Malwarebytes
www.malwarebytes.com
-Detalles del registro-
Fecha del análisis: 14/3/20
Hora del análisis: 14:47
Archivo de registro: a3ddcdf0-662c-11ea-8519-00306703166e.json
-Información del software-
Versión: 4.1.0.56
Versión de los componentes: 1.0.848
Versión del paquete de actualización: 1.0.20714
Licencia: Gratis
-Información del sistema-
SO: Windows 7 Service Pack 1
CPU: x64
Sistema de archivos: NTFS
Usuario: CamoVlog-PC\CamoVlog
-Resumen del análisis-
Tipo de análisis: Análisis de amenazas
Análisis iniciado por:: Manual
Resultado: Completado
Objetos analizados: 250652
Amenazas detectadas: 2
Amenazas en cuarentena: 2
Tiempo transcurrido: 5 min, 45 seg
-Opciones de análisis-
Memoria: Activado
Inicio: Activado
Sistema de archivos: Activado
Archivo: Activado
Rootkits: Desactivado
Heurística: Activado
PUP: Detectar
PUM: Detectar
-Detalles del análisis-
Proceso: 0
(No hay elementos maliciosos detectados)
Módulo: 0
(No hay elementos maliciosos detectados)
Clave del registro: 0
(No hay elementos maliciosos detectados)
Valor del registro: 2
PUP.Optional.OneSystemCare, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\COMPATIBILITYADAPTER\SIGNATURES|ONE SYSTEM CAREPERIOD.JOB, En cuarentena, 719, 728599, 1.0.20714, , ame,
PUP.Optional.OneSystemCare, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\COMPATIBILITYADAPTER\SIGNATURES|ONE SYSTEM CAREPERIOD.JOB.FP, En cuarentena, 719, 728599, 1.0.20714, , ame,
Datos del registro: 0
(No hay elementos maliciosos detectados)
Secuencia de datos: 0
(No hay elementos maliciosos detectados)
Carpeta: 0
(No hay elementos maliciosos detectados)
Archivo: 0
(No hay elementos maliciosos detectados)
Sector físico: 0
(No hay elementos maliciosos detectados)
WMI: 0
(No hay elementos maliciosos detectados)
(end)
# -------------------------------
# Malwarebytes AdwCleaner 8.0.3.0
# -------------------------------
# Build: 03-03-2020
# Database: 2020-03-02.1 (Local)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 03-14-2020
# Duration: 00:00:02
# OS: Windows 7 Professional
# Cleaned: 0
# Failed: 0
***** [ Services ] *****
No malicious services cleaned.
***** [ Folders ] *****
No malicious folders cleaned.
***** [ Files ] *****
No malicious files cleaned.
***** [ DLL ] *****
No malicious DLLs cleaned.
***** [ WMI ] *****
No malicious WMI cleaned.
***** [ Shortcuts ] *****
No malicious shortcuts cleaned.
***** [ Tasks ] *****
No malicious tasks cleaned.
***** [ Registry ] *****
No malicious registry entries cleaned.
***** [ Chromium (and derivatives) ] *****
No malicious Chromium entries cleaned.
***** [ Chromium URLs ] *****
No malicious Chromium URLs cleaned.
***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries cleaned.
***** [ Firefox URLs ] *****
No malicious Firefox URLs cleaned.
***** [ Hosts File Entries ] *****
No malicious hosts file entries cleaned.
***** [ Preinstalled Software ] *****
No Preinstalled Software cleaned.
*************************
[+] Delete Tracing Keys
[+] Reset Winsock
*************************
AdwCleaner[S00].txt - [1345 octets] - [16/11/2018 15:07:01]
AdwCleaner[C00].txt - [1471 octets] - [16/11/2018 15:09:29]
AdwCleaner[S01].txt - [1417 octets] - [15/05/2019 09:46:49]
AdwCleaner[C01].txt - [1583 octets] - [15/05/2019 09:50:14]
AdwCleaner[S02].txt - [1657 octets] - [14/03/2020 15:04:06]
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C02].txt ##########
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.4 (07.09.2017)
Operating System: Windows 7 Professional x64
Ran by CamoVlog (Administrator) on 14/03/2020 at 15:11:14,10
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
File System: 12
Successfully deleted: C:\Users\CamoVlog\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio (Folder)
Successfully deleted: C:\Users\CamoVlog\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\gkojfkhlekighikafcpjkiklfbnlmeio (Folder)
Successfully deleted: C:\Users\CamoVlog\AppData\Roaming\Mozilla\Firefox\Profiles\kegqctbr.default-1547173959495\extensions\staged (Folder)
Successfully deleted: C:\Users\CamoVlog\Documents\add-in express (Folder)
Successfully deleted: C:\Users\CamoVlog\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3LHHKTSI (Temporary Internet Files Folder)
Successfully deleted: C:\Users\CamoVlog\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OI9E0BKK (Temporary Internet Files Folder)
Successfully deleted: C:\Users\CamoVlog\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X5LOYJE8 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\CamoVlog\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YMW5293F (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3LHHKTSI (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OI9E0BKK (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X5LOYJE8 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YMW5293F (Temporary Internet Files Folder)
Registry: 2
Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} (Registry Key)
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} (Registry Key)
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 14/03/2020 at 15:16:22,45
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Resultado del análisis realizado por Farbar Recovery Scan Tool (FRST) (x64) Versión: 08-03-2020
Ejecutado por CamoVlog (administrador) sobre CAMOVLOG-PC (BIOSTAR Group GF8100 M2+ TE) (14-03-2020 15:26:04)
Ejecutado desde C:\Users\CamoVlog\Desktop
Perfiles cargados: CamoVlog & UpdatusUser (Perfiles disponibles: CamoVlog & UpdatusUser)
Platform: Windows 7 Professional Service Pack 1 (X64) Idioma: Español (España, internacional)
Internet Explorer Versión 11 (Navegador predeterminado: FF)
Modo de Inicio: Normal
Tutorial para Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Procesos (Lista blanca) =================
(Si una entrada es incluida en el fixlist, el proceso será cerrado. El archivo no será movido.)
(Adobe Systems, Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avgnt.exe
(Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avguard.exe
(Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avshadow.exe
(Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\sched.exe
(Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
(Geek Software GmbH -> Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.442\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.442\GoogleCrashHandler64.exe
(Huawei Technologies Co., Ltd. -> ) [Archivo no firmado] C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(NVIDIA Corporation -> ) C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
(NVIDIA Corporation -> ) C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Piriform Software Ltd -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
==================== Registro (Lista blanca) ===================
(Si una entrada es incluida en el fixlist, el elemento del registro será restaurado a su valor predeterminado o será eliminado. El archivo no será movido.)
HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [238512 2020-02-26] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [487048 2019-10-21] (Geek Software GmbH -> Geek Software GmbH)
HKU\S-1-5-21-114870127-2458051889-1227169053-1000\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [22256824 2020-02-28] (Piriform Software Ltd -> Piriform Software Ltd)
HKU\S-1-5-21-114870127-2458051889-1227169053-1000\...\Run: [GUDelayStartup] => C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe [44024 2019-07-07] (Glarysoft LTD -> Glarysoft Ltd)
HKU\S-1-5-21-114870127-2458051889-1227169053-1000\...\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-21-114870127-2458051889-1227169053-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\SysWOW64\RETROS~1.SCR [1122304 2013-04-09] (Andy Fielding ([email protected])) [Archivo no firmado]
HKU\S-1-5-21-114870127-2458051889-1227169053-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [22256824 2020-02-28] (Piriform Software Ltd -> Piriform Software Ltd)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\80.0.3987.132\Installer\chrmstp.exe [2020-03-05] (Google LLC -> Google LLC)
Startup: C:\Users\CamoVlog\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MEGAsync.lnk [2019-07-14]
ShortcutTarget: MEGAsync.lnk -> C:\Users\CamoVlog\AppData\Local\MEGAsync\MEGAsync.exe (Mega Limited -> Mega Limited)
BootExecute: autocheck autochk *
GroupPolicy: Restricción ? <==== ATENCIÓN
==================== Tareas programadas (Lista blanca) ============
(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)
Task: {0859AF08-1444-4ED4-A47A-63BF9223A2F6} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [18233016 2020-02-28] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {13B72605-1A80-4B9E-B8CF-4D4B2A4B6C53} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
Task: {1B4EC751-7FA0-4DAC-B38A-C41295624D99} - System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance => C:\Program Files (x86)\AVG\AVG PC TuneUp\tuscanx.exe
Task: {2D5C01AC-A53E-4E0F-A108-11BB39AFB46E} - System32\Tasks\AdobeAAMUpdater-1.0-CamoVlog-PC-CamoVlog => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe
Task: {37E5835E-BB0F-4FF2-92DA-47FB34636245} - System32\Tasks\MEGA\MEGAsync Update Task S-1-5-21-114870127-2458051889-1227169053-1000 => C:\Users\CamoVlog\AppData\Local\MEGAsync\MEGAupdater.exe [615160 2020-03-02] (Mega Limited -> Mega Limited)
Task: {53F08B00-1517-4B6B-947C-D1B729FCCBE2} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2017-11-23] (Google Inc -> Google Inc.)
Task: {59B94E4B-4BB7-4A90-9CB3-3A2D1D724723} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office16\OLicenseHeartbeat.exe [316632 2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {67ED0661-35C1-4E90-A8CF-C413A9091D4A} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\Office16\msoia.exe [416432 2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {703D704A-ACDD-4639-BA7D-639F5BE131A4} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [686384 2020-02-28] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {944C4603-AE03-44AF-AB50-AC9B9157171A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2017-11-23] (Google Inc -> Google Inc.)
Task: {9BE4940B-3126-4091-964A-DD626AFCF483} - System32\Tasks\Adobe Reader and Acrobat Manager => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
Task: {9F6AE999-037B-4638-BB6D-B379493C1C27} - System32\Tasks\{8FA60A6A-DF3D-4FCD-80A1-3951649CA889} => C:\Windows\system32\pcalua.exe -a C:\Users\CamoVlog\Desktop\15.53_nforce_win7_32bit_international_whql.exe -d C:\Users\CamoVlog\Desktop
Task: {A69A6431-0C05-4881-B6D2-D3A2D4B104AD} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\Office16\msoia.exe [416432 2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {B7E07013-8E60-4C8F-8D1E-DA40919FEBFD} - System32\Tasks\Avira_Antivirus_Systray => C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [2760496 2020-02-18] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
(Si una entrada es incluida en el fixlist, el archivo de tarea (.job) será movido. El archivo que está siendo ejecutado por la tarea no será movido.)
==================== Internet (Lista blanca) ====================
(Si un elemento es incluido en el fixlist, y éste pertenece al registro, será eliminado o restaurado a su valor predeterminado.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{59A07129-2A80-4590-8912-728E3F948B7E}: [DhcpNameServer] 192.168.0.1
Internet Explorer:
==================
HKU\S-1-5-21-114870127-2458051889-1227169053-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/es-co/?ocid=iehp
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office16\URLREDIR.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office16\GROOVEEX.DLL [2017-07-11] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office16\OCHelper.dll [2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office16\URLREDIR.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office16\GROOVEEX.DLL [2017-07-11] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files\Microsoft Office\Office16\MSOSB.DLL [2017-08-15] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2017-08-15] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\Office16\MSOSB.DLL [2017-08-15] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2017-08-15] (Microsoft Corporation -> Microsoft Corporation)
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
FireFox:
========
FF DefaultProfile: kegqctbr.default-1547173959495
FF ProfilePath: C:\Users\CamoVlog\AppData\Roaming\Mozilla\Firefox\Profiles\kegqctbr.default-1547173959495 [2020-03-14]
FF Homepage: Mozilla\Firefox\Profiles\kegqctbr.default-1547173959495 -> www.google.com
FF Notifications: Mozilla\Firefox\Profiles\kegqctbr.default-1547173959495 -> hxxps://www.youtube.com; hxxps://a7.mylivechat.com
FF Extension: (Diccionario español Argentina) - C:\Users\CamoVlog\AppData\Roaming\Mozilla\Firefox\Profiles\kegqctbr.default-1547173959495\Extensions\[email protected] [2019-08-12]
