Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Antivirus Compromised During Hack Attempt

Avast Lockup slow startup Abrupt stops

  • Please log in to reply

#31
DR M

DR M

    The Grecian Geek

  • Malware Removal
  • 4,049 posts
Hi, Jim.
 
The logs show that some errors and corrupted files were found and fixed. So, I would suggest once again the procedure we already did. If it fails, we will go with a manual fix.
 
1. Restart in Safe mode
  • Press the Windows icon on the keyboard together with the letter I, to get into the Settings.
  • Choose Update and Security.
  • From the menu at the left, choose Recovery.
  • Under the title Advanced startup at the right, choose Restart now.
  • From the window that will appear choose Troubleshoot and then Advanced options.
  • Choose Startup Settings and then Restart.
  • Press number 5, for choosing Safe mode with networking.
  • You will know that you are in Safe mode, if the background is black and Safe mode is written at the four corners of the screen.
2. Run Revo Uninstaller
  • Double click the program's icon to open it, as you did before.
  • Write in the search area, on the top left, Avast.
  • Choose the Uninstall tab from the menu and let the program to create a Restore point.
  • Choose Scan, and then the Advanced mode scan.
  • Select all the Avast items found, Delete and Next.
  • Let the procedure be completed and click on Finish.
  • Restart the computer.
  • Repeat the same procedure with McAfee.
3. Search for remnants
  • Double-click FRST.exe/FRST64.exe to run it, as you did before.
  • Copy and paste the following into the Search box.
SearchAll: Avast;McAfee
  • Press the Search Files button.
  • When complete, FRST will generate a log in the same location it was run from (Search.txt)
  • Please copy and paste its contents into your next reply.

How is the computer running in general now? Any specific issues?
  • 0

Advertisements


#32
JimBow

JimBow

    Member

  • Topic Starter
  • Member
  • PipPip
  • 88 posts

Thank you. Unfortunately, it doesn't look like Revo took us any farther forward today. The Avast search did not uncover any new programs to uninstall, only one registry item that is always there despite being deleted each time, and a Revo-related file and its host folder that probably gets regenerated on each run. Similarly, the McAfee search also had no new programs or registry items and a small Revo-related file and host folder. Nonetheless, the FRST search still found plenty of Avast and McAfee remnants. I hope the enclosed search file makes the manual delete effort relatively straightforward.

Jim

 

 

Farbar Recovery Scan Tool (x64) Version: 13-05-2020 01
Ran by Jim (23-05-2020 19:22:50)
Running from C:\Users\Jim\Desktop
Boot Mode: Safe Mode (with Networking)
================== Search Files: "SearchAll: Avast;McAfee" =============
File:
========
C:\Windows\avastSS.scr
[2016-09-01 14:20][2016-09-01 14:20] 000053208 _____ (AVAST Software) 12EBDA58437CD1EA7066FCB6455241D2 [File is digitally signed]
C:\Windows\WinSxS\Manifests\amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396.cat
[2019-08-10 20:56][2019-08-10 20:56] 000009249 _____ () C0782A6DD461CAC426127F137ED32A6C [File is digitally signed]
C:\Windows\WinSxS\Manifests\amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396.manifest
[2019-08-10 20:56][2019-08-10 20:56] 000002378 ____N () 5EFC81F732DC830BC96C5A3AABCFE543 [File not signed]
C:\Windows\WinSxS\Manifests\amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5e69e83710ea31f5.cat
[2020-02-25 13:06][2020-05-03 19:48] 000007456 _____ () DE67AC8142C10EB12E8AE6C6CDBAF799 [File is digitally signed]
C:\Windows\WinSxS\Manifests\amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5e69e83710ea31f5.manifest
[2020-02-25 13:06][2020-02-25 13:06] 000024123 ____N () 47437B704B6D56328C347347462CD02D [File not signed]
C:\Windows\WinSxS\Manifests\amd64_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_6349ea290dbe6128.cat
[2020-02-25 13:06][2020-05-03 19:48] 000007457 _____ () 2A9DFB92BD6DECA69672261DFB9E044D [File is digitally signed]
C:\Windows\WinSxS\Manifests\amd64_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_6349ea290dbe6128.manifest
[2020-02-25 13:06][2020-02-25 13:06] 000001231 ____N () A77C3C57546E0E66394A1DD29129052B [File not signed]
C:\Windows\WinSxS\Manifests\amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5158632ac9d8192f.cat
[2020-02-25 13:06][2020-05-03 19:48] 000007456 _____ () EAC8D7698558B21A1A533C6A567C06BD [File is digitally signed]
C:\Windows\WinSxS\Manifests\amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5158632ac9d8192f.manifest
[2020-02-25 13:06][2020-02-25 13:06] 000000754 ____N () F6ED6E08D09EBE10597CB2966F6C394E [File not signed]
C:\Windows\WinSxS\Manifests\amd64_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_5638651cc6ac4862.cat
[2020-02-25 13:06][2020-05-03 19:48] 000007457 _____ () 777DD2D0BC92B002B9236B6F4F61CB05 [File is digitally signed]
C:\Windows\WinSxS\Manifests\amd64_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_5638651cc6ac4862.manifest
[2020-02-25 13:06][2020-02-25 13:06] 000000754 ____N () 44D5DDB1B2C027176887E75382F29D55 [File not signed]
C:\Windows\WinSxS\Manifests\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c.cat
[2019-08-10 20:59][2019-08-10 20:59] 000009249 _____ () F181BD5627947025E1254E2F786AE2BE [File is digitally signed]
C:\Windows\WinSxS\Manifests\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c.manifest
[2019-08-10 20:59][2019-08-10 20:59] 000002376 ____N () 176B3BE4AE48CC8A7FACBB8E89A2131E [File not signed]
C:\Windows\WinSxS\Manifests\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_a6171f0e25665afb.cat
[2020-02-25 13:06][2020-05-03 19:48] 000007457 _____ () F7BAEFE116151719499F97B4D7A29BC5 [File is digitally signed]
C:\Windows\WinSxS\Manifests\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_a6171f0e25665afb.manifest
[2020-02-25 13:06][2020-02-25 13:06] 000023610 ____N () FF9B36754303E435AFFABAB5168718B4 [File not signed]
C:\Windows\WinSxS\Manifests\x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_aaf72100223a8a2e.cat
[2020-02-25 13:06][2020-05-03 19:48] 000007457 _____ () B021FBE34930277301DEEC14CDD9E3FE [File is digitally signed]
C:\Windows\WinSxS\Manifests\x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_aaf72100223a8a2e.manifest
[2020-02-25 13:06][2020-02-25 13:06] 000001227 ____N () 955669576F50AF3D88281103865D3A1D [File not signed]
C:\Windows\WinSxS\Manifests\x86_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_b2556b4035446b41.cat
[2019-08-10 21:05][2019-08-10 21:05] 000009249 _____ () 84E52D0B42207B15BC16A36298AE4110 [File is digitally signed]
C:\Windows\WinSxS\Manifests\x86_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_b2556b4035446b41.manifest
[2019-08-10 21:05][2019-08-10 21:05] 000000608 ____N () E479732F7B82161E923B0DF5B5D09C59 [File not signed]
C:\Windows\WinSxS\Manifests\x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_99059a01de544235.cat
[2020-02-25 13:06][2020-05-03 19:48] 000007457 _____ () F8999365A25BB341C55C70CB32DF2D46 [File is digitally signed]
C:\Windows\WinSxS\Manifests\x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_99059a01de544235.manifest
[2020-02-25 13:06][2020-02-25 13:06] 000000750 ____N () 709C8063694781F6371E817243F0EB0F [File not signed]
C:\Windows\WinSxS\Manifests\x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_9de59bf3db287168.cat
[2020-02-25 13:06][2020-05-03 19:48] 000007456 _____ () DFB0071CF316CD33F04392304A02A289 [File is digitally signed]
C:\Windows\WinSxS\Manifests\x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_9de59bf3db287168.manifest
[2020-02-25 13:06][2020-02-25 13:06] 000000750 ____N () 8D1CB478D2A7A6AFAE2C38C6524EDA4B [File not signed]
C:\Windows\System32\Tasks_Migrated\Avast Emergency Update
[2018-06-29 19:08][2019-07-15 22:35] 000004264 _____ () 6EF2F40451AC098BB7FB16BCDD8340E8 [File not signed]
C:\Windows\System32\Tasks_Migrated\Avast Secure Browser Heartbeat Task (Hourly)
[2019-04-17 10:28][2019-06-30 16:37] 000003856 _____ () F8EB50FDD1AA5C9099C4CD80BFA15FD7 [File not signed]
C:\Windows\System32\Tasks_Migrated\Avast Secure Browser Heartbeat Task (Logon)
[2019-04-17 10:28][2019-06-30 16:37] 000003272 _____ () B7F45D11A051E9ED91976F4E32AB6634 [File not signed]
C:\Windows\System32\Tasks_Migrated\AvastUpdateTaskMachineCore
[2018-06-29 19:08][2018-06-29 19:08] 000003162 _____ () 2FFF683C6CB40793C4E48504B1B4DFDA [File not signed]
C:\Windows\System32\Tasks_Migrated\AvastUpdateTaskMachineUA
[2018-06-29 19:08][2018-06-29 19:09] 000003386 _____ () 403158CDE83FC864E48BC347A28D1D53 [File not signed]
C:\Windows\System32\Tasks_Migrated\AVAST Software\Avast settings backup
[2018-06-29 19:08][2018-06-29 19:08] 000002876 _____ () 15477E3DB06E1308B5608538A5FB3984 [File not signed]
C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396.cat
[2020-05-10 22:15][2019-08-10 20:56] 000009249 _____ () C0782A6DD461CAC426127F137ED32A6C [File is digitally signed]
C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396.manifest
[2020-05-10 22:15][2019-08-10 20:56] 000002378 _____ () 5EFC81F732DC830BC96C5A3AABCFE543 [File not signed]
C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5e69e83710ea31f5.cat
[2020-05-10 22:15][2020-05-03 19:48] 000007456 _____ () DE67AC8142C10EB12E8AE6C6CDBAF799 [File is digitally signed]
C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5e69e83710ea31f5.manifest
[2020-05-10 22:15][2020-02-25 13:06] 000024123 _____ () 47437B704B6D56328C347347462CD02D [File not signed]
C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_6349ea290dbe6128.cat
[2020-05-10 22:15][2020-05-03 19:48] 000007457 _____ () 2A9DFB92BD6DECA69672261DFB9E044D [File is digitally signed]
C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_6349ea290dbe6128.manifest
[2020-05-10 22:15][2020-02-25 13:06] 000001231 _____ () A77C3C57546E0E66394A1DD29129052B [File not signed]
C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5158632ac9d8192f.cat
[2020-05-10 22:15][2020-05-03 19:48] 000007456 _____ () EAC8D7698558B21A1A533C6A567C06BD [File is digitally signed]
C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5158632ac9d8192f.manifest
[2020-05-10 22:15][2020-02-25 13:06] 000000754 _____ () F6ED6E08D09EBE10597CB2966F6C394E [File not signed]
C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_5638651cc6ac4862.cat
[2020-05-10 22:15][2020-05-03 19:48] 000007457 _____ () 777DD2D0BC92B002B9236B6F4F61CB05 [File is digitally signed]
C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_5638651cc6ac4862.manifest
[2020-05-10 22:15][2020-02-25 13:06] 000000754 _____ () 44D5DDB1B2C027176887E75382F29D55 [File not signed]
C:\Users\Jim\SkyDrive\Pictures\Documents\avast (2).lnk
[2020-05-10 22:15][2020-05-10 22:08] 000000788 _____ () 7D3F216F471ADB16EED81B8A8A999893 [File not signed]
C:\Users\Jim\SkyDrive\Pictures\Documents\Avast Password Manager.lnk
[2020-05-10 22:15][2018-06-29 16:12] 000002034 _____ () 51F971AF848E4EB111086B9B479599A1 [File not signed]
C:\Users\Jim\SkyDrive\Pictures\Documents\Avast Secure Browser.lnk
[2020-05-10 22:15][2020-02-25 12:08] 000002582 _____ () 5AB573C919309FE7154CC456A117D7D4 [File not signed]
C:\Users\Jim\SkyDrive\Pictures\Documents\avast! Antivirus
[2020-05-10 22:15][2020-05-10 12:49] 000037014 _____ () 3212927E3EDF091342487F5EBB045245 [File not signed]
C:\Users\Jim\SkyDrive\Pictures\Documents\avast-logo-opt-in.png
[2020-05-10 22:15][2020-01-29 16:42] 000001881 _____ () 2DB8A660D58D1A56961310CA1086C8D8 [File not signed]
C:\Users\Jim\SkyDrive\Pictures\Documents\avast.lnk
[2020-05-10 22:15][2020-05-10 21:46] 000000626 _____ () AFF7DFDEA72559A4125D1C05FEEC6C03 [File not signed]
C:\Users\Jim\SkyDrive\Pictures\Documents\avast.search-ms
[2020-05-10 22:15][2020-05-10 22:08] 000001973 _____ () 41925366CE74EBE05AC4DC79141AA3FE [File not signed]
C:\Users\Jim\SkyDrive\Pictures\Documents\Avastbackend.txt
[2020-05-10 22:15][2019-01-09 00:35] 000010380 _____ () 75F729C0EEC2289236AE30E53BA4DC87 [File not signed]
C:\Users\Jim\SkyDrive\Pictures\Documents\avastclear.exe
[2020-05-10 22:15][2020-05-10 12:38] 010936952 _____ (AVAST Software) 18D43CD7663A775F5DE20FC2C64ABAFE [File is digitally signed]
C:\Users\Jim\SkyDrive\Pictures\Documents\avastclear.exe.fhvb1vu.partial
[2020-05-10 22:15][2020-05-10 12:38] 010936952 _____ (AVAST Software) 18D43CD7663A775F5DE20FC2C64ABAFE [File is digitally signed]
C:\Users\Jim\SkyDrive\Pictures\Documents\avastSS.scr
[2020-05-10 22:15][2016-09-01 14:20] 000053208 _____ (AVAST Software) 12EBDA58437CD1EA7066FCB6455241D2 [File is digitally signed]
C:\Users\Jim\SkyDrive\Pictures\Documents\avast_free_antivirus_setup_online.exe
[2020-05-10 22:15][2020-05-03 14:40] 000230080 _____ (AVAST Software) F6C3AE9D57FA30F04321FDD3CE814479 [File is digitally signed]
C:\Users\Jim\SkyDrive\Pictures\Documents\avast_pam
[2020-05-10 22:15][2020-05-10 17:11] 000037014 _____ () 949DD0F5804127D1C34BA36F7DE7FE92 [File not signed]
C:\Users\Jim\SkyDrive\Pictures\Documents\license.avastlic.lnk
[2020-05-10 22:15][2020-05-10 21:37] 000002550 _____ () F8DC0E8125560EE650D31D39D98B61C2 [File not signed]
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c.cat
[2020-05-10 22:15][2019-08-10 20:59] 000009249 _____ () F181BD5627947025E1254E2F786AE2BE [File is digitally signed]
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c.manifest
[2020-05-10 22:15][2019-08-10 20:59] 000002376 _____ () 176B3BE4AE48CC8A7FACBB8E89A2131E [File not signed]
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_a6171f0e25665afb.cat
[2020-05-10 22:15][2020-05-03 19:48] 000007457 _____ () F7BAEFE116151719499F97B4D7A29BC5 [File is digitally signed]
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_a6171f0e25665afb.manifest
[2020-05-10 22:15][2020-02-25 13:06] 000023610 _____ () FF9B36754303E435AFFABAB5168718B4 [File not signed]
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_aaf72100223a8a2e.cat
[2020-05-10 22:15][2020-05-03 19:48] 000007457 _____ () B021FBE34930277301DEEC14CDD9E3FE [File is digitally signed]
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_aaf72100223a8a2e.manifest
[2020-05-10 22:15][2020-02-25 13:06] 000001227 _____ () 955669576F50AF3D88281103865D3A1D [File not signed]
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_b2556b4035446b41.cat
[2020-05-10 22:15][2019-08-10 21:05] 000009249 _____ () 84E52D0B42207B15BC16A36298AE4110 [File is digitally signed]
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_b2556b4035446b41.manifest
[2020-05-10 22:15][2019-08-10 21:05] 000000608 _____ () E479732F7B82161E923B0DF5B5D09C59 [File not signed]
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_99059a01de544235.cat
[2020-05-10 22:15][2020-05-03 19:48] 000007457 _____ () F8999365A25BB341C55C70CB32DF2D46 [File is digitally signed]
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_99059a01de544235.manifest
[2020-05-10 22:15][2020-02-25 13:06] 000000750 _____ () 709C8063694781F6371E817243F0EB0F [File not signed]
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_9de59bf3db287168.cat
[2020-05-10 22:15][2020-05-03 19:48] 000007456 _____ () DFB0071CF316CD33F04392304A02A289 [File is digitally signed]
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_9de59bf3db287168.manifest
[2020-05-10 22:15][2020-02-25 13:06] 000000750 _____ () 8D1CB478D2A7A6AFAE2C38C6524EDA4B [File not signed]
C:\Users\Jim\SkyDrive\Pictures\Documents\AVAST Software\Avastbackend.txt
[2020-05-10 22:15][2019-01-09 00:35] 000010380 _____ () 75F729C0EEC2289236AE30E53BA4DC87 [File not signed]
C:\Users\Jim\Searches\avast.search-ms
[2020-05-10 22:08][2020-05-10 22:08] 000001973 _____ () 41925366CE74EBE05AC4DC79141AA3FE [File not signed]
C:\Users\Jim\Links\avast (2).lnk
[2020-05-10 22:08][2020-05-10 22:08] 000000788 _____ () 7D3F216F471ADB16EED81B8A8A999893 [File not signed]
C:\Users\Jim\Links\avast.lnk
[2020-05-10 21:46][2020-05-10 21:46] 000000626 _____ () AFF7DFDEA72559A4125D1C05FEEC6C03 [File not signed]
C:\Users\Jim\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Avast Secure Browser.lnk
[2018-05-23 12:05][2020-02-25 12:08] 000002582 _____ () 5AB573C919309FE7154CC456A117D7D4 [File not signed]
C:\ProgramData\Microsoft\Windows\AppRepository\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_4.5.141.1_x64__bq6yxensn79aw.xml
[2015-05-29 00:27][2015-05-29 00:27] 000008032 _____ () D76C146DBF1E8E4ADF7FB5B22727ED16 [File not signed]
C:\ProgramData\Microsoft\Windows\AppRepository\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw.xml
[2018-04-03 15:16][2018-04-03 15:16] 000008032 _____ () BF661174EED69E970DA62F02EDC0E2AA [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\McAfeeIPTHostRTComponent.winmd
[2014-08-28 07:25][2014-08-28 07:25] 000015360 _____ (Daon) 2382858BA1B9ED6CC99284578785522E [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\Partner\images\logo_mcafee.png
[2018-04-03 15:17][2018-04-03 15:17] 000007087 _____ () E4CF58C09E2422CCD9B655ABA854E14B [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\Partner\images\logo_mcafee_login_snapview.png
[2018-04-03 15:17][2018-04-03 15:17] 000005092 _____ () 2367BA6D826456748AF4139327B3854F [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\Partner\images\logo_mcafee_snapview.png
[2018-04-03 15:17][2018-04-03 15:17] 000003937 _____ () EAF52B6227EEE200D8B54B48CC7B7EAF [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\Partner\images\rtl_logo_mcafee.png
[2018-04-03 15:17][2018-04-03 15:17] 000007058 _____ () DD1BBC243734FD2141E01C92108E6850 [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\Partner\images\rtl_logo_mcafee_snapview.png
[2018-04-03 15:17][2018-04-03 15:17] 000003941 _____ () 41D6D1EBD4760E17ED4806A65EBDFC8A [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\js\account.mcafee.js
[2013-10-20 22:13][2013-10-20 22:13] 000001155 _____ () A31CF8096C24315C93C192060272C9A4 [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\js\cache.mcafee.js
[2014-12-10 20:15][2014-12-10 20:15] 000003411 _____ () A1E407E2B0C03F7C802FBDEE6D33C979 [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\js\events.mcafee.js
[2013-10-20 22:13][2013-10-20 22:13] 000002661 _____ () F32DF3BC5BDBBEFABE6FEC77F140828B [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\js\logger.mcafee.js
[2014-12-10 20:15][2014-12-10 20:15] 000010177 _____ () B2E0E2F180B9006D9966135D3A1E05A8 [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\js\resources.mcafee.js
[2014-02-05 20:25][2014-02-05 20:26] 000001127 _____ () 5026813FA1B6C9866956D5F6FDE9C771 [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\js\settings.mcafee.js
[2014-12-10 20:15][2014-12-10 20:15] 000006905 _____ () F0F66E474E0218BFC8B31703EA262AA9 [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\js\telemetry.mcafee.js
[2014-12-10 20:15][2014-12-10 20:15] 000014650 _____ () 93AD4C1C8770158776FA8890A409ED39 [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\js\thirdparty.mcafee.js
[2014-08-28 07:25][2014-08-28 07:25] 000000165 _____ () F04A2EB850AA3E2A5ADFE04C812E970A [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\js\webview.mcafee.js
[2014-12-10 20:15][2014-12-10 20:15] 000012686 _____ () EF4EC375A649578BB1CB86D602E01E61 [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\logo_filledview_mcafee.png
[2018-04-03 15:17][2018-04-03 15:17] 000005564 _____ () 9E12E5CE26C5653C05C7CCB3660EB63C [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\logo_mcafee.png
[2013-10-20 22:13][2013-10-20 22:13] 000003058 _____ () 30E2C595B73F65E133F1E88C7219A873 [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\zh-cn\McAfeeLargeLogo.scale-100.png
[2015-12-08 17:02][2015-12-08 17:02] 000030660 _____ () 75F6E001294D409CE9D4DB3B129C630A [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\zh-cn\McAfeeLargeLogo.scale-140.png
[2015-12-08 17:02][2015-12-08 17:02] 000043175 _____ () B28B8704AFFF713A54DB048BDC3877DF [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\zh-cn\McAfeeLargeLogo.scale-180.png
[2015-12-08 17:02][2015-12-08 17:02] 000055794 _____ () AB6475A30CDA6A44AFFB5E807354B950 [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\zh-cn\McAfeeLargeLogo.scale-80.png
[2015-12-08 17:02][2015-12-08 17:02] 000025288 _____ () 8F0986B39F0A13405CFF327EE053955A [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\zh-cn\McafeeSquareLogo.scale-100.png
[2013-10-20 22:13][2013-10-20 22:13] 000005601 _____ () 4B6FC6A5B813D345D1029950B78189C8 [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\zh-cn\McafeeSquareLogo.scale-140.png
[2013-10-20 22:13][2013-10-20 22:13] 000007510 _____ () FAD52590BB303074920675747538AB74 [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\zh-cn\McafeeSquareLogo.scale-180.png
[2013-10-20 22:13][2013-10-20 22:13] 000009598 _____ () 725B32424ED3CB08310AC7E9D3B86525 [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\zh-cn\McafeeSquareLogo.scale-80.png
[2013-10-20 22:13][2013-10-20 22:13] 000004859 _____ () 68E0CC79368D2729564CFEFD842FD24C [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\zh-cn\McAfeeWideLogo.scale-100.png
[2013-10-20 22:13][2013-10-20 22:13] 000005285 _____ () CF90A5189891D363DD83F7307C077B46 [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\zh-cn\McAfeeWideLogo.scale-140.png
[2013-10-20 22:13][2013-10-20 22:13] 000006606 _____ () E97C9E500BE8D33272DA83A96E5E8A63 [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\zh-cn\McAfeeWideLogo.scale-180.png
[2013-10-20 22:13][2013-10-20 22:13] 000008556 _____ () 7DCB5CF4D8830B9846EB45D82197A873 [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\zh-cn\McAfeeWideLogo.scale-80.png
[2013-10-20 22:13][2013-10-20 22:13] 000004422 _____ () A65CFEDE94BCB86BAE9F15B76FB6DFCD [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\win_store\Logo_splash_mcafee.scale-100.png
[2013-10-20 22:13][2013-10-20 22:13] 000005622 _____ () EBDD27803F3B74D3B73344526E5D662D [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\win_store\Logo_splash_mcafee.scale-140.png
[2013-10-20 22:13][2013-10-20 22:13] 000007497 _____ () 06EB1716E664C21B4CC10E3F388D8CB8 [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\win_store\Logo_splash_mcafee.scale-180.png
[2013-10-20 22:13][2013-10-20 22:13] 000010499 _____ () B4A2E9CD9D3E8FA9E52F2487826279EE [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\win_store\McafeeSmallLogo.scale-100.png
[2014-12-10 20:15][2014-12-10 20:15] 000003725 _____ () 139ED50BDE20C4FF4B9CED83CD347C6E [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\win_store\McafeeSmallLogo.targetsize-16.png
[2013-10-20 22:13][2013-10-20 22:13] 000001403 _____ () B5ACD4CA21411AEBDB3B4D999EFEFB71 [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\win_store\McafeeSmallLogo.targetsize-256.png
[2014-12-10 20:15][2014-12-10 20:15] 000005972 _____ () 12EE875FE7310067E1B14948E5B5C54A [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\win_store\McafeeSmallLogo.targetsize-32.png
[2014-12-10 20:15][2014-12-10 20:15] 000001037 _____ () 2BBACEF9809555973934F0023C7BDD73 [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\win_store\McafeeSmallLogo.targetsize-48.png
[2014-12-10 20:15][2014-12-10 20:15] 000001465 _____ () 8406FC0E1D7DA7DD51FB791C8AF3AD02 [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\win_store\McafeeStoreLogo.scale-100.png
[2014-12-10 20:15][2014-12-10 20:15] 000002377 _____ () 5D76524B6A1FDF0CAF6A643FA2A18FDF [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\win_store\McafeeStoreLogo.scale-140.png
[2014-12-10 20:15][2014-12-10 20:15] 000003625 _____ () 7D9985E22CD815821F654EE06110CAEE [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\win_store\McafeeStoreLogo.scale-180.png
[2014-12-10 20:15][2014-12-10 20:15] 000002560 _____ () 468D56989AEA3AD695D8D591CCD54875 [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\ko\McAfeeLargeLogo.scale-100.png
[2015-12-08 17:02][2015-12-08 17:02] 000029514 _____ () 7804977FCFB952A294996351B7811F18 [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\ko\McAfeeLargeLogo.scale-140.png
[2015-12-08 17:02][2015-12-08 17:02] 000042279 _____ () D88A02B80AB222EAE4626BDF745DBF37 [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\ko\McAfeeLargeLogo.scale-180.png
[2015-12-08 17:02][2015-12-08 17:02] 000055033 _____ () 8283204E208C89FA34DF26D08C2999C3 [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\ko\McAfeeLargeLogo.scale-80.png
[2015-12-08 17:02][2015-12-08 17:02] 000024886 _____ () FE88042B4939BBD782306FF8ED8227F2 [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\ko\McafeeSquareLogo.scale-100.png
[2013-10-20 22:13][2013-10-20 22:13] 000005420 _____ () 8FD27A5D29A916D6F6EA4A3507C51C0A [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\ko\McafeeSquareLogo.scale-140.png
[2013-10-20 22:13][2013-10-20 22:13] 000007424 _____ () 2D789B1668E2E96750760E17393AF48B [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\ko\McafeeSquareLogo.scale-180.png
[2013-10-20 22:13][2013-10-20 22:13] 000009496 _____ () 946B56461299BE3F409466F5234A7CA5 [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\ko\McafeeSquareLogo.scale-80.png
[2013-10-20 22:13][2013-10-20 22:13] 000004796 _____ () C2F26B15FF773028E232A1F54F5485F0 [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\ko\McAfeeWideLogo.scale-100.png
[2013-10-20 22:13][2013-10-20 22:13] 000005095 _____ () FB6525F58924E291BC3DB2D52120492B [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\ko\McAfeeWideLogo.scale-140.png
[2013-10-20 22:13][2013-10-20 22:13] 000006601 _____ () 5D9B6FDA7C53D3008BF9DF3FFD954C3C [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\ko\McAfeeWideLogo.scale-180.png
[2013-10-20 22:13][2013-10-20 22:13] 000008472 _____ () 1DAF873295FAC129BCB86057F6A84258 [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\ko\McAfeeWideLogo.scale-80.png
[2013-10-20 22:13][2013-10-20 22:13] 000004356 _____ () CCDA82EC0AE32C9CCA41E563ECCB904D [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\ja\McAfeeLargeLogo.scale-100.png
[2015-12-08 17:02][2015-12-08 17:02] 000029889 _____ () 8D43518C51C0EB61D7541D10ADC44BC0 [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\ja\McAfeeLargeLogo.scale-140.png
[2015-12-08 17:02][2015-12-08 17:02] 000042115 _____ () FA59EA2AF5A8ED632FE435A01ED15A85 [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\ja\McAfeeLargeLogo.scale-180.png
[2015-12-08 17:02][2015-12-08 17:02] 000055397 _____ () 63F5AE4FA2BD8050910880818F3AB519 [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\ja\McAfeeLargeLogo.scale-80.png
[2015-12-08 17:02][2015-12-08 17:02] 000024823 _____ () BCFD1F184540950CF5F5D22D80B23290 [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\ja\McafeeSquareLogo.scale-100.png
[2013-10-20 22:13][2013-10-20 22:13] 000005615 _____ () 7ABC53BE19C6CECAD8ACD030801D7CCC [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\ja\McafeeSquareLogo.scale-140.png
[2013-10-20 22:13][2013-10-20 22:13] 000007600 _____ () 599A913EDE6A1B57653F7FE5333EB450 [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\ja\McafeeSquareLogo.scale-180.png
[2013-10-20 22:13][2013-10-20 22:13] 000009771 _____ () 59833802843A4713BB07FBC19D40EFBB [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\ja\McafeeSquareLogo.scale-80.png
[2013-10-20 22:13][2013-10-20 22:13] 000004874 _____ () B765CC6495B0B6D002A7E4A2776B2DE9 [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\ja\McAfeeWideLogo.scale-100.png
[2013-10-20 22:13][2013-10-20 22:13] 000005389 _____ () 5AF7DDFB2FD9EBF6840C8A02BDF31588 [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\ja\McAfeeWideLogo.scale-140.png
[2013-10-20 22:13][2013-10-20 22:13] 000006985 _____ () 77F2F3E89A0445E724FB50CF5B0B6B58 [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\ja\McAfeeWideLogo.scale-180.png
[2013-10-20 22:13][2013-10-20 22:13] 000009133 _____ () 26820A81FD4D69C5A54FA1D91B172C3F [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\ja\McAfeeWideLogo.scale-80.png
[2013-10-20 22:13][2013-10-20 22:13] 000004483 _____ () CE6D876D309FD34484EA81A514C15B2A [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\en-us\McAfeeLargeLogo.scale-100.png
[2014-12-10 20:15][2014-12-10 20:15] 000006846 _____ () 36510451A058A137D91C7307E8CD5BE0 [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\en-us\McAfeeLargeLogo.scale-140.png
[2014-12-10 20:15][2014-12-10 20:15] 000010433 _____ () F23D471857EB25AE9B18BF5F0BC3EC4D [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\en-us\McAfeeLargeLogo.scale-180.png
[2014-12-10 20:15][2014-12-10 20:15] 000013768 _____ () 78790D3B7D52A19F1018AED8585CDDF8 [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\en-us\McAfeeLargeLogo.scale-80.png
[2014-12-10 20:15][2014-12-10 20:15] 000005816 _____ () FA0B0B49690E3CC1EF8ADED1C48471FF [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\en-us\McAfeeSmallLogo.scale-100.png
[2014-12-10 20:15][2014-12-10 20:15] 000003666 _____ () 12E87C318DF255F9A20C903A1F1E5BCC [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\en-us\McAfeeSmallLogo.scale-140.png
[2014-12-10 20:15][2014-12-10 20:15] 000001955 _____ () 576F094E90E295D0B0719765B4E4DE8F [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\en-us\McAfeeSmallLogo.scale-180.png
[2014-12-10 20:15][2014-12-10 20:15] 000002194 _____ () F082A6B11E13CBC5A647DC1A2C392432 [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\en-us\McAfeeSmallLogo.scale-80.png
[2014-12-10 20:15][2014-12-10 20:15] 000002701 _____ () 56FCF4D6D401CC549E0E90648639B83E [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\en-us\McafeeSquareLogo.scale-100.png
[2013-10-20 22:13][2013-10-20 22:13] 000005820 _____ () 47221A4C8ECFF65677095832AACFFA57 [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\en-us\McafeeSquareLogo.scale-140.png
[2013-10-20 22:13][2013-10-20 22:13] 000007620 _____ () B53C03470111014C6B2D2904F43750FA [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\en-us\McafeeSquareLogo.scale-180.png
[2013-10-20 22:13][2013-10-20 22:13] 000009980 _____ () 07215F67629113602EF01949D87992A5 [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\en-us\McafeeSquareLogo.scale-80.png
[2013-10-20 22:13][2013-10-20 22:13] 000004669 _____ () 291846D6B91FC9CA1614C414553E87F8 [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\en-us\McAfeeWideLogo.scale-100.png
[2013-10-20 22:13][2013-10-20 22:13] 000005172 _____ () 2A170127B6E0A75B82325FE4902041E6 [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\en-us\McAfeeWideLogo.scale-140.png
[2013-10-20 22:13][2013-10-20 22:13] 000006948 _____ () EAB8C63656F9D2A0CA3353D9CC18A246 [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\en-us\McAfeeWideLogo.scale-180.png
[2013-10-20 22:13][2013-10-20 22:13] 000008776 _____ () 3C3E372F01B04F017494929EB0A8859B [File not signed]
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\en-us\McAfeeWideLogo.scale-80.png
[2013-10-20 22:13][2013-10-20 22:13] 000004344 _____ () EDA095879CD1146E2ACFF6DBA2D3B373 [File not signed]
C:\FRST\Quarantine\C\WINDOWS\System32\Tasks\AVAST Software\Avast settings backup.xBAD
[2019-08-10 19:54][2019-08-10 19:54] 000002876 _____ () 15477E3DB06E1308B5608538A5FB3984 [File not signed]
C:\FRST\Quarantine\C\Users\Jim\Downloads\avast_free_antivirus_setup_online.exe.xBAD
[2020-05-03 14:40][2020-05-03 14:40] 000230080 _____ (AVAST Software) F6C3AE9D57FA30F04321FDD3CE814479 [File is digitally signed]

