SystemLook 30.07.11 by jpshortstuff
Log created at 15:05 on 01/08/2016 by Carina
Administrator - Elevation successful
========== regfind ==========
Searching for "avg"
[HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AVGeneral]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\avg.com]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\e6eac082_0]
@="{0.0.0.00000000}.{c08a20c4-5f8e-4f58-ac78-9bb414022905}|\Device\HarddiskVolume2\Program Files\AVG\Av\avgcomdlgx.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_LOCAL_MACHINE\SOFTWARE\AVG]
[HKEY_LOCAL_MACHINE\SOFTWARE\AVG\AV]
"InstallationResult"="@AVGMSI_Error27054"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A2BB8BF3-B6B7-ED30-0CBD-449D02DDDDAA}\araVGm]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\12.0\Registration\{90120000-0030-0000-0000-0000000FF1CE}]
"Current"="TQBJAEMAUgBPAFMATwBGAFQAIABTAE8ARgBUAFcAQQBSAEUAIABMAEkAQwBFAE4AVABJAEUAQgBFAFAAQQBMAEkATgBHAEUATgANAAoAMgAwADAANwAgAE0ASQBDAFIATwBTAE8ARgBUACAATwBGAEYASQBDAEUAIABTAFkAUwBUAEUATQAgAFMATwBGAFQAVwBBAFIARQAgAFYATwBPAFIAIABEAEUAUwBLAFQATwBQAFQATwBFAFAAQQBTAFMASQBOAEcARQBOAA0ACgBIAGkAZQByAG8AbgBkAGUAcgAgAHYAaQBuAGQAdAAgAHUAIABkAHIAaQBlACAAdgBlAHIAcwBjAGgAaQBsAGwAZQBuAGQAZQAgAHYAZQByAHMAaQBlAHMAIAB2AGEAbgAgAGwAaQBjAGUAbgB0AGkAZQBiAGUAcABhAGwAaQBuAGcAZQBuAC4AIABTAGwAZQBjAGgAdABzACAA6QDpAG4AIABlAHIAdgBhAG4AIABpAHMAIAB2AGEAbgAgAHQAbwBlAHAAYQBzAHMAaQBuAGcALgAgAE8AbQAgAHQAZQAgAGsAdQBuAG4AZQBuACAAYgBlAHAAYQBsAGUAbgAgAHcAZQBsAGsAZQAgAEwAaQBjAGUAbgB0AGkAZQBiAGUAcABhAGwAaQBuAGcAZQBuACAAdgBvAG8AcgAgAHUAIABnAGUAbABkAGUAbgAsACAAZABpAGUAbgB0ACAAdQAgAGQAZQAgAGwAaQBjAGUAbgB0AGkAZQBhAGEAbgBkAHUAaQBkAGkAbgBnACAAdABlACAAYwBvAG4AdAByAG8AbABlAHIAZQBuAC4AIABEAGUAegBlACAAcwB0AGEAYQB0ACAAbwBwACAAZABlACAAcAByAG8AZAB1AGMAdABj
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\12.0\Registration\{91120000-0030-0000-0000-0000000FF1CE}]
"Current"="TQBJAEMAUgBPAFMATwBGAFQAIABTAE8ARgBUAFcAQQBSAEUAIABMAEkAQwBFAE4AVABJAEUAQgBFAFAAQQBMAEkATgBHAEUATgANAAoAMgAwADAANwAgAE0ASQBDAFIATwBTAE8ARgBUACAATwBGAEYASQBDAEUAIABTAFkAUwBUAEUATQAgAFMATwBGAFQAVwBBAFIARQAgAFYATwBPAFIAIABEAEUAUwBLAFQATwBQAFQATwBFAFAAQQBTAFMASQBOAEcARQBOAA0ACgBIAGkAZQByAG8AbgBkAGUAcgAgAHYAaQBuAGQAdAAgAHUAIABkAHIAaQBlACAAdgBlAHIAcwBjAGgAaQBsAGwAZQBuAGQAZQAgAHYAZQByAHMAaQBlAHMAIAB2AGEAbgAgAGwAaQBjAGUAbgB0AGkAZQBiAGUAcABhAGwAaQBuAGcAZQBuAC4AIABTAGwAZQBjAGgAdABzACAA6QDpAG4AIABlAHIAdgBhAG4AIABpAHMAIAB2AGEAbgAgAHQAbwBlAHAAYQBzAHMAaQBuAGcALgAgAE8AbQAgAHQAZQAgAGsAdQBuAG4AZQBuACAAYgBlAHAAYQBsAGUAbgAgAHcAZQBsAGsAZQAgAEwAaQBjAGUAbgB0AGkAZQBiAGUAcABhAGwAaQBuAGcAZQBuACAAdgBvAG8AcgAgAHUAIABnAGUAbABkAGUAbgAsACAAZABpAGUAbgB0ACAAdQAgAGQAZQAgAGwAaQBjAGUAbgB0AGkAZQBhAGEAbgBkAHUAaQBkAGkAbgBnACAAdABlACAAYwBvAG4AdAByAG8AbABlAHIAZQBuAC4AIABEAGUAegBlACAAcwB0AGEAYQB0ACAAbwBwACAAZABlACAAcAByAG8AZAB1AGMAdABj
