also ich mach es mal mit grep: Code:
arne@fuckup:/tmp$ <log.txt grep -iEv '(^-|^=|^adm|frst|^search|^systemlook|^log|winsxs|^\s*$)' erzeugt diese Ausgabe: Code:
C:\Program Files\WindowsApps\Fingersoft.HillClimbRacing_1.29.120.0_x86__r6rtpscs7gwyg\Assets\Resources\lavasteam.plist --a---- 3150 bytes [22:22 22/06/2016] [22:22 22/06/2016] B0621B0C570788F06EDFAA41C3713165
C:\Program Files\WindowsApps\Fingersoft.HillClimbRacing_1.29.120.0_x86__r6rtpscs7gwyg\Assets\Resources\lavasteam.png --a---- 2811 bytes [01:16 28/01/2016] [01:17 28/01/2016] 18D5A29318B28D37BAE2CB3C4D5A1A2B
C:\Program Files (x86)\LibreOffice 5\share\config\soffice.cfg\cui\ui\javastartparametersdialog.ui --a---- 12017 bytes [10:22 27/10/2016] [10:22 27/10/2016] 3EF0CE0A67C5A3815447EE906739CDF6
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\10.2.0.190_0\common\scripts\avastwrc.js --a---- 76873 bytes [16:00 28/03/2015] [11:33 12/03/2015] F6DCB16E57983987C2D47C169C4C21B6
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\10.2.0.190_0\common\skin\img\avast-logo.png --a---- 3288 bytes [16:00 28/03/2015] [11:33 12/03/2015] 76A6708B5F865F3EB5F3987526B41476
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\10.2.0.190_0\common\skin\img\logo_avast.png --a---- 1980 bytes [16:00 28/03/2015] [11:33 12/03/2015] 3DF2DD6A3439328186E1E2D489962D65
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\10.2.0.190_0\common\skin\img\logo_avastblack.png --a---- 801 bytes [16:00 28/03/2015] [11:33 12/03/2015] 9FE1D40146ECBD3C5A64862C6FF9E844
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\10.2.0.190_0\common\skin\img\logo_avastsmall.png --a---- 503 bytes [16:00 28/03/2015] [11:33 12/03/2015] 346401841DB70073E56E122E76A349A2
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\10.2.0.190_0\common\ui\bgs\logo-avast-dark.png --a---- 3848 bytes [16:00 28/03/2015] [11:33 12/03/2015] 09896FF055C7AC2FD04C64F915F6E1D6
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\10.2.0.190_0\common\ui\bgs\logo-avast-white.png --a---- 3719 bytes [16:00 28/03/2015] [11:33 12/03/2015] CFEC7D263D4214D1DEE342F12AF26C1C
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\10.2.0.190_0\common\ui\bgs\logo-avast.png --a---- 2924 bytes [16:00 28/03/2015] [11:33 12/03/2015] BE10A7523C3CF2E6D7E48410CC6E6EDF
C:\Users\Administrator\AppData\Roaming\AVAST Software\Avast\log\avastium.log --a---- 101 bytes [15:59 28/03/2015] [15:25 05/04/2015] C9FE1C2CE8EE1041225746815DF6B50C
C:\Windows\System32\Tasks_Migrated\avastBCLRestartS-1-5-21-624198674-977653023-2037852723-1003 --a---- 3252 bytes [15:28 03/08/2016] [11:12 28/01/2015] B8706A285EA54564077948408345B345
C:\Program Files\Common Files\AV\avast! Antivirus d------ [15:05 23/03/2017]
C:\Program Files (x86)\Common Files\AV\avast! Antivirus d------ [15:05 23/03/2017]
