cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

Task::
Avast Emergency Update

KEY::
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{f9e93b39-49d1-4179-9848-a5a2896955ea}]
[HKU\S-1-5-21-3749229121-239879379-510366881-1001\Software\Microsoft\Windows\CurrentVersion\Run]|"Opera Browser Assistant"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]|"AvastUI.exe"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32]|"Avira SystrayStartTrigger"
[HKU\S-1-5-21-3749229121-239879379-510366881-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store]
[HKU\S-1-5-21-3749229121-239879379-510366881-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store]|""|REG_SZ|""
[HKU\S-1-5-21-3749229121-239879379-510366881-1001\Software\AVAST Software]
[HKU\S-1-5-21-3749229121-239879379-510366881-1001\Software\AvastAdSDK]
[HKU\S-1-5-21-3749229121-239879379-510366881-1001\Software\Avira]
[HKU\S-1-5-21-3749229121-239879379-510366881-1001\Software\Chromium]
[HKLM\Software\AVAST Software]
[HKLM\Software\WOW6432Node\AVAST Software]
[HKLM\Software\WOW6432Node\Avira]

File::
C:\Users\Andre\AppData\Local\Lavasoft
C:\ProgramData\AVAST Software
C:\ProgramData\Avira
C:\WINDOWS\System32\Tasks\Avast Emergency Update
C:\WINDOWS\System32\Tasks\AVAST Software

RegRead::
[HKLM\Software\Microsoft\Windows\UpdateApi]

txt::
C:\WINDOWS\System32\GroupPolicy\Machine\Registry.pol
CMD::
Attrib.exe -h -r -s -a C:\WINDOWS\Temp /s /d
del /f /q C:\WINDOWS\Temp\*
rd /s /q C:\WINDOWS\Temp\*
Attrib.exe -h -r -s -a %Temp% /s /d
del /f /q %Temp%\*
rd /s /q %Temp%\*
###

RecurseList::
C:\WINDOWS\System32\Tasks\S-1-5-21-3749229121-239879379-510366881-1001

Clean::
Yes

Publicité


Signaler le contenu de ce document

Publicité