Necesito ayuda para que me digáis como poder eliminar un malware en bíos que es indetectada por ninguna herramienta hasta ahora, os explico:
Parece ser que tengo el boot infectado de la bios y cada vez qu instalo limpio windows10 , mi sistema operativo para a estar en modo virtualizado, he deshabilitado muchas aplicaciones y deshabilitado opciones de virtualización desde administrados de dispositivos.
Las herramientas de seguridad utilizadas quedan inutilizadas con el tiempo, utilizando una herramienta antimalware una vez de Comodo , me neutralizó 2 archivos decriptor de la rama ransomware. Pero siempre todas las herramientas de seguridad finalmente me indican que no hay nada o en algún caso he podido neutralizar virus con Eset online Scaner. Siempre en la carpeta appdata\local\temp.
Mi pregunta es la siguiente. Que herramienta de limpieza de bios me recomendais para poder eliminar dicho malware? He usado Tdsskiller y 0, he usado gmer2 y es el único que si me detecta alteraciones pero dado que es un software antiguo pues no me fio mucho.
Otro software de Avast para bios si me detecta pero luego peta con pantallazo azul .
Os paso un informe de Farvar Recovery scan
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 22-12-2019
Ran by lobo (administrator) on LOBO (Acer Aspire 7540) (23-12-2019 22:39:51)
Running from C:\Users\lobo\Downloads
Loaded Profiles: lobo (Available Profiles: lobo)
Platform: Windows 10 Home Version 1909 18363.418 (X64) Language: Español (España, internacional)
Default browser: Edge
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\aswidsagent.exe
(AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\AVGSvc.exe
(AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\AVGUI.exe
(AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\AVGUI.exe
(AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\wsc_proxy.exe
(Google Inc -> Google Inc.) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_11811.1001.18.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SystemSettingsAdminFlows.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.18362.411_none_5f53d2d858cf8961\TiWorker.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atiesrxx.exe
(Piriform Software Ltd -> Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AVGUI.exe] => C:\Program Files\AVG\Antivirus\AvLaunch.exe [316336 2019-12-23] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
HKU\S-1-5-21-2225362386-2777678899-3998696106-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [24552064 2019-10-14] (Piriform Software Ltd -> Piriform Ltd)
HKU\S-1-5-21-2225362386-2777678899-3998696106-1001\...\MountPoints2: {68afd86c-24fa-11ea-8e90-806e6f6e6963} - "D:\setup.exe"
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\79.0.3945.88\Installer\chrmstp.exe [2019-12-23] (Google LLC -> Google LLC)
BootExecute: autocheck autochk * avgBoot.exe /A:"C:" /A:"* STARTUP" /L:"3082" /heur:80 /RA:fix /pup /archives /IA:0 /KBD:1 /dir:"C:\Program Files\AVG\Antivirus"
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0A6449E3-0BA7-48CD-A235-F3DFE6859618} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2019-12-23] (Google Inc -> Google Inc.)
Task: {189A4A56-BDA5-48DD-8EB1-D9F32D2C4E04} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [608384 2019-10-14] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {9F59AB80-B601-4832-A57F-5A1C358F03B0} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2019-12-23] (Google Inc -> Google Inc.)
Task: {C8E822A1-CB01-43A6-B81C-5B23F6E21755} - System32\Tasks\AVG\Overseer => C:\Program Files\Common Files\AVG\Overseer\overseer.exe [1905072 2019-12-23] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
Task: {C8F81FC9-9FBE-4C83-A815-28B525758C62} - System32\Tasks\Antivirus Emergency Update => C:\Program Files\AVG\Antivirus\AvEmUpdate.exe [3981232 2019-12-23] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
Task: {EE4E9724-9CDD-4B33-8B3E-FBE5CD16A5C6} - System32\Tasks\Microsoft\Windows\RetailDemo\CleanupOfflineContent => {61f77d5e-afe9-400b-a5e6-e9e80fc8e601} C:\Windows\System32\RDXTaskFactory.dll [415744 2019-03-19] (Microsoft Windows -> Microsoft Corporation)
Task: {F25B2617-9817-4144-84E8-1E0C3B7531FB} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [18458752 2019-10-14] (Piriform Software Ltd -> Piriform Ltd)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job => C:\Windows\explorer.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\..\Interfaces\{f690ace6-be20-40b6-9a18-99739479f803}: [NameServer] 80.58.61.254,80.58.61.250
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
FireFox:
========
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.35.422\npGoogleUpdate3.dll [2019-12-23] (Google LLC -> Google LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.35.422\npGoogleUpdate3.dll [2019-12-23] (Google LLC -> Google LLC)
Chrome:
=======
CHR StartupUrls: Default -> "hxxp://www.google.com"
CHR Profile: C:\Users\lobo\AppData\Local\Google\Chrome\User Data\Default [2019-12-23]
CHR Extension: (Presentaciones) - C:\Users\lobo\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-12-23]
CHR Extension: (Documentos) - C:\Users\lobo\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-12-23]
CHR Extension: (Google Drive) - C:\Users\lobo\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2019-12-23]
CHR Extension: (Hojas de cálculo) - C:\Users\lobo\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-12-23]
CHR Extension: (Chrome Media Router) - C:\Users\lobo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-12-23]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [238080 2015-01-13] (Microsoft Windows Hardware Compatibility Publisher -> AMD)
R2 AVG Antivirus; C:\Program Files\AVG\Antivirus\AVGSvc.exe [996928 2019-12-23] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
R3 avgbIDSAgent; C:\Program Files\AVG\Antivirus\aswidsagent.exe [6307248 2019-12-23] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
R2 AvgWscReporter; C:\Program Files\AVG\Antivirus\wsc_proxy.exe [110560 2019-12-23] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [6960640 2019-12-23] (Malwarebytes Inc -> Malwarebytes)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [4098056 2019-03-19] (Microsoft Corporation -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [113992 2019-03-19] (Microsoft Corporation -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AgereSoftModem; C:\Windows\system32\DRIVERS\agrsm64.sys [1146880 2019-03-19] (Microsoft Windows -> LSI Corp)
R3 amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [11922944 2015-01-13] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)
R3 amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [359936 2015-01-13] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)
S3 athr; C:\Windows\System32\drivers\athwnx.sys [4233728 2019-03-19] (Microsoft Windows -> Qualcomm Atheros Communications, Inc.)
R0 avgArDisk; C:\Windows\System32\drivers\avgArDisk.sys [37880 2019-12-23] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
R1 avgArPot; C:\Windows\System32\drivers\avgArPot.sys [205600 2019-12-23] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
R1 avgbidsdriver; C:\Windows\System32\drivers\avgbidsdriver.sys [275232 2019-12-23] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
R0 avgbidsh; C:\Windows\System32\drivers\avgbidsh.sys [210328 2019-12-23] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
R0 avgbuniv; C:\Windows\System32\drivers\avgbuniv.sys [65376 2019-12-23] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
R0 avgElam; C:\Windows\System32\drivers\avgElam.sys [16520 2019-12-23] (Microsoft Windows Early Launch Anti-malware Publisher -> AVG Technologies CZ, s.r.o.)
R1 avgKbd; C:\Windows\System32\drivers\avgKbd.sys [43512 2019-12-23] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
R2 avgMonFlt; C:\Windows\System32\drivers\avgMonFlt.sys [171640 2019-12-23] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
R1 avgRdr; C:\Windows\System32\drivers\avgRdr2.sys [111096 2019-12-23] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
R0 avgRvrt; C:\Windows\System32\drivers\avgRvrt.sys [84560 2019-12-23] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
R1 avgSnx; C:\Windows\System32\drivers\avgSnx.sys [848688 2019-12-23] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
R1 avgSP; C:\Windows\System32\drivers\avgSP.sys [461216 2019-12-23] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
R2 avgStm; C:\Windows\System32\drivers\avgStm.sys [236288 2019-12-23] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
R0 avgVmm; C:\Windows\System32\drivers\avgVmm.sys [317304 2019-12-23] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [153312 2019-12-23] (Malwarebytes Corporation -> Malwarebytes)
R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [216544 2019-12-23] (Malwarebytes Inc -> Malwarebytes)
S0 MbamElam; C:\Windows\System32\DRIVERS\MbamElam.sys [20936 2019-12-23] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [224408 2019-12-23] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMProtection; C:\Windows\system32\DRIVERS\mbam.sys [73584 2019-12-23] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [278344 2019-12-23] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMWebProtection; C:\Windows\system32\DRIVERS\mwac.sys [116832 2019-12-23] (Malwarebytes Corporation -> Malwarebytes)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [46472 2019-03-19] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [333784 2019-03-19] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [62432 2019-03-19] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) ===================
(If an entry is included in the fixlist, the file/folder will be moved.)
2019-12-23 22:40 - 2019-12-23 22:40 - 000022919 _____ C:\Users\lobo\Downloads\informefrst.txt
2019-12-23 22:37 - 2019-12-23 22:39 - 000022919 _____ C:\Users\lobo\Downloads\Addition.txt
2019-12-23 22:34 - 2019-12-23 22:41 - 000013056 _____ C:\Users\lobo\Downloads\FRST.txt
2019-12-23 22:34 - 2019-12-23 22:40 - 000000000 ____D C:\FRST
2019-12-23 22:28 - 2019-12-23 22:28 - 024578944 _____ (Piriform Software Ltd) C:\Users\lobo\Downloads\ccsetup563.exe
2019-12-23 22:26 - 2019-12-23 22:30 - 000003936 _____ C:\Windows\system32\Tasks\CCleaner Update
2019-12-23 22:26 - 2019-12-23 22:29 - 000000863 _____ C:\Users\Public\Desktop\CCleaner.lnk
2019-12-23 22:26 - 2019-12-23 22:27 - 000000000 ____D C:\Program Files\CCleaner
2019-12-23 22:26 - 2019-12-23 22:26 - 000002864 _____ C:\Windows\system32\Tasks\CCleanerSkipUAC
2019-12-23 22:26 - 2019-12-23 22:26 - 000002375 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2019-12-23 22:26 - 2019-12-23 22:26 - 000002334 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2019-12-23 22:26 - 2019-12-23 22:26 - 000000000 ____D C:\Users\lobo\AppData\Local\Google
2019-12-23 22:26 - 2019-12-23 22:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2019-12-23 22:25 - 2019-12-23 22:31 - 000003622 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineUA
2019-12-23 22:25 - 2019-12-23 22:31 - 000003498 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineCore
2019-12-23 22:25 - 2019-12-23 22:31 - 000000000 ____D C:\Program Files (x86)\Google
2019-12-23 22:24 - 2019-12-23 22:24 - 000001326 _____ C:\Users\lobo\Desktop\AdwCleaner[S00].txt
2019-12-23 22:23 - 2019-12-23 22:24 - 000000000 ____D C:\AdwCleaner
2019-12-23 22:20 - 2019-12-23 22:20 - 000001536 _____ C:\Users\lobo\Desktop\informemalwarebytes.txt
2019-12-23 22:17 - 2019-12-23 22:20 - 000000000 ____D C:\Users\lobo\AppData\LocalLow\IGDump
2019-12-23 22:17 - 2019-12-23 22:17 - 000224408 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2019-12-23 22:17 - 2019-12-23 22:17 - 000116832 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2019-12-23 22:17 - 2019-12-23 22:17 - 000073584 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2019-12-23 22:15 - 2019-12-23 22:15 - 000278344 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2019-12-23 22:15 - 2019-12-23 22:15 - 000216544 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
2019-12-23 22:15 - 2019-12-23 22:15 - 000153312 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae64.sys
2019-12-23 22:15 - 2019-12-23 22:15 - 000002021 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2019-12-23 22:15 - 2019-12-23 22:15 - 000000000 ____D C:\Users\lobo\AppData\Local\mbamtray
2019-12-23 22:15 - 2019-12-23 22:15 - 000000000 ____D C:\Users\lobo\AppData\Local\mbam
2019-12-23 22:15 - 2019-12-23 22:15 - 000000000 ____D C:\Users\lobo\AppData\Local\cache
2019-12-23 22:15 - 2019-12-23 22:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2019-12-23 22:15 - 2019-12-23 22:15 - 000000000 ____D C:\ProgramData\Malwarebytes
2019-12-23 22:15 - 2019-12-23 22:14 - 000020936 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamElam.sys
2019-12-23 22:14 - 2019-12-23 22:14 - 000000000 ____D C:\Program Files\Malwarebytes
2019-12-23 22:12 - 2019-12-23 22:12 - 008237744 _____ (Malwarebytes) C:\Users\lobo\Downloads\adwcleaner_8.0.1.exe
2019-12-23 22:09 - 2019-12-23 22:09 - 002260480 _____ (Farbar) C:\Users\lobo\Downloads\FRST64.exe
2019-12-23 22:08 - 2019-12-23 22:08 - 025441808 _____ (Piriform Software Ltd) C:\Users\lobo\Downloads\ccsetup562.exe
2019-12-23 22:08 - 2019-12-23 22:08 - 001883976 _____ (Malwarebytes) C:\Users\lobo\Downloads\MBSetup.exe
2019-12-23 21:41 - 2019-12-23 21:41 - 000000000 ____D C:\Users\lobo\AppData\Roaming\Macromedia
2019-12-23 21:31 - 2019-12-23 20:25 - 000355760 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\avgBoot.exe
2019-12-23 20:43 - 2019-12-23 20:43 - 000000214 _____ C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job
2019-12-23 20:41 - 2019-12-23 21:26 - 000000000 ____D C:\Windows\pss
2019-12-23 20:40 - 2019-12-23 22:31 - 000000000 ____D C:\Users\lobo\AppData\Local\CrashDumps
2019-12-23 20:28 - 2019-12-23 20:28 - 000000000 ____D C:\Users\lobo\AppData\Roaming\AVG
2019-12-23 20:28 - 2019-12-23 20:28 - 000000000 ____D C:\Users\lobo\AppData\Local\CEF
2019-12-23 20:28 - 2019-12-23 20:28 - 000000000 ____D C:\Users\lobo\AppData\Local\Avg
2019-12-23 20:27 - 2019-12-23 21:31 - 000002075 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG AntiVirus FREE.lnk
2019-12-23 20:27 - 2019-12-23 21:31 - 000002063 _____ C:\Users\Public\Desktop\AVG AntiVirus FREE.lnk
2019-12-23 20:26 - 2019-12-23 21:31 - 000003992 _____ C:\Windows\system32\Tasks\Antivirus Emergency Update
2019-12-23 20:26 - 2019-12-23 20:26 - 000848688 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgSnx.sys
2019-12-23 20:26 - 2019-12-23 20:26 - 000461216 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgSP.sys
2019-12-23 20:26 - 2019-12-23 20:26 - 000171640 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgMonFlt.sys
2019-12-23 20:26 - 2019-12-23 20:26 - 000000000 ____D C:\Windows\system32\Tasks\AVG
2019-12-23 20:26 - 2019-12-23 20:26 - 000000000 ____D C:\Program Files\Common Files\AVG
2019-12-23 20:26 - 2019-12-23 20:25 - 000317304 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgVmm.sys
2019-12-23 20:26 - 2019-12-23 20:25 - 000275232 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgbidsdriver.sys
2019-12-23 20:26 - 2019-12-23 20:25 - 000236288 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgStm.sys
2019-12-23 20:26 - 2019-12-23 20:25 - 000210328 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgbidsh.sys
2019-12-23 20:26 - 2019-12-23 20:25 - 000205600 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgArPot.sys
2019-12-23 20:26 - 2019-12-23 20:25 - 000111096 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgRdr2.sys
2019-12-23 20:26 - 2019-12-23 20:25 - 000084560 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgRvrt.sys
2019-12-23 20:26 - 2019-12-23 20:25 - 000065376 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgbuniv.sys
2019-12-23 20:26 - 2019-12-23 20:25 - 000043512 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgKbd.sys
2019-12-23 20:26 - 2019-12-23 20:25 - 000037880 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgArDisk.sys
2019-12-23 20:26 - 2019-12-23 20:25 - 000016520 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgElam.sys
2019-12-23 20:25 - 2019-12-23 20:25 - 000000000 ____D C:\Program Files\AVG
2019-12-23 20:24 - 2019-12-23 20:26 - 000000000 ____D C:\ProgramData\AVG
2019-12-23 19:44 - 2019-12-23 19:45 - 000000378 _____ C:\DelFix.txt
2019-12-23 19:43 - 2019-12-23 19:43 - 000000000 ___HD C:\Users\lobo\MicrosoftEdgeBackups
2019-12-23 19:34 - 2019-12-23 19:50 - 000000000 ____D C:\Users\lobo\AppData\Local\PlaceholderTileLogoFolder
2019-12-23 19:34 - 2019-12-23 19:34 - 000000000 _____ C:\Windows\ativpsrm.bin
2019-12-22 22:11 - 2019-12-22 22:11 - 000000000 ____D C:\Users\lobo\AppData\Local\Comms
2019-12-22 22:04 - 2019-12-22 22:11 - 000000000 ____D C:\ProgramData\Packages
2019-12-22 22:03 - 2019-12-22 22:03 - 000000000 ____D C:\Users\lobo\AppData\Local\OneDrive
2019-12-22 22:00 - 2019-12-22 22:00 - 000000000 ___RD C:\Users\lobo\OneDrive
2019-12-22 21:57 - 2019-12-22 21:57 - 000001450 _____ C:\Users\lobo\Desktop\Microsoft Edge.lnk
2019-12-22 21:57 - 2019-12-22 21:57 - 000000000 ____D C:\Users\lobo\AppData\Local\MicrosoftEdge
2019-12-22 21:57 - 2019-12-22 21:57 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2019-12-22 21:56 - 2019-12-22 21:56 - 000000000 ____D C:\Users\lobo\AppData\Local\Publishers
2019-12-22 21:55 - 2019-12-23 19:38 - 000000000 ____D C:\Users\lobo\AppData\Local\Packages
2019-12-22 21:55 - 2019-12-22 21:55 - 000000000 __RHD C:\Users\Public\AccountPictures
2019-12-22 21:55 - 2019-12-22 21:55 - 000000000 ___RD C:\Users\lobo\3D Objects
2019-12-22 21:55 - 2019-12-22 21:55 - 000000000 ____D C:\Users\lobo\AppData\Roaming\Adobe
2019-12-22 21:55 - 2019-12-22 21:55 - 000000000 ____D C:\Users\lobo\AppData\Local\VirtualStore
2019-12-22 21:55 - 2019-12-22 21:55 - 000000000 ____D C:\Users\lobo\AppData\Local\ConnectedDevicesPlatform
2019-12-22 21:54 - 2019-12-23 19:43 - 000000000 ____D C:\Users\lobo
2019-12-22 21:54 - 2019-12-22 21:54 - 000000020 ___SH C:\Users\lobo\ntuser.ini
2019-12-22 21:54 - 2019-12-22 21:54 - 000000000 _SHDL C:\Users\lobo\Reciente
2019-12-22 21:54 - 2019-12-22 21:54 - 000000000 _SHDL C:\Users\lobo\Plantillas
2019-12-22 21:54 - 2019-12-22 21:54 - 000000000 _SHDL C:\Users\lobo\Mis documentos
2019-12-22 21:54 - 2019-12-22 21:54 - 000000000 _SHDL C:\Users\lobo\Menú Inicio
2019-12-22 21:54 - 2019-12-22 21:54 - 000000000 _SHDL C:\Users\lobo\Impresoras
2019-12-22 21:54 - 2019-12-22 21:54 - 000000000 _SHDL C:\Users\lobo\Entorno de red
2019-12-22 21:54 - 2019-12-22 21:54 - 000000000 _SHDL C:\Users\lobo\Documents\Mis vídeos
2019-12-22 21:54 - 2019-12-22 21:54 - 000000000 _SHDL C:\Users\lobo\Documents\Mis imágenes
2019-12-22 21:54 - 2019-12-22 21:54 - 000000000 _SHDL C:\Users\lobo\Documents\Mi música
2019-12-22 21:54 - 2019-12-22 21:54 - 000000000 _SHDL C:\Users\lobo\Datos de programa
2019-12-22 21:54 - 2019-12-22 21:54 - 000000000 _SHDL C:\Users\lobo\Configuración local
2019-12-22 21:54 - 2019-12-22 21:54 - 000000000 _SHDL C:\Users\lobo\AppData\Roaming\Microsoft\Windows\Start Menu\Programas
2019-12-22 21:54 - 2019-12-22 21:54 - 000000000 _SHDL C:\Users\lobo\AppData\Local\Historial
2019-12-22 21:54 - 2019-12-22 21:54 - 000000000 _SHDL C:\Users\lobo\AppData\Local\Datos de programa
2019-12-22 21:54 - 2019-12-22 21:54 - 000000000 _SHDL C:\Users\lobo\AppData\Local\Archivos temporales de Internet
2019-12-22 21:48 - 2019-12-23 21:32 - 001684176 _____ C:\Windows\system32\PerfStringBackup.INI
2019-12-22 21:47 - 2019-12-22 21:47 - 000000000 ____D C:\Windows\minidump
2019-12-22 21:43 - 2019-12-22 21:43 - 000000000 _SHDL C:\Users\Public\Documents\Mis vídeos
2019-12-22 21:43 - 2019-12-22 21:43 - 000000000 _SHDL C:\Users\Public\Documents\Mis imágenes
2019-12-22 21:43 - 2019-12-22 21:43 - 000000000 _SHDL C:\Users\Public\Documents\Mi música
2019-12-22 21:43 - 2019-12-22 21:43 - 000000000 _SHDL C:\Users\Default\Reciente
2019-12-22 21:43 - 2019-12-22 21:43 - 000000000 _SHDL C:\Users\Default\Plantillas
2019-12-22 21:43 - 2019-12-22 21:43 - 000000000 _SHDL C:\Users\Default\Mis documentos
2019-12-22 21:43 - 2019-12-22 21:43 - 000000000 _SHDL C:\Users\Default\Menú Inicio
2019-12-22 21:43 - 2019-12-22 21:43 - 000000000 _SHDL C:\Users\Default\Impresoras
2019-12-22 21:43 - 2019-12-22 21:43 - 000000000 _SHDL C:\Users\Default\Entorno de red
2019-12-22 21:43 - 2019-12-22 21:43 - 000000000 _SHDL C:\Users\Default\Documents\Mis vídeos
2019-12-22 21:43 - 2019-12-22 21:43 - 000000000 _SHDL C:\Users\Default\Documents\Mis imágenes
2019-12-22 21:43 - 2019-12-22 21:43 - 000000000 _SHDL C:\Users\Default\Documents\Mi música
2019-12-22 21:43 - 2019-12-22 21:43 - 000000000 _SHDL C:\Users\Default\Datos de programa
2019-12-22 21:43 - 2019-12-22 21:43 - 000000000 _SHDL C:\Users\Default\Configuración local
2019-12-22 21:43 - 2019-12-22 21:43 - 000000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programas
2019-12-22 21:43 - 2019-12-22 21:43 - 000000000 _SHDL C:\Users\Default\AppData\Local\Historial
2019-12-22 21:43 - 2019-12-22 21:43 - 000000000 _SHDL C:\Users\Default\AppData\Local\Datos de programa
2019-12-22 21:43 - 2019-12-22 21:43 - 000000000 _SHDL C:\Users\Default\AppData\Local\Archivos temporales de Internet
2019-12-22 21:43 - 2019-12-22 21:43 - 000000000 _SHDL C:\Users\Default User\Reciente
2019-12-22 21:43 - 2019-12-22 21:43 - 000000000 _SHDL C:\Users\Default User\Plantillas
2019-12-22 21:43 - 2019-12-22 21:43 - 000000000 _SHDL C:\Users\Default User\Mis documentos
2019-12-22 21:43 - 2019-12-22 21:43 - 000000000 _SHDL C:\Users\Default User\Menú Inicio
2019-12-22 21:43 - 2019-12-22 21:43 - 000000000 _SHDL C:\Users\Default User\Impresoras
2019-12-22 21:43 - 2019-12-22 21:43 - 000000000 _SHDL C:\Users\Default User\Entorno de red
2019-12-22 21:43 - 2019-12-22 21:43 - 000000000 _SHDL C:\Users\Default User\Documents\Mis vídeos
2019-12-22 21:43 - 2019-12-22 21:43 - 000000000 _SHDL C:\Users\Default User\Documents\Mis imágenes
2019-12-22 21:43 - 2019-12-22 21:43 - 000000000 _SHDL C:\Users\Default User\Documents\Mi música
2019-12-22 21:43 - 2019-12-22 21:43 - 000000000 _SHDL C:\Users\Default User\Datos de programa
2019-12-22 21:43 - 2019-12-22 21:43 - 000000000 _SHDL C:\Users\Default User\Configuración local
2019-12-22 21:43 - 2019-12-22 21:43 - 000000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programas
2019-12-22 21:43 - 2019-12-22 21:43 - 000000000 _SHDL C:\Users\Default User\AppData\Local\Historial
2019-12-22 21:43 - 2019-12-22 21:43 - 000000000 _SHDL C:\Users\Default User\AppData\Local\Datos de programa
2019-12-22 21:43 - 2019-12-22 21:43 - 000000000 _SHDL C:\Users\Default User\AppData\Local\Archivos temporales de Internet
2019-12-22 21:43 - 2019-12-22 21:43 - 000000000 _SHDL C:\ProgramData\Plantillas
2019-12-22 21:43 - 2019-12-22 21:43 - 000000000 _SHDL C:\ProgramData\Microsoft\Windows\Start Menu\Programas
2019-12-22 21:43 - 2019-12-22 21:43 - 000000000 _SHDL C:\ProgramData\Menú Inicio
2019-12-22 21:43 - 2019-12-22 21:43 - 000000000 _SHDL C:\ProgramData\Escritorio
2019-12-22 21:43 - 2019-12-22 21:43 - 000000000 _SHDL C:\ProgramData\Documentos
2019-12-22 21:43 - 2019-12-22 21:43 - 000000000 _SHDL C:\ProgramData\Datos de programa
2019-12-22 21:43 - 2019-12-22 21:43 - 000000000 _SHDL C:\Program Files\Archivos comunes
2019-12-22 21:43 - 2019-12-22 21:43 - 000000000 _SHDL C:\Documents and Settings
2019-12-22 21:43 - 2019-12-22 21:43 - 000000000 _SHDL C:\Archivos de programa
2019-12-22 21:37 - 2019-10-07 03:55 - 002874368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2019-12-22 21:35 - 2019-12-23 21:27 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2019-12-22 21:35 - 2019-12-22 21:35 - 000000000 ____D C:\Windows\system32\Drivers\wd
2019-12-22 21:34 - 2019-12-22 21:35 - 000000000 ____D C:\Windows\system32\SleepStudy
2019-12-22 21:34 - 2019-12-22 21:34 - 000258152 _____ C:\Windows\system32\FNTCACHE.DAT
2019-12-22 21:34 - 2019-12-22 21:34 - 000000000 ____D C:\Windows\ServiceProfiles
2019-12-22 21:33 - 2019-12-23 22:31 - 000000000 ____D C:\Windows\Panther
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2019-12-23 22:31 - 2019-03-19 05:50 - 000000000 ____D C:\Windows\INF
2019-12-23 22:21 - 2019-03-19 05:52 - 000000000 ____D C:\Windows\system32\WinBioPlugIns
2019-12-23 22:21 - 2019-03-19 05:37 - 000000000 ____D C:\Windows\CbsTemp
2019-12-23 22:15 - 2019-03-19 05:52 - 000000000 ___HD C:\Windows\ELAMBKUP
2019-12-23 21:44 - 2019-03-19 05:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2019-12-23 21:32 - 2019-03-19 12:59 - 000752322 _____ C:\Windows\system32\perfh00A.dat
2019-12-23 21:32 - 2019-03-19 12:59 - 000147902 _____ C:\Windows\system32\perfc00A.dat
2019-12-23 21:26 - 2019-03-19 05:37 - 000524288 _____ C:\Windows\system32\config\BBI
2019-12-23 19:56 - 2019-03-19 05:52 - 000000000 ____D C:\Windows\AppReadiness
2019-12-23 19:51 - 2019-03-19 05:52 - 000000000 ___HD C:\Program Files\WindowsApps
2019-12-23 18:55 - 2019-03-19 05:52 - 000000000 ____D C:\ProgramData\USOPrivate
2019-12-22 22:06 - 2019-03-19 05:52 - 000000000 ____D C:\Windows\SystemResources
2019-12-22 22:06 - 2019-03-19 05:52 - 000000000 ____D C:\Windows\system32\spool
2019-12-22 22:06 - 2019-03-19 05:52 - 000000000 ____D C:\Windows\system32\setup
2019-12-22 22:06 - 2019-03-19 05:52 - 000000000 ____D C:\Windows\ServiceState
2019-12-22 22:06 - 2019-03-19 05:52 - 000000000 ____D C:\Windows\PolicyDefinitions
2019-12-22 21:54 - 2019-03-19 05:52 - 000000000 ____D C:\Windows\system32\WinBioDatabase
2019-12-22 21:43 - 2019-03-19 05:52 - 000000000 ____D C:\Program Files\Windows NT
2019-12-22 21:37 - 2019-03-19 05:52 - 000000000 ___RD C:\Windows\PrintDialog
2019-12-22 21:37 - 2019-03-19 05:52 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2019-12-22 21:36 - 2019-03-19 05:52 - 000000000 ____D C:\Windows\appcompat
2019-12-22 21:36 - 2019-03-19 05:37 - 000032768 _____ C:\Windows\system32\config\ELAM
2019-12-22 21:33 - 2019-03-19 05:49 - 000028672 _____ C:\Windows\system32\config\BCD-Template
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================