Farbar Recovery Scan Tool (x64) Version: 4.02.2019 Ran by Jules (05-02-2019 19:28:24) Running from C:\Users\Jules\Desktop Boot Mode: Normal ================== Search Registry: "TotalAV" =========== [HKEY_USERS\S-1-5-21-2701981542-1479078516-1186315799-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "C:\Program Files (x86)\TotalAV\TotalAV.exe"="0x5341435001000000000000000700000028000000D08C950023B4950001000000000000000000000A00210000BFA2139DEDD1D30100000000000000000200000050000000000000000000004000000000000000000000000000000000CA08000000000000010000000100000000000000000000000000000000000000000000000000000022FE9500000000000600000000000000" [HKEY_USERS\S-1-5-21-2701981542-1479078516-1186315799-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "C:\Program Files (x86)\TotalAV\Update.Win.exe"="0x5341435001000000000000000700000028000000F8F844001781450001000000000000000000000A00210000BFA2139DEDD1D3010000000000000000020000002800000000000000000000000000000000000000000000000000000014210000000000000100000001000000" [HKEY_USERS\S-1-5-21-2701981542-1479078516-1186315799-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "C:\Program Files (x86)\TotalAV\SecurityService.exe"="0x5341435001000000000000000700000028000000D095430017C3430001000000000000000000000A00210000BFA2139DEDD1D30100000000000000000200000028000000000000000000004000000000000000000000000000000000361E0000000000000100000001000000" [HKEY_USERS\S-1-5-21-2701981542-1479078516-1186315799-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "C:\Users\Jules\Desktop\TotalAV_Setup.exe"="0x534143500100000000000000070000002800000010E2C40011C7C50001000000000000000000000A00210000BFA2139DEDD1D301000000000000000002000000280000000000000000000040000000000000000000000000000000002A451D00000000000200000002000000" [HKEY_USERS\S-1-5-21-2701981542-1479078516-1186315799-1001\Software\Classes\VirtualStore\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\TotalAV_RASAPI32] [HKEY_USERS\S-1-5-21-2701981542-1479078516-1186315799-1001\Software\Classes\VirtualStore\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\TotalAV_RASMANCS] [HKEY_USERS\S-1-5-21-2701981542-1479078516-1186315799-1001\Software\Classes\WOW6432Node\CLSID\{d79b57ed-727c-4ab8-ba67-e7c6fd30fac1}\LocalServer32] ""="C:\Program Files (x86)\TotalAV\TotalAV.exe" ====== End of Search ======