Frank McEnroe
Posts: 12 +0
Hi,
I never had any issue with my home wifi connection. I lent my laptop to my friend for a week and got back yesterday. Since then, I found the intermittent wifi connection issue. Connection stays only for few minutes. Every time I need to connect manually to continue browsing. I have another laptop which doesn't meet up this issue. This laptop has seamless connectivity. When I checked similar issue in another post in this forum, it was advised to run Farbar Recovery Scan Tool (FRST) and paste the FRST.txt and Addition.txt
I am not sure these documents will help or not. However I have run the tool, scanned and pasted the output below. I paste FRST.txt here and Addtion.txt in another thread
I do highly appreciate your valuable guidance. Thank you.
FRST:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 01-01-2017
Ran by HP (administrator) on HP-PC (05-01-2017 06:12:34)
Running from C:\Users\HP\Downloads
Loaded Profiles: HP (Available Profiles: HP)
Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) Language: English (United States)
Internet Explorer Version 7 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_827e372d\stacsv.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(Validity Sensors, Inc.) C:\Windows\System32\vfsFPService.exe
(DigitalPersona, Inc.) C:\Program Files\DigitalPersona\Bin\DpHostW.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
() C:\Program Files\INet\BackgroundService\ServiceManager.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
() C:\Program Files\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe
(CyberLink) C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe
(CyberLink) C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
() C:\Program Files\SMINST\BLService.exe
() C:\Program Files\CyberLink\Shared files\RichVideo.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray.exe
(BitTorrent Inc.) C:\Users\HP\AppData\Roaming\uTorrent\uTorrent.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Launcher\Avira.Systray.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.32.7\GoogleCrashHandler.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(BitTorrent Inc.) C:\Users\HP\AppData\Roaming\uTorrent\updates\3.4.9_43085\utorrentie.exe
(BitTorrent Inc.) C:\Users\HP\AppData\Roaming\uTorrent\updates\3.4.9_43085\utorrentie.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avscan.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avscan.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Zhuhai Kingsoft Office Software Co.,Ltd) C:\Program Files\Kingsoft\Kingsoft Office\10.2.0.5804\office6\wpscloudsvr.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Zhuhai Kingsoft Office Software Co.,Ltd) C:\Program Files\Kingsoft\Kingsoft Office\10.2.0.5804\office6\et.exe
(Zhuhai Kingsoft Office Software Co.,Ltd) C:\Program Files\Kingsoft\Kingsoft Office\10.2.0.5804\office6\ktpcntr.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [831576 2016-10-26] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [Avira SystrayStartTrigger] => C:\Program Files\Avira\Launcher\Avira.SystrayStartTrigger.exe [67840 2016-07-11] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray.exe [450652 2009-06-03] (IDT, Inc.)
HKU\S-1-5-21-244761216-2061140223-1076214149-1003\...\Run: [uTorrent] => C:\Users\HP\AppData\Roaming\uTorrent\uTorrent.exe [1979072 2016-12-21] (BitTorrent Inc.)
HKU\S-1-5-21-244761216-2061140223-1076214149-1003\...\MountPoints2: {27dbade0-81a2-11e3-9508-00247e74b26d} - H:\Windows\CHECK\DriveNavigator.exe
HKU\S-1-5-21-244761216-2061140223-1076214149-1003\...\MountPoints2: {32531e80-2328-11e5-a990-00247e74b26d} - F:\autorun.exe
HKU\S-1-5-21-244761216-2061140223-1076214149-1003\...\MountPoints2: {770262b1-9348-11e6-a57c-00247e74b26d} - F:\HiSuiteDownLoader.exe
HKU\S-1-5-21-244761216-2061140223-1076214149-1003\...\MountPoints2: {7ed807ca-394b-11e6-b5db-00247e74b26d} - F:\iLinker.exe
Lsa: [Notification Packages] scecli DPPWDFLT
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{52CD09EC-A697-4374-892B-AFB722ED7822}: [DhcpNameServer] 192.168.0.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKU\S-1-5-21-244761216-2061140223-1076214149-1003\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_my&c=91&bd=Pavilion&pf=cnnb
HKU\S-1-5-21-244761216-2061140223-1076214149-1003\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
SearchScopes: HKLM -> DefaultScope {D81FF4A6-9D40-4359-B02A-2B504BEA2F72} URL = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1929&query={searchTerms}&invocationType=tb50hpcnnbie7-en-my
SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2488} URL = hxxp://dts.search.ask.com/sr?src=ieb&gct=ds&appid=210&systemid=488&v=a13277-351&apn_uid=6223357303424548&apn_dtid=TCH001&o=APN11459&apn_ptnrs=AG1&q={searchTerms}
SearchScopes: HKLM -> {D81FF4A6-9D40-4359-B02A-2B504BEA2F72} URL = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1929&query={searchTerms}&invocationType=tb50hpcnnbie7-en-my
SearchScopes: HKU\S-1-5-21-244761216-2061140223-1076214149-1003 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-244761216-2061140223-1076214149-1003 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={sear
SearchScopes: HKU\S-1-5-21-244761216-2061140223-1076214149-1003 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2488} URL = hxxp://dts.search.ask.com/sr?src=ieb&gct=ds&appid=210&systemid=488&v=a13277-351&apn_uid=6223357303424548&apn_dtid=TCH001&o=APN11459&apn_ptnrs=AG1&q={searchTerms}
SearchScopes: HKU\S-1-5-21-244761216-2061140223-1076214149-1003 -> {D81FF4A6-9D40-4359-B02A-2B504BEA2F72} URL = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1929&query={searchTerms}&invocationType=tb50hpcnnbie7-en-my
BHO: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> No File
BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23] (Adobe Systems Incorporated)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2014-01-19] (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-01-19] (Oracle Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2016-09-23] (Skype Technologies)
FireFox:
========
FF DefaultProfile: j81iy2ak.default-1480519304692
FF ProfilePath: C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\j81iy2ak.default-1480519304692 [2016-12-04]
FF HKLM\...\Firefox\Extensions: [otis@digitalpersona.com] - C:\Program Files\DigitalPersona\Bin\FirefoxExt
FF Extension: (DigitalPersona Extension) - C:\Program Files\DigitalPersona\Bin\FirefoxExt [2014-01-19] [not signed]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: (Microsoft .NET Framework Assistant) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2014-10-06] [not signed]
FF HKU\S-1-5-21-244761216-2061140223-1076214149-1003\...\Firefox\Extensions: [otis@digitalpersona.com] - C:\Program Files\DigitalPersona\Bin\firefoxext
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\Ask.xml [2014-07-04]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_24_0_0_186.dll [2016-12-15] ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw.dll [2008-08-07] (Adobe Systems, Inc.)
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2016-10-06] (Google)
FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll [2014-01-07] (Google, Inc.)
FF Plugin: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-01-19] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2014-01-19] (Oracle Corporation)
FF Plugin: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 -> C:\Program Files\Yahoo!\Shared\npYState.dll [2012-05-25] (Yahoo! Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll [2011-08-30] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2012-12-19] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-244761216-2061140223-1076214149-1003: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\HP\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
FF Plugin ProgramFiles/Appdata: C:\Users\HP\AppData\Roaming\mozilla\plugins\npatgpc.dll [2014-06-13] (Cisco WebEx LLC)
Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.msn.com/en-us/?pc=__PARAM__&ocid=__PARAM__DHP
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR Profile: C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default [2017-01-05]
CHR Extension: (Wechat) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\ckhliaadcjmdjbhdlkpjkffidcifglba [2016-08-03]
CHR Extension: (AdBlock) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-12-29]
CHR Extension: (Chrome Web Store Payments) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-05]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-244761216-2061140223-1076214149-1003\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - hxxps://clients2.google.com/service/update2/crx
StartMenuInternet: Google Chrome.CHZLC2TPTJSKDO6KA67BA3Y5UU - C:\Users\HP\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 Alcatel FOLK Modem Device Helper; C:\Program Files\INet\BackgroundService\ServiceManager.exe [58192 2013-06-18] ()
S2 AntiVirMailService; C:\Program Files\Avira\AntiVir Desktop\avmailc.exe [970632 2016-10-26] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [470600 2016-10-26] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [470600 2016-10-26] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [1253352 2016-10-26] (Avira Operations GmbH & Co. KG)
R2 Avira.ServiceHost; C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe [309384 2016-07-11] (Avira Operations GmbH & Co. KG)
R2 CLHNServiceForPowerDVD; C:\Program Files\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe [83240 2011-04-20] ()
R2 CyberLink PowerDVD 11.0 Monitor Service; C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe [70952 2011-03-31] (CyberLink)
R2 CyberLink PowerDVD 11.0 Service; C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe [312616 2011-03-31] (CyberLink)
R2 DpHost; C:\Program Files\DigitalPersona\Bin\DpHostW.exe [322624 2008-12-11] (DigitalPersona, Inc.) [File not signed]
S3 hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [223232 2008-10-24] (Hewlett-Packard Development Company, L.P.) [File not signed]
R2 LightScribeService; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [73728 2009-06-17] (Hewlett-Packard Company) [File not signed]
S4 MSSQLServerADHelper; c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [45272 2005-10-14] (Microsoft Corporation)
R2 Recovery Service for Windows; C:\Program Files\SMINST\BLService.exe [365952 2008-12-18] ()
R2 RichVideo; C:\Program Files\CyberLink\Shared files\RichVideo.exe [241734 2008-09-15] () [File not signed]
R2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_827e372d\STacSV.exe [217170 2009-06-03] (IDT, Inc.)
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-21] (Microsoft Corporation)
S3 wpscloudsvr; C:\Program Files\Kingsoft\Kingsoft Office\wpscloudsvr.exe [173824 2016-11-16] (Zhuhai Kingsoft Office Software Co.,Ltd)
S2 Norton Internet Security; "C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe" /s "Norton Internet Security" /m "C:\Program Files\Norton Internet Security\Engine\16.0.0.125\diMaster.dll" /prefetch:1
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AlcatelOTnet; C:\Windows\System32\DRIVERS\AlcatelOTUsbnet.sys [118272 2013-06-18] (TCT International Mobile Ltd)
R3 AVerBDA6x; C:\Windows\System32\DRIVERS\AVerBDA716x.sys [1114880 2008-12-03] (AVerMedia TECHNOLOGIES, Inc.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [115600 2016-10-26] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [140272 2016-10-26] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37896 2015-05-07] (Avira Operations GmbH & Co. KG)
S3 jrdusbser; C:\Windows\System32\DRIVERS\jrdusbser.sys [106112 2013-06-18] (TCT International Mobile Ltd)
R2 ntk_PowerDVD; C:\Program Files\CyberLink\PowerDVD11\Kernel\DMP\ntk_PowerDVD.sys [71664 2011-04-20] (Cyberlink Corp.)
R2 {329F96B6-DF1E-4328-BFDA-39EA953C1312}; C:\Program Files\CyberLink\PowerDVD11\Common\NavFilter\000.fcl [77296 2011-04-12] (CyberLink Corp.)
U0 aswVmm; no ImagePath
S1 F06DEFF2-5B9C-490D-910F-35D3A91196222; \??\C:\Program Files\Browser Tab Search by Ask\SafetyNut\configmgrc2.cfg [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20080829.024\NAVENG.SYS [X]
S3 NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20080829.024\NAVEX15.SYS [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S1 SRTSP; \??\C:\Windows\system32\drivers\NIS\1000000.07D\SRTSP.SYS [X]
S1 SRTSPX; \??\C:\Windows\system32\drivers\NIS\1000000.07D\SRTSPX.SYS [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-01-05 06:12 - 2017-01-05 06:15 - 00018089 _____ C:\Users\HP\Downloads\FRST.txt
2017-01-05 05:42 - 2017-01-05 06:12 - 00000000 ____D C:\FRST
2017-01-05 05:42 - 2017-01-05 05:42 - 00000000 ____D C:\Users\HP\Downloads\FRST-OlderVersion
2017-01-05 05:41 - 2017-01-05 05:42 - 01760256 _____ (Farbar) C:\Users\HP\Downloads\FRST.exe
2017-01-05 05:20 - 2017-01-05 05:20 - 00000000 ____D C:\Program Files\AVAST Software
2017-01-05 05:19 - 2017-01-05 05:19 - 06334848 _____ (AVAST Software) C:\Users\Public\Desktop\avast_free_antivirus_setup.exe
2017-01-05 05:19 - 2017-01-05 05:19 - 06334848 _____ (AVAST Software) C:\Users\HP\Downloads\avast_free_antivirus_setup.exe
2017-01-05 05:19 - 2017-01-05 05:19 - 00000000 ____D C:\ProgramData\AVAST Software
2017-01-05 03:57 - 2012-06-03 06:19 - 01933848 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2017-01-05 03:57 - 2012-06-03 06:19 - 00053784 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2017-01-05 03:57 - 2012-06-03 06:19 - 00045080 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2017-01-05 03:57 - 2012-06-03 06:12 - 02422272 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2017-01-05 03:56 - 2012-06-03 06:19 - 00577048 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2017-01-05 03:56 - 2012-06-03 06:19 - 00035864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2017-01-05 03:56 - 2012-06-03 06:12 - 00088576 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2017-01-05 03:56 - 2012-06-02 15:19 - 00171904 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2017-01-05 03:56 - 2012-06-02 15:12 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2017-01-04 20:14 - 2017-01-04 20:14 - 00015051 _____ C:\Users\HP\Downloads\www.TamilRockers.ac - Pazhaya Vannarapettai (2016) Tamil HDRip Xvid MP3 700MB.avi.torrent
2017-01-04 12:44 - 2017-01-04 12:46 - 00000000 ____D C:\Windows\system32\vi-VN
2017-01-04 12:44 - 2017-01-04 12:46 - 00000000 ____D C:\Windows\system32\eu-ES
2017-01-04 12:44 - 2017-01-04 12:46 - 00000000 ____D C:\Windows\system32\ca-ES
2017-01-04 12:39 - 2017-01-04 12:39 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_HpqKbFiltr_01005.Wdf
2017-01-04 12:38 - 2009-06-03 20:43 - 00483840 ____N (IDT, Inc.) C:\Windows\system32\stapi32.dll
2017-01-04 12:14 - 2017-01-04 12:14 - 00000000 ____D C:\Windows\system32\EventProviders
2017-01-02 07:53 - 2017-01-02 07:53 - 00036765 _____ C:\Users\HP\Downloads\en-the-magnificent-seven-2016-SubRip-utf-8 (1).zip
2017-01-02 07:52 - 2017-01-02 07:52 - 00000727 _____ C:\Users\HP\Downloads\en-the-magnificent-seven-2016-SubRip-utf-8.zip
2017-01-02 07:47 - 2017-01-02 07:47 - 00012899 _____ C:\Users\HP\Downloads\509AB327F9138FB1B2385C61D74FDA915E8480E1.torrent
2017-01-02 04:33 - 2017-01-02 04:33 - 00016862 _____ C:\Users\HP\Downloads\www.TamilRockers.ac - Kaashmora (2016)HDRip - x264 - 400MB - Tamil.mkv (1).torrent
2016-12-31 06:14 - 2016-12-31 06:14 - 00036137 _____ C:\Users\HP\Downloads\en-he-named-me-malala-2015-SubRip-utf-8 (2).zip
2016-12-31 06:13 - 2016-12-31 06:13 - 00030219 _____ C:\Users\HP\Downloads\en-he-named-me-malala-2015-SubRip-utf-8 (1).zip
2016-12-31 06:12 - 2016-12-31 06:12 - 00032579 _____ C:\Users\HP\Downloads\en-he-named-me-malala-2015-SubRip-utf-8.zip
2016-12-31 05:11 - 2016-12-31 05:11 - 00065948 _____ C:\Users\HP\Downloads\2B2E66699511D4D217AC742A766B5EAEC42A95A4.torrent
2016-12-31 04:52 - 2016-12-31 04:53 - 00004817 _____ C:\Users\HP\Downloads\2DC7F72513B65D4512A8BF28397E90527F1272FB.torrent
2016-12-29 19:04 - 2016-12-29 19:04 - 00103478 _____ C:\Users\HP\Downloads\D3FEB398D61D253D3A25F6472351E171FA9030DF.torrent
2016-12-29 19:02 - 2016-12-29 19:02 - 00014728 _____ C:\Users\HP\Downloads\www.TamilRockers.ac - Maaveeran Kittu (2016)HDRip - x264 - 700MB - Tamil.mkv.torrent
2016-12-29 19:01 - 2016-12-29 19:01 - 00016862 _____ C:\Users\HP\Downloads\www.TamilRockers.ac - Kaashmora (2016)HDRip - x264 - 400MB - Tamil.mkv.torrent
2016-12-29 19:00 - 2016-12-29 19:00 - 00015782 _____ C:\Users\HP\Downloads\www.TamilRockers.ac - Kaashmora (2016)HDRip - XviD - 700MB - Tamil.avi.torrent
2016-12-27 04:09 - 2016-12-27 04:08 - 00326695 _____ C:\Users\HP\Desktop\with beard.jpg
2016-12-27 04:08 - 2016-12-27 04:08 - 00326695 _____ C:\Users\HP\Downloads\tango-watermark20161226_232010.jpg
2016-12-26 03:22 - 2016-12-26 03:22 - 00047685 _____ C:\Users\HP\Downloads\Akira English subtitle [Hastidownload.biz] (2).zip
2016-12-26 03:05 - 2016-12-26 03:05 - 00047688 _____ C:\Users\HP\Downloads\Akira English subtitle [Hastidownload.biz] (1).zip
2016-12-26 03:04 - 2016-12-26 03:04 - 00047582 _____ C:\Users\HP\Downloads\Akira English subtitle [Hastidownload.biz].zip
2016-12-25 05:22 - 2016-12-25 05:22 - 00083374 _____ C:\Users\HP\Downloads\5998512E34A224338EA3CE62A8B4CA86AFEE2636.torrent
2016-12-25 05:19 - 2016-12-25 05:19 - 00017163 _____ C:\Users\HP\Downloads\C66D03384420795AA087EF284DF71D2B3C1AF1EB.torrent
2016-12-25 04:12 - 2016-12-25 04:12 - 00015223 _____ C:\Users\HP\Downloads\BF8DADF6B801F1744EDECB978B039194129BA170.torrent
2016-12-25 02:43 - 2016-12-25 02:43 - 00816107 _____ C:\Users\HP\Downloads\with Sharm and Bryan on Christmas.jpg
2016-12-25 02:14 - 2016-12-25 02:14 - 00017842 _____ C:\Users\HP\Downloads\www.TamilRockers.ac - Dangal (2016)Tamil (Neat Audio) DVDScr - x264 - 400MB.mkv.torrent
2016-12-25 02:02 - 2016-12-25 02:02 - 00015753 _____ C:\Users\HP\Downloads\www.TamilRockers.ac - Dangal (2016)Tamil (Neat Audio) DVDScr - x264 - 700MB.torrent
2016-12-23 06:32 - 2016-12-23 06:32 - 00115348 _____ C:\Users\HP\Downloads\AEECD546B072D19F75B9B869595C369AFC3828E6.torrent
2016-12-23 06:28 - 2016-12-23 06:28 - 00059017 _____ C:\Users\HP\Downloads\E0212728938BB1FF833EF1302B2089BD2F7B2A1A.torrent
2016-12-23 06:26 - 2016-12-23 06:26 - 00116797 _____ C:\Users\HP\Downloads\8E9EDCED2ACD2A220949E01E5C0A3AFD4D9C5A63.torrent
2016-12-23 06:25 - 2016-12-23 06:25 - 00057655 _____ C:\Users\HP\Downloads\A545A0A6BFD03A44DDC4E09207EC78E129D3D734.torrent
2016-12-21 23:18 - 2016-12-21 23:18 - 00017426 _____ C:\Users\HP\Downloads\www.TamilRockers.ac - Shenbaga Kottai (2016)DVDRip - Tamil (DVDScr Aud) + Malayalam - x264 - 800MB - ESubs.mkv.torrent
2016-12-21 17:16 - 2016-12-21 17:16 - 00014838 _____ C:\Users\HP\Downloads\www.TamilRockers.ac - Virumandikum Sivanandikum (2016)HDRip - x264 - 700MB - Tamil.mkv.torrent
2016-12-21 17:04 - 2016-12-21 17:04 - 00017885 _____ C:\Users\HP\Downloads\www.TamilRockers.ac - Chennai 600028 II Second Innings (2016)HQ Real DVDScr -x264 - 400MB - Tamil.mkv.torrent
2016-12-19 19:26 - 2016-12-19 19:26 - 00017858 _____ C:\Users\HP\Downloads\66B802AB6D07FC75DC843AFEA906553B45BC60E9.torrent
2016-12-19 15:46 - 2016-12-19 15:46 - 00016147 _____ C:\Users\HP\Downloads\5BE0B03B5A99ED4924E6AA7D228ACCB27D67E9D5.torrent
2016-12-19 15:44 - 2016-12-19 15:44 - 00002098 _____ C:\Users\HP\Downloads\54742E18683FB720146ABA86D8967AEAD65ACA7B.torrent
2016-12-19 15:23 - 2016-12-19 15:23 - 00002075 _____ C:\Users\HP\Downloads\09A2B3FA486ED08A2EC6987B4CA7E7DF231563A0.torrent
2016-12-19 15:21 - 2016-12-19 15:21 - 00013127 _____ C:\Users\HP\Downloads\7EE7EA184D84949773FD3A278B574AE527B67060.torrent
2016-12-18 23:51 - 2016-12-18 23:51 - 00027344 _____ C:\Users\HP\Downloads\f6622cacd1c2e30616dc00ac8f8e3c26e57429e2.zip
2016-12-18 23:49 - 2016-12-18 23:49 - 00013882 _____ C:\Users\HP\Downloads\5C93E35A2F4B79C418FCCD27ED15FE836C95BEC6.torrent
2016-12-18 23:39 - 2016-12-18 23:39 - 00001873 _____ C:\Users\HP\Downloads\01AB6ED1CFAE3E5460906868A5C86CC6FC4B2DEE.torrent
2016-12-18 23:37 - 2016-12-18 23:37 - 00036701 _____ C:\Users\HP\Downloads\C8994E9FA3D4D37810AE6B77C293E0AEA665736A.torrent
2016-12-18 21:18 - 2016-12-18 21:18 - 00014743 _____ C:\Users\HP\Downloads\www.TamilRockers.ac - Kadavul Irukaan Kumaru (2016)HDRip - x264 - 700MB - ESubs - Tamil.mkv.torrent
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-01-05 06:14 - 2016-07-22 05:09 - 00000686 _____ C:\Windows\Tasks\WpsKtpcntrQingTask_HP.job
2017-01-05 06:14 - 2014-01-20 15:05 - 00000000 ____D C:\Users\HP\AppData\Roaming\uTorrent
2017-01-05 06:02 - 2014-02-03 14:42 - 00000000 ____D C:\frank
2017-01-05 06:00 - 2016-11-16 02:24 - 00000370 _____ C:\Windows\Tasks\WpsUpdateTask_HP.job
2017-01-05 05:55 - 2014-01-19 11:59 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2017-01-05 05:42 - 2016-11-16 02:24 - 00000564 _____ C:\Windows\Tasks\WpsExternal_HP_20161116022425.job
2017-01-05 04:43 - 2006-11-02 19:18 - 00000000 ____D C:\Windows\rescache
2017-01-05 04:32 - 2006-11-02 19:18 - 00000000 ____D C:\Windows\inf
2017-01-05 04:32 - 2006-11-02 18:33 - 00769072 _____ C:\Windows\system32\PerfStringBackup.INI
2017-01-05 04:29 - 2016-10-07 13:07 - 00000000 ____D C:\Users\HP\AppData\LocalLow\uTorrent
2017-01-05 04:26 - 2006-11-02 21:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-01-05 04:26 - 2006-11-02 20:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2017-01-05 04:26 - 2006-11-02 20:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2017-01-05 04:23 - 2014-01-19 13:26 - 00000012 _____ C:\Windows\bthservsdp.dat
2017-01-05 04:23 - 2006-11-02 21:01 - 00032536 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2017-01-05 03:58 - 2006-11-02 20:50 - 00001661 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk
2017-01-05 03:56 - 2014-01-20 09:50 - 00000916 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-244761216-2061140223-1076214149-1003UA.job
2017-01-04 20:22 - 2014-01-20 18:46 - 00000000 ____D C:\Movies
2017-01-04 13:02 - 2014-01-19 11:34 - 00002001 _____ C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-01-04 13:02 - 2014-01-18 21:57 - 00000949 _____ C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2017-01-04 13:02 - 2014-01-18 21:57 - 00000915 _____ C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
2017-01-04 13:01 - 2016-10-02 15:07 - 00001971 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-01-04 13:01 - 2016-08-26 17:58 - 00001983 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-01-04 12:57 - 2006-11-02 20:47 - 00376744 _____ C:\Windows\system32\FNTCACHE.DAT
2017-01-04 12:46 - 2006-11-02 20:37 - 00000000 ____D C:\Windows\system32\XPSViewer
2017-01-04 12:46 - 2006-11-02 20:37 - 00000000 ____D C:\Program Files\Windows Sidebar
2017-01-04 12:46 - 2006-11-02 20:37 - 00000000 ____D C:\Program Files\Windows Photo Gallery
2017-01-04 12:46 - 2006-11-02 20:37 - 00000000 ____D C:\Program Files\Windows Journal
2017-01-04 12:46 - 2006-11-02 20:37 - 00000000 ____D C:\Program Files\Windows Defender
2017-01-04 12:46 - 2006-11-02 20:37 - 00000000 ____D C:\Program Files\Windows Collaboration
2017-01-04 12:46 - 2006-11-02 20:37 - 00000000 ____D C:\Program Files\Windows Calendar
2017-01-04 12:46 - 2006-11-02 20:37 - 00000000 ____D C:\Program Files\Movie Maker
2017-01-04 12:46 - 2006-11-02 19:18 - 00000000 ____D C:\Windows\system32\SLUI
2017-01-04 12:46 - 2006-11-02 19:18 - 00000000 ____D C:\Windows\system32\setup
2017-01-04 12:46 - 2006-11-02 19:18 - 00000000 ____D C:\Windows\system32\oobe
2017-01-04 12:46 - 2006-11-02 19:18 - 00000000 ____D C:\Windows\system32\manifeststore
2017-01-04 12:46 - 2006-11-02 19:18 - 00000000 ____D C:\Windows\system32\lv-LV
2017-01-04 12:46 - 2006-11-02 19:18 - 00000000 ____D C:\Windows\system32\et-EE
2017-01-04 12:46 - 2006-11-02 19:18 - 00000000 ____D C:\Windows\system32\AdvancedInstallers
2017-01-04 12:46 - 2006-11-02 19:18 - 00000000 ____D C:\Windows\servicing
2017-01-04 12:46 - 2006-11-02 19:18 - 00000000 ____D C:\Windows\IME
2017-01-04 12:46 - 2006-11-02 19:18 - 00000000 ____D C:\Program Files\Common Files\System
2017-01-04 12:45 - 2006-11-02 19:18 - 00000000 ____D C:\Windows\system32\migwiz
2017-01-04 12:45 - 2006-11-02 19:18 - 00000000 ____D C:\Windows\system32\lt-LT
2017-01-03 07:11 - 2014-01-20 15:00 - 00000000 ____D C:\Users\HP\AppData\Roaming\vlc
2017-01-01 05:22 - 2014-02-08 20:10 - 00000000 ____D C:\Photos
2016-12-30 09:56 - 2014-01-20 09:50 - 00000894 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-244761216-2061140223-1076214149-1003Core.job
2016-12-27 18:59 - 2014-01-20 20:29 - 00099840 _____ C:\Users\HP\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2016-12-20 10:52 - 2014-01-19 11:57 - 00000000 ____D C:\Users\HP\AppData\Roaming\Skype
2016-12-17 05:38 - 2009-01-17 11:29 - 00000000 __SHD C:\Windows\Installer
2016-12-16 03:06 - 2014-01-18 22:21 - 00000000 ____D C:\Windows\system32\MRT
2016-12-16 03:01 - 2006-11-02 18:24 - 133430776 ____C (Microsoft Corporation) C:\Windows\system32\mrt.exe
2016-12-15 08:56 - 2014-01-19 11:59 - 00802904 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2016-12-15 08:56 - 2014-01-19 11:59 - 00144472 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2016-12-15 08:55 - 2009-01-17 12:06 - 00000000 ____D C:\Windows\system32\Macromed
==================== Files in the root of some directories =======
2014-01-18 21:58 - 2014-01-18 21:58 - 0000000 _____ () C:\Users\HP\AppData\Local\AtStart.txt
2014-06-14 20:46 - 2015-10-04 22:50 - 0006836 _____ () C:\Users\HP\AppData\Local\d3d9caps.dat
2014-01-20 20:29 - 2016-12-27 18:59 - 0099840 _____ () C:\Users\HP\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-01-18 21:58 - 2014-01-18 21:58 - 0000000 _____ () C:\Users\HP\AppData\Local\DSwitch.txt
2014-01-21 23:11 - 2016-11-15 07:48 - 0000000 _____ () C:\Users\HP\AppData\Local\FnF4.txt
2014-01-18 21:58 - 2014-01-18 21:58 - 0000000 _____ () C:\Users\HP\AppData\Local\QSwitch.txt
2014-01-18 21:58 - 2016-11-17 16:00 - 0029425 _____ () C:\ProgramData\HPWALog.txt
2014-01-19 13:46 - 2014-01-19 13:46 - 0000032 _____ () C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log
2009-01-17 13:10 - 2009-01-17 13:11 - 0000109 _____ () C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
2014-01-19 13:45 - 2014-01-19 13:45 - 0000032 _____ () C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log
2009-01-17 13:04 - 2009-01-17 13:06 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
2014-01-19 13:45 - 2014-01-19 13:45 - 0000032 _____ () C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log
2014-01-19 13:46 - 2014-01-19 13:46 - 0000032 _____ () C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log
2009-01-17 13:03 - 2009-01-17 13:04 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
2009-01-17 13:06 - 2009-01-17 13:10 - 0000110 _____ () C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
2014-01-19 13:46 - 2014-01-19 13:46 - 0000105 _____ () C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log
Some files in TEMP:
====================
C:\Users\HP\AppData\Local\Temp\avgnt.exe
C:\Users\HP\AppData\Local\Temp\DseShExt-x86.dll
C:\Users\HP\AppData\Local\Temp\Inputps.exe
C:\Users\HP\AppData\Local\Temp\SDShelEx-win32.dll
C:\Users\HP\AppData\Local\Temp\SkypeSetup.exe
C:\Users\HP\AppData\Local\Temp\vlc-2.2.4-win32.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-01-05 04:31
==================== End of FRST.txt ============================
I never had any issue with my home wifi connection. I lent my laptop to my friend for a week and got back yesterday. Since then, I found the intermittent wifi connection issue. Connection stays only for few minutes. Every time I need to connect manually to continue browsing. I have another laptop which doesn't meet up this issue. This laptop has seamless connectivity. When I checked similar issue in another post in this forum, it was advised to run Farbar Recovery Scan Tool (FRST) and paste the FRST.txt and Addition.txt
I am not sure these documents will help or not. However I have run the tool, scanned and pasted the output below. I paste FRST.txt here and Addtion.txt in another thread
I do highly appreciate your valuable guidance. Thank you.
FRST:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 01-01-2017
Ran by HP (administrator) on HP-PC (05-01-2017 06:12:34)
Running from C:\Users\HP\Downloads
Loaded Profiles: HP (Available Profiles: HP)
Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) Language: English (United States)
Internet Explorer Version 7 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_827e372d\stacsv.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(Validity Sensors, Inc.) C:\Windows\System32\vfsFPService.exe
(DigitalPersona, Inc.) C:\Program Files\DigitalPersona\Bin\DpHostW.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
() C:\Program Files\INet\BackgroundService\ServiceManager.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
() C:\Program Files\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe
(CyberLink) C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe
(CyberLink) C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
() C:\Program Files\SMINST\BLService.exe
() C:\Program Files\CyberLink\Shared files\RichVideo.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray.exe
(BitTorrent Inc.) C:\Users\HP\AppData\Roaming\uTorrent\uTorrent.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Launcher\Avira.Systray.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.32.7\GoogleCrashHandler.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(BitTorrent Inc.) C:\Users\HP\AppData\Roaming\uTorrent\updates\3.4.9_43085\utorrentie.exe
(BitTorrent Inc.) C:\Users\HP\AppData\Roaming\uTorrent\updates\3.4.9_43085\utorrentie.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avscan.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avscan.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Zhuhai Kingsoft Office Software Co.,Ltd) C:\Program Files\Kingsoft\Kingsoft Office\10.2.0.5804\office6\wpscloudsvr.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Zhuhai Kingsoft Office Software Co.,Ltd) C:\Program Files\Kingsoft\Kingsoft Office\10.2.0.5804\office6\et.exe
(Zhuhai Kingsoft Office Software Co.,Ltd) C:\Program Files\Kingsoft\Kingsoft Office\10.2.0.5804\office6\ktpcntr.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [831576 2016-10-26] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [Avira SystrayStartTrigger] => C:\Program Files\Avira\Launcher\Avira.SystrayStartTrigger.exe [67840 2016-07-11] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray.exe [450652 2009-06-03] (IDT, Inc.)
HKU\S-1-5-21-244761216-2061140223-1076214149-1003\...\Run: [uTorrent] => C:\Users\HP\AppData\Roaming\uTorrent\uTorrent.exe [1979072 2016-12-21] (BitTorrent Inc.)
HKU\S-1-5-21-244761216-2061140223-1076214149-1003\...\MountPoints2: {27dbade0-81a2-11e3-9508-00247e74b26d} - H:\Windows\CHECK\DriveNavigator.exe
HKU\S-1-5-21-244761216-2061140223-1076214149-1003\...\MountPoints2: {32531e80-2328-11e5-a990-00247e74b26d} - F:\autorun.exe
HKU\S-1-5-21-244761216-2061140223-1076214149-1003\...\MountPoints2: {770262b1-9348-11e6-a57c-00247e74b26d} - F:\HiSuiteDownLoader.exe
HKU\S-1-5-21-244761216-2061140223-1076214149-1003\...\MountPoints2: {7ed807ca-394b-11e6-b5db-00247e74b26d} - F:\iLinker.exe
Lsa: [Notification Packages] scecli DPPWDFLT
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{52CD09EC-A697-4374-892B-AFB722ED7822}: [DhcpNameServer] 192.168.0.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKU\S-1-5-21-244761216-2061140223-1076214149-1003\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_my&c=91&bd=Pavilion&pf=cnnb
HKU\S-1-5-21-244761216-2061140223-1076214149-1003\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
SearchScopes: HKLM -> DefaultScope {D81FF4A6-9D40-4359-B02A-2B504BEA2F72} URL = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1929&query={searchTerms}&invocationType=tb50hpcnnbie7-en-my
SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2488} URL = hxxp://dts.search.ask.com/sr?src=ieb&gct=ds&appid=210&systemid=488&v=a13277-351&apn_uid=6223357303424548&apn_dtid=TCH001&o=APN11459&apn_ptnrs=AG1&q={searchTerms}
SearchScopes: HKLM -> {D81FF4A6-9D40-4359-B02A-2B504BEA2F72} URL = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1929&query={searchTerms}&invocationType=tb50hpcnnbie7-en-my
SearchScopes: HKU\S-1-5-21-244761216-2061140223-1076214149-1003 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-244761216-2061140223-1076214149-1003 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={sear
SearchScopes: HKU\S-1-5-21-244761216-2061140223-1076214149-1003 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2488} URL = hxxp://dts.search.ask.com/sr?src=ieb&gct=ds&appid=210&systemid=488&v=a13277-351&apn_uid=6223357303424548&apn_dtid=TCH001&o=APN11459&apn_ptnrs=AG1&q={searchTerms}
SearchScopes: HKU\S-1-5-21-244761216-2061140223-1076214149-1003 -> {D81FF4A6-9D40-4359-B02A-2B504BEA2F72} URL = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1929&query={searchTerms}&invocationType=tb50hpcnnbie7-en-my
BHO: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> No File
BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23] (Adobe Systems Incorporated)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2014-01-19] (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-01-19] (Oracle Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2016-09-23] (Skype Technologies)
FireFox:
========
FF DefaultProfile: j81iy2ak.default-1480519304692
FF ProfilePath: C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\j81iy2ak.default-1480519304692 [2016-12-04]
FF HKLM\...\Firefox\Extensions: [otis@digitalpersona.com] - C:\Program Files\DigitalPersona\Bin\FirefoxExt
FF Extension: (DigitalPersona Extension) - C:\Program Files\DigitalPersona\Bin\FirefoxExt [2014-01-19] [not signed]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: (Microsoft .NET Framework Assistant) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2014-10-06] [not signed]
FF HKU\S-1-5-21-244761216-2061140223-1076214149-1003\...\Firefox\Extensions: [otis@digitalpersona.com] - C:\Program Files\DigitalPersona\Bin\firefoxext
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\Ask.xml [2014-07-04]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_24_0_0_186.dll [2016-12-15] ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw.dll [2008-08-07] (Adobe Systems, Inc.)
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2016-10-06] (Google)
FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll [2014-01-07] (Google, Inc.)
FF Plugin: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-01-19] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2014-01-19] (Oracle Corporation)
FF Plugin: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 -> C:\Program Files\Yahoo!\Shared\npYState.dll [2012-05-25] (Yahoo! Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll [2011-08-30] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2012-12-19] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-244761216-2061140223-1076214149-1003: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\HP\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
FF Plugin ProgramFiles/Appdata: C:\Users\HP\AppData\Roaming\mozilla\plugins\npatgpc.dll [2014-06-13] (Cisco WebEx LLC)
Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.msn.com/en-us/?pc=__PARAM__&ocid=__PARAM__DHP
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR Profile: C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default [2017-01-05]
CHR Extension: (Wechat) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\ckhliaadcjmdjbhdlkpjkffidcifglba [2016-08-03]
CHR Extension: (AdBlock) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-12-29]
CHR Extension: (Chrome Web Store Payments) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-05]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-244761216-2061140223-1076214149-1003\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - hxxps://clients2.google.com/service/update2/crx
StartMenuInternet: Google Chrome.CHZLC2TPTJSKDO6KA67BA3Y5UU - C:\Users\HP\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 Alcatel FOLK Modem Device Helper; C:\Program Files\INet\BackgroundService\ServiceManager.exe [58192 2013-06-18] ()
S2 AntiVirMailService; C:\Program Files\Avira\AntiVir Desktop\avmailc.exe [970632 2016-10-26] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [470600 2016-10-26] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [470600 2016-10-26] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [1253352 2016-10-26] (Avira Operations GmbH & Co. KG)
R2 Avira.ServiceHost; C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe [309384 2016-07-11] (Avira Operations GmbH & Co. KG)
R2 CLHNServiceForPowerDVD; C:\Program Files\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe [83240 2011-04-20] ()
R2 CyberLink PowerDVD 11.0 Monitor Service; C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe [70952 2011-03-31] (CyberLink)
R2 CyberLink PowerDVD 11.0 Service; C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe [312616 2011-03-31] (CyberLink)
R2 DpHost; C:\Program Files\DigitalPersona\Bin\DpHostW.exe [322624 2008-12-11] (DigitalPersona, Inc.) [File not signed]
S3 hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [223232 2008-10-24] (Hewlett-Packard Development Company, L.P.) [File not signed]
R2 LightScribeService; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [73728 2009-06-17] (Hewlett-Packard Company) [File not signed]
S4 MSSQLServerADHelper; c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [45272 2005-10-14] (Microsoft Corporation)
R2 Recovery Service for Windows; C:\Program Files\SMINST\BLService.exe [365952 2008-12-18] ()
R2 RichVideo; C:\Program Files\CyberLink\Shared files\RichVideo.exe [241734 2008-09-15] () [File not signed]
R2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_827e372d\STacSV.exe [217170 2009-06-03] (IDT, Inc.)
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-21] (Microsoft Corporation)
S3 wpscloudsvr; C:\Program Files\Kingsoft\Kingsoft Office\wpscloudsvr.exe [173824 2016-11-16] (Zhuhai Kingsoft Office Software Co.,Ltd)
S2 Norton Internet Security; "C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe" /s "Norton Internet Security" /m "C:\Program Files\Norton Internet Security\Engine\16.0.0.125\diMaster.dll" /prefetch:1
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AlcatelOTnet; C:\Windows\System32\DRIVERS\AlcatelOTUsbnet.sys [118272 2013-06-18] (TCT International Mobile Ltd)
R3 AVerBDA6x; C:\Windows\System32\DRIVERS\AVerBDA716x.sys [1114880 2008-12-03] (AVerMedia TECHNOLOGIES, Inc.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [115600 2016-10-26] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [140272 2016-10-26] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37896 2015-05-07] (Avira Operations GmbH & Co. KG)
S3 jrdusbser; C:\Windows\System32\DRIVERS\jrdusbser.sys [106112 2013-06-18] (TCT International Mobile Ltd)
R2 ntk_PowerDVD; C:\Program Files\CyberLink\PowerDVD11\Kernel\DMP\ntk_PowerDVD.sys [71664 2011-04-20] (Cyberlink Corp.)
R2 {329F96B6-DF1E-4328-BFDA-39EA953C1312}; C:\Program Files\CyberLink\PowerDVD11\Common\NavFilter\000.fcl [77296 2011-04-12] (CyberLink Corp.)
U0 aswVmm; no ImagePath
S1 F06DEFF2-5B9C-490D-910F-35D3A91196222; \??\C:\Program Files\Browser Tab Search by Ask\SafetyNut\configmgrc2.cfg [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20080829.024\NAVENG.SYS [X]
S3 NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20080829.024\NAVEX15.SYS [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S1 SRTSP; \??\C:\Windows\system32\drivers\NIS\1000000.07D\SRTSP.SYS [X]
S1 SRTSPX; \??\C:\Windows\system32\drivers\NIS\1000000.07D\SRTSPX.SYS [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-01-05 06:12 - 2017-01-05 06:15 - 00018089 _____ C:\Users\HP\Downloads\FRST.txt
2017-01-05 05:42 - 2017-01-05 06:12 - 00000000 ____D C:\FRST
2017-01-05 05:42 - 2017-01-05 05:42 - 00000000 ____D C:\Users\HP\Downloads\FRST-OlderVersion
2017-01-05 05:41 - 2017-01-05 05:42 - 01760256 _____ (Farbar) C:\Users\HP\Downloads\FRST.exe
2017-01-05 05:20 - 2017-01-05 05:20 - 00000000 ____D C:\Program Files\AVAST Software
2017-01-05 05:19 - 2017-01-05 05:19 - 06334848 _____ (AVAST Software) C:\Users\Public\Desktop\avast_free_antivirus_setup.exe
2017-01-05 05:19 - 2017-01-05 05:19 - 06334848 _____ (AVAST Software) C:\Users\HP\Downloads\avast_free_antivirus_setup.exe
2017-01-05 05:19 - 2017-01-05 05:19 - 00000000 ____D C:\ProgramData\AVAST Software
2017-01-05 03:57 - 2012-06-03 06:19 - 01933848 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2017-01-05 03:57 - 2012-06-03 06:19 - 00053784 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2017-01-05 03:57 - 2012-06-03 06:19 - 00045080 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2017-01-05 03:57 - 2012-06-03 06:12 - 02422272 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2017-01-05 03:56 - 2012-06-03 06:19 - 00577048 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2017-01-05 03:56 - 2012-06-03 06:19 - 00035864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2017-01-05 03:56 - 2012-06-03 06:12 - 00088576 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2017-01-05 03:56 - 2012-06-02 15:19 - 00171904 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2017-01-05 03:56 - 2012-06-02 15:12 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2017-01-04 20:14 - 2017-01-04 20:14 - 00015051 _____ C:\Users\HP\Downloads\www.TamilRockers.ac - Pazhaya Vannarapettai (2016) Tamil HDRip Xvid MP3 700MB.avi.torrent
2017-01-04 12:44 - 2017-01-04 12:46 - 00000000 ____D C:\Windows\system32\vi-VN
2017-01-04 12:44 - 2017-01-04 12:46 - 00000000 ____D C:\Windows\system32\eu-ES
2017-01-04 12:44 - 2017-01-04 12:46 - 00000000 ____D C:\Windows\system32\ca-ES
2017-01-04 12:39 - 2017-01-04 12:39 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_HpqKbFiltr_01005.Wdf
2017-01-04 12:38 - 2009-06-03 20:43 - 00483840 ____N (IDT, Inc.) C:\Windows\system32\stapi32.dll
2017-01-04 12:14 - 2017-01-04 12:14 - 00000000 ____D C:\Windows\system32\EventProviders
2017-01-02 07:53 - 2017-01-02 07:53 - 00036765 _____ C:\Users\HP\Downloads\en-the-magnificent-seven-2016-SubRip-utf-8 (1).zip
2017-01-02 07:52 - 2017-01-02 07:52 - 00000727 _____ C:\Users\HP\Downloads\en-the-magnificent-seven-2016-SubRip-utf-8.zip
2017-01-02 07:47 - 2017-01-02 07:47 - 00012899 _____ C:\Users\HP\Downloads\509AB327F9138FB1B2385C61D74FDA915E8480E1.torrent
2017-01-02 04:33 - 2017-01-02 04:33 - 00016862 _____ C:\Users\HP\Downloads\www.TamilRockers.ac - Kaashmora (2016)HDRip - x264 - 400MB - Tamil.mkv (1).torrent
2016-12-31 06:14 - 2016-12-31 06:14 - 00036137 _____ C:\Users\HP\Downloads\en-he-named-me-malala-2015-SubRip-utf-8 (2).zip
2016-12-31 06:13 - 2016-12-31 06:13 - 00030219 _____ C:\Users\HP\Downloads\en-he-named-me-malala-2015-SubRip-utf-8 (1).zip
2016-12-31 06:12 - 2016-12-31 06:12 - 00032579 _____ C:\Users\HP\Downloads\en-he-named-me-malala-2015-SubRip-utf-8.zip
2016-12-31 05:11 - 2016-12-31 05:11 - 00065948 _____ C:\Users\HP\Downloads\2B2E66699511D4D217AC742A766B5EAEC42A95A4.torrent
2016-12-31 04:52 - 2016-12-31 04:53 - 00004817 _____ C:\Users\HP\Downloads\2DC7F72513B65D4512A8BF28397E90527F1272FB.torrent
2016-12-29 19:04 - 2016-12-29 19:04 - 00103478 _____ C:\Users\HP\Downloads\D3FEB398D61D253D3A25F6472351E171FA9030DF.torrent
2016-12-29 19:02 - 2016-12-29 19:02 - 00014728 _____ C:\Users\HP\Downloads\www.TamilRockers.ac - Maaveeran Kittu (2016)HDRip - x264 - 700MB - Tamil.mkv.torrent
2016-12-29 19:01 - 2016-12-29 19:01 - 00016862 _____ C:\Users\HP\Downloads\www.TamilRockers.ac - Kaashmora (2016)HDRip - x264 - 400MB - Tamil.mkv.torrent
2016-12-29 19:00 - 2016-12-29 19:00 - 00015782 _____ C:\Users\HP\Downloads\www.TamilRockers.ac - Kaashmora (2016)HDRip - XviD - 700MB - Tamil.avi.torrent
2016-12-27 04:09 - 2016-12-27 04:08 - 00326695 _____ C:\Users\HP\Desktop\with beard.jpg
2016-12-27 04:08 - 2016-12-27 04:08 - 00326695 _____ C:\Users\HP\Downloads\tango-watermark20161226_232010.jpg
2016-12-26 03:22 - 2016-12-26 03:22 - 00047685 _____ C:\Users\HP\Downloads\Akira English subtitle [Hastidownload.biz] (2).zip
2016-12-26 03:05 - 2016-12-26 03:05 - 00047688 _____ C:\Users\HP\Downloads\Akira English subtitle [Hastidownload.biz] (1).zip
2016-12-26 03:04 - 2016-12-26 03:04 - 00047582 _____ C:\Users\HP\Downloads\Akira English subtitle [Hastidownload.biz].zip
2016-12-25 05:22 - 2016-12-25 05:22 - 00083374 _____ C:\Users\HP\Downloads\5998512E34A224338EA3CE62A8B4CA86AFEE2636.torrent
2016-12-25 05:19 - 2016-12-25 05:19 - 00017163 _____ C:\Users\HP\Downloads\C66D03384420795AA087EF284DF71D2B3C1AF1EB.torrent
2016-12-25 04:12 - 2016-12-25 04:12 - 00015223 _____ C:\Users\HP\Downloads\BF8DADF6B801F1744EDECB978B039194129BA170.torrent
2016-12-25 02:43 - 2016-12-25 02:43 - 00816107 _____ C:\Users\HP\Downloads\with Sharm and Bryan on Christmas.jpg
2016-12-25 02:14 - 2016-12-25 02:14 - 00017842 _____ C:\Users\HP\Downloads\www.TamilRockers.ac - Dangal (2016)Tamil (Neat Audio) DVDScr - x264 - 400MB.mkv.torrent
2016-12-25 02:02 - 2016-12-25 02:02 - 00015753 _____ C:\Users\HP\Downloads\www.TamilRockers.ac - Dangal (2016)Tamil (Neat Audio) DVDScr - x264 - 700MB.torrent
2016-12-23 06:32 - 2016-12-23 06:32 - 00115348 _____ C:\Users\HP\Downloads\AEECD546B072D19F75B9B869595C369AFC3828E6.torrent
2016-12-23 06:28 - 2016-12-23 06:28 - 00059017 _____ C:\Users\HP\Downloads\E0212728938BB1FF833EF1302B2089BD2F7B2A1A.torrent
2016-12-23 06:26 - 2016-12-23 06:26 - 00116797 _____ C:\Users\HP\Downloads\8E9EDCED2ACD2A220949E01E5C0A3AFD4D9C5A63.torrent
2016-12-23 06:25 - 2016-12-23 06:25 - 00057655 _____ C:\Users\HP\Downloads\A545A0A6BFD03A44DDC4E09207EC78E129D3D734.torrent
2016-12-21 23:18 - 2016-12-21 23:18 - 00017426 _____ C:\Users\HP\Downloads\www.TamilRockers.ac - Shenbaga Kottai (2016)DVDRip - Tamil (DVDScr Aud) + Malayalam - x264 - 800MB - ESubs.mkv.torrent
2016-12-21 17:16 - 2016-12-21 17:16 - 00014838 _____ C:\Users\HP\Downloads\www.TamilRockers.ac - Virumandikum Sivanandikum (2016)HDRip - x264 - 700MB - Tamil.mkv.torrent
2016-12-21 17:04 - 2016-12-21 17:04 - 00017885 _____ C:\Users\HP\Downloads\www.TamilRockers.ac - Chennai 600028 II Second Innings (2016)HQ Real DVDScr -x264 - 400MB - Tamil.mkv.torrent
2016-12-19 19:26 - 2016-12-19 19:26 - 00017858 _____ C:\Users\HP\Downloads\66B802AB6D07FC75DC843AFEA906553B45BC60E9.torrent
2016-12-19 15:46 - 2016-12-19 15:46 - 00016147 _____ C:\Users\HP\Downloads\5BE0B03B5A99ED4924E6AA7D228ACCB27D67E9D5.torrent
2016-12-19 15:44 - 2016-12-19 15:44 - 00002098 _____ C:\Users\HP\Downloads\54742E18683FB720146ABA86D8967AEAD65ACA7B.torrent
2016-12-19 15:23 - 2016-12-19 15:23 - 00002075 _____ C:\Users\HP\Downloads\09A2B3FA486ED08A2EC6987B4CA7E7DF231563A0.torrent
2016-12-19 15:21 - 2016-12-19 15:21 - 00013127 _____ C:\Users\HP\Downloads\7EE7EA184D84949773FD3A278B574AE527B67060.torrent
2016-12-18 23:51 - 2016-12-18 23:51 - 00027344 _____ C:\Users\HP\Downloads\f6622cacd1c2e30616dc00ac8f8e3c26e57429e2.zip
2016-12-18 23:49 - 2016-12-18 23:49 - 00013882 _____ C:\Users\HP\Downloads\5C93E35A2F4B79C418FCCD27ED15FE836C95BEC6.torrent
2016-12-18 23:39 - 2016-12-18 23:39 - 00001873 _____ C:\Users\HP\Downloads\01AB6ED1CFAE3E5460906868A5C86CC6FC4B2DEE.torrent
2016-12-18 23:37 - 2016-12-18 23:37 - 00036701 _____ C:\Users\HP\Downloads\C8994E9FA3D4D37810AE6B77C293E0AEA665736A.torrent
2016-12-18 21:18 - 2016-12-18 21:18 - 00014743 _____ C:\Users\HP\Downloads\www.TamilRockers.ac - Kadavul Irukaan Kumaru (2016)HDRip - x264 - 700MB - ESubs - Tamil.mkv.torrent
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-01-05 06:14 - 2016-07-22 05:09 - 00000686 _____ C:\Windows\Tasks\WpsKtpcntrQingTask_HP.job
2017-01-05 06:14 - 2014-01-20 15:05 - 00000000 ____D C:\Users\HP\AppData\Roaming\uTorrent
2017-01-05 06:02 - 2014-02-03 14:42 - 00000000 ____D C:\frank
2017-01-05 06:00 - 2016-11-16 02:24 - 00000370 _____ C:\Windows\Tasks\WpsUpdateTask_HP.job
2017-01-05 05:55 - 2014-01-19 11:59 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2017-01-05 05:42 - 2016-11-16 02:24 - 00000564 _____ C:\Windows\Tasks\WpsExternal_HP_20161116022425.job
2017-01-05 04:43 - 2006-11-02 19:18 - 00000000 ____D C:\Windows\rescache
2017-01-05 04:32 - 2006-11-02 19:18 - 00000000 ____D C:\Windows\inf
2017-01-05 04:32 - 2006-11-02 18:33 - 00769072 _____ C:\Windows\system32\PerfStringBackup.INI
2017-01-05 04:29 - 2016-10-07 13:07 - 00000000 ____D C:\Users\HP\AppData\LocalLow\uTorrent
2017-01-05 04:26 - 2006-11-02 21:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-01-05 04:26 - 2006-11-02 20:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2017-01-05 04:26 - 2006-11-02 20:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2017-01-05 04:23 - 2014-01-19 13:26 - 00000012 _____ C:\Windows\bthservsdp.dat
2017-01-05 04:23 - 2006-11-02 21:01 - 00032536 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2017-01-05 03:58 - 2006-11-02 20:50 - 00001661 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk
2017-01-05 03:56 - 2014-01-20 09:50 - 00000916 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-244761216-2061140223-1076214149-1003UA.job
2017-01-04 20:22 - 2014-01-20 18:46 - 00000000 ____D C:\Movies
2017-01-04 13:02 - 2014-01-19 11:34 - 00002001 _____ C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-01-04 13:02 - 2014-01-18 21:57 - 00000949 _____ C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2017-01-04 13:02 - 2014-01-18 21:57 - 00000915 _____ C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
2017-01-04 13:01 - 2016-10-02 15:07 - 00001971 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-01-04 13:01 - 2016-08-26 17:58 - 00001983 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-01-04 12:57 - 2006-11-02 20:47 - 00376744 _____ C:\Windows\system32\FNTCACHE.DAT
2017-01-04 12:46 - 2006-11-02 20:37 - 00000000 ____D C:\Windows\system32\XPSViewer
2017-01-04 12:46 - 2006-11-02 20:37 - 00000000 ____D C:\Program Files\Windows Sidebar
2017-01-04 12:46 - 2006-11-02 20:37 - 00000000 ____D C:\Program Files\Windows Photo Gallery
2017-01-04 12:46 - 2006-11-02 20:37 - 00000000 ____D C:\Program Files\Windows Journal
2017-01-04 12:46 - 2006-11-02 20:37 - 00000000 ____D C:\Program Files\Windows Defender
2017-01-04 12:46 - 2006-11-02 20:37 - 00000000 ____D C:\Program Files\Windows Collaboration
2017-01-04 12:46 - 2006-11-02 20:37 - 00000000 ____D C:\Program Files\Windows Calendar
2017-01-04 12:46 - 2006-11-02 20:37 - 00000000 ____D C:\Program Files\Movie Maker
2017-01-04 12:46 - 2006-11-02 19:18 - 00000000 ____D C:\Windows\system32\SLUI
2017-01-04 12:46 - 2006-11-02 19:18 - 00000000 ____D C:\Windows\system32\setup
2017-01-04 12:46 - 2006-11-02 19:18 - 00000000 ____D C:\Windows\system32\oobe
2017-01-04 12:46 - 2006-11-02 19:18 - 00000000 ____D C:\Windows\system32\manifeststore
2017-01-04 12:46 - 2006-11-02 19:18 - 00000000 ____D C:\Windows\system32\lv-LV
2017-01-04 12:46 - 2006-11-02 19:18 - 00000000 ____D C:\Windows\system32\et-EE
2017-01-04 12:46 - 2006-11-02 19:18 - 00000000 ____D C:\Windows\system32\AdvancedInstallers
2017-01-04 12:46 - 2006-11-02 19:18 - 00000000 ____D C:\Windows\servicing
2017-01-04 12:46 - 2006-11-02 19:18 - 00000000 ____D C:\Windows\IME
2017-01-04 12:46 - 2006-11-02 19:18 - 00000000 ____D C:\Program Files\Common Files\System
2017-01-04 12:45 - 2006-11-02 19:18 - 00000000 ____D C:\Windows\system32\migwiz
2017-01-04 12:45 - 2006-11-02 19:18 - 00000000 ____D C:\Windows\system32\lt-LT
2017-01-03 07:11 - 2014-01-20 15:00 - 00000000 ____D C:\Users\HP\AppData\Roaming\vlc
2017-01-01 05:22 - 2014-02-08 20:10 - 00000000 ____D C:\Photos
2016-12-30 09:56 - 2014-01-20 09:50 - 00000894 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-244761216-2061140223-1076214149-1003Core.job
2016-12-27 18:59 - 2014-01-20 20:29 - 00099840 _____ C:\Users\HP\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2016-12-20 10:52 - 2014-01-19 11:57 - 00000000 ____D C:\Users\HP\AppData\Roaming\Skype
2016-12-17 05:38 - 2009-01-17 11:29 - 00000000 __SHD C:\Windows\Installer
2016-12-16 03:06 - 2014-01-18 22:21 - 00000000 ____D C:\Windows\system32\MRT
2016-12-16 03:01 - 2006-11-02 18:24 - 133430776 ____C (Microsoft Corporation) C:\Windows\system32\mrt.exe
2016-12-15 08:56 - 2014-01-19 11:59 - 00802904 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2016-12-15 08:56 - 2014-01-19 11:59 - 00144472 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2016-12-15 08:55 - 2009-01-17 12:06 - 00000000 ____D C:\Windows\system32\Macromed
==================== Files in the root of some directories =======
2014-01-18 21:58 - 2014-01-18 21:58 - 0000000 _____ () C:\Users\HP\AppData\Local\AtStart.txt
2014-06-14 20:46 - 2015-10-04 22:50 - 0006836 _____ () C:\Users\HP\AppData\Local\d3d9caps.dat
2014-01-20 20:29 - 2016-12-27 18:59 - 0099840 _____ () C:\Users\HP\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-01-18 21:58 - 2014-01-18 21:58 - 0000000 _____ () C:\Users\HP\AppData\Local\DSwitch.txt
2014-01-21 23:11 - 2016-11-15 07:48 - 0000000 _____ () C:\Users\HP\AppData\Local\FnF4.txt
2014-01-18 21:58 - 2014-01-18 21:58 - 0000000 _____ () C:\Users\HP\AppData\Local\QSwitch.txt
2014-01-18 21:58 - 2016-11-17 16:00 - 0029425 _____ () C:\ProgramData\HPWALog.txt
2014-01-19 13:46 - 2014-01-19 13:46 - 0000032 _____ () C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log
2009-01-17 13:10 - 2009-01-17 13:11 - 0000109 _____ () C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
2014-01-19 13:45 - 2014-01-19 13:45 - 0000032 _____ () C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log
2009-01-17 13:04 - 2009-01-17 13:06 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
2014-01-19 13:45 - 2014-01-19 13:45 - 0000032 _____ () C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log
2014-01-19 13:46 - 2014-01-19 13:46 - 0000032 _____ () C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log
2009-01-17 13:03 - 2009-01-17 13:04 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
2009-01-17 13:06 - 2009-01-17 13:10 - 0000110 _____ () C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
2014-01-19 13:46 - 2014-01-19 13:46 - 0000105 _____ () C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log
Some files in TEMP:
====================
C:\Users\HP\AppData\Local\Temp\avgnt.exe
C:\Users\HP\AppData\Local\Temp\DseShExt-x86.dll
C:\Users\HP\AppData\Local\Temp\Inputps.exe
C:\Users\HP\AppData\Local\Temp\SDShelEx-win32.dll
C:\Users\HP\AppData\Local\Temp\SkypeSetup.exe
C:\Users\HP\AppData\Local\Temp\vlc-2.2.4-win32.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-01-05 04:31
==================== End of FRST.txt ============================