This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Sound Driver Died, Blue Screens, Cluttered and Cleanup! [Solved]

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I wanted to do a big cleanup before I start switching to a new machine and using this one for fewer things and therefore safer, but I had to try out various software for stuff, especially lately, so now it just feels very slowed down, cluttered and even starts up harder plus seems to take up more CPU.

 

One mobile stupid software came with a "cleaner" that keeps giving me popups and won't uninstall. There were several Blue Screens lately too ever since on this video recording software I had to set its audio paramaters. Something weird happened last uninstall and ruined my audio driver and now I have no sound from anywhere. Tried updates and manual reinstall and just doesn't work. Says in device manager that registry key for it is missing or corrupted.

 

Even now as I ran aswMBR it crashed/restarted 2 times, one that I witnessed with the blue screen. So in any case here are the logs…
 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2017-08-10 21:09:00
—————————–
21:09:00.450    OS Version: Windows x64 6.1.7601 Service Pack 1
21:09:00.450    Number of processors: 2 586 0x2A07
21:09:00.466    ComputerName: SALTYSKY  UserName: 
21:09:01.371    Initialize success
21:09:01.464    VM: initialized successfully
21:09:01.464    VM: Intel CPU supported 
21:09:03.742    VM: supported disk I/O iaStor.sys
21:09:21.510    The log file has been saved successfully to "C:\Users\salty-san\Desktop\mjnnjn.txt"
21:11:40.382    AVAST engine defs: 17030301
21:14:33.121    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
21:14:33.136    Disk 0 Vendor: TOSHIBA_ AM0Q Size: 476940MB BusType: 3
21:14:33.323    VM: Disk 0 MBR read successfully
21:14:33.339    Disk 0 MBR scan
21:14:33.355    Disk 0 Windows 7 default MBR code
21:14:33.370    Disk 0 Partition 1 00     07    HPFS/NTFS NTFS       351940 MB offset 256000000
21:14:33.401    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS       124999 MB offset 2048
21:14:33.401    Disk 0 Boot: NTFS     code=2
21:14:33.433    Disk 0 scanning C:\Windows\system32\drivers
21:14:53.026    Service scanning
21:15:26.005    Modules scanning
21:15:26.005    Disk 0 trace - called modules:
21:15:26.052    ntoskrnl.exe CLASSPNP.SYS disk.sys avgSP.sys ACPI.sys iaStor.sys hal.dll 
21:15:26.052    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004b59060]
21:15:26.052    3 avgSP.sys[fffff8800428e1d2] -> nt!IofCallDriver -> [0xfffffa8004762480]
21:15:26.052    5 ACPI.sys[fffff88000e0b7a1] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8004789050]
21:15:26.816    AVAST engine scan C:\Windows
21:15:29.328    AVAST engine scan C:\Windows\system32
21:21:08.971    AVAST engine scan C:\Windows\system32\drivers
21:21:44.508    AVAST engine scan C:\Users\salty-san
21:46:47.508    AVAST engine scan C:\ProgramData
21:48:54.462    Disk 0 statistics 5157955/0/18 @ 1.63 MB/s
21:48:54.477    Scan finished successfully
21:49:16.926    Disk 0 MBR has been saved successfully to "C:\Users\salty-san\Desktop\MBR.dat"
21:49:16.926    The log file has been saved successfully to "C:\Users\salty-san\Desktop\aswMBR.txt"
 
 
 
ADDITION is next and the longest.
 
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 09-08-2017
Ran by [removed] (10-08-2017 21:02:41)
Running from C:\Users\[removed]\Desktop
Windows 7 Ultimate Service Pack 1 (X64) (2015-11-01 10:20:21)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-384921765-1548902971-3406650631-500 - Administrator - Disabled)
Guest (S-1-5-21-384921765-1548902971-3406650631-501 - Limited - Disabled)
salty-san (S-1-5-21-384921765-1548902971-3406650631-1000 - Administrator - Enabled) => C:\Users\salty-san
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: AVG Antivirus (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG Antivirus (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}
FW: ZoneAlarm Free Firewall Firewall (Enabled) {1B8D532F-88B1-B2AD-ED22-AED92687A1D2}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
7-Zip 15.12 (x64) (HKLM\…\7-Zip) (Version: 15.12 - Igor Pavlov)
7-Zip 15.14 (x64 edition) (HKLM\…\{23170F69-40C1-2702-1514-000001000000}) (Version: 15.14.00.0 - Igor Pavlov)
Adobe Acrobat Reader DC (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.016.20039 - Adobe Systems Incorporated)
AirDroid 3.4.1.0 (HKLM-x32\…\AirDroid) (Version: 3.4.1.0 - Sand Studio)
Apowersoft Online Launcher version 1.6.0 (HKLM-x32\…\{20BF67A8-D81A-4489-8225-FABAA0896E2D}_is1) (Version: 1.6.0 - APOWERSOFT LIMITED)
Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\…\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.12.5.0 - Asmedia Technology)
Avant Browser (remove only) (HKLM-x32\…\AvantBrowser) (Version: 12.5.0.0 - Avant Force)
AVG (HKLM\…\{434FBA38-0562-4F98-9436-4B45C0C0EF0B}) (Version: 1.201.2 - AVG Technologies) Hidden
AVG AntiVirus FREE (HKLM-x32\…\AVG Antivirus) (Version: 17.5.3022 - AVG Technologies)
Avidemux 2.6 - 64 bits (HKLM-x32\…\Avidemux 2.6 - 64 bits (64-bit)) (Version: 2.6.12.160304 - )
Battlefield Vietnam(TM) (HKLM-x32\…\{E35B3C63-E958-4E31-A178-95D22024109A}) (Version:  - )
BlazBlue -  Calamity Trigger (HKLM-x32\…\GOGPACKBLAZBLUECT_is1) (Version: 2.0.0.3 - GOG.com)
BlazBlue: Chronophantasma Extend (HKLM\…\YmxhemJsdWVjaHJvbm9waGFudGFzbWFleHRlbmQ_is1) (Version: 1 - )
BlazBlue: Continuum Shift Extend (HKLM-x32\…\BlazBlue: Continuum Shift Extend_is1) (Version:  - H2 Interactive Co., Ltd.)
CamStudio 2.7.4 (HKLM\…\{04B83666-3A62-452B-85D3-70F8117F2329}_is1) (Version: 2.7.4 - CamStudio Open Source)
Canon MP180 (HKLM\…\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP180) (Version:  - )
Cheatbook Database 2016 (HKLM-x32\…\Cheatbook Database 2016) (Version:  - )
Cisco EAP-FAST Module (HKLM-x32\…\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\…\{AF312B06-5C5C-468E-89B3-BE6DE2645722}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\…\{0A4EF0E6-A912-4CDE-A7F3-6E56E7C13A2F}) (Version: 1.1.6 - Cisco Systems, Inc.)
Command And Conquer Red Alert 2 Yuri's Revenge 1.001 (HKLM-x32\…\Command_And_Conquer_Yuri's_Revenge_1.001_MPI) (Version:  - )
Comodo Dragon (HKLM-x32\…\Comodo Dragon) (Version: 52.15.25.664 - Comodo)
DuelystLauncher (HKU\S-1-5-21-384921765-1548902971-3406650631-1000\…\launcher) (Version: 0.010 - Counterplay Games Inc.)
Dynasty Warriors 4 Hyper (HKU\S-1-5-21-384921765-1548902971-3406650631-1000\…\{DBFF7A38-F460-419A-A2E7-2D55BD2D9AD4}) (Version:  - )
Enigma Virtual Box v7.40 Build 20160125 (HKLM-x32\…\Enigma Virtual Box_is1) (Version:  - The Enigma Protector Developers Team)
Epic Privacy Browser (HKU\S-1-5-21-384921765-1548902971-3406650631-1000\…\Epic) (Version: 58.0.3300.190 - Epic)
Eraser 6.2.0.2970 (HKLM\…\{58F37E51-2A83-49F3-9117-6005C63CF399}) (Version: 6.2.2970 - The Eraser Project)
ESET Online Scanner v3 (HKLM-x32\…\ESET Online Scanner) (Version:  - )
ETDWare PS/2-X64 8.0.5.1_WHQL (HKLM\…\Elantech) (Version: 8.0.5.1 - ELAN Microelectronic Corp.)
Ezvid (HKLM-x32\…\{F96D619D-99D6-4C9C-A393-0CD22DE1CA66}_is1) (Version: 1.004 - Ezvid, inc.)
FlashPeak SlimBrowser (HKLM-x32\…\SlimBrowser) (Version: 7.00.143 - FlashPeak Inc.)
FlashRip(Full Version) (HKLM-x32\…\FlashRip(Full Version)_is1) (Version:  - )
FlatOut 2 (HKLM-x32\…\{4E6D2462-AB33-40BB-AA9F-3FA3E0DD0290}) (Version: 1.00.0000 - Empire Interactive)
FMW 1 (HKLM\…\{1DA9CD4A-687F-4075-A828-0A3ACB901438}) (Version: 1.222.1 - AVG Technologies) Hidden
foobar2000 v1.3.9 (HKLM-x32\…\foobar2000) (Version: 1.3.9 - Peter Pawlowski)
Fraps (remove only) (HKLM-x32\…\Fraps) (Version:  - )
Free Virtual Keyboard 3.0.1.0 (HKLM-x32\…\{CA4F9519-1A83-4907-8651-F17073A0E1CE}_is1) (Version: 3.0 - Comfort Software Group)
FreeUndelete 2.1.36867.1 (HKLM-x32\…\{0F5ADA2F-C0B2-4AD6-8FF7-7DFA9D6B4CBA}) (Version: 2.1.36867.1 - Recoveronix)
FTP Manager Lite 2 (HKLM-x32\…\FTP Manager Lite_is1) (Version:  - DeskShare Inc.)
Getleft v1.2 (HKLM-x32\…\Getleft_is1) (Version:  - )
Glary Undelete 5.0.1.19 (HKLM-x32\…\Glary Undelete) (Version: 5.0.1.19 - Glarysoft Ltd)
GPGNet (HKLM-x32\…\{C194D333-B84A-4BB7-B35E-060732D98DC4}) (Version: 1.0.0 - Gas Powered Games)
Hero Editor V1.04 (HKLM-x32\…\ST6UNST #1) (Version:  - )
Hextech Repair Tool (HKLM-x32\…\{7F9A97E6-E666-11E5-B582-B88687E82322}) (Version: 1.1.15 - Riot Games, Inc.)
Intel(R) Control Center (HKLM-x32\…\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2476 - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\…\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 3.0.0.33 - Intel Corporation)
IrfanView 64 (remove only) (HKLM\…\IrfanView64) (Version: 4.41 - Irfan Skiljan)
League of Legends (HKLM-x32\…\{E80C09B5-A296-47E9-BD4B-BCCF2FDCA13E}) (Version: 4.1.2 - Riot Games) Hidden
League of Legends (HKLM-x32\…\League of Legends 4.1.2) (Version: 4.1.2 - Riot Games)
LinuxLive USB Creator (HKLM-x32\…\LinuxLive USB Creator) (Version: 2.9 - Thibaut Lauziere)
Maxthon App Store (HKLM-x32\…\Maxthon App Store 1.1.0.10848) (Version: 1.1.0.10848 - Maxthon, Inc.)
Maxthon Cloud Browser (HKLM-x32\…\Maxthon3) (Version: 4.9.2.1000 - Maxthon International Limited)
Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\…\{56E962F0-4FB0-3C67-88DB-9EAA6EEFC493}) (Version: 4.5.50710 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (ENU) (HKLM-x32\…\{D3517C62-68A5-37CF-92F7-93C029A89681}) (Version: 4.5.50932 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (HKLM-x32\…\{6A0C6700-EA93-372C-8871-DCCF13D160A4}) (Version: 4.5.50932 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 SDK (HKLM-x32\…\{19A5926D-66E1-46FC-854D-163AA10A52D3}) (Version: 4.5.51641 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (ENU) (HKLM-x32\…\{290FC320-2F5A-329E-8840-C4193BD7A9EE}) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (HKLM-x32\…\{B941AFB4-8851-33A1-9E72-0C33D463C41C}) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.6.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft Help Viewer 2.2 (HKLM-x32\…\Microsoft Help Viewer 2.2) (Version: 2.2.23107 - Microsoft Corporation)
Microsoft Office Professional Plus 2013 (HKLM\…\Office15.PROPLUS) (Version: 15.0.4420.1017 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\…\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (HKLM\…\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\…\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\…\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\…\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23026 (HKLM-x32\…\{e46eca4f-393b-40df-9f49-076faf788d83}) (Version: 14.0.23026.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23506 (HKLM-x32\…\{23daf363-3020-4059-b3ae-dc4ad39fed19}) (Version: 14.0.23506.0 - Microsoft Corporation)
Microsoft Visual J# 2.0 Redistributable Package (HKLM-x32\…\Microsoft Visual J# 2.0 Redistributable Package) (Version:  - Microsoft Corporation)
Microsoft Visual Studio 2015 Shell (Isolated) (HKLM-x32\…\{d2981c27-a434-4c9a-96c7-0209e97c4eac}) (Version: 14.0.23107.10 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2015 (HKLM-x32\…\{ab213ab7-4792-4c6f-a3fa-8485d06c3475}) (Version: 14.0.23829 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2015 Language Support (HKLM-x32\…\{353253a9-15a3-4727-b415-79b4e6be765e}) (Version: 14.0.23107.10 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\…\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation)
Mount and Blade (HKLM-x32\…\1207666893_is1) (Version: 2.0.0.4 - GOG.com)
Movavi Screen Capture 8 (HKLM-x32\…\Movavi Screen Capture 8) (Version: 8.6.0 - Movavi)
Mozilla Firefox 54.0.1 (x64 en-US) (HKLM\…\Mozilla Firefox 54.0.1 (x64 en-US)) (Version: 54.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\…\MozillaMaintenanceService) (Version: 53.0.2 - Mozilla)
MPC-HC 1.7.10 (64-bit) (HKLM\…\{2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1) (Version: 1.7.10 - MPC-HC Team)
MyDefrag v4.3.1 (HKLM\…\MyDefrag v4.3.1_is1) (Version: 4.0.0.0 - J.C. Kessels)
One Finger Death Punch 1.0 (HKLM-x32\…\One Finger Death Punch 1.0) (Version: 1.0 - Cat-A-Cat)
Opera Stable 46.0.2597.57 (HKU\S-1-5-21-384921765-1548902971-3406650631-1000\…\Opera 46.0.2597.57) (Version: 46.0.2597.57 - Opera Software)
Oracle VM VirtualBox 5.1.0 (HKLM\…\{0C801AA7-A02E-4DCF-BD09-0EACB11D9863}) (Version: 5.1.0 - Oracle Corporation)
Outils de vérification linguistique 2013 de Microsoft Office - Français (HKLM\…\{90150000-001F-040C-1000-0000000FF1CE}) (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Panda Cloud Cleaner (HKLM-x32\…\{92B2B132-C7F0-43DC-921A-4493C04F78A4}_is1) (Version: 1.1.9 - Panda Security)
PCSX2 - Playstation 2 Emulator (HKLM-x32\…\pcsx2) (Version:  - )
PowerISO (HKLM-x32\…\PowerISO) (Version: 6.3 - Power Software Ltd)
Puran File Recovery 1.2 (HKLM\…\Puran File Recovery_is1) (Version:  - Puran Software)
Qualcomm Atheros WiFi Driver Installation (HKLM-x32\…\{7D916FA5-DAE9-4A25-B089-655C70EAF607}) (Version: 9.2 - Qualcomm Atheros)
Realtek Card Reader (HKLM-x32\…\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.9600.29084 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.92.115.2015 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6454 - Realtek Semiconductor Corp.)
REALTEK Wireless LAN Driver (HKLM-x32\…\{9DAABC60-A5EF-41FF-B2B9-17329590CD5}) (Version: 1.00.0263 - REALTEK Semiconductor Corp.)
Revo Uninstaller 1.95 (HKLM-x32\…\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
RMPrepUSB (HKLM-x32\…\RMPrepUSB) (Version:  - )
Roslyn Language Services - x86 (HKLM-x32\…\{5B47029B-1E62-30FF-906E-694851C22782}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
Roslyn Language Services - x86 (HKLM-x32\…\{6C1985E7-E1C5-3A95-86EF-2C62465F15C3}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
SAMSUNG USB Driver for Mobile Phones (HKLM\…\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.3.450.0 - SAMSUNG Electronics Co., Ltd.)
SeaMonkey 2.46 (x86 en-US) (HKLM-x32\…\SeaMonkey 2.46 (x86 en-US)) (Version: 2.46 - Mozilla)
Sonic Focus (HKLM-x32\…\{09BCB9CE-964B-4BDA-AE46-B5A0ABEF1D3F}) (Version: 1.0.0.4 - Synopsys )
Star wars Battlefront II version 1.3 (HKLM-x32\…\{2EF34761-F147-4984-8AF1-BB9F8DA76CDD}_is1) (Version: 1.3 - )
Streaming Video Recorder V6.1.7 (HKLM-x32\…\{01c39b1f-d465-48ca-9d71-7d5afa53b4eb}_is1) (Version: 6.1.7 - APOWERSOFT LIMITED)
Supreme Commander - Forged Alliance (HKLM-x32\…\{31D95937-B237-405D-920C-A3EF4E482395}) (Version: 1.00.0000 - Gas Powered Games)
SWF File Player (HKLM-x32\…\{6A86F611-906C-422D-B34A-103662CBC195}_is1) (Version:  - swffileplayer.com)
Time Travel Browser (HKLM-x32\…\Time Travel Browser) (Version: 1.0.0 - LuksSoftware)
Torchlight (HKLM-x32\…\GOGPACKTORCHLIGHT_is1) (Version: 2.0.0.12 - GOG.com)
Tweaking.com - Registry Backup (HKLM-x32\…\Tweaking.com - Registry Backup) (Version: 3.3.1 - Tweaking.com)
UndeleteMyFiles Pro (HKLM-x32\…\UndeleteMyFiles Pro_is1) (Version:  - SeriousBit)
Unity Web Player (HKU\S-1-5-21-384921765-1548902971-3406650631-1000\…\UnityWebPlayer) (Version: 5.3.7f1 - Unity Technologies ApS)
Universal Adb Driver (HKLM-x32\…\{D9C4202E-6D51-4B06-A8F1-22316E654BCA}) (Version: 1.0.0 - ClockworkMod)
Unknown File Handler (HKLM-x32\…\UFH_is1) (Version: 2015.12.29.0 - File.org)
Update for  (KB2504637) (HKLM-x32\…\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation)
UpdateReminder 1.2017.4.14 (HKLM-x32\…\UpdateReminder_is1) (Version:  - eSupport.com, Inc)
Video Download Capture V6.2.1 (HKLM-x32\…\{b3336f66-e079-4ff6-abdb-51e2fab781d5}_is1) (Version: 6.2.1 - APOWERSOFT LIMITED)
Visual Studio 2012 x64 Redistributables (HKLM\…\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\…\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VLC media player (HKLM-x32\…\VLC media player) (Version: 2.2.1 - VideoLAN)
Wampserver64 3.0.6 (HKLM\…\{wampserver64}_is1) (Version: 3.0.6 - Dominique Ottello aka Otomatic)
Warcraft III (HKLM-x32\…\Warcraft III) (Version:  - Blizzard Entertainment)
Warcraft III: All Products (HKU\S-1-5-21-384921765-1548902971-3406650631-1000\…\Warcraft III) (Version:  - )
Warhammer 40,000 - Storm of Vengeance (HKLM-x32\…\Warhammer 40,000 - Storm of Vengeance_is1) (Version: Warhammer 40,000 - Storm of Vengeance - Eutechnyx)
WebReaper v10 (HKLM-x32\…\WebReaper_is1) (Version: 10b - WebReaper.net)
Winamp (HKLM-x32\…\Winamp) (Version: 5.666  - Nullsoft, Inc)
Windows Driver Package - Google, Inc. (WinUSB) AndroidUsbDeviceClass  (08/28/2014 11.0.0000.00000) (HKLM\…\092555911492C6959D2596D612F52DCA71881CA2) (Version: 08/28/2014 11.0.0000.00000 - Google, Inc.)
WinPcap 4.1.3 (HKLM-x32\…\WinPcapInst) (Version: 4.1.0.2980 - Riverbed Technology, Inc.)
WinRAR 5.21 (64-bit) (HKLM\…\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH)
WinToUSB version 2.8 (HKLM\…\WinToUSB_is1) (Version: 2.8 - The EasyUEFI Development Team.)
Wondershare MobileGo(Version 8.2.3) (HKLM-x32\…\{1E04C795-7359-4E05-8A0E-5644F777AA09}_is1) (Version: 8.2.3 - Wondershare)
YouTube Video Ripper 2.90 (HKLM-x32\…\YouTube Video Ripper_is1) (Version:  - YoutubeGetting.com)
ZoneAlarm Firewall (HKLM-x32\…\{85819737-D33F-49F2-AFF0-EBD643428AA4}) (Version: 15.0.123.17051 - Check Point Software Technologies Ltd.) Hidden
ZoneAlarm Free Firewall (HKLM-x32\…\ZoneAlarm Free Firewall) (Version: 15.0.123.17051 - Check Point)
ZoneAlarm Security (HKLM-x32\…\{BC26330A-F6A0-40F1-B521-896E79FB7372}) (Version: 15.0.123.17051 - Check Point Software Technologies Ltd.) Hidden
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-384921765-1548902971-3406650631-1000_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\Windows\system32\igfxEM.exe (Intel Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2015-12-31] (Igor Pavlov)
ContextMenuHandlers1: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files (x86)\AVG\Antivirus\ashShA64.dll [2017-07-19] (AVG Technologies CZ, s.r.o.)
ContextMenuHandlers1: [Eraser] -> {BC9B776A-90D7-4476-A791-79D835F30650} => C:\Program Files\Eraser\Eraser.Shell.dll [2015-09-03] (The Eraser Project)
ContextMenuHandlers1: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => C:\Program Files\PowerISO\PWRISOSH.DLL [2015-07-23] (Power Software Ltd)
ContextMenuHandlers1: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAShell.dll -> No File
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2015-02-16] (Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2015-02-16] (Alexander Roshal)
ContextMenuHandlers2: [Eraser] -> {BC9B776A-90D7-4476-A791-79D835F30650} => C:\Program Files\Eraser\Eraser.Shell.dll [2015-09-03] (The Eraser Project)
ContextMenuHandlers3: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ContextMenuHandlers3: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2015-12-31] (Igor Pavlov)
ContextMenuHandlers4: [Eraser] -> {BC9B776A-90D7-4476-A791-79D835F30650} => C:\Program Files\Eraser\Eraser.Shell.dll [2015-09-03] (The Eraser Project)
ContextMenuHandlers4: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => C:\Program Files\PowerISO\PWRISOSH.DLL [2015-07-23] (Power Software Ltd)
ContextMenuHandlers5: [Eraser] -> {BC9B776A-90D7-4476-A791-79D835F30650} => C:\Program Files\Eraser\Eraser.Shell.dll [2015-09-03] (The Eraser Project)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\Windows\system32\igfxpph.dll [2011-09-16] (Intel Corporation)
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\Windows\system32\igfxDTCM.dll [2014-10-10] (Intel Corporation)
ContextMenuHandlers5: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAShell.dll -> No File
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2015-12-31] (Igor Pavlov)
ContextMenuHandlers6: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files (x86)\AVG\Antivirus\ashShA64.dll [2017-07-19] (AVG Technologies CZ, s.r.o.)
ContextMenuHandlers6: [Eraser] -> {BC9B776A-90D7-4476-A791-79D835F30650} => C:\Program Files\Eraser\Eraser.Shell.dll [2015-09-03] (The Eraser Project)
ContextMenuHandlers6: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => C:\Program Files\PowerISO\PWRISOSH.DLL [2015-07-23] (Power Software Ltd)
ContextMenuHandlers6: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAShell.dll -> No File
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2015-02-16] (Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2015-02-16] (Alexander Roshal)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {06CFA027-1C9B-4AD6-BB7F-E11546E6153E} - System32\Tasks\Opera scheduled Autoupdate 1494414816 => C:\Program Files\Opera\launcher.exe [2017-07-18] (Opera Software)
Task: {0C38AE2D-18A0-48F0-B68B-E17B888171DD} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2017-08-01] (AVAST Software)
Task: {3261E316-AFD8-4063-A2CC-389DED3A5B4F} - System32\Tasks\AVG EUpdate Task => avgsetupx.exe
Task: {439ADCDD-9069-427F-BA0A-FDAB1AD5F6DA} - System32\Tasks\{229E9532-8EC8-4310-8097-EDD225B446C7} => C:\Windows\system32\pcalua.exe -a C:\Users\salty-san\Desktop\unetbootin-windows-613.exe -d C:\Users\salty-san\Desktop
Task: {46878AA7-1AA3-4113-BEB4-F039108AF39F} - System32\Tasks\MyDefrag v4.3.1 Daily => C:\Program Files\MyDefrag v4.3.1\Scripts\AutomaticDaily.MyD [2010-05-21] ()
Task: {774096DF-72C1-4134-B9CE-EB898AFAC4E3} - System32\Tasks\Antivirus Emergency Update => C:\Program Files (x86)\AVG\Antivirus\AvEmUpdate.exe [2017-07-19] (AVG Technologies CZ, s.r.o.)
Task: {A819E346-DD87-49B7-8F95-90430AFBC631} - System32\Tasks\Maxthon Update => C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe [2017-05-31] (Maxthon International ltd.)
Task: {AC9B9D29-42CD-43AB-861C-6B9198CD59AB} - System32\Tasks\{838A64F0-1784-412C-A1A1-DAC18FC1209B} => C:\Program Files (x86)\Command And Conquer Red Alert 2 Yuri's Revenge\RA2MD.exe [2001-08-23] ()
Task: {C673A044-1E70-4CC0-85C5-F079F0C6596C} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation)
Task: {CA4A6E7F-6B77-414B-B595-97CDD1B0B259} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2012-10-01] (Microsoft Corporation)
Task: {CE4E4352-61BE-4AEA-B41F-74A61CC1BA25} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation)
Task: {E4DD8000-2703-4934-A02B-75252ABFE56C} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-07-19] (Adobe Systems Incorporated)
Task: {E5DBA818-1F9F-4B43-AC1E-570F51A6036D} - System32\Tasks\MyDefrag v4.3.1 Monthly => C:\Program Files\MyDefrag v4.3.1\Scripts\AutomaticMonthly.MyD [2010-05-21] ()
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
 
==================== Loaded Modules (Whitelisted) ==============
 
2012-10-01 21:36 - 2012-10-01 21:36 - 006522480 _____ () C:\Program Files\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2017-05-13 11:39 - 2017-05-13 11:39 - 000163152 _____ () c:\Program Files (x86)\AVG\Antivirus\x64\vaarclient.dll
2017-07-03 20:55 - 2017-07-03 20:55 - 000832784 _____ () C:\Program Files (x86)\AVG\Antivirus\x64\ffl2.dll
2017-07-03 20:55 - 2017-07-03 20:55 - 000277416 _____ () c:\Program Files (x86)\AVG\Antivirus\x64\StreamBack.dll
2015-11-01 13:28 - 2014-10-10 11:45 - 000094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2017-05-13 11:39 - 2017-05-13 11:39 - 000171344 _____ () C:\Program Files (x86)\AVG\Antivirus\JsonRpcServer.dll
2017-07-03 20:55 - 2017-07-03 20:55 - 000193784 _____ () C:\Program Files (x86)\AVG\Antivirus\event_routing_rpc.dll
2017-07-03 20:55 - 2017-07-03 20:55 - 000225376 _____ () C:\Program Files (x86)\AVG\Antivirus\tasks_core.dll
2017-08-10 09:52 - 2017-08-10 09:52 - 005890008 _____ () C:\Program Files (x86)\AVG\Antivirus\defs\17081000\algo.dll
2017-07-03 20:55 - 2017-07-03 20:55 - 000690392 _____ () C:\Program Files (x86)\AVG\Antivirus\ffl2.dll
2017-07-03 20:55 - 2017-07-03 20:55 - 000232784 _____ () C:\Program Files (x86)\AVG\Antivirus\streamback.dll
2015-02-06 06:31 - 2015-02-06 06:31 - 000050840 _____ () C:\Program Files (x86)\Genie Soft\Genie Cleaner\MGCommon.dll
2017-01-18 15:19 - 2017-01-18 15:18 - 048920064 _____ () C:\Program Files (x86)\AVG\UiDll\2623\libcef.dll
2017-07-19 08:17 - 2017-07-19 08:17 - 001067056 _____ () C:\Program Files (x86)\AVG\Antivirus\AvChrome.dll
2017-07-03 20:55 - 2017-07-03 20:55 - 067109376 _____ () C:\Program Files (x86)\AVG\Antivirus\libcef.dll
2013-12-13 05:47 - 2013-12-13 05:47 - 000333824 _____ () C:\Program Files (x86)\Winamp\Plugins\freeform\wacs\freetype\freetype.wac
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vsmon => ""="Service"
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-14 05:34 - 2016-07-18 09:56 - 000000035 _____ C:\Windows\system32\Drivers\etc\hosts
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-384921765-1548902971-3406650631-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\salty-san\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: Media is not connected to internet.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is disabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{01DD5918-283F-4F3C-AC26-AF593412DF9F}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{508DDC13-5096-41A1-BE2C-A24C77183C13}] => (Block) D:\WASTELAND!\Wasteland 2 Directors Cut\Build\WL2.exe
FirewallRules: [TCP Query User{EEB53623-0283-483F-B645-04DD48C46786}C:\users\salty-san\documents\octgn\octgn\octgn.exe] => (Allow) C:\users\salty-san\documents\octgn\octgn\octgn.exe
FirewallRules: [UDP Query User{14C2698F-42A4-41BB-9169-2211FDC0ECB1}C:\users\salty-san\documents\octgn\octgn\octgn.exe] => (Allow) C:\users\salty-san\documents\octgn\octgn\octgn.exe
FirewallRules: [TCP Query User{DF6BC443-CABE-4E5A-9F0E-F4C4A78535F6}C:\users\salty-san\documents\octgn\octgn\octgn.exe] => (Allow) C:\users\salty-san\documents\octgn\octgn\octgn.exe
FirewallRules: [UDP Query User{0D9DECF9-7EE8-4932-81B6-5AA519CD2957}C:\users\salty-san\documents\octgn\octgn\octgn.exe] => (Allow) C:\users\salty-san\documents\octgn\octgn\octgn.exe
FirewallRules: [{F89C0384-F502-44A5-B00A-9826C8B9E172}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{BB9DFD0F-5CC0-4A92-A4C5-E4DE9031F0C6}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{19FBF323-28DA-4563-9196-790954D5F72D}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{5D4FF2EB-07A6-4F96-AFF0-58616E255410}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{95B66243-C6D0-4B85-90F6-547B69CE822E}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{BCFAED00-B5EE-4558-AFC6-E54BC68D9562}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [TCP Query User{B247EA9C-0A1B-4E95-8AC0-562403FC4950}C:\users\salty-san\documents\octgn\octgn\octgn.online.standaloneserver.exe] => (Allow) C:\users\salty-san\documents\octgn\octgn\octgn.online.standaloneserver.exe
FirewallRules: [UDP Query User{260782A1-34CD-4BA2-9F89-72C24BA3BF7B}C:\users\salty-san\documents\octgn\octgn\octgn.online.standaloneserver.exe] => (Allow) C:\users\salty-san\documents\octgn\octgn\octgn.online.standaloneserver.exe
FirewallRules: [TCP Query User{AD90B0F5-5A10-4C62-A7A3-3CBA144F4692}D:\playboard\call of duty 2  full game  mp - sp  -=aviara=-\call of duty 2\cod2mp_s.exe] => (Block) D:\playboard\call of duty 2  full game  mp - sp  -=aviara=-\call of duty 2\cod2mp_s.exe
FirewallRules: [UDP Query User{E45AB548-5CA2-49FC-BCAA-420157AA80F9}D:\playboard\call of duty 2  full game  mp - sp  -=aviara=-\call of duty 2\cod2mp_s.exe] => (Block) D:\playboard\call of duty 2  full game  mp - sp  -=aviara=-\call of duty 2\cod2mp_s.exe
FirewallRules: [{9D79CD9D-1138-4471-9107-72DC3CDE88B1}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{3BFEB175-5043-44EA-B2C6-7D52F51741EE}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{2E2BBFA3-FB0B-479D-85AD-963E99B02215}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{2BEE2144-B70C-4420-BC9E-5A25585FF686}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{05C545A5-8C9C-41C3-B89E-E65D6D8A0192}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
FirewallRules: [{E91111AF-B2E6-4408-A180-D898C8699190}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
FirewallRules: [TCP Query User{69F0FD99-0EC7-4032-A241-6D327E2A6239}C:\users\salty-san\documents\octgn\octgn\octgn.online.standaloneserver.exe] => (Allow) C:\users\salty-san\documents\octgn\octgn\octgn.online.standaloneserver.exe
FirewallRules: [UDP Query User{68EFF557-0A01-48DF-ADF5-F95A6BCF5C2F}C:\users\salty-san\documents\octgn\octgn\octgn.online.standaloneserver.exe] => (Allow) C:\users\salty-san\documents\octgn\octgn\octgn.online.standaloneserver.exe
FirewallRules: [TCP Query User{78AF15E1-CC17-4FE7-BDCE-5427620D4861}D:\zergoth!\the minks!\portable\mirc\mirc.exe] => (Allow) D:\zergoth!\the minks!\portable\mirc\mirc.exe
FirewallRules: [UDP Query User{36A39718-5949-41EE-93B6-6318ACE5812B}D:\zergoth!\the minks!\portable\mirc\mirc.exe] => (Allow) D:\zergoth!\the minks!\portable\mirc\mirc.exe
FirewallRules: [TCP Query User{4CDB7BB9-A122-4B17-BA93-EF671730BED0}D:\playboard\duel masters civilization!\duelmasters\duelmasters.exe] => (Allow) D:\playboard\duel masters civilization!\duelmasters\duelmasters.exe
FirewallRules: [UDP Query User{9EDB7F0F-B21C-4096-9A73-82A834AABA6D}D:\playboard\duel masters civilization!\duelmasters\duelmasters.exe] => (Allow) D:\playboard\duel masters civilization!\duelmasters\duelmasters.exe
FirewallRules: [{4C549C43-8769-43DD-9C4C-D832FAD6EA76}] => (Block) D:\playboard\duel masters civilization!\duelmasters\duelmasters.exe
FirewallRules: [{EAC4EBEF-0920-44DC-BE2C-0C1DE5FD23B7}] => (Block) D:\playboard\duel masters civilization!\duelmasters\duelmasters.exe
FirewallRules: [{7EC18199-F2F4-4E81-808E-B4AF8C069627}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe
FirewallRules: [{4051053A-8CCA-4822-B6DF-EB780F910B61}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe
FirewallRules: [{D42F9D68-6F43-4682-B3ED-C973FE575538}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe
FirewallRules: [{2478CB98-BB64-4FA9-842C-5FC7598BD6DB}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe
FirewallRules: [{1EE51A2D-F50E-4993-A34B-65E5CE39866A}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe
FirewallRules: [{F5DD2F8C-BC93-471C-9078-4D647E90DCE4}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe
FirewallRules: [{616F09ED-6DEE-4DB2-B541-38366AAC8A1C}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe
FirewallRules: [{C3F233A1-A686-4A64-9179-318E8C697C57}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe
FirewallRules: [TCP Query User{947EFFAD-F69E-4185-AC31-C5B988C9D459}C:\gog games\impossible creatures\ic.exe] => (Allow) C:\gog games\impossible creatures\ic.exe
FirewallRules: [UDP Query User{350CBCCF-86C4-4DD0-9F00-93692E8138D8}C:\gog games\impossible creatures\ic.exe] => (Allow) C:\gog games\impossible creatures\ic.exe
FirewallRules: [TCP Query User{6D711751-94CC-4740-8736-2AC7042FB237}C:\program files (x86)\command and conquer red alert 2 yuri's revenge\gamemd.exe] => (Allow) C:\program files (x86)\command and conquer red alert 2 yuri's revenge\gamemd.exe
FirewallRules: [UDP Query User{E7B29111-52F7-477F-B24A-5224F4BE11E8}C:\program files (x86)\command and conquer red alert 2 yuri's revenge\gamemd.exe] => (Allow) C:\program files (x86)\command and conquer red alert 2 yuri's revenge\gamemd.exe
FirewallRules: [{6C4DF875-2630-426C-BE46-04D1E8A0F790}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{23217DC7-B15A-47EE-8489-28C05A8C9AB4}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{01236CE6-09FC-4F0A-A6C6-B7B8A8073E42}] => (Allow) C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe
FirewallRules: [{116FBB49-70D1-4D4E-A2CA-F8C18B04A33A}] => (Allow) C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe
FirewallRules: [{359AE9CA-9C0E-42CF-8D17-1999E507C96E}] => (Allow) C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe
FirewallRules: [{68CE8494-D98E-4431-9953-BEBE55599E4A}] => (Allow) C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe
FirewallRules: [{E275E889-4E5B-4C75-A274-D510BA3F7900}] => (Allow) C:\Users\salty-san\AppData\Local\Apowersoft\Apowersoft Online Launcher\Apowersoft Online Launcher.exe
FirewallRules: [{7A764B84-AD36-4946-8897-4EE1A3C2BC4D}] => (Allow) C:\Users\salty-san\AppData\Local\Apowersoft\Apowersoft Online Launcher\Apowersoft Online Launcher.exe
FirewallRules: [{CE859985-D3D1-4BE0-A165-986E267E1EDC}] => (Allow) C:\Program Files (x86)\Apowersoft\Video Download Capture 6\Video Download Capture 6.exe
FirewallRules: [{7C8920A4-9C1B-401F-891D-831B9583BB7D}] => (Allow) C:\Program Files (x86)\Apowersoft\Video Download Capture 6\Video Download Capture 6.exe
FirewallRules: [{5E30974E-B7B4-446C-996E-35AF012E563B}] => (Allow) C:\Program Files (x86)\Apowersoft\Video Download Capture 6\rtmpsrv.exe
FirewallRules: [{39CB306C-1EB4-4A68-80D6-15914471CD1E}] => (Allow) C:\Program Files (x86)\Apowersoft\Video Download Capture 6\rtmpsrv.exe
FirewallRules: [{D7CCC354-351E-412D-822E-2E6D3A6827C9}] => (Allow) D:\StallINS\GAMES!\Supreme\Supreme Commander - Forged Alliance\bin\ForgedAlliance.exe
FirewallRules: [{34DD22FE-120E-45B9-93FA-31D597BEACE0}] => (Allow) D:\StallINS\GAMES!\Supreme\Supreme Commander - Forged Alliance\bin\ForgedAlliance.exe
FirewallRules: [{51EE86B5-AFA1-4182-9AE5-D740067626D5}] => (Allow) D:\StallINS\GAMES!\Supreme\GPGNet\GPG.Multiplayer.Client.exe
FirewallRules: [{85FF2AF4-E435-49B3-BDC8-38BC684CC484}] => (Allow) D:\StallINS\GAMES!\Supreme\GPGNet\GPG.Multiplayer.Client.exe
FirewallRules: [{93202B76-48DA-4BAE-9B39-D3A5E6F03040}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{BCF48B71-492C-40C8-8D51-259D5DA468BE}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{6021398B-D6BB-4273-A649-669DF7EA64E7}] => (Allow) C:\Program Files (x86)\Deskshare\FTP Manager Lite 2\FTP Manager Lite.exe
FirewallRules: [{29BE94E3-FB74-421C-8A92-B50F3CBA0982}] => (Allow) C:\Program Files (x86)\Deskshare\FTP Manager Lite 2\FTP Manager Lite.exe
FirewallRules: [{DE4320C8-4903-4C49-9F28-9B267A61A753}] => (Allow) C:\Program Files (x86)\Apowersoft\Streaming Video Recorder 6\Streaming Video Recorder 6.exe
FirewallRules: [{93158FFC-367F-40D3-98E0-EEC8F91BE006}] => (Allow) C:\Program Files (x86)\Apowersoft\Streaming Video Recorder 6\Streaming Video Recorder 6.exe
FirewallRules: [{B5EDECD6-6E16-487B-BFA4-780DBF26FFF0}] => (Allow) C:\Program Files (x86)\Apowersoft\Streaming Video Recorder 6\rtmpsrv.exe
FirewallRules: [{83AF7565-8478-45FE-9052-5E7CBAB6C381}] => (Allow) C:\Program Files (x86)\Apowersoft\Streaming Video Recorder 6\rtmpsrv.exe
FirewallRules: [{BF5FBB92-C3FB-46FD-BAD5-F0E2752E79E9}] => (Allow) C:\Program Files (x86)\Mobogenie3\mobogenieP2sp.exe
FirewallRules: [{024C2FB3-30E2-451C-A2E2-AD730EEC078A}] => (Allow) C:\Program Files\Opera\46.0.2597.46\opera.exe
FirewallRules: [{DEF54DCD-21E0-4622-B7BF-5A19DC3272E9}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{9DD49FAB-A449-4D58-94A2-D51D9D67A7FA}] => (Allow) C:\Program Files\Opera\46.0.2597.57\opera.exe
 
==================== Restore Points =========================
 
03-08-2017 15:02:03 Removed Dynasty Warriors 4 Hyper
10-08-2017 15:26:10 Revo Uninstaller's restore point - Adobe Acrobat Reader DC
 
==================== Faulty Device Manager Devices =============
 
Name: Intel(R) Display Audio
Description: Intel(R) Display Audio
Class Guid: {4d36e96c-e325-11ce-bfc1-08002be10318}
Manufacturer: Intel(R) Corporation
Service: IntcDAud
Problem: : Windows cannot start this hardware device because its configuration information (in the registry) is incomplete or damaged. (Code 19)
Resolution: A registry problem was detected.
 This can occur when more than one service is defined for a device, if there is a failure opening the service subkey, or if the driver name cannot be obtained from the service subkey. Try these options:
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Click "Uninstall", and then click "Scan for hardware changes" to load a usable driver.
 
Name: USB Sound Device        
Description: USB Audio Device
Class Guid: {4d36e96c-e325-11ce-bfc1-08002be10318}
Manufacturer: (Generic USB Audio)
Service: usbaudio
Problem: : Windows cannot start this hardware device because its configuration information (in the registry) is incomplete or damaged. (Code 19)
Resolution: A registry problem was detected.
 This can occur when more than one service is defined for a device, if there is a failure opening the service subkey, or if the driver name cannot be obtained from the service subkey. Try these options:
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Click "Uninstall", and then click "Scan for hardware changes" to load a usable driver.
 
Name: SM Bus Controller
Description: SM Bus Controller
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
Name: Realtek High Definition Audio
Description: Realtek High Definition Audio
Class Guid: {4d36e96c-e325-11ce-bfc1-08002be10318}
Manufacturer: Realtek
Service: IntcAzAudAddService
Problem: : Windows cannot start this hardware device because its configuration information (in the registry) is incomplete or damaged. (Code 19)
Resolution: A registry problem was detected.
 This can occur when more than one service is defined for a device, if there is a failure opening the service subkey, or if the driver name cannot be obtained from the service subkey. Try these options:
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Click "Uninstall", and then click "Scan for hardware changes" to load a usable driver.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (08/10/2017 09:01:41 PM) (Source: lupdate) (EventID: 0) (User: )
Description: Event-ID 0
 
Error: (08/10/2017 08:58:42 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
Error: (08/10/2017 08:50:28 PM) (Source: lupdate) (EventID: 0) (User: )
Description: Event-ID 0
 
Error: (08/10/2017 08:47:22 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
Error: (08/10/2017 08:35:04 PM) (Source: lupdate) (EventID: 0) (User: )
Description: Event-ID 0
 
Error: (08/10/2017 08:35:03 PM) (Source: lupdate) (EventID: 0) (User: )
Description: Event-ID 0
 
Error: (08/10/2017 05:16:53 PM) (Source: lupdate) (EventID: 0) (User: )
Description: Event-ID 0
 
Error: (08/10/2017 05:16:52 PM) (Source: lupdate) (EventID: 0) (User: )
Description: Event-ID 0
 
Error: (08/10/2017 05:05:39 PM) (Source: lupdate) (EventID: 0) (User: )
Description: Event-ID 0
 
Error: (08/10/2017 05:02:32 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
 
System errors:
=============
Error: (08/10/2017 08:57:59 PM) (Source: BugCheck) (EventID: 1001) (User: )
Description: The computer has rebooted from a bugcheck.  The bugcheck was: 0x00000101 (0x0000000000000061, 0x0000000000000000, 0xfffff880009ed180, 0x0000000000000001). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 081017-16894-01.
 
Error: (08/10/2017 08:57:58 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 8:56:27 PM on ‎8/‎10/‎2017 was unexpected.
 
Error: (08/10/2017 08:47:21 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The Wondershare Application Framework Service service hung on starting.
 
Error: (08/10/2017 08:45:46 PM) (Source: BugCheck) (EventID: 1001) (User: )
Description: The computer has rebooted from a bugcheck.  The bugcheck was: 0x00000109 (0xa3a039d8a388b616, 0xb3b7465ef606f46c, 0xfffff880009f8540, 0x0000000000000002). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 081017-20935-01.
 
Error: (08/10/2017 08:45:34 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 8:43:27 PM on ‎8/‎10/‎2017 was unexpected.
 
Error: (08/10/2017 04:17:11 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: The server {078AEF33-C48A-49F7-AFF3-A0EE810BFE7C} did not register with DCOM within the required timeout.
 
Error: (08/10/2017 04:12:49 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Windows Update service terminated with the following error: 
The class is configured to run as a security id different from the caller
 
Error: (08/10/2017 04:00:27 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The DrvAgent64 service failed to start due to the following error: 
The system cannot find the file specified.
 
Error: (08/10/2017 04:00:27 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The DrvAgent64 service failed to start due to the following error: 
The system cannot find the file specified.
 
Error: (08/10/2017 04:00:27 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The DrvAgent64 service failed to start due to the following error: 
The system cannot find the file specified.
 
 
CodeIntegrity:
===================================
  Date: 2016-01-14 19:28:38.733
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\AVG\AVG PC TuneUp\avgdumpx.exe because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-01-14 19:28:38.591
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\AVG\AVG PC TuneUp\avgdumpx.exe because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-01-14 19:28:38.368
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\AVG\AVG PC TuneUp\avgdumpa.exe because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-01-14 19:28:38.201
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\AVG\AVG PC TuneUp\avgdumpa.exe because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-12-17 10:29:48.300
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\AVG\AVG PC TuneUp\avgdumpx.exe because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-12-17 10:29:48.191
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\AVG\AVG PC TuneUp\avgdumpx.exe because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-12-17 10:29:48.082
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\AVG\AVG PC TuneUp\avgdumpx.exe because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-12-16 03:51:45.976
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\AVG\AVG PC TuneUp\avgdumpx.exe because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-12-16 03:51:45.867
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\AVG\AVG PC TuneUp\avgdumpx.exe because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-12-16 03:51:45.773
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\AVG\AVG PC TuneUp\avgdumpx.exe because the set of per-page image hashes could not be found on the system.
 
 
==================== Memory info =========================== 
 
Processor: Intel(R) Celeron(R) CPU B815 @ 1.60GHz
Percentage of memory in use: 39%
Total physical RAM: 4000.13 MB
Available physical RAM: 2413.32 MB
Total Virtual: 7998.45 MB
Available Virtual: 6459.59 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:122.07 GB) (Free:35.74 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (East) (Fixed) (Total:343.69 GB) (Free:175.34 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: D9FA2484)
Partition 1: (Not Active) - (Size=343.7 GB) - (Type=07 NTFS)
Partition 2: (Active) - (Size=122.1 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================
 
 
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 09-08-2017
Ran by [removed] (administrator) on SALTYSKY (10-08-2017 21:00:58)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: "C:\Program Files (x86)\SeaMonkey\seamonkey.exe" -requestPending -osint -url "%1")
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Check Point Software Technologies Ltd.) C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\AVGSvc.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe
(Comodo) C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe
(Oppoos.com) C:\Program Files (x86)\Genie Soft\Genie Cleaner\GenieCleanService.exe
(Maxthon) C:\Program Files (x86)\Maxthon App Store\1.1.0.10848\MaxthonAppstoreSvc.exe
(Maxthon) C:\Program Files (x86)\Maxthon\Modules\Service\Update\MaxthonUpdateSvc.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Wondershare) C:\Program Files (x86)\Wondershare\WAF\2.3.1.1\WsAppService.exe
(Check Point Software Technologies Ltd.) C:\Program Files (x86)\CheckPoint\ZoneAlarm\ICM-Service.exe
(Lenovo) C:\Windows\System32\LenovoUpdate.exe
(Oppoos.com) C:\Program Files (x86)\Genie Soft\Genie Cleaner\GenieFloater.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\x64\aswidsagenta.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Epic Privacy Browser) C:\Users\salty-san\AppData\Local\Epic Privacy Browser\Installer\EpicUpdate.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\avgui.exe
(eSupport.com) C:\ProgramData\DriverAgentPlus\UpdateReminder\UpdateReminder.exe
(Wondershare) C:\Program Files (x86)\Wondershare\MobileGo\MobileGoService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Power Software Ltd) C:\Program Files\PowerISO\PWRISOVM.EXE
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Nullsoft, Inc.) C:\Program Files (x86)\Winamp\winampa.exe
(Check Point Software Technologies Ltd.) C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe
(Virage Logic Corporation / Sonic Focus) C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
(Nullsoft, Inc.) C:\Program Files (x86)\Winamp\winamp.exe
(Comodo) C:\Program Files (x86)\Comodo\Dragon\dragon.exe
(Comodo) C:\Program Files (x86)\Comodo\Dragon\dragon.exe
(Comodo) C:\Program Files (x86)\Comodo\Dragon\dragon.exe
(Comodo) C:\Program Files (x86)\Comodo\Dragon\dragon.exe
(Comodo) C:\Program Files (x86)\Comodo\Dragon\dragon.exe
(Comodo) C:\Program Files (x86)\Comodo\Dragon\dragon.exe
(Comodo) C:\Program Files (x86)\Comodo\Dragon\dragon.exe
(Comodo) C:\Program Files (x86)\Comodo\Dragon\dragon.exe
(Comodo) C:\Program Files (x86)\Comodo\Dragon\dragon.exe
(Comodo) C:\Program Files (x86)\Comodo\Dragon\dragon.exe
(Comodo) C:\Program Files (x86)\Comodo\Dragon\dragon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
 
==================== Registry (Whitelisted) ====================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [Eraser] => C:\Program Files\Eraser\Eraser.exe [1074088 2015-09-03] (The Eraser Project)
HKLM\…\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2587944 2010-12-31] (ELAN Microelectronics Corp.)
HKLM\…\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [239592 2017-08-01] (AVG Technologies CZ, s.r.o.)
HKLM\…\Run: [AVGUI.exe] => C:\Program Files (x86)\AVG\Antivirus\AvLaunch.exe [263232 2017-07-19] (AVG Technologies CZ, s.r.o.)
HKLM\…\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12850792 2011-09-05] (Realtek Semiconductor)
HKLM-x32\…\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2014-06-09] (Intel Corporation)
HKLM-x32\…\Run: [PWRISOVM.EXE] => C:\Program Files\PowerISO\PWRISOVM.EXE [408888 2015-07-23] (Power Software Ltd)
HKLM-x32\…\Run: [WinampAgent] => C:\Program Files (x86)\Winamp\winampa.exe [85600 2013-12-13] (Nullsoft, Inc.)
HKLM-x32\…\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [239592 2017-08-01] (AVG Technologies CZ, s.r.o.)
HKLM-x32\…\Run: [ZoneAlarm] => C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe [144184 2016-09-07] (Check Point Software Technologies Ltd.)
HKLM-x32\…\Run: [SonicMasterTray] => C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe [984400 2010-07-09] (Virage Logic Corporation / Sonic Focus)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-384921765-1548902971-3406650631-1000\…\Run: [Epic Privacy Browser Installer] => C:\Users\salty-san\AppData\Local\Epic Privacy Browser\Installer\EpicUpdate.exe [509096 2016-02-28] (Epic Privacy Browser)
HKU\S-1-5-21-384921765-1548902971-3406650631-1000\…\Run: [GenieFloater] => C:\Program Files (x86)\Genie Soft\Genie Cleaner\GenieFloater.exe [1850520 2015-02-06] (Oppoos.com)
HKU\S-1-5-21-384921765-1548902971-3406650631-1000\…\Run: [UpdateReminder] => C:\ProgramData\DriverAgentPlus\UpdateReminder\UpdateReminder.exe [682488 2017-04-14] (eSupport.com)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\MobileGo Service.lnk [2017-04-09]
ShortcutTarget: MobileGo Service.lnk -> C:\Program Files (x86)\Wondershare\MobileGo\MobileGoService.exe (Wondershare)
BootExecute: autocheck autochk * PCloudBroom64.exe \systemroot\system32\BroomData.bitPCloudBroom64.exe \systemroot\system32\BroomData.bitPCloudBroom64.exe \systemroot\system32\BroomData.bitPCloudBroom64.exe \systemroot\system32\BroomData.bit
GroupPolicy: Restriction <==== ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{997EDB05-CBD3-4358-97F4-A47B17E7987F}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{BB2A1C55-6917-4C3A-8770-C53876319A70}: [DhcpNameServer] 192.168.0.1
 
Internet Explorer:
==================
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=msnhome
HKU\S-1-5-21-384921765-1548902971-3406650631-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
HKU\S-1-5-21-384921765-1548902971-3406650631-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://us.yahoo.com/?fr=fp-comodo&type;=19_25050030005_52.15.25.664_u_hp
SearchScopes: HKU\S-1-5-21-384921765-1548902971-3406650631-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2012-10-01] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2012-10-01] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation)
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2012-10-01] (Microsoft Corporation)
 
FireFox:
========
FF DefaultProfile: oi0sxqu4.default
FF DefaultProfile: kl9fv1vt.default
FF ProfilePath: C:\Users\salty-san\AppData\Roaming\Mozilla\SeaMonkey\Profiles\oi0sxqu4.default [2017-08-10]
FF DefaultSearchEngine: Mozilla\SeaMonkey\Profiles\oi0sxqu4.default -> DuckDuckGo
FF Extension: (MEGA) - C:\Users\salty-san\AppData\Roaming\Mozilla\SeaMonkey\Profiles\oi0sxqu4.default\Extensions\[removed] [2016-07-06]
FF Extension: (DOM Inspector) - C:\Users\salty-san\AppData\Roaming\Mozilla\SeaMonkey\Profiles\oi0sxqu4.default\Extensions\[removed] [2016-04-27]
FF Extension: (ChatZilla) - C:\Users\salty-san\AppData\Roaming\Mozilla\SeaMonkey\Profiles\oi0sxqu4.default\Extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2} [2017-01-18]
FF Extension: (Flash and Video Download) - C:\Users\salty-san\AppData\Roaming\Mozilla\SeaMonkey\Profiles\oi0sxqu4.default\Extensions\{bee6eb20-01e0-ebd1-da83-080329fb9a3a} [2017-08-10]
FF Extension: (DownThemAll!) - C:\Users\salty-san\AppData\Roaming\Mozilla\SeaMonkey\Profiles\oi0sxqu4.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2017-03-19]
FF ProfilePath: C:\Users\salty-san\AppData\Roaming\Mozilla\Firefox\Profiles\kl9fv1vt.default [2017-08-10]
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\kl9fv1vt.default -> DuckDuckGo
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2012-10-01] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-05-03] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-384921765-1548902971-3406650631-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\salty-san\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2016-10-26] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-384921765-1548902971-3406650631-1000: @updates.epicbrowser.com/Epic Privacy Browser Installer;version=3 -> C:\Users\salty-san\AppData\Local\Epic Privacy Browser\Installer\1.3.27.13\npEpicUpdate3.dll [2016-02-28] (Epic Privacy Browser)
FF Plugin HKU\S-1-5-21-384921765-1548902971-3406650631-1000: @updates.epicbrowser.com/Epic Privacy Browser Installer;version=9 -> C:\Users\salty-san\AppData\Local\Epic Privacy Browser\Installer\1.3.27.13\npEpicUpdate3.dll [2016-02-28] (Epic Privacy Browser)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2012-10-01] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2015-12-18] (Adobe Systems Inc.)
 
Chrome: 
=======
CHR HKU\S-1-5-21-384921765-1548902971-3406650631-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [hcjjaajflhellmcfcecojihhmdbjmmlm] - hxxps://clients2.google.com/service/update2/crx
 
Opera: 
=======
OPR Extension: (Bookmarks) - C:\Users\salty-san\AppData\Roaming\Opera Software\Opera Stable\Extensions\fnlanmpednndkaaaleibncenahckbmhc [2017-05-10]
OPR Extension: (Opera Welcome Page) - C:\Users\salty-san\AppData\Roaming\Opera Software\Opera Stable\Extensions\kejfhjjgjmgpfcdoiiccindaajbglghl [2017-05-10]
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AVG Antivirus; C:\Program Files (x86)\AVG\Antivirus\AVGSvc.exe [264432 2017-07-19] (AVG Technologies CZ, s.r.o.)
R3 avgbIDSAgent; C:\Program Files (x86)\AVG\Antivirus\x64\aswidsagenta.exe [7481648 2017-07-19] (AVG Technologies CZ, s.r.o.)
R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1428656 2017-08-01] (AVG Technologies CZ, s.r.o.)
R2 DragonUpdater; C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe [2272904 2016-09-29] (Comodo)
R2 GenieCleanService; C:\Program Files (x86)\Genie Soft\Genie Cleaner\GenieCleanService.exe [53400 2015-02-06] (Oppoos.com) [File not signed]
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [318568 2014-10-10] (Intel Corporation)
R3 LenovoUpdate; C:\Windows\System32\LenovoUpdate.exe [26608 2017-08-10] (Lenovo)
R2 MaxthonAppStoreSvc; C:\Program Files (x86)\Maxthon App Store\1.1.0.10848\MaxthonAppstoreSvc.exe [1867544 2015-08-11] (Maxthon)
R2 MaxthonUpdateSvc; C:\Program Files (x86)\Maxthon\Modules\Service\Update\MaxthonUpdateSvc.exe [2385832 2016-06-10] (Maxthon)
S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-03-01] (Riverbed Technology, Inc.)
R2 vsmon; C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe [4087568 2016-09-07] (Check Point Software Technologies Ltd.)
S3 wampapache64; c:\wamp64\bin\apache\apache2.4.23\bin\httpd.exe [29696 2016-07-01] (Apache Software Foundation) [File not signed]
S3 wampmysqld64; c:\wamp64\bin\mysql\mysql5.7.14\bin\mysqld.exe [39885824 2016-07-12] () [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2015-08-05] (Microsoft Corporation)
R2 WsAppService; C:\Program Files (x86)\Wondershare\WAF\2.3.1.1\WsAppService.exe [437392 2016-10-10] (Wondershare)
S3 WsDrvInst; C:\Program Files (x86)\Wondershare\MobileGo\DriverInstall.exe [116368 2016-10-18] (Wondershare)
S3 ZAPrivacyService; C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZaPrivacyService.exe [114936 2016-08-09] (Check Point Software Technologies, Ltd.)
R2 ZoneAlarm ICM Service; C:\Program Files (x86)\CheckPoint\ZoneAlarm\ICM-Service.exe [794424 2016-09-07] (Check Point Software Technologies Ltd.)
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 avgbdisk; C:\Windows\system32\drivers\avgbdiska.sys [166624 2017-07-19] (AVG Technologies CZ, s.r.o.)
R1 avgbidsdriver; C:\Windows\system32\drivers\avgbidsdrivera.sys [313616 2017-07-19] (AVG Technologies CZ, s.r.o.)
R0 avgbidsh; C:\Windows\system32\drivers\avgbidsha.sys [192584 2017-07-19] (AVG Technologies CZ, s.r.o.)
R0 avgblog; C:\Windows\system32\drivers\avgbloga.sys [336896 2017-07-19] (AVG Technologies CZ, s.r.o.)
R0 avgbuniv; C:\Windows\system32\drivers\avgbuniva.sys [51336 2017-07-19] (AVG Technologies CZ, s.r.o.)
S3 avgHwid; C:\Windows\system32\drivers\avgHwid.sys [39424 2017-07-19] (AVG Technologies CZ, s.r.o.)
R2 avgMonFlt; C:\Windows\system32\drivers\avgMonFlt.sys [139112 2017-07-19] (AVG Technologies CZ, s.r.o.)
R1 avgRdr; C:\Windows\system32\drivers\avgRdr2.sys [102792 2017-07-19] (AVG Technologies CZ, s.r.o.)
R0 avgRvrt; C:\Windows\system32\drivers\avgRvrt.sys [76832 2017-07-19] (AVG Technologies CZ, s.r.o.)
R1 avgSnx; C:\Windows\system32\drivers\avgSnx.sys [1008288 2017-07-19] (AVG Technologies CZ, s.r.o.)
R1 avgSP; C:\Windows\system32\drivers\avgSP.sys [578048 2017-07-19] (AVG Technologies CZ, s.r.o.)
R2 avgStm; C:\Windows\system32\drivers\avgStm.sys [191208 2017-07-19] (AVG Technologies CZ, s.r.o.)
R0 avgVmm; C:\Windows\system32\drivers\avgVmm.sys [353744 2017-07-19] (AVG Technologies CZ, s.r.o.)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
R2 npf; C:\Windows\system32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.)
S3 PSKMAD; C:\Windows\System32\DRIVERS\PSKMAD.sys [50320 2015-01-29] (Panda Security, S.L.)
S3 RSP2STOR; C:\Windows\System32\DRIVERS\RtsP2Stor.sys [294104 2014-12-10] (Realtek Semiconductor Corp.)
S3 RTWlanE; C:\Windows\System32\DRIVERS\rtwlane.sys [3513048 2015-03-23] (Realtek Semiconductor Corporation )
R1 VBoxNetAdp; C:\Windows\System32\DRIVERS\VBoxNetAdp6.sys [121824 2016-07-12] (Oracle Corporation)
R1 VBoxNetLwf; C:\Windows\System32\DRIVERS\VBoxNetLwf.sys [195424 2016-07-12] (Oracle Corporation)
S3 VBoxUSB; C:\Windows\System32\Drivers\VBoxUSB.sys [135824 2016-07-12] (Oracle Corporation)
R1 Vsdatant; C:\Windows\System32\DRIVERS\vsdatant.sys [461240 2017-03-16] (Check Point Software Technologies Ltd.)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-08-10 21:00 - 2017-08-10 21:02 - 000018132 _____ C:\Users\salty-san\Desktop\FRST.txt
2017-08-10 20:59 - 2017-08-10 21:00 - 000000000 ____D C:\FRST
2017-08-10 20:57 - 2017-08-10 20:57 - 000262144 _____ C:\Windows\Minidump\081017-16894-01.dmp
2017-08-10 20:45 - 2017-08-10 20:45 - 000262144 _____ C:\Windows\Minidump\081017-20935-01.dmp
2017-08-10 18:40 - 2017-08-10 18:40 - 002381824 _____ (Farbar) C:\Users\salty-san\Desktop\FRST64.exe
2017-08-10 18:39 - 2017-08-10 18:39 - 005198336 _____ (AVAST Software) C:\Users\salty-san\Desktop\aswMBR.exe
2017-08-10 16:50 - 2017-08-10 16:50 - 000931447 _____ C:\Users\salty-san\Favorites-WIN MOVE!.rar
2017-08-10 16:43 - 2017-08-10 16:43 - 000089841 _____ C:\Windows\unins000.dat
2017-08-10 16:43 - 2017-08-10 16:43 - 000004608 _____ C:\Users\salty-san\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2017-08-10 16:43 - 2017-08-10 16:43 - 000001029 _____ C:\Users\Public\Desktop\ezvid.lnk
2017-08-10 16:43 - 2017-08-10 16:43 - 000000000 ____D C:\Users\salty-san\Documents\ezvid
2017-08-10 16:43 - 2017-08-10 16:43 - 000000000 ____D C:\Users\salty-san\AppData\Local\ezvid,_inc
2017-08-10 16:43 - 2017-08-10 16:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ezvid
2017-08-10 16:43 - 2017-08-10 16:40 - 000761531 _____ C:\Windows\unins000.exe
2017-08-10 16:43 - 2015-03-10 20:29 - 000462584 _____ (Bytescout) C:\Windows\SysWOW64\BytescoutScreenCapturing.dll
2017-08-10 16:43 - 2015-03-10 20:29 - 000360184 _____ (Bytescout) C:\Windows\SysWOW64\BytescoutScreenCapturingFilter.dll
2017-08-10 16:43 - 2015-03-10 20:29 - 000196344 _____ (Bytescout) C:\Windows\SysWOW64\BytescoutVideoMixerFilter.dll
2017-08-10 16:43 - 2013-04-07 18:09 - 000216064 _____ ( ) C:\Windows\SysWOW64\Lagarith.dll
2017-08-10 16:43 - 2013-04-07 18:09 - 000148992 _____ ( ) C:\Windows\system32\Lagarith.dll
2017-08-10 16:42 - 2017-08-10 16:43 - 000000000 ____D C:\Program Files (x86)\ezvid
2017-08-10 16:11 - 2017-08-10 16:11 - 000000000 ____D C:\Windows\SysWOW64\RTCOM
2017-08-10 16:11 - 2011-09-06 19:58 - 003074536 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHD64.sys
2017-08-10 16:11 - 2011-09-06 10:16 - 002519656 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtPgEx64.dll
2017-08-10 16:11 - 2011-09-05 17:06 - 000097896 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoInst64.dll
2017-08-10 16:11 - 2011-09-02 13:27 - 003201128 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkAPO64.dll
2017-08-10 16:11 - 2011-09-01 15:08 - 001510912 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoRes64.dat
2017-08-10 16:11 - 2011-08-19 14:54 - 001881704 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApi64.dll
2017-08-10 16:11 - 2011-07-28 00:55 - 002604376 _____ (Waves Audio Ltd.) C:\Windows\system32\WavesGUILib.dll
2017-08-10 16:11 - 2011-07-28 00:55 - 002132824 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioEQ.dll
2017-08-10 16:11 - 2011-07-22 19:35 - 001247848 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTCOM64.dll
2017-08-10 16:11 - 2011-06-30 16:14 - 001560168 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSnMg64.cpl
2017-08-10 16:11 - 2011-05-31 09:42 - 001756264 _____ (DTS) C:\Windows\system32\DTSS2SpeakerDLL64.dll
2017-08-10 16:11 - 2011-05-31 09:42 - 001568360 _____ (DTS) C:\Windows\system32\DTSS2HeadphoneDLL64.dll
2017-08-10 16:11 - 2011-05-31 09:42 - 001486952 _____ (DTS) C:\Windows\system32\DTSBoostDLL64.dll
2017-08-10 16:11 - 2011-05-31 09:42 - 000728680 _____ (DTS) C:\Windows\system32\DTSBassEnhancementDLL64.dll
2017-08-10 16:11 - 2011-05-31 09:42 - 000693352 _____ (DTS) C:\Windows\system32\DTSVoiceClarityDLL64.dll
2017-08-10 16:11 - 2011-05-31 09:42 - 000491112 _____ (DTS) C:\Windows\system32\DTSNeoPCDLL64.dll
2017-08-10 16:11 - 2011-05-31 09:42 - 000432744 _____ (DTS) C:\Windows\system32\DTSLimiterDLL64.dll
2017-08-10 16:11 - 2011-05-31 09:42 - 000428648 _____ (DTS) C:\Windows\system32\DTSGainCompensatorDLL64.dll
2017-08-10 16:11 - 2011-05-31 09:42 - 000242792 _____ (DTS) C:\Windows\system32\DTSLFXAPO64.dll
2017-08-10 16:11 - 2011-05-31 09:42 - 000242792 _____ (DTS) C:\Windows\system32\DTSGFXAPO64.dll
2017-08-10 16:11 - 2011-05-05 15:24 - 002085440 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO64.dll
2017-08-10 16:11 - 2011-05-05 14:15 - 000220512 _____ (Synopsys, Inc.) C:\Windows\system32\SFNHK64.dll
2017-08-10 16:11 - 2011-05-05 14:14 - 000081248 _____ (Synopsys, Inc.) C:\Windows\system32\SFCOM64.dll
2017-08-10 16:11 - 2011-05-05 14:14 - 000078176 _____ (Synopsys, Inc.) C:\Windows\system32\SFAPO64.dll
2017-08-10 16:11 - 2010-11-08 08:31 - 000375128 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEP64A.dll
2017-08-10 16:11 - 2010-11-08 08:31 - 000310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DHT64.dll
2017-08-10 16:11 - 2010-11-08 08:31 - 000310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DAA64.dll
2017-08-10 16:11 - 2010-11-08 08:31 - 000204120 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEED64A.dll
2017-08-10 16:11 - 2010-11-08 08:31 - 000101208 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEL64A.dll
2017-08-10 16:11 - 2010-11-08 08:31 - 000078680 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEG64A.dll
2017-08-10 16:11 - 2010-11-03 19:31 - 000332392 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtlCPAPI64.dll
2017-08-10 16:11 - 2010-11-03 19:30 - 000149608 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCfg64.dll
2017-08-10 16:11 - 2010-09-27 09:34 - 000318808 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO20.dll
2017-08-10 16:11 - 2010-07-22 16:48 - 000074064 _____ (Virage Logic Corporation / Sonic Focus) C:\Windows\SysWOW64\SFCOM.dll
2017-08-10 16:11 - 2010-07-22 16:37 - 000200800 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAC64.dll
2017-08-10 16:11 - 2010-07-11 21:28 - 000180048 _____ (Sonic Focus, Inc.) C:\Windows\system32\SFProc64.dll
2017-08-10 16:11 - 2010-07-11 21:28 - 000086352 _____ (Sonic Focus, Inc.) C:\Windows\system32\SFComm64.dll
2017-08-10 16:11 - 2010-07-11 21:28 - 000083792 _____ (Sonic Focus, Inc.) C:\Windows\system32\SFSAPO64.dll
2017-08-10 16:11 - 2010-07-11 21:28 - 000082768 _____ (Sonic Focus, Inc.) C:\Windows\system32\SFHAPO64.dll
2017-08-10 16:11 - 2010-07-11 21:28 - 000082768 _____ (Sonic Focus, Inc.) C:\Windows\system32\SFDAPO64.dll
2017-08-10 16:11 - 2009-11-24 10:55 - 000518896 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSX64.dll
2017-08-10 16:11 - 2009-11-24 10:55 - 000211184 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSH64.dll
2017-08-10 16:11 - 2009-11-24 10:55 - 000198896 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSHP64.dll
2017-08-10 16:11 - 2009-11-24 10:55 - 000155888 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSWOW64.dll
2017-08-10 16:11 - 2009-11-17 19:12 - 000108960 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAR64.dll
2017-08-10 16:00 - 2017-08-10 16:06 - 000000000 ____D C:\Users\salty-san\AppData\Roaming\DriverAgentPlus
2017-08-10 16:00 - 2017-08-10 16:06 - 000000000 ____D C:\ProgramData\DriverAgentPlus
2017-08-10 15:34 - 2017-08-10 15:34 - 000000000 ____D C:\Users\salty-san\AppData\Local\ElevatedDiagnostics
2017-08-10 14:46 - 2017-08-10 14:46 - 000034512 _____ C:\Windows\system32\Drivers\debutfilterx64.sys
2017-08-09 18:26 - 2017-08-09 18:26 - 000000000 ____D C:\ProgramData\Steam
2017-08-09 18:24 - 2017-08-09 18:24 - 000002038 _____ C:\Users\salty-san\Desktop\BlazBlue Chronophantasma Extend.lnk
2017-08-09 18:16 - 2017-08-09 18:16 - 000001101 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlazBlue Chronophantasma Extend.lnk
2017-08-03 20:23 - 2017-08-03 20:23 - 000262144 _____ C:\Windows\Minidump\080317-15303-01.dmp
2017-08-03 20:22 - 2017-08-10 14:46 - 000001181 _____ C:\Users\salty-san\AppData\Roaming\trace_FilterInstaller.txt
2017-08-03 20:22 - 2017-08-10 14:46 - 000000000 _____ C:\Users\salty-san\AppData\Roaming\trace_FilterInstaller.txt-CRT.txt
2017-08-03 20:22 - 2017-08-10 09:48 - 000000919 _____ C:\Users\salty-san\AppData\Roaming\trace_FilterInstaller.1.txt
2017-08-03 20:22 - 2017-08-03 20:22 - 000001181 _____ C:\Users\salty-san\AppData\Roaming\trace_FilterInstaller.2.txt
2017-08-02 23:53 - 2017-08-02 23:53 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Koei
2017-08-02 23:51 - 2017-08-02 23:51 - 000000000 ____D C:\Users\salty-san\AppData\Roaming\InstallShield Installation Information
2017-08-01 14:43 - 2017-08-01 14:43 - 000000000 ____D C:\ProgramData\Apowersoft
2017-07-30 09:36 - 2017-07-30 09:36 - 000001241 _____ C:\Users\Public\Desktop\BlazBlue Continuum Shift Extend.lnk
2017-07-30 09:36 - 2017-07-30 09:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlazBlue Continuum Shift Extend
2017-07-26 18:49 - 2017-08-09 18:26 - 000000000 ____D C:\Users\salty-san\Documents\ARC SYSTEM WORKS
2017-07-26 18:38 - 2017-07-26 18:38 - 000001220 _____ C:\Users\Public\Desktop\BlazBlue - Calamity Trigger.lnk
2017-07-19 08:17 - 2017-07-19 08:17 - 000401584 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\avgBoot.exe
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-08-10 20:58 - 2009-07-14 08:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2017-08-10 20:57 - 2016-05-21 18:52 - 550383420 _____ C:\Windows\MEMORY.DMP
2017-08-10 20:57 - 2016-05-21 18:52 - 000000000 ____D C:\Windows\Minidump
2017-08-10 20:57 - 2015-11-01 23:10 - 000097264 _____ (Lenovo (Beijing) Limited) C:\Windows\system32\LenovoCheck.exe
2017-08-10 20:57 - 2015-11-01 23:10 - 000026608 _____ (Lenovo) C:\Windows\system32\LenovoUpdate.exe
2017-08-10 20:55 - 2009-07-14 07:45 - 000026352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-08-10 20:55 - 2009-07-14 07:45 - 000026352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-08-10 20:54 - 2017-03-22 10:28 - 000004178 _____ C:\Windows\System32\Tasks\Antivirus Emergency Update
2017-08-10 18:37 - 2016-05-04 16:47 - 000000000 ____D C:\TheIt
2017-08-10 18:22 - 2017-07-09 23:46 - 000000000 ____D C:\Program Files (x86)\NCH Software
2017-08-10 17:48 - 2016-02-10 21:08 - 000000000 ____D C:\Users\salty-san\Documents\Mount&Blade; Savegames
2017-08-10 16:51 - 2015-11-01 13:21 - 000000000 ____D C:\Users\salty-san
2017-08-10 16:49 - 2017-01-20 14:26 - 000000000 ____D C:\Users\salty-san\AppData\LocalLow\Mozilla
2017-08-10 16:35 - 2016-02-28 08:06 - 000000000 ____D C:\Users\salty-san\AppData\Local\Epic Privacy Browser
2017-08-10 16:17 - 2017-06-28 09:15 - 000000000 ____D C:\Windows\System32\Tasks\NCH Software
2017-08-10 16:12 - 2017-01-16 17:18 - 000000000 ___HD C:\Program Files (x86)\Temp
2017-08-10 16:11 - 2015-11-01 13:28 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2017-08-10 16:11 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\inf
2017-08-10 15:33 - 2015-11-05 14:53 - 000000000 ____D C:\Users\salty-san\Documents\OCTGN
2017-08-10 15:27 - 2016-06-02 19:07 - 000002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-08-10 15:27 - 2016-01-03 02:37 - 000002047 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk
2017-08-10 15:01 - 2016-05-03 22:51 - 000003942 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{F51745E5-CA05-4A07-82FD-E977DEA96A94}
2017-08-10 13:41 - 2017-01-18 15:19 - 000003600 _____ C:\Windows\System32\Tasks\AVG EUpdate Task
2017-08-10 03:14 - 2015-12-04 12:06 - 000000000 ____D C:\Users\salty-san\AppData\Roaming\vlc
2017-08-09 22:47 - 2016-02-08 00:58 - 000000000 ____D C:\Users\salty-san\AppData\Local\Eraser 6
2017-08-09 18:16 - 2009-07-14 08:13 - 000781298 _____ C:\Windows\system32\PerfStringBackup.INI
2017-08-08 08:39 - 2016-01-03 22:46 - 000000000 ____D C:\Users\salty-san\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2017-08-07 08:35 - 2009-07-14 08:08 - 000032592 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2017-08-04 14:48 - 2016-01-03 02:38 - 000004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2017-08-03 21:06 - 2016-02-18 17:23 - 000000400 __RSH C:\ProgramData\ntuser.pol
2017-08-03 20:33 - 2016-05-04 16:13 - 000000000 ____D C:\Users\salty-san\AppData\Roaming\SlimBrowser
2017-08-01 14:14 - 2017-02-01 17:27 - 000000000 ____D C:\Users\salty-san\AppData\Roaming\Apowersoft
2017-07-26 18:38 - 2016-02-10 20:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com
2017-07-26 18:38 - 2009-07-14 08:32 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2017-07-24 08:41 - 2017-05-10 14:13 - 000004040 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1494414816
2017-07-24 08:41 - 2017-05-10 14:13 - 000000000 ____D C:\Program Files\Opera
2017-07-23 21:21 - 2017-07-08 18:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Genie Soft
2017-07-23 21:21 - 2017-07-08 18:35 - 000000000 ____D C:\Users\salty-san\Documents\Mobogenie
2017-07-23 21:21 - 2017-07-08 18:35 - 000000000 ____D C:\Program Files (x86)\Mobogenie3
2017-07-20 09:52 - 2017-07-04 09:03 - 000000000 ____D C:\Users\salty-san\AppData\Local\Google
2017-07-20 09:52 - 2015-11-08 00:29 - 000000000 ____D C:\Program Files (x86)\Google
2017-07-19 08:18 - 2017-03-22 10:28 - 000139112 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgmonflt.sys
2017-07-19 08:17 - 2017-03-22 10:28 - 001008288 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgSnx.sys
2017-07-19 08:17 - 2017-03-22 10:28 - 000578048 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgSP.sys
2017-07-19 08:17 - 2017-03-22 10:28 - 000353744 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgVmm.sys
2017-07-19 08:17 - 2017-03-22 10:28 - 000336896 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgbloga.sys
2017-07-19 08:17 - 2017-03-22 10:28 - 000313616 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgbidsdrivera.sys
2017-07-19 08:17 - 2017-03-22 10:28 - 000192584 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgbidsha.sys
2017-07-19 08:17 - 2017-03-22 10:28 - 000191208 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgStm.sys
2017-07-19 08:17 - 2017-03-22 10:28 - 000166624 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgbdiska.sys
2017-07-19 08:17 - 2017-03-22 10:28 - 000139112 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgmonflt.sys.150044149958401
2017-07-19 08:17 - 2017-03-22 10:28 - 000102792 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgRdr2.sys
2017-07-19 08:17 - 2017-03-22 10:28 - 000076832 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgRvrt.sys
2017-07-19 08:17 - 2017-03-22 10:28 - 000051336 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgbuniva.sys
2017-07-19 08:17 - 2017-03-22 10:28 - 000039424 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgHwid.sys
2017-07-18 10:45 - 2017-04-06 13:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2017-07-18 10:45 - 2016-09-18 08:48 - 000001008 _____ C:\Users\Public\Desktop\AVG.lnk
 
==================== Files in the root of some directories =======
 
2016-03-13 14:21 - 2017-03-28 18:30 - 000000105 _____ () C:\Users\salty-san\AppData\Roaming\Camdata.ini
2016-03-13 14:21 - 2017-03-28 18:30 - 000000408 _____ () C:\Users\salty-san\AppData\Roaming\CamLayout.ini
2016-03-13 14:21 - 2017-03-28 18:30 - 000000408 _____ () C:\Users\salty-san\AppData\Roaming\CamShapes.ini
2016-03-13 14:21 - 2017-03-28 18:30 - 000004548 _____ () C:\Users\salty-san\AppData\Roaming\CamStudio.cfg
2017-08-03 20:22 - 2017-08-10 09:48 - 000000919 _____ () C:\Users\salty-san\AppData\Roaming\trace_FilterInstaller.1.txt
2017-08-03 20:22 - 2017-08-03 20:22 - 000001181 _____ () C:\Users\salty-san\AppData\Roaming\trace_FilterInstaller.2.txt
2017-08-03 20:22 - 2017-08-10 14:46 - 000001181 _____ () C:\Users\salty-san\AppData\Roaming\trace_FilterInstaller.txt
2017-08-03 20:22 - 2017-08-10 14:46 - 000000000 _____ () C:\Users\salty-san\AppData\Roaming\trace_FilterInstaller.txt-CRT.txt
2016-03-13 14:21 - 2017-03-28 18:29 - 000000096 _____ () C:\Users\salty-san\AppData\Roaming\version2.xml
2017-08-10 16:43 - 2017-08-10 16:43 - 000004608 _____ () C:\Users\salty-san\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2016-05-30 19:43 - 2017-01-30 10:02 - 000007607 _____ () C:\Users\salty-san\AppData\Local\Resmon.ResmonCfg
2017-06-28 09:02 - 2017-06-28 09:02 - 000000016 _____ () C:\ProgramData\mntemp
2017-06-28 09:02 - 2017-06-28 09:02 - 000004970 _____ () C:\ProgramData\nakuvtjg.ewu
 
Some files in TEMP:
====================
2017-03-01 18:50 - 2017-07-04 10:12 - 085152552 _____ (Avant Force) C:\Users\salty-san\AppData\Local\Temp\$avantbrowser$.update.exe
2017-04-22 17:29 - 2017-04-22 17:29 - 000036864 _____ () C:\Users\salty-san\AppData\Local\Temp\CmdLineExt02.dll
2017-04-22 17:29 - 2017-04-22 17:29 - 000012067 _____ () C:\Users\salty-san\AppData\Local\Temp\SIntf16.dll
2017-04-22 17:29 - 2017-04-22 17:29 - 000019924 _____ () C:\Users\salty-san\AppData\Local\Temp\SIntf32.dll
2017-04-22 17:29 - 2017-04-22 17:29 - 000024516 _____ () C:\Users\salty-san\AppData\Local\Temp\SIntfNT.dll
2017-03-13 04:08 - 2017-03-13 04:08 - 007682154 _____ () C:\Users\salty-san\AppData\Local\Temp\tmp153C.tmp.exe
2017-02-25 00:40 - 2017-02-25 00:40 - 007663397 _____ () C:\Users\salty-san\AppData\Local\Temp\tmp87E9.tmp.exe
2017-04-19 21:52 - 2016-04-04 02:19 - 000116796 _____ () C:\Users\salty-san\AppData\Local\Temp\Uninstall.exe
2007-09-22 00:33 - 2007-09-22 00:33 - 000456416 ____R (Macrovision Corporation) C:\Users\salty-san\AppData\Local\Temp\_is9530.exe
2007-09-22 00:33 - 2007-09-22 00:33 - 000456416 ____R (Macrovision Corporation) C:\Users\salty-san\AppData\Local\Temp\_isC2BA.exe
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
LastRegBack: 2017-08-01 01:00
 
==================== End of FRST.txt ============================
 

 

See if you can uninstall Comodo Dragon


~~~~~~~~~~~~~~~~~~~~~~~

Start Farbar Recovery Scan Tool (Please double-click on FRST/FRST64) with Administrator privileges

or Right click on the FRST icon and select Run as administrator
Highlight the below information then hit the Ctrl + C keys at the same time
or

Right click/highlight on the text below and select Copy.[beginning with Start:: and finishing with End::]

Start::
CreateRestorePoint:
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers1: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAShell.dll -> No File
ContextMenuHandlers3: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers3: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers5: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAShell.dll -> No File
ContextMenuHandlers6: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAShell.dll -> No File
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
GroupPolicy: Restriction <==== ATTENTION
HKU\S-1-5-21-384921765-1548902971-3406650631-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://us.yahoo.com/?fr=fp-comodo&type=19_25050030005_52.15.25.664_u_hp
SearchScopes: HKU\S-1-5-21-384921765-1548902971-3406650631-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
S3 PSKMAD; C:\Windows\System32\DRIVERS\PSKMAD.sys [50320 2015-01-29] (Panda Security, S.L.)
C:\Windows\System32\DRIVERS\PSKMAD.sys
C:\ProgramData\nakuvtjg.ewu
2017-03-01 18:50 - 2017-07-04 10:12 - 085152552 _____ (Avant Force) C:\Users\salty-san\AppData\Local\Temp\$avantbrowser$.update.exe
2017-04-22 17:29 - 2017-04-22 17:29 - 000036864 _____ () C:\Users\salty-san\AppData\Local\Temp\CmdLineExt02.dll
2017-04-22 17:29 - 2017-04-22 17:29 - 000012067 _____ () C:\Users\salty-san\AppData\Local\Temp\SIntf16.dll
2017-04-22 17:29 - 2017-04-22 17:29 - 000019924 _____ () C:\Users\salty-san\AppData\Local\Temp\SIntf32.dll
2017-04-22 17:29 - 2017-04-22 17:29 - 000024516 _____ () C:\Users\salty-san\AppData\Local\Temp\SIntfNT.dll
2017-03-13 04:08 - 2017-03-13 04:08 - 007682154 _____ () C:\Users\salty-san\AppData\Local\Temp\tmp153C.tmp.exe
2017-02-25 00:40 - 2017-02-25 00:40 - 007663397 _____ () C:\Users\salty-san\AppData\Local\Temp\tmp87E9.tmp.exe
2017-04-19 21:52 - 2016-04-04 02:19 - 000116796 _____ () C:\Users\salty-san\AppData\Local\Temp\Uninstall.exe
2007-09-22 00:33 - 2007-09-22 00:33 - 000456416 ____R (Macrovision Corporation) C:\Users\salty-san\AppData\Local\Temp\_is9530.exe
2007-09-22 00:33 - 2007-09-22 00:33 - 000456416 ____R (Macrovision Corporation) C:\Users\salty-san\AppData\Local\Temp\_isC2BA.exe
Emptytemp:
End::


Press the Fix button.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.



******

[external image: h3qKPnn.png]Malwarebytes AdwCleaner
  • Please download Malwarebytes AdwCleaner and save the file to your Desktop
  • Right-click AdwCleaner.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Follow the prompts.
  • Click [external image: A49sxPr.png]Scan.
  • and wait until it ends.
    When the scan is over,
    Click on Clean, read the informative message. If you have any questions about it, please ask.
    All unrequired programs will be closed during the cleaning process, so be sure to save your work before.
    When the clean is over, the computer may reboot and shows the logfile
    Copy/Paste it in your answer.
  • ~~~~~~~~~~~~~~~~~~~~~~~~

    Please download the Malwarebytes Anti-Malware setup file to your Desktop.

    OR from this location Here
  • Open mbam-setup.x.x.xxxx.exe (x represents the version #) and follow the prompts to install the programme.
  • Windows Vista, Windows 7 , 8, 8.1 and 10 : Right click and select "Run as Administrator"
    [external image: MBAM3_zpsw0f8rn9n.jpg]
    • After the installation IS complete let it update if it asks.
    • Under SETTINGS…..APPLICATIONS leave everything at default
    • Under SETTINGS…..PROTECTION make sure AUTOMATIC QUARANTINE is on.
    • Then go to the Dashboard and click on SCAN NOW
    • When the scan is finished click on EXPORT SUMMARY……COPY TO CLIPBOARD
    • Then come back to this thread and and under REPLY TO THIS TOPIC, right click in the reply and select Paste
    • Then click on POST
    • Exit Malwarebytes
~~
please post these 3 logs when finished.

Ok uninstalled Commodo but it never felt like it did anything other than an update prompt. So what's the deal with it? The one that was giving me pop-ups is gone on the AdwCleaner scan, and still no sound driver, but comp feels slightly more responsive now, thanks. And here are the other logs…
 

Fix result of Farbar Recovery Scan Tool (x64) Version: 09-08-2017
Ran by [removed] (13-08-2017 04:56:00) Run:1
Running from C:\Users\[removed]\Desktop
[removed]
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
 
CreateRestorePoint:
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers1: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAShell.dll -> No File
ContextMenuHandlers3: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers3: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers5: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAShell.dll -> No File
ContextMenuHandlers6: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAShell.dll -> No File
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
GroupPolicy: Restriction <==== ATTENTION
HKU\S-1-5-21-384921765-1548902971-3406650631-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://us.yahoo.com/?fr=fp-comodo&type=19_25050030005_52.15.25.664_u_hp
SearchScopes: HKU\S-1-5-21-384921765-1548902971-3406650631-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
S3 PSKMAD; C:\Windows\System32\DRIVERS\PSKMAD.sys [50320 2015-01-29] (Panda Security, S.L.)
C:\Windows\System32\DRIVERS\PSKMAD.sys
C:\ProgramData\nakuvtjg.ewu
2017-03-01 18:50 - 2017-07-04 10:12 - 085152552 _____ (Avant Force) C:\Users\salty-san\AppData\Local\Temp\$avantbrowser$.update.exe
2017-04-22 17:29 - 2017-04-22 17:29 - 000036864 _____ () C:\Users\salty-san\AppData\Local\Temp\CmdLineExt02.dll
2017-04-22 17:29 - 2017-04-22 17:29 - 000012067 _____ () C:\Users\salty-san\AppData\Local\Temp\SIntf16.dll
2017-04-22 17:29 - 2017-04-22 17:29 - 000019924 _____ () C:\Users\salty-san\AppData\Local\Temp\SIntf32.dll
2017-04-22 17:29 - 2017-04-22 17:29 - 000024516 _____ () C:\Users\salty-san\AppData\Local\Temp\SIntfNT.dll
2017-03-13 04:08 - 2017-03-13 04:08 - 007682154 _____ () C:\Users\salty-san\AppData\Local\Temp\tmp153C.tmp.exe
2017-02-25 00:40 - 2017-02-25 00:40 - 007663397 _____ () C:\Users\salty-san\AppData\Local\Temp\tmp87E9.tmp.exe
2017-04-19 21:52 - 2016-04-04 02:19 - 000116796 _____ () C:\Users\salty-san\AppData\Local\Temp\Uninstall.exe
2007-09-22 00:33 - 2007-09-22 00:33 - 000456416 ____R (Macrovision Corporation) C:\Users\salty-san\AppData\Local\Temp\_is9530.exe
2007-09-22 00:33 - 2007-09-22 00:33 - 000456416 ____R (Macrovision Corporation) C:\Users\salty-san\AppData\Local\Temp\_isC2BA.exe
Emptytemp:
 
*****************
 
Restore point was successfully created.
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast => key removed successfully
HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => key not found. 
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avg => key removed successfully
HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => key not found. 
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\UAContextMenu => key removed successfully
HKLM\Software\Classes\CLSID\{A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => key removed successfully
HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\00avast => key removed successfully
HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => key not found. 
HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\00avg => key removed successfully
HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => key not found. 
HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\UAContextMenu => key removed successfully
HKLM\Software\Classes\CLSID\{A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => key not found. 
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\UAContextMenu => key removed successfully
HKLM\Software\Classes\CLSID\{A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => key not found. 
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender => key removed successfully
C:\Windows\system32\GroupPolicy\Machine => moved successfully
C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully
C:\Windows\SysWOW64\GroupPolicy\GPT.ini => moved successfully
HKU\S-1-5-21-384921765-1548902971-3406650631-1000\Software\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKU\S-1-5-21-384921765-1548902971-3406650631-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
HKLM\System\CurrentControlSet\Services\PSKMAD => key removed successfully
PSKMAD => service removed successfully
C:\Windows\System32\DRIVERS\PSKMAD.sys => moved successfully
C:\ProgramData\nakuvtjg.ewu => moved successfully
C:\Users\salty-san\AppData\Local\Temp\$avantbrowser$.update.exe => moved successfully
C:\Users\salty-san\AppData\Local\Temp\CmdLineExt02.dll => moved successfully
C:\Users\salty-san\AppData\Local\Temp\SIntf16.dll => moved successfully
C:\Users\salty-san\AppData\Local\Temp\SIntf32.dll => moved successfully
C:\Users\salty-san\AppData\Local\Temp\SIntfNT.dll => moved successfully
C:\Users\salty-san\AppData\Local\Temp\tmp153C.tmp.exe => moved successfully
C:\Users\salty-san\AppData\Local\Temp\tmp87E9.tmp.exe => moved successfully
C:\Users\salty-san\AppData\Local\Temp\Uninstall.exe => moved successfully
C:\Users\salty-san\AppData\Local\Temp\_is9530.exe => moved successfully
C:\Users\salty-san\AppData\Local\Temp\_isC2BA.exe => moved successfully
 
=========== EmptyTemp: ==========
 
BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 338799111 B
Java, Flash, Steam htmlcache => 770 B
Windows/system/drivers => 216073861 B
Edge => 0 B
Chrome => 0 B
Firefox => 377587065 B
Opera => 73833862 B
 
Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 0 B
systemprofile32 => 20789114 B
LocalService => 0 B
NetworkService => 0 B
salty-san => 1317993721 B
 
RecycleBin => 1642600 B
EmptyTemp: => 2.2 GB temporary data Removed.
 
================================
 
 
The system needed a reboot.
 
==== End of Fixlog 05:04:52 ====
 
 
# AdwCleaner 7.0.1.0 - Logfile created on Sun Aug 13 03:52:33 2017
# Updated on 2017/05/08 by Malwarebytes 
# Running on Windows 7 Ultimate (X64)
# Mode: clean
# Support: https://www.malwarebytes.com/support
 
***** [ Services ] *****
 
No malicious services deleted.
 
***** [ Folders ] *****
 
Deleted: C:\Users\salty-san\AppData\Roaming\Mobogenie
Deleted: C:\Users\salty-san\Documents\Mobogenie
Deleted: C:\Program Files (x86)\Mobogenie3
Deleted: C:\ProgramData\DriverAgentPlus
Deleted: C:\ProgramData\Application Data\DriverAgentPlus
Deleted: C:\Users\All Users\DriverAgentPlus
Deleted: C:\Users\salty-san\AppData\Roaming\DriverAgentPlus
 
 
***** [ Files ] *****
 
No malicious files deleted.
 
***** [ DLL ] *****
 
No malicious DLLs cleaned.
 
***** [ WMI ] *****
 
No malicious WMI cleaned.
 
***** [ Shortcuts ] *****
 
No malicious shortcuts cleaned.
 
***** [ Tasks ] *****
 
No malicious tasks deleted.
 
***** [ Registry ] *****
 
Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\DOMStorage\cloudfront.net
Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\DOMStorage\cloudfront.net
Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\DOMStorage\d2uzdrx7k4koxz.cloudfront.net
Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\DOMStorage\d2uzdrx7k4koxz.cloudfront.net
Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\chatango.com
Deleted: [Key] - HKU\S-1-5-21-384921765-1548902971-3406650631-1000\Software\eSupport.com
Deleted: [Key] - HKCU\Software\eSupport.com
Deleted: [Key] - HKU\.DEFAULT\Software\Mobogenie
Deleted: [Key] - HKU\S-1-5-18\Software\Mobogenie
 
 
***** [ Firefox (and derivatives) ] *****
 
No malicious Firefox entries deleted.
 
***** [ Chromium (and derivatives) ] *****
 
No malicious Chromium entries deleted.
 
*************************
 
::Tracing keys deleted
::Winsock settings cleared
::Additional Actions: 0
 
 
 
*************************
 
C:/AdwCleaner/AdwCleaner[S0].txt - [2171 B] - [2017/8/13 3:46:41]
 
 
########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt ##########
 
 
Malwarebytes
www.malwarebytes.com
 
-Log Details-
Scan Date: 8/13/17
Scan Time: 7:17 AM
Log File: Malawarebytes Scan!.txt
Administrator: Yes
 
-Software Information-
Version: 3.1.2.1733
Components Version: 1.0.160
Update Package Version: 1.0.2573
License: Trial
 
-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Saltysky\salty-san
 
-Scan Summary-
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 344495
Threats Detected: 2
Threats Quarantined: 2
Time Elapsed: 5 min, 42 sec
 
-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
 
-Scan Details-
Process: 0
(No malicious items detected)
 
Module: 0
(No malicious items detected)
 
Registry Key: 2
PUP.Optional.ByteFence, HKLM\SOFTWARE\MICROSOFT\TRACING\ByteFence_RASAPI32, Quarantined, [613], [389038],1.0.2573
PUP.Optional.ByteFence, HKLM\SOFTWARE\MICROSOFT\TRACING\ByteFence_RASMANCS, Quarantined, [613], [389038],1.0.2573
 
Registry Value: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Data Stream: 0
(No malicious items detected)
 
Folder: 0
(No malicious items detected)
 
File: 0
(No malicious items detected)
 
Physical Sector: 0
(No malicious items detected)
 
 
(end)

 

Commodo but it never felt like it did anything other than an update prompt. So what's the deal with it?

Could be likely other security apps on the machine interfered.

After we run a couple more scans for malware, if still no sound, I'll get you to post in the tech forum to see if they can figure that out.

~~
Zemana AntiMalware Free
download it from here:


Double-click on the file named Zemana.AntiMalware.Portable to perform a system scan with Zemana AntiMalware Free.

You may be presented with a User Account Control dialog asking you if you want to run this program. If this happens, you should click Yes to allow Zemana AntiMalware to run.
When Zemana AntiMalware starts, click on the Scan button to perform a system scan.
without changing any options, press Scan

When Zemana has finished finished scanning it will show a screen that displays any malware that has been detected. To remove all the malicious files, click on the Next button.
Zemana AntiMalware will now start to remove all the malicious programs from your computer.
Note: If restart is required to finish the cleaning process, you should click Reboot. If reboot isn't required, please restart your computer manually.
  • open Zemana AntiMalware again and locate the latest report
  • please paste the contents into your reply

  • When the process is complete, you can close Zemana AntiMalware
~~

Emsisoft Emergency Kit

Please download Emsisoft Emergency Kit and save it to your desktop. Double click on the EmsisoftEmergencyKit file you downloaded to extract its contents and create a shortcut on the desktop. Leave all settings as they are and click the Extract button at the bottom. A folder named EEK will be created in the root of the drive (usually c:\).
  • After extraction please double-click on the new Start Emsisoft Emergency Kit icon on your desktop.
  • The first time you launch it, Emsisoft Emergency Kit will recommend that you allow it to download updates. Please click Yes so that it downloads the latest database updates.
  • When update is complete, click Malware Scan. When asked if you want the scanner to scan for Potentially Unwanted Programs, click Yes. Emsisoft Emergency Kit will start scanning.
  • When the scan is completed click Quarantine selected objects. Note, this option is only available if malicious objects were detected during the scan.
  • When the threats have been quarantined, click the View report button in the lower-right corner, and the scan log will be opened in Notepad.
  • Please save the log in Notepad on your desktop and post the contents in your next reply.
  • When you close Emsisoft Emergency Kit, it will give you an option to sign up for a newsletter. This is optional, and is not necessary for the malware removal process.
Please post these 2 logs when finished.

Well I wanted to clean comp anyway, but I am pretty sure the sound damage is just due to that one screen recording software I already uninstalled before doing these scans. Even as I was messing with its sound options for where it should record it crashed the comp, but otherwise had no problems. I just don't get why driver reinstall doesn't work then.

Anyway here are the logs and they didn't have that much. The genie thing is what gave me popup adds.
 

Zemana AntiMalware 2.74.2.76 (Installed)
 
——————————————————-
Scan Result            : Completed
Scan Date              : 2017/8/13
Operating System       : Windows 7 64-bit
Processor              : 2X Intel(R) Celeron(R) CPU B815 @ 1.60GHz
BIOS Mode              : Legacy
CUID                   : 123194E6AFCF69860EBBEB
Scan Type              : System Scan
Duration               : 15m 8s
Scanned Objects        : 107477
Detected Objects       : 5
Excluded Objects       : 0
Read Level             : SCSI
Auto Upload            : Enabled
Detect All Extensions  : Disabled
Scan Documents         : Disabled
Domain Info            : WORKGROUP,0,2
 
Detected Objects
——————————————————-
 
GenieFloater.exe
Status             : Scanned
Object             : %programfiles%\genie soft\genie cleaner\geniefloater.exe
MD5                : 5855EE6FD18BD683398C597705B52E5C
Publisher          : LeCheng(beijing) Technology Development Co.Ltd.
Size               : 1850520
Version            : 1.0.0.1
Detection          : Adware:Win32/AutoBulk.c5ea7c!Ep
Cleaning Action    : Quarantine
Related Objects    :
                File - %programfiles%\genie soft\genie cleaner\geniefloater.exe
                Process - 2356 - C:\Program Files (x86)\Genie Soft\Genie Cleaner\GenieFloater.exe
                Registry Entry - HKCU\Software\Microsoft\Windows\CurrentVersion\Run\GenieFloater = C:\Program Files (x86)\Genie Soft\Genie Cleaner\GenieFloater.exe
 
GenieCleaner.exe
Status             : Scanned
Object             : %programfiles%\genie soft\genie cleaner\geniecleaner.exe
MD5                : F2F63F67F3B20CF18A40EE9AE31B6500
Publisher          : LeCheng(beijing) Technology Development Co.Ltd.
Size               : 785048
Version            : 1.0.0.2
Detection          : Adware:Win32/AutoBulk.c5ea7c!Ep
Cleaning Action    : Quarantine
Related Objects    :
                File - %programfiles%\genie soft\genie cleaner\geniecleaner.exe
                Reference - C:\Users\salty-san\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Genie Cleaner.lnk
 
log.dll
Status             : Scanned
Object             : %programfiles%\genie soft\genie cleaner\log.dll
MD5                : FBFEC94B4BE3344424528BF1BA0E09F6
Publisher          : LeCheng(beijing) Technology Development Co.Ltd.
Size               : 728216
Version            : 1.0.0.6
Detection          : Adware:Win32/AutoBulk.c5ea7c!Ep
Cleaning Action    : Quarantine
Related Objects    :
                File - %programfiles%\genie soft\genie cleaner\log.dll
                DLL - 2356 - C:\Program Files (x86)\Genie Soft\Genie Cleaner\GenieFloater.exe
                DLL - 2596 - C:\Program Files (x86)\Genie Soft\Genie Cleaner\GenieCleanService.exe
 
GenieCleanService.exe
Status             : Scanned
Object             : %programfiles%\genie soft\genie cleaner\geniecleanservice.exe
MD5                : 8DD9C4243510CCB45844A6C5FBCC6421
Publisher          : LeCheng(beijing) Technology Development Co.Ltd.
Size               : 53400
Version            : 1.0.0.1
Detection          : Adware:Win32/AutoBulk.c5ea7c!Ep
Cleaning Action    : Quarantine
Related Objects    :
                File - %programfiles%\genie soft\genie cleaner\geniecleanservice.exe
                Process - 2596 - C:\Program Files (x86)\Genie Soft\Genie Cleaner\GenieCleanService.exe
                Registry Entry - HKLM\System\CurrentControlSet\Services\GenieCleanService\ImagePath = "C:\Program Files (x86)\Genie Soft\Genie Cleaner\GenieCleanService.exe"
 
MGCommon.dll
Status             : Scanned
Object             : %programfiles%\genie soft\genie cleaner\mgcommon.dll
MD5                : 18D2B2253960F4FCF00B1C4B70ECD258
Publisher          : LeCheng(beijing) Technology Development Co.Ltd.
Size               : 50840
Version            : 1.0.0.1003
Detection          : Adware:Win32/AutoBulk.c5ea7c!Ep
Cleaning Action    : Quarantine
Related Objects    :
                File - %programfiles%\genie soft\genie cleaner\mgcommon.dll
                DLL - 2596 - C:\Program Files (x86)\Genie Soft\Genie Cleaner\GenieCleanService.exe
 
 
Cleaning Result
——————————————————-
Cleaned               : 5
Reported as safe      : 0
Failed                : 0
 
 
 
And then the 2nd log…
 
 
 
Emsisoft Emergency Kit - Version 2017.6
Last update: 8/13/2017 3:23:49 PM
User account: Saltysky\salty-san
Computer name: SALTYSKY
OS version: Windows 7x64 Service Pack 1
 
Scan settings:
 
Scan type: Malware Scan
Objects: Rootkits, Memory, Traces, Files
 
Detect PUPs: On
Scan archives: Off
Scan mail archives: Off
ADS Scan: On
File extension filter: Off
Direct disk access: Off
 
Scan start: 8/13/2017 3:24:21 PM
Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\F detected: Application.AdReg (A) [271742]
 
Scanned 79270
Found 1
 
Scan end: 8/13/2017 3:29:03 PM
Scan time: 0:04:42
 
Key: HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\F Application.AdReg (A)
 
Quarantined 1
 
I've read/heard that uninstalling/deleting the driver through the hardware devices,…sometimes works but I'm not that familiar with that part of windows.

I think the computer is cleaned up.

I want you to run a tool that will remove the tools and quarantine folders we used then, I want you to start a new topic in this forum describing whats going on with no sound.

https://forums.whatthetech.com/index.php?showforum=119

DelFix
  • Please download DelFix or from Here and save the file to your Desktop.
  • Double-click DelFix.exe to run the programme.
  • Place a checkmark next to the following items:
  • Activate UAC
  • Remove disinfection tools
  • Click the Run button.
  • – This will remove the specialized tools we used to disinfect your system.
    Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually (right-click the file + delete
    ).
*********************

I've read/heard that uninstalling/deleting the driver through the hardware devices,…sometimes works but I'm not that familiar with that part of windows.

I think the computer is cleaned up.

I want you to run a tool that will remove the tools and quarantine folders we used then, I want you to start a new topic in this forum describing whats going on with no sound.
 

 

Figured this might be a different issue but that's cool. Glad to know at least that I wasn't that infected, so I know how to avoid issues. I'll do the topic there then and thanks for the help.
 

# DelFix v1.010 - Logfile created 13/08/2017 at 20:21:41
# Updated 26/04/2015 by Xplode
# Username : salty-san - SALTYSKY
# Operating System : Windows 7 Ultimate Service Pack 1 (64 bits)
 
~ Activating UAC … OK
 
~ Removing disinfection tools …
 
Deleted : C:\FRST
Deleted : C:\AdwCleaner
Deleted : C:\Users\salty-san\Desktop\AdwCleaner.exe
Deleted : C:\Users\salty-san\Desktop\aswMBR.exe
Deleted : C:\Users\salty-san\Desktop\Fixlog.txt
Deleted : C:\Users\salty-san\Desktop\FRST64.exe
Deleted : HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWMBR
 
########## - EOF - ##########

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI