I wanted to do a big cleanup before I start switching to a new machine and using this one for fewer things and therefore safer, but I had to try out various software for stuff, especially lately, so now it just feels very slowed down, cluttered and even starts up harder plus seems to take up more CPU.
One mobile stupid software came with a "cleaner" that keeps giving me popups and won't uninstall. There were several Blue Screens lately too ever since on this video recording software I had to set its audio paramaters. Something weird happened last uninstall and ruined my audio driver and now I have no sound from anywhere. Tried updates and manual reinstall and just doesn't work. Says in device manager that registry key for it is missing or corrupted.
Even now as I ran aswMBR it crashed/restarted 2 times, one that I witnessed with the blue screen. So in any case here are the logs…
21:09:21.510 The log file has been saved successfully to "C:\Users\salty-san\Desktop\mjnnjn.txt"
21:14:33.121 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
21:14:33.370 Disk 0 Partition 1 00 07 HPFS/NTFS NTFS 351940 MB offset 256000000
21:14:33.401 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 124999 MB offset 2048
21:15:26.052 ntoskrnl.exe CLASSPNP.SYS disk.sys avgSP.sys ACPI.sys iaStor.sys hal.dll
21:15:26.052 3 avgSP.sys[fffff8800428e1d2] -> nt!IofCallDriver -> [0xfffffa8004762480]
21:15:26.052 5 ACPI.sys[fffff88000e0b7a1] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8004789050]
21:49:16.926 Disk 0 MBR has been saved successfully to "C:\Users\salty-san\Desktop\MBR.dat"
21:49:16.926 The log file has been saved successfully to "C:\Users\salty-san\Desktop\aswMBR.txt"
ADDITION is next and the longest.
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 09-08-2017
Ran by [removed] (10-08-2017 21:02:41)
Running from C:\Users\[removed]\Desktop
Windows 7 Ultimate Service Pack 1 (X64) (2015-11-01 10:20:21)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-384921765-1548902971-3406650631-500 - Administrator - Disabled)
Guest (S-1-5-21-384921765-1548902971-3406650631-501 - Limited - Disabled)
salty-san (S-1-5-21-384921765-1548902971-3406650631-1000 - Administrator - Enabled) => C:\Users\salty-san
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: AVG Antivirus (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG Antivirus (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}
FW: ZoneAlarm Free Firewall Firewall (Enabled) {1B8D532F-88B1-B2AD-ED22-AED92687A1D2}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
7-Zip 15.12 (x64) (HKLM\…\7-Zip) (Version: 15.12 - Igor Pavlov)
7-Zip 15.14 (x64 edition) (HKLM\…\{23170F69-40C1-2702-1514-000001000000}) (Version: 15.14.00.0 - Igor Pavlov)
Adobe Acrobat Reader DC (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.016.20039 - Adobe Systems Incorporated)
AirDroid 3.4.1.0 (HKLM-x32\…\AirDroid) (Version: 3.4.1.0 - Sand Studio)
Apowersoft Online Launcher version 1.6.0 (HKLM-x32\…\{20BF67A8-D81A-4489-8225-FABAA0896E2D}_is1) (Version: 1.6.0 - APOWERSOFT LIMITED)
Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\…\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.12.5.0 - Asmedia Technology)
Avant Browser (remove only) (HKLM-x32\…\AvantBrowser) (Version: 12.5.0.0 - Avant Force)
AVG (HKLM\…\{434FBA38-0562-4F98-9436-4B45C0C0EF0B}) (Version: 1.201.2 - AVG Technologies) Hidden
AVG AntiVirus FREE (HKLM-x32\…\AVG Antivirus) (Version: 17.5.3022 - AVG Technologies)
Avidemux 2.6 - 64 bits (HKLM-x32\…\Avidemux 2.6 - 64 bits (64-bit)) (Version: 2.6.12.160304 - )
Battlefield Vietnam(TM) (HKLM-x32\…\{E35B3C63-E958-4E31-A178-95D22024109A}) (Version: - )
BlazBlue - Calamity Trigger (HKLM-x32\…\GOGPACKBLAZBLUECT_is1) (Version: 2.0.0.3 - GOG.com)
BlazBlue: Chronophantasma Extend (HKLM\…\YmxhemJsdWVjaHJvbm9waGFudGFzbWFleHRlbmQ_is1) (Version: 1 - )
BlazBlue: Continuum Shift Extend (HKLM-x32\…\BlazBlue: Continuum Shift Extend_is1) (Version: - H2 Interactive Co., Ltd.)
CamStudio 2.7.4 (HKLM\…\{04B83666-3A62-452B-85D3-70F8117F2329}_is1) (Version: 2.7.4 - CamStudio Open Source)
Canon MP180 (HKLM\…\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP180) (Version: - )
Cheatbook Database 2016 (HKLM-x32\…\Cheatbook Database 2016) (Version: - )
Cisco EAP-FAST Module (HKLM-x32\…\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\…\{AF312B06-5C5C-468E-89B3-BE6DE2645722}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\…\{0A4EF0E6-A912-4CDE-A7F3-6E56E7C13A2F}) (Version: 1.1.6 - Cisco Systems, Inc.)
Command And Conquer Red Alert 2 Yuri's Revenge 1.001 (HKLM-x32\…\Command_And_Conquer_Yuri's_Revenge_1.001_MPI) (Version: - )
Comodo Dragon (HKLM-x32\…\Comodo Dragon) (Version: 52.15.25.664 - Comodo)
DuelystLauncher (HKU\S-1-5-21-384921765-1548902971-3406650631-1000\…\launcher) (Version: 0.010 - Counterplay Games Inc.)
Dynasty Warriors 4 Hyper (HKU\S-1-5-21-384921765-1548902971-3406650631-1000\…\{DBFF7A38-F460-419A-A2E7-2D55BD2D9AD4}) (Version: - )
Enigma Virtual Box v7.40 Build 20160125 (HKLM-x32\…\Enigma Virtual Box_is1) (Version: - The Enigma Protector Developers Team)
Epic Privacy Browser (HKU\S-1-5-21-384921765-1548902971-3406650631-1000\…\Epic) (Version: 58.0.3300.190 - Epic)
Eraser 6.2.0.2970 (HKLM\…\{58F37E51-2A83-49F3-9117-6005C63CF399}) (Version: 6.2.2970 - The Eraser Project)
ESET Online Scanner v3 (HKLM-x32\…\ESET Online Scanner) (Version: - )
ETDWare PS/2-X64 8.0.5.1_WHQL (HKLM\…\Elantech) (Version: 8.0.5.1 - ELAN Microelectronic Corp.)
Ezvid (HKLM-x32\…\{F96D619D-99D6-4C9C-A393-0CD22DE1CA66}_is1) (Version: 1.004 - Ezvid, inc.)
FlashPeak SlimBrowser (HKLM-x32\…\SlimBrowser) (Version: 7.00.143 - FlashPeak Inc.)
FlashRip(Full Version) (HKLM-x32\…\FlashRip(Full Version)_is1) (Version: - )
FlatOut 2 (HKLM-x32\…\{4E6D2462-AB33-40BB-AA9F-3FA3E0DD0290}) (Version: 1.00.0000 - Empire Interactive)
FMW 1 (HKLM\…\{1DA9CD4A-687F-4075-A828-0A3ACB901438}) (Version: 1.222.1 - AVG Technologies) Hidden
foobar2000 v1.3.9 (HKLM-x32\…\foobar2000) (Version: 1.3.9 - Peter Pawlowski)
Fraps (remove only) (HKLM-x32\…\Fraps) (Version: - )
Free Virtual Keyboard 3.0.1.0 (HKLM-x32\…\{CA4F9519-1A83-4907-8651-F17073A0E1CE}_is1) (Version: 3.0 - Comfort Software Group)
FreeUndelete 2.1.36867.1 (HKLM-x32\…\{0F5ADA2F-C0B2-4AD6-8FF7-7DFA9D6B4CBA}) (Version: 2.1.36867.1 - Recoveronix)
FTP Manager Lite 2 (HKLM-x32\…\FTP Manager Lite_is1) (Version: - DeskShare Inc.)
Getleft v1.2 (HKLM-x32\…\Getleft_is1) (Version: - )
Glary Undelete 5.0.1.19 (HKLM-x32\…\Glary Undelete) (Version: 5.0.1.19 - Glarysoft Ltd)
GPGNet (HKLM-x32\…\{C194D333-B84A-4BB7-B35E-060732D98DC4}) (Version: 1.0.0 - Gas Powered Games)
Hero Editor V1.04 (HKLM-x32\…\ST6UNST #1) (Version: - )
Hextech Repair Tool (HKLM-x32\…\{7F9A97E6-E666-11E5-B582-B88687E82322}) (Version: 1.1.15 - Riot Games, Inc.)
Intel(R) Control Center (HKLM-x32\…\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2476 - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\…\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 3.0.0.33 - Intel Corporation)
IrfanView 64 (remove only) (HKLM\…\IrfanView64) (Version: 4.41 - Irfan Skiljan)
League of Legends (HKLM-x32\…\{E80C09B5-A296-47E9-BD4B-BCCF2FDCA13E}) (Version: 4.1.2 - Riot Games) Hidden
League of Legends (HKLM-x32\…\League of Legends 4.1.2) (Version: 4.1.2 - Riot Games)
LinuxLive USB Creator (HKLM-x32\…\LinuxLive USB Creator) (Version: 2.9 - Thibaut Lauziere)
Maxthon App Store (HKLM-x32\…\Maxthon App Store 1.1.0.10848) (Version: 1.1.0.10848 - Maxthon, Inc.)
Maxthon Cloud Browser (HKLM-x32\…\Maxthon3) (Version: 4.9.2.1000 - Maxthon International Limited)
Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\…\{56E962F0-4FB0-3C67-88DB-9EAA6EEFC493}) (Version: 4.5.50710 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (ENU) (HKLM-x32\…\{D3517C62-68A5-37CF-92F7-93C029A89681}) (Version: 4.5.50932 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (HKLM-x32\…\{6A0C6700-EA93-372C-8871-DCCF13D160A4}) (Version: 4.5.50932 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 SDK (HKLM-x32\…\{19A5926D-66E1-46FC-854D-163AA10A52D3}) (Version: 4.5.51641 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (ENU) (HKLM-x32\…\{290FC320-2F5A-329E-8840-C4193BD7A9EE}) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (HKLM-x32\…\{B941AFB4-8851-33A1-9E72-0C33D463C41C}) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.6.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft Help Viewer 2.2 (HKLM-x32\…\Microsoft Help Viewer 2.2) (Version: 2.2.23107 - Microsoft Corporation)
Microsoft Office Professional Plus 2013 (HKLM\…\Office15.PROPLUS) (Version: 15.0.4420.1017 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\…\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\…\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\…\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\…\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\…\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23026 (HKLM-x32\…\{e46eca4f-393b-40df-9f49-076faf788d83}) (Version: 14.0.23026.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23506 (HKLM-x32\…\{23daf363-3020-4059-b3ae-dc4ad39fed19}) (Version: 14.0.23506.0 - Microsoft Corporation)
Microsoft Visual J# 2.0 Redistributable Package (HKLM-x32\…\Microsoft Visual J# 2.0 Redistributable Package) (Version: - Microsoft Corporation)
Microsoft Visual Studio 2015 Shell (Isolated) (HKLM-x32\…\{d2981c27-a434-4c9a-96c7-0209e97c4eac}) (Version: 14.0.23107.10 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2015 (HKLM-x32\…\{ab213ab7-4792-4c6f-a3fa-8485d06c3475}) (Version: 14.0.23829 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2015 Language Support (HKLM-x32\…\{353253a9-15a3-4727-b415-79b4e6be765e}) (Version: 14.0.23107.10 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\…\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation)
Mount and Blade (HKLM-x32\…\1207666893_is1) (Version: 2.0.0.4 - GOG.com)
Movavi Screen Capture 8 (HKLM-x32\…\Movavi Screen Capture 8) (Version: 8.6.0 - Movavi)
Mozilla Firefox 54.0.1 (x64 en-US) (HKLM\…\Mozilla Firefox 54.0.1 (x64 en-US)) (Version: 54.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\…\MozillaMaintenanceService) (Version: 53.0.2 - Mozilla)
MPC-HC 1.7.10 (64-bit) (HKLM\…\{2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1) (Version: 1.7.10 - MPC-HC Team)
MyDefrag v4.3.1 (HKLM\…\MyDefrag v4.3.1_is1) (Version: 4.0.0.0 - J.C. Kessels)
One Finger Death Punch 1.0 (HKLM-x32\…\One Finger Death Punch 1.0) (Version: 1.0 - Cat-A-Cat)
Opera Stable 46.0.2597.57 (HKU\S-1-5-21-384921765-1548902971-3406650631-1000\…\Opera 46.0.2597.57) (Version: 46.0.2597.57 - Opera Software)
Oracle VM VirtualBox 5.1.0 (HKLM\…\{0C801AA7-A02E-4DCF-BD09-0EACB11D9863}) (Version: 5.1.0 - Oracle Corporation)
Outils de vérification linguistique 2013 de Microsoft Office - Français (HKLM\…\{90150000-001F-040C-1000-0000000FF1CE}) (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Panda Cloud Cleaner (HKLM-x32\…\{92B2B132-C7F0-43DC-921A-4493C04F78A4}_is1) (Version: 1.1.9 - Panda Security)
PCSX2 - Playstation 2 Emulator (HKLM-x32\…\pcsx2) (Version: - )
PowerISO (HKLM-x32\…\PowerISO) (Version: 6.3 - Power Software Ltd)
Puran File Recovery 1.2 (HKLM\…\Puran File Recovery_is1) (Version: - Puran Software)
Qualcomm Atheros WiFi Driver Installation (HKLM-x32\…\{7D916FA5-DAE9-4A25-B089-655C70EAF607}) (Version: 9.2 - Qualcomm Atheros)
Realtek Card Reader (HKLM-x32\…\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.9600.29084 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.92.115.2015 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6454 - Realtek Semiconductor Corp.)
REALTEK Wireless LAN Driver (HKLM-x32\…\{9DAABC60-A5EF-41FF-B2B9-17329590CD5}) (Version: 1.00.0263 - REALTEK Semiconductor Corp.)
Revo Uninstaller 1.95 (HKLM-x32\…\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
RMPrepUSB (HKLM-x32\…\RMPrepUSB) (Version: - )
Roslyn Language Services - x86 (HKLM-x32\…\{5B47029B-1E62-30FF-906E-694851C22782}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
Roslyn Language Services - x86 (HKLM-x32\…\{6C1985E7-E1C5-3A95-86EF-2C62465F15C3}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
SAMSUNG USB Driver for Mobile Phones (HKLM\…\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.3.450.0 - SAMSUNG Electronics Co., Ltd.)
SeaMonkey 2.46 (x86 en-US) (HKLM-x32\…\SeaMonkey 2.46 (x86 en-US)) (Version: 2.46 - Mozilla)
Sonic Focus (HKLM-x32\…\{09BCB9CE-964B-4BDA-AE46-B5A0ABEF1D3F}) (Version: 1.0.0.4 - Synopsys )
Star wars Battlefront II version 1.3 (HKLM-x32\…\{2EF34761-F147-4984-8AF1-BB9F8DA76CDD}_is1) (Version: 1.3 - )
Streaming Video Recorder V6.1.7 (HKLM-x32\…\{01c39b1f-d465-48ca-9d71-7d5afa53b4eb}_is1) (Version: 6.1.7 - APOWERSOFT LIMITED)
Supreme Commander - Forged Alliance (HKLM-x32\…\{31D95937-B237-405D-920C-A3EF4E482395}) (Version: 1.00.0000 - Gas Powered Games)
SWF File Player (HKLM-x32\…\{6A86F611-906C-422D-B34A-103662CBC195}_is1) (Version: - swffileplayer.com)
Time Travel Browser (HKLM-x32\…\Time Travel Browser) (Version: 1.0.0 - LuksSoftware)
Torchlight (HKLM-x32\…\GOGPACKTORCHLIGHT_is1) (Version: 2.0.0.12 - GOG.com)
Tweaking.com - Registry Backup (HKLM-x32\…\Tweaking.com - Registry Backup) (Version: 3.3.1 - Tweaking.com)
UndeleteMyFiles Pro (HKLM-x32\…\UndeleteMyFiles Pro_is1) (Version: - SeriousBit)
Unity Web Player (HKU\S-1-5-21-384921765-1548902971-3406650631-1000\…\UnityWebPlayer) (Version: 5.3.7f1 - Unity Technologies ApS)
Universal Adb Driver (HKLM-x32\…\{D9C4202E-6D51-4B06-A8F1-22316E654BCA}) (Version: 1.0.0 - ClockworkMod)
Unknown File Handler (HKLM-x32\…\UFH_is1) (Version: 2015.12.29.0 - File.org)
Update for (KB2504637) (HKLM-x32\…\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation)
UpdateReminder 1.2017.4.14 (HKLM-x32\…\UpdateReminder_is1) (Version: - eSupport.com, Inc)
Video Download Capture V6.2.1 (HKLM-x32\…\{b3336f66-e079-4ff6-abdb-51e2fab781d5}_is1) (Version: 6.2.1 - APOWERSOFT LIMITED)
Visual Studio 2012 x64 Redistributables (HKLM\…\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\…\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VLC media player (HKLM-x32\…\VLC media player) (Version: 2.2.1 - VideoLAN)
Wampserver64 3.0.6 (HKLM\…\{wampserver64}_is1) (Version: 3.0.6 - Dominique Ottello aka Otomatic)
Warcraft III (HKLM-x32\…\Warcraft III) (Version: - Blizzard Entertainment)
Warcraft III: All Products (HKU\S-1-5-21-384921765-1548902971-3406650631-1000\…\Warcraft III) (Version: - )
Warhammer 40,000 - Storm of Vengeance (HKLM-x32\…\Warhammer 40,000 - Storm of Vengeance_is1) (Version: Warhammer 40,000 - Storm of Vengeance - Eutechnyx)
WebReaper v10 (HKLM-x32\…\WebReaper_is1) (Version: 10b - WebReaper.net)
Winamp (HKLM-x32\…\Winamp) (Version: 5.666 - Nullsoft, Inc)
Windows Driver Package - Google, Inc. (WinUSB) AndroidUsbDeviceClass (08/28/2014 11.0.0000.00000) (HKLM\…\092555911492C6959D2596D612F52DCA71881CA2) (Version: 08/28/2014 11.0.0000.00000 - Google, Inc.)
WinPcap 4.1.3 (HKLM-x32\…\WinPcapInst) (Version: 4.1.0.2980 - Riverbed Technology, Inc.)
WinRAR 5.21 (64-bit) (HKLM\…\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH)
WinToUSB version 2.8 (HKLM\…\WinToUSB_is1) (Version: 2.8 - The EasyUEFI Development Team.)
Wondershare MobileGo(Version 8.2.3) (HKLM-x32\…\{1E04C795-7359-4E05-8A0E-5644F777AA09}_is1) (Version: 8.2.3 - Wondershare)
YouTube Video Ripper 2.90 (HKLM-x32\…\YouTube Video Ripper_is1) (Version: - YoutubeGetting.com)
ZoneAlarm Firewall (HKLM-x32\…\{85819737-D33F-49F2-AFF0-EBD643428AA4}) (Version: 15.0.123.17051 - Check Point Software Technologies Ltd.) Hidden
ZoneAlarm Free Firewall (HKLM-x32\…\ZoneAlarm Free Firewall) (Version: 15.0.123.17051 - Check Point)
ZoneAlarm Security (HKLM-x32\…\{BC26330A-F6A0-40F1-B521-896E79FB7372}) (Version: 15.0.123.17051 - Check Point Software Technologies Ltd.) Hidden
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-384921765-1548902971-3406650631-1000_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\Windows\system32\igfxEM.exe (Intel Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2015-12-31] (Igor Pavlov)
ContextMenuHandlers1: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files (x86)\AVG\Antivirus\ashShA64.dll [2017-07-19] (AVG Technologies CZ, s.r.o.)
ContextMenuHandlers1: [Eraser] -> {BC9B776A-90D7-4476-A791-79D835F30650} => C:\Program Files\Eraser\Eraser.Shell.dll [2015-09-03] (The Eraser Project)
ContextMenuHandlers1: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => C:\Program Files\PowerISO\PWRISOSH.DLL [2015-07-23] (Power Software Ltd)
ContextMenuHandlers1: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAShell.dll -> No File
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2015-02-16] (Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2015-02-16] (Alexander Roshal)
ContextMenuHandlers2: [Eraser] -> {BC9B776A-90D7-4476-A791-79D835F30650} => C:\Program Files\Eraser\Eraser.Shell.dll [2015-09-03] (The Eraser Project)
ContextMenuHandlers3: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers3: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2015-12-31] (Igor Pavlov)
ContextMenuHandlers4: [Eraser] -> {BC9B776A-90D7-4476-A791-79D835F30650} => C:\Program Files\Eraser\Eraser.Shell.dll [2015-09-03] (The Eraser Project)
ContextMenuHandlers4: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => C:\Program Files\PowerISO\PWRISOSH.DLL [2015-07-23] (Power Software Ltd)
ContextMenuHandlers5: [Eraser] -> {BC9B776A-90D7-4476-A791-79D835F30650} => C:\Program Files\Eraser\Eraser.Shell.dll [2015-09-03] (The Eraser Project)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\Windows\system32\igfxpph.dll [2011-09-16] (Intel Corporation)
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\Windows\system32\igfxDTCM.dll [2014-10-10] (Intel Corporation)
ContextMenuHandlers5: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAShell.dll -> No File
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2015-12-31] (Igor Pavlov)
ContextMenuHandlers6: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files (x86)\AVG\Antivirus\ashShA64.dll [2017-07-19] (AVG Technologies CZ, s.r.o.)
ContextMenuHandlers6: [Eraser] -> {BC9B776A-90D7-4476-A791-79D835F30650} => C:\Program Files\Eraser\Eraser.Shell.dll [2015-09-03] (The Eraser Project)
ContextMenuHandlers6: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => C:\Program Files\PowerISO\PWRISOSH.DLL [2015-07-23] (Power Software Ltd)
ContextMenuHandlers6: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAShell.dll -> No File
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2015-02-16] (Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2015-02-16] (Alexander Roshal)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {06CFA027-1C9B-4AD6-BB7F-E11546E6153E} - System32\Tasks\Opera scheduled Autoupdate 1494414816 => C:\Program Files\Opera\launcher.exe [2017-07-18] (Opera Software)
Task: {0C38AE2D-18A0-48F0-B68B-E17B888171DD} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2017-08-01] (AVAST Software)
Task: {3261E316-AFD8-4063-A2CC-389DED3A5B4F} - System32\Tasks\AVG EUpdate Task => avgsetupx.exe
Task: {439ADCDD-9069-427F-BA0A-FDAB1AD5F6DA} - System32\Tasks\{229E9532-8EC8-4310-8097-EDD225B446C7} => C:\Windows\system32\pcalua.exe -a C:\Users\salty-san\Desktop\unetbootin-windows-613.exe -d C:\Users\salty-san\Desktop
Task: {46878AA7-1AA3-4113-BEB4-F039108AF39F} - System32\Tasks\MyDefrag v4.3.1 Daily => C:\Program Files\MyDefrag v4.3.1\Scripts\AutomaticDaily.MyD [2010-05-21] ()
Task: {774096DF-72C1-4134-B9CE-EB898AFAC4E3} - System32\Tasks\Antivirus Emergency Update => C:\Program Files (x86)\AVG\Antivirus\AvEmUpdate.exe [2017-07-19] (AVG Technologies CZ, s.r.o.)
Task: {A819E346-DD87-49B7-8F95-90430AFBC631} - System32\Tasks\Maxthon Update => C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe [2017-05-31] (Maxthon International ltd.)
Task: {AC9B9D29-42CD-43AB-861C-6B9198CD59AB} - System32\Tasks\{838A64F0-1784-412C-A1A1-DAC18FC1209B} => C:\Program Files (x86)\Command And Conquer Red Alert 2 Yuri's Revenge\RA2MD.exe [2001-08-23] ()
Task: {C673A044-1E70-4CC0-85C5-F079F0C6596C} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation)
Task: {CA4A6E7F-6B77-414B-B595-97CDD1B0B259} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2012-10-01] (Microsoft Corporation)
Task: {CE4E4352-61BE-4AEA-B41F-74A61CC1BA25} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation)
Task: {E4DD8000-2703-4934-A02B-75252ABFE56C} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-07-19] (Adobe Systems Incorporated)
Task: {E5DBA818-1F9F-4B43-AC1E-570F51A6036D} - System32\Tasks\MyDefrag v4.3.1 Monthly => C:\Program Files\MyDefrag v4.3.1\Scripts\AutomaticMonthly.MyD [2010-05-21] ()
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
==================== Loaded Modules (Whitelisted) ==============
2012-10-01 21:36 - 2012-10-01 21:36 - 006522480 _____ () C:\Program Files\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2017-05-13 11:39 - 2017-05-13 11:39 - 000163152 _____ () c:\Program Files (x86)\AVG\Antivirus\x64\vaarclient.dll
2017-07-03 20:55 - 2017-07-03 20:55 - 000832784 _____ () C:\Program Files (x86)\AVG\Antivirus\x64\ffl2.dll
2017-07-03 20:55 - 2017-07-03 20:55 - 000277416 _____ () c:\Program Files (x86)\AVG\Antivirus\x64\StreamBack.dll
2015-11-01 13:28 - 2014-10-10 11:45 - 000094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2017-05-13 11:39 - 2017-05-13 11:39 - 000171344 _____ () C:\Program Files (x86)\AVG\Antivirus\JsonRpcServer.dll
2017-07-03 20:55 - 2017-07-03 20:55 - 000193784 _____ () C:\Program Files (x86)\AVG\Antivirus\event_routing_rpc.dll
2017-07-03 20:55 - 2017-07-03 20:55 - 000225376 _____ () C:\Program Files (x86)\AVG\Antivirus\tasks_core.dll
2017-08-10 09:52 - 2017-08-10 09:52 - 005890008 _____ () C:\Program Files (x86)\AVG\Antivirus\defs\17081000\algo.dll
2017-07-03 20:55 - 2017-07-03 20:55 - 000690392 _____ () C:\Program Files (x86)\AVG\Antivirus\ffl2.dll
2017-07-03 20:55 - 2017-07-03 20:55 - 000232784 _____ () C:\Program Files (x86)\AVG\Antivirus\streamback.dll
2015-02-06 06:31 - 2015-02-06 06:31 - 000050840 _____ () C:\Program Files (x86)\Genie Soft\Genie Cleaner\MGCommon.dll
2017-01-18 15:19 - 2017-01-18 15:18 - 048920064 _____ () C:\Program Files (x86)\AVG\UiDll\2623\libcef.dll
2017-07-19 08:17 - 2017-07-19 08:17 - 001067056 _____ () C:\Program Files (x86)\AVG\Antivirus\AvChrome.dll
2017-07-03 20:55 - 2017-07-03 20:55 - 067109376 _____ () C:\Program Files (x86)\AVG\Antivirus\libcef.dll
2013-12-13 05:47 - 2013-12-13 05:47 - 000333824 _____ () C:\Program Files (x86)\Winamp\Plugins\freeform\wacs\freetype\freetype.wac
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vsmon => ""="Service"
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 05:34 - 2016-07-18 09:56 - 000000035 _____ C:\Windows\system32\Drivers\etc\hosts
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-384921765-1548902971-3406650631-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\salty-san\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: Media is not connected to internet.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is disabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{01DD5918-283F-4F3C-AC26-AF593412DF9F}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{508DDC13-5096-41A1-BE2C-A24C77183C13}] => (Block) D:\WASTELAND!\Wasteland 2 Directors Cut\Build\WL2.exe
FirewallRules: [TCP Query User{EEB53623-0283-483F-B645-04DD48C46786}C:\users\salty-san\documents\octgn\octgn\octgn.exe] => (Allow) C:\users\salty-san\documents\octgn\octgn\octgn.exe
FirewallRules: [UDP Query User{14C2698F-42A4-41BB-9169-2211FDC0ECB1}C:\users\salty-san\documents\octgn\octgn\octgn.exe] => (Allow) C:\users\salty-san\documents\octgn\octgn\octgn.exe
FirewallRules: [TCP Query User{DF6BC443-CABE-4E5A-9F0E-F4C4A78535F6}C:\users\salty-san\documents\octgn\octgn\octgn.exe] => (Allow) C:\users\salty-san\documents\octgn\octgn\octgn.exe
FirewallRules: [UDP Query User{0D9DECF9-7EE8-4932-81B6-5AA519CD2957}C:\users\salty-san\documents\octgn\octgn\octgn.exe] => (Allow) C:\users\salty-san\documents\octgn\octgn\octgn.exe
FirewallRules: [{F89C0384-F502-44A5-B00A-9826C8B9E172}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{BB9DFD0F-5CC0-4A92-A4C5-E4DE9031F0C6}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{19FBF323-28DA-4563-9196-790954D5F72D}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{5D4FF2EB-07A6-4F96-AFF0-58616E255410}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{95B66243-C6D0-4B85-90F6-547B69CE822E}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{BCFAED00-B5EE-4558-AFC6-E54BC68D9562}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [TCP Query User{B247EA9C-0A1B-4E95-8AC0-562403FC4950}C:\users\salty-san\documents\octgn\octgn\octgn.online.standaloneserver.exe] => (Allow) C:\users\salty-san\documents\octgn\octgn\octgn.online.standaloneserver.exe
FirewallRules: [UDP Query User{260782A1-34CD-4BA2-9F89-72C24BA3BF7B}C:\users\salty-san\documents\octgn\octgn\octgn.online.standaloneserver.exe] => (Allow) C:\users\salty-san\documents\octgn\octgn\octgn.online.standaloneserver.exe
FirewallRules: [TCP Query User{AD90B0F5-5A10-4C62-A7A3-3CBA144F4692}D:\playboard\call of duty 2 full game mp - sp -=aviara=-\call of duty 2\cod2mp_s.exe] => (Block) D:\playboard\call of duty 2 full game mp - sp -=aviara=-\call of duty 2\cod2mp_s.exe
FirewallRules: [UDP Query User{E45AB548-5CA2-49FC-BCAA-420157AA80F9}D:\playboard\call of duty 2 full game mp - sp -=aviara=-\call of duty 2\cod2mp_s.exe] => (Block) D:\playboard\call of duty 2 full game mp - sp -=aviara=-\call of duty 2\cod2mp_s.exe
FirewallRules: [{9D79CD9D-1138-4471-9107-72DC3CDE88B1}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{3BFEB175-5043-44EA-B2C6-7D52F51741EE}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{2E2BBFA3-FB0B-479D-85AD-963E99B02215}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{2BEE2144-B70C-4420-BC9E-5A25585FF686}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{05C545A5-8C9C-41C3-B89E-E65D6D8A0192}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
FirewallRules: [{E91111AF-B2E6-4408-A180-D898C8699190}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
FirewallRules: [TCP Query User{69F0FD99-0EC7-4032-A241-6D327E2A6239}C:\users\salty-san\documents\octgn\octgn\octgn.online.standaloneserver.exe] => (Allow) C:\users\salty-san\documents\octgn\octgn\octgn.online.standaloneserver.exe
FirewallRules: [UDP Query User{68EFF557-0A01-48DF-ADF5-F95A6BCF5C2F}C:\users\salty-san\documents\octgn\octgn\octgn.online.standaloneserver.exe] => (Allow) C:\users\salty-san\documents\octgn\octgn\octgn.online.standaloneserver.exe
FirewallRules: [TCP Query User{78AF15E1-CC17-4FE7-BDCE-5427620D4861}D:\zergoth!\the minks!\portable\mirc\mirc.exe] => (Allow) D:\zergoth!\the minks!\portable\mirc\mirc.exe
FirewallRules: [UDP Query User{36A39718-5949-41EE-93B6-6318ACE5812B}D:\zergoth!\the minks!\portable\mirc\mirc.exe] => (Allow) D:\zergoth!\the minks!\portable\mirc\mirc.exe
FirewallRules: [TCP Query User{4CDB7BB9-A122-4B17-BA93-EF671730BED0}D:\playboard\duel masters civilization!\duelmasters\duelmasters.exe] => (Allow) D:\playboard\duel masters civilization!\duelmasters\duelmasters.exe
FirewallRules: [UDP Query User{9EDB7F0F-B21C-4096-9A73-82A834AABA6D}D:\playboard\duel masters civilization!\duelmasters\duelmasters.exe] => (Allow) D:\playboard\duel masters civilization!\duelmasters\duelmasters.exe
FirewallRules: [{4C549C43-8769-43DD-9C4C-D832FAD6EA76}] => (Block) D:\playboard\duel masters civilization!\duelmasters\duelmasters.exe
FirewallRules: [{EAC4EBEF-0920-44DC-BE2C-0C1DE5FD23B7}] => (Block) D:\playboard\duel masters civilization!\duelmasters\duelmasters.exe
FirewallRules: [{7EC18199-F2F4-4E81-808E-B4AF8C069627}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe
FirewallRules: [{4051053A-8CCA-4822-B6DF-EB780F910B61}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe
FirewallRules: [{D42F9D68-6F43-4682-B3ED-C973FE575538}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe
FirewallRules: [{2478CB98-BB64-4FA9-842C-5FC7598BD6DB}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe
FirewallRules: [{1EE51A2D-F50E-4993-A34B-65E5CE39866A}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe
FirewallRules: [{F5DD2F8C-BC93-471C-9078-4D647E90DCE4}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe
FirewallRules: [{616F09ED-6DEE-4DB2-B541-38366AAC8A1C}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe
FirewallRules: [{C3F233A1-A686-4A64-9179-318E8C697C57}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe
FirewallRules: [TCP Query User{947EFFAD-F69E-4185-AC31-C5B988C9D459}C:\gog games\impossible creatures\ic.exe] => (Allow) C:\gog games\impossible creatures\ic.exe
FirewallRules: [UDP Query User{350CBCCF-86C4-4DD0-9F00-93692E8138D8}C:\gog games\impossible creatures\ic.exe] => (Allow) C:\gog games\impossible creatures\ic.exe
FirewallRules: [TCP Query User{6D711751-94CC-4740-8736-2AC7042FB237}C:\program files (x86)\command and conquer red alert 2 yuri's revenge\gamemd.exe] => (Allow) C:\program files (x86)\command and conquer red alert 2 yuri's revenge\gamemd.exe
FirewallRules: [UDP Query User{E7B29111-52F7-477F-B24A-5224F4BE11E8}C:\program files (x86)\command and conquer red alert 2 yuri's revenge\gamemd.exe] => (Allow) C:\program files (x86)\command and conquer red alert 2 yuri's revenge\gamemd.exe
FirewallRules: [{6C4DF875-2630-426C-BE46-04D1E8A0F790}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{23217DC7-B15A-47EE-8489-28C05A8C9AB4}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{01236CE6-09FC-4F0A-A6C6-B7B8A8073E42}] => (Allow) C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe
FirewallRules: [{116FBB49-70D1-4D4E-A2CA-F8C18B04A33A}] => (Allow) C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe
FirewallRules: [{359AE9CA-9C0E-42CF-8D17-1999E507C96E}] => (Allow) C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe
FirewallRules: [{68CE8494-D98E-4431-9953-BEBE55599E4A}] => (Allow) C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe
FirewallRules: [{E275E889-4E5B-4C75-A274-D510BA3F7900}] => (Allow) C:\Users\salty-san\AppData\Local\Apowersoft\Apowersoft Online Launcher\Apowersoft Online Launcher.exe
FirewallRules: [{7A764B84-AD36-4946-8897-4EE1A3C2BC4D}] => (Allow) C:\Users\salty-san\AppData\Local\Apowersoft\Apowersoft Online Launcher\Apowersoft Online Launcher.exe
FirewallRules: [{CE859985-D3D1-4BE0-A165-986E267E1EDC}] => (Allow) C:\Program Files (x86)\Apowersoft\Video Download Capture 6\Video Download Capture 6.exe
FirewallRules: [{7C8920A4-9C1B-401F-891D-831B9583BB7D}] => (Allow) C:\Program Files (x86)\Apowersoft\Video Download Capture 6\Video Download Capture 6.exe
FirewallRules: [{5E30974E-B7B4-446C-996E-35AF012E563B}] => (Allow) C:\Program Files (x86)\Apowersoft\Video Download Capture 6\rtmpsrv.exe
FirewallRules: [{39CB306C-1EB4-4A68-80D6-15914471CD1E}] => (Allow) C:\Program Files (x86)\Apowersoft\Video Download Capture 6\rtmpsrv.exe
FirewallRules: [{D7CCC354-351E-412D-822E-2E6D3A6827C9}] => (Allow) D:\StallINS\GAMES!\Supreme\Supreme Commander - Forged Alliance\bin\ForgedAlliance.exe
FirewallRules: [{34DD22FE-120E-45B9-93FA-31D597BEACE0}] => (Allow) D:\StallINS\GAMES!\Supreme\Supreme Commander - Forged Alliance\bin\ForgedAlliance.exe
FirewallRules: [{51EE86B5-AFA1-4182-9AE5-D740067626D5}] => (Allow) D:\StallINS\GAMES!\Supreme\GPGNet\GPG.Multiplayer.Client.exe
FirewallRules: [{85FF2AF4-E435-49B3-BDC8-38BC684CC484}] => (Allow) D:\StallINS\GAMES!\Supreme\GPGNet\GPG.Multiplayer.Client.exe
FirewallRules: [{93202B76-48DA-4BAE-9B39-D3A5E6F03040}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{BCF48B71-492C-40C8-8D51-259D5DA468BE}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{6021398B-D6BB-4273-A649-669DF7EA64E7}] => (Allow) C:\Program Files (x86)\Deskshare\FTP Manager Lite 2\FTP Manager Lite.exe
FirewallRules: [{29BE94E3-FB74-421C-8A92-B50F3CBA0982}] => (Allow) C:\Program Files (x86)\Deskshare\FTP Manager Lite 2\FTP Manager Lite.exe
FirewallRules: [{DE4320C8-4903-4C49-9F28-9B267A61A753}] => (Allow) C:\Program Files (x86)\Apowersoft\Streaming Video Recorder 6\Streaming Video Recorder 6.exe
FirewallRules: [{93158FFC-367F-40D3-98E0-EEC8F91BE006}] => (Allow) C:\Program Files (x86)\Apowersoft\Streaming Video Recorder 6\Streaming Video Recorder 6.exe
FirewallRules: [{B5EDECD6-6E16-487B-BFA4-780DBF26FFF0}] => (Allow) C:\Program Files (x86)\Apowersoft\Streaming Video Recorder 6\rtmpsrv.exe
FirewallRules: [{83AF7565-8478-45FE-9052-5E7CBAB6C381}] => (Allow) C:\Program Files (x86)\Apowersoft\Streaming Video Recorder 6\rtmpsrv.exe
FirewallRules: [{BF5FBB92-C3FB-46FD-BAD5-F0E2752E79E9}] => (Allow) C:\Program Files (x86)\Mobogenie3\mobogenieP2sp.exe
FirewallRules: [{024C2FB3-30E2-451C-A2E2-AD730EEC078A}] => (Allow) C:\Program Files\Opera\46.0.2597.46\opera.exe
FirewallRules: [{DEF54DCD-21E0-4622-B7BF-5A19DC3272E9}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{9DD49FAB-A449-4D58-94A2-D51D9D67A7FA}] => (Allow) C:\Program Files\Opera\46.0.2597.57\opera.exe
==================== Restore Points =========================
03-08-2017 15:02:03 Removed Dynasty Warriors 4 Hyper
10-08-2017 15:26:10 Revo Uninstaller's restore point - Adobe Acrobat Reader DC
==================== Faulty Device Manager Devices =============
Name: Intel(R) Display Audio
Description: Intel(R) Display Audio
Class Guid: {4d36e96c-e325-11ce-bfc1-08002be10318}
Manufacturer: Intel(R) Corporation
Service: IntcDAud
Problem: : Windows cannot start this hardware device because its configuration information (in the registry) is incomplete or damaged. (Code 19)
Resolution: A registry problem was detected.
This can occur when more than one service is defined for a device, if there is a failure opening the service subkey, or if the driver name cannot be obtained from the service subkey. Try these options:
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Click "Uninstall", and then click "Scan for hardware changes" to load a usable driver.
Name: USB Sound Device
Description: USB Audio Device
Class Guid: {4d36e96c-e325-11ce-bfc1-08002be10318}
Manufacturer: (Generic USB Audio)
Service: usbaudio
Problem: : Windows cannot start this hardware device because its configuration information (in the registry) is incomplete or damaged. (Code 19)
Resolution: A registry problem was detected.
This can occur when more than one service is defined for a device, if there is a failure opening the service subkey, or if the driver name cannot be obtained from the service subkey. Try these options:
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Click "Uninstall", and then click "Scan for hardware changes" to load a usable driver.
Name: SM Bus Controller
Description: SM Bus Controller
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: Realtek High Definition Audio
Description: Realtek High Definition Audio
Class Guid: {4d36e96c-e325-11ce-bfc1-08002be10318}
Manufacturer: Realtek
Service: IntcAzAudAddService
Problem: : Windows cannot start this hardware device because its configuration information (in the registry) is incomplete or damaged. (Code 19)
Resolution: A registry problem was detected.
This can occur when more than one service is defined for a device, if there is a failure opening the service subkey, or if the driver name cannot be obtained from the service subkey. Try these options:
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Click "Uninstall", and then click "Scan for hardware changes" to load a usable driver.
==================== Event log errors: =========================
Application errors:
==================
Error: (08/10/2017 09:01:41 PM) (Source: lupdate) (EventID: 0) (User: )
Description: Event-ID 0
Error: (08/10/2017 08:58:42 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Error: (08/10/2017 08:50:28 PM) (Source: lupdate) (EventID: 0) (User: )
Description: Event-ID 0
Error: (08/10/2017 08:47:22 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Error: (08/10/2017 08:35:04 PM) (Source: lupdate) (EventID: 0) (User: )
Description: Event-ID 0
Error: (08/10/2017 08:35:03 PM) (Source: lupdate) (EventID: 0) (User: )
Description: Event-ID 0
Error: (08/10/2017 05:16:53 PM) (Source: lupdate) (EventID: 0) (User: )
Description: Event-ID 0
Error: (08/10/2017 05:16:52 PM) (Source: lupdate) (EventID: 0) (User: )
Description: Event-ID 0
Error: (08/10/2017 05:05:39 PM) (Source: lupdate) (EventID: 0) (User: )
Description: Event-ID 0
Error: (08/10/2017 05:02:32 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
System errors:
=============
Error: (08/10/2017 08:57:59 PM) (Source: BugCheck) (EventID: 1001) (User: )
Description: The computer has rebooted from a bugcheck. The bugcheck was: 0x00000101 (0x0000000000000061, 0x0000000000000000, 0xfffff880009ed180, 0x0000000000000001). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 081017-16894-01.
Error: (08/10/2017 08:57:58 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 8:56:27 PM on 8/10/2017 was unexpected.
Error: (08/10/2017 08:47:21 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The Wondershare Application Framework Service service hung on starting.
Error: (08/10/2017 08:45:46 PM) (Source: BugCheck) (EventID: 1001) (User: )
Description: The computer has rebooted from a bugcheck. The bugcheck was: 0x00000109 (0xa3a039d8a388b616, 0xb3b7465ef606f46c, 0xfffff880009f8540, 0x0000000000000002). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 081017-20935-01.
Error: (08/10/2017 08:45:34 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 8:43:27 PM on 8/10/2017 was unexpected.
Error: (08/10/2017 04:17:11 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: The server {078AEF33-C48A-49F7-AFF3-A0EE810BFE7C} did not register with DCOM within the required timeout.
Error: (08/10/2017 04:12:49 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Windows Update service terminated with the following error:
The class is configured to run as a security id different from the caller
Error: (08/10/2017 04:00:27 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The DrvAgent64 service failed to start due to the following error:
The system cannot find the file specified.
Error: (08/10/2017 04:00:27 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The DrvAgent64 service failed to start due to the following error:
The system cannot find the file specified.
Error: (08/10/2017 04:00:27 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The DrvAgent64 service failed to start due to the following error:
The system cannot find the file specified.
CodeIntegrity:
===================================
Date: 2016-01-14 19:28:38.733
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\AVG\AVG PC TuneUp\avgdumpx.exe because the set of per-page image hashes could not be found on the system.
Date: 2016-01-14 19:28:38.591
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\AVG\AVG PC TuneUp\avgdumpx.exe because the set of per-page image hashes could not be found on the system.
Date: 2016-01-14 19:28:38.368
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\AVG\AVG PC TuneUp\avgdumpa.exe because the set of per-page image hashes could not be found on the system.
Date: 2016-01-14 19:28:38.201
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\AVG\AVG PC TuneUp\avgdumpa.exe because the set of per-page image hashes could not be found on the system.
Date: 2015-12-17 10:29:48.300
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\AVG\AVG PC TuneUp\avgdumpx.exe because the set of per-page image hashes could not be found on the system.
Date: 2015-12-17 10:29:48.191
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\AVG\AVG PC TuneUp\avgdumpx.exe because the set of per-page image hashes could not be found on the system.
Date: 2015-12-17 10:29:48.082
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\AVG\AVG PC TuneUp\avgdumpx.exe because the set of per-page image hashes could not be found on the system.
Date: 2015-12-16 03:51:45.976
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\AVG\AVG PC TuneUp\avgdumpx.exe because the set of per-page image hashes could not be found on the system.
Date: 2015-12-16 03:51:45.867
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\AVG\AVG PC TuneUp\avgdumpx.exe because the set of per-page image hashes could not be found on the system.
Date: 2015-12-16 03:51:45.773
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\AVG\AVG PC TuneUp\avgdumpx.exe because the set of per-page image hashes could not be found on the system.
==================== Memory info ===========================
Processor: Intel(R) Celeron(R) CPU B815 @ 1.60GHz
Percentage of memory in use: 39%
Total physical RAM: 4000.13 MB
Available physical RAM: 2413.32 MB
Total Virtual: 7998.45 MB
Available Virtual: 6459.59 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:122.07 GB) (Free:35.74 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (East) (Fixed) (Total:343.69 GB) (Free:175.34 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: D9FA2484)
Partition 1: (Not Active) - (Size=343.7 GB) - (Type=07 NTFS)
Partition 2: (Active) - (Size=122.1 GB) - (Type=07 NTFS)
==================== End of Addition.txt ============================
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 09-08-2017
Ran by [removed] (administrator) on SALTYSKY (10-08-2017 21:00:58)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: "C:\Program Files (x86)\SeaMonkey\seamonkey.exe" -requestPending -osint -url "%1")
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Check Point Software Technologies Ltd.) C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\AVGSvc.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe
(Comodo) C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe
(Oppoos.com) C:\Program Files (x86)\Genie Soft\Genie Cleaner\GenieCleanService.exe
(Maxthon) C:\Program Files (x86)\Maxthon App Store\1.1.0.10848\MaxthonAppstoreSvc.exe
(Maxthon) C:\Program Files (x86)\Maxthon\Modules\Service\Update\MaxthonUpdateSvc.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Wondershare) C:\Program Files (x86)\Wondershare\WAF\2.3.1.1\WsAppService.exe
(Check Point Software Technologies Ltd.) C:\Program Files (x86)\CheckPoint\ZoneAlarm\ICM-Service.exe
(Lenovo) C:\Windows\System32\LenovoUpdate.exe
(Oppoos.com) C:\Program Files (x86)\Genie Soft\Genie Cleaner\GenieFloater.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\x64\aswidsagenta.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Epic Privacy Browser) C:\Users\salty-san\AppData\Local\Epic Privacy Browser\Installer\EpicUpdate.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\avgui.exe
(eSupport.com) C:\ProgramData\DriverAgentPlus\UpdateReminder\UpdateReminder.exe
(Wondershare) C:\Program Files (x86)\Wondershare\MobileGo\MobileGoService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Power Software Ltd) C:\Program Files\PowerISO\PWRISOVM.EXE
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Nullsoft, Inc.) C:\Program Files (x86)\Winamp\winampa.exe
(Check Point Software Technologies Ltd.) C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe
(Virage Logic Corporation / Sonic Focus) C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
(Nullsoft, Inc.) C:\Program Files (x86)\Winamp\winamp.exe
(Comodo) C:\Program Files (x86)\Comodo\Dragon\dragon.exe
(Comodo) C:\Program Files (x86)\Comodo\Dragon\dragon.exe
(Comodo) C:\Program Files (x86)\Comodo\Dragon\dragon.exe
(Comodo) C:\Program Files (x86)\Comodo\Dragon\dragon.exe
(Comodo) C:\Program Files (x86)\Comodo\Dragon\dragon.exe
(Comodo) C:\Program Files (x86)\Comodo\Dragon\dragon.exe
(Comodo) C:\Program Files (x86)\Comodo\Dragon\dragon.exe
(Comodo) C:\Program Files (x86)\Comodo\Dragon\dragon.exe
(Comodo) C:\Program Files (x86)\Comodo\Dragon\dragon.exe
(Comodo) C:\Program Files (x86)\Comodo\Dragon\dragon.exe
(Comodo) C:\Program Files (x86)\Comodo\Dragon\dragon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [Eraser] => C:\Program Files\Eraser\Eraser.exe [1074088 2015-09-03] (The Eraser Project)
HKLM\…\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2587944 2010-12-31] (ELAN Microelectronics Corp.)
HKLM\…\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [239592 2017-08-01] (AVG Technologies CZ, s.r.o.)
HKLM\…\Run: [AVGUI.exe] => C:\Program Files (x86)\AVG\Antivirus\AvLaunch.exe [263232 2017-07-19] (AVG Technologies CZ, s.r.o.)
HKLM\…\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12850792 2011-09-05] (Realtek Semiconductor)
HKLM-x32\…\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2014-06-09] (Intel Corporation)
HKLM-x32\…\Run: [PWRISOVM.EXE] => C:\Program Files\PowerISO\PWRISOVM.EXE [408888 2015-07-23] (Power Software Ltd)
HKLM-x32\…\Run: [WinampAgent] => C:\Program Files (x86)\Winamp\winampa.exe [85600 2013-12-13] (Nullsoft, Inc.)
HKLM-x32\…\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [239592 2017-08-01] (AVG Technologies CZ, s.r.o.)
HKLM-x32\…\Run: [ZoneAlarm] => C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe [144184 2016-09-07] (Check Point Software Technologies Ltd.)
HKLM-x32\…\Run: [SonicMasterTray] => C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe [984400 2010-07-09] (Virage Logic Corporation / Sonic Focus)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-384921765-1548902971-3406650631-1000\…\Run: [Epic Privacy Browser Installer] => C:\Users\salty-san\AppData\Local\Epic Privacy Browser\Installer\EpicUpdate.exe [509096 2016-02-28] (Epic Privacy Browser)
HKU\S-1-5-21-384921765-1548902971-3406650631-1000\…\Run: [GenieFloater] => C:\Program Files (x86)\Genie Soft\Genie Cleaner\GenieFloater.exe [1850520 2015-02-06] (Oppoos.com)
HKU\S-1-5-21-384921765-1548902971-3406650631-1000\…\Run: [UpdateReminder] => C:\ProgramData\DriverAgentPlus\UpdateReminder\UpdateReminder.exe [682488 2017-04-14] (eSupport.com)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\MobileGo Service.lnk [2017-04-09]
ShortcutTarget: MobileGo Service.lnk -> C:\Program Files (x86)\Wondershare\MobileGo\MobileGoService.exe (Wondershare)
BootExecute: autocheck autochk * PCloudBroom64.exe \systemroot\system32\BroomData.bitPCloudBroom64.exe \systemroot\system32\BroomData.bitPCloudBroom64.exe \systemroot\system32\BroomData.bitPCloudBroom64.exe \systemroot\system32\BroomData.bit
GroupPolicy: Restriction <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{997EDB05-CBD3-4358-97F4-A47B17E7987F}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{BB2A1C55-6917-4C3A-8770-C53876319A70}: [DhcpNameServer] 192.168.0.1
Internet Explorer:
==================
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=msnhome
HKU\S-1-5-21-384921765-1548902971-3406650631-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
HKU\S-1-5-21-384921765-1548902971-3406650631-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://us.yahoo.com/?fr=fp-comodo&type;=19_25050030005_52.15.25.664_u_hp
SearchScopes: HKU\S-1-5-21-384921765-1548902971-3406650631-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2012-10-01] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2012-10-01] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation)
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2012-10-01] (Microsoft Corporation)
FireFox:
========
FF DefaultProfile: oi0sxqu4.default
FF DefaultProfile: kl9fv1vt.default
FF ProfilePath: C:\Users\salty-san\AppData\Roaming\Mozilla\SeaMonkey\Profiles\oi0sxqu4.default [2017-08-10]
FF DefaultSearchEngine: Mozilla\SeaMonkey\Profiles\oi0sxqu4.default -> DuckDuckGo
FF Extension: (MEGA) - C:\Users\salty-san\AppData\Roaming\Mozilla\SeaMonkey\Profiles\oi0sxqu4.default\Extensions\[removed] [2016-07-06]
FF Extension: (DOM Inspector) - C:\Users\salty-san\AppData\Roaming\Mozilla\SeaMonkey\Profiles\oi0sxqu4.default\Extensions\[removed] [2016-04-27]
FF Extension: (ChatZilla) - C:\Users\salty-san\AppData\Roaming\Mozilla\SeaMonkey\Profiles\oi0sxqu4.default\Extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2} [2017-01-18]
FF Extension: (Flash and Video Download) - C:\Users\salty-san\AppData\Roaming\Mozilla\SeaMonkey\Profiles\oi0sxqu4.default\Extensions\{bee6eb20-01e0-ebd1-da83-080329fb9a3a} [2017-08-10]
FF Extension: (DownThemAll!) - C:\Users\salty-san\AppData\Roaming\Mozilla\SeaMonkey\Profiles\oi0sxqu4.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2017-03-19]
FF ProfilePath: C:\Users\salty-san\AppData\Roaming\Mozilla\Firefox\Profiles\kl9fv1vt.default [2017-08-10]
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\kl9fv1vt.default -> DuckDuckGo
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2012-10-01] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-05-03] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-384921765-1548902971-3406650631-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\salty-san\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2016-10-26] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-384921765-1548902971-3406650631-1000: @updates.epicbrowser.com/Epic Privacy Browser Installer;version=3 -> C:\Users\salty-san\AppData\Local\Epic Privacy Browser\Installer\1.3.27.13\npEpicUpdate3.dll [2016-02-28] (Epic Privacy Browser)
FF Plugin HKU\S-1-5-21-384921765-1548902971-3406650631-1000: @updates.epicbrowser.com/Epic Privacy Browser Installer;version=9 -> C:\Users\salty-san\AppData\Local\Epic Privacy Browser\Installer\1.3.27.13\npEpicUpdate3.dll [2016-02-28] (Epic Privacy Browser)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2012-10-01] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2015-12-18] (Adobe Systems Inc.)
Chrome:
=======
CHR HKU\S-1-5-21-384921765-1548902971-3406650631-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [hcjjaajflhellmcfcecojihhmdbjmmlm] - hxxps://clients2.google.com/service/update2/crx
Opera:
=======
OPR Extension: (Bookmarks) - C:\Users\salty-san\AppData\Roaming\Opera Software\Opera Stable\Extensions\fnlanmpednndkaaaleibncenahckbmhc [2017-05-10]
OPR Extension: (Opera Welcome Page) - C:\Users\salty-san\AppData\Roaming\Opera Software\Opera Stable\Extensions\kejfhjjgjmgpfcdoiiccindaajbglghl [2017-05-10]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AVG Antivirus; C:\Program Files (x86)\AVG\Antivirus\AVGSvc.exe [264432 2017-07-19] (AVG Technologies CZ, s.r.o.)
R3 avgbIDSAgent; C:\Program Files (x86)\AVG\Antivirus\x64\aswidsagenta.exe [7481648 2017-07-19] (AVG Technologies CZ, s.r.o.)
R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1428656 2017-08-01] (AVG Technologies CZ, s.r.o.)
R2 DragonUpdater; C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe [2272904 2016-09-29] (Comodo)
R2 GenieCleanService; C:\Program Files (x86)\Genie Soft\Genie Cleaner\GenieCleanService.exe [53400 2015-02-06] (Oppoos.com) [File not signed]
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [318568 2014-10-10] (Intel Corporation)
R3 LenovoUpdate; C:\Windows\System32\LenovoUpdate.exe [26608 2017-08-10] (Lenovo)
R2 MaxthonAppStoreSvc; C:\Program Files (x86)\Maxthon App Store\1.1.0.10848\MaxthonAppstoreSvc.exe [1867544 2015-08-11] (Maxthon)
R2 MaxthonUpdateSvc; C:\Program Files (x86)\Maxthon\Modules\Service\Update\MaxthonUpdateSvc.exe [2385832 2016-06-10] (Maxthon)
S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-03-01] (Riverbed Technology, Inc.)
R2 vsmon; C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe [4087568 2016-09-07] (Check Point Software Technologies Ltd.)
S3 wampapache64; c:\wamp64\bin\apache\apache2.4.23\bin\httpd.exe [29696 2016-07-01] (Apache Software Foundation) [File not signed]
S3 wampmysqld64; c:\wamp64\bin\mysql\mysql5.7.14\bin\mysqld.exe [39885824 2016-07-12] () [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2015-08-05] (Microsoft Corporation)
R2 WsAppService; C:\Program Files (x86)\Wondershare\WAF\2.3.1.1\WsAppService.exe [437392 2016-10-10] (Wondershare)
S3 WsDrvInst; C:\Program Files (x86)\Wondershare\MobileGo\DriverInstall.exe [116368 2016-10-18] (Wondershare)
S3 ZAPrivacyService; C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZaPrivacyService.exe [114936 2016-08-09] (Check Point Software Technologies, Ltd.)
R2 ZoneAlarm ICM Service; C:\Program Files (x86)\CheckPoint\ZoneAlarm\ICM-Service.exe [794424 2016-09-07] (Check Point Software Technologies Ltd.)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 avgbdisk; C:\Windows\system32\drivers\avgbdiska.sys [166624 2017-07-19] (AVG Technologies CZ, s.r.o.)
R1 avgbidsdriver; C:\Windows\system32\drivers\avgbidsdrivera.sys [313616 2017-07-19] (AVG Technologies CZ, s.r.o.)
R0 avgbidsh; C:\Windows\system32\drivers\avgbidsha.sys [192584 2017-07-19] (AVG Technologies CZ, s.r.o.)
R0 avgblog; C:\Windows\system32\drivers\avgbloga.sys [336896 2017-07-19] (AVG Technologies CZ, s.r.o.)
R0 avgbuniv; C:\Windows\system32\drivers\avgbuniva.sys [51336 2017-07-19] (AVG Technologies CZ, s.r.o.)
S3 avgHwid; C:\Windows\system32\drivers\avgHwid.sys [39424 2017-07-19] (AVG Technologies CZ, s.r.o.)
R2 avgMonFlt; C:\Windows\system32\drivers\avgMonFlt.sys [139112 2017-07-19] (AVG Technologies CZ, s.r.o.)
R1 avgRdr; C:\Windows\system32\drivers\avgRdr2.sys [102792 2017-07-19] (AVG Technologies CZ, s.r.o.)
R0 avgRvrt; C:\Windows\system32\drivers\avgRvrt.sys [76832 2017-07-19] (AVG Technologies CZ, s.r.o.)
R1 avgSnx; C:\Windows\system32\drivers\avgSnx.sys [1008288 2017-07-19] (AVG Technologies CZ, s.r.o.)
R1 avgSP; C:\Windows\system32\drivers\avgSP.sys [578048 2017-07-19] (AVG Technologies CZ, s.r.o.)
R2 avgStm; C:\Windows\system32\drivers\avgStm.sys [191208 2017-07-19] (AVG Technologies CZ, s.r.o.)
R0 avgVmm; C:\Windows\system32\drivers\avgVmm.sys [353744 2017-07-19] (AVG Technologies CZ, s.r.o.)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
R2 npf; C:\Windows\system32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.)
S3 PSKMAD; C:\Windows\System32\DRIVERS\PSKMAD.sys [50320 2015-01-29] (Panda Security, S.L.)
S3 RSP2STOR; C:\Windows\System32\DRIVERS\RtsP2Stor.sys [294104 2014-12-10] (Realtek Semiconductor Corp.)
S3 RTWlanE; C:\Windows\System32\DRIVERS\rtwlane.sys [3513048 2015-03-23] (Realtek Semiconductor Corporation )
R1 VBoxNetAdp; C:\Windows\System32\DRIVERS\VBoxNetAdp6.sys [121824 2016-07-12] (Oracle Corporation)
R1 VBoxNetLwf; C:\Windows\System32\DRIVERS\VBoxNetLwf.sys [195424 2016-07-12] (Oracle Corporation)
S3 VBoxUSB; C:\Windows\System32\Drivers\VBoxUSB.sys [135824 2016-07-12] (Oracle Corporation)
R1 Vsdatant; C:\Windows\System32\DRIVERS\vsdatant.sys [461240 2017-03-16] (Check Point Software Technologies Ltd.)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-08-10 21:00 - 2017-08-10 21:02 - 000018132 _____ C:\Users\salty-san\Desktop\FRST.txt
2017-08-10 20:59 - 2017-08-10 21:00 - 000000000 ____D C:\FRST
2017-08-10 20:57 - 2017-08-10 20:57 - 000262144 _____ C:\Windows\Minidump\081017-16894-01.dmp
2017-08-10 20:45 - 2017-08-10 20:45 - 000262144 _____ C:\Windows\Minidump\081017-20935-01.dmp
2017-08-10 18:40 - 2017-08-10 18:40 - 002381824 _____ (Farbar) C:\Users\salty-san\Desktop\FRST64.exe
2017-08-10 18:39 - 2017-08-10 18:39 - 005198336 _____ (AVAST Software) C:\Users\salty-san\Desktop\aswMBR.exe
2017-08-10 16:50 - 2017-08-10 16:50 - 000931447 _____ C:\Users\salty-san\Favorites-WIN MOVE!.rar
2017-08-10 16:43 - 2017-08-10 16:43 - 000089841 _____ C:\Windows\unins000.dat
2017-08-10 16:43 - 2017-08-10 16:43 - 000004608 _____ C:\Users\salty-san\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2017-08-10 16:43 - 2017-08-10 16:43 - 000001029 _____ C:\Users\Public\Desktop\ezvid.lnk
2017-08-10 16:43 - 2017-08-10 16:43 - 000000000 ____D C:\Users\salty-san\Documents\ezvid
2017-08-10 16:43 - 2017-08-10 16:43 - 000000000 ____D C:\Users\salty-san\AppData\Local\ezvid,_inc
2017-08-10 16:43 - 2017-08-10 16:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ezvid
2017-08-10 16:43 - 2017-08-10 16:40 - 000761531 _____ C:\Windows\unins000.exe
2017-08-10 16:43 - 2015-03-10 20:29 - 000462584 _____ (Bytescout) C:\Windows\SysWOW64\BytescoutScreenCapturing.dll
2017-08-10 16:43 - 2015-03-10 20:29 - 000360184 _____ (Bytescout) C:\Windows\SysWOW64\BytescoutScreenCapturingFilter.dll
2017-08-10 16:43 - 2015-03-10 20:29 - 000196344 _____ (Bytescout) C:\Windows\SysWOW64\BytescoutVideoMixerFilter.dll
2017-08-10 16:43 - 2013-04-07 18:09 - 000216064 _____ ( ) C:\Windows\SysWOW64\Lagarith.dll
2017-08-10 16:43 - 2013-04-07 18:09 - 000148992 _____ ( ) C:\Windows\system32\Lagarith.dll
2017-08-10 16:42 - 2017-08-10 16:43 - 000000000 ____D C:\Program Files (x86)\ezvid
2017-08-10 16:11 - 2017-08-10 16:11 - 000000000 ____D C:\Windows\SysWOW64\RTCOM
2017-08-10 16:11 - 2011-09-06 19:58 - 003074536 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHD64.sys
2017-08-10 16:11 - 2011-09-06 10:16 - 002519656 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtPgEx64.dll
2017-08-10 16:11 - 2011-09-05 17:06 - 000097896 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoInst64.dll
2017-08-10 16:11 - 2011-09-02 13:27 - 003201128 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkAPO64.dll
2017-08-10 16:11 - 2011-09-01 15:08 - 001510912 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoRes64.dat
2017-08-10 16:11 - 2011-08-19 14:54 - 001881704 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApi64.dll
2017-08-10 16:11 - 2011-07-28 00:55 - 002604376 _____ (Waves Audio Ltd.) C:\Windows\system32\WavesGUILib.dll
2017-08-10 16:11 - 2011-07-28 00:55 - 002132824 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioEQ.dll
2017-08-10 16:11 - 2011-07-22 19:35 - 001247848 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTCOM64.dll
2017-08-10 16:11 - 2011-06-30 16:14 - 001560168 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSnMg64.cpl
2017-08-10 16:11 - 2011-05-31 09:42 - 001756264 _____ (DTS) C:\Windows\system32\DTSS2SpeakerDLL64.dll
2017-08-10 16:11 - 2011-05-31 09:42 - 001568360 _____ (DTS) C:\Windows\system32\DTSS2HeadphoneDLL64.dll
2017-08-10 16:11 - 2011-05-31 09:42 - 001486952 _____ (DTS) C:\Windows\system32\DTSBoostDLL64.dll
2017-08-10 16:11 - 2011-05-31 09:42 - 000728680 _____ (DTS) C:\Windows\system32\DTSBassEnhancementDLL64.dll
2017-08-10 16:11 - 2011-05-31 09:42 - 000693352 _____ (DTS) C:\Windows\system32\DTSVoiceClarityDLL64.dll
2017-08-10 16:11 - 2011-05-31 09:42 - 000491112 _____ (DTS) C:\Windows\system32\DTSNeoPCDLL64.dll
2017-08-10 16:11 - 2011-05-31 09:42 - 000432744 _____ (DTS) C:\Windows\system32\DTSLimiterDLL64.dll
2017-08-10 16:11 - 2011-05-31 09:42 - 000428648 _____ (DTS) C:\Windows\system32\DTSGainCompensatorDLL64.dll
2017-08-10 16:11 - 2011-05-31 09:42 - 000242792 _____ (DTS) C:\Windows\system32\DTSLFXAPO64.dll
2017-08-10 16:11 - 2011-05-31 09:42 - 000242792 _____ (DTS) C:\Windows\system32\DTSGFXAPO64.dll
2017-08-10 16:11 - 2011-05-05 15:24 - 002085440 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO64.dll
2017-08-10 16:11 - 2011-05-05 14:15 - 000220512 _____ (Synopsys, Inc.) C:\Windows\system32\SFNHK64.dll
2017-08-10 16:11 - 2011-05-05 14:14 - 000081248 _____ (Synopsys, Inc.) C:\Windows\system32\SFCOM64.dll
2017-08-10 16:11 - 2011-05-05 14:14 - 000078176 _____ (Synopsys, Inc.) C:\Windows\system32\SFAPO64.dll
2017-08-10 16:11 - 2010-11-08 08:31 - 000375128 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEP64A.dll
2017-08-10 16:11 - 2010-11-08 08:31 - 000310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DHT64.dll
2017-08-10 16:11 - 2010-11-08 08:31 - 000310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DAA64.dll
2017-08-10 16:11 - 2010-11-08 08:31 - 000204120 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEED64A.dll
2017-08-10 16:11 - 2010-11-08 08:31 - 000101208 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEL64A.dll
2017-08-10 16:11 - 2010-11-08 08:31 - 000078680 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEG64A.dll
2017-08-10 16:11 - 2010-11-03 19:31 - 000332392 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtlCPAPI64.dll
2017-08-10 16:11 - 2010-11-03 19:30 - 000149608 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCfg64.dll
2017-08-10 16:11 - 2010-09-27 09:34 - 000318808 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO20.dll
2017-08-10 16:11 - 2010-07-22 16:48 - 000074064 _____ (Virage Logic Corporation / Sonic Focus) C:\Windows\SysWOW64\SFCOM.dll
2017-08-10 16:11 - 2010-07-22 16:37 - 000200800 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAC64.dll
2017-08-10 16:11 - 2010-07-11 21:28 - 000180048 _____ (Sonic Focus, Inc.) C:\Windows\system32\SFProc64.dll
2017-08-10 16:11 - 2010-07-11 21:28 - 000086352 _____ (Sonic Focus, Inc.) C:\Windows\system32\SFComm64.dll
2017-08-10 16:11 - 2010-07-11 21:28 - 000083792 _____ (Sonic Focus, Inc.) C:\Windows\system32\SFSAPO64.dll
2017-08-10 16:11 - 2010-07-11 21:28 - 000082768 _____ (Sonic Focus, Inc.) C:\Windows\system32\SFHAPO64.dll
2017-08-10 16:11 - 2010-07-11 21:28 - 000082768 _____ (Sonic Focus, Inc.) C:\Windows\system32\SFDAPO64.dll
2017-08-10 16:11 - 2009-11-24 10:55 - 000518896 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSX64.dll
2017-08-10 16:11 - 2009-11-24 10:55 - 000211184 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSH64.dll
2017-08-10 16:11 - 2009-11-24 10:55 - 000198896 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSHP64.dll
2017-08-10 16:11 - 2009-11-24 10:55 - 000155888 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSWOW64.dll
2017-08-10 16:11 - 2009-11-17 19:12 - 000108960 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAR64.dll
2017-08-10 16:00 - 2017-08-10 16:06 - 000000000 ____D C:\Users\salty-san\AppData\Roaming\DriverAgentPlus
2017-08-10 16:00 - 2017-08-10 16:06 - 000000000 ____D C:\ProgramData\DriverAgentPlus
2017-08-10 15:34 - 2017-08-10 15:34 - 000000000 ____D C:\Users\salty-san\AppData\Local\ElevatedDiagnostics
2017-08-10 14:46 - 2017-08-10 14:46 - 000034512 _____ C:\Windows\system32\Drivers\debutfilterx64.sys
2017-08-09 18:26 - 2017-08-09 18:26 - 000000000 ____D C:\ProgramData\Steam
2017-08-09 18:24 - 2017-08-09 18:24 - 000002038 _____ C:\Users\salty-san\Desktop\BlazBlue Chronophantasma Extend.lnk
2017-08-09 18:16 - 2017-08-09 18:16 - 000001101 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlazBlue Chronophantasma Extend.lnk
2017-08-03 20:23 - 2017-08-03 20:23 - 000262144 _____ C:\Windows\Minidump\080317-15303-01.dmp
2017-08-03 20:22 - 2017-08-10 14:46 - 000001181 _____ C:\Users\salty-san\AppData\Roaming\trace_FilterInstaller.txt
2017-08-03 20:22 - 2017-08-10 14:46 - 000000000 _____ C:\Users\salty-san\AppData\Roaming\trace_FilterInstaller.txt-CRT.txt
2017-08-03 20:22 - 2017-08-10 09:48 - 000000919 _____ C:\Users\salty-san\AppData\Roaming\trace_FilterInstaller.1.txt
2017-08-03 20:22 - 2017-08-03 20:22 - 000001181 _____ C:\Users\salty-san\AppData\Roaming\trace_FilterInstaller.2.txt
2017-08-02 23:53 - 2017-08-02 23:53 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Koei
2017-08-02 23:51 - 2017-08-02 23:51 - 000000000 ____D C:\Users\salty-san\AppData\Roaming\InstallShield Installation Information
2017-08-01 14:43 - 2017-08-01 14:43 - 000000000 ____D C:\ProgramData\Apowersoft
2017-07-30 09:36 - 2017-07-30 09:36 - 000001241 _____ C:\Users\Public\Desktop\BlazBlue Continuum Shift Extend.lnk
2017-07-30 09:36 - 2017-07-30 09:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlazBlue Continuum Shift Extend
2017-07-26 18:49 - 2017-08-09 18:26 - 000000000 ____D C:\Users\salty-san\Documents\ARC SYSTEM WORKS
2017-07-26 18:38 - 2017-07-26 18:38 - 000001220 _____ C:\Users\Public\Desktop\BlazBlue - Calamity Trigger.lnk
2017-07-19 08:17 - 2017-07-19 08:17 - 000401584 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\avgBoot.exe
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-08-10 20:58 - 2009-07-14 08:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2017-08-10 20:57 - 2016-05-21 18:52 - 550383420 _____ C:\Windows\MEMORY.DMP
2017-08-10 20:57 - 2016-05-21 18:52 - 000000000 ____D C:\Windows\Minidump
2017-08-10 20:57 - 2015-11-01 23:10 - 000097264 _____ (Lenovo (Beijing) Limited) C:\Windows\system32\LenovoCheck.exe
2017-08-10 20:57 - 2015-11-01 23:10 - 000026608 _____ (Lenovo) C:\Windows\system32\LenovoUpdate.exe
2017-08-10 20:55 - 2009-07-14 07:45 - 000026352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-08-10 20:55 - 2009-07-14 07:45 - 000026352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-08-10 20:54 - 2017-03-22 10:28 - 000004178 _____ C:\Windows\System32\Tasks\Antivirus Emergency Update
2017-08-10 18:37 - 2016-05-04 16:47 - 000000000 ____D C:\TheIt
2017-08-10 18:22 - 2017-07-09 23:46 - 000000000 ____D C:\Program Files (x86)\NCH Software
2017-08-10 17:48 - 2016-02-10 21:08 - 000000000 ____D C:\Users\salty-san\Documents\Mount&Blade; Savegames
2017-08-10 16:51 - 2015-11-01 13:21 - 000000000 ____D C:\Users\salty-san
2017-08-10 16:49 - 2017-01-20 14:26 - 000000000 ____D C:\Users\salty-san\AppData\LocalLow\Mozilla
2017-08-10 16:35 - 2016-02-28 08:06 - 000000000 ____D C:\Users\salty-san\AppData\Local\Epic Privacy Browser
2017-08-10 16:17 - 2017-06-28 09:15 - 000000000 ____D C:\Windows\System32\Tasks\NCH Software
2017-08-10 16:12 - 2017-01-16 17:18 - 000000000 ___HD C:\Program Files (x86)\Temp
2017-08-10 16:11 - 2015-11-01 13:28 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2017-08-10 16:11 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\inf
2017-08-10 15:33 - 2015-11-05 14:53 - 000000000 ____D C:\Users\salty-san\Documents\OCTGN
2017-08-10 15:27 - 2016-06-02 19:07 - 000002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-08-10 15:27 - 2016-01-03 02:37 - 000002047 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk
2017-08-10 15:01 - 2016-05-03 22:51 - 000003942 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{F51745E5-CA05-4A07-82FD-E977DEA96A94}
2017-08-10 13:41 - 2017-01-18 15:19 - 000003600 _____ C:\Windows\System32\Tasks\AVG EUpdate Task
2017-08-10 03:14 - 2015-12-04 12:06 - 000000000 ____D C:\Users\salty-san\AppData\Roaming\vlc
2017-08-09 22:47 - 2016-02-08 00:58 - 000000000 ____D C:\Users\salty-san\AppData\Local\Eraser 6
2017-08-09 18:16 - 2009-07-14 08:13 - 000781298 _____ C:\Windows\system32\PerfStringBackup.INI
2017-08-08 08:39 - 2016-01-03 22:46 - 000000000 ____D C:\Users\salty-san\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2017-08-07 08:35 - 2009-07-14 08:08 - 000032592 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2017-08-04 14:48 - 2016-01-03 02:38 - 000004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2017-08-03 21:06 - 2016-02-18 17:23 - 000000400 __RSH C:\ProgramData\ntuser.pol
2017-08-03 20:33 - 2016-05-04 16:13 - 000000000 ____D C:\Users\salty-san\AppData\Roaming\SlimBrowser
2017-08-01 14:14 - 2017-02-01 17:27 - 000000000 ____D C:\Users\salty-san\AppData\Roaming\Apowersoft
2017-07-26 18:38 - 2016-02-10 20:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com
2017-07-26 18:38 - 2009-07-14 08:32 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2017-07-24 08:41 - 2017-05-10 14:13 - 000004040 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1494414816
2017-07-24 08:41 - 2017-05-10 14:13 - 000000000 ____D C:\Program Files\Opera
2017-07-23 21:21 - 2017-07-08 18:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Genie Soft
2017-07-23 21:21 - 2017-07-08 18:35 - 000000000 ____D C:\Users\salty-san\Documents\Mobogenie
2017-07-23 21:21 - 2017-07-08 18:35 - 000000000 ____D C:\Program Files (x86)\Mobogenie3
2017-07-20 09:52 - 2017-07-04 09:03 - 000000000 ____D C:\Users\salty-san\AppData\Local\Google
2017-07-20 09:52 - 2015-11-08 00:29 - 000000000 ____D C:\Program Files (x86)\Google
2017-07-19 08:18 - 2017-03-22 10:28 - 000139112 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgmonflt.sys
2017-07-19 08:17 - 2017-03-22 10:28 - 001008288 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgSnx.sys
2017-07-19 08:17 - 2017-03-22 10:28 - 000578048 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgSP.sys
2017-07-19 08:17 - 2017-03-22 10:28 - 000353744 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgVmm.sys
2017-07-19 08:17 - 2017-03-22 10:28 - 000336896 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgbloga.sys
2017-07-19 08:17 - 2017-03-22 10:28 - 000313616 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgbidsdrivera.sys
2017-07-19 08:17 - 2017-03-22 10:28 - 000192584 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgbidsha.sys
2017-07-19 08:17 - 2017-03-22 10:28 - 000191208 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgStm.sys
2017-07-19 08:17 - 2017-03-22 10:28 - 000166624 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgbdiska.sys
2017-07-19 08:17 - 2017-03-22 10:28 - 000139112 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgmonflt.sys.150044149958401
2017-07-19 08:17 - 2017-03-22 10:28 - 000102792 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgRdr2.sys
2017-07-19 08:17 - 2017-03-22 10:28 - 000076832 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgRvrt.sys
2017-07-19 08:17 - 2017-03-22 10:28 - 000051336 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgbuniva.sys
2017-07-19 08:17 - 2017-03-22 10:28 - 000039424 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgHwid.sys
2017-07-18 10:45 - 2017-04-06 13:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2017-07-18 10:45 - 2016-09-18 08:48 - 000001008 _____ C:\Users\Public\Desktop\AVG.lnk
==================== Files in the root of some directories =======
2016-03-13 14:21 - 2017-03-28 18:30 - 000000105 _____ () C:\Users\salty-san\AppData\Roaming\Camdata.ini
2016-03-13 14:21 - 2017-03-28 18:30 - 000000408 _____ () C:\Users\salty-san\AppData\Roaming\CamLayout.ini
2016-03-13 14:21 - 2017-03-28 18:30 - 000000408 _____ () C:\Users\salty-san\AppData\Roaming\CamShapes.ini
2016-03-13 14:21 - 2017-03-28 18:30 - 000004548 _____ () C:\Users\salty-san\AppData\Roaming\CamStudio.cfg
2017-08-03 20:22 - 2017-08-10 09:48 - 000000919 _____ () C:\Users\salty-san\AppData\Roaming\trace_FilterInstaller.1.txt
2017-08-03 20:22 - 2017-08-03 20:22 - 000001181 _____ () C:\Users\salty-san\AppData\Roaming\trace_FilterInstaller.2.txt
2017-08-03 20:22 - 2017-08-10 14:46 - 000001181 _____ () C:\Users\salty-san\AppData\Roaming\trace_FilterInstaller.txt
2017-08-03 20:22 - 2017-08-10 14:46 - 000000000 _____ () C:\Users\salty-san\AppData\Roaming\trace_FilterInstaller.txt-CRT.txt
2016-03-13 14:21 - 2017-03-28 18:29 - 000000096 _____ () C:\Users\salty-san\AppData\Roaming\version2.xml
2017-08-10 16:43 - 2017-08-10 16:43 - 000004608 _____ () C:\Users\salty-san\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2016-05-30 19:43 - 2017-01-30 10:02 - 000007607 _____ () C:\Users\salty-san\AppData\Local\Resmon.ResmonCfg
2017-06-28 09:02 - 2017-06-28 09:02 - 000000016 _____ () C:\ProgramData\mntemp
2017-06-28 09:02 - 2017-06-28 09:02 - 000004970 _____ () C:\ProgramData\nakuvtjg.ewu
Some files in TEMP:
====================
2017-03-01 18:50 - 2017-07-04 10:12 - 085152552 _____ (Avant Force) C:\Users\salty-san\AppData\Local\Temp\$avantbrowser$.update.exe
2017-04-22 17:29 - 2017-04-22 17:29 - 000036864 _____ () C:\Users\salty-san\AppData\Local\Temp\CmdLineExt02.dll
2017-04-22 17:29 - 2017-04-22 17:29 - 000012067 _____ () C:\Users\salty-san\AppData\Local\Temp\SIntf16.dll
2017-04-22 17:29 - 2017-04-22 17:29 - 000019924 _____ () C:\Users\salty-san\AppData\Local\Temp\SIntf32.dll
2017-04-22 17:29 - 2017-04-22 17:29 - 000024516 _____ () C:\Users\salty-san\AppData\Local\Temp\SIntfNT.dll
2017-03-13 04:08 - 2017-03-13 04:08 - 007682154 _____ () C:\Users\salty-san\AppData\Local\Temp\tmp153C.tmp.exe
2017-02-25 00:40 - 2017-02-25 00:40 - 007663397 _____ () C:\Users\salty-san\AppData\Local\Temp\tmp87E9.tmp.exe
2017-04-19 21:52 - 2016-04-04 02:19 - 000116796 _____ () C:\Users\salty-san\AppData\Local\Temp\Uninstall.exe
2007-09-22 00:33 - 2007-09-22 00:33 - 000456416 ____R (Macrovision Corporation) C:\Users\salty-san\AppData\Local\Temp\_is9530.exe
2007-09-22 00:33 - 2007-09-22 00:33 - 000456416 ____R (Macrovision Corporation) C:\Users\salty-san\AppData\Local\Temp\_isC2BA.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-08-01 01:00
==================== End of FRST.txt ============================