folder:
========
2014-11-15 18:56 - 2014-11-15 18:56 _____ C:\AVAST Software
2019-08-10 20:56 - 2019-08-10 20:56 _____ C:\Windows\WinSxS\amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396
2020-02-25 13:06 - 2020-02-25 13:06 _____ C:\Windows\WinSxS\amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5e69e83710ea31f5
2020-02-25 13:06 - 2020-02-25 13:06 _____ C:\Windows\WinSxS\amd64_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_6349ea290dbe6128
2019-08-10 20:59 - 2019-08-10 20:59 _____ C:\Windows\WinSxS\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c
2020-02-25 13:06 - 2020-02-25 13:06 _____ C:\Windows\WinSxS\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_a6171f0e25665afb
2020-02-25 13:06 - 2020-02-25 13:06 _____ C:\Windows\WinSxS\x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_aaf72100223a8a2e
2018-06-29 19:08 - 2019-08-10 17:12 _____ C:\Windows\System32\Tasks_Migrated\AVAST Software
2019-08-10 19:54 - 2020-05-21 13:39 _____ C:\Windows\System32\Tasks\AVAST Software
2020-05-10 22:15 - 2020-05-10 22:15 _____ C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396
2020-05-10 22:15 - 2020-05-10 22:15 _____ C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5e69e83710ea31f5
2020-05-10 22:15 - 2020-05-10 22:15 _____ C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_6349ea290dbe6128
2020-05-10 22:15 - 2020-05-10 22:15 _____ C:\Users\Jim\SkyDrive\Pictures\Documents\Avast
2020-05-10 22:15 - 2020-05-10 22:15 _____ C:\Users\Jim\SkyDrive\Pictures\Documents\AVAST Software
2020-05-10 22:15 - 2020-05-10 22:15 _____ C:\Users\Jim\SkyDrive\Pictures\Documents\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c
2020-05-10 22:15 - 2020-05-10 22:15 _____ C:\Users\Jim\SkyDrive\Pictures\Documents\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_a6171f0e25665afb
2020-05-10 22:15 - 2020-05-10 22:15 _____ C:\Users\Jim\SkyDrive\Pictures\Documents\x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_aaf72100223a8a2e
2020-05-10 22:15 - 2020-05-05 17:01 _____ C:\Users\Jim\SkyDrive\Pictures\Documents\_avast_
2020-05-10 22:15 - 2020-05-10 22:15 _____ C:\Users\Jim\SkyDrive\Pictures\Documents\AVAST Software\Avast
2020-05-14 13:39 - 2020-05-14 13:40 _____ C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Browser Cleanup
2020-05-14 13:41 - 2020-05-14 13:41 _____ C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Browser Cleanup(1)
2020-05-14 13:53 - 2020-05-14 13:53 _____ C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Browser Cleanup(2)
2020-05-14 13:06 - 2020-05-14 13:06 _____ C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Free Antivirus
2020-05-14 13:57 - 2020-05-14 13:57 _____ C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Free Antivirus(1)
2020-05-14 13:58 - 2020-05-14 13:58 _____ C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Free Antivirus(2)
2020-05-14 13:59 - 2020-05-14 13:59 _____ C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Free Antivirus(3)
2020-05-14 13:59 - 2020-05-14 13:59 _____ C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Free Antivirus(4)
2020-05-14 13:41 - 2020-05-14 13:41 _____ C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Pro Antivirus
2020-05-14 14:00 - 2020-05-14 14:00 _____ C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Pro Antivirus(1)
2020-05-14 13:37 - 2020-05-14 13:37 _____ C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee LiveSafe
2020-05-14 14:01 - 2020-05-14 14:01 _____ C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee LiveSafe(1)
2020-05-14 14:02 - 2020-05-14 14:02 _____ C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee LiveSafe(2)
2020-05-14 14:03 - 2020-05-14 14:03 _____ C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee LiveSafe(3)
2020-05-14 14:04 - 2020-05-14 14:04 _____ C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee LiveSafe(4)
2020-05-14 14:05 - 2020-05-14 14:05 _____ C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee LiveSafe(5)
2020-05-14 13:36 - 2020-05-14 13:36 _____ C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee Security Scan Plus
2020-05-14 14:06 - 2020-05-14 14:06 _____ C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee Security Scan Plus(1)
2020-05-14 13:38 - 2020-05-14 13:38 _____ C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee WebAdvisor
2020-05-14 14:06 - 2020-05-14 14:06 _____ C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee WebAdvisor(1)
2020-05-14 13:42 - 2020-05-14 13:42 _____ C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\Avast-14052020-134203
2020-05-14 13:42 - 2020-05-14 13:42 _____ C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\Avast-14052020-134250
2020-05-14 13:47 - 2020-05-14 13:47 _____ C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\Avast-14052020-134720
2020-05-14 13:57 - 2020-05-14 13:57 _____ C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\Avast-14052020-135743
2020-05-14 13:57 - 2020-05-14 13:57 _____ C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\Avast-14052020-135752
2020-05-20 15:14 - 2020-05-20 15:14 _____ C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\Avast-20052020-151429
2020-05-20 15:44 - 2020-05-20 15:44 _____ C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\Avast-20052020-154404
2020-05-23 18:25 - 2020-05-23 18:25 _____ C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\Avast-23052020-182559
2020-05-14 13:39 - 2020-05-14 13:39 _____ C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\McAfee-14052020-133905
2020-05-14 14:01 - 2020-05-14 14:01 _____ C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\McAfee-14052020-140130
2020-05-14 14:01 - 2020-05-14 14:01 _____ C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\McAfee-14052020-140151
2020-05-14 14:02 - 2020-05-14 14:02 _____ C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\McAfee-14052020-140240
2020-05-14 14:02 - 2020-05-14 14:02 _____ C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\McAfee-14052020-140248
2020-05-14 14:03 - 2020-05-14 14:03 _____ C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\McAfee-14052020-140332
2020-05-14 14:03 - 2020-05-14 14:03 _____ C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\McAfee-14052020-140342
2020-05-14 14:04 - 2020-05-14 14:04 _____ C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\McAfee-14052020-140435
2020-05-14 14:05 - 2020-05-14 14:05 _____ C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\McAfee-14052020-140529
2018-04-03 15:16 - 2018-04-03 15:17 _____ C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw
2020-05-21 13:39 - 2020-05-21 13:39 _____ C:\FRST\Quarantine\C\WINDOWS\System32\Tasks\AVAST Software
2014-11-15 18:56 - 2014-11-15 18:56 _____ C:\AVAST Software\Avast
Registry:
========
===================== Search result for "Avast" ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\AvastGUIProxy.DLL]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{5020EF2C-60F4-47BE-8918-A167229B11EE}]
""="AvastGUIProxy"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\Av\{8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}]
"DISPLAYNAME"="Avast Antivirus"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\Av\{8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}]
"PRODUCTEXE"="C:\Program Files\AVAST Software\Avast\wsc_proxy.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\Av\{8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}]
"REPORTINGEXE"="C:\Program Files\AVAST Software\Avast\wsc_proxy.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\Av\{EB19B86E-3998-C706-90EF-92B41EB091AF}]
"DISPLAYNAME"="Avast Antivirus"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\Av\{EB19B86E-3998-C706-90EF-92B41EB091AF}]
"PRODUCTEXE"="C:\Program Files\AVAST Software\Avast\wsc_proxy.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\Av\{EB19B86E-3998-C706-90EF-92B41EB091AF}]
"REPORTINGEXE"="C:\Program Files\AVAST Software\Avast\wsc_proxy.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\avast! Mail Scanner Cache]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\avast! Mail Scanner Trusted]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\avast! SSL Scanner Cache]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]
"AvastUI.exe"="0x020000000000000000000000"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32]
"AvastUI.exe"="0x020000000000000000000000"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396"="0x41766173742E56433131302E4352542C2043756C747572653D6E65757472616C2C20547970653D77696E33322C2056657273696F6E3D31312E302E36303631302E312C205075626C69634B6579546F6B656E3D323033366231346131316538336534612C2050726F636573736F724172636869746563747572653D616D643634"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_5ca6eb17137337f1"="0x41766173742E56433134302E4352542C2043756C747572653D6E65757472616C2C20547970653D77696E33322C2056657273696F6E3D31342E302E32373031322E302C205075626C69634B6579546F6B656E3D666363393965653631393365626263612C2050726F636573736F724172636869746563747572653D616D643634"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_4f95660acc611f2b"="0x506F6C6963792E31342E302E41766173742E56433134302E4352542C2043756C747572653D6E65757472616C2C20547970653D77696E33322D706F6C6963792C2056657273696F6E3D31342E302E32373031322E302C205075626C69634B6579546F6B656E3D666363393965653631393365626263612C2050726F636573736F724172636869746563747572653D616D643634"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"amd64_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_547567fcc9354e5e"="0x506F6C6963792E31342E302E41766173742E56433134302E4D46432C2043756C747572653D6E65757472616C2C20547970653D77696E33322D706F6C6963792C2056657273696F6E3D31342E302E32373031322E302C205075626C69634B6579546F6B656E3D666363393965653631393365626263612C2050726F636573736F724172636869746563747572653D616D643634"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"amd64_avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_6186ed0910476724"="0x41766173742E56433134302E4D46432C2043756C747572653D6E65757472616C2C20547970653D77696E33322C2056657273696F6E3D31342E302E32373031322E302C205075626C69634B6579546F6B656E3D666363393965653631393365626263612C2050726F636573736F724172636869746563747572653D616D643634"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c"="0x41766173742E56433131302E4352542C2043756C747572653D6E65757472616C2C20547970653D77696E33322C2056657273696F6E3D31312E302E36303631302E312C205075626C69634B6579546F6B656E3D323033366231346131316538336534612C2050726F636573736F724172636869746563747572653D783836"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_a45421ee27ef60f7"="0x41766173742E56433134302E4352542C2043756C747572653D6E65757472616C2C20547970653D77696E33322C2056657273696F6E3D31342E302E32373031322E302C205075626C69634B6579546F6B656E3D666363393965653631393365626263612C2050726F636573736F724172636869746563747572653D783836"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_a93423e024c3902a"="0x41766173742E56433134302E4D46432C2043756C747572653D6E65757472616C2C20547970653D77696E33322C2056657273696F6E3D31342E302E32373031322E302C205075626C69634B6579546F6B656E3D666363393965653631393365626263612C2050726F636573736F724172636869746563747572653D783836"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_b2556b4035446b41"="0x706F6C6963792E31312E302E41766173742E56433131302E4352542C2043756C747572653D6E65757472616C2C20547970653D77696E33322D706F6C6963792C2056657273696F6E3D31312E302E36303631302E312C205075626C69634B6579546F6B656E3D323033366231346131316538336534612C2050726F636573736F724172636869746563747572653D783836"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_97429ce1e0dd4831"="0x506F6C6963792E31342E302E41766173742E56433134302E4352542C2043756C747572653D6E65757472616C2C20547970653D77696E33322D706F6C6963792C2056657273696F6E3D31342E302E32373031322E302C205075626C69634B6579546F6B656E3D666363393965653631393365626263612C2050726F636573736F724172636869746563747572653D783836"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_9c229ed3ddb17764"="0x506F6C6963792E31342E302E41766173742E56433134302E4D46432C2043756C747572653D6E65757472616C2C20547970653D77696E33322D706F6C6963792C2056657273696F6E3D31342E302E32373031322E302C205075626C69634B6579546F6B656E3D666363393965653631393365626263612C2050726F636573736F724172636869746563747572653D783836"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_a6171f0e25665afb"="0x41766173742E56433134302E4352542C2043756C747572653D6E65757472616C2C20547970653D77696E33322C2056657273696F6E3D31342E302E32383132372E302C205075626C69634B6579546F6B656E3D666363393965653631393365626263612C2050726F636573736F724172636869746563747572653D783836"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5e69e83710ea31f5"="0x41766173742E56433134302E4352542C2043756C747572653D6E65757472616C2C20547970653D77696E33322C2056657273696F6E3D31342E302E32383132372E302C205075626C69634B6579546F6B656E3D666363393965653631393365626263612C2050726F636573736F724172636869746563747572653D616D643634"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_aaf72100223a8a2e"="0x41766173742E56433134302E4D46432C2043756C747572653D6E65757472616C2C20547970653D77696E33322C2056657273696F6E3D31342E302E32383132372E302C205075626C69634B6579546F6B656E3D666363393965653631393365626263612C2050726F636573736F724172636869746563747572653D783836"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"amd64_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_6349ea290dbe6128"="0x41766173742E56433134302E4D46432C2043756C747572653D6E65757472616C2C20547970653D77696E33322C2056657273696F6E3D31342E302E32383132372E302C205075626C69634B6579546F6B656E3D666363393965653631393365626263612C2050726F636573736F724172636869746563747572653D616D643634"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_99059a01de544235"="0x506F6C6963792E31342E302E41766173742E56433134302E4352542C2043756C747572653D6E65757472616C2C20547970653D77696E33322D706F6C6963792C2056657273696F6E3D31342E302E32383132372E302C205075626C69634B6579546F6B656E3D666363393965653631393365626263612C2050726F636573736F724172636869746563747572653D783836"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5158632ac9d8192f"="0x506F6C6963792E31342E302E41766173742E56433134302E4352542C2043756C747572653D6E65757472616C2C20547970653D77696E33322D706F6C6963792C2056657273696F6E3D31342E302E32383132372E302C205075626C69634B6579546F6B656E3D666363393965653631393365626263612C2050726F636573736F724172636869746563747572653D616D643634"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_9de59bf3db287168"="0x506F6C6963792E31342E302E41766173742E56433134302E4D46432C2043756C747572653D6E65757472616C2C20547970653D77696E33322D706F6C6963792C2056657273696F6E3D31342E302E32383132372E302C205075626C69634B6579546F6B656E3D666363393965653631393365626263612C2050726F636573736F724172636869746563747572653D783836"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"amd64_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_5638651cc6ac4862"="0x506F6C6963792E31342E302E41766173742E56433134302E4D46432C2043756C747572653D6E65757472616C2C20547970653D77696E33322D706F6C6963792C2056657273696F6E3D31342E302E32383132372E302C205075626C69634B6579546F6B656E3D666363393965653631393365626263612C2050726F636573736F724172636869746563747572653D616D643634"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_avast.vc110.crt_2036b14a11e83e4a_none_c373722873c01144]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_avast.vc140.crt_fcc99ee6193ebbca_none_020285fe6d6e0580]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_avast.vc140.mfc_fcc99ee6193ebbca_none_018be6966dc83925]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_none_ef17e13d91c55d96]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_none_eea141d5921f913b]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_avast.vc110.crt_2036b14a11e83e4a_none_0b20a8ff883c3a4a]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_avast.vc140.crt_fcc99ee6193ebbca_none_49afbcd581ea2e86]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_avast.vc140.mfc_fcc99ee6193ebbca_none_49391d6d8244622b]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_none_5679bb9c25dbf18d]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_none_36c51814a641869c]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_none_364e78aca69bba41]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvastBrowserUpdate.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsSelfHost\OneSettings]
"TargetingAttributes"="{
  "Version": 93,
  "SchemaVersion": 1,
  "PartA": [
    "App",
    "AppVer",
    "AttrDataVer"
  ],
  "Default": [
    "DeviceFamily",
    "f:FlightRing",
    "t:OSVersionFull"
  ],
  "PartB": {
    "ACSOVERRIDE": [
      "OSArchitecture",
      "c:IsAlwaysOnAlwaysConnectedCapable"
    ],
    "CDM": [
      "ChassisTypeId",
      "r:CurrentBranch",
      "DeviceFamily",
      "f:FlightingBranchName",
      "f:FlightRing",
      "c:InstallLanguage",
      "c:IsDomainJoined",
      "t:IsTestLab",
      "OEMModel",
      "OSArchitecture",
      "OSVersion",
      "t:OSSkuId",
      "c:ProcessorIdentifier",
      "c:TelemetryLevel",
      "t:IsMsftOwned",
      "t:WCOSProductId",
      "c:OSUILocale",
      "c:CommercialId",
      "s:MinShellVersion",
      "s:MaxShellVersion",
      "c:ActivationChannel",
      "c:SCCMClientId",
      "c:IsCloudDomainJoined"
    ],
    "COMPATLOGGER": [
      "osVer",
      "ring",
      "deviceId"
    ],
    "CORTANA_GATEKEEPER": [
      "r:CurrentBranch",
      "f:FlightRing",
      "f:IsRetailOS"
    ],
    "CORTANAUWP": [
      "c:OSUILocale",
      "t:OSVersionFull",
      "v:CortanaAppVer"
    ],
    "CORTANAUWPTEST": [
      "+CORTANAUWP",
      "v:CortanaAppVerTest"
    ],
    "CTAC": [
      "+FSS"
    ],
    "DDC": [
      "+WU_STORE",
      "+_WU_PTI"
    ],
    "DXDB": [
      "DeviceFamily",
      "f:FlightRing",
      "r:IsHybridOrXGpu",
      "t:OSVersionFull"
    ],
    "EDGE_SERVICEUI": [
      "t:LocalDeviceID",
      "t:LocalUserID"
    ],
    "FCON": [
      "+CDM"
    ],
    "FSS": [
      "r:PreviewBuildsManagerEnabled",
      "f:BranchReadinessLevelRaw",
      "u:BranchReadinessLevelSource",
      "r:BuildFID",
      "t:DeviceFamily",
      "DeviceId",
      "c:EnablePreviewBuilds",
      "f:FlightingPolicyValue",
      "f:IsRetailOS",
      "f:ManagePreviewBuilds",
      "OSVersionFull",
      "t:WCOSProductId",
      "r:SmartActiveHoursState",
      "r:ActiveHoursStart",
      "r:ActiveHoursEnd"
    ],
    "FXIRISCLIENT": [
      "+IRISCLIENT"
    ],
    "IRISCLIENT": [
      "DeviceFamily",
      "OSVersion",
      "t:OSSkuId",
      "OSArchitecture",
      "c:TelemetryLevel",
      "f:FlightRing",
      "f:FlightingBranchName",
      "c:InternalPrimaryDisplayResolutionHorizontal",
      "c:InternalPrimaryDisplayResolutionVetical",
      "t:IsMsftOwned",
      "c:ChassisType",
      "c:IsDomainJoined",
      "c:ProcessorIdentifier",
      "c:CommercialId",
      "OEMModel",
      "c:OSUILocale",
      "c:OSEdition",
      "c:FlightIds",
      "t:LocalUserID"
    ],
    "MICROSOFT.WINDOWSFEEDBACKHUB_8WEKYB3D8BBWE": [
      "t:OSVersionFull",
      "t:IsTestLab",
      "f:FlightRing"
    ],
    "MITIGATION": [
      "t:DeviceFamily",
      "f:FlightRing",
      "c:FlightIds",
      "c:IsDomainJoined",
      "t:IsMsftOwned",
      "f:IsRetailOS",
      "t:IsTestLab",
      "IsVM",
      "OEMModel",
      "c:OSEdition",
      "t:OSSkuId",
      "t:OSVersionFull",
      "c:OSUILocale",
      "t:SMode",
      "f:IsFlightingEnabled",
      "c:FirmwareVersion",
      "c:TelemetryLevel",
      "f:FlightingBranchName",
      "r:CurrentBranch",
      "OSVersion"
    ],
    "MLMOD": [
      "ChassisTypeId",
      "t:DeviceFamily",
      "f:FlightingBranchName",
      "f:FlightRing",
      "f:IsRetailOS",
      "t:OSSkuId",
      "t:OSVersionFull",
      "c:OSUILocale",
      "OSVersion",
      "c:TelemetryLevel",
      "r:CurrentBranch"
    ],
    "MTP": [
      "+_WU_OS_CORE"
    ],
    "MUSE": [
      "+_WU_FB",
      "ChassisTypeId",
      "deviceClass",
      "deviceId",
      "c:FlightIds",
      "locale",
      "ms",
      "os",
      "osVer",
      "ring",
      "sampleId",
      "sku",
      "r:DaysSince19H1FUOffer",
      "u:DisableDualScan",
      "u:UpdateServiceUrl",
      "c:CommercialId",
      "f:FlightingBranchName"
    ],
    "NOISYHAMMER": [
      "+WU_OS"
    ],
    "SEDIMENTPACK": [
      "+WU_OS"
    ],
    "SETUP360": [
      "t:OSSkuId",
      "f:FlightRing"
    ],
    "STORAGEGROVELER": [
      "a:Free",
      "c:TelemetryLevel",
      "f:FlightRing",
      "f:IsFlightingEnabled",
      "IsVM",
      "t:OSVersionFull"
    ],
    "UTC": [
      "+UTC_STATIC",
      "osVer",
      "locale",
      "ring",
      "f:PilotRing",
      "f:IsRetailOS",
      "ms",
      "expId",
      "t:SMode",
      "f:FlightingBranchName",
      "c:CommercialId"
    ],
    "UTC_STATIC": [
      "os",
      "deviceId",
      "sampleId",
      "deviceClass",
      "sku",
      "OEMModel",
      "OEMName_Uncleaned",
      "c:PrimaryDiskType",
      "c:ProcessorModel",
      "c:TotalPhysicalRAM"
    ],
    "WAASASSESSMENT": [
      "+WU_OS"
    ],
    "WOSC": [
      "t:DeviceFamily",
      "f:FlightRing",
      "f:IsFlightingEnabled",
      "t:IsMsftOwned",
      "t:LocalDeviceID",
      "t:OSSkuId",
      "c:OSUILocale",
      "t:OSVersionFull",
      "c:TelemetryLevel",
      "r:IsHybridOrXGpu"
    ],
    "WPSHIFT": [
      "+MTP"
    ],
    "WU": [
      "+WU_OS",
      "r:DUInternal"
    ],
    "_WU_AV": [
      "r:AvastReg",
      "r:AvastBlackScreen",
      "v:AvastVer",
      "r:AvgReg",
      "v:AvgVer",
      "r:EsetReg",
      "v:EsetVer",
      "r:KasperskyReg",
      "v:KasperskyVer",
      "v:SymantecVer",
      "r:TencentReg",
      "r:TencentType"
    ],
    "_WU_COMMON": [
      "r:CurrentBranch",
      "r:DefaultUserRegion",
      "DeviceFamily",
      "r:DriverPartnerRing",
      "r:FlightContent",
      "f:FlightingBranchName",
      "f:FlightRing",
      "HoloLens",
      "c:InstallationType",
      "c:InstallLanguage",
      "f:IsFlightingEnabled",
      "r:IsFlightingEnabled",
      "c:MobileOperatorCommercialized",
      "OEMModel",
      "OEMName_Uncleaned",
      "r:OemPartnerRing",
      "OSArchitecture",
      "OSVersion",
      "t:OSSkuId",
      "c:OSUILocale",
      "c:ProcessorManufacturer",
      "r:ReleaseType",
      "v:SkypeRoomSystem",
      "t:SMode",
      "c:TelemetryLevel",
      "r:WindowsMixedReality",
      "v:WuClientVer",
      "p:DucPublisherId",
      "p:DucDeviceModelId",
      "p:DucOemPartnerRing",
      "p:DucCustomPackageId",
      "p:DesiredOsVersion",
      "p:DesiredSystemManifestVersion"
    ],
    "_WU_FB": [
      "u:BranchReadinessLevel",
      "u:DeferQualityUpdatePeriodInDays",
      "u:DeferFeatureUpdatePeriodInDays",
      "r:PausedFeatureStatus",
      "r:PausedQualityStatus",
      "u:TargetReleaseVersion",
      "r:QUDeadline",
      "r:UpdatePreference",
      "r:UpdateOfferedDays"
    ],
    "WU_OS": [
      "+_WU_OS_CORE",
      "+_WU_FB"
    ],
    "_WU_OS_CORE": [
      "+_WU_COMMON",
      "+_WU_AV",
      "r:AhnLabKeyboard",
      "a:Bios",
      "r:BlockFeatureUpdates",
      "c:CommercialId",
      "a:DataVer_RS5",
      "r:DisconnectedStandby",
      "r:DchuNvidiaGrfxExists",
      "r:DchuNvidiaGrfxVen",
      "r:DchuIntelGrfxExists",
      "r:DchuIntelGrfxVen",
      "r:DchuAmdGrfxExists",
      "r:DchuAmdGrfxVen",
      "c:FirmwareVersion",
      "a:Free",
      "a:GStatus_RS3",
      "a:GStatus_RS4",
      "a:GStatus_RS5",
      "r:HidOverGattReg",
      "r:InstallDate",
      "c:IsDeviceRetailDemo",
      "c:IsPortableOperatingSystem",
      "IsVM",
      "c:OEMModelBaseBoard",
      "r:OobeSeeker",
      "r:OSRollbackBuild",
      "r:OSRollbackCount",
      "r:OSRollbackDate",
      "PhoneTargetingName",
      "r:PonchAllow",
      "r:PonchBlock",
      "c:ProcessorIdentifier",
      "r:RecoveredFromBuild",
      "r:RecoveredOnDate",
      "r:Steam",
      "v:TobiiVer",
      "v:TrendMicroVer",
      "r:UninstallActive",
      "l:UpdateManagementGroup",
      "a:UpgEx_RS3",
      "a:UpgEx_RS4",
      "a:UpgEx_RS5",
      "a:Version_RS5",
      "r:DisableWUfBOfferBlock",
      "a:UpgEx_19H1",
      "a:SdbVer_19H1",
      "a:GStatus_19H1",
      "a:GStatus_19H1Setup",
      "a:TimestampEpochString_19H1Setup",
      "a:GenTelRunTimestamp_19H1",
      "a:DataExpDateEpoch_19H1",
      "u:EnableWUfBUpgradeGates",
      "r:GStatusBlockIDs_All",
      "TimestampDelta_19H1Subtract19H1Setup",
      "DataExpDateDelta_19H1Subtract19H1Setup",
      "a:DataExpDateEpoch_19H1Setup",
      "a:TimestampEpochString_19H1",
      "r:IsContainerMgrInstalled",
      "r:IsWDAGEnabled",
      "r:MTPTargetingInfo",
      "r:EKB19H2InstallCount",
      "r:EKB19H2UnInstallCount",
      "r:EKB19H2InstallTimeEpoch",
      "r:EKB19H2UnInstallTimeEpoch",
      "r:BlockEdgeWithChromiumUpdate",
      "r:IsWDATPEnabled",
      "r:IsAutopilotRegistered",
      "r:EdgeWithChromiumInstallVersion",
      "r:EdgeWithChromiumInstallFailureCount",
      "r:IsEdgeWithChromiumInstalled",
      "r:KioskMode",
      "c:IsCloudDomainJoined",
      "c:IsDomainJoined",
      "p:DSS_Enrolled",
      "a:DataExpDateEpoch_20H1",
      "a:DataExpDateEpoch_20H1Setup",
      "a:GStatus_20H1",
      "a:GStatus_20H1Setup",
      "a:SdbVer_20H1",
      "a:TimestampEpochString_20H1",
      "a:TimestampEpochString_20H1Setup",
      "DataExpDateDelta_20H1Subtract20H1Setup",
      "TimestampDelta_20H1Subtract20H1Setup",
      "a:UpgEx_20H1",
      "r:AutopilotUpdateInProgress",
      "r:UHSEnrolled"
    ],
    "_WU_PTI": [
      "c:FrontFacingCameraResolution",
      "c:RearFacingCameraResolution",
      "c:TotalPhysicalRAM",
      "c:NFCProximity",
      "c:Magnetometer",
      "c:Gyroscope",
      "c:D3DMaxFeatureLevel",
      "c:InternalPrimaryDisplayResolutionHorizontal",
      "c:InternalPrimaryDisplayResolutionVetical"
    ],
    "WU_STORE": [
      "+_WU_COMMON",
      "r:AppChannels",
      "r:AppRMIDs",
      "u:BranchReadinessLevel"
    ]
  },
  "Required": [
    "App",
    "AppVer",
    "AttrDataVer"
  ],
  "Aliases": {
    "ChassisTypeId": "c:ChassisType",
    "DataExpDateDelta_19H1Subtract19H1Setup": "a:DataExpDateEpoch_19H1_Subtract_DataExpDateEpoch_19H1Setup",
    "DataExpDateDelta_20H1Subtract20H1Setup": "a:DataExpDateEpoch_20H1_Subtract_DataExpDateEpoch_20H1Setup",
    "deviceClass": "t:DeviceFamily",
    "deviceId": "t:LocalDeviceID",
    "DeviceId": "t:LocalDeviceID",
    "expId": "c:FlightIds",
    "FlightRing": "f:FlightRing",
    "IsVM": "a:ISVM",
    "locale": "c:OSUILocale",
    "ms": "t:IsMsftOwned",
    "OEMModel": "c:OEMModelNumber",
    "OEMName_Uncleaned": "c:OEMManufacturerName",
    "osVer": "t:OSVersionFull",
    "OSVersionFull": "t:OSVersionFull",
    "PhoneTargetingName": "c:OEMModelName",
    "ring": "f:FlightRing",
    "sampleId": "t:PopVal",
    "sku": "t:OSSkuId",
    "TimestampDelta_19H1Subtract19H1Setup": "a:TimestampEpochString_19H1_Subtract_TimestampEpochString_19H1Setup",
    "TimestampDelta_20H1Subtract20H1Setup": "a:TimestampEpochString_20H1_Subtract_TimestampEpochString_20H1Setup"
  },
  "Fallback": {
    "r:AvastBlackScreen": "r:AvgBlackScreen",
    "a:Bios": "a:Bios_RS3",
    "a:Bios_RS3": "a:Bios_RS4",
    "a:Bios_RS4": "a:Bios_RS5",
    "r:BlockFeatureUpdates": "r:BlockWUUpgrades",
    "r:BlockWUUpgrades": "r:BlockWUUpgradesWow",
    "r:BuildFID": "r:BuildFID_WCOS",
    "r:BuildFID_WCOS": "r:BuildFID_WCOS2",
    "r:DchuAmdGrfxVen": "r:DchuAmdGrfxVen2",
    "r:DchuAmdGrfxVen2": "r:DchuAmdGrfxDeletePending",
    "r:DchuIntelGrfxVen": "r:DchuIntelGrfxVen2",
    "r:DchuIntelGrfxVen2": "r:DchuIntelGrfxDeletePending",
    "r:DchuNvidiaGrfxVen": "r:DchuNvidiaGrfxVen2",
    "r:DchuNvidiaGrfxVen2": "r:DchuNvidiaGrfxDeletePending",
    "r:DriverPartnerRing": "r:OSDataDriverPartnerRing",
    "p:DSS_Enrolled": "r:DSS_EnrolledReg",
    "r:EdgeWithChromiumInstallFailureCount": "r:EdgeWithChromiumInstallFailureCountWow",
    "r:EdgeWithChromiumInstallVersion": "r:EdgeWithChromiumInstallVersionWow",
    "u:EnableWUfBUpgradeGates": "r:EnableWUfBUpgradeGatesRS5",
    "f:FlightingBranchName": "c:FlightingBranchName",
    "a:Free": "a:Free_RS3",
    "a:Free_RS3": "a:Free_RS4",
    "a:Free_RS4": "a:Free_RS5",
    "HoloLens": "r:WindowsMixedReality",
    "r:IsEdgeWithChromiumInstalled": "r:IsEdgeWithChromiumInstalledWow",
    "a:ISVM": "a:ISVM_RS3",
    "a:ISVM_RS3": "a:ISVM_RS4",
    "a:ISVM_RS4": "a:ISVM_RS5",
    "c:OEMModelBaseBoard": "r:OEMModelBaseBoard",
    "r:PonchAllow": "r:PonchAllowKey",
    "r:PonchAllowKey": "r:PonchAllowWow",
    "r:PonchAllowWow": "r:PonchAllowWowKey",
    "r:QUDeadline": "r:QUDeadlineMDM",
    "v:SymantecVer": "v:SymantecVer64",
    "u:TargetReleaseVersion": "r:TargetReleaseVersionGP",
    "r:TargetReleaseVersionGP": "r:TargetReleaseVersionMDM",
    "v:TobiiVer": "v:TobiiVerx86",
    "v:TobiiVerx86": "v:TobiiVer1x86"
  },
  "Transform": {
    "IsDomainJoined": {
      "Ignore": [
        "0"
      ]
    },
    "IsHybridOrXGpu": {
      "Ignore": [
        "0"
      ]
    },
    "IsMsftOwned": {
      "Ignore": [
        "0"
      ]
    },
    "IsPortableOperatingSystem": {
      "Ignore": [
        "0"
      ]
    },
    "IsTestLab": {
      "Ignore": [
        "0"
      ]
    },
    "IsVM": {
      "Ignore": [
        "0"
      ]
    },
    "OEMModel": {
      "SubLength": 100
    },
    "OEMName_Uncleaned": {
      "SubLength": 100
    },
    "PausedFeatureStatus": {
      "Ignore": [
        "0"
      ]
    },
    "PausedQualityStatus": {
      "Ignore": [
        "0"
      ]
    },
    "SMode": {
      "Ignore": [
        "0"
      ]
    }
  },
  "Registry": {
    "ActiveHoursEnd": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\WindowsUpdate\\UX\\Settings",
      "ValueName": "ActiveHoursEnd",
      "RegValueType": "REG_DWORD"
    },
    "ActiveHoursStart": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\WindowsUpdate\\UX\\Settings",
      "ValueName": "ActiveHoursStart",
      "RegValueType": "REG_DWORD"
    },
    "AhnLabKeyboard": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\Mkd2kfNt",
      "ValueName": "NbTpMsExist"
    },
    "AppChannels": {
      "FullPath": "SOFTWARE\\Policies\\Microsoft\\WindowsStore\\Apps\\*",
      "ValueName": "ChannelId",
      "EncodingType": "Json"
    },
    "AppRMIDs": {
      "FullPath": "SOFTWARE\\Policies\\Microsoft\\WindowsStore\\Apps\\*",
      "ValueName": "ReleaseManagementId",
      "EncodingType": "Json"
    },
    "AutopilotUpdateInProgress": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Provisioning\\AutopilotSettings\\VolatileAutopilotUpdate",
      "ValueName": "AutopilotUpdateInProgress",
      "RegValueType": "REG_DWORD"
    },
    "AvastBlackScreen": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\aswVmm\\Parameters",
      "ValueName": "Win10-1803"
    },
    "AvastReg": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\aswVmm\\Parameters",
      "ValueName": "QualityCompat"
    },
    "AvgBlackScreen": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\avgVmm\\Parameters",
      "ValueName": "Win10-1803"
    },
    "AvgReg": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\avgVmm\\Parameters",
      "ValueName": "QualityCompat"
    },
    "BlockEdgeWithChromiumUpdate": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\EdgeUpdate",
      "ValueName": "DoNotUpdateToEdgeWithChromium",
      "RegValueType": "REG_DWORD"
    },
    "BlockFeatureUpdates": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\WindowsUpdate\\OSUpgrade",
      "ValueName": "BlockFeatureUpdates",
      "RegValueType": "REG_DWORD"
    },
    "BlockWUUpgrades": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows10Upgrader\\Volatile",
      "ValueName": "BlockWUUpgrades",
      "RegValueType": "REG_DWORD"
    },
    "BlockWUUpgradesWow": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\WOW6432Node\\Microsoft\\Windows10Upgrader\\Volatile",
      "ValueName": "BlockWUUpgrades",
      "RegValueType": "REG_DWORD"
    },
    "BuildFID": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "Software\\Microsoft\\Windows\\CurrentVersion\\Flighting\\Build",
      "ValueName": "EsdFlightData",
      "RegValueType": "REG_SZ"
    },
    "BuildFID_WCOS": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "OSDATA\\Software\\Microsoft\\Windows\\CurrentVersion\\Flighting\\Build",
      "ValueName": "EsdFlightData",
      "RegValueType": "REG_SZ"
    },
    "BuildFID_WCOS2": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "OSDATA\\Microsoft\\Windows\\CurrentVersion\\Flighting\\Build",
      "ValueName": "EsdFlightData",
      "RegValueType": "REG_SZ"
    },
    "CurrentBranch": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion",
      "ValueName": "BuildBranch",
      "RegValueType": "REG_SZ"
    },
    "DaysSince19H1FUOffer": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\rempl\\irplugin",
      "ValueName": "DaysSinceLastOffer",
      "RegValueType": "REG_QWORD"
    },
    "DchuAmdGrfxDeletePending": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\amdkmdap",
      "ValueName": "DriverDelete"
    },
    "DchuAmdGrfxExists": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\amdkmdap",
      "IfExists": true
    },
    "DchuAmdGrfxVen": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\amdkmdap",
      "ValueName": "DCHUVen"
    },
    "DchuAmdGrfxVen2": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\amdkmdap\\Parameters",
      "ValueName": "DCHUVen"
    },
    "DchuIntelGrfxDeletePending": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\igfx",
      "ValueName": "DriverDelete"
    },
    "DchuIntelGrfxExists": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\igfx",
      "IfExists": true
    },
    "DchuIntelGrfxVen": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\igfx",
      "ValueName": "DCHUVen"
    },
    "DchuIntelGrfxVen2": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\igfx\\Parameters",
      "ValueName": "DCHUVen"
    },
    "DchuNvidiaGrfxDeletePending": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\nvlddmkm",
      "ValueName": "DriverDelete"
    },
    "DchuNvidiaGrfxExists": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\nvlddmkm",
      "IfExists": true
    },
    "DchuNvidiaGrfxVen": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\nvlddmkm",
      "ValueName": "DCHUVen"
    },
    "DchuNvidiaGrfxVen2": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\nvlddmkm\\Parameters",
      "ValueName": "DCHUVen"
    },
    "DefaultUserRegion": {
      "HKey": "HKEY_USERS",
      "FullPath": ".DEFAULT\\Control Panel\\International\\Geo",
      "ValueName": "Nation",
      "RegValueType": "REG_SZ"
    },
    "DisableWUfBOfferBlock": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\WindowsUpdate\\UpdatePolicy\\Settings",
      "ValueName": "DisableWUfBOfferBlock",
      "RegValueType": "REG_DWORD"
    },
    "DisconnectedStandby": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SYSTEM\\CurrentControlSet\\Control\\Power",
      "ValueName": "EnforceDisconnectedStandby",
      "RegValueType": "REG_DWORD"
    },
    "DriverPartnerRing": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\DriverFlighting\\Partner",
      "ValueName": "TargetRing",
      "RegValueType": "REG_SZ"
    },
    "DSS_EnrolledReg": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Policies\\Microsoft\\Windows\\WindowsUpdate",
      "ValueName": "EnableWUfBCloud",
      "RegValueType": "REG_DWORD"
    },
    "DUInternal": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SYSTEM\\Setup\\MoSetup",
      "ValueName": "DynamicUpdateInternalTest",
      "RegValueType": "REG_DWORD"
    },
    "EdgeWithChromiumInstallFailureCount": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\EdgeUpdate",
      "ValueName": "WindowsUpdateAttempts"
    },
    "EdgeWithChromiumInstallFailureCountWow": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Wow6432Node\\Microsoft\\EdgeUpdate",
      "ValueName": "WindowsUpdateAttempts"
    },
    "EdgeWithChromiumInstallVersion": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\EdgeUpdate",
      "ValueName": "WindowsUpdateVersion"
    },
    "EdgeWithChromiumInstallVersionWow": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Wow6432Node\\Microsoft\\EdgeUpdate",
      "ValueName": "WindowsUpdateVersion"
    },
    "EKB19H2InstallCount": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SYSTEM\\Setup\\FeatureStaging\\20455539\\2",
      "ValueName": "Count"
    },
    "EKB19H2InstallTimeEpoch": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SYSTEM\\Setup\\FeatureStaging\\20455539\\2",
      "ValueName": "Timestamp"
    },
    "EKB19H2UnInstallCount": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SYSTEM\\Setup\\FeatureStaging\\20455539\\0",
      "ValueName": "Count"
    },
    "EKB19H2UnInstallTimeEpoch": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SYSTEM\\Setup\\FeatureStaging\\20455539\\0",
      "ValueName": "Timestamp"
    },
    "EnableWUfBUpgradeGatesRS5": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "Software\\Microsoft\\Windows NT\\CurrentVersion\\502505fe-762c-4e80-911e-0c3fa4c63fb0",
      "ValueName": "DataRequireGatedScanForFeatureUpdates",
      "RegValueType": "REG_DWORD"
    },
    "EsetReg": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\ehdrv\\Parameters",
      "ValueName": "WindowsCompatibilityLevel",
      "RegValueType": "REG_DWORD"
    },
    "FlightContent": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\WindowsSelfHost\\Applicability",
      "ValueName": "ContentType",
      "RegValueType": "REG_SZ"
    },
    "GStatusBlockIDs_All": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\Appraiser\\GWX",
      "ValueName": "SdbEntries",
      "RegValueType": "REG_SZ"
    },
    "HidOverGattReg": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\PnpLockdownFiles\\%SystemRoot%/System32/drivers/UMDF/Microsoft.Bluetooth.Profiles.HidOverGatt.dll",
      "ValueName": "Source",
      "RegValueType": "REG_SZ"
    },
    "InstallDate": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion",
      "ValueName": "InstallDate",
      "RegValueType": "REG_DWORD"
    },
    "IsAutopilotRegistered": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Provisioning\\AutopilotPolicyCache",
      "ValueName": "ProfileAvailable",
      "RegValueType": "REG_DWORD"
    },
    "IsFlightingEnabled": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\WindowsSelfHost\\Applicability",
      "ValueName": "IsBuildFlightingEnabled",
      "RegValueType": "REG_DWORD"
    },
    "IsContainerMgrInstalled": {
      "FullPath": "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Containers\\CmService",
      "IfExists": true
    },
    "IsEdgeWithChromiumInstalled": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\EdgeUpdate\\Clients\\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}",
      "IfExists": true
    },
    "IsEdgeWithChromiumInstalledWow": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Wow6432Node\\Microsoft\\EdgeUpdate\\Clients\\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}",
      "IfExists": true
    },
    "IsHybridOrXGpu": {
      "FullPath": "SOFTWARE\\Microsoft\\DirectX",
      "ValueName": "HybridDeviceApplicableForDxDbGpuPreferences"
    },
    "IsWDAGEnabled": {
      "FullPath": "SYSTEM\\ControlSet001\\Services\\hvsics",
      "IfExists": true
    },
    "IsWDATPEnabled": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows Advanced Threat Protection\\Status",
      "ValueName": "OnboardingState"
    },
    "KasperskyReg": {
      "FullPath": "System\\CurrentControlSet\\Services\\klhk\\Parameters",
      "ValueName": "UseVtHardware"
    },
    "KioskMode": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows\\AssignedAccessCsp\\AutoLogonAccount",
      "ValueName": "ConfigSource",
      "RegValueType": "REG_DWORD"
    },
    "MTPTargetingInfo": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SYSTEM\\Platform\\MTPTargetingInfo",
      "ValueName": "TargetRing"
    },
    "OEMModelBaseBoard": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "HARDWARE\\DESCRIPTION\\System\\BIOS",
      "ValueName": "BaseBoardProduct",
      "RegValueType": "REG_SZ"
    },
    "OemPartnerRing": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SYSTEM\\Platform\\DeviceTargetingInfo",
      "ValueName": "TargetRing",
      "RegValueType": "REG_SZ"
    },
    "OobeSeeker": {
      "FullPath": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\OOBE\\Updates",
      "ValueName": "OOBEUpdateStarted"
    },
    "OSDataDriverPartnerRing": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "OSData\\SOFTWARE\\Microsoft\\DriverFlighting\\Partner",
      "ValueName": "TargetRing",
      "RegValueType": "REG_SZ"
    },
    "OSRollbackBuild": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\WindowsUpdate\\OSUpgrade\\Rollback",
      "ValueName": "BuildString",
      "RegValueType": "REG_SZ"
    },
    "OSRollbackCount": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\WindowsUpdate\\OSUpgrade\\Rollback",
      "ValueName": "Count",
      "RegValueType": "REG_DWORD"
    },
    "OSRollbackDate": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\WindowsUpdate\\OSUpgrade\\Rollback",
      "ValueName": "DateStamp",
      "RegValueType": "REG_DWORD"
    },
    "PausedFeatureStatus": {
      "FullPath": "SOFTWARE\\Microsoft\\WindowsUpdate\\UpdatePolicy\\Settings",
      "ValueName": "PausedFeatureStatus"
    },
    "PausedQualityStatus": {
      "FullPath": "SOFTWARE\\Microsoft\\WindowsUpdate\\UpdatePolicy\\Settings",
      "ValueName": "PausedQualityStatus"
    },
    "PonchAllow": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\QualityCompat",
      "ValueName": "cadca5fe-87d3-4b96-b7fb-a231484277cc",
      "RegValueType": "REG_DWORD"
    },
    "PonchAllowKey": {
      "FullPath": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\QualityCompat\\cadca5fe-87d3-4b96-b7fb-a231484277cc",
      "IfExists": true
    },
    "PonchAllowWow": {
      "FullPath": "SOFTWARE\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\QualityCompat",
      "ValueName": "cadca5fe-87d3-4b96-b7fb-a231484277cc"
    },
    "PonchAllowWowKey": {
      "FullPath": "SOFTWARE\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\QualityCompat\\cadca5fe-87d3-4b96-b7fb-a231484277cc",
      "IfExists": true
    },
    "PonchBlock": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\QualityCompat",
      "ValueName": "65d75b03-6f4d-46e9-b870-517731e06cf9",
      "RegValueType": "REG_DWORD"
    },
    "PreviewBuildsManagerEnabled": {
      "FullPath": "SOFTWARE\\Microsoft\\WindowsSelfhost\\Manager",
      "ValueName": "ArePreviewBuildsAllowed"
    },
    "QUDeadline": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Policies\\Microsoft\\Windows\\WindowsUpdate",
      "ValueName": "ConfigureDeadlineForQualityUpdates",
      "RegValueType": "REG_DWORD"
    },
    "QUDeadlineMDM": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\PolicyManager\\current\\device\\Update",
      "ValueName": "ConfigureDeadlineForQualityUpdates",
      "RegValueType": "REG_DWORD"
    },
    "RecoveredFromBuild": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "Software\\Microsoft\\WindowsSelfHost\\Applicability\\RecoveredFrom",
      "ValueName": "LastBuild",
      "RegValueType": "REG_DWORD"
    },
    "RecoveredOnDate": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "Software\\Microsoft\\WindowsSelfHost\\Applicability\\RecoveredFrom",
      "ValueName": "DateStamp",
      "RegValueType": "REG_DWORD"
    },
    "ReleaseType": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Update\\TargetingInfo",
      "ValueName": "ReleaseType",
      "RegValueType": "REG_SZ"
    },
    "SmartActiveHoursState": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\WindowsUpdate\\UX\\Settings",
      "ValueName": "SmartActiveHoursState",
      "RegValueType": "REG_DWORD"
    },
    "Steam": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Classes\\Steam",
      "ValueName": "",
      "RegValueType": "REG_SZ"
    },
    "TargetReleaseVersionGP": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Policies\\Microsoft\\Windows\\WindowsUpdate",
      "ValueName": "TargetReleaseVersionInfo",
      "RegValueType": "REG_SZ"
    },
    "TargetReleaseVersionMDM": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\PolicyManager\\current\\device\\Update",
      "ValueName": "TargetReleaseVersion",
      "RegValueType": "REG_SZ"
    },
    "TencentReg": {
      "FullPath": "SYSTEM\\CurrentControlSet\\services\\TesSafe",
      "ValueName": "LoadStartTime"
    },
    "TencentType": {
      "FullPath": "SYSTEM\\CurrentControlSet\\services\\TesSafe",
      "ValueName": "Type"
    },
    "UHSEnrolled": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion",
      "ValueName": "UHSEnrolled",
      "RegValueType": "REG_SZ",
      "IfExists": true
    },
    "UninstallActive": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "System\\Setup",
      "ValueName": "UninstallActive",
      "RegValueType": "REG_DWORD"
    },
    "UpdateOfferedDays": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\WaaSAssessment\\Cache\\",
      "ValueName": "UpToDateDays",
      "RegValueType": "REG_DWORD"
    },
    "UpdatePreference": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Policies\\Microsoft\\Windows\\WindowsUpdate",
      "ValueName": "UpdatePreference",
      "RegValueType": "REG_DWORD"
    },
    "WindowsMixedReality": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\WUDF\\Services\\HoloLensSensors",
      "ValueName": "WdfMajorVersion",
      "RegValueType": "REG_DWORD"
    }
  },
  "FileInfo": {
    "AvastVer": {
      "Path": "\\system32\\Drivers\\aswVmm.sys",
      "FolderGuid": "{F38BF404-1D43-42F2-9305-67DE0B28FC23}"
    },
    "AvgVer": {
      "Path": "\\system32\\Drivers\\avgVmm.sys",
      "FolderGuid": "{F38BF404-1D43-42F2-9305-67DE0B28FC23}"
    },
    "CortanaAppVer": {
      "Path": "\\WindowsApps\\Microsoft.549981C3F5F10_8wekyb3d8bbwe\\CortanaApp.View.exe",
      "FolderGuid": "{905E63B6-C1BF-494E-B29C-65B732D3D21A}"
    },
    "CortanaAppVerTest": {
      "Path": "\\WindowsApps\\3242f7d9-db60-4380-a379-4205ea768bfc_1.0.0.0_x64__zs4v8rx04ex0m\\UndockingTestApp.exe",
      "FolderGuid": "{905E63B6-C1BF-494E-B29C-65B732D3D21A}"
    },
    "EsetVer": {
      "Path": "\\drivers\\ehdrv.sys",
      "FolderGuid": "{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}"
    },
    "KasperskyVer": {
      "Path": "\\system32\\Drivers\\klhk.sys",
      "FolderGuid": "{F38BF404-1D43-42F2-9305-67DE0B28FC23}"
    },
    "SkypeRoomSystem": {
      "Path": "%systemdrive%\\Recovery\\OEM\\$oem$\\$1\\Rigel\\x64\\Scripts\\Provisioning\\AutoUnattend.xml",
      "IfExists": true
    },
    "SymantecVer": {
      "Path": "\\Symantec\\Shared\\EENGINE\\eeCtrl.sys",
      "FolderGuid": "{DE974D24-D9C6-4D3E-BF91-F4455120B917}"
    },
    "SymantecVer64": {
      "Path": "\\Symantec\\Shared\\EENGINE\\eeCtrl64.sys",
      "FolderGuid": "{DE974D24-D9C6-4D3E-BF91-F4455120B917}"
    },
    "TobiiVer": {
      "Path": "\\Tobii\\Tobii EyeX Interaction\\Tobii.EyeX.Interaction.exe",
      "FolderGuid": "{905E63B6-C1BF-494E-B29C-65B732D3D21A}"
    },
    "TobiiVer1x86": {
      "Path": "\\Tobii\\tobii EyeX Interaction\\Tobii.EyeX.Interaction.exe",
      "FolderGuid": "{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}"
    },
    "TobiiVerx86": {
      "Path": "\\tobii EyeX Interaction\\Tobii.EyeX.Interaction.exe",
      "FolderGuid": "{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}"
    },
    "TrendMicroVer": {
      "Path": "\\drivers\\TMUMH.sys",
      "FolderGuid": "{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}"
    },
    "WuClientVer": {
      "Path": "\\system32\\wuaueng.dll",
      "FolderGuid": "{F38BF404-1D43-42F2-9305-67DE0B28FC23}"
    }
  },
  "Licensing": {
    "UpdateManagementGroup": {
      "Name": "UpdatePolicy-UpdateManagementGroup"
    }
  },
  "UpdatePolicy": {
    "BranchReadinessLevel": {
      "PolicyEnum": 5,
      "Enterprise": true
    },
    "BranchReadinessLevelSource": {
      "PolicyEnum": 5,
      "Enterprise": true,
      "UseSource": true
    },
    "DeferFeatureUpdatePeriodInDays": {
      "PolicyEnum": 9,
      "Enterprise": true
    },
    "DeferQualityUpdatePeriodInDays": {
      "PolicyEnum": 7,
      "Enterprise": true
    },
    "DisableDualScan": {
      "PolicyEnum": 42,
      "Enterprise": true
    },
    "EnableWUfBUpgradeGates": {
      "PolicyEnum": 51,
      "Enterprise": true
    },
    "TargetReleaseVersion": {
      "PolicyEnum": 50,
      "Enterprise": true
    },
    "UpdateServiceUrl": {
      "PolicyEnum": 12
    }
  },
  "Policy": {
    "DesiredOsVersion": {
      "LocUri": "./Device/Vendor/MSFT/DeviceUpdateCenter/DesiredUpdates/OsVersion"
    },
    "DesiredSystemManifestVersion": {
      "LocUri": "./Device/Vendor/MSFT/DeviceUpdateCenter/DesiredUpdates/SystemManifestVersion"
    },
    "DSS_Enrolled": {
      "Area": "Update",
      "Name": "EnableWUfBCloud"
    },
    "DucCustomPackageId": {
      "LocUri": "./Device/Vendor/MSFT/DeviceUpdateCenter/Enrollment/CustomPackageId"
    },
    "DucDeviceModelId": {
      "LocUri": "./Device/Vendor/MSFT/DeviceUpdateCenter/Enrollment/DeviceModelId"
    },
    "DucOemPartnerRing": {
      "LocUri": "./Device/Vendor/MSFT/DeviceUpdateCenter/Enrollment/OemPartnerRing"
    },
    "DucPublisherId": {
      "LocUri": "./Device/Vendor/MSFT/DeviceUpdateCenter/Enrollment/PublisherId"
    }
  }
}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsSelfHost\OneSettings]
"TargetingAttributesVerified"="{
  "Version": 93,
  "SchemaVersion": 1,
  "PartA": [
    "App",
    "AppVer",
    "AttrDataVer"
  ],
  "Default": [
    "DeviceFamily",
    "f:FlightRing",
    "t:OSVersionFull"
  ],
  "PartB": {
    "ACSOVERRIDE": [
      "OSArchitecture",
      "c:IsAlwaysOnAlwaysConnectedCapable"
    ],
    "CDM": [
      "ChassisTypeId",
      "r:CurrentBranch",
      "DeviceFamily",
      "f:FlightingBranchName",
      "f:FlightRing",
      "c:InstallLanguage",
      "c:IsDomainJoined",
      "t:IsTestLab",
      "OEMModel",
      "OSArchitecture",
      "OSVersion",
      "t:OSSkuId",
      "c:ProcessorIdentifier",
      "c:TelemetryLevel",
      "t:IsMsftOwned",
      "t:WCOSProductId",
      "c:OSUILocale",
      "c:CommercialId",
      "s:MinShellVersion",
      "s:MaxShellVersion",
      "c:ActivationChannel",
      "c:SCCMClientId",
      "c:IsCloudDomainJoined"
    ],
    "COMPATLOGGER": [
      "osVer",
      "ring",
      "deviceId"
    ],
    "CORTANA_GATEKEEPER": [
      "r:CurrentBranch",
      "f:FlightRing",
      "f:IsRetailOS"
    ],
    "CORTANAUWP": [
      "c:OSUILocale",
      "t:OSVersionFull",
      "v:CortanaAppVer"
    ],
    "CORTANAUWPTEST": [
      "+CORTANAUWP",
      "v:CortanaAppVerTest"
    ],
    "CTAC": [
      "+FSS"
    ],
    "DDC": [
      "+WU_STORE",
      "+_WU_PTI"
    ],
    "DXDB": [
      "DeviceFamily",
      "f:FlightRing",
      "r:IsHybridOrXGpu",
      "t:OSVersionFull"
    ],
    "EDGE_SERVICEUI": [
      "t:LocalDeviceID",
      "t:LocalUserID"
    ],
    "FCON": [
      "+CDM"
    ],
    "FSS": [
      "r:PreviewBuildsManagerEnabled",
      "f:BranchReadinessLevelRaw",
      "u:BranchReadinessLevelSource",
      "r:BuildFID",
      "t:DeviceFamily",
      "DeviceId",
      "c:EnablePreviewBuilds",
      "f:FlightingPolicyValue",
      "f:IsRetailOS",
      "f:ManagePreviewBuilds",
      "OSVersionFull",
      "t:WCOSProductId",
      "r:SmartActiveHoursState",
      "r:ActiveHoursStart",
      "r:ActiveHoursEnd"
    ],
    "FXIRISCLIENT": [
      "+IRISCLIENT"
    ],
    "IRISCLIENT": [
      "DeviceFamily",
      "OSVersion",
      "t:OSSkuId",
      "OSArchitecture",
      "c:TelemetryLevel",
      "f:FlightRing",
      "f:FlightingBranchName",
      "c:InternalPrimaryDisplayResolutionHorizontal",
      "c:InternalPrimaryDisplayResolutionVetical",
      "t:IsMsftOwned",
      "c:ChassisType",
      "c:IsDomainJoined",
      "c:ProcessorIdentifier",
      "c:CommercialId",
      "OEMModel",
      "c:OSUILocale",
      "c:OSEdition",
      "c:FlightIds",
      "t:LocalUserID"
    ],
    "MICROSOFT.WINDOWSFEEDBACKHUB_8WEKYB3D8BBWE": [
      "t:OSVersionFull",
      "t:IsTestLab",
      "f:FlightRing"
    ],
    "MITIGATION": [
      "t:DeviceFamily",
      "f:FlightRing",
      "c:FlightIds",
      "c:IsDomainJoined",
      "t:IsMsftOwned",
      "f:IsRetailOS",
      "t:IsTestLab",
      "IsVM",
      "OEMModel",
      "c:OSEdition",
      "t:OSSkuId",
      "t:OSVersionFull",
      "c:OSUILocale",
      "t:SMode",
      "f:IsFlightingEnabled",
      "c:FirmwareVersion",
      "c:TelemetryLevel",
      "f:FlightingBranchName",
      "r:CurrentBranch",
      "OSVersion"
    ],
    "MLMOD": [
      "ChassisTypeId",
      "t:DeviceFamily",
      "f:FlightingBranchName",
      "f:FlightRing",
      "f:IsRetailOS",
      "t:OSSkuId",
      "t:OSVersionFull",
      "c:OSUILocale",
      "OSVersion",
      "c:TelemetryLevel",
      "r:CurrentBranch"
    ],
    "MTP": [
      "+_WU_OS_CORE"
    ],
    "MUSE": [
      "+_WU_FB",
      "ChassisTypeId",
      "deviceClass",
      "deviceId",
      "c:FlightIds",
      "locale",
      "ms",
      "os",
      "osVer",
      "ring",
      "sampleId",
      "sku",
      "r:DaysSince19H1FUOffer",
      "u:DisableDualScan",
      "u:UpdateServiceUrl",
      "c:CommercialId",
      "f:FlightingBranchName"
    ],
    "NOISYHAMMER": [
      "+WU_OS"
    ],
    "SEDIMENTPACK": [
      "+WU_OS"
    ],
    "SETUP360": [
      "t:OSSkuId",
      "f:FlightRing"
    ],
    "STORAGEGROVELER": [
      "a:Free",
      "c:TelemetryLevel",
      "f:FlightRing",
      "f:IsFlightingEnabled",
      "IsVM",
      "t:OSVersionFull"
    ],
    "UTC": [
      "+UTC_STATIC",
      "osVer",
      "locale",
      "ring",
      "f:PilotRing",
      "f:IsRetailOS",
      "ms",
      "expId",
      "t:SMode",
      "f:FlightingBranchName",
      "c:CommercialId"
    ],
    "UTC_STATIC": [
      "os",
      "deviceId",
      "sampleId",
      "deviceClass",
      "sku",
      "OEMModel",
      "OEMName_Uncleaned",
      "c:PrimaryDiskType",
      "c:ProcessorModel",
      "c:TotalPhysicalRAM"
    ],
    "WAASASSESSMENT": [
      "+WU_OS"
    ],
    "WOSC": [
      "t:DeviceFamily",
      "f:FlightRing",
      "f:IsFlightingEnabled",
      "t:IsMsftOwned",
      "t:LocalDeviceID",
      "t:OSSkuId",
      "c:OSUILocale",
      "t:OSVersionFull",
      "c:TelemetryLevel",
      "r:IsHybridOrXGpu"
    ],
    "WPSHIFT": [
      "+MTP"
    ],
    "WU": [
      "+WU_OS",
      "r:DUInternal"
    ],
    "_WU_AV": [
      "r:AvastReg",
      "r:AvastBlackScreen",
      "v:AvastVer",
      "r:AvgReg",
      "v:AvgVer",
      "r:EsetReg",
      "v:EsetVer",
      "r:KasperskyReg",
      "v:KasperskyVer",
      "v:SymantecVer",
      "r:TencentReg",
      "r:TencentType"
    ],
    "_WU_COMMON": [
      "r:CurrentBranch",
      "r:DefaultUserRegion",
      "DeviceFamily",
      "r:DriverPartnerRing",
      "r:FlightContent",
      "f:FlightingBranchName",
      "f:FlightRing",
      "HoloLens",
      "c:InstallationType",
      "c:InstallLanguage",
      "f:IsFlightingEnabled",
      "r:IsFlightingEnabled",
      "c:MobileOperatorCommercialized",
      "OEMModel",
      "OEMName_Uncleaned",
      "r:OemPartnerRing",
      "OSArchitecture",
      "OSVersion",
      "t:OSSkuId",
      "c:OSUILocale",
      "c:ProcessorManufacturer",
      "r:ReleaseType",
      "v:SkypeRoomSystem",
      "t:SMode",
      "c:TelemetryLevel",
      "r:WindowsMixedReality",
      "v:WuClientVer",
      "p:DucPublisherId",
      "p:DucDeviceModelId",
      "p:DucOemPartnerRing",
      "p:DucCustomPackageId",
      "p:DesiredOsVersion",
      "p:DesiredSystemManifestVersion"
    ],
    "_WU_FB": [
      "u:BranchReadinessLevel",
      "u:DeferQualityUpdatePeriodInDays",
      "u:DeferFeatureUpdatePeriodInDays",
      "r:PausedFeatureStatus",
      "r:PausedQualityStatus",
      "u:TargetReleaseVersion",
      "r:QUDeadline",
      "r:UpdatePreference",
      "r:UpdateOfferedDays"
    ],
    "WU_OS": [
      "+_WU_OS_CORE",
      "+_WU_FB"
    ],
    "_WU_OS_CORE": [
      "+_WU_COMMON",
      "+_WU_AV",
      "r:AhnLabKeyboard",
      "a:Bios",
      "r:BlockFeatureUpdates",
      "c:CommercialId",
      "a:DataVer_RS5",
      "r:DisconnectedStandby",
      "r:DchuNvidiaGrfxExists",
      "r:DchuNvidiaGrfxVen",
      "r:DchuIntelGrfxExists",
      "r:DchuIntelGrfxVen",
      "r:DchuAmdGrfxExists",
      "r:DchuAmdGrfxVen",
      "c:FirmwareVersion",
      "a:Free",
      "a:GStatus_RS3",
      "a:GStatus_RS4",
      "a:GStatus_RS5",
      "r:HidOverGattReg",
      "r:InstallDate",
      "c:IsDeviceRetailDemo",
      "c:IsPortableOperatingSystem",
      "IsVM",
      "c:OEMModelBaseBoard",
      "r:OobeSeeker",
      "r:OSRollbackBuild",
      "r:OSRollbackCount",
      "r:OSRollbackDate",
      "PhoneTargetingName",
      "r:PonchAllow",
      "r:PonchBlock",
      "c:ProcessorIdentifier",
      "r:RecoveredFromBuild",
      "r:RecoveredOnDate",
      "r:Steam",
      "v:TobiiVer",
      "v:TrendMicroVer",
      "r:UninstallActive",
      "l:UpdateManagementGroup",
      "a:UpgEx_RS3",
      "a:UpgEx_RS4",
      "a:UpgEx_RS5",
      "a:Version_RS5",
      "r:DisableWUfBOfferBlock",
      "a:UpgEx_19H1",
      "a:SdbVer_19H1",
      "a:GStatus_19H1",
      "a:GStatus_19H1Setup",
      "a:TimestampEpochString_19H1Setup",
      "a:GenTelRunTimestamp_19H1",
      "a:DataExpDateEpoch_19H1",
      "u:EnableWUfBUpgradeGates",
      "r:GStatusBlockIDs_All",
      "TimestampDelta_19H1Subtract19H1Setup",
      "DataExpDateDelta_19H1Subtract19H1Setup",
      "a:DataExpDateEpoch_19H1Setup",
      "a:TimestampEpochString_19H1",
      "r:IsContainerMgrInstalled",
      "r:IsWDAGEnabled",
      "r:MTPTargetingInfo",
      "r:EKB19H2InstallCount",
      "r:EKB19H2UnInstallCount",
      "r:EKB19H2InstallTimeEpoch",
      "r:EKB19H2UnInstallTimeEpoch",
      "r:BlockEdgeWithChromiumUpdate",
      "r:IsWDATPEnabled",
      "r:IsAutopilotRegistered",
      "r:EdgeWithChromiumInstallVersion",
      "r:EdgeWithChromiumInstallFailureCount",
      "r:IsEdgeWithChromiumInstalled",
      "r:KioskMode",
      "c:IsCloudDomainJoined",
      "c:IsDomainJoined",
      "p:DSS_Enrolled",
      "a:DataExpDateEpoch_20H1",
      "a:DataExpDateEpoch_20H1Setup",
      "a:GStatus_20H1",
      "a:GStatus_20H1Setup",
      "a:SdbVer_20H1",
      "a:TimestampEpochString_20H1",
      "a:TimestampEpochString_20H1Setup",
      "DataExpDateDelta_20H1Subtract20H1Setup",
      "TimestampDelta_20H1Subtract20H1Setup",
      "a:UpgEx_20H1",
      "r:AutopilotUpdateInProgress",
      "r:UHSEnrolled"
    ],
    "_WU_PTI": [
      "c:FrontFacingCameraResolution",
      "c:RearFacingCameraResolution",
      "c:TotalPhysicalRAM",
      "c:NFCProximity",
      "c:Magnetometer",
      "c:Gyroscope",
      "c:D3DMaxFeatureLevel",
      "c:InternalPrimaryDisplayResolutionHorizontal",
      "c:InternalPrimaryDisplayResolutionVetical"
    ],
    "WU_STORE": [
      "+_WU_COMMON",
      "r:AppChannels",
      "r:AppRMIDs",
      "u:BranchReadinessLevel"
    ]
  },
  "Required": [
    "App",
    "AppVer",
    "AttrDataVer"
  ],
  "Aliases": {
    "ChassisTypeId": "c:ChassisType",
    "DataExpDateDelta_19H1Subtract19H1Setup": "a:DataExpDateEpoch_19H1_Subtract_DataExpDateEpoch_19H1Setup",
    "DataExpDateDelta_20H1Subtract20H1Setup": "a:DataExpDateEpoch_20H1_Subtract_DataExpDateEpoch_20H1Setup",
    "deviceClass": "t:DeviceFamily",
    "deviceId": "t:LocalDeviceID",
    "DeviceId": "t:LocalDeviceID",
    "expId": "c:FlightIds",
    "FlightRing": "f:FlightRing",
    "IsVM": "a:ISVM",
    "locale": "c:OSUILocale",
    "ms": "t:IsMsftOwned",
    "OEMModel": "c:OEMModelNumber",
    "OEMName_Uncleaned": "c:OEMManufacturerName",
    "osVer": "t:OSVersionFull",
    "OSVersionFull": "t:OSVersionFull",
    "PhoneTargetingName": "c:OEMModelName",
    "ring": "f:FlightRing",
    "sampleId": "t:PopVal",
    "sku": "t:OSSkuId",
    "TimestampDelta_19H1Subtract19H1Setup": "a:TimestampEpochString_19H1_Subtract_TimestampEpochString_19H1Setup",
    "TimestampDelta_20H1Subtract20H1Setup": "a:TimestampEpochString_20H1_Subtract_TimestampEpochString_20H1Setup"
  },
  "Fallback": {
    "r:AvastBlackScreen": "r:AvgBlackScreen",
    "a:Bios": "a:Bios_RS3",
    "a:Bios_RS3": "a:Bios_RS4",
    "a:Bios_RS4": "a:Bios_RS5",
    "r:BlockFeatureUpdates": "r:BlockWUUpgrades",
    "r:BlockWUUpgrades": "r:BlockWUUpgradesWow",
    "r:BuildFID": "r:BuildFID_WCOS",
    "r:BuildFID_WCOS": "r:BuildFID_WCOS2",
    "r:DchuAmdGrfxVen": "r:DchuAmdGrfxVen2",
    "r:DchuAmdGrfxVen2": "r:DchuAmdGrfxDeletePending",
    "r:DchuIntelGrfxVen": "r:DchuIntelGrfxVen2",
    "r:DchuIntelGrfxVen2": "r:DchuIntelGrfxDeletePending",
    "r:DchuNvidiaGrfxVen": "r:DchuNvidiaGrfxVen2",
    "r:DchuNvidiaGrfxVen2": "r:DchuNvidiaGrfxDeletePending",
    "r:DriverPartnerRing": "r:OSDataDriverPartnerRing",
    "p:DSS_Enrolled": "r:DSS_EnrolledReg",
    "r:EdgeWithChromiumInstallFailureCount": "r:EdgeWithChromiumInstallFailureCountWow",
    "r:EdgeWithChromiumInstallVersion": "r:EdgeWithChromiumInstallVersionWow",
    "u:EnableWUfBUpgradeGates": "r:EnableWUfBUpgradeGatesRS5",
    "f:FlightingBranchName": "c:FlightingBranchName",
    "a:Free": "a:Free_RS3",
    "a:Free_RS3": "a:Free_RS4",
    "a:Free_RS4": "a:Free_RS5",
    "HoloLens": "r:WindowsMixedReality",
    "r:IsEdgeWithChromiumInstalled": "r:IsEdgeWithChromiumInstalledWow",
    "a:ISVM": "a:ISVM_RS3",
    "a:ISVM_RS3": "a:ISVM_RS4",
    "a:ISVM_RS4": "a:ISVM_RS5",
    "c:OEMModelBaseBoard": "r:OEMModelBaseBoard",
    "r:PonchAllow": "r:PonchAllowKey",
    "r:PonchAllowKey": "r:PonchAllowWow",
    "r:PonchAllowWow": "r:PonchAllowWowKey",
    "r:QUDeadline": "r:QUDeadlineMDM",
    "v:SymantecVer": "v:SymantecVer64",
    "u:TargetReleaseVersion": "r:TargetReleaseVersionGP",
    "r:TargetReleaseVersionGP": "r:TargetReleaseVersionMDM",
    "v:TobiiVer": "v:TobiiVerx86",
    "v:TobiiVerx86": "v:TobiiVer1x86"
  },
  "Transform": {
    "IsDomainJoined": {
      "Ignore": [
        "0"
      ]
    },
    "IsHybridOrXGpu": {
      "Ignore": [
        "0"
      ]
    },
    "IsMsftOwned": {
      "Ignore": [
        "0"
      ]
    },
    "IsPortableOperatingSystem": {
      "Ignore": [
        "0"
      ]
    },
    "IsTestLab": {
      "Ignore": [
        "0"
      ]
    },
    "IsVM": {
      "Ignore": [
        "0"
      ]
    },
    "OEMModel": {
      "SubLength": 100
    },
    "OEMName_Uncleaned": {
      "SubLength": 100
    },
    "PausedFeatureStatus": {
      "Ignore": [
        "0"
      ]
    },
    "PausedQualityStatus": {
      "Ignore": [
        "0"
      ]
    },
    "SMode": {
      "Ignore": [
        "0"
      ]
    }
  },
  "Registry": {
    "ActiveHoursEnd": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\WindowsUpdate\\UX\\Settings",
      "ValueName": "ActiveHoursEnd",
      "RegValueType": "REG_DWORD"
    },
    "ActiveHoursStart": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\WindowsUpdate\\UX\\Settings",
      "ValueName": "ActiveHoursStart",
      "RegValueType": "REG_DWORD"
    },
    "AhnLabKeyboard": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\Mkd2kfNt",
      "ValueName": "NbTpMsExist"
    },
    "AppChannels": {
      "FullPath": "SOFTWARE\\Policies\\Microsoft\\WindowsStore\\Apps\\*",
      "ValueName": "ChannelId",
      "EncodingType": "Json"
    },
    "AppRMIDs": {
      "FullPath": "SOFTWARE\\Policies\\Microsoft\\WindowsStore\\Apps\\*",
      "ValueName": "ReleaseManagementId",
      "EncodingType": "Json"
    },
    "AutopilotUpdateInProgress": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Provisioning\\AutopilotSettings\\VolatileAutopilotUpdate",
      "ValueName": "AutopilotUpdateInProgress",
      "RegValueType": "REG_DWORD"
    },
    "AvastBlackScreen": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\aswVmm\\Parameters",
      "ValueName": "Win10-1803"
    },
    "AvastReg": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\aswVmm\\Parameters",
      "ValueName": "QualityCompat"
    },
    "AvgBlackScreen": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\avgVmm\\Parameters",
      "ValueName": "Win10-1803"
    },
    "AvgReg": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\avgVmm\\Parameters",
      "ValueName": "QualityCompat"
    },
    "BlockEdgeWithChromiumUpdate": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\EdgeUpdate",
      "ValueName": "DoNotUpdateToEdgeWithChromium",
      "RegValueType": "REG_DWORD"
    },
    "BlockFeatureUpdates": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\WindowsUpdate\\OSUpgrade",
      "ValueName": "BlockFeatureUpdates",
      "RegValueType": "REG_DWORD"
    },
    "BlockWUUpgrades": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows10Upgrader\\Volatile",
      "ValueName": "BlockWUUpgrades",
      "RegValueType": "REG_DWORD"
    },
    "BlockWUUpgradesWow": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\WOW6432Node\\Microsoft\\Windows10Upgrader\\Volatile",
      "ValueName": "BlockWUUpgrades",
      "RegValueType": "REG_DWORD"
    },
    "BuildFID": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "Software\\Microsoft\\Windows\\CurrentVersion\\Flighting\\Build",
      "ValueName": "EsdFlightData",
      "RegValueType": "REG_SZ"
    },
    "BuildFID_WCOS": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "OSDATA\\Software\\Microsoft\\Windows\\CurrentVersion\\Flighting\\Build",
      "ValueName": "EsdFlightData",
      "RegValueType": "REG_SZ"
    },
    "BuildFID_WCOS2": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "OSDATA\\Microsoft\\Windows\\CurrentVersion\\Flighting\\Build",
      "ValueName": "EsdFlightData",
      "RegValueType": "REG_SZ"
    },
    "CurrentBranch": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion",
      "ValueName": "BuildBranch",
      "RegValueType": "REG_SZ"
    },
    "DaysSince19H1FUOffer": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\rempl\\irplugin",
      "ValueName": "DaysSinceLastOffer",
      "RegValueType": "REG_QWORD"
    },
    "DchuAmdGrfxDeletePending": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\amdkmdap",
      "ValueName": "DriverDelete"
    },
    "DchuAmdGrfxExists": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\amdkmdap",
      "IfExists": true
    },
    "DchuAmdGrfxVen": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\amdkmdap",
      "ValueName": "DCHUVen"
    },
    "DchuAmdGrfxVen2": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\amdkmdap\\Parameters",
      "ValueName": "DCHUVen"
    },
    "DchuIntelGrfxDeletePending": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\igfx",
      "ValueName": "DriverDelete"
    },
    "DchuIntelGrfxExists": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\igfx",
      "IfExists": true
    },
    "DchuIntelGrfxVen": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\igfx",
      "ValueName": "DCHUVen"
    },
    "DchuIntelGrfxVen2": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\igfx\\Parameters",
      "ValueName": "DCHUVen"
    },
    "DchuNvidiaGrfxDeletePending": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\nvlddmkm",
      "ValueName": "DriverDelete"
    },
    "DchuNvidiaGrfxExists": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\nvlddmkm",
      "IfExists": true
    },
    "DchuNvidiaGrfxVen": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\nvlddmkm",
      "ValueName": "DCHUVen"
    },
    "DchuNvidiaGrfxVen2": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\nvlddmkm\\Parameters",
      "ValueName": "DCHUVen"
    },
    "DefaultUserRegion": {
      "HKey": "HKEY_USERS",
      "FullPath": ".DEFAULT\\Control Panel\\International\\Geo",
      "ValueName": "Nation",
      "RegValueType": "REG_SZ"
    },
    "DisableWUfBOfferBlock": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\WindowsUpdate\\UpdatePolicy\\Settings",
      "ValueName": "DisableWUfBOfferBlock",
      "RegValueType": "REG_DWORD"
    },
    "DisconnectedStandby": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SYSTEM\\CurrentControlSet\\Control\\Power",
      "ValueName": "EnforceDisconnectedStandby",
      "RegValueType": "REG_DWORD"
    },
    "DriverPartnerRing": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\DriverFlighting\\Partner",
      "ValueName": "TargetRing",
      "RegValueType": "REG_SZ"
    },
    "DSS_EnrolledReg": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Policies\\Microsoft\\Windows\\WindowsUpdate",
      "ValueName": "EnableWUfBCloud",
      "RegValueType": "REG_DWORD"
    },
    "DUInternal": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SYSTEM\\Setup\\MoSetup",
      "ValueName": "DynamicUpdateInternalTest",
      "RegValueType": "REG_DWORD"
    },
    "EdgeWithChromiumInstallFailureCount": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\EdgeUpdate",
      "ValueName": "WindowsUpdateAttempts"
    },
    "EdgeWithChromiumInstallFailureCountWow": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Wow6432Node\\Microsoft\\EdgeUpdate",
      "ValueName": "WindowsUpdateAttempts"
    },
    "EdgeWithChromiumInstallVersion": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\EdgeUpdate",
      "ValueName": "WindowsUpdateVersion"
    },
    "EdgeWithChromiumInstallVersionWow": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Wow6432Node\\Microsoft\\EdgeUpdate",
      "ValueName": "WindowsUpdateVersion"
    },
    "EKB19H2InstallCount": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SYSTEM\\Setup\\FeatureStaging\\20455539\\2",
      "ValueName": "Count"
    },
    "EKB19H2InstallTimeEpoch": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SYSTEM\\Setup\\FeatureStaging\\20455539\\2",
      "ValueName": "Timestamp"
    },
    "EKB19H2UnInstallCount": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SYSTEM\\Setup\\FeatureStaging\\20455539\\0",
      "ValueName": "Count"
    },
    "EKB19H2UnInstallTimeEpoch": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SYSTEM\\Setup\\FeatureStaging\\20455539\\0",
      "ValueName": "Timestamp"
    },
    "EnableWUfBUpgradeGatesRS5": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "Software\\Microsoft\\Windows NT\\CurrentVersion\\502505fe-762c-4e80-911e-0c3fa4c63fb0",
      "ValueName": "DataRequireGatedScanForFeatureUpdates",
      "RegValueType": "REG_DWORD"
    },
    "EsetReg": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\ehdrv\\Parameters",
      "ValueName": "WindowsCompatibilityLevel",
      "RegValueType": "REG_DWORD"
    },
    "FlightContent": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\WindowsSelfHost\\Applicability",
      "ValueName": "ContentType",
      "RegValueType": "REG_SZ"
    },
    "GStatusBlockIDs_All": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\Appraiser\\GWX",
      "ValueName": "SdbEntries",
      "RegValueType": "REG_SZ"
    },
    "HidOverGattReg": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\PnpLockdownFiles\\%SystemRoot%/System32/drivers/UMDF/Microsoft.Bluetooth.Profiles.HidOverGatt.dll",
      "ValueName": "Source",
      "RegValueType": "REG_SZ"
    },
    "InstallDate": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion",
      "ValueName": "InstallDate",
      "RegValueType": "REG_DWORD"
    },
    "IsAutopilotRegistered": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Provisioning\\AutopilotPolicyCache",
      "ValueName": "ProfileAvailable",
      "RegValueType": "REG_DWORD"
    },
    "IsFlightingEnabled": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\WindowsSelfHost\\Applicability",
      "ValueName": "IsBuildFlightingEnabled",
      "RegValueType": "REG_DWORD"
    },
    "IsContainerMgrInstalled": {
      "FullPath": "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Containers\\CmService",
      "IfExists": true
    },
    "IsEdgeWithChromiumInstalled": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\EdgeUpdate\\Clients\\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}",
      "IfExists": true
    },
    "IsEdgeWithChromiumInstalledWow": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Wow6432Node\\Microsoft\\EdgeUpdate\\Clients\\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}",
      "IfExists": true
    },
    "IsHybridOrXGpu": {
      "FullPath": "SOFTWARE\\Microsoft\\DirectX",
      "ValueName": "HybridDeviceApplicableForDxDbGpuPreferences"
    },
    "IsWDAGEnabled": {
      "FullPath": "SYSTEM\\ControlSet001\\Services\\hvsics",
      "IfExists": true
    },
    "IsWDATPEnabled": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows Advanced Threat Protection\\Status",
      "ValueName": "OnboardingState"
    },
    "KasperskyReg": {
      "FullPath": "System\\CurrentControlSet\\Services\\klhk\\Parameters",
      "ValueName": "UseVtHardware"
    },
    "KioskMode": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows\\AssignedAccessCsp\\AutoLogonAccount",
      "ValueName": "ConfigSource",
      "RegValueType": "REG_DWORD"
    },
    "MTPTargetingInfo": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SYSTEM\\Platform\\MTPTargetingInfo",
      "ValueName": "TargetRing"
    },
    "OEMModelBaseBoard": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "HARDWARE\\DESCRIPTION\\System\\BIOS",
      "ValueName": "BaseBoardProduct",
      "RegValueType": "REG_SZ"
    },
    "OemPartnerRing": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SYSTEM\\Platform\\DeviceTargetingInfo",
      "ValueName": "TargetRing",
      "RegValueType": "REG_SZ"
    },
    "OobeSeeker": {
      "FullPath": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\OOBE\\Updates",
      "ValueName": "OOBEUpdateStarted"
    },
    "OSDataDriverPartnerRing": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "OSData\\SOFTWARE\\Microsoft\\DriverFlighting\\Partner",
      "ValueName": "TargetRing",
      "RegValueType": "REG_SZ"
    },
    "OSRollbackBuild": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\WindowsUpdate\\OSUpgrade\\Rollback",
      "ValueName": "BuildString",
      "RegValueType": "REG_SZ"
    },
    "OSRollbackCount": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\WindowsUpdate\\OSUpgrade\\Rollback",
      "ValueName": "Count",
      "RegValueType": "REG_DWORD"
    },
    "OSRollbackDate": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\WindowsUpdate\\OSUpgrade\\Rollback",
      "ValueName": "DateStamp",
      "RegValueType": "REG_DWORD"
    },
    "PausedFeatureStatus": {
      "FullPath": "SOFTWARE\\Microsoft\\WindowsUpdate\\UpdatePolicy\\Settings",
      "ValueName": "PausedFeatureStatus"
    },
    "PausedQualityStatus": {
      "FullPath": "SOFTWARE\\Microsoft\\WindowsUpdate\\UpdatePolicy\\Settings",
      "ValueName": "PausedQualityStatus"
    },
    "PonchAllow": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\QualityCompat",
      "ValueName": "cadca5fe-87d3-4b96-b7fb-a231484277cc",
      "RegValueType": "REG_DWORD"
    },
    "PonchAllowKey": {
      "FullPath": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\QualityCompat\\cadca5fe-87d3-4b96-b7fb-a231484277cc",
      "IfExists": true
    },
    "PonchAllowWow": {
      "FullPath": "SOFTWARE\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\QualityCompat",
      "ValueName": "cadca5fe-87d3-4b96-b7fb-a231484277cc"
    },
    "PonchAllowWowKey": {
      "FullPath": "SOFTWARE\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\QualityCompat\\cadca5fe-87d3-4b96-b7fb-a231484277cc",
      "IfExists": true
    },
    "PonchBlock": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\QualityCompat",
      "ValueName": "65d75b03-6f4d-46e9-b870-517731e06cf9",
      "RegValueType": "REG_DWORD"
    },
    "PreviewBuildsManagerEnabled": {
      "FullPath": "SOFTWARE\\Microsoft\\WindowsSelfhost\\Manager",
      "ValueName": "ArePreviewBuildsAllowed"
    },
    "QUDeadline": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Policies\\Microsoft\\Windows\\WindowsUpdate",
      "ValueName": "ConfigureDeadlineForQualityUpdates",
      "RegValueType": "REG_DWORD"
    },
    "QUDeadlineMDM": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\PolicyManager\\current\\device\\Update",
      "ValueName": "ConfigureDeadlineForQualityUpdates",
      "RegValueType": "REG_DWORD"
    },
    "RecoveredFromBuild": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "Software\\Microsoft\\WindowsSelfHost\\Applicability\\RecoveredFrom",
      "ValueName": "LastBuild",
      "RegValueType": "REG_DWORD"
    },
    "RecoveredOnDate": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "Software\\Microsoft\\WindowsSelfHost\\Applicability\\RecoveredFrom",
      "ValueName": "DateStamp",
      "RegValueType": "REG_DWORD"
    },
    "ReleaseType": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Update\\TargetingInfo",
      "ValueName": "ReleaseType",
      "RegValueType": "REG_SZ"
    },
    "SmartActiveHoursState": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\WindowsUpdate\\UX\\Settings",
      "ValueName": "SmartActiveHoursState",
      "RegValueType": "REG_DWORD"
    },
    "Steam": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Classes\\Steam",
      "ValueName": "",
      "RegValueType": "REG_SZ"
    },
    "TargetReleaseVersionGP": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Policies\\Microsoft\\Windows\\WindowsUpdate",
      "ValueName": "TargetReleaseVersionInfo",
      "RegValueType": "REG_SZ"
    },
    "TargetReleaseVersionMDM": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\PolicyManager\\current\\device\\Update",
      "ValueName": "TargetReleaseVersion",
      "RegValueType": "REG_SZ"
    },
    "TencentReg": {
      "FullPath": "SYSTEM\\CurrentControlSet\\services\\TesSafe",
      "ValueName": "LoadStartTime"
    },
    "TencentType": {
      "FullPath": "SYSTEM\\CurrentControlSet\\services\\TesSafe",
      "ValueName": "Type"
    },
    "UHSEnrolled": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion",
      "ValueName": "UHSEnrolled",
      "RegValueType": "REG_SZ",
      "IfExists": true
    },
    "UninstallActive": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "System\\Setup",
      "ValueName": "UninstallActive",
      "RegValueType": "REG_DWORD"
    },
    "UpdateOfferedDays": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\WaaSAssessment\\Cache\\",
      "ValueName": "UpToDateDays",
      "RegValueType": "REG_DWORD"
    },
    "UpdatePreference": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Policies\\Microsoft\\Windows\\WindowsUpdate",
      "ValueName": "UpdatePreference",
      "RegValueType": "REG_DWORD"
    },
    "WindowsMixedReality": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\WUDF\\Services\\HoloLensSensors",
      "ValueName": "WdfMajorVersion",
      "RegValueType": "REG_DWORD"
    }
  },
  "FileInfo": {
    "AvastVer": {
      "Path": "\\system32\\Drivers\\aswVmm.sys",
      "FolderGuid": "{F38BF404-1D43-42F2-9305-67DE0B28FC23}"
    },
    "AvgVer": {
      "Path": "\\system32\\Drivers\\avgVmm.sys",
      "FolderGuid": "{F38BF404-1D43-42F2-9305-67DE0B28FC23}"
    },
    "CortanaAppVer": {
      "Path": "\\WindowsApps\\Microsoft.549981C3F5F10_8wekyb3d8bbwe\\CortanaApp.View.exe",
      "FolderGuid": "{905E63B6-C1BF-494E-B29C-65B732D3D21A}"
    },
    "CortanaAppVerTest": {
      "Path": "\\WindowsApps\\3242f7d9-db60-4380-a379-4205ea768bfc_1.0.0.0_x64__zs4v8rx04ex0m\\UndockingTestApp.exe",
      "FolderGuid": "{905E63B6-C1BF-494E-B29C-65B732D3D21A}"
    },
    "EsetVer": {
      "Path": "\\drivers\\ehdrv.sys",
      "FolderGuid": "{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}"
    },
    "KasperskyVer": {
      "Path": "\\system32\\Drivers\\klhk.sys",
      "FolderGuid": "{F38BF404-1D43-42F2-9305-67DE0B28FC23}"
    },
    "SkypeRoomSystem": {
      "Path": "%systemdrive%\\Recovery\\OEM\\$oem$\\$1\\Rigel\\x64\\Scripts\\Provisioning\\AutoUnattend.xml",
      "IfExists": true
    },
    "SymantecVer": {
      "Path": "\\Symantec\\Shared\\EENGINE\\eeCtrl.sys",
      "FolderGuid": "{DE974D24-D9C6-4D3E-BF91-F4455120B917}"
    },
    "SymantecVer64": {
      "Path": "\\Symantec\\Shared\\EENGINE\\eeCtrl64.sys",
      "FolderGuid": "{DE974D24-D9C6-4D3E-BF91-F4455120B917}"
    },
    "TobiiVer": {
      "Path": "\\Tobii\\Tobii EyeX Interaction\\Tobii.EyeX.Interaction.exe",
      "FolderGuid": "{905E63B6-C1BF-494E-B29C-65B732D3D21A}"
    },
    "TobiiVer1x86": {
      "Path": "\\Tobii\\tobii EyeX Interaction\\Tobii.EyeX.Interaction.exe",
      "FolderGuid": "{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}"
    },
    "TobiiVerx86": {
      "Path": "\\tobii EyeX Interaction\\Tobii.EyeX.Interaction.exe",
      "FolderGuid": "{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}"
    },
    "TrendMicroVer": {
      "Path": "\\drivers\\TMUMH.sys",
      "FolderGuid": "{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}"
    },
    "WuClientVer": {
      "Path": "\\system32\\wuaueng.dll",
      "FolderGuid": "{F38BF404-1D43-42F2-9305-67DE0B28FC23}"
    }
  },
  "Licensing": {
    "UpdateManagementGroup": {
      "Name": "UpdatePolicy-UpdateManagementGroup"
    }
  },
  "UpdatePolicy": {
    "BranchReadinessLevel": {
      "PolicyEnum": 5,
      "Enterprise": true
    },
    "BranchReadinessLevelSource": {
      "PolicyEnum": 5,
      "Enterprise": true,
      "UseSource": true
    },
    "DeferFeatureUpdatePeriodInDays": {
      "PolicyEnum": 9,
      "Enterprise": true
    },
    "DeferQualityUpdatePeriodInDays": {
      "PolicyEnum": 7,
      "Enterprise": true
    },
    "DisableDualScan": {
      "PolicyEnum": 42,
      "Enterprise": true
    },
    "EnableWUfBUpgradeGates": {
      "PolicyEnum": 51,
      "Enterprise": true
    },
    "TargetReleaseVersion": {
      "PolicyEnum": 50,
      "Enterprise": true
    },
    "UpdateServiceUrl": {
      "PolicyEnum": 12
    }
  },
  "Policy": {
    "DesiredOsVersion": {
      "LocUri": "./Device/Vendor/MSFT/DeviceUpdateCenter/DesiredUpdates/OsVersion"
    },
    "DesiredSystemManifestVersion": {
      "LocUri": "./Device/Vendor/MSFT/DeviceUpdateCenter/DesiredUpdates/SystemManifestVersion"
    },
    "DSS_Enrolled": {
      "Area": "Update",
      "Name": "EnableWUfBCloud"
    },
    "DucCustomPackageId": {
      "LocUri": "./Device/Vendor/MSFT/DeviceUpdateCenter/Enrollment/CustomPackageId"
    },
    "DucDeviceModelId": {
      "LocUri": "./Device/Vendor/MSFT/DeviceUpdateCenter/Enrollment/DeviceModelId"
    },
    "DucOemPartnerRing": {
      "LocUri": "./Device/Vendor/MSFT/DeviceUpdateCenter/Enrollment/OemPartnerRing"
    },
    "DucPublisherId": {
      "LocUri": "./Device/Vendor/MSFT/DeviceUpdateCenter/Enrollment/PublisherId"
    }
  }
}"
[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\AVAST Software]
[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvastBrowserUpdate.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\SystemCertificates\avast! Mail Scanner Cache]
[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\SystemCertificates\avast! Mail Scanner Trusted]
[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\SystemCertificates\avast! SSL Scanner Cache]
[HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\aswbIDSAgent]
"Path"=""C:\Program Files\AVAST Software\Avast\aswidsagent.exe""
[HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\aswbIDSAgent]
"Path.Org"=""C:\Program Files\AVAST Software\Avast\aswidsagent.exe""
[HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\aswbIDSAgent]
"Path.Win32"="C:\Program Files\AVAST Software\Avast\aswidsagent.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\avast]
[HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\avast]
"ServiceName"="avast"
[HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\avast]
"Path"=""C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe" /svc"
[HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\avast]
"Path.Org"=""C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe" /svc"
[HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\avast]
"Path.Win32"="C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\avast]
"DisplayName"="%1!s! Update Service (avast)"
[HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\avast! Antivirus]
[HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\avast! Antivirus]
"ServiceName"="avast! Antivirus"
[HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\avast! Antivirus]
"Path"=""C:\Program Files\AVAST Software\Avast\AvastSvc.exe""
[HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\avast! Antivirus]
"Path.Org"=""C:\Program Files\AVAST Software\Avast\AvastSvc.exe""
[HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\avast! Antivirus]
"Path.Win32"="C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\avast! Antivirus]
"DisplayName"="Avast Antivirus"
[HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\avastm]
[HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\avastm]
"ServiceName"="avastm"
[HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\avastm]
"Path"=""C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe" /medsvc"
[HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\avastm]
"Path.Org"=""C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe" /medsvc"
[HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\avastm]
"Path.Win32"="C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\avastm]
"DisplayName"="%1!s! Update Service (avastm)"
[HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\AvastSecureBrowserElevationService]
[HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\AvastSecureBrowserElevationService]
"ServiceName"="AvastSecureBrowserElevationService"
[HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\AvastSecureBrowserElevationService]
"Path"=""C:\Program Files (x86)\AVAST Software\Browser\Application\75.0.1447.80\elevation_service.exe""
[HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\AvastSecureBrowserElevationService]
"Path.Org"=""C:\Program Files (x86)\AVAST Software\Browser\Application\75.0.1447.80\elevation_service.exe""
[HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\AvastSecureBrowserElevationService]
"Path.Win32"="C:\Program Files (x86)\AVAST Software\Browser\Application\75.0.1447.80\elevation_service.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\AvastSecureBrowserElevationService]
"DisplayName"="Avast Secure Browser Elevation Service"
[HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\AvastWscReporter]
[HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\AvastWscReporter]
"ServiceName"="AvastWscReporter"
[HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\AvastWscReporter]
"Path"=""C:\Program Files\AVAST Software\Avast\wsc_proxy.exe" /runassvc"
[HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\AvastWscReporter]
"Path.Org"=""C:\Program Files\AVAST Software\Avast\wsc_proxy.exe" /runassvc"
[HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\AvastWscReporter]
"Path.Win32"="C:\Program Files\AVAST Software\Avast\wsc_proxy.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\AvastWscReporter]
"DisplayName"="AvastWscReporter"
[HKEY_USERS\.DEFAULT\Software\Avast Software]
[HKEY_USERS\.DEFAULT\Software\Avast Software]
"Last Stable Install Path"="C:\Program Files\AVAST Software\SZBrowser\"
[HKEY_USERS\.DEFAULT\Software\Avast Software\Avast]
[HKEY_USERS\.DEFAULT\Software\Avast Software\Avast Browser Cleanup]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\IntelliPoint\AppSpecific\AvastUI.exe]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\IntelliType Pro\AppSpecific\AvastUI.exe]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Avast Software]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\e5c97fd7_0]
""="{2}.\\?\hdaudio#func_01&ven_10ec&dev_0269&subsys_17aac022&rev_1002#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\singlelineouttopo/00010001|\Device\HarddiskVolume5\Program Files\AVAST Software\Avast\AvastUI.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\f3982c37_0]
""="{2}.\\?\hdaudio#func_01&ven_10ec&dev_0269&subsys_17aac022&rev_1002#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\singlelineouttopo/00010001|\Device\HarddiskVolume5\Program Files\AVAST Software\Avast\avastui.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Office\Outlook\Addins\avast.AsOutExt]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts]
"AvastHTML_.pdf"="0"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts]
"AvastHTML_https"="0"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts]
"AvastHTML_http"="0"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts]
"AvastHTML_.htm"="0"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts]
"AvastHTML_.html"="0"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts]
"AvastHTML_mailto"="0"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.avastlic]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.avastlic]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\Search\RecentApps\{B7862F08-B068-439C-8549-BBCE83F57707}]
"AppId"="avast! antivirus"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\Search\RecentApps\{B7862F08-B068-439C-8549-BBCE83F57707}]
"AppPath"="C:\Program Files\AVAST Software\Avast\AvastUI.exe"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Piriform\CCleaner]
"CookiesToSave"="*.avast.com|*.ccleaner.com|*.ccleanercloud.com|*.piriform.com|accounts.google.com|aol.com|facebook.com|google.com|login.live.com|mail.aol.com|my.screenname.aol.com|screenname.aol.com|twitter.com|www.google.com|yahoo.com"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\Avast Antivirus]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\Avast Antivirus\Avast Free Antivirus]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\Avast Antivirus\Avast Free Antivirus]
"DisplayName"="Avast Free Antivirus"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\Avast Antivirus\Avast Free Antivirus]
"UninstallString"="C:\Program Files\AVAST Software\Avast\Setup\Instup.exe /control_panel"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\Avast Antivirus\Avast Free Antivirus(1)]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\Avast Antivirus\Avast Free Antivirus(1)]
"DisplayName"="Avast Free Antivirus"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\Avast Antivirus\Avast Free Antivirus(1)]
"UninstallString"="C:\Program Files\AVAST Software\Avast\Setup\Instup.exe /control_panel"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\Avast Antivirus\Avast Free Antivirus(2)]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\Avast Antivirus\Avast Free Antivirus(2)]
"DisplayName"="Avast Free Antivirus"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\Avast Antivirus\Avast Free Antivirus(2)]
"UninstallString"="C:\Program Files\AVAST Software\Avast\Setup\Instup.exe /control_panel"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\Avast Antivirus\Avast Free Antivirus(3)]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\Avast Antivirus\Avast Free Antivirus(3)]
"DisplayName"="Avast Free Antivirus"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\Avast Antivirus\Avast Free Antivirus(3)]
"UninstallString"="C:\Program Files\AVAST Software\Avast\Setup\Instup.exe /control_panel"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\Avast Antivirus\Avast Free Antivirus(4)]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\Avast Antivirus\Avast Free Antivirus(4)]
"DisplayName"="Avast Free Antivirus"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\Avast Antivirus\Avast Free Antivirus(4)]
"UninstallString"="C:\Program Files\AVAST Software\Avast\Setup\Instup.exe /control_panel"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\Avast Antivirus\Avast Pro Antivirus]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\Avast Antivirus\Avast Pro Antivirus]
"DisplayName"="Avast Pro Antivirus"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\Avast Antivirus\Avast Pro Antivirus]
"UninstallString"="C:\Program Files\AVAST Software\Avast\Setup\Instup.exe /control_panel"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\Avast Antivirus\Avast Pro Antivirus(1)]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\Avast Antivirus\Avast Pro Antivirus(1)]
"DisplayName"="Avast Pro Antivirus"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\Avast Antivirus\Avast Pro Antivirus(1)]
"UninstallString"="C:\Program Files\AVAST Software\Avast\Setup\Instup.exe /control_panel"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\Avast Browser Cleanup]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\Avast Browser Cleanup\Avast Browser Cleanup]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\Avast Browser Cleanup\Avast Browser Cleanup]
"UninstallString"=""C:\Users\Jim\AppData\Roaming\AVAST Software\Browser Cleanup\browsercleanup.exe" /setup"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\Avast Browser Cleanup\Avast Browser Cleanup]
"DisplayName"="Avast Browser Cleanup"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\Avast Browser Cleanup\Avast Browser Cleanup(1)]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\Avast Browser Cleanup\Avast Browser Cleanup(1)]
"UninstallString"=""C:\Users\Jim\AppData\Roaming\AVAST Software\Browser Cleanup\browsercleanup.exe" /setup"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\Avast Browser Cleanup\Avast Browser Cleanup(1)]
"DisplayName"="Avast Browser Cleanup"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\Avast Browser Cleanup\Avast Browser Cleanup(2)]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\Avast Browser Cleanup\Avast Browser Cleanup(2)]
"UninstallString"=""C:\Users\Jim\AppData\Roaming\AVAST Software\Browser Cleanup\browsercleanup.exe" /setup"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\Avast Browser Cleanup\Avast Browser Cleanup(2)]
"DisplayName"="Avast Browser Cleanup"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\SafeZone 3.55.2393.609\Avast Free Antivirus]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\SafeZone 3.55.2393.609\Avast Free Antivirus]
"UninstallString"=""C:\Program Files\AVAST Software\SZBrowser\Launcher.exe" /uninstall"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\SafeZone 3.55.2393.609\Avast Free Antivirus(1)]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\SafeZone 3.55.2393.609\Avast Free Antivirus(1)]
"UninstallString"=""C:\Program Files\AVAST Software\SZBrowser\Launcher.exe" /uninstall"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\SafeZone 3.55.2393.609\Avast Free Antivirus(2)]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\SafeZone 3.55.2393.609\Avast Free Antivirus(2)]
"UninstallString"=""C:\Program Files\AVAST Software\SZBrowser\Launcher.exe" /uninstall"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\SafeZone 3.55.2393.609\Avast Free Antivirus(3)]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\SafeZone 3.55.2393.609\Avast Free Antivirus(3)]
"UninstallString"=""C:\Program Files\AVAST Software\SZBrowser\Launcher.exe" /uninstall"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\SafeZone 3.55.2393.609\Avast Free Antivirus(4)]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\SafeZone 3.55.2393.609\Avast Free Antivirus(4)]
"UninstallString"=""C:\Program Files\AVAST Software\SZBrowser\Launcher.exe" /uninstall"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\SafeZone 3.55.2393.609\Avast Pro Antivirus]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\SafeZone 3.55.2393.609\Avast Pro Antivirus]
"UninstallString"=""C:\Program Files\AVAST Software\SZBrowser\Launcher.exe" /uninstall"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\SafeZone 3.55.2393.609\Avast Pro Antivirus(1)]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\SafeZone 3.55.2393.609\Avast Pro Antivirus(1)]
"UninstallString"=""C:\Program Files\AVAST Software\SZBrowser\Launcher.exe" /uninstall"