FF Extension: (Tags for YouTube™) - C:\Users\CamoVlog\AppData\Roaming\Mozilla\Firefox\Profiles\kegqctbr.default-1547173959495\Extensions\[email protected] [2019-06-21]
FF Extension: (Magic Actions for YouTube™) - C:\Users\CamoVlog\AppData\Roaming\Mozilla\Firefox\Profiles\kegqctbr.default-1547173959495\Extensions\[email protected] [2019-11-12]
FF Extension: (Español (AR) Language Pack) - C:\Users\CamoVlog\AppData\Roaming\Mozilla\Firefox\Profiles\kegqctbr.default-1547173959495\Extensions\[email protected] [2020-03-13]
FF Extension: (Español (México) Language Pack) - C:\Users\CamoVlog\AppData\Roaming\Mozilla\Firefox\Profiles\kegqctbr.default-1547173959495\Extensions\[email protected] [2020-03-13]
FF Extension: (Video DownloadHelper) - C:\Users\CamoVlog\AppData\Roaming\Mozilla\Firefox\Profiles\kegqctbr.default-1547173959495\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2019-07-08]
FF Extension: (Adblock Plus - bloqueador de anuncios gratis) - C:\Users\CamoVlog\AppData\Roaming\Mozilla\Firefox\Profiles\kegqctbr.default-1547173959495\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2020-02-12]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_27_0_0_187.dll [2017-12-10] (Adobe Systems Incorporated -> )
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2018-06-22] (Adobe Systems Incorporated -> Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_187.dll [2017-12-10] (Adobe Systems Incorporated -> )
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2019-02-18] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2018-06-22] (Adobe Systems Incorporated -> Adobe Systems)
StartMenuInternet: FIREFOX.EXE - firefox.exe
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\CamoVlog\AppData\Local\Google\Chrome\User Data\Default [2020-03-14]
CHR Extension: (Magic Actions for YouTube™) - C:\Users\CamoVlog\AppData\Local\Google\Chrome\User Data\Default\Extensions\abjcfabbhafbcdfjoecdgepllmpfceif [2019-11-25]
CHR Extension: (MEGA) - C:\Users\CamoVlog\AppData\Local\Google\Chrome\User Data\Default\Extensions\bigefpfhnfcobdlfbedofhhaibnlghod [2020-03-13]
CHR Extension: (Unlock Premium Content) - C:\Users\CamoVlog\AppData\Local\Google\Chrome\User Data\Default\Extensions\bjmcpnogioojilaohalakcjniiaekgcp [2020-03-03]
CHR Extension: (Tags for YouTube™) - C:\Users\CamoVlog\AppData\Local\Google\Chrome\User Data\Default\Extensions\dggphokdgjikekfiakjcpidcclbmkfga [2019-03-28]
CHR Extension: (Web for Instagram plus DM) - C:\Users\CamoVlog\AppData\Local\Google\Chrome\User Data\Default\Extensions\dgkhjjcoidmkfegigfdedmafpfemccpk [2019-11-29]
CHR Extension: (ZenMate Free VPN - Mejor VPN para Chrome) - C:\Users\CamoVlog\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdcgdnkidjaadafnichfpabhfomcebme [2020-03-13]
CHR Extension: (AdBlock: el mejor bloqueador de anuncios) - C:\Users\CamoVlog\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2020-03-06]
CHR Extension: (Video DownloadHelper) - C:\Users\CamoVlog\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjnegcaeklhafolokijcfjliaokphfk [2019-06-26]
CHR Extension: (Sistema de pagos de Chrome Web Store) - C:\Users\CamoVlog\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-09-30]
CHR Extension: (Flash-HTML5 for YouTube™) - C:\Users\CamoVlog\AppData\Local\Google\Chrome\User Data\Default\Extensions\omimccinlhlkpjaeaocglgmkbelejlhj [2018-08-19]
CHR Extension: (Chrome Media Router) - C:\Users\CamoVlog\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-03-13]
CHR Profile: C:\Users\CamoVlog\AppData\Local\Google\Chrome\User Data\Guest Profile [2018-11-18]
==================== Servicios (Lista blanca) ===================
(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)
S2 AntiVirMailService; C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe [1208848 2020-02-18] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\Antivirus\sched.exe [483432 2020-02-18] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\Antivirus\avguard.exe [483432 2020-02-18] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe [574952 2020-02-18] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
R2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [631944 2020-02-26] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
S4 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [2330224 2018-07-25] (ESET, spol. s r.o. -> ESET)
R2 ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [625184 2009-04-19] (NVIDIA Corporation -> )
R2 HuaweiHiSuiteService64.exe; C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe [190784 2019-10-31] (Huawei Technologies Co., Ltd. -> ) [Archivo no firmado]
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [6933272 2020-03-14] (Malwarebytes Inc -> Malwarebytes)
R2 nSvcIp; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [207904 2009-04-19] (NVIDIA Corporation -> )
R2 PDF24; C:\Program Files (x86)\PDF24\pdf24.exe [487048 2019-10-21] (Geek Software GmbH -> Geek Software GmbH)
S4 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Windows -> Microsoft Corporation)
===================== Controladores (Lista blanca) ===================
(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)
R3 atikmdag; C:\Windows\System32\DRIVERS\atikmdag.sys [5020672 2009-07-13] (Microsoft Windows -> ATI Technologies Inc.)
R0 avdevprot; C:\Windows\System32\DRIVERS\avdevprot.sys [68152 2019-06-12] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [222696 2020-02-18] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [175808 2019-09-24] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [36072 2019-02-21] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [78600 2018-06-28] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
R0 avusbflt; C:\Windows\System32\Drivers\avusbflt.sys [35376 2019-02-21] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
R1 GUBootStartup; C:\Windows\System32\drivers\GUBootStartup.sys [28936 2018-07-28] (Glarysoft LTD -> Glarysoft Ltd)
S3 HPFXBULK; C:\Windows\System32\drivers\hpfx64bulk.sys [20504 2007-07-16] (Hewlett-Packard Company -> Hewlett Packard)
S3 HWHandSet; C:\Windows\System32\DRIVERS\hw_quusbmdm.sys [226560 2019-10-31] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [116864 2019-10-31] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [214496 2020-03-14] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [248968 2020-03-14] (Malwarebytes Inc -> Malwarebytes)
==================== NetSvcs (Lista blanca) ===================
(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)
==================== Un mes (creado) ===================
(Si una entrada es incluida en el fixlist, el archivo/carpeta será eliminado/a.)
2020-03-14 15:23 - 2020-03-14 15:25 - 000029621 _____ C:\Users\CamoVlog\Desktop\Addition.txt
2020-03-14 15:19 - 2020-03-14 15:27 - 000020628 _____ C:\Users\CamoVlog\Desktop\FRST.txt
2020-03-14 15:16 - 2020-03-14 15:17 - 000002671 _____ C:\Users\CamoVlog\Desktop\JRT.txt
2020-03-14 15:08 - 2020-03-14 15:08 - 000214496 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
2020-03-14 15:07 - 2020-03-14 15:08 - 000001847 _____ C:\Users\CamoVlog\Desktop\AdwCleaner[C02].txt
2020-03-14 15:06 - 2020-03-14 15:06 - 000248968 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2020-03-14 14:54 - 2020-03-14 14:54 - 000001891 _____ C:\Users\CamoVlog\Desktop\MALWAREBYTES.txt
2020-03-14 14:33 - 2020-03-14 14:33 - 000000000 ____D C:\Users\CamoVlog\AppData\Local\cache
2020-03-14 14:32 - 2020-03-14 14:32 - 000001948 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2020-03-14 14:32 - 2020-03-14 14:32 - 000001948 _____ C:\ProgramData\Desktop\Malwarebytes.lnk
2020-03-14 14:32 - 2020-03-14 14:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2020-03-14 14:32 - 2020-03-14 14:31 - 000153312 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae64.sys
2020-03-14 14:23 - 2020-03-14 14:23 - 000000822 _____ C:\Users\Public\Desktop\CCleaner.lnk
2020-03-14 14:23 - 2020-03-14 14:23 - 000000822 _____ C:\ProgramData\Desktop\CCleaner.lnk
2020-03-14 14:21 - 2020-03-14 14:21 - 002279936 _____ (Farbar) C:\Users\CamoVlog\Desktop\FRST64.exe
2020-03-14 14:20 - 2020-03-14 14:20 - 008199856 _____ (Malwarebytes) C:\Users\CamoVlog\Desktop\adwcleaner_8.0.3.exe
2020-03-14 14:20 - 2020-03-14 14:20 - 001790024 _____ (Malwarebytes) C:\Users\CamoVlog\Desktop\JRT.exe
2020-03-14 14:15 - 2020-03-14 14:15 - 022195736 _____ (Piriform Software Ltd) C:\Users\CamoVlog\Desktop\ccsetup564.exe
2020-03-14 14:15 - 2020-03-14 14:15 - 001928352 _____ (Malwarebytes) C:\Users\CamoVlog\Desktop\MBSetup.exe
2020-03-14 01:13 - 2020-03-14 01:13 - 000015270 _____ C:\Users\CamoVlog\Downloads\cc_20200314_011314.reg
2020-03-14 00:45 - 2020-03-14 00:45 - 000000430 __RSH C:\ProgramData\ntuser.pol
2020-03-13 13:42 - 2020-03-13 13:42 - 000000030 _____ C:\Users\CamoVlog\Documents\MAGO.avi.sfl
2020-03-13 13:08 - 2020-03-13 13:42 - 2481251328 _____ C:\Users\CamoVlog\Documents\MAGO.avi
2020-03-13 12:18 - 2020-03-13 14:52 - 1590620482 _____ C:\Users\CamoVlog\Documents\MAGO.mp4
2020-03-12 23:58 - 2020-03-13 22:40 - 000000000 ____D C:\Program Files\Mozilla Firefox
2020-03-10 14:06 - 2020-03-12 15:43 - 000000000 ____D C:\Users\CamoVlog\Desktop\ML PUBLICACIONES
2020-03-09 23:02 - 2020-03-09 23:02 - 000367461 _____ C:\Users\CamoVlog\Downloads\0190ebb66b704423860f67aeb817b7d0.mp4
2020-03-09 22:45 - 2020-03-09 22:45 - 001701494 _____ C:\Users\CamoVlog\Downloads\71751179_500732087430719_2310841927345167068_n.mp4
2020-03-09 00:39 - 2020-03-08 23:52 - 000389188 _____ C:\Users\CamoVlog\Desktop\Instagram.mp4
2020-03-05 22:12 - 2020-03-05 22:12 - 006007425 _____ C:\Users\CamoVlog\Downloads\sept.rar
2020-03-04 22:51 - 2020-03-04 22:51 - 001215706 _____ C:\Users\CamoVlog\Documents\Katherine Mansfield - En Una Pension Alemana.pdf
2020-03-04 12:43 - 2020-03-04 12:43 - 001666770 _____ C:\Users\CamoVlog\Downloads\barcode-qr-code-s-set.zip
2020-02-26 10:25 - 2020-02-26 10:25 - 000000847 _____ C:\Users\CamoVlog\Downloads\detalle.gz
2020-02-25 23:37 - 2020-02-25 23:37 - 000165906 _____ C:\Users\CamoVlog\Downloads\287___5___Marker_I.zip