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\avgfws_RASAPI32]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\avgui_RASAPI32]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\avgui_RASMANCS]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_voor_avg-remover[1]_RASAPI32]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_voor_avg-remover[1]_RASMANCS]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_voor_avg-remover[2]_RASAPI32]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_voor_avg-remover[2]_RASMANCS]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\AVG\AV"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\AVG\AV\Cfg"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00002119030000000000000000F01FEC\Features]
"VSTAIDEFiles"="*'=!-^1,a=%'HvwuM1s`lKe5wH&]&@iPgg*yzeka^FHUlH5uN9JD-'X2le-Ps(AJAjg'5=pm02,i9u5Td?k78go{S9v~.(_vyvb?7hLd@@7WH?biopFjqbsZ4?0!M_EtF9n3t3Yv}eU**z@Br{g1g(Rsy?VXB]2dxS}AW1_mOA!$oMQKOGPv*5!ULp'a99B&BsXmnNlg^k^shb2)g(FNy?VXB]2dgMB+sWA*0?jr)%4E?mxW}?0KnSBBC@uW&p3_R8rRJ54(qwdUx@+wP31En{vb`BzOcNs9F9~+.(+LTJE7ydnm1rV!1A1_C0b~kk=YW@g!R3IjB@l52{kc-~ak={8UQmN?b?x%%F%R9~S_@!iX2C%EJ@-,dmh3~OTp%chs4XT1W@.n.cJ&=gEZ%m[NUKVZU?&~nA,q7iv-R*hIkzh[)@*)d?=di1Y&v,B]z(D@4AAgL2?R3hF,z@(CfHR}{9(tu$Vq'QBd!FH'Qp8GB@Z2YrD[[C?9x)rAZTkpo9u!-Gb}$QWPlH*czRL2*96Y3KkKmxWX_q'UA+WQJAj%VbnaI0G?y68!l89BL@n~CX`crX-O5$&uxpTp_=A89%l7Qjzj46CT9*IvZ8=EXq+,6+([Ae-p$J{+o=QtITuzyO8Zs.C2V_Fe`A~HkA-Ty8qv!42?$gW$r9lZ)wXcl7aRwE?=@sCO3=HmWx%iGDJ*,!!V-bI9%9sresQy6&Xc'BFM1pD(u8=H@`P&+d$2m}[fE+4Ia?QI?y=)RA)^-d%_JNIM]8P1ch1vDV6P}'-*F{zoM@Slv={j_uap)^fAv9p'S?&tq64pQ10,{zJA,Yg!GA[^F.EP^h6RToHvwCweq?[FVtL,~k~,kDG-p
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\009]
"Counter"="1 1847 2 System 4 Memory 6 % Processor Time 10 File Read Operations/sec 12 File Write Operations/sec 14 File Control Operations/sec 16 File Read Bytes/sec 18 File Write Bytes/sec 20 File Control Bytes/sec 24 Available Bytes 26 Committed Bytes 28 Page Faults/sec 30 Commit Limit 32 Write Copies/sec 34 Transition Faults/sec 36 Cache Faults/sec 38 Demand Zero Faults/sec 40 Pages/sec 42 Page Reads/sec 44 Processor Queue Length 46 Thread State 48 Pages Output/sec 50 Page Writes/sec 52 Browser 54 Announcements Server/sec 56 Pool Paged Bytes 58 Pool Nonpaged Bytes 60 Pool Paged Allocs 64 Pool Nonpaged Allocs 66 Pool Paged Resident Bytes 68 System Code Total Bytes 70 System Code Resident Bytes 72 System Driver Total Bytes 74 System Driver Resident Bytes 76 System Cache Resident Bytes 78 Announcements Domain/sec 80 Election Packets/sec 82 Mailslot Writes/sec 84 Server List Requests/sec 86 Cache 88 Data Maps/sec 90 Sync Data Maps/s
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\009]
"Help"="3 The System performance object consists of counters that apply to more than one instance of a component processors on the computer. 5 The Memory performance object consists of counters that describe the behavior of physical and virtual memory on the computer. Physical memory is the amount of random access memory on the computer. Virtual memory consists of the space in physical memory and on disk. Many of the memory counters monitor paging, which is the movement of pages of code and data between disk and physical memory. Excessive paging, a symptom of a memory shortage, can cause delays which interfere with all system processes. 7 % Processor Time is the percentage of elapsed time that the processor spends to execute a non-Idle thread. It is calculated by measuring the percentage of time that the processor spends executing the idle thread and then subtracting that value from 100%. (Each processor has an idle thread tha
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Network]
"FilterClasses"="ms_firewall_upper scheduler encryption compression vpn loadbalance avgfilter failover diagnostic custom"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVGFWFD]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVGFWFD\0000]
"Service"="Avgfwfd"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVGFWFD\0000]
"DeviceDesc"="AVG network filter service"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVGIDSHX]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVGIDSHX\0000]
"Service"="AVGIDSHX"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVGIDSHX\0000]
"DeviceDesc"="AVGIDSHX"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVGIDSSHIM]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVGIDSSHIM\0000]
"Service"="AVGIDSShim"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVGIDSSHIM\0000]
"DeviceDesc"="AVGIDSShim"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVGRKX86]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVGRKX86\0000]
"Service"="Avgrkx86"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVGRKX86\0000]
"DeviceDesc"="AVG Anti-Rootkit Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVGTDIX]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVGTDIX\0000]
"Service"="Avgtdix"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVGTDIX\0000]
"DeviceDesc"="AVG TDI Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVGUNIVX]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVGUNIVX\0000]
"Service"="avgunivx"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVGUNIVX\0000]
"DeviceDesc"="AVG Universal Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Network]
"FilterClasses"="ms_firewall_upper scheduler encryption compression vpn loadbalance avgfilter failover diagnostic custom"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_AVGFWFD]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_AVGFWFD\0000]
"Service"="Avgfwfd"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_AVGFWFD\0000]
"DeviceDesc"="AVG network filter service"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_AVGIDSHX]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_AVGIDSHX\0000]
"Service"="AVGIDSHX"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_AVGIDSHX\0000]
"DeviceDesc"="AVGIDSHX"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_AVGIDSSHIM]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_AVGIDSSHIM\0000]
"Service"="AVGIDSShim"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_AVGIDSSHIM\0000]
"DeviceDesc"="AVGIDSShim"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_AVGRKX86]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_AVGRKX86\0000]
"Service"="Avgrkx86"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_AVGRKX86\0000]
"DeviceDesc"="AVG Anti-Rootkit Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_AVGTDIX]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_AVGTDIX\0000]
"Service"="Avgtdix"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_AVGTDIX\0000]
"DeviceDesc"="AVG TDI Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_AVGUNIVX]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_AVGUNIVX\0000]
"Service"="avgunivx"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_AVGUNIVX\0000]
"DeviceDesc"="AVG Universal Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Network]
"FilterClasses"="ms_firewall_upper scheduler encryption compression vpn loadbalance avgfilter failover diagnostic custom"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVGFWFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVGFWFD\0000]
"Service"="Avgfwfd"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVGFWFD\0000]
"DeviceDesc"="AVG network filter service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVGIDSHX]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVGIDSHX\0000]
"Service"="AVGIDSHX"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVGIDSHX\0000]
"DeviceDesc"="AVGIDSHX"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVGIDSSHIM]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVGIDSSHIM\0000]
"Service"="AVGIDSShim"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVGIDSSHIM\0000]
"DeviceDesc"="AVGIDSShim"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVGRKX86]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVGRKX86\0000]
"Service"="Avgrkx86"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVGRKX86\0000]
"DeviceDesc"="AVG Anti-Rootkit Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVGTDIX]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVGTDIX\0000]
"Service"="Avgtdix"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVGTDIX\0000]
"DeviceDesc"="AVG TDI Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVGUNIVX]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVGUNIVX\0000]
"Service"="avgunivx"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AVGUNIVX\0000]
"DeviceDesc"="AVG Universal Driver"
[HKEY_USERS\.DEFAULT\AppEvents\EventLabels\avguiRSAlert]
[HKEY_USERS\.DEFAULT\AppEvents\EventLabels\avguiScanFinished]
[HKEY_USERS\.DEFAULT\AppEvents\EventLabels\avguiScanFinishedThreatFound]
[HKEY_USERS\.DEFAULT\AppEvents\EventLabels\avguiScanStarted]
[HKEY_USERS\.DEFAULT\AppEvents\EventLabels\avguiUpdEnd]
[HKEY_USERS\.DEFAULT\AppEvents\EventLabels\avguiUpdEndFail]
[HKEY_USERS\.DEFAULT\AppEvents\EventLabels\avguiUpdStart]
[HKEY_USERS\.DEFAULT\AppEvents\EventLabels\avguiWSAlert]
[HKEY_USERS\.DEFAULT\AppEvents\Schemes\Apps\avgui]
[HKEY_USERS\.DEFAULT\AppEvents\Schemes\Apps\avgui]
@="AVG"
[HKEY_USERS\.DEFAULT\Software\Avg Secure Update]
[HKEY_USERS\.DEFAULT\Software\Microsoft\IdentityCRL\DeviceIdentities\production\S-1-5-21-978799163-2666783903-3883505682-1000\02ckbelmzkei]
"DeviceId"="<Data><User username="02CKBELMZKEI"><Pwd Det="false">AQAAANCMnd8BFdERjHoAwE/Cl+sBAAAAJAGZw7nrA0umbz6Lg23YGQQAAAACAAAAAAAQZgAAAAEAACAAAACiSQOB1ZsB0J73vymtIVfbfs6vjyzHZ2Zici2j1zYqrAAAAAAOgAAAAAIAACAAAAA7jAavVTm6AmUSsJZzRvO48gIRhXgqR7v0DF/W/u3cHDAAAAAUL3RNP0ikmneMrcZe2Q2034yxQgWsTpdBJGumGKFiZpW9bElyxmIzCoDxnYFGQCdAAAAAsScQG0LgR9PpFrOJcg658FC9q88T6xNTKrRBADvrvurJpNKMGP8ynMKXj49W7BfuN6CVKf+9+3/hjEJ0v93+EQ==</Pwd><Certificate targetname="WindowsLive

