These are the codes of FRST 64.
[removed]
Platform: Windows 8.1 Single Language (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Softex Inc.) C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
() C:\Program Files\Hewlett-Packard\SimplePass\opvapp.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\ClientCore.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.Reader_6.4.9926.17994_x64__8wekyb3d8bbwe\glcnd.exe
(Microsoft Corporation) C:\Windows\System32\WWAHost.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.28.13\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.28.13\GoogleCrashHandler64.exe
(Microsoft Corporation) C:\Windows\System32\WWAHost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\WWAHost.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7510896 2014-01-14] (Realtek Semiconductor)
HKLM\…\Run: [SimplePass] => C:\Program Files\Hewlett-Packard\SimplePass\ClientCore.exe [3962936 2014-03-29] (Hewlett-Packard)
HKLM\…\Run: [OPBHOBroker] => C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe [415288 2014-03-29] (Hewlett-Packard)
HKLM\…\Run: [OPBHOBrokerDesktop] => C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe [415288 2014-03-29] (Hewlett-Packard)
HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2803440 2013-12-13] (Synaptics Incorporated)
HKLM-x32\…\Run: [HPMessageService] => C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe [1045304 2013-10-09] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\…\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6111824 2015-08-30] (AVAST Software)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-08-30] (AVAST Software)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] [removed] 8.8.8.8
Tcpip\..\Interfaces\{37846DCB-AA4B-417D-A9B4-E637341E7C0D}: [DhcpNameServer] 192.168.0.1 192.168.0.1
Tcpip\..\Interfaces\{9F15CB36-5474-4B97-A532-353C7A039D91}: [DhcpNameServer] [removed] 8.8.8.8
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.jp.msn.com/HPALL14/26
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.jp.msn.com/HPALL14/26
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.jp.msn.com/HPALL14/26
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.jp.msn.com/HPALL14/26
HKU\S-1-5-21-1288256610-1555022158-1377111214-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.jp.msn.com/HPALL14/26
HKU\S-1-5-21-1288256610-1555022158-1377111214-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.jp.msn.com/HPALL14/26
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-08-30] (AVAST Software)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28] (Hewlett-Packard)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-08-30] (AVAST Software)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28] (Hewlett-Packard)
FireFox:
========
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1219160.dll [2015-07-23] (Adobe Systems, Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll [2011-05-30] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2013-02-06] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-09-02] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-09-02] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2012-10-13] ()
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-08-30]
Chrome:
=======
CHR StartupUrls: Profile 1 -> "hxxp://www.google.com/"
CHR Profile: C:\Users\OMKARA\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\OMKARA\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-08-23]
CHR Extension: (Google Docs) - C:\Users\OMKARA\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-08-23]
CHR Extension: (Google Drive) - C:\Users\OMKARA\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-08-23]
CHR Extension: (YouTube) - C:\Users\OMKARA\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-08-23]
CHR Extension: (Google Search) - C:\Users\OMKARA\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-08-23]
CHR Extension: (Google Sheets) - C:\Users\OMKARA\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-08-23]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\OMKARA\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-08-23]
CHR Extension: (Chrome Web Store Payments) - C:\Users\OMKARA\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-23]
CHR Extension: (Gmail) - C:\Users\OMKARA\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-08-23]
CHR Profile: C:\Users\OMKARA\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Google Slides) - C:\Users\OMKARA\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-08-30]
CHR Extension: (Google Docs) - C:\Users\OMKARA\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2015-08-30]
CHR Extension: (Google Drive) - C:\Users\OMKARA\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-08-30]
CHR Extension: (YouTube) - C:\Users\OMKARA\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-08-30]
CHR Extension: (Google Search) - C:\Users\OMKARA\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-08-30]
CHR Extension: (Google Sheets) - C:\Users\OMKARA\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-08-30]
CHR Extension: (Avast Online Security) - C:\Users\OMKARA\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-08-30]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\OMKARA\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-08-30]
CHR Extension: (Chrome Web Store Payments) - C:\Users\OMKARA\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-30]
CHR Extension: (Gmail) - C:\Users\OMKARA\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-08-30]
CHR HKLM-x32\…\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-08-30]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-08-30] (AVAST Software)
R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [109008 2015-08-30] (AVAST Software)
R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [92160 2014-01-13] (Hewlett-Packard Company) [File not signed]
R2 HPWMISVC; C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe [1039160 2013-10-09] (Hewlett-Packard Development Company, L.P.)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-11-08] (Intel Corporation)
R2 omniserv; C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe [88064 2014-03-29] (Softex Inc.) [File not signed]
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [290520 2014-01-09] (Realtek Semiconductor)
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [76800 2014-04-02] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-08-08] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-08-08] (Microsoft Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-08-30] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [28144 2015-08-30] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [90968 2015-08-30] (AVAST Software)
R0 aswNdisFlt; C:\Windows\System32\DRIVERS\aswNdisFlt.sys [454016 2015-08-30] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-08-30] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-08-30] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1048344 2015-08-30] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [447944 2015-08-30] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [150672 2015-08-30] (AVAST Software)
S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-03-18] (Microsoft Corporation)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [91712 2013-03-06] (CyberLink)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [100312 2013-12-10] (Intel Corporation)
S3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [291544 2014-01-04] (Realtek Semiconductor Corp.)
R3 rtbth; C:\Windows\System32\drivers\rtbth.sys [1204424 2013-12-25] (Ralink Technology, Corp.)
S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [29936 2013-12-13] (Synaptics Incorporated)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [31472 2013-12-13] (Synaptics Incorporated)
R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20800 2013-07-23] (Hewlett-Packard Development Company, L.P.)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-09-02 21:16 - 2015-09-02 21:16 - 00000000 ____D C:\FRST
2015-09-02 21:15 - 2015-09-02 21:15 - 01687595 _____ C:\Users\OMKARA\Downloads\FRST64.zip
2015-09-02 20:40 - 2015-09-02 20:58 - 00000000 ____D C:\Program Files (x86)\Tensons
2015-09-01 23:57 - 2015-09-01 23:58 - 00000000 ____D C:\Users\OMKARA\AppData\Roaming\BitTorrent
2015-08-30 22:45 - 2015-08-30 22:45 - 00000000 ____D C:\Users\OMKARA\AppData\Roaming\AVAST Software
2015-08-30 22:44 - 2015-08-30 22:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2015-08-30 22:42 - 2015-08-30 22:42 - 00003924 _____ C:\WINDOWS\System32\Tasks\avast! Emergency Update
2015-08-30 22:41 - 2015-08-30 22:42 - 01048344 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsnx.sys
2015-08-30 22:41 - 2015-08-30 22:41 - 00454016 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswNdisFlt.sys
2015-08-30 22:41 - 2015-08-30 22:41 - 00447944 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2015-08-30 22:41 - 2015-08-30 22:41 - 00378880 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2015-08-30 22:41 - 2015-08-30 22:41 - 00274808 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2015-08-30 22:41 - 2015-08-30 22:41 - 00150672 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
2015-08-30 22:41 - 2015-08-30 22:41 - 00093528 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2015-08-30 22:41 - 2015-08-30 22:41 - 00090968 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2015-08-30 22:41 - 2015-08-30 22:41 - 00065224 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2015-08-30 22:41 - 2015-08-30 22:41 - 00043112 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2015-08-30 22:41 - 2015-08-30 22:41 - 00028656 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
2015-08-30 22:41 - 2015-08-30 22:41 - 00028144 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswKbd.sys
2015-08-30 22:09 - 2015-08-30 22:09 - 00000000 ____D C:\Program Files\AVAST Software
2015-08-30 22:07 - 2015-08-30 22:07 - 00000000 ____D C:\ProgramData\AVAST Software
2015-08-30 19:31 - 2015-09-01 23:57 - 00000000 ____D C:\Users\OMKARA\Desktop\New folder (2)
2015-08-30 18:43 - 2015-08-30 18:43 - 05198336 _____ (AVAST Software) C:\Users\OMKARA\Desktop\aswMBR.exe
2015-08-30 18:42 - 2015-08-30 18:43 - 05198336 _____ (AVAST Software) C:\Users\OMKARA\Downloads\aswMBR.exe
2015-08-30 17:12 - 2015-08-30 17:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-08-30 17:12 - 2015-08-30 17:12 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2015-08-25 23:17 - 2015-08-25 23:18 - 00217600 _____ C:\Users\OMKARA\Downloads\Workbook3.xls
2015-08-23 19:14 - 2015-08-23 19:14 - 00002286 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-08-23 19:14 - 2015-08-23 19:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-08-23 13:03 - 2015-09-02 21:14 - 00000926 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-08-23 13:03 - 2015-09-02 19:14 - 00000922 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-08-23 13:03 - 2015-09-02 19:09 - 00003898 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-08-23 13:03 - 2015-09-02 19:09 - 00003662 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2015-08-23 13:03 - 2015-08-23 19:13 - 00000000 ____D C:\Program Files (x86)\Google
2015-08-23 13:02 - 2015-08-30 17:01 - 00000000 ____D C:\Users\OMKARA\AppData\Local\Google
2015-08-23 12:58 - 2015-09-02 19:48 - 00000000 ____D C:\Users\OMKARA\AppData\Local\Deployment
2015-08-23 12:58 - 2015-08-23 12:58 - 00000000 ____D C:\Users\OMKARA\AppData\Local\Apps\2.0
2015-08-23 11:11 - 2015-08-23 11:12 - 00000000 ____D C:\Users\OMKARA\AppData\Roaming\WildTangent
2015-08-22 21:18 - 2015-09-02 18:27 - 00003172 _____ C:\WINDOWS\System32\Tasks\HPCeeScheduleForOMKARA
2015-08-22 21:18 - 2015-09-02 18:27 - 00000356 _____ C:\WINDOWS\Tasks\HPCeeScheduleForOMKARA.job
2015-08-22 01:08 - 2015-08-30 22:07 - 00000000 ____D C:\WINDOWS\System32\Tasks\McAfee
2015-08-21 08:14 - 2015-08-30 14:46 - 00000166 _____ C:\WINDOWS\SysWOW64\DOErrors.log
2015-08-20 20:45 - 2015-09-02 19:52 - 00000000 ____D C:\Users\OMKARA\Desktop\New folder
2015-08-20 20:45 - 2015-08-30 18:49 - 00000000 ____D C:\Users\OMKARA\Desktop\AIMS
2015-08-20 20:31 - 2015-09-02 21:03 - 00003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1288256610-1555022158-1377111214-1001
2015-08-20 20:29 - 2015-08-20 08:11 - 00000000 ____D C:\Users\OMKARA\AppData\Roaming\Hewlett-Packard
2015-08-20 20:28 - 2015-08-20 20:28 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf
2015-08-20 20:27 - 2015-09-02 18:19 - 00000000 ____D C:\Users\OMKARA\Documents\Youcam
2015-08-20 20:27 - 2015-08-20 20:27 - 00000000 ____D C:\Users\OMKARA\AppData\Local\CyberLink
2015-08-20 20:26 - 2015-08-20 20:26 - 00000000 ____D C:\WINDOWS\System32\Tasks\WPD
2015-08-20 20:26 - 2015-08-20 20:26 - 00000000 ____D C:\Users\OMKARA\AppData\Roaming\Synaptics
2015-08-20 20:26 - 2015-08-20 20:26 - 00000000 ____D C:\Users\OMKARA\AppData\Local\Power2Go8
2015-08-20 20:26 - 2015-08-20 20:26 - 00000000 ____D C:\ProgramData\Synaptics
2015-08-20 20:25 - 2015-09-02 20:52 - 01718739 _____ C:\WINDOWS\WindowsUpdate.log
2015-08-20 20:25 - 2015-08-30 14:50 - 00000000 ____D C:\Users\OMKARA
2015-08-20 20:25 - 2015-08-22 13:08 - 00000000 ____D C:\Users\OMKARA\AppData\Local\Packages
2015-08-20 20:25 - 2015-08-20 20:25 - 00002155 _____ C:\Users\Public\Desktop\WildTangent Games For HP.lnk
2015-08-20 20:25 - 2015-08-20 20:25 - 00001453 _____ C:\Users\OMKARA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-08-20 20:25 - 2015-08-20 20:25 - 00000020 ___SH C:\Users\OMKARA\ntuser.ini
2015-08-20 20:25 - 2015-08-20 20:25 - 00000000 ____D C:\Users\OMKARA\AppData\Roaming\Adobe
2015-08-20 20:25 - 2015-08-20 20:25 - 00000000 ____D C:\Users\OMKARA\AppData\Local\VirtualStore
2015-08-20 20:25 - 2015-08-20 19:37 - 00003918 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{CACEAAF6-02B1-464E-8451-2C83B40FD4FC}
2015-08-20 20:25 - 2014-08-08 01:11 - 00000000 ___RD C:\Users\OMKARA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-08-20 20:25 - 2014-04-25 07:34 - 00000000 ___HD C:\Users\OMKARA\Documents\hp.system.package.metadata
2015-08-20 20:25 - 2014-03-18 15:36 - 00000000 ___RD C:\Users\OMKARA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-08-20 20:25 - 2014-03-18 15:24 - 00000369 _____ C:\Users\OMKARA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk
2015-08-20 20:25 - 2014-03-18 15:24 - 00000369 _____ C:\Users\OMKARA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk
2015-08-20 20:25 - 2013-08-22 21:06 - 00000000 ___RD C:\Users\OMKARA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-20 20:25 - 2013-08-22 21:06 - 00000000 ____D C:\Users\OMKARA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-08-20 20:21 - 2015-08-20 20:21 - 00000000 ____D C:\Users\OMKARA\AppData\Roaming\Macromedia
2015-08-20 20:20 - 2015-08-20 20:20 - 00000000 __SHD C:\Users\OMKARA\AppData\Local\EmieUserList
2015-08-20 20:20 - 2015-08-20 20:20 - 00000000 __SHD C:\Users\OMKARA\AppData\Local\EmieSiteList
2015-08-20 20:12 - 2015-08-20 20:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2015-08-20 20:09 - 2015-08-20 20:09 - 00000000 ____D C:\WINDOWS\System32\Tasks\OfficeSoftwareProtectionPlatform
2015-08-20 20:07 - 2015-08-20 20:07 - 00000000 ____D C:\Program Files\Microsoft Office
2015-08-20 20:06 - 2015-08-29 23:30 - 00000000 ____D C:\Users\OMKARA\AppData\Local\Microsoft Help
2015-08-20 20:06 - 2015-08-20 20:17 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-08-20 20:06 - 2015-08-20 20:06 - 00000000 __RHD C:\MSOCache
2015-08-20 20:06 - 2015-08-20 20:06 - 00000000 ____D C:\Program Files (x86)\Microsoft Analysis Services
2015-08-20 16:51 - 2015-08-20 16:51 - 00000000 _____ C:\Recovery.txt
2015-08-20 16:36 - 2015-08-20 16:36 - 00002324 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1288256610-1555022158-1377111214-500
2015-08-20 08:19 - 2015-08-20 08:19 - 00000000 ____D C:\Users\OMKARA\AppData\Roaming\hpqlog
2015-08-20 08:11 - 2015-08-21 08:17 - 00000000 ____D C:\Users\OMKARA\AppData\Local\Hewlett-Packard
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-09-02 20:30 - 2013-08-22 21:06 - 00000000 ____D C:\WINDOWS\system32\sru
2015-09-01 23:27 - 2014-03-18 15:23 - 00958292 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-08-31 17:37 - 2013-08-22 20:50 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-08-31 13:01 - 2013-08-22 21:06 - 00000000 ____D C:\WINDOWS\system32\NDF
2015-08-30 22:58 - 2014-08-08 00:33 - 00000000 ____D C:\Program Files\Common Files\mcafee
2015-08-30 22:58 - 2014-08-08 00:33 - 00000000 ____D C:\Program Files (x86)\McAfee
2015-08-30 22:58 - 2014-08-08 00:32 - 00000000 ____D C:\ProgramData\McAfee
2015-08-30 22:58 - 2013-08-22 20:15 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-08-30 22:57 - 2014-03-18 15:14 - 00008496 _____ C:\WINDOWS\PFRO.log
2015-08-30 22:57 - 2013-08-22 18:55 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2015-08-30 22:10 - 2013-08-22 21:06 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
2015-08-30 22:10 - 2013-08-22 18:55 - 00262144 ___SH C:\WINDOWS\system32\config\ELAM
2015-08-30 21:53 - 2014-04-25 07:38 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Security and Protection
2015-08-23 11:12 - 2014-04-25 07:58 - 00000000 ____D C:\ProgramData\WildTangent
2015-08-22 13:13 - 2013-08-22 21:06 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-08-22 00:04 - 2013-08-22 20:14 - 00414144 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-08-21 00:00 - 2014-04-02 15:55 - 00000000 ____D C:\WINDOWS\Panther
2015-08-20 20:35 - 2013-08-22 20:16 - 00022312 _____ C:\WINDOWS\setupact.log
2015-08-20 20:25 - 2014-08-08 00:38 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Communication and Chat
2015-08-20 20:25 - 2014-04-25 07:49 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support
2015-08-20 20:25 - 2014-04-25 07:47 - 00000000 ___RD C:\Program Files (x86)\Online Services
2015-08-20 20:25 - 2014-04-25 07:37 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Productivity and Tools
2015-08-20 20:25 - 2014-04-01 06:37 - 00000000 ___HD C:\SYSTEM.SAV
2015-08-20 20:11 - 2014-04-25 07:39 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2015-08-20 20:09 - 2013-08-22 21:06 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2015-08-20 20:07 - 2013-08-22 21:06 - 00000000 ____D C:\WINDOWS\rescache
2015-08-20 20:06 - 2014-03-18 15:08 - 00000000 ____D C:\WINDOWS\ShellNew
2015-08-20 20:05 - 2013-08-22 21:06 - 00000000 ____D C:\WINDOWS\system32\restore
2015-08-20 19:55 - 2014-08-08 00:39 - 00000000 ____D C:\Users\Public\CyberLink
2015-08-20 16:50 - 2013-08-22 21:06 - 00262144 _____ C:\WINDOWS\system32\config\BCD-Template
2015-08-20 16:39 - 2014-04-01 06:37 - 00000000 ____D C:\SWSetup
2015-08-20 16:39 - 2013-08-22 21:06 - 00000000 ____D C:\WINDOWS\system32\Recovery
2015-08-20 16:38 - 2014-04-02 15:22 - 00010342 _____ C:\WINDOWS\iis.log
2015-08-20 16:38 - 2013-08-22 21:07 - 00005496 _____ C:\WINDOWS\DtcInstall.log
2015-08-08 19:25 - 2013-08-22 21:08 - 00794088 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-08-08 19:25 - 2013-08-22 21:08 - 00179688 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
Some files in TEMP:
====================
C:\Users\OMKARA\AppData\Local\Temp\0244041440951700mcinst.exe
C:\Users\OMKARA\AppData\Local\Temp\McCSPInstall.dll
C:\Users\OMKARA\AppData\Local\Temp\mccspuninstall.exe
C:\Users\OMKARA\AppData\Local\Temp\ose00000.exe
C:\Users\OMKARA\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-04-02 14:55
==================== End of FRST.txt ============================
ADDITION :
Additional scan result of Farbar Recovery Scan Tool (x64) Version:31-08-2015
Ran by [removed] (2015-09-02 21:18:08)
Running from C:\Users\[removed]\AppData\Local\Temp\Temp1_FRST64.zip
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-1288256610-1555022158-1377111214-500 - Administrator - Disabled)
Guest (S-1-5-21-1288256610-1555022158-1377111214-501 - Limited - Disabled)
OMKARA (S-1-5-21-1288256610-1555022158-1377111214-1001 - Administrator - Enabled) => C:\Users\OMKARA
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: avast! Antivirus (Enabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
4 Elements II (x32 Version: 2.2.0.98 - WildTangent) Hidden
7-Zip 9.20 (x64 edition) (HKLM\…\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Adobe Shockwave Player 12.1 (HKLM-x32\…\Adobe Shockwave Player) (Version: 12.1.9.160 - Adobe Systems, Inc.)
Airport Mania (x32 Version: 2.2.0.95 - WildTangent) Hidden
Aloha TriPeaks (x32 Version: 2.2.0.98 - WildTangent) Hidden
Avast Internet Security (HKLM-x32\…\Avast) (Version: 10.3.2225 - AVAST Software)
Azkend 2: The World Beneath (x32 Version: 2.2.0.98 - WildTangent) Hidden
Bejeweled 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden
Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Bounce Symphony (x32 Version: 2.2.0.97 - WildTangent) Hidden
Build-a-lot (x32 Version: 2.2.0.98 - WildTangent) Hidden
Connected Music powered by Universal Music Group version 1.0 (HKLM-x32\…\{4A3579A7-8A6A-4F07-8EFD-9E1DD7605864}_is1) (Version: 1.0 - Universal Music India)
Cradle of Rome 2 (x32 Version: 2.2.0.98 - WildTangent) Hidden
Curse at Twilight (x32 Version: 3.0.2.32 - WildTangent) Hidden
CyberLink LabelPrint (HKLM-x32\…\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.5.6902 - CyberLink Corp.)
CyberLink Media Suite 10 (HKLM-x32\…\InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}) (Version: 10.0.5.3303 - CyberLink Corp.)
CyberLink Power2Go 8 (HKLM-x32\…\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}) (Version: 8.0.5.3416 - CyberLink Corp.)
CyberLink PowerDVD 12 (HKLM-x32\…\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.3.3709 - CyberLink Corp.)
CyberLink YouCam (HKLM-x32\…\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 5.0.3.3907 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Delicious: Emily's Childhood Memories Premium Edition (x32 Version: 3.0.2.32 - WildTangent) Hidden
DisableMSDefender (Version: 1.0.0 - Hewlett-Packard Company) Hidden
Energy Star (HKLM\…\{465CA2B6-98AF-4E77-BE22-A908C34BB9EC}) (Version: 1.0.9 - Hewlett-Packard Company)
Farm Frenzy (x32 Version: 2.2.0.98 - WildTangent) Hidden
Fishdom 3: Collector's Edition (x32 Version: 3.0.2.38 - WildTangent) Hidden
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 44.0.2403.157 - Google Inc.)
Google Update Helper (x32 Version: 1.3.28.13 - Google Inc.) Hidden
Governor of Poker 2 Premium Edition (x32 Version: 2.2.0.110 - WildTangent) Hidden
Hewlett-Packard ACLM.NET v1.2.2.3 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden
House of 1000 Doors: Family Secrets (x32 Version: 2.2.0.98 - WildTangent) Hidden
HP Documentation (HKLM-x32\…\{F29E3AA8-CF19-4452-92B7-F1FE31CD11C5}) (Version: 1.1.0.0 - Hewlett-Packard)
HP Registration Service (HKLM\…\{D1E8F2D7-7794-4245-B286-87ED86C1893C}) (Version: 1.2.7372.4698 - Hewlett-Packard)
HP SimplePass (HKLM-x32\…\InstallShield_{314FAD12-F785-4471-BCE8-AB506642B9A1}) (Version: 8.01.11 - Hewlett-Packard)
HP Support Assistant (HKLM-x32\…\{8C696B4B-6AB1-44BC-9416-96EAC474CABE}) (Version: 7.5.2.12 - Hewlett-Packard Company)
HP System Event Utility (HKLM-x32\…\{C78E8F51-3EAD-4F0C-83F0-EF371075E0B4}) (Version: 1.0.10 - Hewlett-Packard Company)
HP Utility Center (HKLM\…\{891A1782-8B20-4403-8383-458962525926}) (Version: 2.3.4 - Hewlett-Packard Company)
HP Wireless Button Driver (HKLM-x32\…\{30B2D1D8-0A07-4B71-9553-0710C5D31E35}) (Version: 1.1.2.1 - Hewlett-Packard Company)
Inst5675 (Version: 8.01.11 - Softex Inc.) Hidden
Inst5676 (Version: 8.01.11 - Softex Inc.) Hidden
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.24.1790 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3368 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\…\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.9.1000 - Intel Corporation)
Jewel Match 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden
John Deere Drive Green (x32 Version: 2.2.0.95 - WildTangent) Hidden
Letters from Nowhere 2 (x32 Version: 2.2.0.97 - WildTangent) Hidden
Luxor Evolved (x32 Version: 2.2.0.98 - WildTangent) Hidden
Mahjongg Dimensions Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Mediatek Bluetooth (HKLM\…\{16BCAEDC-C115-1729-07C4-7A0091C699A6}) (Version: 11.0.749.0 - Mediatek)
Microsoft Office (HKLM-x32\…\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Office Home and Student 2010 (HKLM-x32\…\Office14.SingleImage) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Outlook Social Connector (KB2289116) ªº§ó·s (HKLM-x32\…\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{75F91382-920C-4AE1-B9E6-FFFCEDA797E8}) (Version: - Microsoft)
Microsoft Silverlight (HKLM-x32\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.0.60531.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\…\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\…\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Peggle Nights (x32 Version: 2.2.0.98 - WildTangent) Hidden
Penguins! (x32 Version: 2.2.0.98 - WildTangent) Hidden
Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.98 - WildTangent) Hidden
Polar Bowler (x32 Version: 2.2.0.97 - WildTangent) Hidden
Ralink RT3290 802.11bgn Wi-Fi Adapter (HKLM-x32\…\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: 5.0.37.0 - Mediatek)
Realtek Card Reader (HKLM-x32\…\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.9600.29075 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller All-In-One Windows Driver (HKLM-x32\…\{F7E7F0CB-AA41-4D5A-B6F2-8E6738EB063F}) (Version: 8.24.1218.2013 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7156 - Realtek Semiconductor Corp.)
Roads of Rome 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 18.0.4.0 - Synaptics Incorporated)
The Treasures of Mystery Island: The Ghost Ship (x32 Version: 2.2.0.98 - WildTangent) Hidden
Trinklit Supreme (x32 Version: 2.2.0.98 - WildTangent) Hidden
Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden
Vacation Questâ„¢ - Australia (x32 Version: 3.0.2.32 - WildTangent) Hidden
WildTangent Games (HKLM-x32\…\WildTangent wildgames Master Uninstall) (Version: 1.0.4.0 - WildTangent)
WildTangent Games App (HP Games) (x32 Version: 4.0.10.15 - WildTangent) Hidden
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation)
Youda Jewel Shop (x32 Version: 3.0.2.32 - WildTangent) Hidden
Zuma's Revenge (x32 Version: 2.2.0.98 - WildTangent) Hidden
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== Restore Points =========================
20-08-2015 20:05:38 Installed Microsoft Office Home and Student 2010
30-08-2015 22:08:28 avast! antivirus system restore point
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2013-08-22 18:55 - 2013-08-22 18:55 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {490C808D-27AE-495F-B39F-308393F45EFE} - System32\Tasks\Synaptics TouchPad Enhancements => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2013-12-13] (Synaptics Incorporated)
Task: {4E146DE8-1922-432C-8094-5E10DCD04C99} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-23] (Google Inc.)
Task: {68A0F3AE-8815-48D1-BE13-89F4F5F7176C} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2014-01-13] (Hewlett-Packard Company)
Task: {90D35AA6-A0BF-4011-89C3-EC0EBB2FA931} - System32\Tasks\HPCeeScheduleForOMKARA => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2011-07-15] (Hewlett-Packard)
Task: {9BB6633F-A1D5-496A-A0B3-9C9679E7F85E} - System32\Tasks\CLVDLauncher => C:\Program Files (x86)\CyberLink\Power2Go8\CLVDLauncher.exe [2013-03-12] (CyberLink Corp.)
Task: {A3D66FC6-476A-43B9-8EDE-1B57E0B4FDC9} - System32\Tasks\YCMServiceAgent => C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe [2014-03-07] (CyberLink Corp.)
Task: {AA8F7FC1-8CF8-4293-A613-76DC335611E2} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2014-01-13] (Hewlett-Packard Company)
Task: {C37EA4F0-2436-4491-9759-1845DECEE8AF} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2012-11-30] (Hewlett-Packard Company)
Task: {C42C3AC6-D5D7-4DAE-B008-57E624965467} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-08-30] (AVAST Software)
Task: {CA6A2682-E0FF-42F5-BC68-D39E3539270B} - System32\Tasks\CLMLSvc_P2G8 => C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [2013-08-05] (CyberLink)
Task: {EA81368D-30D3-4A27-B973-A5CAB45E7BDC} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-23] (Google Inc.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\HPCeeScheduleForOMKARA.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
==================== Loaded Modules (Whitelisted) ==============
2014-03-29 02:01 - 2014-03-29 02:01 - 02110464 _____ () C:\Program Files\Hewlett-Packard\SimplePass\autheng.dll
2014-03-29 01:57 - 2014-03-29 01:57 - 00021504 _____ () C:\Program Files\Hewlett-Packard\SimplePass\cryptodll.dll
2014-03-29 01:57 - 2014-03-29 01:57 - 00035328 _____ () C:\Program Files\Hewlett-Packard\SimplePass\ssplogon.dll
2014-03-29 01:57 - 2014-03-29 01:57 - 00055296 _____ () C:\Program Files\Hewlett-Packard\SimplePass\RandomPass.dll
2014-03-29 02:18 - 2014-03-29 02:18 - 00367504 _____ () C:\Program Files\Hewlett-Packard\SimplePass\mstrpwd.dll
2014-03-29 02:18 - 2014-03-29 02:18 - 00712080 _____ () C:\Program Files\Hewlett-Packard\SimplePass\GraphicalPwd.dll
2014-03-29 02:06 - 2014-03-29 02:06 - 00065024 _____ () C:\Program Files\Hewlett-Packard\SimplePass\opvapp.exe
2015-08-30 22:41 - 2015-08-30 22:41 - 00102864 _____ () C:\Program Files\AVAST Software\Avast\log.dll
2015-08-30 22:41 - 2015-08-30 22:41 - 00123976 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2015-08-30 22:41 - 2015-08-30 22:41 - 02961920 _____ () C:\Program Files\AVAST Software\Avast\defs\15083000\algo.dll
2015-09-02 18:21 - 2015-09-02 18:21 - 02961408 _____ () C:\Program Files\AVAST Software\Avast\defs\15090200\algo.dll
2015-08-30 22:41 - 2015-08-30 22:41 - 40540672 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2014-08-08 00:40 - 2013-08-05 13:19 - 00627672 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll
2013-08-06 04:18 - 2013-08-06 04:18 - 00016856 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll
2015-08-23 19:13 - 2015-08-18 10:53 - 01405768 _____ () C:\Program Files (x86)\Google\Chrome\Application\44.0.2403.157\libglesv2.dll
2015-08-23 19:13 - 2015-08-18 10:53 - 00081224 _____ () C:\Program Files (x86)\Google\Chrome\Application\44.0.2403.157\libegl.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
==================== EXE Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-1288256610-1555022158-1377111214-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\OMKARA\AppData\Local\Microsoft\Windows\Themes\Panoramas\DesktopBackground\13_joshrobinson-ruakokopatunacavesfarmlandmartinboroughnz.jpg
DNS Servers: [removed] - 8.8.8.8
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{3043CEAD-CAC4-4CC3-A490-81D56E3987D2}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{4A830FA1-A93C-444D-8359-B44DA301D4C0}] => (Allow) LPort=2869
FirewallRules: [{FDFC436C-B749-4713-9143-D2C405D56AA5}] => (Allow) LPort=1900
FirewallRules: [{E03F2F9F-4F12-4D18-9DC5-1A629AB50D70}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{E2E5C87B-890B-40D8-9BEA-4589D41D7768}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{8AEC143D-5E8F-45E6-A554-1DB60EB0D689}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{549864EE-B034-411A-B32D-2A20BC26DA02}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{0F0D705E-53DA-4114-80CA-199757C28A24}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{C214C126-BE89-4730-91BE-9C67052290C0}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12.exe
FirewallRules: [{B2B25A76-32FC-4F31-9881-FF5C28A9FB18}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe
FirewallRules: [{6D0B1DC2-BBDD-4221-8245-91FF1D4D656C}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe
FirewallRules: [{E31B6D9B-BA1D-4D2E-B1D0-73ACB88DF8C0}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe
FirewallRules: [{46D8CD8C-C4DF-408B-9A0D-95DC9C9DA425}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12ML.exe
FirewallRules: [{B62FCE6E-866E-469C-BBBF-5ACC163324BA}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Movie\PowerDVD.exe
FirewallRules: [{B37DC80F-318F-4D4B-A374-55D89B8C30B6}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [TCP Query User{80FA99BC-CD47-408F-9CE2-67B2CB668A7D}C:\users\omkara\appdata\roaming\bittorrent\bittorrent.exe] => (Block) C:\users\omkara\appdata\roaming\bittorrent\bittorrent.exe
FirewallRules: [UDP Query User{5B1DA134-ADEA-46AC-A221-8EEBE6100472}C:\users\omkara\appdata\roaming\bittorrent\bittorrent.exe] => (Block) C:\users\omkara\appdata\roaming\bittorrent\bittorrent.exe
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (09/02/2015 06:18:20 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 65956046
Error: (09/02/2015 06:18:20 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 65956046
Error: (09/02/2015 06:18:20 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (09/01/2015 11:35:18 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (08/31/2015 12:29:38 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program iexplore.exe version 11.0.9600.17037 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
Process ID: d0c
Start Time: 01d0e3a5fb411eaa
Termination Time: 0
Application Path: C:\Program Files\Internet Explorer\iexplore.exe
Report Id: c49aae65-4fad-11e5-8265-1458d00cf34a
Faulting package full name:
Faulting package-relative application ID:
Error: (08/31/2015 10:21:15 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (08/31/2015 09:57:17 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 30464094
Error: (08/31/2015 09:57:17 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 30464094
Error: (08/31/2015 09:57:17 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (08/31/2015 01:29:26 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: ACHAREKAR)
Description: Activation of app AD2F1837.GettingStartedwithWindows8_v10z8vjag6ke6!App failed with error: -2144927141 See the Microsoft-Windows-TWinUI/Operational log for additional information.
System errors:
=============
Error: (08/31/2015 01:29:26 AM) (Source: DCOM) (EventID: 10010) (User: ACHAREKAR)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
Error: (08/31/2015 01:29:26 AM) (Source: DCOM) (EventID: 10010) (User: ACHAREKAR)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
Error: (08/31/2015 01:29:26 AM) (Source: DCOM) (EventID: 10010) (User: ACHAREKAR)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
Error: (08/31/2015 01:29:26 AM) (Source: DCOM) (EventID: 10010) (User: ACHAREKAR)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
Error: (08/31/2015 01:29:21 AM) (Source: DCOM) (EventID: 10010) (User: ACHAREKAR)
Description: App.AppXvmd16qvfmzznt9bwxyppsy3jj2gv4trt.wwa
Error: (08/30/2015 09:55:16 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: {209500FC-6B45-4693-8871-6296C4843751}
Error: (08/30/2015 09:53:32 PM) (Source: DCOM) (EventID: 10010) (User: ACHAREKAR)
Description: {209500FC-6B45-4693-8871-6296C4843751}
Error: (08/30/2015 09:53:01 PM) (Source: DCOM) (EventID: 10010) (User: ACHAREKAR)
Description: {209500FC-6B45-4693-8871-6296C4843751}
Error: (08/30/2015 09:52:42 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The McAfee Proxy Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
Error: (08/30/2015 09:52:42 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The McAfee Boot Delay Start Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
Microsoft Office:
=========================
Error: (09/02/2015 06:18:20 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 65956046
Error: (09/02/2015 06:18:20 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 65956046
Error: (09/02/2015 06:18:20 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (09/01/2015 11:35:18 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (08/31/2015 12:29:38 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: iexplore.exe11.0.9600.17037d0c01d0e3a5fb411eaa0C:\Program Files\Internet Explorer\iexplore.exec49aae65-4fad-11e5-8265-1458d00cf34a
Error: (08/31/2015 10:21:15 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (08/31/2015 09:57:17 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 30464094
Error: (08/31/2015 09:57:17 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 30464094
Error: (08/31/2015 09:57:17 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (08/31/2015 01:29:26 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: ACHAREKAR)
Description: AD2F1837.GettingStartedwithWindows8_v10z8vjag6ke6!App-2144927141
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i3-4005U CPU @ 1.70GHz
Percentage of memory in use: 40%
Total physical RAM: 4027.84 MB
Available physical RAM: 2416.05 MB
Total Virtual: 4731.84 MB
Available Virtual: 2782.09 MB
==================== Drives ================================
Drive c: (Windows) (Fixed) (Total:907.8 GB) (Free:867.95 GB) NTFS
Drive d: (RECOVERY) (Fixed) (Total:21.86 GB) (Free:2.11 GB) NTFS ==>[system with boot components (obtained from reading drive)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 5CAA5BBA)
Partition: GPT.
==================== End of Addition.txt ============================
THANK YOU