===================== Search result for "McAfee" ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\PackageRepository\Packages\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\PackageRepository\Packages\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
"Path"="C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Data\3f6]
"PackageRelativeApplicationId"="McAfeeCentral"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Data\3f6]
"ApplicationUserModelId"="McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw!McAfeeCentral"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Data\3f6]
"_IndexKeys"="Package\8c8\3f6
PackageAndPackageRelativeApplicationId\8c8^McAfeeCentral"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Index\PackageAndPackageRelativeApplicationId\8c8^McAfeeCentral]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\ApplicationUser\Data\8e]
"ApplicationUserModelId"="McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw!McAfeeCentral"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\ApplicationUser\Data\8e]
"_IndexKeys"="Application\3f6\8e
UserAndApplication\1^3f6
UserAndApplicationUserModelId\1^McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw!McAfeeCentral\8e"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\ApplicationUser\Index\UserAndApplicationUserModelId\1^McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw!McAfeeCentral]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\8c8]
"PackageFullName"="McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\8c8]
"InstalledLocation"="C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\8c8]
"_IndexKeys"="PackageFamily\38\8c8
PackageFullName\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Index\PackageFullName\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageFamily\Data\38]
"PackageFamilyName"="McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageFamily\Data\38]
"_IndexKeys"="PackageFamilyName\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageFamily\Index\PackageFamilyName\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Applications\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Applications\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
"Path"="C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\AppxManifest.xml"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\S-1-5-21-1203430805-1345111560-1046767822-1002\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[HKEY_LOCAL_MACHINE\SYSTEM\Setup\Upgrade\Appx\Applications\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw]
[HKEY_LOCAL_MACHINE\SYSTEM\Setup\Upgrade\Appx\Applications\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[HKEY_LOCAL_MACHINE\SYSTEM\Setup\Upgrade\Appx\Applications\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
"Path"="C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\AppxManifest.xml"
[HKEY_LOCAL_MACHINE\SYSTEM\Setup\Upgrade\Appx\AppxAllUserStore\S-1-5-21-1203430805-1345111560-1046767822-1002\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[HKEY_LOCAL_MACHINE\SYSTEM\Setup\Upgrade\Appx\DownlevelGather\AppxAllUserStore\Applications\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[HKEY_LOCAL_MACHINE\SYSTEM\Setup\Upgrade\Appx\DownlevelGather\AppxAllUserStore\Applications\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
"Path"="C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\AppxManifest.xml"
[HKEY_LOCAL_MACHINE\SYSTEM\Setup\Upgrade\Appx\DownlevelGather\AppxAllUserStore\S-1-5-21-1203430805-1345111560-1046767822-1002\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[HKEY_LOCAL_MACHINE\SYSTEM\Setup\Upgrade\Appx\DownlevelGather\InstalledPackages\Main\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[HKEY_LOCAL_MACHINE\SYSTEM\Setup\Upgrade\Appx\DownlevelGather\PackageInstallState\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[HKEY_LOCAL_MACHINE\SYSTEM\Setup\Upgrade\Appx\DownlevelGather\S-1-5-21-1203430805-1345111560-1046767822-1002\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[HKEY_LOCAL_MACHINE\SYSTEM\Setup\Upgrade\Appx\DownlevelGather\SisDirectory\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CMcAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw%5Cresources.pri]
[HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CMcAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw%5Cresources.pri\1d3cb9132267590\a37dfe62]
"@{C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\resources.pri? ms-resource:///resources/AppName}"="McAfee Central"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\AppXBackupContentType\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_3.5.169.1_x64__bq6yxensn79aw]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\UserData\UninstallTimes]
"McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw"="0x8367D4902B23D601"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\Authentication\LogonUI\Notifications\BackgroundCapability\S-1-15-2-3278776214-1635354653-2314643131-251295766-804234917-407627331-3835975369\McAfeeCentral.AppXk7xg7tyv3z7a0jg74fpkz1sxrqje481a.mca]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\Authentication\LogonUI\Notifications\BackgroundCapability\S-1-15-2-3278776214-1635354653-2314643131-251295766-804234917-407627331-3835975369\McAfeeCentral.AppXk7xg7tyv3z7a0jg74fpkz1sxrqje481a.mca]
"AppUserModelId"="McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw!McAfeeCentral"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\Authentication\LogonUI\Notifications\BackgroundCapability\S-1-15-2-3278776214-1635354653-2314643131-251295766-804234917-407627331-3835975369\McAfeeCentral.AppXsdzk65mbvr9xjt93y1177j9q8jny7x90.mca]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\Authentication\LogonUI\Notifications\BackgroundCapability\S-1-15-2-3278776214-1635354653-2314643131-251295766-804234917-407627331-3835975369\McAfeeCentral.AppXsdzk65mbvr9xjt93y1177j9q8jny7x90.mca]
"AppUserModelId"="McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw!McAfeeCentral"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\PushNotifications\Backup\McAfee.McAgent]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\SettingSync\00034001B2142CBB\Registrar\Data\Registered\packagestate-mcafeeinc.06.mcafeesecurityadvisorforlenovo_bq6yxensn79aw-0]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\SettingSync\00034001B2142CBB\Registrar\Data\Registered\packagestate-mcafeeinc.06.mcafeesecurityadvisorforlenovo_bq6yxensn79aw-0]
"ChannelSettingsWLSSubscriptionUri"="https://bn1304.stora...-1802B0361B02)"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\SettingSync\Namespace\PackageState\mcafeeinc.06.mcafeesecurityadvisorforlenovo_bq6yxensn79aw-0]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\SettingSync\Namespace\WindowsPackageSettings\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\SettingSync\Namespace\WindowsPackageSettings\Notifications-McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\CollectionStaging\packagestate-mcafeeinc.06.mcafeesecurityadvisorforlenovo_bq6yxensn79aw-0]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\packagestate\mcafeeinc.06.mcafeesecurityadvisorforlenovo_bq6yxensn79aw-0]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\RemoteCollectionInfo\packagestate-mcafeeinc.06.mcafeesecurityadvisorforlenovo_bq6yxensn79aw-0]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\SettingSync\Telemetry\SaveKnowledgeLastSuccess]
"packagestate-mcafeeinc.06.mcafeesecurityadvisorforlenovo_bq6yxensn79aw-0"="0x127EA9CB57CAD501"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\Store\ContentId]
"McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw"="{93bb1f49-5e3d-4e00-475e-13116e443cba}"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\McAfee Security Scan]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\McAfee Security Scan\McAfee Security Scan Plus]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\McAfee Security Scan\McAfee Security Scan Plus]
"UninstallString"=""C:\Program Files\McAfee Security Scan\uninstall.exe""
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\McAfee Security Scan\McAfee Security Scan Plus]
"DisplayName"="McAfee Security Scan Plus"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\McAfee Security Scan\McAfee Security Scan Plus(1)]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\McAfee Security Scan\McAfee Security Scan Plus(1)]
"UninstallString"=""C:\Program Files\McAfee Security Scan\uninstall.exe""
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\McAfee Security Scan\McAfee Security Scan Plus(1)]
"DisplayName"="McAfee Security Scan Plus"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\MSC\McAfee LiveSafe]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\MSC\McAfee LiveSafe]
"UninstallString"="C:\Program Files\McAfee\MSC\mcuihost.exe /body:misp://MSCJsRes.dll::uninstall.html /id:uninstall"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\MSC\McAfee LiveSafe]
"DisplayName"="McAfee LiveSafe"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\MSC\McAfee LiveSafe(1)]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\MSC\McAfee LiveSafe(1)]
"UninstallString"="C:\Program Files\McAfee\MSC\mcuihost.exe /body:misp://MSCJsRes.dll::uninstall.html /id:uninstall"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\MSC\McAfee LiveSafe(1)]
"DisplayName"="McAfee LiveSafe"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\MSC\McAfee LiveSafe(2)]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\MSC\McAfee LiveSafe(2)]
"UninstallString"="C:\Program Files\McAfee\MSC\mcuihost.exe /body:misp://MSCJsRes.dll::uninstall.html /id:uninstall"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\MSC\McAfee LiveSafe(2)]
"DisplayName"="McAfee LiveSafe"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\MSC\McAfee LiveSafe(3)]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\MSC\McAfee LiveSafe(3)]
"UninstallString"="C:\Program Files\McAfee\MSC\mcuihost.exe /body:misp://MSCJsRes.dll::uninstall.html /id:uninstall"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\MSC\McAfee LiveSafe(3)]
"DisplayName"="McAfee LiveSafe"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\MSC\McAfee LiveSafe(4)]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\MSC\McAfee LiveSafe(4)]
"UninstallString"="C:\Program Files\McAfee\MSC\mcuihost.exe /body:misp://MSCJsRes.dll::uninstall.html /id:uninstall"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\MSC\McAfee LiveSafe(4)]
"DisplayName"="McAfee LiveSafe"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\MSC\McAfee LiveSafe(5)]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\MSC\McAfee LiveSafe(5)]
"UninstallString"="C:\Program Files\McAfee\MSC\mcuihost.exe /body:misp://MSCJsRes.dll::uninstall.html /id:uninstall"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\MSC\McAfee LiveSafe(5)]
"DisplayName"="McAfee LiveSafe"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee LiveSafe]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee LiveSafe]
"DisplayName"="McAfee WebAdvisor"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee LiveSafe]
"UninstallString"="C:\Program Files (x86)\McAfee\SiteAdvisor\Uninstall.exe"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee LiveSafe(1)]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee LiveSafe(1)]
"DisplayName"="McAfee WebAdvisor"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee LiveSafe(1)]
"UninstallString"="C:\Program Files (x86)\McAfee\SiteAdvisor\Uninstall.exe"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee LiveSafe(2)]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee LiveSafe(2)]
"DisplayName"="McAfee WebAdvisor"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee LiveSafe(2)]
"UninstallString"="C:\Program Files (x86)\McAfee\SiteAdvisor\Uninstall.exe"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee LiveSafe(3)]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee LiveSafe(3)]
"DisplayName"="McAfee WebAdvisor"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee LiveSafe(3)]
"UninstallString"="C:\Program Files (x86)\McAfee\SiteAdvisor\Uninstall.exe"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee LiveSafe(4)]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee LiveSafe(4)]
"DisplayName"="McAfee WebAdvisor"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee LiveSafe(4)]
"UninstallString"="C:\Program Files (x86)\McAfee\SiteAdvisor\Uninstall.exe"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee LiveSafe(5)]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee LiveSafe(5)]
"DisplayName"="McAfee WebAdvisor"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee LiveSafe(5)]
"UninstallString"="C:\Program Files (x86)\McAfee\SiteAdvisor\Uninstall.exe"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee WebAdvisor]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee WebAdvisor]
"DisplayName"="McAfee WebAdvisor"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee WebAdvisor]
"UninstallString"="C:\Program Files (x86)\McAfee\SiteAdvisor\Uninstall.exe"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee WebAdvisor(1)]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee WebAdvisor(1)]
"DisplayName"="McAfee WebAdvisor"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee WebAdvisor(1)]
"UninstallString"="C:\Program Files (x86)\McAfee\SiteAdvisor\Uninstall.exe"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CMcAfeeInc.06.McAfeeSecurityAdvisorforLenovo_4.5.141.1_x64__bq6yxensn79aw%5Cresources.pri]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CMcAfeeInc.06.McAfeeSecurityAdvisorforLenovo_4.5.141.1_x64__bq6yxensn79aw%5Cresources.pri\1d099d87f8e7520\2fa68a72]
"@{McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_4.5.141.1_x64__bq6yxensn79aw?ms-resource://McAfeeInc.06.McAfeeSecurityAdvisorforLenovo/resources/AppName}"="McAfee Central"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CMcAfeeInc.06.McAfeeSecurityAdvisorforLenovo_4.5.141.1_x64__bq6yxensn79aw%5Cresources.pri\1d099d87f8e7520\2fa68a72]
"@{McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_4.5.141.1_x64__bq6yxensn79aw?ms-resource://McAfeeInc.06.McAfeeSecurityAdvisorforLenovo/Files/images/win_store/McafeeSmallLogo.png}"="C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_4.5.141.1_x64__bq6yxensn79aw\images\win_store\McafeeSmallLogo.scale-100.png"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CMcAfeeInc.06.McAfeeSecurityAdvisorforLenovo_4.5.141.1_x64__bq6yxensn79aw%5Cresources.pri\1d099d87f8e7520\502b3ce7]
"@{McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_4.5.141.1_x64__bq6yxensn79aw?ms-resource://McAfeeInc.06.McAfeeSecurityAdvisorforLenovo/resources/AppName}"="McAfee Central"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CMcAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.110.1_x64__bq6yxensn79aw%5Cresources.pri]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CMcAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.110.1_x64__bq6yxensn79aw%5Cresources.pri\1d1320c841324d3\2fa68a72]
"@{McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.110.1_x64__bq6yxensn79aw?ms-resource://McAfeeInc.06.McAfeeSecurityAdvisorforLenovo/Files/images/win_store/McafeeSmallLogo.png}"="C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.110.1_x64__bq6yxensn79aw\images\win_store\McafeeSmallLogo.scale-100.png"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CMcAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.110.1_x64__bq6yxensn79aw%5Cresources.pri\1d1320c841324d3\2fa68a72]
"@{McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.110.1_x64__bq6yxensn79aw?ms-resource://McAfeeInc.06.McAfeeSecurityAdvisorforLenovo/resources/AppName}"="McAfee Central"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CMcAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.110.1_x64__bq6yxensn79aw%5Cresources.pri\1d1320c841324d3\502b3ce7]
"@{McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.110.1_x64__bq6yxensn79aw?ms-resource://McAfeeInc.06.McAfeeSecurityAdvisorforLenovo/resources/AppName}"="McAfee Central"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CMcAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.110.1_x64__bq6yxensn79aw%5Cresources.pri\1d1320c841324d3\502b3ce7]
"@{McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.110.1_x64__bq6yxensn79aw?ms-resource://McAfeeInc.06.McAfeeSecurityAdvisorforLenovo/Files/images/win_store/McafeeSmallLogo.png}"="C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.110.1_x64__bq6yxensn79aw\images\win_store\McafeeSmallLogo.scale-100.png"

