\Rifandi\AppData\Roaming\TornTV.com\Torntv Downloader.exe /c=startup
HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\Run: [Only-search] => C:\Users\Rifandi\AppData\Local\onlysearch\onlysearch\1.3.15.4\onlysearch.exe
HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\Run: [GoogleChromeAutoLaunch_2044B68C092258CC6B61BEF807401E47] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [815944 2015-09-12] (Google Inc.)
HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [3882576 2014-12-12] (Tonec Inc.)
HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\RunOnce: [FlashPlayerUpdate] => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_17_0_0_134_Plugin.exe [962224 2015-03-24] (Adobe Systems Incorporated)
AppInit_DLLs: C:\PROGRA~2\SupTab\SEARCH~2.DLL => C:\Program Files (x86)\SupTab\SearchProtect64.dll [96768 2014-03-05] (Skytech Co., Ltd.)
AppInit_DLLs: ,C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [166568 2014-05-20] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\PROGRA~2\SupTab\SEARCH~1.DLL => C:\Program Files (x86)\SupTab\SearchProtect32.dll [85504 2014-03-05] (Skytech Co., Ltd.)
AppInit_DLLs-x32: ,C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [146480 2014-05-20] (NVIDIA Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  No File
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Rifandi\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Rifandi\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Rifandi\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Rifandi\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll [2014-04-21] (Tonec Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Rifandi\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Rifandi\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Rifandi\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\StartupModem.lnk [2014-01-28]
ShortcutTarget: StartupModem.lnk -> C:\Program Files (x86)\3G Connect\StartUpRun.exe ()
Startup: C:\Users\Rifandi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Rainmeter.lnk [2014-10-22]
ShortcutTarget: Rainmeter.lnk -> C:\Program Files\Rainmeter\Rainmeter.exe ()
Startup: C:\Users\Rifandi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TornTvDownloader.lnk [2014-10-30]
ShortcutTarget: TornTvDownloader.lnk -> C:\Users\Rifandi\AppData\Roaming\TornTV.com\TornTV Downloader.exe (No File)
GroupPolicy: Restriction - Chrome <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.43.1
Tcpip\..\Interfaces\{659EBD27-2A47-4029-8B7F-C20452FF1B3D}: [DhcpNameServer] 192.168.43.1
Tcpip\..\Interfaces\{970D6D83-F3E5-4CA0-B64D-27F554407A29}: [DhcpNameServer] 202.0.107.1 202.0.107.2
 
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.qone8.com/?type=hp&ts=1395502286&from=ild&uid=ST1000LM024XHN-M101MBB_S2U5J9KD102731
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?trackid=sp-006
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.qone8.com/web/?type=ds&ts=1395502286&from=ild&uid=ST1000LM024XHN-M101MBB_S2U5J9KD102731&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://start.qone8.com/?type=hp&ts=1395502286&from=ild&uid=ST1000LM024XHN-M101MBB_S2U5J9KD102731
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = 
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.qone8.com/web/?type=ds&ts=1395502286&from=ild&uid=ST1000LM024XHN-M101MBB_S2U5J9KD102731&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = 
HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?trackid=sp-006
HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxps://www.google.com/?trackid=sp-006
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.qone8.com/web/?type=ds&ts=1395502286&from=ild&uid=ST1000LM024XHN-M101MBB_S2U5J9KD102731&q={searchTerms}
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=irmsd0103&cd=2XzuyEtN2Y1L1QzutB0C0DtDyD0AtCtAzz0CyCyCyB0E0D0EtN0D0Tzu0SyByCyDtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R&cr=1961462397&ir=
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.qone8.com/web/?type=ds&ts=1395502286&from=ild&uid=ST1000LM024XHN-M101MBB_S2U5J9KD102731&q={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.qone8.com/web/?type=ds&ts=1395502286&from=ild&uid=ST1000LM024XHN-M101MBB_S2U5J9KD102731&q={searchTerms}
SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1232603322-3645337139-1979953262-1001 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1232603322-3645337139-1979953262-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=irmsd0103&cd=2XzuyEtN2Y1L1QzutB0C0DtDyD0AtCtAzz0CyCyCyB0E0D0EtN0D0Tzu0SyByCyDtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R&cr=1961462397&ir=
SearchScopes: HKU\S-1-5-21-1232603322-3645337139-1979953262-1001 -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.only-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=B6BD2ED05A138C66&affID=129300&tsp=5416
SearchScopes: HKU\S-1-5-21-1232603322-3645337139-1979953262-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.qone8.com/web/?type=ds&ts=1395502286&from=ild&uid=ST1000LM024XHN-M101MBB_S2U5J9KD102731&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1232603322-3645337139-1979953262-1001 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll [2015-05-20] (Internet Download Manager, Tonec Inc.)
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2012-10-01] (Microsoft Corporation)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-06-04] (Oracle Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-06-04] (Oracle Corporation)
BHO-x32: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll [2015-05-20] (Internet Download Manager, Tonec Inc.)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-09-06] (Adobe Systems Incorporated)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2012-10-01] (Microsoft Corporation)
BHO-x32: Microsoft Web Test Recorder 10.0 Helper -> {876d9f09-c6d6-4324-a2cc-04dd9a4de12f} -> C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll [2012-07-26] (Microsoft Corporation)
BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2011-09-06] (Adobe Systems Incorporated)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation)
BHO-x32: mysearchdial Helper Object -> {EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD} -> C:\Program Files (x86)\Mysearchdial\1.8.21.0\bh\mysearchdial.dll [2014-02-04] (MySearchDial)
BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2011-09-06] (Adobe Systems Incorporated)
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  No File
Toolbar: HKLM-x32 - mysearchdial Toolbar - {3004627E-F8E9-4E8B-909D-316753CBA923} - C:\Program Files (x86)\Mysearchdial\1.8.21.0\mysearchdialTlbr.dll [2014-02-04] (MySearchDial)
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2011-09-06] (Adobe Systems Incorporated)
DPF: HKLM-x32 {6A060448-60F9-11D5-A6CD-0002B31F7455} 
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2012-10-01] (Microsoft Corporation)
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://start.qone8.com/?type=sc&ts=1395502286&from=ild&uid=ST1000LM024XHN-M101MBB_S2U5J9KD102731
 
FireFox:
========
FF ProfilePath: C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default
FF NewTab: 
FF Homepage: about:home
FF Keyword.URL: 
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_134.dll [2015-03-24] ()
FF Plugin: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-06-04] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-06-04] (Oracle Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_134.dll [2015-03-24] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-08-08] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-08-08] (Intel Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2012-10-01] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll [2012-04-11] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation)
FF Plugin-x32: @nullsoft.com/winampDetector;version=1 -> C:\Program Files (x86)\Winamp Detect\npwachk.dll [2013-12-13] (Nullsoft, Inc.)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2014-05-20] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2014-05-20] (NVIDIA Corporation)
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll [No File]
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll [No File]
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-09-01] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-09-01] (Google Inc.)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll [2011-09-06] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1232603322-3645337139-1979953262-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Rifandi\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2014-02-21] (Unity Technologies ApS)
FF user.js: detected! => C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\user.js [2014-03-22]
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2012-10-01] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2011-09-06] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2014-01-25] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2014-01-25] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2014-01-25] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2014-01-25] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2014-01-25] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Rifandi\AppData\Roaming\mozilla\plugins\np-mswmp.dll [2009-09-26] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Users\Rifandi\AppData\Roaming\mozilla\plugins\npatgpc.dll [2014-10-13] (Cisco WebEx LLC)
FF SearchPlugin: C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\searchplugins\MyOnlineSearch.xml [2014-10-30]
FF SearchPlugin: C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\searchplugins\onlysearchkms.xml [2014-10-30]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\qone8.xml [2014-03-22]
FF Extension: SavePass 1.2 - C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\Extensions\[email protected] [2015-08-19]
FF Extension: YoutubeAdblocker - C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\Extensions\[email protected] [2014-02-04]
FF Extension: anonymoX - C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\Extensions\[email protected] [2014-01-25]
FF Extension: SQLite Manager - C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\Extensions\[email protected] [2015-06-09]
FF Extension: Themes Menu - C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\Extensions\{84625510-7e5d-11e0-a411-0800200c9a66}.xpi [2014-10-30]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\extensions\[email protected]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2015-09-09]
FF HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\Firefox\Extensions: [[email protected]] - C:\Users\Rifandi\AppData\Roaming\IDM\idmmzcc5
FF Extension: IDM CC - C:\Users\Rifandi\AppData\Roaming\IDM\idmmzcc5 [2015-09-19]
FF HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\SeaMonkey\Extensions: [[email protected]] - C:\Users\Rifandi\AppData\Roaming\IDM\idmmzcc5
 
Chrome: 
=======
CHR HomePage: Default -> hxxps://www.google.com/
CHR StartupUrls: Default -> "hxxps://www.google.com/"
CHR Profile: C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-12-21]
CHR Extension: (Google Drive) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-12-21]
CHR Extension: (Earth View from Google Earth) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhloflhklmhfpedakmangadcdofhnnoh [2014-11-17]
CHR Extension: (YouTube) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-12-21]
CHR Extension: (The Elder Scrolls Online - Theme) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\bodeacmfbgjollphdaehplmjobapnbin [2015-06-30]
CHR Extension: (Google Search) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-12-21]
CHR Extension: (Adblock Plus) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\efmppbpipefbijnpmokkcfnedohbiije [2015-04-12]
CHR Extension: (Google Docs Offline) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-09-06]
CHR Extension: (Privacy manager) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\giccehglhacakcfemddmfhdkahamfcmd [2014-02-04]
CHR Extension: (YoutubeAdblocker) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkoghcmfjgopofakhllpdmflopkhccoj [2014-02-04]
CHR Extension: (Advanced REST client) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\hgmloofddffdnphfgcellkdfbfbjeloo [2015-05-09]
CHR Extension: (YYTBoOkMark) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kmjboicapmacdaecgldenkpdcdkkifgc [2014-02-04]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-14]
CHR Extension: (Speed Dial [FVD] - New Tab Page, 3D, Sync...) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\llaficoajjainaijghjlofdfmbjpebpa [2015-06-30]
CHR Extension: (IDM Integration Module) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2015-06-16]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-21]
CHR Extension: (Adblock Pro) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ocifcklkibdehekfnmflempfgjhbedch [2015-06-30]
CHR Extension: (gREatSaveer) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\oefifkdlbdfmnhdkbagencoidhfjcich [2014-02-04]
CHR Extension: (Currently) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojhmphdkpgbibohbnpbfiefkgieacjmh [2014-11-17]
CHR Extension: (Quick start) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma [2014-03-22]
CHR Extension: (Gmail) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-12-21]
CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2015-05-20]
CHR HKLM-x32\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2015-05-20]
CHR HKLM-x32\...\Chrome\Extension: [pelmeidfhdlhlbjimpabfcbnnojbboma] - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx [2014-03-22]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AtherosSvc; C:\Windows\system32\AdminService.exe [208384 2012-08-29] (Atheros Commnucations)
R2 Change Modem Device Service; C:\Windows\SysWOW64\ChgService.exe [135168 2009-08-20] () [File not signed]
S3 fussvc; C:\Program Files (x86)\Windows Kits\8.0\App Certification Kit\fussvc.exe [139776 2012-07-25] (Microsoft Corporation) [File not signed]
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1148560 2014-12-13] (NVIDIA Corporation)
R2 Intel® Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel® Corporation) [File not signed]
S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel® Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [169432 2013-08-08] (Intel Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1701520 2014-12-13] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [19823248 2014-12-13] (NVIDIA Corporation)
R2 RzKLService; C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe [105448 2013-11-22] (Razer Inc.)
S2 Service KMSELDI; C:\Program Files\KMSpico\Service_KMS.exe [691480 2013-11-20] () [File not signed]
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe [126976 2012-07-25] (Microsoft Corporation) [File not signed]
R2 UI Assistant Service; C:\Program Files (x86)\Join Air\AssistantServices.exe [246272 2009-07-15] () [File not signed]
R2 VSSS; C:\Users\Rifandi\AppData\Roaming\Microsoft\SystemCertificates\VSSVC.exe [103523264 2015-06-24] (Microsoft Corporation) [File not signed] <==== ATTENTION
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [346872 2013-08-22] (Microsoft Corporation)
S2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23840 2013-08-22] (Microsoft Corporation)
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 athr; C:\Windows\system32\DRIVERS\athwbx.sys [3837440 2013-07-15] (Qualcomm Atheros Communications, Inc.)
S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [224768 2013-08-22] (Microsoft Corporation)
S3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [132480 2012-10-01] (Motorola Solutions, Inc.)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-04-20] (Disc Soft Ltd)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
S3 fcusbser; C:\Windows\system32\DRIVERS\fcusbser.sys [119552 2010-06-03] (BM)
S3 hxsyol; C:\Windows\system32\hxsy64.sys [86352 2015-02-27] ()
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-08-08] (Intel Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2014-12-13] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [38032 2014-11-22] (NVIDIA Corporation)
S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [27520 2007-05-14] (Research In Motion Limited)
S3 SDGame; C:\Windows\System32\svchost.exe [37768 2013-08-22] (Microsoft Corporation)
R3 SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [230912 2013-08-22] (Microsoft Corporation)
S3 VSPerfDrv110; C:\Program Files (x86)\Microsoft Visual Studio 11.0\Team Tools\Performance Tools\x64\VSPerfDrv110.sys [70264 2012-07-13] (Microsoft Corporation)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [34760 2013-08-22] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [265056 2013-08-22] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124256 2013-08-22] (Microsoft Corporation)
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
R4 KProcessHacker2; \??\C:\Program Files\kprocesshacker.sys [X]
S2 {09BB444F-B2E2-4009-BAF2-7B727681223E}; \??\D:\GAMES\VMLaunch\BuddyVM.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-09-19 04:32 - 2015-09-19 04:32 - 00035133 _____ C:\Users\Rifandi\Desktop\FRST.txt
2015-09-19 04:32 - 2015-09-19 04:32 - 00000000 ____D C:\FRST
2015-09-19 04:28 - 2015-09-19 04:28 - 02191360 _____ (Farbar) C:\Users\Rifandi\Desktop\FRST64.exe
2015-09-19 04:03 - 2015-09-19 04:04 - 02019656 _____ (Bleeping Computer, LLC) C:\Users\Rifandi\Downloads\rkill.com
2015-09-19 02:29 - 2015-09-19 01:56 - 00427636 _____ C:\Users\Rifandi\Documents\Backup_of_Font.cdr
2015-09-19 01:56 - 2015-09-19 02:29 - 00427689 _____ C:\Users\Rifandi\Documents\Font.cdr
2015-09-19 00:19 - 2015-09-19 00:20 - 00000000 ____D C:\ProgramData\Avg
2015-09-19 00:16 - 2015-09-19 00:16 - 00000000 ____D C:\Users\Rifandi\AppData\Local\Avg2014
2015-09-18 14:24 - 2015-09-19 00:20 - 00000000 ____D C:\Program Files (x86)\AVG
2015-09-18 11:14 - 2015-09-18 11:14 - 00000258 _____ C:\Users\Rifandi\Documents\CorelDRAW Graphics Suite X5.txt
2015-09-18 11:07 - 2015-09-18 11:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CorelDRAW Graphics Suite X5
2015-09-18 10:59 - 2015-09-18 11:04 - 00000000 ____D C:\ProgramData\CorelDRAW Graphics Suite X7 x64
2015-09-18 08:57 - 2015-09-19 00:20 - 00000000 ____D C:\Users\Rifandi\AppData\Local\AvgSetupLog
2015-09-18 08:56 - 2015-09-18 08:56 - 00000000 ____D C:\Users\Rifandi\AppData\Local\Avg
2015-09-18 08:53 - 2015-09-18 08:57 - 00000000 ____D C:\ProgramData\Protexis
2015-09-18 08:53 - 2015-09-18 08:53 - 00000000 ____D C:\Users\Rifandi\AppData\Roaming\Corel
2015-09-18 08:50 - 2015-09-18 11:10 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 9.0
2015-09-18 08:49 - 2015-09-18 11:09 - 00000000 ____D C:\ProgramData\Corel
2015-09-18 08:45 - 2015-09-18 08:45 - 00000000 ____D C:\Program Files (x86)\Corel
2015-09-10 15:23 - 2015-09-10 15:23 - 01415680 _____ (wj32) C:\Program Files\ZNZUJ1KC.exe
2015-09-10 15:23 - 2015-09-10 15:23 - 01415680 _____ (wj32) C:\Program Files\YB8FRRCJ.exe
2015-09-10 15:23 - 2015-09-10 15:23 - 01415680 _____ (wj32) C:\Program Files\X1ZWBCHI.exe
2015-09-10 15:23 - 2015-09-10 15:23 - 01415680 _____ (wj32) C:\Program Files\W04V9Y20.exe
2015-09-10 15:23 - 2015-09-10 15:23 - 01415680 _____ (wj32) C:\Program Files\R5UVZL04.exe
2015-09-10 15:23 - 2015-09-10 15:23 - 01415680 _____ (wj32) C:\Program Files\ICJKVJ4B.exe
2015-09-10 15:23 - 2015-09-10 15:23 - 01415680 _____ (wj32) C:\Program Files\9GOV2WKR.exe
2015-09-10 15:23 - 2015-09-10 15:23 - 01415680 _____ (wj32) C:\Program Files\39Y7K2I0.exe
2015-09-10 15:23 - 2015-09-10 15:23 - 01415680 _____ (wj32) C:\Program Files\31XFGLPK.exe
2015-09-10 15:19 - 2015-09-10 15:19 - 01415680 _____ (wj32) C:\Program Files\AET6IA57.exe
2015-09-10 15:10 - 2015-03-02 18:22 - 202313264 _____ (Avast Software s.r.o.) C:\Users\Public\Desktop\avast_premier_antivirus_setup.exe
2015-09-10 15:05 - 2015-09-10 15:05 - 01415680 _____ (wj32) C:\Program Files\TUYNETRG.exe
2015-09-10 14:56 - 2015-09-10 14:57 - 00008278 _____ C:\Users\Rifandi\Documents\Uninstall Dragon Age Origins.log
2015-09-09 22:36 - 2015-09-09 22:36 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2015-09-09 22:29 - 2015-09-09 22:29 - 00000000 ____D C:\ProgramData\ALM
2015-09-09 22:27 - 2015-09-09 22:27 - 00000000 ____D C:\Users\Rifandi\Adobe Flash Builder 4.6
2015-09-09 22:24 - 2015-09-09 22:24 - 00002481 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller X.lnk
2015-09-09 22:24 - 2015-09-09 22:24 - 00002469 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat X Pro.lnk
2015-09-09 22:24 - 2015-09-09 22:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe LiveCycle ES2
2015-09-09 22:21 - 2015-09-09 22:21 - 00001113 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Widget Browser.lnk
2015-09-09 22:21 - 2015-09-09 22:21 - 00000000 ____D C:\Program Files (x86)\My Company Name
2015-09-09 22:21 - 2011-11-03 03:01 - 00056208 ____N (Rovi Corporation) C:\Windows\system32\Drivers\PxHlpa64.sys
2015-09-09 22:21 - 2011-10-17 03:00 - 00010224 ____N (Sonic Solutions) C:\Windows\system32\Drivers\cdralw2k.sys
2015-09-09 22:21 - 2011-10-17 03:00 - 00010224 ____N (Sonic Solutions) C:\Windows\system32\Drivers\cdr4_xp.sys
2015-09-09 22:19 - 2015-09-09 22:19 - 00001013 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk
2015-09-09 22:19 - 2015-09-09 22:19 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
2015-09-09 22:19 - 2015-09-09 22:19 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
2015-09-09 22:16 - 2015-09-09 22:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Master Collection CS6
2015-09-09 22:16 - 2015-09-09 22:35 - 00000000 ____D C:\Program Files\Adobe
2015-09-09 22:15 - 2015-09-09 22:35 - 00000000 ____D C:\Program Files\Common Files\Adobe
2015-09-09 22:11 - 2015-09-10 14:17 - 00000000 ____D C:\Users\Rifandi\AppData\Local\Adobe
2015-09-09 22:11 - 2015-09-09 22:36 - 00000000 ____D C:\ProgramData\Adobe
2015-09-03 11:16 - 2015-09-03 11:16 - 01415680 _____ (wj32) C:\Program Files\O6YOYI62.exe
2015-09-03 11:16 - 2015-09-03 11:16 - 01415680 _____ (wj32) C:\Program Files\B3T3NBZJ.exe
2015-09-03 09:54 - 2015-09-03 09:54 - 01415680 _____ (wj32) C:\Program Files\J5PP7DXH.exe
2015-08-30 23:33 - 2015-08-30 23:33 - 01415680 _____ (wj32) C:\Program Files\9TAOZDU8.exe
2015-08-30 23:32 - 2015-08-30 23:32 - 01415680 _____ (wj32) C:\Program Files\2WKICE8A.exe
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-09-19 04:32 - 2013-12-22 10:05 - 00000000 ____D C:\Users\Rifandi\AppData\Roaming\DMCache
2015-09-19 04:19 - 2013-12-20 20:53 - 00001028 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-09-19 04:18 - 2013-12-20 20:47 - 00003914 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{0217303C-CD5D-4BA1-8084-41BF826BC10F}
2015-09-19 04:03 - 2015-04-06 23:03 - 00001302 _____ C:\Windows\Tasks\help4u_notification_service.job
2015-09-19 04:03 - 2015-04-06 23:03 - 00000664 _____ C:\Windows\Tasks\help4u_updating_service.job
2015-09-19 04:00 - 2013-08-22 22:36 - 00000000 ____D C:\Windows\system32\sru
2015-09-19 03:24 - 2014-05-24 19:33 - 00000000 ____D C:\Users\Rifandi\AppData\Roaming\IDM
2015-09-19 01:44 - 2013-08-22 22:36 - 00000000 ____D C:\Windows\LiveKernelReports
2015-09-19 01:03 - 2015-04-07 00:03 - 00000004 _____ C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-09-19 00:36 - 2013-12-20 11:58 - 01379563 _____ C:\Windows\WindowsUpdate.log
2015-09-19 00:28 - 2013-12-20 14:21 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1232603322-3645337139-1979953262-1001
2015-09-19 00:25 - 2013-12-31 12:58 - 00000434 _____ C:\Windows\system32\Drivers\etc\hosts.ics
2015-09-19 00:23 - 2015-03-25 18:15 - 00065536 _____ C:\Windows\system32\Ikeext.etl
2015-09-19 00:23 - 2013-12-22 12:26 - 00000000 ____D C:\ProgramData\AVAST Software
2015-09-19 00:23 - 2013-12-22 09:35 - 00000000 ____D C:\ProgramData\NVIDIA
2015-09-19 00:23 - 2013-12-20 20:53 - 00001024 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-09-19 00:23 - 2013-12-20 14:24 - 00000000 ____D C:\ProgramData\MFAData
2015-09-19 00:23 - 2013-09-30 11:02 - 01212318 _____ C:\Windows\PFRO.log
2015-09-19 00:23 - 2013-08-22 22:36 - 00000000 ____D C:\Windows\tracing
2015-09-19 00:23 - 2013-08-22 21:45 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-09-19 00:22 - 2013-08-22 20:25 - 00262144 ___SH C:\Windows\system32\config\BBI
2015-09-19 00:12 - 2013-09-30 11:14 - 00005392 _____ C:\Windows\system32\PerfStringBackup.INI
2015-09-18 14:28 - 2013-08-22 22:36 - 00000000 ___HD C:\Windows\ELAMBKUP
2015-09-18 14:20 - 2013-08-22 21:44 - 05378416 _____ C:\Windows\system32\FNTCACHE.DAT
2015-09-18 11:12 - 2014-01-27 23:24 - 00000000 ____D C:\ProgramData\CorelDRAW Graphics Suite X5
2015-09-18 11:11 - 2014-01-26 11:53 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-09-18 10:44 - 2013-08-22 21:46 - 00191074 _____ C:\Windows\setupact.log
2015-09-18 08:50 - 2015-07-08 20:52 - 00000000 ____D C:\Program Files\Internet Download Manager
2015-09-13 23:38 - 2013-12-20 20:53 - 00000000 ____D C:\Users\Rifandi\AppData\Local\Google
2015-09-10 14:57 - 2014-11-17 16:32 - 00000000 ____D C:\ProgramData\BioWare
2015-09-10 14:54 - 2014-12-16 13:13 - 00000000 ____D C:\Program Files (x86)\Steam
2015-09-10 13:35 - 2013-12-20 11:59 - 00000000 ____D C:\Users\Rifandi\AppData\Roaming\Adobe
2015-09-09 22:34 - 2015-02-18 21:56 - 00000000 ____D C:\Program Files (x86)\Adobe
2015-09-09 22:27 - 2013-12-20 11:58 - 00000000 ____D C:\Users\Rifandi
2015-09-01 20:14 - 2013-12-20 20:53 - 00004000 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-09-01 20:14 - 2013-12-20 20:53 - 00003764 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-09-01 19:51 - 2013-10-23 11:30 - 00000000 ____D C:\Users\Rifandi\Downloads\Wallpaper
2015-08-30 23:34 - 2013-08-22 22:36 - 00000000 ____D C:\Windows\AppReadiness
2015-08-24 20:46 - 2014-09-27 14:54 - 00000000 ____D C:\Program Files (x86)\Origin
2015-08-22 11:22 - 2013-12-22 09:00 - 00000000 ____D C:\Users\Rifandi\AppData\Roaming\CodeBlocks
2015-08-20 05:35 - 2013-12-20 11:59 - 00000000 ____D C:\Users\Rifandi\AppData\Local\Packages
 
==================== Files in the root of some directories =======
 
2015-08-30 23:32 - 2015-08-30 23:32 - 1415680 _____ (wj32) C:\Program Files\2WKICE8A.exe
2015-09-10 15:23 - 2015-09-10 15:23 - 1415680 _____ (wj32) C:\Program Files\31XFGLPK.exe
2015-09-10 15:23 - 2015-09-10 15:23 - 1415680 _____ (wj32) C:\Program Files\39Y7K2I0.exe
2015-09-10 15:23 - 2015-09-10 15:23 - 1415680 _____ (wj32) C:\Program Files\9GOV2WKR.exe
2015-08-30 23:33 - 2015-08-30 23:33 - 1415680 _____ (wj32) C:\Program Files\9TAOZDU8.exe
2015-09-10 15:19 - 2015-09-10 15:19 - 1415680 _____ (wj32) C:\Program Files\AET6IA57.exe
2015-09-03 11:16 - 2015-09-03 11:16 - 1415680 _____ (wj32) C:\Program Files\B3T3NBZJ.exe
2015-06-27 04:47 - 2015-06-27 04:47 - 1415680 _____ (wj32) C:\Program Files\F7N7RDTD.exe
2015-09-10 15:23 - 2015-09-10 15:23 - 1415680 _____ (wj32) C:\Program Files\ICJKVJ4B.exe
2015-06-28 14:44 - 2015-06-28 14:44 - 1415680 _____ (wj32) C:\Program Files\IRJS8N3R.exe
2015-09-03 09:54 - 2015-09-03 09:54 - 1415680 _____ (wj32) C:\Program Files\J5PP7DXH.exe
2015-09-03 11:16 - 2015-09-03 11:16 - 1415680 _____ (wj32) C:\Program Files\O6YOYI62.exe
2015-09-10 15:23 - 2015-09-10 15:23 - 1415680 _____ (wj32) C:\Program Files\R5UVZL04.exe
2015-09-10 15:05 - 2015-09-10 15:05 - 1415680 _____ (wj32) C:\Program Files\TUYNETRG.exe
2015-09-10 15:23 - 2015-09-10 15:23 - 1415680 _____ (wj32) C:\Program Files\W04V9Y20.exe
2015-09-10 15:23 - 2015-09-10 15:23 - 1415680 _____ (wj32) C:\Program Files\X1ZWBCHI.exe
2015-09-10 15:23 - 2015-09-10 15:23 - 1415680 _____ (wj32) C:\Program Files\YB8FRRCJ.exe
2015-07-22 13:25 - 2015-07-22 13:25 - 1415680 _____ (wj32) C:\Program Files\YIWGU8PH.exe
2015-09-10 15:23 - 2015-09-10 15:23 - 1415680 _____ (wj32) C:\Program Files\ZNZUJ1KC.exe
2013-12-20 12:04 - 2014-10-22 23:47 - 0007605 _____ () C:\Users\Rifandi\AppData\Local\Resmon.ResmonCfg
2014-11-18 16:11 - 2014-11-18 16:11 - 0000000 _____ () C:\Users\Rifandi\AppData\Local\{28B07EFD-C22E-4EAF-BB9A-886224995B4E}
2014-11-22 20:25 - 2014-11-22 20:25 - 0000000 _____ () C:\Users\Rifandi\AppData\Local\{918915E7-62D3-4955-BD85-3C711153C0F0}
2014-11-21 17:59 - 2014-11-21 17:59 - 0000000 _____ () C:\Users\Rifandi\AppData\Local\{DE111176-0A34-4308-8E0C-5FC04B4A97A7}
2013-12-22 10:35 - 2013-12-22 10:35 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2013-08-22 10:56 - 2013-08-22 10:56 - 68792320 ___SH () C:\ProgramData\msctqoijn.exe
 
Files to move or delete:
====================
C:\ProgramData\msctqoijn.exe
 
 
Some files in TEMP:
====================
C:\Users\Rifandi\AppData\Local\Temp\15403.exe
C:\Users\Rifandi\AppData\Local\Temp\26349.exe
C:\Users\Rifandi\AppData\Local\Temp\9w0z7hhv.dll
C:\Users\Rifandi\AppData\Local\Temp\AutoRun.exe
C:\Users\Rifandi\AppData\Local\Temp\AutoRunGUI.dll
C:\Users\Rifandi\AppData\Local\Temp\avg-0d57d41c-69a9-4d1f-ad46-a451f87f8704.exe
C:\Users\Rifandi\AppData\Local\Temp\avg-437f951d-ef0d-4914-8bd2-a57dbd1c2d51.exe
C:\Users\Rifandi\AppData\Local\Temp\avg-f26c3a2b-1a46-4946-91e2-dc349aa1d27b.exe
C:\Users\Rifandi\AppData\Local\Temp\AVGTBInstall.exe
C:\Users\Rifandi\AppData\Local\Temp\bassmod.dll
C:\Users\Rifandi\AppData\Local\Temp\cdo1012559675.dll
C:\Users\Rifandi\AppData\Local\Temp\cdo1884421863.dll
C:\Users\Rifandi\AppData\Local\Temp\cdo1947574289.dll
C:\Users\Rifandi\AppData\Local\Temp\cdo2320784150.dll
C:\Users\Rifandi\AppData\Local\Temp\cdo279897222.dll
C:\Users\Rifandi\AppData\Local\Temp\cdo2965365908.dll
C:\Users\Rifandi\AppData\Local\Temp\cdo3081841414.dll
C:\Users\Rifandi\AppData\Local\Temp\cdo3085677782.dll
C:\Users\Rifandi\AppData\Local\Temp\cdo3203406440.dll
C:\Users\Rifandi\AppData\Local\Temp\cdo3261657765.dll
C:\Users\Rifandi\AppData\Local\Temp\cdo3348599862.dll
C:\Users\Rifandi\AppData\Local\Temp\cdo483604587.dll
C:\Users\Rifandi\AppData\Local\Temp\cdo653551628.dll
C:\Users\Rifandi\AppData\Local\Temp\cdo740167257.dll
C:\Users\Rifandi\AppData\Local\Temp\down.5564.OptimizerProInstaller.exe
C:\Users\Rifandi\AppData\Local\Temp\drm_dialogs.dll
C:\Users\Rifandi\AppData\Local\Temp\drm_dyndata_7360010.dll
C:\Users\Rifandi\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpwrxywa.dll
C:\Users\Rifandi\AppData\Local\Temp\EAInstall.dll
C:\Users\Rifandi\AppData\Local\Temp\eauninstall.exe
C:\Users\Rifandi\AppData\Local\Temp\FreeAvastLicenseFile2015__11652_il77739.exe
C:\Users\Rifandi\AppData\Local\Temp\jre-8u40-windows-au.exe
C:\Users\Rifandi\AppData\Local\Temp\KB157937515.exe
C:\Users\Rifandi\AppData\Local\Temp\MySearchDial.exe
C:\Users\Rifandi\AppData\Local\Temp\nv3DVStreaming.dll
C:\Users\Rifandi\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\Rifandi\AppData\Local\Temp\nvStereoApiI.dll
C:\Users\Rifandi\AppData\Local\Temp\nvStInst.exe
C:\Users\Rifandi\AppData\Local\Temp\oi_{E3BDEA52-C4B7-4ABC-A0C4-19DE141CBCF7}.exe
C:\Users\Rifandi\AppData\Local\Temp\onlysetup.exe
C:\Users\Rifandi\AppData\Local\Temp\ose00000.exe
C:\Users\Rifandi\AppData\Local\Temp\ose00002.exe
C:\Users\Rifandi\AppData\Local\Temp\res.dll
C:\Users\Rifandi\AppData\Local\Temp\sqlite-3.7.151-amd64-sqlitejdbc.dll
C:\Users\Rifandi\AppData\Local\Temp\TELKOMSELFlash SU-9000 Install.exe
C:\Users\Rifandi\AppData\Local\Temp\The Sims 2 Double Deluxe_uninst.exe
C:\Users\Rifandi\AppData\Local\Temp\TsuF605ED4F.dll
C:\Users\Rifandi\AppData\Local\Temp\utt40F4.tmp.exe
C:\Users\Rifandi\AppData\Local\Temp\VP6Install.exe
C:\Users\Rifandi\AppData\Local\Temp\VP6VFW.dll
C:\Users\Rifandi\AppData\Local\Temp\xmlUpdater.exe
C:\Users\Rifandi\AppData\Local\Temp\[OOP]Arfan_131402021_04.exe
C:\Users\Rifandi\AppData\Local\Temp\_isA208.exe
C:\Users\Rifandi\AppData\Local\Temp\{6DCC0AC0-6630-4153-B6D9-371220D47689}-32.0.1700.107_32.0.1700.102_chrome_updater.exe
 
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-09-12 14:00
 
==================== End of FRST.txt ============================
 
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version:15-09-2015
Ran by Rifandi (2015-09-19 04:33:15)
Running from C:\Users\Rifandi\Desktop
Windows 8.1 Pro (X64) (2013-12-20 04:58:43)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-1232603322-3645337139-1979953262-500 - Administrator - Disabled)
Guest (S-1-5-21-1232603322-3645337139-1979953262-501 - Limited - Disabled)
Rifandi (S-1-5-21-1232603322-3645337139-1979953262-1001 - Administrator - Enabled) => C:\Users\Rifandi
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
µTorrent (HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\uTorrent) (Version: 3.4.2.35702 - BitTorrent Inc.)
7-Zip 9.22beta (HKLM-x32\...\7-Zip) (Version:  - )
Adobe Acrobat X Pro - English, Français, Deutsch (HKLM-x32\...\{AC76BA86-1033-F400-7760-000000000005}) (Version: 10.1.1 - Adobe Systems)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.1.0.4880 - Adobe Systems Incorporated)
Adobe Creative Suite 6 Master Collection (HKLM-x32\...\{E8AD3069-9EB7-4BA8-8BFE-83F4E69355C0}) (Version: 6 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.134 - Adobe Systems Incorporated)
Adobe Help Manager (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 4.0.244 - Adobe Systems Incorporated)
Adobe Widget Browser (HKLM-x32\...\com.adobe.WidgetBrowser) (Version: 2.0 Build 348 - Adobe Systems Incorporated.)
Ambulant Player 2.4 (HKLM-x32\...\Ambulant Player 2.4) (Version: 2.4 - Centrum voor Wiskunde en Informatica)
Apache Tomcat 8.0.15 (HKLM-x32\...\nbi-tomcat-8.0.15.0.0) (Version:  - )
Apple Application Support (HKLM-x32\...\{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}) (Version: 2.3.4 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Artificial Girl 3 (HKLM-x32\...\{9F0B447F-7E14-4BB9-BCFE-1D5C06F7EE35}) (Version: 1.5 - ILLUSION)
Battlefield 4 Update 1 (HKLM-x32\...\QmF0dGxlZmllbGQ0_is1) (Version: 1 - )
bl (x32 Version: 1.0.0 - Your Company Name) Hidden
Blend for Visual Studio 2012 (x32 Version: 5.0.30709.0 - Microsoft Corporation) Hidden
Blend for Visual Studio 2012 ENU resources (x32 Version: 5.0.30709.0 - Microsoft Corporation) Hidden
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Cheat Engine 6.4 (HKLM-x32\...\Cheat Engine 6.4_is1) (Version:  - Cheat Engine)
Cisco Packet Tracer 5.3.3 (HKLM-x32\...\Cisco Packet Tracer 5.3.3_is1) (Version:  - Cisco Systems, Inc.)
CodeBlocks (HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\CodeBlocks) (Version: 12.11 - The Code::Blocks Team)
Corel Graphics - Windows Shell Extension (HKLM-x32\...\_{B6BFCD02-BA0E-41A9-9C9C-6624C4BB475F}) (Version: 15.2.0.686 - Corel Corporation)
Corel Graphics - Windows Shell Extension (x32 Version: 15.2.686 - Corel Corporation) Hidden
Corel Graphics - Windows Shell Extension 64 Bit (Version: 15.2.686 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Capture (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Common (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Connect (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Custom Data (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Draw (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - EN (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Filters (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - FontNav (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - IPM (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - PHOTO-PAINT (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Photozoom Plugin (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Redist (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Setup Files (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - VBA (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - VideoBrowser (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - VSTA (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - WT (x32 Version: 15.3 -  Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW® Graphics Suite X5 (HKLM-x32\...\_{CE54DCE1-E00A-4D91-ACB9-A2D916C24051}) (Version: 15.2.0.686 - Corel Corporation)
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.48.1.0347 - Disc Soft Ltd)
Devil May Cry 5 - Complete Edition version 1.0.0 (HKLM-x32\...\Devil May Cry 5 - Complete Edition_is1) (Version: 1.0.0 - Capcom)
Dolby Digital Plus Home Theater (HKLM\...\{7E3D8FA1-6092-469A-955B-68FC4A2C67CA}) (Version: 7.3.2.2 - Dolby Laboratories Inc)
Dolphin 4.0 (HKLM-x32\...\Dolphin) (Version: 4.0 - Dolphin Development Team)
Dota 2 (HKLM-x32\...\Steam App 570) (Version:  - Valve)
Dotfuscator and Analytics Community Edition (x32 Version: 5.5.4521.29298 - PreEmptive Solutions) Hidden
Dragonball Xenoverse (HKLM-x32\...\Dragonball Xenoverse_is1) (Version:  - )
DreadOut (HKLM-x32\...\DreadOut_is1) (Version:  - )
Dropbox (HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\Dropbox) (Version: 2.6.24 - Dropbox, Inc.)
Empire Earth III (HKLM-x32\...\{B17E235C-7A3B-4482-B650-21FFDE1D452E}) (Version: 1.00.0000 - Sierra Entertainment)
Energy Management (HKLM-x32\...\InstallShield_{D0956C11-0F60-43FE-99AD-524E833471BB}) (Version: 8.0.2.14 - Lenovo)
Energy Management (x32 Version: 8.0.2.14 - Lenovo) Hidden
Entity Framework Designer for Visual Studio 2012 - enu (HKLM-x32\...\{0A1A1D48-DB23-443A-BC7B-49255D138020}) (Version: 11.1.20702.00 - Microsoft Corporation)
GlassFish Server Open Source Edition 4.1 (HKLM-x32\...\nbi-glassfish-mod-4.1.0.13.0) (Version:  - )
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 45.0.2454.93 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.28.13 - Google Inc.) Hidden
GReaatsaver (HKLM-x32\...\{CA41BB14-E67B-1653-C57B-5CA99418A866}) (Version: 4.3.0.1718 - gureATsuavear) <==== ATTENTION
HSPA Modem version 1.5 (HKLM-x32\...\3G Connect Normal Version 6280 USB_is1) (Version:  - )
IIS 8.0 Express (HKLM\...\{7BF61FA9-BDFB-4563-98AD-FCB0DA28CCC7}) (Version: 8.0.1557 - Microsoft Corporation)
IIS Express Application Compatibility Database for x64 (HKLM\...\{9f4f4a9b-eec5-4906-92fe-d1f43ccf5c8d}.sdb) (Version:  - )
IIS Express Application Compatibility Database for x86 (HKLM\...\{fdfba1f3-74ae-4255-9c10-a0f552b4610f}.sdb) (Version:  - )
ILLUSION ワケあり! (HKLM-x32\...\{FD1E17BC-2956-4AD7-B937-D23F06F1A5E8}) (Version: 1.00.0000 - ILLUSION)
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.13.1706 - Intel Corporation)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3277 - Intel Corporation)
Intel® PROSet/Wireless Software for Bluetooth® Technology (HKLM\...\{DA2600C1-6BDF-4FD1-8F3D-148929CC1385}) (Version: 2.6.1210.0278 - Intel Corporation)
Internet Download Manager (HKLM-x32\...\Internet Download Manager) (Version:  - Tonec Inc.)
Java 8 Update 45 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418045F0}) (Version: 8.0.450 - Oracle Corporation)
Java SE Development Kit 8 Update 45 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0180450}) (Version: 8.0.450.15 - Oracle Corporation)
Join Air (HKLM-x32\...\{A9E5EDA7-2E6C-49E7-924B-A32B89C24A04}) (Version: 1.0.0.2 - ZTE)
Just Cause 2 (HKLM-x32\...\Just Cause 2_is1) (Version:  - R.G.Âèíòèê è Øïóíòèê)
KMSnano 24 (HKLM\...\KMSnano 24_is1) (Version: KMSnano 24 - )
KMSpico v9.0.6.20131120 (HKLM\...\KMSpico_is1) (Version: 9.0.6.20131120 - )
LocalESPC (x32 Version: 8.59.25584 - Microsoft Corporation) Hidden
LocalESPCui for en-us (x32 Version: 8.59.25584 - Microsoft) Hidden
Macromedia Dreamweaver 8 (HKLM-x32\...\{0837A661-FEC3-48B3-876C-91E7D32048A9}) (Version: 8.0.0.2734 - Macromedia)
Macromedia Extension Manager (HKLM-x32\...\{5546CDB5-2CE2-498B-B059-5B3BF81FC41F}) (Version: 1.7.240 - Macromedia, Inc.)
Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\...\{5CBFF3F3-2D40-34EE-BCA5-A95BC19E400D}) (Version: 4.5.50709 - Microsoft Corporation)
Microsoft .NET Framework 4.5 SDK (HKLM-x32\...\{1948E039-EC79-4591-951D-9867A8C14C90}) (Version: 4.5.50709 - Microsoft Corporation)
Microsoft ASP.NET MVC 3 (HKLM-x32\...\{DCDEC776-BADD-48B9-8F9A-DFF513C3D7FA}) (Version: 3.0.20105.0 - Microsoft Corporation)
Microsoft ASP.NET Web Pages (HKLM-x32\...\{631471BE-DEAB-454B-A9AC-CE3EB42C28B3}) (Version: 1.0.20105.0 - Microsoft Corporation)
Microsoft Help Viewer 2.0 (HKLM-x32\...\Microsoft Help Viewer 2.0) (Version: 2.0.50727 - Microsoft Corporation)
Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUSR) (Version: 15.0.4420.1017 - Microsoft Corporation)
Microsoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.10411.0 - Microsoft Corporation)
Microsoft Silverlight 4 SDK (HKLM-x32\...\{189AEA94-DAFB-487A-8CEE-F9D3DDE0A748}) (Version: 4.0.60310.0 - Microsoft Corporation)
Microsoft Silverlight 5 SDK (HKLM-x32\...\{E1FBB3D4-ADB0-4949-B101-855DA061C735}) (Version: 5.0.61118.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Command Line Utilities  (HKLM\...\{9D573E71-1077-4C7E-B4DB-4E22A5D2B48B}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 Data-Tier App Framework  (HKLM\...\{36E619BC-A234-4EC3-849B-779A7C865A45}) (Version: 11.0.2316.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Data-Tier App Framework  (HKLM-x32\...\{FBA6F90E-36EC-4FC9-9B25-3834E3BD46A8}) (Version: 11.0.2316.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Express LocalDB  (HKLM\...\{13D558FE-A863-402C-B115-160007277033}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 Management Objects  (HKLM-x32\...\{DA1C1761-5F4F-4332-AB9D-29EDF3F8EA0A}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 Management Objects  (x64) (HKLM\...\{FA0A244E-F3C2-4589-B42A-3D522DE79A42}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 Native Client  (HKLM\...\{49D665A2-4C2A-476E-9AB8-FCC425F526FC}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 Transact-SQL Compiler Service  (HKLM\...\{BEB0F91E-F2EA-48A1-B938-7857ABF2A93D}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 Transact-SQL ScriptDom  (HKLM\...\{0E8670B8-3965-4930-ADA6-570348B67153}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 T-SQL Language Service  (HKLM-x32\...\{6D6D43E5-218C-4B05-92D3-2240810F4760}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server Compact 4.0 SP1 x64 ENU (HKLM\...\{78909610-D229-459C-A936-25D92283D3FD}) (Version: 4.0.8876.1 - Microsoft Corporation)
Microsoft SQL Server Data Tools - enu (11.1.20627.00) (HKLM-x32\...\{FA804794-2CCB-4301-954F-2C2894698876}) (Version: 11.1.20627.00 - Microsoft Corporation)
Microsoft SQL Server Data Tools Build Utilities - enu (11.1.20627.00) (HKLM-x32\...\{790E9425-8570-493F-9AE7-81AFC9E46930}) (Version: 11.1.20627.00 - Microsoft Corporation)
Microsoft SQL Server System CLR Types (HKLM-x32\...\{A47FD1BF-A815-4A76-BE65-53A15BD5D25D}) (Version: 10.50.1600.1 - Microsoft Corporation)
Microsoft SQL Server System CLR Types (x64) (HKLM\...\{4701DEDE-1888-49E0-BAE5-857875924CA2}) (Version: 10.50.1600.1 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2012 (HKLM-x32\...\{E2082604-4BA5-44BB-BBFB-AF0F3CB8C6AB}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2012 (x64) (HKLM\...\{F1949145-EB64-4DE7-9D81-E6D27937146C}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 Redistributable - x64 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 Redistributable - x86 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.31125 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2.0 - ENU (HKLM-x32\...\{AA4A4B2C-0465-3CF8-BA76-27A027D8ACAB}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2.0 Runtime (HKLM-x32\...\{299C0434-4F4E-341F-A916-4E07AEB35E79}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual Studio Ultimate 2012 (HKLM-x32\...\{ae17ae9b-af38-40d2-a194-6102c56ed502}) (Version: 11.0.50727.26 - Microsoft Corporation)
Microsoft Web Deploy 3.0 (HKLM\...\{AA72C306-30BE-4BB1-9E42-59552BAD2CDF}) (Version: 3.1236.1631 - Microsoft Corporation)
Microsoft Web Deploy dbSqlPackage Provider - enu (HKLM-x32\...\{E4C33F5B-1B2F-466E-957E-B274F08151A0}) (Version: 10.3.20225.0 - Microsoft Corporation)
Microsoft Web Platform Installer 4.0 (HKLM\...\{E2B8249D-895C-4685-8C83-00F3B1A13028}) (Version: 4.0.1622 - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
Middle-Earth - Shadow of Mordor (by Hommy Games) (HKLM-x32\...\{3E74CDB4-8B8F-4640-BE71-4B66886615F7}_is1) (Version: 1.0.1636.20 - )
Mozilla Firefox 36.0.4 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 36.0.4 (x86 en-US)) (Version: 36.0.4 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
MPC-HC 1.7.1 (64-bit) (HKLM\...\{2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1) (Version: 1.7.1.0 - MPC-HC Team)
Need for Speed™ Carbon (HKLM-x32\...\{259C0ABB-A3B2-4D70-008F-BF7EE491B70B}) (Version:  - )
NetBeans IDE 8.0.2 (HKLM-x32\...\nbi-nb-base-8.0.2.0.201411181905) (Version: 8.0.2 - NetBeans.org)
Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.47.3 - Black Tree Gaming)
Notepad++ (HKLM-x32\...\Notepad++) (Version: 5.9.6.2 - )
NVIDIA 3D Vision Driver 337.88 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 337.88 - NVIDIA Corporation)
NVIDIA GeForce Experience 2.1.5 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.1.5 - NVIDIA Corporation)
NVIDIA Graphics Driver 337.88 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 337.88 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation)
Oracle VM VirtualBox 4.3.16 (HKLM\...\{D7FAEA32-7CE3-4D9F-9139-F7B87BCC50AF}) (Version: 4.3.16 - Oracle Corporation)
Origin (HKLM-x32\...\Origin) (Version: 9.4.1.116 - Electronic Arts, Inc.)
Outils de vérification linguistique 2013 de Microsoft Office - Français (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
PCSX2 - Playstation 2 Emulator (HKLM-x32\...\pcsx2-r5875) (Version:  - )
PDF Settings CS6 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden
ph (x32 Version: 1.0.0 - Your Company Name) Hidden
PreEmptive Analytics Visual Studio Components (x32 Version: 1.0.2180.1 - PreEmptive Solutions) Hidden
Prerequisites for SSDT  (HKLM-x32\...\{9169C939-ED01-446A-BD0C-29873BAF4E48}) (Version: 11.0.2100.60 - Microsoft Corporation)
Pro Evolution Soccer 2015 (HKLM-x32\...\UHJvRXZvbHV0aW9uU29jY2VyMjAxNQ==_is1) (Version: 1 - )
Prototype 2 (HKLM-x32\...\Prototype 2_is1) (Version: Prototype 2 - )
Qualcomm Atheros Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 10.0 - Qualcomm Atheros)
QuickTime (HKLM-x32\...\{B67BAFBA-4C9F-48FA-9496-933E3B255044}) (Version: 7.74.80.86 - Apple Inc.)
Rainmeter (HKLM-x32\...\Rainmeter) (Version: 3.1 r2290 - )
RapeLay (remove only) (HKLM-x32\...\RapeLay) (Version:  - )
RAR Password Recovery v1.1 RC16 (remove only) (HKLM-x32\...\Intelore - RAR Password Recovery) (Version:  - )
RAR Password Unlocker 4.2.0.0 (HKLM-x32\...\{B789FA51-6A71-408F-92DE-EDE4A517B8F9}_is1) (Version:  - Password Unlocker Studio)
Razer Game Booster (HKLM-x32\...\Razer Game Booster_is1) (Version: 4.1.59.0 - Razer Inc.)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9200.39048 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.2.612.2012 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7027 - Realtek Semiconductor Corp.)
Safari (HKLM-x32\...\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.)
SavePass 1.1 (HKLM-x32\...\SavePass 1.1) (Version: 1.35.3.9 - OB) <==== ATTENTION
School Mate 2 (HKLM-x32\...\{BC980840-FC67-4027-9055-251136406614}_is1) (Version: 1.3 - randompirate)
Sexy Beach 3 - Complete English Edition (remove only) (HKLM-x32\...\Sexy Beach 3 - Complete English Edition) (Version:  - )
SHIELD Streaming (Version: 3.1.3000 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 16.18.9 - NVIDIA Corporation) Hidden
SPORE™ (HKLM-x32\...\{9DF0196F-B6B8-4C3A-8790-DE42AA530101}) (Version: 1.00.0000 - Electronic Arts)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Stronghold Crusader 2 (HKLM-x32\...\Stronghold Crusader 2_is1) (Version: 1.0 - PLAZA)
System Requirements Lab Detection (HKLM-x32\...\{2C9D426D-3F38-4B1A-BAC5-DEC1212BB852}) (Version: 2.2.4.0 - Husdawg, LLC)
TAP-Windows 9.9.2 (HKLM\...\TAP-Windows) (Version: 9.9.2 - )
TELKOMSELFlash SU-9000 version 5.117 (HKLM-x32\...\TELKOMSELFlash SU-9000 version_is1) (Version:  - )
The Sims" 3 (HKLM-x32\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.63.5 - Electronic Arts)
The Sims" 3 70s, 80s, & 90s Stuff (HKLM-x32\...\{E1868CAE-E3B9-4099-8C18-AA8944D336FD}) (Version: 17.0.77 - Electronic Arts)
The Sims" 3 Ambitions (HKLM-x32\...\{910F4A29-1134-49E0-AD8B-56E4A3152BD1}) (Version: 4.0.87 - Electronic Arts)
The Sims" 3 Diesel Stuff (HKLM-x32\...\{1C9B6173-6DC9-4EEE-9EFC-6BA115CFBE43}) (Version: 14.0.48 - Electronic Arts)
The Sims" 3 Fast Lane Stuff (HKLM-x32\...\{ED436EA8-4145-4703-AE5D-4D09DD24AF5A}) (Version: 5.0.44 - Electronic Arts)
The Sims" 3 Generations (HKLM-x32\...\{E6B88BD6-E4B2-4701-A648-B6DAC6E491CC}) (Version: 8.0.152 - Electronic Arts)
The Sims" 3 High-End Loft Stuff (HKLM-x32\...\{71828142-5A24-4BD0-97E7-976DA08CE6CF}) (Version: 3.0.38 - Electronic Arts)
The Sims" 3 Into the Future (HKLM-x32\...\{A0BBD6C7-B546-4048-B33A-F21F5C9F5B09}) (Version: 21.0.150 - Electronic Arts)
The Sims" 3 Island Paradise (HKLM-x32\...\{DB21639E-FE55-432C-BCA2-0C5249E3F79E}) (Version: 19.0.101 - Electronic Arts)
The Sims" 3 Katy Perry's Sweet Treats (HKLM-x32\...\{9B2506E3-9A3F-45B5-96BF-509CAD584650}) (Version: 13.0.62 - Electronic Arts)
The Sims" 3 Late Night (HKLM-x32\...\{45057FCE-5784-48BE-8176-D9D00AF56C3C}) (Version: 6.0.81 - Electronic Arts)
The Sims" 3 Master Suite Stuff (HKLM-x32\...\{08A25478-C5DD-4EA7-B168-3D687CA987FF}) (Version: 11.0.84 - Electronic Arts)
The Sims" 3 Movie Stuff (HKLM-x32\...\{D0087539-3C57-44E0-BEE7-D779D546CBE1}) (Version: 20.0.53 - Electronic Arts)
The Sims" 3 Outdoor Living Stuff (HKLM-x32\...\{117B6BF6-82C3-420C-B284-9247C8568E53}) (Version: 7.0.55 - Electronic Arts)
The Sims" 3 Pets (HKLM-x32\...\{C12631C6-804D-4B32-B0DD-8A496462F106}) (Version: 10.0.96 - Electronic Arts)
The Sims" 3 Seasons (HKLM-x32\...\{3DE92282-CB49-434F-81BF-94E5B380E889}) (Version: 16.0.136 - Electronic Arts)
The Sims" 3 Showtime (HKLM-x32\...\{3BBFD444-5FAB-49F6-98B1-A1954E831399}) (Version: 12.0.273 - Electronic Arts)
The Sims" 3 Supernatural (HKLM-x32\...\{B37DAFA5-717D-41F8-BDFB-3A4B68C0B3A1}) (Version: 15.0.135 - Electronic Arts)
The Sims" 3 Town Life Stuff (HKLM-x32\...\{7B11296A-F894-449C-8DF6-6AAAA7D4D118}) (Version: 9.0.73 - Electronic Arts)
The Sims" 3 University Life (HKLM-x32\...\{F26DE8EF-F2CF-40DC-8CDA-CC0D82D11B36}) (Version: 18.0.126 - Electronic Arts)
The Sims" 3 World Adventures (HKLM-x32\...\{BA26FFA5-6D47-47DB-BE56-34C357B5F8CC}) (Version: 2.0.86 - Electronic Arts)
The Sims™ 3 + Expansions Uninstaller (HKLM-x32\...\The Sims™ 3 + Expansions Uninstaller) (Version: 1.0.0.11 - Electronic Arts)
Total Video Converter 3.71 100812 (HKLM-x32\...\Total Video Converter 3.71_is1) (Version:  - EffectMatrix Inc.)
TSEV Skyrim LE (HKLM-x32\...\TSEV Skyrim LE_is1) (Version: 2.0.0.0 - )
UltraISO Premium V9.62 (HKLM-x32\...\UltraISO_is1) (Version:  - )
Unity Web Player (HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\UnityWebPlayer) (Version:  - Unity Technologies ApS)
Update for  (KB2504637) (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
Watch Dogs (HKLM-x32\...\Watch Dogs_R.G. Mechanics_is1) (Version:  - R.G. Mechanics, spider91)
WCF Data Services 5.0 (for OData v3) Primary Components (x32 Version: 5.0.50628.0 - Microsoft Corporation) Hidden
WCF Data Services Tools for Microsoft Visual Studio 2012 (x32 Version: 5.0.50710.0 - Microsoft Corporation) Hidden
WCF RIA Services V1.0 SP2 (HKLM-x32\...\{3A523AF9-D32F-4C85-8388-0335731F3405}) (Version: 4.1.61829.0 - Microsoft Corporation)
Winamp (HKLM-x32\...\Winamp) (Version: 5.666  - Nullsoft, Inc)
Winamp Detector Plug-in (HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc)
Windows 7 USB/DVD Download Tool (HKLM-x32\...\{CCF298AF-9CE1-4B26-B251-486E98A34789}) (Version: 1.0.30 - Microsoft Corporation)
Windows Driver Package - Lenovo (ACPIVPC) System  (02/17/2013 9.52.0.776) (HKLM\...\35DD26BE48DAF4A9F35F969F3CB1E3E1435E661E) (Version: 02/17/2013 9.52.0.776 - Lenovo)
Windows Driver Package - Lenovo (WUDFRd) LenovoVhid  (07/25/2013 10.30.0.288) (HKLM\...\6BCA401E9CBEED970D75F55FA5320F60D11984E9) (Version: 07/25/2013 10.30.0.288 - Lenovo)
WinRAR 5.00 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.00.0 - win.rar GmbH)
WOW Slider (HKLM-x32\...\WOW Slider_is1) (Version:  - )
XAMPP (HKLM-x32\...\xampp) (Version: 1.8.3-2 - BitNami)
YoutubeAdblocker (HKLM-x32\...\{4820778D-AB0D-6D18-C316-52A6A0E1D507}) (Version: 4.2.0.1591 - YoutubeAdblocker) <==== ATTENTION
YoutubeAdblocker (HKLM-x32\...\{CF830981-8F31-C561-C7A0-FE2CE1878B40}) (Version: 4.2.0.1447 - YoutubeAdblocker) <==== ATTENTION
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-1232603322-3645337139-1979953262-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Rifandi\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1232603322-3645337139-1979953262-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Rifandi\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1232603322-3645337139-1979953262-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Rifandi\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1232603322-3645337139-1979953262-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Rifandi\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1232603322-3645337139-1979953262-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Rifandi\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
 
==================== Restore Points =========================
 
ATTENTION: System Restore is disabled
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2013-08-22 20:25 - 2013-08-22 20:25 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {2AAB2F86-2217-46D4-8004-88F4A8F9C72E} - System32\Tasks\help4u_notification_service => C:\Program Files (x86)\help4u\help4u_notification_service.exe [2015-04-06] (FileProperties_CompanyName) <==== ATTENTION
Task: {351C2021-978E-48D5-8B8E-18C5D168A284} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation)
Task: {3A8AF67F-D4A2-4830-93C5-666CBB8285DE} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {3B5AD782-9EA1-448B-BCC2-9383C65F05A3} - System32\Tasks\{6BA0FAB1-B899-472D-AFB0-B490EA3BD58D} => pcalua.exe -a "G:\Cai Dat Game\setup.exe" -d "G:\Cai Dat Game"
Task: {3E9BB584-BAB7-4855-AC19-11D577E342ED} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.)
Task: {41A93C16-4B1F-449F-9AD6-AEECC8A9FBE7} - System32\Tasks\{CBE073F7-A1DD-4027-B793-2EE54ADF6B0C} => pcalua.exe -a F:\Sims2EP1\eauninstall.exe -d F:\Sims2EP1
Task: {5D9B967E-9E0F-4213-BA24-896CDCB181B5} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2012-10-01] (Microsoft Corporation)
Task: {81DCD15E-230D-458D-9943-3D597965D212} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.)
Task: {8C1B1656-0D90-4DD7-B839-30970D425D89} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation)
Task: {96B7DC84-1C5F-4AC1-8EF8-D697CE121B1A} - System32\Tasks\{8627B382-5A88-4FF9-A728-51F1974DF348} => pcalua.exe -a F:\AutoRun.exe -d F:\
Task: {A1EEE3CA-8222-464D-BD7C-0E48D2C118DF} - System32\Tasks\help4u_updating_service => C:\Program Files (x86)\help4u\help4u_updating_service.exe [2015-04-06] () <==== ATTENTION
Task: {AC9DE117-FBDF-48AC-ACE6-122B0835D672} - System32\Tasks\AutoPico Daily Restart => C:\Program Files\KMSpico\AutoPico.exe [2013-11-20] ()
Task: {C5EA213E-BFBF-436F-B6B2-DF62BD727E8A} - System32\Tasks\EPUpdater => C:\Users\Rifandi\AppData\Roaming\BabSolution\Shared\BabMaint.exe [2013-12-12] () <==== ATTENTION
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\64b5c250-015d-48b5-b157-300a8e3bfe82.job => C:\Program Files (x86)\SavePass 1.1\64b5c250-015d-48b5-b157-300a8e3bfe82.exe <==== ATTENTION
Task: C:\Windows\Tasks\c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-1.job => C:\Program Files (x86)\SavePass 1.1\SavePass 1.1-codedownloader.exe <==== ATTENTION
Task: C:\Windows\Tasks\c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-11.job => C:\Program Files (x86)\SavePass 1.1\c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-11.exe <==== ATTENTION
Task: C:\Windows\Tasks\c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.job => C:\Program Files (x86)\SavePass 1.1\c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe <==== ATTENTION
Task: C:\Windows\Tasks\c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-5.job => C:\Program Files (x86)\SavePass 1.1\c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-5.exe <==== ATTENTION
Task: C:\Windows\Tasks\c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-5_user.job => C:\Program Files (x86)\SavePass 1.1\c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-5.exe <==== ATTENTION
Task: C:\Windows\Tasks\c6f17427-280e-44d4-88bc-561c1fe0d308.job => C:\Program Files (x86)\SavePass 1.1\c6f17427-280e-44d4-88bc-561c1fe0d308.exeȘ/agentregpath='SavePass 1.1' /appid=63429 /srcid='001504' /subid='0' /zdata='0' /bic=2827820446154BECB360AC217BBD185EIE /verifier=a2bd8b9c017cd558c9844388bde7f117 /installerversion=1_35_09_03 /installationtime=1410537375 /statsdomain=http:/stats.newclientgenservice.com /errorsdomain=http:/errors.newclientgenservice.com /extensionname='Information' /torpedoiesleeps=1000 /torpedoieplugins=93-0,102-0,104-0,178-288,179-288,180-288,223-288,263-24 /monetizationdomain=http:/logs.newclientgenservice.com <==== ATTENTION
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\help4u_notification_service.job => C:\Program Files (x86)\help4u\help4u_notification_service.exeǢ/url='http:/cdn.selectbestopt.com/notf_sys/index.html' /crregname='help4u' /appid='73143' /srcid='2913' /bic='3c4f7bfbe922fc9e30d0f7a9a7b1bbad' /verifier='1d6ae977715d5d15586c376a4be34ff3' /installerversion='1.50.3.10' /statsdomain='http:/stats.buildomserv.com/data.gif?' /errorsdomain='http:/stats.buildomserv.com/data.gif?' /monetizationdomain='http:/logs.buildomserv.com/monetization.gif <==== ATTENTION
Task: C:\Windows\Tasks\help4u_updating_service.job => C:\Program Files (x86)\help4u\help4u_updating_service.exe§ /campid=2913 /verid=1 /url=http:/cdn.buildomserv.com/txt/@CAMPID@/@VER@/file.txt /appid=73143 /taskname=help4u_updating_service /funurl=http:/stats.buildomserv.com <==== ATTENTION
 
==================== Loaded Modules (Whitelisted) ==============
 
2013-12-22 09:35 - 2014-05-20 08:25 - 00116568 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2014-01-28 01:16 - 2009-08-20 14:22 - 00135168 _____ () C:\Windows\SysWOW64\ChgService.exe
2013-12-21 09:45 - 2009-07-15 09:37 - 00246272 _____ () C:\Program Files (x86)\Join Air\AssistantServices.exe
2012-10-01 20:36 - 2012-10-01 20:36 - 06522480 _____ () C:\Program Files\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2013-12-20 19:59 - 2013-08-23 05:07 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2014-05-25 21:18 - 2014-05-25 21:18 - 00036536 ____N () C:\Program Files\Rainmeter\Rainmeter.exe
2014-05-25 21:18 - 2014-05-25 21:18 - 00747192 _____ () C:\Program Files\Rainmeter\Rainmeter.dll
2014-05-25 21:17 - 2014-05-25 21:17 - 00056832 _____ () C:\Program Files\Rainmeter\Plugins\WebParser.dll
2012-10-01 20:37 - 2012-10-01 20:37 - 06522480 _____ () C:\Program Files (x86)\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2015-09-18 11:24 - 2015-09-12 07:22 - 01501512 _____ () C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.93\libglesv2.dll
2015-09-18 11:24 - 2015-09-12 07:22 - 00081224 _____ () C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.93\libegl.dll
2013-12-20 20:48 - 2013-08-08 13:23 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\ACE.dll
2015-09-18 11:24 - 2015-09-12 07:22 - 16393032 _____ () C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.93\PepperFlash\pepflashplayer.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Rifandi\Downloads\Wallpaper\trafalgar-law-jolly-roger-one-piece.jpg
DNS Servers: 192.168.43.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
HKLM\...\StartupApproved\StartupFolder: => "StartupModem.lnk"
HKLM\...\StartupApproved\Run32: => "UIExec"
HKLM\...\StartupApproved\Run32: => "APSDaemon"
HKLM\...\StartupApproved\Run32: => "QuickTime Task"
HKLM\...\StartupApproved\Run32: => "WinampAgent"
HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\StartupApproved\Run: => "DAEMON Tools Lite"
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{1A06DCD8-8738-438C-8399-A80A5E0B8728}] => (Allow) C:\Program Files (x86)\AVG\AVG2014\avgmfapx.exe
FirewallRules: [{F2AE1ED8-46AE-444B-AB1C-B23A4870D723}] => (Allow) C:\Program Files (x86)\AVG\AVG2014\avgmfapx.exe
FirewallRules: [{09DDA33A-F684-498B-A248-1FF2A010503B}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{9240A9AF-274B-4D6B-80E5-BCEA62BEDD87}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{AB0F5B93-B492-45C8-8B0C-92E9C2A7B5EE}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{8905FE43-37DD-48A5-8C71-4E849017C3B8}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{562750CB-3D48-4CEF-84F8-0554B9BF4601}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{BE82E2D9-F899-4F2B-A3E9-6B44EA1C87CA}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{EC871DAD-58DB-4A2C-BFBC-74D670725D1C}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{97A03C4D-04F4-4878-8797-A2A1557665C8}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{B6F7FC4E-3F4B-4469-98AC-6F6B3877AB22}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{4F0DB9E4-E763-48D4-AF84-14834AFAF53C}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{4A3E9165-9DB0-46EB-890F-DCE89376C612}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{20083BF8-F33B-4932-BBC1-7DAEE01E3710}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{588D0D49-B694-4391-BB67-4F279A9BA92C}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{D7490F1E-D3BA-4A4D-93F6-A6D8A309FEC5}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [TCP Query User{9B45E7F0-30EE-47DD-A6A3-5C61DFE3E55E}D:\games\prototype 2\prototype2.exe] => (Block) D:\games\prototype 2\prototype2.exe
FirewallRules: [UDP Query User{765FB244-EE57-4E0A-A1A8-4254A4AE4C90}D:\games\prototype 2\prototype2.exe] => (Block) D:\games\prototype 2\prototype2.exe
FirewallRules: [TCP Query User{19635119-F6FE-450D-91C7-B69050C4FBAD}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe] => (Allow) C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe
FirewallRules: [UDP Query User{70D36063-2C68-44E0-A9F2-6C99883C4168}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe] => (Allow) C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe
FirewallRules: [TCP Query User{A49822FF-6416-4240-8E79-F95943201E2C}D:\games\konami\pro evolution soccer 2013\pes2013.exe] => (Block) D:\games\konami\pro evolution soccer 2013\pes2013.exe
FirewallRules: [UDP Query User{45DEE90E-9EBF-43F9-8799-998E83696311}D:\games\konami\pro evolution soccer 2013\pes2013.exe] => (Block) D:\games\konami\pro evolution soccer 2013\pes2013.exe
FirewallRules: [{775A3945-A3B4-4B4E-AFDF-0CCC57EB45F9}] => (Allow) %systemroot%\system32\alg.exe
FirewallRules: [TCP Query User{D891051F-84BD-4B10-923F-C293F54DD09E}D:\games\dota\war3.exe] => (Allow) D:\games\dota\war3.exe
FirewallRules: [UDP Query User{4C2C0E42-89CE-488C-8B12-F2392966F600}D:\games\dota\war3.exe] => (Allow) D:\games\dota\war3.exe
FirewallRules: [{27FB2FF6-1E02-4AF4-B515-BE58E7F66AED}] => (Allow) C:\Program Files\KMSpico\KMSELDI.exe
FirewallRules: [{D31A831A-E4FA-41E1-98ED-24EF2D307FDA}] => (Allow) C:\Program Files\KMSpico\KMSELDI.exe
FirewallRules: [{07799367-4E73-4629-B22A-23952A4E3A98}] => (Allow) C:\Program Files\KMSpico\KMSServer.exe
FirewallRules: [{D7FFEC2F-1027-45F8-BF55-9E803B26383D}] => (Allow) C:\Program Files\KMSpico\KMSServer.exe
FirewallRules: [{3E856337-07D0-4D60-B6DE-E6B7F3221DA2}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe
FirewallRules: [{B0BA9B87-C926-41A7-B95D-6428E7C88BA7}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe
FirewallRules: [TCP Query User{E6622835-0D2A-4DEF-9567-5E451F3EA331}C:\program files (x86)\winamp\winamp.exe] => (Block) C:\program files (x86)\winamp\winamp.exe
FirewallRules: [UDP Query User{C9C1066E-BE2F-49CC-99F8-50AAE4B9E3AE}C:\program files (x86)\winamp\winamp.exe] => (Block) C:\program files (x86)\winamp\winamp.exe
FirewallRules: [{E10061AB-4E65-496F-9FE1-55C9ED05FAD8}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe
FirewallRules: [TCP Query User{5FB4513F-2E57-47EF-A0FE-CE5F2E1615B9}C:\program files (x86)\winamp\winamp.exe] => (Block) C:\program files (x86)\winamp\winamp.exe
FirewallRules: [UDP Query User{25006CC4-CE19-4424-946D-E20E4C243FD1}C:\program files (x86)\winamp\winamp.exe] => (Block) C:\program files (x86)\winamp\winamp.exe
FirewallRules: [TCP Query User{CC65259C-1AA7-4F1C-9436-334BFA693245}D:\games\battle field 4\bf4_x86.exe] => (Block) D:\games\battle field 4\bf4_x86.exe
FirewallRules: [UDP Query User{E807EE63-8880-4009-AD1C-0BC5990364D9}D:\games\battle field 4\bf4_x86.exe] => (Block) D:\games\battle field 4\bf4_x86.exe
FirewallRules: [TCP Query User{66E425DA-B20D-4E19-9180-7A976439C34B}D:\games\left 4 dead\left4dead.exe] => (Block) D:\games\left 4 dead\left4dead.exe
FirewallRules: [UDP Query User{3A2BEAC6-C02C-4634-B01A-AE94B750A88E}D:\games\left 4 dead\left4dead.exe] => (Block) D:\games\left 4 dead\left4dead.exe
FirewallRules: [{8EC7C0D2-469D-425A-B1B6-B81075B83C37}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe
FirewallRules: [{0EB4AB0D-4A4A-4D49-B669-6857DFBAAA39}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe
FirewallRules: [{971E3028-9FB4-4F27-9B29-7DBC1424F8A5}] => (Allow) C:\Windows\System32\KMSServer.exe
FirewallRules: [{213EADAA-1CFE-4D58-9E21-C09621DE09D5}] => (Allow) C:\Windows\System32\KMSServer.exe
FirewallRules: [{EBCA317D-CC83-43ED-AAE3-74866A4DFFD5}] => (Allow) D:\GAMES\Dragon Nest SEA\DragonNest.exe
FirewallRules: [{E6B27D11-BF45-4183-A96A-5CB3D7C3791D}] => (Allow) D:\GAMES\Dragon Nest SEA\DragonNest.exe
FirewallRules: [{CCC5C3B9-E51F-4B73-8BC1-2D66C70840D9}] => (Allow) D:\GAMES\Dragon Nest SEA\DragonNest.exe
FirewallRules: [{B16D292D-99B8-4EA4-AC6F-0B9132F3EE53}] => (Allow) D:\GAMES\Dragon Nest SEA\DragonNest.exe
FirewallRules: [TCP Query User{90F7424A-8CFA-4BB1-BA55-EB24C74E71F7}D:\game installer\ygopro-1.032.1-v2-percy-full\ygopro_vs.exe] => (Allow) D:\game installer\ygopro-1.032.1-v2-percy-full\ygopro_vs.exe
FirewallRules: [UDP Query User{D4C32738-7C8E-4867-9329-62743A543310}D:\game installer\ygopro-1.032.1-v2-percy-full\ygopro_vs.exe] => (Allow) D:\game installer\ygopro-1.032.1-v2-percy-full\ygopro_vs.exe
FirewallRules: [{C19AF992-2A97-4322-9A2A-34F9139E6D1F}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{02774A92-C7BD-44E0-A9F3-9549069A0057}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{275ECE94-FC70-494D-BD2F-49BB9652950D}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{CE39FD7D-5A3D-4D17-8487-46323B83F7CD}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [TCP Query User{BA753D81-75AA-4A12-9D7F-A2D1DAD7E556}D:\games\prototype 2\prototype2.exe] => (Block) D:\games\prototype 2\prototype2.exe
FirewallRules: [UDP Query User{185D5014-4109-4234-AA47-1DDBFF073CA9}D:\games\prototype 2\prototype2.exe] => (Block) D:\games\prototype 2\prototype2.exe
FirewallRules: [{DF926D87-1BE0-4685-88BB-E8509C8AA040}] => (Allow) C:\Program Files\KMSnano\qemu-system-i386.exe
FirewallRules: [{69799192-0148-4AFD-90AF-84E0FB23EB56}] => (Allow) C:\Program Files\KMSnano\qemu-system-i386.exe
FirewallRules: [TCP Query User{AF03422E-9BCC-4E54-A80E-890A78693EDF}C:\xampp\apache\bin\httpd.exe] => (Allow) C:\xampp\apache\bin\httpd.exe
FirewallRules: [UDP Query User{1BB7E18C-5720-4F80-A26C-4B4D6759F5F1}C:\xampp\apache\bin\httpd.exe] => (Allow) C:\xampp\apache\bin\httpd.exe
FirewallRules: [TCP Query User{98AAD854-2D55-4A73-AC8D-7A754DCE2A6E}C:\xampp\mysql\bin\mysqld.exe] => (Allow) C:\xampp\mysql\bin\mysqld.exe
FirewallRules: [UDP Query User{22279E3E-2B1E-4548-947E-861FE12B4F2E}C:\xampp\mysql\bin\mysqld.exe] => (Allow) C:\xampp\mysql\bin\mysqld.exe
FirewallRules: [TCP Query User{20ACCA7D-677B-49C4-9FBB-1054D7DCC002}C:\xampp\filezillaftp\filezillaserver.exe] => (Block) C:\xampp\filezillaftp\filezillaserver.exe
FirewallRules: [UDP Query User{51AE80A9-24F9-41FC-B991-C92BA2F16493}C:\xampp\filezillaftp\filezillaserver.exe] => (Block) C:\xampp\filezillaftp\filezillaserver.exe
FirewallRules: [TCP Query User{FAAC8729-32D6-4E1E-B3A1-33EE26EC6DA9}C:\xampp\mercurymail\mercury.exe] => (Block) C:\xampp\mercurymail\mercury.exe
FirewallRules: [UDP Query User{6B59466B-7787-460A-8135-8584676DDD3D}C:\xampp\mercurymail\mercury.exe] => (Block) C:\xampp\mercurymail\mercury.exe
FirewallRules: [TCP Query User{B34030A8-37BC-4369-8E40-9E8593FCA786}D:\game installer\yu-gi-oh!\ygopro-1.032.1-v2-percy-full\ygopro_vs.exe] => (Allow) D:\game installer\yu-gi-oh!\ygopro-1.032.1-v2-percy-full\ygopro_vs.exe
FirewallRules: [UDP Query User{1BC3E71A-6D5B-4055-A44D-20339D07333B}D:\game installer\yu-gi-oh!\ygopro-1.032.1-v2-percy-full\ygopro_vs.exe] => (Allow) D:\game installer\yu-gi-oh!\ygopro-1.032.1-v2-percy-full\ygopro_vs.exe
FirewallRules: [{59C6CA05-CDA7-4977-AAA5-F11DEBD92122}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\devenv.exe
FirewallRules: [{3946D93A-3163-47B2-AE52-0217794C2B3F}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\devenv.exe
FirewallRules: [{826D336A-FEFC-43BF-982B-BF5195301D96}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\devenv.exe
FirewallRules: [{38A36E27-11A4-455B-8519-9D9B9B6F35A4}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\devenv.exe
FirewallRules: [{DDF81497-B651-4F9B-872E-FEFDD9489202}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\devenv.exe
FirewallRules: [{2C6D4CCD-4DD9-47E8-9148-DE1C59A5A4AE}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\devenv.exe
FirewallRules: [{1D0F16D8-87B1-45A6-A597-ECA32834DB8D}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\devenv.exe
FirewallRules: [TCP Query User{DDFCA80E-0E24-4BD5-BC1C-91CEB65A42B6}D:\games\farcry 3\bin\farcry3_d3d11.exe] => (Block) D:\games\farcry 3\bin\farcry3_d3d11.exe
FirewallRules: [UDP Query User{7BDAB37E-85AD-47D5-9232-DA4FBE791CC8}D:\games\farcry 3\bin\farcry3_d3d11.exe] => (Block) D:\games\farcry 3\bin\farcry3_d3d11.exe
FirewallRules: [{F6ACCA3B-0F7F-4BCB-9202-2382097D23B1}] => (Allow) C:\Users\Rifandi\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{A835423B-9920-4C72-86A3-2FDE848D1AD0}] => (Allow) C:\Users\Rifandi\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [TCP Query User{0B1F268B-D381-43B7-96D5-8091703066EC}D:\games\divinity original sin\shipping\eocapp.exe] => (Block) D:\games\divinity original sin\shipping\eocapp.exe
FirewallRules: [UDP Query User{6306DE96-53C2-439D-A523-9E26BFC2D7D2}D:\games\divinity original sin\shipping\eocapp.exe] => (Block) D:\games\divinity original sin\shipping\eocapp.exe
FirewallRules: [TCP Query User{08EE761A-7CD2-49B4-8627-8534CC0A0158}H:\game installer\yu-gi-oh!\ygopro-1.032.1-v2-percy-full\ygopro_vs.exe] => (Block) H:\game installer\yu-gi-oh!\ygopro-1.032.1-v2-percy-full\ygopro_vs.exe
FirewallRules: [UDP Query User{63B09064-974F-4436-B236-ABE88D1D683F}H:\game installer\yu-gi-oh!\ygopro-1.032.1-v2-percy-full\ygopro_vs.exe] => (Block) H:\game installer\yu-gi-oh!\ygopro-1.032.1-v2-percy-full\ygopro_vs.exe
FirewallRules: [TCP Query User{F1617650-D557-4FD9-910D-86489DA5B55A}D:\games\outlast\outlast\binaries\win64\olgame.exe] => (Allow) D:\games\outlast\outlast\binaries\win64\olgame.exe
FirewallRules: [UDP Query User{F0C3E966-0FA0-4118-AE9B-45599BC8E5EB}D:\games\outlast\outlast\binaries\win64\olgame.exe] => (Allow) D:\games\outlast\outlast\binaries\win64\olgame.exe
FirewallRules: [{515B5948-489D-48C0-9607-0E2E1BBCC843}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
FirewallRules: [{4A95A6AD-35AF-4038-BA25-01A1ADA3EAB6}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
FirewallRules: [TCP Query User{6E87AF5C-8E18-490A-A9A5-1C8E3CC9623F}C:\users\rifandi\appdata\roaming\torntv.com\torntv downloader.exe] => (Allow) C:\users\rifandi\appdata\roaming\torntv.com\torntv downloader.exe
FirewallRules: [UDP Query User{4DE8BECB-1C50-478D-A1DD-6450237F7C27}C:\users\rifandi\appdata\roaming\torntv.com\torntv downloader.exe] => (Allow) C:\users\rifandi\appdata\roaming\torntv.com\torntv downloader.exe
FirewallRules: [{2A58B125-FA27-4763-923F-962854AC4C64}] => (Allow) C:\Users\Rifandi\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{16606177-8490-41B5-8A89-817542833D73}] => (Allow) C:\Users\Rifandi\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [TCP Query User{1B01E919-DD5D-4C53-9A08-6FA46EC14E69}C:\program files (x86)\stronghold crusader 2\bin\win32_release\crusader2.exe] => (Block) C:\program files (x86)\stronghold crusader 2\bin\win32_release\crusader2.exe
FirewallRules: [UDP Query User{983E342C-763C-4F85-B0F9-48B66631F44F}C:\program files (x86)\stronghold crusader 2\bin\win32_release\crusader2.exe] => (Block) C:\program files (x86)\stronghold crusader 2\bin\win32_release\crusader2.exe
FirewallRules: [TCP Query User{9C6A7B15-3DE6-4258-9CE7-8FCCBBDE7FE6}D:\games\stronghold crusader 2\bin\win32_release\crusader2.exe] => (Allow) D:\games\stronghold crusader 2\bin\win32_release\crusader2.exe
FirewallRules: [UDP Query User{CB15A0A3-D243-43D8-9621-0FFD3B91B959}D:\games\stronghold crusader 2\bin\win32_release\crusader2.exe] => (Allow) D:\games\stronghold crusader 2\bin\win32_release\crusader2.exe
FirewallRules: [{CE95B2B9-8A50-4D43-A53B-967115E4BA08}] => (Allow) D:\GAMES\Sierra Entertainment\Empire Earth III\EE3.exe
FirewallRules: [{743E21E2-9067-4D72-9CB8-58CC60AF37F4}] => (Allow) D:\GAMES\Sierra Entertainment\Empire Earth III\EE3.exe
FirewallRules: [{53AF91DF-0050-4B9B-8981-DF6F4FB160B9}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{3A971CE2-F559-42D0-93F3-4A2365E792F8}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{8BEE11D2-7F86-4B46-9669-E96517FC5AB7}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{6F618C98-4506-4A99-98C2-AAE190AA3A9B}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{FFBFA651-18E8-4F3C-BDD7-0BB25117FE71}] => (Allow) D:\GAMES\SteamLibrary\steamapps\common\dota 2 beta\dota.exe
FirewallRules: [{E83DC855-BB23-47A9-85A7-E165E628CA83}] => (Allow) D:\GAMES\SteamLibrary\steamapps\common\dota 2 beta\dota.exe
FirewallRules: [TCP Query User{C438FD29-9201-4750-BCE5-C78BD9D3DB2B}C:\program files (x86)\cisco packet tracer 5.3.3\bin\packettracer5.exe] => (Block) C:\program files (x86)\cisco packet tracer 5.3.3\bin\packettracer5.exe
FirewallRules: [UDP Query User{DC7E8C51-20F3-4920-BE94-5FD0B64F8789}C:\program files (x86)\cisco packet tracer 5.3.3\bin\packettracer5.exe] => (Block) C:\program files (x86)\cisco packet tracer 5.3.3\bin\packettracer5.exe
FirewallRules: [TCP Query User{4F71FC4A-674D-4914-9235-9C566EF79522}D:\games\battle field 4\bf4.exe] => (Allow) D:\games\battle field 4\bf4.exe
FirewallRules: [UDP Query User{CD03D387-6214-43AC-8C63-B342DF7E224A}D:\games\battle field 4\bf4.exe] => (Allow) D:\games\battle field 4\bf4.exe
FirewallRules: [TCP Query User{406C305E-219C-4CF8-AA6D-FEE4ADAF9D6A}D:\games\company of heroes\bugreport\bugreport.exe] => (Block) D:\games\company of heroes\bugreport\bugreport.exe
FirewallRules: [UDP Query User{0C7D59B2-DDA8-434C-8400-65A342A9D1F2}D:\games\company of heroes\bugreport\bugreport.exe] => (Block) D:\games\company of heroes\bugreport\bugreport.exe
FirewallRules: [{9DDF3AC0-45AA-4706-83DD-4AB1E6C059D0}] => (Allow) D:\GAMES\SteamLibrary\steamapps\common\Aura Kingdom\game.bin
FirewallRules: [{7C11A026-5E0B-469C-8101-39A26E6AF45F}] => (Allow) D:\GAMES\SteamLibrary\steamapps\common\Aura Kingdom\game.bin
FirewallRules: [TCP Query User{F6389871-CABA-428C-A860-FD222EC6B270}D:\games\pro evolution soccer 2015\pes2015.exe] => (Block) D:\games\pro evolution soccer 2015\pes2015.exe
FirewallRules: [UDP Query User{8BE9F98D-8DA0-4C44-A98D-6497171661EF}D:\games\pro evolution soccer 2015\pes2015.exe] => (Block) D:\games\pro evolution soccer 2015\pes2015.exe
FirewallRules: [TCP Query User{3D794DA7-A0BF-4E42-A700-1F93299411F4}D:\games\devil may cry 5 - complete edition\binaries\win32\dmc-devilmaycry.exe] => (Allow) D:\games\devil may cry 5 - complete edition\binaries\win32\dmc-devilmaycry.exe
FirewallRules: [UDP Query User{F05D44A1-7268-4885-9BD1-2CC2F50C04B9}D:\games\devil may cry 5 - complete edition\binaries\win32\dmc-devilmaycry.exe] => (Allow) D:\games\devil may cry 5 - complete edition\binaries\win32\dmc-devilmaycry.exe
FirewallRules: [{EE0F8D63-27BE-4EF2-8BDE-26AA454297C0}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{7605257A-3D4B-49AB-B2DD-132CCB812A10}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{9A5B1E8A-B31F-4B38-B6D9-5E00A45FF065}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{BD3755B2-254D-4C99-9AB3-6C9A3CB42267}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{44D20B8C-A835-4767-9306-134F953356F9}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe
FirewallRules: [{B3303EAD-5EE2-461A-AAF0-CB56CCE10C86}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe
FirewallRules: [{A41FF3C1-CF80-4D64-956E-D623EBA66A93}] => (Allow) C:\Windows\System32\KMSServer.exe
FirewallRules: [{B9C6AC4A-06A8-44A3-A2D7-910AC3D1DEAA}] => (Allow) C:\Windows\System32\KMSServer.exe
FirewallRules: [TCP Query User{CB038158-67D6-4066-B1EF-B01AEB8547E0}C:\program files (x86)\java\jdk1.7.0_40\bin\java.exe] => (Allow) C:\program files (x86)\java\jdk1.7.0_40\bin\java.exe
FirewallRules: [UDP Query User{355E4826-AEF9-4DE1-91C3-3545BEC33CB1}C:\program files (x86)\java\jdk1.7.0_40\bin\java.exe] => (Allow) C:\program files (x86)\java\jdk1.7.0_40\bin\java.exe
FirewallRules: [{029E27FF-EE21-4AC9-AEBF-2626CF8A0E29}] => (Block) C:\program files (x86)\java\jdk1.7.0_40\bin\java.exe
FirewallRules: [{8E58488F-C3EC-40E4-87DD-E6B23DE3CD13}] => (Block) C:\program files (x86)\java\jdk1.7.0_40\bin\java.exe
FirewallRules: [TCP Query User{D3E3887D-DC4D-46F8-85BB-A17DB4DF3143}C:\program files (x86)\netbeans 8.0.2\bin\netbeans.exe] => (Allow) C:\program files (x86)\netbeans 8.0.2\bin\netbeans.exe
FirewallRules: [UDP Query User{A751FD98-134E-4AEC-9F8B-E7E253030F48}C:\program files (x86)\netbeans 8.0.2\bin\netbeans.exe] => (Allow) C:\program files (x86)\netbeans 8.0.2\bin\netbeans.exe
FirewallRules: [{E5B43872-E575-4F3D-986A-64D619871AD3}] => (Allow) D:\GAMES\Lost Saga\LostSaga\autoupgrade.exe
FirewallRules: [{69B3670B-2F4D-4167-B798-5B149BA07E62}] => (Allow) D:\GAMES\Lost Saga\LostSaga\autoupgrade.exe
FirewallRules: [{CD9A082D-3309-48CB-BDE1-39391F4F243E}] => (Allow) D:\GAMES\Lost Saga\LostSaga\lostsaga.exe
FirewallRules: [{37642C02-07E0-4AAC-9BD9-3C8B1895FFFC}] => (Allow) D:\GAMES\Lost Saga\LostSaga\lostsaga.exe
FirewallRules: [TCP Query User{D4092692-D5C5-4D48-8B18-D81225C3825B}C:\program files (x86)\java\jdk1.8.0\bin\java.exe] => (Block) C:\program files (x86)\java\jdk1.8.0\bin\java.exe
FirewallRules: [UDP Query User{46354920-75FC-4F1F-A024-57422E213465}C:\program files (x86)\java\jdk1.8.0\bin\java.exe] => (Block) C:\program files (x86)\java\jdk1.8.0\bin\java.exe
FirewallRules: [TCP Query User{FE8B8914-6097-4301-BD5F-B0D69500EB11}C:\program files\java\jdk1.8.0_45\bin\java.exe] => (Block) C:\program files\java\jdk1.8.0_45\bin\java.exe
FirewallRules: [UDP Query User{F298C8CA-5E47-4D38-BBA2-37840677E966}C:\program files\java\jdk1.8.0_45\bin\java.exe] => (Block) C:\program files\java\jdk1.8.0_45\bin\java.exe
FirewallRules: [TCP Query User{D753E326-1315-41D8-818C-82CD5647D11E}C:\program files\java\jdk1.8.0_45\jre\bin\javaw.exe] => (Allow) C:\program files\java\jdk1.8.0_45\jre\bin\javaw.exe
FirewallRules: [UDP Query User{F8ED93EC-2756-4CEA-BB2D-2233892BCBF5}C:\program files\java\jdk1.8.0_45\jre\bin\javaw.exe] => (Allow) C:\program files\java\jdk1.8.0_45\jre\bin\javaw.exe
FirewallRules: [TCP Query User{DB6151F1-04FD-48A9-8E07-2F307A3FE61F}D:\software installer\eclipse luna\eclipse.exe] => (Block) D:\software installer\eclipse luna\eclipse.exe
FirewallRules: [UDP Query User{3E5D112C-48BE-4D66-87B7-55E3CEA6EB97}D:\software installer\eclipse luna\eclipse.exe] => (Block) D:\software installer\eclipse luna\eclipse.exe
FirewallRules: [{929EA187-A7BC-4475-AE10-0276AB7258B2}] => (Allow) C:\Program Files (x86)\Adobe\Adobe Flash Builder 4.6\FlashBuilder.exe
FirewallRules: [{15087077-58B1-4AC5-9883-69C8EE642A7F}] => (Allow) C:\Program Files (x86)\Adobe\Adobe Flash Builder 4.6\FlashBuilder.exe
FirewallRules: [{F7E106CA-25D3-4AA0-8E8D-9C2FB54E483D}] => (Allow) LPort=7935
FirewallRules: [{03156271-3F11-48B1-9D43-6206B176FA0A}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (09/19/2015 12:23:43 AM) (Source: NvStreamSvc) (EventID: 2001) (User: )
Description: NvStreamSvcNvVAD initialization failed [6]
 
Error: (09/19/2015 12:23:43 AM) (Source: NvStreamSvc) (EventID: 2001) (User: )
Description: NvStreamSvcFailed to set NvVAD endpoint as default Audio endpoint [0]
 
Error: (09/19/2015 12:23:43 AM) (Source: NvStreamSvc) (EventID: 2001) (User: )
Description: NvStreamSvcNvVAD endpoint registration failed [0]
 
Error: (09/19/2015 12:13:50 AM) (Source: MsiInstaller) (EventID: 11321) (User: RIP)
Description: SA_Error1709: StandardAction(0xC00706AD): Product: AVG 2015 -- Error 1321. SA_Error1321: StandardAction(0xC0070529): The Installer has insufficient privileges to modify this file: C:\Program Files (x86)\AVG\AVG2015\avgcrema.exe.
 
Error: (09/19/2015 12:12:20 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.
 
Error: (09/19/2015 12:12:20 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.
 
Error: (09/18/2015 02:30:40 PM) (Source: MsiInstaller) (EventID: 11321) (User: RIP)
Description: SA_Error1709: StandardAction(0xC00706AD): Produk: AVG 2015 -- Kesalahan 1321. SA_Error1321: StandardAction(0xC0070529): Penginstal tidak mempunyai privilese yang cukup untuk mengubah file ini: C:\Program Files (x86)\AVG\AVG2015\avgcrema.exe.
 
Error: (09/18/2015 02:28:19 PM) (Source: MsiInstaller) (EventID: 10005) (User: RIP)
Description: SA_Error1709: StandardAction(0xC00706AD): Product: AVG 2015 -- Error 27007. CA_Error27007: Wait4StartWD(0xC0070426): Waiting for watchdog service start failed
 
Error: (09/18/2015 02:28:19 PM) (Source: MsiInstaller) (EventID: 10005) (User: RIP)
Description: SA_Error1709: StandardAction(0xC00706AD): Product: AVG 2015 -- Error 27007. CA_Error27007: Wait4StartWD(0xC0070426): Waiting for watchdog service start failed
 
Error: (09/18/2015 02:20:31 PM) (Source: NvStreamSvc) (EventID: 2001) (User: )
Description: NvStreamSvcNvVAD initialization failed [6]
 
 
System errors:
=============
Error: (09/19/2015 04:00:35 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Windows Defender Service service failed to start due to the following error: 
%%1053
 
Error: (09/19/2015 04:00:35 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Windows Defender Service service to connect.
 
Error: (09/19/2015 12:25:57 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Windows Defender Service service terminated unexpectedly.  It has done this 3 time(s).
 
Error: (09/19/2015 12:25:30 AM) (Source: ipnathlp) (EventID: 30013) (User: )
Description: 192.168.43.251192.168.137.0255.255.255.0
 
Error: (09/19/2015 12:25:30 AM) (Source: ipnathlp) (EventID: 1233) (User: )
Description: 
 
Error: (09/19/2015 12:25:30 AM) (Source: ipnathlp) (EventID: 1233) (User: )
Description: 
 
Error: (09/19/2015 12:25:30 AM) (Source: ipnathlp) (EventID: 1233) (User: )
Description: 
 
Error: (09/19/2015 12:24:56 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Defender Service service terminated unexpectedly.  It has done this 2 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.
 
Error: (09/19/2015 12:24:02 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Service KMSELDI service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (09/19/2015 12:23:55 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Defender Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.
 
 
CodeIntegrity:
===================================
  Date: 2015-07-27 04:23:14.067
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-06-15 20:50:59.848
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-06-15 20:50:58.778
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-05-04 19:21:05.000
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-05-03 18:41:37.484
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-05-03 18:28:38.544
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-05-03 18:19:41.800
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-05-03 14:45:34.731
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-05-03 06:53:29.838
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-05-03 06:24:57.206
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
 
 
==================== Memory info =========================== 
 
Processor: Intel® Core™ i5-3230M CPU @ 2.60GHz
Percentage of memory in use: 42%
Total physical RAM: 3957.6 MB
Available physical RAM: 2283 MB
Total Virtual: 4661.6 MB
Available Virtual: 2408.54 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:146.49 GB) (Free:26.35 GB) NTFS
Drive d: () (Fixed) (Total:690.8 GB) (Free:56.59 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: C24F1638)
Partition 1: (Active) - (Size=102 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=146.5 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=690.8 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=94.1 GB) - (Type=05)
 
==================== End of Addition.txt ============================

 


  • 0

Advertisements


#2
BrianDrab

BrianDrab

    Trusted Helper

  • Malware Removal
  • 3,591 posts

Hi. My name is Brian, and I would be happy to look into your issue.
 


- General Instructions -


  • Please read all instructions and fixes thoroughly. Read the ENTIRE post BEFORE performing any steps so you understand all that needs to be done.
  • I would advise printing any instructions for easy reference as some of the fixes may require you to boot in Safe mode. Access to these instructions may not be available in Safe Mode.
  • Any fixes provided by myself are for this log file only and should not be used on any other systems.
  • Do not run any other removal software or perform updates other than the ones I provide, as it will complicate the cleaning process.
  • It's very likely that part of our cleanup will include emptying your recycle bin. If you use your recycle bin as an archive and do not wish this to be emptied, please let me know.
  • It is also likely during our cleaning process that your internet browsing history will be removed. Your favorites will be untouched. If you don't want this to happen you need to let me know before running any steps so I can adjust my fixes accordingly.
  • You have 4 days to reply to each post or the topic will be closed. You will be able to request that the topic be re-opened by sending me a PM (Personal Message) or PM a moderator.
  • Please feel free to ask any questions, especially if you are having problems with my instructions.


- Save ALL Tools to your Desktop-



All tools that I have you download should be placed on the desktop unless otherwise stated. If you are familiar with how to save files to the desktop then you can skip this step.
 
Since you are continuing with this step then I assume you are unfamiliar with saving files to your desktop. As a result it's easiest if you configure your browser(s) to download any tools to the desktop by default. Please use the appropriate instructions below depending on the browser you are using.
Chrome.JPGGoogle Chrome - Click the "Customize and control Google Chrome" button in the upper right-corner of the browser.Settings.JPG Choose Settings. at the bottom of the screen click the
"Show advanced settings..." link. Scroll down to find the Downloads section and click the Change... button. Select your desktop and click OK.
Firefox.JPGMozilla Firefox - Click the "Open Menu" button in the upper right-corner of the browser. Settings.JPG Choose Options. In the downloads section, click the Browse button, click on the Desktop folder
and the click the "Select Folder" button. Click OK to get out of the Options menu.
IE.jpgInternet Explorer - Click the Tools menu in the upper right-corner of the browser. Tools.JPG Select View downloads. Select the Options link in the lower left of the window. Click Browse and
select the Desktop and then choose the Select Folder button. Click OK to get out of the download options screen and then click Close to get out of the View Downloads screen.
NOTE: IE8 Does not support changing download locations in this manner. You will need to download the tool(s) to the default folder, usually Downloads, then copy them to the desktop.
 

- Finally Before We Start-


 
Removing malware is a complicated multiple step process, Please stay with me until I have declared your system clean. I strongly recommend you backup your personal files and folders. Although rare, attempting to remove malware can render your machine unbootable or cause data loss. Having backups of your data is your responsibility. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.

 

 

 

I'm reviewing your logs now.


  • 0

#3
BrianDrab

BrianDrab

    Trusted Helper

  • Malware Removal
  • 3,591 posts

I've reviewed the logs and created a fix as you are definitely infected. However I noticed that you have illegal software on your machine. Our Terms of Use prohibit me from assisting while this software is on the machine. The part of the TOU that states this is quoted below. If you would like to continue with the cleanup, please remove any illegal software and provide a fresh set of logs and we'll get you cleaned up. Thank you for your understanding.

 

 

We will NOT help anyone we suspect of having obtained their software or services illegally.

 


  • 0

#4
fandy

fandy

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts

umm can you tell me the list of illegal software in my pc, so i can remove them completly


  • 0

#5
BrianDrab

BrianDrab

    Trusted Helper

  • Malware Removal
  • 3,591 posts

Sure thing. Assuming your copy of Windows is a legal copy, the following programs appear to be the issues.

 

Microsoft Office Professional Plus 2013

Adobe Creative Suite 6 Master Collection

 

If you think this software is legit and paid for, please let me know and we'll do some other checks to validate.

 

Thank you.


  • 0

#6
fandy

fandy

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts

I can uninstall Adobe Creative Suite 6 Master Collection, but i still need the Ms Office
 

i know its a illegal software but can you help me please, i really need the software

 

Thank you


Edited by fandy, 21 September 2015 - 01:09 AM.

  • 0

#7
BrianDrab

BrianDrab

    Trusted Helper

  • Malware Removal
  • 3,591 posts

I'm sorry by the Terms of Use I agreed to when signing up on the forum as well as my personal ethical stance prohibits me from doing so.

 

If you are looking for Word, Excel, Powerpoint, etc. you can always use the online version which is free.

 

https://www.office.com/


  • 0

#8
fandy

fandy

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts

I already remove the software you told
and this is the new scan report...

now you can help me right?

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:15-09-2015
Ran by Rifandi (administrator) on RIP (23-09-2015 12:23:06)
Running from C:\Users\Rifandi\Desktop
Loaded Profiles: Rifandi (Available Profiles: Rifandi)
Platform: Windows 8.1 Pro (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Atheros Commnucations) C:\Windows\System32\AdminService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\Windows\SysWOW64\ChgService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
() C:\Program Files (x86)\Join Air\AssistantServices.exe
(Microsoft Corporation) C:\Users\Rifandi\AppData\Roaming\Microsoft\SystemCertificates\VSSVC.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(FileProperties_CompanyName) C:\Program Files (x86)\help4u\help4u_notification_service.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation) C:\Users\Rifandi\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Integrated Clock Controller Service\ICCProxy.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMan.exe
() C:\Program Files\Rainmeter\Rainmeter.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [17111056 2013-12-20] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [193008 2013-12-20] (Lenovo(beijing) Limited)
HKLM\...\Run: [Nvtmru] => "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2531472 2014-12-13] (NVIDIA Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13647576 2013-08-27] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1321688 2013-08-07] (Realtek Semiconductor)
HKLM-x32\...\Run: [UIExec] => C:\Program Files (x86)\Join Air\UIExec.exe [713728 2010-12-16] ()
HKLM-x32\...\Run: [WinampAgent] => C:\Program Files (x86)\Winamp\winampa.exe [85600 2013-12-13] (Nullsoft, Inc.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [TaskbarNoNotification] 1
HKLM\...\Policies\Explorer: [HideSCAHealth] 1
HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\Run: [TornTv Downloader] => C:\Users\Rifandi\AppData\Roaming\TornTV.com\Torntv Downloader.exe /c=startup
HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\Run: [Only-search] => C:\Users\Rifandi\AppData\Local\onlysearch\onlysearch\1.3.15.4\onlysearch.exe
HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\Run: [GoogleChromeAutoLaunch_2044B68C092258CC6B61BEF807401E47] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [815944 2015-09-19] (Google Inc.)
HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [3882576 2014-12-12] (Tonec Inc.)
HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\Run: [AdobeBridge] => [X]
AppInit_DLLs: C:\PROGRA~2\SupTab\SEARCH~2.DLL => C:\Program Files (x86)\SupTab\SearchProtect64.dll [96768 2014-03-05] (Skytech Co., Ltd.)
AppInit_DLLs: ,C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [166568 2014-05-20] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\PROGRA~2\SupTab\SEARCH~1.DLL => C:\Program Files (x86)\SupTab\SearchProtect32.dll [85504 2014-03-05] (Skytech Co., Ltd.)
AppInit_DLLs-x32: ,C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [146480 2014-05-20] (NVIDIA Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  No File
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Rifandi\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Rifandi\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Rifandi\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Rifandi\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll [2014-04-21] (Tonec Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Rifandi\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Rifandi\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Rifandi\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\StartupModem.lnk [2014-01-28]
ShortcutTarget: StartupModem.lnk -> C:\Program Files (x86)\3G Connect\StartUpRun.exe ()
Startup: C:\Users\Rifandi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Rainmeter.lnk [2014-10-22]
ShortcutTarget: Rainmeter.lnk -> C:\Program Files\Rainmeter\Rainmeter.exe ()
Startup: C:\Users\Rifandi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TornTvDownloader.lnk [2014-10-30]
ShortcutTarget: TornTvDownloader.lnk -> C:\Users\Rifandi\AppData\Roaming\TornTV.com\TornTV Downloader.exe (No File)
GroupPolicy: Restriction - Chrome <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.43.1
Tcpip\..\Interfaces\{659EBD27-2A47-4029-8B7F-C20452FF1B3D}: [DhcpNameServer] 192.168.43.1
Tcpip\..\Interfaces\{970D6D83-F3E5-4CA0-B64D-27F554407A29}: [DhcpNameServer] 202.0.107.1 202.0.107.2
 
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.qone8.com/?type=hp&ts=1395502286&from=ild&uid=ST1000LM024XHN-M101MBB_S2U5J9KD102731
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?trackid=sp-006
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.qone8.com/web/?type=ds&ts=1395502286&from=ild&uid=ST1000LM024XHN-M101MBB_S2U5J9KD102731&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://start.qone8.com/?type=hp&ts=1395502286&from=ild&uid=ST1000LM024XHN-M101MBB_S2U5J9KD102731
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = 
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.qone8.com/web/?type=ds&ts=1395502286&from=ild&uid=ST1000LM024XHN-M101MBB_S2U5J9KD102731&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = 
HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?trackid=sp-006
HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxps://www.google.com/?trackid=sp-006
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.qone8.com/web/?type=ds&ts=1395502286&from=ild&uid=ST1000LM024XHN-M101MBB_S2U5J9KD102731&q={searchTerms}
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=irmsd0103&cd=2XzuyEtN2Y1L1QzutB0C0DtDyD0AtCtAzz0CyCyCyB0E0D0EtN0D0Tzu0SyByCyDtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R&cr=1961462397&ir=
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.qone8.com/web/?type=ds&ts=1395502286&from=ild&uid=ST1000LM024XHN-M101MBB_S2U5J9KD102731&q={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.qone8.com/web/?type=ds&ts=1395502286&from=ild&uid=ST1000LM024XHN-M101MBB_S2U5J9KD102731&q={searchTerms}
SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1232603322-3645337139-1979953262-1001 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1232603322-3645337139-1979953262-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=irmsd0103&cd=2XzuyEtN2Y1L1QzutB0C0DtDyD0AtCtAzz0CyCyCyB0E0D0EtN0D0Tzu0SyByCyDtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R&cr=1961462397&ir=
SearchScopes: HKU\S-1-5-21-1232603322-3645337139-1979953262-1001 -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.only-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=B6BD2ED05A138C66&affID=129300&tsp=5416
SearchScopes: HKU\S-1-5-21-1232603322-3645337139-1979953262-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.qone8.com/web/?type=ds&ts=1395502286&from=ild&uid=ST1000LM024XHN-M101MBB_S2U5J9KD102731&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1232603322-3645337139-1979953262-1001 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll [2015-05-20] (Internet Download Manager, Tonec Inc.)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-06-04] (Oracle Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-06-04] (Oracle Corporation)
BHO-x32: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll [2015-05-20] (Internet Download Manager, Tonec Inc.)
BHO-x32: Microsoft Web Test Recorder 10.0 Helper -> {876d9f09-c6d6-4324-a2cc-04dd9a4de12f} -> C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll [2012-07-26] (Microsoft Corporation)
BHO-x32: mysearchdial Helper Object -> {EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD} -> C:\Program Files (x86)\Mysearchdial\1.8.21.0\bh\mysearchdial.dll [2014-02-04] (MySearchDial)
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  No File
Toolbar: HKLM-x32 - mysearchdial Toolbar - {3004627E-F8E9-4E8B-909D-316753CBA923} - C:\Program Files (x86)\Mysearchdial\1.8.21.0\mysearchdialTlbr.dll [2014-02-04] (MySearchDial)
DPF: HKLM-x32 {6A060448-60F9-11D5-A6CD-0002B31F7455} 
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://start.qone8.com/?type=sc&ts=1395502286&from=ild&uid=ST1000LM024XHN-M101MBB_S2U5J9KD102731
 
FireFox:
========
FF ProfilePath: C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default
FF NewTab: 
FF Homepage: about:home
FF Keyword.URL: 
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_134.dll [2015-03-24] ()
FF Plugin: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-06-04] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-06-04] (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_134.dll [2015-03-24] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-08-08] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-08-08] (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll [2012-04-11] ( Microsoft Corporation)
FF Plugin-x32: @nullsoft.com/winampDetector;version=1 -> C:\Program Files (x86)\Winamp Detect\npwachk.dll [2013-12-13] (Nullsoft, Inc.)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2014-05-20] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2014-05-20] (NVIDIA Corporation)
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll [No File]
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll [No File]
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-19] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-19] (Google Inc.)
FF Plugin HKU\S-1-5-21-1232603322-3645337139-1979953262-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Rifandi\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2014-02-21] (Unity Technologies ApS)
FF user.js: detected! => C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\user.js [2014-03-22]
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2014-01-25] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2014-01-25] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2014-01-25] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2014-01-25] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2014-01-25] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Rifandi\AppData\Roaming\mozilla\plugins\np-mswmp.dll [2009-09-26] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Users\Rifandi\AppData\Roaming\mozilla\plugins\npatgpc.dll [2014-10-13] (Cisco WebEx LLC)
FF SearchPlugin: C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\searchplugins\MyOnlineSearch.xml [2014-10-30]
FF SearchPlugin: C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\searchplugins\onlysearchkms.xml [2014-10-30]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\qone8.xml [2014-03-22]
FF Extension: SavePass 1.2 - C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\Extensions\[email protected] [2015-08-19]
FF Extension: YoutubeAdblocker - C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\Extensions\[email protected] [2014-02-04]
FF Extension: anonymoX - C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\Extensions\[email protected] [2014-01-25]
FF Extension: SQLite Manager - C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\Extensions\[email protected] [2015-06-09]
FF Extension: Themes Menu - C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\Extensions\{84625510-7e5d-11e0-a411-0800200c9a66}.xpi [2014-10-30]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\extensions\[email protected]
FF HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\Firefox\Extensions: [[email protected]] - C:\Users\Rifandi\AppData\Roaming\IDM\idmmzcc5
FF Extension: IDM CC - C:\Users\Rifandi\AppData\Roaming\IDM\idmmzcc5 [2015-09-23]
FF HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\SeaMonkey\Extensions: [[email protected]] - C:\Users\Rifandi\AppData\Roaming\IDM\idmmzcc5
 
Chrome: 
=======
CHR HomePage: Default -> hxxps://www.google.com/
CHR StartupUrls: Default -> "hxxps://www.google.com/"
CHR Profile: C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-12-21]
CHR Extension: (Google Drive) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-12-21]
CHR Extension: (Earth View from Google Earth) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhloflhklmhfpedakmangadcdofhnnoh [2014-11-17]
CHR Extension: (YouTube) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-12-21]
CHR Extension: (The Elder Scrolls Online - Theme) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\bodeacmfbgjollphdaehplmjobapnbin [2015-06-30]
CHR Extension: (Google Search) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-12-21]
CHR Extension: (Adblock Plus) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\efmppbpipefbijnpmokkcfnedohbiije [2015-04-12]
CHR Extension: (Google Docs Offline) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-09-06]
CHR Extension: (Privacy manager) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\giccehglhacakcfemddmfhdkahamfcmd [2014-02-04]
CHR Extension: (YoutubeAdblocker) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkoghcmfjgopofakhllpdmflopkhccoj [2014-02-04]
CHR Extension: (Advanced REST client) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\hgmloofddffdnphfgcellkdfbfbjeloo [2015-05-09]
CHR Extension: (YYTBoOkMark) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kmjboicapmacdaecgldenkpdcdkkifgc [2014-02-04]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-14]
CHR Extension: (Speed Dial [FVD] - New Tab Page, 3D, Sync...) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\llaficoajjainaijghjlofdfmbjpebpa [2015-06-30]
CHR Extension: (IDM Integration Module) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2015-06-16]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-21]
CHR Extension: (Adblock Pro) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ocifcklkibdehekfnmflempfgjhbedch [2015-06-30]
CHR Extension: (gREatSaveer) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\oefifkdlbdfmnhdkbagencoidhfjcich [2014-02-04]
CHR Extension: (Currently) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojhmphdkpgbibohbnpbfiefkgieacjmh [2014-11-17]
CHR Extension: (Quick start) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma [2014-03-22]
CHR Extension: (Gmail) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-12-21]
CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2015-05-20]
CHR HKLM-x32\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2015-05-20]
CHR HKLM-x32\...\Chrome\Extension: [pelmeidfhdlhlbjimpabfcbnnojbboma] - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx [2014-03-22]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AtherosSvc; C:\Windows\system32\AdminService.exe [208384 2012-08-29] (Atheros Commnucations)
R2 Change Modem Device Service; C:\Windows\SysWOW64\ChgService.exe [135168 2009-08-20] () [File not signed]
S3 fussvc; C:\Program Files (x86)\Windows Kits\8.0\App Certification Kit\fussvc.exe [139776 2012-07-25] (Microsoft Corporation) [File not signed]
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1148560 2014-12-13] (NVIDIA Corporation)
R2 Intel® Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel® Corporation) [File not signed]
S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel® Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [169432 2013-08-08] (Intel Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1701520 2014-12-13] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [19823248 2014-12-13] (NVIDIA Corporation)
R2 RzKLService; C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe [105448 2013-11-22] (Razer Inc.)
S2 Service KMSELDI; C:\Program Files\KMSpico\Service_KMS.exe [691480 2013-11-20] () [File not signed]
S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe [126976 2012-07-25] (Microsoft Corporation) [File not signed]
R2 UI Assistant Service; C:\Program Files (x86)\Join Air\AssistantServices.exe [246272 2009-07-15] () [File not signed]
R2 VSSS; C:\Users\Rifandi\AppData\Roaming\Microsoft\SystemCertificates\VSSVC.exe [103523264 2015-06-24] (Microsoft Corporation) [File not signed] <==== ATTENTION
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [346872 2013-08-22] (Microsoft Corporation)
S2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23840 2013-08-22] (Microsoft Corporation)
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 athr; C:\Windows\system32\DRIVERS\athwbx.sys [3837440 2013-07-15] (Qualcomm Atheros Communications, Inc.)
S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [224768 2013-08-22] (Microsoft Corporation)
S3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [132480 2012-10-01] (Motorola Solutions, Inc.)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-04-20] (Disc Soft Ltd)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
S3 fcusbser; C:\Windows\system32\DRIVERS\fcusbser.sys [119552 2010-06-03] (BM)
S3 hxsyol; C:\Windows\system32\hxsy64.sys [86352 2015-02-27] ()
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-08-08] (Intel Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2014-12-13] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [38032 2014-11-22] (NVIDIA Corporation)
S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [27520 2007-05-14] (Research In Motion Limited)
S3 SDGame; C:\Windows\System32\svchost.exe [37768 2013-08-22] (Microsoft Corporation)
R3 SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [230912 2013-08-22] (Microsoft Corporation)
S3 VSPerfDrv110; C:\Program Files (x86)\Microsoft Visual Studio 11.0\Team Tools\Performance Tools\x64\VSPerfDrv110.sys [70264 2012-07-13] (Microsoft Corporation)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [34760 2013-08-22] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [265056 2013-08-22] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124256 2013-08-22] (Microsoft Corporation)
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
R4 KProcessHacker2; \??\C:\Program Files\kprocesshacker.sys [X]
S2 {09BB444F-B2E2-4009-BAF2-7B727681223E}; \??\D:\GAMES\VMLaunch\BuddyVM.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-09-23 12:23 - 2015-09-23 12:23 - 00030149 _____ C:\Users\Rifandi\Desktop\FRST.txt
2015-09-21 13:58 - 2015-09-21 13:58 - 01415680 _____ (wj32) C:\Program Files\MNOHIJGH.exe
2015-09-19 21:31 - 2015-09-19 17:59 - 00456493 _____ C:\Users\Rifandi\Documents\Backup_of_font baru.cdr
2015-09-19 18:59 - 2015-09-19 18:59 - 01415680 _____ (wj32) C:\Program Files\HTIAGJZW.exe
2015-09-19 17:59 - 2015-09-19 21:31 - 00473711 _____ C:\Users\Rifandi\Documents\font baru.cdr
2015-09-19 04:32 - 2015-09-23 12:23 - 00000000 ____D C:\FRST
2015-09-19 04:28 - 2015-09-19 04:28 - 02191360 _____ (Farbar) C:\Users\Rifandi\Desktop\FRST64.exe
2015-09-19 04:03 - 2015-09-19 04:04 - 02019656 _____ (Bleeping Computer, LLC) C:\Users\Rifandi\Downloads\rkill.com
2015-09-19 02:29 - 2015-09-19 02:29 - 00427689 _____ C:\Users\Rifandi\Documents\Backup_of_Font.cdr
2015-09-19 01:56 - 2015-09-19 16:05 - 00440731 _____ C:\Users\Rifandi\Documents\Font.cdr
2015-09-19 00:19 - 2015-09-19 00:20 - 00000000 ____D C:\ProgramData\Avg
2015-09-19 00:16 - 2015-09-19 00:16 - 00000000 ____D C:\Users\Rifandi\AppData\Local\Avg2014
2015-09-18 14:24 - 2015-09-19 00:20 - 00000000 ____D C:\Program Files (x86)\AVG
2015-09-18 11:14 - 2015-09-18 11:14 - 00000258 _____ C:\Users\Rifandi\Documents\CorelDRAW Graphics Suite X5.txt
2015-09-18 11:07 - 2015-09-18 11:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CorelDRAW Graphics Suite X5
2015-09-18 10:59 - 2015-09-18 11:04 - 00000000 ____D C:\ProgramData\CorelDRAW Graphics Suite X7 x64
2015-09-18 08:57 - 2015-09-19 00:20 - 00000000 ____D C:\Users\Rifandi\AppData\Local\AvgSetupLog
2015-09-18 08:56 - 2015-09-18 08:56 - 00000000 ____D C:\Users\Rifandi\AppData\Local\Avg
2015-09-18 08:53 - 2015-09-18 08:57 - 00000000 ____D C:\ProgramData\Protexis
2015-09-18 08:53 - 2015-09-18 08:53 - 00000000 ____D C:\Users\Rifandi\AppData\Roaming\Corel
2015-09-18 08:50 - 2015-09-18 11:10 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 9.0
2015-09-18 08:49 - 2015-09-18 11:09 - 00000000 ____D C:\ProgramData\Corel
2015-09-18 08:45 - 2015-09-18 08:45 - 00000000 ____D C:\Program Files (x86)\Corel
2015-09-10 15:23 - 2015-09-10 15:23 - 01415680 _____ (wj32) C:\Program Files\ZNZUJ1KC.exe
2015-09-10 15:23 - 2015-09-10 15:23 - 01415680 _____ (wj32) C:\Program Files\YB8FRRCJ.exe
2015-09-10 15:23 - 2015-09-10 15:23 - 01415680 _____ (wj32) C:\Program Files\X1ZWBCHI.exe
2015-09-10 15:23 - 2015-09-10 15:23 - 01415680 _____ (wj32) C:\Program Files\W04V9Y20.exe
2015-09-10 15:23 - 2015-09-10 15:23 - 01415680 _____ (wj32) C:\Program Files\R5UVZL04.exe
2015-09-10 15:23 - 2015-09-10 15:23 - 01415680 _____ (wj32) C:\Program Files\ICJKVJ4B.exe
2015-09-10 15:23 - 2015-09-10 15:23 - 01415680 _____ (wj32) C:\Program Files\9GOV2WKR.exe
2015-09-10 15:23 - 2015-09-10 15:23 - 01415680 _____ (wj32) C:\Program Files\39Y7K2I0.exe
2015-09-10 15:23 - 2015-09-10 15:23 - 01415680 _____ (wj32) C:\Program Files\31XFGLPK.exe
2015-09-10 15:19 - 2015-09-10 15:19 - 01415680 _____ (wj32) C:\Program Files\AET6IA57.exe
2015-09-10 15:10 - 2015-03-02 18:22 - 202313264 _____ (Avast Software s.r.o.) C:\Users\Public\Desktop\avast_premier_antivirus_setup.exe
2015-09-10 15:05 - 2015-09-10 15:05 - 01415680 _____ (wj32) C:\Program Files\TUYNETRG.exe
2015-09-10 14:56 - 2015-09-10 14:57 - 00008278 _____ C:\Users\Rifandi\Documents\Uninstall Dragon Age Origins.log
2015-09-09 22:36 - 2015-09-09 22:36 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2015-09-09 22:21 - 2015-09-09 22:21 - 00001113 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Widget Browser.lnk
2015-09-09 22:21 - 2015-09-09 22:21 - 00000000 ____D C:\Program Files (x86)\My Company Name
2015-09-09 22:21 - 2011-11-03 03:01 - 00056208 ____N (Rovi Corporation) C:\Windows\system32\Drivers\PxHlpa64.sys
2015-09-09 22:21 - 2011-10-17 03:00 - 00010224 ____N (Sonic Solutions) C:\Windows\system32\Drivers\cdralw2k.sys
2015-09-09 22:21 - 2011-10-17 03:00 - 00010224 ____N (Sonic Solutions) C:\Windows\system32\Drivers\cdr4_xp.sys
2015-09-09 22:19 - 2015-09-09 22:19 - 00001013 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk
2015-09-09 22:19 - 2015-09-09 22:19 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
2015-09-09 22:19 - 2015-09-09 22:19 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
2015-09-09 22:15 - 2015-09-23 12:18 - 00000000 ____D C:\Program Files\Common Files\Adobe
2015-09-09 22:11 - 2015-09-23 12:19 - 00000000 ____D C:\ProgramData\Adobe
2015-09-09 22:11 - 2015-09-10 14:17 - 00000000 ____D C:\Users\Rifandi\AppData\Local\Adobe
2015-09-03 11:16 - 2015-09-03 11:16 - 01415680 _____ (wj32) C:\Program Files\O6YOYI62.exe
2015-09-03 11:16 - 2015-09-03 11:16 - 01415680 _____ (wj32) C:\Program Files\B3T3NBZJ.exe
2015-09-03 09:54 - 2015-09-03 09:54 - 01415680 _____ (wj32) C:\Program Files\J5PP7DXH.exe
2015-08-30 23:33 - 2015-08-30 23:33 - 01415680 _____ (wj32) C:\Program Files\9TAOZDU8.exe
2015-08-30 23:32 - 2015-08-30 23:32 - 01415680 _____ (wj32) C:\Program Files\2WKICE8A.exe
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-09-23 12:22 - 2013-12-31 12:58 - 00000434 _____ C:\Windows\system32\Drivers\etc\hosts.ics
2015-09-23 12:22 - 2013-12-20 11:58 - 01573589 _____ C:\Windows\WindowsUpdate.log
2015-09-23 12:21 - 2015-04-07 00:03 - 00000004 _____ C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-09-23 12:21 - 2015-04-06 23:03 - 00001302 _____ C:\Windows\Tasks\help4u_notification_service.job
2015-09-23 12:21 - 2015-04-06 23:03 - 00000664 _____ C:\Windows\Tasks\help4u_updating_service.job
2015-09-23 12:21 - 2013-12-20 20:53 - 00001024 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-09-23 12:20 - 2015-03-25 18:15 - 00065536 _____ C:\Windows\system32\Ikeext.etl
2015-09-23 12:20 - 2013-12-22 09:35 - 00000000 ____D C:\ProgramData\NVIDIA
2015-09-23 12:20 - 2013-08-22 22:36 - 00000000 ____D C:\Windows\tracing
2015-09-23 12:20 - 2013-08-22 21:45 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-09-23 12:20 - 2013-08-22 21:44 - 05385720 _____ C:\Windows\system32\FNTCACHE.DAT
2015-09-23 12:19 - 2013-12-22 10:05 - 00000000 ____D C:\Users\Rifandi\AppData\Roaming\DMCache
2015-09-23 12:19 - 2013-12-20 20:47 - 00003914 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{0217303C-CD5D-4BA1-8084-41BF826BC10F}
2015-09-23 12:19 - 2013-12-20 11:58 - 00000000 ____D C:\Users\Rifandi
2015-09-23 12:19 - 2013-09-30 11:02 - 01213520 _____ C:\Windows\PFRO.log
2015-09-23 12:19 - 2013-08-22 20:25 - 00262144 ___SH C:\Windows\system32\config\BBI
2015-09-23 12:18 - 2015-02-18 21:56 - 00000000 ____D C:\Program Files (x86)\Adobe
2015-09-23 12:17 - 2013-12-20 14:21 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1232603322-3645337139-1979953262-1001
2015-09-23 12:08 - 2014-01-26 11:53 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-09-23 12:07 - 2014-03-25 14:39 - 00000000 ____D C:\Program Files\Microsoft Office
2015-09-23 12:07 - 2013-09-30 10:54 - 00000000 ____D C:\Windows\ShellNew
2015-09-23 12:07 - 2013-08-22 22:36 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2015-09-23 12:05 - 2013-08-22 22:36 - 00000000 ____D C:\Program Files\Common Files\System
2015-09-23 12:05 - 2013-08-22 20:25 - 00000076 _____ C:\Windows\win.ini
2015-09-23 12:02 - 2013-08-22 22:36 - 00000000 ____D C:\Windows\system32\sru
2015-09-22 12:40 - 2013-12-20 20:53 - 00001028 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-09-22 12:04 - 2013-09-30 11:14 - 00005392 _____ C:\Windows\system32\PerfStringBackup.INI
2015-09-21 15:43 - 2013-12-20 11:59 - 00000000 ____D C:\Users\Rifandi\AppData\Local\Packages
2015-09-21 15:14 - 2013-08-22 21:46 - 00192765 _____ C:\Windows\setupact.log
2015-09-19 15:21 - 2013-12-20 20:53 - 00004000 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-09-19 15:21 - 2013-12-20 20:53 - 00003764 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-09-19 14:30 - 2013-08-22 22:36 - 00000000 ____D C:\Windows\AppReadiness
2015-09-19 03:24 - 2014-05-24 19:33 - 00000000 ____D C:\Users\Rifandi\AppData\Roaming\IDM
2015-09-19 01:44 - 2013-08-22 22:36 - 00000000 ____D C:\Windows\LiveKernelReports
2015-09-19 00:23 - 2013-12-22 12:26 - 00000000 ____D C:\ProgramData\AVAST Software
2015-09-19 00:23 - 2013-12-20 14:24 - 00000000 ____D C:\ProgramData\MFAData
2015-09-18 14:28 - 2013-08-22 22:36 - 00000000 ___HD C:\Windows\ELAMBKUP
2015-09-18 11:12 - 2014-01-27 23:24 - 00000000 ____D C:\ProgramData\CorelDRAW Graphics Suite X5
2015-09-18 08:50 - 2015-07-08 20:52 - 00000000 ____D C:\Program Files\Internet Download Manager
2015-09-13 23:38 - 2013-12-20 20:53 - 00000000 ____D C:\Users\Rifandi\AppData\Local\Google
2015-09-10 14:57 - 2014-11-17 16:32 - 00000000 ____D C:\ProgramData\BioWare
2015-09-10 14:54 - 2014-12-16 13:13 - 00000000 ____D C:\Program Files (x86)\Steam
2015-09-10 13:35 - 2013-12-20 11:59 - 00000000 ____D C:\Users\Rifandi\AppData\Roaming\Adobe
2015-09-01 19:51 - 2013-10-23 11:30 - 00000000 ____D C:\Users\Rifandi\Downloads\Wallpaper
2015-08-24 20:46 - 2014-09-27 14:54 - 00000000 ____D C:\Program Files (x86)\Origin
 
==================== Files in the root of some directories =======
 
2015-08-30 23:32 - 2015-08-30 23:32 - 1415680 _____ (wj32) C:\Program Files\2WKICE8A.exe
2015-09-10 15:23 - 2015-09-10 15:23 - 1415680 _____ (wj32) C:\Program Files\31XFGLPK.exe
2015-09-10 15:23 - 2015-09-10 15:23 - 1415680 _____ (wj32) C:\Program Files\39Y7K2I0.exe
2015-09-10 15:23 - 2015-09-10 15:23 - 1415680 _____ (wj32) C:\Program Files\9GOV2WKR.exe
2015-08-30 23:33 - 2015-08-30 23:33 - 1415680 _____ (wj32) C:\Program Files\9TAOZDU8.exe
2015-09-10 15:19 - 2015-09-10 15:19 - 1415680 _____ (wj32) C:\Program Files\AET6IA57.exe
2015-09-03 11:16 - 2015-09-03 11:16 - 1415680 _____ (wj32) C:\Program Files\B3T3NBZJ.exe
2015-06-27 04:47 - 2015-06-27 04:47 - 1415680 _____ (wj32) C:\Program Files\F7N7RDTD.exe
2015-09-19 18:59 - 2015-09-19 18:59 - 1415680 _____ (wj32) C:\Program Files\HTIAGJZW.exe
2015-09-10 15:23 - 2015-09-10 15:23 - 1415680 _____ (wj32) C:\Program Files\ICJKVJ4B.exe
2015-06-28 14:44 - 2015-06-28 14:44 - 1415680 _____ (wj32) C:\Program Files\IRJS8N3R.exe
2015-09-03 09:54 - 2015-09-03 09:54 - 1415680 _____ (wj32) C:\Program Files\J5PP7DXH.exe
2015-09-21 13:58 - 2015-09-21 13:58 - 1415680 _____ (wj32) C:\Program Files\MNOHIJGH.exe
2015-09-03 11:16 - 2015-09-03 11:16 - 1415680 _____ (wj32) C:\Program Files\O6YOYI62.exe
2015-09-10 15:23 - 2015-09-10 15:23 - 1415680 _____ (wj32) C:\Program Files\R5UVZL04.exe
2015-09-10 15:05 - 2015-09-10 15:05 - 1415680 _____ (wj32) C:\Program Files\TUYNETRG.exe
2015-09-10 15:23 - 2015-09-10 15:23 - 1415680 _____ (wj32) C:\Program Files\W04V9Y20.exe
2015-09-10 15:23 - 2015-09-10 15:23 - 1415680 _____ (wj32) C:\Program Files\X1ZWBCHI.exe
2015-09-10 15:23 - 2015-09-10 15:23 - 1415680 _____ (wj32) C:\Program Files\YB8FRRCJ.exe
2015-07-22 13:25 - 2015-07-22 13:25 - 1415680 _____ (wj32) C:\Program Files\YIWGU8PH.exe
2015-09-10 15:23 - 2015-09-10 15:23 - 1415680 _____ (wj32) C:\Program Files\ZNZUJ1KC.exe
2013-12-20 12:04 - 2014-10-22 23:47 - 0007605 _____ () C:\Users\Rifandi\AppData\Local\Resmon.ResmonCfg
2014-11-18 16:11 - 2014-11-18 16:11 - 0000000 _____ () C:\Users\Rifandi\AppData\Local\{28B07EFD-C22E-4EAF-BB9A-886224995B4E}
2014-11-22 20:25 - 2014-11-22 20:25 - 0000000 _____ () C:\Users\Rifandi\AppData\Local\{918915E7-62D3-4955-BD85-3C711153C0F0}
2014-11-21 17:59 - 2014-11-21 17:59 - 0000000 _____ () C:\Users\Rifandi\AppData\Local\{DE111176-0A34-4308-8E0C-5FC04B4A97A7}
2013-12-22 10:35 - 2013-12-22 10:35 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2013-08-22 10:56 - 2013-08-22 10:56 - 68792320 ___SH () C:\ProgramData\msctqoijn.exe
 