C:\Users\Administrator\AppData\Roaming\AVAST Software d------ [15:58 28/03/2015]
C:\Users\Administrator\AppData\Roaming\AVAST Software\Avast d------ [15:58 28/03/2015]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B7E6B353-129C-43BE-86A5-1041305A828C}]
"HwIdAvastFull"="7504B3B60366CBE94B30222771F46867B797C694B5159D9CB278441B67BC7328"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2EA85D9B-3E57-343A-8AFA-4BDF08FD7EAC}]
@="IJavaStruct"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4F42A312-5754-35EB-947D-D93BE775B522}]
@="_JavaStructMarshalHelper"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{2EA85D9B-3E57-343A-8AFA-4BDF08FD7EAC}]
@="IJavaStruct"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{4F42A312-5754-35EB-947D-D93BE775B522}]
@="_JavaStructMarshalHelper"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications\AvastSvc.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_avast.vc110.crt_2036b14a11e83e4a_none_c373722873c01144]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_avast.vc140.crt_fcc99ee6193ebbca_none_020285fe6d6e0580]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_none_ef17e13d91c55d96]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_avast.vc110.crt_2036b14a11e83e4a_none_0b20a8ff883c3a4a]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_avast.vc140.crt_fcc99ee6193ebbca_none_49afbcd581ea2e86]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_avast.vc140.mfc_fcc99ee6193ebbca_none_49391d6d8244622b]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_none_5679bb9c25dbf18d]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_none_36c51814a641869c]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_none_364e78aca69bba41]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVAST Software]
[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\Interface\{2EA85D9B-3E57-343A-8AFA-4BDF08FD7EAC}]
@="IJavaStruct"
[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\Interface\{4F42A312-5754-35EB-947D-D93BE775B522}]
@="_JavaStructMarshalHelper"
C:\$RECYCLE.BIN\S-1-5-21-624198674-977653023-2037852723-1017\$I4WAVGP.jpg --a---- 544 bytes [11:59 05/07/2015] [11:59 05/07/2015] F34DEC5E349F89B7CFD3E3935B160B96
C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\avgntflt.cat --a-s-- 8172 bytes [19:09 23/01/2014] [08:32 18/12/2013] 2863C8AB8B4955EAACED764FA07CC212
C:\Users\lem0th\AppData\Local\Avg d------ [15:43 23/03/2017]
[HKEY_CURRENT_USER\SOFTWARE\AVG]
[HKEY_CURRENT_USER\SOFTWARE\AVG\AVG Browser Cleanup]
[HKEY_CURRENT_USER\SOFTWARE\AVG\Avgdiag]
[HKEY_CURRENT_USER\SOFTWARE\AVG Web TuneUp]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.avg]
[HKEY_CURRENT_USER\SOFTWARE\paint.net]
