Fix result of Farbar Recovery Scan Tool (x64) Version: 22-06-2020 Ran by Tom (23-06-2020 15:24:42) Run:1 Running from D:\pobrane\avast pobrane Loaded Profiles: Tom & DefaultAppPool Boot Mode: Normal ============================================== fixlist content: ***************** CreateRestorePoint: CMD: reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options" /s ***************** Restore point was successfully created. ========= reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options" /s ========= HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\appvlp.exe UseFilter REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\appvlp.exe\710eccaedf4af036_PD Debugger REG_SZ "C:\Program Files\Avast Software\Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files\microsoft office\root\client\appvlp.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvastBrowserUpdate.exe DisableExceptionChainValidation REG_DWORD 0x0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\clview.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cnfnot32.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions mscoree.dll REG_DWORD 0x1 mscorwks.dll REG_DWORD 0x1 mso.dll REG_DWORD 0x1 msjava.dll REG_DWORD 0x1 msci_uno.dll REG_DWORD 0x1 jvm.dll REG_DWORD 0x1 jvm_g.dll REG_DWORD 0x1 javai.dll REG_DWORD 0x1 vb40032.dll REG_DWORD 0x1 vbe6.dll REG_DWORD 0x1 ums.dll REG_DWORD 0x1 main123w.dll REG_DWORD 0x1 udtapi.dll REG_DWORD 0x1 mscorsvr.dll REG_DWORD 0x1 eMigrationmmc.dll REG_DWORD 0x1 eProcedureMMC.dll REG_DWORD 0x1 eQueryMMC.dll REG_DWORD 0x1 EncryptPatchVer.dll REG_DWORD 0x1 Cleanup.dll REG_DWORD 0x1 divx.dll REG_DWORD 0x1 divxdec.ax REG_DWORD 0x1 fullsoft.dll REG_DWORD 0x1 NSWSTE.dll REG_DWORD 0x1 ASSTE.dll REG_DWORD 0x1 NPMLIC.dll REG_DWORD 0x1 PMSTE.dll REG_DWORD 0x1 AVSTE.dll REG_DWORD 0x1 NAVOPTRF.dll REG_DWORD 0x1 DRMINST.dll REG_DWORD 0x1 TFDTCTT8.dll REG_DWORD 0x1 DJSMAR00.dll REG_DWORD 0x1 xlmlEN.dll REG_DWORD 0x1 ISSTE.dll REG_DWORD 0x1 symlcnet.dll REG_DWORD 0x1 ppw32hlp.dll REG_DWORD 0x1 Apitrap.dll REG_DWORD 0x1 Vegas60k.dll REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\errorreport.exe UseFilter REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\errorreport.exe\8ddfb0c1_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ d:\programy\todo backup\bin\errorreport.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\excel.exe UseFilter REG_DWORD 0x1 MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\excel.exe\b6cf088aaed5f530_PD Debugger REG_SZ "C:\Program Files\Avast Software\Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files\microsoft office\root\office16\excel.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\excel.exe\be5b9a08_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files\microsoft office\office14\excel.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\excelcnv.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ExtExport.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fifa19_demo.exe UseFilter REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fifa19_demo.exe\83c3e836_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ f:\gry\fifa 19 demo\fifa19_demo.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashPlayerApp.exe DisableExceptionChainValidation REG_DWORD 0x0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashPlayerPlugin_32_0_0_387.exe DisableExceptionChainValidation REG_DWORD 0x0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashPlayerUpdateService.exe DisableExceptionChainValidation REG_DWORD 0x0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashUtil32_14_0_0_145_pepper.exe DisableExceptionChainValidation REG_DWORD 0x0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashUtil32_14_0_0_179_pepper.exe DisableExceptionChainValidation REG_DWORD 0x0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashUtil32_15_0_0_152_pepper.exe DisableExceptionChainValidation REG_DWORD 0x0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashUtil32_15_0_0_189_pepper.exe DisableExceptionChainValidation REG_DWORD 0x0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashUtil32_15_0_0_223_pepper.exe DisableExceptionChainValidation REG_DWORD 0x0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashUtil32_15_0_0_239_pepper.exe DisableExceptionChainValidation REG_DWORD 0x0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashUtil32_32_0_0_387_ActiveX.exe DisableExceptionChainValidation REG_DWORD 0x0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashUtil32_32_0_0_387_pepper.exe DisableExceptionChainValidation REG_DWORD 0x0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashUtil32_32_0_0_387_Plugin.exe DisableExceptionChainValidation REG_DWORD 0x0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashUtil64_14_0_0_145_pepper.exe DisableExceptionChainValidation REG_DWORD 0x0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashUtil64_14_0_0_179_pepper.exe DisableExceptionChainValidation REG_DWORD 0x0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashUtil64_15_0_0_152_pepper.exe DisableExceptionChainValidation REG_DWORD 0x0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashUtil64_15_0_0_189_pepper.exe DisableExceptionChainValidation REG_DWORD 0x0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashUtil64_15_0_0_223_pepper.exe DisableExceptionChainValidation REG_DWORD 0x0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashUtil64_15_0_0_239_pepper.exe DisableExceptionChainValidation REG_DWORD 0x0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashUtil64_32_0_0_387_ActiveX.exe DisableExceptionChainValidation REG_DWORD 0x0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashUtil64_32_0_0_387_pepper.exe DisableExceptionChainValidation REG_DWORD 0x0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashUtil64_32_0_0_387_Plugin.exe DisableExceptionChainValidation REG_DWORD 0x0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\foxitreader.exe UseFilter REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\foxitreader.exe\54afbbcbbf0c8614_PD Debugger REG_SZ "C:\Program Files\Avast Software\Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files (x86)\foxit software\foxit reader\foxitreader.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GoogleUpdate.exe DisableExceptionChainValidation REG_DWORD 0x0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\graph.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\groove.exe UseFilter REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\groove.exe\2a33dc50_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files\microsoft office\root\office16\groove.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\groove.exe\be5b9a08_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files\microsoft office\office14\groove.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ie4uinit.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\IEInstal.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ielowutil.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ieUnatt.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iexplore.exe MitigationOptions REG_QWORD 0x100 DisableExceptionChainValidation REG_DWORD 0x0 DisableUserModeCallbackFilter REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\infopath.exe UseFilter REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\infopath.exe\be5b9a08_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files\microsoft office\office14\infopath.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\loader.exe UseFilter REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\loader.exe\8ddfb0c1_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ d:\programy\todo backup\bin\loader.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\lync.exe MitigationOptions REG_QWORD 0x100 UseFilter REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\lync.exe\b6cf088aaed5f530_PD Debugger REG_SZ "C:\Program Files\Avast Software\Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files\microsoft office\root\office16\lync.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\misc.exe UseFilter REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\misc.exe\670ca995_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\windows\installer\{90140000-0011-0000-1000-0000000ff1ce}\misc.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msaccess.exe UseFilter REG_DWORD 0x1 MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msaccess.exe\b6cf088aaed5f530_PD Debugger REG_SZ "C:\Program Files\Avast Software\Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files\microsoft office\root\office16\msaccess.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msaccess.exe\be5b9a08_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files\microsoft office\office14\msaccess.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msfeedssync.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mshta.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msoadfsb.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msoasb.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msoev.exe UseFilter REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msoev.exe\b6cf088aaed5f530_PD Debugger REG_SZ "C:\Program Files\Avast Software\Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files\microsoft office\root\office16\msoev.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msohtmed.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msosrec.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msosync.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msotd.exe UseFilter REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msotd.exe\b6cf088aaed5f530_PD Debugger REG_SZ "C:\Program Files\Avast Software\Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files\microsoft office\root\office16\msotd.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msoxmled.exe UseFilter REG_DWORD 0x1 MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msoxmled.exe\a750c0ed_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files\common files\microsoft shared\office14\msoxmled.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msoxmled.exe\ab6d359c4cdd6b94_PD Debugger REG_SZ "C:\Program Files\Avast Software\Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files\microsoft office\root\vfs\programfilescommonx64\microsoft shared\office16\msoxmled.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mspub.exe UseFilter REG_DWORD 0x1 MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mspub.exe\b6cf088aaed5f530_PD Debugger REG_SZ "C:\Program Files\Avast Software\Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files\microsoft office\root\office16\mspub.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mspub.exe\be5b9a08_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files\microsoft office\office14\mspub.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msqry32.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mstore.exe UseFilter REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mstore.exe\be5b9a08_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files\microsoft office\office14\mstore.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nvidia geforce experience.exe UseFilter REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nvidia geforce experience.exe\4b227ee6_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files\nvidia corporation\nvidia geforce experience\nvidia geforce experience.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nvidia geforce experience.exe\818e5aa6ef62fc86_PD Debugger REG_SZ "C:\Program Files\Avast Software\Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files\nvidia corporation\nvidia geforce experience\nvidia geforce experience.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nvidia geforce experience.exe\e6daf751_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files (x86)\nvidia corporation\nvidia geforce experience\nvidia geforce experience.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ocpubmgr.exe UseFilter REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ocpubmgr.exe\b6cf088aaed5f530_PD Debugger REG_SZ "C:\Program Files\Avast Software\Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files\microsoft office\root\office16\ocpubmgr.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ois.exe UseFilter REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ois.exe\be5b9a08_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files\microsoft office\office14\ois.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\onenote.exe UseFilter REG_DWORD 0x1 MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\onenote.exe\b6cf088aaed5f530_PD Debugger REG_SZ "C:\Program Files\Avast Software\Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files\microsoft office\root\office16\onenote.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\onenote.exe\be5b9a08_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files\microsoft office\office14\onenote.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\onenotem.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\openfm.exe UseFilter REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\openfm.exe\30aa08f9_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\users\tom\appdata\local\openfm\application\openfm.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\orgchart.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\origin.exe UseFilter REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\origin.exe\cae331b6_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files (x86)\origin\origin.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\originer.exe UseFilter REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\originer.exe\cae331b6_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files (x86)\origin\originer.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\originuninstall.exe UseFilter REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\originuninstall.exe\cae331b6_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files (x86)\origin\originuninstall.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\OSppSvc.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\outlook.exe UseFilter REG_DWORD 0x1 MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\outlook.exe\b6cf088aaed5f530_PD Debugger REG_SZ "C:\Program Files\Avast Software\Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files\microsoft office\root\office16\outlook.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\outlook.exe\be5b9a08_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files\microsoft office\office14\outlook.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\overwolflauncher.exe UseFilter REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\overwolflauncher.exe\b905e852_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files (x86)\overwolf\\overwolflauncher.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\overwolflauncher.exe\f4f7e7de_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files (x86)\overwolf\overwolflauncher.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pccompanion.exe UseFilter REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pccompanion.exe\aa1b1f43_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files (x86)\sony\sony pc companion\pccompanion.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\powerpnt.exe UseFilter REG_DWORD 0x1 MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\powerpnt.exe\b6cf088aaed5f530_PD Debugger REG_SZ "C:\Program Files\Avast Software\Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files\microsoft office\root\office16\powerpnt.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\powerpnt.exe\be5b9a08_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files\microsoft office\office14\powerpnt.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\scanost.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\scanpst.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sdxhelper.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\selfcert.exe MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setlang.exe MitigationOptions REG_QWORD 0x100 UseFilter REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setlang.exe\b6cf088aaed5f530_PD Debugger REG_SZ "C:\Program Files\Avast Software\Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files\microsoft office\root\office16\setlang.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup.exe UseFilter REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup.exe\ccb6fbe2_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files (x86)\installshield installation information\{f09ef8f2-0976-42c1-8d9d-8df78337c6e3}\setup.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\softwareupdate.exe UseFilter REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\softwareupdate.exe\21864dcc_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files (x86)\apple software update\softwareupdate.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SppSvc.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\steam.exe UseFilter REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\steam.exe\527e540_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ d:\programy\steam\steam.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\unins000.exe UseFilter REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\unins000.exe\5b545e58_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ d:\programy\todo backup\unins000.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\unins001.exe UseFilter REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\unins001.exe\54afbbcbbf0c8614_PD Debugger REG_SZ "C:\Program Files\Avast Software\Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files (x86)\foxit software\foxit reader\unins001.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winword.exe UseFilter REG_DWORD 0x1 MitigationOptions REG_QWORD 0x100 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winword.exe\b6cf088aaed5f530_PD Debugger REG_SZ "C:\Program Files\Avast Software\Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files\microsoft office\root\office16\winword.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winword.exe\be5b9a08_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files\microsoft office\office14\winword.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wmplayer.exe UseFilter REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wmplayer.exe\a6d175d_PD Debugger REG_SZ "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe" FilterFullPath REG_SZ c:\program files\windows media player\wmplayer.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wordconv.exe MitigationOptions REG_QWORD 0x100 ========= End of CMD: ========= ==== End of Fixlog 15:25:13 ====