====== End of Search ======

  • 0

#33
DR M

DR M

    The Grecian Geek

  • Malware Removal
  • 4,049 posts

Hi, Jim.

Was/Is this computer or some browsers ever Synced with other devices?

Was/Is Avast or McAfee installed on these devices?

If yes, please report back,

If no, please proceed to the following:


1. Backup the registry

  • Download Tweaking.com Registry Backup from here, and save tweaking.com_registry_backup_portable.zip to your desktop.
  • Now we need to create a new folder to extract the zipped contents into. Right click on the Desktop, choose New, then Folder and call the New Folder RegBackup.
  • Right click on the zip folder on the Desktop and select Extract all.
  • Click on Browse, and find the new created file on the Desktop (RegBackup). Choose Select folder and then Extract.
  • Double click on the RegBackup folder and find TweakingRegistryBackup. Double click it to start Tweaking.com Registry Backup.
  • From the screen that will appear, choose Backup Now.
  • If backup is successful, a message will appear at the lower half of the screen with an option to view logs.
  • Close Tweaking.com Registry Backup when done.

 

2. Restart in Safe mode

  • Press the Windows icon on the keyboard together with the letter I, to get into the Settings.
  • Choose Update and Security.
  • From the menu at the left, choose Recovery.
  • Under the title Advanced startup at the right, choose Restart now.
  • From the window that will appear choose Troubleshoot and then Advanced options.
  • Choose Startup Settings and then Restart.
  • Press number 5, for choosing Safe mode with networking.
  • You will know that you are in Safe mode, if the background is black and Safe mode is written at the four corners of the screen.

 

3. Run FRST fix

NOTICE: This script was written specifically for this user. Running it on another machine may cause damage to your operating system

  • Please select the entire contents of the code box below, from the "Start::" line to "End::", including both lines. Right-click and select "Copy ". No need to paste anything to anywhere.
Start::
CreateRestorePoint:
CloseProcesses:
C:\Windows\avastSS.scr
C:\Windows\WinSxS\Manifests\amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396.cat
C:\Windows\WinSxS\Manifests\amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396.manifest
C:\Windows\WinSxS\Manifests\amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5e69e83710ea31f5.cat
C:\Windows\WinSxS\Manifests\amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5e69e83710ea31f5.manifest
C:\Windows\WinSxS\Manifests\amd64_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_6349ea290dbe6128.cat
C:\Windows\WinSxS\Manifests\amd64_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_6349ea290dbe6128.manifest
C:\Windows\WinSxS\Manifests\amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5158632ac9d8192f.cat
C:\Windows\WinSxS\Manifests\amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5158632ac9d8192f.manifest
C:\Windows\WinSxS\Manifests\amd64_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_5638651cc6ac4862.cat
C:\Windows\WinSxS\Manifests\amd64_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_5638651cc6ac4862.manifest
C:\Windows\WinSxS\Manifests\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c.cat
C:\Windows\WinSxS\Manifests\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c.manifest
C:\Windows\WinSxS\Manifests\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_a6171f0e25665afb.cat
C:\Windows\WinSxS\Manifests\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_a6171f0e25665afb.manifest
C:\Windows\WinSxS\Manifests\x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_aaf72100223a8a2e.cat
C:\Windows\WinSxS\Manifests\x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_aaf72100223a8a2e.manifest
C:\Windows\WinSxS\Manifests\x86_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_b2556b4035446b41.cat
C:\Windows\WinSxS\Manifests\x86_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_b2556b4035446b41.manifest
C:\Windows\WinSxS\Manifests\x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_99059a01de544235.cat
C:\Windows\WinSxS\Manifests\x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_99059a01de544235.manifest
C:\Windows\WinSxS\Manifests\x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_9de59bf3db287168.cat
C:\Windows\WinSxS\Manifests\x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_9de59bf3db287168.manifest
C:\Windows\System32\Tasks_Migrated\Avast Emergency Update
C:\Windows\System32\Tasks_Migrated\Avast Secure Browser Heartbeat Task (Hourly)
C:\Windows\System32\Tasks_Migrated\Avast Secure Browser Heartbeat Task (Logon)
C:\Windows\System32\Tasks_Migrated\AvastUpdateTaskMachineCore
C:\Windows\System32\Tasks_Migrated\AvastUpdateTaskMachineUA
C:\Windows\System32\Tasks_Migrated\AVAST Software\Avast settings backup
C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396.cat
C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396.manifest
C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5e69e83710ea31f5.cat
C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5e69e83710ea31f5.manifest
C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_6349ea290dbe6128.cat
C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_6349ea290dbe6128.manifest
C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5158632ac9d8192f.cat
C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5158632ac9d8192f.manifest
C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_5638651cc6ac4862.cat
C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_5638651cc6ac4862.manifest
C:\Users\Jim\SkyDrive\Pictures\Documents\avast (2).lnk
C:\Users\Jim\SkyDrive\Pictures\Documents\Avast Password Manager.lnk
C:\Users\Jim\SkyDrive\Pictures\Documents\Avast Secure Browser.lnk
C:\Users\Jim\SkyDrive\Pictures\Documents\avast! Antivirus
C:\Users\Jim\SkyDrive\Pictures\Documents\avast-logo-opt-in.png
C:\Users\Jim\SkyDrive\Pictures\Documents\avast.lnk
C:\Users\Jim\SkyDrive\Pictures\Documents\avast.search-ms
C:\Users\Jim\SkyDrive\Pictures\Documents\Avastbackend.txt
C:\Users\Jim\SkyDrive\Pictures\Documents\avastclear.exe
C:\Users\Jim\SkyDrive\Pictures\Documents\avastclear.exe.fhvb1vu.partial
C:\Users\Jim\SkyDrive\Pictures\Documents\avastSS.scr
C:\Users\Jim\SkyDrive\Pictures\Documents\avast_free_antivirus_setup_online.exe
C:\Users\Jim\SkyDrive\Pictures\Documents\avast_pam
C:\Users\Jim\SkyDrive\Pictures\Documents\license.avastlic.lnk
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c.cat
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c.manifest
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_a6171f0e25665afb.cat
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_a6171f0e25665afb.manifest
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_aaf72100223a8a2e.cat
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_aaf72100223a8a2e.manifest
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_b2556b4035446b41.cat
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_b2556b4035446b41.manifest
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_99059a01de544235.cat
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_99059a01de544235.manifest
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_9de59bf3db287168.cat
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_9de59bf3db287168.manifest
C:\Users\Jim\SkyDrive\Pictures\Documents\AVAST Software\Avastbackend.txt
C:\Users\Jim\Searches\avast.search-ms
C:\Users\Jim\Links\avast (2).lnk
C:\Users\Jim\Links\avast.lnk
C:\Users\Jim\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Avast Secure Browser.lnk
C:\ProgramData\Microsoft\Windows\AppRepository\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_4.5.141.1_x64__bq6yxensn79aw.xml
C:\ProgramData\Microsoft\Windows\AppRepository\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw.xml
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw
C:\FRST\Quarantine\C\WINDOWS\System32\Tasks\AVAST Software
C:\FRST\Quarantine\C\Users\Jim\Downloads\avast_free_antivirus_setup_online.exe.xBAD
C:\AVAST Software
C:\Windows\WinSxS\amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396
C:\Windows\WinSxS\amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5e69e83710ea31f5
C:\Windows\WinSxS\amd64_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_6349ea290dbe6128
C:\Windows\WinSxS\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c
C:\Windows\WinSxS\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_a6171f0e25665afb
C:\Windows\WinSxS\x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_aaf72100223a8a2e
C:\Windows\System32\Tasks_Migrated\AVAST Software
C:\Windows\System32\Tasks\AVAST Software
C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396
C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5e69e83710ea31f5
C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_6349ea290dbe6128
C:\Users\Jim\SkyDrive\Pictures\Documents\Avast
C:\Users\Jim\SkyDrive\Pictures\Documents\AVAST Software
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_a6171f0e25665afb
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_aaf72100223a8a2e
C:\Users\Jim\SkyDrive\Pictures\Documents\_avast_
C:\Users\Jim\SkyDrive\Pictures\Documents\AVAST Software\Avast
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Browser Cleanup
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Browser Cleanup(1)
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Browser Cleanup(2)
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Free Antivirus
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Free Antivirus(1)
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Free Antivirus(2)
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Free Antivirus(3)
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Free Antivirus(4)
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Pro Antivirus
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Pro Antivirus(1)
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee LiveSafe
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee LiveSafe(1)
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee LiveSafe(2)
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee LiveSafe(3)
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee LiveSafe(4)
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee LiveSafe(5)
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee Security Scan Plus
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee Security Scan Plus(1)
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee WebAdvisor
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee WebAdvisor(1)
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\Avast-14052020-134203
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\Avast-14052020-134250
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\Avast-14052020-134720
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\Avast-14052020-135743
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\Avast-14052020-135752
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\Avast-20052020-151429
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\Avast-20052020-154404
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\Avast-23052020-182559
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\McAfee-14052020-133905
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\McAfee-14052020-140130
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\McAfee-14052020-140151
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\McAfee-14052020-140240
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\McAfee-14052020-140248
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\McAfee-14052020-140332
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\McAfee-14052020-140342
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\McAfee-14052020-140435
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\McAfee-14052020-140529
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw
C:\FRST\Quarantine\C\WINDOWS\System32\Tasks\AVAST Software
C:\AVAST Software\Avast

StartRegedit:
Windows Registry Editor Version 5.00

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\AvastGUIProxy.DLL]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{5020EF2C-60F4-47BE-8918-A167229B11EE}]
""=-
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\Av\{8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\Av\{EB19B86E-3998-C706-90EF-92B41EB091AF}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\avast! Mail Scanner Cache]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\avast! Mail Scanner Trusted]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\avast! SSL Scanner Cache]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]
"AvastUI.exe"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32]
"AvastUI.exe"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_5ca6eb17137337f1"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_4f95660acc611f2b"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"amd64_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_547567fcc9354e5e"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"amd64_avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_6186ed0910476724"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_a45421ee27ef60f7"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_a93423e024c3902a"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_b2556b4035446b41"="-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_97429ce1e0dd4831"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_9c229ed3ddb17764"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_a6171f0e25665afb"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5e69e83710ea31f5"="-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_aaf72100223a8a2e"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"amd64_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_6349ea290dbe6128"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_99059a01de544235"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5158632ac9d8192f"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_9de59bf3db287168"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"amd64_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_5638651cc6ac4862"=-
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_avast.vc110.crt_2036b14a11e83e4a_none_c373722873c01144]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_avast.vc140.crt_fcc99ee6193ebbca_none_020285fe6d6e0580]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_avast.vc140.mfc_fcc99ee6193ebbca_none_018be6966dc83925]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_none_ef17e13d91c55d96]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_none_eea141d5921f913b]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_avast.vc110.crt_2036b14a11e83e4a_none_0b20a8ff883c3a4a]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_avast.vc140.crt_fcc99ee6193ebbca_none_49afbcd581ea2e86]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_avast.vc140.mfc_fcc99ee6193ebbca_none_49391d6d8244622b]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_none_5679bb9c25dbf18d]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_none_36c51814a641869c]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_none_364e78aca69bba41]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvastBrowserUpdate.exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\AVAST Software]
[-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvastBrowserUpdate.exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\SystemCertificates\avast! Mail Scanner Cache]
[-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\SystemCertificates\avast! Mail Scanner Trusted]
[-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\SystemCertificates\avast! SSL Scanner Cache]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\aswbIDSAgent]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\avast]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\avast! Antivirus]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\avastm]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\AvastSecureBrowserElevationService]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\AvastWscReporter]
[-HKEY_USERS\.DEFAULT\Software\Avast Software]
[-HKEY_USERS\.DEFAULT\Software\Avast Software\Avast Browser Cleanup]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\IntelliPoint\AppSpecific\AvastUI.exe]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\IntelliType Pro\AppSpecific\AvastUI.exe]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Avast Software]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\e5c97fd7_0]
""=-
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\f3982c37_0]
""="-
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Office\Outlook\Addins\avast.AsOutExt]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts]
"AvastHTML_.pdf"=-
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts]
"AvastHTML_https"=-
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts]
"AvastHTML_http"=-
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts]
"AvastHTML_.htm"=-
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts]
"AvastHTML_.html"=-
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts]
"AvastHTML_mailto"=-
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.avastlic]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.avastlic]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\Search\RecentApps\{B7862F08-B068-439C-8549-BBCE83F57707}]
"AppId"=-
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\Search\RecentApps\{B7862F08-B068-439C-8549-BBCE83F57707}]
"AppPath"=-
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Piriform\CCleaner]
"CookiesToSave"=-
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\Avast Antivirus]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\Avast Browser Cleanup]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\SafeZone 3.55.2393.609\Avast Free Antivirus]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\PackageRepository\Packages\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Data\3f6]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Index\PackageAndPackageRelativeApplicationId\8c8^McAfeeCentral]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\ApplicationUser\Data\8e]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\ApplicationUser\Index\UserAndApplicationUserModelId\1^McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw!McAfeeCentral]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\8c8]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Index\PackageFullName\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageFamily\Data\38]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageFamily\Index\PackageFamilyName\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Applications\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\S-1-5-21-1203430805-1345111560-1046767822-1002\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\Upgrade\Appx\Applications\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\Upgrade\Appx\AppxAllUserStore\S-1-5-21-1203430805-1345111560-1046767822-1002\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\Upgrade\Appx\DownlevelGather\AppxAllUserStore\Applications\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\Upgrade\Appx\DownlevelGather\AppxAllUserStore\S-1-5-21-1203430805-1345111560-1046767822-1002\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\Upgrade\Appx\DownlevelGather\InstalledPackages\Main\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\Upgrade\Appx\DownlevelGather\PackageInstallState\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\Upgrade\Appx\DownlevelGather\S-1-5-21-1203430805-1345111560-1046767822-1002\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\Upgrade\Appx\DownlevelGather\SisDirectory\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[-HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CMcAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw%5Cresources.pri]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\AppXBackupContentType\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_3.5.169.1_x64__bq6yxensn79aw]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\UserData\UninstallTimes]
"McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw"=-
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\Authentication\LogonUI\Notifications\BackgroundCapability\S-1-15-2-3278776214-1635354653-2314643131-251295766-804234917-407627331-3835975369\McAfeeCentral.AppXk7xg7tyv3z7a0jg74fpkz1sxrqje481a.mca]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\Authentication\LogonUI\Notifications\BackgroundCapability\S-1-15-2-3278776214-1635354653-2314643131-251295766-804234917-407627331-3835975369\McAfeeCentral.AppXsdzk65mbvr9xjt93y1177j9q8jny7x90.mca]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\PushNotifications\Backup\McAfee.McAgent]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\SettingSync\00034001B2142CBB\Registrar\Data\Registered\packagestate-mcafeeinc.06.mcafeesecurityadvisorforlenovo_bq6yxensn79aw-0]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\SettingSync\00034001B2142CBB\Registrar\Data\Registered\packagestate-mcafeeinc.06.mcafeesecurityadvisorforlenovo_bq6yxensn79aw-0]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\SettingSync\Namespace\PackageState\mcafeeinc.06.mcafeesecurityadvisorforlenovo_bq6yxensn79aw-0]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\SettingSync\Namespace\WindowsPackageSettings\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\SettingSync\Namespace\WindowsPackageSettings\Notifications-McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\CollectionStaging\packagestate-mcafeeinc.06.mcafeesecurityadvisorforlenovo_bq6yxensn79aw-0]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\packagestate\mcafeeinc.06.mcafeesecurityadvisorforlenovo_bq6yxensn79aw-0]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\RemoteCollectionInfo\packagestate-mcafeeinc.06.mcafeesecurityadvisorforlenovo_bq6yxensn79aw-0]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\SettingSync\Telemetry\SaveKnowledgeLastSuccess]
"packagestate-mcafeeinc.06.mcafeesecurityadvisorforlenovo_bq6yxensn79aw-0"=-
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\Store\ContentId]
"McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw"=-
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\McAfee Security Scan]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\MSC\McAfee LiveSafe]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\MSC\McAfee LiveSafe(1)]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\MSC\McAfee LiveSafe(2)]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\MSC\McAfee LiveSafe(3)]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\MSC\McAfee LiveSafe(4)]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\MSC\McAfee LiveSafe(5)]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee LiveSafe]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee LiveSafe(1)]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee LiveSafe(2)]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee LiveSafe(3)]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee LiveSafe(4)]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee LiveSafe(5)]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee WebAdvisor]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee WebAdvisor(1)]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CMcAfeeInc.06.McAfeeSecurityAdvisorforLenovo_4.5.141.1_x64__bq6yxensn79aw%5Cresources.pri]
Endregedit:
EmptyTemp:
End::
  • Please right-click on FRST64 on your Desktop, to run it as administrator. When the tool opens, click "yes" to the disclaimer.
  • Press the Fix button once and wait.
  • FRST will process fixlist.txt
  • When finished, it will produce a log fixlog.txt on your Desktop.
  • Please post the log in your next reply.

 

4. How is the computer now? Any specific issue?


 


  • 0

#34
JimBow

JimBow

    Member

  • Topic Starter
  • Member
  • PipPip
  • 88 posts

Looks like you've been quite busy. Thank you. 

 

This computer and browsers have not been synced with any other devices. Avast was my primary anti-virus software program on this computer until it became corrupted in late April. As you know, I uninstalled it replaced it with Malwarebytes. I think McAfee came preloaded on this computer and was offered as a trial but I never activated it. I do not like McAfee products and have had trouble with them in the past.

 

Since I have a positive answer to your question about Avast, I assume you don't want me to proceed yet with the procedures you just sent.

 

I should also let you know that I have been having difficulty with Start-up for the past few days. The first incidence was that the computer would not proceed past the Windows-provided screen saver image during my morning start-up. I did a hard restart and it opened normally, but slowly. The next morning it opened to a screen full of gibberish several times, then finally started fine after a few hard restarts. This morning it would not open beyond the Lenovo logo for three tries until I let it rest for several minutes after the third hard restart, then it opened normally. Any ideas?


  • 0

#35
DR M

DR M

    The Grecian Geek

  • Malware Removal
  • 4,049 posts

 

Since I have a positive answer to your question about Avast, I assume you don't want me to proceed yet with the procedures you just sent.

 

Hi, Jim.

 

Actually your answer is negative: no synced with other devices. So you can proceed to the next steps. At least we can get rid of those remnants and then check if something else occurs.


  • 0

#36
JimBow

JimBow

    Member

  • Topic Starter
  • Member
  • PipPip
  • 88 posts

Thank you for the quick response. It looks like most of the fixes worked. In a quick scan of the log I see a few results of "not found" and "access denied." Here is the Fix Log. I really appreciate all that you are doing.

Jim

 

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 24-05-2020 01
Ran by Jim (25-05-2020 14:21:30) Run:4
Running from C:\Users\Jim\Desktop
Loaded Profiles: Jim
Boot Mode: Safe Mode (with Networking)
==============================================
fixlist content:
*****************
CreateRestorePoint:
CloseProcesses:
C:\Windows\avastSS.scr
C:\Windows\WinSxS\Manifests\amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396.cat
C:\Windows\WinSxS\Manifests\amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396.manifest
C:\Windows\WinSxS\Manifests\amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5e69e83710ea31f5.cat
C:\Windows\WinSxS\Manifests\amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5e69e83710ea31f5.manifest
C:\Windows\WinSxS\Manifests\amd64_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_6349ea290dbe6128.cat
C:\Windows\WinSxS\Manifests\amd64_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_6349ea290dbe6128.manifest
C:\Windows\WinSxS\Manifests\amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5158632ac9d8192f.cat
C:\Windows\WinSxS\Manifests\amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5158632ac9d8192f.manifest
C:\Windows\WinSxS\Manifests\amd64_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_5638651cc6ac4862.cat
C:\Windows\WinSxS\Manifests\amd64_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_5638651cc6ac4862.manifest
C:\Windows\WinSxS\Manifests\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c.cat
C:\Windows\WinSxS\Manifests\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c.manifest
C:\Windows\WinSxS\Manifests\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_a6171f0e25665afb.cat
C:\Windows\WinSxS\Manifests\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_a6171f0e25665afb.manifest
C:\Windows\WinSxS\Manifests\x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_aaf72100223a8a2e.cat
C:\Windows\WinSxS\Manifests\x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_aaf72100223a8a2e.manifest
C:\Windows\WinSxS\Manifests\x86_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_b2556b4035446b41.cat
C:\Windows\WinSxS\Manifests\x86_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_b2556b4035446b41.manifest
C:\Windows\WinSxS\Manifests\x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_99059a01de544235.cat
C:\Windows\WinSxS\Manifests\x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_99059a01de544235.manifest
C:\Windows\WinSxS\Manifests\x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_9de59bf3db287168.cat
C:\Windows\WinSxS\Manifests\x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_9de59bf3db287168.manifest
C:\Windows\System32\Tasks_Migrated\Avast Emergency Update
C:\Windows\System32\Tasks_Migrated\Avast Secure Browser Heartbeat Task (Hourly)
C:\Windows\System32\Tasks_Migrated\Avast Secure Browser Heartbeat Task (Logon)
C:\Windows\System32\Tasks_Migrated\AvastUpdateTaskMachineCore
C:\Windows\System32\Tasks_Migrated\AvastUpdateTaskMachineUA
C:\Windows\System32\Tasks_Migrated\AVAST Software\Avast settings backup
C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396.cat
C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396.manifest
C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5e69e83710ea31f5.cat
C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5e69e83710ea31f5.manifest
C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_6349ea290dbe6128.cat
C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_6349ea290dbe6128.manifest
C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5158632ac9d8192f.cat
C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5158632ac9d8192f.manifest
C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_5638651cc6ac4862.cat
C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_5638651cc6ac4862.manifest
C:\Users\Jim\SkyDrive\Pictures\Documents\avast (2).lnk
C:\Users\Jim\SkyDrive\Pictures\Documents\Avast Password Manager.lnk
C:\Users\Jim\SkyDrive\Pictures\Documents\Avast Secure Browser.lnk
C:\Users\Jim\SkyDrive\Pictures\Documents\avast! Antivirus
C:\Users\Jim\SkyDrive\Pictures\Documents\avast-logo-opt-in.png
C:\Users\Jim\SkyDrive\Pictures\Documents\avast.lnk
C:\Users\Jim\SkyDrive\Pictures\Documents\avast.search-ms
C:\Users\Jim\SkyDrive\Pictures\Documents\Avastbackend.txt
C:\Users\Jim\SkyDrive\Pictures\Documents\avastclear.exe
C:\Users\Jim\SkyDrive\Pictures\Documents\avastclear.exe.fhvb1vu.partial
C:\Users\Jim\SkyDrive\Pictures\Documents\avastSS.scr
C:\Users\Jim\SkyDrive\Pictures\Documents\avast_free_antivirus_setup_online.exe
C:\Users\Jim\SkyDrive\Pictures\Documents\avast_pam
C:\Users\Jim\SkyDrive\Pictures\Documents\license.avastlic.lnk
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c.cat
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c.manifest
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_a6171f0e25665afb.cat
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_a6171f0e25665afb.manifest
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_aaf72100223a8a2e.cat
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_aaf72100223a8a2e.manifest
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_b2556b4035446b41.cat
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_b2556b4035446b41.manifest
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_99059a01de544235.cat
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_99059a01de544235.manifest
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_9de59bf3db287168.cat
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_9de59bf3db287168.manifest
C:\Users\Jim\SkyDrive\Pictures\Documents\AVAST Software\Avastbackend.txt
C:\Users\Jim\Searches\avast.search-ms
C:\Users\Jim\Links\avast (2).lnk
C:\Users\Jim\Links\avast.lnk
C:\Users\Jim\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Avast Secure Browser.lnk
C:\ProgramData\Microsoft\Windows\AppRepository\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_4.5.141.1_x64__bq6yxensn79aw.xml
C:\ProgramData\Microsoft\Windows\AppRepository\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw.xml
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw
C:\FRST\Quarantine\C\WINDOWS\System32\Tasks\AVAST Software
C:\FRST\Quarantine\C\Users\Jim\Downloads\avast_free_antivirus_setup_online.exe.xBAD
C:\AVAST Software
C:\Windows\WinSxS\amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396
C:\Windows\WinSxS\amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5e69e83710ea31f5
C:\Windows\WinSxS\amd64_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_6349ea290dbe6128
C:\Windows\WinSxS\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c
C:\Windows\WinSxS\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_a6171f0e25665afb
C:\Windows\WinSxS\x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_aaf72100223a8a2e
C:\Windows\System32\Tasks_Migrated\AVAST Software
C:\Windows\System32\Tasks\AVAST Software
C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396
C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5e69e83710ea31f5
C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_6349ea290dbe6128
C:\Users\Jim\SkyDrive\Pictures\Documents\Avast
C:\Users\Jim\SkyDrive\Pictures\Documents\AVAST Software
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_a6171f0e25665afb
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_aaf72100223a8a2e
C:\Users\Jim\SkyDrive\Pictures\Documents\_avast_
C:\Users\Jim\SkyDrive\Pictures\Documents\AVAST Software\Avast
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Browser Cleanup
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Browser Cleanup(1)
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Browser Cleanup(2)
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Free Antivirus
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Free Antivirus(1)
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Free Antivirus(2)
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Free Antivirus(3)
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Free Antivirus(4)
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Pro Antivirus
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Pro Antivirus(1)
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee LiveSafe
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee LiveSafe(1)
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee LiveSafe(2)
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee LiveSafe(3)
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee LiveSafe(4)
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee LiveSafe(5)
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee Security Scan Plus
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee Security Scan Plus(1)
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee WebAdvisor
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee WebAdvisor(1)
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\Avast-14052020-134203
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\Avast-14052020-134250
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\Avast-14052020-134720
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\Avast-14052020-135743
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\Avast-14052020-135752
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\Avast-20052020-151429
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\Avast-20052020-154404
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\Avast-23052020-182559
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\McAfee-14052020-133905
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\McAfee-14052020-140130
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\McAfee-14052020-140151
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\McAfee-14052020-140240
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\McAfee-14052020-140248
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\McAfee-14052020-140332
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\McAfee-14052020-140342
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\McAfee-14052020-140435
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\McAfee-14052020-140529
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw
C:\FRST\Quarantine\C\WINDOWS\System32\Tasks\AVAST Software
C:\AVAST Software\Avast
StartRegedit:
Windows Registry Editor Version 5.00
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\AvastGUIProxy.DLL]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{5020EF2C-60F4-47BE-8918-A167229B11EE}]
""=-
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\Av\{8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\Av\{EB19B86E-3998-C706-90EF-92B41EB091AF}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\avast! Mail Scanner Cache]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\avast! Mail Scanner Trusted]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\avast! SSL Scanner Cache]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]
"AvastUI.exe"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32]
"AvastUI.exe"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_5ca6eb17137337f1"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_4f95660acc611f2b"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"amd64_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_547567fcc9354e5e"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"amd64_avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_6186ed0910476724"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_a45421ee27ef60f7"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_a93423e024c3902a"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_b2556b4035446b41"="-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_97429ce1e0dd4831"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_9c229ed3ddb17764"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_a6171f0e25665afb"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5e69e83710ea31f5"="-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_aaf72100223a8a2e"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"amd64_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_6349ea290dbe6128"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_99059a01de544235"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5158632ac9d8192f"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_9de59bf3db287168"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"amd64_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_5638651cc6ac4862"=-
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_avast.vc110.crt_2036b14a11e83e4a_none_c373722873c01144]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_avast.vc140.crt_fcc99ee6193ebbca_none_020285fe6d6e0580]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_avast.vc140.mfc_fcc99ee6193ebbca_none_018be6966dc83925]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_none_ef17e13d91c55d96]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_none_eea141d5921f913b]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_avast.vc110.crt_2036b14a11e83e4a_none_0b20a8ff883c3a4a]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_avast.vc140.crt_fcc99ee6193ebbca_none_49afbcd581ea2e86]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_avast.vc140.mfc_fcc99ee6193ebbca_none_49391d6d8244622b]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_none_5679bb9c25dbf18d]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_none_36c51814a641869c]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_none_364e78aca69bba41]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvastBrowserUpdate.exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\AVAST Software]
[-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvastBrowserUpdate.exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\SystemCertificates\avast! Mail Scanner Cache]
[-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\SystemCertificates\avast! Mail Scanner Trusted]
[-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\SystemCertificates\avast! SSL Scanner Cache]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\aswbIDSAgent]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\avast]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\avast! Antivirus]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\avastm]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\AvastSecureBrowserElevationService]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\AvastWscReporter]
[-HKEY_USERS\.DEFAULT\Software\Avast Software]
[-HKEY_USERS\.DEFAULT\Software\Avast Software\Avast Browser Cleanup]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\IntelliPoint\AppSpecific\AvastUI.exe]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\IntelliType Pro\AppSpecific\AvastUI.exe]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Avast Software]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\e5c97fd7_0]
""=-
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\f3982c37_0]
""="-
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Office\Outlook\Addins\avast.AsOutExt]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts]
"AvastHTML_.pdf"=-
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts]
"AvastHTML_https"=-
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts]
"AvastHTML_http"=-
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts]
"AvastHTML_.htm"=-
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts]
"AvastHTML_.html"=-
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts]
"AvastHTML_mailto"=-
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.avastlic]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.avastlic]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\Search\RecentApps\{B7862F08-B068-439C-8549-BBCE83F57707}]
"AppId"=-
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\Search\RecentApps\{B7862F08-B068-439C-8549-BBCE83F57707}]
"AppPath"=-
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Piriform\CCleaner]
"CookiesToSave"=-
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\Avast Antivirus]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\Avast Browser Cleanup]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\SafeZone 3.55.2393.609\Avast Free Antivirus]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\PackageRepository\Packages\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Data\3f6]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Index\PackageAndPackageRelativeApplicationId\8c8^McAfeeCentral]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\ApplicationUser\Data\8e]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\ApplicationUser\Index\UserAndApplicationUserModelId\1^McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw!McAfeeCentral]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\8c8]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Index\PackageFullName\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageFamily\Data\38]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageFamily\Index\PackageFamilyName\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Applications\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\S-1-5-21-1203430805-1345111560-1046767822-1002\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\Upgrade\Appx\Applications\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\Upgrade\Appx\AppxAllUserStore\S-1-5-21-1203430805-1345111560-1046767822-1002\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\Upgrade\Appx\DownlevelGather\AppxAllUserStore\Applications\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\Upgrade\Appx\DownlevelGather\AppxAllUserStore\S-1-5-21-1203430805-1345111560-1046767822-1002\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\Upgrade\Appx\DownlevelGather\InstalledPackages\Main\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\Upgrade\Appx\DownlevelGather\PackageInstallState\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\Upgrade\Appx\DownlevelGather\S-1-5-21-1203430805-1345111560-1046767822-1002\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\Upgrade\Appx\DownlevelGather\SisDirectory\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[-HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CMcAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw%5Cresources.pri]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\AppXBackupContentType\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_3.5.169.1_x64__bq6yxensn79aw]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\UserData\UninstallTimes]
"McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw"=-
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\Authentication\LogonUI\Notifications\BackgroundCapability\S-1-15-2-3278776214-1635354653-2314643131-251295766-804234917-407627331-3835975369\McAfeeCentral.AppXk7xg7tyv3z7a0jg74fpkz1sxrqje481a.mca]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\Authentication\LogonUI\Notifications\BackgroundCapability\S-1-15-2-3278776214-1635354653-2314643131-251295766-804234917-407627331-3835975369\McAfeeCentral.AppXsdzk65mbvr9xjt93y1177j9q8jny7x90.mca]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\PushNotifications\Backup\McAfee.McAgent]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\SettingSync\00034001B2142CBB\Registrar\Data\Registered\packagestate-mcafeeinc.06.mcafeesecurityadvisorforlenovo_bq6yxensn79aw-0]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\SettingSync\00034001B2142CBB\Registrar\Data\Registered\packagestate-mcafeeinc.06.mcafeesecurityadvisorforlenovo_bq6yxensn79aw-0]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\SettingSync\Namespace\PackageState\mcafeeinc.06.mcafeesecurityadvisorforlenovo_bq6yxensn79aw-0]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\SettingSync\Namespace\WindowsPackageSettings\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\SettingSync\Namespace\WindowsPackageSettings\Notifications-McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\CollectionStaging\packagestate-mcafeeinc.06.mcafeesecurityadvisorforlenovo_bq6yxensn79aw-0]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\packagestate\mcafeeinc.06.mcafeesecurityadvisorforlenovo_bq6yxensn79aw-0]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\RemoteCollectionInfo\packagestate-mcafeeinc.06.mcafeesecurityadvisorforlenovo_bq6yxensn79aw-0]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\SettingSync\Telemetry\SaveKnowledgeLastSuccess]
"packagestate-mcafeeinc.06.mcafeesecurityadvisorforlenovo_bq6yxensn79aw-0"=-
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\Store\ContentId]
"McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw"=-
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\McAfee Security Scan]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\MSC\McAfee LiveSafe]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\MSC\McAfee LiveSafe(1)]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\MSC\McAfee LiveSafe(2)]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\MSC\McAfee LiveSafe(3)]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\MSC\McAfee LiveSafe(4)]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\MSC\McAfee LiveSafe(5)]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee LiveSafe]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee LiveSafe(1)]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee LiveSafe(2)]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee LiveSafe(3)]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee LiveSafe(4)]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee LiveSafe(5)]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee WebAdvisor]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee WebAdvisor(1)]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CMcAfeeInc.06.McAfeeSecurityAdvisorforLenovo_4.5.141.1_x64__bq6yxensn79aw%5Cresources.pri]
Endregedit:
EmptyTemp:
*****************
Error: Restore point can only be created in normal mode.
Processes closed successfully.
C:\Windows\avastSS.scr => moved successfully
C:\Windows\WinSxS\Manifests\amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396.cat => moved successfully
C:\Windows\WinSxS\Manifests\amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396.manifest => moved successfully
C:\Windows\WinSxS\Manifests\amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5e69e83710ea31f5.cat => moved successfully
C:\Windows\WinSxS\Manifests\amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5e69e83710ea31f5.manifest => moved successfully
C:\Windows\WinSxS\Manifests\amd64_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_6349ea290dbe6128.cat => moved successfully
C:\Windows\WinSxS\Manifests\amd64_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_6349ea290dbe6128.manifest => moved successfully
C:\Windows\WinSxS\Manifests\amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5158632ac9d8192f.cat => moved successfully
C:\Windows\WinSxS\Manifests\amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5158632ac9d8192f.manifest => moved successfully
C:\Windows\WinSxS\Manifests\amd64_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_5638651cc6ac4862.cat => moved successfully
C:\Windows\WinSxS\Manifests\amd64_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_5638651cc6ac4862.manifest => moved successfully
C:\Windows\WinSxS\Manifests\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c.cat => moved successfully
C:\Windows\WinSxS\Manifests\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c.manifest => moved successfully
C:\Windows\WinSxS\Manifests\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_a6171f0e25665afb.cat => moved successfully
C:\Windows\WinSxS\Manifests\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_a6171f0e25665afb.manifest => moved successfully
C:\Windows\WinSxS\Manifests\x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_aaf72100223a8a2e.cat => moved successfully
C:\Windows\WinSxS\Manifests\x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_aaf72100223a8a2e.manifest => moved successfully
C:\Windows\WinSxS\Manifests\x86_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_b2556b4035446b41.cat => moved successfully
C:\Windows\WinSxS\Manifests\x86_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_b2556b4035446b41.manifest => moved successfully
C:\Windows\WinSxS\Manifests\x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_99059a01de544235.cat => moved successfully
C:\Windows\WinSxS\Manifests\x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_99059a01de544235.manifest => moved successfully
C:\Windows\WinSxS\Manifests\x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_9de59bf3db287168.cat => moved successfully
C:\Windows\WinSxS\Manifests\x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_9de59bf3db287168.manifest => moved successfully
C:\Windows\System32\Tasks_Migrated\Avast Emergency Update => moved successfully
C:\Windows\System32\Tasks_Migrated\Avast Secure Browser Heartbeat Task (Hourly) => moved successfully
C:\Windows\System32\Tasks_Migrated\Avast Secure Browser Heartbeat Task (Logon) => moved successfully
C:\Windows\System32\Tasks_Migrated\AvastUpdateTaskMachineCore => moved successfully
C:\Windows\System32\Tasks_Migrated\AvastUpdateTaskMachineUA => moved successfully
C:\Windows\System32\Tasks_Migrated\AVAST Software\Avast settings backup => moved successfully
C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396.cat => moved successfully
C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396.manifest => moved successfully
C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5e69e83710ea31f5.cat => moved successfully
C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5e69e83710ea31f5.manifest => moved successfully
C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_6349ea290dbe6128.cat => moved successfully
C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_6349ea290dbe6128.manifest => moved successfully
C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5158632ac9d8192f.cat => moved successfully
C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5158632ac9d8192f.manifest => moved successfully
C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_5638651cc6ac4862.cat => moved successfully
C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_5638651cc6ac4862.manifest => moved successfully
C:\Users\Jim\SkyDrive\Pictures\Documents\avast (2).lnk => moved successfully
C:\Users\Jim\SkyDrive\Pictures\Documents\Avast Password Manager.lnk => moved successfully
C:\Users\Jim\SkyDrive\Pictures\Documents\Avast Secure Browser.lnk => moved successfully
C:\Users\Jim\SkyDrive\Pictures\Documents\avast! Antivirus => moved successfully
C:\Users\Jim\SkyDrive\Pictures\Documents\avast-logo-opt-in.png => moved successfully
C:\Users\Jim\SkyDrive\Pictures\Documents\avast.lnk => moved successfully
C:\Users\Jim\SkyDrive\Pictures\Documents\avast.search-ms => moved successfully
C:\Users\Jim\SkyDrive\Pictures\Documents\Avastbackend.txt => moved successfully
C:\Users\Jim\SkyDrive\Pictures\Documents\avastclear.exe => moved successfully
C:\Users\Jim\SkyDrive\Pictures\Documents\avastclear.exe.fhvb1vu.partial => moved successfully
C:\Users\Jim\SkyDrive\Pictures\Documents\avastSS.scr => moved successfully
C:\Users\Jim\SkyDrive\Pictures\Documents\avast_free_antivirus_setup_online.exe => moved successfully
C:\Users\Jim\SkyDrive\Pictures\Documents\avast_pam => moved successfully
C:\Users\Jim\SkyDrive\Pictures\Documents\license.avastlic.lnk => moved successfully
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c.cat => moved successfully
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c.manifest => moved successfully
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_a6171f0e25665afb.cat => moved successfully
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_a6171f0e25665afb.manifest => moved successfully
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_aaf72100223a8a2e.cat => moved successfully
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_aaf72100223a8a2e.manifest => moved successfully
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_b2556b4035446b41.cat => moved successfully
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_b2556b4035446b41.manifest => moved successfully
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_99059a01de544235.cat => moved successfully
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_99059a01de544235.manifest => moved successfully
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_9de59bf3db287168.cat => moved successfully
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_9de59bf3db287168.manifest => moved successfully
C:\Users\Jim\SkyDrive\Pictures\Documents\AVAST Software\Avastbackend.txt => moved successfully
C:\Users\Jim\Searches\avast.search-ms => moved successfully
C:\Users\Jim\Links\avast (2).lnk => moved successfully
C:\Users\Jim\Links\avast.lnk => moved successfully
C:\Users\Jim\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Avast Secure Browser.lnk => moved successfully
C:\ProgramData\Microsoft\Windows\AppRepository\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_4.5.141.1_x64__bq6yxensn79aw.xml => moved successfully
C:\ProgramData\Microsoft\Windows\AppRepository\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw.xml => moved successfully
C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw => moved successfully
C:\FRST\Quarantine\C\WINDOWS\System32\Tasks\AVAST Software => moved successfully
C:\FRST\Quarantine\C\Users\Jim\Downloads\avast_free_antivirus_setup_online.exe.xBAD => moved successfully
C:\AVAST Software => moved successfully
C:\Windows\WinSxS\amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396 => moved successfully
C:\Windows\WinSxS\amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5e69e83710ea31f5 => moved successfully
C:\Windows\WinSxS\amd64_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_6349ea290dbe6128 => moved successfully
C:\Windows\WinSxS\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c => moved successfully
C:\Windows\WinSxS\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_a6171f0e25665afb => moved successfully
C:\Windows\WinSxS\x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_aaf72100223a8a2e => moved successfully
C:\Windows\System32\Tasks_Migrated\AVAST Software => moved successfully
C:\Windows\System32\Tasks\AVAST Software => moved successfully
C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396 => moved successfully
C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5e69e83710ea31f5 => moved successfully
C:\Users\Jim\SkyDrive\Pictures\Documents\amd64_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_6349ea290dbe6128 => moved successfully
C:\Users\Jim\SkyDrive\Pictures\Documents\Avast => moved successfully
C:\Users\Jim\SkyDrive\Pictures\Documents\AVAST Software => moved successfully
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c => moved successfully
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_a6171f0e25665afb => moved successfully
C:\Users\Jim\SkyDrive\Pictures\Documents\x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_aaf72100223a8a2e => moved successfully
C:\Users\Jim\SkyDrive\Pictures\Documents\_avast_ => moved successfully
"C:\Users\Jim\SkyDrive\Pictures\Documents\AVAST Software\Avast" => not found
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Browser Cleanup => moved successfully
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Browser Cleanup(1) => moved successfully
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Browser Cleanup(2) => moved successfully
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Free Antivirus => moved successfully
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Free Antivirus(1) => moved successfully
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Free Antivirus(2) => moved successfully
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Free Antivirus(3) => moved successfully
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Free Antivirus(4) => moved successfully
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Pro Antivirus => moved successfully
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Pro Antivirus(1) => moved successfully
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee LiveSafe => moved successfully
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee LiveSafe(1) => moved successfully
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee LiveSafe(2) => moved successfully
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee LiveSafe(3) => moved successfully
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee LiveSafe(4) => moved successfully
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee LiveSafe(5) => moved successfully
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee Security Scan Plus => moved successfully
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee Security Scan Plus(1) => moved successfully
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee WebAdvisor => moved successfully
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee WebAdvisor(1) => moved successfully
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\Avast-14052020-134203 => moved successfully
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\Avast-14052020-134250 => moved successfully
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\Avast-14052020-134720 => moved successfully
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\Avast-14052020-135743 => moved successfully
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\Avast-14052020-135752 => moved successfully
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\Avast-20052020-151429 => moved successfully
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\Avast-20052020-154404 => moved successfully
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\Avast-23052020-182559 => moved successfully
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\McAfee-14052020-133905 => moved successfully
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\McAfee-14052020-140130 => moved successfully
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\McAfee-14052020-140151 => moved successfully
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\McAfee-14052020-140240 => moved successfully
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\McAfee-14052020-140248 => moved successfully
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\McAfee-14052020-140332 => moved successfully
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\McAfee-14052020-140342 => moved successfully
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\McAfee-14052020-140435 => moved successfully
C:\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\McAfee-14052020-140529 => moved successfully
"C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw" => not found
C:\FRST\Quarantine\C\WINDOWS\System32\Tasks\AVAST Software => moved successfully
"C:\AVAST Software\Avast" => not found
Registry ====> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\Av\{8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF} <==== Access Denied
Registry ====> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\Av\{EB19B86E-3998-C706-90EF-92B41EB091AF} <==== Access Denied
Registry ====> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Data\3f6 <==== Access Denied
Registry ====> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Index\PackageAndPackageRelativeApplicationId\8c8^McAfeeCentral <==== Access Denied
Registry ====> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\ApplicationUser\Data\8e <==== Access Denied
Registry ====> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\ApplicationUser\Index\UserAndApplicationUserModelId\1^McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw!McAfeeCentral <==== Access Denied
Registry ====> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\8c8 <==== Access Denied
Registry ====> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Index\PackageFullName\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw <==== Access Denied
Registry ====> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageFamily\Data\38 <==== Access Denied
Registry ====> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageFamily\Index\PackageFamilyName\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw <==== Access Denied
Registry ====> The operation completed successfully.

=========== EmptyTemp: ==========
BITS transfer queue => 10772480 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 28501056 B
Java, Flash, Steam htmlcache => 0 B
Windows/system/drivers => 4104675 B
Edge => 9667173 B
Chrome => 29899971 B
Firefox => 0 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 0 B
NetworkService => 57466 B
UpdatusUser => 57466 B
Jim => 8540909 B
RecycleBin => 29784189 B
EmptyTemp: => 115.8 MB temporary data Removed.
================================

The system needed a reboot.
==== End of Fixlog 14:22:04 ====

  • 0

#37
JimBow

JimBow

    Member

  • Topic Starter
  • Member
  • PipPip
  • 88 posts

I just conducted a Windows search of my computer to see what Avast and McAfee remnants it could find. I was surprised to find that McAfee still lives in a D: partition on my hard drive.  I was not aware that there were any programs on there. It is the only program in a 425 MB file folder labeled Application; the other file folder is all drivers. The other remnants that Windows identified appear to be FRST Quarantine files.

Jim


  • 0

#38
DR M

DR M

    The Grecian Geek

  • Malware Removal
  • 4,049 posts

Hi, Jim.

 

The good thing is there is no sign of malware in the computer. My instructor and I, we are currently discussing the situation. I will be back to you as soon as possible.


  • 0

#39
DR M

DR M

    The Grecian Geek

  • Malware Removal
  • 4,049 posts

Hi, Jim.

 

We are trying a different approach now:

 

  • Please download Farbar Recovery Scan Tool x64 and save it to a flash drive.
  • In the same flash drive, save in notepad the content of the code below. Name it as fixscript.

 
Then,

1. Boot in the Recovery Environment

  • Press the Windows icon on the keyboard together with the letter I, to get into the Settings.
  • Choose Update and Security.
  • From the menu at the left, choose Recovery.
  • Under the title Advanced startup at the right, choose Restart now.
  • From the window that will appear choose Troubleshoot and then Advanced options.
  • Choose Command Prompt.

2. Once in the command prompt

  • In the command prompt, type notepad and press on Enter
  • Notepad will open. Click on the File menu and select Open
  • Click on Computer/This PC, find the letter for your USB Flash Drive, and double click on it to open it.
  • Find the fixscript.txt, open it, select all its content, right click and copy.
  • Close the Notepad.
  • In the command prompt, type e:\frst64.exe and press Enter.
  • Note: Replace the letter e with the drive letter of your USB Flash Drive.
  • FRST will open.
  • Click on Yes to accept the disclaimer.
  • Click on Fix.
  • After the tool finishes, let the computer restart.
  • A fixlog.txt will be created in the usb drive.
  • Copy its content and paste it in your next reply.

 

The fixscript:

start::
closeprocesses:

StartRegedit:
Windows Registry Editor Version 5.00

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\AvastGUIProxy.DLL]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{5020EF2C-60F4-47BE-8918-A167229B11EE}]
""=-
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\Av\{8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\Av\{EB19B86E-3998-C706-90EF-92B41EB091AF}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\avast! Mail Scanner Cache]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\avast! Mail Scanner Trusted]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\avast! SSL Scanner Cache]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]
"AvastUI.exe"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32]
"AvastUI.exe"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_5ca6eb17137337f1"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_4f95660acc611f2b"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"amd64_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_547567fcc9354e5e"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"amd64_avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_6186ed0910476724"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_a45421ee27ef60f7"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_a93423e024c3902a"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_b2556b4035446b41"="-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_97429ce1e0dd4831"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_9c229ed3ddb17764"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_a6171f0e25665afb"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5e69e83710ea31f5"="-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_aaf72100223a8a2e"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"amd64_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_6349ea290dbe6128"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_99059a01de544235"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5158632ac9d8192f"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_9de59bf3db287168"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"amd64_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_5638651cc6ac4862"=-
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_avast.vc110.crt_2036b14a11e83e4a_none_c373722873c01144]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_avast.vc140.crt_fcc99ee6193ebbca_none_020285fe6d6e0580]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_avast.vc140.mfc_fcc99ee6193ebbca_none_018be6966dc83925]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_none_ef17e13d91c55d96]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_none_eea141d5921f913b]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_avast.vc110.crt_2036b14a11e83e4a_none_0b20a8ff883c3a4a]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_avast.vc140.crt_fcc99ee6193ebbca_none_49afbcd581ea2e86]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_avast.vc140.mfc_fcc99ee6193ebbca_none_49391d6d8244622b]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_none_5679bb9c25dbf18d]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_none_36c51814a641869c]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_none_364e78aca69bba41]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvastBrowserUpdate.exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\AVAST Software]
[-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvastBrowserUpdate.exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\SystemCertificates\avast! Mail Scanner Cache]
[-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\SystemCertificates\avast! Mail Scanner Trusted]
[-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\SystemCertificates\avast! SSL Scanner Cache]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\aswbIDSAgent]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\avast]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\avast! Antivirus]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\avastm]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\AvastSecureBrowserElevationService]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\AvastWscReporter]
[-HKEY_USERS\.DEFAULT\Software\Avast Software]
[-HKEY_USERS\.DEFAULT\Software\Avast Software\Avast Browser Cleanup]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\IntelliPoint\AppSpecific\AvastUI.exe]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\IntelliType Pro\AppSpecific\AvastUI.exe]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Avast Software]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\e5c97fd7_0]
""=-
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\f3982c37_0]
""="-
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Office\Outlook\Addins\avast.AsOutExt]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts]
"AvastHTML_.pdf"=-
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts]
"AvastHTML_https"=-
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts]
"AvastHTML_http"=-
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts]
"AvastHTML_.htm"=-
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts]
"AvastHTML_.html"=-
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts]
"AvastHTML_mailto"=-
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.avastlic]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.avastlic]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\Search\RecentApps\{B7862F08-B068-439C-8549-BBCE83F57707}]
"AppId"=-
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\Search\RecentApps\{B7862F08-B068-439C-8549-BBCE83F57707}]
"AppPath"=-
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Piriform\CCleaner]
"CookiesToSave"=-
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\Avast Antivirus]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\Avast Browser Cleanup]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\SafeZone 3.55.2393.609\Avast Free Antivirus]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\PackageRepository\Packages\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Data\3f6]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Index\PackageAndPackageRelativeApplicationId\8c8^McAfeeCentral]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\ApplicationUser\Data\8e]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\ApplicationUser\Index\UserAndApplicationUserModelId\1^McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw!McAfeeCentral]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\8c8]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Index\PackageFullName\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageFamily\Data\38]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageFamily\Index\PackageFamilyName\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Applications\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\S-1-5-21-1203430805-1345111560-1046767822-1002\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\Upgrade\Appx\Applications\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\Upgrade\Appx\AppxAllUserStore\S-1-5-21-1203430805-1345111560-1046767822-1002\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\Upgrade\Appx\DownlevelGather\AppxAllUserStore\Applications\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\Upgrade\Appx\DownlevelGather\AppxAllUserStore\S-1-5-21-1203430805-1345111560-1046767822-1002\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\Upgrade\Appx\DownlevelGather\InstalledPackages\Main\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\Upgrade\Appx\DownlevelGather\PackageInstallState\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\Upgrade\Appx\DownlevelGather\S-1-5-21-1203430805-1345111560-1046767822-1002\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\Upgrade\Appx\DownlevelGather\SisDirectory\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[-HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CMcAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw%5Cresources.pri]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\AppXBackupContentType\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_3.5.169.1_x64__bq6yxensn79aw]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\UserData\UninstallTimes]
"McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw"=-
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\Authentication\LogonUI\Notifications\BackgroundCapability\S-1-15-2-3278776214-1635354653-2314643131-251295766-804234917-407627331-3835975369\McAfeeCentral.AppXk7xg7tyv3z7a0jg74fpkz1sxrqje481a.mca]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\Authentication\LogonUI\Notifications\BackgroundCapability\S-1-15-2-3278776214-1635354653-2314643131-251295766-804234917-407627331-3835975369\McAfeeCentral.AppXsdzk65mbvr9xjt93y1177j9q8jny7x90.mca]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\PushNotifications\Backup\McAfee.McAgent]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\SettingSync\00034001B2142CBB\Registrar\Data\Registered\packagestate-mcafeeinc.06.mcafeesecurityadvisorforlenovo_bq6yxensn79aw-0]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\SettingSync\00034001B2142CBB\Registrar\Data\Registered\packagestate-mcafeeinc.06.mcafeesecurityadvisorforlenovo_bq6yxensn79aw-0]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\SettingSync\Namespace\PackageState\mcafeeinc.06.mcafeesecurityadvisorforlenovo_bq6yxensn79aw-0]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\SettingSync\Namespace\WindowsPackageSettings\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\SettingSync\Namespace\WindowsPackageSettings\Notifications-McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\CollectionStaging\packagestate-mcafeeinc.06.mcafeesecurityadvisorforlenovo_bq6yxensn79aw-0]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\packagestate\mcafeeinc.06.mcafeesecurityadvisorforlenovo_bq6yxensn79aw-0]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\RemoteCollectionInfo\packagestate-mcafeeinc.06.mcafeesecurityadvisorforlenovo_bq6yxensn79aw-0]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\SettingSync\Telemetry\SaveKnowledgeLastSuccess]
"packagestate-mcafeeinc.06.mcafeesecurityadvisorforlenovo_bq6yxensn79aw-0"=-
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\Store\ContentId]
"McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw"=-
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\McAfee Security Scan]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\MSC\McAfee LiveSafe]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\MSC\McAfee LiveSafe(1)]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\MSC\McAfee LiveSafe(2)]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\MSC\McAfee LiveSafe(3)]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\MSC\McAfee LiveSafe(4)]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\MSC\McAfee LiveSafe(5)]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee LiveSafe]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee LiveSafe(1)]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee LiveSafe(2)]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee LiveSafe(3)]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee LiveSafe(4)]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee LiveSafe(5)]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee WebAdvisor]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee WebAdvisor(1)]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CMcAfeeInc.06.McAfeeSecurityAdvisorforLenovo_4.5.141.1_x64__bq6yxensn79aw%5Cresources.pri]
Endregedit:
EmptyTemp:
End::

Lastly,

 

3. Search for remnants

  • Double-click FRST.exe/FRST64.exe to run it, as you did before.
  • Copy and paste the following into the Search box.
SearchAll: Avast;McAfee
  • Press the Search Files button.
  • When complete, FRST will generate a log in the same location it was run from (Search.txt)
  • Please copy and paste its contents into your next reply.

 

In your next reply, please post:

 

1. The fixlog.txt

2. The search.txt

 

 


  • 0

#40
JimBow

JimBow

    Member

  • Topic Starter
  • Member
  • PipPip
  • 88 posts

I'm not so sure this is good news. Thank you for sticking with it.

 

I ran FRST from the thumb drive for both the fix and the search functions. It did not automatically restart at the end of the fix function, so I restarted before running the search.  Here are both of the files.

 

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 27-05-2020 01
Ran by SYSTEM (27-05-2020 14:48:32) Run:5
Running from e:\
Boot Mode: Recovery
==============================================
fixlist content:
*****************
closeprocesses:
StartRegedit:
Windows Registry Editor Version 5.00
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\AvastGUIProxy.DLL]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{5020EF2C-60F4-47BE-8918-A167229B11EE}]
""=-
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\Av\{8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\Av\{EB19B86E-3998-C706-90EF-92B41EB091AF}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\avast! Mail Scanner Cache]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\avast! Mail Scanner Trusted]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\avast! SSL Scanner Cache]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]
"AvastUI.exe"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32]
"AvastUI.exe"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_5ca6eb17137337f1"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_4f95660acc611f2b"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"amd64_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_547567fcc9354e5e"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"amd64_avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_6186ed0910476724"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_a45421ee27ef60f7"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_a93423e024c3902a"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_b2556b4035446b41"="-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_97429ce1e0dd4831"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_9c229ed3ddb17764"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_a6171f0e25665afb"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5e69e83710ea31f5"="-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_aaf72100223a8a2e"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"amd64_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_6349ea290dbe6128"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_99059a01de544235"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5158632ac9d8192f"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_9de59bf3db287168"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"amd64_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_5638651cc6ac4862"=-
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_avast.vc110.crt_2036b14a11e83e4a_none_c373722873c01144]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_avast.vc140.crt_fcc99ee6193ebbca_none_020285fe6d6e0580]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_avast.vc140.mfc_fcc99ee6193ebbca_none_018be6966dc83925]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_none_ef17e13d91c55d96]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_none_eea141d5921f913b]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_avast.vc110.crt_2036b14a11e83e4a_none_0b20a8ff883c3a4a]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_avast.vc140.crt_fcc99ee6193ebbca_none_49afbcd581ea2e86]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_avast.vc140.mfc_fcc99ee6193ebbca_none_49391d6d8244622b]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_none_5679bb9c25dbf18d]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_none_36c51814a641869c]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_none_364e78aca69bba41]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvastBrowserUpdate.exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\AVAST Software]
[-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvastBrowserUpdate.exe]
[-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\SystemCertificates\avast! Mail Scanner Cache]
[-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\SystemCertificates\avast! Mail Scanner Trusted]
[-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\SystemCertificates\avast! SSL Scanner Cache]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\aswbIDSAgent]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\avast]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\avast! Antivirus]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\avastm]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\AvastSecureBrowserElevationService]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\FirstBoot\Services\AvastWscReporter]
[-HKEY_USERS\.DEFAULT\Software\Avast Software]
[-HKEY_USERS\.DEFAULT\Software\Avast Software\Avast Browser Cleanup]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\IntelliPoint\AppSpecific\AvastUI.exe]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\IntelliType Pro\AppSpecific\AvastUI.exe]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Avast Software]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\e5c97fd7_0]
""=-
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\f3982c37_0]
""="-
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Office\Outlook\Addins\avast.AsOutExt]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts]
"AvastHTML_.pdf"=-
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts]
"AvastHTML_https"=-
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts]
"AvastHTML_http"=-
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts]
"AvastHTML_.htm"=-
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts]
"AvastHTML_.html"=-
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts]
"AvastHTML_mailto"=-
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.avastlic]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.avastlic]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\Search\RecentApps\{B7862F08-B068-439C-8549-BBCE83F57707}]
"AppId"=-
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\Search\RecentApps\{B7862F08-B068-439C-8549-BBCE83F57707}]
"AppPath"=-
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Piriform\CCleaner]
"CookiesToSave"=-
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\Avast Antivirus]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\Avast Browser Cleanup]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\SafeZone 3.55.2393.609\Avast Free Antivirus]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\PackageRepository\Packages\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Data\3f6]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Index\PackageAndPackageRelativeApplicationId\8c8^McAfeeCentral]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\ApplicationUser\Data\8e]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\ApplicationUser\Index\UserAndApplicationUserModelId\1^McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw!McAfeeCentral]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\8c8]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Index\PackageFullName\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageFamily\Data\38]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageFamily\Index\PackageFamilyName\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\Applications\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore\S-1-5-21-1203430805-1345111560-1046767822-1002\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\Upgrade\Appx\Applications\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\Upgrade\Appx\AppxAllUserStore\S-1-5-21-1203430805-1345111560-1046767822-1002\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\Upgrade\Appx\DownlevelGather\AppxAllUserStore\Applications\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\Upgrade\Appx\DownlevelGather\AppxAllUserStore\S-1-5-21-1203430805-1345111560-1046767822-1002\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\Upgrade\Appx\DownlevelGather\InstalledPackages\Main\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\Upgrade\Appx\DownlevelGather\PackageInstallState\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\Upgrade\Appx\DownlevelGather\S-1-5-21-1203430805-1345111560-1046767822-1002\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[-HKEY_LOCAL_MACHINE\SYSTEM\Setup\Upgrade\Appx\DownlevelGather\SisDirectory\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[-HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CMcAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw%5Cresources.pri]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\AppXBackupContentType\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_3.5.169.1_x64__bq6yxensn79aw]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\UserData\UninstallTimes]
"McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw"=-
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\Authentication\LogonUI\Notifications\BackgroundCapability\S-1-15-2-3278776214-1635354653-2314643131-251295766-804234917-407627331-3835975369\McAfeeCentral.AppXk7xg7tyv3z7a0jg74fpkz1sxrqje481a.mca]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\Authentication\LogonUI\Notifications\BackgroundCapability\S-1-15-2-3278776214-1635354653-2314643131-251295766-804234917-407627331-3835975369\McAfeeCentral.AppXsdzk65mbvr9xjt93y1177j9q8jny7x90.mca]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\PushNotifications\Backup\McAfee.McAgent]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\SettingSync\00034001B2142CBB\Registrar\Data\Registered\packagestate-mcafeeinc.06.mcafeesecurityadvisorforlenovo_bq6yxensn79aw-0]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\SettingSync\00034001B2142CBB\Registrar\Data\Registered\packagestate-mcafeeinc.06.mcafeesecurityadvisorforlenovo_bq6yxensn79aw-0]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\SettingSync\Namespace\PackageState\mcafeeinc.06.mcafeesecurityadvisorforlenovo_bq6yxensn79aw-0]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\SettingSync\Namespace\WindowsPackageSettings\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\SettingSync\Namespace\WindowsPackageSettings\Notifications-McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\CollectionStaging\packagestate-mcafeeinc.06.mcafeesecurityadvisorforlenovo_bq6yxensn79aw-0]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\packagestate\mcafeeinc.06.mcafeesecurityadvisorforlenovo_bq6yxensn79aw-0]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\RemoteCollectionInfo\packagestate-mcafeeinc.06.mcafeesecurityadvisorforlenovo_bq6yxensn79aw-0]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\SettingSync\Telemetry\SaveKnowledgeLastSuccess]
"packagestate-mcafeeinc.06.mcafeesecurityadvisorforlenovo_bq6yxensn79aw-0"=-
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Windows\CurrentVersion\Store\ContentId]
"McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw"=-
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\McAfee Security Scan]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\MSC\McAfee LiveSafe]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\MSC\McAfee LiveSafe(1)]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\MSC\McAfee LiveSafe(2)]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\MSC\McAfee LiveSafe(3)]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\MSC\McAfee LiveSafe(4)]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\MSC\McAfee LiveSafe(5)]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee LiveSafe]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee LiveSafe(1)]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee LiveSafe(2)]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee LiveSafe(3)]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee LiveSafe(4)]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee LiveSafe(5)]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee WebAdvisor]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}\McAfee WebAdvisor(1)]
[-HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CMcAfeeInc.06.McAfeeSecurityAdvisorforLenovo_4.5.141.1_x64__bq6yxensn79aw%5Cresources.pri]
Endregedit:
EmptyTemp:
*****************
closeprocesses: => Error: This directive works only outside recovery mode.
Registry ====> ERROR: Error accessing the registry.
EmptyTemp: => Error: This directive works only outside recovery mode.
==== End of Fixlog 14:48:33 ====

 

Farbar Recovery Scan Tool (x64) Version: 27-05-2020 01
Ran by Jim (27-05-2020 15:14:12)
Running from F:\
Boot Mode: Normal
================== Search Files: "SearchAll: Avast;McAfee" =============
File:
========
C:\FRST\Quarantine\C\WINDOWS\avastSS.scr.xBAD
[2016-09-01 14:20][2016-09-01 14:20] 000053208 _____ (AVAST Software) 12EBDA58437CD1EA7066FCB6455241D2 [File is digitally signed]
C:\FRST\Quarantine\C\WINDOWS\WinSxS\Manifests\amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396.cat.xBAD
[2019-08-10 20:56][2019-08-10 20:56] 000009249 _____ () C0782A6DD461CAC426127F137ED32A6C [File is digitally signed]
C:\FRST\Quarantine\C\WINDOWS\WinSxS\Manifests\amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396.manifest.xBAD
[2019-08-10 20:56][2019-08-10 20:56] 000002378 _____ () 5EFC81F732DC830BC96C5A3AABCFE543 [File not signed]
C:\FRST\Quarantine\C\WINDOWS\WinSxS\Manifests\amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5e69e83710ea31f5.cat.xBAD
[2020-02-25 13:06][2020-05-03 19:48] 000007456 _____ () DE67AC8142C10EB12E8AE6C6CDBAF799 [File is digitally signed]
C:\FRST\Quarantine\C\WINDOWS\WinSxS\Manifests\amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5e69e83710ea31f5.manifest.xBAD
[2020-02-25 13:06][2020-02-25 13:06] 000024123 _____ () 47437B704B6D56328C347347462CD02D [File not signed]
C:\FRST\Quarantine\C\WINDOWS\WinSxS\Manifests\amd64_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_6349ea290dbe6128.cat.xBAD
[2020-02-25 13:06][2020-05-03 19:48] 000007457 _____ () 2A9DFB92BD6DECA69672261DFB9E044D [File is digitally signed]
C:\FRST\Quarantine\C\WINDOWS\WinSxS\Manifests\amd64_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_6349ea290dbe6128.manifest.xBAD
[2020-02-25 13:06][2020-02-25 13:06] 000001231 _____ () A77C3C57546E0E66394A1DD29129052B [File not signed]
C:\FRST\Quarantine\C\WINDOWS\WinSxS\Manifests\amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5158632ac9d8192f.cat.xBAD
[2020-02-25 13:06][2020-05-03 19:48] 000007456 _____ () EAC8D7698558B21A1A533C6A567C06BD [File is digitally signed]
C:\FRST\Quarantine\C\WINDOWS\WinSxS\Manifests\amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5158632ac9d8192f.manifest.xBAD
[2020-02-25 13:06][2020-02-25 13:06] 000000754 _____ () F6ED6E08D09EBE10597CB2966F6C394E [File not signed]
C:\FRST\Quarantine\C\WINDOWS\WinSxS\Manifests\amd64_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_5638651cc6ac4862.cat.xBAD
[2020-02-25 13:06][2020-05-03 19:48] 000007457 _____ () 777DD2D0BC92B002B9236B6F4F61CB05 [File is digitally signed]
C:\FRST\Quarantine\C\WINDOWS\WinSxS\Manifests\amd64_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_5638651cc6ac4862.manifest.xBAD
[2020-02-25 13:06][2020-02-25 13:06] 000000754 _____ () 44D5DDB1B2C027176887E75382F29D55 [File not signed]
C:\FRST\Quarantine\C\WINDOWS\WinSxS\Manifests\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c.cat.xBAD
[2019-08-10 20:59][2019-08-10 20:59] 000009249 _____ () F181BD5627947025E1254E2F786AE2BE [File is digitally signed]
C:\FRST\Quarantine\C\WINDOWS\WinSxS\Manifests\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c.manifest.xBAD
[2019-08-10 20:59][2019-08-10 20:59] 000002376 _____ () 176B3BE4AE48CC8A7FACBB8E89A2131E [File not signed]
C:\FRST\Quarantine\C\WINDOWS\WinSxS\Manifests\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_a6171f0e25665afb.cat.xBAD
[2020-02-25 13:06][2020-05-03 19:48] 000007457 _____ () F7BAEFE116151719499F97B4D7A29BC5 [File is digitally signed]
C:\FRST\Quarantine\C\WINDOWS\WinSxS\Manifests\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_a6171f0e25665afb.manifest.xBAD
[2020-02-25 13:06][2020-02-25 13:06] 000023610 _____ () FF9B36754303E435AFFABAB5168718B4 [File not signed]
C:\FRST\Quarantine\C\WINDOWS\WinSxS\Manifests\x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_aaf72100223a8a2e.cat.xBAD
[2020-02-25 13:06][2020-05-03 19:48] 000007457 _____ () B021FBE34930277301DEEC14CDD9E3FE [File is digitally signed]
C:\FRST\Quarantine\C\WINDOWS\WinSxS\Manifests\x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_aaf72100223a8a2e.manifest.xBAD
[2020-02-25 13:06][2020-02-25 13:06] 000001227 _____ () 955669576F50AF3D88281103865D3A1D [File not signed]
C:\FRST\Quarantine\C\WINDOWS\WinSxS\Manifests\x86_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_b2556b4035446b41.cat.xBAD
[2019-08-10 21:05][2019-08-10 21:05] 000009249 _____ () 84E52D0B42207B15BC16A36298AE4110 [File is digitally signed]
C:\FRST\Quarantine\C\WINDOWS\WinSxS\Manifests\x86_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_b2556b4035446b41.manifest.xBAD
[2019-08-10 21:05][2019-08-10 21:05] 000000608 _____ () E479732F7B82161E923B0DF5B5D09C59 [File not signed]
C:\FRST\Quarantine\C\WINDOWS\WinSxS\Manifests\x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_99059a01de544235.cat.xBAD
[2020-02-25 13:06][2020-05-03 19:48] 000007457 _____ () F8999365A25BB341C55C70CB32DF2D46 [File is digitally signed]
C:\FRST\Quarantine\C\WINDOWS\WinSxS\Manifests\x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_99059a01de544235.manifest.xBAD
[2020-02-25 13:06][2020-02-25 13:06] 000000750 _____ () 709C8063694781F6371E817243F0EB0F [File not signed]
C:\FRST\Quarantine\C\WINDOWS\WinSxS\Manifests\x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_9de59bf3db287168.cat.xBAD
[2020-02-25 13:06][2020-05-03 19:48] 000007456 _____ () DFB0071CF316CD33F04392304A02A289 [File is digitally signed]
C:\FRST\Quarantine\C\WINDOWS\WinSxS\Manifests\x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_9de59bf3db287168.manifest.xBAD
[2020-02-25 13:06][2020-02-25 13:06] 000000750 _____ () 8D1CB478D2A7A6AFAE2C38C6524EDA4B [File not signed]
C:\FRST\Quarantine\C\WINDOWS\System32\Tasks_Migrated\Avast Emergency Update.xBAD
[2018-06-29 19:08][2019-07-15 22:35] 000004264 _____ () 6EF2F40451AC098BB7FB16BCDD8340E8 [File not signed]
C:\FRST\Quarantine\C\WINDOWS\System32\Tasks_Migrated\Avast Secure Browser Heartbeat Task (Hourly).xBAD
[2019-04-17 10:28][2019-06-30 16:37] 000003856 _____ () F8EB50FDD1AA5C9099C4CD80BFA15FD7 [File not signed]
C:\FRST\Quarantine\C\WINDOWS\System32\Tasks_Migrated\Avast Secure Browser Heartbeat Task (Logon).xBAD
[2019-04-17 10:28][2019-06-30 16:37] 000003272 _____ () B7F45D11A051E9ED91976F4E32AB6634 [File not signed]
C:\FRST\Quarantine\C\WINDOWS\System32\Tasks_Migrated\AvastUpdateTaskMachineCore.xBAD
[2018-06-29 19:08][2018-06-29 19:08] 000003162 _____ () 2FFF683C6CB40793C4E48504B1B4DFDA [File not signed]
C:\FRST\Quarantine\C\WINDOWS\System32\Tasks_Migrated\AvastUpdateTaskMachineUA.xBAD
[2018-06-29 19:08][2018-06-29 19:09] 000003386 _____ () 403158CDE83FC864E48BC347A28D1D53 [File not signed]
C:\FRST\Quarantine\C\WINDOWS\System32\Tasks_Migrated\AVAST Software\Avast settings backup.xBAD
[2018-06-29 19:08][2018-06-29 19:08] 000002876 _____ () 15477E3DB06E1308B5608538A5FB3984 [File not signed]
C:\FRST\Quarantine\C\Users\Jim\SkyDrive\Pictures\Documents\amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396.cat.xBAD
[2020-05-10 22:15][2019-08-10 20:56] 000009249 _____ () C0782A6DD461CAC426127F137ED32A6C [File is digitally signed]
C:\FRST\Quarantine\C\Users\Jim\SkyDrive\Pictures\Documents\amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396.manifest.xBAD
[2020-05-10 22:15][2019-08-10 20:56] 000002378 _____ () 5EFC81F732DC830BC96C5A3AABCFE543 [File not signed]
C:\FRST\Quarantine\C\Users\Jim\SkyDrive\Pictures\Documents\amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5e69e83710ea31f5.cat.xBAD
[2020-05-10 22:15][2020-05-03 19:48] 000007456 _____ () DE67AC8142C10EB12E8AE6C6CDBAF799 [File is digitally signed]
C:\FRST\Quarantine\C\Users\Jim\SkyDrive\Pictures\Documents\amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5e69e83710ea31f5.manifest.xBAD
[2020-05-10 22:15][2020-02-25 13:06] 000024123 _____ () 47437B704B6D56328C347347462CD02D [File not signed]
C:\FRST\Quarantine\C\Users\Jim\SkyDrive\Pictures\Documents\amd64_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_6349ea290dbe6128.cat.xBAD
[2020-05-10 22:15][2020-05-03 19:48] 000007457 _____ () 2A9DFB92BD6DECA69672261DFB9E044D [File is digitally signed]
C:\FRST\Quarantine\C\Users\Jim\SkyDrive\Pictures\Documents\amd64_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_6349ea290dbe6128.manifest.xBAD
[2020-05-10 22:15][2020-02-25 13:06] 000001231 _____ () A77C3C57546E0E66394A1DD29129052B [File not signed]
C:\FRST\Quarantine\C\Users\Jim\SkyDrive\Pictures\Documents\amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5158632ac9d8192f.cat.xBAD
[2020-05-10 22:15][2020-05-03 19:48] 000007456 _____ () EAC8D7698558B21A1A533C6A567C06BD [File is digitally signed]
C:\FRST\Quarantine\C\Users\Jim\SkyDrive\Pictures\Documents\amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5158632ac9d8192f.manifest.xBAD
[2020-05-10 22:15][2020-02-25 13:06] 000000754 _____ () F6ED6E08D09EBE10597CB2966F6C394E [File not signed]
C:\FRST\Quarantine\C\Users\Jim\SkyDrive\Pictures\Documents\amd64_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_5638651cc6ac4862.cat.xBAD
[2020-05-10 22:15][2020-05-03 19:48] 000007457 _____ () 777DD2D0BC92B002B9236B6F4F61CB05 [File is digitally signed]
C:\FRST\Quarantine\C\Users\Jim\SkyDrive\Pictures\Documents\amd64_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_5638651cc6ac4862.manifest.xBAD
[2020-05-10 22:15][2020-02-25 13:06] 000000754 _____ () 44D5DDB1B2C027176887E75382F29D55 [File not signed]
C:\FRST\Quarantine\C\Users\Jim\SkyDrive\Pictures\Documents\avast (2).lnk.xBAD
[2020-05-10 22:15][2020-05-10 22:08] 000000788 _____ () 7D3F216F471ADB16EED81B8A8A999893 [File not signed]
C:\FRST\Quarantine\C\Users\Jim\SkyDrive\Pictures\Documents\Avast Password Manager.lnk.xBAD
[2020-05-10 22:15][2018-06-29 16:12] 000002034 _____ () 51F971AF848E4EB111086B9B479599A1 [File not signed]
C:\FRST\Quarantine\C\Users\Jim\SkyDrive\Pictures\Documents\Avast Secure Browser.lnk.xBAD
[2020-05-10 22:15][2020-02-25 12:08] 000002582 _____ () 5AB573C919309FE7154CC456A117D7D4 [File not signed]
C:\FRST\Quarantine\C\Users\Jim\SkyDrive\Pictures\Documents\avast! Antivirus.xBAD
[2020-05-10 22:15][2020-05-10 12:49] 000037014 _____ () 3212927E3EDF091342487F5EBB045245 [File not signed]
C:\FRST\Quarantine\C\Users\Jim\SkyDrive\Pictures\Documents\avast-logo-opt-in.png.xBAD
[2020-05-10 22:15][2020-01-29 16:42] 000001881 _____ () 2DB8A660D58D1A56961310CA1086C8D8 [File not signed]
C:\FRST\Quarantine\C\Users\Jim\SkyDrive\Pictures\Documents\avast.lnk.xBAD
[2020-05-10 22:15][2020-05-10 21:46] 000000626 _____ () AFF7DFDEA72559A4125D1C05FEEC6C03 [File not signed]
C:\FRST\Quarantine\C\Users\Jim\SkyDrive\Pictures\Documents\avast.search-ms.xBAD
[2020-05-10 22:15][2020-05-10 22:08] 000001973 _____ () 41925366CE74EBE05AC4DC79141AA3FE [File not signed]
C:\FRST\Quarantine\C\Users\Jim\SkyDrive\Pictures\Documents\Avastbackend.txt.xBAD
[2020-05-10 22:15][2019-01-09 00:35] 000010380 _____ () 75F729C0EEC2289236AE30E53BA4DC87 [File not signed]
C:\FRST\Quarantine\C\Users\Jim\SkyDrive\Pictures\Documents\avastclear.exe.fhvb1vu.partial.xBAD
[2020-05-10 22:15][2020-05-10 12:38] 010936952 _____ (AVAST Software) 18D43CD7663A775F5DE20FC2C64ABAFE [File is digitally signed]
C:\FRST\Quarantine\C\Users\Jim\SkyDrive\Pictures\Documents\avastclear.exe.xBAD
[2020-05-10 22:15][2020-05-10 12:38] 010936952 _____ (AVAST Software) 18D43CD7663A775F5DE20FC2C64ABAFE [File is digitally signed]
C:\FRST\Quarantine\C\Users\Jim\SkyDrive\Pictures\Documents\avastSS.scr.xBAD
[2020-05-10 22:15][2016-09-01 14:20] 000053208 _____ (AVAST Software) 12EBDA58437CD1EA7066FCB6455241D2 [File is digitally signed]
C:\FRST\Quarantine\C\Users\Jim\SkyDrive\Pictures\Documents\avast_free_antivirus_setup_online.exe.xBAD
[2020-05-10 22:15][2020-05-03 14:40] 000230080 _____ (AVAST Software) F6C3AE9D57FA30F04321FDD3CE814479 [File is digitally signed]
C:\FRST\Quarantine\C\Users\Jim\SkyDrive\Pictures\Documents\avast_pam.xBAD
[2020-05-10 22:15][2020-05-10 17:11] 000037014 _____ () 949DD0F5804127D1C34BA36F7DE7FE92 [File not signed]
C:\FRST\Quarantine\C\Users\Jim\SkyDrive\Pictures\Documents\license.avastlic.lnk.xBAD
[2020-05-10 22:15][2020-05-10 21:37] 000002550 _____ () F8DC0E8125560EE650D31D39D98B61C2 [File not signed]
C:\FRST\Quarantine\C\Users\Jim\SkyDrive\Pictures\Documents\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c.cat.xBAD
[2020-05-10 22:15][2019-08-10 20:59] 000009249 _____ () F181BD5627947025E1254E2F786AE2BE [File is digitally signed]
C:\FRST\Quarantine\C\Users\Jim\SkyDrive\Pictures\Documents\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c.manifest.xBAD
[2020-05-10 22:15][2019-08-10 20:59] 000002376 _____ () 176B3BE4AE48CC8A7FACBB8E89A2131E [File not signed]
C:\FRST\Quarantine\C\Users\Jim\SkyDrive\Pictures\Documents\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_a6171f0e25665afb.cat.xBAD
[2020-05-10 22:15][2020-05-03 19:48] 000007457 _____ () F7BAEFE116151719499F97B4D7A29BC5 [File is digitally signed]
C:\FRST\Quarantine\C\Users\Jim\SkyDrive\Pictures\Documents\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_a6171f0e25665afb.manifest.xBAD
[2020-05-10 22:15][2020-02-25 13:06] 000023610 _____ () FF9B36754303E435AFFABAB5168718B4 [File not signed]
C:\FRST\Quarantine\C\Users\Jim\SkyDrive\Pictures\Documents\x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_aaf72100223a8a2e.cat.xBAD
[2020-05-10 22:15][2020-05-03 19:48] 000007457 _____ () B021FBE34930277301DEEC14CDD9E3FE [File is digitally signed]
C:\FRST\Quarantine\C\Users\Jim\SkyDrive\Pictures\Documents\x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_aaf72100223a8a2e.manifest.xBAD
[2020-05-10 22:15][2020-02-25 13:06] 000001227 _____ () 955669576F50AF3D88281103865D3A1D [File not signed]
C:\FRST\Quarantine\C\Users\Jim\SkyDrive\Pictures\Documents\x86_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_b2556b4035446b41.cat.xBAD
[2020-05-10 22:15][2019-08-10 21:05] 000009249 _____ () 84E52D0B42207B15BC16A36298AE4110 [File is digitally signed]
C:\FRST\Quarantine\C\Users\Jim\SkyDrive\Pictures\Documents\x86_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_b2556b4035446b41.manifest.xBAD
[2020-05-10 22:15][2019-08-10 21:05] 000000608 _____ () E479732F7B82161E923B0DF5B5D09C59 [File not signed]
C:\FRST\Quarantine\C\Users\Jim\SkyDrive\Pictures\Documents\x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_99059a01de544235.cat.xBAD
[2020-05-10 22:15][2020-05-03 19:48] 000007457 _____ () F8999365A25BB341C55C70CB32DF2D46 [File is digitally signed]
C:\FRST\Quarantine\C\Users\Jim\SkyDrive\Pictures\Documents\x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_99059a01de544235.manifest.xBAD
[2020-05-10 22:15][2020-02-25 13:06] 000000750 _____ () 709C8063694781F6371E817243F0EB0F [File not signed]
C:\FRST\Quarantine\C\Users\Jim\SkyDrive\Pictures\Documents\x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_9de59bf3db287168.cat.xBAD
[2020-05-10 22:15][2020-05-03 19:48] 000007456 _____ () DFB0071CF316CD33F04392304A02A289 [File is digitally signed]
C:\FRST\Quarantine\C\Users\Jim\SkyDrive\Pictures\Documents\x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_9de59bf3db287168.manifest.xBAD
[2020-05-10 22:15][2020-02-25 13:06] 000000750 _____ () 8D1CB478D2A7A6AFAE2C38C6524EDA4B [File not signed]
C:\FRST\Quarantine\C\Users\Jim\SkyDrive\Pictures\Documents\AVAST Software\Avastbackend.txt.xBAD
[2020-05-10 22:15][2019-01-09 00:35] 000010380 _____ () 75F729C0EEC2289236AE30E53BA4DC87 [File not signed]
C:\FRST\Quarantine\C\Users\Jim\Searches\avast.search-ms.xBAD
[2020-05-10 22:08][2020-05-10 22:08] 000001973 _____ () 41925366CE74EBE05AC4DC79141AA3FE [File not signed]
C:\FRST\Quarantine\C\Users\Jim\Links\avast (2).lnk.xBAD
[2020-05-10 22:08][2020-05-10 22:08] 000000788 _____ () 7D3F216F471ADB16EED81B8A8A999893 [File not signed]
C:\FRST\Quarantine\C\Users\Jim\Links\avast.lnk.xBAD
[2020-05-10 21:46][2020-05-10 21:46] 000000626 _____ () AFF7DFDEA72559A4125D1C05FEEC6C03 [File not signed]
C:\FRST\Quarantine\C\Users\Jim\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Avast Secure Browser.lnk.xBAD
[2018-05-23 12:05][2020-02-25 12:08] 000002582 _____ () 5AB573C919309FE7154CC456A117D7D4 [File not signed]
C:\FRST\Quarantine\C\ProgramData\Microsoft\Windows\AppRepository\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_4.5.141.1_x64__bq6yxensn79aw.xml.xBAD
[2015-05-29 00:27][2015-05-29 00:27] 000008032 _____ () D76C146DBF1E8E4ADF7FB5B22727ED16 [File not signed]
C:\FRST\Quarantine\C\ProgramData\Microsoft\Windows\AppRepository\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw.xml.xBAD
[2018-04-03 15:16][2018-04-03 15:16] 000008032 _____ () BF661174EED69E970DA62F02EDC0E2AA [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\McAfeeIPTHostRTComponent.winmd
[2014-08-28 07:25][2014-08-28 07:25] 000015360 _____ (Daon) 2382858BA1B9ED6CC99284578785522E [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\Partner\images\logo_mcafee.png
[2018-04-03 15:17][2018-04-03 15:17] 000007087 _____ () E4CF58C09E2422CCD9B655ABA854E14B [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\Partner\images\logo_mcafee_login_snapview.png
[2018-04-03 15:17][2018-04-03 15:17] 000005092 _____ () 2367BA6D826456748AF4139327B3854F [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\Partner\images\logo_mcafee_snapview.png
[2018-04-03 15:17][2018-04-03 15:17] 000003937 _____ () EAF52B6227EEE200D8B54B48CC7B7EAF [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\Partner\images\rtl_logo_mcafee.png
[2018-04-03 15:17][2018-04-03 15:17] 000007058 _____ () DD1BBC243734FD2141E01C92108E6850 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\Partner\images\rtl_logo_mcafee_snapview.png
[2018-04-03 15:17][2018-04-03 15:17] 000003941 _____ () 41D6D1EBD4760E17ED4806A65EBDFC8A [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\js\account.mcafee.js
[2013-10-20 22:13][2013-10-20 22:13] 000001155 _____ () A31CF8096C24315C93C192060272C9A4 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\js\api.mcafee.js
[2015-12-08 17:02][2015-12-08 17:02] 000009021 _____ () EF8D76C5D175CA68B5CC6570AF136747 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\js\application.mcafee.js
[2018-04-03 15:17][2018-04-03 15:17] 000022129 _____ () 4E8C05354349C4EF041F10A4D68651C6 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\js\cache.mcafee.js
[2014-12-10 20:15][2014-12-10 20:15] 000003411 _____ () A1E407E2B0C03F7C802FBDEE6D33C979 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\js\constants.mcafee.js
[2015-12-08 17:02][2015-12-08 17:02] 000017681 _____ () E9F3C28163025700320AC1337CD83A73 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\js\data.mcafee.js
[2015-12-08 17:02][2015-12-08 17:02] 000024440 _____ () 5BF28C6573552A9408DD5B6106D1F031 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\js\demo.mcafee.js
[2015-12-08 17:02][2015-12-08 17:02] 000014218 _____ () A3BA5C7FFF9124F5191A988F548109B0 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\js\events.mcafee.js
[2013-10-20 22:13][2013-10-20 22:13] 000002661 _____ () F32DF3BC5BDBBEFABE6FEC77F140828B [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\js\idmap.playlist.mcafee.js
[2015-12-08 17:02][2015-12-08 17:02] 000022012 _____ () D7E4BCE642ED04C84199689A2635B92E [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\js\logger.mcafee.js
[2014-12-10 20:15][2014-12-10 20:15] 000010177 _____ () B2E0E2F180B9006D9966135D3A1E05A8 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\js\resources.mcafee.js
[2014-02-05 20:25][2014-02-05 20:26] 000001127 _____ () 5026813FA1B6C9866956D5F6FDE9C771 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\js\settings.mcafee.js
[2014-12-10 20:15][2014-12-10 20:15] 000006905 _____ () F0F66E474E0218BFC8B31703EA262AA9 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\js\telemetry.mcafee.js
[2014-12-10 20:15][2014-12-10 20:15] 000014650 _____ () 93AD4C1C8770158776FA8890A409ED39 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\js\thirdparty.mcafee.js
[2014-08-28 07:25][2014-08-28 07:25] 000000165 _____ () F04A2EB850AA3E2A5ADFE04C812E970A [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\js\utilities.mcafee.js
[2015-12-08 17:02][2015-12-08 17:02] 000046537 _____ () B14E8F676D9BC1C26A43D9CD690AA8E8 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\js\webview.mcafee.js
[2014-12-10 20:15][2014-12-10 20:15] 000012686 _____ () EF4EC375A649578BB1CB86D602E01E61 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\js\wrapper.mcafee.js
[2015-12-08 17:02][2015-12-08 17:02] 000012801 _____ () 95F9D6F834B6D124247B4B6C6604142E [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\js\wstore.mcafee.js
[2015-12-08 17:02][2015-12-08 17:02] 000035359 _____ () DBDD5274365064319466608710C9DB0D [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\js\xdata.mcafee.js
[2015-12-08 17:02][2015-12-08 17:02] 000017225 _____ () 0AAFF02F0EC8878C081091955BDDFB97 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\logo_filledview_mcafee.png
[2018-04-03 15:17][2018-04-03 15:17] 000005564 _____ () 9E12E5CE26C5653C05C7CCB3660EB63C [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\logo_mcafee.png
[2013-10-20 22:13][2013-10-20 22:13] 000003058 _____ () 30E2C595B73F65E133F1E88C7219A873 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\zh-cn\McAfeeLargeLogo.scale-100.png
[2015-12-08 17:02][2015-12-08 17:02] 000030660 _____ () 75F6E001294D409CE9D4DB3B129C630A [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\zh-cn\McAfeeLargeLogo.scale-140.png
[2015-12-08 17:02][2015-12-08 17:02] 000043175 _____ () B28B8704AFFF713A54DB048BDC3877DF [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\zh-cn\McAfeeLargeLogo.scale-180.png
[2015-12-08 17:02][2015-12-08 17:02] 000055794 _____ () AB6475A30CDA6A44AFFB5E807354B950 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\zh-cn\McAfeeLargeLogo.scale-80.png
[2015-12-08 17:02][2015-12-08 17:02] 000025288 _____ () 8F0986B39F0A13405CFF327EE053955A [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\zh-cn\McafeeSquareLogo.scale-100.png
[2013-10-20 22:13][2013-10-20 22:13] 000005601 _____ () 4B6FC6A5B813D345D1029950B78189C8 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\zh-cn\McafeeSquareLogo.scale-140.png
[2013-10-20 22:13][2013-10-20 22:13] 000007510 _____ () FAD52590BB303074920675747538AB74 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\zh-cn\McafeeSquareLogo.scale-180.png
[2013-10-20 22:13][2013-10-20 22:13] 000009598 _____ () 725B32424ED3CB08310AC7E9D3B86525 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\zh-cn\McafeeSquareLogo.scale-80.png
[2013-10-20 22:13][2013-10-20 22:13] 000004859 _____ () 68E0CC79368D2729564CFEFD842FD24C [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\zh-cn\McAfeeWideLogo.scale-100.png
[2013-10-20 22:13][2013-10-20 22:13] 000005285 _____ () CF90A5189891D363DD83F7307C077B46 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\zh-cn\McAfeeWideLogo.scale-140.png
[2013-10-20 22:13][2013-10-20 22:13] 000006606 _____ () E97C9E500BE8D33272DA83A96E5E8A63 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\zh-cn\McAfeeWideLogo.scale-180.png
[2013-10-20 22:13][2013-10-20 22:13] 000008556 _____ () 7DCB5CF4D8830B9846EB45D82197A873 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\zh-cn\McAfeeWideLogo.scale-80.png
[2013-10-20 22:13][2013-10-20 22:13] 000004422 _____ () A65CFEDE94BCB86BAE9F15B76FB6DFCD [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\win_store\Logo_splash_mcafee.scale-100.png
[2013-10-20 22:13][2013-10-20 22:13] 000005622 _____ () EBDD27803F3B74D3B73344526E5D662D [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\win_store\Logo_splash_mcafee.scale-140.png
[2013-10-20 22:13][2013-10-20 22:13] 000007497 _____ () 06EB1716E664C21B4CC10E3F388D8CB8 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\win_store\Logo_splash_mcafee.scale-180.png
[2013-10-20 22:13][2013-10-20 22:13] 000010499 _____ () B4A2E9CD9D3E8FA9E52F2487826279EE [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\win_store\McafeeSmallLogo.scale-100.png
[2014-12-10 20:15][2014-12-10 20:15] 000003725 _____ () 139ED50BDE20C4FF4B9CED83CD347C6E [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\win_store\McafeeSmallLogo.targetsize-16.png
[2013-10-20 22:13][2013-10-20 22:13] 000001403 _____ () B5ACD4CA21411AEBDB3B4D999EFEFB71 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\win_store\McafeeSmallLogo.targetsize-256.png
[2014-12-10 20:15][2014-12-10 20:15] 000005972 _____ () 12EE875FE7310067E1B14948E5B5C54A [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\win_store\McafeeSmallLogo.targetsize-32.png
[2014-12-10 20:15][2014-12-10 20:15] 000001037 _____ () 2BBACEF9809555973934F0023C7BDD73 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\win_store\McafeeSmallLogo.targetsize-48.png
[2014-12-10 20:15][2014-12-10 20:15] 000001465 _____ () 8406FC0E1D7DA7DD51FB791C8AF3AD02 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\win_store\McafeeStoreLogo.scale-100.png
[2014-12-10 20:15][2014-12-10 20:15] 000002377 _____ () 5D76524B6A1FDF0CAF6A643FA2A18FDF [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\win_store\McafeeStoreLogo.scale-140.png
[2014-12-10 20:15][2014-12-10 20:15] 000003625 _____ () 7D9985E22CD815821F654EE06110CAEE [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\win_store\McafeeStoreLogo.scale-180.png
[2014-12-10 20:15][2014-12-10 20:15] 000002560 _____ () 468D56989AEA3AD695D8D591CCD54875 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\ko\McAfeeLargeLogo.scale-100.png
[2015-12-08 17:02][2015-12-08 17:02] 000029514 _____ () 7804977FCFB952A294996351B7811F18 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\ko\McAfeeLargeLogo.scale-140.png
[2015-12-08 17:02][2015-12-08 17:02] 000042279 _____ () D88A02B80AB222EAE4626BDF745DBF37 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\ko\McAfeeLargeLogo.scale-180.png
[2015-12-08 17:02][2015-12-08 17:02] 000055033 _____ () 8283204E208C89FA34DF26D08C2999C3 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\ko\McAfeeLargeLogo.scale-80.png
[2015-12-08 17:02][2015-12-08 17:02] 000024886 _____ () FE88042B4939BBD782306FF8ED8227F2 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\ko\McafeeSquareLogo.scale-100.png
[2013-10-20 22:13][2013-10-20 22:13] 000005420 _____ () 8FD27A5D29A916D6F6EA4A3507C51C0A [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\ko\McafeeSquareLogo.scale-140.png
[2013-10-20 22:13][2013-10-20 22:13] 000007424 _____ () 2D789B1668E2E96750760E17393AF48B [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\ko\McafeeSquareLogo.scale-180.png
[2013-10-20 22:13][2013-10-20 22:13] 000009496 _____ () 946B56461299BE3F409466F5234A7CA5 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\ko\McafeeSquareLogo.scale-80.png
[2013-10-20 22:13][2013-10-20 22:13] 000004796 _____ () C2F26B15FF773028E232A1F54F5485F0 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\ko\McAfeeWideLogo.scale-100.png
[2013-10-20 22:13][2013-10-20 22:13] 000005095 _____ () FB6525F58924E291BC3DB2D52120492B [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\ko\McAfeeWideLogo.scale-140.png
[2013-10-20 22:13][2013-10-20 22:13] 000006601 _____ () 5D9B6FDA7C53D3008BF9DF3FFD954C3C [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\ko\McAfeeWideLogo.scale-180.png
[2013-10-20 22:13][2013-10-20 22:13] 000008472 _____ () 1DAF873295FAC129BCB86057F6A84258 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\ko\McAfeeWideLogo.scale-80.png
[2013-10-20 22:13][2013-10-20 22:13] 000004356 _____ () CCDA82EC0AE32C9CCA41E563ECCB904D [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\ja\McAfeeLargeLogo.scale-100.png
[2015-12-08 17:02][2015-12-08 17:02] 000029889 _____ () 8D43518C51C0EB61D7541D10ADC44BC0 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\ja\McAfeeLargeLogo.scale-140.png
[2015-12-08 17:02][2015-12-08 17:02] 000042115 _____ () FA59EA2AF5A8ED632FE435A01ED15A85 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\ja\McAfeeLargeLogo.scale-180.png
[2015-12-08 17:02][2015-12-08 17:02] 000055397 _____ () 63F5AE4FA2BD8050910880818F3AB519 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\ja\McAfeeLargeLogo.scale-80.png
[2015-12-08 17:02][2015-12-08 17:02] 000024823 _____ () BCFD1F184540950CF5F5D22D80B23290 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\ja\McafeeSquareLogo.scale-100.png
[2013-10-20 22:13][2013-10-20 22:13] 000005615 _____ () 7ABC53BE19C6CECAD8ACD030801D7CCC [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\ja\McafeeSquareLogo.scale-140.png
[2013-10-20 22:13][2013-10-20 22:13] 000007600 _____ () 599A913EDE6A1B57653F7FE5333EB450 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\ja\McafeeSquareLogo.scale-180.png
[2013-10-20 22:13][2013-10-20 22:13] 000009771 _____ () 59833802843A4713BB07FBC19D40EFBB [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\ja\McafeeSquareLogo.scale-80.png
[2013-10-20 22:13][2013-10-20 22:13] 000004874 _____ () B765CC6495B0B6D002A7E4A2776B2DE9 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\ja\McAfeeWideLogo.scale-100.png
[2013-10-20 22:13][2013-10-20 22:13] 000005389 _____ () 5AF7DDFB2FD9EBF6840C8A02BDF31588 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\ja\McAfeeWideLogo.scale-140.png
[2013-10-20 22:13][2013-10-20 22:13] 000006985 _____ () 77F2F3E89A0445E724FB50CF5B0B6B58 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\ja\McAfeeWideLogo.scale-180.png
[2013-10-20 22:13][2013-10-20 22:13] 000009133 _____ () 26820A81FD4D69C5A54FA1D91B172C3F [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\ja\McAfeeWideLogo.scale-80.png
[2013-10-20 22:13][2013-10-20 22:13] 000004483 _____ () CE6D876D309FD34484EA81A514C15B2A [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\en-us\McAfeeLargeLogo.scale-100.png
[2014-12-10 20:15][2014-12-10 20:15] 000006846 _____ () 36510451A058A137D91C7307E8CD5BE0 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\en-us\McAfeeLargeLogo.scale-140.png
[2014-12-10 20:15][2014-12-10 20:15] 000010433 _____ () F23D471857EB25AE9B18BF5F0BC3EC4D [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\en-us\McAfeeLargeLogo.scale-180.png
[2014-12-10 20:15][2014-12-10 20:15] 000013768 _____ () 78790D3B7D52A19F1018AED8585CDDF8 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\en-us\McAfeeLargeLogo.scale-80.png
[2014-12-10 20:15][2014-12-10 20:15] 000005816 _____ () FA0B0B49690E3CC1EF8ADED1C48471FF [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\en-us\McAfeeSmallLogo.scale-100.png
[2014-12-10 20:15][2014-12-10 20:15] 000003666 _____ () 12E87C318DF255F9A20C903A1F1E5BCC [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\en-us\McAfeeSmallLogo.scale-140.png
[2014-12-10 20:15][2014-12-10 20:15] 000001955 _____ () 576F094E90E295D0B0719765B4E4DE8F [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\en-us\McAfeeSmallLogo.scale-180.png
[2014-12-10 20:15][2014-12-10 20:15] 000002194 _____ () F082A6B11E13CBC5A647DC1A2C392432 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\en-us\McAfeeSmallLogo.scale-80.png
[2014-12-10 20:15][2014-12-10 20:15] 000002701 _____ () 56FCF4D6D401CC549E0E90648639B83E [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\en-us\McafeeSquareLogo.scale-100.png
[2013-10-20 22:13][2013-10-20 22:13] 000005820 _____ () 47221A4C8ECFF65677095832AACFFA57 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\en-us\McafeeSquareLogo.scale-140.png
[2013-10-20 22:13][2013-10-20 22:13] 000007620 _____ () B53C03470111014C6B2D2904F43750FA [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\en-us\McafeeSquareLogo.scale-180.png
[2013-10-20 22:13][2013-10-20 22:13] 000009980 _____ () 07215F67629113602EF01949D87992A5 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\en-us\McafeeSquareLogo.scale-80.png
[2013-10-20 22:13][2013-10-20 22:13] 000004669 _____ () 291846D6B91FC9CA1614C414553E87F8 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\en-us\McAfeeWideLogo.scale-100.png
[2013-10-20 22:13][2013-10-20 22:13] 000005172 _____ () 2A170127B6E0A75B82325FE4902041E6 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\en-us\McAfeeWideLogo.scale-140.png
[2013-10-20 22:13][2013-10-20 22:13] 000006948 _____ () EAB8C63656F9D2A0CA3353D9CC18A246 [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\en-us\McAfeeWideLogo.scale-180.png
[2013-10-20 22:13][2013-10-20 22:13] 000008776 _____ () 3C3E372F01B04F017494929EB0A8859B [File not signed]
C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw\images\en-us\McAfeeWideLogo.scale-80.png
[2013-10-20 22:13][2013-10-20 22:13] 000004344 _____ () EDA095879CD1146E2ACFF6DBA2D3B373 [File not signed]
C:\FRST\Quarantine\C\FRST\Quarantine\C\WINDOWS\System32\Tasks\AVAST Software\Avast settings backup.xBAD
[2019-08-10 19:54][2019-08-10 19:54] 000002876 _____ () 15477E3DB06E1308B5608538A5FB3984 [File not signed]
C:\FRST\Quarantine\C\FRST\Quarantine\C\Users\Jim\Downloads\avast_free_antivirus_setup_online.exe.xBAD.xBAD
[2020-05-03 14:40][2020-05-03 14:40] 000230080 _____ (AVAST Software) F6C3AE9D57FA30F04321FDD3CE814479 [File is digitally signed]

folder:
========
2014-11-15 18:56 - 2014-11-15 18:56 _____ C:\FRST\Quarantine\C\AVAST Software
2019-08-10 20:56 - 2019-08-10 20:56 _____ C:\FRST\Quarantine\C\WINDOWS\WinSxS\amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396
2020-02-25 13:06 - 2020-02-25 13:06 _____ C:\FRST\Quarantine\C\WINDOWS\WinSxS\amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5e69e83710ea31f5
2020-02-25 13:06 - 2020-02-25 13:06 _____ C:\FRST\Quarantine\C\WINDOWS\WinSxS\amd64_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_6349ea290dbe6128
2019-08-10 20:59 - 2019-08-10 20:59 _____ C:\FRST\Quarantine\C\WINDOWS\WinSxS\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c
2020-02-25 13:06 - 2020-02-25 13:06 _____ C:\FRST\Quarantine\C\WINDOWS\WinSxS\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_a6171f0e25665afb
2020-02-25 13:06 - 2020-02-25 13:06 _____ C:\FRST\Quarantine\C\WINDOWS\WinSxS\x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_aaf72100223a8a2e
2020-05-25 14:21 - 2020-05-25 14:21 _____ C:\FRST\Quarantine\C\WINDOWS\System32\Tasks_Migrated\AVAST Software
2018-06-29 19:08 - 2020-05-25 14:21 _____ C:\FRST\Quarantine\C\WINDOWS\System32\Tasks_Migrated\AVAST Software\AVAST Software
2020-05-10 22:15 - 2020-05-10 22:15 _____ C:\FRST\Quarantine\C\Users\Jim\SkyDrive\Pictures\Documents\amd64_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_d58a6d64ab65b396
2020-05-10 22:15 - 2020-05-10 22:15 _____ C:\FRST\Quarantine\C\Users\Jim\SkyDrive\Pictures\Documents\amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5e69e83710ea31f5
2020-05-10 22:15 - 2020-05-10 22:15 _____ C:\FRST\Quarantine\C\Users\Jim\SkyDrive\Pictures\Documents\amd64_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_6349ea290dbe6128
2020-05-10 22:15 - 2020-05-10 22:15 _____ C:\FRST\Quarantine\C\Users\Jim\SkyDrive\Pictures\Documents\Avast
2020-05-25 14:21 - 2020-05-25 14:21 _____ C:\FRST\Quarantine\C\Users\Jim\SkyDrive\Pictures\Documents\AVAST Software
2020-05-10 22:15 - 2020-05-10 22:15 _____ C:\FRST\Quarantine\C\Users\Jim\SkyDrive\Pictures\Documents\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c
2020-05-10 22:15 - 2020-05-10 22:15 _____ C:\FRST\Quarantine\C\Users\Jim\SkyDrive\Pictures\Documents\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_a6171f0e25665afb
2020-05-10 22:15 - 2020-05-10 22:15 _____ C:\FRST\Quarantine\C\Users\Jim\SkyDrive\Pictures\Documents\x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.28127.0_none_aaf72100223a8a2e
2020-05-10 22:15 - 2020-05-05 17:01 _____ C:\FRST\Quarantine\C\Users\Jim\SkyDrive\Pictures\Documents\_avast_
2020-05-10 22:15 - 2020-05-25 14:21 _____ C:\FRST\Quarantine\C\Users\Jim\SkyDrive\Pictures\Documents\AVAST Software\AVAST Software
2020-05-10 22:15 - 2020-05-10 22:15 _____ C:\FRST\Quarantine\C\Users\Jim\SkyDrive\Pictures\Documents\AVAST Software\AVAST Software\Avast
2020-05-14 13:39 - 2020-05-14 13:40 _____ C:\FRST\Quarantine\C\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Browser Cleanup
2020-05-14 13:41 - 2020-05-14 13:41 _____ C:\FRST\Quarantine\C\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Browser Cleanup(1)
2020-05-14 13:53 - 2020-05-14 13:53 _____ C:\FRST\Quarantine\C\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Browser Cleanup(2)
2020-05-14 13:06 - 2020-05-14 13:06 _____ C:\FRST\Quarantine\C\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Free Antivirus
2020-05-14 13:57 - 2020-05-14 13:57 _____ C:\FRST\Quarantine\C\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Free Antivirus(1)
2020-05-14 13:58 - 2020-05-14 13:58 _____ C:\FRST\Quarantine\C\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Free Antivirus(2)
2020-05-14 13:59 - 2020-05-14 13:59 _____ C:\FRST\Quarantine\C\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Free Antivirus(3)
2020-05-14 13:59 - 2020-05-14 13:59 _____ C:\FRST\Quarantine\C\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Free Antivirus(4)
2020-05-14 13:41 - 2020-05-14 13:41 _____ C:\FRST\Quarantine\C\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Pro Antivirus
2020-05-14 14:00 - 2020-05-14 14:00 _____ C:\FRST\Quarantine\C\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\Avast Pro Antivirus(1)
2020-05-14 13:37 - 2020-05-14 13:37 _____ C:\FRST\Quarantine\C\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee LiveSafe
2020-05-14 14:01 - 2020-05-14 14:01 _____ C:\FRST\Quarantine\C\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee LiveSafe(1)
2020-05-14 14:02 - 2020-05-14 14:02 _____ C:\FRST\Quarantine\C\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee LiveSafe(2)
2020-05-14 14:03 - 2020-05-14 14:03 _____ C:\FRST\Quarantine\C\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee LiveSafe(3)
2020-05-14 14:04 - 2020-05-14 14:04 _____ C:\FRST\Quarantine\C\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee LiveSafe(4)
2020-05-14 14:05 - 2020-05-14 14:05 _____ C:\FRST\Quarantine\C\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee LiveSafe(5)
2020-05-14 13:36 - 2020-05-14 13:36 _____ C:\FRST\Quarantine\C\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee Security Scan Plus
2020-05-14 14:06 - 2020-05-14 14:06 _____ C:\FRST\Quarantine\C\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee Security Scan Plus(1)
2020-05-14 13:38 - 2020-05-14 13:38 _____ C:\FRST\Quarantine\C\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee WebAdvisor
2020-05-14 14:06 - 2020-05-14 14:06 _____ C:\FRST\Quarantine\C\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\Logs\McAfee WebAdvisor(1)
2020-05-14 13:42 - 2020-05-14 13:42 _____ C:\FRST\Quarantine\C\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\Avast-14052020-134203
2020-05-14 13:42 - 2020-05-14 13:42 _____ C:\FRST\Quarantine\C\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\Avast-14052020-134250
2020-05-14 13:47 - 2020-05-14 13:47 _____ C:\FRST\Quarantine\C\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\Avast-14052020-134720
2020-05-14 13:57 - 2020-05-14 13:57 _____ C:\FRST\Quarantine\C\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\Avast-14052020-135743
2020-05-14 13:57 - 2020-05-14 13:57 _____ C:\FRST\Quarantine\C\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\Avast-14052020-135752
2020-05-20 15:14 - 2020-05-20 15:14 _____ C:\FRST\Quarantine\C\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\Avast-20052020-151429
2020-05-20 15:44 - 2020-05-20 15:44 _____ C:\FRST\Quarantine\C\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\Avast-20052020-154404
2020-05-23 18:25 - 2020-05-23 18:25 _____ C:\FRST\Quarantine\C\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\Avast-23052020-182559
2020-05-14 13:39 - 2020-05-14 13:39 _____ C:\FRST\Quarantine\C\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\McAfee-14052020-133905
2020-05-14 14:01 - 2020-05-14 14:01 _____ C:\FRST\Quarantine\C\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\McAfee-14052020-140130
2020-05-14 14:01 - 2020-05-14 14:01 _____ C:\FRST\Quarantine\C\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\McAfee-14052020-140151
2020-05-14 14:02 - 2020-05-14 14:02 _____ C:\FRST\Quarantine\C\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\McAfee-14052020-140240
2020-05-14 14:02 - 2020-05-14 14:02 _____ C:\FRST\Quarantine\C\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\McAfee-14052020-140248
2020-05-14 14:03 - 2020-05-14 14:03 _____ C:\FRST\Quarantine\C\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\McAfee-14052020-140332
2020-05-14 14:03 - 2020-05-14 14:03 _____ C:\FRST\Quarantine\C\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\McAfee-14052020-140342
2020-05-14 14:04 - 2020-05-14 14:04 _____ C:\FRST\Quarantine\C\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\McAfee-14052020-140435
2020-05-14 14:05 - 2020-05-14 14:05 _____ C:\FRST\Quarantine\C\Users\Jim\AppData\Local\VS Revo Group\Revo Uninstaller Pro\BackUpsData\McAfee-14052020-140529
2018-04-03 15:16 - 2018-04-03 15:17 _____ C:\FRST\Quarantine\C\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw
2020-05-21 13:39 - 2020-05-25 14:21 _____ C:\FRST\Quarantine\C\FRST\Quarantine\C\WINDOWS\System32\Tasks\AVAST Software
2019-08-10 19:54 - 2020-05-21 13:39 _____ C:\FRST\Quarantine\C\FRST\Quarantine\C\WINDOWS\System32\Tasks\AVAST Software\AVAST Software
2014-11-15 18:56 - 2014-11-15 18:56 _____ C:\FRST\Quarantine\C\AVAST Software\Avast
Registry:
========
===================== Search result for "Avast" ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\Av\{8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}]
"DISPLAYNAME"="Avast Antivirus"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\Av\{8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}]
"PRODUCTEXE"="C:\Program Files\AVAST Software\Avast\wsc_proxy.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\Av\{8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}]
"REPORTINGEXE"="C:\Program Files\AVAST Software\Avast\wsc_proxy.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\Av\{EB19B86E-3998-C706-90EF-92B41EB091AF}]
"DISPLAYNAME"="Avast Antivirus"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\Av\{EB19B86E-3998-C706-90EF-92B41EB091AF}]
"PRODUCTEXE"="C:\Program Files\AVAST Software\Avast\wsc_proxy.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\Av\{EB19B86E-3998-C706-90EF-92B41EB091AF}]
"REPORTINGEXE"="C:\Program Files\AVAST Software\Avast\wsc_proxy.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"x86_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_b2556b4035446b41"="0x706F6C6963792E31312E302E41766173742E56433131302E4352542C2043756C747572653D6E65757472616C2C20547970653D77696E33322D706F6C6963792C2056657273696F6E3D31312E302E36303631302E312C205075626C69634B6579546F6B656E3D323033366231346131316538336534612C2050726F636573736F724172636869746563747572653D783836"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\IsolatedSxSAssemblies]
"amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.28127.0_none_5e69e83710ea31f5"="0x41766173742E56433134302E4352542C2043756C747572653D6E65757472616C2C20547970653D77696E33322C2056657273696F6E3D31342E302E32383132372E302C205075626C69634B6579546F6B656E3D666363393965653631393365626263612C2050726F636573736F724172636869746563747572653D616D643634"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsSelfHost\OneSettings]
"TargetingAttributes"="{
  "Version": 94,
  "SchemaVersion": 1,
  "PartA": [
    "App",
    "AppVer",
    "AttrDataVer"
  ],
  "Default": [
    "DeviceFamily",
    "f:FlightRing",
    "t:OSVersionFull"
  ],
  "PartB": {
    "ACSOVERRIDE": [
      "OSArchitecture",
      "c:IsAlwaysOnAlwaysConnectedCapable"
    ],
    "CDM": [
      "ChassisTypeId",
      "r:CurrentBranch",
      "DeviceFamily",
      "f:FlightingBranchName",
      "f:FlightRing",
      "c:InstallLanguage",
      "c:IsDomainJoined",
      "t:IsTestLab",
      "OEMModel",
      "OSArchitecture",
      "OSVersion",
      "t:OSSkuId",
      "c:ProcessorIdentifier",
      "c:TelemetryLevel",
      "t:IsMsftOwned",
      "t:WCOSProductId",
      "c:OSUILocale",
      "c:CommercialId",
      "s:MinShellVersion",
      "s:MaxShellVersion",
      "c:ActivationChannel",
      "c:SCCMClientId",
      "c:IsCloudDomainJoined"
    ],
    "COMPATLOGGER": [
      "osVer",
      "ring",
      "deviceId"
    ],
    "CORTANA_GATEKEEPER": [
      "r:CurrentBranch",
      "f:FlightRing",
      "f:IsRetailOS"
    ],
    "CORTANAUWP": [
      "c:OSUILocale",
      "t:OSVersionFull",
      "v:CortanaAppVer"
    ],
    "CORTANAUWPTEST": [
      "+CORTANAUWP",
      "v:CortanaAppVerTest"
    ],
    "CTAC": [
      "+FSS"
    ],
    "DDC": [
      "+WU_STORE",
      "+_WU_PTI"
    ],
    "DXDB": [
      "DeviceFamily",
      "f:FlightRing",
      "r:IsHybridOrXGpu",
      "t:OSVersionFull"
    ],
    "EDGE_SERVICEUI": [
      "t:LocalDeviceID",
      "t:LocalUserID"
    ],
    "FCON": [
      "+CDM"
    ],
    "FSS": [
      "r:PreviewBuildsManagerEnabled",
      "f:BranchReadinessLevelRaw",
      "u:BranchReadinessLevelSource",
      "r:BuildFID",
      "t:DeviceFamily",
      "DeviceId",
      "c:EnablePreviewBuilds",
      "f:FlightingPolicyValue",
      "f:IsRetailOS",
      "f:ManagePreviewBuilds",
      "OSVersionFull",
      "t:WCOSProductId",
      "r:SmartActiveHoursState",
      "r:ActiveHoursStart",
      "r:ActiveHoursEnd"
    ],
    "FXIRISCLIENT": [
      "+IRISCLIENT"
    ],
    "IRISCLIENT": [
      "DeviceFamily",
      "OSVersion",
      "t:OSSkuId",
      "OSArchitecture",
      "c:TelemetryLevel",
      "f:FlightRing",
      "f:FlightingBranchName",
      "c:InternalPrimaryDisplayResolutionHorizontal",
      "c:InternalPrimaryDisplayResolutionVetical",
      "t:IsMsftOwned",
      "c:ChassisType",
      "c:IsDomainJoined",
      "c:ProcessorIdentifier",
      "c:CommercialId",
      "OEMModel",
      "c:OSUILocale",
      "c:OSEdition",
      "c:FlightIds",
      "t:LocalUserID"
    ],
    "MICROSOFT.WINDOWSFEEDBACKHUB_8WEKYB3D8BBWE": [
      "t:OSVersionFull",
      "t:IsTestLab",
      "f:FlightRing"
    ],
    "MITIGATION": [
      "t:DeviceFamily",
      "f:FlightRing",
      "c:FlightIds",
      "c:IsDomainJoined",
      "t:IsMsftOwned",
      "f:IsRetailOS",
      "t:IsTestLab",
      "IsVM",
      "OEMModel",
      "c:OSEdition",
      "t:OSSkuId",
      "t:OSVersionFull",
      "c:OSUILocale",
      "t:SMode",
      "f:IsFlightingEnabled",
      "c:FirmwareVersion",
      "c:TelemetryLevel",
      "f:FlightingBranchName",
      "r:CurrentBranch",
      "OSVersion"
    ],
    "MLMOD": [
      "ChassisTypeId",
      "t:DeviceFamily",
      "f:FlightingBranchName",
      "f:FlightRing",
      "f:IsRetailOS",
      "t:OSSkuId",
      "t:OSVersionFull",
      "c:OSUILocale",
      "OSVersion",
      "c:TelemetryLevel",
      "r:CurrentBranch"
    ],
    "MTP": [
      "+_WU_OS_CORE"
    ],
    "MUSE": [
      "+_WU_FB",
      "ChassisTypeId",
      "deviceClass",
      "deviceId",
      "c:FlightIds",
      "locale",
      "ms",
      "os",
      "osVer",
      "ring",
      "sampleId",
      "sku",
      "r:DaysSince19H1FUOffer",
      "u:DisableDualScan",
      "u:UpdateServiceUrl",
      "c:CommercialId",
      "f:FlightingBranchName"
    ],
    "NOISYHAMMER": [
      "+WU_OS"
    ],
    "SEDIMENTPACK": [
      "+WU_OS"
    ],
    "SETUP360": [
      "t:OSSkuId",
      "f:FlightRing"
    ],
    "STORAGEGROVELER": [
      "a:Free",
      "c:TelemetryLevel",
      "f:FlightRing",
      "f:IsFlightingEnabled",
      "IsVM",
      "t:OSVersionFull"
    ],
    "UTC": [
      "+UTC_STATIC",
      "osVer",
      "locale",
      "ring",
      "f:PilotRing",
      "f:IsRetailOS",
      "ms",
      "expId",
      "t:SMode",
      "f:FlightingBranchName",
      "c:CommercialId"
    ],
    "UTC_STATIC": [
      "os",
      "deviceId",
      "sampleId",
      "deviceClass",
      "sku",
      "OEMModel",
      "OEMName_Uncleaned",
      "c:PrimaryDiskType",
      "c:ProcessorModel",
      "c:TotalPhysicalRAM"
    ],
    "UUS": [
      "OSVersion",
      "f:FlightRing",
      "t:IsTestLab",
      "t:OSVersionFull",
      "f:FlightingBranchName",
      "r:CurrentBranch"
    ],
    "WAASASSESSMENT": [
      "+WU_OS"
    ],
    "WOSC": [
      "t:DeviceFamily",
      "f:FlightRing",
      "f:IsFlightingEnabled",
      "t:IsMsftOwned",
      "t:LocalDeviceID",
      "t:OSSkuId",
      "c:OSUILocale",
      "t:OSVersionFull",
      "c:TelemetryLevel",
      "r:IsHybridOrXGpu",
      "r:PlayFabPartyRelay"
    ],
    "WPSHIFT": [
      "+MTP"
    ],
    "WU": [
      "+WU_OS",
      "r:DUInternal"
    ],
    "_WU_AV": [
      "r:AvastReg",
      "r:AvastBlackScreen",
      "v:AvastVer",
      "r:AvgReg",
      "v:AvgVer",
      "r:EsetReg",
      "v:EsetVer",
      "r:KasperskyReg",
      "v:KasperskyVer",
      "v:SymantecVer",
      "r:TencentReg",
      "r:TencentType"
    ],
    "_WU_COMMON": [
      "r:CurrentBranch",
      "r:DefaultUserRegion",
      "DeviceFamily",
      "r:DriverPartnerRing",
      "r:FlightContent",
      "f:FlightingBranchName",
      "f:FlightRing",
      "HoloLens",
      "c:InstallationType",
      "c:InstallLanguage",
      "f:IsFlightingEnabled",
      "r:IsFlightingEnabled",
      "c:MobileOperatorCommercialized",
      "OEMModel",
      "OEMName_Uncleaned",
      "r:OemPartnerRing",
      "OSArchitecture",
      "OSVersion",
      "t:OSSkuId",
      "c:OSUILocale",
      "c:ProcessorManufacturer",
      "r:ReleaseType",
      "v:SkypeRoomSystem",
      "t:SMode",
      "c:TelemetryLevel",
      "r:WindowsMixedReality",
      "v:WuClientVer",
      "p:DucPublisherId",
      "p:DucDeviceModelId",
      "p:DucOemPartnerRing",
      "p:DucCustomPackageId",
      "p:DesiredOsVersion",
      "p:DesiredSystemManifestVersion"
    ],
    "_WU_FB": [
      "u:BranchReadinessLevel",
      "u:DeferQualityUpdatePeriodInDays",
      "u:DeferFeatureUpdatePeriodInDays",
      "r:PausedFeatureStatus",
      "r:PausedQualityStatus",
      "u:TargetReleaseVersion",
      "r:QUDeadline",
      "r:UpdatePreference",
      "r:UpdateOfferedDays"
    ],
    "WU_OS": [
      "+_WU_OS_CORE",
      "+_WU_FB"
    ],
    "_WU_OS_CORE": [
      "+_WU_COMMON",
      "+_WU_AV",
      "r:AhnLabKeyboard",
      "a:Bios",
      "r:BlockFeatureUpdates",
      "c:CommercialId",
      "a:DataVer_RS5",
      "r:DisconnectedStandby",
      "r:DchuNvidiaGrfxExists",
      "r:DchuNvidiaGrfxVen",
      "r:DchuIntelGrfxExists",
      "r:DchuIntelGrfxVen",
      "r:DchuAmdGrfxExists",
      "r:DchuAmdGrfxVen",
      "c:FirmwareVersion",
      "a:Free",
      "a:GStatus_RS3",
      "a:GStatus_RS4",
      "a:GStatus_RS5",
      "r:HidOverGattReg",
      "r:InstallDate",
      "c:IsDeviceRetailDemo",
      "c:IsPortableOperatingSystem",
      "IsVM",
      "c:OEMModelBaseBoard",
      "r:OobeSeeker",
      "r:OSRollbackBuild",
      "r:OSRollbackCount",
      "r:OSRollbackDate",
      "PhoneTargetingName",
      "r:PonchAllow",
      "r:PonchBlock",
      "c:ProcessorIdentifier",
      "r:RecoveredFromBuild",
      "r:RecoveredOnDate",
      "r:Steam",
      "v:TobiiVer",
      "v:TrendMicroVer",
      "r:UninstallActive",
      "l:UpdateManagementGroup",
      "a:UpgEx_RS3",
      "a:UpgEx_RS4",
      "a:UpgEx_RS5",
      "a:Version_RS5",
      "r:DisableWUfBOfferBlock",
      "a:UpgEx_19H1",
      "a:SdbVer_19H1",
      "a:GStatus_19H1",
      "a:GStatus_19H1Setup",
      "a:TimestampEpochString_19H1Setup",
      "a:GenTelRunTimestamp_19H1",
      "a:DataExpDateEpoch_19H1",
      "u:EnableWUfBUpgradeGates",
      "r:GStatusBlockIDs_All",
      "TimestampDelta_19H1Subtract19H1Setup",
      "DataExpDateDelta_19H1Subtract19H1Setup",
      "a:DataExpDateEpoch_19H1Setup",
      "a:TimestampEpochString_19H1",
      "r:IsContainerMgrInstalled",
      "r:IsWDAGEnabled",
      "r:MTPTargetingInfo",
      "r:EKB19H2InstallCount",
      "r:EKB19H2UnInstallCount",
      "r:EKB19H2InstallTimeEpoch",
      "r:EKB19H2UnInstallTimeEpoch",
      "r:BlockEdgeWithChromiumUpdate",
      "r:IsWDATPEnabled",
      "r:IsAutopilotRegistered",
      "r:EdgeWithChromiumInstallVersion",
      "r:EdgeWithChromiumInstallFailureCount",
      "r:IsEdgeWithChromiumInstalled",
      "r:KioskMode",
      "c:IsCloudDomainJoined",
      "c:IsDomainJoined",
      "p:DSS_Enrolled",
      "a:DataExpDateEpoch_20H1",
      "a:DataExpDateEpoch_20H1Setup",
      "a:GStatus_20H1",
      "a:GStatus_20H1Setup",
      "a:SdbVer_20H1",
      "a:TimestampEpochString_20H1",
      "a:TimestampEpochString_20H1Setup",
      "DataExpDateDelta_20H1Subtract20H1Setup",
      "TimestampDelta_20H1Subtract20H1Setup",
      "a:UpgEx_20H1",
      "r:AutopilotUpdateInProgress",
      "r:UHSEnrolled"
    ],
    "_WU_PTI": [
      "c:FrontFacingCameraResolution",
      "c:RearFacingCameraResolution",
      "c:TotalPhysicalRAM",
      "c:NFCProximity",
      "c:Magnetometer",
      "c:Gyroscope",
      "c:D3DMaxFeatureLevel",
      "c:InternalPrimaryDisplayResolutionHorizontal",
      "c:InternalPrimaryDisplayResolutionVetical"
    ],
    "WU_STORE": [
      "+_WU_COMMON",
      "r:AppChannels",
      "r:AppRMIDs",
      "u:BranchReadinessLevel"
    ]
  },
  "Required": [
    "App",
    "AppVer",
    "AttrDataVer"
  ],
  "Aliases": {
    "ChassisTypeId": "c:ChassisType",
    "DataExpDateDelta_19H1Subtract19H1Setup": "a:DataExpDateEpoch_19H1_Subtract_DataExpDateEpoch_19H1Setup",
    "DataExpDateDelta_20H1Subtract20H1Setup": "a:DataExpDateEpoch_20H1_Subtract_DataExpDateEpoch_20H1Setup",
    "deviceClass": "t:DeviceFamily",
    "deviceId": "t:LocalDeviceID",
    "DeviceId": "t:LocalDeviceID",
    "expId": "c:FlightIds",
    "FlightRing": "f:FlightRing",
    "IsVM": "a:ISVM",
    "locale": "c:OSUILocale",
    "ms": "t:IsMsftOwned",
    "OEMModel": "c:OEMModelNumber",
    "OEMName_Uncleaned": "c:OEMManufacturerName",
    "osVer": "t:OSVersionFull",
    "OSVersionFull": "t:OSVersionFull",
    "PhoneTargetingName": "c:OEMModelName",
    "ring": "f:FlightRing",
    "sampleId": "t:PopVal",
    "sku": "t:OSSkuId",
    "TimestampDelta_19H1Subtract19H1Setup": "a:TimestampEpochString_19H1_Subtract_TimestampEpochString_19H1Setup",
    "TimestampDelta_20H1Subtract20H1Setup": "a:TimestampEpochString_20H1_Subtract_TimestampEpochString_20H1Setup"
  },
  "Fallback": {
    "r:AvastBlackScreen": "r:AvgBlackScreen",
    "a:Bios": "a:Bios_RS3",
    "a:Bios_RS3": "a:Bios_RS4",
    "a:Bios_RS4": "a:Bios_RS5",
    "r:BlockFeatureUpdates": "r:BlockWUUpgrades",
    "r:BlockWUUpgrades": "r:BlockWUUpgradesWow",
    "r:BuildFID": "r:BuildFID_WCOS",
    "r:BuildFID_WCOS": "r:BuildFID_WCOS2",
    "r:DchuAmdGrfxVen": "r:DchuAmdGrfxVen2",
    "r:DchuAmdGrfxVen2": "r:DchuAmdGrfxDeletePending",
    "r:DchuIntelGrfxVen": "r:DchuIntelGrfxVen2",
    "r:DchuIntelGrfxVen2": "r:DchuIntelGrfxDeletePending",
    "r:DchuNvidiaGrfxVen": "r:DchuNvidiaGrfxVen2",
    "r:DchuNvidiaGrfxVen2": "r:DchuNvidiaGrfxDeletePending",
    "r:DriverPartnerRing": "r:OSDataDriverPartnerRing",
    "p:DSS_Enrolled": "r:DSS_EnrolledReg",
    "r:EdgeWithChromiumInstallFailureCount": "r:EdgeWithChromiumInstallFailureCountWow",
    "r:EdgeWithChromiumInstallVersion": "r:EdgeWithChromiumInstallVersionWow",
    "u:EnableWUfBUpgradeGates": "r:EnableWUfBUpgradeGatesRS5",
    "f:FlightingBranchName": "c:FlightingBranchName",
    "a:Free": "a:Free_RS3",
    "a:Free_RS3": "a:Free_RS4",
    "a:Free_RS4": "a:Free_RS5",
    "HoloLens": "r:WindowsMixedReality",
    "r:IsEdgeWithChromiumInstalled": "r:IsEdgeWithChromiumInstalledWow",
    "a:ISVM": "a:ISVM_RS3",
    "a:ISVM_RS3": "a:ISVM_RS4",
    "a:ISVM_RS4": "a:ISVM_RS5",
    "c:OEMModelBaseBoard": "r:OEMModelBaseBoard",
    "r:PonchAllow": "r:PonchAllowKey",
    "r:PonchAllowKey": "r:PonchAllowWow",
    "r:PonchAllowWow": "r:PonchAllowWowKey",
    "r:QUDeadline": "r:QUDeadlineMDM",
    "v:SymantecVer": "v:SymantecVer64",
    "u:TargetReleaseVersion": "r:TargetReleaseVersionGP",
    "r:TargetReleaseVersionGP": "r:TargetReleaseVersionMDM",
    "v:TobiiVer": "v:TobiiVerx86",
    "v:TobiiVerx86": "v:TobiiVer1x86"
  },
  "Transform": {
    "IsDomainJoined": {
      "Ignore": [
        "0"
      ]
    },
    "IsHybridOrXGpu": {
      "Ignore": [
        "0"
      ]
    },
    "IsMsftOwned": {
      "Ignore": [
        "0"
      ]
    },
    "IsPortableOperatingSystem": {
      "Ignore": [
        "0"
      ]
    },
    "IsTestLab": {
      "Ignore": [
        "0"
      ]
    },
    "IsVM": {
      "Ignore": [
        "0"
      ]
    },
    "OEMModel": {
      "SubLength": 100
    },
    "OEMName_Uncleaned": {
      "SubLength": 100
    },
    "PausedFeatureStatus": {
      "Ignore": [
        "0"
      ]
    },
    "PausedQualityStatus": {
      "Ignore": [
        "0"
      ]
    },
    "SMode": {
      "Ignore": [
        "0"
      ]
    }
  },
  "Registry": {
    "ActiveHoursEnd": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\WindowsUpdate\\UX\\Settings",
      "ValueName": "ActiveHoursEnd",
      "RegValueType": "REG_DWORD"
    },
    "ActiveHoursStart": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\WindowsUpdate\\UX\\Settings",
      "ValueName": "ActiveHoursStart",
      "RegValueType": "REG_DWORD"
    },
    "AhnLabKeyboard": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\Mkd2kfNt",
      "ValueName": "NbTpMsExist"
    },
    "AppChannels": {
      "FullPath": "SOFTWARE\\Policies\\Microsoft\\WindowsStore\\Apps\\*",
      "ValueName": "ChannelId",
      "EncodingType": "Json"
    },
    "AppRMIDs": {
      "FullPath": "SOFTWARE\\Policies\\Microsoft\\WindowsStore\\Apps\\*",
      "ValueName": "ReleaseManagementId",
      "EncodingType": "Json"
    },
    "AutopilotUpdateInProgress": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Provisioning\\AutopilotSettings\\VolatileAutopilotUpdate",
      "ValueName": "AutopilotUpdateInProgress",
      "RegValueType": "REG_DWORD"
    },
    "AvastBlackScreen": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\aswVmm\\Parameters",
      "ValueName": "Win10-1803"
    },
    "AvastReg": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\aswVmm\\Parameters",
      "ValueName": "QualityCompat"
    },
    "AvgBlackScreen": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\avgVmm\\Parameters",
      "ValueName": "Win10-1803"
    },
    "AvgReg": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\avgVmm\\Parameters",
      "ValueName": "QualityCompat"
    },
    "BlockEdgeWithChromiumUpdate": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\EdgeUpdate",
      "ValueName": "DoNotUpdateToEdgeWithChromium",
      "RegValueType": "REG_DWORD"
    },
    "BlockFeatureUpdates": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\WindowsUpdate\\OSUpgrade",
      "ValueName": "BlockFeatureUpdates",
      "RegValueType": "REG_DWORD"
    },
    "BlockWUUpgrades": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows10Upgrader\\Volatile",
      "ValueName": "BlockWUUpgrades",
      "RegValueType": "REG_DWORD"
    },
    "BlockWUUpgradesWow": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\WOW6432Node\\Microsoft\\Windows10Upgrader\\Volatile",
      "ValueName": "BlockWUUpgrades",
      "RegValueType": "REG_DWORD"
    },
    "BuildFID": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "Software\\Microsoft\\Windows\\CurrentVersion\\Flighting\\Build",
      "ValueName": "EsdFlightData",
      "RegValueType": "REG_SZ"
    },
    "BuildFID_WCOS": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "OSDATA\\Software\\Microsoft\\Windows\\CurrentVersion\\Flighting\\Build",
      "ValueName": "EsdFlightData",
      "RegValueType": "REG_SZ"
    },
    "BuildFID_WCOS2": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "OSDATA\\Microsoft\\Windows\\CurrentVersion\\Flighting\\Build",
      "ValueName": "EsdFlightData",
      "RegValueType": "REG_SZ"
    },
    "CurrentBranch": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion",
      "ValueName": "BuildBranch",
      "RegValueType": "REG_SZ"
    },
    "DaysSince19H1FUOffer": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\rempl\\irplugin",
      "ValueName": "DaysSinceLastOffer",
      "RegValueType": "REG_QWORD"
    },
    "DchuAmdGrfxDeletePending": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\amdkmdap",
      "ValueName": "DriverDelete"
    },
    "DchuAmdGrfxExists": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\amdkmdap",
      "IfExists": true
    },
    "DchuAmdGrfxVen": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\amdkmdap",
      "ValueName": "DCHUVen"
    },
    "DchuAmdGrfxVen2": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\amdkmdap\\Parameters",
      "ValueName": "DCHUVen"
    },
    "DchuIntelGrfxDeletePending": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\igfx",
      "ValueName": "DriverDelete"
    },
    "DchuIntelGrfxExists": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\igfx",
      "IfExists": true
    },
    "DchuIntelGrfxVen": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\igfx",
      "ValueName": "DCHUVen"
    },
    "DchuIntelGrfxVen2": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\igfx\\Parameters",
      "ValueName": "DCHUVen"
    },
    "DchuNvidiaGrfxDeletePending": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\nvlddmkm",
      "ValueName": "DriverDelete"
    },
    "DchuNvidiaGrfxExists": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\nvlddmkm",
      "IfExists": true
    },
    "DchuNvidiaGrfxVen": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\nvlddmkm",
      "ValueName": "DCHUVen"
    },
    "DchuNvidiaGrfxVen2": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\nvlddmkm\\Parameters",
      "ValueName": "DCHUVen"
    },
    "DefaultUserRegion": {
      "HKey": "HKEY_USERS",
      "FullPath": ".DEFAULT\\Control Panel\\International\\Geo",
      "ValueName": "Nation",
      "RegValueType": "REG_SZ"
    },
    "DisableWUfBOfferBlock": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\WindowsUpdate\\UpdatePolicy\\Settings",
      "ValueName": "DisableWUfBOfferBlock",
      "RegValueType": "REG_DWORD"
    },
    "DisconnectedStandby": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SYSTEM\\CurrentControlSet\\Control\\Power",
      "ValueName": "EnforceDisconnectedStandby",
      "RegValueType": "REG_DWORD"
    },
    "DriverPartnerRing": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\DriverFlighting\\Partner",
      "ValueName": "TargetRing",
      "RegValueType": "REG_SZ"
    },
    "DSS_EnrolledReg": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Policies\\Microsoft\\Windows\\WindowsUpdate",
      "ValueName": "EnableWUfBCloud",
      "RegValueType": "REG_DWORD"
    },
    "DUInternal": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SYSTEM\\Setup\\MoSetup",
      "ValueName": "DynamicUpdateInternalTest",
      "RegValueType": "REG_DWORD"
    },
    "EdgeWithChromiumInstallFailureCount": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\EdgeUpdate",
      "ValueName": "WindowsUpdateAttempts"
    },
    "EdgeWithChromiumInstallFailureCountWow": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Wow6432Node\\Microsoft\\EdgeUpdate",
      "ValueName": "WindowsUpdateAttempts"
    },
    "EdgeWithChromiumInstallVersion": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\EdgeUpdate",
      "ValueName": "WindowsUpdateVersion"
    },
    "EdgeWithChromiumInstallVersionWow": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Wow6432Node\\Microsoft\\EdgeUpdate",
      "ValueName": "WindowsUpdateVersion"
    },
    "EKB19H2InstallCount": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SYSTEM\\Setup\\FeatureStaging\\20455539\\2",
      "ValueName": "Count"
    },
    "EKB19H2InstallTimeEpoch": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SYSTEM\\Setup\\FeatureStaging\\20455539\\2",
      "ValueName": "Timestamp"
    },
    "EKB19H2UnInstallCount": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SYSTEM\\Setup\\FeatureStaging\\20455539\\0",
      "ValueName": "Count"
    },
    "EKB19H2UnInstallTimeEpoch": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SYSTEM\\Setup\\FeatureStaging\\20455539\\0",
      "ValueName": "Timestamp"
    },
    "EnableWUfBUpgradeGatesRS5": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "Software\\Microsoft\\Windows NT\\CurrentVersion\\502505fe-762c-4e80-911e-0c3fa4c63fb0",
      "ValueName": "DataRequireGatedScanForFeatureUpdates",
      "RegValueType": "REG_DWORD"
    },
    "EsetReg": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\ehdrv\\Parameters",
      "ValueName": "WindowsCompatibilityLevel",
      "RegValueType": "REG_DWORD"
    },
    "FlightContent": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\WindowsSelfHost\\Applicability",
      "ValueName": "ContentType",
      "RegValueType": "REG_SZ"
    },
    "GStatusBlockIDs_All": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\Appraiser\\GWX",
      "ValueName": "SdbEntries",
      "RegValueType": "REG_SZ"
    },
    "HidOverGattReg": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\PnpLockdownFiles\\%SystemRoot%/System32/drivers/UMDF/Microsoft.Bluetooth.Profiles.HidOverGatt.dll",
      "ValueName": "Source",
      "RegValueType": "REG_SZ"
    },
    "InstallDate": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion",
      "ValueName": "InstallDate",
      "RegValueType": "REG_DWORD"
    },
    "IsAutopilotRegistered": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Provisioning\\AutopilotPolicyCache",
      "ValueName": "ProfileAvailable",
      "RegValueType": "REG_DWORD"
    },
    "IsFlightingEnabled": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\WindowsSelfHost\\Applicability",
      "ValueName": "IsBuildFlightingEnabled",
      "RegValueType": "REG_DWORD"
    },
    "IsContainerMgrInstalled": {
      "FullPath": "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Containers\\CmService",
      "IfExists": true
    },
    "IsEdgeWithChromiumInstalled": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\EdgeUpdate\\Clients\\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}",
      "IfExists": true
    },
    "IsEdgeWithChromiumInstalledWow": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Wow6432Node\\Microsoft\\EdgeUpdate\\Clients\\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}",
      "IfExists": true
    },
    "IsHybridOrXGpu": {
      "FullPath": "SOFTWARE\\Microsoft\\DirectX",
      "ValueName": "HybridDeviceApplicableForDxDbGpuPreferences"
    },
    "IsWDAGEnabled": {
      "FullPath": "SYSTEM\\ControlSet001\\Services\\hvsics",
      "IfExists": true
    },
    "IsWDATPEnabled": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows Advanced Threat Protection\\Status",
      "ValueName": "OnboardingState"
    },
    "KasperskyReg": {
      "FullPath": "System\\CurrentControlSet\\Services\\klhk\\Parameters",
      "ValueName": "UseVtHardware"
    },
    "KioskMode": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows\\AssignedAccessCsp\\AutoLogonAccount",
      "ValueName": "ConfigSource",
      "RegValueType": "REG_DWORD"
    },
    "MTPTargetingInfo": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SYSTEM\\Platform\\MTPTargetingInfo",
      "ValueName": "TargetRing"
    },
    "OEMModelBaseBoard": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "HARDWARE\\DESCRIPTION\\System\\BIOS",
      "ValueName": "BaseBoardProduct",
      "RegValueType": "REG_SZ"
    },
    "OemPartnerRing": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SYSTEM\\Platform\\DeviceTargetingInfo",
      "ValueName": "TargetRing",
      "RegValueType": "REG_SZ"
    },
    "OobeSeeker": {
      "FullPath": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\OOBE\\Updates",
      "ValueName": "OOBEUpdateStarted"
    },
    "OSDataDriverPartnerRing": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "OSData\\SOFTWARE\\Microsoft\\DriverFlighting\\Partner",
      "ValueName": "TargetRing",
      "RegValueType": "REG_SZ"
    },
    "OSRollbackBuild": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\WindowsUpdate\\OSUpgrade\\Rollback",
      "ValueName": "BuildString",
      "RegValueType": "REG_SZ"
    },
    "OSRollbackCount": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\WindowsUpdate\\OSUpgrade\\Rollback",
      "ValueName": "Count",
      "RegValueType": "REG_DWORD"
    },
    "OSRollbackDate": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\WindowsUpdate\\OSUpgrade\\Rollback",
      "ValueName": "DateStamp",
      "RegValueType": "REG_DWORD"
    },
    "PausedFeatureStatus": {
      "FullPath": "SOFTWARE\\Microsoft\\WindowsUpdate\\UpdatePolicy\\Settings",
      "ValueName": "PausedFeatureStatus"
    },
    "PausedQualityStatus": {
      "FullPath": "SOFTWARE\\Microsoft\\WindowsUpdate\\UpdatePolicy\\Settings",
      "ValueName": "PausedQualityStatus"
    },
    "PlayFabPartyRelay": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\PlayFabPartyRelay",
      "IfExists": true
    },
    "PonchAllow": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\QualityCompat",
      "ValueName": "cadca5fe-87d3-4b96-b7fb-a231484277cc",
      "RegValueType": "REG_DWORD"
    },
    "PonchAllowKey": {
      "FullPath": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\QualityCompat\\cadca5fe-87d3-4b96-b7fb-a231484277cc",
      "IfExists": true
    },
    "PonchAllowWow": {
      "FullPath": "SOFTWARE\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\QualityCompat",
      "ValueName": "cadca5fe-87d3-4b96-b7fb-a231484277cc"
    },
    "PonchAllowWowKey": {
      "FullPath": "SOFTWARE\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\QualityCompat\\cadca5fe-87d3-4b96-b7fb-a231484277cc",
      "IfExists": true
    },
    "PonchBlock": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\QualityCompat",
      "ValueName": "65d75b03-6f4d-46e9-b870-517731e06cf9",
      "RegValueType": "REG_DWORD"
    },
    "PreviewBuildsManagerEnabled": {
      "FullPath": "SOFTWARE\\Microsoft\\WindowsSelfhost\\Manager",
      "ValueName": "ArePreviewBuildsAllowed"
    },
    "QUDeadline": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Policies\\Microsoft\\Windows\\WindowsUpdate",
      "ValueName": "ConfigureDeadlineForQualityUpdates",
      "RegValueType": "REG_DWORD"
    },
    "QUDeadlineMDM": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\PolicyManager\\current\\device\\Update",
      "ValueName": "ConfigureDeadlineForQualityUpdates",
      "RegValueType": "REG_DWORD"
    },
    "RecoveredFromBuild": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "Software\\Microsoft\\WindowsSelfHost\\Applicability\\RecoveredFrom",
      "ValueName": "LastBuild",
      "RegValueType": "REG_DWORD"
    },
    "RecoveredOnDate": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "Software\\Microsoft\\WindowsSelfHost\\Applicability\\RecoveredFrom",
      "ValueName": "DateStamp",
      "RegValueType": "REG_DWORD"
    },
    "ReleaseType": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Update\\TargetingInfo",
      "ValueName": "ReleaseType",
      "RegValueType": "REG_SZ"
    },
    "SmartActiveHoursState": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\WindowsUpdate\\UX\\Settings",
      "ValueName": "SmartActiveHoursState",
      "RegValueType": "REG_DWORD"
    },
    "Steam": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Classes\\Steam",
      "ValueName": "",
      "RegValueType": "REG_SZ"
    },
    "TargetReleaseVersionGP": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Policies\\Microsoft\\Windows\\WindowsUpdate",
      "ValueName": "TargetReleaseVersionInfo",
      "RegValueType": "REG_SZ"
    },
    "TargetReleaseVersionMDM": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\PolicyManager\\current\\device\\Update",
      "ValueName": "TargetReleaseVersion",
      "RegValueType": "REG_SZ"
    },
    "TencentReg": {
      "FullPath": "SYSTEM\\CurrentControlSet\\services\\TesSafe",
      "ValueName": "LoadStartTime"
    },
    "TencentType": {
      "FullPath": "SYSTEM\\CurrentControlSet\\services\\TesSafe",
      "ValueName": "Type"
    },
    "UHSEnrolled": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion",
      "ValueName": "UHSEnrolled",
      "RegValueType": "REG_SZ",
      "IfExists": true
    },
    "UninstallActive": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "System\\Setup",
      "ValueName": "UninstallActive",
      "RegValueType": "REG_DWORD"
    },
    "UpdateOfferedDays": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\WaaSAssessment\\Cache\\",
      "ValueName": "UpToDateDays",
      "RegValueType": "REG_DWORD"
    },
    "UpdatePreference": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Policies\\Microsoft\\Windows\\WindowsUpdate",
      "ValueName": "UpdatePreference",
      "RegValueType": "REG_DWORD"
    },
    "WindowsMixedReality": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\WUDF\\Services\\HoloLensSensors",
      "ValueName": "WdfMajorVersion",
      "RegValueType": "REG_DWORD"
    }
  },
  "FileInfo": {
    "AvastVer": {
      "Path": "\\system32\\Drivers\\aswVmm.sys",
      "FolderGuid": "{F38BF404-1D43-42F2-9305-67DE0B28FC23}"
    },
    "AvgVer": {
      "Path": "\\system32\\Drivers\\avgVmm.sys",
      "FolderGuid": "{F38BF404-1D43-42F2-9305-67DE0B28FC23}"
    },
    "CortanaAppVer": {
      "Path": "\\WindowsApps\\Microsoft.549981C3F5F10_8wekyb3d8bbwe\\CortanaApp.View.exe",
      "FolderGuid": "{905E63B6-C1BF-494E-B29C-65B732D3D21A}"
    },
    "CortanaAppVerTest": {
      "Path": "\\WindowsApps\\3242f7d9-db60-4380-a379-4205ea768bfc_1.0.0.0_x64__zs4v8rx04ex0m\\UndockingTestApp.exe",
      "FolderGuid": "{905E63B6-C1BF-494E-B29C-65B732D3D21A}"
    },
    "EsetVer": {
      "Path": "\\drivers\\ehdrv.sys",
      "FolderGuid": "{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}"
    },
    "KasperskyVer": {
      "Path": "\\system32\\Drivers\\klhk.sys",
      "FolderGuid": "{F38BF404-1D43-42F2-9305-67DE0B28FC23}"
    },
    "SkypeRoomSystem": {
      "Path": "%systemdrive%\\Recovery\\OEM\\$oem$\\$1\\Rigel\\x64\\Scripts\\Provisioning\\AutoUnattend.xml",
      "IfExists": true
    },
    "SymantecVer": {
      "Path": "\\Symantec\\Shared\\EENGINE\\eeCtrl.sys",
      "FolderGuid": "{DE974D24-D9C6-4D3E-BF91-F4455120B917}"
    },
    "SymantecVer64": {
      "Path": "\\Symantec\\Shared\\EENGINE\\eeCtrl64.sys",
      "FolderGuid": "{DE974D24-D9C6-4D3E-BF91-F4455120B917}"
    },
    "TobiiVer": {
      "Path": "\\Tobii\\Tobii EyeX Interaction\\Tobii.EyeX.Interaction.exe",
      "FolderGuid": "{905E63B6-C1BF-494E-B29C-65B732D3D21A}"
    },
    "TobiiVer1x86": {
      "Path": "\\Tobii\\tobii EyeX Interaction\\Tobii.EyeX.Interaction.exe",
      "FolderGuid": "{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}"
    },
    "TobiiVerx86": {
      "Path": "\\tobii EyeX Interaction\\Tobii.EyeX.Interaction.exe",
      "FolderGuid": "{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}"
    },
    "TrendMicroVer": {
      "Path": "\\drivers\\TMUMH.sys",
      "FolderGuid": "{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}"
    },
    "WuClientVer": {
      "Path": "\\system32\\wuaueng.dll",
      "FolderGuid": "{F38BF404-1D43-42F2-9305-67DE0B28FC23}"
    }
  },
  "Licensing": {
    "UpdateManagementGroup": {
      "Name": "UpdatePolicy-UpdateManagementGroup"
    }
  },
  "UpdatePolicy": {
    "BranchReadinessLevel": {
      "PolicyEnum": 5,
      "Enterprise": true
    },
    "BranchReadinessLevelSource": {
      "PolicyEnum": 5,
      "Enterprise": true,
      "UseSource": true
    },
    "DeferFeatureUpdatePeriodInDays": {
      "PolicyEnum": 9,
      "Enterprise": true
    },
    "DeferQualityUpdatePeriodInDays": {
      "PolicyEnum": 7,
      "Enterprise": true
    },
    "DisableDualScan": {
      "PolicyEnum": 42,
      "Enterprise": true
    },
    "EnableWUfBUpgradeGates": {
      "PolicyEnum": 51,
      "Enterprise": true
    },
    "TargetReleaseVersion": {
      "PolicyEnum": 50,
      "Enterprise": true
    },
    "UpdateServiceUrl": {
      "PolicyEnum": 12
    }
  },
  "Policy": {
    "DesiredOsVersion": {
      "LocUri": "./Device/Vendor/MSFT/DeviceUpdateCenter/DesiredUpdates/OsVersion"
    },
    "DesiredSystemManifestVersion": {
      "LocUri": "./Device/Vendor/MSFT/DeviceUpdateCenter/DesiredUpdates/SystemManifestVersion"
    },
    "DSS_Enrolled": {
      "Area": "Update",
      "Name": "EnableWUfBCloud"
    },
    "DucCustomPackageId": {
      "LocUri": "./Device/Vendor/MSFT/DeviceUpdateCenter/Enrollment/CustomPackageId"
    },
    "DucDeviceModelId": {
      "LocUri": "./Device/Vendor/MSFT/DeviceUpdateCenter/Enrollment/DeviceModelId"
    },
    "DucOemPartnerRing": {
      "LocUri": "./Device/Vendor/MSFT/DeviceUpdateCenter/Enrollment/OemPartnerRing"
    },
    "DucPublisherId": {
      "LocUri": "./Device/Vendor/MSFT/DeviceUpdateCenter/Enrollment/PublisherId"
    }
  }
}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsSelfHost\OneSettings]
"TargetingAttributesVerified"="{
  "Version": 94,
  "SchemaVersion": 1,
  "PartA": [
    "App",
    "AppVer",
    "AttrDataVer"
  ],
  "Default": [
    "DeviceFamily",
    "f:FlightRing",
    "t:OSVersionFull"
  ],
  "PartB": {
    "ACSOVERRIDE": [
      "OSArchitecture",
      "c:IsAlwaysOnAlwaysConnectedCapable"
    ],
    "CDM": [
      "ChassisTypeId",
      "r:CurrentBranch",
      "DeviceFamily",
      "f:FlightingBranchName",
      "f:FlightRing",
      "c:InstallLanguage",
      "c:IsDomainJoined",
      "t:IsTestLab",
      "OEMModel",
      "OSArchitecture",
      "OSVersion",
      "t:OSSkuId",
      "c:ProcessorIdentifier",
      "c:TelemetryLevel",
      "t:IsMsftOwned",
      "t:WCOSProductId",
      "c:OSUILocale",
      "c:CommercialId",
      "s:MinShellVersion",
      "s:MaxShellVersion",
      "c:ActivationChannel",
      "c:SCCMClientId",
      "c:IsCloudDomainJoined"
    ],
    "COMPATLOGGER": [
      "osVer",
      "ring",
      "deviceId"
    ],
    "CORTANA_GATEKEEPER": [
      "r:CurrentBranch",
      "f:FlightRing",
      "f:IsRetailOS"
    ],
    "CORTANAUWP": [
      "c:OSUILocale",
      "t:OSVersionFull",
      "v:CortanaAppVer"
    ],
    "CORTANAUWPTEST": [
      "+CORTANAUWP",
      "v:CortanaAppVerTest"
    ],
    "CTAC": [
      "+FSS"
    ],
    "DDC": [
      "+WU_STORE",
      "+_WU_PTI"
    ],
    "DXDB": [
      "DeviceFamily",
      "f:FlightRing",
      "r:IsHybridOrXGpu",
      "t:OSVersionFull"
    ],
    "EDGE_SERVICEUI": [
      "t:LocalDeviceID",
      "t:LocalUserID"
    ],
    "FCON": [
      "+CDM"
    ],
    "FSS": [
      "r:PreviewBuildsManagerEnabled",
      "f:BranchReadinessLevelRaw",
      "u:BranchReadinessLevelSource",
      "r:BuildFID",
      "t:DeviceFamily",
      "DeviceId",
      "c:EnablePreviewBuilds",
      "f:FlightingPolicyValue",
      "f:IsRetailOS",
      "f:ManagePreviewBuilds",
      "OSVersionFull",
      "t:WCOSProductId",
      "r:SmartActiveHoursState",
      "r:ActiveHoursStart",
      "r:ActiveHoursEnd"
    ],
    "FXIRISCLIENT": [
      "+IRISCLIENT"
    ],
    "IRISCLIENT": [
      "DeviceFamily",
      "OSVersion",
      "t:OSSkuId",
      "OSArchitecture",
      "c:TelemetryLevel",
      "f:FlightRing",
      "f:FlightingBranchName",
      "c:InternalPrimaryDisplayResolutionHorizontal",
      "c:InternalPrimaryDisplayResolutionVetical",
      "t:IsMsftOwned",
      "c:ChassisType",
      "c:IsDomainJoined",
      "c:ProcessorIdentifier",
      "c:CommercialId",
      "OEMModel",
      "c:OSUILocale",
      "c:OSEdition",
      "c:FlightIds",
      "t:LocalUserID"
    ],
    "MICROSOFT.WINDOWSFEEDBACKHUB_8WEKYB3D8BBWE": [
      "t:OSVersionFull",
      "t:IsTestLab",
      "f:FlightRing"
    ],
    "MITIGATION": [
      "t:DeviceFamily",
      "f:FlightRing",
      "c:FlightIds",
      "c:IsDomainJoined",
      "t:IsMsftOwned",
      "f:IsRetailOS",
      "t:IsTestLab",
      "IsVM",
      "OEMModel",
      "c:OSEdition",
      "t:OSSkuId",
      "t:OSVersionFull",
      "c:OSUILocale",
      "t:SMode",
      "f:IsFlightingEnabled",
      "c:FirmwareVersion",
      "c:TelemetryLevel",
      "f:FlightingBranchName",
      "r:CurrentBranch",
      "OSVersion"
    ],
    "MLMOD": [
      "ChassisTypeId",
      "t:DeviceFamily",
      "f:FlightingBranchName",
      "f:FlightRing",
      "f:IsRetailOS",
      "t:OSSkuId",
      "t:OSVersionFull",
      "c:OSUILocale",
      "OSVersion",
      "c:TelemetryLevel",
      "r:CurrentBranch"
    ],
    "MTP": [
      "+_WU_OS_CORE"
    ],
    "MUSE": [
      "+_WU_FB",
      "ChassisTypeId",
      "deviceClass",
      "deviceId",
      "c:FlightIds",
      "locale",
      "ms",
      "os",
      "osVer",
      "ring",
      "sampleId",
      "sku",
      "r:DaysSince19H1FUOffer",
      "u:DisableDualScan",
      "u:UpdateServiceUrl",
      "c:CommercialId",
      "f:FlightingBranchName"
    ],
    "NOISYHAMMER": [
      "+WU_OS"
    ],
    "SEDIMENTPACK": [
      "+WU_OS"
    ],
    "SETUP360": [
      "t:OSSkuId",
      "f:FlightRing"
    ],
    "STORAGEGROVELER": [
      "a:Free",
      "c:TelemetryLevel",
      "f:FlightRing",
      "f:IsFlightingEnabled",
      "IsVM",
      "t:OSVersionFull"
    ],
    "UTC": [
      "+UTC_STATIC",
      "osVer",
      "locale",
      "ring",
      "f:PilotRing",
      "f:IsRetailOS",
      "ms",
      "expId",
      "t:SMode",
      "f:FlightingBranchName",
      "c:CommercialId"
    ],
    "UTC_STATIC": [
      "os",
      "deviceId",
      "sampleId",
      "deviceClass",
      "sku",
      "OEMModel",
      "OEMName_Uncleaned",
      "c:PrimaryDiskType",
      "c:ProcessorModel",
      "c:TotalPhysicalRAM"
    ],
    "UUS": [
      "OSVersion",
      "f:FlightRing",
      "t:IsTestLab",
      "t:OSVersionFull",
      "f:FlightingBranchName",
      "r:CurrentBranch"
    ],
    "WAASASSESSMENT": [
      "+WU_OS"
    ],
    "WOSC": [
      "t:DeviceFamily",
      "f:FlightRing",
      "f:IsFlightingEnabled",
      "t:IsMsftOwned",
      "t:LocalDeviceID",
      "t:OSSkuId",
      "c:OSUILocale",
      "t:OSVersionFull",
      "c:TelemetryLevel",
      "r:IsHybridOrXGpu",
      "r:PlayFabPartyRelay"
    ],
    "WPSHIFT": [
      "+MTP"
    ],
    "WU": [
      "+WU_OS",
      "r:DUInternal"
    ],
    "_WU_AV": [
      "r:AvastReg",
      "r:AvastBlackScreen",
      "v:AvastVer",
      "r:AvgReg",
      "v:AvgVer",
      "r:EsetReg",
      "v:EsetVer",
      "r:KasperskyReg",
      "v:KasperskyVer",
      "v:SymantecVer",
      "r:TencentReg",
      "r:TencentType"
    ],
    "_WU_COMMON": [
      "r:CurrentBranch",
      "r:DefaultUserRegion",
      "DeviceFamily",
      "r:DriverPartnerRing",
      "r:FlightContent",
      "f:FlightingBranchName",
      "f:FlightRing",
      "HoloLens",
      "c:InstallationType",
      "c:InstallLanguage",
      "f:IsFlightingEnabled",
      "r:IsFlightingEnabled",
      "c:MobileOperatorCommercialized",
      "OEMModel",
      "OEMName_Uncleaned",
      "r:OemPartnerRing",
      "OSArchitecture",
      "OSVersion",
      "t:OSSkuId",
      "c:OSUILocale",
      "c:ProcessorManufacturer",
      "r:ReleaseType",
      "v:SkypeRoomSystem",
      "t:SMode",
      "c:TelemetryLevel",
      "r:WindowsMixedReality",
      "v:WuClientVer",
      "p:DucPublisherId",
      "p:DucDeviceModelId",
      "p:DucOemPartnerRing",
      "p:DucCustomPackageId",
      "p:DesiredOsVersion",
      "p:DesiredSystemManifestVersion"
    ],
    "_WU_FB": [
      "u:BranchReadinessLevel",
      "u:DeferQualityUpdatePeriodInDays",
      "u:DeferFeatureUpdatePeriodInDays",
      "r:PausedFeatureStatus",
      "r:PausedQualityStatus",
      "u:TargetReleaseVersion",
      "r:QUDeadline",
      "r:UpdatePreference",
      "r:UpdateOfferedDays"
    ],
    "WU_OS": [
      "+_WU_OS_CORE",
      "+_WU_FB"
    ],
    "_WU_OS_CORE": [
      "+_WU_COMMON",
      "+_WU_AV",
      "r:AhnLabKeyboard",
      "a:Bios",
      "r:BlockFeatureUpdates",
      "c:CommercialId",
      "a:DataVer_RS5",
      "r:DisconnectedStandby",
      "r:DchuNvidiaGrfxExists",
      "r:DchuNvidiaGrfxVen",
      "r:DchuIntelGrfxExists",
      "r:DchuIntelGrfxVen",
      "r:DchuAmdGrfxExists",
      "r:DchuAmdGrfxVen",
      "c:FirmwareVersion",
      "a:Free",
      "a:GStatus_RS3",
      "a:GStatus_RS4",
      "a:GStatus_RS5",
      "r:HidOverGattReg",
      "r:InstallDate",
      "c:IsDeviceRetailDemo",
      "c:IsPortableOperatingSystem",
      "IsVM",
      "c:OEMModelBaseBoard",
      "r:OobeSeeker",
      "r:OSRollbackBuild",
      "r:OSRollbackCount",
      "r:OSRollbackDate",
      "PhoneTargetingName",
      "r:PonchAllow",
      "r:PonchBlock",
      "c:ProcessorIdentifier",
      "r:RecoveredFromBuild",
      "r:RecoveredOnDate",
      "r:Steam",
      "v:TobiiVer",
      "v:TrendMicroVer",
      "r:UninstallActive",
      "l:UpdateManagementGroup",
      "a:UpgEx_RS3",
      "a:UpgEx_RS4",
      "a:UpgEx_RS5",
      "a:Version_RS5",
      "r:DisableWUfBOfferBlock",
      "a:UpgEx_19H1",
      "a:SdbVer_19H1",
      "a:GStatus_19H1",
      "a:GStatus_19H1Setup",
      "a:TimestampEpochString_19H1Setup",
      "a:GenTelRunTimestamp_19H1",
      "a:DataExpDateEpoch_19H1",
      "u:EnableWUfBUpgradeGates",
      "r:GStatusBlockIDs_All",
      "TimestampDelta_19H1Subtract19H1Setup",
      "DataExpDateDelta_19H1Subtract19H1Setup",
      "a:DataExpDateEpoch_19H1Setup",
      "a:TimestampEpochString_19H1",
      "r:IsContainerMgrInstalled",
      "r:IsWDAGEnabled",
      "r:MTPTargetingInfo",
      "r:EKB19H2InstallCount",
      "r:EKB19H2UnInstallCount",
      "r:EKB19H2InstallTimeEpoch",
      "r:EKB19H2UnInstallTimeEpoch",
      "r:BlockEdgeWithChromiumUpdate",
      "r:IsWDATPEnabled",
      "r:IsAutopilotRegistered",
      "r:EdgeWithChromiumInstallVersion",
      "r:EdgeWithChromiumInstallFailureCount",
      "r:IsEdgeWithChromiumInstalled",
      "r:KioskMode",
      "c:IsCloudDomainJoined",
      "c:IsDomainJoined",
      "p:DSS_Enrolled",
      "a:DataExpDateEpoch_20H1",
      "a:DataExpDateEpoch_20H1Setup",
      "a:GStatus_20H1",
      "a:GStatus_20H1Setup",
      "a:SdbVer_20H1",
      "a:TimestampEpochString_20H1",
      "a:TimestampEpochString_20H1Setup",
      "DataExpDateDelta_20H1Subtract20H1Setup",
      "TimestampDelta_20H1Subtract20H1Setup",
      "a:UpgEx_20H1",
      "r:AutopilotUpdateInProgress",
      "r:UHSEnrolled"
    ],
    "_WU_PTI": [
      "c:FrontFacingCameraResolution",
      "c:RearFacingCameraResolution",
      "c:TotalPhysicalRAM",
      "c:NFCProximity",
      "c:Magnetometer",
      "c:Gyroscope",
      "c:D3DMaxFeatureLevel",
      "c:InternalPrimaryDisplayResolutionHorizontal",
      "c:InternalPrimaryDisplayResolutionVetical"
    ],
    "WU_STORE": [
      "+_WU_COMMON",
      "r:AppChannels",
      "r:AppRMIDs",
      "u:BranchReadinessLevel"
    ]
  },
  "Required": [
    "App",
    "AppVer",
    "AttrDataVer"
  ],
  "Aliases": {
    "ChassisTypeId": "c:ChassisType",
    "DataExpDateDelta_19H1Subtract19H1Setup": "a:DataExpDateEpoch_19H1_Subtract_DataExpDateEpoch_19H1Setup",
    "DataExpDateDelta_20H1Subtract20H1Setup": "a:DataExpDateEpoch_20H1_Subtract_DataExpDateEpoch_20H1Setup",
    "deviceClass": "t:DeviceFamily",
    "deviceId": "t:LocalDeviceID",
    "DeviceId": "t:LocalDeviceID",
    "expId": "c:FlightIds",
    "FlightRing": "f:FlightRing",
    "IsVM": "a:ISVM",
    "locale": "c:OSUILocale",
    "ms": "t:IsMsftOwned",
    "OEMModel": "c:OEMModelNumber",
    "OEMName_Uncleaned": "c:OEMManufacturerName",
    "osVer": "t:OSVersionFull",
    "OSVersionFull": "t:OSVersionFull",
    "PhoneTargetingName": "c:OEMModelName",
    "ring": "f:FlightRing",
    "sampleId": "t:PopVal",
    "sku": "t:OSSkuId",
    "TimestampDelta_19H1Subtract19H1Setup": "a:TimestampEpochString_19H1_Subtract_TimestampEpochString_19H1Setup",
    "TimestampDelta_20H1Subtract20H1Setup": "a:TimestampEpochString_20H1_Subtract_TimestampEpochString_20H1Setup"
  },
  "Fallback": {
    "r:AvastBlackScreen": "r:AvgBlackScreen",
    "a:Bios": "a:Bios_RS3",
    "a:Bios_RS3": "a:Bios_RS4",
    "a:Bios_RS4": "a:Bios_RS5",
    "r:BlockFeatureUpdates": "r:BlockWUUpgrades",
    "r:BlockWUUpgrades": "r:BlockWUUpgradesWow",
    "r:BuildFID": "r:BuildFID_WCOS",
    "r:BuildFID_WCOS": "r:BuildFID_WCOS2",
    "r:DchuAmdGrfxVen": "r:DchuAmdGrfxVen2",
    "r:DchuAmdGrfxVen2": "r:DchuAmdGrfxDeletePending",
    "r:DchuIntelGrfxVen": "r:DchuIntelGrfxVen2",
    "r:DchuIntelGrfxVen2": "r:DchuIntelGrfxDeletePending",
    "r:DchuNvidiaGrfxVen": "r:DchuNvidiaGrfxVen2",
    "r:DchuNvidiaGrfxVen2": "r:DchuNvidiaGrfxDeletePending",
    "r:DriverPartnerRing": "r:OSDataDriverPartnerRing",
    "p:DSS_Enrolled": "r:DSS_EnrolledReg",
    "r:EdgeWithChromiumInstallFailureCount": "r:EdgeWithChromiumInstallFailureCountWow",
    "r:EdgeWithChromiumInstallVersion": "r:EdgeWithChromiumInstallVersionWow",
    "u:EnableWUfBUpgradeGates": "r:EnableWUfBUpgradeGatesRS5",
    "f:FlightingBranchName": "c:FlightingBranchName",
    "a:Free": "a:Free_RS3",
    "a:Free_RS3": "a:Free_RS4",
    "a:Free_RS4": "a:Free_RS5",
    "HoloLens": "r:WindowsMixedReality",
    "r:IsEdgeWithChromiumInstalled": "r:IsEdgeWithChromiumInstalledWow",
    "a:ISVM": "a:ISVM_RS3",
    "a:ISVM_RS3": "a:ISVM_RS4",
    "a:ISVM_RS4": "a:ISVM_RS5",
    "c:OEMModelBaseBoard": "r:OEMModelBaseBoard",
    "r:PonchAllow": "r:PonchAllowKey",
    "r:PonchAllowKey": "r:PonchAllowWow",
    "r:PonchAllowWow": "r:PonchAllowWowKey",
    "r:QUDeadline": "r:QUDeadlineMDM",
    "v:SymantecVer": "v:SymantecVer64",
    "u:TargetReleaseVersion": "r:TargetReleaseVersionGP",
    "r:TargetReleaseVersionGP": "r:TargetReleaseVersionMDM",
    "v:TobiiVer": "v:TobiiVerx86",
    "v:TobiiVerx86": "v:TobiiVer1x86"
  },
  "Transform": {
    "IsDomainJoined": {
      "Ignore": [
        "0"
      ]
    },
    "IsHybridOrXGpu": {
      "Ignore": [
        "0"
      ]
    },
    "IsMsftOwned": {
      "Ignore": [
        "0"
      ]
    },
    "IsPortableOperatingSystem": {
      "Ignore": [
        "0"
      ]
    },
    "IsTestLab": {
      "Ignore": [
        "0"
      ]
    },
    "IsVM": {
      "Ignore": [
        "0"
      ]
    },
    "OEMModel": {
      "SubLength": 100
    },
    "OEMName_Uncleaned": {
      "SubLength": 100
    },
    "PausedFeatureStatus": {
      "Ignore": [
        "0"
      ]
    },
    "PausedQualityStatus": {
      "Ignore": [
        "0"
      ]
    },
    "SMode": {
      "Ignore": [
        "0"
      ]
    }
  },
  "Registry": {
    "ActiveHoursEnd": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\WindowsUpdate\\UX\\Settings",
      "ValueName": "ActiveHoursEnd",
      "RegValueType": "REG_DWORD"
    },
    "ActiveHoursStart": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\WindowsUpdate\\UX\\Settings",
      "ValueName": "ActiveHoursStart",
      "RegValueType": "REG_DWORD"
    },
    "AhnLabKeyboard": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\Mkd2kfNt",
      "ValueName": "NbTpMsExist"
    },
    "AppChannels": {
      "FullPath": "SOFTWARE\\Policies\\Microsoft\\WindowsStore\\Apps\\*",
      "ValueName": "ChannelId",
      "EncodingType": "Json"
    },
    "AppRMIDs": {
      "FullPath": "SOFTWARE\\Policies\\Microsoft\\WindowsStore\\Apps\\*",
      "ValueName": "ReleaseManagementId",
      "EncodingType": "Json"
    },
    "AutopilotUpdateInProgress": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Provisioning\\AutopilotSettings\\VolatileAutopilotUpdate",
      "ValueName": "AutopilotUpdateInProgress",
      "RegValueType": "REG_DWORD"
    },
    "AvastBlackScreen": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\aswVmm\\Parameters",
      "ValueName": "Win10-1803"
    },
    "AvastReg": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\aswVmm\\Parameters",
      "ValueName": "QualityCompat"
    },
    "AvgBlackScreen": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\avgVmm\\Parameters",
      "ValueName": "Win10-1803"
    },
    "AvgReg": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\avgVmm\\Parameters",
      "ValueName": "QualityCompat"
    },
    "BlockEdgeWithChromiumUpdate": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\EdgeUpdate",
      "ValueName": "DoNotUpdateToEdgeWithChromium",
      "RegValueType": "REG_DWORD"
    },
    "BlockFeatureUpdates": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\WindowsUpdate\\OSUpgrade",
      "ValueName": "BlockFeatureUpdates",
      "RegValueType": "REG_DWORD"
    },
    "BlockWUUpgrades": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows10Upgrader\\Volatile",
      "ValueName": "BlockWUUpgrades",
      "RegValueType": "REG_DWORD"
    },
    "BlockWUUpgradesWow": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\WOW6432Node\\Microsoft\\Windows10Upgrader\\Volatile",
      "ValueName": "BlockWUUpgrades",
      "RegValueType": "REG_DWORD"
    },
    "BuildFID": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "Software\\Microsoft\\Windows\\CurrentVersion\\Flighting\\Build",
      "ValueName": "EsdFlightData",
      "RegValueType": "REG_SZ"
    },
    "BuildFID_WCOS": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "OSDATA\\Software\\Microsoft\\Windows\\CurrentVersion\\Flighting\\Build",
      "ValueName": "EsdFlightData",
      "RegValueType": "REG_SZ"
    },
    "BuildFID_WCOS2": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "OSDATA\\Microsoft\\Windows\\CurrentVersion\\Flighting\\Build",
      "ValueName": "EsdFlightData",
      "RegValueType": "REG_SZ"
    },
    "CurrentBranch": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion",
      "ValueName": "BuildBranch",
      "RegValueType": "REG_SZ"
    },
    "DaysSince19H1FUOffer": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\rempl\\irplugin",
      "ValueName": "DaysSinceLastOffer",
      "RegValueType": "REG_QWORD"
    },
    "DchuAmdGrfxDeletePending": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\amdkmdap",
      "ValueName": "DriverDelete"
    },
    "DchuAmdGrfxExists": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\amdkmdap",
      "IfExists": true
    },
    "DchuAmdGrfxVen": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\amdkmdap",
      "ValueName": "DCHUVen"
    },
    "DchuAmdGrfxVen2": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\amdkmdap\\Parameters",
      "ValueName": "DCHUVen"
    },
    "DchuIntelGrfxDeletePending": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\igfx",
      "ValueName": "DriverDelete"
    },
    "DchuIntelGrfxExists": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\igfx",
      "IfExists": true
    },
    "DchuIntelGrfxVen": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\igfx",
      "ValueName": "DCHUVen"
    },
    "DchuIntelGrfxVen2": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\igfx\\Parameters",
      "ValueName": "DCHUVen"
    },
    "DchuNvidiaGrfxDeletePending": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\nvlddmkm",
      "ValueName": "DriverDelete"
    },
    "DchuNvidiaGrfxExists": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\nvlddmkm",
      "IfExists": true
    },
    "DchuNvidiaGrfxVen": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\nvlddmkm",
      "ValueName": "DCHUVen"
    },
    "DchuNvidiaGrfxVen2": {
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\nvlddmkm\\Parameters",
      "ValueName": "DCHUVen"
    },
    "DefaultUserRegion": {
      "HKey": "HKEY_USERS",
      "FullPath": ".DEFAULT\\Control Panel\\International\\Geo",
      "ValueName": "Nation",
      "RegValueType": "REG_SZ"
    },
    "DisableWUfBOfferBlock": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\WindowsUpdate\\UpdatePolicy\\Settings",
      "ValueName": "DisableWUfBOfferBlock",
      "RegValueType": "REG_DWORD"
    },
    "DisconnectedStandby": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SYSTEM\\CurrentControlSet\\Control\\Power",
      "ValueName": "EnforceDisconnectedStandby",
      "RegValueType": "REG_DWORD"
    },
    "DriverPartnerRing": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\DriverFlighting\\Partner",
      "ValueName": "TargetRing",
      "RegValueType": "REG_SZ"
    },
    "DSS_EnrolledReg": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Policies\\Microsoft\\Windows\\WindowsUpdate",
      "ValueName": "EnableWUfBCloud",
      "RegValueType": "REG_DWORD"
    },
    "DUInternal": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SYSTEM\\Setup\\MoSetup",
      "ValueName": "DynamicUpdateInternalTest",
      "RegValueType": "REG_DWORD"
    },
    "EdgeWithChromiumInstallFailureCount": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\EdgeUpdate",
      "ValueName": "WindowsUpdateAttempts"
    },
    "EdgeWithChromiumInstallFailureCountWow": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Wow6432Node\\Microsoft\\EdgeUpdate",
      "ValueName": "WindowsUpdateAttempts"
    },
    "EdgeWithChromiumInstallVersion": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\EdgeUpdate",
      "ValueName": "WindowsUpdateVersion"
    },
    "EdgeWithChromiumInstallVersionWow": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Wow6432Node\\Microsoft\\EdgeUpdate",
      "ValueName": "WindowsUpdateVersion"
    },
    "EKB19H2InstallCount": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SYSTEM\\Setup\\FeatureStaging\\20455539\\2",
      "ValueName": "Count"
    },
    "EKB19H2InstallTimeEpoch": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SYSTEM\\Setup\\FeatureStaging\\20455539\\2",
      "ValueName": "Timestamp"
    },
    "EKB19H2UnInstallCount": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SYSTEM\\Setup\\FeatureStaging\\20455539\\0",
      "ValueName": "Count"
    },
    "EKB19H2UnInstallTimeEpoch": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SYSTEM\\Setup\\FeatureStaging\\20455539\\0",
      "ValueName": "Timestamp"
    },
    "EnableWUfBUpgradeGatesRS5": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "Software\\Microsoft\\Windows NT\\CurrentVersion\\502505fe-762c-4e80-911e-0c3fa4c63fb0",
      "ValueName": "DataRequireGatedScanForFeatureUpdates",
      "RegValueType": "REG_DWORD"
    },
    "EsetReg": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SYSTEM\\CurrentControlSet\\Services\\ehdrv\\Parameters",
      "ValueName": "WindowsCompatibilityLevel",
      "RegValueType": "REG_DWORD"
    },
    "FlightContent": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\WindowsSelfHost\\Applicability",
      "ValueName": "ContentType",
      "RegValueType": "REG_SZ"
    },
    "GStatusBlockIDs_All": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\Appraiser\\GWX",
      "ValueName": "SdbEntries",
      "RegValueType": "REG_SZ"
    },
    "HidOverGattReg": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\PnpLockdownFiles\\%SystemRoot%/System32/drivers/UMDF/Microsoft.Bluetooth.Profiles.HidOverGatt.dll",
      "ValueName": "Source",
      "RegValueType": "REG_SZ"
    },
    "InstallDate": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion",
      "ValueName": "InstallDate",
      "RegValueType": "REG_DWORD"
    },
    "IsAutopilotRegistered": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Provisioning\\AutopilotPolicyCache",
      "ValueName": "ProfileAvailable",
      "RegValueType": "REG_DWORD"
    },
    "IsFlightingEnabled": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\WindowsSelfHost\\Applicability",
      "ValueName": "IsBuildFlightingEnabled",
      "RegValueType": "REG_DWORD"
    },
    "IsContainerMgrInstalled": {
      "FullPath": "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Containers\\CmService",
      "IfExists": true
    },
    "IsEdgeWithChromiumInstalled": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\EdgeUpdate\\Clients\\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}",
      "IfExists": true
    },
    "IsEdgeWithChromiumInstalledWow": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Wow6432Node\\Microsoft\\EdgeUpdate\\Clients\\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}",
      "IfExists": true
    },
    "IsHybridOrXGpu": {
      "FullPath": "SOFTWARE\\Microsoft\\DirectX",
      "ValueName": "HybridDeviceApplicableForDxDbGpuPreferences"
    },
    "IsWDAGEnabled": {
      "FullPath": "SYSTEM\\ControlSet001\\Services\\hvsics",
      "IfExists": true
    },
    "IsWDATPEnabled": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows Advanced Threat Protection\\Status",
      "ValueName": "OnboardingState"
    },
    "KasperskyReg": {
      "FullPath": "System\\CurrentControlSet\\Services\\klhk\\Parameters",
      "ValueName": "UseVtHardware"
    },
    "KioskMode": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows\\AssignedAccessCsp\\AutoLogonAccount",
      "ValueName": "ConfigSource",
      "RegValueType": "REG_DWORD"
    },
    "MTPTargetingInfo": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SYSTEM\\Platform\\MTPTargetingInfo",
      "ValueName": "TargetRing"
    },
    "OEMModelBaseBoard": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "HARDWARE\\DESCRIPTION\\System\\BIOS",
      "ValueName": "BaseBoardProduct",
      "RegValueType": "REG_SZ"
    },
    "OemPartnerRing": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SYSTEM\\Platform\\DeviceTargetingInfo",
      "ValueName": "TargetRing",
      "RegValueType": "REG_SZ"
    },
    "OobeSeeker": {
      "FullPath": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\OOBE\\Updates",
      "ValueName": "OOBEUpdateStarted"
    },
    "OSDataDriverPartnerRing": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "OSData\\SOFTWARE\\Microsoft\\DriverFlighting\\Partner",
      "ValueName": "TargetRing",
      "RegValueType": "REG_SZ"
    },
    "OSRollbackBuild": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\WindowsUpdate\\OSUpgrade\\Rollback",
      "ValueName": "BuildString",
      "RegValueType": "REG_SZ"
    },
    "OSRollbackCount": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\WindowsUpdate\\OSUpgrade\\Rollback",
      "ValueName": "Count",
      "RegValueType": "REG_DWORD"
    },
    "OSRollbackDate": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\WindowsUpdate\\OSUpgrade\\Rollback",
      "ValueName": "DateStamp",
      "RegValueType": "REG_DWORD"
    },
    "PausedFeatureStatus": {
      "FullPath": "SOFTWARE\\Microsoft\\WindowsUpdate\\UpdatePolicy\\Settings",
      "ValueName": "PausedFeatureStatus"
    },
    "PausedQualityStatus": {
      "FullPath": "SOFTWARE\\Microsoft\\WindowsUpdate\\UpdatePolicy\\Settings",
      "ValueName": "PausedQualityStatus"
    },
    "PlayFabPartyRelay": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\PlayFabPartyRelay",
      "IfExists": true
    },
    "PonchAllow": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\QualityCompat",
      "ValueName": "cadca5fe-87d3-4b96-b7fb-a231484277cc",
      "RegValueType": "REG_DWORD"
    },
    "PonchAllowKey": {
      "FullPath": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\QualityCompat\\cadca5fe-87d3-4b96-b7fb-a231484277cc",
      "IfExists": true
    },
    "PonchAllowWow": {
      "FullPath": "SOFTWARE\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\QualityCompat",
      "ValueName": "cadca5fe-87d3-4b96-b7fb-a231484277cc"
    },
    "PonchAllowWowKey": {
      "FullPath": "SOFTWARE\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\QualityCompat\\cadca5fe-87d3-4b96-b7fb-a231484277cc",
      "IfExists": true
    },
    "PonchBlock": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\QualityCompat",
      "ValueName": "65d75b03-6f4d-46e9-b870-517731e06cf9",
      "RegValueType": "REG_DWORD"
    },
    "PreviewBuildsManagerEnabled": {
      "FullPath": "SOFTWARE\\Microsoft\\WindowsSelfhost\\Manager",
      "ValueName": "ArePreviewBuildsAllowed"
    },
    "QUDeadline": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Policies\\Microsoft\\Windows\\WindowsUpdate",
      "ValueName": "ConfigureDeadlineForQualityUpdates",
      "RegValueType": "REG_DWORD"
    },
    "QUDeadlineMDM": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\PolicyManager\\current\\device\\Update",
      "ValueName": "ConfigureDeadlineForQualityUpdates",
      "RegValueType": "REG_DWORD"
    },
    "RecoveredFromBuild": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "Software\\Microsoft\\WindowsSelfHost\\Applicability\\RecoveredFrom",
      "ValueName": "LastBuild",
      "RegValueType": "REG_DWORD"
    },
    "RecoveredOnDate": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "Software\\Microsoft\\WindowsSelfHost\\Applicability\\RecoveredFrom",
      "ValueName": "DateStamp",
      "RegValueType": "REG_DWORD"
    },
    "ReleaseType": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Update\\TargetingInfo",
      "ValueName": "ReleaseType",
      "RegValueType": "REG_SZ"
    },
    "SmartActiveHoursState": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\WindowsUpdate\\UX\\Settings",
      "ValueName": "SmartActiveHoursState",
      "RegValueType": "REG_DWORD"
    },
    "Steam": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Classes\\Steam",
      "ValueName": "",
      "RegValueType": "REG_SZ"
    },
    "TargetReleaseVersionGP": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Policies\\Microsoft\\Windows\\WindowsUpdate",
      "ValueName": "TargetReleaseVersionInfo",
      "RegValueType": "REG_SZ"
    },
    "TargetReleaseVersionMDM": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\PolicyManager\\current\\device\\Update",
      "ValueName": "TargetReleaseVersion",
      "RegValueType": "REG_SZ"
    },
    "TencentReg": {
      "FullPath": "SYSTEM\\CurrentControlSet\\services\\TesSafe",
      "ValueName": "LoadStartTime"
    },
    "TencentType": {
      "FullPath": "SYSTEM\\CurrentControlSet\\services\\TesSafe",
      "ValueName": "Type"
    },
    "UHSEnrolled": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion",
      "ValueName": "UHSEnrolled",
      "RegValueType": "REG_SZ",
      "IfExists": true
    },
    "UninstallActive": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "System\\Setup",
      "ValueName": "UninstallActive",
      "RegValueType": "REG_DWORD"
    },
    "UpdateOfferedDays": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\WaaSAssessment\\Cache\\",
      "ValueName": "UpToDateDays",
      "RegValueType": "REG_DWORD"
    },
    "UpdatePreference": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Policies\\Microsoft\\Windows\\WindowsUpdate",
      "ValueName": "UpdatePreference",
      "RegValueType": "REG_DWORD"
    },
    "WindowsMixedReality": {
      "HKey": "HKEY_LOCAL_MACHINE",
      "FullPath": "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\WUDF\\Services\\HoloLensSensors",
      "ValueName": "WdfMajorVersion",
      "RegValueType": "REG_DWORD"
    }
  },
  "FileInfo": {
    "AvastVer": {
      "Path": "\\system32\\Drivers\\aswVmm.sys",
      "FolderGuid": "{F38BF404-1D43-42F2-9305-67DE0B28FC23}"
    },
    "AvgVer": {
      "Path": "\\system32\\Drivers\\avgVmm.sys",
      "FolderGuid": "{F38BF404-1D43-42F2-9305-67DE0B28FC23}"
    },
    "CortanaAppVer": {
      "Path": "\\WindowsApps\\Microsoft.549981C3F5F10_8wekyb3d8bbwe\\CortanaApp.View.exe",
      "FolderGuid": "{905E63B6-C1BF-494E-B29C-65B732D3D21A}"
    },
    "CortanaAppVerTest": {
      "Path": "\\WindowsApps\\3242f7d9-db60-4380-a379-4205ea768bfc_1.0.0.0_x64__zs4v8rx04ex0m\\UndockingTestApp.exe",
      "FolderGuid": "{905E63B6-C1BF-494E-B29C-65B732D3D21A}"
    },
    "EsetVer": {
      "Path": "\\drivers\\ehdrv.sys",
      "FolderGuid": "{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}"
    },
    "KasperskyVer": {
      "Path": "\\system32\\Drivers\\klhk.sys",
      "FolderGuid": "{F38BF404-1D43-42F2-9305-67DE0B28FC23}"
    },
    "SkypeRoomSystem": {
      "Path": "%systemdrive%\\Recovery\\OEM\\$oem$\\$1\\Rigel\\x64\\Scripts\\Provisioning\\AutoUnattend.xml",
      "IfExists": true
    },
    "SymantecVer": {
      "Path": "\\Symantec\\Shared\\EENGINE\\eeCtrl.sys",
      "FolderGuid": "{DE974D24-D9C6-4D3E-BF91-F4455120B917}"
    },
    "SymantecVer64": {
      "Path": "\\Symantec\\Shared\\EENGINE\\eeCtrl64.sys",
      "FolderGuid": "{DE974D24-D9C6-4D3E-BF91-F4455120B917}"
    },
    "TobiiVer": {
      "Path": "\\Tobii\\Tobii EyeX Interaction\\Tobii.EyeX.Interaction.exe",
      "FolderGuid": "{905E63B6-C1BF-494E-B29C-65B732D3D21A}"
    },
    "TobiiVer1x86": {
      "Path": "\\Tobii\\tobii EyeX Interaction\\Tobii.EyeX.Interaction.exe",
      "FolderGuid": "{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}"
    },
    "TobiiVerx86": {
      "Path": "\\tobii EyeX Interaction\\Tobii.EyeX.Interaction.exe",
      "FolderGuid": "{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}"
    },
    "TrendMicroVer": {
      "Path": "\\drivers\\TMUMH.sys",
      "FolderGuid": "{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}"
    },
    "WuClientVer": {
      "Path": "\\system32\\wuaueng.dll",
      "FolderGuid": "{F38BF404-1D43-42F2-9305-67DE0B28FC23}"
    }
  },
  "Licensing": {
    "UpdateManagementGroup": {
      "Name": "UpdatePolicy-UpdateManagementGroup"
    }
  },
  "UpdatePolicy": {
    "BranchReadinessLevel": {
      "PolicyEnum": 5,
      "Enterprise": true
    },
    "BranchReadinessLevelSource": {
      "PolicyEnum": 5,
      "Enterprise": true,
      "UseSource": true
    },
    "DeferFeatureUpdatePeriodInDays": {
      "PolicyEnum": 9,
      "Enterprise": true
    },
    "DeferQualityUpdatePeriodInDays": {
      "PolicyEnum": 7,
      "Enterprise": true
    },
    "DisableDualScan": {
      "PolicyEnum": 42,
      "Enterprise": true
    },
    "EnableWUfBUpgradeGates": {
      "PolicyEnum": 51,
      "Enterprise": true
    },
    "TargetReleaseVersion": {
      "PolicyEnum": 50,
      "Enterprise": true
    },
    "UpdateServiceUrl": {
      "PolicyEnum": 12
    }
  },
  "Policy": {
    "DesiredOsVersion": {
      "LocUri": "./Device/Vendor/MSFT/DeviceUpdateCenter/DesiredUpdates/OsVersion"
    },
    "DesiredSystemManifestVersion": {
      "LocUri": "./Device/Vendor/MSFT/DeviceUpdateCenter/DesiredUpdates/SystemManifestVersion"
    },
    "DSS_Enrolled": {
      "Area": "Update",
      "Name": "EnableWUfBCloud"
    },
    "DucCustomPackageId": {
      "LocUri": "./Device/Vendor/MSFT/DeviceUpdateCenter/Enrollment/CustomPackageId"
    },
    "DucDeviceModelId": {
      "LocUri": "./Device/Vendor/MSFT/DeviceUpdateCenter/Enrollment/DeviceModelId"
    },
    "DucOemPartnerRing": {
      "LocUri": "./Device/Vendor/MSFT/DeviceUpdateCenter/Enrollment/OemPartnerRing"
    },
    "DucPublisherId": {
      "LocUri": "./Device/Vendor/MSFT/DeviceUpdateCenter/Enrollment/PublisherId"
    }
  }
}"
[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\AVAST Software]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\f3982c37_0]
""="{2}.\\?\hdaudio#func_01&ven_10ec&dev_0269&subsys_17aac022&rev_1002#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\singlelineouttopo/00010001|\Device\HarddiskVolume5\Program Files\AVAST Software\Avast\avastui.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\SafeZone 3.55.2393.609\Avast Free Antivirus(1)]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\SafeZone 3.55.2393.609\Avast Free Antivirus(1)]
"UninstallString"=""C:\Program Files\AVAST Software\SZBrowser\Launcher.exe" /uninstall"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\SafeZone 3.55.2393.609\Avast Free Antivirus(2)]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\SafeZone 3.55.2393.609\Avast Free Antivirus(2)]
"UninstallString"=""C:\Program Files\AVAST Software\SZBrowser\Launcher.exe" /uninstall"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\SafeZone 3.55.2393.609\Avast Free Antivirus(3)]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\SafeZone 3.55.2393.609\Avast Free Antivirus(3)]
"UninstallString"=""C:\Program Files\AVAST Software\SZBrowser\Launcher.exe" /uninstall"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\SafeZone 3.55.2393.609\Avast Free Antivirus(4)]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\SafeZone 3.55.2393.609\Avast Free Antivirus(4)]
"UninstallString"=""C:\Program Files\AVAST Software\SZBrowser\Launcher.exe" /uninstall"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\SafeZone 3.55.2393.609\Avast Pro Antivirus]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\SafeZone 3.55.2393.609\Avast Pro Antivirus]
"UninstallString"=""C:\Program Files\AVAST Software\SZBrowser\Launcher.exe" /uninstall"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\SafeZone 3.55.2393.609\Avast Pro Antivirus(1)]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\SafeZone 3.55.2393.609\Avast Pro Antivirus(1)]
"UninstallString"=""C:\Program Files\AVAST Software\SZBrowser\Launcher.exe" /uninstall"

===================== Search result for "McAfee" ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Data\3f6]
"PackageRelativeApplicationId"="McAfeeCentral"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Data\3f6]
"ApplicationUserModelId"="McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw!McAfeeCentral"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Data\3f6]
"_IndexKeys"="Package\8c8\3f6
PackageAndPackageRelativeApplicationId\8c8^McAfeeCentral"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Index\PackageAndPackageRelativeApplicationId\8c8^McAfeeCentral]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\ApplicationUser\Data\8e]
"ApplicationUserModelId"="McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw!McAfeeCentral"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\ApplicationUser\Data\8e]
"_IndexKeys"="Application\3f6\8e
UserAndApplication\1^3f6
UserAndApplicationUserModelId\1^McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw!McAfeeCentral\8e"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\ApplicationUser\Index\UserAndApplicationUserModelId\1^McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw!McAfeeCentral]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\8c8]
"PackageFullName"="McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\8c8]
"InstalledLocation"="C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\8c8]
"_IndexKeys"="PackageFamily\38\8c8
PackageFullName\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Index\PackageFullName\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageFamily\Data\38]
"PackageFamilyName"="McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageFamily\Data\38]
"_IndexKeys"="PackageFamilyName\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageFamily\Index\PackageFamilyName\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CMcAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.110.1_x64__bq6yxensn79aw%5Cresources.pri]
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CMcAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.110.1_x64__bq6yxensn79aw%5Cresources.pri\1d1320c841324d3\2fa68a72]
"@{McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.110.1_x64__bq6yxensn79aw?ms-resource://McAfeeInc.06.McAfeeSecurityAdvisorforLenovo/Files/images/win_store/McafeeSmallLogo.png}"="C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.110.1_x64__bq6yxensn79aw\images\win_store\McafeeSmallLogo.scale-100.png"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CMcAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.110.1_x64__bq6yxensn79aw%5Cresources.pri\1d1320c841324d3\2fa68a72]
"@{McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.110.1_x64__bq6yxensn79aw?ms-resource://McAfeeInc.06.McAfeeSecurityAdvisorforLenovo/resources/AppName}"="McAfee Central"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CMcAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.110.1_x64__bq6yxensn79aw%5Cresources.pri\1d1320c841324d3\502b3ce7]
"@{McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.110.1_x64__bq6yxensn79aw?ms-resource://McAfeeInc.06.McAfeeSecurityAdvisorforLenovo/resources/AppName}"="McAfee Central"
[HKEY_USERS\S-1-5-21-1203430805-1345111560-1046767822-1002\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CMcAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.110.1_x64__bq6yxensn79aw%5Cresources.pri\1d1320c841324d3\502b3ce7]
"@{McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.110.1_x64__bq6yxensn79aw?ms-resource://McAfeeInc.06.McAfeeSecurityAdvisorforLenovo/Files/images/win_store/McafeeSmallLogo.png}"="C:\Program Files\WindowsApps\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.110.1_x64__bq6yxensn79aw\images\win_store\McafeeSmallLogo.scale-100.png"

====== End of Search ======

  • 0

Advertisements


#41
DR M

DR M

    The Grecian Geek

  • Malware Removal
  • 4,049 posts

Moving on, Jim!

Boot in the Recovery Environment

  • Press the Windows icon on the keyboard together with the letter I, to get into the Settings.
  • Choose Update and Security.
  • From the menu at the left, choose Recovery.
  • Under the title Advanced startup at the right, choose Restart now.
  • From the window that will appear choose Troubleshoot and then Advanced options.
  • Choose Command Prompt.

Once in the command prompt

  • Copy and paste the following command lines, one by one, and press Enter after each one, to execute them:
reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\Av\{8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF} /f
reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\Av\{EB19B86E-3998-C706-90EF-92B41EB091AF} /f
reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Data\3f6 /f
reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Index\PackageAndPackageRelativeApplicationId\8c8^McAfeeCentral /f
reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\ApplicationUser\Data\8e /f
reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\ApplicationUser\Index\UserAndApplicationUserModelId\1^McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw!McAfeeCentral /f 
reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\8c8 /f
reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Index\PackageFullName\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw /f
reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageFamily\Data\38 /f
reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageFamily\Index\PackageFamilyName\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw /f
  • When the commands get completed successfully, restart the computer.

 

Were the commands ran fine? Did you get any error? If yes, please report back.


  • 0

#42
JimBow

JimBow

    Member

  • Topic Starter
  • Member
  • PipPip
  • 88 posts

This was an interesting exercise because I got to apply a few new (to me) tricks on my computer, but frustrating in that we were not able to make any visible progress. At first I was stymied when I went into the Recovery Environment and no longer had access to a browser, Mail, or items previously stored in memory.  Fortunately, you had just taught me how to use Notebook from the Command Prompt, so I was able to place all of the registry entries into a Notebook file and copy them one at a time within the Recovery Environment.

 

Unfortunately, I did not have any success in deleting those registry entries. The instructions took me to X:\windows\systems32 at the Command Prompt. I executed the reg delete commands from there.  I also tried several from the C: prompt with identical results.

 

For:

reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\Av\{8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF} /f
reg
delete HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\Av\{EB19B86E-3998-C706-90EF-92B41EB091AF} /f

The first attempt at each returned an Invalid syntax error.  After I added a / after the word "delete," each returned ERROR: Invalid key name.

 

The remaining entries all returned the error: The system was unable to find the specified key or value. 

 

I did not alter your commands on the final eight lines. I have no idea why the first two lines reported a syntax error and the others did not.  It was pure trial and error on my part after looking at the examples offered by Windows at REG DELETE /? that came along with the syntax error report.

 

I hope you can find something of value in my response. I sure appreciate all that you are doing to help.

Jim


  • 0

#43
DR M

DR M

    The Grecian Geek

  • Malware Removal
  • 4,049 posts

Hi, Jim.

I really apologize for this delay.
 

I hope you can find something of value in my response.


Yes! Your detailed replies, give us a lot of valuable information.

What is happening here, and I didn't take it in mind in my previous instructions, is that things work differently when we are in the Recovery Environment. So, we have to work a bit different.

Boot in the Recovery Environment

  • Press the Windows icon on the keyboard together with the letter I, to get into the Settings.
  • Choose Update and Security.
  • From the menu at the left, choose Recovery.
  • Under the title Advanced startup at the right, choose Restart now.
  • From the window that will appear choose Troubleshoot and then Advanced options.
  • Choose Command Prompt.

Once in the command prompt

  • Type REGEDIT and press ENTER to launch the Registry Editor.
  • Select the HKEY_LOCAL_MACHINE hive, click the File menu and select Load Hive…
  • From the menu at the left, select This PC, and make sure what the letter for your hard disk letter is (usually is d).
  • Type the path "d:\windows\system32\config\software" beside the File name option, and click Open.
  • Type a name for the loaded hive, e.g. TEST. The SOFTWARE registry key is now mounted to a branch named TEST.
  • Expand the TEST key, by clicking on the arrow at the left of it.
  • Find one by one the following keys, right click on each one and select Delete, confirming the operation.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\Av\{8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF} 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\Av\{EB19B86E-3998-C706-90EF-92B41EB091AF} 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Data\3f6 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Application\Index\PackageAndPackageRelativeApplicationId\8c8^McAfeeCentral
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\ApplicationUser\Data\8e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\ApplicationUser\Index\UserAndApplicationUserModelId\1^McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw!McAfeeCentral 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Data\8c8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\Package\Index\PackageFullName\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_5.0.173.1_x64__bq6yxensn79aw
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageFamily\Data\38
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageFamily\Index\PackageFamilyName\McAfeeInc.06.McAfeeSecurityAdvisorforLenovo_bq6yxensn79aw
  • When you finish, select File from the menu, Unload the hive, and close the Registry Editor.
  • Type Exit and Enter.
  • Let the computer start normally, by selecting Continue.

I hope this time, the key deletion will run without problem. In case you get any errors... well, we are here, until we find a solution! :)

 

 


  • 0

#44
JimBow

JimBow

    Member

  • Topic Starter
  • Member
  • PipPip
  • 88 posts

No apology needed. I really appreciate what you are doing. This has been a complex case that has needed more than quick and easy responses. It looks like that trend is likely to continue for a bit.

 

Your instructions were easy to follow, but my computer threw a couple of wrinkles at me. I found the windows\system32\config\software path in the C: drive and mapped it as you instructed.  My first surprise, was that once I labeled the path as TEST, I still had separate branches under the registry for SOFTWARE and for TEST. My expectation was that SOFTWARE would be apart of TEST. The SOFTWARE branch had subsets like Classes, Installed Options, and Microsoft.  However, there were no lower branches for Security Center or AppModel, so I couldn't find any of the keys we were looking for on the C: drive. The TEST branch had subsets like Adobe, Classes, Clients, Cyberlink, Dolby, Epson, Google, HP, Lenovo, Licenses, Policies, and Windows/CurrentVersion/AutoRotation.

 

I unloaded the hive and tried the other compartmented hard drives.  Only the X: drive also responded to the windows\system32\config\software path. However, it would not allow me to name the path, stating that "The process cannot access the file because it is being used by another process." Perhaps by the Command Prompt? Nonetheless, I conducted a manual search through the X: drive registry files and found that it was structured much like the C: drive; i.e., HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\... but no Security Center or AppModel subbranch.

 

I also used the Search function in the Registry Editor to look for unique words in each key and got no hits. The Command Prompt was on X:\windows\systems32 when I performed this search. So I don't know if I searched the entire computer registry or only a portion housed on the X: drive.


  • 0

#45
DR M

DR M

    The Grecian Geek

  • Malware Removal
  • 4,049 posts
Hi, Jim.

Have you checked about the letter of your hard drive? In the Recovery Environment usually is not C, but D. So the path you will type will be in d. You will find the above keys in TEST.
  • 0






Similar Topics


Also tagged with one or more of these keywords: Avast, Lockup, slow startup, Abrupt stops

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP