Start:: CreateRestorePoint: CloseProcesses: C:\ProgramData\eMule C:\Users\Pierre\AppData\Roaming\uTorrent DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{68B3E1F9-28D6-4996-9D0B-51B5ADB1FFDD} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{68B3E1F9-28D6-4996-9D0B-51B5ADB1FFDD} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{68B3E1F9-28D6-4996-9D0B-51B5ADB1FFDD} C:\Windows\System32\Tasks\XoftSpySE C:\Program Files\Internet Explorer\iexplore.exe DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{06E507FF-28C1-4A02-8923-F54E539028EB} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{06E507FF-28C1-4A02-8923-F54E539028EB} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{06E507FF-28C1-4A02-8923-F54E539028EB} C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{072AE338-519D-46A2-8D0D-334BCA5DFE29} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{072AE338-519D-46A2-8D0D-334BCA5DFE29} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{072AE338-519D-46A2-8D0D-334BCA5DFE29} C:\Windows\System32\Tasks\{58441F3E-DBBA-4901-A534-3B5D25500296} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{080BA877-06C4-4758-A656-77399A1035B1} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{080BA877-06C4-4758-A656-77399A1035B1} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{080BA877-06C4-4758-A656-77399A1035B1} C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0A0CFBCE-76FD-41C3-910C-66310E75C077} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{0A0CFBCE-76FD-41C3-910C-66310E75C077} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{0A0CFBCE-76FD-41C3-910C-66310E75C077} C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{15E9EC32-1127-4570-8294-8BAB62536F46} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{15E9EC32-1127-4570-8294-8BAB62536F46} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{15E9EC32-1127-4570-8294-8BAB62536F46} C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{16A6CCFC-F721-4329-96FA-9DE7A82C3964} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{16A6CCFC-F721-4329-96FA-9DE7A82C3964} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{16A6CCFC-F721-4329-96FA-9DE7A82C3964} C:\Windows\System32\Tasks\{E17E53AF-0565-4CBD-A2BD-573BDAF8A2A8} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1CFF5D78-9717-4501-B269-5E89639158E6} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{1CFF5D78-9717-4501-B269-5E89639158E6} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{1CFF5D78-9717-4501-B269-5E89639158E6} C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2148FDB5-93CE-4CBB-9D23-B8C4DEACCC7A} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{2148FDB5-93CE-4CBB-9D23-B8C4DEACCC7A} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{2148FDB5-93CE-4CBB-9D23-B8C4DEACCC7A} C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2718E356-8858-4C7E-A7F6-03FBC8CB2DC0} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{2718E356-8858-4C7E-A7F6-03FBC8CB2DC0} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{2718E356-8858-4C7E-A7F6-03FBC8CB2DC0} C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3DB506C0-19B8-408F-B930-DAE99AE19AF1} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{3DB506C0-19B8-408F-B930-DAE99AE19AF1} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{3DB506C0-19B8-408F-B930-DAE99AE19AF1} C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\mcupdate DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5EEA9D50-B503-4B8E-89CC-782044D4A77F} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{5EEA9D50-B503-4B8E-89CC-782044D4A77F} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{5EEA9D50-B503-4B8E-89CC-782044D4A77F} C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6AA28F04-8676-4E12-9C9D-77308E5B61D1} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{6AA28F04-8676-4E12-9C9D-77308E5B61D1} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{6AA28F04-8676-4E12-9C9D-77308E5B61D1} C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6AC8886C-69D1-4A38-8692-749673851DC5} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{6AC8886C-69D1-4A38-8692-749673851DC5} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{6AC8886C-69D1-4A38-8692-749673851DC5} C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6E4221ED-754E-4B51-A304-77D115B573C4} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{6E4221ED-754E-4B51-A304-77D115B573C4} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{6E4221ED-754E-4B51-A304-77D115B573C4} C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{73C4073E-6FC3-4EFB-A2AE-955CCEA0D380} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{73C4073E-6FC3-4EFB-A2AE-955CCEA0D380} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{73C4073E-6FC3-4EFB-A2AE-955CCEA0D380} C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{77B1A29C-3D07-4DE4-85E7-FB01734F70AA} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{77B1A29C-3D07-4DE4-85E7-FB01734F70AA} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{77B1A29C-3D07-4DE4-85E7-FB01734F70AA} C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8A618F4D-064C-4647-83D9-598F11BDF84B} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{8A618F4D-064C-4647-83D9-598F11BDF84B} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{8A618F4D-064C-4647-83D9-598F11BDF84B} C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8EE15C59-151A-4907-B3D7-86B80B270311} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{8EE15C59-151A-4907-B3D7-86B80B270311} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{8EE15C59-151A-4907-B3D7-86B80B270311} C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{95402F73-0E9C-4513-9C59-91C1A35625CE} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{95402F73-0E9C-4513-9C59-91C1A35625CE} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{95402F73-0E9C-4513-9C59-91C1A35625CE} C:\Windows\System32\Tasks\{438D42B3-2A52-4180-94C3-900E352F6BB7} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9B424E13-18A0-4269-82E7-9D8DF1F4C90D} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{9B424E13-18A0-4269-82E7-9D8DF1F4C90D} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{9B424E13-18A0-4269-82E7-9D8DF1F4C90D} C:\Windows\System32\Tasks\CreateChoiceProcessTask DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B6A384CC-89D8-4D83-B21C-DADF8185E35F} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{B6A384CC-89D8-4D83-B21C-DADF8185E35F} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{B6A384CC-89D8-4D83-B21C-DADF8185E35F} C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BB51A8C2-46F4-4E14-AA75-0E7CB82615C2} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{BB51A8C2-46F4-4E14-AA75-0E7CB82615C2} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{BB51A8C2-46F4-4E14-AA75-0E7CB82615C2} C:\Windows\System32\Tasks\{B0A9A45A-EEAF-4D3B-B05E-EE602959BCE3} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BC6EF148-C4CE-494D-AD82-752D6DCFF1A5} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{BC6EF148-C4CE-494D-AD82-752D6DCFF1A5} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{BC6EF148-C4CE-494D-AD82-752D6DCFF1A5} C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C5EDE16B-6F92-4089-B44D-917FFB94A5A1} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{C5EDE16B-6F92-4089-B44D-917FFB94A5A1} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{C5EDE16B-6F92-4089-B44D-917FFB94A5A1} C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\OCURActivate DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D9036D6B-75F0-418D-8385-8D2A4571F1D8} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{D9036D6B-75F0-418D-8385-8D2A4571F1D8} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{D9036D6B-75F0-418D-8385-8D2A4571F1D8} C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E3059421-2B5C-464F-91CB-BA4465B98024} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{E3059421-2B5C-464F-91CB-BA4465B98024} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{E3059421-2B5C-464F-91CB-BA4465B98024} C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{ECFD7384-F826-4FF5-8E08-F50421506830} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{ECFD7384-F826-4FF5-8E08-F50421506830} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{ECFD7384-F826-4FF5-8E08-F50421506830} C:\Windows\System32\Tasks\{19DD6C83-DCC2-467D-955F-530C5B613D91} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F15EE91C-EBD0-4065-B468-035AB7C59E98} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{F15EE91C-EBD0-4065-B468-035AB7C59E98} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{F15EE91C-EBD0-4065-B468-035AB7C59E98} C:\Windows\System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F1F9A2F5-68C1-4EB2-A967-BAB6BB65DEC4} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{F1F9A2F5-68C1-4EB2-A967-BAB6BB65DEC4} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{F1F9A2F5-68C1-4EB2-A967-BAB6BB65DEC4} C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F497DF68-8A40-430C-BA25-1D28165099AF} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{F497DF68-8A40-430C-BA25-1D28165099AF} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{F497DF68-8A40-430C-BA25-1D28165099AF} C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\StartRecording C:\WINDOWS\System32\Tasks\XoftSpySE DeleteKey: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9} DeleteKey: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435b-BC74-9C25C1C588A9} DeleteKey: HKLM\Software\Classes\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9} DeleteKey: HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\xoftspy DeleteKey: HKLM\Software\Classes\CLSID\{FF190C9D-15C4-4ffe-A990-66412CD32E77} DeleteKey: HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\Gadgets DeleteKey: HKLM\Software\Classes\CLSID\{6B9228DA-9C15-419e-856C-19E768A13BDC} DeleteKey: HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\xoftspy DeleteKey: HKLM\Software\Classes\CLSID\{FF190C9D-15C4-4ffe-A990-66412CD32E77} DeleteKey: HKLM\SOFTWARE\Classes\Drive\shellex\ContextMenuHandlers\xoftspy DeleteKey: HKLM\Software\Classes\CLSID\{FF190C9D-15C4-4ffe-A990-66412CD32E77} DeleteValue: HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{FA3EA245-3EBF-494F-9A2F-4A8539E71684} DeleteValue: HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{96D6F911-5F8D-46E7-A266-2442E8FAC666} C:\WINDOWS\Installer\2a776.msp C:\WINDOWS\Installer\2cf90.msp C:\WINDOWS\Installer\44a1905.msp DeleteKey: HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9} DeleteKey: HKLM\Software\Classes\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9} DeleteKey: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435b-BC74-9C25C1C588A9} DeleteKey: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{DBC80044-A445-435b-BC74-9C25C1C588A9} DeleteKey: HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\xoftspy DeleteKey: HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\Gadgets DeleteKey: HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\xoftspy DeleteKey: HKLM\Software\Classes\Drive\shellex\ContextMenuHandlers\xoftspy C:\Users\Pierre\AppData\Local\Google\Chrome\User Data\Default\File System\000 EmptyTemp: Hosts: