Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 01-03-2019
Ran by Carlos (administrator) on CARLOS-PC (01-03-2019 23:50:15)
Running from C:\Users\Carlos\Desktop
Loaded Profiles: Carlos (Available Profiles: Carlos)
Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) Language: Español (España, internacional)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Crystal Rich Ltd -> Crystal Rich Ltd) C:\Program Files\USB Safely Remove\USBSRService.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
(Adobe Systems, Incorporated -> Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
(Nero AG -> Nero AG) C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
(TuneUp Software GmbH -> TuneUp Software) C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
(VIA Technologies Inc. -> VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
(Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(TuneUp Software GmbH -> TuneUp Software) C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\Alwil Software\Avast5\aswidsagent.exe
(Crystal Rich Ltd -> Crystal Rich Ltd) C:\Program Files\USB Safely Remove\USBSafelyRemove.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastUI.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Google LLC -> Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office\Office15\WINWORD.EXE
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Google LLC -> Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\Alwil Software\Avast5\AvLaunch.exe [221576 2019-02-17] (AVAST Software s.r.o. -> AVAST Software)
HKLM\...\RunOnce: [MSPCLOCK] => rundll32.exe streamci,StreamingDeviceSetup {97ebaacc-95bd-11d0-a3ea-00a0c9223196},{53172480-4791-11D0-A5D6-28DB04C10000},{53172480-4791-11D0-A5D6-28DB04C10000}
HKLM\...\RunOnce: [MSPQM] => rundll32.exe streamci,StreamingDeviceSetup {DDF4358E-BB2C-11D0-A42F-00A0C9223196},{97EBAACB-95BD-11D0-A3EA-00A0C9223196},{97EBAACB-95BD-11D0-A3EA-00A0C9223196}
HKLM\...\RunOnce: [MSKSSRV] => rundll32.exe streamci,StreamingDeviceSetup {96E080C7-143C-11D1-B40F-00A0C9223196},{3C0D501A-140B-11D1-B40F-00A0C9223196},{3C0D501A-140B-11D1-B40F-00A0C9223196}
HKLM\...\RunOnce: [MSTEE.CxTransform] => rundll32.exe streamci,StreamingDeviceSetup {cfd669f1-9bc2-11d0-8299-0000f822fe8a},{CF1DDA2C-9743-11D0-A3EE-00A0C9223196},{CF1DDA2C-9743-11D0-A3EE-00A0C9223196},C:\Windows\inf\ksfilter.inf,MSTEE.Interf (the data entry has 11 more characters).
HKLM\...\RunOnce: [MSTEE.Splitter] => rundll32.exe streamci,StreamingDeviceSetup {cfd669f1-9bc2-11d0-8299-0000f822fe8a},{0A4252A0-7E70-11D0-A5D6-28DB04C10000},{0A4252A0-7E70-11D0-A5D6-28DB04C10000},C:\Windows\inf\ksfilter.inf,MSTEE.Interf (the data entry has 11 more characters).
HKLM\...\RunOnce: [WDM_DRMKAUD] => C:\Windows\inf\WDMAUDIO.inf [9172 2018-12-08] (Microsoft Windows -> )
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-1985454927-2253292353-2952214705-1000\...\Run: [USB Safely Remove] => C:\Program Files\USB Safely Remove\USBSafelyRemove.exe [6544992 2018-09-08] (Crystal Rich Ltd -> Crystal Rich Ltd)
HKU\S-1-5-21-1985454927-2253292353-2952214705-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Bubbles.scr [878592 2010-11-20] (Microsoft Windows -> Microsoft Corporation)
HKLM\...\Drivers32: [VIDC.FMVC] => C:\Windows\system32\fmcodec.dll [77824 2008-08-18] (Fox Magic Software) [File not signed]
HKLM\...\Drivers32: [vidc.ffds] => C:\Windows\system32\ff_vfw.dll [79360 2012-02-26] () [File not signed]
HKLM\...\Drivers32: [vidc.xvid] => C:\Windows\system32\xvidvfw.dll [240640 2011-05-30] () [File not signed]
HKLM\...\Drivers32: [vidc.lags] => C:\Windows\system32\lagarith.dll [216064 2011-12-07] ( ) [File not signed]
HKLM\...\Drivers32: [msacm.divxa32] => C:\Windows\system32\DivXa32.acm [291408 2000-04-01] (Packed With Joy !) [File not signed]
HKLM\...\Drivers32: [msacm.lameacm] => C:\Windows\system32\LameACM.acm [839680 2008-09-24] (hxxp://www.mp3dev.org/) [File not signed]
HKLM\Software\Microsoft\Active Setup\Installed Components: [{2D46B6DC-2207-486B-B523-A557E6D54B47}] -> C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\72.0.3626.119\Installer\chrmstp.exe [2019-02-25] (Google LLC -> Google Inc.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{A6EADE66-0000-0000-484E-7E8A45000000}] -> C:\Program Files\Adobe\Acrobat Reader DC\Esl\AiodLite.dll [2018-12-04] (Adobe Systems, Incorporated -> Adobe Systems, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{280528F6-FB7D-4438-919B-F51240DA1340}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{3331B6DA-BE1E-443A-A6A2-35D124498494}: [DhcpNameServer] 192.168.42.129
Internet Explorer:
==================
HKU\S-1-5-21-1985454927-2253292353-2952214705-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?ocid=iehp
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2018-10-31] (Microsoft Corporation -> Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_201\bin\ssv.dll [2019-01-23] (Oracle America, Inc. -> Oracle Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2014-01-23] (Microsoft Corporation -> Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2018-07-18] (Microsoft Corporation -> Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_201\bin\jp2ssv.dll [2019-01-23] (Oracle America, Inc. -> Oracle Corporation)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2018-03-14] (Microsoft Corporation -> Microsoft Corporation)
FireFox:
========
FF ProfilePath: C:\Users\Carlos\AppData\Roaming\Mozilla\Firefox\Profiles\pfdir8oe.default [2019-02-23]
FF user.js: detected! => C:\Users\Carlos\AppData\Roaming\Mozilla\Firefox\Profiles\pfdir8oe.default\user.js [2015-08-06]
FF Extension: (Avast SafePrice | Comparaciones, ofertas y cupones) - C:\Users\Carlos\AppData\Roaming\Mozilla\Firefox\Profiles\pfdir8oe.default\Extensions\[email protected] [2019-02-16]
FF Extension: (Avast Online Security) - C:\Users\Carlos\AppData\Roaming\Mozilla\Firefox\Profiles\pfdir8oe.default\Extensions\[email protected] [2019-02-19]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_32_0_0_142.dll [2019-02-12] (Adobe Systems Incorporated -> )
FF Plugin: @java.com/DTPlugin,version=11.201.2 -> C:\Program Files\Java\jre1.8.0_201\bin\dtplugin\npDeployJava1.dll [2019-01-23] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.201.2 -> C:\Program Files\Java\jre1.8.0_201\bin\plugin2\npjp2.dll [2019-01-23] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2018-10-31] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2018-12-17] (Google Inc -> Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2018-12-17] (Google Inc -> Google Inc.)
FF Plugin: @videolan.org/vlc,version=3.0.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2018-08-09] (VideoLAN -> VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-12-04] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.google.com
CHR StartupUrls: Default -> "chrome://newtab/"
CHR Profile: C:\Users\Carlos\AppData\Local\Google\Chrome\User Data\Default [2019-03-01]
CHR Extension: (Documentos) - C:\Users\Carlos\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-11-24]
CHR Extension: (Google Drive) - C:\Users\Carlos\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-07-17]
CHR Extension: (MEGA) - C:\Users\Carlos\AppData\Local\Google\Chrome\User Data\Default\Extensions\bigefpfhnfcobdlfbedofhhaibnlghod [2019-03-01]
CHR Extension: (YouTube) - C:\Users\Carlos\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-11-24]
CHR Extension: (Facebook) - C:\Users\Carlos\AppData\Local\Google\Chrome\User Data\Default\Extensions\boeajhmfdjldchidhphikilcgdacljfm [2014-12-03]
CHR Extension: (Adblock Plus - bloqueador de anuncios gratis) - C:\Users\Carlos\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2019-01-23]
CHR Extension: (Búsqueda de Google) - C:\Users\Carlos\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-03-27]
CHR Extension: (ColorMandala) - C:\Users\Carlos\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbafebdejmcgpbfkppndjeajebpppnei [2014-12-03]
CHR Extension: (Adobe Acrobat) - C:\Users\Carlos\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2018-12-11]
CHR Extension: (Avast Passwords) - C:\Users\Carlos\AppData\Local\Google\Chrome\User Data\Default\Extensions\emhginjpijfggbofeediiojmdlmlkoik [2019-01-10]
CHR Extension: (ZenMate Security, Privacy & Unblock VPN) - C:\Users\Carlos\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdcgdnkidjaadafnichfpabhfomcebme [2015-08-27]
CHR Extension: (Documentos de Google sin conexión) - C:\Users\Carlos\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-11-25]
CHR Extension: (Hola Free VPN Proxy Unblocker) - C:\Users\Carlos\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2019-02-27]
CHR Extension: (Avast Online Security) - C:\Users\Carlos\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2019-02-19]
CHR Extension: (Skype) - C:\Users\Carlos\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2018-11-24]
CHR Extension: (Sistema de pagos de Chrome Web Store) - C:\Users\Carlos\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-11-24]
CHR Extension: (hxxps://login.live.com/login.srf?wa=wsignin1.) - C:\Users\Carlos\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbiaafcnnfdejnhbnkidgacaagpjkcjc [2015-07-09]
CHR Extension: (Outlook.com) - C:\Users\Carlos\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfpeapihoiogbcmdmnibeplnikfnhoge [2014-12-03]
CHR Extension: (Gmail) - C:\Users\Carlos\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-27]
CHR Extension: (Chrome Media Router) - C:\Users\Carlos\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-02-09]
CHR Profile: C:\Users\Carlos\AppData\Local\Google\Chrome\User Data\Guest Profile [2019-02-15]
CHR Profile: C:\Users\Carlos\AppData\Local\Google\Chrome\User Data\Profile 1 [2019-02-15]
CHR Extension: (Documentos) - C:\Users\Carlos\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2019-01-04]
CHR Extension: (Google Drive) - C:\Users\Carlos\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-01-17]
CHR Extension: (YouTube) - C:\Users\Carlos\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-01-04]
CHR Extension: (Búsqueda de Google) - C:\Users\Carlos\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-01-17]
CHR Extension: (Adobe Acrobat) - C:\Users\Carlos\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2019-01-04]
CHR Extension: (Documentos de Google sin conexión) - C:\Users\Carlos\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2019-01-04]
CHR Extension: (Avast Online Security) - C:\Users\Carlos\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gomekmidlodglbbmalcneegieacbdmki [2019-01-04]
CHR Extension: (Skype) - C:\Users\Carlos\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2019-01-04]
CHR Extension: (Sistema de pagos de Chrome Web Store) - C:\Users\Carlos\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-01-04]
CHR Extension: (Gmail) - C:\Users\Carlos\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-01-04]
CHR Extension: (Chrome Media Router) - C:\Users\Carlos\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-01-04]
CHR Profile: C:\Users\Carlos\AppData\Local\Google\Chrome\User Data\System Profile [2019-02-15]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\Alwil Software\Avast5\WebRep\Chrome\aswWebRepChrome.crx <not found>
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-1985454927-2253292353-2952214705-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 aswbIDSAgent; C:\Program Files\Alwil Software\Avast5\aswidsagent.exe [5458712 2019-02-17] (AVAST Software s.r.o. -> AVAST Software)
R2 avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [309480 2019-02-17] (AVAST Software s.r.o. -> AVAST Software)
S2 LiveUpdateSvc; C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe [2909472 2015-07-31] (IObit Information Technology -> IObit)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [5073376 2018-09-19] (Malwarebytes Corporation -> Malwarebytes)
S3 TuneUp.Defrag; C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe [435016 2014-12-03] (TuneUp Software GmbH -> TuneUp Software)
R2 TuneUp.UtilitiesSvc; C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [1044808 2009-12-10] (TuneUp Software GmbH -> TuneUp Software)
R2 USBSafelyRemoveService; C:\Program Files\USB Safely Remove\USBSRService.exe [1176672 2018-09-08] (Crystal Rich Ltd -> Crystal Rich Ltd)
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27768 2012-12-11] (VIA Technologies Inc. -> VIA Technologies, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Windows -> Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 aswArDisk; C:\Windows\System32\drivers\aswArDisk.sys [34488 2019-02-17] (AVAST Software s.r.o. -> AVAST Software)
R1 aswArPot; C:\Windows\System32\drivers\aswArPot.sys [171128 2019-02-17] (AVAST Software s.r.o. -> AVAST Software)
R1 aswbidsdriver; C:\Windows\System32\drivers\aswbidsdriver.sys [188784 2019-02-17] (AVAST Software s.r.o. -> AVAST Software)
R0 aswbidsh; C:\Windows\System32\drivers\aswbidsh.sys [158096 2019-02-17] (AVAST Software s.r.o. -> AVAST Software)
R0 aswblog; C:\Windows\System32\drivers\aswblog.sys [255224 2019-02-17] (AVAST Software s.r.o. -> AVAST Software)
R0 aswbuniv; C:\Windows\System32\drivers\aswbuniv.sys [51128 2019-02-17] (AVAST Software s.r.o. -> AVAST Software)
R1 aswHdsKe; C:\Windows\System32\drivers\aswHdsKe.sys [188712 2019-02-17] (AVAST Software s.r.o. -> AVAST Software)
R1 aswKbd; C:\Windows\System32\drivers\aswKbd.sys [40688 2019-02-17] (AVAST Software s.r.o. -> AVAST Software)
R2 aswMonFlt; C:\Windows\System32\drivers\aswMonFlt.sys [139296 2019-02-17] (AVAST Software s.r.o. -> AVAST Software)
R1 aswRdr; C:\Windows\System32\drivers\aswRdr2.sys [100984 2019-02-17] (AVAST Software s.r.o. -> AVAST Software)
R0 aswRvrt; C:\Windows\System32\drivers\aswRvrt.sys [72800 2019-02-17] (AVAST Software s.r.o. -> AVAST Software)
R1 aswSnx; C:\Windows\System32\drivers\aswSnx.sys [785584 2019-02-17] (AVAST Software s.r.o. -> AVAST Software)
R1 aswSP; C:\Windows\System32\drivers\aswSP.sys [401632 2019-02-17] (AVAST Software s.r.o. -> AVAST Software)
R2 aswStm; C:\Windows\System32\drivers\aswStm.sys [162632 2019-02-17] (AVAST Software s.r.o. -> AVAST Software)
R0 aswVmm; C:\Windows\System32\drivers\aswVmm.sys [310200 2019-02-17] (AVAST Software s.r.o. -> AVAST Software)
S3 dg_ssudbus; C:\Windows\System32\DRIVERS\ssudbus.sys [110088 2018-12-12] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO32.SYS [23840 2015-08-27] (Martin Malik - REALiX -> REALiX(tm))
R3 igfx; C:\Windows\System32\DRIVERS\igdkmd32.sys [9037312 2012-11-13] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
R3 L1C; C:\Windows\System32\DRIVERS\L1C62x86.sys [110280 2013-11-29] (Qualcomm Atheros -> Qualcomm Atheros Co., Ltd.)
S3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv.sys [48280 2014-12-29] (ManyCam LLC -> Visicom Media Inc.)
R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [172280 2019-02-04] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [230120 2019-03-01] (Malwarebytes Corporation -> Malwarebytes)
S3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv.sys [30488 2014-12-28] (ManyCam LLC -> Visicom Media Inc.)
S3 RimUsb; C:\Windows\System32\Drivers\RimUsb.sys [22784 2008-04-16] (Microsoft Windows Hardware Compatibility Publisher -> Research In Motion Limited)
R3 Serenum; C:\Windows\System32\DRIVERS\nuvserenum.sys [17920 2014-01-12] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
R3 Serial; C:\Windows\System32\DRIVERS\nuvserial.sys [76288 2014-01-12] (Microsoft Windows Hardware Compatibility Publisher -> Nuvoton Technology Corp.)
R3 TuneUpUtilitiesDrv; C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [10064 2009-10-14] (TuneUp Software GmbH -> TuneUp Software)
S3 usbrndis6; C:\Windows\System32\DRIVERS\usb80236.sys [15872 2013-02-11] (Microsoft Windows -> Microsoft Corporation)
R3 VIAHdAudAddService; C:\Windows\System32\drivers\viahduaa.sys [565424 2013-12-16] (VIA Technologies Inc. -> VIA Technologies, Inc.)
S1 asrdmon; \SystemRoot\system32\drivers\asrdmon.sys [X]
S3 Movilnet; system32\DRIVERS\movilnetusbser.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2019-03-01 23:50 - 2019-03-01 23:51 - 000022306 _____ C:\Users\Carlos\Desktop\FRST.txt
2019-03-01 23:45 - 2019-03-01 23:50 - 000000000 ____D C:\FRST
2019-03-01 23:10 - 2019-03-01 23:10 - 001801372 _____ C:\Users\Carlos\Desktop\4_5877589700067198606.pdf
2019-03-01 22:42 - 2019-03-01 22:47 - 001793024 _____ (Farbar) C:\Users\Carlos\Desktop\FRST.exe
2019-03-01 21:47 - 2019-03-01 21:47 - 000230120 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2019-02-28 20:24 - 2019-03-01 21:47 - 000000000 ____D C:\Users\Carlos\AppData\Roaming\USBSafelyRemove
2019-02-28 20:24 - 2019-02-28 20:24 - 000001067 _____ C:\Users\Carlos\Desktop\USB Safely Remove.lnk
2019-02-28 20:24 - 2019-02-28 20:24 - 000000000 ____D C:\Users\Carlos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\USB Safely Remove
2019-02-28 20:24 - 2019-02-28 20:24 - 000000000 ____D C:\ProgramData\USBSRService
2019-02-28 20:24 - 2019-02-28 20:24 - 000000000 ____D C:\Program Files\USB Safely Remove
2019-02-26 18:36 - 2019-01-27 10:32 - 000348760 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2019-02-26 18:36 - 2019-01-25 20:27 - 020279808 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2019-02-26 18:36 - 2019-01-25 20:06 - 000498176 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2019-02-26 18:36 - 2019-01-25 20:05 - 000341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2019-02-26 18:36 - 2019-01-25 20:03 - 002295808 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2019-02-26 18:36 - 2019-01-25 19:58 - 000476160 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2019-02-26 18:36 - 2019-01-25 19:57 - 000663040 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2019-02-26 18:36 - 2019-01-25 19:56 - 000620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2019-02-26 18:36 - 2019-01-25 19:48 - 000416256 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2019-02-26 18:36 - 2019-01-25 19:40 - 000168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2019-02-26 18:36 - 2019-01-25 19:40 - 000076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2019-02-26 18:36 - 2019-01-25 19:39 - 000279040 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2019-02-26 18:36 - 2019-01-25 19:37 - 000130048 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2019-02-26 18:36 - 2019-01-25 19:34 - 004494336 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2019-02-26 18:36 - 2019-01-25 19:32 - 000230400 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2019-02-26 18:36 - 2019-01-25 19:31 - 000696320 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2019-02-26 18:36 - 2019-01-25 19:30 - 002060288 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2019-02-26 18:36 - 2019-01-25 19:29 - 013680640 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2019-02-26 18:36 - 2019-01-25 19:29 - 001155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2019-02-26 18:36 - 2019-01-25 19:11 - 004386304 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2019-02-26 18:36 - 2019-01-25 19:08 - 001331200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2019-02-26 18:36 - 2019-01-25 19:06 - 000710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2019-02-26 18:36 - 2019-01-15 02:55 - 000067304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2019-02-26 18:36 - 2019-01-15 02:54 - 000137960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2019-02-26 18:36 - 2019-01-15 02:52 - 001072640 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2019-02-26 18:36 - 2019-01-15 02:52 - 000655360 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2019-02-26 18:36 - 2019-01-15 02:52 - 000554496 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2019-02-26 18:36 - 2019-01-15 02:52 - 000099840 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2019-02-26 18:36 - 2019-01-15 02:52 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2019-02-26 18:36 - 2019-01-15 02:30 - 000126464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2019-02-26 18:36 - 2019-01-15 02:29 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2019-02-26 18:36 - 2019-01-15 02:29 - 000015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2019-02-26 18:36 - 2019-01-11 22:55 - 000044032 _____ (Microsoft Corporation) C:\Windows\system32\mf3216.dll
2019-02-26 18:36 - 2019-01-11 22:55 - 000004608 _____ (Microsoft Corporation) C:\Windows\system32\msimg32.dll
2019-02-26 18:36 - 2019-01-11 22:36 - 001311744 _____ (Microsoft Corporation) C:\Windows\system32\msjet40.dll
2019-02-26 18:36 - 2019-01-11 22:36 - 000352768 _____ (Microsoft Corporation) C:\Windows\system32\msrd3x40.dll
2019-02-26 18:36 - 2019-01-11 22:36 - 000313344 _____ (Microsoft Corporation) C:\Windows\system32\msrd2x40.dll
2019-02-26 18:36 - 2019-01-08 22:58 - 004055784 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2019-02-26 18:36 - 2019-01-08 22:58 - 003960552 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2019-02-26 18:36 - 2019-01-08 22:58 - 000189672 _____ (Microsoft Corporation) C:\Windows\system32\halmacpi.dll
2019-02-26 18:36 - 2019-01-08 22:58 - 000189672 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2019-02-26 18:36 - 2019-01-08 22:58 - 000136424 _____ (Microsoft Corporation) C:\Windows\system32\halacpi.dll
2019-02-26 18:36 - 2019-01-08 22:57 - 001310528 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2019-02-26 18:36 - 2019-01-08 22:55 - 000644096 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2019-02-26 18:36 - 2019-01-08 22:55 - 000167936 _____ (Microsoft Corporation) C:\Windows\system32\srvsvc.dll
2019-02-26 18:36 - 2019-01-08 22:40 - 000026496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2019-02-26 18:36 - 2019-01-08 22:37 - 000009728 _____ (Microsoft Corporation) C:\Windows\system32\sscore.dll
2019-02-26 18:36 - 2019-01-08 22:36 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\videoprt.sys
2019-02-26 18:36 - 2019-01-08 22:34 - 000317440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2019-02-26 18:36 - 2019-01-08 22:34 - 000314368 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2019-02-26 18:36 - 2019-01-08 22:34 - 000117248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2019-02-26 18:36 - 2019-01-08 22:33 - 000069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2019-02-26 18:36 - 2019-01-07 13:15 - 002405376 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2019-02-26 18:36 - 2019-01-01 12:01 - 000105192 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2019-02-26 18:36 - 2019-01-01 11:58 - 002368000 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2019-02-26 18:36 - 2019-01-01 11:39 - 000073216 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe
2019-02-26 18:36 - 2018-12-28 15:48 - 001425920 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2019-02-26 18:36 - 2018-12-28 15:48 - 000582144 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2019-02-26 18:36 - 2018-12-28 15:48 - 000380928 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2019-02-26 18:36 - 2018-12-04 11:55 - 000142848 _____ (Microsoft Corporation) C:\Windows\system32\itss.dll
2019-02-26 18:36 - 2018-12-02 11:55 - 000527872 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2019-02-26 18:35 - 2019-01-25 20:18 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2019-02-26 18:35 - 2019-01-25 20:18 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2019-02-26 18:35 - 2019-01-25 20:06 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2019-02-26 18:35 - 2019-01-25 20:06 - 000047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2019-02-26 18:35 - 2019-01-25 20:05 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2019-02-26 18:35 - 2019-01-25 20:00 - 000047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2019-02-26 18:35 - 2019-01-25 19:59 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2019-02-26 18:35 - 2019-01-25 19:57 - 000104960 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2019-02-26 18:35 - 2019-01-25 19:56 - 000115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2019-02-26 18:35 - 2019-01-25 19:51 - 000668160 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2019-02-26 18:35 - 2019-01-25 19:44 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2019-02-26 18:35 - 2019-01-25 19:43 - 000091136 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2019-02-26 18:35 - 2019-01-25 19:43 - 000073216 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2019-02-26 18:35 - 2019-01-25 19:30 - 000692224 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2019-02-26 18:35 - 2019-01-15 02:52 - 000261120 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2019-02-26 18:35 - 2019-01-15 02:52 - 000254464 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2019-02-26 18:35 - 2019-01-15 02:52 - 000223232 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2019-02-26 18:35 - 2019-01-15 02:52 - 000172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2019-02-26 18:35 - 2019-01-15 02:52 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2019-02-26 18:35 - 2019-01-15 02:52 - 000141312 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2019-02-26 18:35 - 2019-01-15 02:52 - 000070144 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2019-02-26 18:35 - 2019-01-15 02:52 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2019-02-26 18:35 - 2019-01-15 02:52 - 000017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2019-02-26 18:35 - 2019-01-15 02:51 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2019-02-26 18:35 - 2019-01-15 02:51 - 000082432 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2019-02-26 18:35 - 2019-01-15 02:33 - 000050688 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2019-02-26 18:35 - 2019-01-15 02:30 - 000226304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2019-02-26 18:35 - 2019-01-15 02:30 - 000098816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2019-02-26 18:35 - 2019-01-15 02:29 - 000036352 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2019-02-26 18:35 - 2019-01-08 22:55 - 000400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2019-02-26 18:35 - 2019-01-08 22:55 - 000050688 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2019-02-26 18:35 - 2019-01-08 22:55 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2019-02-26 18:35 - 2019-01-08 22:55 - 000043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2019-02-26 18:35 - 2019-01-08 22:55 - 000038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2019-02-26 18:35 - 2019-01-08 22:55 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2019-02-26 18:35 - 2019-01-08 22:40 - 000056320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2019-02-26 18:35 - 2019-01-08 22:40 - 000024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidusb.sys
2019-02-26 18:35 - 2019-01-08 22:37 - 000097792 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2019-02-26 18:35 - 2019-01-08 22:37 - 000050688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2019-02-26 18:35 - 2019-01-08 22:37 - 000029696 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2019-02-26 18:35 - 2019-01-08 22:37 - 000016896 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2019-02-26 18:35 - 2019-01-08 22:35 - 000262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2019-02-26 18:35 - 2019-01-08 22:33 - 000055296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\amdk8.sys
2019-02-26 18:35 - 2019-01-08 22:33 - 000053760 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\intelppm.sys
2019-02-26 18:35 - 2019-01-08 22:33 - 000053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\viac7.sys
2019-02-26 18:35 - 2019-01-08 22:33 - 000052736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\amdppm.sys
2019-02-26 18:35 - 2019-01-08 22:33 - 000052224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\processr.sys
2019-02-26 18:35 - 2019-01-01 11:58 - 000337408 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2019-02-26 18:35 - 2019-01-01 11:58 - 000025088 _____ (Microsoft Corporation) C:\Windows\system32\msimsg.dll
2019-02-26 18:35 - 2019-01-01 11:57 - 001806848 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2019-02-26 18:35 - 2019-01-01 11:57 - 000047104 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2019-02-26 18:35 - 2018-12-28 15:48 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\oleres.dll
2019-02-26 18:35 - 2018-12-28 15:32 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\comcat.dll
2019-02-26 18:35 - 2018-12-04 11:55 - 000158720 _____ (Microsoft Corporation) C:\Windows\system32\itircl.dll
2019-02-23 20:14 - 2019-02-23 22:56 - 000000000 ____D C:\Users\Carlos\AppData\Roaming\.minecraft
2019-02-17 20:38 - 2019-02-17 20:38 - 000002983 _____ C:\Users\Carlos\Desktop\dd_vcredist_x86_20190217203713.log-VISUAL C++2012.txt
2019-02-17 16:22 - 2019-02-17 21:01 - 000000000 ____D C:\Users\Carlos\Desktop\Nueva carpeta
2019-02-17 11:51 - 2019-02-17 11:51 - 000188712 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHdsKe.sys
2019-02-17 11:46 - 2019-02-17 11:45 - 000310664 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2019-02-16 19:45 - 2019-02-16 19:45 - 000045241 _____ C:\Users\Carlos\Desktop\DIOS PERDONÓ A VENEZUELA.pdf
2019-02-15 22:23 - 2019-02-15 22:25 - 000012634 _____ C:\Users\Carlos\Desktop\cc_20190215_222343.reg
2019-02-15 22:16 - 2019-02-15 22:32 - 000000000 ____D C:\Program Files\CCleaner
2019-02-15 22:16 - 2019-02-15 22:16 - 000000969 _____ C:\Users\Public\Desktop\CCleaner.lnk
2019-02-15 22:16 - 2019-02-15 22:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2019-02-13 19:43 - 2019-02-13 19:43 - 000000346 _____ C:\Users\Carlos\Desktop\DelFix.txt
2019-02-13 19:42 - 2019-02-13 19:43 - 000000346 _____ C:\DelFix.txt
2019-02-10 08:42 - 2019-02-10 08:47 - 000000000 ____D C:\Users\Carlos\Desktop\OTRO-CHEQUEO
2019-02-09 14:38 - 2019-02-09 14:39 - 000132255 _____ C:\Users\Carlos\Desktop\WhatsApp Image 2019-02-09 at 14.05.16.jpeg
2019-02-08 22:00 - 2019-02-08 22:00 - 000000000 ____D C:\Users\Carlos\AppData\Local\ESET
2019-02-08 20:19 - 2019-02-08 20:20 - 000000000 ____D C:\Users\Carlos\Desktop\PDF
2019-02-08 20:18 - 2019-02-08 22:23 - 000000000 ____D C:\Users\Carlos\Desktop\NOTAS
2019-02-05 21:06 - 2019-02-05 21:06 - 000000000 ____D C:\Users\Carlos\Desktop\contra web
2019-02-04 20:16 - 2019-02-04 20:16 - 000172280 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
2019-02-04 20:14 - 2019-02-04 20:14 - 000002024 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2019-02-04 20:14 - 2019-02-04 20:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2019-02-04 20:14 - 2018-12-04 08:09 - 000129248 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae.sys
2019-02-04 19:20 - 2019-03-01 22:40 - 000000000 ____D C:\Users\Carlos\Desktop\CHEQUEO PC
2019-02-04 18:11 - 2019-02-04 18:11 - 000000000 ____D C:\Users\Carlos\AppData\Local\mbamtray
2019-02-04 18:11 - 2019-02-04 18:11 - 000000000 ____D C:\Users\Carlos\AppData\Local\mbam
2019-02-04 18:10 - 2019-02-04 18:10 - 000000000 ____D C:\Program Files\Malwarebytes
2019-02-01 23:23 - 2019-02-24 19:18 - 000000000 ___RD C:\Users\Carlos\CARLOS-PC
2019-02-01 23:23 - 2019-02-01 23:23 - 000000528 ____R C:\Users\Carlos\MediaID.bin
==================== One month (modified) ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2019-03-01 22:10 - 2009-07-14 00:34 - 000021072 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2019-03-01 22:10 - 2009-07-14 00:34 - 000021072 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2019-03-01 21:56 - 2015-02-05 22:11 - 005611008 ___SH C:\Users\Carlos\Desktop\Thumbs.db
2019-03-01 21:46 - 2009-07-14 00:53 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2019-02-27 19:03 - 2011-01-22 06:31 - 000751538 _____ C:\Windows\system32\perfh00A.dat
2019-02-27 19:03 - 2011-01-22 06:31 - 000160562 _____ C:\Windows\system32\perfc00A.dat
2019-02-27 19:03 - 2010-11-20 17:01 - 001687570 _____ C:\Windows\system32\PerfStringBackup.INI
2019-02-27 19:03 - 2009-07-13 22:37 - 000000000 ____D C:\Windows\inf
2019-02-27 18:57 - 2009-07-14 00:33 - 000437424 _____ C:\Windows\system32\FNTCACHE.DAT
2019-02-27 18:53 - 2014-12-03 18:11 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2019-02-27 18:52 - 2015-05-15 12:00 - 000000000 ____D C:\Windows\system32\MRT
2019-02-27 18:43 - 2015-05-15 12:00 - 126228304 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2019-02-26 14:09 - 2015-07-19 19:35 - 000000000 ____D C:\ProgramData\ProductData
2019-02-25 17:33 - 2014-12-03 18:59 - 000002168 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2019-02-25 17:33 - 2014-12-03 18:59 - 000002127 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2019-02-24 19:56 - 2014-12-03 16:22 - 000000000 ____D C:\Users\Carlos
2019-02-24 09:02 - 2018-12-02 18:19 - 000000000 ____D C:\Users\Carlos\AppData\Local\AVAST Software
2019-02-23 22:58 - 2018-12-14 22:33 - 000000000 ____D C:\Users\Carlos\AppData\Roaming\vlc
2019-02-23 14:56 - 2018-12-19 19:47 - 000000000 ____D C:\Users\Carlos\AppData\LocalLow\Mozilla
2019-02-21 20:16 - 2018-11-19 20:49 - 000000000 ___HD C:\Users\Carlos\Documents\Youcam
2019-02-20 05:09 - 2018-12-08 21:37 - 000000000 ____D C:\Program Files\Mozilla Firefox
2019-02-20 05:09 - 2014-12-03 17:58 - 000000000 ____D C:\Program Files\Mozilla Maintenance Service
2019-02-19 15:24 - 2014-12-03 17:58 - 000000000 ____D C:\ProgramData\Mozilla
2019-02-18 13:34 - 2019-01-06 11:15 - 000000000 ___HD C:\Users\Carlos\Desktop\Las habilidades curativas de los árboles
2019-02-18 12:07 - 2009-07-14 00:53 - 000032630 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2019-02-17 15:21 - 2014-12-04 10:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2019-02-17 15:21 - 2014-12-03 18:54 - 000000000 ____D C:\Program Files\Java
2019-02-17 14:19 - 2014-12-30 18:39 - 000000000 ____D C:\ProgramData\Apple
2019-02-17 11:52 - 2014-12-03 16:58 - 000401632 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2019-02-17 11:46 - 2018-12-02 16:09 - 000040688 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2019-02-17 11:46 - 2015-04-11 22:17 - 000162632 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2019-02-17 11:46 - 2015-04-11 22:02 - 000100984 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2019-02-17 11:46 - 2015-04-11 22:01 - 000310200 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2019-02-17 11:46 - 2015-04-11 22:01 - 000072800 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2019-02-17 11:46 - 2014-12-03 16:57 - 000139296 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2019-02-17 11:45 - 2019-01-14 14:10 - 000188784 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbidsdriver.sys
2019-02-17 11:45 - 2019-01-06 10:48 - 000255224 _____ (AVAST Software) C:\Windows\system32\Drivers\aswblog.sys
2019-02-17 11:45 - 2019-01-06 10:48 - 000158096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbidsh.sys
2019-02-17 11:45 - 2019-01-06 10:48 - 000051128 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbuniv.sys
2019-02-17 11:45 - 2019-01-06 10:48 - 000034488 _____ (AVAST Software) C:\Windows\system32\Drivers\aswArDisk.sys
2019-02-17 11:45 - 2018-12-02 16:09 - 000171128 _____ (AVAST Software) C:\Windows\system32\Drivers\aswArPot.sys
2019-02-17 11:45 - 2015-04-11 22:01 - 000785584 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2019-02-16 12:14 - 2009-07-13 22:03 - 061341696 _____ C:\Windows\system32\config\SOFTWARE_tureg_old
2019-02-16 12:14 - 2009-07-13 22:03 - 016515072 _____ C:\Windows\system32\config\SYSTEM_tureg_old
2019-02-16 12:14 - 2009-07-13 22:03 - 000262144 _____ C:\Windows\system32\config\SECURITY_tureg_old
2019-02-16 12:10 - 2009-07-13 22:03 - 001835008 _____ C:\Windows\system32\config\DEFAULT_tureg_old
2019-02-16 12:10 - 2009-07-13 22:03 - 000262144 _____ C:\Windows\system32\config\SAM_tureg_old
2019-02-15 22:19 - 2014-12-03 19:01 - 000000000 ____D C:\Users\Carlos\AppData\Roaming\MPC-HC
2019-02-15 22:02 - 2015-04-12 16:39 - 000000191 _____ C:\Users\Carlos\AppData\Roaming\default.rss
2019-02-15 21:17 - 2019-01-27 10:07 - 000000000 ____D C:\Users\Carlos\Desktop\postrac y marcha
2019-02-12 21:57 - 2014-12-03 18:56 - 000842240 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2019-02-12 21:57 - 2014-12-03 18:56 - 000175104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2019-02-12 21:57 - 2014-12-03 18:56 - 000000000 ____D C:\Windows\system32\Macromed
2019-02-11 18:22 - 2015-07-19 19:35 - 000000000 ____D C:\Users\Carlos\AppData\Roaming\IObit
2019-02-11 17:17 - 2015-07-31 23:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 8
2019-02-11 17:17 - 2014-12-03 18:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\aTube Catcher
2019-02-10 10:07 - 2014-12-17 22:22 - 000000000 ____D C:\Users\Carlos\AppData\Local\ElevatedDiagnostics
2019-02-10 08:54 - 2019-01-15 21:32 - 000000000 ____D C:\Users\Carlos\Desktop\FOTOS-VIVERO- YO-JOEL
2019-02-10 08:53 - 2019-01-15 21:26 - 000000000 ____D C:\Users\Carlos\Desktop\FOTOS FLIA
2019-02-09 10:46 - 2015-06-11 19:00 - 000044032 ___SH C:\Users\Carlos\Downloads\Thumbs.db
2019-02-08 23:52 - 2014-12-03 18:48 - 000000000 ____D C:\Windows\AutoKMS
2019-02-08 15:24 - 2009-07-13 22:04 - 000000478 _____ C:\Windows\win.ini
2019-02-05 18:57 - 2019-01-07 20:30 - 000000000 ___HD C:\Users\Carlos\Desktop\visual c++
2019-02-05 18:57 - 2019-01-02 22:15 - 000000000 __RHD C:\Users\Carlos\Documents\MEGAsync
2019-02-04 20:14 - 2015-01-09 21:35 - 000000000 ____D C:\ProgramData\Malwarebytes
2019-02-04 19:00 - 2015-07-19 19:34 - 000000000 ____D C:\ProgramData\IObit
2019-02-04 18:57 - 2015-07-19 19:35 - 000000000 ____D C:\Users\Carlos\AppData\LocalLow\IObit
2019-02-04 18:57 - 2015-07-19 19:35 - 000000000 ____D C:\Program Files\Common Files\IObit
2019-02-04 17:01 - 2009-07-13 22:37 - 000000000 ____D C:\Windows\rescache
2019-02-04 07:54 - 2018-12-10 23:11 - 000035928 _____ C:\url_setting_definitions.txt
2019-02-03 11:48 - 2019-01-21 21:44 - 000000000 ____D C:\Users\Carlos\Desktop\FOTOS CUMPLE-varios
2019-02-01 23:43 - 2019-01-06 15:11 - 000000000 ____D C:\ProgramData\CLSK
2019-02-01 23:34 - 2019-01-21 00:33 - 305486616 _____ C:\Users\Carlos\Downloads\YouCam_8.0.0925.0a_Essential_Essential_YUC180820-01.exe
==================== Files in the root of some directories =======
2015-04-12 16:39 - 2019-02-15 22:02 - 000000191 _____ () C:\Users\Carlos\AppData\Roaming\default.rss
2018-10-02 00:27 - 2018-10-02 00:27 - 000000000 _____ () C:\Users\Carlos\AppData\Roaming\downloads.m3u
2014-12-03 17:09 - 2015-06-18 00:10 - 000087608 _____ () C:\Users\Carlos\AppData\Roaming\inst.exe
2014-12-03 17:09 - 2015-06-18 00:10 - 000007887 _____ () C:\Users\Carlos\AppData\Roaming\pcouffin.cat
2014-12-03 17:09 - 2015-06-18 00:10 - 000001144 _____ () C:\Users\Carlos\AppData\Roaming\pcouffin.inf
2014-12-03 17:10 - 2015-06-18 00:10 - 000000055 _____ () C:\Users\Carlos\AppData\Roaming\pcouffin.log
2014-12-03 17:09 - 2015-06-18 00:10 - 000047360 _____ (VSO Software) C:\Users\Carlos\AppData\Roaming\pcouffin.sys
2014-12-03 17:10 - 2015-06-10 13:37 - 000000664 _____ () C:\Users\Carlos\AppData\Roaming\vso_ts_preview.xml
2018-12-27 13:27 - 2018-12-27 13:27 - 000000000 _____ () C:\Users\Carlos\AppData\Local\{16DCE90F-6D25-4B5A-9514-AA5E6A1D6373}
Some files in TEMP:
====================
2019-02-22 15:18 - 2019-02-22 15:18 - 002411864 _____ ( ) C:\Users\Carlos\AppData\Local\Temp\minecraft_0468639699.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\dllhost.exe => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2019-02-22 19:21
==================== End of FRST.txt ============================