Files to move or delete:
====================
C:\ProgramData\msctqoijn.exe
 
 
Some files in TEMP:
====================
C:\Users\Rifandi\AppData\Local\Temp\15403.exe
C:\Users\Rifandi\AppData\Local\Temp\26349.exe
C:\Users\Rifandi\AppData\Local\Temp\9w0z7hhv.dll
C:\Users\Rifandi\AppData\Local\Temp\AutoRun.exe
C:\Users\Rifandi\AppData\Local\Temp\AutoRunGUI.dll
C:\Users\Rifandi\AppData\Local\Temp\avg-0d57d41c-69a9-4d1f-ad46-a451f87f8704.exe
C:\Users\Rifandi\AppData\Local\Temp\avg-437f951d-ef0d-4914-8bd2-a57dbd1c2d51.exe
C:\Users\Rifandi\AppData\Local\Temp\avg-f26c3a2b-1a46-4946-91e2-dc349aa1d27b.exe
C:\Users\Rifandi\AppData\Local\Temp\AVGTBInstall.exe
C:\Users\Rifandi\AppData\Local\Temp\bassmod.dll
C:\Users\Rifandi\AppData\Local\Temp\cdo1012559675.dll
C:\Users\Rifandi\AppData\Local\Temp\cdo1884421863.dll
C:\Users\Rifandi\AppData\Local\Temp\cdo1947574289.dll
C:\Users\Rifandi\AppData\Local\Temp\cdo2320784150.dll
C:\Users\Rifandi\AppData\Local\Temp\cdo279897222.dll
C:\Users\Rifandi\AppData\Local\Temp\cdo2965365908.dll
C:\Users\Rifandi\AppData\Local\Temp\cdo3081841414.dll
C:\Users\Rifandi\AppData\Local\Temp\cdo3085677782.dll
C:\Users\Rifandi\AppData\Local\Temp\cdo3203406440.dll
C:\Users\Rifandi\AppData\Local\Temp\cdo3261657765.dll
C:\Users\Rifandi\AppData\Local\Temp\cdo3348599862.dll
C:\Users\Rifandi\AppData\Local\Temp\cdo483604587.dll
C:\Users\Rifandi\AppData\Local\Temp\cdo653551628.dll
C:\Users\Rifandi\AppData\Local\Temp\cdo740167257.dll
C:\Users\Rifandi\AppData\Local\Temp\down.5564.OptimizerProInstaller.exe
C:\Users\Rifandi\AppData\Local\Temp\drm_dialogs.dll
C:\Users\Rifandi\AppData\Local\Temp\drm_dyndata_7360010.dll
C:\Users\Rifandi\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpwrxywa.dll
C:\Users\Rifandi\AppData\Local\Temp\EAInstall.dll
C:\Users\Rifandi\AppData\Local\Temp\eauninstall.exe
C:\Users\Rifandi\AppData\Local\Temp\FreeAvastLicenseFile2015__11652_il77739.exe
C:\Users\Rifandi\AppData\Local\Temp\jre-8u40-windows-au.exe
C:\Users\Rifandi\AppData\Local\Temp\KB157937515.exe
C:\Users\Rifandi\AppData\Local\Temp\MySearchDial.exe
C:\Users\Rifandi\AppData\Local\Temp\nv3DVStreaming.dll
C:\Users\Rifandi\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\Rifandi\AppData\Local\Temp\nvStereoApiI.dll
C:\Users\Rifandi\AppData\Local\Temp\nvStInst.exe
C:\Users\Rifandi\AppData\Local\Temp\oi_{E3BDEA52-C4B7-4ABC-A0C4-19DE141CBCF7}.exe
C:\Users\Rifandi\AppData\Local\Temp\onlysetup.exe
C:\Users\Rifandi\AppData\Local\Temp\ose00000.exe
C:\Users\Rifandi\AppData\Local\Temp\ose00002.exe
C:\Users\Rifandi\AppData\Local\Temp\res.dll
C:\Users\Rifandi\AppData\Local\Temp\sqlite-3.7.151-amd64-sqlitejdbc.dll
C:\Users\Rifandi\AppData\Local\Temp\TELKOMSELFlash SU-9000 Install.exe
C:\Users\Rifandi\AppData\Local\Temp\The Sims 2 Double Deluxe_uninst.exe
C:\Users\Rifandi\AppData\Local\Temp\TsuF605ED4F.dll
C:\Users\Rifandi\AppData\Local\Temp\utt40F4.tmp.exe
C:\Users\Rifandi\AppData\Local\Temp\VP6Install.exe
C:\Users\Rifandi\AppData\Local\Temp\VP6VFW.dll
C:\Users\Rifandi\AppData\Local\Temp\xmlUpdater.exe
C:\Users\Rifandi\AppData\Local\Temp\[OOP]Arfan_131402021_04.exe
C:\Users\Rifandi\AppData\Local\Temp\_isA208.exe
C:\Users\Rifandi\AppData\Local\Temp\{6DCC0AC0-6630-4153-B6D9-371220D47689}-32.0.1700.107_32.0.1700.102_chrome_updater.exe
 
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-09-12 14:00
 
==================== End of FRST.txt ============================
 
 
 
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version:15-09-2015
Ran by Rifandi (2015-09-23 12:24:32)
Running from C:\Users\Rifandi\Desktop
Windows 8.1 Pro (X64) (2013-12-20 04:58:43)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-1232603322-3645337139-1979953262-500 - Administrator - Disabled)
Guest (S-1-5-21-1232603322-3645337139-1979953262-501 - Limited - Disabled)
Rifandi (S-1-5-21-1232603322-3645337139-1979953262-1001 - Administrator - Enabled) => C:\Users\Rifandi
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
µTorrent (HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\uTorrent) (Version: 3.4.2.35702 - BitTorrent Inc.)
7-Zip 9.22beta (HKLM-x32\...\7-Zip) (Version:  - )
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.1.0.4880 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.134 - Adobe Systems Incorporated)
Adobe Help Manager (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 4.0.244 - Adobe Systems Incorporated)
Adobe Widget Browser (HKLM-x32\...\com.adobe.WidgetBrowser) (Version: 2.0 Build 348 - Adobe Systems Incorporated.)
Ambulant Player 2.4 (HKLM-x32\...\Ambulant Player 2.4) (Version: 2.4 - Centrum voor Wiskunde en Informatica)
Apache Tomcat 8.0.15 (HKLM-x32\...\nbi-tomcat-8.0.15.0.0) (Version:  - )
Apple Application Support (HKLM-x32\...\{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}) (Version: 2.3.4 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Artificial Girl 3 (HKLM-x32\...\{9F0B447F-7E14-4BB9-BCFE-1D5C06F7EE35}) (Version: 1.5 - ILLUSION)
Battlefield 4 Update 1 (HKLM-x32\...\QmF0dGxlZmllbGQ0_is1) (Version: 1 - )
bl (x32 Version: 1.0.0 - Your Company Name) Hidden
Blend for Visual Studio 2012 (x32 Version: 5.0.30709.0 - Microsoft Corporation) Hidden
Blend for Visual Studio 2012 ENU resources (x32 Version: 5.0.30709.0 - Microsoft Corporation) Hidden
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Cheat Engine 6.4 (HKLM-x32\...\Cheat Engine 6.4_is1) (Version:  - Cheat Engine)
Cisco Packet Tracer 5.3.3 (HKLM-x32\...\Cisco Packet Tracer 5.3.3_is1) (Version:  - Cisco Systems, Inc.)
CodeBlocks (HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\CodeBlocks) (Version: 12.11 - The Code::Blocks Team)
Corel Graphics - Windows Shell Extension (HKLM-x32\...\_{B6BFCD02-BA0E-41A9-9C9C-6624C4BB475F}) (Version: 15.2.0.686 - Corel Corporation)
Corel Graphics - Windows Shell Extension (x32 Version: 15.2.686 - Corel Corporation) Hidden
Corel Graphics - Windows Shell Extension 64 Bit (Version: 15.2.686 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Capture (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Common (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Connect (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Custom Data (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Draw (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - EN (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Filters (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - FontNav (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - IPM (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - PHOTO-PAINT (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Photozoom Plugin (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Redist (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Setup Files (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - VBA (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - VideoBrowser (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - VSTA (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - WT (x32 Version: 15.3 -  Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW® Graphics Suite X5 (HKLM-x32\...\_{CE54DCE1-E00A-4D91-ACB9-A2D916C24051}) (Version: 15.2.0.686 - Corel Corporation)
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.48.1.0347 - Disc Soft Ltd)
Devil May Cry 5 - Complete Edition version 1.0.0 (HKLM-x32\...\Devil May Cry 5 - Complete Edition_is1) (Version: 1.0.0 - Capcom)
Dolby Digital Plus Home Theater (HKLM\...\{7E3D8FA1-6092-469A-955B-68FC4A2C67CA}) (Version: 7.3.2.2 - Dolby Laboratories Inc)
Dolphin 4.0 (HKLM-x32\...\Dolphin) (Version: 4.0 - Dolphin Development Team)
Dota 2 (HKLM-x32\...\Steam App 570) (Version:  - Valve)
Dotfuscator and Analytics Community Edition (x32 Version: 5.5.4521.29298 - PreEmptive Solutions) Hidden
Dragonball Xenoverse (HKLM-x32\...\Dragonball Xenoverse_is1) (Version:  - )
DreadOut (HKLM-x32\...\DreadOut_is1) (Version:  - )
Dropbox (HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\Dropbox) (Version: 2.6.24 - Dropbox, Inc.)
Empire Earth III (HKLM-x32\...\{B17E235C-7A3B-4482-B650-21FFDE1D452E}) (Version: 1.00.0000 - Sierra Entertainment)
Energy Management (HKLM-x32\...\InstallShield_{D0956C11-0F60-43FE-99AD-524E833471BB}) (Version: 8.0.2.14 - Lenovo)
Energy Management (x32 Version: 8.0.2.14 - Lenovo) Hidden
Entity Framework Designer for Visual Studio 2012 - enu (HKLM-x32\...\{0A1A1D48-DB23-443A-BC7B-49255D138020}) (Version: 11.1.20702.00 - Microsoft Corporation)
GlassFish Server Open Source Edition 4.1 (HKLM-x32\...\nbi-glassfish-mod-4.1.0.13.0) (Version:  - )
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 45.0.2454.99 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.28.15 - Google Inc.) Hidden
GReaatsaver (HKLM-x32\...\{CA41BB14-E67B-1653-C57B-5CA99418A866}) (Version: 4.3.0.1718 - gureATsuavear) <==== ATTENTION
HSPA Modem version 1.5 (HKLM-x32\...\3G Connect Normal Version 6280 USB_is1) (Version:  - )
IIS 8.0 Express (HKLM\...\{7BF61FA9-BDFB-4563-98AD-FCB0DA28CCC7}) (Version: 8.0.1557 - Microsoft Corporation)
IIS Express Application Compatibility Database for x64 (HKLM\...\{9f4f4a9b-eec5-4906-92fe-d1f43ccf5c8d}.sdb) (Version:  - )
IIS Express Application Compatibility Database for x86 (HKLM\...\{fdfba1f3-74ae-4255-9c10-a0f552b4610f}.sdb) (Version:  - )
ILLUSION ワケあり! (HKLM-x32\...\{FD1E17BC-2956-4AD7-B937-D23F06F1A5E8}) (Version: 1.00.0000 - ILLUSION)
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.13.1706 - Intel Corporation)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3277 - Intel Corporation)
Intel® PROSet/Wireless Software for Bluetooth® Technology (HKLM\...\{DA2600C1-6BDF-4FD1-8F3D-148929CC1385}) (Version: 2.6.1210.0278 - Intel Corporation)
Internet Download Manager (HKLM-x32\...\Internet Download Manager) (Version:  - Tonec Inc.)
Java 8 Update 45 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418045F0}) (Version: 8.0.450 - Oracle Corporation)
Java SE Development Kit 8 Update 45 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0180450}) (Version: 8.0.450.15 - Oracle Corporation)
Join Air (HKLM-x32\...\{A9E5EDA7-2E6C-49E7-924B-A32B89C24A04}) (Version: 1.0.0.2 - ZTE)
Just Cause 2 (HKLM-x32\...\Just Cause 2_is1) (Version:  - R.G.Âèíòèê è Øïóíòèê)
KMSnano 24 (HKLM\...\KMSnano 24_is1) (Version: KMSnano 24 - )
KMSpico v9.0.6.20131120 (HKLM\...\KMSpico_is1) (Version: 9.0.6.20131120 - )
LocalESPC (x32 Version: 8.59.25584 - Microsoft Corporation) Hidden
LocalESPCui for en-us (x32 Version: 8.59.25584 - Microsoft) Hidden
Macromedia Dreamweaver 8 (HKLM-x32\...\{0837A661-FEC3-48B3-876C-91E7D32048A9}) (Version: 8.0.0.2734 - Macromedia)
Macromedia Extension Manager (HKLM-x32\...\{5546CDB5-2CE2-498B-B059-5B3BF81FC41F}) (Version: 1.7.240 - Macromedia, Inc.)
Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\...\{5CBFF3F3-2D40-34EE-BCA5-A95BC19E400D}) (Version: 4.5.50709 - Microsoft Corporation)
Microsoft .NET Framework 4.5 SDK (HKLM-x32\...\{1948E039-EC79-4591-951D-9867A8C14C90}) (Version: 4.5.50709 - Microsoft Corporation)
Microsoft ASP.NET MVC 3 (HKLM-x32\...\{DCDEC776-BADD-48B9-8F9A-DFF513C3D7FA}) (Version: 3.0.20105.0 - Microsoft Corporation)
Microsoft ASP.NET Web Pages (HKLM-x32\...\{631471BE-DEAB-454B-A9AC-CE3EB42C28B3}) (Version: 1.0.20105.0 - Microsoft Corporation)
Microsoft Help Viewer 2.0 (HKLM-x32\...\Microsoft Help Viewer 2.0) (Version: 2.0.50727 - Microsoft Corporation)
Microsoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.10411.0 - Microsoft Corporation)
Microsoft Silverlight 4 SDK (HKLM-x32\...\{189AEA94-DAFB-487A-8CEE-F9D3DDE0A748}) (Version: 4.0.60310.0 - Microsoft Corporation)
Microsoft Silverlight 5 SDK (HKLM-x32\...\{E1FBB3D4-ADB0-4949-B101-855DA061C735}) (Version: 5.0.61118.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Command Line Utilities  (HKLM\...\{9D573E71-1077-4C7E-B4DB-4E22A5D2B48B}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 Data-Tier App Framework  (HKLM\...\{36E619BC-A234-4EC3-849B-779A7C865A45}) (Version: 11.0.2316.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Data-Tier App Framework  (HKLM-x32\...\{FBA6F90E-36EC-4FC9-9B25-3834E3BD46A8}) (Version: 11.0.2316.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Express LocalDB  (HKLM\...\{13D558FE-A863-402C-B115-160007277033}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 Management Objects  (HKLM-x32\...\{DA1C1761-5F4F-4332-AB9D-29EDF3F8EA0A}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 Management Objects  (x64) (HKLM\...\{FA0A244E-F3C2-4589-B42A-3D522DE79A42}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 Native Client  (HKLM\...\{49D665A2-4C2A-476E-9AB8-FCC425F526FC}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 Transact-SQL Compiler Service  (HKLM\...\{BEB0F91E-F2EA-48A1-B938-7857ABF2A93D}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 Transact-SQL ScriptDom  (HKLM\...\{0E8670B8-3965-4930-ADA6-570348B67153}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 T-SQL Language Service  (HKLM-x32\...\{6D6D43E5-218C-4B05-92D3-2240810F4760}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server Compact 4.0 SP1 x64 ENU (HKLM\...\{78909610-D229-459C-A936-25D92283D3FD}) (Version: 4.0.8876.1 - Microsoft Corporation)
Microsoft SQL Server Data Tools - enu (11.1.20627.00) (HKLM-x32\...\{FA804794-2CCB-4301-954F-2C2894698876}) (Version: 11.1.20627.00 - Microsoft Corporation)
Microsoft SQL Server Data Tools Build Utilities - enu (11.1.20627.00) (HKLM-x32\...\{790E9425-8570-493F-9AE7-81AFC9E46930}) (Version: 11.1.20627.00 - Microsoft Corporation)
Microsoft SQL Server System CLR Types (HKLM-x32\...\{A47FD1BF-A815-4A76-BE65-53A15BD5D25D}) (Version: 10.50.1600.1 - Microsoft Corporation)
Microsoft SQL Server System CLR Types (x64) (HKLM\...\{4701DEDE-1888-49E0-BAE5-857875924CA2}) (Version: 10.50.1600.1 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2012 (HKLM-x32\...\{E2082604-4BA5-44BB-BBFB-AF0F3CB8C6AB}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2012 (x64) (HKLM\...\{F1949145-EB64-4DE7-9D81-E6D27937146C}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 Redistributable - x64 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 Redistributable - x86 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.31125 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2.0 - ENU (HKLM-x32\...\{AA4A4B2C-0465-3CF8-BA76-27A027D8ACAB}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2.0 Runtime (HKLM-x32\...\{299C0434-4F4E-341F-A916-4E07AEB35E79}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual Studio Ultimate 2012 (HKLM-x32\...\{ae17ae9b-af38-40d2-a194-6102c56ed502}) (Version: 11.0.50727.26 - Microsoft Corporation)
Microsoft Web Deploy 3.0 (HKLM\...\{AA72C306-30BE-4BB1-9E42-59552BAD2CDF}) (Version: 3.1236.1631 - Microsoft Corporation)
Microsoft Web Deploy dbSqlPackage Provider - enu (HKLM-x32\...\{E4C33F5B-1B2F-466E-957E-B274F08151A0}) (Version: 10.3.20225.0 - Microsoft Corporation)
Microsoft Web Platform Installer 4.0 (HKLM\...\{E2B8249D-895C-4685-8C83-00F3B1A13028}) (Version: 4.0.1622 - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
Middle-Earth - Shadow of Mordor (by Hommy Games) (HKLM-x32\...\{3E74CDB4-8B8F-4640-BE71-4B66886615F7}_is1) (Version: 1.0.1636.20 - )
Mozilla Firefox 36.0.4 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 36.0.4 (x86 en-US)) (Version: 36.0.4 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
MPC-HC 1.7.1 (64-bit) (HKLM\...\{2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1) (Version: 1.7.1.0 - MPC-HC Team)
Need for Speed™ Carbon (HKLM-x32\...\{259C0ABB-A3B2-4D70-008F-BF7EE491B70B}) (Version:  - )
NetBeans IDE 8.0.2 (HKLM-x32\...\nbi-nb-base-8.0.2.0.201411181905) (Version: 8.0.2 - NetBeans.org)
Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.47.3 - Black Tree Gaming)
Notepad++ (HKLM-x32\...\Notepad++) (Version: 5.9.6.2 - )
NVIDIA 3D Vision Driver 337.88 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 337.88 - NVIDIA Corporation)
NVIDIA GeForce Experience 2.1.5 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.1.5 - NVIDIA Corporation)
NVIDIA Graphics Driver 337.88 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 337.88 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation)
Oracle VM VirtualBox 4.3.16 (HKLM\...\{D7FAEA32-7CE3-4D9F-9139-F7B87BCC50AF}) (Version: 4.3.16 - Oracle Corporation)
Origin (HKLM-x32\...\Origin) (Version: 9.4.1.116 - Electronic Arts, Inc.)
PCSX2 - Playstation 2 Emulator (HKLM-x32\...\pcsx2-r5875) (Version:  - )
ph (x32 Version: 1.0.0 - Your Company Name) Hidden
PreEmptive Analytics Visual Studio Components (x32 Version: 1.0.2180.1 - PreEmptive Solutions) Hidden
Prerequisites for SSDT  (HKLM-x32\...\{9169C939-ED01-446A-BD0C-29873BAF4E48}) (Version: 11.0.2100.60 - Microsoft Corporation)
Pro Evolution Soccer 2015 (HKLM-x32\...\UHJvRXZvbHV0aW9uU29jY2VyMjAxNQ==_is1) (Version: 1 - )
Prototype 2 (HKLM-x32\...\Prototype 2_is1) (Version: Prototype 2 - )
Qualcomm Atheros Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 10.0 - Qualcomm Atheros)
QuickTime (HKLM-x32\...\{B67BAFBA-4C9F-48FA-9496-933E3B255044}) (Version: 7.74.80.86 - Apple Inc.)
Rainmeter (HKLM-x32\...\Rainmeter) (Version: 3.1 r2290 - )
RapeLay (remove only) (HKLM-x32\...\RapeLay) (Version:  - )
RAR Password Recovery v1.1 RC16 (remove only) (HKLM-x32\...\Intelore - RAR Password Recovery) (Version:  - )
RAR Password Unlocker 4.2.0.0 (HKLM-x32\...\{B789FA51-6A71-408F-92DE-EDE4A517B8F9}_is1) (Version:  - Password Unlocker Studio)
Razer Game Booster (HKLM-x32\...\Razer Game Booster_is1) (Version: 4.1.59.0 - Razer Inc.)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9200.39048 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.2.612.2012 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7027 - Realtek Semiconductor Corp.)
Safari (HKLM-x32\...\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.)
SavePass 1.1 (HKLM-x32\...\SavePass 1.1) (Version: 1.35.3.9 - OB) <==== ATTENTION
School Mate 2 (HKLM-x32\...\{BC980840-FC67-4027-9055-251136406614}_is1) (Version: 1.3 - randompirate)
Sexy Beach 3 - Complete English Edition (remove only) (HKLM-x32\...\Sexy Beach 3 - Complete English Edition) (Version:  - )
SHIELD Streaming (Version: 3.1.3000 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 16.18.9 - NVIDIA Corporation) Hidden
SPORE™ (HKLM-x32\...\{9DF0196F-B6B8-4C3A-8790-DE42AA530101}) (Version: 1.00.0000 - Electronic Arts)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Stronghold Crusader 2 (HKLM-x32\...\Stronghold Crusader 2_is1) (Version: 1.0 - PLAZA)
System Requirements Lab Detection (HKLM-x32\...\{2C9D426D-3F38-4B1A-BAC5-DEC1212BB852}) (Version: 2.2.4.0 - Husdawg, LLC)
TAP-Windows 9.9.2 (HKLM\...\TAP-Windows) (Version: 9.9.2 - )
TELKOMSELFlash SU-9000 version 5.117 (HKLM-x32\...\TELKOMSELFlash SU-9000 version_is1) (Version:  - )
The Sims" 3 (HKLM-x32\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.63.5 - Electronic Arts)
The Sims" 3 70s, 80s, & 90s Stuff (HKLM-x32\...\{E1868CAE-E3B9-4099-8C18-AA8944D336FD}) (Version: 17.0.77 - Electronic Arts)
The Sims" 3 Ambitions (HKLM-x32\...\{910F4A29-1134-49E0-AD8B-56E4A3152BD1}) (Version: 4.0.87 - Electronic Arts)
The Sims" 3 Diesel Stuff (HKLM-x32\...\{1C9B6173-6DC9-4EEE-9EFC-6BA115CFBE43}) (Version: 14.0.48 - Electronic Arts)
The Sims" 3 Fast Lane Stuff (HKLM-x32\...\{ED436EA8-4145-4703-AE5D-4D09DD24AF5A}) (Version: 5.0.44 - Electronic Arts)
The Sims" 3 Generations (HKLM-x32\...\{E6B88BD6-E4B2-4701-A648-B6DAC6E491CC}) (Version: 8.0.152 - Electronic Arts)
The Sims" 3 High-End Loft Stuff (HKLM-x32\...\{71828142-5A24-4BD0-97E7-976DA08CE6CF}) (Version: 3.0.38 - Electronic Arts)
The Sims" 3 Into the Future (HKLM-x32\...\{A0BBD6C7-B546-4048-B33A-F21F5C9F5B09}) (Version: 21.0.150 - Electronic Arts)
The Sims" 3 Island Paradise (HKLM-x32\...\{DB21639E-FE55-432C-BCA2-0C5249E3F79E}) (Version: 19.0.101 - Electronic Arts)
The Sims" 3 Katy Perry's Sweet Treats (HKLM-x32\...\{9B2506E3-9A3F-45B5-96BF-509CAD584650}) (Version: 13.0.62 - Electronic Arts)
The Sims" 3 Late Night (HKLM-x32\...\{45057FCE-5784-48BE-8176-D9D00AF56C3C}) (Version: 6.0.81 - Electronic Arts)
The Sims" 3 Master Suite Stuff (HKLM-x32\...\{08A25478-C5DD-4EA7-B168-3D687CA987FF}) (Version: 11.0.84 - Electronic Arts)
The Sims" 3 Movie Stuff (HKLM-x32\...\{D0087539-3C57-44E0-BEE7-D779D546CBE1}) (Version: 20.0.53 - Electronic Arts)
The Sims" 3 Outdoor Living Stuff (HKLM-x32\...\{117B6BF6-82C3-420C-B284-9247C8568E53}) (Version: 7.0.55 - Electronic Arts)
The Sims" 3 Pets (HKLM-x32\...\{C12631C6-804D-4B32-B0DD-8A496462F106}) (Version: 10.0.96 - Electronic Arts)
The Sims" 3 Seasons (HKLM-x32\...\{3DE92282-CB49-434F-81BF-94E5B380E889}) (Version: 16.0.136 - Electronic Arts)
The Sims" 3 Showtime (HKLM-x32\...\{3BBFD444-5FAB-49F6-98B1-A1954E831399}) (Version: 12.0.273 - Electronic Arts)
The Sims" 3 Supernatural (HKLM-x32\...\{B37DAFA5-717D-41F8-BDFB-3A4B68C0B3A1}) (Version: 15.0.135 - Electronic Arts)
The Sims" 3 Town Life Stuff (HKLM-x32\...\{7B11296A-F894-449C-8DF6-6AAAA7D4D118}) (Version: 9.0.73 - Electronic Arts)
The Sims" 3 University Life (HKLM-x32\...\{F26DE8EF-F2CF-40DC-8CDA-CC0D82D11B36}) (Version: 18.0.126 - Electronic Arts)
The Sims" 3 World Adventures (HKLM-x32\...\{BA26FFA5-6D47-47DB-BE56-34C357B5F8CC}) (Version: 2.0.86 - Electronic Arts)
The Sims™ 3 + Expansions Uninstaller (HKLM-x32\...\The Sims™ 3 + Expansions Uninstaller) (Version: 1.0.0.11 - Electronic Arts)
Total Video Converter 3.71 100812 (HKLM-x32\...\Total Video Converter 3.71_is1) (Version:  - EffectMatrix Inc.)
TSEV Skyrim LE (HKLM-x32\...\TSEV Skyrim LE_is1) (Version: 2.0.0.0 - )
UltraISO Premium V9.62 (HKLM-x32\...\UltraISO_is1) (Version:  - )
Unity Web Player (HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\UnityWebPlayer) (Version:  - Unity Technologies ApS)
Update for  (KB2504637) (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
Watch Dogs (HKLM-x32\...\Watch Dogs_R.G. Mechanics_is1) (Version:  - R.G. Mechanics, spider91)
WCF Data Services 5.0 (for OData v3) Primary Components (x32 Version: 5.0.50628.0 - Microsoft Corporation) Hidden
WCF Data Services Tools for Microsoft Visual Studio 2012 (x32 Version: 5.0.50710.0 - Microsoft Corporation) Hidden
WCF RIA Services V1.0 SP2 (HKLM-x32\...\{3A523AF9-D32F-4C85-8388-0335731F3405}) (Version: 4.1.61829.0 - Microsoft Corporation)
Winamp (HKLM-x32\...\Winamp) (Version: 5.666  - Nullsoft, Inc)
Winamp Detector Plug-in (HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc)
Windows 7 USB/DVD Download Tool (HKLM-x32\...\{CCF298AF-9CE1-4B26-B251-486E98A34789}) (Version: 1.0.30 - Microsoft Corporation)
Windows Driver Package - Lenovo (ACPIVPC) System  (02/17/2013 9.52.0.776) (HKLM\...\35DD26BE48DAF4A9F35F969F3CB1E3E1435E661E) (Version: 02/17/2013 9.52.0.776 - Lenovo)
Windows Driver Package - Lenovo (WUDFRd) LenovoVhid  (07/25/2013 10.30.0.288) (HKLM\...\6BCA401E9CBEED970D75F55FA5320F60D11984E9) (Version: 07/25/2013 10.30.0.288 - Lenovo)
WinRAR 5.00 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.00.0 - win.rar GmbH)
WOW Slider (HKLM-x32\...\WOW Slider_is1) (Version:  - )
XAMPP (HKLM-x32\...\xampp) (Version: 1.8.3-2 - BitNami)
YoutubeAdblocker (HKLM-x32\...\{4820778D-AB0D-6D18-C316-52A6A0E1D507}) (Version: 4.2.0.1591 - YoutubeAdblocker) <==== ATTENTION
YoutubeAdblocker (HKLM-x32\...\{CF830981-8F31-C561-C7A0-FE2CE1878B40}) (Version: 4.2.0.1447 - YoutubeAdblocker) <==== ATTENTION
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-1232603322-3645337139-1979953262-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Rifandi\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1232603322-3645337139-1979953262-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Rifandi\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1232603322-3645337139-1979953262-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Rifandi\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1232603322-3645337139-1979953262-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Rifandi\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1232603322-3645337139-1979953262-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Rifandi\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
 
==================== Restore Points =========================
 
ATTENTION: System Restore is disabled
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2013-08-22 20:25 - 2013-08-22 20:25 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {2AAB2F86-2217-46D4-8004-88F4A8F9C72E} - System32\Tasks\help4u_notification_service => C:\Program Files (x86)\help4u\help4u_notification_service.exe [2015-04-06] (FileProperties_CompanyName) <==== ATTENTION
Task: {3A8AF67F-D4A2-4830-93C5-666CBB8285DE} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {3B5AD782-9EA1-448B-BCC2-9383C65F05A3} - System32\Tasks\{6BA0FAB1-B899-472D-AFB0-B490EA3BD58D} => pcalua.exe -a "G:\Cai Dat Game\setup.exe" -d "G:\Cai Dat Game"
Task: {3E9BB584-BAB7-4855-AC19-11D577E342ED} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.)
Task: {41A93C16-4B1F-449F-9AD6-AEECC8A9FBE7} - System32\Tasks\{CBE073F7-A1DD-4027-B793-2EE54ADF6B0C} => pcalua.exe -a F:\Sims2EP1\eauninstall.exe -d F:\Sims2EP1
Task: {81DCD15E-230D-458D-9943-3D597965D212} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.)
Task: {96B7DC84-1C5F-4AC1-8EF8-D697CE121B1A} - System32\Tasks\{8627B382-5A88-4FF9-A728-51F1974DF348} => pcalua.exe -a F:\AutoRun.exe -d F:\
Task: {A1EEE3CA-8222-464D-BD7C-0E48D2C118DF} - System32\Tasks\help4u_updating_service => C:\Program Files (x86)\help4u\help4u_updating_service.exe [2015-04-06] () <==== ATTENTION
Task: {AC9DE117-FBDF-48AC-ACE6-122B0835D672} - System32\Tasks\AutoPico Daily Restart => C:\Program Files\KMSpico\AutoPico.exe [2013-11-20] ()
Task: {C5EA213E-BFBF-436F-B6B2-DF62BD727E8A} - System32\Tasks\EPUpdater => C:\Users\Rifandi\AppData\Roaming\BabSolution\Shared\BabMaint.exe [2013-12-12] () <==== ATTENTION
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\64b5c250-015d-48b5-b157-300a8e3bfe82.job => C:\Program Files (x86)\SavePass 1.1\64b5c250-015d-48b5-b157-300a8e3bfe82.exe <==== ATTENTION
Task: C:\Windows\Tasks\c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-1.job => C:\Program Files (x86)\SavePass 1.1\SavePass 1.1-codedownloader.exe <==== ATTENTION
Task: C:\Windows\Tasks\c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-11.job => C:\Program Files (x86)\SavePass 1.1\c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-11.exe <==== ATTENTION
Task: C:\Windows\Tasks\c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.job => C:\Program Files (x86)\SavePass 1.1\c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe <==== ATTENTION
Task: C:\Windows\Tasks\c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-5.job => C:\Program Files (x86)\SavePass 1.1\c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-5.exe <==== ATTENTION
Task: C:\Windows\Tasks\c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-5_user.job => C:\Program Files (x86)\SavePass 1.1\c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-5.exe <==== ATTENTION
Task: C:\Windows\Tasks\c6f17427-280e-44d4-88bc-561c1fe0d308.job => C:\Program Files (x86)\SavePass 1.1\c6f17427-280e-44d4-88bc-561c1fe0d308.exeȘ/agentregpath='SavePass 1.1' /appid=63429 /srcid='001504' /subid='0' /zdata='0' /bic=2827820446154BECB360AC217BBD185EIE /verifier=a2bd8b9c017cd558c9844388bde7f117 /installerversion=1_35_09_03 /installationtime=1410537375 /statsdomain=http:/stats.newclientgenservice.com /errorsdomain=http:/errors.newclientgenservice.com /extensionname='Information' /torpedoiesleeps=1000 /torpedoieplugins=93-0,102-0,104-0,178-288,179-288,180-288,223-288,263-24 /monetizationdomain=http:/logs.newclientgenservice.com <==== ATTENTION
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\help4u_notification_service.job => C:\Program Files (x86)\help4u\help4u_notification_service.exeǢ/url='http:/cdn.selectbestopt.com/notf_sys/index.html' /crregname='help4u' /appid='73143' /srcid='2913' /bic='3c4f7bfbe922fc9e30d0f7a9a7b1bbad' /verifier='1d6ae977715d5d15586c376a4be34ff3' /installerversion='1.50.3.10' /statsdomain='http:/stats.buildomserv.com/data.gif?' /errorsdomain='http:/stats.buildomserv.com/data.gif?' /monetizationdomain='http:/logs.buildomserv.com/monetization.gif <==== ATTENTION
Task: C:\Windows\Tasks\help4u_updating_service.job => C:\Program Files (x86)\help4u\help4u_updating_service.exe§ /campid=2913 /verid=1 /url=http:/cdn.buildomserv.com/txt/@CAMPID@/@VER@/file.txt /appid=73143 /taskname=help4u_updating_service /funurl=http:/stats.buildomserv.com <==== ATTENTION
 
==================== Loaded Modules (Whitelisted) ==============
 
2013-12-22 09:35 - 2014-05-20 08:25 - 00116568 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2014-01-28 01:16 - 2009-08-20 14:22 - 00135168 _____ () C:\Windows\SysWOW64\ChgService.exe
2013-12-21 09:45 - 2009-07-15 09:37 - 00246272 _____ () C:\Program Files (x86)\Join Air\AssistantServices.exe
2013-12-20 19:59 - 2013-08-23 05:07 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2014-05-25 21:18 - 2014-05-25 21:18 - 00036536 ____N () C:\Program Files\Rainmeter\Rainmeter.exe
2014-05-25 21:18 - 2014-05-25 21:18 - 00747192 _____ () C:\Program Files\Rainmeter\Rainmeter.dll
2014-05-25 21:17 - 2014-05-25 21:17 - 00056832 _____ () C:\Program Files\Rainmeter\Plugins\WebParser.dll
2015-09-22 12:39 - 2015-09-19 05:13 - 01501512 _____ () C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.99\libglesv2.dll
2015-09-22 12:39 - 2015-09-19 05:13 - 00081224 _____ () C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.99\libegl.dll
2013-12-20 20:48 - 2013-08-08 13:23 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\ACE.dll
2014-10-30 02:23 - 2013-12-12 16:41 - 00010224 _____ () C:\Users\Rifandi\AppData\Roaming\BabSolution\Shared\BabMaint.exe
2014-10-30 02:23 - 2013-12-12 16:41 - 00431600 _____ () C:\Users\Rifandi\AppData\Roaming\BabSolution\Shared\BUSolution.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Rifandi\Downloads\Wallpaper\trafalgar-law-jolly-roger-one-piece.jpg
DNS Servers: 192.168.43.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
HKLM\...\StartupApproved\StartupFolder: => "StartupModem.lnk"
HKLM\...\StartupApproved\Run32: => "UIExec"
HKLM\...\StartupApproved\Run32: => "APSDaemon"
HKLM\...\StartupApproved\Run32: => "QuickTime Task"
HKLM\...\StartupApproved\Run32: => "WinampAgent"
HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\StartupApproved\Run: => "DAEMON Tools Lite"
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{1A06DCD8-8738-438C-8399-A80A5E0B8728}] => (Allow) C:\Program Files (x86)\AVG\AVG2014\avgmfapx.exe
FirewallRules: [{F2AE1ED8-46AE-444B-AB1C-B23A4870D723}] => (Allow) C:\Program Files (x86)\AVG\AVG2014\avgmfapx.exe
FirewallRules: [{09DDA33A-F684-498B-A248-1FF2A010503B}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{9240A9AF-274B-4D6B-80E5-BCEA62BEDD87}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{AB0F5B93-B492-45C8-8B0C-92E9C2A7B5EE}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{8905FE43-37DD-48A5-8C71-4E849017C3B8}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{562750CB-3D48-4CEF-84F8-0554B9BF4601}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{BE82E2D9-F899-4F2B-A3E9-6B44EA1C87CA}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{EC871DAD-58DB-4A2C-BFBC-74D670725D1C}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{97A03C4D-04F4-4878-8797-A2A1557665C8}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{B6F7FC4E-3F4B-4469-98AC-6F6B3877AB22}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{4F0DB9E4-E763-48D4-AF84-14834AFAF53C}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{4A3E9165-9DB0-46EB-890F-DCE89376C612}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{20083BF8-F33B-4932-BBC1-7DAEE01E3710}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{588D0D49-B694-4391-BB67-4F279A9BA92C}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{D7490F1E-D3BA-4A4D-93F6-A6D8A309FEC5}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [TCP Query User{9B45E7F0-30EE-47DD-A6A3-5C61DFE3E55E}D:\games\prototype 2\prototype2.exe] => (Block) D:\games\prototype 2\prototype2.exe
FirewallRules: [UDP Query User{765FB244-EE57-4E0A-A1A8-4254A4AE4C90}D:\games\prototype 2\prototype2.exe] => (Block) D:\games\prototype 2\prototype2.exe
FirewallRules: [TCP Query User{19635119-F6FE-450D-91C7-B69050C4FBAD}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe] => (Allow) C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe
FirewallRules: [UDP Query User{70D36063-2C68-44E0-A9F2-6C99883C4168}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe] => (Allow) C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe
FirewallRules: [TCP Query User{A49822FF-6416-4240-8E79-F95943201E2C}D:\games\konami\pro evolution soccer 2013\pes2013.exe] => (Block) D:\games\konami\pro evolution soccer 2013\pes2013.exe
FirewallRules: [UDP Query User{45DEE90E-9EBF-43F9-8799-998E83696311}D:\games\konami\pro evolution soccer 2013\pes2013.exe] => (Block) D:\games\konami\pro evolution soccer 2013\pes2013.exe
FirewallRules: [{775A3945-A3B4-4B4E-AFDF-0CCC57EB45F9}] => (Allow) %systemroot%\system32\alg.exe
FirewallRules: [TCP Query User{D891051F-84BD-4B10-923F-C293F54DD09E}D:\games\dota\war3.exe] => (Allow) D:\games\dota\war3.exe
FirewallRules: [UDP Query User{4C2C0E42-89CE-488C-8B12-F2392966F600}D:\games\dota\war3.exe] => (Allow) D:\games\dota\war3.exe
FirewallRules: [{27FB2FF6-1E02-4AF4-B515-BE58E7F66AED}] => (Allow) C:\Program Files\KMSpico\KMSELDI.exe
FirewallRules: [{D31A831A-E4FA-41E1-98ED-24EF2D307FDA}] => (Allow) C:\Program Files\KMSpico\KMSELDI.exe
FirewallRules: [{07799367-4E73-4629-B22A-23952A4E3A98}] => (Allow) C:\Program Files\KMSpico\KMSServer.exe
FirewallRules: [{D7FFEC2F-1027-45F8-BF55-9E803B26383D}] => (Allow) C:\Program Files\KMSpico\KMSServer.exe
FirewallRules: [{3E856337-07D0-4D60-B6DE-E6B7F3221DA2}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe
FirewallRules: [{B0BA9B87-C926-41A7-B95D-6428E7C88BA7}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe
FirewallRules: [TCP Query User{E6622835-0D2A-4DEF-9567-5E451F3EA331}C:\program files (x86)\winamp\winamp.exe] => (Block) C:\program files (x86)\winamp\winamp.exe
FirewallRules: [UDP Query User{C9C1066E-BE2F-49CC-99F8-50AAE4B9E3AE}C:\program files (x86)\winamp\winamp.exe] => (Block) C:\program files (x86)\winamp\winamp.exe
FirewallRules: [{E10061AB-4E65-496F-9FE1-55C9ED05FAD8}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe
FirewallRules: [TCP Query User{5FB4513F-2E57-47EF-A0FE-CE5F2E1615B9}C:\program files (x86)\winamp\winamp.exe] => (Block) C:\program files (x86)\winamp\winamp.exe
FirewallRules: [UDP Query User{25006CC4-CE19-4424-946D-E20E4C243FD1}C:\program files (x86)\winamp\winamp.exe] => (Block) C:\program files (x86)\winamp\winamp.exe
FirewallRules: [TCP Query User{CC65259C-1AA7-4F1C-9436-334BFA693245}D:\games\battle field 4\bf4_x86.exe] => (Block) D:\games\battle field 4\bf4_x86.exe
FirewallRules: [UDP Query User{E807EE63-8880-4009-AD1C-0BC5990364D9}D:\games\battle field 4\bf4_x86.exe] => (Block) D:\games\battle field 4\bf4_x86.exe
FirewallRules: [TCP Query User{66E425DA-B20D-4E19-9180-7A976439C34B}D:\games\left 4 dead\left4dead.exe] => (Block) D:\games\left 4 dead\left4dead.exe
FirewallRules: [UDP Query User{3A2BEAC6-C02C-4634-B01A-AE94B750A88E}D:\games\left 4 dead\left4dead.exe] => (Block) D:\games\left 4 dead\left4dead.exe
FirewallRules: [{8EC7C0D2-469D-425A-B1B6-B81075B83C37}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe
FirewallRules: [{0EB4AB0D-4A4A-4D49-B669-6857DFBAAA39}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe
FirewallRules: [{971E3028-9FB4-4F27-9B29-7DBC1424F8A5}] => (Allow) C:\Windows\System32\KMSServer.exe
FirewallRules: [{213EADAA-1CFE-4D58-9E21-C09621DE09D5}] => (Allow) C:\Windows\System32\KMSServer.exe
FirewallRules: [{EBCA317D-CC83-43ED-AAE3-74866A4DFFD5}] => (Allow) D:\GAMES\Dragon Nest SEA\DragonNest.exe
FirewallRules: [{E6B27D11-BF45-4183-A96A-5CB3D7C3791D}] => (Allow) D:\GAMES\Dragon Nest SEA\DragonNest.exe
FirewallRules: [{CCC5C3B9-E51F-4B73-8BC1-2D66C70840D9}] => (Allow) D:\GAMES\Dragon Nest SEA\DragonNest.exe
FirewallRules: [{B16D292D-99B8-4EA4-AC6F-0B9132F3EE53}] => (Allow) D:\GAMES\Dragon Nest SEA\DragonNest.exe
FirewallRules: [TCP Query User{90F7424A-8CFA-4BB1-BA55-EB24C74E71F7}D:\game installer\ygopro-1.032.1-v2-percy-full\ygopro_vs.exe] => (Allow) D:\game installer\ygopro-1.032.1-v2-percy-full\ygopro_vs.exe
FirewallRules: [UDP Query User{D4C32738-7C8E-4867-9329-62743A543310}D:\game installer\ygopro-1.032.1-v2-percy-full\ygopro_vs.exe] => (Allow) D:\game installer\ygopro-1.032.1-v2-percy-full\ygopro_vs.exe
FirewallRules: [TCP Query User{BA753D81-75AA-4A12-9D7F-A2D1DAD7E556}D:\games\prototype 2\prototype2.exe] => (Block) D:\games\prototype 2\prototype2.exe
FirewallRules: [UDP Query User{185D5014-4109-4234-AA47-1DDBFF073CA9}D:\games\prototype 2\prototype2.exe] => (Block) D:\games\prototype 2\prototype2.exe
FirewallRules: [{DF926D87-1BE0-4685-88BB-E8509C8AA040}] => (Allow) C:\Program Files\KMSnano\qemu-system-i386.exe
FirewallRules: [{69799192-0148-4AFD-90AF-84E0FB23EB56}] => (Allow) C:\Program Files\KMSnano\qemu-system-i386.exe
FirewallRules: [TCP Query User{AF03422E-9BCC-4E54-A80E-890A78693EDF}C:\xampp\apache\bin\httpd.exe] => (Allow) C:\xampp\apache\bin\httpd.exe
FirewallRules: [UDP Query User{1BB7E18C-5720-4F80-A26C-4B4D6759F5F1}C:\xampp\apache\bin\httpd.exe] => (Allow) C:\xampp\apache\bin\httpd.exe
FirewallRules: [TCP Query User{98AAD854-2D55-4A73-AC8D-7A754DCE2A6E}C:\xampp\mysql\bin\mysqld.exe] => (Allow) C:\xampp\mysql\bin\mysqld.exe
FirewallRules: [UDP Query User{22279E3E-2B1E-4548-947E-861FE12B4F2E}C:\xampp\mysql\bin\mysqld.exe] => (Allow) C:\xampp\mysql\bin\mysqld.exe
FirewallRules: [TCP Query User{20ACCA7D-677B-49C4-9FBB-1054D7DCC002}C:\xampp\filezillaftp\filezillaserver.exe] => (Block) C:\xampp\filezillaftp\filezillaserver.exe
FirewallRules: [UDP Query User{51AE80A9-24F9-41FC-B991-C92BA2F16493}C:\xampp\filezillaftp\filezillaserver.exe] => (Block) C:\xampp\filezillaftp\filezillaserver.exe
FirewallRules: [TCP Query User{FAAC8729-32D6-4E1E-B3A1-33EE26EC6DA9}C:\xampp\mercurymail\mercury.exe] => (Block) C:\xampp\mercurymail\mercury.exe
FirewallRules: [UDP Query User{6B59466B-7787-460A-8135-8584676DDD3D}C:\xampp\mercurymail\mercury.exe] => (Block) C:\xampp\mercurymail\mercury.exe
FirewallRules: [TCP Query User{B34030A8-37BC-4369-8E40-9E8593FCA786}D:\game installer\yu-gi-oh!\ygopro-1.032.1-v2-percy-full\ygopro_vs.exe] => (Allow) D:\game installer\yu-gi-oh!\ygopro-1.032.1-v2-percy-full\ygopro_vs.exe
FirewallRules: [UDP Query User{1BC3E71A-6D5B-4055-A44D-20339D07333B}D:\game installer\yu-gi-oh!\ygopro-1.032.1-v2-percy-full\ygopro_vs.exe] => (Allow) D:\game installer\yu-gi-oh!\ygopro-1.032.1-v2-percy-full\ygopro_vs.exe
FirewallRules: [{59C6CA05-CDA7-4977-AAA5-F11DEBD92122}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\devenv.exe
FirewallRules: [{3946D93A-3163-47B2-AE52-0217794C2B3F}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\devenv.exe
FirewallRules: [{826D336A-FEFC-43BF-982B-BF5195301D96}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\devenv.exe
FirewallRules: [{38A36E27-11A4-455B-8519-9D9B9B6F35A4}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\devenv.exe
FirewallRules: [{DDF81497-B651-4F9B-872E-FEFDD9489202}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\devenv.exe
FirewallRules: [{2C6D4CCD-4DD9-47E8-9148-DE1C59A5A4AE}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\devenv.exe
FirewallRules: [{1D0F16D8-87B1-45A6-A597-ECA32834DB8D}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\devenv.exe
FirewallRules: [TCP Query User{DDFCA80E-0E24-4BD5-BC1C-91CEB65A42B6}D:\games\farcry 3\bin\farcry3_d3d11.exe] => (Block) D:\games\farcry 3\bin\farcry3_d3d11.exe
FirewallRules: [UDP Query User{7BDAB37E-85AD-47D5-9232-DA4FBE791CC8}D:\games\farcry 3\bin\farcry3_d3d11.exe] => (Block) D:\games\farcry 3\bin\farcry3_d3d11.exe
FirewallRules: [{F6ACCA3B-0F7F-4BCB-9202-2382097D23B1}] => (Allow) C:\Users\Rifandi\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{A835423B-9920-4C72-86A3-2FDE848D1AD0}] => (Allow) C:\Users\Rifandi\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [TCP Query User{0B1F268B-D381-43B7-96D5-8091703066EC}D:\games\divinity original sin\shipping\eocapp.exe] => (Block) D:\games\divinity original sin\shipping\eocapp.exe
FirewallRules: [UDP Query User{6306DE96-53C2-439D-A523-9E26BFC2D7D2}D:\games\divinity original sin\shipping\eocapp.exe] => (Block) D:\games\divinity original sin\shipping\eocapp.exe
FirewallRules: [TCP Query User{08EE761A-7CD2-49B4-8627-8534CC0A0158}H:\game installer\yu-gi-oh!\ygopro-1.032.1-v2-percy-full\ygopro_vs.exe] => (Block) H:\game installer\yu-gi-oh!\ygopro-1.032.1-v2-percy-full\ygopro_vs.exe
FirewallRules: [UDP Query User{63B09064-974F-4436-B236-ABE88D1D683F}H:\game installer\yu-gi-oh!\ygopro-1.032.1-v2-percy-full\ygopro_vs.exe] => (Block) H:\game installer\yu-gi-oh!\ygopro-1.032.1-v2-percy-full\ygopro_vs.exe
FirewallRules: [TCP Query User{F1617650-D557-4FD9-910D-86489DA5B55A}D:\games\outlast\outlast\binaries\win64\olgame.exe] => (Allow) D:\games\outlast\outlast\binaries\win64\olgame.exe
FirewallRules: [UDP Query User{F0C3E966-0FA0-4118-AE9B-45599BC8E5EB}D:\games\outlast\outlast\binaries\win64\olgame.exe] => (Allow) D:\games\outlast\outlast\binaries\win64\olgame.exe
FirewallRules: [{515B5948-489D-48C0-9607-0E2E1BBCC843}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
FirewallRules: [{4A95A6AD-35AF-4038-BA25-01A1ADA3EAB6}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
FirewallRules: [TCP Query User{6E87AF5C-8E18-490A-A9A5-1C8E3CC9623F}C:\users\rifandi\appdata\roaming\torntv.com\torntv downloader.exe] => (Allow) C:\users\rifandi\appdata\roaming\torntv.com\torntv downloader.exe
FirewallRules: [UDP Query User{4DE8BECB-1C50-478D-A1DD-6450237F7C27}C:\users\rifandi\appdata\roaming\torntv.com\torntv downloader.exe] => (Allow) C:\users\rifandi\appdata\roaming\torntv.com\torntv downloader.exe
FirewallRules: [{2A58B125-FA27-4763-923F-962854AC4C64}] => (Allow) C:\Users\Rifandi\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{16606177-8490-41B5-8A89-817542833D73}] => (Allow) C:\Users\Rifandi\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [TCP Query User{1B01E919-DD5D-4C53-9A08-6FA46EC14E69}C:\program files (x86)\stronghold crusader 2\bin\win32_release\crusader2.exe] => (Block) C:\program files (x86)\stronghold crusader 2\bin\win32_release\crusader2.exe
FirewallRules: [UDP Query User{983E342C-763C-4F85-B0F9-48B66631F44F}C:\program files (x86)\stronghold crusader 2\bin\win32_release\crusader2.exe] => (Block) C:\program files (x86)\stronghold crusader 2\bin\win32_release\crusader2.exe
FirewallRules: [TCP Query User{9C6A7B15-3DE6-4258-9CE7-8FCCBBDE7FE6}D:\games\stronghold crusader 2\bin\win32_release\crusader2.exe] => (Allow) D:\games\stronghold crusader 2\bin\win32_release\crusader2.exe
FirewallRules: [UDP Query User{CB15A0A3-D243-43D8-9621-0FFD3B91B959}D:\games\stronghold crusader 2\bin\win32_release\crusader2.exe] => (Allow) D:\games\stronghold crusader 2\bin\win32_release\crusader2.exe
FirewallRules: [{CE95B2B9-8A50-4D43-A53B-967115E4BA08}] => (Allow) D:\GAMES\Sierra Entertainment\Empire Earth III\EE3.exe
FirewallRules: [{743E21E2-9067-4D72-9CB8-58CC60AF37F4}] => (Allow) D:\GAMES\Sierra Entertainment\Empire Earth III\EE3.exe
FirewallRules: [{53AF91DF-0050-4B9B-8981-DF6F4FB160B9}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{3A971CE2-F559-42D0-93F3-4A2365E792F8}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{8BEE11D2-7F86-4B46-9669-E96517FC5AB7}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{6F618C98-4506-4A99-98C2-AAE190AA3A9B}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{FFBFA651-18E8-4F3C-BDD7-0BB25117FE71}] => (Allow) D:\GAMES\SteamLibrary\steamapps\common\dota 2 beta\dota.exe
FirewallRules: [{E83DC855-BB23-47A9-85A7-E165E628CA83}] => (Allow) D:\GAMES\SteamLibrary\steamapps\common\dota 2 beta\dota.exe
FirewallRules: [TCP Query User{C438FD29-9201-4750-BCE5-C78BD9D3DB2B}C:\program files (x86)\cisco packet tracer 5.3.3\bin\packettracer5.exe] => (Block) C:\program files (x86)\cisco packet tracer 5.3.3\bin\packettracer5.exe
FirewallRules: [UDP Query User{DC7E8C51-20F3-4920-BE94-5FD0B64F8789}C:\program files (x86)\cisco packet tracer 5.3.3\bin\packettracer5.exe] => (Block) C:\program files (x86)\cisco packet tracer 5.3.3\bin\packettracer5.exe
FirewallRules: [TCP Query User{4F71FC4A-674D-4914-9235-9C566EF79522}D:\games\battle field 4\bf4.exe] => (Allow) D:\games\battle field 4\bf4.exe
FirewallRules: [UDP Query User{CD03D387-6214-43AC-8C63-B342DF7E224A}D:\games\battle field 4\bf4.exe] => (Allow) D:\games\battle field 4\bf4.exe
FirewallRules: [TCP Query User{406C305E-219C-4CF8-AA6D-FEE4ADAF9D6A}D:\games\company of heroes\bugreport\bugreport.exe] => (Block) D:\games\company of heroes\bugreport\bugreport.exe
FirewallRules: [UDP Query User{0C7D59B2-DDA8-434C-8400-65A342A9D1F2}D:\games\company of heroes\bugreport\bugreport.exe] => (Block) D:\games\company of heroes\bugreport\bugreport.exe
FirewallRules: [{9DDF3AC0-45AA-4706-83DD-4AB1E6C059D0}] => (Allow) D:\GAMES\SteamLibrary\steamapps\common\Aura Kingdom\game.bin
FirewallRules: [{7C11A026-5E0B-469C-8101-39A26E6AF45F}] => (Allow) D:\GAMES\SteamLibrary\steamapps\common\Aura Kingdom\game.bin
FirewallRules: [TCP Query User{F6389871-CABA-428C-A860-FD222EC6B270}D:\games\pro evolution soccer 2015\pes2015.exe] => (Block) D:\games\pro evolution soccer 2015\pes2015.exe
FirewallRules: [UDP Query User{8BE9F98D-8DA0-4C44-A98D-6497171661EF}D:\games\pro evolution soccer 2015\pes2015.exe] => (Block) D:\games\pro evolution soccer 2015\pes2015.exe
FirewallRules: [TCP Query User{3D794DA7-A0BF-4E42-A700-1F93299411F4}D:\games\devil may cry 5 - complete edition\binaries\win32\dmc-devilmaycry.exe] => (Allow) D:\games\devil may cry 5 - complete edition\binaries\win32\dmc-devilmaycry.exe
FirewallRules: [UDP Query User{F05D44A1-7268-4885-9BD1-2CC2F50C04B9}D:\games\devil may cry 5 - complete edition\binaries\win32\dmc-devilmaycry.exe] => (Allow) D:\games\devil may cry 5 - complete edition\binaries\win32\dmc-devilmaycry.exe
FirewallRules: [{EE0F8D63-27BE-4EF2-8BDE-26AA454297C0}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{7605257A-3D4B-49AB-B2DD-132CCB812A10}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{9A5B1E8A-B31F-4B38-B6D9-5E00A45FF065}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{BD3755B2-254D-4C99-9AB3-6C9A3CB42267}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{44D20B8C-A835-4767-9306-134F953356F9}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe
FirewallRules: [{B3303EAD-5EE2-461A-AAF0-CB56CCE10C86}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe
FirewallRules: [{A41FF3C1-CF80-4D64-956E-D623EBA66A93}] => (Allow) C:\Windows\System32\KMSServer.exe
FirewallRules: [{B9C6AC4A-06A8-44A3-A2D7-910AC3D1DEAA}] => (Allow) C:\Windows\System32\KMSServer.exe
FirewallRules: [TCP Query User{CB038158-67D6-4066-B1EF-B01AEB8547E0}C:\program files (x86)\java\jdk1.7.0_40\bin\java.exe] => (Allow) C:\program files (x86)\java\jdk1.7.0_40\bin\java.exe
FirewallRules: [UDP Query User{355E4826-AEF9-4DE1-91C3-3545BEC33CB1}C:\program files (x86)\java\jdk1.7.0_40\bin\java.exe] => (Allow) C:\program files (x86)\java\jdk1.7.0_40\bin\java.exe
FirewallRules: [{029E27FF-EE21-4AC9-AEBF-2626CF8A0E29}] => (Block) C:\program files (x86)\java\jdk1.7.0_40\bin\java.exe
FirewallRules: [{8E58488F-C3EC-40E4-87DD-E6B23DE3CD13}] => (Block) C:\program files (x86)\java\jdk1.7.0_40\bin\java.exe
FirewallRules: [TCP Query User{D3E3887D-DC4D-46F8-85BB-A17DB4DF3143}C:\program files (x86)\netbeans 8.0.2\bin\netbeans.exe] => (Allow) C:\program files (x86)\netbeans 8.0.2\bin\netbeans.exe
FirewallRules: [UDP Query User{A751FD98-134E-4AEC-9F8B-E7E253030F48}C:\program files (x86)\netbeans 8.0.2\bin\netbeans.exe] => (Allow) C:\program files (x86)\netbeans 8.0.2\bin\netbeans.exe
FirewallRules: [{E5B43872-E575-4F3D-986A-64D619871AD3}] => (Allow) D:\GAMES\Lost Saga\LostSaga\autoupgrade.exe
FirewallRules: [{69B3670B-2F4D-4167-B798-5B149BA07E62}] => (Allow) D:\GAMES\Lost Saga\LostSaga\autoupgrade.exe
FirewallRules: [{CD9A082D-3309-48CB-BDE1-39391F4F243E}] => (Allow) D:\GAMES\Lost Saga\LostSaga\lostsaga.exe
FirewallRules: [{37642C02-07E0-4AAC-9BD9-3C8B1895FFFC}] => (Allow) D:\GAMES\Lost Saga\LostSaga\lostsaga.exe
FirewallRules: [TCP Query User{D4092692-D5C5-4D48-8B18-D81225C3825B}C:\program files (x86)\java\jdk1.8.0\bin\java.exe] => (Block) C:\program files (x86)\java\jdk1.8.0\bin\java.exe
FirewallRules: [UDP Query User{46354920-75FC-4F1F-A024-57422E213465}C:\program files (x86)\java\jdk1.8.0\bin\java.exe] => (Block) C:\program files (x86)\java\jdk1.8.0\bin\java.exe
FirewallRules: [TCP Query User{FE8B8914-6097-4301-BD5F-B0D69500EB11}C:\program files\java\jdk1.8.0_45\bin\java.exe] => (Block) C:\program files\java\jdk1.8.0_45\bin\java.exe
FirewallRules: [UDP Query User{F298C8CA-5E47-4D38-BBA2-37840677E966}C:\program files\java\jdk1.8.0_45\bin\java.exe] => (Block) C:\program files\java\jdk1.8.0_45\bin\java.exe
FirewallRules: [TCP Query User{D753E326-1315-41D8-818C-82CD5647D11E}C:\program files\java\jdk1.8.0_45\jre\bin\javaw.exe] => (Allow) C:\program files\java\jdk1.8.0_45\jre\bin\javaw.exe
FirewallRules: [UDP Query User{F8ED93EC-2756-4CEA-BB2D-2233892BCBF5}C:\program files\java\jdk1.8.0_45\jre\bin\javaw.exe] => (Allow) C:\program files\java\jdk1.8.0_45\jre\bin\javaw.exe
FirewallRules: [TCP Query User{DB6151F1-04FD-48A9-8E07-2F307A3FE61F}D:\software installer\eclipse luna\eclipse.exe] => (Block) D:\software installer\eclipse luna\eclipse.exe
FirewallRules: [UDP Query User{3E5D112C-48BE-4D66-87B7-55E3CEA6EB97}D:\software installer\eclipse luna\eclipse.exe] => (Block) D:\software installer\eclipse luna\eclipse.exe
FirewallRules: [{B2ECFC14-358D-4C41-91DC-3D31C9DD46A0}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (09/23/2015 12:20:40 PM) (Source: NvStreamSvc) (EventID: 2001) (User: )
Description: NvStreamSvcNvVAD initialization failed [6]
 
Error: (09/23/2015 12:20:40 PM) (Source: NvStreamSvc) (EventID: 2001) (User: )
Description: NvStreamSvcFailed to set NvVAD endpoint as default Audio endpoint [0]
 
Error: (09/23/2015 12:20:40 PM) (Source: NvStreamSvc) (EventID: 2001) (User: )
Description: NvStreamSvcNvVAD endpoint registration failed [0]
 
Error: (09/23/2015 11:58:13 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: Service_KMS.exe, version: 10.4.1.0, time stamp: 0x528ccd03
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0x00000000
Fault offset: 0x00007fff75df252c
Faulting process id: 0x538
Faulting application start time: 0xService_KMS.exe0
Faulting application path: Service_KMS.exe1
Faulting module path: Service_KMS.exe2
Report Id: Service_KMS.exe3
Faulting package full name: Service_KMS.exe4
Faulting package-relative application ID: Service_KMS.exe5
 
Error: (09/23/2015 11:57:31 AM) (Source: NvStreamSvc) (EventID: 2001) (User: )
Description: NvStreamSvcNvVAD initialization failed [6]
 
Error: (09/23/2015 11:57:31 AM) (Source: NvStreamSvc) (EventID: 2001) (User: )
Description: NvStreamSvcFailed to set NvVAD endpoint as default Audio endpoint [0]
 
Error: (09/23/2015 11:57:31 AM) (Source: NvStreamSvc) (EventID: 2001) (User: )
Description: NvStreamSvcNvVAD endpoint registration failed [0]
 
Error: (09/22/2015 12:45:49 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
 
Error: (09/22/2015 12:04:24 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.
 
Error: (09/22/2015 12:04:24 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.
 
 
System errors:
=============
Error: (09/23/2015 12:22:52 PM) (Source: ipnathlp) (EventID: 30013) (User: )
Description: 192.168.43.251192.168.137.0255.255.255.0
 
Error: (09/23/2015 12:22:52 PM) (Source: ipnathlp) (EventID: 1233) (User: )
Description: 
 
Error: (09/23/2015 12:22:52 PM) (Source: ipnathlp) (EventID: 1233) (User: )
Description: 
 
Error: (09/23/2015 12:22:52 PM) (Source: ipnathlp) (EventID: 1233) (User: )
Description: 
 
Error: (09/23/2015 12:22:50 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Windows Defender Service service terminated unexpectedly.  It has done this 3 time(s).
 
Error: (09/23/2015 12:21:49 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Defender Service service terminated unexpectedly.  It has done this 2 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.
 
Error: (09/23/2015 12:20:52 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Service KMSELDI service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (09/23/2015 12:20:48 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Defender Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.
 
Error: (09/23/2015 12:20:43 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The BuddyVM service failed to start due to the following error: 
%%3
 
Error: (09/23/2015 12:02:05 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The Intel® Management and Security Application Local Management Service service hung on starting.
 
 
CodeIntegrity:
===================================
  Date: 2015-07-27 04:23:14.067
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-06-15 20:50:59.848
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-06-15 20:50:58.778
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-05-04 19:21:05.000
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-05-03 18:41:37.484
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-05-03 18:28:38.544
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-05-03 18:19:41.800
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-05-03 14:45:34.731
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-05-03 06:53:29.838
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-05-03 06:24:57.206
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
 
 
==================== Memory info =========================== 
 
Processor: Intel® Core™ i5-3230M CPU @ 2.60GHz
Percentage of memory in use: 35%
Total physical RAM: 3957.6 MB
Available physical RAM: 2537.52 MB
Total Virtual: 4661.6 MB
Available Virtual: 3155.62 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:146.49 GB) (Free:41.49 GB) NTFS
Drive d: () (Fixed) (Total:690.8 GB) (Free:53.2 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: C24F1638)
Partition 1: (Active) - (Size=102 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=146.5 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=690.8 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=94.1 GB) - (Type=05)
 
==================== End of Addition.txt ============================

  • 0

#9
BrianDrab

BrianDrab

    Trusted Helper

  • Malware Removal
  • 3,591 posts

Thank you. Let's begin.

 

Step#1 - Uninstalls
Please uninstall the following programs one at a time. Instructions for doing so are here.
If any of the programs give you an error during the uninstall, notate it and move on to the next one. Just let me know which ones had issues. If you are asked to reboot, answer No until all the programs have been uninstalled and then you can reboot. All of these programs are either outdated, malware/adware, have a bad reputation or are not recommended. 
 

KMSpico v9.0.6.20131120

KMSnano 24

 

Step#2 - FRST Fix
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
1. Download attached file and save it to the Desktop. Attached File  fixlist.txt   10.47KB   194 downloads
Note. It's important that both files, FRST64 and fixlist.txt are in the same location or the fix will not work (in this case...the desktop).
2. Run FRST64 by Right-Clicking on the file and choosing Run as administrator.
3. Press the Fix button just once and wait. If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
4. When finished FRST64 will generate a log on the Desktop (Fixlog.txt). Please post the contents of it in your reply.
 

Step#3 - AdWCleaner
1. Please download AdwCleaner by Xplode onto your desktop.
2. Close all open programs and internet browsers.
3. Right-click on AdwCleaner.exe and select Run as administrator to run the tool. Click I agree if you agree with the terms of use.
4. Click on Scan.
5. After the scan is complete click on "Cleaning"
6. Confirm each time with Ok.
7. Your computer will be rebooted automatically. A text file will open after the restart.
8. Please post the content of that logfile with your next answer.
9. If need be, you can also find the logfile at C:\AdwCleaner\AdwCleaner[C1].txt as well.

 

Step#4 - Fresh Set of Logs
1. Right click on FRST64.exe and select Run as administrator. When the tool opens click Yes to disclaimer.
2. Please ensure you place a check mark in the Addition.txt check box at the bottom of the form before running.
3. Press Scan button.
4. It will produce a log called FRST.txt in the same directory the tool is run from (which should now be the desktop)
5. Please copy and paste log back here.
6. Because you selected the Addition.txt check box this log will be created as well. Please copy and paste this log as well.
 
 
 
Items for your next post

1. Fix log

2. AdwCleaner Log
1. FRST and Addition logs

 

 


  • 0

#10
fandy

fandy

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts

I have follow your instruction,

but i forgot to move adwcleaner to my desktop, is that going to be bad?

 

here the log

Fix result of Farbar Recovery Scan Tool (x64) Version:23-09-2015
Ran by Rifandi (2015-09-24 17:22:19) Run:1
Running from C:\Users\Rifandi\Desktop
Loaded Profiles: Rifandi (Available Profiles: Rifandi)
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
CreateRestorePoint:
(FileProperties_CompanyName) C:\Program Files (x86)\help4u\help4u_notification_service.exe
C:\Program Files (x86)\help4u\
HKLM-x32\...\Run: [] => [X]
HKLM\...\Policies\Explorer: [TaskbarNoNotification] 1
HKLM\...\Policies\Explorer: [HideSCAHealth] 1
HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\Run: [TornTv Downloader] => C:\Users\Rifandi\AppData\Roaming\TornTV.com\Torntv Downloader.exe /c=startup
HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\Run: [Only-search] => C:\Users\Rifandi\AppData\Local\onlysearch\onlysearch\1.3.15.4\onlysearch.exe
AppInit_DLLs: C:\PROGRA~2\SupTab\SEARCH~2.DLL => C:\Program Files (x86)\SupTab\SearchProtect64.dll [96768 2014-03-05] (Skytech Co., Ltd.)
AppInit_DLLs-x32: C:\PROGRA~2\SupTab\SEARCH~1.DLL => C:\Program Files (x86)\SupTab\SearchProtect32.dll [85504 2014-03-05] (Skytech Co., Ltd.)
Startup: C:\Users\Rifandi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TornTvDownloader.lnk [2014-10-30]
ShortcutTarget: TornTvDownloader.lnk -> C:\Users\Rifandi\AppData\Roaming\TornTV.com\TornTV Downloader.exe (No File)
GroupPolicy: Restriction - Chrome <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.qone8.com/?type=hp&ts=1395502286&from=ild&uid=ST1000LM024XHN-M101MBB_S2U5J9KD102731
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.qone8.com/web/?type=ds&ts=1395502286&from=ild&uid=ST1000LM024XHN-M101MBB_S2U5J9KD102731&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.qone8.com/web/?type=ds&ts=1395502286&from=ild&uid=ST1000LM024XHN-M101MBB_S2U5J9KD102731&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://start.qone8.com/?type=hp&ts=1395502286&from=ild&uid=ST1000LM024XHN-M101MBB_S2U5J9KD102731
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.qone8.com/web/?type=ds&ts=1395502286&from=ild&uid=ST1000LM024XHN-M101MBB_S2U5J9KD102731&q={searchTerms}
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=irmsd0103&cd=2XzuyEtN2Y1L1QzutB0C0DtDyD0AtCtAzz0CyCyCyB0E0D0EtN0D0Tzu0SyByCyDtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R&cr=1961462397&ir=
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.qone8.com/web/?type=ds&ts=1395502286&from=ild&uid=ST1000LM024XHN-M101MBB_S2U5J9KD102731&q={searchTerms}
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.qone8.com/web/?type=ds&ts=1395502286&from=ild&uid=ST1000LM024XHN-M101MBB_S2U5J9KD102731&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1232603322-3645337139-1979953262-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=irmsd0103&cd=2XzuyEtN2Y1L1QzutB0C0DtDyD0AtCtAzz0CyCyCyB0E0D0EtN0D0Tzu0SyByCyDtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R&cr=1961462397&ir=
SearchScopes: HKU\S-1-5-21-1232603322-3645337139-1979953262-1001 -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.only-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=B6BD2ED05A138C66&affID=129300&tsp=5416
SearchScopes: HKU\S-1-5-21-1232603322-3645337139-1979953262-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.qone8.com/web/?type=ds&ts=1395502286&from=ild&uid=ST1000LM024XHN-M101MBB_S2U5J9KD102731&q={searchTerms}
BHO-x32: mysearchdial Helper Object -> {EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD} -> C:\Program Files (x86)\Mysearchdial\1.8.21.0\bh\mysearchdial.dll [2014-02-04] (MySearchDial)
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  No File
Toolbar: HKLM-x32 - mysearchdial Toolbar - {3004627E-F8E9-4E8B-909D-316753CBA923} - C:\Program Files (x86)\Mysearchdial\1.8.21.0\mysearchdialTlbr.dll [2014-02-04] (MySearchDial)
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://start.qone8.com/?type=sc&ts=1395502286&from=ild&uid=ST1000LM024XHN-M101MBB_S2U5J9KD102731
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll [No File]
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll [No File]
FF SearchPlugin: C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\searchplugins\MyOnlineSearch.xml [2014-10-30]
FF SearchPlugin: C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\searchplugins\onlysearchkms.xml [2014-10-30]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\qone8.xml [2014-03-22]
CHR Extension: (YYTBoOkMark) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kmjboicapmacdaecgldenkpdcdkkifgc [2014-02-04]
CHR Extension: (gREatSaveer) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\oefifkdlbdfmnhdkbagencoidhfjcich [2014-02-04]
2015-09-10 15:23 - 2015-09-10 15:23 - 01415680 _____ (wj32) C:\Program Files\ZNZUJ1KC.exe
2015-09-10 15:23 - 2015-09-10 15:23 - 01415680 _____ (wj32) C:\Program Files\YB8FRRCJ.exe
2015-09-10 15:23 - 2015-09-10 15:23 - 01415680 _____ (wj32) C:\Program Files\X1ZWBCHI.exe
2015-09-10 15:23 - 2015-09-10 15:23 - 01415680 _____ (wj32) C:\Program Files\W04V9Y20.exe
2015-09-10 15:23 - 2015-09-10 15:23 - 01415680 _____ (wj32) C:\Program Files\R5UVZL04.exe
2015-09-10 15:23 - 2015-09-10 15:23 - 01415680 _____ (wj32) C:\Program Files\ICJKVJ4B.exe
2015-09-10 15:23 - 2015-09-10 15:23 - 01415680 _____ (wj32) C:\Program Files\9GOV2WKR.exe
2015-09-10 15:23 - 2015-09-10 15:23 - 01415680 _____ (wj32) C:\Program Files\39Y7K2I0.exe
2015-09-10 15:23 - 2015-09-10 15:23 - 01415680 _____ (wj32) C:\Program Files\31XFGLPK.exe
2015-09-10 15:19 - 2015-09-10 15:19 - 01415680 _____ (wj32) C:\Program Files\AET6IA57.exe
2015-09-10 15:05 - 2015-09-10 15:05 - 01415680 _____ (wj32) C:\Program Files\TUYNETRG.exe
2015-09-03 11:16 - 2015-09-03 11:16 - 01415680 _____ (wj32) C:\Program Files\O6YOYI62.exe
2015-09-03 11:16 - 2015-09-03 11:16 - 01415680 _____ (wj32) C:\Program Files\B3T3NBZJ.exe
2015-09-03 09:54 - 2015-09-03 09:54 - 01415680 _____ (wj32) C:\Program Files\J5PP7DXH.exe
2015-08-30 23:33 - 2015-08-30 23:33 - 01415680 _____ (wj32) C:\Program Files\9TAOZDU8.exe
2015-08-30 23:32 - 2015-08-30 23:32 - 01415680 _____ (wj32) C:\Program Files\2WKICE8A.exe
2015-09-19 04:03 - 2015-04-06 23:03 - 00001302 _____ C:\Windows\Tasks\help4u_notification_service.job
2015-09-19 04:03 - 2015-04-06 23:03 - 00000664 _____ C:\Windows\Tasks\help4u_updating_service.job
2014-11-18 16:11 - 2014-11-18 16:11 - 0000000 _____ () C:\Users\Rifandi\AppData\Local\{28B07EFD-C22E-4EAF-BB9A-886224995B4E}
2014-11-22 20:25 - 2014-11-22 20:25 - 0000000 _____ () C:\Users\Rifandi\AppData\Local\{918915E7-62D3-4955-BD85-3C711153C0F0}
2014-11-21 17:59 - 2014-11-21 17:59 - 0000000 _____ () C:\Users\Rifandi\AppData\Local\{DE111176-0A34-4308-8E0C-5FC04B4A97A7}
2013-08-22 10:56 - 2013-08-22 10:56 - 68792320 ___SH () C:\ProgramData\msctqoijn.exe
Task: {2AAB2F86-2217-46D4-8004-88F4A8F9C72E} - System32\Tasks\help4u_notification_service => C:\Program Files (x86)\help4u\help4u_notification_service.exe [2015-04-06] (FileProperties_CompanyName) <==== ATTENTION
Task: {A1EEE3CA-8222-464D-BD7C-0E48D2C118DF} - System32\Tasks\help4u_updating_service => C:\Program Files (x86)\help4u\help4u_updating_service.exe [2015-04-06] () <==== ATTENTION
Task: {C5EA213E-BFBF-436F-B6B2-DF62BD727E8A} - System32\Tasks\EPUpdater => C:\Users\Rifandi\AppData\Roaming\BabSolution\Shared\BabMaint.exe [2013-12-12] () <==== ATTENTION
Task: C:\Windows\Tasks\64b5c250-015d-48b5-b157-300a8e3bfe82.job => C:\Program Files (x86)\SavePass 1.1\64b5c250-015d-48b5-b157-300a8e3bfe82.exe <==== ATTENTION
Task: C:\Windows\Tasks\c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-1.job => C:\Program Files (x86)\SavePass 1.1\SavePass 1.1-codedownloader.exe <==== ATTENTION
Task: C:\Windows\Tasks\c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-11.job => C:\Program Files (x86)\SavePass 1.1\c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-11.exe <==== ATTENTION
Task: C:\Windows\Tasks\c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.job => C:\Program Files (x86)\SavePass 1.1\c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe <==== ATTENTION
Task: C:\Windows\Tasks\c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-5.job => C:\Program Files (x86)\SavePass 1.1\c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-5.exe <==== ATTENTION
Task: C:\Windows\Tasks\c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-5_user.job => C:\Program Files (x86)\SavePass 1.1\c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-5.exe <==== ATTENTION
Task: C:\Windows\Tasks\c6f17427-280e-44d4-88bc-561c1fe0d308.job => C:\Program Files (x86)\SavePass 1.1\c6f17427-280e-44d4-88bc-561c1fe0d308.exeȘ/agentregpath='SavePass 1.1' /appid=63429 /srcid='001504' /subid='0' /zdata='0' /bic=2827820446154BECB360AC217BBD185EIE /verifier=a2bd8b9c017cd558c9844388bde7f117 /installerversion=1_35_09_03 /installationtime=1410537375 /statsdomain=http:/stats.newclientgenservice.com /errorsdomain=http:/errors.newclientgenservice.com /extensionname='Information' /torpedoiesleeps=1000 /torpedoieplugins=93-0,102-0,104-0,178-288,179-288,180-288,223-288,263-24 /monetizationdomain=http:/logs.newclientgenservice.com <==== ATTENTION
Task: C:\Windows\Tasks\help4u_notification_service.job => C:\Program Files (x86)\help4u\help4u_notification_service.exeǢ/url='http:/cdn.selectbestopt.com/notf_sys/index.html' /crregname='help4u' /appid='73143' /srcid='2913' /bic='3c4f7bfbe922fc9e30d0f7a9a7b1bbad' /verifier='1d6ae977715d5d15586c376a4be34ff3' /installerversion='1.50.3.10' /statsdomain='http:/stats.buildomserv.com/data.gif?' /errorsdomain='http:/stats.buildomserv.com/data.gif?' /monetizationdomain='http:/logs.buildomserv.com/monetization.gif <==== ATTENTION
Task: C:\Windows\Tasks\help4u_updating_service.job => C:\Program Files (x86)\help4u\help4u_updating_service.exe§ /campid=2913 /verid=1 /url=http:/cdn.buildomserv.com/txt/@CAMPID@/@VER@/file.txt /appid=73143 /taskname=help4u_updating_service /funurl=http:/stats.buildomserv.com <==== ATTENTION
FirewallRules: [TCP Query User{6E87AF5C-8E18-490A-A9A5-1C8E3CC9623F}C:\users\rifandi\appdata\roaming\torntv.com\torntv downloader.exe] => (Allow) C:\users\rifandi\appdata\roaming\torntv.com\torntv downloader.exe
FirewallRules: [UDP Query User{4DE8BECB-1C50-478D-A1DD-6450237F7C27}C:\users\rifandi\appdata\roaming\torntv.com\torntv downloader.exe] => (Allow) C:\users\rifandi\appdata\roaming\torntv.com\torntv downloader.exe
EmptyTemp:
 
*****************
 
Error: (0) Failed to create a restore point.
[3480] C:\Program Files (x86)\help4u\help4u_notification_service.exe => process closed successfully.
C:\Program Files (x86)\help4u => moved successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value not found.
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\TaskbarNoNotification => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\HideSCAHealth => value removed successfully
HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\Software\Microsoft\Windows\CurrentVersion\Run\\TornTv Downloader => value removed successfully
HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Only-search => value removed successfully
"C:\PROGRA~2\SupTab\SEARCH~2.DLL" => Value data removed successfully.
"C:\PROGRA~2\SupTab\SEARCH~1.DLL" => Value data removed successfully.
C:\Users\Rifandi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TornTvDownloader.lnk => moved successfully
C:\Users\Rifandi\AppData\Roaming\TornTV.com\TornTV Downloader.exe => not found.
C:\Windows\system32\GroupPolicy\Machine => moved successfully
C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully
C:\Windows\SysWOW64\GroupPolicy\GPT.ini => moved successfully
"HKLM\SOFTWARE\Policies\Google" => key removed successfully
HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully
HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully
HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found. 
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => key removed successfully
HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => key not found. 
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => key removed successfully
HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => key not found. 
"HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found. 
"HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}" => key removed successfully
HKCR\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => key not found. 
"HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => key removed successfully
HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => key not found. 
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD}" => key removed successfully
"HKCR\Wow6432Node\CLSID\{EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => value removed successfully
HKCR\CLSID\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => key not found. 
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{3004627E-F8E9-4E8B-909D-316753CBA923} => value removed successfully
"HKCR\Wow6432Node\CLSID\{3004627E-F8E9-4E8B-909D-316753CBA923}" => key removed successfully
HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => value restored successfully
"HKLM\Software\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10" => key removed successfully
"HKLM\Software\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4" => key removed successfully
C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\searchplugins\MyOnlineSearch.xml => moved successfully
C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\searchplugins\onlysearchkms.xml => moved successfully
C:\Program Files (x86)\mozilla firefox\browser\searchplugins\qone8.xml => moved successfully
C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kmjboicapmacdaecgldenkpdcdkkifgc => moved successfully
C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\oefifkdlbdfmnhdkbagencoidhfjcich => moved successfully
C:\Program Files\ZNZUJ1KC.exe => moved successfully
C:\Program Files\YB8FRRCJ.exe => moved successfully
C:\Program Files\X1ZWBCHI.exe => moved successfully
C:\Program Files\W04V9Y20.exe => moved successfully
C:\Program Files\R5UVZL04.exe => moved successfully
C:\Program Files\ICJKVJ4B.exe => moved successfully
C:\Program Files\9GOV2WKR.exe => moved successfully
C:\Program Files\39Y7K2I0.exe => moved successfully
C:\Program Files\31XFGLPK.exe => moved successfully
C:\Program Files\AET6IA57.exe => moved successfully
C:\Program Files\TUYNETRG.exe => moved successfully
C:\Program Files\O6YOYI62.exe => moved successfully
C:\Program Files\B3T3NBZJ.exe => moved successfully
C:\Program Files\J5PP7DXH.exe => moved successfully
C:\Program Files\9TAOZDU8.exe => moved successfully
C:\Program Files\2WKICE8A.exe => moved successfully
C:\Windows\Tasks\help4u_notification_service.job => moved successfully
C:\Windows\Tasks\help4u_updating_service.job => moved successfully
C:\Users\Rifandi\AppData\Local\{28B07EFD-C22E-4EAF-BB9A-886224995B4E} => moved successfully
C:\Users\Rifandi\AppData\Local\{918915E7-62D3-4955-BD85-3C711153C0F0} => moved successfully
C:\Users\Rifandi\AppData\Local\{DE111176-0A34-4308-8E0C-5FC04B4A97A7} => moved successfully
Could not move "C:\ProgramData\msctqoijn.exe" => Scheduled to move on reboot.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{2AAB2F86-2217-46D4-8004-88F4A8F9C72E}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2AAB2F86-2217-46D4-8004-88F4A8F9C72E}" => key removed successfully
C:\Windows\System32\Tasks\help4u_notification_service => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\help4u_notification_service" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{A1EEE3CA-8222-464D-BD7C-0E48D2C118DF}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A1EEE3CA-8222-464D-BD7C-0E48D2C118DF}" => key removed successfully
C:\Windows\System32\Tasks\help4u_updating_service => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\help4u_updating_service" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C5EA213E-BFBF-436F-B6B2-DF62BD727E8A}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C5EA213E-BFBF-436F-B6B2-DF62BD727E8A}" => key removed successfully
C:\Windows\System32\Tasks\EPUpdater => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EPUpdater" => key removed successfully
C:\Windows\Tasks\64b5c250-015d-48b5-b157-300a8e3bfe82.job => moved successfully
C:\Windows\Tasks\c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-1.job => moved successfully
C:\Windows\Tasks\c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-11.job => moved successfully
C:\Windows\Tasks\c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.job => moved successfully
C:\Windows\Tasks\c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-5.job => moved successfully
C:\Windows\Tasks\c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-5_user.job => moved successfully
C:\Windows\Tasks\c6f17427-280e-44d4-88bc-561c1fe0d308.job => moved successfully
C:\Windows\Tasks\help4u_notification_service.job => not found.
C:\Windows\Tasks\help4u_updating_service.job => not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{6E87AF5C-8E18-490A-A9A5-1C8E3CC9623F}C:\users\rifandi\appdata\roaming\torntv.com\torntv downloader.exe => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{4DE8BECB-1C50-478D-A1DD-6450237F7C27}C:\users\rifandi\appdata\roaming\torntv.com\torntv downloader.exe => value removed successfully
EmptyTemp: => 3.1 GB temporary data Removed.
 
Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 2015-09-24 17:24:59)<=
 
C:\ProgramData\msctqoijn.exe => Is moved successfully
 
==== End of Fixlog 17:24:59 ====
 
 
 
# AdwCleaner v5.008 - Logfile created 24/09/2015 at 17:35:35
# Updated 18/09/2015 by Xplode
# Database : 2015-09-23.1 [Server]
# Operating system : Windows 8.1 Pro  (x64)
# Username : Rifandi - RIP
# Running from : C:\Users\Rifandi\Downloads\Anime\Programs\AdwCleaner.exe
# Option : Scan
 
***** [ Services ] *****
 
 
***** [ Folders ] *****
 
Folder Found : C:\Program Files (x86)\globalUpdate
Folder Found : C:\Program Files (x86)\Mysearchdial
Folder Found : C:\Program Files (x86)\rightsurf
Folder Found : C:\Program Files (x86)\SupTab
Folder Found : C:\Program Files (x86)\SavePass 1.1
Folder Found : C:\Program Files (x86)\GReaatsaver
Folder Found : C:\Program Files (x86)\SavePass 1.1
Folder Found : C:\Program Files (x86)\YoutubeAdblocker
Folder Found : C:\Program Files (x86)\SavePass 1.1
Folder Found : C:\ProgramData\apn
Folder Found : C:\ProgramData\DSearchLink
Folder Found : C:\ProgramData\IePluginService
Folder Found : C:\ProgramData\WPM
Folder Found : C:\ProgramData\GReaatsaver
Folder Found : C:\ProgramData\YoutubeAdblocker
Folder Found : C:\ProgramData\ae98960d435764d3
Folder Found : C:\Users\Rifandi\AppData\Local\cool_mirage
Folder Found : C:\Users\Rifandi\AppData\Local\globalUpdate
Folder Found : C:\Users\Rifandi\AppData\Local\onlysearch
Folder Found : C:\Users\Rifandi\AppData\Local\torch
Folder Found : C:\Users\Rifandi\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bpclmfjinbmadbbclhkbabnnecmaaopa
Folder Found : C:\Users\Rifandi\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\giccehglhacakcfemddmfhdkahamfcmd
Folder Found : C:\Users\Rifandi\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gkoghcmfjgopofakhllpdmflopkhccoj
Folder Found : C:\Users\Rifandi\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\giccehglhacakcfemddmfhdkahamfcmd
Folder Found : C:\Users\Rifandi\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gkoghcmfjgopofakhllpdmflopkhccoj
Folder Found : C:\Users\Rifandi\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\kmjboicapmacdaecgldenkpdcdkkifgc
Folder Found : C:\Users\Rifandi\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\giccehglhacakcfemddmfhdkahamfcmd
Folder Found : C:\Users\Rifandi\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gkoghcmfjgopofakhllpdmflopkhccoj
Folder Found : C:\Users\Rifandi\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\kmjboicapmacdaecgldenkpdcdkkifgc
Folder Found : C:\Users\Rifandi\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bpclmfjinbmadbbclhkbabnnecmaaopa
Folder Found : C:\Users\Rifandi\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\giccehglhacakcfemddmfhdkahamfcmd
Folder Found : C:\Users\Rifandi\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gkoghcmfjgopofakhllpdmflopkhccoj
Folder Found : C:\Users\Rifandi\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\giccehglhacakcfemddmfhdkahamfcmd
Folder Found : C:\Users\Rifandi\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gkoghcmfjgopofakhllpdmflopkhccoj
Folder Found : C:\Users\Rifandi\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\kmjboicapmacdaecgldenkpdcdkkifgc
Folder Found : C:\Users\Rifandi\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\giccehglhacakcfemddmfhdkahamfcmd
Folder Found : C:\Users\Rifandi\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gkoghcmfjgopofakhllpdmflopkhccoj
Folder Found : C:\Users\Rifandi\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\kmjboicapmacdaecgldenkpdcdkkifgc
Folder Found : C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma
Folder Found : C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\giccehglhacakcfemddmfhdkahamfcmd
Folder Found : C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkoghcmfjgopofakhllpdmflopkhccoj
Folder Found : C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\giccehglhacakcfemddmfhdkahamfcmd
Folder Found : C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkoghcmfjgopofakhllpdmflopkhccoj
Folder Found : C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\giccehglhacakcfemddmfhdkahamfcmd
Folder Found : C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkoghcmfjgopofakhllpdmflopkhccoj
Folder Found : C:\Users\Rifandi\AppData\Roaming\BabSolution
Folder Found : C:\Users\Rifandi\AppData\Roaming\Mysearchdial
Folder Found : C:\Users\Rifandi\AppData\Roaming\SupTab
Folder Found : C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\Extensions\[email protected]
Folder Found : C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\Extensions\[email protected]
Folder Found : C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\Extensions\[email protected]
Folder Found : C:\Users\Rifandi\Documents\Mobogenie
 
***** [ Files ] *****
 
File Found : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\yahoo.xml
File Found : C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\gkoghcmfjgopofakhllpdmflopkhccoj
File Found : C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\gkoghcmfjgopofakhllpdmflopkhccoj
File Found : C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\oefifkdlbdfmnhdkbagencoidhfjcich
File Found : C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\gkoghcmfjgopofakhllpdmflopkhccoj
File Found : C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\oefifkdlbdfmnhdkbagencoidhfjcich
File Found : C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx
File Found : C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\user.js
 
***** [ Shortcuts ] *****
 
Shortcut Infected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk ( hxxp://start.qone8.com/?type=sc&ts=1395502286&from=ild&uid=ST1000LM024XHN-M101MBB_S2U5J9KD102731 )
 
***** [ Scheduled tasks ] *****
 
 
***** [ Registry ] *****
 
Key Found : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Key Found : HKLM\SOFTWARE\Classes\esrv.mysearchdialesrvc
Key Found : HKLM\SOFTWARE\Classes\esrv.mysearchdialesrvc.1
Key Found : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
Key Found : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Key Found : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Key Found : HKLM\SOFTWARE\Classes\mysearchdial.mysearchdialappCore
Key Found : HKLM\SOFTWARE\Classes\mysearchdial.mysearchdialappCore.1
Key Found : HKLM\SOFTWARE\Classes\mysearchdial.mysearchdialdskBnd
Key Found : HKLM\SOFTWARE\Classes\mysearchdial.mysearchdialdskBnd.1
Key Found : HKLM\SOFTWARE\Classes\mysearchdial.mysearchdialHlpr
Key Found : HKLM\SOFTWARE\Classes\mysearchdial.mysearchdialHlpr.1
Key Found : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IePluginService
Key Found : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Wpm
Key Found : HKCU\Software\Mozilla\Extends
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION [SavePass 1.1-bg.exe]
Key Found : HKLM\SOFTWARE\Classes\CrossriderApp0063429.BHO
Key Found : HKLM\SOFTWARE\Classes\CrossriderApp0063429.BHO.1
Key Found : HKLM\SOFTWARE\Classes\CrossriderApp0063429.Sandbox
Key Found : HKLM\SOFTWARE\Classes\CrossriderApp0063429.Sandbox.1
Value Found : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [[email protected]]
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma
Key Found : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Found : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Found : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Key Found : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Found : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Key Found : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
Key Found : HKLM\SOFTWARE\Classes\AppID\{C292AD0A-C11F-479B-B8DB-743E72D283B0}
Key Found : HKLM\SOFTWARE\Classes\AppID\{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}
Key Found : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{4ED063C9-4A0B-4B44-A9DC-23AFF424A0D3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{6D4506CE-F855-4657-AA38-DB6B1F733982}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{C358B3D0-B911-41E3-A276-E7D43A6BA56D}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{D40753C7-8A59-4C1F-BE88-C300F4624D5B}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611341129}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622342229}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611341129}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622342229}
Key Found : HKLM\SOFTWARE\Classes\Interface\{0400EBCA-042C-4000-AA89-9713FBEDB671}
Key Found : HKLM\SOFTWARE\Classes\Interface\{0BD19251-4B4B-4B94-AB16-617106245BB7}
Key Found : HKLM\SOFTWARE\Classes\Interface\{3281114F-BCAB-45E3-80D9-A6CD64D4E636}
Key Found : HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Key Found : HKLM\SOFTWARE\Classes\Interface\{44533FCB-F9FB-436A-8B6B-CF637B2D465A}
Key Found : HKLM\SOFTWARE\Classes\Interface\{44B29DDD-CF7A-454A-A275-A322A398D93F}
Key Found : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Key Found : HKLM\SOFTWARE\Classes\Interface\{A4DE94DB-DF03-45A3-8A5D-D1B7464B242D}
Key Found : HKLM\SOFTWARE\Classes\Interface\{AA0F50A8-2618-4AE4-A779-9F7378555A8F}
Key Found : HKLM\SOFTWARE\Classes\Interface\{B2DB115C-8278-4947-9A07-57B53D1C4215}
Key Found : HKLM\SOFTWARE\Classes\Interface\{B97FC455-DB33-431D-84DB-6F1514110BD5}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C67281E0-78F5-4E49-9FAE-4B1B2ADAF17B}
Key Found : HKLM\SOFTWARE\Classes\Interface\{D54C859C-6066-4F31-8FE0-2AAEDCAE67D7}
Key Found : HKLM\SOFTWARE\Classes\Interface\{E72E9312-0367-4216-BFC7-21485FA8390B}
Key Found : HKLM\SOFTWARE\Classes\Interface\{F6CCB6C9-127E-44AE-8552-B94356F39FFE}
Key Found : HKLM\SOFTWARE\Classes\Interface\{FFD25630-2734-4AE9-88E6-21BF6525F3FE}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{03771AEF-400D-4A13-B712-25878EC4A3F5}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{C292AD0A-C11F-479B-B8DB-743E72D283B0}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{DCABB943-792E-44C4-9029-ECBEE6265AF9}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{FBC322D5-407E-4854-8C0B-555B951FD8E3}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440644344429}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440644344429}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3004627E-F8E9-4E8B-909D-316753CBA923}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110611341129}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110611341129}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3004627E-F8E9-4E8B-909D-316753CBA923}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{219046AE-358F-4CF1-B1FD-2B4DE83642A8}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{056ddd55-13e4-41e4-b00c-7e512c42be0c}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{89ddacd0-0d24-463d-878c-d5c921345790}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611341129}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622342229}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611341129}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622342229}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{0400EBCA-042C-4000-AA89-9713FBEDB671}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{0BD19251-4B4B-4B94-AB16-617106245BB7}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{3281114F-BCAB-45E3-80D9-A6CD64D4E636}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{44533FCB-F9FB-436A-8B6B-CF637B2D465A}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{44B29DDD-CF7A-454A-A275-A322A398D93F}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{A4DE94DB-DF03-45A3-8A5D-D1B7464B242D}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{AA0F50A8-2618-4AE4-A779-9F7378555A8F}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{B2DB115C-8278-4947-9A07-57B53D1C4215}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{B97FC455-DB33-431D-84DB-6F1514110BD5}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{C67281E0-78F5-4E49-9FAE-4B1B2ADAF17B}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{D54C859C-6066-4F31-8FE0-2AAEDCAE67D7}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{E72E9312-0367-4216-BFC7-21485FA8390B}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{F6CCB6C9-127E-44AE-8552-B94356F39FFE}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{FFD25630-2734-4AE9-88E6-21BF6525F3FE}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{056ddd55-13e4-41e4-b00c-7e512c42be0c}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{89ddacd0-0d24-463d-878c-d5c921345790}
Key Found : HKU\.DEFAULT\Software\TornTv Downloader
Key Found : HKU\.DEFAULT\Software\AppDataLow\Software\SavePass 1.1
Key Found : HKU\.DEFAULT\Software\AppDataLow\Software\SavePass 1.1
Key Found : HKU\.DEFAULT\Software\AppDataLow\Software\SavePass 1.1
Key Found : HKU\.DEFAULT\Software\AppDataLow\Software\SavePass 1.1
Key Found : HKCU\Software\1ClickDownload
Key Found : HKCU\Software\BABSOLUTION
Key Found : HKCU\Software\GlobalUpdate
Key Found : HKCU\Software\InstallCore
Key Found : HKCU\Software\InstalledBrowserExtensions
Key Found : HKCU\Software\mysearchdial
Key Found : HKCU\Software\RegisteredApplicationsEx
Key Found : HKCU\Software\TornTv Downloader
Key Found : HKCU\Software\help4u
Key Found : HKCU\Software\AppDataLow\Software\Crossrider
Key Found : HKCU\Software\AppDataLow\Software\SavePass 1.1
Key Found : HKCU\Software\AppDataLow\Software\SavePass 1.1
Key Found : HKCU\Software\AppDataLow\Software\SavePass 1.1
Key Found : HKCU\Software\AppDataLow\Software\SavePass 1.1
Key Found : HKLM\SOFTWARE\AVG SafeGuard toolbar
Key Found : HKLM\SOFTWARE\Conduit
Key Found : HKLM\SOFTWARE\GlobalUpdate
Key Found : HKLM\SOFTWARE\IePlugin
Key Found : HKLM\SOFTWARE\InstallCore
Key Found : HKLM\SOFTWARE\InstalledBrowserExtensions
Key Found : HKLM\SOFTWARE\qone8Software
Key Found : HKLM\SOFTWARE\SavePass 1.1
Key Found : HKLM\SOFTWARE\SupTab
Key Found : HKLM\SOFTWARE\supWPM
Key Found : HKLM\SOFTWARE\Wpm
Key Found : HKLM\SOFTWARE\SiteSee
Key Found : HKLM\SOFTWARE\SavePass 1.1
Key Found : HKLM\SOFTWARE\SavePass 1.1
Key Found : HKLM\SOFTWARE\SavePass 1.1
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{CA41BB14-E67B-1653-C57B-5CA99418A866}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SavePass 1.1
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AD11DADE-C597-45D9-D8C5-1D2EB0B89613}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SavePass 1.1
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SavePass 1.1
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{CA41BB14-E67B-1653-C57B-5CA99418A866}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{CF830981-8F31-C561-C7A0-FE2CE1878B40}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SavePass 1.1
Key Found : [x64] HKCU\Software\1ClickDownload
Key Found : [x64] HKCU\Software\BABSOLUTION
Key Found : [x64] HKCU\Software\GlobalUpdate
Key Found : [x64] HKCU\Software\InstallCore
Key Found : [x64] HKCU\Software\InstalledBrowserExtensions
Key Found : [x64] HKCU\Software\mysearchdial
Key Found : [x64] HKCU\Software\RegisteredApplicationsEx
Key Found : [x64] HKCU\Software\TornTv Downloader
Key Found : [x64] HKCU\Software\help4u
Key Found : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
Key Found : HKU\.DEFAULT\Software\AppDataLow\Software\SavePass 1.1
Key Found : HKU\.DEFAULT\Software\AppDataLow\Software\SavePass 1.1
Key Found : HKU\.DEFAULT\Software\AppDataLow\Software\SavePass 1.1
Key Found : HKU\.DEFAULT\Software\AppDataLow\Software\SavePass 1.1
Key Found : HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\Software\AppDataLow\Software\Crossrider
Key Found : HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\Software\AppDataLow\Software\SavePass 1.1
Key Found : HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\Software\AppDataLow\Software\SavePass 1.1
Key Found : HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\Software\AppDataLow\Software\SavePass 1.1
Key Found : HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\Software\AppDataLow\Software\SavePass 1.1
Key Found : HKU\S-1-5-18\Software\AppDataLow\Software\SavePass 1.1
Key Found : HKU\S-1-5-18\Software\AppDataLow\Software\SavePass 1.1
Key Found : HKU\S-1-5-18\Software\AppDataLow\Software\SavePass 1.1
Key Found : HKU\S-1-5-18\Software\AppDataLow\Software\SavePass 1.1
Data Found : HKLM\SOFTWARE\Clients\StartMenuInternet\SAFARI.EXE\shell\open\command [] - "C:\Program Files (x86)\Safari\Safari.exe" hxxp://start.qone8.com/?type=sc&ts=1395502286&from=ild&uid=ST1000LM024XHN-M101MBB_S2U5J9KD102731
 
***** [ Web browsers ] *****
 
[C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\prefs.js] [Preference] Found : user_pref("extensions.N6bAB9UK0.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sumoro[...]
[C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\prefs.js] [Preference] Found : user_pref("extensions.aVJKPXI46039420JMZUIOB85844870com63429.63429.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssfiles.com%22%5D%7D%2C%22dealply_p%22[...]
[C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\prefs.js] [Preference] Found : user_pref("extensions.crossrider.bic", "1486a98ae4e4e5a827c89d53f243dee9");
[C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\prefs.js] [Preference] Found : user_pref("extensions.mysearchdial.AL", 2);
[C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\prefs.js] [Preference] Found : user_pref("extensions.mysearchdial.aflt", "irmsd0103");
[C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\prefs.js] [Preference] Found : user_pref("extensions.mysearchdial.appId", "{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}");
[C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\prefs.js] [Preference] Found : user_pref("extensions.mysearchdial.cd", "2XzuyEtN2Y1L1QzutB0C0DtDyD0AtCtAzz0CyCyCyB0E0D0EtN0D0Tzu0SyByCyDtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R");
[C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\prefs.js] [Preference] Found : user_pref("extensions.mysearchdial.cr", "1961462397");
[C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\prefs.js] [Preference] Found : user_pref("extensions.mysearchdial.dfltLng", "");
[C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\prefs.js] [Preference] Found : user_pref("extensions.mysearchdial.dfltSrch", true);
[C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\prefs.js] [Preference] Found : user_pref("extensions.mysearchdial.dnsErr", true);
[C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\prefs.js] [Preference] Found : user_pref("extensions.mysearchdial.excTlbr", false);
[C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\prefs.js] [Preference] Found : user_pref("extensions.mysearchdial.hmpg", true);
[C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\prefs.js] [Preference] Found : user_pref("extensions.mysearchdial.hmpgUrl", "hxxp://start.mysearchdial.com/?f=1&a=irmsd0103&cd=2XzuyEtN2Y1L1QzutB0C0DtDyD0AtCtAzz0CyCyCyB0E0D0EtN0D0Tzu0SyByCyDtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutB[...]
[C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\prefs.js] [Preference] Found : user_pref("extensions.mysearchdial.id", "2CD05A138C667EDE");
[C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\prefs.js] [Preference] Found : user_pref("extensions.mysearchdial.instlDay", "16105");
[C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\prefs.js] [Preference] Found : user_pref("extensions.mysearchdial.instlRef", "");
[C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\prefs.js] [Preference] Found : user_pref("extensions.mysearchdial.newTabUrl", "hxxp://start.mysearchdial.com/?f=2&a=irmsd0103&cd=2XzuyEtN2Y1L1QzutB0C0DtDyD0AtCtAzz0CyCyCyB0E0D0EtN0D0Tzu0SyByCyDtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1Czu[...]
[C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\prefs.js] [Preference] Found : user_pref("extensions.mysearchdial.prdct", "mysearchdial");
[C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\prefs.js] [Preference] Found : user_pref("extensions.mysearchdial.prtnrId", "mysearchdial");
[C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\prefs.js] [Preference] Found : user_pref("extensions.mysearchdial.srchPrvdr", "Mysearchdial");
[C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\prefs.js] [Preference] Found : user_pref("extensions.mysearchdial.tlbrId", "base");
[C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\prefs.js] [Preference] Found : user_pref("extensions.mysearchdial.tlbrSrchUrl", "hxxp://start.mysearchdial.com/?f=3&a=irmsd0103&cd=2XzuyEtN2Y1L1QzutB0C0DtDyD0AtCtAzz0CyCyCyB0E0D0EtN0D0Tzu0SyByCyDtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1C[...]
[C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\prefs.js] [Preference] Found : user_pref("extensions.mysearchdial.vrsn", "1.8.21.0");
[C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\prefs.js] [Preference] Found : user_pref("extensions.mysearchdial.vrsni", "1.8.21.0");
[C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\prefs.js] [Preference] Found : user_pref("extensions.mysearchdial_i.hmpg", true);
[C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\prefs.js] [Preference] Found : user_pref("extensions.mysearchdial_i.newTab", false);
[C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\prefs.js] [Preference] Found : user_pref("extensions.mysearchdial_i.smplGrp", "none");
[C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\prefs.js] [Preference] Found : user_pref("extensions.mysearchdial_i.vrsnTs", "1.8.21.01:36:6");
[C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\prefs.js] [Preference] Found : user_pref("extensions.n8nmrPkP.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sumorob[...]
[C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\prefs.js] [Preference] Found : user_pref("extensions.quick_start.enable_search1", false);
[C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\prefs.js] [Preference] Found : user_pref("extensions.quick_start.sd.closeWindowWithLastTab_prev_state", false);
[C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : giccehglhacakcfemddmfhdkahamfcmd
[C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : giccehglhacakcfemddmfhdkahamfcmd
[C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : giccehglhacakcfemddmfhdkahamfcmd
[C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : gkoghcmfjgopofakhllpdmflopkhccoj
[C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : gkoghcmfjgopofakhllpdmflopkhccoj
[C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : gkoghcmfjgopofakhllpdmflopkhccoj
[C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : kmjboicapmacdaecgldenkpdcdkkifgc
[C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : kmjboicapmacdaecgldenkpdcdkkifgc
[C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : oefifkdlbdfmnhdkbagencoidhfjcich
[C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : oefifkdlbdfmnhdkbagencoidhfjcich
[C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : pelmeidfhdlhlbjimpabfcbnnojbboma
 
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [31206 bytes] ##########
 
 
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:23-09-2015
Ran by Rifandi (administrator) on RIP (24-09-2015 17:49:44)
Running from C:\Users\Rifandi\Desktop
Loaded Profiles: Rifandi (Available Profiles: Rifandi)
Platform: Windows 8.1 Pro (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Atheros Commnucations) C:\Windows\System32\AdminService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\Windows\SysWOW64\ChgService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
() C:\Program Files (x86)\Join Air\AssistantServices.exe
(Microsoft Corporation) C:\Users\Rifandi\AppData\Roaming\Microsoft\SystemCertificates\VSSVC.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(NVIDIA Corporation) C:\Users\Rifandi\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Integrated Clock Controller Service\ICCProxy.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMan.exe
() C:\Program Files\Rainmeter\Rainmeter.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Don HO [email protected]) C:\Program Files (x86)\Notepad++\notepad++.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [17111056 2013-12-20] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [193008 2013-12-20] (Lenovo(beijing) Limited)
HKLM\...\Run: [Nvtmru] => "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2531472 2014-12-13] (NVIDIA Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13647576 2013-08-27] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1321688 2013-08-07] (Realtek Semiconductor)
HKLM-x32\...\Run: [UIExec] => C:\Program Files (x86)\Join Air\UIExec.exe [713728 2010-12-16] ()
HKLM-x32\...\Run: [WinampAgent] => C:\Program Files (x86)\Winamp\winampa.exe [85600 2013-12-13] (Nullsoft, Inc.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [TaskbarNoNotification] 1
HKLM\...\Policies\Explorer: [HideSCAHealth] 1
HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\Run: [GoogleChromeAutoLaunch_2044B68C092258CC6B61BEF807401E47] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [815944 2015-09-19] (Google Inc.)
HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [3882576 2014-12-12] (Tonec Inc.)
HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\CurrentVersion\Windows: [Load] C:\ProgramData\msctqoijn.exe <===== ATTENTION
HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\MountPoints2: {0fb37f05-8757-11e4-83cc-20898440e341} - "H:\Install.exe" 
HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\MountPoints2: {1f44dd11-4479-11e4-83aa-20898440e341} - "F:\WD Drive Unlock.exe" autoplay=true
HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\MountPoints2: {7d215ca6-2d82-11e4-8386-20898440e341} - "F:\Install.exe" 
HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\MountPoints2: {e6f05941-877b-11e3-82b4-20898440e341} - "G:\.\Start.exe" 
AppInit_DLLs: ,C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [166568 2014-05-20] (NVIDIA Corporation)
AppInit_DLLs-x32: ,C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [146480 2014-05-20] (NVIDIA Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  No File
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Rifandi\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Rifandi\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Rifandi\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Rifandi\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll [2014-04-21] (Tonec Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Rifandi\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Rifandi\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Rifandi\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\StartupModem.lnk [2014-01-28]
ShortcutTarget: StartupModem.lnk -> C:\Program Files (x86)\3G Connect\StartUpRun.exe ()
Startup: C:\Users\Rifandi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Rainmeter.lnk [2014-10-22]
ShortcutTarget: Rainmeter.lnk -> C:\Program Files\Rainmeter\Rainmeter.exe ()
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\..\Interfaces\{659EBD27-2A47-4029-8B7F-C20452FF1B3D}: [DhcpNameServer] 192.168.43.1
Tcpip\..\Interfaces\{970D6D83-F3E5-4CA0-B64D-27F554407A29}: [DhcpNameServer] 202.0.107.1 202.0.107.2
 
Internet Explorer:
==================
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?trackid=sp-006
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = 
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = 
HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?trackid=sp-006
HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxps://www.google.com/?trackid=sp-006
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1232603322-3645337139-1979953262-1001 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1232603322-3645337139-1979953262-1001 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll [2015-05-20] (Internet Download Manager, Tonec Inc.)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-06-04] (Oracle Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-06-04] (Oracle Corporation)
BHO-x32: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll [2015-05-20] (Internet Download Manager, Tonec Inc.)
BHO-x32: Microsoft Web Test Recorder 10.0 Helper -> {876d9f09-c6d6-4324-a2cc-04dd9a4de12f} -> C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll [2012-07-26] (Microsoft Corporation)
DPF: HKLM-x32 {6A060448-60F9-11D5-A6CD-0002B31F7455} 
 
FireFox:
========
FF ProfilePath: C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default
FF NewTab: 
FF Homepage: about:home
FF Keyword.URL: 
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_134.dll [2015-03-24] ()
FF Plugin: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-06-04] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-06-04] (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_134.dll [2015-03-24] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-08-08] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-08-08] (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll [2012-04-11] ( Microsoft Corporation)
FF Plugin-x32: @nullsoft.com/winampDetector;version=1 -> C:\Program Files (x86)\Winamp Detect\npwachk.dll [2013-12-13] (Nullsoft, Inc.)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2014-05-20] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2014-05-20] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-19] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-19] (Google Inc.)
FF Plugin HKU\S-1-5-21-1232603322-3645337139-1979953262-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Rifandi\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2014-02-21] (Unity Technologies ApS)
FF user.js: detected! => C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\user.js [2014-03-22]
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2014-01-25] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2014-01-25] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2014-01-25] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2014-01-25] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2014-01-25] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Rifandi\AppData\Roaming\mozilla\plugins\np-mswmp.dll [2009-09-26] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Users\Rifandi\AppData\Roaming\mozilla\plugins\npatgpc.dll [2014-10-13] (Cisco WebEx LLC)
FF Extension: SavePass 1.2 - C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\Extensions\[email protected] [2015-08-19]
FF Extension: YoutubeAdblocker - C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\Extensions\[email protected] [2014-02-04]
FF Extension: anonymoX - C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\Extensions\[email protected] [2014-01-25]
FF Extension: SQLite Manager - C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\Extensions\[email protected] [2015-06-09]
FF Extension: Themes Menu - C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\Extensions\{84625510-7e5d-11e0-a411-0800200c9a66}.xpi [2014-10-30]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\extensions\[email protected]
FF HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\Firefox\Extensions: [[email protected]] - C:\Users\Rifandi\AppData\Roaming\IDM\idmmzcc5
FF Extension: IDM CC - C:\Users\Rifandi\AppData\Roaming\IDM\idmmzcc5 [2015-09-24]
FF HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\SeaMonkey\Extensions: [[email protected]] - C:\Users\Rifandi\AppData\Roaming\IDM\idmmzcc5
 
Chrome: 
=======
CHR HomePage: Default -> hxxps://www.google.com/
CHR StartupUrls: Default -> "hxxps://www.google.com/"
CHR Profile: C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-12-21]
CHR Extension: (Google Drive) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-12-21]
CHR Extension: (Earth View from Google Earth) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhloflhklmhfpedakmangadcdofhnnoh [2014-11-17]
CHR Extension: (YouTube) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-12-21]
CHR Extension: (The Elder Scrolls Online - Theme) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\bodeacmfbgjollphdaehplmjobapnbin [2015-06-30]
CHR Extension: (Google Search) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-12-21]
CHR Extension: (Adblock Plus) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\efmppbpipefbijnpmokkcfnedohbiije [2015-04-12]
CHR Extension: (Google Docs Offline) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-09-06]
CHR Extension: (Privacy manager) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\giccehglhacakcfemddmfhdkahamfcmd [2014-02-04]
CHR Extension: (YoutubeAdblocker) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkoghcmfjgopofakhllpdmflopkhccoj [2014-02-04]
CHR Extension: (Advanced REST client) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\hgmloofddffdnphfgcellkdfbfbjeloo [2015-05-09]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-14]
CHR Extension: (Speed Dial [FVD] - New Tab Page, 3D, Sync...) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\llaficoajjainaijghjlofdfmbjpebpa [2015-06-30]
CHR Extension: (IDM Integration Module) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2015-06-16]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-21]
CHR Extension: (Adblock Pro) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ocifcklkibdehekfnmflempfgjhbedch [2015-06-30]
CHR Extension: (Currently) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojhmphdkpgbibohbnpbfiefkgieacjmh [2014-11-17]
CHR Extension: (Quick start) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma [2014-03-22]
CHR Extension: (Gmail) - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-12-21]
CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2015-05-20]
CHR HKLM-x32\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2015-05-20]
CHR HKLM-x32\...\Chrome\Extension: [pelmeidfhdlhlbjimpabfcbnnojbboma] - C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx [2014-03-22]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AtherosSvc; C:\Windows\system32\AdminService.exe [208384 2012-08-29] (Atheros Commnucations)
R2 Change Modem Device Service; C:\Windows\SysWOW64\ChgService.exe [135168 2009-08-20] () [File not signed]
S3 fussvc; C:\Program Files (x86)\Windows Kits\8.0\App Certification Kit\fussvc.exe [139776 2012-07-25] (Microsoft Corporation) [File not signed]
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1148560 2014-12-13] (NVIDIA Corporation)
R2 Intel® Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel® Corporation) [File not signed]
S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel® Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [169432 2013-08-08] (Intel Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1701520 2014-12-13] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [19823248 2014-12-13] (NVIDIA Corporation)
R2 RzKLService; C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe [105448 2013-11-22] (Razer Inc.)
S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe [126976 2012-07-25] (Microsoft Corporation) [File not signed]
R2 UI Assistant Service; C:\Program Files (x86)\Join Air\AssistantServices.exe [246272 2009-07-15] () [File not signed]
R2 VSSS; C:\Users\Rifandi\AppData\Roaming\Microsoft\SystemCertificates\VSSVC.exe [103523264 2015-06-24] (Microsoft Corporation) [File not signed] <==== ATTENTION
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [346872 2013-08-22] (Microsoft Corporation)
S2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23840 2013-08-22] (Microsoft Corporation)
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 athr; C:\Windows\system32\DRIVERS\athwbx.sys [3837440 2013-07-15] (Qualcomm Atheros Communications, Inc.)
S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [224768 2013-08-22] (Microsoft Corporation)
S3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [132480 2012-10-01] (Motorola Solutions, Inc.)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-04-20] (Disc Soft Ltd)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
S3 fcusbser; C:\Windows\system32\DRIVERS\fcusbser.sys [119552 2010-06-03] (BM)
S3 hxsyol; C:\Windows\system32\hxsy64.sys [86352 2015-02-27] ()
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-08-08] (Intel Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2014-12-13] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [38032 2014-11-22] (NVIDIA Corporation)
S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [27520 2007-05-14] (Research In Motion Limited)
S3 SDGame; C:\Windows\System32\svchost.exe [37768 2013-08-22] (Microsoft Corporation)
R3 SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [230912 2013-08-22] (Microsoft Corporation)
S3 VSPerfDrv110; C:\Program Files (x86)\Microsoft Visual Studio 11.0\Team Tools\Performance Tools\x64\VSPerfDrv110.sys [70264 2012-07-13] (Microsoft Corporation)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [34760 2013-08-22] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [265056 2013-08-22] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124256 2013-08-22] (Microsoft Corporation)
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
R4 KProcessHacker2; \??\C:\Program Files\kprocesshacker.sys [X]
S2 {09BB444F-B2E2-4009-BAF2-7B727681223E}; \??\D:\GAMES\VMLaunch\BuddyVM.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-09-24 17:49 - 2015-09-24 17:50 - 00025631 _____ C:\Users\Rifandi\Desktop\FRST.txt
2015-09-24 17:38 - 2015-09-24 17:38 - 529641648 _____ C:\Windows\MEMORY.DMP
2015-09-24 17:35 - 2015-09-24 17:35 - 00000000 ____D C:\AdwCleaner
2015-09-24 17:32 - 2015-09-24 17:32 - 00002514 _____ C:\Users\Rifandi\Desktop\new  2.txt
2015-09-24 17:29 - 2015-09-24 17:29 - 00010725 _____ C:\Users\Rifandi\Desktop\fixlist.txt
2015-09-24 17:22 - 2015-09-24 17:22 - 00000000 ____D C:\Users\Rifandi\Desktop\FRST-OlderVersion
2015-09-21 13:58 - 2015-09-21 13:58 - 01415680 _____ (wj32) C:\Program Files\MNOHIJGH.exe
2015-09-19 21:31 - 2015-09-19 17:59 - 00456493 _____ C:\Users\Rifandi\Documents\Backup_of_font baru.cdr
2015-09-19 18:59 - 2015-09-19 18:59 - 01415680 _____ (wj32) C:\Program Files\HTIAGJZW.exe
2015-09-19 17:59 - 2015-09-19 21:31 - 00473711 _____ C:\Users\Rifandi\Documents\font baru.cdr
2015-09-19 04:32 - 2015-09-24 17:49 - 00000000 ____D C:\FRST
2015-09-19 04:28 - 2015-09-24 17:22 - 02192384 _____ (Farbar) C:\Users\Rifandi\Desktop\FRST64.exe
2015-09-19 04:03 - 2015-09-19 04:04 - 02019656 _____ (Bleeping Computer, LLC) C:\Users\Rifandi\Downloads\rkill.com
2015-09-19 02:29 - 2015-09-19 02:29 - 00427689 _____ C:\Users\Rifandi\Documents\Backup_of_Font.cdr
2015-09-19 01:56 - 2015-09-19 16:05 - 00440731 _____ C:\Users\Rifandi\Documents\Font.cdr
2015-09-19 00:19 - 2015-09-19 00:20 - 00000000 ____D C:\ProgramData\Avg
2015-09-19 00:16 - 2015-09-19 00:16 - 00000000 ____D C:\Users\Rifandi\AppData\Local\Avg2014
2015-09-18 14:24 - 2015-09-19 00:20 - 00000000 ____D C:\Program Files (x86)\AVG
2015-09-18 11:14 - 2015-09-18 11:14 - 00000258 _____ C:\Users\Rifandi\Documents\CorelDRAW Graphics Suite X5.txt
2015-09-18 11:07 - 2015-09-18 11:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CorelDRAW Graphics Suite X5
2015-09-18 10:59 - 2015-09-18 11:04 - 00000000 ____D C:\ProgramData\CorelDRAW Graphics Suite X7 x64
2015-09-18 08:57 - 2015-09-19 00:20 - 00000000 ____D C:\Users\Rifandi\AppData\Local\AvgSetupLog
2015-09-18 08:56 - 2015-09-18 08:56 - 00000000 ____D C:\Users\Rifandi\AppData\Local\Avg
2015-09-18 08:53 - 2015-09-18 08:57 - 00000000 ____D C:\ProgramData\Protexis
2015-09-18 08:53 - 2015-09-18 08:53 - 00000000 ____D C:\Users\Rifandi\AppData\Roaming\Corel
2015-09-18 08:50 - 2015-09-18 11:10 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 9.0
2015-09-18 08:49 - 2015-09-18 11:09 - 00000000 ____D C:\ProgramData\Corel
2015-09-18 08:45 - 2015-09-18 08:45 - 00000000 ____D C:\Program Files (x86)\Corel
2015-09-10 15:10 - 2015-03-02 18:22 - 202313264 _____ (Avast Software s.r.o.) C:\Users\Public\Desktop\avast_premier_antivirus_setup.exe
2015-09-10 14:56 - 2015-09-10 14:57 - 00008278 _____ C:\Users\Rifandi\Documents\Uninstall Dragon Age Origins.log
2015-09-09 22:36 - 2015-09-09 22:36 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2015-09-09 22:21 - 2015-09-09 22:21 - 00001113 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Widget Browser.lnk
2015-09-09 22:21 - 2015-09-09 22:21 - 00000000 ____D C:\Program Files (x86)\My Company Name
2015-09-09 22:21 - 2011-11-03 03:01 - 00056208 ____N (Rovi Corporation) C:\Windows\system32\Drivers\PxHlpa64.sys
2015-09-09 22:21 - 2011-10-17 03:00 - 00010224 ____N (Sonic Solutions) C:\Windows\system32\Drivers\cdralw2k.sys
2015-09-09 22:21 - 2011-10-17 03:00 - 00010224 ____N (Sonic Solutions) C:\Windows\system32\Drivers\cdr4_xp.sys
2015-09-09 22:19 - 2015-09-09 22:19 - 00001013 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk
2015-09-09 22:19 - 2015-09-09 22:19 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
2015-09-09 22:19 - 2015-09-09 22:19 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
2015-09-09 22:15 - 2015-09-23 12:18 - 00000000 ____D C:\Program Files\Common Files\Adobe
2015-09-09 22:11 - 2015-09-23 12:19 - 00000000 ____D C:\ProgramData\Adobe
2015-09-09 22:11 - 2015-09-10 14:17 - 00000000 ____D C:\Users\Rifandi\AppData\Local\Adobe
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-09-24 17:50 - 2013-12-31 12:58 - 00000434 _____ C:\Windows\system32\Drivers\etc\hosts.ics
2015-09-24 17:50 - 2013-12-20 11:58 - 01612604 _____ C:\Windows\WindowsUpdate.log
2015-09-24 17:50 - 2013-08-22 22:36 - 00000000 ____D C:\Windows\tracing
2015-09-24 17:48 - 2013-12-20 20:53 - 00001024 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-09-24 17:47 - 2013-12-20 11:58 - 00000000 ____D C:\Users\Rifandi
2015-09-24 17:46 - 2015-03-25 18:15 - 00065536 _____ C:\Windows\system32\Ikeext.etl
2015-09-24 17:46 - 2013-12-22 09:35 - 00000000 ____D C:\ProgramData\NVIDIA
2015-09-24 17:46 - 2013-08-22 21:45 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-09-24 17:30 - 2013-12-20 14:21 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1232603322-3645337139-1979953262-1001
2015-09-24 17:27 - 2013-12-20 20:53 - 00001028 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-09-24 17:27 - 2013-12-20 20:47 - 00003914 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{0217303C-CD5D-4BA1-8084-41BF826BC10F}
2015-09-24 17:24 - 2014-02-04 02:08 - 00000008 __RSH C:\ProgramData\ntuser.pol
2015-09-24 17:24 - 2013-09-30 11:02 - 01214332 _____ C:\Windows\PFRO.log
2015-09-24 17:23 - 2013-12-22 10:05 - 00000000 ____D C:\Users\Rifandi\AppData\Roaming\DMCache
2015-09-24 17:23 - 2013-08-22 20:25 - 00262144 ___SH C:\Windows\system32\config\BBI
2015-09-24 17:22 - 2013-08-22 22:36 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2015-09-24 17:22 - 2013-08-22 22:36 - 00000000 ____D C:\Windows\SysWOW64\GroupPolicy
2015-09-24 17:20 - 2014-03-25 14:48 - 00000000 ____D C:\Program Files\KMSnano
2015-09-24 17:03 - 2015-04-07 00:03 - 00000004 _____ C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-09-24 17:00 - 2013-08-22 22:36 - 00000000 ____D C:\Windows\system32\sru
2015-09-23 14:29 - 2013-09-30 11:14 - 00005392 _____ C:\Windows\system32\PerfStringBackup.INI
2015-09-23 14:16 - 2013-08-22 21:46 - 00193559 _____ C:\Windows\setupact.log
2015-09-23 12:26 - 2013-08-22 22:36 - 00000000 ____D C:\Windows\system32\NDF
2015-09-23 12:20 - 2013-08-22 21:44 - 05385720 _____ C:\Windows\system32\FNTCACHE.DAT
2015-09-23 12:18 - 2015-02-18 21:56 - 00000000 ____D C:\Program Files (x86)\Adobe
2015-09-23 12:08 - 2014-01-26 11:53 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-09-23 12:07 - 2014-03-25 14:39 - 00000000 ____D C:\Program Files\Microsoft Office
2015-09-23 12:07 - 2013-09-30 10:54 - 00000000 ____D C:\Windows\ShellNew
2015-09-23 12:07 - 2013-08-22 22:36 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2015-09-23 12:05 - 2013-08-22 22:36 - 00000000 ____D C:\Program Files\Common Files\System
2015-09-23 12:05 - 2013-08-22 20:25 - 00000076 _____ C:\Windows\win.ini
2015-09-21 15:43 - 2013-12-20 11:59 - 00000000 ____D C:\Users\Rifandi\AppData\Local\Packages
2015-09-19 15:21 - 2013-12-20 20:53 - 00004000 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-09-19 15:21 - 2013-12-20 20:53 - 00003764 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-09-19 14:30 - 2013-08-22 22:36 - 00000000 ____D C:\Windows\AppReadiness
2015-09-19 03:24 - 2014-05-24 19:33 - 00000000 ____D C:\Users\Rifandi\AppData\Roaming\IDM
2015-09-19 01:44 - 2013-08-22 22:36 - 00000000 ____D C:\Windows\LiveKernelReports
2015-09-19 00:23 - 2013-12-22 12:26 - 00000000 ____D C:\ProgramData\AVAST Software
2015-09-19 00:23 - 2013-12-20 14:24 - 00000000 ____D C:\ProgramData\MFAData
2015-09-18 14:28 - 2013-08-22 22:36 - 00000000 ___HD C:\Windows\ELAMBKUP
2015-09-18 11:12 - 2014-01-27 23:24 - 00000000 ____D C:\ProgramData\CorelDRAW Graphics Suite X5
2015-09-18 08:50 - 2015-07-08 20:52 - 00000000 ____D C:\Program Files\Internet Download Manager
2015-09-13 23:38 - 2013-12-20 20:53 - 00000000 ____D C:\Users\Rifandi\AppData\Local\Google
2015-09-10 14:57 - 2014-11-17 16:32 - 00000000 ____D C:\ProgramData\BioWare
2015-09-10 14:54 - 2014-12-16 13:13 - 00000000 ____D C:\Program Files (x86)\Steam
2015-09-10 13:35 - 2013-12-20 11:59 - 00000000 ____D C:\Users\Rifandi\AppData\Roaming\Adobe
2015-09-01 19:51 - 2013-10-23 11:30 - 00000000 ____D C:\Users\Rifandi\Downloads\Wallpaper
 
==================== Files in the root of some directories =======
 
2015-06-27 04:47 - 2015-06-27 04:47 - 1415680 _____ (wj32) C:\Program Files\F7N7RDTD.exe
2015-09-19 18:59 - 2015-09-19 18:59 - 1415680 _____ (wj32) C:\Program Files\HTIAGJZW.exe
2015-06-28 14:44 - 2015-06-28 14:44 - 1415680 _____ (wj32) C:\Program Files\IRJS8N3R.exe
2015-09-21 13:58 - 2015-09-21 13:58 - 1415680 _____ (wj32) C:\Program Files\MNOHIJGH.exe
2015-07-22 13:25 - 2015-07-22 13:25 - 1415680 _____ (wj32) C:\Program Files\YIWGU8PH.exe
2013-12-20 12:04 - 2014-10-22 23:47 - 0007605 _____ () C:\Users\Rifandi\AppData\Local\Resmon.ResmonCfg
2013-12-22 10:35 - 2013-12-22 10:35 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
 
Some files in TEMP:
====================
C:\Users\Rifandi\AppData\Local\Temp\sqlite3.dll
 
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-09-24 10:29
 
==================== End of FRST.txt ============================
 
 
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version:23-09-2015
Ran by Rifandi (2015-09-24 17:50:56)
Running from C:\Users\Rifandi\Desktop
Windows 8.1 Pro (X64) (2013-12-20 04:58:43)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-1232603322-3645337139-1979953262-500 - Administrator - Disabled)
Guest (S-1-5-21-1232603322-3645337139-1979953262-501 - Limited - Disabled)
Rifandi (S-1-5-21-1232603322-3645337139-1979953262-1001 - Administrator - Enabled) => C:\Users\Rifandi
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
µTorrent (HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\uTorrent) (Version: 3.4.2.35702 - BitTorrent Inc.)
7-Zip 9.22beta (HKLM-x32\...\7-Zip) (Version:  - )
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.1.0.4880 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.134 - Adobe Systems Incorporated)
Adobe Help Manager (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 4.0.244 - Adobe Systems Incorporated)
Adobe Widget Browser (HKLM-x32\...\com.adobe.WidgetBrowser) (Version: 2.0 Build 348 - Adobe Systems Incorporated.)
Ambulant Player 2.4 (HKLM-x32\...\Ambulant Player 2.4) (Version: 2.4 - Centrum voor Wiskunde en Informatica)
Apache Tomcat 8.0.15 (HKLM-x32\...\nbi-tomcat-8.0.15.0.0) (Version:  - )
Apple Application Support (HKLM-x32\...\{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}) (Version: 2.3.4 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Artificial Girl 3 (HKLM-x32\...\{9F0B447F-7E14-4BB9-BCFE-1D5C06F7EE35}) (Version: 1.5 - ILLUSION)
Battlefield 4 Update 1 (HKLM-x32\...\QmF0dGxlZmllbGQ0_is1) (Version: 1 - )
bl (x32 Version: 1.0.0 - Your Company Name) Hidden
Blend for Visual Studio 2012 (x32 Version: 5.0.30709.0 - Microsoft Corporation) Hidden
Blend for Visual Studio 2012 ENU resources (x32 Version: 5.0.30709.0 - Microsoft Corporation) Hidden
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Cheat Engine 6.4 (HKLM-x32\...\Cheat Engine 6.4_is1) (Version:  - Cheat Engine)
Cisco Packet Tracer 5.3.3 (HKLM-x32\...\Cisco Packet Tracer 5.3.3_is1) (Version:  - Cisco Systems, Inc.)
CodeBlocks (HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\CodeBlocks) (Version: 12.11 - The Code::Blocks Team)
Corel Graphics - Windows Shell Extension (HKLM-x32\...\_{B6BFCD02-BA0E-41A9-9C9C-6624C4BB475F}) (Version: 15.2.0.686 - Corel Corporation)
Corel Graphics - Windows Shell Extension (x32 Version: 15.2.686 - Corel Corporation) Hidden
Corel Graphics - Windows Shell Extension 64 Bit (Version: 15.2.686 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Capture (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Common (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Connect (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Custom Data (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Draw (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - EN (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Filters (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - FontNav (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - IPM (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - PHOTO-PAINT (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Photozoom Plugin (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Redist (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Setup Files (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - VBA (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - VideoBrowser (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - VSTA (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - WT (x32 Version: 15.3 -  Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW® Graphics Suite X5 (HKLM-x32\...\_{CE54DCE1-E00A-4D91-ACB9-A2D916C24051}) (Version: 15.2.0.686 - Corel Corporation)
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.48.1.0347 - Disc Soft Ltd)
Devil May Cry 5 - Complete Edition version 1.0.0 (HKLM-x32\...\Devil May Cry 5 - Complete Edition_is1) (Version: 1.0.0 - Capcom)
Dolby Digital Plus Home Theater (HKLM\...\{7E3D8FA1-6092-469A-955B-68FC4A2C67CA}) (Version: 7.3.2.2 - Dolby Laboratories Inc)
Dolphin 4.0 (HKLM-x32\...\Dolphin) (Version: 4.0 - Dolphin Development Team)
Dota 2 (HKLM-x32\...\Steam App 570) (Version:  - Valve)
Dotfuscator and Analytics Community Edition (x32 Version: 5.5.4521.29298 - PreEmptive Solutions) Hidden
Dragonball Xenoverse (HKLM-x32\...\Dragonball Xenoverse_is1) (Version:  - )
DreadOut (HKLM-x32\...\DreadOut_is1) (Version:  - )
Dropbox (HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\Dropbox) (Version: 2.6.24 - Dropbox, Inc.)
Empire Earth III (HKLM-x32\...\{B17E235C-7A3B-4482-B650-21FFDE1D452E}) (Version: 1.00.0000 - Sierra Entertainment)
Energy Management (HKLM-x32\...\InstallShield_{D0956C11-0F60-43FE-99AD-524E833471BB}) (Version: 8.0.2.14 - Lenovo)
Energy Management (x32 Version: 8.0.2.14 - Lenovo) Hidden
Entity Framework Designer for Visual Studio 2012 - enu (HKLM-x32\...\{0A1A1D48-DB23-443A-BC7B-49255D138020}) (Version: 11.1.20702.00 - Microsoft Corporation)
GlassFish Server Open Source Edition 4.1 (HKLM-x32\...\nbi-glassfish-mod-4.1.0.13.0) (Version:  - )
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 45.0.2454.99 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.28.15 - Google Inc.) Hidden
GReaatsaver (HKLM-x32\...\{CA41BB14-E67B-1653-C57B-5CA99418A866}) (Version: 4.3.0.1718 - gureATsuavear) <==== ATTENTION
HSPA Modem version 1.5 (HKLM-x32\...\3G Connect Normal Version 6280 USB_is1) (Version:  - )
IIS 8.0 Express (HKLM\...\{7BF61FA9-BDFB-4563-98AD-FCB0DA28CCC7}) (Version: 8.0.1557 - Microsoft Corporation)
IIS Express Application Compatibility Database for x64 (HKLM\...\{9f4f4a9b-eec5-4906-92fe-d1f43ccf5c8d}.sdb) (Version:  - )
IIS Express Application Compatibility Database for x86 (HKLM\...\{fdfba1f3-74ae-4255-9c10-a0f552b4610f}.sdb) (Version:  - )
ILLUSION ワケあり! (HKLM-x32\...\{FD1E17BC-2956-4AD7-B937-D23F06F1A5E8}) (Version: 1.00.0000 - ILLUSION)
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.13.1706 - Intel Corporation)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3277 - Intel Corporation)
Intel® PROSet/Wireless Software for Bluetooth® Technology (HKLM\...\{DA2600C1-6BDF-4FD1-8F3D-148929CC1385}) (Version: 2.6.1210.0278 - Intel Corporation)
Internet Download Manager (HKLM-x32\...\Internet Download Manager) (Version:  - Tonec Inc.)
Java 8 Update 45 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418045F0}) (Version: 8.0.450 - Oracle Corporation)
Java SE Development Kit 8 Update 45 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0180450}) (Version: 8.0.450.15 - Oracle Corporation)
Join Air (HKLM-x32\...\{A9E5EDA7-2E6C-49E7-924B-A32B89C24A04}) (Version: 1.0.0.2 - ZTE)
Just Cause 2 (HKLM-x32\...\Just Cause 2_is1) (Version:  - R.G.Âèíòèê è Øïóíòèê)
LocalESPC (x32 Version: 8.59.25584 - Microsoft Corporation) Hidden
LocalESPCui for en-us (x32 Version: 8.59.25584 - Microsoft) Hidden
Macromedia Dreamweaver 8 (HKLM-x32\...\{0837A661-FEC3-48B3-876C-91E7D32048A9}) (Version: 8.0.0.2734 - Macromedia)
Macromedia Extension Manager (HKLM-x32\...\{5546CDB5-2CE2-498B-B059-5B3BF81FC41F}) (Version: 1.7.240 - Macromedia, Inc.)
Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\...\{5CBFF3F3-2D40-34EE-BCA5-A95BC19E400D}) (Version: 4.5.50709 - Microsoft Corporation)
Microsoft .NET Framework 4.5 SDK (HKLM-x32\...\{1948E039-EC79-4591-951D-9867A8C14C90}) (Version: 4.5.50709 - Microsoft Corporation)
Microsoft ASP.NET MVC 3 (HKLM-x32\...\{DCDEC776-BADD-48B9-8F9A-DFF513C3D7FA}) (Version: 3.0.20105.0 - Microsoft Corporation)
Microsoft ASP.NET Web Pages (HKLM-x32\...\{631471BE-DEAB-454B-A9AC-CE3EB42C28B3}) (Version: 1.0.20105.0 - Microsoft Corporation)
Microsoft Help Viewer 2.0 (HKLM-x32\...\Microsoft Help Viewer 2.0) (Version: 2.0.50727 - Microsoft Corporation)
Microsoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.10411.0 - Microsoft Corporation)
Microsoft Silverlight 4 SDK (HKLM-x32\...\{189AEA94-DAFB-487A-8CEE-F9D3DDE0A748}) (Version: 4.0.60310.0 - Microsoft Corporation)
Microsoft Silverlight 5 SDK (HKLM-x32\...\{E1FBB3D4-ADB0-4949-B101-855DA061C735}) (Version: 5.0.61118.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Command Line Utilities  (HKLM\...\{9D573E71-1077-4C7E-B4DB-4E22A5D2B48B}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 Data-Tier App Framework  (HKLM\...\{36E619BC-A234-4EC3-849B-779A7C865A45}) (Version: 11.0.2316.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Data-Tier App Framework  (HKLM-x32\...\{FBA6F90E-36EC-4FC9-9B25-3834E3BD46A8}) (Version: 11.0.2316.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Express LocalDB  (HKLM\...\{13D558FE-A863-402C-B115-160007277033}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 Management Objects  (HKLM-x32\...\{DA1C1761-5F4F-4332-AB9D-29EDF3F8EA0A}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 Management Objects  (x64) (HKLM\...\{FA0A244E-F3C2-4589-B42A-3D522DE79A42}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 Native Client  (HKLM\...\{49D665A2-4C2A-476E-9AB8-FCC425F526FC}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 Transact-SQL Compiler Service  (HKLM\...\{BEB0F91E-F2EA-48A1-B938-7857ABF2A93D}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 Transact-SQL ScriptDom  (HKLM\...\{0E8670B8-3965-4930-ADA6-570348B67153}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 T-SQL Language Service  (HKLM-x32\...\{6D6D43E5-218C-4B05-92D3-2240810F4760}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server Compact 4.0 SP1 x64 ENU (HKLM\...\{78909610-D229-459C-A936-25D92283D3FD}) (Version: 4.0.8876.1 - Microsoft Corporation)
Microsoft SQL Server Data Tools - enu (11.1.20627.00) (HKLM-x32\...\{FA804794-2CCB-4301-954F-2C2894698876}) (Version: 11.1.20627.00 - Microsoft Corporation)
Microsoft SQL Server Data Tools Build Utilities - enu (11.1.20627.00) (HKLM-x32\...\{790E9425-8570-493F-9AE7-81AFC9E46930}) (Version: 11.1.20627.00 - Microsoft Corporation)
Microsoft SQL Server System CLR Types (HKLM-x32\...\{A47FD1BF-A815-4A76-BE65-53A15BD5D25D}) (Version: 10.50.1600.1 - Microsoft Corporation)
Microsoft SQL Server System CLR Types (x64) (HKLM\...\{4701DEDE-1888-49E0-BAE5-857875924CA2}) (Version: 10.50.1600.1 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2012 (HKLM-x32\...\{E2082604-4BA5-44BB-BBFB-AF0F3CB8C6AB}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2012 (x64) (HKLM\...\{F1949145-EB64-4DE7-9D81-E6D27937146C}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 Redistributable - x64 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 Redistributable - x86 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.31125 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2.0 - ENU (HKLM-x32\...\{AA4A4B2C-0465-3CF8-BA76-27A027D8ACAB}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2.0 Runtime (HKLM-x32\...\{299C0434-4F4E-341F-A916-4E07AEB35E79}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual Studio Ultimate 2012 (HKLM-x32\...\{ae17ae9b-af38-40d2-a194-6102c56ed502}) (Version: 11.0.50727.26 - Microsoft Corporation)
Microsoft Web Deploy 3.0 (HKLM\...\{AA72C306-30BE-4BB1-9E42-59552BAD2CDF}) (Version: 3.1236.1631 - Microsoft Corporation)
Microsoft Web Deploy dbSqlPackage Provider - enu (HKLM-x32\...\{E4C33F5B-1B2F-466E-957E-B274F08151A0}) (Version: 10.3.20225.0 - Microsoft Corporation)
Microsoft Web Platform Installer 4.0 (HKLM\...\{E2B8249D-895C-4685-8C83-00F3B1A13028}) (Version: 4.0.1622 - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
Middle-Earth - Shadow of Mordor (by Hommy Games) (HKLM-x32\...\{3E74CDB4-8B8F-4640-BE71-4B66886615F7}_is1) (Version: 1.0.1636.20 - )
Mozilla Firefox 36.0.4 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 36.0.4 (x86 en-US)) (Version: 36.0.4 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
MPC-HC 1.7.1 (64-bit) (HKLM\...\{2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1) (Version: 1.7.1.0 - MPC-HC Team)
Need for Speed™ Carbon (HKLM-x32\...\{259C0ABB-A3B2-4D70-008F-BF7EE491B70B}) (Version:  - )
NetBeans IDE 8.0.2 (HKLM-x32\...\nbi-nb-base-8.0.2.0.201411181905) (Version: 8.0.2 - NetBeans.org)
Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.47.3 - Black Tree Gaming)
Notepad++ (HKLM-x32\...\Notepad++) (Version: 5.9.6.2 - )
NVIDIA 3D Vision Driver 337.88 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 337.88 - NVIDIA Corporation)
NVIDIA GeForce Experience 2.1.5 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.1.5 - NVIDIA Corporation)
NVIDIA Graphics Driver 337.88 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 337.88 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation)
Oracle VM VirtualBox 4.3.16 (HKLM\...\{D7FAEA32-7CE3-4D9F-9139-F7B87BCC50AF}) (Version: 4.3.16 - Oracle Corporation)
Origin (HKLM-x32\...\Origin) (Version: 9.4.1.116 - Electronic Arts, Inc.)
PCSX2 - Playstation 2 Emulator (HKLM-x32\...\pcsx2-r5875) (Version:  - )
ph (x32 Version: 1.0.0 - Your Company Name) Hidden
PreEmptive Analytics Visual Studio Components (x32 Version: 1.0.2180.1 - PreEmptive Solutions) Hidden
Prerequisites for SSDT  (HKLM-x32\...\{9169C939-ED01-446A-BD0C-29873BAF4E48}) (Version: 11.0.2100.60 - Microsoft Corporation)
Pro Evolution Soccer 2015 (HKLM-x32\...\UHJvRXZvbHV0aW9uU29jY2VyMjAxNQ==_is1) (Version: 1 - )
Prototype 2 (HKLM-x32\...\Prototype 2_is1) (Version: Prototype 2 - )
Qualcomm Atheros Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 10.0 - Qualcomm Atheros)
QuickTime (HKLM-x32\...\{B67BAFBA-4C9F-48FA-9496-933E3B255044}) (Version: 7.74.80.86 - Apple Inc.)
Rainmeter (HKLM-x32\...\Rainmeter) (Version: 3.1 r2290 - )
RapeLay (remove only) (HKLM-x32\...\RapeLay) (Version:  - )
RAR Password Recovery v1.1 RC16 (remove only) (HKLM-x32\...\Intelore - RAR Password Recovery) (Version:  - )
RAR Password Unlocker 4.2.0.0 (HKLM-x32\...\{B789FA51-6A71-408F-92DE-EDE4A517B8F9}_is1) (Version:  - Password Unlocker Studio)
Razer Game Booster (HKLM-x32\...\Razer Game Booster_is1) (Version: 4.1.59.0 - Razer Inc.)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9200.39048 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.2.612.2012 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7027 - Realtek Semiconductor Corp.)
Safari (HKLM-x32\...\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.)
SavePass 1.1 (HKLM-x32\...\SavePass 1.1) (Version: 1.35.3.9 - OB) <==== ATTENTION
School Mate 2 (HKLM-x32\...\{BC980840-FC67-4027-9055-251136406614}_is1) (Version: 1.3 - randompirate)
Sexy Beach 3 - Complete English Edition (remove only) (HKLM-x32\...\Sexy Beach 3 - Complete English Edition) (Version:  - )
SHIELD Streaming (Version: 3.1.3000 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 16.18.9 - NVIDIA Corporation) Hidden
SPORE™ (HKLM-x32\...\{9DF0196F-B6B8-4C3A-8790-DE42AA530101}) (Version: 1.00.0000 - Electronic Arts)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Stronghold Crusader 2 (HKLM-x32\...\Stronghold Crusader 2_is1) (Version: 1.0 - PLAZA)
System Requirements Lab Detection (HKLM-x32\...\{2C9D426D-3F38-4B1A-BAC5-DEC1212BB852}) (Version: 2.2.4.0 - Husdawg, LLC)
TELKOMSELFlash SU-9000 version 5.117 (HKLM-x32\...\TELKOMSELFlash SU-9000 version_is1) (Version:  - )
The Sims" 3 (HKLM-x32\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.63.5 - Electronic Arts)
The Sims" 3 70s, 80s, & 90s Stuff (HKLM-x32\...\{E1868CAE-E3B9-4099-8C18-AA8944D336FD}) (Version: 17.0.77 - Electronic Arts)
The Sims" 3 Ambitions (HKLM-x32\...\{910F4A29-1134-49E0-AD8B-56E4A3152BD1}) (Version: 4.0.87 - Electronic Arts)
The Sims" 3 Diesel Stuff (HKLM-x32\...\{1C9B6173-6DC9-4EEE-9EFC-6BA115CFBE43}) (Version: 14.0.48 - Electronic Arts)
The Sims" 3 Fast Lane Stuff (HKLM-x32\...\{ED436EA8-4145-4703-AE5D-4D09DD24AF5A}) (Version: 5.0.44 - Electronic Arts)
The Sims" 3 Generations (HKLM-x32\...\{E6B88BD6-E4B2-4701-A648-B6DAC6E491CC}) (Version: 8.0.152 - Electronic Arts)
The Sims" 3 High-End Loft Stuff (HKLM-x32\...\{71828142-5A24-4BD0-97E7-976DA08CE6CF}) (Version: 3.0.38 - Electronic Arts)
The Sims" 3 Into the Future (HKLM-x32\...\{A0BBD6C7-B546-4048-B33A-F21F5C9F5B09}) (Version: 21.0.150 - Electronic Arts)
The Sims" 3 Island Paradise (HKLM-x32\...\{DB21639E-FE55-432C-BCA2-0C5249E3F79E}) (Version: 19.0.101 - Electronic Arts)
The Sims" 3 Katy Perry's Sweet Treats (HKLM-x32\...\{9B2506E3-9A3F-45B5-96BF-509CAD584650}) (Version: 13.0.62 - Electronic Arts)
The Sims" 3 Late Night (HKLM-x32\...\{45057FCE-5784-48BE-8176-D9D00AF56C3C}) (Version: 6.0.81 - Electronic Arts)
The Sims" 3 Master Suite Stuff (HKLM-x32\...\{08A25478-C5DD-4EA7-B168-3D687CA987FF}) (Version: 11.0.84 - Electronic Arts)
The Sims" 3 Movie Stuff (HKLM-x32\...\{D0087539-3C57-44E0-BEE7-D779D546CBE1}) (Version: 20.0.53 - Electronic Arts)
The Sims" 3 Outdoor Living Stuff (HKLM-x32\...\{117B6BF6-82C3-420C-B284-9247C8568E53}) (Version: 7.0.55 - Electronic Arts)
The Sims" 3 Pets (HKLM-x32\...\{C12631C6-804D-4B32-B0DD-8A496462F106}) (Version: 10.0.96 - Electronic Arts)
The Sims" 3 Seasons (HKLM-x32\...\{3DE92282-CB49-434F-81BF-94E5B380E889}) (Version: 16.0.136 - Electronic Arts)
The Sims" 3 Showtime (HKLM-x32\...\{3BBFD444-5FAB-49F6-98B1-A1954E831399}) (Version: 12.0.273 - Electronic Arts)
The Sims" 3 Supernatural (HKLM-x32\...\{B37DAFA5-717D-41F8-BDFB-3A4B68C0B3A1}) (Version: 15.0.135 - Electronic Arts)
The Sims" 3 Town Life Stuff (HKLM-x32\...\{7B11296A-F894-449C-8DF6-6AAAA7D4D118}) (Version: 9.0.73 - Electronic Arts)
The Sims" 3 University Life (HKLM-x32\...\{F26DE8EF-F2CF-40DC-8CDA-CC0D82D11B36}) (Version: 18.0.126 - Electronic Arts)
The Sims" 3 World Adventures (HKLM-x32\...\{BA26FFA5-6D47-47DB-BE56-34C357B5F8CC}) (Version: 2.0.86 - Electronic Arts)
The Sims™ 3 + Expansions Uninstaller (HKLM-x32\...\The Sims™ 3 + Expansions Uninstaller) (Version: 1.0.0.11 - Electronic Arts)
Total Video Converter 3.71 100812 (HKLM-x32\...\Total Video Converter 3.71_is1) (Version:  - EffectMatrix Inc.)
TSEV Skyrim LE (HKLM-x32\...\TSEV Skyrim LE_is1) (Version: 2.0.0.0 - )
UltraISO Premium V9.62 (HKLM-x32\...\UltraISO_is1) (Version:  - )
Unity Web Player (HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\UnityWebPlayer) (Version:  - Unity Technologies ApS)
Update for  (KB2504637) (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
Watch Dogs (HKLM-x32\...\Watch Dogs_R.G. Mechanics_is1) (Version:  - R.G. Mechanics, spider91)
WCF Data Services 5.0 (for OData v3) Primary Components (x32 Version: 5.0.50628.0 - Microsoft Corporation) Hidden
WCF Data Services Tools for Microsoft Visual Studio 2012 (x32 Version: 5.0.50710.0 - Microsoft Corporation) Hidden
WCF RIA Services V1.0 SP2 (HKLM-x32\...\{3A523AF9-D32F-4C85-8388-0335731F3405}) (Version: 4.1.61829.0 - Microsoft Corporation)
Winamp (HKLM-x32\...\Winamp) (Version: 5.666  - Nullsoft, Inc)
Winamp Detector Plug-in (HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc)
Windows 7 USB/DVD Download Tool (HKLM-x32\...\{CCF298AF-9CE1-4B26-B251-486E98A34789}) (Version: 1.0.30 - Microsoft Corporation)
Windows Driver Package - Lenovo (ACPIVPC) System  (02/17/2013 9.52.0.776) (HKLM\...\35DD26BE48DAF4A9F35F969F3CB1E3E1435E661E) (Version: 02/17/2013 9.52.0.776 - Lenovo)
Windows Driver Package - Lenovo (WUDFRd) LenovoVhid  (07/25/2013 10.30.0.288) (HKLM\...\6BCA401E9CBEED970D75F55FA5320F60D11984E9) (Version: 07/25/2013 10.30.0.288 - Lenovo)
WinRAR 5.00 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.00.0 - win.rar GmbH)
WOW Slider (HKLM-x32\...\WOW Slider_is1) (Version:  - )
XAMPP (HKLM-x32\...\xampp) (Version: 1.8.3-2 - BitNami)
YoutubeAdblocker (HKLM-x32\...\{4820778D-AB0D-6D18-C316-52A6A0E1D507}) (Version: 4.2.0.1591 - YoutubeAdblocker) <==== ATTENTION
YoutubeAdblocker (HKLM-x32\...\{CF830981-8F31-C561-C7A0-FE2CE1878B40}) (Version: 4.2.0.1447 - YoutubeAdblocker) <==== ATTENTION
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-1232603322-3645337139-1979953262-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Rifandi\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1232603322-3645337139-1979953262-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Rifandi\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1232603322-3645337139-1979953262-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Rifandi\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1232603322-3645337139-1979953262-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Rifandi\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1232603322-3645337139-1979953262-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Rifandi\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
 
==================== Restore Points =========================
 
ATTENTION: System Restore is disabled
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2013-08-22 20:25 - 2013-08-22 20:25 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {3A8AF67F-D4A2-4830-93C5-666CBB8285DE} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {3B5AD782-9EA1-448B-BCC2-9383C65F05A3} - System32\Tasks\{6BA0FAB1-B899-472D-AFB0-B490EA3BD58D} => pcalua.exe -a "G:\Cai Dat Game\setup.exe" -d "G:\Cai Dat Game"
Task: {3E9BB584-BAB7-4855-AC19-11D577E342ED} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.)
Task: {41A93C16-4B1F-449F-9AD6-AEECC8A9FBE7} - System32\Tasks\{CBE073F7-A1DD-4027-B793-2EE54ADF6B0C} => pcalua.exe -a F:\Sims2EP1\eauninstall.exe -d F:\Sims2EP1
Task: {81DCD15E-230D-458D-9943-3D597965D212} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.)
Task: {96B7DC84-1C5F-4AC1-8EF8-D697CE121B1A} - System32\Tasks\{8627B382-5A88-4FF9-A728-51F1974DF348} => pcalua.exe -a F:\AutoRun.exe -d F:\
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Loaded Modules (Whitelisted) ==============
 
2013-12-22 09:35 - 2014-05-20 08:25 - 00116568 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2014-01-28 01:16 - 2009-08-20 14:22 - 00135168 _____ () C:\Windows\SysWOW64\ChgService.exe
2013-12-21 09:45 - 2009-07-15 09:37 - 00246272 _____ () C:\Program Files (x86)\Join Air\AssistantServices.exe
2013-12-20 19:59 - 2013-08-23 05:07 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2014-05-25 21:18 - 2014-05-25 21:18 - 00036536 ____N () C:\Program Files\Rainmeter\Rainmeter.exe
2014-05-25 21:18 - 2014-05-25 21:18 - 00747192 _____ () C:\Program Files\Rainmeter\Rainmeter.dll
2014-05-25 21:17 - 2014-05-25 21:17 - 00056832 _____ () C:\Program Files\Rainmeter\Plugins\WebParser.dll
2015-09-22 12:39 - 2015-09-19 05:13 - 01501512 _____ () C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.99\libglesv2.dll
2015-09-22 12:39 - 2015-09-19 05:13 - 00081224 _____ () C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.99\libegl.dll
2011-07-19 04:07 - 2011-07-19 04:07 - 00014336 _____ () C:\Program Files (x86)\Notepad++\plugins\NppExport.dll
2011-09-22 03:46 - 2011-09-22 03:46 - 01673728 _____ () C:\Program Files (x86)\Notepad++\plugins\NppFTP.dll
2013-12-20 20:48 - 2013-08-08 13:23 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\ACE.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Rifandi\Downloads\Wallpaper\trafalgar-law-jolly-roger-one-piece.jpg
DNS Servers: 192.168.43.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
HKLM\...\StartupApproved\StartupFolder: => "StartupModem.lnk"
HKLM\...\StartupApproved\Run32: => "UIExec"
HKLM\...\StartupApproved\Run32: => "APSDaemon"
HKLM\...\StartupApproved\Run32: => "QuickTime Task"
HKLM\...\StartupApproved\Run32: => "WinampAgent"
HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\StartupApproved\Run: => "DAEMON Tools Lite"
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{1A06DCD8-8738-438C-8399-A80A5E0B8728}] => (Allow) C:\Program Files (x86)\AVG\AVG2014\avgmfapx.exe
FirewallRules: [{F2AE1ED8-46AE-444B-AB1C-B23A4870D723}] => (Allow) C:\Program Files (x86)\AVG\AVG2014\avgmfapx.exe
FirewallRules: [{09DDA33A-F684-498B-A248-1FF2A010503B}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{9240A9AF-274B-4D6B-80E5-BCEA62BEDD87}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{AB0F5B93-B492-45C8-8B0C-92E9C2A7B5EE}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{8905FE43-37DD-48A5-8C71-4E849017C3B8}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{562750CB-3D48-4CEF-84F8-0554B9BF4601}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{BE82E2D9-F899-4F2B-A3E9-6B44EA1C87CA}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{EC871DAD-58DB-4A2C-BFBC-74D670725D1C}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{97A03C4D-04F4-4878-8797-A2A1557665C8}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{B6F7FC4E-3F4B-4469-98AC-6F6B3877AB22}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{4F0DB9E4-E763-48D4-AF84-14834AFAF53C}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{4A3E9165-9DB0-46EB-890F-DCE89376C612}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{20083BF8-F33B-4932-BBC1-7DAEE01E3710}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{588D0D49-B694-4391-BB67-4F279A9BA92C}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{D7490F1E-D3BA-4A4D-93F6-A6D8A309FEC5}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [TCP Query User{9B45E7F0-30EE-47DD-A6A3-5C61DFE3E55E}D:\games\prototype 2\prototype2.exe] => (Block) D:\games\prototype 2\prototype2.exe
FirewallRules: [UDP Query User{765FB244-EE57-4E0A-A1A8-4254A4AE4C90}D:\games\prototype 2\prototype2.exe] => (Block) D:\games\prototype 2\prototype2.exe
FirewallRules: [TCP Query User{19635119-F6FE-450D-91C7-B69050C4FBAD}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe] => (Allow) C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe
FirewallRules: [UDP Query User{70D36063-2C68-44E0-A9F2-6C99883C4168}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe] => (Allow) C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe
FirewallRules: [TCP Query User{A49822FF-6416-4240-8E79-F95943201E2C}D:\games\konami\pro evolution soccer 2013\pes2013.exe] => (Block) D:\games\konami\pro evolution soccer 2013\pes2013.exe
FirewallRules: [UDP Query User{45DEE90E-9EBF-43F9-8799-998E83696311}D:\games\konami\pro evolution soccer 2013\pes2013.exe] => (Block) D:\games\konami\pro evolution soccer 2013\pes2013.exe
FirewallRules: [{775A3945-A3B4-4B4E-AFDF-0CCC57EB45F9}] => (Allow) %systemroot%\system32\alg.exe
FirewallRules: [TCP Query User{D891051F-84BD-4B10-923F-C293F54DD09E}D:\games\dota\war3.exe] => (Allow) D:\games\dota\war3.exe
FirewallRules: [UDP Query User{4C2C0E42-89CE-488C-8B12-F2392966F600}D:\games\dota\war3.exe] => (Allow) D:\games\dota\war3.exe
FirewallRules: [{27FB2FF6-1E02-4AF4-B515-BE58E7F66AED}] => (Allow) C:\Program Files\KMSpico\KMSELDI.exe
FirewallRules: [{D31A831A-E4FA-41E1-98ED-24EF2D307FDA}] => (Allow) C:\Program Files\KMSpico\KMSELDI.exe
FirewallRules: [{07799367-4E73-4629-B22A-23952A4E3A98}] => (Allow) C:\Program Files\KMSpico\KMSServer.exe
FirewallRules: [{D7FFEC2F-1027-45F8-BF55-9E803B26383D}] => (Allow) C:\Program Files\KMSpico\KMSServer.exe
FirewallRules: [{3E856337-07D0-4D60-B6DE-E6B7F3221DA2}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe
FirewallRules: [{B0BA9B87-C926-41A7-B95D-6428E7C88BA7}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe
FirewallRules: [TCP Query User{E6622835-0D2A-4DEF-9567-5E451F3EA331}C:\program files (x86)\winamp\winamp.exe] => (Block) C:\program files (x86)\winamp\winamp.exe
FirewallRules: [UDP Query User{C9C1066E-BE2F-49CC-99F8-50AAE4B9E3AE}C:\program files (x86)\winamp\winamp.exe] => (Block) C:\program files (x86)\winamp\winamp.exe
FirewallRules: [{E10061AB-4E65-496F-9FE1-55C9ED05FAD8}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe
FirewallRules: [TCP Query User{5FB4513F-2E57-47EF-A0FE-CE5F2E1615B9}C:\program files (x86)\winamp\winamp.exe] => (Block) C:\program files (x86)\winamp\winamp.exe
FirewallRules: [UDP Query User{25006CC4-CE19-4424-946D-E20E4C243FD1}C:\program files (x86)\winamp\winamp.exe] => (Block) C:\program files (x86)\winamp\winamp.exe
FirewallRules: [TCP Query User{CC65259C-1AA7-4F1C-9436-334BFA693245}D:\games\battle field 4\bf4_x86.exe] => (Block) D:\games\battle field 4\bf4_x86.exe
FirewallRules: [UDP Query User{E807EE63-8880-4009-AD1C-0BC5990364D9}D:\games\battle field 4\bf4_x86.exe] => (Block) D:\games\battle field 4\bf4_x86.exe
FirewallRules: [TCP Query User{66E425DA-B20D-4E19-9180-7A976439C34B}D:\games\left 4 dead\left4dead.exe] => (Block) D:\games\left 4 dead\left4dead.exe
FirewallRules: [UDP Query User{3A2BEAC6-C02C-4634-B01A-AE94B750A88E}D:\games\left 4 dead\left4dead.exe] => (Block) D:\games\left 4 dead\left4dead.exe
FirewallRules: [{8EC7C0D2-469D-425A-B1B6-B81075B83C37}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe
FirewallRules: [{0EB4AB0D-4A4A-4D49-B669-6857DFBAAA39}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe
FirewallRules: [{971E3028-9FB4-4F27-9B29-7DBC1424F8A5}] => (Allow) C:\Windows\System32\KMSServer.exe
FirewallRules: [{213EADAA-1CFE-4D58-9E21-C09621DE09D5}] => (Allow) C:\Windows\System32\KMSServer.exe
FirewallRules: [{EBCA317D-CC83-43ED-AAE3-74866A4DFFD5}] => (Allow) D:\GAMES\Dragon Nest SEA\DragonNest.exe
FirewallRules: [{E6B27D11-BF45-4183-A96A-5CB3D7C3791D}] => (Allow) D:\GAMES\Dragon Nest SEA\DragonNest.exe
FirewallRules: [{CCC5C3B9-E51F-4B73-8BC1-2D66C70840D9}] => (Allow) D:\GAMES\Dragon Nest SEA\DragonNest.exe
FirewallRules: [{B16D292D-99B8-4EA4-AC6F-0B9132F3EE53}] => (Allow) D:\GAMES\Dragon Nest SEA\DragonNest.exe
FirewallRules: [TCP Query User{90F7424A-8CFA-4BB1-BA55-EB24C74E71F7}D:\game installer\ygopro-1.032.1-v2-percy-full\ygopro_vs.exe] => (Allow) D:\game installer\ygopro-1.032.1-v2-percy-full\ygopro_vs.exe
FirewallRules: [UDP Query User{D4C32738-7C8E-4867-9329-62743A543310}D:\game installer\ygopro-1.032.1-v2-percy-full\ygopro_vs.exe] => (Allow) D:\game installer\ygopro-1.032.1-v2-percy-full\ygopro_vs.exe
FirewallRules: [TCP Query User{BA753D81-75AA-4A12-9D7F-A2D1DAD7E556}D:\games\prototype 2\prototype2.exe] => (Block) D:\games\prototype 2\prototype2.exe
FirewallRules: [UDP Query User{185D5014-4109-4234-AA47-1DDBFF073CA9}D:\games\prototype 2\prototype2.exe] => (Block) D:\games\prototype 2\prototype2.exe
FirewallRules: [{DF926D87-1BE0-4685-88BB-E8509C8AA040}] => (Allow) C:\Program Files\KMSnano\qemu-system-i386.exe
FirewallRules: [{69799192-0148-4AFD-90AF-84E0FB23EB56}] => (Allow) C:\Program Files\KMSnano\qemu-system-i386.exe
FirewallRules: [TCP Query User{AF03422E-9BCC-4E54-A80E-890A78693EDF}C:\xampp\apache\bin\httpd.exe] => (Allow) C:\xampp\apache\bin\httpd.exe
FirewallRules: [UDP Query User{1BB7E18C-5720-4F80-A26C-4B4D6759F5F1}C:\xampp\apache\bin\httpd.exe] => (Allow) C:\xampp\apache\bin\httpd.exe
FirewallRules: [TCP Query User{98AAD854-2D55-4A73-AC8D-7A754DCE2A6E}C:\xampp\mysql\bin\mysqld.exe] => (Allow) C:\xampp\mysql\bin\mysqld.exe
FirewallRules: [UDP Query User{22279E3E-2B1E-4548-947E-861FE12B4F2E}C:\xampp\mysql\bin\mysqld.exe] => (Allow) C:\xampp\mysql\bin\mysqld.exe
FirewallRules: [TCP Query User{20ACCA7D-677B-49C4-9FBB-1054D7DCC002}C:\xampp\filezillaftp\filezillaserver.exe] => (Block) C:\xampp\filezillaftp\filezillaserver.exe
FirewallRules: [UDP Query User{51AE80A9-24F9-41FC-B991-C92BA2F16493}C:\xampp\filezillaftp\filezillaserver.exe] => (Block) C:\xampp\filezillaftp\filezillaserver.exe
FirewallRules: [TCP Query User{FAAC8729-32D6-4E1E-B3A1-33EE26EC6DA9}C:\xampp\mercurymail\mercury.exe] => (Block) C:\xampp\mercurymail\mercury.exe
FirewallRules: [UDP Query User{6B59466B-7787-460A-8135-8584676DDD3D}C:\xampp\mercurymail\mercury.exe] => (Block) C:\xampp\mercurymail\mercury.exe
FirewallRules: [TCP Query User{B34030A8-37BC-4369-8E40-9E8593FCA786}D:\game installer\yu-gi-oh!\ygopro-1.032.1-v2-percy-full\ygopro_vs.exe] => (Allow) D:\game installer\yu-gi-oh!\ygopro-1.032.1-v2-percy-full\ygopro_vs.exe
FirewallRules: [UDP Query User{1BC3E71A-6D5B-4055-A44D-20339D07333B}D:\game installer\yu-gi-oh!\ygopro-1.032.1-v2-percy-full\ygopro_vs.exe] => (Allow) D:\game installer\yu-gi-oh!\ygopro-1.032.1-v2-percy-full\ygopro_vs.exe
FirewallRules: [{59C6CA05-CDA7-4977-AAA5-F11DEBD92122}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\devenv.exe
FirewallRules: [{3946D93A-3163-47B2-AE52-0217794C2B3F}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\devenv.exe
FirewallRules: [{826D336A-FEFC-43BF-982B-BF5195301D96}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\devenv.exe
FirewallRules: [{38A36E27-11A4-455B-8519-9D9B9B6F35A4}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\devenv.exe
FirewallRules: [{DDF81497-B651-4F9B-872E-FEFDD9489202}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\devenv.exe
FirewallRules: [{2C6D4CCD-4DD9-47E8-9148-DE1C59A5A4AE}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\devenv.exe
FirewallRules: [{1D0F16D8-87B1-45A6-A597-ECA32834DB8D}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\devenv.exe
FirewallRules: [TCP Query User{DDFCA80E-0E24-4BD5-BC1C-91CEB65A42B6}D:\games\farcry 3\bin\farcry3_d3d11.exe] => (Block) D:\games\farcry 3\bin\farcry3_d3d11.exe
FirewallRules: [UDP Query User{7BDAB37E-85AD-47D5-9232-DA4FBE791CC8}D:\games\farcry 3\bin\farcry3_d3d11.exe] => (Block) D:\games\farcry 3\bin\farcry3_d3d11.exe
FirewallRules: [{F6ACCA3B-0F7F-4BCB-9202-2382097D23B1}] => (Allow) C:\Users\Rifandi\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{A835423B-9920-4C72-86A3-2FDE848D1AD0}] => (Allow) C:\Users\Rifandi\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [TCP Query User{0B1F268B-D381-43B7-96D5-8091703066EC}D:\games\divinity original sin\shipping\eocapp.exe] => (Block) D:\games\divinity original sin\shipping\eocapp.exe
FirewallRules: [UDP Query User{6306DE96-53C2-439D-A523-9E26BFC2D7D2}D:\games\divinity original sin\shipping\eocapp.exe] => (Block) D:\games\divinity original sin\shipping\eocapp.exe
FirewallRules: [TCP Query User{08EE761A-7CD2-49B4-8627-8534CC0A0158}H:\game installer\yu-gi-oh!\ygopro-1.032.1-v2-percy-full\ygopro_vs.exe] => (Block) H:\game installer\yu-gi-oh!\ygopro-1.032.1-v2-percy-full\ygopro_vs.exe
FirewallRules: [UDP Query User{63B09064-974F-4436-B236-ABE88D1D683F}H:\game installer\yu-gi-oh!\ygopro-1.032.1-v2-percy-full\ygopro_vs.exe] => (Block) H:\game installer\yu-gi-oh!\ygopro-1.032.1-v2-percy-full\ygopro_vs.exe
FirewallRules: [TCP Query User{F1617650-D557-4FD9-910D-86489DA5B55A}D:\games\outlast\outlast\binaries\win64\olgame.exe] => (Allow) D:\games\outlast\outlast\binaries\win64\olgame.exe
FirewallRules: [UDP Query User{F0C3E966-0FA0-4118-AE9B-45599BC8E5EB}D:\games\outlast\outlast\binaries\win64\olgame.exe] => (Allow) D:\games\outlast\outlast\binaries\win64\olgame.exe
FirewallRules: [{515B5948-489D-48C0-9607-0E2E1BBCC843}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
FirewallRules: [{4A95A6AD-35AF-4038-BA25-01A1ADA3EAB6}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
FirewallRules: [{2A58B125-FA27-4763-923F-962854AC4C64}] => (Allow) C:\Users\Rifandi\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{16606177-8490-41B5-8A89-817542833D73}] => (Allow) C:\Users\Rifandi\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [TCP Query User{1B01E919-DD5D-4C53-9A08-6FA46EC14E69}C:\program files (x86)\stronghold crusader 2\bin\win32_release\crusader2.exe] => (Block) C:\program files (x86)\stronghold crusader 2\bin\win32_release\crusader2.exe
FirewallRules: [UDP Query User{983E342C-763C-4F85-B0F9-48B66631F44F}C:\program files (x86)\stronghold crusader 2\bin\win32_release\crusader2.exe] => (Block) C:\program files (x86)\stronghold crusader 2\bin\win32_release\crusader2.exe
FirewallRules: [TCP Query User{9C6A7B15-3DE6-4258-9CE7-8FCCBBDE7FE6}D:\games\stronghold crusader 2\bin\win32_release\crusader2.exe] => (Allow) D:\games\stronghold crusader 2\bin\win32_release\crusader2.exe
FirewallRules: [UDP Query User{CB15A0A3-D243-43D8-9621-0FFD3B91B959}D:\games\stronghold crusader 2\bin\win32_release\crusader2.exe] => (Allow) D:\games\stronghold crusader 2\bin\win32_release\crusader2.exe
FirewallRules: [{CE95B2B9-8A50-4D43-A53B-967115E4BA08}] => (Allow) D:\GAMES\Sierra Entertainment\Empire Earth III\EE3.exe
FirewallRules: [{743E21E2-9067-4D72-9CB8-58CC60AF37F4}] => (Allow) D:\GAMES\Sierra Entertainment\Empire Earth III\EE3.exe
FirewallRules: [{53AF91DF-0050-4B9B-8981-DF6F4FB160B9}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{3A971CE2-F559-42D0-93F3-4A2365E792F8}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{8BEE11D2-7F86-4B46-9669-E96517FC5AB7}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{6F618C98-4506-4A99-98C2-AAE190AA3A9B}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{FFBFA651-18E8-4F3C-BDD7-0BB25117FE71}] => (Allow) D:\GAMES\SteamLibrary\steamapps\common\dota 2 beta\dota.exe
FirewallRules: [{E83DC855-BB23-47A9-85A7-E165E628CA83}] => (Allow) D:\GAMES\SteamLibrary\steamapps\common\dota 2 beta\dota.exe
FirewallRules: [TCP Query User{C438FD29-9201-4750-BCE5-C78BD9D3DB2B}C:\program files (x86)\cisco packet tracer 5.3.3\bin\packettracer5.exe] => (Block) C:\program files (x86)\cisco packet tracer 5.3.3\bin\packettracer5.exe
FirewallRules: [UDP Query User{DC7E8C51-20F3-4920-BE94-5FD0B64F8789}C:\program files (x86)\cisco packet tracer 5.3.3\bin\packettracer5.exe] => (Block) C:\program files (x86)\cisco packet tracer 5.3.3\bin\packettracer5.exe
FirewallRules: [TCP Query User{4F71FC4A-674D-4914-9235-9C566EF79522}D:\games\battle field 4\bf4.exe] => (Allow) D:\games\battle field 4\bf4.exe
FirewallRules: [UDP Query User{CD03D387-6214-43AC-8C63-B342DF7E224A}D:\games\battle field 4\bf4.exe] => (Allow) D:\games\battle field 4\bf4.exe
FirewallRules: [TCP Query User{406C305E-219C-4CF8-AA6D-FEE4ADAF9D6A}D:\games\company of heroes\bugreport\bugreport.exe] => (Block) D:\games\company of heroes\bugreport\bugreport.exe
FirewallRules: [UDP Query User{0C7D59B2-DDA8-434C-8400-65A342A9D1F2}D:\games\company of heroes\bugreport\bugreport.exe] => (Block) D:\games\company of heroes\bugreport\bugreport.exe
FirewallRules: [{9DDF3AC0-45AA-4706-83DD-4AB1E6C059D0}] => (Allow) D:\GAMES\SteamLibrary\steamapps\common\Aura Kingdom\game.bin
FirewallRules: [{7C11A026-5E0B-469C-8101-39A26E6AF45F}] => (Allow) D:\GAMES\SteamLibrary\steamapps\common\Aura Kingdom\game.bin
FirewallRules: [TCP Query User{F6389871-CABA-428C-A860-FD222EC6B270}D:\games\pro evolution soccer 2015\pes2015.exe] => (Block) D:\games\pro evolution soccer 2015\pes2015.exe
FirewallRules: [UDP Query User{8BE9F98D-8DA0-4C44-A98D-6497171661EF}D:\games\pro evolution soccer 2015\pes2015.exe] => (Block) D:\games\pro evolution soccer 2015\pes2015.exe
FirewallRules: [TCP Query User{3D794DA7-A0BF-4E42-A700-1F93299411F4}D:\games\devil may cry 5 - complete edition\binaries\win32\dmc-devilmaycry.exe] => (Allow) D:\games\devil may cry 5 - complete edition\binaries\win32\dmc-devilmaycry.exe
FirewallRules: [UDP Query User{F05D44A1-7268-4885-9BD1-2CC2F50C04B9}D:\games\devil may cry 5 - complete edition\binaries\win32\dmc-devilmaycry.exe] => (Allow) D:\games\devil may cry 5 - complete edition\binaries\win32\dmc-devilmaycry.exe
FirewallRules: [{EE0F8D63-27BE-4EF2-8BDE-26AA454297C0}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{7605257A-3D4B-49AB-B2DD-132CCB812A10}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{9A5B1E8A-B31F-4B38-B6D9-5E00A45FF065}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{BD3755B2-254D-4C99-9AB3-6C9A3CB42267}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{44D20B8C-A835-4767-9306-134F953356F9}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe
FirewallRules: [{B3303EAD-5EE2-461A-AAF0-CB56CCE10C86}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe
FirewallRules: [{A41FF3C1-CF80-4D64-956E-D623EBA66A93}] => (Allow) C:\Windows\System32\KMSServer.exe
FirewallRules: [{B9C6AC4A-06A8-44A3-A2D7-910AC3D1DEAA}] => (Allow) C:\Windows\System32\KMSServer.exe
FirewallRules: [TCP Query User{CB038158-67D6-4066-B1EF-B01AEB8547E0}C:\program files (x86)\java\jdk1.7.0_40\bin\java.exe] => (Allow) C:\program files (x86)\java\jdk1.7.0_40\bin\java.exe
FirewallRules: [UDP Query User{355E4826-AEF9-4DE1-91C3-3545BEC33CB1}C:\program files (x86)\java\jdk1.7.0_40\bin\java.exe] => (Allow) C:\program files (x86)\java\jdk1.7.0_40\bin\java.exe
FirewallRules: [{029E27FF-EE21-4AC9-AEBF-2626CF8A0E29}] => (Block) C:\program files (x86)\java\jdk1.7.0_40\bin\java.exe
FirewallRules: [{8E58488F-C3EC-40E4-87DD-E6B23DE3CD13}] => (Block) C:\program files (x86)\java\jdk1.7.0_40\bin\java.exe
FirewallRules: [TCP Query User{D3E3887D-DC4D-46F8-85BB-A17DB4DF3143}C:\program files (x86)\netbeans 8.0.2\bin\netbeans.exe] => (Allow) C:\program files (x86)\netbeans 8.0.2\bin\netbeans.exe
FirewallRules: [UDP Query User{A751FD98-134E-4AEC-9F8B-E7E253030F48}C:\program files (x86)\netbeans 8.0.2\bin\netbeans.exe] => (Allow) C:\program files (x86)\netbeans 8.0.2\bin\netbeans.exe
FirewallRules: [{E5B43872-E575-4F3D-986A-64D619871AD3}] => (Allow) D:\GAMES\Lost Saga\LostSaga\autoupgrade.exe
FirewallRules: [{69B3670B-2F4D-4167-B798-5B149BA07E62}] => (Allow) D:\GAMES\Lost Saga\LostSaga\autoupgrade.exe
FirewallRules: [{CD9A082D-3309-48CB-BDE1-39391F4F243E}] => (Allow) D:\GAMES\Lost Saga\LostSaga\lostsaga.exe
FirewallRules: [{37642C02-07E0-4AAC-9BD9-3C8B1895FFFC}] => (Allow) D:\GAMES\Lost Saga\LostSaga\lostsaga.exe
FirewallRules: [TCP Query User{D4092692-D5C5-4D48-8B18-D81225C3825B}C:\program files (x86)\java\jdk1.8.0\bin\java.exe] => (Block) C:\program files (x86)\java\jdk1.8.0\bin\java.exe
FirewallRules: [UDP Query User{46354920-75FC-4F1F-A024-57422E213465}C:\program files (x86)\java\jdk1.8.0\bin\java.exe] => (Block) C:\program files (x86)\java\jdk1.8.0\bin\java.exe
FirewallRules: [TCP Query User{FE8B8914-6097-4301-BD5F-B0D69500EB11}C:\program files\java\jdk1.8.0_45\bin\java.exe] => (Block) C:\program files\java\jdk1.8.0_45\bin\java.exe
FirewallRules: [UDP Query User{F298C8CA-5E47-4D38-BBA2-37840677E966}C:\program files\java\jdk1.8.0_45\bin\java.exe] => (Block) C:\program files\java\jdk1.8.0_45\bin\java.exe
FirewallRules: [TCP Query User{D753E326-1315-41D8-818C-82CD5647D11E}C:\program files\java\jdk1.8.0_45\jre\bin\javaw.exe] => (Allow) C:\program files\java\jdk1.8.0_45\jre\bin\javaw.exe
FirewallRules: [UDP Query User{F8ED93EC-2756-4CEA-BB2D-2233892BCBF5}C:\program files\java\jdk1.8.0_45\jre\bin\javaw.exe] => (Allow) C:\program files\java\jdk1.8.0_45\jre\bin\javaw.exe
FirewallRules: [TCP Query User{DB6151F1-04FD-48A9-8E07-2F307A3FE61F}D:\software installer\eclipse luna\eclipse.exe] => (Block) D:\software installer\eclipse luna\eclipse.exe
FirewallRules: [UDP Query User{3E5D112C-48BE-4D66-87B7-55E3CEA6EB97}D:\software installer\eclipse luna\eclipse.exe] => (Block) D:\software installer\eclipse luna\eclipse.exe
FirewallRules: [{B2ECFC14-358D-4C41-91DC-3D31C9DD46A0}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (09/24/2015 05:47:09 PM) (Source: NvStreamSvc) (EventID: 2001) (User: )
Description: NvStreamSvcNvVAD initialization failed [6]
 
Error: (09/24/2015 05:47:09 PM) (Source: NvStreamSvc) (EventID: 2001) (User: )
Description: NvStreamSvcFailed to set NvVAD endpoint as default Audio endpoint [0]
 
Error: (09/24/2015 05:47:09 PM) (Source: NvStreamSvc) (EventID: 2001) (User: )
Description: NvStreamSvcNvVAD endpoint registration failed [0]
 
Error: (09/24/2015 05:24:41 PM) (Source: NvStreamSvc) (EventID: 2001) (User: )
Description: NvStreamSvcNvVAD initialization failed [6]
 
Error: (09/24/2015 05:24:41 PM) (Source: NvStreamSvc) (EventID: 2001) (User: )
Description: NvStreamSvcFailed to set NvVAD endpoint as default Audio endpoint [0]
 
Error: (09/24/2015 05:24:41 PM) (Source: NvStreamSvc) (EventID: 2001) (User: )
Description: NvStreamSvcNvVAD endpoint registration failed [0]
 
Error: (09/23/2015 02:29:14 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.
 
Error: (09/23/2015 02:29:14 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.
 
Error: (09/23/2015 02:20:05 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.
 
Error: (09/23/2015 02:20:05 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.
 
 
System errors:
=============
Error: (09/24/2015 05:50:06 PM) (Source: ipnathlp) (EventID: 30013) (User: )
Description: 192.168.43.251192.168.137.0255.255.255.0
 
Error: (09/24/2015 05:50:06 PM) (Source: ipnathlp) (EventID: 1233) (User: )
Description: 
 
Error: (09/24/2015 05:50:06 PM) (Source: ipnathlp) (EventID: 1233) (User: )
Description: 
 
Error: (09/24/2015 05:50:06 PM) (Source: ipnathlp) (EventID: 1233) (User: )
Description: 
 
Error: (09/24/2015 05:49:52 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Defender Network Inspection Service service terminated unexpectedly.  It has done this 2 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.
 
Error: (09/24/2015 05:49:52 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Windows Defender Service service terminated unexpectedly.  It has done this 3 time(s).
 
Error: (09/24/2015 05:48:51 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Defender Network Inspection Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.
 
Error: (09/24/2015 05:48:51 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Defender Service service terminated unexpectedly.  It has done this 2 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.
 
Error: (09/24/2015 05:47:50 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Defender Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.
 
Error: (09/24/2015 05:47:12 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The BuddyVM service failed to start due to the following error: 
%%3
 
 
CodeIntegrity:
===================================
  Date: 2015-07-27 04:23:14.067
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-06-15 20:50:59.848
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-06-15 20:50:58.778
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-05-04 19:21:05.000
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-05-03 18:41:37.484
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-05-03 18:28:38.544
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-05-03 18:19:41.800
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-05-03 14:45:34.731
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-05-03 06:53:29.838
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-05-03 06:24:57.206
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
 
 
==================== Memory info =========================== 
 
Processor: Intel® Core™ i5-3230M CPU @ 2.60GHz
Percentage of memory in use: 39%
Total physical RAM: 3957.6 MB
Available physical RAM: 2393.26 MB
Total Virtual: 4661.6 MB
Available Virtual: 3036.8 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:146.49 GB) (Free:44.16 GB) NTFS
Drive d: () (Fixed) (Total:690.8 GB) (Free:53.2 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: C24F1638)
Partition 1: (Active) - (Size=102 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=146.5 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=690.8 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=94.1 GB) - (Type=05)
 
==================== End of Addition.txt ============================
 

  • 0

Advertisements


#11
BrianDrab

BrianDrab

    Trusted Helper

  • Malware Removal
  • 3,591 posts

Thank. There will be no problem from forgetting to move Adwcleaner to the desktop.

 

Please do the following.

 

Step#1 - Warnings
The Dangers of P2P Programs
IMPORTANT: I noticed that you have a P2P (Peer to Peer) file sharing program on your computer. I cannot stress highly enough the danger in using these types of programs. P2P programs are one of the major avenues of infection these days. The files downloaded with these programs are more than likely infected with trojans, malware, rootkits, etc.
You run the risk of getting an infection that can compromise your sensitive data, such as financial records, personal information, etc. That is just the infection aspect of using P2P programs. You also run the risk of possible arrest, fines, or in severe cases, jail time for illegal downloading of copyrighted material.
 
Here are some information sources about the dangers of P2P programs:
FBI - Peer to Peer Scams
USA Today Artticle on P2P Programs
File Sharing Infects 500,000 Computers
 
I very much recommend you uninstall this program from your machine. If not, you will likely be back needing help with your machine again. The risks of infections from content downloaded with P2P programs far outweigh any benefit of using them.
 
It is, of course, your choice as to whether or not you remove the program from your machine. It is my duty though, to point out how dangerous it is to use these programs. However, I must request that you do not use it while we are cleaning your machine.
 
Please uninstall the following Peer-to-Peer program(s): uTorrent

 

Step#2 - Uninstalls
Please uninstall the following programs one at a time. Instructions for doing so are here.
If any of the programs give you an error during the uninstall, notate it and move on to the next one. Just let me know which ones had issues. If you are asked to reboot, answer No until all the programs have been uninstalled and then you can reboot. All of these programs are either outdated, malware/adware, have a bad reputation or are not recommended. If you absolutely must have one of them I suggest that you wait until you are declared clean before reinstalling.

SavePass 1.1
YoutubeAdblocker

 

 

Step#3 - AVG Remnant Removal

There are still remnants of AVG on your system. We need to ensure we remove these so there are no conflicts.

 

1. Please download and run the AVG Removal Tool.

 

 

Step#4 - Enable System Restore

Your System Restore is disabled. If you did this intentionally, although not recommended, you may disable again after your machine is free from malware. Until that time we need to re-enable it. Please do the following.

 

1. Right-click your Start button and choose File Explorer

2. Right-click on This PC in the left hand side of the screen and select Properties.

3. This will bring up the System screen. Click the System Protection link.

4. Click on your (C:) drive in the list of Available Drives and click the Configure button.

5. Click on Turn on system protection. Adjust the Max Usage slider to your preference. If you are unsure of what to set it to, I suggest 10% based on your free disk space.

6. Click on Apply. Click OK to close the System Protection dialog.

 

Note: If you have any issues re-enabling System Restore, please don't go on to the next steps and let me know.

 

 

Step#5 - FRST Fix
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
1. Download attached file and save it to the Desktop. Attached File  fixlist.txt   2.83KB   214 downloads
Note. It's important that both files, FRST64 and fixlist.txt are in the same location or the fix will not work (in this case...the desktop).
2. Run FRST64 by Right-Clicking on the file and choosing Run as administrator.
3. Press the Fix button just once and wait. If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
4. When finished FRST64 will generate a log on the Desktop (Fixlog.txt). Please post the contents of it in your reply.

 

 

Step#6 - JRT by Malwarebytes
1. Download Junkware Removal Tool to your desktop.
2. Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
3. The tool will open. Press any key at the Disclaimer screen and the program will start scanning your system.
4. Please be patient as this can take a while to complete depending on your system's specifications.
5. On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
6. Close the text file and reboot your machine.
7. Post the contents of JRT.txt into your next message.

 

 

 

Items for your next post

1. Fixlog

2. Junkware log

 

 


  • 0

#12
fandy

fandy

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts

i have follow your instruction and nothing wrong happen

 

this is the log file

Fix result of Farbar Recovery Scan Tool (x64) Version:23-09-2015
Ran by Rifandi (2015-09-25 01:22:45) Run:2
Running from C:\Users\Rifandi\Desktop
Loaded Profiles: Rifandi (Available Profiles: Rifandi)
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
CreateRestorePoint:
HKLM\...\Policies\Explorer: [TaskbarNoNotification] 1
HKLM\...\Policies\Explorer: [HideSCAHealth] 1
HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\CurrentVersion\Windows: [Load] C:\ProgramData\msctqoijn.exe <===== ATTENTION
HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\MountPoints2: {0fb37f05-8757-11e4-83cc-20898440e341} - "H:\Install.exe" 
HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\MountPoints2: {1f44dd11-4479-11e4-83aa-20898440e341} - "F:\WD Drive Unlock.exe" autoplay=true
HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\MountPoints2: {7d215ca6-2d82-11e4-8386-20898440e341} - "F:\Install.exe" 
HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\...\MountPoints2: {e6f05941-877b-11e3-82b4-20898440e341} - "G:\.\Start.exe" 
C:\ProgramData\msctqoijn.exe
FF user.js: detected! => C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\user.js [2014-03-22]
FF Extension: SavePass 1.2 - C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\Extensions\[email protected] [2015-08-19]
2015-09-21 13:58 - 2015-09-21 13:58 - 01415680 _____ (wj32) C:\Program Files\MNOHIJGH.exe
2015-09-19 18:59 - 2015-09-19 18:59 - 01415680 _____ (wj32) C:\Program Files\HTIAGJZW.exe
2015-09-24 17:20 - 2014-03-25 14:48 - 00000000 ____D C:\Program Files\KMSnano
2015-06-27 04:47 - 2015-06-27 04:47 - 1415680 _____ (wj32) C:\Program Files\F7N7RDTD.exe
2015-06-28 14:44 - 2015-06-28 14:44 - 1415680 _____ (wj32) C:\Program Files\IRJS8N3R.exe
2015-07-22 13:25 - 2015-07-22 13:25 - 1415680 _____ (wj32) C:\Program Files\YIWGU8PH.exe
FirewallRules: [{8EC7C0D2-469D-425A-B1B6-B81075B83C37}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe
FirewallRules: [{0EB4AB0D-4A4A-4D49-B669-6857DFBAAA39}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe
FirewallRules: [{971E3028-9FB4-4F27-9B29-7DBC1424F8A5}] => (Allow) C:\Windows\System32\KMSServer.exe
FirewallRules: [{213EADAA-1CFE-4D58-9E21-C09621DE09D5}] => (Allow) C:\Windows\System32\KMSServer.exe
FirewallRules: [{EBCA317D-CC83-43ED-AAE3-74866A4DFFD5}] => (Allow) D:\GAMES\Dragon Nest SEA\DragonNest.exe
FirewallRules: [{27FB2FF6-1E02-4AF4-B515-BE58E7F66AED}] => (Allow) C:\Program Files\KMSpico\KMSELDI.exe
FirewallRules: [{D31A831A-E4FA-41E1-98ED-24EF2D307FDA}] => (Allow) C:\Program Files\KMSpico\KMSELDI.exe
FirewallRules: [{07799367-4E73-4629-B22A-23952A4E3A98}] => (Allow) C:\Program Files\KMSpico\KMSServer.exe
FirewallRules: [{D7FFEC2F-1027-45F8-BF55-9E803B26383D}] => (Allow) C:\Program Files\KMSpico\KMSServer.exe
FirewallRules: [{3E856337-07D0-4D60-B6DE-E6B7F3221DA2}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe
FirewallRules: [{B0BA9B87-C926-41A7-B95D-6428E7C88BA7}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe
EmptyTemp:
*****************
 
Restore point was successfully created.
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\TaskbarNoNotification => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\HideSCAHealth => value removed successfully
HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge => value removed successfully
HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\Software\Microsoft\Windows NT\CurrentVersion\Windows\\Load => value restored successfully
"HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0fb37f05-8757-11e4-83cc-20898440e341}" => key removed successfully
HKCR\CLSID\{0fb37f05-8757-11e4-83cc-20898440e341} => key not found. 
"HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1f44dd11-4479-11e4-83aa-20898440e341}" => key removed successfully
HKCR\CLSID\{1f44dd11-4479-11e4-83aa-20898440e341} => key not found. 
"HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7d215ca6-2d82-11e4-8386-20898440e341}" => key removed successfully
HKCR\CLSID\{7d215ca6-2d82-11e4-8386-20898440e341} => key not found. 
"HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e6f05941-877b-11e3-82b4-20898440e341}" => key removed successfully
HKCR\CLSID\{e6f05941-877b-11e3-82b4-20898440e341} => key not found. 
"C:\ProgramData\msctqoijn.exe" => File/Folder not found.
C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\user.js => moved successfully
C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\Extensions\[email protected] => not found.
C:\Program Files\MNOHIJGH.exe => moved successfully
C:\Program Files\HTIAGJZW.exe => moved successfully
C:\Program Files\KMSnano => moved successfully
C:\Program Files\F7N7RDTD.exe => moved successfully
C:\Program Files\IRJS8N3R.exe => moved successfully
C:\Program Files\YIWGU8PH.exe => moved successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{8EC7C0D2-469D-425A-B1B6-B81075B83C37} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{0EB4AB0D-4A4A-4D49-B669-6857DFBAAA39} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{971E3028-9FB4-4F27-9B29-7DBC1424F8A5} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{213EADAA-1CFE-4D58-9E21-C09621DE09D5} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{EBCA317D-CC83-43ED-AAE3-74866A4DFFD5} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{27FB2FF6-1E02-4AF4-B515-BE58E7F66AED} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{D31A831A-E4FA-41E1-98ED-24EF2D307FDA} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{07799367-4E73-4629-B22A-23952A4E3A98} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{D7FFEC2F-1027-45F8-BF55-9E803B26383D} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{3E856337-07D0-4D60-B6DE-E6B7F3221DA2} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{B0BA9B87-C926-41A7-B95D-6428E7C88BA7} => value removed successfully
EmptyTemp: => 72.4 MB temporary data Removed.
 
 
The system needed a reboot.. 
 
==== End of Fixlog 01:23:24 ====
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.6.3 (09.21.2015:1)
OS: Windows 8.1 Pro x64
Ran by Rifandi on 25/09/2015 at  1:31:03,88
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
~~~ Services
 
Successfully deleted: [Service] vsss [Reboot required]
 
 
 
~~~ Tasks
 
 
 
~~~ Registry Values
 
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\GoogleChromeAutoLaunch_2044B68C092258CC6B61BEF807401E47
 
 
 
~~~ Registry Keys
 
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{11111111-1111-1111-1111-110611341129}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{22222222-2222-2222-2222-220622342229}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0063429.BHO
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0063429.BHO.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0063429.Sandbox
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0063429.Sandbox.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{55555555-5555-5555-5555-550655345529}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66666666-6666-6666-6666-660666346629}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{44444444-4444-4444-4444-440644344429}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{11111111-1111-1111-1111-110611341129}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{22222222-2222-2222-2222-220622342229}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{55555555-5555-5555-5555-550655345529}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{66666666-6666-6666-6666-660666346629}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\TypeLib\{44444444-4444-4444-4444-440644344429}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110611341129}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0063429.BHO
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0063429.BHO.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0063429.Sandbox
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0063429.Sandbox.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{55555555-5555-5555-5555-550655345529}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{66666666-6666-6666-6666-660666346629}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\TypeLib\{44444444-4444-4444-4444-440644344429}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{55555555-5555-5555-5555-550655345529}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{66666666-6666-6666-6666-660666346629}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\TypeLib\{44444444-4444-4444-4444-440644344429}
 
 
 
~~~ Files
 
Failed to delete: [File] C:\Users\Rifandi\AppData\Roaming\microsoft\systemcertificates\vssvc.exe
Successfully disinfected: [Shortcut] C:\ProgramData\Microsoft\windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk
 
 
 
~~~ Folders
 
Successfully deleted: [Folder] C:\Program Files (x86)\globalupdate
Successfully deleted: [Folder] C:\Program Files (x86)\mysearchdial
Successfully deleted: [Folder] C:\Program Files (x86)\rightsurf
Successfully deleted: [Folder] C:\Program Files (x86)\SavePass 1.1
Successfully deleted: [Folder] C:\Program Files (x86)\suptab
Successfully deleted: [Folder] C:\Program Files (x86)\youtubeadblocker
Successfully deleted: [Folder] C:\ProgramData\apn
Successfully deleted: [Folder] C:\ProgramData\dsearchlink
Successfully deleted: [Folder] C:\ProgramData\youtubeadblocker
Successfully deleted: [Folder] C:\Users\Rifandi\Appdata\Local\cool_mirage
Successfully deleted: [Folder] C:\Users\Rifandi\Appdata\Local\crashrpt
Successfully deleted: [Folder] C:\Users\Rifandi\Appdata\Local\globalupdate
Successfully deleted: [Folder] C:\Users\Rifandi\Appdata\Local\installer
Successfully deleted: [Folder] C:\Users\Rifandi\Appdata\Local\onlysearch
Successfully deleted: [Folder] C:\Users\Rifandi\Appdata\Local\torch
Successfully deleted: [Folder] C:\Users\Rifandi\AppData\Roaming\babsolution
Successfully deleted: [Folder] C:\Users\Rifandi\AppData\Roaming\mysearchdial
Successfully deleted: [Folder] C:\Users\Rifandi\AppData\Roaming\suptab
Successfully deleted: [Folder] C:\ProgramData\ae98960d435764d3
 
 
 
~~~ FireFox
 
Successfully deleted the following from C:\Users\Rifandi\AppData\Roaming\mozilla\firefox\profiles\ly7cncgi.default\prefs.js
 
user_pref(extensions.N6bAB9UK0.scode, (function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\acebook\)>-1||url.indexOf(\warnalert11.com\)
user_pref(extensions.aVJKPXI46039420JMZUIOB85844870com63429.63429.internaldb.monetization_plugin_bundledUrls.value, %7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssfiles.com%2
user_pref(extensions.crossrider.bic, 1486a98ae4e4e5a827c89d53f243dee9);
user_pref(extensions.mysearchdial.AL, 2);
user_pref(extensions.mysearchdial.aflt, irmsd0103);
user_pref(extensions.mysearchdial.appId, {CA5CAA63-B27C-4963-9BEC-CB16A36D56F8});
user_pref(extensions.mysearchdial.cd, 2XzuyEtN2Y1L1QzutB0C0DtDyD0AtCtAzz0CyCyCyB0E0D0EtN0D0Tzu0SyByCyDtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R);
user_pref(extensions.mysearchdial.cr, 1961462397);
user_pref(extensions.mysearchdial.dfltLng, );
user_pref(extensions.mysearchdial.dfltSrch, true);
user_pref(extensions.mysearchdial.dnsErr, true);
user_pref(extensions.mysearchdial.excTlbr, false);
user_pref(extensions.mysearchdial.hmpg, true);
user_pref(extensions.mysearchdial.hmpgUrl, hxxp://start.mysearchdial.com/?f=1&a=irmsd0103&cd=2XzuyEtN2Y1L1QzutB0C0DtDyD0AtCtAzz0CyCyCyB0E0D0EtN0D0Tzu0SyByCyDtN1L2XzutBtFtBt
user_pref(extensions.mysearchdial.id, 2CD05A138C667EDE);
user_pref(extensions.mysearchdial.instlDay, 16105);
user_pref(extensions.mysearchdial.instlRef, );
user_pref(extensions.mysearchdial.newTabUrl, hxxp://start.mysearchdial.com/?f=2&a=irmsd0103&cd=2XzuyEtN2Y1L1QzutB0C0DtDyD0AtCtAzz0CyCyCyB0E0D0EtN0D0Tzu0SyByCyDtN1L2XzutBtFt
user_pref(extensions.mysearchdial.prdct, mysearchdial);
user_pref(extensions.mysearchdial.prtnrId, mysearchdial);
user_pref(extensions.mysearchdial.srchPrvdr, Mysearchdial);
user_pref(extensions.mysearchdial.tlbrId, base);
user_pref(extensions.mysearchdial.tlbrSrchUrl, hxxp://start.mysearchdial.com/?f=3&a=irmsd0103&cd=2XzuyEtN2Y1L1QzutB0C0DtDyD0AtCtAzz0CyCyCyB0E0D0EtN0D0Tzu0SyByCyDtN1L2XzutBt
user_pref(extensions.mysearchdial.vrsn, 1.8.21.0);
user_pref(extensions.mysearchdial.vrsni, 1.8.21.0);
user_pref(extensions.mysearchdial_i.hmpg, true);
user_pref(extensions.mysearchdial_i.newTab, false);
user_pref(extensions.mysearchdial_i.smplGrp, none);
user_pref(extensions.mysearchdial_i.vrsnTs, 1.8.21.01:36:6);
user_pref(extensions.n8nmrPkP.scode, (function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\acebook\)>-1||url.indexOf(\warnalert11.com\)>
user_pref(extensions.quick_start.enable_search1, false);
user_pref(extensions.quick_start.sd.closeWindowWithLastTab_prev_state, false);
Emptied folder: C:\Users\Rifandi\AppData\Roaming\mozilla\firefox\profiles\ly7cncgi.default\minidumps [41 files]
 
 
 
~~~ Chrome
 
Successfully deleted: [Folder] C:\Users\Rifandi\Appdata\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma
 
[C:\Users\Rifandi\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset
 
[C:\Users\Rifandi\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:
pelmeidfhdlhlbjimpabfcbnnojbboma
 
[C:\Users\Rifandi\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset
 
[C:\Users\Rifandi\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[
  pelmeidfhdlhlbjimpabfcbnnojbboma
]
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 25/09/2015 at  1:33:16,97
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 

  • 0

#13
BrianDrab

BrianDrab

    Trusted Helper

  • Malware Removal
  • 3,591 posts

Excellent. Things are looking better. Please do the following.

 

Step#1 - Malwarebytes Scan


  • Download Malwarebytes to your desktop from here.
  • Right-click on the file that is downloaded to your desktop and select Run as administrator. Answer Yes when asked to Allow.
  • Select the appropriate language and click OK.
  • Click Next.
  • Select "I accept the agreement" and click Next.
  • Click Next
  • Change the install path if desired. Normally you will keep this as is. Click Next.
  • Click Next again.
  • Click Next again.
  • Click Install.
  • Uncheck "Enable free trial of Malwarebytes Anti-Malware Premium".
  • Click Finish
  • If an update is found you will be prompted to download and install. Go ahead.
  • Click the Settings button and then the Detection and Protection tab. Then check the box to Scan for rootkits. as shown below.
  • ScanForRootkits.JPG
     
  • Click the Scan button at the top of the form and then click Start Scan button and let complete.
  • If malware was detected you can now click the Remove Selected Button. If no malware was detected you can skip the rest of these bullet items and go to the next step which is to retrieve the Malwarebytes log.
  • RemoveSelected.JPG
  • Once the malware is removed you may get a prompt asking you to reboot. Note: Please answer Yes.
  • Restart.JPG.

 
Step#2 - Retrieve Malwarebytes Log
1. Open up the Malwarebytes program again if it's not already. You can simply double click on the shortcut on your desktop that says "Malwarebytes Anti-Malware".
2. Click the History button as shown in the picture below.
3. Click Application Logs as shown in the picture below.
4. Click on the most recent Scan Log as shown in the picture below.
ApplicationLog.JPG
 
5. The Scanning History Log screen will open. Click the Export button in the lower left and choose Copy to Clipboard. Paste the info into your next post (Right-click your mouse in the post and select Paste).
ScanningHistory.JPG

 


  • 0

#14
fandy

fandy

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts

i have completed the scanning
and this is the log

 

Malwarebytes Anti-Malware
www.malwarebytes.org
 
Scan Date: 25/09/2015
Scan Time: 2:25
Logfile: 
Administrator: Yes
 
Version: 2.1.8.1057
Malware Database: v2015.06.03.03
Rootkit Database: v2015.09.22.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
 
OS: Windows 8.1
CPU: x64
File System: NTFS
User: Rifandi
 
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 417329
Time Elapsed: 21 min, 10 sec
 
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
 
Processes: 0
(No malicious items detected)
 
Modules: 0
(No malicious items detected)
 
Registry Keys: 736
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\APPID\{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}, Quarantined, [dc732591d6b4e155c1112379956e17e9], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}, Quarantined, [dc732591d6b4e155c1112379956e17e9], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}, Quarantined, [dc732591d6b4e155c1112379956e17e9], 
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, Quarantined, [e26da115d4b6f24419d385e2ca394eb2], 
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}, Quarantined, [e26da115d4b6f24419d385e2ca394eb2], 
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{917CAAE9-DD47-4025-936E-1414F07DF5B8}, Quarantined, [e26da115d4b6f24419d385e2ca394eb2], 
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{917CAAE9-DD47-4025-936E-1414F07DF5B8}, Quarantined, [e26da115d4b6f24419d385e2ca394eb2], 
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{917CAAE9-DD47-4025-936E-1414F07DF5B8}, Quarantined, [e26da115d4b6f24419d385e2ca394eb2], 
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}, Quarantined, [e26da115d4b6f24419d385e2ca394eb2], 
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}, Quarantined, [e26da115d4b6f24419d385e2ca394eb2], 
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, Quarantined, [e26da115d4b6f24419d385e2ca394eb2], 
PUP.Optional.SupTab.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, Quarantined, [e26da115d4b6f24419d385e2ca394eb2], 
PUP.Optional.SupTab.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, Quarantined, [e26da115d4b6f24419d385e2ca394eb2], 
PUP.Optional.Outbrowse, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{6D4506CE-F855-4657-AA38-DB6B1F733982}, Quarantined, [a9a6bff7bdcd67cfda762b75e61da15f], 
PUP.Optional.Outbrowse, HKLM\SOFTWARE\CLASSES\TYPELIB\{03771AEF-400D-4A13-B712-25878EC4A3F5}, Quarantined, [a9a6bff7bdcd67cfda762b75e61da15f], 
PUP.Optional.Outbrowse, HKLM\SOFTWARE\CLASSES\INTERFACE\{3408AC0D-510E-4808-8F7B-6B70B1F88534}, Quarantined, [a9a6bff7bdcd67cfda762b75e61da15f], 
PUP.Optional.Outbrowse, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3408AC0D-510E-4808-8F7B-6B70B1F88534}, Quarantined, [a9a6bff7bdcd67cfda762b75e61da15f], 
PUP.Optional.Outbrowse, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{3408AC0D-510E-4808-8F7B-6B70B1F88534}, Quarantined, [a9a6bff7bdcd67cfda762b75e61da15f], 
PUP.Optional.Outbrowse, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{03771AEF-400D-4A13-B712-25878EC4A3F5}, Quarantined, [a9a6bff7bdcd67cfda762b75e61da15f], 
PUP.Optional.Outbrowse, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{03771AEF-400D-4A13-B712-25878EC4A3F5}, Quarantined, [a9a6bff7bdcd67cfda762b75e61da15f], 
PUP.Optional.Outbrowse, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{6D4506CE-F855-4657-AA38-DB6B1F733982}, Quarantined, [a9a6bff7bdcd67cfda762b75e61da15f], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{D40753C7-8A59-4C1F-BE88-C300F4624D5B}, Quarantined, [440bd1e5bdcd69cd656e019ba65d3ec2], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{C292AD0A-C11F-479B-B8DB-743E72D283B0}, Quarantined, [440bd1e5bdcd69cd656e019ba65d3ec2], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{C292AD0A-C11F-479B-B8DB-743E72D283B0}, Quarantined, [440bd1e5bdcd69cd656e019ba65d3ec2], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{C292AD0A-C11F-479B-B8DB-743E72D283B0}, Quarantined, [440bd1e5bdcd69cd656e019ba65d3ec2], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\esrv.mysearchdialESrvc.1, Quarantined, [440bd1e5bdcd69cd656e019ba65d3ec2], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\esrv.mysearchdialESrvc, Quarantined, [440bd1e5bdcd69cd656e019ba65d3ec2], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\esrv.mysearchdialESrvc, Quarantined, [440bd1e5bdcd69cd656e019ba65d3ec2], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\esrv.mysearchdialESrvc, Quarantined, [440bd1e5bdcd69cd656e019ba65d3ec2], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\esrv.mysearchdialESrvc.1, Quarantined, [440bd1e5bdcd69cd656e019ba65d3ec2], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\esrv.mysearchdialESrvc.1, Quarantined, [440bd1e5bdcd69cd656e019ba65d3ec2], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{D40753C7-8A59-4C1F-BE88-C300F4624D5B}, Quarantined, [440bd1e5bdcd69cd656e019ba65d3ec2], 
PUP.Optional.OutBrowse, HKLM\SOFTWARE\CLASSES\TYPELIB\{DCABB943-792E-44C4-9029-ECBEE6265AF9}, Quarantined, [d877ebcb7119de5860f7194f3ac948b8], 
PUP.Optional.OutBrowse, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{DCABB943-792E-44C4-9029-ECBEE6265AF9}, Quarantined, [d877ebcb7119de5860f7194f3ac948b8], 
PUP.Optional.OutBrowse, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{DCABB943-792E-44C4-9029-ECBEE6265AF9}, Quarantined, [d877ebcb7119de5860f7194f3ac948b8], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{FBC322D5-407E-4854-8C0B-555B951FD8E3}, Quarantined, [3718e2d4bcce8fa7d95fb0ed57ac44bc], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{0400EBCA-042C-4000-AA89-9713FBEDB671}, Quarantined, [3718e2d4bcce8fa7d95fb0ed57ac44bc], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{0BD19251-4B4B-4B94-AB16-617106245BB7}, Quarantined, [3718e2d4bcce8fa7d95fb0ed57ac44bc], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{3281114F-BCAB-45E3-80D9-A6CD64D4E636}, Quarantined, [3718e2d4bcce8fa7d95fb0ed57ac44bc], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{44533FCB-F9FB-436A-8B6B-CF637B2D465A}, Quarantined, [3718e2d4bcce8fa7d95fb0ed57ac44bc], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{44B29DDD-CF7A-454A-A275-A322A398D93F}, Quarantined, [3718e2d4bcce8fa7d95fb0ed57ac44bc], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{A4DE94DB-DF03-45A3-8A5D-D1B7464B242D}, Quarantined, [3718e2d4bcce8fa7d95fb0ed57ac44bc], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{AA0F50A8-2618-4AE4-A779-9F7378555A8F}, Quarantined, [3718e2d4bcce8fa7d95fb0ed57ac44bc], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B2DB115C-8278-4947-9A07-57B53D1C4215}, Quarantined, [3718e2d4bcce8fa7d95fb0ed57ac44bc], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B97FC455-DB33-431D-84DB-6F1514110BD5}, Quarantined, [3718e2d4bcce8fa7d95fb0ed57ac44bc], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{C67281E0-78F5-4E49-9FAE-4B1B2ADAF17B}, Quarantined, [3718e2d4bcce8fa7d95fb0ed57ac44bc], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{E72E9312-0367-4216-BFC7-21485FA8390B}, Quarantined, [3718e2d4bcce8fa7d95fb0ed57ac44bc], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{F6CCB6C9-127E-44AE-8552-B94356F39FFE}, Quarantined, [3718e2d4bcce8fa7d95fb0ed57ac44bc], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{FFD25630-2734-4AE9-88E6-21BF6525F3FE}, Quarantined, [3718e2d4bcce8fa7d95fb0ed57ac44bc], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{0400EBCA-042C-4000-AA89-9713FBEDB671}, Quarantined, [3718e2d4bcce8fa7d95fb0ed57ac44bc], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{0BD19251-4B4B-4B94-AB16-617106245BB7}, Quarantined, [3718e2d4bcce8fa7d95fb0ed57ac44bc], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3281114F-BCAB-45E3-80D9-A6CD64D4E636}, Quarantined, [3718e2d4bcce8fa7d95fb0ed57ac44bc], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{44533FCB-F9FB-436A-8B6B-CF637B2D465A}, Quarantined, [3718e2d4bcce8fa7d95fb0ed57ac44bc], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{44B29DDD-CF7A-454A-A275-A322A398D93F}, Quarantined, [3718e2d4bcce8fa7d95fb0ed57ac44bc], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{A4DE94DB-DF03-45A3-8A5D-D1B7464B242D}, Quarantined, [3718e2d4bcce8fa7d95fb0ed57ac44bc], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{AA0F50A8-2618-4AE4-A779-9F7378555A8F}, Quarantined, [3718e2d4bcce8fa7d95fb0ed57ac44bc], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B2DB115C-8278-4947-9A07-57B53D1C4215}, Quarantined, [3718e2d4bcce8fa7d95fb0ed57ac44bc], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B97FC455-DB33-431D-84DB-6F1514110BD5}, Quarantined, [3718e2d4bcce8fa7d95fb0ed57ac44bc], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{C67281E0-78F5-4E49-9FAE-4B1B2ADAF17B}, Quarantined, [3718e2d4bcce8fa7d95fb0ed57ac44bc], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{E72E9312-0367-4216-BFC7-21485FA8390B}, Quarantined, [3718e2d4bcce8fa7d95fb0ed57ac44bc], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{F6CCB6C9-127E-44AE-8552-B94356F39FFE}, Quarantined, [3718e2d4bcce8fa7d95fb0ed57ac44bc], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{FFD25630-2734-4AE9-88E6-21BF6525F3FE}, Quarantined, [3718e2d4bcce8fa7d95fb0ed57ac44bc], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{0400EBCA-042C-4000-AA89-9713FBEDB671}, Quarantined, [3718e2d4bcce8fa7d95fb0ed57ac44bc], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{0BD19251-4B4B-4B94-AB16-617106245BB7}, Quarantined, [3718e2d4bcce8fa7d95fb0ed57ac44bc], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{3281114F-BCAB-45E3-80D9-A6CD64D4E636}, Quarantined, [3718e2d4bcce8fa7d95fb0ed57ac44bc], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{44533FCB-F9FB-436A-8B6B-CF637B2D465A}, Quarantined, [3718e2d4bcce8fa7d95fb0ed57ac44bc], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{44B29DDD-CF7A-454A-A275-A322A398D93F}, Quarantined, [3718e2d4bcce8fa7d95fb0ed57ac44bc], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{A4DE94DB-DF03-45A3-8A5D-D1B7464B242D}, Quarantined, [3718e2d4bcce8fa7d95fb0ed57ac44bc], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{AA0F50A8-2618-4AE4-A779-9F7378555A8F}, Quarantined, [3718e2d4bcce8fa7d95fb0ed57ac44bc], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{B2DB115C-8278-4947-9A07-57B53D1C4215}, Quarantined, [3718e2d4bcce8fa7d95fb0ed57ac44bc], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{B97FC455-DB33-431D-84DB-6F1514110BD5}, Quarantined, [3718e2d4bcce8fa7d95fb0ed57ac44bc], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{C67281E0-78F5-4E49-9FAE-4B1B2ADAF17B}, Quarantined, [3718e2d4bcce8fa7d95fb0ed57ac44bc], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{E72E9312-0367-4216-BFC7-21485FA8390B}, Quarantined, [3718e2d4bcce8fa7d95fb0ed57ac44bc], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{F6CCB6C9-127E-44AE-8552-B94356F39FFE}, Quarantined, [3718e2d4bcce8fa7d95fb0ed57ac44bc], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{FFD25630-2734-4AE9-88E6-21BF6525F3FE}, Quarantined, [3718e2d4bcce8fa7d95fb0ed57ac44bc], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{FBC322D5-407E-4854-8C0B-555B951FD8E3}, Quarantined, [3718e2d4bcce8fa7d95fb0ed57ac44bc], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{FBC322D5-407E-4854-8C0B-555B951FD8E3}, Quarantined, [3718e2d4bcce8fa7d95fb0ed57ac44bc], 
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}, Quarantined, [0748684e6b1fee48c8d177ec06fd9b65], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}, Quarantined, [0748684e6b1fee48c8d177ec06fd9b65], 
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{3004627E-F8E9-4E8B-909D-316753CBA923}, Quarantined, [ff5081351c6ecc6a73158c107192b749], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\mysearchdial.mysearchdialdskBnd, Quarantined, [ff5081351c6ecc6a73158c107192b749], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\mysearchdial.mysearchdialdskBnd.1, Quarantined, [ff5081351c6ecc6a73158c107192b749], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\mysearchdial.mysearchdialdskBnd, Quarantined, [ff5081351c6ecc6a73158c107192b749], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\mysearchdial.mysearchdialdskBnd.1, Quarantined, [ff5081351c6ecc6a73158c107192b749], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\mysearchdial.mysearchdialdskBnd, Quarantined, [ff5081351c6ecc6a73158c107192b749], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\mysearchdial.mysearchdialdskBnd.1, Quarantined, [ff5081351c6ecc6a73158c107192b749], 
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{3004627E-F8E9-4E8B-909D-316753CBA923}, Quarantined, [ff5081351c6ecc6a73158c107192b749], 
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD}, Quarantined, [2a25397d07835cda681fb7e5976c7c84], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\mysearchdial.mysearchdialHlpr, Quarantined, [2a25397d07835cda681fb7e5976c7c84], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\mysearchdial.mysearchdialHlpr.1, Quarantined, [2a25397d07835cda681fb7e5976c7c84], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\mysearchdial.mysearchdialHlpr, Quarantined, [2a25397d07835cda681fb7e5976c7c84], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\mysearchdial.mysearchdialHlpr.1, Quarantined, [2a25397d07835cda681fb7e5976c7c84], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\mysearchdial.mysearchdialHlpr, Quarantined, [2a25397d07835cda681fb7e5976c7c84], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\mysearchdial.mysearchdialHlpr.1, Quarantined, [2a25397d07835cda681fb7e5976c7c84], 
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD}, Quarantined, [2a25397d07835cda681fb7e5976c7c84], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{219046AE-358F-4CF1-B1FD-2B4DE83642A8}, Quarantined, [7cd36650d9b137ff21688f0dee154db3], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdate.OneClickCtrl.10, Quarantined, [cd824c6aacde6dc9818d27526a9ba35d], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdate.OneClickProcessLauncherMachine, Quarantined, [5ff0981e503a49ed29e5d6a3778eb947], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdate.OneClickProcessLauncherMachine.1.0, Quarantined, [2728ad09167476c0af5f8ced50b59d63], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.CoCreateAsync, Quarantined, [95bae8ceeaa051e5789768117d88d030], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.CoCreateAsync.1.0, Quarantined, [63ecae08167411250906fa7f8b7a6e92], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.CoreClass, Quarantined, [c887dfd74743ad8920ef2a4f0104936d], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.CoreClass.1, Quarantined, [55fa991dfb8f0b2bed22b1c862a36997], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.CoreMachineClass, Quarantined, [4e010caa41499a9c12fd730633d2d22e], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.CoreMachineClass.1, Quarantined, [94bbb7ff23678ea858b7641548bd2ad6], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.CredentialDialogMachine, Quarantined, [e26d00b6a0eac86eaa65661314f1c33d], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.CredentialDialogMachine.1.0, Quarantined, [50ff81356822d46253bc09707c896e92], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.OnDemandCOMClassMachine, Quarantined, [aba4ccea1971181e5bb4443553b2926e], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.OnDemandCOMClassMachine.1.0, Quarantined, [8cc33c7af69476c098772059020306fa], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.OnDemandCOMClassMachineFallback, Quarantined, [a5aa179f1971be78ff102a4fab5a936d], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0, Quarantined, [54fbd5e15b2f75c1db3492e74eb7cd33], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.OnDemandCOMClassSvc, Quarantined, [f7585e584347a69076990475f11409f7], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.OnDemandCOMClassSvc.1.0, Quarantined, [77d8cfe768227db95cb3a8d1bd488e72], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.ProcessLauncher, Quarantined, [3a15aa0cd6b444f265aa08713dc857a9], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.ProcessLauncher.1.0, Quarantined, [ec638d29791180b699767cfd3ec719e7], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.Update3COMClassService, Quarantined, [450a516525652d0943ccf18857ae5ca4], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.Update3COMClassService.1.0, Quarantined, [bb9476402367171f9e7195e46d986b95], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.Update3WebMachine, Quarantined, [d27de6d0dab084b2dc337ffa5aaba45c], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.Update3WebMachine.1.0, Quarantined, [95baf3c3e5a53006b45b24559570b050], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.Update3WebMachineFallback, Quarantined, [bd92c2f49af0aa8cbd529adf4fb660a0], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.Update3WebMachineFallback.1.0, Quarantined, [e36c90263b4f5dd929e6c5b46b9aeb15], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.Update3WebSvc, Quarantined, [ba95ecca5832f73f56b9f8819b6a16ea], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.Update3WebSvc.1.0, Quarantined, [8fc0536354361125c14ea6d324e13ec2], 
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\29777, Quarantined, [8ec1ded8bcce59dd0c57b672b64efa06], 
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{056DDD55-13E4-41E4-B00C-7E512C42BE0C}, Quarantined, [eb6490261971db5ba4738af4e71e5da3], 
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{89DDACD0-0D24-463D-878C-D5C921345790}, Quarantined, [f758d6e0eaa078be67b27fffa06530d0], 
PUP.Optional.Qone8.A, HKLM\SOFTWARE\WOW6432NODE\qone8Software, Quarantined, [4609585e4d3d65d169a3c98b7f86ae52], 
PUP.Optional.SavePass.A, HKLM\SOFTWARE\WOW6432NODE\SavePass 1.1, Quarantined, [5ef115a18802b3831435bc506c981ce4], 
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\supWPM, Quarantined, [c689585e662478be4fda67a32ed6c937], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdate.OneClickCtrl.10, Quarantined, [4a0503b3602ac76f7c92b4c57d886a96], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdate.OneClickProcessLauncherMachine, Quarantined, [113ef0c6800a83b3d03ef980da2b5ba5], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdate.OneClickProcessLauncherMachine.1.0, Quarantined, [b897595d95f577bf729c3d3c768f2dd3], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.CoCreateAsync, Quarantined, [b29ddcda93f782b499766d0c15f07f81], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.CoCreateAsync.1.0, Quarantined, [2f2032841773340224ebbdbc4cb99d63], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.CoreClass, Quarantined, [2d22605649412b0b5db2b1c832d3ae52], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.CoreClass.1, Quarantined, [2a25d2e4dfab6cca0b04eb8ebf46a858], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.CoreMachineClass, Quarantined, [cd820ea83c4e9d99c24dec8d39cc7d83], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.CoreMachineClass.1, Quarantined, [2b243c7ad5b5989e65aa15647b8a659b], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.CredentialDialogMachine, Quarantined, [58f771452d5d82b4957a0c6dc63ff709], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.CredentialDialogMachine.1.0, Quarantined, [153a52643852cc6aa46b88f15baacb35], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.OnDemandCOMClassMachine, Quarantined, [ba95288e59317abcd23ded8c4fb6d62a], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.OnDemandCOMClassMachine.1.0, Quarantined, [f25df1c59cee350164ab94e5cb3ade22], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.OnDemandCOMClassMachineFallback, Quarantined, [c58a4670b6d42115e728a9d0d72e639d], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0, Quarantined, [63ec40768efc072f050ad1a8788d31cf], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.OnDemandCOMClassSvc, Quarantined, [e16e1b9b2763f541907f354415f0c838], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.OnDemandCOMClassSvc.1.0, Quarantined, [85cad9dd8dfdc076df3013661ce95aa6], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.ProcessLauncher, Quarantined, [bf90e6d097f30e28b85786f3df265aa6], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.ProcessLauncher.1.0, Quarantined, [113e85316f1b38fe25eac3b6fc097888], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.Update3COMClassService, Quarantined, [fd5213a38cfe48eeba55b9c0986d966a], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.Update3COMClassService.1.0, Quarantined, [8dc22f877b0f83b350bf1960bd48b749], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.Update3WebMachine, Quarantined, [430ce5d10684b87ec04f80f9b94c3dc3], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.Update3WebMachine.1.0, Quarantined, [73dc8f27dcaee74fde311d5cca3b8b75], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.Update3WebMachineFallback, Quarantined, [331cddd999f1e3530b04cfaac83d51af], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.Update3WebMachineFallback.1.0, Quarantined, [123deccaa3e7d2641ff072075fa63dc3], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.Update3WebSvc, Quarantined, [242b62541d6d9a9c16f9cdacf41105fb], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.Update3WebSvc.1.0, Quarantined, [ce81b6008208da5c24eb5f1a83824cb4], 
PUP.Optional.GlobalUpdate.C, HKLM\SOFTWARE\WOW6432NODE\GLOBALUPDATE\UPDATE\Clients, Quarantined, [f55a3f773a50b284c457374846bf2ad6], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\GLOBALUPDATE\UPDATE, Quarantined, [70dfbafcc2c8c373aeb0a26f14f09a66], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\INSTALLCORE\mysearchdial, Quarantined, [f05f08aed6b45dd9092e92b728dd8d73], 
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\INSTALLEDBROWSEREXTENSIONS\29777, Quarantined, [ada25d595d2de6505310bb6d01038d73], 
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{056DDD55-13E4-41E4-B00C-7E512C42BE0C}, Quarantined, [034c783ee2a85cda64b3df9fe52037c9], 
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{89DDACD0-0D24-463D-878C-D5C921345790}, Quarantined, [6de208aea4e645f164b54d313dc8ac54], 
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB, Quarantined, [74db1b9bf09a0b2b0b1d020893712fd1], 
PUP.Optional.IEPluginServices.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\IePluginService, Quarantined, [4e014c6a7614bf772bfcf00d5fa43ec2], 
PUP.Optional.TornTV.A, HKU\S-1-5-18\SOFTWARE\TornTv Downloader, Quarantined, [b39cf9bd325887af5ecd3ebfad56d729], 
PUP.Optional.SavePass.A, HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\SavePass 1.1, Quarantined, [68e7a70fdcae3204f45754b87b89629e], 
PUP.Optional.1ClickDownload.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\1ClickDownload, Quarantined, [3916f0c60288d2648a9cd972c441e61a], 
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\mysearchdial, Quarantined, [88c7b2042f5b0630379d5eecf70e738d], 
PUP.Optional.TornTV.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\TornTv Downloader, Quarantined, [5af5c4f2f2980f271813db222fd4be42], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, Quarantined, [ce814e68008a280e1accf865de2706fa], 
PUP.Optional.SavePass.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\APPDATALOW\SOFTWARE\SavePass 1.1, Quarantined, [ca85c4f28dfdf541aaa18983f01429d7], 
PUP.Optional.Babylon.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\BABSOLUTION\Updater, Quarantined, [db74734395f550e6595f77d37e87a15f], 
PUP.Optional.GlobalUpdate.C, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\GLOBALUPDATE\UPDATE\PROXY, Quarantined, [18379224c2c8c96dbb9aad3b010232ce], 
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\INSTALLCORE\1I1T1Q1S, Quarantined, [95ba16a04c3ea195b95f5cd8e71dec14], 
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\INSTALLCORE\mysearchdial, Quarantined, [c788e0d6602a69cdf9823e1057ae1ce4], 
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\INSTALLCORE, Quarantined, [ec6371456129023449907dcc5ea7cb35], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\29777, Quarantined, [60ef981e7713d2648231a85e0004c33d], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\OB, Quarantined, [e6698d2997f338fe26295e96917217e9], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{056DDD55-13E4-41E4-B00C-7E512C42BE0C}, Quarantined, [f659eacce6a42313e232e698b64fdd23], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{10607258-B643-4877-A925-50F8C3D3C1BB}, Quarantined, [bf90d8de7f0b48eedd391d6156af58a8], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{106D78B9-B9E0-4387-8835-4667F113328C}, Quarantined, [b39cbcfa4a4050e6d1440b733cc9df21], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{109F821D-BD2A-4440-979B-A9ED44B8E488}, Quarantined, [a9a6c6f0d9b1b680b363522cbb4af808], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{10BBFB4A-39F1-4D32-BBCE-32C1875014A9}, Quarantined, [46091b9b474365d18b8b344a58ad0000], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{117CF6EA-6180-49D7-A3E7-625360BE42ED}, Quarantined, [53fc8234abdf83b36aac542a1de82cd4], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{11D4C2DB-6CB7-4E0D-B728-F92B93E3528A}, Quarantined, [db746d492862181e53c283fb60a5a65a], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{12745D75-2545-4DC7-A14C-8CFD948ABEC3}, Quarantined, [70df843297f3ae888c8ad7a743c2a35d], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{12D652B9-C4AE-4B11-8F16-6D2DFA40EEC6}, Quarantined, [b09fd6e0325879bd779e710d21e4a25e], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{12D693FE-5DC1-438B-9682-76D01DD063CB}, Quarantined, [a5aa5363addde35304121c62887dc43c], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{12EB231D-1F3F-4CB4-BF8D-66941D1C65C0}, Quarantined, [37183680fd8d0f2702145c223dc8fb05], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{14242C9D-C987-4D4E-97B3-3483BC7C949E}, Quarantined, [301f08aef29854e28b8ac8b611f457a9], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{144C9E53-356A-4115-B23B-A642FBD3BB4A}, Quarantined, [8ac515a1bad0b482b1645c2233d2e917], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1508D8EF-68CD-4DFB-A7C7-BC83F8D869E7}, Quarantined, [bc9320962e5cc76f96803c42ff06b947], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{15205666-A84A-45F4-A89C-C484B649868C}, Quarantined, [ee61b20438524ceafe18215df60f15eb], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{156FDFD5-EC30-43A4-9C5E-C1103B161BD1}, Quarantined, [56f9e4d205857fb724f1205e917410f0], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{15B92B65-53A2-40C0-9D1B-988698EBA587}, Quarantined, [8cc3496d5238a4922ce9a8d6759021df], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{160907B3-4343-426E-B5E9-881154D389EC}, Quarantined, [b8972d894c3e37ff7e983d4115f08b75], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{160ECCC3-FBDE-445B-9AF3-CC70188C4AED}, Quarantined, [e669c3f35d2ded4942d488f6c243857b], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{161D550F-7D9D-47CE-B511-9966306A48E5}, Quarantined, [60ef01b5fa90a88edc3982fc3bca8d73], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{16614EF8-DE8B-4763-8BDC-50CBD3E2761A}, Quarantined, [87c84f67028810263dd983fb27debb45], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{175F4E01-A78F-4EC9-BD1D-6DF54BAE257C}, Quarantined, [ee61a80ef595181e60b5433bc441ab55], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{17F607A3-D236-4C5E-97D6-F0A24115B8DE}, Quarantined, [be91fbbb1575a39358becfaf80854fb1], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{184ABC97-890E-4C66-8E61-DEABC2FFB398}, Quarantined, [6ee10fa7eaa033039b7a720c51b4946c], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{18E4CFC3-2723-4C58-8089-B238E0543D78}, Quarantined, [de7109ad7d0da5918a8c413d07fe44bc], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{19018BAD-1637-4135-8056-FE5F271211CF}, Quarantined, [242b496d5d2d251165b099e5f5105fa1], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1950A10F-9E9A-41C4-A4C4-38E7E37360B6}, Quarantined, [87c8e1d54347f442d243b5c9b253ef11], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{19843CCB-63F0-4CAB-AA97-7495C3A3A655}, Quarantined, [3d12783e6d1d72c4bf57502e6e97a15f], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1A1609AE-D76A-4C08-946B-75647522306C}, Quarantined, [bd92793d8a004bebcc4993ebe025cf31], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1A294DF6-B274-480D-A263-AD876A3E57FB}, Quarantined, [f15ef3c31f6b2214ae686c126c999a66], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1C09EC12-E0ED-4460-B6F5-207AF8EAF873}, Quarantined, [a9a6ebcbacdee94d2de8f48a8f76fe02], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1C28E76A-BAB7-4C2A-9E76-CF72FB498E9B}, Quarantined, [71de575f9cee6bcb1ef76f0f0ef77e82], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1C815EAC-4549-4962-9FDC-4C8EB5E6123D}, Quarantined, [70dfa90d64263df92ee7a3dbe42160a0], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1CA1BE04-6FEB-4952-86D7-6DD468987A96}, Quarantined, [59f62a8c7d0d48ee060f126c040114ec], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1CC80490-3239-40FB-9493-1AEA4CD0AAEB}, Quarantined, [da759a1c305a072f33e20a740500c937], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1CCC3093-DC08-435C-B8EB-96337AD42D26}, Quarantined, [d17e5b5b305ab1850c0a49350ff6da26], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1CFB70E5-78A3-494F-8957-E64022A7AD56}, Quarantined, [212ef0c6b3d7a98d37df6d1150b5718f], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1DDF82C4-4267-4B62-AA46-225391164F85}, Quarantined, [c48b8b2b3b4f6ec89a7b0b73d62f6997], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1E463F89-8974-4024-BD5F-EE11D4A19C2E}, Quarantined, [371801b52c5e8da930e676085baaca36], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1E5739D0-6F1E-472A-9C63-F67192722699}, Quarantined, [311eb204d0bac96d56bf1c628382f907], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1EC56C5C-BCCB-4CDE-BCEC-657A152347A7}, Quarantined, [3718981e1a700d29a471add1020354ac], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1FE95C6D-231D-4FCD-99D0-1CA828975482}, Quarantined, [044b298d51393600b85d96e88283b947], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2085B5B1-C1FF-4FB9-B923-E32FDA15439D}, Quarantined, [eb6405b168221c1a65b0e49a83821de3], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{21B5A649-338B-4993-A88F-10EC3ACFABC7}, Quarantined, [67e82492345664d253c3fe8014f19d63], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{221561D4-7DBF-4884-ABD7-2FB5967A8ACB}, Quarantined, [d9761b9bc6c43afc799c225c00059d63], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2231964E-A1FB-4CC8-946F-FFE1AEC59529}, Quarantined, [38172294bad0251172a47c02689d0ef2], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2236D9C0-D477-44B7-8578-EDA7549D629B}, Quarantined, [fe51bef86f1b5fd721f486f86f96ad53], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{22BBA9AB-A6C4-43A6-B4E2-CDCD28344671}, Quarantined, [321db1056d1d95a19c7a5c2232d30bf5], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{233CEA76-FEC7-4D79-9CF7-C79F99D8433F}, Quarantined, [f659823443476accb65f5a24c045728e], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2406F9D8-5838-4331-91D2-C6B771BCB4C8}, Quarantined, [2f2031851872fa3c2beb5c2247be4cb4], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{24B4A41B-6FF4-48E8-BFA7-B7989E476C8E}, Quarantined, [2e216b4b5733f73ff12488f6cc393bc5], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{24D79978-FCD1-4DC7-A2F4-9082D014268B}, Quarantined, [f25de6d08604dc5a060f601eee17738d], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{24E2324A-B00C-415B-ACA3-8A75AA37B2EA}, Quarantined, [fd5293239eec0a2c4fc737478b7a956b], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{25644787-3A38-4E3B-A3E8-D9CFD816D33C}, Quarantined, [70dfa412ddade650d541cdb1ae57817f], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{25C35C62-D598-474D-90A0-649F6AAEC3A2}, Quarantined, [d37c5660701a70c68a8cdba3ec19cb35], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{260E9537-A83B-4CE8-BC27-6CCB22CC26C8}, Quarantined, [3718a214404a1e18f3224d31c24349b7], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2631D085-7C48-4C56-9C6F-27661F14A0E4}, Quarantined, [b39c8c2a692146f00e086f0fd530a15f], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{26472572-55BE-4340-9DB9-FA6AB66EA6D3}, Quarantined, [b39cc6f0b0dad4623bdb5727729305fb], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{268F4669-9F9D-4D69-BBC9-1E1E2D6F3424}, Quarantined, [c6891a9c0981b1850b0b8df1b5500af6], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{26F8F265-176F-4734-821C-EEC063CDB853}, Quarantined, [cb848f27860496a00610374740c5e020], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{27006013-38C6-4BD1-B2E3-9FC59B5EA2CD}, Quarantined, [51fee4d2bbcf8da967af730b4cb928d8], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2774C56B-DAFA-451B-88FB-50282050F4C6}, Quarantined, [83ccb303226881b53fd7e39b08fdab55], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2779F78B-7BC8-41C8-8E4E-99827A41CCEA}, Quarantined, [ec636a4c701a60d692846d11e0257c84], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{285D92B6-680C-4D8F-8B3D-B8C37CE3FC66}, Quarantined, [85ca298d5337f54141d5344a62a30bf5], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{28DCA798-3B15-4D1C-9CFD-C14D90D0268D}, Quarantined, [a3ac12a41179a3931500e797fa0bae52], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{28E47D33-824B-414F-97AF-77647123E644}, Quarantined, [470821958cfedc5aca4b1767e81d46ba], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2970EAEB-523D-46DB-852B-EE9DD3BCB24E}, Quarantined, [b39cac0a71196dc96baa700ee32236ca], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{29EC0E28-F5C3-4749-9D8D-E2A74012B45C}, Quarantined, [e9667e38622864d2dc3aa3db2fd6827e], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2A281A10-44B2-458C-BDD0-D08FE7FBB88A}, Quarantined, [331c823487036bcb69adc1bd3dc83ec2], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2A511A2A-EA36-46BA-8B81-571FA3D56529}, Quarantined, [6ce311a531592c0aa76e87f71ee7da26], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2BD95269-EA81-4454-BC27-4410E37B76E1}, Quarantined, [96b93a7cdcaefe38b363087640c5ae52], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2D2F009E-CD99-432A-8C6D-2E532632B021}, Quarantined, [3b14cfe70486e5511cfac7b749bcc13f], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2D84E883-78DB-43CB-8D29-6C9381D5AC81}, Quarantined, [c18e4571eaa086b0f12599e5d530f808], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2D8969BC-37BA-42A0-87F2-AFB5799CD24D}, Quarantined, [b798bafc8bffaa8c6ca9f28c82839e62], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2DE4B463-D5B6-437C-AEDF-A48367175031}, Quarantined, [c68910a6593196a0ea2cb5c9b74eef11], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2E2BFA3A-2834-4C1D-BB21-DC815A50F0D3}, Quarantined, [4a05d5e1e5a5d95d24f1c1bd09fc738d], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2E6A1216-19D0-4F92-BF49-22BE5E1AB2D0}, Quarantined, [a2add2e452380f27080de896f41155ab], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2E831696-C219-417D-B04E-5EB053CE2370}, Quarantined, [a0af4a6cfb8f02349c7a4b333acb817f], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2FFBE1B4-FB54-4A8E-8A93-BA7142653BED}, Quarantined, [5df215a10a80f1458c8a433b07feb947], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{308BA1D9-215C-4E67-9813-E117BF931AA1}, Quarantined, [ba9562541278043261b4fa84ce3726da], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{30AD5CE6-9321-4ED5-912B-3942CF67FDF6}, Quarantined, [83cc496dc3c7ce681ff65e20de27ab55], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{30B4DC87-AA4C-4AF3-BAB4-B57E37E9A329}, Quarantined, [3e11a5116b1f2a0c71a5e6987b8a43bd], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{30B5DBCE-25AC-4CAE-BF27-8C843A7F8EA5}, Quarantined, [a3ac575f5b2f46f019fd1668d035f907], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{30DD076B-9F25-41E2-BF27-226A9BA2B262}, Quarantined, [63ec8135fa9044f29680750947bee51b], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{31618DD4-11F6-461C-AE39-E36F3B5F918F}, Quarantined, [4708ab0bee9c8fa7d244bdc1d134748c], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{316C5490-8058-407D-8893-111B48529897}, Quarantined, [6fe0b006dbaf6bcb0f069ae4798c12ee], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{31E3D3AE-B51F-4F03-90D6-13919C243D68}, Quarantined, [331ce6d0b6d41c1a8f871f5f937217e9], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{326A7C75-3022-42BB-AD5C-52E5987AD4E1}, Quarantined, [b19e179fc6c4c5713adc5f1f8283669a], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3273B4FA-193A-4613-AFB7-354C5478353B}, Quarantined, [80cfdadc2961f442d342ee9057aea55b], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{32928202-C620-4A2D-A6E9-CF59448BF629}, Quarantined, [d6798b2b2a60de5843d2b6c89471ae52], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{32DFE042-3F1B-4B90-BE3B-C2F4AA4614B8}, Quarantined, [ba95e9cd424803337c9a413df70e6b95], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{335191F8-155F-4833-8AE5-7E8CF7468BB4}, Quarantined, [f05fd0e6ed9d95a14cca641aa26334cc], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{33AEB12F-D06F-465B-8FFB-9CF6C13F4994}, Quarantined, [480734827812142221f5b1cd0df831cf], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{344AAE88-3516-4584-BA6A-E0715714BECB}, Quarantined, [d57a387ef09a1a1c20f5146a4abb0bf5], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{34627DB7-48BB-4C00-83B7-D354FB34549E}, Quarantined, [a7a8cfe7860484b2c5505529c342e31d], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{348981D1-312C-4CF6-9775-BB2BA7B827EF}, Quarantined, [36190aacf496de5812031d61e91cb64a], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{34E14550-49BF-49AE-B2D9-4060F6F0AEFB}, Quarantined, [da75a70f98f272c4d44145398d78e020], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3506CD08-D30F-4D46-9FAB-7D7F96F6FC10}, Quarantined, [2c23d2e40a80bc7a2aec037b22e3f010], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3510550F-8B82-48C8-B17C-C0A1E2D31AB3}, Quarantined, [47088a2cd3b75fd7ee28e9956c99fd03], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3512B418-313C-4139-9087-3BA0CB8BEE4D}, Quarantined, [e7685c5a8bfff2447c999fdff90c916f], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{352ED206-FA27-4B50-ABFD-2F13FD649871}, Quarantined, [b7983f77bfcb989ea96cc0be947138c8], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3578DCBB-CBE2-49C0-A818-B1E27584C929}, Quarantined, [212e9422008a0e28977eaad4bb4aea16], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{366CDDFB-98F9-4E54-855F-4084A7C2192A}, Quarantined, [95ba3086d6b43afcac69f58930d5c33d], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{36827FAC-DC8E-452B-BDDA-5594767A5699}, Quarantined, [e9663383b8d264d29f764e3009fc9e62], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3699A7C2-CE12-4716-9498-14238A8787C5}, Quarantined, [2b246b4bb4d6fd39f61f047aa75ec739], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{37E7465F-2B0F-4429-827B-C71229931EE3}, Quarantined, [0d423c7a66245dd90610e09e3bca26da], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3929358E-54F5-440E-8769-B14796891A93}, Quarantined, [66e9377f2f5b91a5d343daa4f90cad53], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{396A310C-8D2D-49FD-8F43-E3D27DB6A767}, Quarantined, [3619b6005931b28439dce6988184d828], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{39BFF0AA-120C-4DF7-A116-43AB3FAB2585}, Quarantined, [1b34e3d35e2c9b9b6bab631bc44139c7], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3A17518A-B657-41C3-AFBD-EDF31799EC47}, Quarantined, [39169c1a5337be78b5613b43da2b2dd3], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3A253602-CD5B-4E35-8CC9-F344F8B93F31}, Quarantined, [52fd7c3a0b7fce68140249353acb21df], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3A50526B-70D3-47A8-9C66-6A9629208C3E}, Quarantined, [d07f8c2a4b3f6fc735e1255937ced12f], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3AC57B78-B4DB-4776-B43E-3871202ACE22}, Quarantined, [014e1c9a4248b3832de9daa48a7bbf41], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3AF84000-D5AE-443B-8ADB-73591BD0A890}, Quarantined, [113e7640c6c4dc5a6caa0d71d62f41bf], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3BE55B0A-6CF0-4D6A-885F-20526A6A2139}, Quarantined, [4f004076c5c5ce68b36294ea50b5b64a], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3C3E2308-4E60-4D0F-A651-14C88C2D4572}, Quarantined, [dd7208ae5c2e44f2d441007e70958d73], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3DCE007A-3544-43AB-B073-7EE78DE1D955}, Quarantined, [fe51ab0b5d2dab8b9580681610f5fb05], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3E2804CA-34DD-4517-8281-C2AFA1EBCCA3}, Quarantined, [1a35338361292016ca4cf886ae578878], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3E32D8CE-D350-4CB1-9C56-DAD7DC6EB250}, Quarantined, [2c2376409febe25420f63c42e025817f], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3E9A7BBF-2756-45BA-9328-1537A3637193}, Quarantined, [0c43d4e21f6b6ccae82d99e542c3d828], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3E9E1C50-E043-434F-BA90-B1A995A5B02B}, Quarantined, [430c595d068488ae28ed512d1ee78f71], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3EC1F12C-ED88-467E-B169-F2AD7197D7CE}, Quarantined, [b897f4c27b0fcb6b4dc94737c63fce32], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3ED59D58-2C77-4C0E-94B5-3433DF71C196}, Quarantined, [c18ecde990fada5c03126c1249bcd62a], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3FF9410F-FBB2-4DF9-BF83-90A044815169}, Quarantined, [331c6056a1e9989e6ca9abd3d0359e62], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{402ACF5C-ADC4-42BF-8959-21476D6E5531}, Quarantined, [c887496dbeccfd3968ae3a4457ae6f91], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{40AD692E-A801-4757-8FDA-78E3396825AC}, Quarantined, [e36c7f3738522d09f91ca9d55fa67b85], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{41523F02-40C1-4B1D-A617-D78DA38284EF}, Quarantined, [341bccea0e7c221428ee730b8d78f709], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4231D998-A396-4F79-B078-20A1DADBE7E4}, Quarantined, [e26d4b6bdeacba7ca274146ace371de3], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{430A0784-7EEC-4518-AB7F-27AB6CF9D973}, Quarantined, [e16e872f85051c1a0e07b7c734d1d22e], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4327B14E-ACCA-457C-93AE-3BD55922614E}, Quarantined, [7fd04d69840679bdcf4699e561a4fd03], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{433C1164-49E2-4BF8-BE11-CBB811829739}, Quarantined, [a5aa199d2c5e1d19a37289f5a65f659b], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{440FD445-253F-4EFA-AF2C-CA3BB7B9D652}, Quarantined, [1b3405b14b3fa1950e076a1441c4ce32], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{44483649-74EE-4C5A-8173-41CEDD32D98D}, Quarantined, [b19ed6e01278ee48df369be327de837d], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{45158C07-4450-4D20-87D5-525FE073F5AF}, Quarantined, [123d11a50189181e3dd86816897ce51b], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{45B59595-FD0D-4246-B8FD-2248B77CA2E2}, Quarantined, [5ff0fdb949410b2b7a9b611d768f2bd5], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{45BC50E4-B8C1-47D7-AF53-A1837464483F}, Quarantined, [ee61fbbbf8925fd7e035562822e331cf], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4692EDE1-B172-4E1A-BFDA-F0D8B7BD7C70}, Quarantined, [d877c9ed7e0c7abc36e0156908fd09f7], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{471ED992-44BE-4AA6-8E14-9E69BF114884}, Quarantined, [ba95882ea9e11a1cfb1a1b63b74e9a66], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{47420E9E-119A-44EB-8327-F6E771934DD1}, Quarantined, [d778f2c41e6c49ed1005a6d8de2745bb], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{47FCB10C-723A-443A-963D-4589D8F91E5C}, Quarantined, [3718674f7e0cc670df37710d59ac619f], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{48B1AAEB-1F12-4E88-A2CA-8E94845B1633}, Quarantined, [a9a603b38703b5811ff60e7049bc857b], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{48CD7F2C-8791-4F5A-8BD5-E6D411B8B2D6}, Quarantined, [a2ad6254f991cc6ad144215de91ca65a], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{48DB5457-FBB5-4ADD-9554-637D30CF3823}, Quarantined, [d7781e9862281620aa6bec92be475ea2], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{492D71BE-ED27-4E5D-8DBC-F51EE256F1B7}, Quarantined, [72ddf9bd8efcce682aec9ae4c34203fd], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{49C5900F-DA54-4CA1-8810-5EDF4050BBFE}, Quarantined, [55fa2e88b7d378bee431fe804cb9de22], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{49F1C3A2-2E44-40F5-B2FB-218490504D4B}, Quarantined, [c887c7ef2268db5be431a1dd59ac2dd3], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4A2D6C55-FDB0-494B-BBD1-6BB62AF5C2EA}, Quarantined, [7bd4d2e46b1f81b50015dea015f0df21], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4B19B8ED-A8A4-4AAE-9362-C2EDE72BAF96}, Quarantined, [86c93383375366d030e6f48a92734fb1], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4B8A4C2D-2950-47A1-841C-C6FEFCEB3724}, Quarantined, [c8873086e4a61d19f32389f5b74eac54], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4B96B74B-C0BB-4BA4-A196-9F1763EAE987}, Quarantined, [97b8eec82c5e5ed8938288f619ecb050], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4D6C1AEC-A04D-46A9-B4BC-F821E52BE379}, Quarantined, [232c3c7a32587eb8868f78060005b44c], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4D7D5467-CE0C-499F-9C74-337A3CB6BECF}, Quarantined, [440b1e986c1ed660bc59b3cbb352a858], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4DA10542-2648-40E6-8015-C26DEBA6DDB4}, Quarantined, [c48bc9ed76144de9967f097521e4f40c], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4DE33814-E058-47EC-BE31-1091693DE4B8}, Quarantined, [222de8ceff8b3afcc0568df149bc7987], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4E00576A-538D-4B26-80BB-AAD83AE0D6A5}, Quarantined, [fa557f3704865bdbcb4aaad4b45146ba], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4E0B2DF7-FD89-413F-9C3D-A279687ADC6C}, Quarantined, [0d42c2f4fe8c1d1935e18fef3dc89769], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4EFCDCDB-E97E-4EC5-A2A6-631779E14A3F}, Quarantined, [3c139d193159181e1cf9631bb55029d7], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4EFEBE2A-A42B-47D3-A8F7-52C1C24156AB}, Quarantined, [212e52649feb49eddb3b9de135d03bc5], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4F423835-778C-4EF1-AD85-EB99247F4518}, Quarantined, [a6a92e88860453e3fe17aad4bc4935cb], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4FCCCC12-9439-4E74-BA97-4253C4ECC02C}, Quarantined, [a5aaab0bafdbd56141d5ccb2c045827e], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{504E40D4-342C-4C96-B8C3-DA4F7CB856BF}, Quarantined, [e26dbef8b8d2fa3c70a57c0235d0d030], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{51BA6E88-EF2A-4C1E-9A11-E11540AC8E1F}, Quarantined, [84cba511e8a2a5918b8a58268a7b1ce4], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{52668907-F813-4058-8599-4E2963CB8B83}, Quarantined, [3c13783eafdb4cea91852559877e3cc4], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{52BC3755-4BBC-416F-A0E2-D370B1A3C84B}, Quarantined, [4c03ae0861290b2b090d601eda2b12ee], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{53DC17D2-16A9-470D-BC3D-6BC38F2557FB}, Quarantined, [3a156e48ed9dc76f8a8c9be328dd738d], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{540F2050-B15C-4AA8-A6D2-29FB1D787C5D}, Quarantined, [b49b179f0d7dce685cba1569778e629e], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{54334F2F-9C25-49AF-A17F-A65E80A7C971}, Quarantined, [410e199ded9d63d3fe18cbb307fe32ce], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{54AB0BB0-D5C3-4FBB-B3B8-346016267F6C}, Quarantined, [054a991d4b3f2610af67f98549bc669a], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{552E56ED-F52C-4A31-BD7D-DB3BF49E1B84}, Quarantined, [4f00d1e593f7f34347ce1668ae578c74], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{556779DD-2D3C-457F-B2BD-81BF2647FF3A}, Quarantined, [b49bbdf9137750e6070e2f4fc1445ea2], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5654FD56-6BAB-45E4-9552-4554483A62B3}, Quarantined, [2728e8ce19711d19c94c35492dd8738d], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{56AFBBD7-D24E-40F6-BAF8-65D1C14CCC20}, Quarantined, [4906ae08dfab74c2af6769158f76827e], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{57D1ECB3-2A72-4113-B344-1A43BA5D9122}, Quarantined, [3619229448423cfa8b8a5c2294719c64], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{587A783E-4448-4A53-A51C-C43574B19830}, Quarantined, [bc9302b4ccbec0769580add1788da060], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{58B389E4-5DD7-4564-A4C8-2F6C1CF8876A}, Quarantined, [79d6387e1e6cb87e769fb0ce85803cc4], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5919307C-F2EF-475D-8E82-C22C81306BCA}, Quarantined, [a2ad377f31595adc6da898e63bca41bf], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{592991FE-4901-4031-AB94-78D81D1B3446}, Quarantined, [fd529c1a7416fc3a0e08433b0bfa52ae], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{59739E73-C5D7-4D0B-8CBB-49A74867A8F7}, Quarantined, [0f404b6b59311620e72f6c12ae57cb35], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5A348355-9C2C-401C-8F48-C81DF7C4D23F}, Quarantined, [3c1316a0e3a7d56137df47371ce9f808], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5A942C12-EEEE-4119-B3AA-F58156C0D05E}, Quarantined, [80cfe6d0305aab8b95819ae47d88de22], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5AAE0AE1-175D-41D6-AD68-FE5E2B2DA19C}, Quarantined, [0a454c6a800a22147c994a341de82fd1], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5AC732C2-4176-43C7-8CFE-9C67507F7B64}, Quarantined, [0748ac0aa1e9d4622de84e3038cd6898], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5B318E1E-8AB5-405D-90F2-E3FFE0457FDF}, Quarantined, [85cac7ef27630036d1447fff47be23dd], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5BEAA832-5A2F-47DB-9B31-F47F175E6C4C}, Quarantined, [400f10a65c2e47efac69007e739204fc], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5C0959A3-2F4C-487D-9476-FCDE7A93A823}, Quarantined, [a5aa9d19bfcbcf6720f64836976eb749], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5C820995-D340-43F1-B08E-109CA7FDEA5F}, Quarantined, [084760568109f640d83ee896db2af20e], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5CE1B294-11DB-4D7E-A1E0-6B94FB1F16E7}, Quarantined, [a0af417514761422f91d9fdfa1643dc3], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5D7C5177-3C96-434F-A5F4-B13DFA5FF43E}, Quarantined, [ce81278fddade353849182fc27de5ca4], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5DAD61E7-F55E-432A-B2C9-FAABD3D8C732}, Quarantined, [4d02882e44461d19a6703e40b74eec14], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5DADCE15-8E82-4E99-BA55-88BBF5D1B677}, Quarantined, [81ced2e4b9d1be78908688f6877e42be], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5E9B20C5-259C-42C7-8FF1-3C2B122AA724}, Quarantined, [b39c6a4c8efc33038d89a5d927debd43], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{60447517-FED5-403A-A751-86DD96A04EE6}, Quarantined, [1c339e183d4d79bd0411abd35da854ac], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{60C238DF-DF46-49A4-BEA7-A297D74CAF21}, Quarantined, [212effb7315960d6f322df9f57aeec14], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{60D2859D-72A2-4E11-9A92-C753625E55B3}, Quarantined, [4c034a6c2961c76f967f532b778e10f0], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{611DB9F6-C474-4303-9018-3CB3F4A6F067}, Quarantined, [3a152e885832e15527ef4c322ed739c7], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{62993CD6-7EEA-4FE3-8E63-D028763E3C26}, Quarantined, [5ff0b60045453204db3ac7b7e223f40c], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{62A86078-BBF5-418C-94FD-F279E4E02C81}, Quarantined, [06492096355576c01402c0bee81d8f71], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{633B4C6F-6713-4C9A-A1C4-8B95C6E2CAA4}, Quarantined, [e966f4c2117995a1d046ccb211f4d828], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{63998CEA-6341-4ECA-8D93-3984F44827FE}, Quarantined, [63ec73433b4fcd6993831866b64fcb35], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{63D6B6F2-5A2D-4547-B966-30F069C5291A}, Quarantined, [80cf9125ec9e4de924f278063acb30d0], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{63ED0511-62EC-451C-9998-3B49B47E9414}, Quarantined, [d27de3d3e7a3eb4b61b4047a669fe41c], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6417EC79-F240-4F2B-8458-B85F5D55C4E4}, Quarantined, [3916feb899f12214d83d90ee1fe6fc04], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{642F3BB3-F4B1-4038-B75E-3B7D1EF58929}, Quarantined, [47085462fc8ecd69b85efe808f76e818], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6458D1D7-DA3F-47BE-BF51-F28DAE72773E}, Quarantined, [1b34ab0b24660d2990850d719b6a2fd1], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6478360C-74DE-457B-9165-F51063C2217B}, Quarantined, [3d1211a579113501799c94ea0ff6ab55], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{64A71C6A-A42E-4E9B-B283-932E61ACE8F2}, Quarantined, [9fb040766426f541f323f38bd5305da3], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{64D11568-2E59-42CA-95E2-2D20744AC5B2}, Quarantined, [f35cf4c22f5b4bebe62f2d51a65fb64a], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{64DCA81B-82C7-4A8C-933F-BA9BE8952BB6}, Quarantined, [8bc4d2e46a20db5bb85e94eaa263916f], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{65638577-8D34-4EAB-BF9A-905AD9CFF49B}, Quarantined, [3e11991df99171c5e92c85f9b94cbc44], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{65A4E2BC-3C0B-4DD3-88FD-6F1B3E4B74B0}, Quarantined, [ec637046e7a3e650d83e26587e87ba46], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{65E541C2-1A8B-48D6-B88C-3064C32B2961}, Quarantined, [52fd3185d4b636003dd9a5d921e47b85], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{65ED8C4C-EB17-48FE-8AC6-30155D99408E}, Quarantined, [e6698f27d3b7a88e42d39ee050b534cc], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6600EC8C-9501-4A8F-B7B2-1D9A4474569B}, Quarantined, [74db486e781248ee0114b9c5679ea55b], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{66DC90C3-4CD4-459E-8EA4-15BD73B64E1B}, Quarantined, [afa0c9edfb8fb185f323fc8246bfe61a], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6763A4AB-5D9B-455F-806E-FF2ED039C9DA}, Quarantined, [e36c1f9716741323b46189f546bf28d8], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{67A6264F-D7D3-486F-9870-D5479671D6A3}, Quarantined, [c38c7d3968220d29fe187d01f312d927], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{689053DD-5B84-4EF9-9BD2-D29D2040F5EC}, Quarantined, [f45b7c3a4b3f12244dc85925030212ee], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6963953B-B690-4C81-B746-8FD56180EBED}, Quarantined, [fb54d3e3e8a2f73fa1756e109174db25], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{69FFA09C-21B5-47F8-B393-A383BEA4B64F}, Quarantined, [88c76353f5958fa78294f38b70950af6], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6A1D66C8-3594-4589-A686-668ECBCC2A68}, Quarantined, [f35ce3d339511422d93d552923e208f8], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6AC13D3A-2B01-44C6-8EAD-9E17DB26C711}, Quarantined, [66e95c5a5a30072ff81de896a263a35d], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6B02DC7B-4821-47E2-82A4-18D7B81A43BE}, Quarantined, [440b6a4c95f5fb3bb85e0777e223b44c], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6B18325F-6704-4E25-9989-C665B8ECD9CC}, Quarantined, [3916c0f6404a47ef15003d41ab5afa06], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6B1E9C0F-E6BA-4968-8ECB-FC156CC5E7B3}, Quarantined, [c6894373d3b795a12ee7304ee322c23e], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6B34A478-DB21-4D59-A6B3-534715D792C8}, Quarantined, [212e0bab632765d10d0884fafa0bef11], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6BFA1E15-A89C-46AD-BF50-495E8FE03570}, Quarantined, [cc837640038702349c79344a34d116ea], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6C1D92D5-C2A1-44B2-BF62-FE8DBD86DAEE}, Quarantined, [153a42749febce68ce476d11f114c040], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6C43C51A-CED1-48D5-BA21-512249AE595D}, Quarantined, [17388a2c3654033318fe512d7a8b7888], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6C62F9F4-6DE1-4CED-B339-B91A65B91A7C}, Quarantined, [53fcd0e61773ee4835e0047a6e97d12f], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6CB0B738-1E72-4E2D-9E9B-6CEB89CEF046}, Quarantined, [d679cfe735550b2bad685d2121e40df3], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6D1BF86A-9761-4327-9B89-D8712C4B8179}, Quarantined, [60ef16a0c2c8d75f58bddca22bdad52b], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6D806E83-EEA1-4F2B-8956-D4F7D5272B1B}, Quarantined, [014e5660f9917cba997c90eee91cbc44], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6DBC98EB-602B-4779-8799-7730188AC292}, Quarantined, [d57a783e22687db936df5a247d8860a0], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6E17FEEC-69FF-4DBD-ADB9-7F62C7B84A83}, Quarantined, [69e69e1869217bbb948285f9e0253ec2], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6EA2B055-E68C-4F18-8BE6-E72743A97DE9}, Quarantined, [044b8234f7939e98f02678064abbe818], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6FFBB3D5-46A3-433C-BB51-BA2F9E4F3237}, Quarantined, [e16ee1d51f6bc571ae673549ec19867a], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{707CD64D-1280-4D2B-B2E3-59DAE25F5CE0}, Quarantined, [3817783e1971d16561b56519b154a15f], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{708932E4-44D4-4D56-BC6D-569918B71981}, Quarantined, [c28da313afdbaf8734e10b73d2339b65], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{71BF600B-1847-4C18-8D28-C12469DB64B2}, Quarantined, [87c813a35e2cf541e3333b438d78fc04], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{723A54C6-5CF1-4B0F-99E2-7BE99AAA83E9}, Quarantined, [400fd5e1f7937fb70313d8a634d105fb], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{731F9B5D-D390-48D3-9EE1-776EBF3E1F98}, Quarantined, [f45b189ee0aa8fa7997d9be3d33249b7], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{74429341-32E9-48BD-B387-153C86483B5E}, Quarantined, [b09f684e81094de9dc39c3bb43c220e0], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7452CF12-89DD-4797-962D-E95FC23561C0}, Quarantined, [84cb8a2c94f6c27468ae4a349d682dd3], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{758B2126-9199-4B66-A11B-F9DA118031BE}, Quarantined, [cb841a9cddadf93d4bca2c52729325db], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{75D26C9E-101C-4394-9E2A-302FF1763DDA}, Quarantined, [2c230ea8c6c4191dde371d617b8a55ab], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{75E08653-95BC-4E9E-9EA0-42479E99D56A}, Quarantined, [0a4506b0c7c3c4728491ec92798c13ed], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7773BE5B-4C3B-4187-8D37-84E68145CB63}, Quarantined, [4e01971f90fabb7bdb3b97e70ef79e62], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{793901E9-1F3B-4986-89F2-29C8C3B429D6}, Quarantined, [47081c9a5535300648cd65198b7a768a], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{79C3C8F4-AB5E-4DB6-8B5B-BA8FD433C71A}, Quarantined, [f15e1f976f1b0036fb1aa5d99f66a65a], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7AC56D63-3137-4770-AEE5-D2E287C07D8E}, Quarantined, [df70e0d68406ae8865b0562828dd7e82], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7B48D0F2-A669-4F89-BFE7-21A119D11272}, Quarantined, [133ca5111f6b1b1bb85e126cea1b8977], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7BA0FDBE-AF1E-4370-9B6E-739F12E4D323}, Quarantined, [36191c9a2d5d86b047ce671734d12dd3], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7BD13572-D218-4507-995A-717CFA2294F2}, Quarantined, [e66944720981c07656c0295521e41de3], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7C55DE0C-B5D2-4E58-96F1-712F431543CC}, Quarantined, [70dffcbacac061d50e073c429a6b48b8], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7CB0F535-F79B-431F-9F89-C62DE8904784}, Quarantined, [034c4e681f6b2e0830e5413dfa0b4cb4], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7CEAA049-EF1D-4AE0-8FA6-C6BF7C763529}, Quarantined, [f659b8fe593147ef17fe5a24a75eb848], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7EBD6132-4AB4-4541-999D-44A4A581C074}, Quarantined, [56f9c5f12d5dc076b1642d5146bf6f91], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7EE2F444-9C8E-4312-9C7D-1457971234C5}, Quarantined, [3b14aa0c3d4db87e7b9ae99535d0c739], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8038E6E3-EDF1-44D2-B872-F8F7473C7A8F}, Quarantined, [321d5363d1b9c2744bcb334b20e555ab], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8043200A-CC8C-49A7-AE35-E8FE32304BED}, Quarantined, [2c23b6003a50979f37de79058580c13f], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8068755A-9D2F-4D00-92E1-745B64EF4454}, Quarantined, [212eb8febfcbc86ef61fed91887d8779], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{810BDB06-AE0E-4721-9794-5ED0F6C9EC1A}, Quarantined, [4a05199d0882072f1afb3e40e81da957], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{818FE36E-2A1C-4F6A-BBD6-359FCD84F3A8}, Quarantined, [f15e6a4c94f6013550c5bdc1a95ce61a], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8229987A-FA7B-44E3-8CD1-7B9468BD8D13}, Quarantined, [d976e1d50d7d79bdcf47e19ddd287f81], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8249F450-3BFC-4943-AE8F-A5A241CDD03D}, Quarantined, [3e118a2cfe8c241291840f6f887d9b65], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{830A319F-DFC0-462A-A7C1-281F4C9EE3D5}, Quarantined, [3619dadc3b4f3df98d88fb838d783bc5], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8335A4CF-8F32-4B64-8D98-791757C7CF3F}, Quarantined, [60ef09ad602a2610a86d8ef05ea7d030], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{83CABE35-7791-4C7D-B729-37D47E4D286D}, Quarantined, [da759c1a1e6cdf572beaf88659ac7090], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{84531FCF-BBD3-4CFB-8068-ADB7C7884A41}, Quarantined, [301f9422dcaeee48e62fb7c77392ec14], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8471FE29-87F5-4131-A281-79EA9F3DEA3A}, Quarantined, [9cb37f37692189ad54c2ff7f8481de22], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{84E98500-E544-4458-B0D7-8AF4C85265E8}, Quarantined, [1f308a2ce0aa1f17a274126c2dd89769], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8555A638-8C24-4631-B5AD-B5961BEEF9EE}, Quarantined, [bd920da9fd8dca6cbe576618fe071ce4], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{85A26963-FB59-4FD1-A9DE-6E18E52B2542}, Quarantined, [a4abf1c57119c670c551631b59ace31d], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{85C209D8-F6E3-4A08-A1CC-243C45371531}, Quarantined, [450ac6f03e4c9e98090c017dc0456c94], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8601159A-1C01-445A-9EEA-26AE961319E7}, Quarantined, [a7a8bff71971e650987d9be3d134ff01], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{86B89EAF-DA3A-4443-81EB-EBAE9E2138E2}, Quarantined, [a9a614a25733ad89e92cd6a8d035966a], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{86EE1E09-D2D2-4FFC-913D-4DB0C3AA1691}, Quarantined, [d07f0caa24664aeca075b4cad82d07f9], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{87322792-F5F2-40DD-9FFC-B3BF2BEE26DD}, Quarantined, [252a2d89f29847ef27ef760858ad946c], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{873F0931-32D0-4CB7-A277-EAC07C60AEF2}, Quarantined, [6ce3ffb7e8a22a0c03127b0317ee5ea2], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{87DC8583-D6FF-4872-B0C5-EDD86E41EB55}, Quarantined, [82cdcbebdeac59dd75a0334b9372e020], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{87EF7491-935D-4AA2-A882-CDEB582A135C}, Quarantined, [4a053c7a3555ef4739dcb8c646bfd22e], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{898B2938-5F30-4864-98C4-D3797030ACD8}, Quarantined, [6ae58c2aa0ea0e28987d116d7c890ef2], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{898E2C30-D886-4C82-A226-173FE69F4EC3}, Quarantined, [dd72d4e27c0ec670d5419ee0e42139c7], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{89DDACD0-0D24-463D-878C-D5C921345790}, Quarantined, [7dd29f1712786fc77d990c727491be42], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{89EBF78E-97DC-423A-81BB-F029EDD5F779}, Quarantined, [9db274422565d2640015f28cf11458a8], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8A28FD3C-5164-42D0-8080-C06F4AC69776}, Quarantined, [09462294f1996dc95fb7c2bcbd48ff01], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8BBD11C7-6303-4032-871B-FC33442FE6F1}, Quarantined, [2a252096b7d3ff37ae680b73a95cdb25], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8C0643F6-6218-4535-9758-D57996EE7631}, Quarantined, [37186353f09ab97d7e983648b74e1ae6], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8C1F3ACB-E9C2-4E11-B4A4-DEEE3726A8B9}, Quarantined, [72dd6e48b2d88bab9580eb93fd0818e8], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8D795E31-AD58-462E-AF27-E32BD2C6695B}, Quarantined, [d87760561c6ef640b85e4c3247be4db3], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8DC32C5A-94C9-48DB-9681-97B14683AEA9}, Quarantined, [65ea4175f397f442cc494e3035d0f010], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8DD9B84B-9087-4F93-8BEC-224573ADDB6F}, Quarantined, [85ca0caa7c0e41f525f1b8c654b1c739], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8E2A79E3-AAEA-4035-AC42-E627B1A540A8}, Quarantined, [341b3680f298b185ef276717867fde22], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8EA52625-A707-4C33-8481-441E1C921111}, Quarantined, [3817328465255dd965b1423c33d2b749], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8ED293A3-C86D-4DBD-8F1A-6E811AE62E13}, Quarantined, [88c74c6a256578bec451b1cd08fd57a9], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8F0C0E11-FED0-46B1-9EF7-3FB56741D7C4}, Quarantined, [1b3420968604082e0a0cb2cc9c6921df], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8F1D9174-CCC5-4C53-89D9-BFD52CA0CE90}, Quarantined, [fd52fbbbcbbf2016967f542a4abb0ff1], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8F674DE1-9F43-4277-817F-B33898457EB5}, Quarantined, [d47b8c2adbafae88769fa0de12f318e8], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{909DF3F9-8256-4771-ADDC-8CBF5AB77C30}, Quarantined, [bb9443735f2b79bd4bca730b57ae21df], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{90CCBC37-686E-4276-B03B-E72A50638657}, Quarantined, [4b04a0168efcca6c52c3314d8f769c64], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{91167CE1-6AA5-4862-8C44-1BC11EB57178}, Quarantined, [133ccee88cfe68ce71a47fff669f936d], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{915CF0F1-F629-4079-9546-704249F4A6BE}, Quarantined, [91bef3c3c4c6e6500e08304e3cc941bf], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{92315668-F94D-49E9-B67F-66C8FBBC1973}, Quarantined, [69e65b5baedc38fe3fd696e850b56997], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{92AC8BA9-73FB-4282-8289-FBF2AF64A67E}, Quarantined, [75daddd9830751e54acbf8866e97cf31], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{92C197E1-D3D3-473C-90DC-6353FD67941E}, Quarantined, [5ef1b4023c4e13238d894e30cd38dd23], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{930B6774-3FBF-4E65-A7B1-B344A97DBA52}, Quarantined, [94bb5a5c167454e29b7b007e10f53fc1], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{93B5E111-1786-4593-B71A-2061E7F63674}, Quarantined, [2d227a3c642639fdc352d8a6cb3a2ed2], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{93B90287-4E12-4659-B2C6-C7CE5AE2F662}, Quarantined, [65eaf4c20c7ef83e7e9897e7d72e4db3], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{940130BD-67E0-4547-8842-C3A8699E7515}, Quarantined, [f35cefc78208d4628393126cf015857b], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{940BE16C-81CC-4BC2-98EC-A1D7E2C5ADAD}, Quarantined, [f956fcbae7a349ed7a9c116dbb4a46ba], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{944FC134-84FA-48B4-BDC8-3CE5946322E0}, Quarantined, [84cbb2043e4c6dc9080ef48a5ea7f709], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{947562ED-6274-41DC-85F9-8DA1816CF52C}, Quarantined, [a1ae8e286a2094a2be58334b20e5649c], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9563C382-1C0A-4280-8033-5A2D3E9A546B}, Quarantined, [7fd0b8fe553588aee4325727f510d828], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{956EEF6C-455A-4DDD-BEBE-DC91E828BCC1}, Quarantined, [e06fcfe71a7043f35fb688f6de2742be], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{967D9642-F408-458E-9940-C21C1ED4F989}, Quarantined, [5cf3c4f2365479bdc84e700ec24324dc], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{97BF45AC-30B7-4DFA-B5CD-4BE726CD716F}, Quarantined, [68e7ecca5e2ceb4b070f542ae223728e], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{97D071B5-A04F-48B5-9919-50317CB88FAB}, Quarantined, [64ebe2d4008a7bbb2ee8ed910500ac54], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{97DE8C9E-D7FA-4010-9489-5D74632FAC82}, Quarantined, [67e86c4aeb9f4beb67aec5b9887d4bb5], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{97F29A76-9787-449C-8AD7-A11F3D2DD397}, Quarantined, [64eb8234a1e994a205108af4828342be], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{980A78F5-7B2C-4084-BFEA-A93544E3D7CF}, Quarantined, [de7102b44f3b55e1c254ee90c14418e8], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{989F814E-6EC9-4DEB-A63D-751A8F2B3E35}, Quarantined, [9bb45561731739fdc4520e705aab3bc5], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{996EA048-2E40-4912-973E-E74C7A643ED8}, Quarantined, [d778bdf97713e74f090d2f4fc04517e9], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{998F9FAE-5F5F-4EBA-9F9D-596B7667CBA4}, Quarantined, [fc5303b37b0f9c9a0115077717ee09f7], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{99BB7866-E0A1-448F-B8E3-A593C26BE047}, Quarantined, [95bab2043f4bb97db264d0ae09fcc739], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9A36ABDC-6AC2-4E5D-87C1-3D2A8016318E}, Quarantined, [3b14bcfa93f70f27a274324cd035f10f], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9B66A370-C9C9-46C9-8EAD-6B17E435D244}, Quarantined, [f956f1c5bfcb9d991df8b9c5ee17fe02], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9C86EA24-BC85-40CE-BACF-2C3A95F16CC6}, Quarantined, [83ccc0f6f694a39340d6205eb94c0df3], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9CC00DE8-7AFE-4629-8B30-A868AFB55220}, Quarantined, [4a05efc75337082e7f97621c48bd7f81], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9CF02FCF-79F4-4640-BF2E-D67E33D9338A}, Quarantined, [b39ce5d1a7e3e056c64fcdb18481758b], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9E1E6175-50E0-4665-8494-373D592311E2}, Quarantined, [d27d40764e3c1125c94d36484abbf30d], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9E508180-A9C3-42B4-8D15-E6BA8E92999D}, Quarantined, [48075d5996f4b086a76fff7fa3627d83], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9EFB8942-6E90-4DFC-8D98-26781DBA77F5}, Quarantined, [2e219b1bc2c8d3639382e19d8382be42], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9F3385CD-99D0-49E5-8662-A2CB7BF5BD67}, Quarantined, [09464d69e3a7a49295803f3fc144ca36], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9FFCD4CC-C013-4623-8762-239FC294E834}, Quarantined, [430c9d1954367db952c33846cc393cc4], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A0EE8370-3DA5-4F1A-8D28-79A9C6772A62}, Quarantined, [470804b2286291a564b1007e8184d32d], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A1154187-2946-4941-97BA-5E46608231B1}, Quarantined, [d07f5660ef9b77bf5cb9e7978f76c040], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A2539C55-4371-45FE-96CC-529D41E4EB98}, Quarantined, [85ca5462e4a645f120f55c220cf9d927], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A3BC47E5-AD94-4FDC-8F5E-AB785CDB97BF}, Quarantined, [d8773a7cbbcfe353df37d0aee52005fb], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A3CB6150-3A1D-4E2D-9CD0-71BFD1ABF152}, Quarantined, [4807288eec9e62d467afa4daf01541bf], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A3EFC03C-4FD4-4368-9BAA-DA9CA841149C}, Quarantined, [e46b8a2ced9dfc3a19fdc4ba8580d12f], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A410A546-7A20-4DB8-BB1B-906777B2CBE7}, Quarantined, [cd828f2748425cda23f26519f4111ee2], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A45CB193-B89E-44E8-89B9-E54F3D8D6B46}, Quarantined, [56f9d0e60f7b63d3888e651934d1b749], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A4E85A71-1DAB-4A88-8328-674EAC72866F}, Quarantined, [ed623d790d7db87e39ddb7c721e4e21e], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A5227588-A98E-4D92-92BF-FAD9B1E9F867}, Quarantined, [68e75d59098171c562b3e39bcc39b947], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A56310BD-ABD4-4CA3-9B83-ACADB2F9D452}, Quarantined, [4609f2c4206a1521c650e5991fe659a7], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A59696F5-F091-436F-91C1-628111641C63}, Quarantined, [68e77b3b8802e650b362423c0005c739], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A5B0DA9B-6703-49D4-90A3-6CEE54729A6F}, Quarantined, [d27d07af41492115e92df6886e975fa1], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A621A61F-E71B-450D-9C77-587A1495472F}, Quarantined, [7bd43f77682246f0fb1b5c22ec197f81], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A63E8236-EB85-4A06-AB1A-C9F457EB7F17}, Quarantined, [be912591701a7fb717ff502e51b4cd33], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A6615DC4-3E43-492D-9DD4-844ED863E448}, Quarantined, [5ef193235b2f43f3ed28abd3cc39b947], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A6F9C3E2-3CE2-49DC-8484-36D3DD75247E}, Quarantined, [5cf3288e4e3cb482ec2accb2cf36966a], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A6FEF922-B252-46D4-9685-29E95A8A481A}, Quarantined, [aba47c3af892ce681ef8f98537ce1be5], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A7A93E34-B9C6-4C03-AFCD-F37F336A3193}, Quarantined, [7ad51a9c7e0cf14545d092ecb352eb15], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A7D5FCE9-44AE-4292-891F-7D6CDCBDDA10}, Quarantined, [ba95585e7f0b063021f48cf2ec196e92], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A805E0C3-B902-4C6D-8361-1E1BD0EC8271}, Quarantined, [103f5462fc8e1b1bcc4aacd2897cd22e], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A81346F5-47F3-4BB9-8167-39292AF2855A}, Quarantined, [3d123383cfbb81b54acb542a6c991de3], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A81DF0E6-D2E6-460A-9BF8-2949E65B2F7A}, Quarantined, [61ee4373008a58dead68e49a867fd927], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A8EBD043-6E27-42FD-AD40-4615E9C0E130}, Quarantined, [81ce7442038778be2cea2e50ae57956b], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A939590C-C430-4813-AEC3-4F4241ED6656}, Quarantined, [dd72cde98208df57bc59e39b52b332ce], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{AA19F068-E317-409C-9990-627741D05081}, Quarantined, [c48b526402881422a571eb93ec19c43c], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{AA26FB54-9C1D-4EBF-80C9-A8D036543186}, Quarantined, [8bc421953f4bc96d6da8017da362a65a], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{ABFD648C-265E-489A-8876-F4CCC666324F}, Quarantined, [242b4571a0ea5bdb1afba1ddb35248b8], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{AC21F455-A985-4BC3-9DF3-9152E292D979}, Quarantined, [3c13bdf914766ccad93d9fdfa1643dc3], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{AEC45D7F-4FDC-404C-BAB9-FE8F1DE797A7}, Quarantined, [77d8ccea305a12241ff65e20ec1932ce], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{AF136B5D-4043-4C7E-A9FE-B379B15673A1}, Quarantined, [212eb402444639fd42d3e5999e67c13f], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{AF4A1904-3124-4134-AD2D-E3197D2C1BA2}, Quarantined, [c38c3a7cc6c4e74f3ed7d8a6dd2808f8], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{AFA598EB-A8F2-4455-ABC4-1F1622D25126}, Quarantined, [51feccea4f3b4aec62b38df18085728e], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{AFA940D8-5815-4664-86EE-B6BDF532E9E5}, Quarantined, [91be76400d7d54e2e531700e7b8a738d], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B0012DD3-83B0-42FA-8B47-8444E9F14D25}, Quarantined, [cd822096f79394a2be58ceb0c441f50b], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B0CBD6A8-279C-49B3-A476-F668C5CEF29C}, Quarantined, [8fc09b1bed9dfd39b85d7e0046bf6d93], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B176A35B-5F4D-4082-AF82-AF18E31F36CE}, Quarantined, [1c334b6b78124cea021481fda46114ec], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B1AEFEAA-20EA-4D86-9525-EA48FC8D7ECF}, Quarantined, [a8a7b1055e2c989e69ad2757ff060af6], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B2246094-17FF-42AA-AFDA-5E128E2AC5E1}, Quarantined, [afa0dbdbc6c486b0a0768af456af09f7], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B2A5859E-FEDA-4F76-AFC0-21EAE7C52BEC}, Quarantined, [470895214d3d5ed8bc59700e34d1748c], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B3D0D1E7-6037-4345-9078-FBC16D6F60D9}, Quarantined, [b798c7ef2f5bf640e62f3846e32230d0], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B45094F2-815E-4CF4-9F12-F3D0187CBC18}, Quarantined, [133c2e88d4b6f73fa274ea94689d7c84], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B45ACE54-FF3F-47A9-B2C0-96163851DB5C}, Quarantined, [301fd1e5dab00b2b070e641a5ea7c739], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B475BB73-371C-43FB-9419-399B586A3D14}, Quarantined, [68e71c9ac0cac96d0214502e04010bf5], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B47B9F35-EF5D-4A76-A5C5-812CE2706A7E}, Quarantined, [d27d80363b4fc17569ad0c7272935ea2], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B49F45BE-CD2A-4880-AF95-BE94DDA0C9E0}, Quarantined, [afa0f8bef99153e30f063648ba4b06fa], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B507220C-7153-4DE3-8052-6AFA2B4B2215}, Quarantined, [85cac3f32862af87b95d7a045ca9936d], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B5D46B22-A820-41E0-9953-B4D17A8BAE23}, Quarantined, [d37c6056b1d9a49270a5b5c9c83dfd03], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B5DE8D1A-A55C-4940-9B7F-8C165BA01BCE}, Quarantined, [143bbdf9ef9b3bfbd3435f1fb94c0bf5], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B7C3CDA8-4BB4-4337-8A79-1F3F1C768E4A}, Quarantined, [ada290265f2b7bbba86dd7a790750ef2], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B80C4C61-162C-460C-80F6-BED8AE493BAA}, Quarantined, [f45b04b2ccbe55e10510b1cdce37837d], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B91897BB-E5A5-4D69-BB6A-66F43B6F75F9}, Quarantined, [61eebafcdeac5adc8c8a4d319a6b5ba5], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B93998FF-EBAB-488A-B9A7-FF6EA65014DF}, Quarantined, [da754b6b6327bc7a6ea85727f90c6997], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{BA008C75-E7B7-4909-B6C2-5219B3F38ED9}, Quarantined, [b09f387e0189e25441d44d3113f214ec], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{BA85107D-CEA6-4134-834B-4AE56386C4B5}, Quarantined, [5ff0caec92f8d0667e98e29cc144649c], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{BC5714F6-40B5-4EF1-8A9C-11131D387451}, Quarantined, [67e84571f09a5fd77a9c1f5f9d68649c], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{BCE1AB6A-BADC-46B8-B553-9D50E6DD9DBC}, Quarantined, [ce81a0163c4e89adfe17d3abab5aee12], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{BD903554-491A-469C-9968-CC1C3737F64C}, Quarantined, [a1ae6f47e0aa7eb8c451e19dc14425db], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{BE3D653C-8DE0-4638-9B10-BDCBB7B79825}, Quarantined, [80cf5165c9c15dd9fb1a512d1beae31d], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{BEEC60BA-2B69-45D7-82A5-B4F5C2BF2EAB}, Quarantined, [83cc3482acde1521dc3a6f0f6d9858a8], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{BF693D9C-9860-456A-8AE2-FE20B1A8D7B5}, Quarantined, [f758e9cd375338fe799da6d824e1f808], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{BFDD074A-DA9B-4C8C-8B2D-76D929BBEC5E}, Quarantined, [c18e2294fd8d9c9a3adc403e4db821df], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C0AAFDA2-91D8-46DF-B9FD-A1687B39FF1E}, Quarantined, [bc93e4d21d6dcd69080ef688ab5aa55b], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C1F1EF66-D552-4590-B8D6-3AA9166126EB}, Quarantined, [6be45462c1c9e551c74e423c6f96ed13], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C27857BF-4574-4510-BC59-A37A17856C22}, Quarantined, [7bd426909cee9b9b38dd532b9372b34d], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C2ADD5A1-FBBC-483F-A872-FD423F25BB6F}, Quarantined, [1837397d6f1bf73f7a9b18669f66817f], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C3003382-1E5E-4FEF-80AB-81F7C66939F4}, Quarantined, [89c6981eff8b1b1bd144add110f5669a], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C35B3D95-4F89-43B5-B4DA-AB6FCCAC27CE}, Quarantined, [5ff01b9bff8b34020e0782fce322b44c], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C36FB017-AE84-43D5-B83E-8428E7D1AE7A}, Quarantined, [eb644c6ae9a1aa8c06101e60c63fe719], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C3757E3F-E546-40A5-A626-D58C7FAE44B9}, Quarantined, [b19e84322a60082ee530aad4f312629e], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C3AEEF1C-D169-45A4-AD36-AD20C763E894}, Quarantined, [f15e2492dbaf2d09c94c4638996ca858], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C4001CF2-D5D3-4077-859C-FBA174A2F83E}, Quarantined, [b996724441490036789d4f2f8e77738d], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C4FBA2F8-7335-4E1B-8E2B-3641D3CD65C0}, Quarantined, [4e017b3b86044bebd244e797c540639d], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C50E4E3E-BA11-4869-AA9D-81E23F68F6BE}, Quarantined, [6fe06e4890fadc5a17ff1767b84d936d], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C56F3F14-139B-495D-8AA4-5C528643F729}, Quarantined, [b699179f672344f2bf579de116efa759], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C68D9AD4-6331-4F04-8B6D-D8142377BF7E}, Quarantined, [6ae512a425650f27fa1cd3ab9b6a7888], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C6DA3D7F-E481-4006-A48F-A8BB50232EEE}, Quarantined, [74db7c3aacde78bedb3b3c429a6b8080], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C75C91C8-4D56-4074-965D-F04DABEADB62}, Quarantined, [2a25773fff8bcf67d343f886be478d73], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C78B678F-A13F-4925-8BD1-73823DAE7164}, Quarantined, [60efffb79ded57dfd93d502e31d48a76], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C837A751-C2D6-4513-8F3A-9626557865D1}, Quarantined, [301f84321179f24463b30e7012f3a759], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C84A3873-C7BB-4117-9142-D781EC87EBCD}, Quarantined, [212e2096f298a690f3222d5164a128d8], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C871263D-E744-4A20-8310-108C6AF0AEAC}, Quarantined, [ba95d5e1701a45f1ca4b6e1033d27e82], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C92EBF16-35AA-4090-86A5-CBD845BED69F}, Quarantined, [0f405e588dfdd26468ad225c21e449b7], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C92FCF70-47C2-4FE2-A6AB-BA7A90EB7596}, Quarantined, [113e92248bffa2940b0bd6a822e3d828], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C97E147C-E4FE-408B-9472-CED828491FAC}, Quarantined, [50ff46705c2ef4425bbb5529bd485aa6], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C9ED7304-5214-44F9-AE52-FFA2BF636D47}, Quarantined, [9db290263d4d7fb7be58f6880ff6fc04], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CAB6DE32-FFF7-47F4-8164-A84A23F27DE3}, Quarantined, [ba9515a12f5b41f54ec8d6a815f09b65], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CB1966CD-C34B-4BBD-824E-FB25EC448AC5}, Quarantined, [fe513086573347ef29ed80fe669fc040], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CB737A36-C0AC-4B29-B6FB-B033A2F4226F}, Quarantined, [39161f97355568ce2aebe49a1ee7f907], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CB7B68E5-D42C-4BE0-ABCB-A5C4185B94BC}, Quarantined, [c986b303f39755e193822d51da2bc040], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CB8E2435-3DB0-4906-824A-9C7F5F907A4A}, Quarantined, [76d9cbebaae0de5841d4ec9242c33ac6], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CBFE28DF-F285-4993-9CFD-2925908789CC}, Quarantined, [440b7c3a8ffb072f23f2631b4fb610f0], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CC11E1C5-F9CA-4CED-9774-2429F323555A}, Quarantined, [2a25714589011323a471017da65f3dc3], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CC24B639-ADE0-4B50-887F-2C78C01A5F19}, Quarantined, [c48b8d2957338fa79f76b1cd0401e719], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CDEC0958-1EE5-49EF-9496-31A4CD71FC9D}, Quarantined, [8cc36353b9d16ec81afc99e5c63fcd33], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CE103B4B-F372-4C98-9653-C1675033CB1A}, Quarantined, [9cb33e7889013ff7f81df08e679e768a], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CE33EFC3-1E5A-4814-BDB7-2D7FBDAD3B82}, Quarantined, [d07f3482117988aea273c6b818edeb15], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CE4EA8A6-BFC5-4C99-8DB8-58ECBD882034}, Quarantined, [ef6061552d5db680ec296b130cf98779], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CF570C0F-BD76-49EE-A116-5647E22940F2}, Quarantined, [252a3c7a5c2e46f04ec808763cc9a15f], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CF71B29E-3A95-4348-B5DC-D65168B0C7D1}, Quarantined, [66e9a214f09a1026e630fd8133d2be42], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CFB5FC35-7D9D-46DE-8AA5-DB5733F0A07A}, Quarantined, [36192d893654b6806ea8f48ad82da65a], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D0331C44-EAC8-4197-85F8-FEBB13E44C39}, Quarantined, [8fc0dfd7246680b67d98651959ac6c94], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D044B141-D89E-45B4-AC36-4753B2E13E76}, Quarantined, [98b714a2c0ca4beb0510c5b9bb4a5fa1], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D08F5FCC-64E0-46F4-B64D-EE7D55B29F70}, Quarantined, [7cd3a21476149a9c69ad205e33d2916f], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D0BA3190-B72E-4562-8618-1F7CF9F7A2B5}, Quarantined, [75da5f571179be78b660b6c8fb0aba46], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D120E6D9-A31D-4AAA-9CE5-1D2C973EC8EB}, Quarantined, [93bc1a9c97f3989e6baa631bef16f60a], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D13A1552-385C-47DD-BDC8-8E73E2879E44}, Quarantined, [4807d7df2367ca6c47cea5d926dfcf31], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D19529DB-8EF3-4893-8E12-4E5F2EDBC0FF}, Quarantined, [c18e3c7a2565ef47a66f1b63f80da65a], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D1AFE3E4-EB94-4CB2-8ADC-1953553462C9}, Quarantined, [410e6155018976c038ddcbb3c93c06fa], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D1CCC8EC-55D3-430E-8B44-26ED7A3D6E2F}, Quarantined, [5ef1e1d5fc8eea4c5eb8077737ce5fa1], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D27DBDA1-9091-44F9-9F4C-F64FBD8363F1}, Quarantined, [cf806e487713ff371df9fe803cc9f808], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D355597E-F18D-4262-97BA-38281254A6DD}, Quarantined, [3c134472f991d06659bcaad407fe34cc], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D45EA191-763A-4E2A-9C84-7BAF95333C30}, Quarantined, [331c9f17beccf73f18fdc1bd40c5d42c], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D4A0BFB0-FC4E-46CA-BC31-1433D3FB1D98}, Quarantined, [252a4c6acfbb0234b165b9c5ab5a5da3], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D5710DF7-825A-448C-BF40-54654D8164EB}, Quarantined, [aea11c9aa5e5f93d53c37905669f53ad], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D579EE4F-233F-4404-B6ED-15C36F24307C}, Quarantined, [3718a214bcce171f0313ff7f28dd738d], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D6ACACE5-588F-4829-969E-D598F0912D23}, Quarantined, [64eb7d39cbbfdc5ae531671727de48b8], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D7B25328-7ECA-4956-8E2D-16F691DB478B}, Quarantined, [f35cb1053f4bca6cdc39ea948e77728e], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D7E2CFCB-4993-41C2-A1FE-5262B143FB21}, Quarantined, [df70d8decac063d30412f38bf70ed927], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D823FB6C-8BE0-452E-8742-4639A5A8796E}, Quarantined, [044b4c6a8bff290dca4c48366c9902fe], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D842A344-F6D3-49EA-A790-A7D42742DE28}, Quarantined, [222d7a3c77135bdbcd48265814f15ba5], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D84A96EC-503F-452B-A7DB-AA31FFE884F9}, Quarantined, [7ed1694df793a88e2ee84836c540ad53], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D8856E62-2060-4E57-87CF-594ED52DB944}, Quarantined, [53fcb7ff90fa2a0ca86d92ec50b59e62], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D94B6561-3FE2-4CE1-A85D-B81123351FF3}, Quarantined, [3f10d0e6800a56e0d243057948bdf30d], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D97A0D10-F9EB-4758-8187-BDC3D8C1FA15}, Quarantined, [e46b4670860476c0e135daa4ee17ca36], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D99210FD-31D8-4AF4-9A18-DCAA61149B72}, Quarantined, [a5aa11a5f595c27465b0fe80a3624db3], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D9A7F85C-6FE8-460F-8288-EBC86E33CCB5}, Quarantined, [aba4cfe771196acc19fcb5c9ed1803fd], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D9E4D09D-B031-4879-A686-52615ECF6D54}, Quarantined, [c8870bab01899e98e2344f2fb74e0ef2], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DB65BE06-1F62-41CF-A765-94AAA38B2A4F}, Quarantined, [f956783e91f943f34dc8b3cbcc39aa56], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DBBB773B-BB6B-4E4D-8A47-BDA58C35C643}, Quarantined, [5bf4ecca94f62f07ae681c6244c16c94], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DBF986D3-D97D-4193-AFE7-1855F424A267}, Quarantined, [153a3e78870366d0cc4ac2bc16efa35d], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DBFFBA56-DC13-45E4-B2AF-78BC94A918BE}, Quarantined, [68e76c4ab7d3cd699086abd343c228d8], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DCF65A78-1066-437C-9C51-1D89DA95845D}, Quarantined, [ada24d696822cf67ba5b3c422cd9b44c], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DE03B2B1-5F7A-4AE9-8A53-ACF48634741D}, Quarantined, [e46bf4c2cebca88e0511a6d8ed1821df], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DE70A271-C8C2-45D3-BC9E-15BB951EEAE1}, Quarantined, [e06f476f345667cf8195017d848158a8], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DE89E01D-C229-4E25-8E26-1D3DEFA3F28D}, Quarantined, [77d8bcfa48421224d0451c628c797c84], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DE8AD8AD-8473-4B19-A2BC-C86E3420E392}, Quarantined, [7ad56d4999f184b216ff522c18ed04fc], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DE921321-82D0-44E7-B9F3-ECD738BE815E}, Quarantined, [bd92edc9f991072f63b3cbb334d16898], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DED6ABA2-E81C-4A64-ADF5-9DCD896FF651}, Quarantined, [a2ad8f272d5dff3774a1423c9471956b], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DF261665-25C2-40E2-BE3C-BDF099845B58}, Quarantined, [f45b16a008824beba57105794fb6d828], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DF82B2BA-D30A-4501-B1BB-C7EE5F7614BF}, Quarantined, [72dd0ea887032e08070e601ea75edd23], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E05C4F14-2A68-44C6-9387-6413E13BC69E}, Quarantined, [1f303086aae0b4825db88af4cb3a9b65], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E07A3B09-BFE8-4F77-991F-58C898E615F2}, Quarantined, [73dc35818703270fb36388f622e3b24e], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E0A8A0D8-8D09-4A50-AB4A-B8D26E3E1E11}, Quarantined, [0d429b1b880289ada76f3945d332cf31], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E0F36729-1AA2-46D9-B567-7E612FF0DC27}, Quarantined, [aaa505b12466c07618fdb9c5a26334cc], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E12C2B8C-25C7-481B-9FA0-136E59FBA9CF}, Quarantined, [5af5b5010f7b1b1bc650304e4bbaaf51], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E1F39206-D029-4C84-B23A-EF7117E32F43}, Quarantined, [8bc4e3d33a501125ea2ca4da40c5758b], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E2E32D68-75BC-490B-8494-6B73694F9AF8}, Quarantined, [c8872492256571c513035628d332ce32], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E3671CC0-BDCB-4980-93CC-F254FCCA4A5E}, Quarantined, [7ed1ffb7fb8f63d337df2955fe07ca36], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E4F54ED6-7DBC-464D-A478-7AF04B6D5253}, Quarantined, [c689892df595c5711ef8f38b996cf60a], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E52BAE5E-862A-4CF0-8926-C767F797DDDA}, Quarantined, [92bdbcfaaedccd693adbe797e0253cc4], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E54F60F3-24ED-4A2F-8F2A-9220B8DEBEDD}, Quarantined, [2926417593f7270f1005f28c07fe44bc], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E5700B42-8E12-439C-A070-1180AA4EBC47}, Quarantined, [e56a75414f3b2214e5319fdfb550857b], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E57B9F05-908A-43CD-BF21-7CDD19B34F7F}, Quarantined, [76d908aef793092d1df9156932d37c84], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E5D4D340-2458-4F7D-AAD1-BFDAF78FAC3C}, Quarantined, [84cb8b2baddd310541d4afcf2fd6d22e], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E60A8018-A08A-4059-8637-2F305D909386}, Quarantined, [014e7046573390a666b06f0ff80d3ec2], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E72BD8B9-9EF4-47CE-BC16-8A1DE36A9C77}, Quarantined, [87c865518208072f39dd75094db8f50b], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E72D5B4B-489C-4533-8E8D-F0AA7242429F}, Quarantined, [e768b2048ffb73c392833a44a362f709], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E73E5E72-4585-4A7D-B13D-7071F022F412}, Quarantined, [1d325462028842f42ee82f4fd82dd828], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E772A5C5-8F6D-4541-944B-D46D4E8D7899}, Quarantined, [cc83e0d67119fb3baa6b4c3265a0a25e], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E7E41E3F-AECA-4E94-8586-E036F0AA5D42}, Quarantined, [76d9863066247cbac353b0ce6f96ef11], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E7FD9FF2-2A44-42D9-BE9D-C7D99BC9F4B0}, Quarantined, [60ef694dd5b5b97d8690522c8d78ca36], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E808C9E8-8332-42F4-B3FF-F5412F9CEF6A}, Quarantined, [440b6254deace0567c9a96e8db2a8d73], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E8973C47-EA5A-4EBA-A29F-AE512BA1CEEC}, Quarantined, [1e31aa0cff8b50e63fd7601e09fc3fc1], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E8B776F8-9BBC-420A-B923-A6AB95371467}, Quarantined, [fa5572445238af87b461f08e51b42fd1], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E8DEDDBB-1E7B-437D-82D2-8A8945572AE5}, Quarantined, [77d86b4be0aa03331df8ed9114f1cb35], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E923A5B9-A57F-4F38-ACFA-1623E4E6719B}, Quarantined, [301f3284b9d1d1650d0892ecf312f709], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E9AB667E-B6E5-4EFA-BB33-796EA89D60D0}, Quarantined, [c38c0da95f2bbd79e0354c3257ae758b], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E9C4C7BB-1218-481A-B09B-40882F1B514F}, Quarantined, [e669298dcfbb8fa72cea76080ff6ea16], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E9DC3EB7-F7E0-408C-86D4-F89A1FFCFE5C}, Quarantined, [83cc9b1b42483bfb7c99344a8f76ef11], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EA855EB1-F572-4C7A-A6A0-C8777F8ACF47}, Quarantined, [d87774429cee0a2c10066a14e81d0000], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EBD9235D-3B2F-46CA-96D6-5592673A46E3}, Quarantined, [07489d19e1a92d09de38601ef510e21e], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EC147239-19EB-4625-8212-B0185885D887}, Quarantined, [bf90e3d33d4dae88cf463c42010408f8], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EC7D6633-37F0-40DF-95CC-99DB45DCD1C7}, Quarantined, [58f74e6891f9cc6a4bca146a5fa639c7], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{ED0B5441-2E19-4262-A9E7-BA432AE381C3}, Quarantined, [0946d4e22169e84eee28017df01549b7], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EDE4343B-68C4-4FCC-8CFD-EBBF3F182A88}, Quarantined, [351a54624446ca6c0b0ad5a9689ddf21], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EE2EE310-9A8A-40F8-93D1-9490CE6BF371}, Quarantined, [ea65674fcfbb270f68ad6d119c6916ea], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EE85F9E5-430B-4A01-B5CE-A641F1B2B8B8}, Quarantined, [47083f77c7c310263bdab5c97392a060], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EE8EED38-E186-4FC8-AE7B-CD8683263D3B}, Quarantined, [fb5491255634c86e5fb7324cd431e61a], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EF397A75-60F6-4E87-8B32-34CFA39B53C9}, Quarantined, [54fbd2e43d4dfb3b2de9d5a915f0b34d], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EF5D9AA9-A7EE-4B1C-9212-4B7978D8BDD3}, Quarantined, [7ad59d193654082ed63f67178283b34d], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EFD10EA6-170D-465D-A725-451DBAE1AB9E}, Quarantined, [57f8a412543643f37c9ad3ab1beab64a], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EFE0F177-CE24-4F36-ADCB-5D9F21E6DD3F}, Quarantined, [2e21ecca1f6be84efa1b3a440df8649c], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EFF6EE17-A27A-4F55-A66A-2DD78F42E38B}, Quarantined, [4e0106b08208b284f2232b534db860a0], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F01FD24E-361E-4B7F-8458-E29AB0B76B5E}, Quarantined, [a0af694d771355e1b95d720c010445bb], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F09FC1A7-6AAD-489D-B721-487F20FC5226}, Quarantined, [d47b7a3c6f1bce68878ef48ac63f8c74], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F0B60918-7289-4FA3-B26D-478580AD45E5}, Quarantined, [88c707afd9b1ed4949cd0876a16427d9], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F0C0B402-A229-47EE-ADC1-A015B891C980}, Quarantined, [0946a016bfcbde5817fea5d97d88718f], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F0CA179C-C7CC-4E93-B0FB-616DB5B8677D}, Quarantined, [f25dc3f31f6bee483fd77d01be47837d], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F0FF68B7-1537-4C77-82B5-4026B68C7154}, Quarantined, [c38ca80ec8c239fd35e197e77c893bc5], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F1C03FF0-3B8D-4B32-A4E7-DFE1D0881BEC}, Quarantined, [86c9585e4941dc5ae530f589be47d828], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F1F535A4-FBB1-4AFE-A8D7-EECCE74E2695}, Quarantined, [321da2148bff79bd85900b730203fd03], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F29FA44F-941F-4DEB-AF54-46893876DDB7}, Quarantined, [e16e0fa70f7b0036b06699e554b1c23e], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F2C2A039-57B1-431C-8D16-B75422EA4918}, Quarantined, [b39c06b08901b383a274314d8283d12f], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F2F0A260-FA5B-4AF1-9197-4B19EAA339E6}, Quarantined, [222d06b0f496ef4746cf6f0fba4b11ef], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F33B818B-13B0-4923-9EAC-EB3E7C985DB0}, Quarantined, [1936c2f4dcae9c9aa175116dc93c3dc3], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F3A181D4-BDBC-4763-9DA4-38E4EB3C6135}, Quarantined, [133cf3c39deded49997dc3bb9471a15f], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F45126EA-9462-456C-A617-C6AC66B5EF98}, Quarantined, [8bc47e38305a1323be573f3fd4314bb5], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F476BEA8-C534-49A1-B5CD-6DCE39B7FA92}, Quarantined, [9bb483338703c47263b2ceb0b64f9070], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F49E8933-5FFB-4F01-8349-3CA5F22DF5FC}, Quarantined, [450a07af16740432c74fb3cbc93c27d9], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F4CF303D-B4CC-46F4-8CFB-CFEC555961A1}, Quarantined, [a7a89620dcae37ffa27387f73cc949b7], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F554DA5E-D2ED-41AB-AA41-BA1ACA74A549}, Quarantined, [113e7f3709814fe7ea2cd0ae966f35cb], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F5A909E5-F237-4AEC-9A83-56EAC0B6E892}, Quarantined, [143b2195a6e46ec8b362d7a75fa62ed2], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F6002B6C-D5EA-4D1B-919A-132E197678CC}, Quarantined, [98b720962268270f35e13e4053b2f20e], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F7486085-390A-4123-A41D-F6BD79CABBBF}, Quarantined, [f15e00b6b2d889ad9e78a5d93cc922de], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F879A82C-34F3-4933-BD93-ADDD2F77F510}, Quarantined, [7dd29d19731739fdf521f18d09fcf808], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F8E55F0A-BF44-45B3-AB95-675CDE2A2654}, Quarantined, [a3ac674fafdb2412d045a9d5a65fa25e], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F9639BAD-9BEA-4877-B720-91C7289836D7}, Quarantined, [55fac9ed602add597e980678af568779], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F99300BE-9556-475E-8939-441E6E87887A}, Quarantined, [49065660a5e510261ff6611dae5758a8], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FA549D59-8621-4CE3-8C82-D67690866EE8}, Quarantined, [50ffb501206adf572de98ef0e61fab55], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FB16AF2C-246C-4C11-9753-21DEF38D61F1}, Quarantined, [0c4380367614ab8b3dd86e108085a55b], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FB4D748E-AF3D-4C1D-91A3-856DA8991AD3}, Quarantined, [351a3185494179bd20f5502ee4214ab6], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FB9073D8-1532-4D9C-B464-73B36F783C91}, Quarantined, [79d62690c9c184b2ef2780fea263e917], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FBD787C2-4A3B-4711-9C49-8524E8C9A9A6}, Quarantined, [84cb40767c0eff37c25425599a6b13ed], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FC08746B-EA08-4C2C-84B9-F4ED4B4C254B}, Quarantined, [9ab514a2c2c89f9700153b4325e034cc], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FC3F2A45-953B-40B9-A885-FD40D438C514}, Quarantined, [64eb9a1c98f2a09655c06f0f4cb9f010], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FC6A40BE-3A10-4847-AD72-5D7427478A72}, Quarantined, [bb94882e5733cb6bfc1a97e7c93c6799], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FC8FE3C9-E2E2-46FC-9E45-2A498C7B94B5}, Quarantined, [db74eec87a105dd93cda304e45c0956b], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FD1A8219-3375-4AF7-B41B-56B44EBE9F8D}, Quarantined, [c689c2f43159082ea2749ce22fd6b947], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FD53FFAB-EE1B-426B-A89F-5C9DC1542BE4}, Quarantined, [4b041c9aed9d84b21ef796e8976e19e7], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FD8C8C4B-B923-4772-A637-F96F8B284157}, Quarantined, [2c232096aedcc6707d99304e3cc96d93], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FDE96B46-ED77-4F92-98E9-B87E78B3686E}, Quarantined, [ea65298d38523ff7f71e3d410ff64ab6], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FEBBEC72-4A0A-47FE-B0DF-95485F5BB43D}, Quarantined, [93bce7cf1278cf677b9b92ec4abb03fd], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FFBA574A-A433-409B-B9EF-16657019BEA2}, Quarantined, [a1ae2e889bef55e1e332a4dac14417e9], 
 
Registry Values: 569
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{056ddd55-13e4-41e4-b00c-7e512c42be0c}|AppName, SavePass 1.1-bg.exe, Quarantined, [eb6490261971db5ba4738af4e71e5da3]
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{89ddacd0-0d24-463d-878c-d5c921345790}|AppName, SavePass 1.1-codedownloader.exe, Quarantined, [f758d6e0eaa078be67b27fffa06530d0]
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\GLOBALUPDATE\UPDATE|path, C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe, Quarantined, [70dfbafcc2c8c373aeb0a26f14f09a66]
PUP.Optional.GlobalUpdate.C, HKLM\SOFTWARE\WOW6432NODE\GLOBALUPDATE\UPDATEDEV|AuCheckPeriodMs, 21600000, Quarantined, [1b3404b245455fd700c26d7abd46d030]
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{056ddd55-13e4-41e4-b00c-7e512c42be0c}|AppName, SavePass 1.1-bg.exe, Quarantined, [034c783ee2a85cda64b3df9fe52037c9]
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{89ddacd0-0d24-463d-878c-d5c921345790}|AppName, SavePass 1.1-codedownloader.exe, Quarantined, [6de208aea4e645f164b54d313dc8ac54]
PUP.Optional.QuickStart.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|[email protected], C:\Users\Rifandi\AppData\Roaming\Mozilla\Firefox\Profiles\ly7cncgi.default\extensions\[email protected], Quarantined, [b7984b6b464469cd9e502afe64a0847c]
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB|ptid, ild, Quarantined, [74db1b9bf09a0b2b0b1d020893712fd1]
PUP.Optional.GlobalUpdate.C, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\GLOBALUPDATE\UPDATE\PROXY|source, direct, Quarantined, [18379224c2c8c96dbb9aad3b010232ce]
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\INSTALLCORE|tb, 0A2O0R1R1H2Z1S1G0H1F, Quarantined, [ec6371456129023449907dcc5ea7cb35]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{056ddd55-13e4-41e4-b00c-7e512c42be0c}|AppName, SavePass 1.1-bg.exe, Quarantined, [f659eacce6a42313e232e698b64fdd23]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{10607258-B643-4877-A925-50F8C3D3C1BB}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [bf90d8de7f0b48eedd391d6156af58a8]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{106D78B9-B9E0-4387-8835-4667F113328C}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [b39cbcfa4a4050e6d1440b733cc9df21]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{109F821D-BD2A-4440-979B-A9ED44B8E488}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [a9a6c6f0d9b1b680b363522cbb4af808]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{10BBFB4A-39F1-4D32-BBCE-32C1875014A9}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [46091b9b474365d18b8b344a58ad0000]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{117CF6EA-6180-49D7-A3E7-625360BE42ED}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [53fc8234abdf83b36aac542a1de82cd4]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{11D4C2DB-6CB7-4E0D-B728-F92B93E3528A}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [db746d492862181e53c283fb60a5a65a]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{12745D75-2545-4DC7-A14C-8CFD948ABEC3}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [70df843297f3ae888c8ad7a743c2a35d]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{12D652B9-C4AE-4B11-8F16-6D2DFA40EEC6}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [b09fd6e0325879bd779e710d21e4a25e]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{12D693FE-5DC1-438B-9682-76D01DD063CB}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [a5aa5363addde35304121c62887dc43c]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{12EB231D-1F3F-4CB4-BF8D-66941D1C65C0}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [37183680fd8d0f2702145c223dc8fb05]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{14242C9D-C987-4D4E-97B3-3483BC7C949E}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [301f08aef29854e28b8ac8b611f457a9]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{144C9E53-356A-4115-B23B-A642FBD3BB4A}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [8ac515a1bad0b482b1645c2233d2e917]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1508D8EF-68CD-4DFB-A7C7-BC83F8D869E7}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [bc9320962e5cc76f96803c42ff06b947]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{15205666-A84A-45F4-A89C-C484B649868C}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [ee61b20438524ceafe18215df60f15eb]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{156FDFD5-EC30-43A4-9C5E-C1103B161BD1}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [56f9e4d205857fb724f1205e917410f0]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{15B92B65-53A2-40C0-9D1B-988698EBA587}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [8cc3496d5238a4922ce9a8d6759021df]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{160907B3-4343-426E-B5E9-881154D389EC}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [b8972d894c3e37ff7e983d4115f08b75]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{160ECCC3-FBDE-445B-9AF3-CC70188C4AED}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [e669c3f35d2ded4942d488f6c243857b]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{161D550F-7D9D-47CE-B511-9966306A48E5}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [60ef01b5fa90a88edc3982fc3bca8d73]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{16614EF8-DE8B-4763-8BDC-50CBD3E2761A}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [87c84f67028810263dd983fb27debb45]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{175F4E01-A78F-4EC9-BD1D-6DF54BAE257C}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [ee61a80ef595181e60b5433bc441ab55]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{17F607A3-D236-4C5E-97D6-F0A24115B8DE}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [be91fbbb1575a39358becfaf80854fb1]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{184ABC97-890E-4C66-8E61-DEABC2FFB398}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [6ee10fa7eaa033039b7a720c51b4946c]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{18E4CFC3-2723-4C58-8089-B238E0543D78}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [de7109ad7d0da5918a8c413d07fe44bc]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{19018BAD-1637-4135-8056-FE5F271211CF}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [242b496d5d2d251165b099e5f5105fa1]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1950A10F-9E9A-41C4-A4C4-38E7E37360B6}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [87c8e1d54347f442d243b5c9b253ef11]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{19843CCB-63F0-4CAB-AA97-7495C3A3A655}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [3d12783e6d1d72c4bf57502e6e97a15f]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1A1609AE-D76A-4C08-946B-75647522306C}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [bd92793d8a004bebcc4993ebe025cf31]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1A294DF6-B274-480D-A263-AD876A3E57FB}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [f15ef3c31f6b2214ae686c126c999a66]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1C09EC12-E0ED-4460-B6F5-207AF8EAF873}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [a9a6ebcbacdee94d2de8f48a8f76fe02]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1C28E76A-BAB7-4C2A-9E76-CF72FB498E9B}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [71de575f9cee6bcb1ef76f0f0ef77e82]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1C815EAC-4549-4962-9FDC-4C8EB5E6123D}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [70dfa90d64263df92ee7a3dbe42160a0]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1CA1BE04-6FEB-4952-86D7-6DD468987A96}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [59f62a8c7d0d48ee060f126c040114ec]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1CC80490-3239-40FB-9493-1AEA4CD0AAEB}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [da759a1c305a072f33e20a740500c937]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1CCC3093-DC08-435C-B8EB-96337AD42D26}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [d17e5b5b305ab1850c0a49350ff6da26]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1CFB70E5-78A3-494F-8957-E64022A7AD56}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [212ef0c6b3d7a98d37df6d1150b5718f]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1DDF82C4-4267-4B62-AA46-225391164F85}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [c48b8b2b3b4f6ec89a7b0b73d62f6997]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1E463F89-8974-4024-BD5F-EE11D4A19C2E}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [371801b52c5e8da930e676085baaca36]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1E5739D0-6F1E-472A-9C63-F67192722699}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [311eb204d0bac96d56bf1c628382f907]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1EC56C5C-BCCB-4CDE-BCEC-657A152347A7}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [3718981e1a700d29a471add1020354ac]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1FE95C6D-231D-4FCD-99D0-1CA828975482}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [044b298d51393600b85d96e88283b947]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2085B5B1-C1FF-4FB9-B923-E32FDA15439D}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [eb6405b168221c1a65b0e49a83821de3]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{21B5A649-338B-4993-A88F-10EC3ACFABC7}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [67e82492345664d253c3fe8014f19d63]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{221561D4-7DBF-4884-ABD7-2FB5967A8ACB}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [d9761b9bc6c43afc799c225c00059d63]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2231964E-A1FB-4CC8-946F-FFE1AEC59529}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [38172294bad0251172a47c02689d0ef2]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2236D9C0-D477-44B7-8578-EDA7549D629B}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [fe51bef86f1b5fd721f486f86f96ad53]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{22BBA9AB-A6C4-43A6-B4E2-CDCD28344671}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [321db1056d1d95a19c7a5c2232d30bf5]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{233CEA76-FEC7-4D79-9CF7-C79F99D8433F}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [f659823443476accb65f5a24c045728e]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2406F9D8-5838-4331-91D2-C6B771BCB4C8}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [2f2031851872fa3c2beb5c2247be4cb4]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{24B4A41B-6FF4-48E8-BFA7-B7989E476C8E}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [2e216b4b5733f73ff12488f6cc393bc5]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{24D79978-FCD1-4DC7-A2F4-9082D014268B}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [f25de6d08604dc5a060f601eee17738d]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{24E2324A-B00C-415B-ACA3-8A75AA37B2EA}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [fd5293239eec0a2c4fc737478b7a956b]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{25644787-3A38-4E3B-A3E8-D9CFD816D33C}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [70dfa412ddade650d541cdb1ae57817f]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{25C35C62-D598-474D-90A0-649F6AAEC3A2}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [d37c5660701a70c68a8cdba3ec19cb35]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{260E9537-A83B-4CE8-BC27-6CCB22CC26C8}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [3718a214404a1e18f3224d31c24349b7]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2631D085-7C48-4C56-9C6F-27661F14A0E4}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [b39c8c2a692146f00e086f0fd530a15f]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{26472572-55BE-4340-9DB9-FA6AB66EA6D3}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [b39cc6f0b0dad4623bdb5727729305fb]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{268F4669-9F9D-4D69-BBC9-1E1E2D6F3424}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [c6891a9c0981b1850b0b8df1b5500af6]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{26F8F265-176F-4734-821C-EEC063CDB853}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [cb848f27860496a00610374740c5e020]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{27006013-38C6-4BD1-B2E3-9FC59B5EA2CD}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [51fee4d2bbcf8da967af730b4cb928d8]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2774C56B-DAFA-451B-88FB-50282050F4C6}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [83ccb303226881b53fd7e39b08fdab55]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2779F78B-7BC8-41C8-8E4E-99827A41CCEA}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [ec636a4c701a60d692846d11e0257c84]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{285D92B6-680C-4D8F-8B3D-B8C37CE3FC66}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [85ca298d5337f54141d5344a62a30bf5]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{28DCA798-3B15-4D1C-9CFD-C14D90D0268D}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [a3ac12a41179a3931500e797fa0bae52]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{28E47D33-824B-414F-97AF-77647123E644}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [470821958cfedc5aca4b1767e81d46ba]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2970EAEB-523D-46DB-852B-EE9DD3BCB24E}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [b39cac0a71196dc96baa700ee32236ca]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{29EC0E28-F5C3-4749-9D8D-E2A74012B45C}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [e9667e38622864d2dc3aa3db2fd6827e]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2A281A10-44B2-458C-BDD0-D08FE7FBB88A}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [331c823487036bcb69adc1bd3dc83ec2]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2A511A2A-EA36-46BA-8B81-571FA3D56529}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [6ce311a531592c0aa76e87f71ee7da26]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2BD95269-EA81-4454-BC27-4410E37B76E1}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [96b93a7cdcaefe38b363087640c5ae52]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2D2F009E-CD99-432A-8C6D-2E532632B021}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [3b14cfe70486e5511cfac7b749bcc13f]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2D84E883-78DB-43CB-8D29-6C9381D5AC81}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [c18e4571eaa086b0f12599e5d530f808]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2D8969BC-37BA-42A0-87F2-AFB5799CD24D}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [b798bafc8bffaa8c6ca9f28c82839e62]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2DE4B463-D5B6-437C-AEDF-A48367175031}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [c68910a6593196a0ea2cb5c9b74eef11]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2E2BFA3A-2834-4C1D-BB21-DC815A50F0D3}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [4a05d5e1e5a5d95d24f1c1bd09fc738d]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2E6A1216-19D0-4F92-BF49-22BE5E1AB2D0}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [a2add2e452380f27080de896f41155ab]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2E831696-C219-417D-B04E-5EB053CE2370}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [a0af4a6cfb8f02349c7a4b333acb817f]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2FFBE1B4-FB54-4A8E-8A93-BA7142653BED}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [5df215a10a80f1458c8a433b07feb947]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{308BA1D9-215C-4E67-9813-E117BF931AA1}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [ba9562541278043261b4fa84ce3726da]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{30AD5CE6-9321-4ED5-912B-3942CF67FDF6}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [83cc496dc3c7ce681ff65e20de27ab55]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{30B4DC87-AA4C-4AF3-BAB4-B57E37E9A329}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [3e11a5116b1f2a0c71a5e6987b8a43bd]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{30B5DBCE-25AC-4CAE-BF27-8C843A7F8EA5}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [a3ac575f5b2f46f019fd1668d035f907]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{30DD076B-9F25-41E2-BF27-226A9BA2B262}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [63ec8135fa9044f29680750947bee51b]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{31618DD4-11F6-461C-AE39-E36F3B5F918F}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [4708ab0bee9c8fa7d244bdc1d134748c]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{316C5490-8058-407D-8893-111B48529897}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [6fe0b006dbaf6bcb0f069ae4798c12ee]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{31E3D3AE-B51F-4F03-90D6-13919C243D68}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [331ce6d0b6d41c1a8f871f5f937217e9]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{326A7C75-3022-42BB-AD5C-52E5987AD4E1}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [b19e179fc6c4c5713adc5f1f8283669a]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3273B4FA-193A-4613-AFB7-354C5478353B}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [80cfdadc2961f442d342ee9057aea55b]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{32928202-C620-4A2D-A6E9-CF59448BF629}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [d6798b2b2a60de5843d2b6c89471ae52]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{32DFE042-3F1B-4B90-BE3B-C2F4AA4614B8}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [ba95e9cd424803337c9a413df70e6b95]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{335191F8-155F-4833-8AE5-7E8CF7468BB4}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [f05fd0e6ed9d95a14cca641aa26334cc]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{33AEB12F-D06F-465B-8FFB-9CF6C13F4994}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [480734827812142221f5b1cd0df831cf]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{344AAE88-3516-4584-BA6A-E0715714BECB}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [d57a387ef09a1a1c20f5146a4abb0bf5]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{34627DB7-48BB-4C00-83B7-D354FB34549E}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [a7a8cfe7860484b2c5505529c342e31d]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{348981D1-312C-4CF6-9775-BB2BA7B827EF}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [36190aacf496de5812031d61e91cb64a]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{34E14550-49BF-49AE-B2D9-4060F6F0AEFB}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [da75a70f98f272c4d44145398d78e020]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3506CD08-D30F-4D46-9FAB-7D7F96F6FC10}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [2c23d2e40a80bc7a2aec037b22e3f010]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3510550F-8B82-48C8-B17C-C0A1E2D31AB3}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [47088a2cd3b75fd7ee28e9956c99fd03]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3512B418-313C-4139-9087-3BA0CB8BEE4D}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [e7685c5a8bfff2447c999fdff90c916f]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{352ED206-FA27-4B50-ABFD-2F13FD649871}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [b7983f77bfcb989ea96cc0be947138c8]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3578DCBB-CBE2-49C0-A818-B1E27584C929}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [212e9422008a0e28977eaad4bb4aea16]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{366CDDFB-98F9-4E54-855F-4084A7C2192A}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [95ba3086d6b43afcac69f58930d5c33d]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{36827FAC-DC8E-452B-BDDA-5594767A5699}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [e9663383b8d264d29f764e3009fc9e62]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3699A7C2-CE12-4716-9498-14238A8787C5}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [2b246b4bb4d6fd39f61f047aa75ec739]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{37E7465F-2B0F-4429-827B-C71229931EE3}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [0d423c7a66245dd90610e09e3bca26da]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3929358E-54F5-440E-8769-B14796891A93}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [66e9377f2f5b91a5d343daa4f90cad53]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{396A310C-8D2D-49FD-8F43-E3D27DB6A767}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [3619b6005931b28439dce6988184d828]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{39BFF0AA-120C-4DF7-A116-43AB3FAB2585}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [1b34e3d35e2c9b9b6bab631bc44139c7]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3A17518A-B657-41C3-AFBD-EDF31799EC47}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [39169c1a5337be78b5613b43da2b2dd3]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3A253602-CD5B-4E35-8CC9-F344F8B93F31}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [52fd7c3a0b7fce68140249353acb21df]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3A50526B-70D3-47A8-9C66-6A9629208C3E}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [d07f8c2a4b3f6fc735e1255937ced12f]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3AC57B78-B4DB-4776-B43E-3871202ACE22}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [014e1c9a4248b3832de9daa48a7bbf41]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3AF84000-D5AE-443B-8ADB-73591BD0A890}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [113e7640c6c4dc5a6caa0d71d62f41bf]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3BE55B0A-6CF0-4D6A-885F-20526A6A2139}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [4f004076c5c5ce68b36294ea50b5b64a]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3C3E2308-4E60-4D0F-A651-14C88C2D4572}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [dd7208ae5c2e44f2d441007e70958d73]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3DCE007A-3544-43AB-B073-7EE78DE1D955}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [fe51ab0b5d2dab8b9580681610f5fb05]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3E2804CA-34DD-4517-8281-C2AFA1EBCCA3}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [1a35338361292016ca4cf886ae578878]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3E32D8CE-D350-4CB1-9C56-DAD7DC6EB250}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [2c2376409febe25420f63c42e025817f]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3E9A7BBF-2756-45BA-9328-1537A3637193}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [0c43d4e21f6b6ccae82d99e542c3d828]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3E9E1C50-E043-434F-BA90-B1A995A5B02B}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [430c595d068488ae28ed512d1ee78f71]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3EC1F12C-ED88-467E-B169-F2AD7197D7CE}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [b897f4c27b0fcb6b4dc94737c63fce32]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3ED59D58-2C77-4C0E-94B5-3433DF71C196}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [c18ecde990fada5c03126c1249bcd62a]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3FF9410F-FBB2-4DF9-BF83-90A044815169}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [331c6056a1e9989e6ca9abd3d0359e62]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{402ACF5C-ADC4-42BF-8959-21476D6E5531}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [c887496dbeccfd3968ae3a4457ae6f91]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{40AD692E-A801-4757-8FDA-78E3396825AC}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [e36c7f3738522d09f91ca9d55fa67b85]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{41523F02-40C1-4B1D-A617-D78DA38284EF}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [341bccea0e7c221428ee730b8d78f709]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4231D998-A396-4F79-B078-20A1DADBE7E4}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [e26d4b6bdeacba7ca274146ace371de3]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{430A0784-7EEC-4518-AB7F-27AB6CF9D973}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [e16e872f85051c1a0e07b7c734d1d22e]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4327B14E-ACCA-457C-93AE-3BD55922614E}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [7fd04d69840679bdcf4699e561a4fd03]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{433C1164-49E2-4BF8-BE11-CBB811829739}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [a5aa199d2c5e1d19a37289f5a65f659b]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{440FD445-253F-4EFA-AF2C-CA3BB7B9D652}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [1b3405b14b3fa1950e076a1441c4ce32]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{44483649-74EE-4C5A-8173-41CEDD32D98D}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [b19ed6e01278ee48df369be327de837d]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{45158C07-4450-4D20-87D5-525FE073F5AF}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [123d11a50189181e3dd86816897ce51b]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{45B59595-FD0D-4246-B8FD-2248B77CA2E2}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [5ff0fdb949410b2b7a9b611d768f2bd5]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{45BC50E4-B8C1-47D7-AF53-A1837464483F}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [ee61fbbbf8925fd7e035562822e331cf]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4692EDE1-B172-4E1A-BFDA-F0D8B7BD7C70}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [d877c9ed7e0c7abc36e0156908fd09f7]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{471ED992-44BE-4AA6-8E14-9E69BF114884}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [ba95882ea9e11a1cfb1a1b63b74e9a66]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{47420E9E-119A-44EB-8327-F6E771934DD1}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [d778f2c41e6c49ed1005a6d8de2745bb]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{47FCB10C-723A-443A-963D-4589D8F91E5C}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [3718674f7e0cc670df37710d59ac619f]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{48B1AAEB-1F12-4E88-A2CA-8E94845B1633}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [a9a603b38703b5811ff60e7049bc857b]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{48CD7F2C-8791-4F5A-8BD5-E6D411B8B2D6}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [a2ad6254f991cc6ad144215de91ca65a]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{48DB5457-FBB5-4ADD-9554-637D30CF3823}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [d7781e9862281620aa6bec92be475ea2]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{492D71BE-ED27-4E5D-8DBC-F51EE256F1B7}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [72ddf9bd8efcce682aec9ae4c34203fd]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{49C5900F-DA54-4CA1-8810-5EDF4050BBFE}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [55fa2e88b7d378bee431fe804cb9de22]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{49F1C3A2-2E44-40F5-B2FB-218490504D4B}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [c887c7ef2268db5be431a1dd59ac2dd3]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4A2D6C55-FDB0-494B-BBD1-6BB62AF5C2EA}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [7bd4d2e46b1f81b50015dea015f0df21]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4B19B8ED-A8A4-4AAE-9362-C2EDE72BAF96}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [86c93383375366d030e6f48a92734fb1]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4B8A4C2D-2950-47A1-841C-C6FEFCEB3724}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [c8873086e4a61d19f32389f5b74eac54]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4B96B74B-C0BB-4BA4-A196-9F1763EAE987}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [97b8eec82c5e5ed8938288f619ecb050]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4D6C1AEC-A04D-46A9-B4BC-F821E52BE379}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [232c3c7a32587eb8868f78060005b44c]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4D7D5467-CE0C-499F-9C74-337A3CB6BECF}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [440b1e986c1ed660bc59b3cbb352a858]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4DA10542-2648-40E6-8015-C26DEBA6DDB4}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [c48bc9ed76144de9967f097521e4f40c]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4DE33814-E058-47EC-BE31-1091693DE4B8}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [222de8ceff8b3afcc0568df149bc7987]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4E00576A-538D-4B26-80BB-AAD83AE0D6A5}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [fa557f3704865bdbcb4aaad4b45146ba]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4E0B2DF7-FD89-413F-9C3D-A279687ADC6C}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [0d42c2f4fe8c1d1935e18fef3dc89769]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4EFCDCDB-E97E-4EC5-A2A6-631779E14A3F}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [3c139d193159181e1cf9631bb55029d7]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4EFEBE2A-A42B-47D3-A8F7-52C1C24156AB}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [212e52649feb49eddb3b9de135d03bc5]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4F423835-778C-4EF1-AD85-EB99247F4518}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [a6a92e88860453e3fe17aad4bc4935cb]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4FCCCC12-9439-4E74-BA97-4253C4ECC02C}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [a5aaab0bafdbd56141d5ccb2c045827e]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{504E40D4-342C-4C96-B8C3-DA4F7CB856BF}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [e26dbef8b8d2fa3c70a57c0235d0d030]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{51BA6E88-EF2A-4C1E-9A11-E11540AC8E1F}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [84cba511e8a2a5918b8a58268a7b1ce4]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{52668907-F813-4058-8599-4E2963CB8B83}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [3c13783eafdb4cea91852559877e3cc4]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{52BC3755-4BBC-416F-A0E2-D370B1A3C84B}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [4c03ae0861290b2b090d601eda2b12ee]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{53DC17D2-16A9-470D-BC3D-6BC38F2557FB}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [3a156e48ed9dc76f8a8c9be328dd738d]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{540F2050-B15C-4AA8-A6D2-29FB1D787C5D}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [b49b179f0d7dce685cba1569778e629e]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{54334F2F-9C25-49AF-A17F-A65E80A7C971}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [410e199ded9d63d3fe18cbb307fe32ce]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{54AB0BB0-D5C3-4FBB-B3B8-346016267F6C}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [054a991d4b3f2610af67f98549bc669a]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{552E56ED-F52C-4A31-BD7D-DB3BF49E1B84}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [4f00d1e593f7f34347ce1668ae578c74]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{556779DD-2D3C-457F-B2BD-81BF2647FF3A}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [b49bbdf9137750e6070e2f4fc1445ea2]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5654FD56-6BAB-45E4-9552-4554483A62B3}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [2728e8ce19711d19c94c35492dd8738d]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{56AFBBD7-D24E-40F6-BAF8-65D1C14CCC20}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [4906ae08dfab74c2af6769158f76827e]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{57D1ECB3-2A72-4113-B344-1A43BA5D9122}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [3619229448423cfa8b8a5c2294719c64]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{587A783E-4448-4A53-A51C-C43574B19830}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [bc9302b4ccbec0769580add1788da060]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{58B389E4-5DD7-4564-A4C8-2F6C1CF8876A}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [79d6387e1e6cb87e769fb0ce85803cc4]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5919307C-F2EF-475D-8E82-C22C81306BCA}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [a2ad377f31595adc6da898e63bca41bf]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{592991FE-4901-4031-AB94-78D81D1B3446}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [fd529c1a7416fc3a0e08433b0bfa52ae]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{59739E73-C5D7-4D0B-8CBB-49A74867A8F7}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [0f404b6b59311620e72f6c12ae57cb35]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5A348355-9C2C-401C-8F48-C81DF7C4D23F}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [3c1316a0e3a7d56137df47371ce9f808]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5A942C12-EEEE-4119-B3AA-F58156C0D05E}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [80cfe6d0305aab8b95819ae47d88de22]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5AAE0AE1-175D-41D6-AD68-FE5E2B2DA19C}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [0a454c6a800a22147c994a341de82fd1]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5AC732C2-4176-43C7-8CFE-9C67507F7B64}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [0748ac0aa1e9d4622de84e3038cd6898]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5B318E1E-8AB5-405D-90F2-E3FFE0457FDF}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [85cac7ef27630036d1447fff47be23dd]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5BEAA832-5A2F-47DB-9B31-F47F175E6C4C}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [400f10a65c2e47efac69007e739204fc]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5C0959A3-2F4C-487D-9476-FCDE7A93A823}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [a5aa9d19bfcbcf6720f64836976eb749]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5C820995-D340-43F1-B08E-109CA7FDEA5F}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [084760568109f640d83ee896db2af20e]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5CE1B294-11DB-4D7E-A1E0-6B94FB1F16E7}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [a0af417514761422f91d9fdfa1643dc3]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5D7C5177-3C96-434F-A5F4-B13DFA5FF43E}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [ce81278fddade353849182fc27de5ca4]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5DAD61E7-F55E-432A-B2C9-FAABD3D8C732}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [4d02882e44461d19a6703e40b74eec14]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5DADCE15-8E82-4E99-BA55-88BBF5D1B677}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [81ced2e4b9d1be78908688f6877e42be]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5E9B20C5-259C-42C7-8FF1-3C2B122AA724}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [b39c6a4c8efc33038d89a5d927debd43]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{60447517-FED5-403A-A751-86DD96A04EE6}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [1c339e183d4d79bd0411abd35da854ac]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{60C238DF-DF46-49A4-BEA7-A297D74CAF21}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [212effb7315960d6f322df9f57aeec14]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{60D2859D-72A2-4E11-9A92-C753625E55B3}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [4c034a6c2961c76f967f532b778e10f0]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{611DB9F6-C474-4303-9018-3CB3F4A6F067}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [3a152e885832e15527ef4c322ed739c7]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{62993CD6-7EEA-4FE3-8E63-D028763E3C26}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [5ff0b60045453204db3ac7b7e223f40c]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{62A86078-BBF5-418C-94FD-F279E4E02C81}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [06492096355576c01402c0bee81d8f71]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{633B4C6F-6713-4C9A-A1C4-8B95C6E2CAA4}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [e966f4c2117995a1d046ccb211f4d828]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{63998CEA-6341-4ECA-8D93-3984F44827FE}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [63ec73433b4fcd6993831866b64fcb35]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{63D6B6F2-5A2D-4547-B966-30F069C5291A}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [80cf9125ec9e4de924f278063acb30d0]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{63ED0511-62EC-451C-9998-3B49B47E9414}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [d27de3d3e7a3eb4b61b4047a669fe41c]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6417EC79-F240-4F2B-8458-B85F5D55C4E4}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [3916feb899f12214d83d90ee1fe6fc04]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{642F3BB3-F4B1-4038-B75E-3B7D1EF58929}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [47085462fc8ecd69b85efe808f76e818]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6458D1D7-DA3F-47BE-BF51-F28DAE72773E}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [1b34ab0b24660d2990850d719b6a2fd1]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6478360C-74DE-457B-9165-F51063C2217B}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [3d1211a579113501799c94ea0ff6ab55]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{64A71C6A-A42E-4E9B-B283-932E61ACE8F2}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [9fb040766426f541f323f38bd5305da3]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{64D11568-2E59-42CA-95E2-2D20744AC5B2}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [f35cf4c22f5b4bebe62f2d51a65fb64a]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{64DCA81B-82C7-4A8C-933F-BA9BE8952BB6}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [8bc4d2e46a20db5bb85e94eaa263916f]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{65638577-8D34-4EAB-BF9A-905AD9CFF49B}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [3e11991df99171c5e92c85f9b94cbc44]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{65A4E2BC-3C0B-4DD3-88FD-6F1B3E4B74B0}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [ec637046e7a3e650d83e26587e87ba46]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{65E541C2-1A8B-48D6-B88C-3064C32B2961}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [52fd3185d4b636003dd9a5d921e47b85]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{65ED8C4C-EB17-48FE-8AC6-30155D99408E}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [e6698f27d3b7a88e42d39ee050b534cc]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6600EC8C-9501-4A8F-B7B2-1D9A4474569B}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [74db486e781248ee0114b9c5679ea55b]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{66DC90C3-4CD4-459E-8EA4-15BD73B64E1B}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [afa0c9edfb8fb185f323fc8246bfe61a]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6763A4AB-5D9B-455F-806E-FF2ED039C9DA}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [e36c1f9716741323b46189f546bf28d8]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{67A6264F-D7D3-486F-9870-D5479671D6A3}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [c38c7d3968220d29fe187d01f312d927]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{689053DD-5B84-4EF9-9BD2-D29D2040F5EC}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [f45b7c3a4b3f12244dc85925030212ee]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6963953B-B690-4C81-B746-8FD56180EBED}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [fb54d3e3e8a2f73fa1756e109174db25]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{69FFA09C-21B5-47F8-B393-A383BEA4B64F}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [88c76353f5958fa78294f38b70950af6]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6A1D66C8-3594-4589-A686-668ECBCC2A68}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [f35ce3d339511422d93d552923e208f8]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6AC13D3A-2B01-44C6-8EAD-9E17DB26C711}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [66e95c5a5a30072ff81de896a263a35d]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6B02DC7B-4821-47E2-82A4-18D7B81A43BE}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [440b6a4c95f5fb3bb85e0777e223b44c]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6B18325F-6704-4E25-9989-C665B8ECD9CC}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [3916c0f6404a47ef15003d41ab5afa06]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6B1E9C0F-E6BA-4968-8ECB-FC156CC5E7B3}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [c6894373d3b795a12ee7304ee322c23e]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6B34A478-DB21-4D59-A6B3-534715D792C8}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [212e0bab632765d10d0884fafa0bef11]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6BFA1E15-A89C-46AD-BF50-495E8FE03570}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [cc837640038702349c79344a34d116ea]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6C1D92D5-C2A1-44B2-BF62-FE8DBD86DAEE}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [153a42749febce68ce476d11f114c040]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6C43C51A-CED1-48D5-BA21-512249AE595D}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [17388a2c3654033318fe512d7a8b7888]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6C62F9F4-6DE1-4CED-B339-B91A65B91A7C}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [53fcd0e61773ee4835e0047a6e97d12f]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6CB0B738-1E72-4E2D-9E9B-6CEB89CEF046}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [d679cfe735550b2bad685d2121e40df3]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6D1BF86A-9761-4327-9B89-D8712C4B8179}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [60ef16a0c2c8d75f58bddca22bdad52b]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6D806E83-EEA1-4F2B-8956-D4F7D5272B1B}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [014e5660f9917cba997c90eee91cbc44]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6DBC98EB-602B-4779-8799-7730188AC292}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [d57a783e22687db936df5a247d8860a0]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6E17FEEC-69FF-4DBD-ADB9-7F62C7B84A83}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [69e69e1869217bbb948285f9e0253ec2]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6EA2B055-E68C-4F18-8BE6-E72743A97DE9}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [044b8234f7939e98f02678064abbe818]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6FFBB3D5-46A3-433C-BB51-BA2F9E4F3237}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [e16ee1d51f6bc571ae673549ec19867a]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{707CD64D-1280-4D2B-B2E3-59DAE25F5CE0}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [3817783e1971d16561b56519b154a15f]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{708932E4-44D4-4D56-BC6D-569918B71981}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [c28da313afdbaf8734e10b73d2339b65]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{71BF600B-1847-4C18-8D28-C12469DB64B2}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [87c813a35e2cf541e3333b438d78fc04]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{723A54C6-5CF1-4B0F-99E2-7BE99AAA83E9}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [400fd5e1f7937fb70313d8a634d105fb]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{731F9B5D-D390-48D3-9EE1-776EBF3E1F98}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [f45b189ee0aa8fa7997d9be3d33249b7]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{74429341-32E9-48BD-B387-153C86483B5E}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [b09f684e81094de9dc39c3bb43c220e0]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7452CF12-89DD-4797-962D-E95FC23561C0}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [84cb8a2c94f6c27468ae4a349d682dd3]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{758B2126-9199-4B66-A11B-F9DA118031BE}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [cb841a9cddadf93d4bca2c52729325db]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{75D26C9E-101C-4394-9E2A-302FF1763DDA}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [2c230ea8c6c4191dde371d617b8a55ab]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{75E08653-95BC-4E9E-9EA0-42479E99D56A}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [0a4506b0c7c3c4728491ec92798c13ed]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7773BE5B-4C3B-4187-8D37-84E68145CB63}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [4e01971f90fabb7bdb3b97e70ef79e62]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{793901E9-1F3B-4986-89F2-29C8C3B429D6}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [47081c9a5535300648cd65198b7a768a]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{79C3C8F4-AB5E-4DB6-8B5B-BA8FD433C71A}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [f15e1f976f1b0036fb1aa5d99f66a65a]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7AC56D63-3137-4770-AEE5-D2E287C07D8E}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [df70e0d68406ae8865b0562828dd7e82]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7B48D0F2-A669-4F89-BFE7-21A119D11272}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [133ca5111f6b1b1bb85e126cea1b8977]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7BA0FDBE-AF1E-4370-9B6E-739F12E4D323}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [36191c9a2d5d86b047ce671734d12dd3]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7BD13572-D218-4507-995A-717CFA2294F2}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [e66944720981c07656c0295521e41de3]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7C55DE0C-B5D2-4E58-96F1-712F431543CC}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [70dffcbacac061d50e073c429a6b48b8]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7CB0F535-F79B-431F-9F89-C62DE8904784}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [034c4e681f6b2e0830e5413dfa0b4cb4]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7CEAA049-EF1D-4AE0-8FA6-C6BF7C763529}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [f659b8fe593147ef17fe5a24a75eb848]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7EBD6132-4AB4-4541-999D-44A4A581C074}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [56f9c5f12d5dc076b1642d5146bf6f91]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7EE2F444-9C8E-4312-9C7D-1457971234C5}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [3b14aa0c3d4db87e7b9ae99535d0c739]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8038E6E3-EDF1-44D2-B872-F8F7473C7A8F}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [321d5363d1b9c2744bcb334b20e555ab]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8043200A-CC8C-49A7-AE35-E8FE32304BED}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [2c23b6003a50979f37de79058580c13f]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8068755A-9D2F-4D00-92E1-745B64EF4454}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [212eb8febfcbc86ef61fed91887d8779]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{810BDB06-AE0E-4721-9794-5ED0F6C9EC1A}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [4a05199d0882072f1afb3e40e81da957]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{818FE36E-2A1C-4F6A-BBD6-359FCD84F3A8}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [f15e6a4c94f6013550c5bdc1a95ce61a]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8229987A-FA7B-44E3-8CD1-7B9468BD8D13}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [d976e1d50d7d79bdcf47e19ddd287f81]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8249F450-3BFC-4943-AE8F-A5A241CDD03D}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [3e118a2cfe8c241291840f6f887d9b65]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{830A319F-DFC0-462A-A7C1-281F4C9EE3D5}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [3619dadc3b4f3df98d88fb838d783bc5]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8335A4CF-8F32-4B64-8D98-791757C7CF3F}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [60ef09ad602a2610a86d8ef05ea7d030]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{83CABE35-7791-4C7D-B729-37D47E4D286D}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [da759c1a1e6cdf572beaf88659ac7090]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{84531FCF-BBD3-4CFB-8068-ADB7C7884A41}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [301f9422dcaeee48e62fb7c77392ec14]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8471FE29-87F5-4131-A281-79EA9F3DEA3A}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [9cb37f37692189ad54c2ff7f8481de22]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{84E98500-E544-4458-B0D7-8AF4C85265E8}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [1f308a2ce0aa1f17a274126c2dd89769]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8555A638-8C24-4631-B5AD-B5961BEEF9EE}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [bd920da9fd8dca6cbe576618fe071ce4]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{85A26963-FB59-4FD1-A9DE-6E18E52B2542}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [a4abf1c57119c670c551631b59ace31d]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{85C209D8-F6E3-4A08-A1CC-243C45371531}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [450ac6f03e4c9e98090c017dc0456c94]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8601159A-1C01-445A-9EEA-26AE961319E7}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [a7a8bff71971e650987d9be3d134ff01]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{86B89EAF-DA3A-4443-81EB-EBAE9E2138E2}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [a9a614a25733ad89e92cd6a8d035966a]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{86EE1E09-D2D2-4FFC-913D-4DB0C3AA1691}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [d07f0caa24664aeca075b4cad82d07f9]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{87322792-F5F2-40DD-9FFC-B3BF2BEE26DD}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [252a2d89f29847ef27ef760858ad946c]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{873F0931-32D0-4CB7-A277-EAC07C60AEF2}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [6ce3ffb7e8a22a0c03127b0317ee5ea2]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{87DC8583-D6FF-4872-B0C5-EDD86E41EB55}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [82cdcbebdeac59dd75a0334b9372e020]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{87EF7491-935D-4AA2-A882-CDEB582A135C}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [4a053c7a3555ef4739dcb8c646bfd22e]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{898B2938-5F30-4864-98C4-D3797030ACD8}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [6ae58c2aa0ea0e28987d116d7c890ef2]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{898E2C30-D886-4C82-A226-173FE69F4EC3}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [dd72d4e27c0ec670d5419ee0e42139c7]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{89ddacd0-0d24-463d-878c-d5c921345790}|AppName, SavePass 1.1-codedownloader.exe, Quarantined, [7dd29f1712786fc77d990c727491be42]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{89EBF78E-97DC-423A-81BB-F029EDD5F779}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [9db274422565d2640015f28cf11458a8]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8A28FD3C-5164-42D0-8080-C06F4AC69776}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [09462294f1996dc95fb7c2bcbd48ff01]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8BBD11C7-6303-4032-871B-FC33442FE6F1}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [2a252096b7d3ff37ae680b73a95cdb25]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8C0643F6-6218-4535-9758-D57996EE7631}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [37186353f09ab97d7e983648b74e1ae6]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8C1F3ACB-E9C2-4E11-B4A4-DEEE3726A8B9}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [72dd6e48b2d88bab9580eb93fd0818e8]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8D795E31-AD58-462E-AF27-E32BD2C6695B}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [d87760561c6ef640b85e4c3247be4db3]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8DC32C5A-94C9-48DB-9681-97B14683AEA9}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [65ea4175f397f442cc494e3035d0f010]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8DD9B84B-9087-4F93-8BEC-224573ADDB6F}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [85ca0caa7c0e41f525f1b8c654b1c739]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8E2A79E3-AAEA-4035-AC42-E627B1A540A8}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [341b3680f298b185ef276717867fde22]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8EA52625-A707-4C33-8481-441E1C921111}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [3817328465255dd965b1423c33d2b749]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8ED293A3-C86D-4DBD-8F1A-6E811AE62E13}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [88c74c6a256578bec451b1cd08fd57a9]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8F0C0E11-FED0-46B1-9EF7-3FB56741D7C4}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [1b3420968604082e0a0cb2cc9c6921df]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8F1D9174-CCC5-4C53-89D9-BFD52CA0CE90}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [fd52fbbbcbbf2016967f542a4abb0ff1]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8F674DE1-9F43-4277-817F-B33898457EB5}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [d47b8c2adbafae88769fa0de12f318e8]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{909DF3F9-8256-4771-ADDC-8CBF5AB77C30}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [bb9443735f2b79bd4bca730b57ae21df]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{90CCBC37-686E-4276-B03B-E72A50638657}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [4b04a0168efcca6c52c3314d8f769c64]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{91167CE1-6AA5-4862-8C44-1BC11EB57178}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [133ccee88cfe68ce71a47fff669f936d]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{915CF0F1-F629-4079-9546-704249F4A6BE}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [91bef3c3c4c6e6500e08304e3cc941bf]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{92315668-F94D-49E9-B67F-66C8FBBC1973}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [69e65b5baedc38fe3fd696e850b56997]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{92AC8BA9-73FB-4282-8289-FBF2AF64A67E}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [75daddd9830751e54acbf8866e97cf31]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{92C197E1-D3D3-473C-90DC-6353FD67941E}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [5ef1b4023c4e13238d894e30cd38dd23]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{930B6774-3FBF-4E65-A7B1-B344A97DBA52}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [94bb5a5c167454e29b7b007e10f53fc1]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{93B5E111-1786-4593-B71A-2061E7F63674}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [2d227a3c642639fdc352d8a6cb3a2ed2]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{93B90287-4E12-4659-B2C6-C7CE5AE2F662}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [65eaf4c20c7ef83e7e9897e7d72e4db3]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{940130BD-67E0-4547-8842-C3A8699E7515}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [f35cefc78208d4628393126cf015857b]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{940BE16C-81CC-4BC2-98EC-A1D7E2C5ADAD}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [f956fcbae7a349ed7a9c116dbb4a46ba]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{944FC134-84FA-48B4-BDC8-3CE5946322E0}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [84cbb2043e4c6dc9080ef48a5ea7f709]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{947562ED-6274-41DC-85F9-8DA1816CF52C}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [a1ae8e286a2094a2be58334b20e5649c]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9563C382-1C0A-4280-8033-5A2D3E9A546B}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [7fd0b8fe553588aee4325727f510d828]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{956EEF6C-455A-4DDD-BEBE-DC91E828BCC1}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [e06fcfe71a7043f35fb688f6de2742be]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{967D9642-F408-458E-9940-C21C1ED4F989}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [5cf3c4f2365479bdc84e700ec24324dc]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{97BF45AC-30B7-4DFA-B5CD-4BE726CD716F}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [68e7ecca5e2ceb4b070f542ae223728e]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{97D071B5-A04F-48B5-9919-50317CB88FAB}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [64ebe2d4008a7bbb2ee8ed910500ac54]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{97DE8C9E-D7FA-4010-9489-5D74632FAC82}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [67e86c4aeb9f4beb67aec5b9887d4bb5]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{97F29A76-9787-449C-8AD7-A11F3D2DD397}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [64eb8234a1e994a205108af4828342be]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{980A78F5-7B2C-4084-BFEA-A93544E3D7CF}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [de7102b44f3b55e1c254ee90c14418e8]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{989F814E-6EC9-4DEB-A63D-751A8F2B3E35}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [9bb45561731739fdc4520e705aab3bc5]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{996EA048-2E40-4912-973E-E74C7A643ED8}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [d778bdf97713e74f090d2f4fc04517e9]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{998F9FAE-5F5F-4EBA-9F9D-596B7667CBA4}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [fc5303b37b0f9c9a0115077717ee09f7]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{99BB7866-E0A1-448F-B8E3-A593C26BE047}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [95bab2043f4bb97db264d0ae09fcc739]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9A36ABDC-6AC2-4E5D-87C1-3D2A8016318E}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [3b14bcfa93f70f27a274324cd035f10f]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9B66A370-C9C9-46C9-8EAD-6B17E435D244}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [f956f1c5bfcb9d991df8b9c5ee17fe02]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9C86EA24-BC85-40CE-BACF-2C3A95F16CC6}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [83ccc0f6f694a39340d6205eb94c0df3]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9CC00DE8-7AFE-4629-8B30-A868AFB55220}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [4a05efc75337082e7f97621c48bd7f81]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9CF02FCF-79F4-4640-BF2E-D67E33D9338A}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [b39ce5d1a7e3e056c64fcdb18481758b]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9E1E6175-50E0-4665-8494-373D592311E2}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [d27d40764e3c1125c94d36484abbf30d]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9E508180-A9C3-42B4-8D15-E6BA8E92999D}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [48075d5996f4b086a76fff7fa3627d83]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9EFB8942-6E90-4DFC-8D98-26781DBA77F5}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [2e219b1bc2c8d3639382e19d8382be42]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9F3385CD-99D0-49E5-8662-A2CB7BF5BD67}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [09464d69e3a7a49295803f3fc144ca36]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9FFCD4CC-C013-4623-8762-239FC294E834}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [430c9d1954367db952c33846cc393cc4]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A0EE8370-3DA5-4F1A-8D28-79A9C6772A62}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [470804b2286291a564b1007e8184d32d]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A1154187-2946-4941-97BA-5E46608231B1}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [d07f5660ef9b77bf5cb9e7978f76c040]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A2539C55-4371-45FE-96CC-529D41E4EB98}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [85ca5462e4a645f120f55c220cf9d927]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A3BC47E5-AD94-4FDC-8F5E-AB785CDB97BF}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [d8773a7cbbcfe353df37d0aee52005fb]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A3CB6150-3A1D-4E2D-9CD0-71BFD1ABF152}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [4807288eec9e62d467afa4daf01541bf]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A3EFC03C-4FD4-4368-9BAA-DA9CA841149C}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [e46b8a2ced9dfc3a19fdc4ba8580d12f]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A410A546-7A20-4DB8-BB1B-906777B2CBE7}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [cd828f2748425cda23f26519f4111ee2]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A45CB193-B89E-44E8-89B9-E54F3D8D6B46}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [56f9d0e60f7b63d3888e651934d1b749]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A4E85A71-1DAB-4A88-8328-674EAC72866F}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [ed623d790d7db87e39ddb7c721e4e21e]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A5227588-A98E-4D92-92BF-FAD9B1E9F867}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [68e75d59098171c562b3e39bcc39b947]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A56310BD-ABD4-4CA3-9B83-ACADB2F9D452}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [4609f2c4206a1521c650e5991fe659a7]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A59696F5-F091-436F-91C1-628111641C63}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [68e77b3b8802e650b362423c0005c739]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A5B0DA9B-6703-49D4-90A3-6CEE54729A6F}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [d27d07af41492115e92df6886e975fa1]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A621A61F-E71B-450D-9C77-587A1495472F}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [7bd43f77682246f0fb1b5c22ec197f81]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A63E8236-EB85-4A06-AB1A-C9F457EB7F17}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [be912591701a7fb717ff502e51b4cd33]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A6615DC4-3E43-492D-9DD4-844ED863E448}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [5ef193235b2f43f3ed28abd3cc39b947]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A6F9C3E2-3CE2-49DC-8484-36D3DD75247E}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [5cf3288e4e3cb482ec2accb2cf36966a]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A6FEF922-B252-46D4-9685-29E95A8A481A}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [aba47c3af892ce681ef8f98537ce1be5]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A7A93E34-B9C6-4C03-AFCD-F37F336A3193}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [7ad51a9c7e0cf14545d092ecb352eb15]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A7D5FCE9-44AE-4292-891F-7D6CDCBDDA10}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [ba95585e7f0b063021f48cf2ec196e92]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A805E0C3-B902-4C6D-8361-1E1BD0EC8271}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [103f5462fc8e1b1bcc4aacd2897cd22e]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A81346F5-47F3-4BB9-8167-39292AF2855A}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [3d123383cfbb81b54acb542a6c991de3]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A81DF0E6-D2E6-460A-9BF8-2949E65B2F7A}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [61ee4373008a58dead68e49a867fd927]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A8EBD043-6E27-42FD-AD40-4615E9C0E130}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [81ce7442038778be2cea2e50ae57956b]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A939590C-C430-4813-AEC3-4F4241ED6656}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [dd72cde98208df57bc59e39b52b332ce]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{AA19F068-E317-409C-9990-627741D05081}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [c48b526402881422a571eb93ec19c43c]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{AA26FB54-9C1D-4EBF-80C9-A8D036543186}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [8bc421953f4bc96d6da8017da362a65a]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{ABFD648C-265E-489A-8876-F4CCC666324F}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [242b4571a0ea5bdb1afba1ddb35248b8]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{AC21F455-A985-4BC3-9DF3-9152E292D979}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [3c13bdf914766ccad93d9fdfa1643dc3]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{AEC45D7F-4FDC-404C-BAB9-FE8F1DE797A7}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [77d8ccea305a12241ff65e20ec1932ce]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{AF136B5D-4043-4C7E-A9FE-B379B15673A1}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [212eb402444639fd42d3e5999e67c13f]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{AF4A1904-3124-4134-AD2D-E3197D2C1BA2}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [c38c3a7cc6c4e74f3ed7d8a6dd2808f8]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{AFA598EB-A8F2-4455-ABC4-1F1622D25126}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [51feccea4f3b4aec62b38df18085728e]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{AFA940D8-5815-4664-86EE-B6BDF532E9E5}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [91be76400d7d54e2e531700e7b8a738d]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B0012DD3-83B0-42FA-8B47-8444E9F14D25}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [cd822096f79394a2be58ceb0c441f50b]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B0CBD6A8-279C-49B3-A476-F668C5CEF29C}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [8fc09b1bed9dfd39b85d7e0046bf6d93]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B176A35B-5F4D-4082-AF82-AF18E31F36CE}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [1c334b6b78124cea021481fda46114ec]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B1AEFEAA-20EA-4D86-9525-EA48FC8D7ECF}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [a8a7b1055e2c989e69ad2757ff060af6]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B2246094-17FF-42AA-AFDA-5E128E2AC5E1}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [afa0dbdbc6c486b0a0768af456af09f7]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B2A5859E-FEDA-4F76-AFC0-21EAE7C52BEC}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [470895214d3d5ed8bc59700e34d1748c]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B3D0D1E7-6037-4345-9078-FBC16D6F60D9}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [b798c7ef2f5bf640e62f3846e32230d0]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B45094F2-815E-4CF4-9F12-F3D0187CBC18}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [133c2e88d4b6f73fa274ea94689d7c84]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B45ACE54-FF3F-47A9-B2C0-96163851DB5C}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [301fd1e5dab00b2b070e641a5ea7c739]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B475BB73-371C-43FB-9419-399B586A3D14}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [68e71c9ac0cac96d0214502e04010bf5]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B47B9F35-EF5D-4A76-A5C5-812CE2706A7E}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [d27d80363b4fc17569ad0c7272935ea2]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B49F45BE-CD2A-4880-AF95-BE94DDA0C9E0}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [afa0f8bef99153e30f063648ba4b06fa]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B507220C-7153-4DE3-8052-6AFA2B4B2215}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [85cac3f32862af87b95d7a045ca9936d]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B5D46B22-A820-41E0-9953-B4D17A8BAE23}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [d37c6056b1d9a49270a5b5c9c83dfd03]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B5DE8D1A-A55C-4940-9B7F-8C165BA01BCE}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [143bbdf9ef9b3bfbd3435f1fb94c0bf5]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B7C3CDA8-4BB4-4337-8A79-1F3F1C768E4A}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [ada290265f2b7bbba86dd7a790750ef2]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B80C4C61-162C-460C-80F6-BED8AE493BAA}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [f45b04b2ccbe55e10510b1cdce37837d]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B91897BB-E5A5-4D69-BB6A-66F43B6F75F9}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [61eebafcdeac5adc8c8a4d319a6b5ba5]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B93998FF-EBAB-488A-B9A7-FF6EA65014DF}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [da754b6b6327bc7a6ea85727f90c6997]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{BA008C75-E7B7-4909-B6C2-5219B3F38ED9}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [b09f387e0189e25441d44d3113f214ec]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{BA85107D-CEA6-4134-834B-4AE56386C4B5}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [5ff0caec92f8d0667e98e29cc144649c]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{BC5714F6-40B5-4EF1-8A9C-11131D387451}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [67e84571f09a5fd77a9c1f5f9d68649c]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{BCE1AB6A-BADC-46B8-B553-9D50E6DD9DBC}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [ce81a0163c4e89adfe17d3abab5aee12]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{BD903554-491A-469C-9968-CC1C3737F64C}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [a1ae6f47e0aa7eb8c451e19dc14425db]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{BE3D653C-8DE0-4638-9B10-BDCBB7B79825}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [80cf5165c9c15dd9fb1a512d1beae31d]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{BEEC60BA-2B69-45D7-82A5-B4F5C2BF2EAB}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [83cc3482acde1521dc3a6f0f6d9858a8]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{BF693D9C-9860-456A-8AE2-FE20B1A8D7B5}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [f758e9cd375338fe799da6d824e1f808]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{BFDD074A-DA9B-4C8C-8B2D-76D929BBEC5E}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [c18e2294fd8d9c9a3adc403e4db821df]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C0AAFDA2-91D8-46DF-B9FD-A1687B39FF1E}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [bc93e4d21d6dcd69080ef688ab5aa55b]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C1F1EF66-D552-4590-B8D6-3AA9166126EB}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [6be45462c1c9e551c74e423c6f96ed13]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C27857BF-4574-4510-BC59-A37A17856C22}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [7bd426909cee9b9b38dd532b9372b34d]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C2ADD5A1-FBBC-483F-A872-FD423F25BB6F}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [1837397d6f1bf73f7a9b18669f66817f]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C3003382-1E5E-4FEF-80AB-81F7C66939F4}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [89c6981eff8b1b1bd144add110f5669a]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C35B3D95-4F89-43B5-B4DA-AB6FCCAC27CE}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [5ff01b9bff8b34020e0782fce322b44c]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C36FB017-AE84-43D5-B83E-8428E7D1AE7A}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [eb644c6ae9a1aa8c06101e60c63fe719]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C3757E3F-E546-40A5-A626-D58C7FAE44B9}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [b19e84322a60082ee530aad4f312629e]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C3AEEF1C-D169-45A4-AD36-AD20C763E894}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [f15e2492dbaf2d09c94c4638996ca858]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C4001CF2-D5D3-4077-859C-FBA174A2F83E}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [b996724441490036789d4f2f8e77738d]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C4FBA2F8-7335-4E1B-8E2B-3641D3CD65C0}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [4e017b3b86044bebd244e797c540639d]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C50E4E3E-BA11-4869-AA9D-81E23F68F6BE}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [6fe06e4890fadc5a17ff1767b84d936d]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C56F3F14-139B-495D-8AA4-5C528643F729}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [b699179f672344f2bf579de116efa759]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C68D9AD4-6331-4F04-8B6D-D8142377BF7E}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [6ae512a425650f27fa1cd3ab9b6a7888]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C6DA3D7F-E481-4006-A48F-A8BB50232EEE}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [74db7c3aacde78bedb3b3c429a6b8080]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C75C91C8-4D56-4074-965D-F04DABEADB62}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [2a25773fff8bcf67d343f886be478d73]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C78B678F-A13F-4925-8BD1-73823DAE7164}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [60efffb79ded57dfd93d502e31d48a76]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C837A751-C2D6-4513-8F3A-9626557865D1}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [301f84321179f24463b30e7012f3a759]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C84A3873-C7BB-4117-9142-D781EC87EBCD}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [212e2096f298a690f3222d5164a128d8]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C871263D-E744-4A20-8310-108C6AF0AEAC}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [ba95d5e1701a45f1ca4b6e1033d27e82]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C92EBF16-35AA-4090-86A5-CBD845BED69F}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [0f405e588dfdd26468ad225c21e449b7]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C92FCF70-47C2-4FE2-A6AB-BA7A90EB7596}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [113e92248bffa2940b0bd6a822e3d828]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C97E147C-E4FE-408B-9472-CED828491FAC}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [50ff46705c2ef4425bbb5529bd485aa6]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C9ED7304-5214-44F9-AE52-FFA2BF636D47}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [9db290263d4d7fb7be58f6880ff6fc04]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CAB6DE32-FFF7-47F4-8164-A84A23F27DE3}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [ba9515a12f5b41f54ec8d6a815f09b65]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CB1966CD-C34B-4BBD-824E-FB25EC448AC5}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [fe513086573347ef29ed80fe669fc040]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CB737A36-C0AC-4B29-B6FB-B033A2F4226F}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [39161f97355568ce2aebe49a1ee7f907]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CB7B68E5-D42C-4BE0-ABCB-A5C4185B94BC}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [c986b303f39755e193822d51da2bc040]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CB8E2435-3DB0-4906-824A-9C7F5F907A4A}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [76d9cbebaae0de5841d4ec9242c33ac6]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CBFE28DF-F285-4993-9CFD-2925908789CC}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [440b7c3a8ffb072f23f2631b4fb610f0]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CC11E1C5-F9CA-4CED-9774-2429F323555A}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [2a25714589011323a471017da65f3dc3]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CC24B639-ADE0-4B50-887F-2C78C01A5F19}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [c48b8d2957338fa79f76b1cd0401e719]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CDEC0958-1EE5-49EF-9496-31A4CD71FC9D}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [8cc36353b9d16ec81afc99e5c63fcd33]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CE103B4B-F372-4C98-9653-C1675033CB1A}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [9cb33e7889013ff7f81df08e679e768a]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CE33EFC3-1E5A-4814-BDB7-2D7FBDAD3B82}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [d07f3482117988aea273c6b818edeb15]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CE4EA8A6-BFC5-4C99-8DB8-58ECBD882034}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [ef6061552d5db680ec296b130cf98779]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CF570C0F-BD76-49EE-A116-5647E22940F2}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [252a3c7a5c2e46f04ec808763cc9a15f]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CF71B29E-3A95-4348-B5DC-D65168B0C7D1}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [66e9a214f09a1026e630fd8133d2be42]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CFB5FC35-7D9D-46DE-8AA5-DB5733F0A07A}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [36192d893654b6806ea8f48ad82da65a]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D0331C44-EAC8-4197-85F8-FEBB13E44C39}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [8fc0dfd7246680b67d98651959ac6c94]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D044B141-D89E-45B4-AC36-4753B2E13E76}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [98b714a2c0ca4beb0510c5b9bb4a5fa1]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D08F5FCC-64E0-46F4-B64D-EE7D55B29F70}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [7cd3a21476149a9c69ad205e33d2916f]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D0BA3190-B72E-4562-8618-1F7CF9F7A2B5}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [75da5f571179be78b660b6c8fb0aba46]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D120E6D9-A31D-4AAA-9CE5-1D2C973EC8EB}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [93bc1a9c97f3989e6baa631bef16f60a]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D13A1552-385C-47DD-BDC8-8E73E2879E44}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [4807d7df2367ca6c47cea5d926dfcf31]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D19529DB-8EF3-4893-8E12-4E5F2EDBC0FF}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [c18e3c7a2565ef47a66f1b63f80da65a]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D1AFE3E4-EB94-4CB2-8ADC-1953553462C9}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [410e6155018976c038ddcbb3c93c06fa]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D1CCC8EC-55D3-430E-8B44-26ED7A3D6E2F}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [5ef1e1d5fc8eea4c5eb8077737ce5fa1]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D27DBDA1-9091-44F9-9F4C-F64FBD8363F1}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [cf806e487713ff371df9fe803cc9f808]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D355597E-F18D-4262-97BA-38281254A6DD}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [3c134472f991d06659bcaad407fe34cc]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D45EA191-763A-4E2A-9C84-7BAF95333C30}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [331c9f17beccf73f18fdc1bd40c5d42c]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D4A0BFB0-FC4E-46CA-BC31-1433D3FB1D98}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [252a4c6acfbb0234b165b9c5ab5a5da3]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D5710DF7-825A-448C-BF40-54654D8164EB}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [aea11c9aa5e5f93d53c37905669f53ad]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D579EE4F-233F-4404-B6ED-15C36F24307C}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [3718a214bcce171f0313ff7f28dd738d]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D6ACACE5-588F-4829-969E-D598F0912D23}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [64eb7d39cbbfdc5ae531671727de48b8]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D7B25328-7ECA-4956-8E2D-16F691DB478B}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [f35cb1053f4bca6cdc39ea948e77728e]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D7E2CFCB-4993-41C2-A1FE-5262B143FB21}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [df70d8decac063d30412f38bf70ed927]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D823FB6C-8BE0-452E-8742-4639A5A8796E}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [044b4c6a8bff290dca4c48366c9902fe]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D842A344-F6D3-49EA-A790-A7D42742DE28}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [222d7a3c77135bdbcd48265814f15ba5]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D84A96EC-503F-452B-A7DB-AA31FFE884F9}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [7ed1694df793a88e2ee84836c540ad53]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D8856E62-2060-4E57-87CF-594ED52DB944}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [53fcb7ff90fa2a0ca86d92ec50b59e62]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D94B6561-3FE2-4CE1-A85D-B81123351FF3}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [3f10d0e6800a56e0d243057948bdf30d]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D97A0D10-F9EB-4758-8187-BDC3D8C1FA15}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [e46b4670860476c0e135daa4ee17ca36]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D99210FD-31D8-4AF4-9A18-DCAA61149B72}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [a5aa11a5f595c27465b0fe80a3624db3]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D9A7F85C-6FE8-460F-8288-EBC86E33CCB5}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [aba4cfe771196acc19fcb5c9ed1803fd]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D9E4D09D-B031-4879-A686-52615ECF6D54}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [c8870bab01899e98e2344f2fb74e0ef2]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DB65BE06-1F62-41CF-A765-94AAA38B2A4F}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [f956783e91f943f34dc8b3cbcc39aa56]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DBBB773B-BB6B-4E4D-8A47-BDA58C35C643}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [5bf4ecca94f62f07ae681c6244c16c94]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DBF986D3-D97D-4193-AFE7-1855F424A267}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [153a3e78870366d0cc4ac2bc16efa35d]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DBFFBA56-DC13-45E4-B2AF-78BC94A918BE}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [68e76c4ab7d3cd699086abd343c228d8]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DCF65A78-1066-437C-9C51-1D89DA95845D}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [ada24d696822cf67ba5b3c422cd9b44c]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DE03B2B1-5F7A-4AE9-8A53-ACF48634741D}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [e46bf4c2cebca88e0511a6d8ed1821df]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DE70A271-C8C2-45D3-BC9E-15BB951EEAE1}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [e06f476f345667cf8195017d848158a8]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DE89E01D-C229-4E25-8E26-1D3DEFA3F28D}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [77d8bcfa48421224d0451c628c797c84]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DE8AD8AD-8473-4B19-A2BC-C86E3420E392}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [7ad56d4999f184b216ff522c18ed04fc]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DE921321-82D0-44E7-B9F3-ECD738BE815E}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [bd92edc9f991072f63b3cbb334d16898]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DED6ABA2-E81C-4A64-ADF5-9DCD896FF651}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [a2ad8f272d5dff3774a1423c9471956b]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DF261665-25C2-40E2-BE3C-BDF099845B58}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [f45b16a008824beba57105794fb6d828]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DF82B2BA-D30A-4501-B1BB-C7EE5F7614BF}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [72dd0ea887032e08070e601ea75edd23]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E05C4F14-2A68-44C6-9387-6413E13BC69E}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [1f303086aae0b4825db88af4cb3a9b65]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E07A3B09-BFE8-4F77-991F-58C898E615F2}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [73dc35818703270fb36388f622e3b24e]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E0A8A0D8-8D09-4A50-AB4A-B8D26E3E1E11}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [0d429b1b880289ada76f3945d332cf31]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E0F36729-1AA2-46D9-B567-7E612FF0DC27}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [aaa505b12466c07618fdb9c5a26334cc]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E12C2B8C-25C7-481B-9FA0-136E59FBA9CF}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [5af5b5010f7b1b1bc650304e4bbaaf51]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E1F39206-D029-4C84-B23A-EF7117E32F43}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [8bc4e3d33a501125ea2ca4da40c5758b]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E2E32D68-75BC-490B-8494-6B73694F9AF8}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [c8872492256571c513035628d332ce32]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E3671CC0-BDCB-4980-93CC-F254FCCA4A5E}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [7ed1ffb7fb8f63d337df2955fe07ca36]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E4F54ED6-7DBC-464D-A478-7AF04B6D5253}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [c689892df595c5711ef8f38b996cf60a]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E52BAE5E-862A-4CF0-8926-C767F797DDDA}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [92bdbcfaaedccd693adbe797e0253cc4]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E54F60F3-24ED-4A2F-8F2A-9220B8DEBEDD}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [2926417593f7270f1005f28c07fe44bc]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E5700B42-8E12-439C-A070-1180AA4EBC47}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [e56a75414f3b2214e5319fdfb550857b]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E57B9F05-908A-43CD-BF21-7CDD19B34F7F}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [76d908aef793092d1df9156932d37c84]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E5D4D340-2458-4F7D-AAD1-BFDAF78FAC3C}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [84cb8b2baddd310541d4afcf2fd6d22e]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E60A8018-A08A-4059-8637-2F305D909386}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [014e7046573390a666b06f0ff80d3ec2]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E72BD8B9-9EF4-47CE-BC16-8A1DE36A9C77}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [87c865518208072f39dd75094db8f50b]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E72D5B4B-489C-4533-8E8D-F0AA7242429F}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [e768b2048ffb73c392833a44a362f709]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E73E5E72-4585-4A7D-B13D-7071F022F412}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [1d325462028842f42ee82f4fd82dd828]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E772A5C5-8F6D-4541-944B-D46D4E8D7899}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [cc83e0d67119fb3baa6b4c3265a0a25e]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E7E41E3F-AECA-4E94-8586-E036F0AA5D42}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [76d9863066247cbac353b0ce6f96ef11]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E7FD9FF2-2A44-42D9-BE9D-C7D99BC9F4B0}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [60ef694dd5b5b97d8690522c8d78ca36]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E808C9E8-8332-42F4-B3FF-F5412F9CEF6A}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [440b6254deace0567c9a96e8db2a8d73]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E8973C47-EA5A-4EBA-A29F-AE512BA1CEEC}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [1e31aa0cff8b50e63fd7601e09fc3fc1]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E8B776F8-9BBC-420A-B923-A6AB95371467}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [fa5572445238af87b461f08e51b42fd1]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E8DEDDBB-1E7B-437D-82D2-8A8945572AE5}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [77d86b4be0aa03331df8ed9114f1cb35]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E923A5B9-A57F-4F38-ACFA-1623E4E6719B}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [301f3284b9d1d1650d0892ecf312f709]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E9AB667E-B6E5-4EFA-BB33-796EA89D60D0}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [c38c0da95f2bbd79e0354c3257ae758b]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E9C4C7BB-1218-481A-B09B-40882F1B514F}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [e669298dcfbb8fa72cea76080ff6ea16]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E9DC3EB7-F7E0-408C-86D4-F89A1FFCFE5C}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [83cc9b1b42483bfb7c99344a8f76ef11]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EA855EB1-F572-4C7A-A6A0-C8777F8ACF47}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [d87774429cee0a2c10066a14e81d0000]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EBD9235D-3B2F-46CA-96D6-5592673A46E3}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [07489d19e1a92d09de38601ef510e21e]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EC147239-19EB-4625-8212-B0185885D887}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [bf90e3d33d4dae88cf463c42010408f8]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EC7D6633-37F0-40DF-95CC-99DB45DCD1C7}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [58f74e6891f9cc6a4bca146a5fa639c7]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{ED0B5441-2E19-4262-A9E7-BA432AE381C3}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [0946d4e22169e84eee28017df01549b7]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EDE4343B-68C4-4FCC-8CFD-EBBF3F182A88}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [351a54624446ca6c0b0ad5a9689ddf21]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EE2EE310-9A8A-40F8-93D1-9490CE6BF371}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [ea65674fcfbb270f68ad6d119c6916ea]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EE85F9E5-430B-4A01-B5CE-A641F1B2B8B8}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [47083f77c7c310263bdab5c97392a060]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EE8EED38-E186-4FC8-AE7B-CD8683263D3B}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [fb5491255634c86e5fb7324cd431e61a]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EF397A75-60F6-4E87-8B32-34CFA39B53C9}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [54fbd2e43d4dfb3b2de9d5a915f0b34d]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EF5D9AA9-A7EE-4B1C-9212-4B7978D8BDD3}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [7ad59d193654082ed63f67178283b34d]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EFD10EA6-170D-465D-A725-451DBAE1AB9E}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [57f8a412543643f37c9ad3ab1beab64a]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EFE0F177-CE24-4F36-ADCB-5D9F21E6DD3F}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [2e21ecca1f6be84efa1b3a440df8649c]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EFF6EE17-A27A-4F55-A66A-2DD78F42E38B}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [4e0106b08208b284f2232b534db860a0]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F01FD24E-361E-4B7F-8458-E29AB0B76B5E}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [a0af694d771355e1b95d720c010445bb]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F09FC1A7-6AAD-489D-B721-487F20FC5226}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [d47b7a3c6f1bce68878ef48ac63f8c74]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F0B60918-7289-4FA3-B26D-478580AD45E5}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [88c707afd9b1ed4949cd0876a16427d9]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F0C0B402-A229-47EE-ADC1-A015B891C980}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [0946a016bfcbde5817fea5d97d88718f]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F0CA179C-C7CC-4E93-B0FB-616DB5B8677D}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [f25dc3f31f6bee483fd77d01be47837d]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F0FF68B7-1537-4C77-82B5-4026B68C7154}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [c38ca80ec8c239fd35e197e77c893bc5]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F1C03FF0-3B8D-4B32-A4E7-DFE1D0881BEC}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [86c9585e4941dc5ae530f589be47d828]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F1F535A4-FBB1-4AFE-A8D7-EECCE74E2695}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [321da2148bff79bd85900b730203fd03]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F29FA44F-941F-4DEB-AF54-46893876DDB7}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [e16e0fa70f7b0036b06699e554b1c23e]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F2C2A039-57B1-431C-8D16-B75422EA4918}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [b39c06b08901b383a274314d8283d12f]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F2F0A260-FA5B-4AF1-9197-4B19EAA339E6}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [222d06b0f496ef4746cf6f0fba4b11ef]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F33B818B-13B0-4923-9EAC-EB3E7C985DB0}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [1936c2f4dcae9c9aa175116dc93c3dc3]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F3A181D4-BDBC-4763-9DA4-38E4EB3C6135}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [133cf3c39deded49997dc3bb9471a15f]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F45126EA-9462-456C-A617-C6AC66B5EF98}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [8bc47e38305a1323be573f3fd4314bb5]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F476BEA8-C534-49A1-B5CD-6DCE39B7FA92}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [9bb483338703c47263b2ceb0b64f9070]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F49E8933-5FFB-4F01-8349-3CA5F22DF5FC}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [450a07af16740432c74fb3cbc93c27d9]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F4CF303D-B4CC-46F4-8CFB-CFEC555961A1}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [a7a89620dcae37ffa27387f73cc949b7]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F554DA5E-D2ED-41AB-AA41-BA1ACA74A549}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [113e7f3709814fe7ea2cd0ae966f35cb]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F5A909E5-F237-4AEC-9A83-56EAC0B6E892}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [143b2195a6e46ec8b362d7a75fa62ed2]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F6002B6C-D5EA-4D1B-919A-132E197678CC}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [98b720962268270f35e13e4053b2f20e]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F7486085-390A-4123-A41D-F6BD79CABBBF}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [f15e00b6b2d889ad9e78a5d93cc922de]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F879A82C-34F3-4933-BD93-ADDD2F77F510}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [7dd29d19731739fdf521f18d09fcf808]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F8E55F0A-BF44-45B3-AB95-675CDE2A2654}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [a3ac674fafdb2412d045a9d5a65fa25e]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F9639BAD-9BEA-4877-B720-91C7289836D7}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [55fac9ed602add597e980678af568779]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F99300BE-9556-475E-8939-441E6E87887A}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [49065660a5e510261ff6611dae5758a8]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FA549D59-8621-4CE3-8C82-D67690866EE8}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [50ffb501206adf572de98ef0e61fab55]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FB16AF2C-246C-4C11-9753-21DEF38D61F1}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [0c4380367614ab8b3dd86e108085a55b]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FB4D748E-AF3D-4C1D-91A3-856DA8991AD3}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [351a3185494179bd20f5502ee4214ab6]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FB9073D8-1532-4D9C-B464-73B36F783C91}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [79d62690c9c184b2ef2780fea263e917]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FBD787C2-4A3B-4711-9C49-8524E8C9A9A6}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [84cb40767c0eff37c25425599a6b13ed]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FC08746B-EA08-4C2C-84B9-F4ED4B4C254B}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [9ab514a2c2c89f9700153b4325e034cc]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FC3F2A45-953B-40B9-A885-FD40D438C514}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [64eb9a1c98f2a09655c06f0f4cb9f010]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FC6A40BE-3A10-4847-AD72-5D7427478A72}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [bb94882e5733cb6bfc1a97e7c93c6799]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FC8FE3C9-E2E2-46FC-9E45-2A498C7B94B5}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [db74eec87a105dd93cda304e45c0956b]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FD1A8219-3375-4AF7-B41B-56B44EBE9F8D}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [c689c2f43159082ea2749ce22fd6b947]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FD53FFAB-EE1B-426B-A89F-5C9DC1542BE4}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [4b041c9aed9d84b21ef796e8976e19e7]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FD8C8C4B-B923-4772-A637-F96F8B284157}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [2c232096aedcc6707d99304e3cc96d93]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FDE96B46-ED77-4F92-98E9-B87E78B3686E}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [ea65298d38523ff7f71e3d410ff64ab6]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FEBBEC72-4A0A-47FE-B0DF-95485F5BB43D}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-codedownloader.exe, Quarantined, [93bce7cf1278cf677b9b92ec4abb03fd]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FFBA574A-A433-409B-B9EF-16657019BEA2}|AppName, c04fc0ec-79d8-4759-ba86-ee0ffb49fea0-2.exe-buttonutil.exe, Quarantined, [a1ae2e889bef55e1e332a4dac14417e9]
PUP.Optional.QuickStart.A, HKU\S-1-5-21-1232603322-3645337139-1979953262-1001\SOFTWARE\MOZILLA\EXTENDS|appid, [email protected], Quarantined, [d17ec4f2d0baf83e54780c0a06fe7a86]
 
Registry Data: 0
(No malicious items detected)
 
Folders: 20
PUP.Optional.MultiPlug.A, C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\giccehglhacakcfemddmfhdkahamfcmd\151, Quarantined, [5ff0e8ce305a5cdab6bdfc7c8b7a4cb4], 
PUP.Optional.MultiPlug.A, C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\giccehglhacakcfemddmfhdkahamfcmd, Quarantined, [5ff0e8ce305a5cdab6bdfc7c8b7a4cb4], 
PUP.Optional.MultiPlug.A, C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkoghcmfjgopofakhllpdmflopkhccoj\1.0, Quarantined, [f659b5017713f93d0c67b7c157ae34cc], 
PUP.Optional.MultiPlug.A, C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkoghcmfjgopofakhllpdmflopkhccoj, Quarantined, [f659b5017713f93d0c67b7c157ae34cc], 
PUP.Optional.MultiPlug.A, C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\kmjboicapmacdaecgldenkpdcdkkifgc\1.1, Quarantined, [9db233831e6cd363046f1b5d12f36799], 
PUP.Optional.MultiPlug.A, C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\kmjboicapmacdaecgldenkpdcdkkifgc, Quarantined, [9db233831e6cd363046f1b5d12f36799], 
PUP.Optional.MultiPlug.A, C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\oefifkdlbdfmnhdkbagencoidhfjcich\2.7, Quarantined, [5cf3c4f25337d561a1d2f58360a5649c], 
PUP.Optional.MultiPlug.A, C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\oefifkdlbdfmnhdkbagencoidhfjcich, Quarantined, [5cf3c4f25337d561a1d2f58360a5649c], 
PUP.Optional.MultiPlug.A, C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\giccehglhacakcfemddmfhdkahamfcmd\151, Quarantined, [75da575f7119ea4c4c2726526b9a52ae], 
PUP.Optional.MultiPlug.A, C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\giccehglhacakcfemddmfhdkahamfcmd, Quarantined, [75da575f7119ea4c4c2726526b9a52ae], 
PUP.Optional.MultiPlug.A, C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkoghcmfjgopofakhllpdmflopkhccoj\1.0, Quarantined, [a5aad5e15a30999df182364226dfe917], 
PUP.Optional.MultiPlug.A, C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkoghcmfjgopofakhllpdmflopkhccoj, Quarantined, [a5aad5e15a30999df182364226dfe917], 
PUP.Optional.MultiPlug.A, C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\kmjboicapmacdaecgldenkpdcdkkifgc\1.1, Quarantined, [eb64e5d17317f343a9ca3246f90c12ee], 
PUP.Optional.MultiPlug.A, C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\kmjboicapmacdaecgldenkpdcdkkifgc, Quarantined, [eb64e5d17317f343a9ca3246f90c12ee], 
PUP.Optional.MultiPlug.A, C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\oefifkdlbdfmnhdkbagencoidhfjcich\2.7, Quarantined, [8fc0595d4d3dd4621f54393f85808b75], 
PUP.Optional.MultiPlug.A, C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\oefifkdlbdfmnhdkbagencoidhfjcich, Quarantined, [8fc0595d4d3dd4621f54393f85808b75], 
PUP.Optional.MultiPlug.A, C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\giccehglhacakcfemddmfhdkahamfcmd\151, Quarantined, [ff5045716327c4727ff40e6af70edc24], 
PUP.Optional.MultiPlug.A, C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\giccehglhacakcfemddmfhdkahamfcmd, Quarantined, [ff5045716327c4727ff40e6af70edc24], 
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService, Quarantined, [92bdd9dd5e2cd2642217fcb8a65d7987], 
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService\update, Quarantined, [92bdd9dd5e2cd2642217fcb8a65d7987], 
 
Files: 43
RiskWare.Tool.HCK, C:\Program Files (x86)\Internet Download Manager\32bit Patch build 11.exe, Quarantined, [2926d1e50486cf6740f499c42dd55da3], 
PUP.Riskware.Patcher, C:\Users\Rifandi\Downloads\_www.gigapurbalingga.com__IDM.6.23_Build_12.rar, Quarantined, [242b08ae008aa5917c0cd76bd52ca759], 
PUP.Riskware.Patcher, C:\Users\Rifandi\Downloads\_www.gigapurbalingga.com__IDM.v6.x.x.Up.8.p-REiS.rar, Quarantined, [5af505b1e5a5f541b4d465dd9071758b], 
PUP.Optional.Amonetize, C:\Users\Rifandi\Downloads\just cause 2 pc patch 1.0.0.2_10924_i14323197_il345.exe, Quarantined, [fc53fbbbdeac12241991571b31d13bc5], 
PUP.Optional.QuickStart.A, C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx, Quarantined, [90bfeacc771382b4c604e82118ec0df3], 
PUP.Optional.MultiPlug.A, C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\giccehglhacakcfemddmfhdkahamfcmd\151\lsdb.js, Quarantined, [5ff0e8ce305a5cdab6bdfc7c8b7a4cb4], 
PUP.Optional.MultiPlug.A, C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\giccehglhacakcfemddmfhdkahamfcmd\151\background.html, Quarantined, [5ff0e8ce305a5cdab6bdfc7c8b7a4cb4], 
PUP.Optional.MultiPlug.A, C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\giccehglhacakcfemddmfhdkahamfcmd\151\content.js, Quarantined, [5ff0e8ce305a5cdab6bdfc7c8b7a4cb4], 
PUP.Optional.MultiPlug.A, C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\giccehglhacakcfemddmfhdkahamfcmd\151\manifest.json, Quarantined, [5ff0e8ce305a5cdab6bdfc7c8b7a4cb4], 
PUP.Optional.MultiPlug.A, C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkoghcmfjgopofakhllpdmflopkhccoj\1.0\lsdb.js, Quarantined, [f659b5017713f93d0c67b7c157ae34cc], 
PUP.Optional.MultiPlug.A, C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkoghcmfjgopofakhllpdmflopkhccoj\1.0\background.html, Quarantined, [f659b5017713f93d0c67b7c157ae34cc], 
PUP.Optional.MultiPlug.A, C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkoghcmfjgopofakhllpdmflopkhccoj\1.0\content.js, Quarantined, [f659b5017713f93d0c67b7c157ae34cc], 
PUP.Optional.MultiPlug.A, C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkoghcmfjgopofakhllpdmflopkhccoj\1.0\manifest.json, Quarantined, [f659b5017713f93d0c67b7c157ae34cc], 
PUP.Optional.MultiPlug.A, C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\kmjboicapmacdaecgldenkpdcdkkifgc\1.1\lsdb.js, Quarantined, [9db233831e6cd363046f1b5d12f36799], 
PUP.Optional.MultiPlug.A, C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\kmjboicapmacdaecgldenkpdcdkkifgc\1.1\background.html, Quarantined, [9db233831e6cd363046f1b5d12f36799], 
PUP.Optional.MultiPlug.A, C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\kmjboicapmacdaecgldenkpdcdkkifgc\1.1\content.js, Quarantined, [9db233831e6cd363046f1b5d12f36799], 
PUP.Optional.MultiPlug.A, C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\kmjboicapmacdaecgldenkpdcdkkifgc\1.1\icon48.png, Quarantined, [9db233831e6cd363046f1b5d12f36799], 
PUP.Optional.MultiPlug.A, C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\kmjboicapmacdaecgldenkpdcdkkifgc\1.1\manifest.json, Quarantined, [9db233831e6cd363046f1b5d12f36799], 
PUP.Optional.MultiPlug.A, C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\oefifkdlbdfmnhdkbagencoidhfjcich\2.7\lsdb.js, Quarantined, [5cf3c4f25337d561a1d2f58360a5649c], 
PUP.Optional.MultiPlug.A, C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\oefifkdlbdfmnhdkbagencoidhfjcich\2.7\background.html, Quarantined, [5cf3c4f25337d561a1d2f58360a5649c], 
PUP.Optional.MultiPlug.A, C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\oefifkdlbdfmnhdkbagencoidhfjcich\2.7\content.js, Quarantined, [5cf3c4f25337d561a1d2f58360a5649c], 
PUP.Optional.MultiPlug.A, C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\oefifkdlbdfmnhdkbagencoidhfjcich\2.7\manifest.json, Quarantined, [5cf3c4f25337d561a1d2f58360a5649c], 
PUP.Optional.MultiPlug.A, C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\giccehglhacakcfemddmfhdkahamfcmd\151\lsdb.js, Quarantined, [75da575f7119ea4c4c2726526b9a52ae], 
PUP.Optional.MultiPlug.A, C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\giccehglhacakcfemddmfhdkahamfcmd\151\background.html, Quarantined, [75da575f7119ea4c4c2726526b9a52ae], 
PUP.Optional.MultiPlug.A, C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\giccehglhacakcfemddmfhdkahamfcmd\151\content.js, Quarantined, [75da575f7119ea4c4c2726526b9a52ae], 
PUP.Optional.MultiPlug.A, C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\giccehglhacakcfemddmfhdkahamfcmd\151\manifest.json, Quarantined, [75da575f7119ea4c4c2726526b9a52ae], 
PUP.Optional.MultiPlug.A, C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkoghcmfjgopofakhllpdmflopkhccoj\1.0\lsdb.js, Quarantined, [a5aad5e15a30999df182364226dfe917], 
PUP.Optional.MultiPlug.A, C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkoghcmfjgopofakhllpdmflopkhccoj\1.0\background.html, Quarantined, [a5aad5e15a30999df182364226dfe917], 
PUP.Optional.MultiPlug.A, C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkoghcmfjgopofakhllpdmflopkhccoj\1.0\content.js, Quarantined, [a5aad5e15a30999df182364226dfe917], 
PUP.Optional.MultiPlug.A, C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkoghcmfjgopofakhllpdmflopkhccoj\1.0\manifest.json, Quarantined, [a5aad5e15a30999df182364226dfe917], 
PUP.Optional.MultiPlug.A, C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\kmjboicapmacdaecgldenkpdcdkkifgc\1.1\lsdb.js, Quarantined, [eb64e5d17317f343a9ca3246f90c12ee], 
PUP.Optional.MultiPlug.A, C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\kmjboicapmacdaecgldenkpdcdkkifgc\1.1\background.html, Quarantined, [eb64e5d17317f343a9ca3246f90c12ee], 
PUP.Optional.MultiPlug.A, C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\kmjboicapmacdaecgldenkpdcdkkifgc\1.1\content.js, Quarantined, [eb64e5d17317f343a9ca3246f90c12ee], 
PUP.Optional.MultiPlug.A, C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\kmjboicapmacdaecgldenkpdcdkkifgc\1.1\icon48.png, Quarantined, [eb64e5d17317f343a9ca3246f90c12ee], 
PUP.Optional.MultiPlug.A, C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\kmjboicapmacdaecgldenkpdcdkkifgc\1.1\manifest.json, Quarantined, [eb64e5d17317f343a9ca3246f90c12ee], 
PUP.Optional.MultiPlug.A, C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\oefifkdlbdfmnhdkbagencoidhfjcich\2.7\lsdb.js, Quarantined, [8fc0595d4d3dd4621f54393f85808b75], 
PUP.Optional.MultiPlug.A, C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\oefifkdlbdfmnhdkbagencoidhfjcich\2.7\background.html, Quarantined, [8fc0595d4d3dd4621f54393f85808b75], 
PUP.Optional.MultiPlug.A, C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\oefifkdlbdfmnhdkbagencoidhfjcich\2.7\content.js, Quarantined, [8fc0595d4d3dd4621f54393f85808b75], 
PUP.Optional.MultiPlug.A, C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\oefifkdlbdfmnhdkbagencoidhfjcich\2.7\manifest.json, Quarantined, [8fc0595d4d3dd4621f54393f85808b75], 
PUP.Optional.MultiPlug.A, C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\giccehglhacakcfemddmfhdkahamfcmd\151\lsdb.js, Quarantined, [ff5045716327c4727ff40e6af70edc24], 
PUP.Optional.MultiPlug.A, C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\giccehglhacakcfemddmfhdkahamfcmd\151\background.html, Quarantined, [ff5045716327c4727ff40e6af70edc24], 
PUP.Optional.MultiPlug.A, C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\giccehglhacakcfemddmfhdkahamfcmd\151\content.js, Quarantined, [ff5045716327c4727ff40e6af70edc24], 
PUP.Optional.MultiPlug.A, C:\Users\Rifandi\AppData\Local\Google\Chrome\User Data\Default\Extensions\giccehglhacakcfemddmfhdkahamfcmd\151\manifest.json, Quarantined, [ff5045716327c4727ff40e6af70edc24], 
 
Physical Sectors: 0
(No malicious items detected)
 
 
(end)

  • 0

#15
BrianDrab

BrianDrab

    Trusted Helper

  • Malware Removal
  • 3,591 posts

Thanks. Let's do the following scan now.

 

 

Step#1 - ESET Online Scanner and Post Results
This scan can take hours to run but is necessary to ensure we don't miss anything. Plan accordingly.

 

  • Please go here and click on 1.JPG
  • Note: This site is optimized for Internet Explorer. Please use it for this scan. If you wish to use Firefox or Chrome you will be asked to download the ESET Smart Installer first (esetsmartinstaller_enu.exe). Go ahead and download and run this file.
  • Please accept the ESET Online Scanner EULA and click Start.
  • If prompted, allow the Add-On/Active X to install. If you have problems with this step please see this link.
  • Make sure Enable detection of potentially unwanted applications is selected.
  • Click the Advanced Settings link.
  • Make sure Remove found threats is NOT checked.
  • Make sure Scan archives IS checked.
  • Make sure Scan for potentially unsafe applications IS checked.
  • Make sure Enable Anti-Stealth technology IS checked
  • 2.JPG
     
  • Click on Start
  • The virus signature database will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed, if anything was detected please click the List of found threats link.
  • ThreatsFound.JPG
     
  • Then click the Copy to Clipboard link and paste this information into your next reply.
  • CopyToClipboard.JPG

     

     

  • Then you may click the Back button.
  • Check Uninstall Application on Close before clicking finish.

 
Items for your next post
1. Contents of the ESET log file

 

 


  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP