[removed]
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: "C:\Program Files (x86)\SeaMonkey\seamonkey.exe" -requestPending -osint -url "%1")
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgcsrva.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Check Point Software Technologies Ltd.) C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgidsagenta.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgwdsvca.exe
(Comodo) C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe
(Maxthon) C:\Program Files (x86)\Maxthon App Store\1.1.0.10848\MaxthonAppstoreSvc.exe
(Maxthon) C:\Program Files (x86)\Maxthon\Modules\Service\Update\MaxthonUpdateSvc.exe
(Check Point Software Technologies Ltd.) C:\Program Files (x86)\CheckPoint\ZoneAlarm\ICM-Service.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgemca.exe
(Lenovo) C:\Windows\System32\LenovoUpdate.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Epic Privacy Browser) C:\Users\salty-san\AppData\Local\Epic Privacy Browser\Installer\EpicUpdate.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Power Software Ltd) C:\Program Files\PowerISO\PWRISOVM.EXE
(Nullsoft, Inc.) C:\Program Files (x86)\Winamp\winampa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
(Check Point Software Technologies Ltd.) C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgui.exe
(Virage Logic Corporation / Sonic Focus) C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Nullsoft, Inc.) C:\Program Files (x86)\Winamp\winamp.exe
(Comodo) C:\Program Files (x86)\Comodo\Dragon\dragon.exe
(Comodo) C:\Program Files (x86)\Comodo\Dragon\dragon.exe
(Comodo) C:\Program Files (x86)\Comodo\Dragon\dragon.exe
(Comodo) C:\Program Files (x86)\Comodo\Dragon\dragon.exe
(Comodo) C:\Program Files (x86)\Comodo\Dragon\dragon.exe
(Comodo) C:\Program Files (x86)\Comodo\Dragon\dragon.exe
(Comodo) C:\Program Files (x86)\Comodo\Dragon\dragon.exe
(Comodo) C:\Program Files (x86)\Comodo\Dragon\dragon.exe
(Comodo) C:\Program Files (x86)\Comodo\Dragon\dragon.exe
(Comodo) C:\Program Files (x86)\Comodo\Dragon\dragon.exe
(Comodo) C:\Program Files (x86)\Comodo\Dragon\dragon.exe
(Comodo) C:\Program Files (x86)\Comodo\Dragon\dragon.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office15\WINWORD.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office15\WINWORD.EXE
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [Eraser] => C:\Program Files\Eraser\Eraser.exe [1074088 2015-09-03] (The Eraser Project)
HKLM\…\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2587944 2010-12-31] (ELAN Microelectronics Corp.)
HKLM\…\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12850792 2011-09-05] (Realtek Semiconductor)
HKLM\…\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2277480 2011-08-16] (Realtek Semiconductor)
HKLM-x32\…\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2014-06-09] (Intel Corporation)
HKLM-x32\…\Run: [PWRISOVM.EXE] => C:\Program Files\PowerISO\PWRISOVM.EXE [408888 2015-07-23] (Power Software Ltd)
HKLM-x32\…\Run: [WinampAgent] => C:\Program Files (x86)\Winamp\winampa.exe [85600 2013-12-13] (Nullsoft, Inc.)
HKLM-x32\…\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [240400 2016-12-06] (AVG Technologies CZ, s.r.o.)
HKLM-x32\…\Run: [AVG_UI] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [240400 2016-12-06] (AVG Technologies CZ, s.r.o.)
HKLM-x32\…\Run: [ZoneAlarm] => C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe [144184 2016-09-07] (Check Point Software Technologies Ltd.)
HKLM-x32\…\Run: [SonicMasterTray] => C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe [984400 2010-07-09] (Virage Logic Corporation / Sonic Focus)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-384921765-1548902971-3406650631-1000\…\Run: [Epic Privacy Browser Installer] => C:\Users\salty-san\AppData\Local\Epic Privacy Browser\Installer\EpicUpdate.exe [509096 2016-02-28] (Epic Privacy Browser)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
BootExecute: autocheck autochk * PCloudBroom64.exe \systemroot\system32\BroomData.bitPCloudBroom64.exe \systemroot\system32\BroomData.bitPCloudBroom64.exe \systemroot\system32\BroomData.bitPCloudBroom64.exe \systemroot\system32\BroomData.bit
GroupPolicy: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{997EDB05-CBD3-4358-97F4-A47B17E7987F}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{BB2A1C55-6917-4C3A-8770-C53876319A70}: [DhcpNameServer] 192.168.0.1
Internet Explorer:
==================
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=msnhome
HKU\S-1-5-21-384921765-1548902971-3406650631-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
HKU\S-1-5-21-384921765-1548902971-3406650631-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://us.yahoo.com/?fr=fp-comodo&type;=19_25050030005_52.15.25.664_u_hp
SearchScopes: HKU\S-1-5-21-384921765-1548902971-3406650631-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://search.yahoo.com/yhs/search?hspart=comodo&hsimp;=yhs-com_chrome&type;=19_25050030005_52.15.25.664_u_ds&p;={searchTerms}
SearchScopes: HKU\S-1-5-21-384921765-1548902971-3406650631-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://search.yahoo.com/yhs/search?hspart=comodo&hsimp;=yhs-com_chrome&type;=19_25050030005_52.15.25.664_u_ds&p;={searchTerms}
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2012-10-01] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2012-10-01] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation)
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2012-10-01] (Microsoft Corporation)
FireFox:
========
FF DefaultProfile: oi0sxqu4.default
FF DefaultProfile: kl9fv1vt.default
FF ProfilePath: C:\Users\salty-san\AppData\Roaming\Mozilla\SeaMonkey\Profiles\oi0sxqu4.default [2017-02-22]
FF DefaultSearchEngine: Mozilla\SeaMonkey\Profiles\oi0sxqu4.default -> DuckDuckGo
FF Extension: (MEGA) - C:\Users\salty-san\AppData\Roaming\Mozilla\SeaMonkey\Profiles\oi0sxqu4.default\Extensions\[removed] [2016-07-06]
FF Extension: (DOM Inspector) - C:\Users\salty-san\AppData\Roaming\Mozilla\SeaMonkey\Profiles\oi0sxqu4.default\Extensions\[removed] [2016-04-27]
FF Extension: (ChatZilla) - C:\Users\salty-san\AppData\Roaming\Mozilla\SeaMonkey\Profiles\oi0sxqu4.default\Extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2} [2017-01-18]
FF ProfilePath: C:\Users\salty-san\AppData\Roaming\Mozilla\Firefox\Profiles\kl9fv1vt.default [2017-02-21]
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\kl9fv1vt.default -> DuckDuckGo
FF Session Restore: Mozilla\Firefox\Profiles\kl9fv1vt.default -> is enabled.
FF Extension: (SHA-1 deprecation staged rollout) - C:\Users\salty-san\AppData\Roaming\Mozilla\Firefox\Profiles\kl9fv1vt.default\features\{df78d30f-f10d-4e7d-844b-1d56ae0458fc}\[removed] [2017-02-17]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2012-10-01] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2017-01-18] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2017-01-18] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-05-03] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-384921765-1548902971-3406650631-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\salty-san\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2016-10-26] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-384921765-1548902971-3406650631-1000: @updates.epicbrowser.com/Epic Privacy Browser Installer;version=3 -> C:\Users\salty-san\AppData\Local\Epic Privacy Browser\Installer\1.3.27.13\npEpicUpdate3.dll [2016-02-28] (Epic Privacy Browser)
FF Plugin HKU\S-1-5-21-384921765-1548902971-3406650631-1000: @updates.epicbrowser.com/Epic Privacy Browser Installer;version=9 -> C:\Users\salty-san\AppData\Local\Epic Privacy Browser\Installer\1.3.27.13\npEpicUpdate3.dll [2016-02-28] (Epic Privacy Browser)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2012-10-01] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2015-12-18] (Adobe Systems Inc.)
Chrome:
=======
CHR DefaultSearchURL: Default -> hxxps://search.yahoo.com/yhs/search?p={searchTerms}&hspart;=comodo&hsimp;=yhs-ccs&type;=default
CHR DefaultSearchKeyword: Default -> Yahoo
CHR DefaultSuggestURL: Default -> hxxps://search.yahoo.com/sugg/ie?output=fxjson&command;={searchTerms}&nResults;=10
CHR Session Restore: Default -> is enabled.
CHR Profile: C:\Users\salty-san\AppData\Local\Google\Chrome\User Data\Default [2017-02-18]
CHR Extension: (Google Slides) - C:\Users\salty-san\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-11-07]
CHR Extension: (Google Docs) - C:\Users\salty-san\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-11-07]
CHR Extension: (Google Drive) - C:\Users\salty-san\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-07]
CHR Extension: (YouTube) - C:\Users\salty-san\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-07]
CHR Extension: (Google Search) - C:\Users\salty-san\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-07]
CHR Extension: (Google Sheets) - C:\Users\salty-san\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-11-07]
CHR Extension: (Google Docs Offline) - C:\Users\salty-san\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-17]
CHR Extension: (Yahoo Partner) - C:\Users\salty-san\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcjjaajflhellmcfcecojihhmdbjmmlm [2017-01-21]
CHR Extension: (Chrome Web Store Payments) - C:\Users\salty-san\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-01-21]
CHR Extension: (Gmail) - C:\Users\salty-san\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-11-07]
CHR Extension: (Chrome Media Router) - C:\Users\salty-san\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-01-28]
CHR HKU\S-1-5-21-384921765-1548902971-3406650631-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [hcjjaajflhellmcfcecojihhmdbjmmlm] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AvgAMPS; C:\Program Files (x86)\AVG\Av\avgamps.exe [971160 2017-01-09] (AVG Technologies CZ, s.r.o.)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\Av\avgidsagenta.exe [5337600 2017-01-09] (AVG Technologies CZ, s.r.o.)
R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1146128 2016-12-06] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\Av\avgwdsvca.exe [725976 2017-01-09] (AVG Technologies CZ, s.r.o.)
R2 DragonUpdater; C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe [2272904 2016-09-29] (Comodo)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [318568 2014-10-10] (Intel Corporation)
R3 LenovoUpdate; C:\Windows\System32\LenovoUpdate.exe [26608 2017-02-22] (Lenovo)
R2 MaxthonAppStoreSvc; C:\Program Files (x86)\Maxthon App Store\1.1.0.10848\MaxthonAppstoreSvc.exe [1867544 2015-08-11] (Maxthon)
R2 MaxthonUpdateSvc; C:\Program Files (x86)\Maxthon\Modules\Service\Update\MaxthonUpdateSvc.exe [2385832 2016-06-10] (Maxthon)
S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-03-01] (Riverbed Technology, Inc.)
R2 vsmon; C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe [4087568 2016-09-07] (Check Point Software Technologies Ltd.)
S3 wampapache64; c:\wamp64\bin\apache\apache2.4.23\bin\httpd.exe [29696 2016-07-01] (Apache Software Foundation) [File not signed]
S3 wampmysqld64; c:\wamp64\bin\mysql\mysql5.7.14\bin\mysqld.exe [39885824 2016-07-12] () [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2015-08-05] (Microsoft Corporation)
S3 ZAPrivacyService; C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZaPrivacyService.exe [114936 2016-08-09] (Check Point Software Technologies, Ltd.)
R2 ZoneAlarm ICM Service; C:\Program Files (x86)\CheckPoint\ZoneAlarm\ICM-Service.exe [794424 2016-09-07] (Check Point Software Technologies Ltd.)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [163072 2016-05-13] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [312576 2016-11-04] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [267008 2016-10-05] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [298240 2016-11-30] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [360736 2016-02-16] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [254208 2016-09-26] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [52992 2016-06-01] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [299264 2016-07-27] (AVG Technologies CZ, s.r.o.)
R0 avguniva; C:\Windows\System32\DRIVERS\avguniva.sys [77056 2016-06-20] (AVG Technologies CZ, s.r.o.)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
R2 npf; C:\Windows\system32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.)
S3 PSKMAD; C:\Windows\System32\DRIVERS\PSKMAD.sys [50320 2015-01-29] (Panda Security, S.L.)
S3 RSP2STOR; C:\Windows\System32\DRIVERS\RtsP2Stor.sys [294104 2014-12-10] (Realtek Semiconductor Corp.)
S3 RTWlanE; C:\Windows\System32\DRIVERS\rtwlane.sys [3513048 2015-03-23] (Realtek Semiconductor Corporation )
R1 VBoxNetAdp; C:\Windows\System32\DRIVERS\VBoxNetAdp6.sys [121824 2016-07-12] (Oracle Corporation)
R1 VBoxNetLwf; C:\Windows\System32\DRIVERS\VBoxNetLwf.sys [195424 2016-07-12] (Oracle Corporation)
S3 VBoxUSB; C:\Windows\System32\Drivers\VBoxUSB.sys [135824 2016-07-12] (Oracle Corporation)
R1 Vsdatant; C:\Windows\System32\DRIVERS\vsdatant.sys [462272 2016-09-07] (Check Point Software Technologies Ltd.)
S3 aswHdsKe; \??\C:\Windows\system32\drivers\aswHdsKe.sys [X]
U3 iswSvc; no ImagePath
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
U3 aswMBR; \??\C:\Users\SALTY-~1\AppData\Local\Temp\aswMBR.sys [X] <==== ATTENTION
U3 aswVmm; \??\C:\Users\SALTY-~1\AppData\Local\Temp\aswVmm.sys [X] <==== ATTENTION
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-02-22 06:38 - 2017-02-22 06:39 - 00019854 _____ C:\Users\salty-san\Desktop\FRST.txt
2017-02-22 06:37 - 2017-02-22 06:38 - 00000000 ____D C:\FRST
2017-02-22 06:36 - 2017-02-22 06:36 - 00002164 _____ C:\Users\salty-san\Desktop\aswMBR.txt
2017-02-22 06:36 - 2017-02-22 06:36 - 00000512 _____ C:\Users\salty-san\Desktop\MBR.dat
2017-02-21 18:17 - 2017-02-21 18:17 - 02422784 _____ (Farbar) C:\Users\salty-san\Desktop\FRST64.exe
2017-02-21 18:16 - 2017-02-21 18:16 - 05198336 _____ (AVAST Software) C:\Users\salty-san\Desktop\aswMBR.exe
2017-02-20 10:08 - 2017-02-20 10:08 - 00000000 _____ C:\Users\salty-san\Desktop\New Text Document.txt
2017-02-20 10:08 - 2017-02-20 10:08 - 00000000 _____ C:\Users\salty-san\Desktop\New Text Document (6).txt
2017-02-20 10:08 - 2017-02-20 10:08 - 00000000 _____ C:\Users\salty-san\Desktop\New Text Document (5).txt
2017-02-20 10:08 - 2017-02-20 10:08 - 00000000 _____ C:\Users\salty-san\Desktop\New Text Document (4).txt
2017-02-20 10:08 - 2017-02-20 10:08 - 00000000 _____ C:\Users\salty-san\Desktop\New Text Document (3).txt
2017-02-20 10:08 - 2017-02-20 10:08 - 00000000 _____ C:\Users\salty-san\Desktop\New Text Document (2).txt
2017-02-18 20:46 - 2017-02-18 20:46 - 00001613 _____ C:\Users\Public\Desktop\League of Legends.lnk
2017-02-18 20:46 - 2017-02-18 20:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends
2017-02-17 07:18 - 2017-02-17 07:18 - 00000000 ____D C:\Users\salty-san\.cache
2017-02-16 17:17 - 2017-02-16 17:17 - 00000000 ____D C:\Users\salty-san\AppData\Local\THQ
2017-02-15 06:46 - 2017-02-15 06:46 - 00000000 ____D C:\Users\salty-san\AppData\Roaming\GCCS
2017-02-01 16:28 - 2017-02-01 16:28 - 00001344 _____ C:\Users\Public\Desktop\Video Download Capture.lnk
2017-02-01 16:28 - 2017-02-01 16:28 - 00000000 ____D C:\Users\salty-san\Documents\Apowersoft
2017-02-01 16:28 - 2017-02-01 16:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apowersoft
2017-02-01 16:27 - 2017-02-17 07:14 - 00000000 ____D C:\Users\salty-san\AppData\Roaming\Apowersoft
2017-02-01 16:27 - 2017-02-01 16:27 - 00000000 ____D C:\Program Files (x86)\Apowersoft
2017-02-01 16:24 - 2017-02-01 16:25 - 00000000 ____D C:\Users\salty-san\AppData\Roaming\downyourtube
2017-02-01 16:24 - 2017-02-01 16:24 - 00001116 _____ C:\Users\Public\Desktop\YouTube Video Ripper.lnk
2017-02-01 16:24 - 2017-02-01 16:24 - 00000000 ____D C:\Users\salty-san\Documents\YoutubeVideos
2017-02-01 16:24 - 2017-02-01 16:24 - 00000000 ____D C:\Users\salty-san\AppData\Roaming\MSDLL
2017-02-01 16:24 - 2017-02-01 16:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YouTube Video Ripper
2017-02-01 16:24 - 2017-02-01 16:24 - 00000000 ____D C:\Program Files (x86)\YouTube Video Ripper
2017-01-30 09:53 - 2017-01-30 09:53 - 00000572 _____ C:\Users\Public\Desktop\Fraps.lnk
2017-01-30 09:53 - 2017-01-30 09:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fraps
2017-01-30 09:53 - 2017-01-30 09:53 - 00000000 ____D C:\Fraps
2017-01-30 09:03 - 2017-01-30 09:04 - 00000000 ____D C:\Users\salty-san\Documents\Visual Studio 2015
2017-01-30 09:03 - 2017-01-30 09:03 - 00000000 ____D C:\Users\salty-san\Documents\SQL Server Management Studio
2017-01-30 08:37 - 2017-01-30 08:37 - 00000000 ____D C:\Program Files (x86)\Microsoft Help Viewer
2017-01-30 08:36 - 2017-01-30 08:36 - 00000000 ____D C:\Program Files (x86)\Windows Kits
2017-01-30 08:33 - 2017-01-30 08:33 - 00000000 ____D C:\Program Files (x86)\Microsoft SDKs
2017-01-30 08:27 - 2017-01-30 09:22 - 00000000 ____D C:\Windows\SysWOW64\1033
2017-01-30 08:27 - 2017-01-30 09:22 - 00000000 ____D C:\Windows\system32\1033
2017-01-30 08:27 - 2017-01-30 08:42 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 14.0
2017-01-30 08:20 - 2017-01-30 08:20 - 00000000 ____D C:\ProgramData\VsTelemetry
2017-01-27 22:07 - 2017-01-28 11:44 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-01-25 15:21 - 2017-01-25 15:21 - 00000355 _____ C:\Users\salty-san\Desktop\Computer - Shortcut.lnk
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-02-22 06:00 - 2016-09-18 07:50 - 00000000 ____D C:\ProgramData\MFAData
2017-02-22 05:55 - 2009-07-14 06:45 - 00026352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-02-22 05:55 - 2009-07-14 06:45 - 00026352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-02-22 05:53 - 2016-07-18 00:05 - 00000410 _____ C:\Windows\Tasks\FreeFileViewerUpdateChecker.job
2017-02-22 05:47 - 2015-11-01 22:10 - 00097264 _____ (Lenovo (Beijing) Limited) C:\Windows\system32\LenovoCheck.exe
2017-02-22 05:47 - 2015-11-01 22:10 - 00026608 _____ (Lenovo) C:\Windows\system32\LenovoUpdate.exe
2017-02-22 05:47 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-02-22 00:03 - 2016-02-28 07:06 - 00000000 ____D C:\Users\salty-san\AppData\Local\Epic Privacy Browser
2017-02-21 21:10 - 2016-05-03 21:51 - 00003942 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{F51745E5-CA05-4A07-82FD-E977DEA96A94}
2017-02-21 20:51 - 2016-02-28 07:07 - 00002385 _____ C:\Users\salty-san\Desktop\Epic Privacy Browser.lnk
2017-02-21 18:02 - 2017-01-20 13:26 - 00000000 ____D C:\Users\salty-san\AppData\LocalLow\Mozilla
2017-02-21 14:02 - 2017-01-18 14:19 - 00003600 _____ C:\Windows\System32\Tasks\AVG EUpdate Task
2017-02-18 22:32 - 2009-07-14 07:13 - 00781298 _____ C:\Windows\system32\PerfStringBackup.INI
2017-02-18 22:32 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf
2017-02-18 20:48 - 2015-11-01 16:02 - 00000000 ____D C:\Users\salty-san\AppData\Roaming\Riot Games
2017-02-18 20:46 - 2015-11-01 16:09 - 00000000 ____D C:\Riot Games
2017-02-18 14:04 - 2015-11-05 13:53 - 00000000 ____D C:\Users\salty-san\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OCTGN
2017-02-18 01:03 - 2016-04-26 22:35 - 00000000 ____D C:\Program Files (x86)\Torchlight II
2017-02-18 00:28 - 2015-12-04 11:06 - 00000000 ____D C:\Users\salty-san\AppData\Roaming\vlc
2017-02-17 07:18 - 2015-11-01 12:21 - 00000000 ____D C:\Users\salty-san
2017-02-16 21:04 - 2016-02-05 01:35 - 00000000 ____D C:\Program Files (x86)\SeaMonkey
2017-02-16 21:03 - 2016-05-24 12:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Diablo II
2017-02-16 17:17 - 2016-04-04 13:23 - 00000000 ____D C:\Users\salty-san\AppData\Local\SKIDROW
2017-02-16 16:58 - 2016-01-03 22:27 - 00000000 ____D C:\Windows\SysWOW64\directx
2017-02-15 06:47 - 2016-02-18 20:02 - 00003846 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1455818550
2017-02-15 06:47 - 2016-01-08 19:03 - 00000000 ____D C:\Program Files (x86)\Opera
2017-02-04 17:49 - 2016-05-04 15:47 - 00000000 ____D C:\TheIt
2017-02-02 02:02 - 2015-11-07 23:30 - 00002195 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-02-02 02:02 - 2015-11-07 23:30 - 00002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-01-30 09:23 - 2016-02-28 04:57 - 00000000 ____D C:\ProgramData\Package Cache
2017-01-30 09:23 - 2016-01-07 03:45 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server
2017-01-30 09:22 - 2016-01-07 03:44 - 00000000 ____D C:\Program Files\Microsoft SQL Server
2017-01-30 09:18 - 2016-01-07 03:41 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2017-01-30 09:08 - 2016-02-01 04:31 - 00000000 ____D C:\Windows\system32\appmgmt
2017-01-30 09:02 - 2016-05-30 18:43 - 00007607 _____ C:\Users\salty-san\AppData\Local\Resmon.ResmonCfg
2017-01-30 08:44 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2017-01-30 08:34 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\MSBuild
2017-01-30 08:23 - 2015-08-10 04:03 - 00774004 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2017-01-29 19:02 - 2016-09-18 13:43 - 00000000 ____D C:\wamp64
2017-01-28 11:44 - 2015-11-01 14:45 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-01-28 09:55 - 2015-11-07 23:29 - 00000000 ____D C:\Users\salty-san\AppData\Local\Google
2017-01-24 00:18 - 2016-05-04 15:13 - 00000000 ____D C:\Users\salty-san\AppData\Roaming\SlimBrowser
==================== Files in the root of some directories =======
2016-03-13 13:21 - 2016-09-12 03:20 - 0000116 _____ () C:\Users\salty-san\AppData\Roaming\Camdata.ini
2016-03-13 13:21 - 2016-09-12 03:20 - 0000408 _____ () C:\Users\salty-san\AppData\Roaming\CamLayout.ini
2016-03-13 13:21 - 2016-09-12 03:20 - 0000408 _____ () C:\Users\salty-san\AppData\Roaming\CamShapes.ini
2016-03-13 13:21 - 2016-09-12 03:20 - 0004548 _____ () C:\Users\salty-san\AppData\Roaming\CamStudio.cfg
2016-03-13 13:21 - 2016-09-12 03:12 - 0000096 _____ () C:\Users\salty-san\AppData\Roaming\version2.xml
2016-05-30 18:43 - 2017-01-30 09:02 - 0007607 _____ () C:\Users\salty-san\AppData\Local\Resmon.ResmonCfg
Some files in TEMP:
====================
2016-07-18 00:02 - 2017-02-15 06:46 - 86211736 _____ (Avant Force) C:\Users\salty-san\AppData\Local\Temp\$avantbrowser$.update.exe
2017-01-18 22:12 - 2017-01-18 22:12 - 8974264 _____ (COMODO) C:\Users\salty-san\AppData\Local\Temp\ccav_installer.exe
2016-05-30 22:46 - 2016-05-30 22:46 - 0000000 _____ () C:\Users\salty-san\AppData\Local\Temp\GUR783A.exe
2016-06-25 13:42 - 2016-06-25 13:42 - 0720896 _____ (Indigo Rose Corporation) C:\Users\salty-san\AppData\Local\Temp\irsetup.exe
2016-09-18 13:08 - 2015-11-17 16:14 - 0158456 _____ (Panda Security S.L.) C:\Users\salty-san\AppData\Local\Temp\PCloudCleanerUpdater.exe
2017-02-17 07:46 - 2017-02-17 07:46 - 7652116 _____ () C:\Users\salty-san\AppData\Local\Temp\tmp8288.tmp.exe
2017-02-17 21:52 - 2017-02-17 21:52 - 7653020 _____ () C:\Users\salty-san\AppData\Local\Temp\tmpEDB3.tmp.exe
2017-02-18 13:55 - 2017-02-18 13:55 - 7653020 _____ () C:\Users\salty-san\AppData\Local\Temp\tmpF2E9.tmp.exe
2006-05-24 05:10 - 2006-05-24 05:10 - 0455600 ____R (Macrovision Corporation) C:\Users\salty-san\AppData\Local\Temp\_is9C10.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-02-16 09:45
==================== End of FRST.txt ============================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 19-02-2017
Ran by [removed] (22-02-2017 06:39:28)
Running from C:\Users\[removed]\Desktop
Windows 7 Ultimate Service Pack 1 (X64) (2015-11-01 10:20:21)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-384921765-1548902971-3406650631-500 - Administrator - Disabled)
Guest (S-1-5-21-384921765-1548902971-3406650631-501 - Limited - Disabled)
salty-san (S-1-5-21-384921765-1548902971-3406650631-1000 - Administrator - Enabled) => C:\Users\salty-san
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: AVG AntiVirus Free Edition (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG AntiVirus Free Edition (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}
FW: ZoneAlarm Free Firewall Firewall (Enabled) {1B8D532F-88B1-B2AD-ED22-AED92687A1D2}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
7-Zip 15.12 (x64) (HKLM\…\7-Zip) (Version: 15.12 - Igor Pavlov)
7-Zip 15.14 (x64 edition) (HKLM\…\{23170F69-40C1-2702-1514-000001000000}) (Version: 15.14.00.0 - Igor Pavlov)
Adobe Acrobat Reader DC (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.016.20039 - Adobe Systems Incorporated)
Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\…\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.12.5.0 - Asmedia Technology)
Avant Browser (remove only) (HKLM-x32\…\AvantBrowser) (Version: 12.5.0.0 - Avant Force)
AVG (HKLM\…\AvgZen) (Version: 1.113.2.50020 - AVG Technologies)
AVG (Version: 16.141.7998 - AVG Technologies) Hidden
AVG 2016 (Version: 16.0.4756 - AVG Technologies) Hidden
AVG Protection (HKLM\…\AVG) (Version: 2016.141.7998 - AVG Technologies)
AVG Zen (Version: 1.113.1 - AVG Technologies) Hidden
Avidemux 2.6 - 64 bits (HKLM-x32\…\Avidemux 2.6 - 64 bits (64-bit)) (Version: 2.6.12.160304 - )
CamStudio 2.7.4 (HKLM\…\{04B83666-3A62-452B-85D3-70F8117F2329}_is1) (Version: 2.7.4 - CamStudio Open Source)
Canon MP180 (HKLM\…\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP180) (Version: - )
Cheatbook Database 2016 (HKLM-x32\…\Cheatbook Database 2016) (Version: - )
Cisco EAP-FAST Module (HKLM-x32\…\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\…\{AF312B06-5C5C-468E-89B3-BE6DE2645722}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\…\{0A4EF0E6-A912-4CDE-A7F3-6E56E7C13A2F}) (Version: 1.1.6 - Cisco Systems, Inc.)
Command And Conquer Red Alert 2 Yuri's Revenge 1.001 (HKLM-x32\…\Command_And_Conquer_Yuri's_Revenge_1.001_MPI) (Version: - )
Comodo Dragon (HKLM-x32\…\Comodo Dragon) (Version: 52.15.25.664 - Comodo)
Corner Sunshine (HKLM-x32\…\Corner Sunshine) (Version: 1.0.4 - Nayun Online Network Technology (Shenzhen) Co.Ltd.)
DuelystLauncher (HKU\S-1-5-21-384921765-1548902971-3406650631-1000\…\launcher) (Version: 0.010 - Counterplay Games Inc.)
Dungeon Siege 2 (HKLM-x32\…\DungeonSiege2) (Version: - Microsoft)
Enigma Virtual Box v7.40 Build 20160125 (HKLM-x32\…\Enigma Virtual Box_is1) (Version: - The Enigma Protector Developers Team)
Epic Privacy Browser (HKU\S-1-5-21-384921765-1548902971-3406650631-1000\…\Epic) (Version: 55.0.2661.75 - Epic)
Eraser 6.2.0.2970 (HKLM\…\{58F37E51-2A83-49F3-9117-6005C63CF399}) (Version: 6.2.2970 - The Eraser Project)
ESET Online Scanner v3 (HKLM-x32\…\ESET Online Scanner) (Version: - )
ETDWare PS/2-X64 8.0.5.1_WHQL (HKLM\…\Elantech) (Version: 8.0.5.1 - ELAN Microelectronic Corp.)
FlashPeak SlimBrowser (HKLM-x32\…\SlimBrowser) (Version: 7.00.143 - FlashPeak Inc.)
FlashRip(Full Version) (HKLM-x32\…\FlashRip(Full Version)_is1) (Version: - )
FMW 1 (Version: 1.143.3 - AVG Technologies) Hidden
foobar2000 v1.3.9 (HKLM-x32\…\foobar2000) (Version: 1.3.9 - Peter Pawlowski)
Fraps (remove only) (HKLM-x32\…\Fraps) (Version: - )
Free File Viewer 2014 (HKLM-x32\…\FreeFileViewer_is1) (Version: 2014.2.16.0 - Bitberry Software) <==== ATTENTION
Free Virtual Keyboard 3.0.1.0 (HKLM-x32\…\{CA4F9519-1A83-4907-8651-F17073A0E1CE}_is1) (Version: 3.0 - Comfort Software Group)
FreeUndelete 2.1.36867.1 (HKLM-x32\…\{0F5ADA2F-C0B2-4AD6-8FF7-7DFA9D6B4CBA}) (Version: 2.1.36867.1 - Recoveronix)
Glary Undelete 5.0.1.19 (HKLM-x32\…\Glary Undelete) (Version: 5.0.1.19 - Glarysoft Ltd)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 56.0.2924.87 - Google Inc.)
Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden
Hero Editor V1.04 (HKLM-x32\…\ST6UNST #1) (Version: - )
Intel(R) Control Center (HKLM-x32\…\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2476 - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\…\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 3.0.0.33 - Intel Corporation)
IrfanView 64 (remove only) (HKLM\…\IrfanView64) (Version: 4.41 - Irfan Skiljan)
League of Legends (HKLM-x32\…\League of Legends 4.1.2) (Version: 4.1.2 - Riot Games)
League of Legends (x32 Version: 4.1.2 - Riot Games) Hidden
LinuxLive USB Creator (HKLM-x32\…\LinuxLive USB Creator) (Version: 2.9 - Thibaut Lauziere)
Maxthon App Store (HKLM-x32\…\Maxthon App Store 1.1.0.10848) (Version: 1.1.0.10848 - Maxthon, Inc.)
Maxthon Cloud Browser (HKLM-x32\…\Maxthon3) (Version: 4.9.2.1000 - Maxthon International Limited)
Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\…\{56E962F0-4FB0-3C67-88DB-9EAA6EEFC493}) (Version: 4.5.50710 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (ENU) (HKLM-x32\…\{D3517C62-68A5-37CF-92F7-93C029A89681}) (Version: 4.5.50932 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (HKLM-x32\…\{6A0C6700-EA93-372C-8871-DCCF13D160A4}) (Version: 4.5.50932 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 SDK (HKLM-x32\…\{19A5926D-66E1-46FC-854D-163AA10A52D3}) (Version: 4.5.51641 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (ENU) (HKLM-x32\…\{290FC320-2F5A-329E-8840-C4193BD7A9EE}) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (HKLM-x32\…\{B941AFB4-8851-33A1-9E72-0C33D463C41C}) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.6.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft Help Viewer 2.2 (HKLM-x32\…\Microsoft Help Viewer 2.2) (Version: 2.2.23107 - Microsoft Corporation)
Microsoft Office Professional Plus 2013 (HKLM\…\Office15.PROPLUS) (Version: 15.0.4420.1017 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\…\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\…\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\…\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23026 (HKLM-x32\…\{e46eca4f-393b-40df-9f49-076faf788d83}) (Version: 14.0.23026.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23506 (HKLM-x32\…\{23daf363-3020-4059-b3ae-dc4ad39fed19}) (Version: 14.0.23506.0 - Microsoft Corporation)
Microsoft Visual Studio 2015 Shell (Isolated) (HKLM-x32\…\{d2981c27-a434-4c9a-96c7-0209e97c4eac}) (Version: 14.0.23107.10 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2015 (HKLM-x32\…\{ab213ab7-4792-4c6f-a3fa-8485d06c3475}) (Version: 14.0.23829 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2015 Language Support (HKLM-x32\…\{353253a9-15a3-4727-b415-79b4e6be765e}) (Version: 14.0.23107.10 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\…\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation)
Mount and Blade (HKLM-x32\…\1207666893_is1) (Version: 2.0.0.4 - GOG.com)
Mozilla Firefox 51.0.1 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 51.0.1 (x86 en-US)) (Version: 51.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 51.0.1.6234 - Mozilla)
MPC-HC 1.7.10 (64-bit) (HKLM\…\{2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1) (Version: 1.7.10 - MPC-HC Team)
MyDefrag v4.3.1 (HKLM\…\MyDefrag v4.3.1_is1) (Version: 4.0.0.0 - J.C. Kessels)
One Finger Death Punch 1.0 (HKLM-x32\…\One Finger Death Punch 1.0) (Version: 1.0 - Cat-A-Cat)
Opera Stable 43.0.2442.806 (HKLM-x32\…\Opera 43.0.2442.806) (Version: 43.0.2442.806 - Opera Software)
Oracle VM VirtualBox 5.1.0 (HKLM\…\{0C801AA7-A02E-4DCF-BD09-0EACB11D9863}) (Version: 5.1.0 - Oracle Corporation)
Outils de vérification linguistique 2013 de Microsoft Office - Français (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Panda Cloud Cleaner (HKLM-x32\…\{92B2B132-C7F0-43DC-921A-4493C04F78A4}_is1) (Version: 1.1.9 - Panda Security)
PCSX2 - Playstation 2 Emulator (HKLM-x32\…\pcsx2) (Version: - )
PowerISO (HKLM-x32\…\PowerISO) (Version: 6.3 - Power Software Ltd)
Puran File Recovery 1.2 (HKLM\…\Puran File Recovery_is1) (Version: - Puran Software)
Qualcomm Atheros WiFi Driver Installation (HKLM-x32\…\{7D916FA5-DAE9-4A25-B089-655C70EAF607}) (Version: 9.2 - Qualcomm Atheros)
Realtek Card Reader (HKLM-x32\…\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.9600.29084 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.92.115.2015 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6454 - Realtek Semiconductor Corp.)
REALTEK Wireless LAN Driver (HKLM-x32\…\{9DAABC60-A5EF-41FF-B2B9-17329590CD5}) (Version: 1.00.0263 - REALTEK Semiconductor Corp.)
Revo Uninstaller 1.95 (HKLM-x32\…\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
RMPrepUSB (HKLM-x32\…\RMPrepUSB) (Version: - )
Roslyn Language Services - x86 (x32 Version: 14.0.23107 - Microsoft Corporation) Hidden
SeaMonkey 2.40 (x86 en-US) (HKLM-x32\…\SeaMonkey 2.40 (x86 en-US)) (Version: 2.40 - Mozilla)
Sonic Focus (HKLM-x32\…\{09BCB9CE-964B-4BDA-AE46-B5A0ABEF1D3F}) (Version: 1.0.0.4 - Synopsys )
SWF File Player (HKLM-x32\…\{6A86F611-906C-422D-B34A-103662CBC195}_is1) (Version: - swffileplayer.com)
The Binding of Isaac Rebirth 1.0 (HKLM-x32\…\The Binding of Isaac Rebirth 1.0) (Version: 1.0 - Games on Cat-A-Cat.Net)
The I of the Dragon (HKLM-x32\…\The I of the Dragon) (Version: 1.00 Ger / Eng - Deep Silver (Koch Media))
Time Travel Browser (HKLM-x32\…\Time Travel Browser) (Version: 1.0.0 - LuksSoftware)
Tweaking.com - Registry Backup (HKLM-x32\…\Tweaking.com - Registry Backup) (Version: 3.3.1 - Tweaking.com)
UndeleteMyFiles Pro (HKLM-x32\…\UndeleteMyFiles Pro_is1) (Version: - SeriousBit)
Unity Web Player (HKU\S-1-5-21-384921765-1548902971-3406650631-1000\…\UnityWebPlayer) (Version: 5.3.7f1 - Unity Technologies ApS)
Unknown File Handler (HKLM-x32\…\UFH_is1) (Version: 2015.12.29.0 - File.org)
Update for (KB2504637) (HKLM-x32\…\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation)
Video Download Capture V6.1.9 (HKLM-x32\…\{b3336f66-e079-4ff6-abdb-51e2fab781d5}_is1) (Version: 6.1.9 - APOWERSOFT LIMITED)
Visual Studio 2012 x64 Redistributables (HKLM\…\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\…\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VLC media player (HKLM-x32\…\VLC media player) (Version: 2.2.1 - VideoLAN)
Wampserver64 3.0.6 (HKLM\…\{wampserver64}_is1) (Version: 3.0.6 - Dominique Ottello aka Otomatic)
WebReaper v10 (HKLM-x32\…\WebReaper_is1) (Version: 10b - WebReaper.net)
Winamp (HKLM-x32\…\Winamp) (Version: 5.666 - Nullsoft, Inc)
WinPcap 4.1.3 (HKLM-x32\…\WinPcapInst) (Version: 4.1.0.2980 - Riverbed Technology, Inc.)
WinRAR 5.21 (64-bit) (HKLM\…\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH)
WinToUSB version 2.8 (HKLM\…\WinToUSB_is1) (Version: 2.8 - The EasyUEFI Development Team.)
YouTube Video Ripper 2.90 (HKLM-x32\…\YouTube Video Ripper_is1) (Version: - YoutubeGetting.com)
ZoneAlarm Firewall (x32 Version: 15.0.123.17051 - Check Point Software Technologies Ltd.) Hidden
ZoneAlarm Free Firewall (HKLM-x32\…\ZoneAlarm Free Firewall) (Version: 15.0.123.17051 - Check Point)
ZoneAlarm Security (x32 Version: 15.0.123.17051 - Check Point Software Technologies Ltd.) Hidden
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-384921765-1548902971-3406650631-1000_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\Windows\system32\igfxEM.exe (Intel Corporation)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0C38AE2D-18A0-48F0-B68B-E17B888171DD} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2016-06-09] (AVAST Software)
Task: {262460D0-CB2A-47F9-8D02-C6BEDBB491F1} - System32\Tasks\FreeFileViewerUpdateChecker => C:\Program Files (x86)\FreeFileViewer\FFVCheckForUpdates.exe [2015-12-30] (Bitberry Software) <==== ATTENTION
Task: {3261E316-AFD8-4063-A2CC-389DED3A5B4F} - System32\Tasks\AVG EUpdate Task => avgsetupx.exe
Task: {439ADCDD-9069-427F-BA0A-FDAB1AD5F6DA} - System32\Tasks\{229E9532-8EC8-4310-8097-EDD225B446C7} => pcalua.exe -a C:\Users\salty-san\Desktop\unetbootin-windows-613.exe -d C:\Users\salty-san\Desktop
Task: {46878AA7-1AA3-4113-BEB4-F039108AF39F} - System32\Tasks\MyDefrag v4.3.1 Daily => C:\Program Files\MyDefrag v4.3.1\Scripts\AutomaticDaily.MyD [2010-05-21] ()
Task: {72FCCA83-504A-4CE8-881D-4DD1C857395E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-11-07] (Google Inc.)
Task: {8B5FF665-AA34-4860-826D-DF6FF8EDB16D} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-12-19] (Adobe Systems Incorporated)
Task: {93E79D3A-7858-4800-8ECD-66F559719ECB} - System32\Tasks\Opera scheduled Autoupdate 1455818550 => C:\Program Files (x86)\Opera\launcher.exe [2017-02-06] (Opera Software)
Task: {A37295E0-5544-4BDE-AAB5-9F122D4E6FC7} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-11-07] (Google Inc.)
Task: {A819E346-DD87-49B7-8F95-90430AFBC631} - System32\Tasks\Maxthon Update => C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe [2016-04-15] (Maxthon International ltd.)
Task: {AC9B9D29-42CD-43AB-861C-6B9198CD59AB} - System32\Tasks\{838A64F0-1784-412C-A1A1-DAC18FC1209B} => C:\Program Files (x86)\Command And Conquer Red Alert 2 Yuri's Revenge\RA2MD.exe [2001-08-23] ()
Task: {C673A044-1E70-4CC0-85C5-F079F0C6596C} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation)
Task: {CA4A6E7F-6B77-414B-B595-97CDD1B0B259} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2012-10-01] (Microsoft Corporation)
Task: {CE4E4352-61BE-4AEA-B41F-74A61CC1BA25} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation)
Task: {E5DBA818-1F9F-4B43-AC1E-570F51A6036D} - System32\Tasks\MyDefrag v4.3.1 Monthly => C:\Program Files\MyDefrag v4.3.1\Scripts\AutomaticMonthly.MyD [2010-05-21] ()
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\FreeFileViewerUpdateChecker.job => C:\Program Files (x86)\FreeFileViewer\FFVCheckForUpdates.exe <==== ATTENTION
==================== Shortcuts =============================
(The entries could be listed to be restored or removed.)
ShortcutWithArgument: C:\Users\salty-san\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\395fbb84ca74fb25\Dragon.lnk -> C:\Program Files (x86)\Comodo\Dragon\dragon.exe (Comodo) -> –profile-directory=Default
==================== Loaded Modules (Whitelisted) ==============
2012-10-01 20:36 - 2012-10-01 20:36 - 06522480 _____ () C:\Program Files\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2015-11-01 12:28 - 2014-10-10 10:45 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2017-01-18 14:19 - 2017-01-18 14:18 - 48920064 _____ () C:\Program Files (x86)\AVG\UiDll\2623\libcef.dll
2013-12-13 04:47 - 2013-12-13 04:47 - 00333824 _____ () C:\Program Files (x86)\Winamp\Plugins\freeform\wacs\freetype\freetype.wac
2016-09-29 15:26 - 2016-09-29 15:26 - 02216056 _____ () C:\Program Files (x86)\Comodo\Dragon\libglesv2.dll
2016-09-29 15:26 - 2016-09-29 15:26 - 00092272 _____ () C:\Program Files (x86)\Comodo\Dragon\libegl.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\Users\salty-san\Desktop\rufus-2.4.exe:xdg.origin.url [45]
AlternateDataStreams: C:\Users\salty-san\Desktop\rufus-2.4.exe:xdg.referrer.url [22]
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vsmon => ""="Service"
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 04:34 - 2016-07-18 08:56 - 00000035 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-384921765-1548902971-3406650631-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\salty-san\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: Media is not connected to internet.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is disabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{01DD5918-283F-4F3C-AC26-AF593412DF9F}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{4C05ACD7-2D66-4535-9966-F85B04F67719}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{508DDC13-5096-41A1-BE2C-A24C77183C13}] => (Block) D:\WASTELAND!\Wasteland 2 Directors Cut\Build\WL2.exe
FirewallRules: [TCP Query User{EEB53623-0283-483F-B645-04DD48C46786}C:\users\salty-san\documents\octgn\octgn\octgn.exe] => (Allow) C:\users\salty-san\documents\octgn\octgn\octgn.exe
FirewallRules: [UDP Query User{14C2698F-42A4-41BB-9169-2211FDC0ECB1}C:\users\salty-san\documents\octgn\octgn\octgn.exe] => (Allow) C:\users\salty-san\documents\octgn\octgn\octgn.exe
FirewallRules: [TCP Query User{DF6BC443-CABE-4E5A-9F0E-F4C4A78535F6}C:\users\salty-san\documents\octgn\octgn\octgn.exe] => (Allow) C:\users\salty-san\documents\octgn\octgn\octgn.exe
FirewallRules: [UDP Query User{0D9DECF9-7EE8-4932-81B6-5AA519CD2957}C:\users\salty-san\documents\octgn\octgn\octgn.exe] => (Allow) C:\users\salty-san\documents\octgn\octgn\octgn.exe
FirewallRules: [{F89C0384-F502-44A5-B00A-9826C8B9E172}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{BB9DFD0F-5CC0-4A92-A4C5-E4DE9031F0C6}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{19FBF323-28DA-4563-9196-790954D5F72D}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{5D4FF2EB-07A6-4F96-AFF0-58616E255410}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{95B66243-C6D0-4B85-90F6-547B69CE822E}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{BCFAED00-B5EE-4558-AFC6-E54BC68D9562}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [TCP Query User{B247EA9C-0A1B-4E95-8AC0-562403FC4950}C:\users\salty-san\documents\octgn\octgn\octgn.online.standaloneserver.exe] => (Allow) C:\users\salty-san\documents\octgn\octgn\octgn.online.standaloneserver.exe
FirewallRules: [UDP Query User{260782A1-34CD-4BA2-9F89-72C24BA3BF7B}C:\users\salty-san\documents\octgn\octgn\octgn.online.standaloneserver.exe] => (Allow) C:\users\salty-san\documents\octgn\octgn\octgn.online.standaloneserver.exe
FirewallRules: [TCP Query User{AD90B0F5-5A10-4C62-A7A3-3CBA144F4692}D:\playboard\call of duty 2 full game mp - sp -=aviara=-\call of duty 2\cod2mp_s.exe] => (Block) D:\playboard\call of duty 2 full game mp - sp -=aviara=-\call of duty 2\cod2mp_s.exe
FirewallRules: [UDP Query User{E45AB548-5CA2-49FC-BCAA-420157AA80F9}D:\playboard\call of duty 2 full game mp - sp -=aviara=-\call of duty 2\cod2mp_s.exe] => (Block) D:\playboard\call of duty 2 full game mp - sp -=aviara=-\call of duty 2\cod2mp_s.exe
FirewallRules: [{9D79CD9D-1138-4471-9107-72DC3CDE88B1}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{3BFEB175-5043-44EA-B2C6-7D52F51741EE}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{2E2BBFA3-FB0B-479D-85AD-963E99B02215}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{2BEE2144-B70C-4420-BC9E-5A25585FF686}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{05C545A5-8C9C-41C3-B89E-E65D6D8A0192}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
FirewallRules: [{E91111AF-B2E6-4408-A180-D898C8699190}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
FirewallRules: [TCP Query User{69F0FD99-0EC7-4032-A241-6D327E2A6239}C:\users\salty-san\documents\octgn\octgn\octgn.online.standaloneserver.exe] => (Allow) C:\users\salty-san\documents\octgn\octgn\octgn.online.standaloneserver.exe
FirewallRules: [UDP Query User{68EFF557-0A01-48DF-ADF5-F95A6BCF5C2F}C:\users\salty-san\documents\octgn\octgn\octgn.online.standaloneserver.exe] => (Allow) C:\users\salty-san\documents\octgn\octgn\octgn.online.standaloneserver.exe
FirewallRules: [TCP Query User{78AF15E1-CC17-4FE7-BDCE-5427620D4861}D:\zergoth!\the minks!\portable\mirc\mirc.exe] => (Allow) D:\zergoth!\the minks!\portable\mirc\mirc.exe
FirewallRules: [UDP Query User{36A39718-5949-41EE-93B6-6318ACE5812B}D:\zergoth!\the minks!\portable\mirc\mirc.exe] => (Allow) D:\zergoth!\the minks!\portable\mirc\mirc.exe
FirewallRules: [TCP Query User{4CDB7BB9-A122-4B17-BA93-EF671730BED0}D:\playboard\duel masters civilization!\duelmasters\duelmasters.exe] => (Allow) D:\playboard\duel masters civilization!\duelmasters\duelmasters.exe
FirewallRules: [UDP Query User{9EDB7F0F-B21C-4096-9A73-82A834AABA6D}D:\playboard\duel masters civilization!\duelmasters\duelmasters.exe] => (Allow) D:\playboard\duel masters civilization!\duelmasters\duelmasters.exe
FirewallRules: [{4C549C43-8769-43DD-9C4C-D832FAD6EA76}] => (Block) D:\playboard\duel masters civilization!\duelmasters\duelmasters.exe
FirewallRules: [{EAC4EBEF-0920-44DC-BE2C-0C1DE5FD23B7}] => (Block) D:\playboard\duel masters civilization!\duelmasters\duelmasters.exe
FirewallRules: [{BF29B07C-1C68-4FFD-A4D3-2A5E6A990D3D}] => (Allow) C:\Program Files (x86)\Microsoft Games\Dungeon Siege 2\DungeonSiege2.exe
FirewallRules: [{CA9D005B-CFBA-4074-8BAC-879957D3F610}] => (Allow) C:\Program Files (x86)\Microsoft Games\Dungeon Siege 2\DungeonSiege2.exe
FirewallRules: [{7EC18199-F2F4-4E81-808E-B4AF8C069627}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe
FirewallRules: [{4051053A-8CCA-4822-B6DF-EB780F910B61}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe
FirewallRules: [{D42F9D68-6F43-4682-B3ED-C973FE575538}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe
FirewallRules: [{2478CB98-BB64-4FA9-842C-5FC7598BD6DB}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe
FirewallRules: [{1EE51A2D-F50E-4993-A34B-65E5CE39866A}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe
FirewallRules: [{F5DD2F8C-BC93-471C-9078-4D647E90DCE4}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe
FirewallRules: [{616F09ED-6DEE-4DB2-B541-38366AAC8A1C}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe
FirewallRules: [{C3F233A1-A686-4A64-9179-318E8C697C57}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe
FirewallRules: [TCP Query User{947EFFAD-F69E-4185-AC31-C5B988C9D459}C:\gog games\impossible creatures\ic.exe] => (Allow) C:\gog games\impossible creatures\ic.exe
FirewallRules: [UDP Query User{350CBCCF-86C4-4DD0-9F00-93692E8138D8}C:\gog games\impossible creatures\ic.exe] => (Allow) C:\gog games\impossible creatures\ic.exe
FirewallRules: [TCP Query User{6D711751-94CC-4740-8736-2AC7042FB237}C:\program files (x86)\command and conquer red alert 2 yuri's revenge\gamemd.exe] => (Allow) C:\program files (x86)\command and conquer red alert 2 yuri's revenge\gamemd.exe
FirewallRules: [UDP Query User{E7B29111-52F7-477F-B24A-5224F4BE11E8}C:\program files (x86)\command and conquer red alert 2 yuri's revenge\gamemd.exe] => (Allow) C:\program files (x86)\command and conquer red alert 2 yuri's revenge\gamemd.exe
FirewallRules: [{25D680AA-59BC-4144-B122-781152AA6F44}] => (Allow) C:\Program Files (x86)\FreeFileViewer\FFVCheckForUpdates.exe
FirewallRules: [{6C4DF875-2630-426C-BE46-04D1E8A0F790}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{23217DC7-B15A-47EE-8489-28C05A8C9AB4}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{01236CE6-09FC-4F0A-A6C6-B7B8A8073E42}] => (Allow) C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe
FirewallRules: [{116FBB49-70D1-4D4E-A2CA-F8C18B04A33A}] => (Allow) C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe
FirewallRules: [{359AE9CA-9C0E-42CF-8D17-1999E507C96E}] => (Allow) C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe
FirewallRules: [{68CE8494-D98E-4431-9953-BEBE55599E4A}] => (Allow) C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe
FirewallRules: [{1CCC1B63-63BF-4D31-A03F-AA4630226230}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe
FirewallRules: [{80308818-6EDA-49EB-A9C3-3BA751BEA563}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe
FirewallRules: [{8D5F0328-1024-4223-A739-E31AAE45A05C}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe
FirewallRules: [{DE514DEA-1907-474A-A160-58949824A816}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe
FirewallRules: [{2CCDB899-B593-4254-A367-3F8E8BDFDAC4}] => (Allow) C:\Program Files (x86)\Opera\42.0.2393.517\opera.exe
FirewallRules: [{DA98B383-67C4-4D56-8BCA-F7FEF6A48658}] => (Allow) C:\Program Files (x86)\Apowersoft\Video Download Capture 6\Video Download Capture 6.exe
FirewallRules: [{549D9961-DCE1-4121-B724-86A0046FA3B7}] => (Allow) C:\Program Files (x86)\Apowersoft\Video Download Capture 6\Video Download Capture 6.exe
FirewallRules: [{72B54C1B-5998-42BF-BA2C-0E6430500A23}] => (Allow) C:\Program Files (x86)\Apowersoft\Video Download Capture 6\rtmpsrv.exe
FirewallRules: [{3D9C3178-06FA-4B8D-97E3-CC7E767D31E9}] => (Allow) C:\Program Files (x86)\Apowersoft\Video Download Capture 6\rtmpsrv.exe
FirewallRules: [{88C7A1F1-5091-4347-A3D0-1145B4157489}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{24F62666-D1FE-4F86-832B-C95EC9679FAF}] => (Allow) C:\Program Files (x86)\Opera\43.0.2442.806\opera.exe
==================== Restore Points =========================
20-02-2017 02:13:46 Scheduled Checkpoint
==================== Faulty Device Manager Devices =============
Name: SM Bus Controller
Description: SM Bus Controller
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (02/22/2017 06:05:45 AM) (Source: lupdate) (EventID: 0) (User: )
Description: Event-ID 0
Error: (02/22/2017 06:05:44 AM) (Source: lupdate) (EventID: 0) (User: )
Description: Event-ID 0
Error: (02/22/2017 05:59:59 AM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
Description: Event-ID 0
Error: (02/22/2017 05:50:56 AM) (Source: lupdate) (EventID: 0) (User: )
Description: Event-ID 0
Error: (02/22/2017 05:48:43 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Error: (02/21/2017 08:42:28 PM) (Source: lupdate) (EventID: 0) (User: )
Description: Event-ID 0
Error: (02/21/2017 08:42:27 PM) (Source: lupdate) (EventID: 0) (User: )
Description: Event-ID 0
Error: (02/21/2017 04:44:03 PM) (Source: lupdate) (EventID: 0) (User: )
Description: Event-ID 0
Error: (02/21/2017 04:44:02 PM) (Source: lupdate) (EventID: 0) (User: )
Description: Event-ID 0
Error: (02/21/2017 02:01:06 PM) (Source: MsiInstaller) (EventID: 1024) (User: NT AUTHORITY)
Description: Product: Adobe Acrobat Reader DC - Update '{AC76BA86-7AD7-0000-2550-AC0F174E5800}' could not be installed. Error code 1646. Windows Installer can create logs to help troubleshoot issues with installing software packages. Use the following link for instructions on turning on logging support:
http://go.microsoft.com/fwlink/?LinkId=23127
System errors:
=============
Error: (02/22/2017 05:47:53 AM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: The ScRegSetValueExW call failed for FailureActions with the following error:
Access is denied.
Error: (02/22/2017 05:47:35 AM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: The ScRegSetValueExW call failed for FailureActions with the following error:
Access is denied.
Error: (02/22/2017 12:04:19 AM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: The ScRegSetValueExW call failed for FailureActions with the following error:
Access is denied.
Error: (02/21/2017 09:41:37 AM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: The ScRegSetValueExW call failed for FailureActions with the following error:
Access is denied.
Error: (02/21/2017 09:41:23 AM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: The ScRegSetValueExW call failed for FailureActions with the following error:
Access is denied.
Error: (02/20/2017 09:48:00 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: The server {078AEF33-C48A-49F7-AFF3-A0EE810BFE7C} did not register with DCOM within the required timeout.
Error: (02/20/2017 09:47:57 PM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: The ScRegSetValueExW call failed for FailureActions with the following error:
Access is denied.
Error: (02/20/2017 10:02:03 AM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: The ScRegSetValueExW call failed for FailureActions with the following error:
Access is denied.
Error: (02/20/2017 10:01:49 AM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: The ScRegSetValueExW call failed for FailureActions with the following error:
Access is denied.
Error: (02/20/2017 03:31:59 AM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: The ScRegSetValueExW call failed for FailureActions with the following error:
Access is denied.
CodeIntegrity:
===================================
Date: 2016-01-14 19:28:38.733
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\AVG\AVG PC TuneUp\avgdumpx.exe because the set of per-page image hashes could not be found on the system.
Date: 2016-01-14 19:28:38.591
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\AVG\AVG PC TuneUp\avgdumpx.exe because the set of per-page image hashes could not be found on the system.
Date: 2016-01-14 19:28:38.368
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\AVG\AVG PC TuneUp\avgdumpa.exe because the set of per-page image hashes could not be found on the system.
Date: 2016-01-14 19:28:38.201
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\AVG\AVG PC TuneUp\avgdumpa.exe because the set of per-page image hashes could not be found on the system.
Date: 2015-12-17 10:29:48.300
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\AVG\AVG PC TuneUp\avgdumpx.exe because the set of per-page image hashes could not be found on the system.
Date: 2015-12-17 10:29:48.191
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\AVG\AVG PC TuneUp\avgdumpx.exe because the set of per-page image hashes could not be found on the system.
Date: 2015-12-17 10:29:48.082
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\AVG\AVG PC TuneUp\avgdumpx.exe because the set of per-page image hashes could not be found on the system.
Date: 2015-12-16 03:51:45.976
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\AVG\AVG PC TuneUp\avgdumpx.exe because the set of per-page image hashes could not be found on the system.
Date: 2015-12-16 03:51:45.867
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\AVG\AVG PC TuneUp\avgdumpx.exe because the set of per-page image hashes could not be found on the system.
Date: 2015-12-16 03:51:45.773
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\AVG\AVG PC TuneUp\avgdumpx.exe because the set of per-page image hashes could not be found on the system.
==================== Memory info ===========================
Processor: Intel(R) Celeron(R) CPU B815 @ 1.60GHz
Percentage of memory in use: 64%
Total physical RAM: 4000.13 MB
Available physical RAM: 1400.27 MB
Total Virtual: 7998.45 MB
Available Virtual: 5245.13 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:122.07 GB) (Free:30.01 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (East) (Fixed) (Total:343.69 GB) (Free:292.7 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: D9FA2484)
Partition 1: (Not Active) - (Size=343.7 GB) - (Type=07 NTFS)
Partition 2: (Active) - (Size=122.1 GB) - (Type=07 NTFS)
==================== End of Addition.txt ============================