ok, aquí están:
Primero el FRST
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 03.03.2019 01
Ran by Antonio1 (administrator) on ANTONIO (04-03-2019 10:46:17)
Running from C:\Users\Antonio1\Desktop
Loaded Profiles: Antonio1 (Available Profiles: Antonio1)
Platform: Windows 8.1 (Update) (X64) Language: Español (España, internacional)
Default browser: FF
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\AVGSvc.exe
(AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\afwServ.exe
(Adobe Systems, Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(SEIKO EPSON Corporation -> SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE
(SEIKO EPSON Corporation -> SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE
(Paramount Software UK Ltd -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\MacriumService.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxHK.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxTray.exe
(AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\AVGUI.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe
(TechPowerUp Ltd -> uWebb Software) E:\documentos\RealTemp_370\RealTemp.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7575256 2014-05-12] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [3942232 2016-10-13] (Logitech -> Logitech, Inc.)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation -> Microsoft Corporation)
HKLM-x32\...\Run: [AVGUI.exe] => C:\Program Files\AVG\Antivirus\AvLaunch.exe [307632 2019-02-12] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
HKU\S-1-5-21-2999475868-1411259359-3238297896-1001\...\RunOnce: [a8a8e154] => C:\ProgramData\a8a8e154\a8a8e154.exe C:\ProgramData\a8a8e154\a8a8e154test.au3
HKU\S-1-5-21-2999475868-1411259359-3238297896-1001\...\RunOnce: [a8a8e1542] => C:\ProgramData\TUMhdP\a8a8e154.exe [937776 2019-03-04] (AutoIt Consulting Ltd -> AutoIt Team)
HKU\S-1-5-21-2999475868-1411259359-3238297896-1001\...\Policies\Explorer: [NoDriveTypeAutoRun] -33
HKU\S-1-5-18\...\Run: [GarminExpress] => C:\Program Files (x86)\Garmin\Express\express.exe [30872640 2018-11-28] (Garmin International, Inc. -> Garmin Ltd. or its subsidiaries)
HKLM\...\Drivers32: [msacm.l3codecp] => C:\WINDOWS\system32\l3codecp.acm [177152 2014-10-29] (Microsoft Windows -> Fraunhofer Institut Integrierte Schaltungen IIS)
HKLM\...\Drivers32: [VIDC.LAGS] => C:\WINDOWS\system32\lagarith.dll [148992 2011-12-07] ( ) [File not signed]
HKLM\...\Drivers32: [msacm.l3codecp] => C:\WINDOWS\SysWOW64\l3codecp.acm [186368 2014-10-29] (Microsoft Windows -> Fraunhofer Institut Integrierte Schaltungen IIS)
HKLM\...\Drivers32: [VIDC.XVID] => C:\Windows\SysWOW64\xvidvfw.dll [243200 2011-06-24] () [File not signed]
HKLM\...\Drivers32: [VIDC.LAGS] => C:\WINDOWS\SysWOW64\lagarith.dll [216064 2011-12-07] ( ) [File not signed]
HKLM\...\Drivers32: [VIDC.FFDS] => C:\Windows\SysWOW64\ff_vfw.dll [112640 2013-01-14] () [File not signed]
HKLM\...\Drivers32: [msacm.ac3acm] => C:\Windows\SysWOW64\ac3acm.acm [151552 2011-12-21] (fccHandler) [File not signed]
HKLM\...\Drivers32: [vidc.MPG4] => C:\Windows\SysWOW64\MPG4C32.dll [413760 2010-03-12] (Microsoft Corporation) [File not signed]
HKLM\...\Drivers32: [vidc.MP42] => C:\Windows\SysWOW64\MPG4C32.dll [413760 2010-03-12] (Microsoft Corporation) [File not signed]
HKLM\...\Drivers32: [vidc.MP43] => C:\Windows\SysWOW64\MPG4C32.dll [413760 2010-03-12] (Microsoft Corporation) [File not signed]
Startup: C:\Users\Antonio1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Samsung SSD Magician.lnk [2013-02-06]
ShortcutTarget: Samsung SSD Magician.lnk -> C:\Program Files (x86)\Samsung SSD Magician\Samsung SSD Magician.exe (Samsung Electronics.) [File not signed]
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 212.89.28.19 212.89.0.77
Tcpip\..\Interfaces\{B4D0352E-184F-44D5-85A7-495EA7632D5F}: [DhcpNameServer] 212.89.28.19 212.89.0.77
Internet Explorer:
==================
HKU\S-1-5-21-2999475868-1411259359-3238297896-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.es/
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-03-09] (Microsoft Corporation -> Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-03-09] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: http - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-02-03] (Microsoft Corporation) [File not signed]
Handler-x32: http - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-02-03] (Microsoft Corporation) [File not signed]
Handler-x32: https - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-02-03] (Microsoft Corporation) [File not signed]
Handler-x32: https - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-02-03] (Microsoft Corporation) [File not signed]
Handler-x32: ipp - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-02-03] (Microsoft Corporation) [File not signed]
Handler-x32: msdaipp - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-02-03] (Microsoft Corporation) [File not signed]
Handler-x32: msdaipp - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-02-03] (Microsoft Corporation) [File not signed]
FireFox:
========
FF ProfilePath: C:\Users\Antonio1\AppData\Roaming\Mozilla\Firefox\Profiles\diij7faq.default [2019-03-04]
FF user.js: detected! => C:\Users\Antonio1\AppData\Roaming\Mozilla\Firefox\Profiles\diij7faq.default\user.js [2013-02-08]
FF Homepage: Mozilla\Firefox\Profiles\diij7faq.default -> hxxp://www.google.es/
FF Extension: (Windscribe VPN) - C:\Users\Antonio1\AppData\Roaming\Mozilla\Firefox\Profiles\diij7faq.default\Extensions\@windscribeff.xpi [2018-10-14]
FF Extension: (MyJDownloader Browser Extension) - C:\Users\Antonio1\AppData\Roaming\Mozilla\Firefox\Profiles\diij7faq.default\Extensions\[email protected] [2018-08-02] [UpdateUrl:hxxps://my.jdownloader.org/extensions/firefox.json]
FF Extension: (KProxy Extension) - C:\Users\Antonio1\AppData\Roaming\Mozilla\Firefox\Profiles\diij7faq.default\Extensions\[email protected] [2018-05-07]
FF Extension: (NoScript) - C:\Users\Antonio1\AppData\Roaming\Mozilla\Firefox\Profiles\diij7faq.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2018-12-23]
FF Extension: (Video DownloadHelper) - C:\Users\Antonio1\AppData\Roaming\Mozilla\Firefox\Profiles\diij7faq.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2018-08-02]
FF Extension: (Adblock Plus - bloqueador de anuncios gratis) - C:\Users\Antonio1\AppData\Roaming\Mozilla\Firefox\Profiles\diij7faq.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2019-01-24]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_32_0_0_142.dll [2019-02-12] (Adobe Systems Incorporated -> )
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.2.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-11-29] (VideoLAN -> VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_142.dll [2019-02-12] (Adobe Systems Incorporated -> )
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [No File]
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2019-02-01] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AVG Antivirus; C:\Program Files\AVG\Antivirus\AVGSvc.exe [357360 2019-02-12] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
R2 AVG Firewall; C:\Program Files\AVG\Antivirus\afwServ.exe [369312 2019-02-12] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
S3 avgbIDSAgent; C:\Program Files\AVG\Antivirus\aswidsagent.exe [6807360 2019-02-12] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
R2 igfxCUIService1.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [320472 2018-01-02] (Intel(R) pGFX -> Intel Corporation)
R2 MacriumService; C:\Program Files\Macrium\Common\MacriumService.exe [3894760 2017-10-19] (Paramount Software UK Ltd -> Paramount Software UK Ltd)
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6347056 2018-09-19] (Malwarebytes Corporation -> Malwarebytes)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [361824 2017-01-12] (Microsoft Corporation -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [119872 2017-01-12] (Microsoft Corporation -> Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 3xHybr64; C:\WINDOWS\system32\DRIVERS\3xHybr64.sys [1425920 2010-12-01] (Microsoft Windows Hardware Compatibility Publisher -> NXP Semiconductors Germany GmbH)
R1 avgArPot; C:\WINDOWS\System32\drivers\avgArPot.sys [205656 2019-02-12] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
R1 avgbidsdriver; C:\WINDOWS\System32\drivers\avgbidsdriver.sys [226448 2019-02-12] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
R0 avgbidsh; C:\WINDOWS\System32\drivers\avgbidsh.sys [196848 2019-02-12] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
R0 avgblog; C:\WINDOWS\System32\drivers\avgblog.sys [320960 2019-02-12] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
R0 avgbuniv; C:\WINDOWS\System32\drivers\avgbuniv.sys [58008 2019-02-12] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
R1 avgKbd; C:\WINDOWS\System32\drivers\avgKbd.sys [42552 2019-02-12] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
R2 avgMonFlt; C:\WINDOWS\System32\drivers\avgMonFlt.sys [167560 2019-02-12] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
R1 avgNetSec; C:\WINDOWS\System32\drivers\avgNetSec.sys [519920 2019-02-13] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
R1 avgRdr; C:\WINDOWS\System32\drivers\avgRdr2.sys [112568 2019-02-12] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
R0 avgRvrt; C:\WINDOWS\System32\drivers\avgRvrt.sys [88208 2019-02-12] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
R1 avgSnx; C:\WINDOWS\System32\drivers\avgSnx.sys [1034184 2019-02-12] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
R1 avgSP; C:\WINDOWS\System32\drivers\avgSP.sys [474712 2019-02-15] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
S2 avgStm; C:\WINDOWS\System32\drivers\avgStm.sys [217040 2019-02-12] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
R0 avgVmm; C:\WINDOWS\System32\drivers\avgVmm.sys [380208 2019-02-12] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
S3 DSDrv4AMD64; C:\Program Files (x86)\DScaler\DSDrv4amd64.sys [22488 2009-08-28] (John Adcock -> )
S3 GenericMount; C:\WINDOWS\System32\drivers\GenericMount.sys [66608 2010-02-12] (Symantec Corporation -> Symantec Corporation)
S3 jakndis; C:\WINDOWS\system32\DRIVERS\jakndis.sys [35648 2011-07-21] (Jaksta Technologies Pty Ltd -> Jaksta Technologies Pty Ltd)
R3 jakndisMP; C:\WINDOWS\system32\DRIVERS\jakndis.sys [35648 2011-07-21] (Jaksta Technologies Pty Ltd -> Jaksta Technologies Pty Ltd)
S3 PSMounterEx; C:\Windows\system32\drivers\psmounterex.sys [168968 2015-10-12] (Paramount Software UK Ltd -> Windows (R) Win 7 DDK provider)
S3 Rockusb; C:\WINDOWS\System32\drivers\rockusb.sys [66704 2013-09-09] (Fuzhou Rockchip Electronics Co., Ltd. -> Fuzhou Rockchip Electronics Co,Ltd.)
R3 RTL8168; C:\WINDOWS\system32\DRIVERS\Rt630x64.sys [591360 2013-06-18] (Microsoft Windows -> Realtek )
R0 speedfan; C:\Windows\SysWow64\speedfan.sys [29592 2011-03-18] (Sokno S.R.L. -> Almico Software)
S3 TRIDCap; C:\WINDOWS\system32\DRIVERS\AVerTM62_x64.sys [1057792 2012-10-17] (AVerMedia TECHNOLOGIES, Inc. ) [File not signed]
R1 VBoxUSBMon; C:\WINDOWS\system32\DRIVERS\VBoxUSBMon.sys [127432 2015-09-16] (Duodian Online Technology Co. Ltd. -> BigNox Corporation)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [46600 2017-02-10] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [274776 2017-01-12] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [117592 2017-01-12] (Microsoft Windows -> Microsoft Corporation)
R3 WinRing0_1_2_0; E:\documentos\RealTemp_370\WinRing0x64.sys [14544 2008-07-26] (Noriyuki MIYAZAKI -> OpenLibSys.org)
R1 XQHDrv; C:\WINDOWS\system32\DRIVERS\XQHDrv.sys [253384 2015-09-16] (Duodian Online Technology Co. Ltd. -> BigNox Corporation)
R1 XQHDrv; C:\Windows\SysWOW64\DRIVERS\XQHDrv.sys [253384 2015-09-16] (Duodian Online Technology Co. Ltd. -> BigNox Corporation)
U2 V2iMount; no ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2019-03-04 10:46 - 2019-03-04 10:46 - 000016127 _____ C:\Users\Antonio1\Desktop\FRST.txt
2019-03-04 10:46 - 2019-03-04 10:46 - 000000000 ____D C:\ProgramData\ekgSjj
2019-03-04 10:46 - 2019-03-04 10:46 - 000000000 ____D C:\FRST
2019-03-04 10:43 - 2019-03-04 10:43 - 002434560 _____ (Farbar) C:\Users\Antonio1\Desktop\FRST64.exe
2019-03-04 09:56 - 2019-03-04 09:56 - 000000000 ____D C:\ProgramData\BhRAkV
2019-03-04 09:54 - 2019-03-04 09:54 - 000000000 ____D C:\ProgramData\LJtmpJ
2019-03-04 09:53 - 2019-03-04 09:54 - 000000000 ____D C:\AdwCleaner
2019-03-03 20:51 - 2019-03-03 20:51 - 000000000 ____D C:\ugixstencq__
2019-02-24 14:10 - 2019-02-24 14:10 - 000001100 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Debut, capturador de vídeo.lnk
2019-02-20 16:09 - 2019-02-20 16:09 - 000001775 _____ C:\Users\Antonio1\Desktop\scummvm - Acceso directo.lnk
2019-02-19 23:16 - 2019-02-19 23:16 - 000000957 _____ C:\Users\Antonio1\Desktop\Autow0rk - Acceso directo.lnk
2019-02-19 22:00 - 2019-02-19 22:49 - 000000000 ____D C:\RPGAMES
2019-02-13 12:54 - 2019-02-13 12:54 - 000519920 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgNetSec.sys
2019-02-13 12:42 - 2019-02-06 03:07 - 003323392 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2019-02-13 12:42 - 2019-02-06 02:43 - 003616768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2019-02-13 12:42 - 2019-02-06 01:53 - 002780160 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2019-02-13 12:42 - 2019-02-06 01:44 - 002464256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2019-02-13 12:42 - 2019-01-26 02:02 - 025736192 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2019-02-13 12:42 - 2019-01-26 01:38 - 002902528 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2019-02-13 12:42 - 2019-01-26 01:36 - 000576512 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2019-02-13 12:42 - 2019-01-26 01:32 - 005778944 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2019-02-13 12:42 - 2019-01-26 01:27 - 020279808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2019-02-13 12:42 - 2019-01-26 01:24 - 000790016 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2019-02-13 12:42 - 2019-01-26 01:06 - 000498176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2019-02-13 12:42 - 2019-01-26 01:03 - 002295808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2019-02-13 12:42 - 2019-01-26 00:57 - 000663040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2019-02-13 12:42 - 2019-01-26 00:56 - 001033216 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2019-02-13 12:42 - 2019-01-26 00:48 - 000809472 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2019-02-13 12:42 - 2019-01-26 00:46 - 015283712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2019-02-13 12:42 - 2019-01-26 00:36 - 000880640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2019-02-13 12:42 - 2019-01-26 00:34 - 004858880 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2019-02-13 12:42 - 2019-01-26 00:34 - 004494336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2019-02-13 12:42 - 2019-01-26 00:31 - 000696320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2019-02-13 12:42 - 2019-01-26 00:29 - 013680640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2019-02-13 12:42 - 2019-01-26 00:22 - 001556480 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2019-02-13 12:42 - 2019-01-26 00:12 - 000800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2019-02-13 12:42 - 2019-01-26 00:11 - 004386304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2019-02-13 12:42 - 2019-01-26 00:08 - 001331200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2019-02-13 12:42 - 2019-01-26 00:06 - 000710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2019-02-13 12:42 - 2019-01-12 02:36 - 000058880 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf3216.dll
2019-02-13 12:42 - 2019-01-12 02:35 - 000044544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf3216.dll
2019-02-13 12:42 - 2019-01-12 02:18 - 000352768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd3x40.dll
2019-02-13 12:42 - 2019-01-09 07:36 - 001901688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2019-02-13 12:42 - 2019-01-09 07:27 - 002533920 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2019-02-13 12:42 - 2019-01-09 07:24 - 007371512 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2019-02-13 12:42 - 2019-01-09 04:34 - 001755136 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2019-02-13 12:42 - 2019-01-09 04:34 - 000134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.NetworkOperators.HotspotAuthentication.dll
2019-02-13 12:42 - 2019-01-09 04:21 - 001493504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2019-02-13 12:42 - 2019-01-09 04:21 - 000102400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.NetworkOperators.HotspotAuthentication.dll
2019-02-13 12:42 - 2019-01-08 05:54 - 000032896 ____C (Microsoft Corporation) C:\WINDOWS\system32\hidparse.sys
2019-02-13 12:42 - 2019-01-08 05:54 - 000032896 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidparse.sys
2019-02-13 12:42 - 2019-01-08 02:22 - 001311744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjet40.dll
2019-02-13 12:42 - 2019-01-08 02:22 - 000313344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd2x40.dll
2019-02-13 12:42 - 2019-01-05 18:48 - 004168704 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2019-02-13 12:42 - 2019-01-05 18:47 - 000684032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2019-02-13 12:42 - 2019-01-05 18:46 - 000243200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys
2019-02-13 12:42 - 2018-12-27 18:57 - 000805376 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2019-02-13 12:42 - 2018-12-27 17:30 - 000626176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2019-02-13 12:42 - 2018-12-08 17:01 - 000513376 _____ C:\WINDOWS\SysWOW64\locale.nls
2019-02-13 12:42 - 2018-12-08 17:01 - 000513376 _____ C:\WINDOWS\system32\locale.nls
2019-02-13 12:42 - 2018-12-02 11:08 - 000179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\itss.dll
2019-02-13 12:42 - 2018-12-01 17:44 - 000151040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\itss.dll
2019-02-13 12:42 - 2018-10-12 14:19 - 000998480 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll
2019-02-12 13:27 - 2019-02-15 14:33 - 000474712 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgSP.sys
2019-02-12 13:27 - 2019-02-12 13:27 - 001034184 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgSnx.sys
2019-02-12 13:27 - 2019-02-12 13:27 - 000380208 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgVmm.sys
2019-02-12 13:27 - 2019-02-12 13:27 - 000362928 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\avgBoot.exe
2019-02-12 13:27 - 2019-02-12 13:27 - 000320960 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgblog.sys
2019-02-12 13:27 - 2019-02-12 13:27 - 000226448 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbidsdriver.sys
2019-02-12 13:27 - 2019-02-12 13:27 - 000217040 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgStm.sys
2019-02-12 13:27 - 2019-02-12 13:27 - 000205656 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgArPot.sys
2019-02-12 13:27 - 2019-02-12 13:27 - 000196848 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbidsh.sys
2019-02-12 13:27 - 2019-02-12 13:27 - 000167560 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgMonFlt.sys
2019-02-12 13:27 - 2019-02-12 13:27 - 000112568 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgRdr2.sys
2019-02-12 13:27 - 2019-02-12 13:27 - 000088208 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgRvrt.sys
2019-02-12 13:27 - 2019-02-12 13:27 - 000058008 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbuniv.sys
2019-02-12 13:27 - 2019-02-12 13:27 - 000042552 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgKbd.sys
2019-02-12 13:27 - 2019-02-12 13:27 - 000003904 _____ C:\WINDOWS\System32\Tasks\Antivirus Emergency Update
2019-02-12 13:27 - 2019-02-12 13:27 - 000000000 ____D C:\Users\Antonio1\AppData\Roaming\AVG
2019-02-12 13:27 - 2019-02-12 13:27 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2019-02-12 13:26 - 2019-02-12 13:26 - 000000000 ____D C:\Program Files\AVG
2019-02-12 13:14 - 2019-02-12 13:24 - 000000000 ____D C:\AVG_Remover
==================== One month (modified) ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2019-03-04 10:44 - 2016-11-20 10:19 - 000000000 ____D C:\Users\Antonio1\AppData\LocalLow\Mozilla
2019-03-04 10:43 - 2015-03-31 21:24 - 000000000 ____D C:\Program Files\JDownloader
2019-03-04 10:02 - 2013-11-14 08:27 - 001740418 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2019-03-04 10:02 - 2013-11-14 08:12 - 000772870 _____ C:\WINDOWS\system32\perfh00A.dat
2019-03-04 10:02 - 2013-11-14 08:12 - 000151708 _____ C:\WINDOWS\system32\perfc00A.dat
2019-03-04 10:02 - 2013-08-22 14:36 - 000000000 ____D C:\WINDOWS\Inf
2019-03-04 10:01 - 2013-03-18 20:44 - 000000000 ____D C:\Users\Antonio1\AppData\Roaming\uTorrent
2019-03-04 10:01 - 2013-02-06 21:57 - 000000000 ____D C:\Users\Antonio1\AppData\Roaming\Media Player Classic
2019-03-04 09:57 - 2014-06-06 16:29 - 000000000 __SHD C:\Users\Antonio1\IntelGraphicsProfiles
2019-03-04 09:57 - 2013-08-22 15:45 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2019-03-04 09:53 - 2019-01-20 22:35 - 000000000 ____D C:\Users\Antonio1\AppData\Roaming\9d5bea8b64a11090a0b46ed648cad278
2019-03-04 04:39 - 2013-02-05 20:11 - 000003600 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2999475868-1411259359-3238297896-1001
2019-03-04 03:19 - 2013-08-22 14:25 - 000262144 ___SH C:\WINDOWS\system32\config\BBI
2019-03-04 03:18 - 2013-03-18 20:44 - 000000000 ____D C:\Program Files (x86)\utorrent
2019-03-04 02:12 - 2013-02-09 13:59 - 000007598 _____ C:\Users\Antonio1\AppData\Local\resmon.resmoncfg
2019-03-03 21:00 - 2018-02-25 19:19 - 000000000 ____D C:\Users\Antonio1\AppData\Roaming\vlc
2019-03-01 21:58 - 2013-03-08 12:54 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2019-03-01 21:58 - 2013-02-06 23:07 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2019-03-01 14:06 - 2013-02-05 20:49 - 000001163 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2019-02-27 16:18 - 2013-02-06 23:09 - 000000000 ____D C:\WINDOWS\System32\Tasks\NCH Software
2019-02-24 14:26 - 2013-02-06 23:41 - 000000000 ____D C:\Users\Antonio1\Desktop\programas
2019-02-24 14:10 - 2013-02-06 23:09 - 000000000 ____D C:\ProgramData\NCH Software
2019-02-24 14:10 - 2013-02-06 23:09 - 000000000 ____D C:\Program Files (x86)\NCH Software
2019-02-24 14:10 - 2013-02-06 23:08 - 000000000 ____D C:\Users\Antonio1\AppData\Roaming\NCH Software
2019-02-23 20:55 - 2013-02-06 22:55 - 000000000 ____D C:\Users\Antonio1\Desktop\docs
2019-02-22 00:46 - 2017-01-11 16:21 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2019-02-21 01:03 - 2013-02-07 00:08 - 000000000 ____D C:\Users\Antonio1\AppData\Roaming\Jaksta Streaming Media Recorder
2019-02-20 13:14 - 2013-08-22 16:36 - 000000000 ____D C:\WINDOWS\system32\NDF
2019-02-18 20:25 - 2013-02-06 23:05 - 000000000 ____D C:\Users\Antonio1\Desktop\emuladores
2019-02-13 15:24 - 2013-08-22 16:36 - 000000000 ____D C:\WINDOWS\rescache
2019-02-13 12:46 - 2018-05-12 11:15 - 000468064 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2019-02-13 12:44 - 2012-07-26 08:59 - 000000000 ____D C:\WINDOWS\CbsTemp
2019-02-13 12:43 - 2013-07-10 09:24 - 000000000 ____D C:\WINDOWS\system32\MRT
2019-02-13 12:42 - 2017-01-21 13:30 - 129330784 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2019-02-12 19:34 - 2017-01-11 16:21 - 000004476 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2019-02-12 19:31 - 2018-03-14 04:00 - 000004496 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player NPAPI Notifier
2019-02-12 19:31 - 2013-08-22 16:36 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2019-02-12 19:31 - 2013-08-22 16:36 - 000000000 ____D C:\WINDOWS\system32\Macromed
2019-02-12 19:31 - 2013-02-06 23:30 - 000004296 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2019-02-12 14:43 - 2013-08-22 16:36 - 000000000 ____D C:\WINDOWS\AppReadiness
2019-02-12 14:25 - 2013-03-27 13:22 - 000000000 ____D C:\Users\Antonio1\AppData\Local\CrashDumps
2019-02-12 13:26 - 2016-07-05 12:20 - 000000000 ____D C:\ProgramData\Avg
2019-02-12 13:22 - 2014-11-19 10:34 - 000000000 ____D C:\Users\Antonio1\AppData\Local\Avg
2019-02-12 13:22 - 2013-02-06 18:13 - 000000000 ____D C:\Program Files (x86)\AVG
2019-02-05 19:41 - 2013-02-06 23:07 - 000000000 ____D C:\ProgramData\Mozilla
2019-02-05 12:14 - 2013-02-08 13:40 - 000000000 ____D C:\Program Files\CCleaner
2019-02-02 21:07 - 2013-08-22 16:38 - 000835480 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2019-02-02 21:07 - 2013-08-22 16:38 - 000179600 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
==================== Files in the root of some directories =======
2013-03-24 12:47 - 2018-11-11 12:30 - 000361022 _____ () C:\Users\Antonio1\AppData\Roaming\VideoPad.dmp
2018-04-25 00:24 - 2018-04-25 00:24 - 000000000 _____ () C:\Users\Antonio1\AppData\Local\D26A82.tmp
2013-04-25 16:51 - 2013-04-25 21:06 - 000005120 _____ () C:\Users\Antonio1\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-02-09 13:59 - 2019-03-04 02:12 - 000007598 _____ () C:\Users\Antonio1\AppData\Local\resmon.resmoncfg
Some files in TEMP:
====================
2019-03-03 20:51 - 2019-03-04 09:57 - 001060864 _____ (AutoIt Team) C:\Users\Antonio1\AppData\Local\Temp\systeminfo.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\dllhost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\dllhost.exe => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2019-03-03 04:07
==================== End of FRST.txt ============================