cert):name=02ckbelmzkei;serviceuri=msn-messenger-didc" keyword="Microsoft_WindowsLive:certificate:" type="1">PABDAGUAcgB0AEkAbgBmAG8APgA8AEsAZQB5AHAAYQBpAHIAPgBBAFEAQQBBAEEATgBDAE0AbgBkADgAQgBGAGQARQBSAGoASABvAEEAdwBFAC8AQwBsACsAcwBCAEEAQQBBAEEAMABqADEAdAB5AGEAMQAwAHkAVQA2ADEATwAvADAASQBwADEAKwB2AC8AQQBRAEEAQQBBAEEAQwBBAEEAQQBBAEEAQQBBAFEAWgBnAEEAQQBBAEEARQBBAEEAQwBBAEEAQQBBAEEATwA1AGcAdwB3AFQAQwBTADQASQAyAEoAbgA1AGIAT
[HKEY_USERS\S-1-5-21-978799163-2666783903-3883505682-1000\Software\Adobe\Acrobat Reader\DC\AVGeneral]
[HKEY_USERS\S-1-5-21-978799163-2666783903-3883505682-1000\Software\Microsoft\Internet Explorer\DOMStorage\avg.com]
[HKEY_USERS\S-1-5-21-978799163-2666783903-3883505682-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\e6eac082_0]
@="{0.0.0.00000000}.{c08a20c4-5f8e-4f58-ac78-9bb414022905}|\Device\HarddiskVolume2\Program Files\AVG\Av\avgcomdlgx.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-18\AppEvents\EventLabels\avguiRSAlert]
[HKEY_USERS\S-1-5-18\AppEvents\EventLabels\avguiScanFinished]
[HKEY_USERS\S-1-5-18\AppEvents\EventLabels\avguiScanFinishedThreatFound]
[HKEY_USERS\S-1-5-18\AppEvents\EventLabels\avguiScanStarted]
[HKEY_USERS\S-1-5-18\AppEvents\EventLabels\avguiUpdEnd]
[HKEY_USERS\S-1-5-18\AppEvents\EventLabels\avguiUpdEndFail]
[HKEY_USERS\S-1-5-18\AppEvents\EventLabels\avguiUpdStart]
[HKEY_USERS\S-1-5-18\AppEvents\EventLabels\avguiWSAlert]
[HKEY_USERS\S-1-5-18\AppEvents\Schemes\Apps\avgui]
[HKEY_USERS\S-1-5-18\AppEvents\Schemes\Apps\avgui]
@="AVG"
[HKEY_USERS\S-1-5-18\Software\Avg Secure Update]
[HKEY_USERS\S-1-5-18\Software\Microsoft\IdentityCRL\DeviceIdentities\production\S-1-5-21-978799163-2666783903-3883505682-1000\02ckbelmzkei]
"DeviceId"="<Data><User username="02CKBELMZKEI"><Pwd Det="false">AQAAANCMnd8BFdERjHoAwE/Cl+sBAAAAJAGZw7nrA0umbz6Lg23YGQQAAAACAAAAAAAQZgAAAAEAACAAAACiSQOB1ZsB0J73vymtIVfbfs6vjyzHZ2Zici2j1zYqrAAAAAAOgAAAAAIAACAAAAA7jAavVTm6AmUSsJZzRvO48gIRhXgqR7v0DF/W/u3cHDAAAAAUL3RNP0ikmneMrcZe2Q2034yxQgWsTpdBJGumGKFiZpW9bElyxmIzCoDxnYFGQCdAAAAAsScQG0LgR9PpFrOJcg658FC9q88T6xNTKrRBADvrvurJpNKMGP8ynMKXj49W7BfuN6CVKf+9+3/hjEJ0v93+EQ==</Pwd><Certificate targetname="WindowsLive

cert):name=02ckbelmzkei;serviceuri=msn-messenger-didc" keyword="Microsoft_WindowsLive:certificate:" type="1">PABDAGUAcgB0AEkAbgBmAG8APgA8AEsAZQB5AHAAYQBpAHIAPgBBAFEAQQBBAEEATgBDAE0AbgBkADgAQgBGAGQARQBSAGoASABvAEEAdwBFAC8AQwBsACsAcwBCAEEAQQBBAEEAMABqADEAdAB5AGEAMQAwAHkAVQA2ADEATwAvADAASQBwADEAKwB2AC8AQQBRAEEAQQBBAEEAQwBBAEEAQQBBAEEAQQBBAFEAWgBnAEEAQQBBAEEARQBBAEEAQwBBAEEAQQBBAEEATwA1AGcAdwB3AFQAQwBTADQASQAyAEoAbgA1AGIAT
========== filefind ==========
Searching for "avg"
No files found.
========== folderfind ==========
Searching for "avg"
C:\ProgramData\Avg d------ [07:42 30/07/2016]
C:\Users\All Users\Avg d------ [07:42 30/07/2016]
C:\Users\Carina\AppData\Local\Avg d------ [13:03 27/07/2016]
C:\Windows\System32\config\systemprofile\AppData\Local\Avg d------ [13:05 27/07/2016]
========== service ==========
avg - Unable to open Service Handle.
-= EOF =-