Advise me please.

ShadowCaster

WF Premium Member
Sep 5, 2010
3,590
138
0
34
So I got a virus, and after I removed it lots of websites stopped loading, this

Server not found
Firefox can't find the server at Google.

error. Tried different browsers, restarted PC etc, still nothing. I would google, but none if the search engines work.

Any advice?
 


Check your hosts file to make sure google.com domain isn't getting redirected.

c:\windows\system32\drivers\etc\hosts

You can try ping google.com in command prompt also and see what it spits out.

You can always reformat too i'm sure that would fix it.
 
Dont even fuck around. Backup what you have to and reformat. PC's are like women, every now and then you need a fresh start
 
Nothing unusual in hosts,

"ping could not find host google.com"
WF pings fine..

Dont even fuck around. Backup what you have to and reformat. PC's are like women, every now and then you need a fresh start
Weirdly I was thinking about that a few days ago, lol
 
Dont even fuck around. Backup what you have to and reformat. PC's are like women, every now and then you need a fresh start

What I would do. It's nice having a fresh install. Make a copy of what you reinstalled with your backup so you can just revert back to it when some shit like this happens again.
 
reformat.


in the future:

always have a clean image backup.

harden / sandbox all internet facing programs.

hips > avs
 
To completely purge RelevantKnowledge from your computer, you need to delete the files, folders, and Windows registry keys, and registry values associated with RelevantKnowledge. These files, folders, and registry keys are respectively listed in the Files, Folders, Registry Keys, and Registry Values sections on this page.
For instructions on deleting the RelevantKnowledge registry keys and registry values, see How to Remove RelevantKnowledge from the Windows Registry.


https://community.mcafee.com/thread/42313
 
  • Like
Reactions: ShadowCaster
Left over browser helper objects, plugins, proxy settings, broken winsock, hijacked windows files, registry hijacks..

If you don't know how to check for half of the above you're better of formatting. While you're doing that learn how to use clonezilla so when this happens again it will take a half hour to get a fresh PC image.

edit: before you go messing around in the registry as noted above, backup all your important stuff.
 
To completely purge RelevantKnowledge from your computer, you need to delete the files, folders, and Windows registry keys, and registry values associated with RelevantKnowledge. These files, folders, and registry keys are respectively listed in the Files, Folders, Registry Keys, and Registry Values sections on this page.
For instructions on deleting the RelevantKnowledge registry keys and registry values, see How to Remove RelevantKnowledge from the Windows Registry.


https://community.mcafee.com/thread/42313
Thanks!
Obviously RelevantKnowledge Removal Tool. Remove RelevantKnowledge Now isn't loading.. Can someone copypaste the list here?


I'm not an expert but maybe google.com is down?

or

perhaps you misspelled "google"? Maybe you wrote "gugle" or "gooogle"?

Please check it again and report back if you found my advise helpful.

Ah yes, probably CCarter broke Google again.
 
NVM, found all mentions of relevantknowledge in registry, deleted and now everything works :D woo!
 
Aliases of RelevantKnowledge (AKA):
[Kaspersky] AdWare.Win32.RK.j, Adware.Win32.RK.k, Trojan-PSW.Win32.LdPinch.atp, AdWare.Win32.RK.I, AdWare.Win32.RK.m, AdWare.Win32.RK.k
[McAfee] Proxy-OSS
[Other] Spyware.Marketscore, Win32/Crulket.A, Program:Win32/Marketscore.gen
How to Remove RelevantKnowledge from Your Computer
To completely purge RelevantKnowledge from your computer, you need to delete the files, folders, and Windows registry keys, and registry values associated with RelevantKnowledge. These files, folders, and registry keys are respectively listed in the Files, Folders, Registry Keys, and Registry Values sections on this page.
For instructions on deleting the RelevantKnowledge registry keys and registry values, see How to Remove RelevantKnowledge from the Windows Registry.
For instructions on deleting the RelevantKnowledge files and folders,
see How to Delete RelevantKnowledge Files (.exe, .dll, etc.)
How to Delete RelevantKnowledge Files (.exe, .dll, etc.)
The files and folders associated with RelevantKnowledge are listed in the Files and Folders sections on this page.
To delete the RelevantKnowledge files and folders:
Using your file explorer, browse to each file and folder listed in the Folders and Files sections.
Note: The paths use certain conventions such as [%PROGRAM_FILES%]. These conventions are explained here.
Select the file or folder and press SHIFT+Delete on the keyboard.
Click Yes in the confirm deletion dialog box.
IMPORTANT: If a file is locked (in use by some application), its deletion will fail (the Windows will display a corresponding message).You can delete such locked files with the RemoveOnReboot utility. To delete a locked file, right-click on the file, select Send To->Remove on Next Reboot on the menu, and restart your computer. You can install the RemoveOnReboot utility from here.
Files:
[%PROFILE_TEMP%]\CSM3D8E.tmp
[%PROFILE_TEMP%]\CSME3EB.tmp
[%PROFILE_TEMP%]\CSM13C0.tmp
[%PROGRAM_FILES%]\RelevantKnowledge\rlls.dll
[%PROGRAM_FILES%]\RelevantKnowledge\rlls64.dll
[%PROGRAM_FILES%]\RelevantKnowledge\rlvknlg64.exe
[%PROGRAM_FILES%]\RelevantKnowledge\rlvknlg.exe
[%PROFILE_TEMP%]\CSM9624.tmp
[%PROFILE_TEMP%]\~os9211.tmp\rlvknlg64.exe
[%PROFILE_TEMP%]\~os8CD4.tmp\rlvknlg.exe
[%PROFILE_TEMP%]\~os8CD4.tmp\rlvknlg64.exe
[%PROFILE_TEMP%]\CSM737F.tmp
[%PROFILE_TEMP%]\~os6F7A.tmp\rlvknlg.exe
[%PROFILE_TEMP%]\~os38ED.tmp\rlvknlg.exe
[%PROFILE_TEMP%]\~os38ED.tmp\rlvknlg64.exe
[%PROFILE_TEMP%]\CSMA276.tmp
[%PROFILE_TEMP%]\~os7CC3.tmp\rlvknlg.exe
[%PROFILE_TEMP%]\~os7CC3.tmp\rlvknlg64.exe
[%PROFILE_TEMP%]\~os70DE.tmp\rlvknlg.exe
[%PROFILE_TEMP%]\~os70DE.tmp\rlvknlg64.exe
[%PROFILE_TEMP%]\~os45F5.tmp\rlvknlg.exe
[%PROFILE_TEMP%]\~os45F5.tmp\rlvknlg64.exe
[%PROFILE_TEMP%]\~osA880.tmp\rlvknlg.exe
[%PROFILE_TEMP%]\~osA880.tmp\rlvknlg64.exe
[%PROFILE_TEMP%]\~os1E3A.tmp\rlvknlg.exe
[%PROFILE_TEMP%]\~os1E3A.tmp\rlvknlg64.exe
[%PROFILE_TEMP%]\CSM7030.tmp
[%PROGRAM_FILES%]\RelevantKnowledge\rlservice.exe
[%WINDOWS%]\Temp\~os1D02.tmp\rlls64.dll
[%WINDOWS%]\Temp\~os1D02.tmp\rlvknlg64.exe
[%WINDOWS%]\Temp\~os2F69.tmp\rlls64.dll
[%WINDOWS%]\Temp\~os6F75.tmp\rlls64.dll
[%WINDOWS%]\Temp\~os95DC.tmp\rlls64.dll
[%WINDOWS%]\Temp\~osC294.tmp\rlls64.dll
[%WINDOWS%]\Temp\~osC294.tmp\rlvknlg64.exe
[%WINDOWS%]\Temp\~osCC73.tmp\rlls64.dll
[%WINDOWS%]\Temp\~osE6F5.tmp\rlls64.dll
[%WINDOWS%]\Temp\~osE6F5.tmp\rlvknlg64.exe
[%WINDOWS%]\Temp\~osF22B.tmp\rlls64.dll
[%PROFILE_TEMP%]\~os3EE0.tmp\rlvknlg.exe
[%PROFILE_TEMP%]\~os3EE0.tmp\rlvknlg64.exe
[%PROFILE_TEMP%]\~os20FA.tmp\rlvknlg.exe
[%PROFILE_TEMP%]\~os20FA.tmp\rlvknlg64.exe
[%PROFILE_TEMP%]\~osD70D.tmp\rlvknlg.exe
[%PROFILE_TEMP%]\~osD70D.tmp\rlvknlg64.exe
[%PROFILE_TEMP%]\~os1140.tmp\rlvknlg.exe
[%PROFILE_TEMP%]\~os1140.tmp\rlvknlg64.exe
[%PROFILE_TEMP%]\~os674B.tmp\rlvknlg.exe
[%PROFILE_TEMP%]\~os674B.tmp\rlvknlg64.exe
[%PROFILE_TEMP%]\~os145B.tmp\rlvknlg.exe
[%PROFILE_TEMP%]\~os145B.tmp\rlvknlg64.exe
[%PROFILE_TEMP%]\~os21B3.tmp\rlvknlg.exe
[%PROFILE_TEMP%]\~os21B3.tmp\rlvknlg64.exe
[%PROFILE_TEMP%]\~os272F.tmp\rlvknlg.exe
[%PROFILE_TEMP%]\~os272F.tmp\rlvknlg64.exe
[%PROFILE_TEMP%]\~os2B45.tmp\rlvknlg.exe
[%PROFILE_TEMP%]\~os2B45.tmp\rlvknlg64.exe
[%PROFILE_TEMP%]\~os2BE1.tmp\rlvknlg.exe
[%PROFILE_TEMP%]\~os2BE1.tmp\rlvknlg64.exe
[%PROFILE_TEMP%]\~os2D77.tmp\rlvknlg.exe
[%PROFILE_TEMP%]\~os2D77.tmp\rlvknlg64.exe
[%PROFILE_TEMP%]\~os2E62.tmp\rlvknlg.exe
[%PROFILE_TEMP%]\~os2E62.tmp\rlvknlg64.exe
[%PROFILE_TEMP%]\~os3017.tmp\rlvknlg.exe
[%PROFILE_TEMP%]\~os3017.tmp\rlvknlg64.exe
[%PROFILE_TEMP%]\~os3A14.tmp\rlvknlg.exe
[%PROFILE_TEMP%]\~os3A14.tmp\rlvknlg64.exe
[%PROFILE_TEMP%]\~os416.tmp\rlvknlg.exe
[%PROFILE_TEMP%]\~os416.tmp\rlvknlg64.exe
[%PROFILE_TEMP%]\~os43E4.tmp\rlvknlg.exe
[%PROFILE_TEMP%]\~os43E4.tmp\rlvknlg64.exe
[%PROFILE_TEMP%]\~os4589.tmp\rlvknlg.exe
[%PROFILE_TEMP%]\~os4589.tmp\rlvknlg64.exe
[%PROFILE_TEMP%]\~os51E9.tmp\rlvknlg.exe
[%PROFILE_TEMP%]\~os51E9.tmp\rlvknlg64.exe
[%PROFILE_TEMP%]\~os5BC6.tmp\rlvknlg.exe
[%PROFILE_TEMP%]\~os5BC6.tmp\rlvknlg64.exe
[%PROFILE_TEMP%]\~os5C64.tmp\rlvknlg.exe
[%PROFILE_TEMP%]\~os5C64.tmp\rlvknlg64.exe
[%PROFILE_TEMP%]\~os5C83.tmp\rlvknlg.exe
[%PROFILE_TEMP%]\~os5C83.tmp\rlvknlg64.exe
[%PROFILE_TEMP%]\~os732E.tmp\rlvknlg.exe
[%PROFILE_TEMP%]\~os732E.tmp\rlvknlg64.exe
[%PROFILE_TEMP%]\~os75CD.tmp\rlvknlg.exe
[%PROFILE_TEMP%]\~os75CD.tmp\rlvknlg64.exe
[%PROFILE_TEMP%]\~os7A21.tmp\rlvknlg.exe
[%PROFILE_TEMP%]\~os7A21.tmp\rlvknlg64.exe
[%PROFILE_TEMP%]\~os7B28.tmp\rlvknlg.exe
[%PROFILE_TEMP%]\~os7B28.tmp\rlvknlg64.exe
[%PROFILE_TEMP%]\~os7DD7.tmp\rlvknlg.exe
[%PROFILE_TEMP%]\~os7DD7.tmp\rlvknlg64.exe
[%PROFILE_TEMP%]\~os7FCB.tmp\rlvknlg.exe
[%PROFILE_TEMP%]\~os7FCB.tmp\rlvknlg64.exe
[%PROFILE_TEMP%]\~os81AE.tmp\rlvknlg.exe
[%PROFILE_TEMP%]\~os81AE.tmp\rlvknlg64.exe
[%PROFILE_TEMP%]\~os84C9.tmp\rlvknlg.exe
[%PROFILE_TEMP%]\~os84C9.tmp\rlvknlg64.exe
[%PROFILE_TEMP%]\~os86EC.tmp\rlvknlg.exe
[%PROFILE_TEMP%]\~os86EC.tmp\rlvknlg64.exe
[%PROFILE_TEMP%]\~os8FD1.tmp\rlvknlg.exe
 
View all RelevantKnowledge files...
view mapping details
Folders:
[%PROGRAM_FILES%]\RelevantKnowledge
[%PROGRAM_FILES%][%COOKIES%][%COOKIES%]\RelevantKnowledge
[%PROGRAMS%]\RelevantKnowledge
view mapping details
Scan your File System for RelevantKnowledge
How to Remove RelevantKnowledge from the Windows Registry
The Windows registry stores important system information such as system preferences, user settings, and installed programs details as well as the information about the applications that are automatically run at start-up. Because of this, spyware, malware, and adware often store references to their own files in your Windows registry so that they can automatically launch every time you start up your computer.
To effectively remove RelevantKnowledge from your Windows registry, you must delete all the registry keys and values associated with RelevantKnowledge, which are listed in the Registry Keys and Registry Values sections on this page.
IMPORTANT: Because the registry is a core component of your Windows system, it is strongly recommended that you back up the registry before you begin deleting keys and values. For information about backing up the Windows registry, refer to the Registry Editor online help.
To remove the RelevantKnowledge registry keys and values:
On the Windows Start menu, click Run.
In the Open box, type regedit and click OK.
The Registry Editor window opens. This window consists of two panes. The left pane displays folders that represent the registry keys arranged in hierarchical order. The right one lists the registry values of the currently selected registry key.
To delete each registry key listed in the Registry Keys section, do the following:
Locate the key in the left pane of the Registry Editor window by sequentially expanding the folders according to the path indicated in the Registry Keys section. For example, if the path of a registry key is HKEY_LOCAL_MACHINE\software\FolderA\FolderB\KeyName1, sequentially expand the HKEY_LOCAL_MACHINE, software, FolderA, and FolderB folders.
Select the key name indicated at the end of the path (KeyName1 in the example above).
Right-click the key name and select Delete on the menu.
Click Yes in the Confirm Key Delete dialog box.
To delete each registry value listed in the Registry Values section, do the following:
Display the value in the right pane of the Registry Editor window by sequentially expanding the folders in the left pane according to the path indicated in the Registry Values section and selecting the specified key name. For example, if the path of a registry value is HKEY_LOCAL_MACHINE\software\FolderA\FolderB\KeyName2\,valueC=, sequentially expand the HKEY_LOCAL_MACHINE, software, FolderA, and FolderB folders and select the KeyName2 key to display the valueC value in the right pane.
In the right pane, select the value name indicated after a comma at the end of the path (valueC in the example above).
Right-click the value name and select Delete on the menu.
Click Yes in the Confirm Value Delete dialog box.
Registry Keys:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RelevantKnowledge
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\RelevantKnowledge
HKEY_LOCAL_MACHINE\software\classes\aboxctl.abox
HKEY_LOCAL_MACHINE\software\classes\clsid\{634e2191-2142-4c32-8a9a-d92032ca5f51}
HKEY_LOCAL_MACHINE\software\classes\clsid\{680c2b92-6fbf-446e-8b32-3bba73f1004d}
HKEY_LOCAL_MACHINE\software\classes\clsid\{7a834f35-3908-4fda-bdac-28eab89a0fb3}
HKEY_LOCAL_MACHINE\software\classes\clsid\{9e563445-b3b2-4a4c-850f-32073a5df93e}
HKEY_LOCAL_MACHINE\software\classes\clsid\{b50ee6c3-c280-47f5-b73f-d624a2980e5d}
HKEY_LOCAL_MACHINE\software\classes\clsid\{d4f6d70a-eca7-4d42-aaec-dad4e26889e1}
HKEY_LOCAL_MACHINE\software\classes\clsid\{e2a1da8f-fb3e-4e4a-8df6-bc54af4f2b7b}
HKEY_LOCAL_MACHINE\software\classes\interface\{083e2157-26b7-4a35-92df-11d886ed88ce}
HKEY_LOCAL_MACHINE\software\classes\interface\{1a23c59a-8c62-4860-a2fe-fc3940e8158c}
HKEY_LOCAL_MACHINE\software\classes\interface\{330849e8-b164-474c-9f09-0fe635d36c3c}
HKEY_LOCAL_MACHINE\software\classes\interface\{3923042b-2c35-4910-8711-4e0712b8e7c0}
HKEY_LOCAL_MACHINE\software\classes\interface\{48372215-470c-4108-b9b3-6de0ea8a6210}
HKEY_LOCAL_MACHINE\software\classes\interface\{77190304-5e62-46b2-a556-599361fb7155}
HKEY_LOCAL_MACHINE\software\classes\interface\{a368e682-63c3-4a6b-90df-d36f1f94b68f}
HKEY_LOCAL_MACHINE\software\classes\interface\{b538d830-1f02-4c5e-a881-a442e48e6310}
HKEY_LOCAL_MACHINE\software\classes\interface\{df329552-2e33-45dd-b529-f1a79c5c14d6}
HKEY_LOCAL_MACHINE\software\classes\interface\{fdf66bea-fec0-4fe5-b6f3-db416f6f7cb9}
HKEY_LOCAL_MACHINE\software\classes\typelib\{03f7cb5f-9e40-4b74-a3ed-7dbeaab01c6c}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{6a347828-bbc8-4344-b2a3-37b3b920dc62}
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\wineggdropshell
HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_regsnthelp
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\regsnthelp
Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\relevantknowledge, asynchronous=1
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\relevantknowledge, dllname=[%PROGRAM_FILES%]\RelevantKnowledge\rlls.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\relevantknowledge, impersonate=1
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\relevantknowledge, runline=[%PROGRAM_FILES%]\RelevantKnowledge\rlvknlg.exe -boot
 
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\relevantknowledge, startshell=StartShellEvent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, RelevantKnowledge=[%PROGRAM_FILES%]\relevantknowledge\rlvknlg.exe -boot
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, RelevantKnowledge=
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\relevantknowledge, dllname=[%SYSTEM%]\rlls.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\relevantknowledge, runline=[%SYSTEM%]\rlvknlg.exe -boot
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\relevantknowledge, dllname=[%PROGRAM_FILES%]\RelevantKnowledge\rlls.dll_old
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, RelevantKnowledge=[%SYSTEM%]\rlvknlg.exe -boot
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\relevantknowledge, dllname=[%PROGRAM_FILES%]\RelevantKnowledge\rlls(2).dll
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{5eafdf74-1830-41e8-8aaa-6babd746c193}, displayname=RelevantKnowledge
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{5eafdf74-1830-41e8-8aaa-6babd746c193}\config\ossproxy\settings, capabilities=1
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{5eafdf74-1830-41e8-8aaa-6babd746c193}\config\ossproxy\settings, extcapabilities=1
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{5eafdf74-1830-41e8-8aaa-6babd746c193}\config\ossproxy\settings, optionsbitmask=256
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{5eafdf74-1830-41e8-8aaa-6babd746c193}\config\ossproxy\settings, revertpath=[%SYSTEM%]\
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{5eafdf74-1830-41e8-8aaa-6babd746c193}\config\ossproxy\settings, sendcontentidtoserver=1
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{5eafdf74-1830-41e8-8aaa-6babd746c193}, uninstallstring=[%SYSTEM%]\mksc.exe -bootremove -uninst:RelevantKnowledge
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{5eafdf74-1830-41e8-8aaa-6babd746c193}\config\ossproxy\settings, installed=12678
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{5eafdf74-1830-41e8-8aaa-6babd746c193}\config\ossproxy\settings, name=x-ns1fMgMd80Iq0a,x-ns24gVf6ERNNNN
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{5eafdf74-1830-41e8-8aaa-6babd746c193}\config\ossproxy\settings, nextspeedtesttime=1106847555
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, RelevantKnowledge=[%WINDOWS%]\Xplorer.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{5eafdf74-1830-41e8-8aaa-6babd746c193}, uninstallstring=[%SYSTEM%]\rlvknlg.exe -bootremove -uninst:RelevantKnowledge
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{5eafdf74-1830-41e8-8aaa-6babd746c193}\config, ks_path=[%SYSTEM%]\rlls.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\relevantknowledge, dllname=
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{5eafdf74-1830-41e8-8aaa-6babd746c193}\config\ossproxy\settings, name=x-ns1LAxwztTtNhY,x-ns2H050NniLLLL
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{5eafdf74-1830-41e8-8aaa-6babd746c193}\config\ossproxy\settings, installed=12810
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{5eafdf74-1830-41e8-8aaa-6babd746c193}\config\ossproxy\settings, name=x-ns1azz8bcrKn0s,x-ns2pwW84DRLLLL
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{5eafdf74-1830-41e8-8aaa-6babd746c193}\config\ossproxy\settings, nextspeedtesttime=1141927452
HKEY_CURRENT_USER\software\microsoft\windows\shellnoroam\muicache, [%SYSTEM%]\rkupginstaller.exe=RelevantKnowledge Installer
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\relevantknowledge, runline=
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{5eafdf74-1830-41e8-8aaa-6babd746c193}\config\ossproxy\settings, installed=13121
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{5eafdf74-1830-41e8-8aaa-6babd746c193}\config\ossproxy\settings, name=x-ns1TAk3FbuINhq,x-ns2V790bt0F682
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{5eafdf74-1830-41e8-8aaa-6babd746c193}\config\ossproxy\settings, nextspeedtesttime=1140053638
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{5eafdf74-1830-41e8-8aaa-6babd746c193}\config\ossproxy\settings, optionsbitmask=0
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\relevantknowledge, asynchronous=1
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\relevantknowledge, dllname=[%SYSTEM%]\rlls.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\relevantknowledge, impersonate=1
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\relevantknowledge, runline=[%SYSTEM%]\rlvknlg.exe -boot
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\relevantknowledge, startshell=StartShellEvent
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce, del2067=cmd /c del [%SYSTEM%]\rkinst~1.exe
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce, del28961=cmd /c del [%SYSTEM%]\rkinst~1.exe
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce, del41=cmd /c del [%SYSTEM%]\rkupginstaller.exe
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce, del485=cmd /c del [%SYSTEM%]\rkinst~1.exe
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce, del8850=cmd /c del [%SYSTEM%]\rkinst~1.exe
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce, ossproxy=[%SYSTEM%]\rlvknlg.exe -bootinstall
HKEY_CURRENT_USER\software\microsoft\windows\shellnoroam\muicache, [%SYSTEM%]\rkupginstaller.exe=
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\relevantknowledge, asynchronous=
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\relevantknowledge, dllname=
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\relevantknowledge, impersonate=
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\relevantknowledge, runline=
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\relevantknowledge, startshell=
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{5eafdf74-1830-41e8-8aaa-6babd746c193}, displayname=
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{5eafdf74-1830-41e8-8aaa-6babd746c193}, uninstallstring=
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{5eafdf74-1830-41e8-8aaa-6babd746c193}\config, hk_path=
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{5eafdf74-1830-41e8-8aaa-6babd746c193}\config, ks_path=
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{5eafdf74-1830-41e8-8aaa-6babd746c193}\config, xf_path=
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{5eafdf74-1830-41e8-8aaa-6babd746c193}\config\ossproxy\settings, capabilities=
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{5eafdf74-1830-41e8-8aaa-6babd746c193}\config\ossproxy\settings, extcapabilities=
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{5eafdf74-1830-41e8-8aaa-6babd746c193}\config\ossproxy\settings, installed=
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{5eafdf74-1830-41e8-8aaa-6babd746c193}\config\ossproxy\settings, name=
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\
 
Thanks all of you! everything is ok now, to celebrate I'll post this OC

WVSzy8z.jpg
 
a little rape is ok, a little murder is just fine n' dandy, a little slavery never hurt no one!