Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

AVG still detecting tracking cookies, even after factory reset


  • This topic is locked This topic is locked
2 replies to this topic

#1 pneumbra

pneumbra

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:10:33 PM

Posted 15 February 2016 - 12:08 AM

So yeah, I'm using AVG as my antivirus and the scan results yield tracking cookies pretty often. This has been a persisting problem and I've tried various programs to get rid of the problem but to no avail. I've even gone to the extent of performing a factory reset on my computer at least twice. After the second reset, which was completed today, I briefly used the internet to reinstall the basic things I had on my computer before: AVG, Wacom, the likes. No odd websites or anything... but shortly after AVG detected like nine more tracking cookies. An hours time passes and it finds like seven more. I don't know what could be causing it so... I'm getting a little bit desperate to say in the least.

 

Here are the logs and stuff...

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:07-02-2016
Ran by Leopardus (administrator) on SUFFERBOX (14-02-2016 23:53:18)
Running from C:\Users\Leopardus\Downloads
Loaded Profiles: Leopardus (Available Profiles: Leopardus)
Platform: Windows 8.1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgcsrva.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\WTabletServicePro.exe
(Wacom Technology) C:\Program Files\Tablet\Wacom\WacomHost.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgfws.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgwdsvcx.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel Corporation) C:\Windows\SysWOW64\IntelCpHeciSvc.exe
(Wacom Technology) C:\Program Files\Tablet\Wacom\WacomHost.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
(Apple Inc.) C:\Program Files\iTunes\iTunes.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgemca.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgui.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
(Microsoft Corporation) C:\Windows\System32\WWAHost.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170256 2015-12-17] (Apple Inc.)
HKLM-x32\...\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirnx.exe [179624 2016-01-12] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\Av\avgui.exe [3873704 2016-02-01] (AVG Technologies CZ, s.r.o.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1886550942-2161786841-2615824287-1001\...\RunOnce: [BeginInteractiveOSUpgrade] => C:\Windows\system32\wuauclt.exe [136904 2015-10-20] (Microsoft Corporation)
HKU\S-1-5-21-1886550942-2161786841-2615824287-1001\...\MountPoints2: {5782cc6f-d32a-11e5-824e-806e6f6e6963} - "E:\Startup.exe"

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{B308F407-62B4-4755-ABCB-96CD170A0F31}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================

FireFox:
========
FF Plugin: @wacom.com/wtPlugin,version=2.1.0.7 -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin: wacom.com/WacomTabletPlugin -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-10-14] ()
FF Plugin-x32: @wacom.com/wtPlugin,version=2.1.0.7 -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin-x32: wacom.com/WacomTabletPlugin -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77104 2015-10-07] (Apple Inc.)
S3 AvgAMPS; C:\Program Files (x86)\AVG\Av\avgamps.exe [604144 2016-02-01] (AVG Technologies CZ, s.r.o.)
R2 avgfws; C:\Program Files (x86)\AVG\Av\avgfws.exe [1580352 2016-02-01] (AVG Technologies CZ, s.r.o.)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\Av\avgidsagent.exe [3881184 2016-02-01] (AVG Technologies CZ, s.r.o.)
R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1048488 2016-01-12] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\Av\avgwdsvcx.exe [561104 2016-02-01] (AVG Technologies CZ, s.r.o.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-11-21] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-11-21] (Microsoft Corporation)
R2 WTabletServicePro; C:\Program Files\Tablet\Wacom\WTabletServicePro.exe [730304 2016-01-11] (Wacom Technology, Corp.)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S0 Avgboota; C:\Windows\System32\DRIVERS\avgboota.sys [21632 2016-01-07] (AVG Technologies CZ, s.r.o.)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [184240 2015-11-06] (AVG Technologies CZ, s.r.o.)
R1 Avgfwfd; C:\Windows\system32\DRIVERS\avgfwd6a.sys [97208 2015-08-29] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [315312 2016-01-05] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [272304 2016-01-08] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [284080 2015-10-21] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [398256 2015-08-14] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [260528 2016-01-22] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [42416 2015-12-04] (AVG Technologies CZ, s.r.o.)
R0 Avguniva; C:\Windows\System32\DRIVERS\avguniva.sys [23472 2016-01-08] (AVG Technologies CZ, s.r.o.)
R1 Avgwfpa; C:\Windows\system32\DRIVERS\avgwfpa.sys [315840 2015-12-16] (AVG Technologies CZ, s.r.o.)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [1936088 2013-07-31] (Realtek Semiconductor Corporation                           )
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [35856 2014-11-21] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [257880 2014-11-21] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-11-21] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-02-14 23:53 - 2016-02-14 23:53 - 00008503 _____ C:\Users\Leopardus\Downloads\FRST.txt
2016-02-14 23:52 - 2016-02-14 23:53 - 00000000 ____D C:\FRST
2016-02-14 23:42 - 2016-02-14 23:42 - 02370560 _____ (Farbar) C:\Users\Leopardus\Downloads\FRST64.exe
2016-02-14 23:27 - 2016-02-14 23:30 - 00000000 ___HD C:\$WINDOWS.~BT
2016-02-14 22:27 - 2016-02-14 22:27 - 00001083 _____ C:\Users\Leopardus\Desktop\Paint Tool SIGH.lnk
2016-02-14 22:26 - 2016-02-14 22:26 - 00000000 ____D C:\Users\Leopardus\AppData\Roaming\SYSTEMAX Software Development
2016-02-14 22:26 - 2016-02-14 22:26 - 00000000 ____D C:\ProgramData\SYSTEMAX Software Development
2016-02-14 22:24 - 2016-02-14 22:24 - 00000000 ____D C:\Users\Leopardus\AppData\Roaming\AVG
2016-02-14 22:24 - 2016-02-14 22:24 - 00000000 ____D C:\Program Files\Common Files\AV
2016-02-14 22:22 - 2016-02-14 22:22 - 00000000 ___HD C:\$AVG
2016-02-14 22:22 - 2016-02-14 22:22 - 00000000 ____D C:\Users\Leopardus\AppData\Roaming\TuneUp Software
2016-02-14 22:22 - 2016-02-14 22:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2016-02-14 22:16 - 2016-02-14 22:58 - 00000000 ____D C:\ProgramData\MFAData
2016-02-14 22:16 - 2016-02-14 22:16 - 00000882 _____ C:\Users\Public\Desktop\AVG.lnk
2016-02-14 22:16 - 2016-02-14 22:16 - 00000000 ____D C:\Users\Leopardus\AppData\Local\MFAData
2016-02-14 22:16 - 2016-02-14 22:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG Zen
2016-02-14 22:12 - 2016-02-14 22:21 - 00000000 ____D C:\Program Files (x86)\AVG
2016-02-14 22:05 - 2016-02-14 22:05 - 00029760 _____ C:\Users\Leopardus\Downloads\elemap.zip
2016-02-14 22:04 - 2016-02-14 22:22 - 00000000 ____D C:\ProgramData\Avg
2016-02-14 22:04 - 2016-02-14 22:05 - 07878617 _____ C:\Users\Leopardus\Downloads\brushtex.zip
2016-02-14 22:02 - 2016-02-14 22:07 - 00000000 ____D C:\Users\Leopardus\AppData\Roaming\Apple Computer
2016-02-14 22:02 - 2016-02-14 22:02 - 00001772 _____ C:\Users\Public\Desktop\iTunes.lnk
2016-02-14 22:02 - 2016-02-14 22:02 - 00000000 ____D C:\Users\Leopardus\AppData\Local\Apple Computer
2016-02-14 22:02 - 2016-02-14 22:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2016-02-14 22:01 - 2016-02-14 22:24 - 00000000 ____D C:\Users\Leopardus\AppData\Local\Avg
2016-02-14 22:01 - 2016-02-14 22:16 - 00000000 ____D C:\Users\Leopardus\AppData\Local\AvgSetupLog
2016-02-14 22:01 - 2016-02-14 22:02 - 00000000 ____D C:\Program Files\iTunes
2016-02-14 22:01 - 2016-02-14 22:01 - 00000000 ____D C:\ProgramData\Apple Computer
2016-02-14 22:01 - 2016-02-14 22:01 - 00000000 ____D C:\Program Files\iPod
2016-02-14 22:01 - 2016-02-14 22:01 - 00000000 ____D C:\Program Files (x86)\iTunes
2016-02-14 22:00 - 2016-02-14 22:00 - 02946424 _____ (AVG Technologies CZ, s.r.o.) C:\Users\Leopardus\Downloads\AVG_Protection_Free_698.exe
2016-02-14 21:59 - 2016-02-14 21:59 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf
2016-02-14 20:24 - 2015-12-08 22:39 - 00301728 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2016-02-14 19:52 - 2016-02-14 19:52 - 00003946 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{17B6F653-83F7-4F67-A0EE-8FFD465B8537}
2016-02-14 19:52 - 2016-02-14 16:53 - 00000000 __SHD C:\Users\Leopardus\AppData\LocalLow\EmieSiteList
2016-02-14 19:51 - 2016-02-14 23:26 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1886550942-2161786841-2615824287-1001
2016-02-14 19:51 - 2016-02-14 19:51 - 00000000 ____D C:\Users\Leopardus\AppData\Local\GWX
2016-02-14 19:47 - 2016-02-14 23:44 - 00000000 ____D C:\Users\Leopardus\OneDrive
2016-02-14 19:47 - 2016-02-14 19:47 - 00000000 ___HD C:\OneDriveTemp
2016-02-14 19:46 - 2016-02-14 19:46 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-02-14 19:46 - 2016-02-14 19:46 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2016-02-14 19:46 - 2016-02-14 19:46 - 00000000 ____D C:\Users\Leopardus\AppData\Local\PackageStaging
2016-02-14 19:45 - 2016-02-14 19:47 - 00000000 ____D C:\Users\Leopardus\AppData\Local\Packages
2016-02-14 19:45 - 2016-02-14 19:45 - 00001453 _____ C:\Users\Leopardus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2016-02-14 19:45 - 2016-02-14 19:45 - 00000000 ____D C:\Users\Leopardus\AppData\Roaming\Adobe
2016-02-14 19:45 - 2016-02-14 19:45 - 00000000 ____D C:\Users\Leopardus\AppData\Local\VirtualStore
2016-02-14 19:45 - 2016-02-14 19:45 - 00000000 ____D C:\Program Files (x86)\Intel
2016-02-14 19:45 - 2016-02-14 19:45 - 00000000 ____D C:\Intel
2016-02-14 19:41 - 2016-02-14 19:45 - 00000000 ___SD C:\Windows\system32\GWX
2016-02-14 19:41 - 2016-02-14 19:41 - 00000000 ___SD C:\Windows\SysWOW64\GWX
2016-02-14 19:40 - 2016-02-14 23:21 - 00000000 ____D C:\Users\Leopardus
2016-02-14 19:40 - 2016-02-14 19:40 - 00000020 ___SH C:\Users\Leopardus\ntuser.ini
2016-02-14 19:40 - 2016-02-14 19:40 - 00000000 _SHDL C:\Users\Leopardus\My Documents
2016-02-14 19:40 - 2016-02-14 19:40 - 00000000 _SHDL C:\Users\Leopardus\Documents\My Videos
2016-02-14 19:40 - 2016-02-14 19:40 - 00000000 _SHDL C:\Users\Leopardus\Documents\My Pictures
2016-02-14 19:40 - 2016-02-14 19:40 - 00000000 _SHDL C:\Users\Leopardus\Documents\My Music
2016-02-14 19:40 - 2015-11-14 09:50 - 00133248 _____ (Microsoft Corporation) C:\Windows\system32\RestoreOptIn.exe
2016-02-14 19:40 - 2015-11-14 09:50 - 00114160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RestoreOptIn.exe
2016-02-14 19:40 - 2015-10-20 16:54 - 00136904 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2016-02-14 19:40 - 2015-10-20 09:53 - 03705856 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2016-02-14 19:40 - 2015-10-20 09:36 - 02243072 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2016-02-14 19:40 - 2015-10-20 09:35 - 00891904 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2016-02-14 19:40 - 2015-10-20 09:34 - 00409088 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll
2016-02-14 19:40 - 2015-10-20 09:34 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2016-02-14 19:40 - 2015-10-20 09:34 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2016-02-14 19:40 - 2015-10-20 09:33 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2016-02-14 19:40 - 2015-10-20 09:14 - 00721920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2016-02-14 19:40 - 2015-10-20 09:13 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2016-02-14 19:40 - 2015-10-20 09:13 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2016-02-14 19:40 - 2015-10-20 09:13 - 00029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2016-02-14 19:40 - 2015-08-10 21:47 - 02757072 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2016-02-14 19:40 - 2015-08-10 21:47 - 02414096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2016-02-14 19:40 - 2015-07-09 13:40 - 00359936 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2016-02-14 19:40 - 2015-06-26 22:08 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2016-02-14 19:40 - 2015-06-26 22:08 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2016-02-14 19:40 - 2015-06-26 21:14 - 00027136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2016-02-14 19:40 - 2015-03-13 20:51 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2016-02-14 19:40 - 2014-11-21 03:52 - 00000369 _____ C:\Users\Leopardus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk
2016-02-14 19:40 - 2014-11-21 03:52 - 00000369 _____ C:\Users\Leopardus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk
2016-02-14 19:40 - 2014-10-18 01:50 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\wuaext.dll
2016-02-14 18:01 - 2016-02-14 18:01 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wacom Tablet
2016-02-14 18:01 - 2016-02-14 18:01 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_silabser_01009.Wdf
2016-02-14 18:01 - 2016-02-14 18:01 - 00000000 ____D C:\Program Files\TabletPlugins
2016-02-14 18:01 - 2016-02-14 18:01 - 00000000 ____D C:\Program Files (x86)\TabletPlugins
2016-02-14 18:01 - 2014-12-01 13:43 - 00079360 _____ (Silicon Laboratories) C:\Windows\system32\Drivers\silabser.sys
2016-02-14 18:01 - 2014-12-01 13:43 - 00023552 _____ (Silicon Laboratories) C:\Windows\system32\Drivers\silabenm.sys
2016-02-14 18:00 - 2015-11-30 12:34 - 00015040 _____ (Wacom Technology) C:\Windows\system32\Drivers\wacomrouterfilter.sys
2016-02-14 17:59 - 2016-02-14 18:01 - 00000000 ____D C:\Program Files\Tablet
2016-02-14 17:59 - 2016-02-14 17:59 - 00002535 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2016-02-14 17:59 - 2016-02-14 17:59 - 00000000 ____D C:\Windows\System32\Tasks\Apple
2016-02-14 17:59 - 2016-02-14 17:59 - 00000000 ____D C:\Users\Leopardus\AppData\Roaming\WTablet
2016-02-14 17:59 - 2016-02-14 17:59 - 00000000 ____D C:\Users\Leopardus\AppData\Local\Apple
2016-02-14 17:59 - 2016-02-14 17:59 - 00000000 ____D C:\Program Files\Bonjour
2016-02-14 17:59 - 2016-02-14 17:59 - 00000000 ____D C:\Program Files (x86)\Bonjour
2016-02-14 17:59 - 2016-02-14 17:59 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
2016-02-14 17:59 - 2016-01-11 12:30 - 02103488 _____ (Wacom Technology, Corp.) C:\Windows\system32\WacomMT.dll
2016-02-14 17:59 - 2016-01-11 12:30 - 02077888 _____ (Wacom Technology, Corp.) C:\Windows\system32\Wacom_Tablet.dll
2016-02-14 17:59 - 2016-01-11 12:30 - 02071232 _____ (Wacom Technology, Corp.) C:\Windows\system32\Wacom_Touch_Tablet.dll
2016-02-14 17:59 - 2016-01-11 12:30 - 01966272 _____ (Wacom Technology, Corp.) C:\Windows\system32\Wintab32.dll
2016-02-14 17:59 - 2016-01-11 12:30 - 01683648 _____ (Wacom Technology, Corp.) C:\Windows\SysWOW64\WacomMT.dll
2016-02-14 17:59 - 2016-01-11 12:30 - 01681600 _____ (Wacom Technology, Corp.) C:\Windows\SysWOW64\Wacom_Tablet.dll
2016-02-14 17:59 - 2016-01-11 12:30 - 01674432 _____ (Wacom Technology, Corp.) C:\Windows\SysWOW64\Wacom_Touch_Tablet.dll
2016-02-14 17:59 - 2016-01-11 12:30 - 01571520 _____ (Wacom Technology, Corp.) C:\Windows\SysWOW64\Wintab32.dll
2016-02-14 17:59 - 2015-11-30 12:34 - 00103616 _____ (Wacom Technology) C:\Windows\system32\Drivers\wachidrouter.sys
2016-02-14 17:59 - 2015-11-30 12:34 - 00014016 _____ (Windows ® Win 7 DDK provider) C:\Windows\system32\Drivers\hidkmdf.sys
2016-02-14 17:59 - 2012-12-11 17:12 - 01721576 _____ (Microsoft Corporation) C:\Windows\system32\wdfcoinstaller01009.dll
2016-02-14 17:59 - 2012-12-11 17:12 - 01721576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wdfcoinstaller01009.dll
2016-02-14 17:58 - 2016-02-14 22:01 - 00000000 ____D C:\Program Files\Common Files\Apple
2016-02-14 17:57 - 2016-02-14 17:59 - 00000000 ____D C:\ProgramData\Apple
2016-02-14 17:14 - 2016-02-14 17:41 - 167583000 _____ (Apple Inc.) C:\Users\Leopardus\Downloads\iTunes6464Setup.exe
2016-02-14 17:11 - 2016-02-14 17:11 - 00000000 ____D C:\Users\Leopardus\Downloads\Sai (Re-Uploaded)
2016-02-14 17:11 - 2016-02-14 17:11 - 00000000 ____D C:\Users\Leopardus\AppData\Roaming\WinRAR
2016-02-14 17:02 - 2016-02-14 17:11 - 42440186 _____ C:\Users\Leopardus\Downloads\Sai (Re-Uploaded).rar
2016-02-14 17:01 - 2016-02-14 17:01 - 00000000 ____D C:\Users\Leopardus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2016-02-14 17:01 - 2016-02-14 17:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2016-02-14 17:01 - 2016-02-14 17:01 - 00000000 ____D C:\Program Files\WinRAR
2016-02-14 17:00 - 2016-02-14 17:00 - 01992496 _____ C:\Users\Leopardus\Downloads\winrar-x64-531.exe
2016-02-14 16:55 - 2016-02-14 16:55 - 00000000 ____D C:\Users\Leopardus\AppData\Roaming\Macromedia
2016-02-14 16:53 - 2016-02-14 16:53 - 00000000 __SHD C:\Users\Leopardus\AppData\LocalLow\EmieUserList
2016-02-14 16:53 - 2016-02-14 16:53 - 00000000 __SHD C:\Users\Leopardus\AppData\LocalLow\EmieBrowserModeList
2016-02-14 16:53 - 2016-02-14 16:53 - 00000000 __SHD C:\Users\Leopardus\AppData\Local\EmieUserList
2016-02-14 16:53 - 2016-02-14 16:53 - 00000000 __SHD C:\Users\Leopardus\AppData\Local\EmieSiteList
2016-02-14 16:53 - 2016-02-14 16:53 - 00000000 __SHD C:\Users\Leopardus\AppData\Local\EmieBrowserModeList
2016-02-14 09:52 - 2016-02-14 09:52 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2016-02-14 09:51 - 2016-02-14 23:34 - 00000000 ____D C:\Windows\Panther
2016-02-14 09:50 - 2016-02-14 09:50 - 00000000 _____ C:\Recovery.txt
2016-01-22 15:15 - 2016-01-22 15:15 - 00260528 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgmfx64.sys

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-02-14 23:28 - 2014-11-21 03:44 - 00818732 _____ C:\Windows\system32\PerfStringBackup.INI
2016-02-14 23:28 - 2013-08-22 08:36 - 00000000 ____D C:\Windows\Inf
2016-02-14 23:27 - 2013-08-22 10:36 - 00000000 ___HD C:\Program Files\WindowsApps
2016-02-14 23:27 - 2013-08-22 10:36 - 00000000 ____D C:\Windows\AppReadiness
2016-02-14 23:21 - 2013-08-22 09:45 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-02-14 22:33 - 2013-08-22 08:25 - 00262144 ___SH C:\Windows\system32\config\ELAM
2016-02-14 22:22 - 2013-08-22 10:36 - 00000000 ___HD C:\Windows\ELAMBKUP
2016-02-14 22:09 - 2013-08-22 10:36 - 00000000 ____D C:\Windows\system32\NDF
2016-02-14 19:40 - 2013-08-22 08:36 - 00000000 ____D C:\Windows\system32\AdvancedInstallers
2016-02-14 18:40 - 2013-08-22 10:20 - 00000000 ____D C:\Windows\CbsTemp
2016-02-14 10:01 - 2013-08-22 10:36 - 00000000 ____D C:\Windows\rescache
2016-02-14 09:55 - 2013-08-22 08:25 - 00262144 ___SH C:\Windows\system32\config\BBI
2016-02-14 09:51 - 2013-08-22 09:44 - 00337808 _____ C:\Windows\system32\FNTCACHE.DAT
2016-02-14 09:50 - 2013-08-22 10:36 - 00262144 _____ C:\Windows\system32\config\BCD-Template

Some files in TEMP:
====================
C:\Users\Leopardus\AppData\Local\Temp\Setup-Wacom.exe

==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2016-02-14 09:51

==================== End of FRST.txt ============================

 

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version:07-02-2016
Ran by Leopardus (2016-02-14 23:54:19)
Running from C:\Users\Leopardus\Downloads
Windows 8.1 (X64) (2016-02-15 00:43:21)
Boot Mode: Normal
==========================================================

==================== Accounts: =============================

Administrator (S-1-5-21-1886550942-2161786841-2615824287-500 - Administrator - Disabled)
Guest (S-1-5-21-1886550942-2161786841-2615824287-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1886550942-2161786841-2615824287-1003 - Limited - Enabled)
Leopardus (S-1-5-21-1886550942-2161786841-2615824287-1001 - Administrator - Enabled) => C:\Users\Leopardus

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: AVG Internet Security (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG Internet Security (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}
FW: AVG Internet Security (Enabled) {757AB44A-78C2-7D1A-E37F-CA42A037B368}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Apple Application Support (32-bit) (HKLM-x32\...\{7FA9ECCF-A2DE-4DA1-BFF3-81260DBDA68F}) (Version: 4.1.2 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\...\{691F30EB-9009-475A-B8A9-E1BF39598FD5}) (Version: 4.1.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{3540181E-340A-4E7A-B409-31663472B2F7}) (Version: 9.1.0.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}) (Version: 2.1.4.131 - Apple Inc.)
AVG (HKLM\...\AvgZen) (Version: 1.31.1.48846 - AVG Technologies)
AVG (Version: 16.41.7442 - AVG Technologies) Hidden
AVG 2016 (Version: 16.0.4522 - AVG Technologies) Hidden
AVG Protection (HKLM\...\AVG) (Version: 2016.41.7442 - AVG Technologies)
AVG Zen (Version: 1.31.9 - AVG Technologies) Hidden
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
FMW 1 (Version: 1.52.1 - AVG Technologies) Hidden
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.4229 - Intel Corporation)
iTunes (HKLM\...\{FBEB98F8-64E4-4FA3-A15E-4A9F42FF962E}) (Version: 12.3.2.35 - Apple Inc.)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
Wacom Tablet (HKLM\...\Wacom Tablet Driver) (Version: 6.3.15-3 - Wacom Technology Corp.)
WebTablet FB Plugin 32 bit (HKLM-x32\...\Wacom WebTabletPlugin for Internet Explorer and Netscape) (Version: 2.1.0.7 - Wacom Technology Corp.)
WebTablet FB Plugin 64 bit (HKLM\...\Wacom WebTabletPlugin for Internet Explorer and Netscape) (Version: 2.1.0.7 - Wacom Technology Corp.)
WinRAR 5.31 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.31.0 - win.rar GmbH)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {96DD8F56-F71A-48D9-AB81-938DA5744DC7} - System32\Tasks\Microsoft\Windows\SetupSQMTask => C:\Windows\SYSTEM32\OOBE\SETUPSQM.EXE [2014-11-21] (Microsoft Corporation)
Task: {EE8EFE58-4B3A-4EF7-8337-79C472B1BD2D} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2015-08-27] (Apple Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

==================== Loaded Modules (Whitelisted) ==============

2015-12-17 18:38 - 2015-12-17 18:38 - 00085800 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-12-17 18:38 - 2015-12-17 18:38 - 01328912 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2015-12-17 18:38 - 2015-12-17 18:38 - 00306960 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxslt.dll
2016-02-14 17:59 - 2016-01-11 12:30 - 01349824 _____ () C:\Program Files\Tablet\Wacom\libxml2.dll
2015-06-01 21:00 - 2015-06-01 21:00 - 00102912 _____ () C:\Windows\System32\IccLibDll_x64.dll
2016-02-14 22:12 - 2016-02-14 22:09 - 40500224 _____ () C:\Program Files (x86)\AVG\UiDll\2171\libcef.dll
2015-12-17 18:39 - 2015-12-17 18:39 - 01040144 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2015-12-17 18:39 - 2015-12-17 18:39 - 00073512 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-08-22 08:25 - 2013-08-22 08:25 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1886550942-2161786841-2615824287-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Windows\img0.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{0932D3F8-137B-4CC4-AFE9-C3A27A2A0DC9}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{5612E103-FF84-46BA-831E-6420E77FE290}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{E2DC8220-367A-4E07-A943-B8BB0346BAD1}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{5021BFCB-F55F-4142-90A9-3618440E60F5}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{1C9A6829-BCF4-4D96-A30D-EABBD1AAB3BB}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{364BB3F3-FF1C-4D50-A72B-4940CE7C7C79}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe
FirewallRules: [{C7FE73B1-B5D8-4B45-84F6-97E6BFDA612C}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe
FirewallRules: [{C1A0893F-371B-4F6B-B2EB-424972F335F4}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe
FirewallRules: [{3D4472DE-93DF-4257-8A78-FA9709ACC5D2}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe
FirewallRules: [{8F97D108-FA26-4BE2-9B8C-A0F231BC500E}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{86EEA284-7149-4ED7-A5AC-5F9166583805}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{B29C9AD7-C495-44A1-B876-437DD5413EB9}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe
FirewallRules: [{EB3B460B-024A-4150-8443-70E35B736458}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe

==================== Restore Points =========================

14-02-2016 18:00:00 Installed iTunes
14-02-2016 19:40:18 Windows Modules Installer

==================== Faulty Device Manager Devices =============

Name: Base System Device
Description: Base System Device
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: Base System Device
Description: Base System Device
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

==================== Event log errors: =========================

Application errors:
==================
Error: (02/14/2016 11:25:39 PM) (Source: WTabletServicePro) (EventID: 1) (User: )
Description: Prefs: Failed to get user path

Error: (02/14/2016 11:25:33 PM) (Source: WTabletServicePro) (EventID: 1) (User: )
Description: Prefs: Failed to get user path

Error: (02/14/2016 10:59:19 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program IEXPLORE.EXE version 11.0.9600.17416 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 7f0

Start Time: 01d167a492f27077

Termination Time: 4294967295

Application Path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

Report Id: 7030bc3c-d398-11e5-8251-b888e3d44df7

Faulting package full name:

Faulting package-relative application ID:

Error: (02/14/2016 10:09:18 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: msiexec.exe, version: 5.0.9600.17415, time stamp: 0x54505262
Faulting module name: RPCRT4.dll, version: 6.3.9600.17415, time stamp: 0x545045a8
Exception code: 0xc0000005
Fault offset: 0x0000000000030b86
Faulting process id: 0x54c
Faulting application start time: 0xmsiexec.exe0
Faulting application path: msiexec.exe1
Faulting module path: msiexec.exe2
Report Id: msiexec.exe3
Faulting package full name: msiexec.exe4
Faulting package-relative application ID: msiexec.exe5

System errors:
=============
Error: (02/14/2016 11:25:20 PM) (Source: DCOM) (EventID: 10016) (User: SUFFERBOX)
Description: application-specificLocalLaunch{7022A3B3-D004-4F52-AF11-E9E987FEE25F}{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}SUFFERBOXLeopardusS-1-5-21-1886550942-2161786841-2615824287-1001LocalHost (Using LRPC)UnavailableUnavailable

Error: (02/14/2016 11:25:19 PM) (Source: DCOM) (EventID: 10016) (User: SUFFERBOX)
Description: application-specificLocalLaunch{7022A3B3-D004-4F52-AF11-E9E987FEE25F}{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}SUFFERBOXLeopardusS-1-5-21-1886550942-2161786841-2615824287-1001LocalHost (Using LRPC)UnavailableUnavailable

Error: (02/14/2016 11:25:19 PM) (Source: DCOM) (EventID: 10016) (User: SUFFERBOX)
Description: application-specificLocalLaunch{7022A3B3-D004-4F52-AF11-E9E987FEE25F}{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}SUFFERBOXLeopardusS-1-5-21-1886550942-2161786841-2615824287-1001LocalHost (Using LRPC)UnavailableUnavailable

Error: (02/14/2016 11:25:19 PM) (Source: DCOM) (EventID: 10016) (User: SUFFERBOX)
Description: application-specificLocalLaunch{7022A3B3-D004-4F52-AF11-E9E987FEE25F}{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}SUFFERBOXLeopardusS-1-5-21-1886550942-2161786841-2615824287-1001LocalHost (Using LRPC)UnavailableUnavailable

Error: (02/14/2016 11:25:19 PM) (Source: DCOM) (EventID: 10016) (User: SUFFERBOX)
Description: application-specificLocalLaunch{7022A3B3-D004-4F52-AF11-E9E987FEE25F}{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}SUFFERBOXLeopardusS-1-5-21-1886550942-2161786841-2615824287-1001LocalHost (Using LRPC)UnavailableUnavailable

Error: (02/14/2016 11:25:19 PM) (Source: DCOM) (EventID: 10016) (User: SUFFERBOX)
Description: application-specificLocalLaunch{7022A3B3-D004-4F52-AF11-E9E987FEE25F}{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}SUFFERBOXLeopardusS-1-5-21-1886550942-2161786841-2615824287-1001LocalHost (Using LRPC)UnavailableUnavailable

Error: (02/14/2016 11:24:45 PM) (Source: DCOM) (EventID: 10010) (User: SUFFERBOX)
Description: {1B1F472E-3221-4826-97DB-2C2324D389AE}

Error: (02/14/2016 11:24:18 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The AVGIDSAgent service hung on starting.

Error: (02/14/2016 11:20:59 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 10:43:01 PM on ‎2/‎14/‎2016 was unexpected.

Error: (02/14/2016 10:09:20 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Installer service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 120000 milliseconds: Restart the service.

CodeIntegrity:
===================================
  Date: 2016-02-14 23:53:00.855
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files (x86)\AVG\Av\avgidsagent.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-02-14 23:53:00.652
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files (x86)\AVG\Av\avgidsagent.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-02-14 23:52:56.146
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files (x86)\AVG\Av\avgidsagent.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-02-14 23:52:55.931
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files (x86)\AVG\Av\avgidsagent.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-02-14 23:24:58.506
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files (x86)\AVG\Av\avgidsagent.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\AVG\Framework\1\avgnetclix.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-02-14 23:24:54.706
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files (x86)\AVG\Av\avgidsagent.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\AVG\Framework\1\avgnetclix.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-02-14 23:24:53.314
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files (x86)\AVG\Av\avgidsagent.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\AVG\Framework\Common\avgfmwbasex.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-02-14 22:59:49.681
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files (x86)\AVG\Av\avgidsagent.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-02-14 22:59:49.654
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files (x86)\AVG\Av\avgidsagent.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\AVG\Framework\Common\avgfmwbasex.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-02-14 22:59:49.404
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files (x86)\AVG\Av\avgidsagent.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

==================== Memory info ===========================

Processor: Intel® Celeron® CPU B830 @ 1.80GHz
Percentage of memory in use: 81%
Total physical RAM: 3909.28 MB
Available physical RAM: 722.08 MB
Total Virtual: 5317.28 MB
Available Virtual: 2723.18 MB

==================== Drives ================================

Drive c: (Gateway) (Fixed) (Total:281.75 GB) (Free:258.25 GB) NTFS
Drive e: (Tablet_CD) (CDROM) (Total:0.42 GB) (Free:0 GB) CDFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 298.1 GB) (Disk ID: E516F944)

Partition: GPT.

==================== End of Addition.txt ============================

Attached Files



BC AdBot (Login to Remove)

 


#2 nasdaq

nasdaq

  • Malware Response Team
  • 38,942 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:11:33 PM

Posted 15 February 2016 - 08:55 AM

Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

Your logs are clean.

You can stop Avast from informing you of this tracking cookies activity.

https://support.avg.com/SupportArticleView?l=en_US&urlName=What-are-tracking-cookies

Hope that helps.

#3 nasdaq

nasdaq

  • Malware Response Team
  • 38,942 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:11:33 PM

Posted 20 February 2016 - 08:09 AM

Due to the lack of feedback, this topic is now closed.

In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days.

Please include a link to your topic in the Private Message. Thank you.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users