"File/MostRecent/Thumbnail1"="iVBORw0KGgoAAAANSUhEUgAAADoAAAA6CAYAAADhu0ooAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsMAAA7DAcdvqGQAAALWSURBVGhD7ZZrkuIwDIS5wRyFI8y9SYAkwIEIkCeQ1SdHwZsBprb2186qq1S2jFtS23KKhcPhcDgcDofD4XA4HA6Hw+Fw/Bx8iC3FPn+ooQ2Ni+V2ux3e2Rz3+32cBTzjxPYMcYxnnNjmgPuMn+f5VyuKYRS7+DwcDsM2y4a9jJmMcRJsjuvt9teFXq/X0Qv8/X7/hWc2x03yYwbbhzCbbzabIUmSIZM1NKpQkqRpOqxWiSQU0eNmMxCf4p8KjfdaHBPKnD3vhM75sVDjY7FQ9KzXa12LhD7E6e3KuNvtZMx0I8HqphmqqtK5CSVZ13XDTorM80I7ohAeXE7S4lR1rfuxru81Vi9C8XvxaS+rQblZrp1V6Ppec5iopmmHtu2mGqiJnHCpFR4iMVt7K5QNnAgiTFArxmhJGimY39hDN8Cxk6RgCmBOcXDYW9eN8hB6kxj4K2kxezZaqHAQiFBakMMAxOCQMIvHb1av1YyZnm+FkkhPWnyC0WoURnCS4HOyAKFwtAvGYpkTY7PZBg78cdSbjHzjUlQYww0XBbebaQ7wiBFEml/AkVrZSwy6yeylUIo2AiedJKkGK8sy3KAUqScr7cg6sPdFkXBjoaybMLsFYEIxy0tOngt56QxudC6UWBi8vr8Op9NJ98e3OLenQjkd2sVuiWQWvKrqqdi2lbcibcz6K6Hms2fqCuHiMzcfLjWwl3z43NBcKDGsFurouuCHnI8P0dwmoRYg3FR4d7bGmwwFhNaiABOgvhi3A+DDgU97UQhz28cBTk9ChKkvT4Mu4XYm8eSV/HCNb08C8eS3tiYWeeG9ggldHqUtj8ejWKkCwf
[HKEY_LOCAL_MACHINE\SOFTWARE\AVG]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.avgdi]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.avgdi]
"Content Type"="AvgDiagExFile"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.avgdi\shell\FmwAvgDiExOpen]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.avgdi\shell\FmwAvgDiExOpen]
@="Open AVG diag file"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.avgdi\shell\FmwAvgDiExOpen\command]
@=""C:\Program Files (x86)\AVG\Framework\1\avgdiagex.exe" /FILE="%1""
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.avgdx]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.avgdx]
"Content Type"="AvgDiagExFile"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.avgdx\shell\FmwAvgDxExOpen]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.avgdx\shell\FmwAvgDxExOpen]
@="Open AVG diag file"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.avgdx\shell\FmwAvgDxExOpen\command]
@=""C:\Program Files (x86)\AVG\Framework\1\avgdiagex.exe" /FILE="%1" /UI"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AVG]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvgPersistentStorage]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B7E6B353-129C-43BE-86A5-1041305A828C}]
"HwIdAvg"="d00cb75301e247cfbf72d16d67550644-07f8905a36838d6e0415a2817090d0dec0976ffe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\07E577C8197A8AD4CB3CA67B31F64448\SourceList]
"LastUsedSource"="n;1;C:\WINDOWS\Temp\AvgSetup\d0032905-01e2-47cf-bf72-d16d67550644\install\fmw\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\07E577C8197A8AD4CB3CA67B31F64448\SourceList\Net]
"1"="C:\WINDOWS\Temp\AvgSetup\d0032905-01e2-47cf-bf72-d16d67550644\install\fmw\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\A91FFE89BA03B4E49B340FB6C136BE8F\SourceList]
"LastUsedSource"="n;1;C:\WINDOWS\Temp\AvgSetup\d0032905-01e2-47cf-bf72-d16d67550644\install\fmw\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\A91FFE89BA03B4E49B340FB6C136BE8F\SourceList\Net]
"1"="C:\WINDOWS\Temp\AvgSetup\d0032905-01e2-47cf-bf72-d16d67550644\install\fmw\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
"DllName"="avgssie.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\Defender\AvgCPULoadFactor]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\Defender\AvgCPULoadFactor]
"RegValueNameRedirect"="AvgCPULoadFactor"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications\avguard.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\Program Files (x86)\AVG\Framework\Common\"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\Program Files (x86)\AVG\Framework\"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\Program Files (x86)\AVG\Framework\1\"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\AVG\log\fmw1\"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\AVG\log\"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\Program Files (x86)\AVG\Zen\"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\Avg\log\zen1\"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\Avg\Diag\"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\Program Files (x86)\AVG\Zen\3rd_party\licenses\"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\Program Files (x86)\AVG\Zen\3rd_party\"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG\"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E577C8197A8AD4CB3CA67B31F64448\InstallProperties]
"InstallSource"="C:\WINDOWS\Temp\AvgSetup\d0032905-01e2-47cf-bf72-d16d67550644\install\fmw\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E577C8197A8AD4CB3CA67B31F64448\InstallProperties]
"Publisher"="AVG Technologies"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1AE8DC971BED2854E914684322B3CD4D\Features]
"gm_Root"="IpDkHDYyO%r6z0'A7Dc'A6-M3,!4'*xctqqD`h&RjrS=Gd@7FTFt=yAu(J2Ab73K[izFW5fu25z_uM`cBSzpWqf*d.,rSofdDfrRlAzP[TcS=^(jwPLIn'T*nC!r*0DWD1M~&h1lxpRCZ$=~AAB1=QtRW-_Tt)-A8KI$mLz44@SKp5W4xwJYQlm.ZpOO~dj6cF-t=lafcx}ct+1GcJ{[]2_x7EQ.H6Yc8B31$PFX]P(c=!+tE@NT4Kq@1F{s36@F+tpLNx_Dz!O?@z?Bfuep0,k+o,dt$a@sW=%TprKdgShE[FAY@6zI[TY29=2-HTTV%R~1LxHEHAUgM34y[VnGv'n`y68'GWHnKd6VOY1@lb1JljuFtH0AYnQO3K_Sw4Y]d@@1Jx_AaO@=swevYtHjACx=~znTomu%~YYAcw$tNd8^5_5uzAFS@G&4$a'JQ2*!?+DobZ%cQ(oDPo~Ikgk'JL+_=t`R.qF?*V})]^tI1NEwLR$nhcv$D)*&E6L*lXunYMew,Dca!3X1INo+p@wg3KQiS0)AkV?kN`Q*wQ@r$!1iOy0RucGHSP=oxy@]$o=bo!Fzw.e$]MqL9D~gzV0dGk)593`Q,udx?9Co=[sWBt!D{DX.AF8'pNX=*?NL80]tCR?)=eB^ENK16x2d4ozH5Ac1-@ut+-4q{4OvUo+tt1a(nl9ILdK@^2WU9O_(!srU@*SPpqHSlJgYF@PkOSaOo!Nz)m.t)(9i_fY6d!^roYC[&)qMTL9+c8YVWZnleY`*Gud.gT]fleX.aSf7DrNKo'diy@8u=TzXLR?nlvc2vNk}{_G+-l0wzZxm85]I2kLf_DRFa6,DVmQMCy)}A-D%IubUg0q@'~vs9=S[%n
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1AE8DC971BED2854E914684322B3CD4D\Features]
"gm_Langpack_Basis_ast"="yU4vlXGjdSkHnWiJc9C?P7D=(yHvyuIWunS6a3VTa5b1kskA5Jlfl4aqN&VWxjMyaVG5k8C}KlnMfu[=89b%C6I?5*}g&HA.&~}s0Nw%V_en`Me!8CKa6t{@Iph3.8%JFq*.D[B=JnP0oZr=NKaZnV+7+z!H7}4A5UXdl]~Zm%@eJAzA''K!,B2CoK*C=flR&UNEX$dm%S$XpLQxy4&m$%i^2GDJAMOAeuz7LH.v@psHv4~W_D?K%5zwxXP4MLrQ?Tl!IjnQ91PGI0}XS?RU_d*E`1aUCWEeE`y.YKD'i_1-pd$=skMp?9G2YKXwL*Kd6uW?1u~h8d5Vud(VVdw`84[mGUIV(ZSUlgHC_{'t2Bw(ZU^DwOPC-jmHPHFJvIEmUGx~3l&,,e*zPQv`vffPNjJ^+e^Wm1_HQ]d&QVNZHXU'{.1-_d.TYbwzTN^@,z4Nx90s*81{BIHup5OVx*W,Q5P9t'bMPlgK!FZxhj=.!)So*2VnzD)k~K&3y[bDy(g'EJcveUsIN~t]22z`~amvia3OZ$F@gm_Langpack_r_ast"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1AE8DC971BED2854E914684322B3CD4D\Features]
"gm_Langpack_Basis_kk"=",,2CfdAog[wg!{kt1Jd*9Lj$n5){4V5dqlm?J$e]%zdbbwPGK=@bGb54ir}EyQ5=b&7K@d81Dy_K@j~e{mPs7c'(r3EWf-z%A6V'Bh}IJ7-t&0M{gw(r0@hHG5qzQ58HI@9CA!5O`r.**J5Sz_&JUo09mf?58{=gUEay$xC8^L)i(vO9Zu=FW6P_0zWf@yBlI*yv7m~mjbKAj=$TS9-jhGR'+]]1n4^%nW-+xwJA37T'J%kQIaolb`HP?D)&$(C-uDTc!&S2rO3QgB00Ky0xr6.tKn2dE$yh?0axJz5W]wAM.E.@kzi5u(XQjLnFYJ%]db9*999_UE1nWONR.yfHM9sBf+7sQf4&Qv+!IR$G'NSz9d$pwWjc,mx2*{sZ?pQ6Jmy`T[U8x^@AH$yp(*CM?-ZBsCJ(DAyb])8]i(RkCkXo2_7vQ{21S)36u.L5jU@d[bfdAg[uL%p-{+]}Iu$Ga6w5PCSp'U-]!PYDekzZ}8t@7bX+_auY'{Er&ud`hjj7&a$oV,Of]4tJW`3]TZGY`{gaVG@Ngm_Langpack_r_kk"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1AE8DC971BED2854E914684322B3CD4D\Features]
"gm_Langpack_Base_kk"="S1nJA2ynL%,BO^PtfRP@c}+XV7FpS&TeaDrkVB0meG^`KMN7t3W~4?q3'XC[?5+2ac?'h)S,y,w-n+TGeMIiPLavGx!7Fvp)y~ju!!V]YNLi(lQybZ.S-F`)@%!9@]~I=AXTJ!bdNaWN9aRqmBkINe97rk$bQo8ugm_Langpack_r_kk"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1AE8DC971BED2854E914684322B3CD4D\Features]
"gm_Langpack_Resource_nb"="+VD84X7'7cG$P_eQ6w6@L{`3OkXP_myB7-rZ?gnJUJZI+@@zl4n@BFQ33h.mOrs}8@=%tYH)C)C6R.CKEww85LOg2u,KAs.G&{bbq@,R,(4zlr9jiME%&~iDVK5WO86KV[NYm=UmK]910nz[!5K(`5)}_0l+@qeuvuE4wEhaI1(6``4G!STt+Ne]mho[=lFHk~Q1ZyX0nlQavw[^3HZya@1%z&tc+[TBtahDl%P`ZZx=roK?)(f+z6v_[3xvLD)4_1U9E.Hjv,n2{h(E*[u_2hI-E44J&~^NFfv~iW-$@GX[h3FGt!k!W.G_LTf2}VyX1kp=K3vHAjQ~yA*0}0RdiG~0o&Va9P`9H43Xblyem]41^%q3EFeI,IGIi+IAgvryR-lzpA0$Dw9TKwsdIeals$1qQynH{uLA5}5*%l7_$dy'L!-]$9ALKTc.ee$chuy'Df$HcjGe^8irSiBqDsJ.!+zOd8Wr$^kARC4zjj8Xym`On_cms_PHuJ7h=I]oyJeEP+{0rvQClwmIdB*36F,xw*p6(FgQyF{0jJOJn,[_WP4Oz0N!HJZ!YV~P1uJBfkmvl@)FS}BPW-0Q[3%xX,'{p-P*-8504btCCOHFnlVUrc_oEWaBxn!u0)&eMdVrIScdB!aNx5Pv2g1[1%8LAf(BM&aC.RwbP9I+,J=*mXH!%eXh7y@ySOX`Ivv12X]xAVgY=o%Yz%9k4Ot9%@t'AsS-B5ekRskKSaLxny*3Za]2)Gv]W3*4PP$3sDp%2+?CG9MCTT*UpumHm6k2YAOXIIX+Vy9C$}ow1w6d.odpGU(T)p[](et!W.O4ys7sREB208z6'^eZrburgm_Langpack_r
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A91FFE89BA03B4E49B340FB6C136BE8F\InstallProperties]
"InstallSource"="C:\WINDOWS\Temp\AvgSetup\d0032905-01e2-47cf-bf72-d16d67550644\install\fmw\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A91FFE89BA03B4E49B340FB6C136BE8F\InstallProperties]
"Publisher"="AVG Technologies CZ, s.r.o."
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\DD0EFD1C08E15CB48B80CE0398566460\Features]
"Core"="$^uNlz0u)AL6o?SnNvn1Tji!zq2){@wN^&p*kncFYFx2HI0w`@kN!pp,[(s_3}.MQT.?x9h0V^B^bUj[y7Lkj01+IA2_&?a*Oh{U4fZI3U=$u@Zl*7zc(N0%(C%5em?9V@02?I0,+8kRkAYObf+&h8C=j[Gv!V%x+4w&PJMB}8(7'^Ts}0Izr_lng01_o9(0cu_6c^zg~l(hmqCz6?d@z1iWsG4l@!eKn]zZY9XdztD$qJsUV1~{M}.Pe?}pvnMpxIFYH{{(&{HyWAP+sx[[oB9UJWws(0byk9HVSM(i)es*oE'Nlw23.9Har*pV(9OO.Z5$ymc65=a{[CS19N@EAXbJaJeBj?6]KwQX0DuQc.Wg6*Wd99OZZDY_(WSn_8P&)oRa9?=-}=G9XZYnCwo-di~![@7zGepw}T`qNvsZN%~p!AGoOlrCwp[r6e.wzg}6R@UzR,VoX+nLmr$jv6B{3@Fr{(W~DucC3BI6vAitl8UX'+XuPr]&FiAPLk!Sp@nQx@jHbS9W[N]xk(JoI@$h_woIx9vq(i.$5hwEL9['0,!W]$ISQW0R7gw?=99g7^q4AJFry^Q!J0Cg[=Ns,urD+[s$?{?izj&`A=wmgopk%)0R)^]e6+{^7?5&Dw4@KG[V_51@9BGUy?i}8@[j')A(7gSS*KWnv=,t7GaQ^'{%{Y+hoea*&@+i3gJJYC^v,xOYfJ?jo8HGL$[Llbo6u*n}2A)ISA_q4ZC!Xlf0]PQXF4`rR@.[2qd^hp)Mt8&z4E}3'=y4+[`BQ5GQeiC(wHppe@4Q4O S-B}quTCIP~~9wL)b3Zi_oJ@_XM?gL819'$W,(=ZtVAO6V@3p(Ap8y@l0=a_m).!ma$+@H(E?=ZR
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_avg.vc140.crt_f92d94485545da78_none_fce6f287894868aa]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_avg.vc140.mfc_f92d94485545da78_none_fd9dc69b88bfb01f]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_policy.14.0.avg.vc140.crt_f92d94485545da78_none_a9ad3a99a4bbc1ec]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_policy.14.0.avg.vc140.mfc_f92d94485545da78_none_aa640eada4330961]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_avg.vc140.crt_f92d94485545da78_none_4494295e9dc491b0]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_avg.vc140.mfc_f92d94485545da78_none_454afd729d3bd925]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_policy.14.0.avg.vc140.crt_f92d94485545da78_none_f15a7170b937eaf2]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_policy.14.0.avg.vc140.mfc_f92d94485545da78_none_f2114584b8af3267]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}]
"InstallSource"="C:\WINDOWS\Temp\AvgSetup\d0032905-01e2-47cf-bf72-d16d67550644\install\fmw\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}]
"Publisher"="AVG Technologies"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\009]
"Counter"="1 1847 2 System 4 Memory 6 % Processor Time 10 File Read Operations/sec 12 File Write Operations/sec 14 File Control Operations/sec 16 File Read Bytes/sec 18 File Write Bytes/sec 20 File Control Bytes/sec 24 Available Bytes 26 Committed Bytes 28 Page Faults/sec 30 Commit Limit 32 Write Copies/sec 34 Transition Faults/sec 36 Cache Faults/sec 38 Demand Zero Faults/sec 40 Pages/sec 42 Page Reads/sec 44 Processor Queue Length 46 Thread State 48 Pages Output/sec 50 Page Writes/sec 52 Browser 54 Announcements Server/sec 56 Pool Paged Bytes 58 Pool Nonpaged Bytes 60 Pool Paged Allocs 64 Pool Nonpaged Allocs 66 Pool Paged Resident Bytes 68 System Code Total Bytes 70 System Code Resident Bytes 72 System Driver Total Bytes 74 System Driver Resident Bytes 76 System Cache Resident Bytes 78 Announcements Domain/sec 80 Election Packets/sec 82 Mailslot Writes/sec 84 Server List Requests/sec 86 Cache 88 Data Maps/sec 90 Sync Data Maps/s
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\009]
"Help"="3 The System performance object consists of counters that apply to more than one instance of a component processors on the computer. 5 The Memory performance object consists of counters that describe the behavior of physical and virtual memory on the computer. Physical memory is the amount of random access memory on the computer. Virtual memory consists of the space in physical memory and on disk. Many of the memory counters monitor paging, which is the movement of pages of code and data between disk and physical memory. Excessive paging, a symptom of a memory shortage, can cause delays which interfere with all system processes. 7 % Processor Time is the percentage of elapsed time that the processor spends to execute a non-Idle thread. It is calculated by measuring the percentage of time that the processor spends executing the idle thread and then subtracting that value from 100%. (Each processor has an idle thread tha
[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\AVG]
[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\AVG\Subscriptions\ActiveProducts]
"AvAvg"="434ad9f5-e461-f611-8f68-d9234df9fa24"
[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Extension Compatibility\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
"DllName"="avgssie.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}]
"InstallSource"="C:\WINDOWS\Temp\AvgSetup\d0032905-01e2-47cf-bf72-d16d67550644\install\fmw\"
[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}]
"Publisher"="AVG Technologies CZ, s.r.o."
[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Perflib\009]
"Counter"="1 1847 2 System 4 Memory 6 % Processor Time 10 File Read Operations/sec 12 File Write Operations/sec 14 File Control Operations/sec 16 File Read Bytes/sec 18 File Write Bytes/sec 20 File Control Bytes/sec 24 Available Bytes 26 Committed Bytes 28 Page Faults/sec 30 Commit Limit 32 Write Copies/sec 34 Transition Faults/sec 36 Cache Faults/sec 38 Demand Zero Faults/sec 40 Pages/sec 42 Page Reads/sec 44 Processor Queue Length 46 Thread State 48 Pages Output/sec 50 Page Writes/sec 52 Browser 54 Announcements Server/sec 56 Pool Paged Bytes 58 Pool Nonpaged Bytes 60 Pool Paged Allocs 64 Pool Nonpaged Allocs 66 Pool Paged Resident Bytes 68 System Code Total Bytes 70 System Code Resident Bytes 72 System Driver Total Bytes 74 System Driver Resident Bytes 76 System Cache Resident Bytes 78 Announcements Domain/sec 80 Election Packets/sec 82 Mailslot Writes/sec 84 Server List Requests/sec 86 Cache 88 Data Maps/sec 90 Sync
[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Perflib\009]
"Help"="3 The System performance object consists of counters that apply to more than one instance of a component processors on the computer. 5 The Memory performance object consists of counters that describe the behavior of physical and virtual memory on the computer. Physical memory is the amount of random access memory on the computer. Virtual memory consists of the space in physical memory and on disk. Many of the memory counters monitor paging, which is the movement of pages of code and data between disk and physical memory. Excessive paging, a symptom of a memory shortage, can cause delays which interfere with all system processes. 7 % Processor Time is the percentage of elapsed time that the processor spends to execute a non-Idle thread. It is calculated by measuring the percentage of time that the processor spends executing the idle thread and then subtracting that value from 100%. (Each processor has an idl
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\avguniva]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\avguniva]
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\AuthCookies\Live\Default\DIDC]
"Data"="ct%3D1490215090%26hashalg%3DSHA256%26bver%3D13%26appid%3DDefault%26da%3D%253CEncryptedData%2520xmlns%253D%2522http://www.w3.org/2001/04/xmlenc%2523%2522%2520Id%253D%2522devicesoftware%2522%2520Type%253D%2522http://www.w3.org/2001/04/xmlenc%2523Element%2522%253E%253CEncryptionMethod%2520Algorithm%253D%2522http://www.w3.org/2001/04/xmlenc%2523tripledes-cbc%2522%253E%253C/EncryptionMethod%253E%253Cds:KeyInfo%2520xmlns:ds%253D%2522http://www.w3.org/2000/09/xmldsig%2523%2522%253E%253Cds:KeyName%253Ehttp://Passport.NET/STS%253C/ds:KeyName%253E%253C/ds:KeyInfo%253E%253CCipherData%253E%253CCipherValue%253ECSefnIpMQ4pVw6/oNXVC594tUNFzPtPsKHkamQXIOfmxKaYF263g7gj0vLTmZWC57nR1pzhCSPc8lU8bTSgW19zcRTURtjkfBAJTxhk0H8IzbGe7e0G1FEVojN3V5CBkf4bGPi3GcvetnDNyA4Xhq9DvhjWBTzgo6ksTUQzEbF3s9UWxXJjngT/cOHtoAj2ExeuYzxsAvzcFnwAXnP4AvwtLJG6X6dAtDQrrL7ueETkQDvvqBkVAwXpNoZhRm2BGp9lHfP2ULJ3jaZM05q5VkSLhOB/r%252Bqkmn4NVG8ZZMgs5vH86o0ba2zdShbUW/9hILQHuRafTdWCJfBc
[HKEY_USERS\S-1-5-21-624198674-977653023-2037852723-1040\SOFTWARE\AVG]
[HKEY_USERS\S-1-5-21-624198674-977653023-2037852723-1040\SOFTWARE\AVG\AVG Browser Cleanup]
[HKEY_USERS\S-1-5-21-624198674-977653023-2037852723-1040\SOFTWARE\AVG\Avgdiag]
[HKEY_USERS\S-1-5-21-624198674-977653023-2037852723-1040\SOFTWARE\AVG Web TuneUp]
[HKEY_USERS\S-1-5-21-624198674-977653023-2037852723-1040\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.avg]
[HKEY_USERS\S-1-5-21-624198674-977653023-2037852723-1040\SOFTWARE\paint.net]
"File/MostRecent/Thumbnail1"="iVBORw0KGgoAAAANSUhEUgAAADoAAAA6CAYAAADhu0ooAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsMAAA7DAcdvqGQAAALWSURBVGhD7ZZrkuIwDIS5wRyFI8y9SYAkwIEIkCeQ1SdHwZsBprb2186qq1S2jFtS23KKhcPhcDgcDofD4XA4HA6Hw+Fw/Bx8iC3FPn+ooQ2Ni+V2ux3e2Rz3+32cBTzjxPYMcYxnnNjmgPuMn+f5VyuKYRS7+DwcDsM2y4a9jJmMcRJsjuvt9teFXq/X0Qv8/X7/hWc2x03yYwbbhzCbbzabIUmSIZM1NKpQkqRpOqxWiSQU0eNmMxCf4p8KjfdaHBPKnD3vhM75sVDjY7FQ9KzXa12LhD7E6e3KuNvtZMx0I8HqphmqqtK5CSVZ13XDTorM80I7ohAeXE7S4lR1rfuxru81Vi9C8XvxaS+rQblZrp1V6Ppec5iopmmHtu2mGqiJnHCpFR4iMVt7K5QNnAgiTFArxmhJGimY39hDN8Cxk6RgCmBOcXDYW9eN8hB6kxj4K2kxezZaqHAQiFBakMMAxOCQMIvHb1av1YyZnm+FkkhPWnyC0WoURnCS4HOyAKFwtAvGYpkTY7PZBg78cdSbjHzjUlQYww0XBbebaQ7wiBFEml/AkVrZSwy6yeylUIo2AiedJKkGK8sy3KAUqScr7cg6sPdFkXBjoaybMLsFYEIxy0tOngt56QxudC6UWBi8vr8Op9NJ98e3OLenQjkd2sVuiWQWvKrqqdi2lbcibcz6K6Hms2fqCuHiMzcfLjWwl3z43NBcKDGsFurouuCHnI8P0dwmoRYg3FR4d7bGmwwFhNaiABOgvhi3A+DDgU97UQhz28cBTk9ChKkvT4Mu4XYm8eSV |