Hi,
This program in bold was previously installed and deleted.
If possible remove it via the Control Panel.
Remove this program in bold using the Control Panel > Programs > Programs and Features.
GridinSoft Anti-Malware (HKLM\...\GridinSoft Anti-Malware) (Version: 4.1.36 - Gridinsoft LLC)
If it fails then to remove it manually.
How to Manually Remove Program Entries from the Apps & Features List
There may come a time when you find that you've uninstalled a program in Apps & Features (Windows 10) or AddRemove Programs (Windows XP, 7, Vista, 8) but the entry is still there. This problem happens when a registry entry wasn't correctly removed during the uninstall.
www.majorgeeks.com
===
Please download the attached
Fixlist.txt file to the
same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the FRST.txt log you have submitted.
Run
FRST and click
Fix only once and wait.
The Computer will restart when the fix is completed.
It will create a log (Fixlog.txt) please post it to your reply.
===
Let find out what we can find in the Registry.
Run the Farbar program .exe as an Administrator.
In the Search text area, copy and paste the following:
Antimalware
Once done, click on the Search
Registry button and wait for FRST to finish the search
On completion, a log will open in Notepad. Copy and paste its content in your next reply
====
Please post the logs and let me know what problem persists.
Hi,
This program in bold was previously installed and deleted.
If possible remove it via the Control Panel.
Remove this program in bold using the Control Panel > Programs > Programs and Features.
GridinSoft Anti-Malware (HKLM\...\GridinSoft Anti-Malware) (Version: 4.1.36 - Gridinsoft LLC)
If it fails then to remove it manually.
How to Manually Remove Program Entries from the Apps & Features List
There may come a time when you find that you've uninstalled a program in Apps & Features (Windows 10) or AddRemove Programs (Windows XP, 7, Vista, 8) but the entry is still there. This problem happens when a registry entry wasn't correctly removed during the uninstall.
www.majorgeeks.com
===
Please download the attached
Fixlist.txt file to the
same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the FRST.txt log you have submitted.
Run
FRST and click
Fix only once and wait.
The Computer will restart when the fix is completed.
It will create a log (Fixlog.txt) please post it to your reply.
===
Let find out what we can find in the Registry.
Run the Farbar program .exe as an Administrator.
In the Search text area, copy and paste the following:
Antimalware
Once done, click on the Search
Registry button and wait for FRST to finish the search
On completion, a log will open in Notepad. Copy and paste its content in your next reply
====
Please post the logs and let me know what problem persists.
Fix result of Farbar Recovery Scan Tool (x64) Version: 07-07-2021
Ran by Win7 (15-07-2021 21:59:40) Run:1
Running from C:\Users\Win7\Desktop
Loaded Profiles: Win7
Boot Mode: Normal
==============================================
fixlist content:
*****************
CreateRestorePoint:
CloseProcesses:
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-3677881058-545421556-1463432810-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-3677881058-545421556-1463432810-1000\...\MountPoints2: G - G:\AutoRun.exe
HKU\S-1-5-21-3677881058-545421556-1463432810-1000\...\MountPoints2: {26d3d847-a39f-11e3-924b-9439e5d231c2} - G:\AutoRun.exe
HKU\S-1-5-21-3677881058-545421556-1463432810-1000\...\MountPoints2: {26d3d859-a39f-11e3-924b-9439e5d231c2} - G:\AutoRun.exe
HKU\S-1-5-21-3677881058-545421556-1463432810-1000\...\MountPoints2: {3cae467e-c7d1-11e4-97e4-9439e5d231c2} - G:\AutoRun.exe
HKU\S-1-5-21-3677881058-545421556-1463432810-1000\...\MountPoints2: {44a17760-a603-11e3-9269-9439e5d231c2} - G:\AutoRun.exe
HKU\S-1-5-21-3677881058-545421556-1463432810-1000\...\MountPoints2: {44dc09c8-a8ef-11e3-bf42-9439e5d231c2} - G:\AutoRun.exe
HKU\S-1-5-21-3677881058-545421556-1463432810-1000\...\MountPoints2: {83da0b8a-ffa3-11e3-98f6-9439e5d231c2} - G:\Setup.exe
HKU\S-1-5-21-3677881058-545421556-1463432810-1000\...\MountPoints2: {b398ecb2-e03d-11e4-9912-9439e5d231c2} - H:\AutoRun.exe
HKU\S-1-5-21-3677881058-545421556-1463432810-1000\...\MountPoints2: {da49e92b-c7be-11e4-8c1e-9439e5d231c2} - G:\AutoRun.exe
GroupPolicy\User: Restriction ? <==== ATTENTION
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
Task: {CE982151-2E30-41C8-904D-C366BC768B56} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [269000 2015-10-01] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
Task: {F5B9CD8D-3C85-4F1D-860A-1B78AEC3EF1F} - System32\Tasks\{909CF490-D741-4B16-B78F-82135F1A5DD6} => C:\Windows\system32\pcalua.exe -a C:\Users\Win7\AppData\Local\Temp\jre-8u101-windows-au.exe -d C:\Windows\SysWOW64 -c /installmethod=jau FAMILYUPGRADE=1 <==== ATTENTION
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_19_0_0_185.dll [2015-10-01] (Adobe Systems Incorporated -> )
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_185.dll [2015-10-01] (Adobe Systems Incorporated -> )
S3 AdobeFlashPlayerUpdateSvc; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [269000 2015-10-01] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
S2 BavMiniService; "C:\ProgramData\Baidu\Antivirus\BavMSService.exe" -r [X]
S2 jehowesy; C:\Users\Win7\AppData\Roaming\4C4C4544-1425874573-4610-8039-B7C04F425231\jnso79D1.tmp [X]
S2 vowegyhi; C:\Users\Win7\AppData\Roaming\4C4C4544-1425874573-4610-8039-B7C04F425231\nsi32FB.tmpfs [X]
S2 vuqgwgr; C:\Windows\SysWOW64\vuqgwgr\gygvdbfd.exe [X]
S4 Qlssvcmmbpc; no ImagePath
U3 avgbdisk; no ImagePath
S3 BprotectEx; \??\C:\Windows\System32\drivers\BprotectEx.sys [X]
S3 clwvd; system32\DRIVERS\clwvd.sys [X]
S3 ewusbmbb; system32\DRIVERS\ewusbwwan.sys [X]
S3 ew_hwusbdev; system32\DRIVERS\ew_hwusbdev.sys [X]
S3 ew_usbenumfilter; system32\DRIVERS\ew_usbenumfilter.sys [X]
S3 huawei_cdcacm; system32\DRIVERS\ew_jucdcacm.sys [X]
S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X]
S3 huawei_ext_ctrl; system32\DRIVERS\ew_juextctrl.sys [X]
S3 huawei_wwanecm; system32\DRIVERS\ew_juwwanecm.sys [X]
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S2 WCMVCAM; system32\DRIVERS\wcmvcam64.sys [X]
S3 WinPhLdrNT; \??\C:\Users\Win7\AppData\Local\Temp\PhLdrX64.SYS [X] <==== ATTENTION
CustomCLSID: HKU\S-1-5-21-3677881058-545421556-1463432810-1000_Classes\CLSID\{6A221957-2D85-42A7-8E19-BE33950D1DEB}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2014\acad.exe => No File
CustomCLSID: HKU\S-1-5-21-3677881058-545421556-1463432810-1000_Classes\CLSID\{7DE1BE5C-CEBA-4F1D-ACBC-9CE11EE9A2A1}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2014\acad.exe /Automation => No File
CustomCLSID: HKU\S-1-5-21-3677881058-545421556-1463432810-1000_Classes\CLSID\{BD0DEB94-63DB-4392-9420-6EEE05094B1F}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2014\acad.exe /Automation => No File
CustomCLSID: HKU\S-1-5-21-3677881058-545421556-1463432810-1000_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD 2014\en-US\acadficn.dll => No File
ShellIconOverlayIdentifiers: [BaiduAntivirusIconLock] -> {0A93904A-BB1E-4a0c-9753-B57B9AE272CC} => -> No File
ShellIconOverlayIdentifiers-x32-x32: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\SysWOW64\AcSignIcon.dll -> No File
ContextMenuHandlers1: [Baidu_Scan] -> {0A93904A-BB1E-4a0c-9753-B57B9AE272CB} => C:\Program Files (x86)\Baidu Security\Baidu Antivirus\5.4.3.114997.0\BavShx64.dll -> No File
ContextMenuHandlers2: [Baidu_Scan] -> {0A93904A-BB1E-4a0c-9753-B57B9AE272CB} => C:\Program Files (x86)\Baidu Security\Baidu Antivirus\5.4.3.114997.0\BavShx64.dll -> No File
ContextMenuHandlers3: [SmadExt] -> {8AB81E72-CB2F-11D3-8D3B-AC2F34F1FA3C} => C:\Program Files (x86)\Smadav\SmadExtc64.dll -> No File
ContextMenuHandlers6: [Baidu_Scan] -> {0A93904A-BB1E-4a0c-9753-B57B9AE272CB} => C:\Program Files (x86)\Baidu Security\Baidu Antivirus\5.4.3.114997.0\BavShx64.dll -> No File
ContextMenuHandlers6: [SmadExt] -> {8AB81E72-CB2F-11D3-8D3B-AC2F34F1FA3C} => C:\Program Files (x86)\Smadav\SmadExtc64.dll -> No File
URLSearchHook: HKU\S-1-5-21-3677881058-545421556-1463432810-1000 - (No Name) - {D8278076-BC68-4484-9233-6E7F1628B56C} - No File
C:\Windows\Securebootthemes
C:\Wndows\Syswow64\Securebootthemes
CMD: netsh int ip reset
CMD: ipconfig /flushDNS
EmptyTemp:
*****************
Restore point was successfully created.
Processes closed successfully.
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender => removed successfully
"HKU\S-1-5-21-3677881058-545421556-1463432810-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoLowDiskSpaceChecks" => removed successfully
HKU\S-1-5-21-3677881058-545421556-1463432810-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\G => removed successfully
HKU\S-1-5-21-3677881058-545421556-1463432810-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{26d3d847-a39f-11e3-924b-9439e5d231c2} => removed successfully
HKU\S-1-5-21-3677881058-545421556-1463432810-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{26d3d859-a39f-11e3-924b-9439e5d231c2} => removed successfully
HKU\S-1-5-21-3677881058-545421556-1463432810-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3cae467e-c7d1-11e4-97e4-9439e5d231c2} => removed successfully
HKU\S-1-5-21-3677881058-545421556-1463432810-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{44a17760-a603-11e3-9269-9439e5d231c2} => removed successfully
HKU\S-1-5-21-3677881058-545421556-1463432810-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{44dc09c8-a8ef-11e3-bf42-9439e5d231c2} => removed successfully
HKU\S-1-5-21-3677881058-545421556-1463432810-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{83da0b8a-ffa3-11e3-98f6-9439e5d231c2} => removed successfully
HKU\S-1-5-21-3677881058-545421556-1463432810-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b398ecb2-e03d-11e4-9912-9439e5d231c2} => removed successfully
HKU\S-1-5-21-3677881058-545421556-1463432810-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{da49e92b-c7be-11e4-8c1e-9439e5d231c2} => removed successfully
C:\Windows\system32\GroupPolicy\User => moved successfully
C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully
C:\Windows\SysWOW64\GroupPolicy\GPT.ini => moved successfully
HKLM\SOFTWARE\Policies\Google => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CE982151-2E30-41C8-904D-C366BC768B56}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CE982151-2E30-41C8-904D-C366BC768B56}" => removed successfully
C:\Windows\System32\Tasks\Adobe Flash Player Updater => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Flash Player Updater" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F5B9CD8D-3C85-4F1D-860A-1B78AEC3EF1F}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F5B9CD8D-3C85-4F1D-860A-1B78AEC3EF1F}" => removed successfully
C:\Windows\System32\Tasks\{909CF490-D741-4B16-B78F-82135F1A5DD6} => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{909CF490-D741-4B16-B78F-82135F1A5DD6}" => removed successfully
C:\Windows\Tasks\Adobe Flash Player Updater.job => moved successfully
HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer => removed successfully
C:\Windows\system32\Macromed\Flash\NPSWF64_19_0_0_185.dll => moved successfully
"HKLM\Software\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_185.dll [2015-10-01] (Adobe Systems Incorporated" => not found
C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_185.dll => moved successfully
HKLM\System\CurrentControlSet\Services\AdobeFlashPlayerUpdateSvc => removed successfully
AdobeFlashPlayerUpdateSvc => service removed successfully
HKLM\System\CurrentControlSet\Services\BavMiniService => removed successfully
BavMiniService => service removed successfully
HKLM\System\CurrentControlSet\Services\jehowesy => removed successfully
jehowesy => service removed successfully
HKLM\System\CurrentControlSet\Services\vowegyhi => removed successfully
vowegyhi => service removed successfully
HKLM\System\CurrentControlSet\Services\vuqgwgr => removed successfully
vuqgwgr => service removed successfully
HKLM\System\CurrentControlSet\Services\Qlssvcmmbpc => removed successfully
Qlssvcmmbpc => service removed successfully
HKLM\System\CurrentControlSet\Services\avgbdisk => could not remove, key could be protected
HKLM\System\CurrentControlSet\Services\BprotectEx => removed successfully
BprotectEx => service removed successfully
HKLM\System\CurrentControlSet\Services\clwvd => removed successfully
clwvd => service removed successfully
HKLM\System\CurrentControlSet\Services\ewusbmbb => removed successfully
ewusbmbb => service removed successfully
HKLM\System\CurrentControlSet\Services\ew_hwusbdev => removed successfully
ew_hwusbdev => service removed successfully
HKLM\System\CurrentControlSet\Services\ew_usbenumfilter => removed successfully
ew_usbenumfilter => service removed successfully
HKLM\System\CurrentControlSet\Services\huawei_cdcacm => removed successfully
huawei_cdcacm => service removed successfully
HKLM\System\CurrentControlSet\Services\huawei_enumerator => removed successfully
huawei_enumerator => service removed successfully
HKLM\System\CurrentControlSet\Services\huawei_ext_ctrl => removed successfully
huawei_ext_ctrl => service removed successfully
HKLM\System\CurrentControlSet\Services\huawei_wwanecm => removed successfully
huawei_wwanecm => service removed successfully
HKLM\System\CurrentControlSet\Services\hwdatacard => removed successfully
hwdatacard => service removed successfully
HKLM\System\CurrentControlSet\Services\VGPU => removed successfully
VGPU => service removed successfully
HKLM\System\CurrentControlSet\Services\WCMVCAM => removed successfully
WCMVCAM => service removed successfully
HKLM\System\CurrentControlSet\Services\WinPhLdrNT => removed successfully
WinPhLdrNT => service removed successfully
HKU\S-1-5-21-3677881058-545421556-1463432810-1000_Classes\CLSID\{6A221957-2D85-42A7-8E19-BE33950D1DEB} => removed successfully
HKU\S-1-5-21-3677881058-545421556-1463432810-1000_Classes\CLSID\{7DE1BE5C-CEBA-4F1D-ACBC-9CE11EE9A2A1} => removed successfully
HKU\S-1-5-21-3677881058-545421556-1463432810-1000_Classes\CLSID\{BD0DEB94-63DB-4392-9420-6EEE05094B1F} => removed successfully
HKU\S-1-5-21-3677881058-545421556-1463432810-1000_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005} => removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\BaiduAntivirusIconLock => removed successfully
ShellIconOverlayIdentifiers-x32-x32: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\SysWOW64\AcSignIcon.dll -> No File => Error: No automatic fix found for this entry.
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\Baidu_Scan => removed successfully
HKLM\Software\Classes\CLSID\{0A93904A-BB1E-4a0c-9753-B57B9AE272CB} => removed successfully
HKLM\Software\Classes\Drive\ShellEx\ContextMenuHandlers\Baidu_Scan => removed successfully
HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\SmadExt => removed successfully
HKLM\Software\Classes\CLSID\{8AB81E72-CB2F-11D3-8D3B-AC2F34F1FA3C} => removed successfully
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\Baidu_Scan => removed successfully
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\SmadExt => removed successfully
"HKU\S-1-5-21-3677881058-545421556-1463432810-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\{D8278076-BC68-4484-9233-6E7F1628B56C}" => removed successfully
C:\Windows\Securebootthemes => moved successfully
"C:\Wndows\Syswow64\Securebootthemes" => not found
========= netsh int ip reset =========
Reseting Global, OK!
Reseting Interface, OK!
Restart the computer to complete this action.
========= End of CMD: =========
========= ipconfig /flushDNS =========
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
========= End of CMD: =========
=========== EmptyTemp: ==========
BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 10484736 B
Java, Flash, Steam htmlcache => 3436 B
Windows/system/drivers => 24727534 B
Edge => 0 B
Chrome => 752492312 B
Firefox => 1307215293 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Default => 2174 B
Public => 2174 B
ProgramData => 2174 B
systemprofile => 85498 B
systemprofile32 => 368002 B
LocalService => 434230 B
NetworkService => 560386 B
Win7 => 36530440 B
RecycleBin => 25905810 B
EmptyTemp: => 2 GB temporary data Removed.
================================
Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 15-07-2021 22:08:27)
Result of scheduled keys to remove after reboot:
HKLM\System\CurrentControlSet\Services\avgbdisk => could not remove, key could be protected
==== End of Fixlog 22:08:27 ====