2020-02-25 23:16 - 2020-02-25 23:16 - 000017916 _____ C:\Users\CamoVlog\Downloads\narcotics-anonymous-vector-logo-49FF9F7AB4-seeklogo.com.zip
2020-02-25 22:35 - 2020-02-25 22:35 - 003559153 _____ C:\Users\CamoVlog\Downloads\sport-poster-template-with-chiaroscuro-photo.zip
2020-02-25 15:35 - 2020-02-25 15:35 - 016985616 _____ C:\Users\CamoVlog\Downloads\celebration-banner-with-gold-balloons-stars.zip
2020-02-25 14:55 - 2020-02-25 14:56 - 004572620 _____ C:\Users\CamoVlog\Downloads\anniversary-emblems-with-happy-birthday-congratulations.zip
2020-02-25 14:32 - 2020-02-25 14:32 - 001172244 _____ C:\Users\CamoVlog\Downloads\anniversary-background-design.zip
2020-02-25 10:38 - 2020-03-04 22:51 - 000000000 ____D C:\Users\CamoVlog\AppData\Roaming\Adobe
2020-02-23 15:08 - 2020-02-23 15:08 - 000075739 _____ C:\Users\CamoVlog\Downloads\dhIMG_Instagram.zip
2020-02-23 14:59 - 2020-02-23 14:59 - 000048122 _____ C:\Users\CamoVlog\Downloads\dhIMG_Twitter (1).zip
2020-02-23 14:59 - 2019-08-14 21:19 - 000071168 _____ (Dale Hay) C:\Users\CamoVlog\Desktop\dhIMG Twitter.exe
2020-02-23 14:56 - 2020-02-23 14:56 - 025960557 _____ C:\Users\CamoVlog\Downloads\TwitterImageDownload (1).zip
2020-02-23 14:51 - 2020-02-23 14:52 - 025960557 _____ C:\Users\CamoVlog\Downloads\TwitterImageDownload.zip
2020-02-21 11:44 - 2020-02-21 11:44 - 001772383 _____ C:\Users\CamoVlog\Downloads\payu-vector-logo-989E67C03F-seeklogo.com.zip
2020-02-20 10:11 - 2020-02-20 10:11 - 001529554 _____ C:\Users\CamoVlog\Downloads\pack-different-palm-trees.zip
2020-02-20 10:07 - 2020-02-20 10:07 - 003242019 _____ C:\Users\CamoVlog\Downloads\conjunto-etiquetas-verano-ola-sol.zip
2020-02-19 18:31 - 2020-02-19 18:31 - 000000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2020-02-19 18:08 - 2020-02-19 18:08 - 002354318 _____ C:\Users\CamoVlog\Downloads\stationery-elements-collection-with-flag-colombia-design.zip
2020-02-19 18:01 - 2020-02-19 18:01 - 002480669 _____ C:\Users\CamoVlog\Downloads\map-columbia-with-landmarks.zip
2020-02-18 12:32 - 2020-02-18 12:32 - 000000000 ____D C:\Users\CamoVlog\AppData\Local\Adobe
2020-02-18 12:32 - 2020-02-18 12:32 - 000000000 ____D C:\ProgramData\Adobe
2020-02-17 11:11 - 2020-02-22 10:09 - 000000000 ____D C:\Users\CamoVlog\Desktop\Japas
2020-02-15 00:25 - 2020-02-15 00:25 - 000048122 _____ C:\Users\CamoVlog\Downloads\dhIMG_Twitter.zip
2020-02-14 23:53 - 2020-02-17 23:16 - 000000000 ____D C:\Users\CamoVlog\Desktop\Blogshop
2020-02-14 23:50 - 2020-02-14 23:50 - 002743910 _____ C:\Users\CamoVlog\Downloads\Blogshop.rar
==================== Un mes (modificado) ==================
(Si una entrada es incluida en el fixlist, el archivo/carpeta será eliminado/a.)
2020-03-14 15:26 - 2018-11-16 22:29 - 000000000 ____D C:\FRST
2020-03-14 15:25 - 2019-05-15 10:07 - 000004128 _____ C:\Windows\system32\Tasks\CCleaner Update
2020-03-14 15:17 - 2017-11-23 17:39 - 000000000 ____D C:\Users\CamoVlog\AppData\LocalLow\Mozilla
2020-03-14 15:12 - 2009-07-13 23:45 - 000035024 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2020-03-14 15:12 - 2009-07-13 23:45 - 000035024 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2020-03-14 15:08 - 2019-07-14 22:45 - 000000000 ___RD C:\Users\CamoVlog\Documents\MEGAsync
2020-03-14 15:05 - 2009-07-14 00:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2020-03-14 14:32 - 2018-01-13 13:58 - 000000000 ____D C:\ProgramData\Malwarebytes
2020-03-14 14:32 - 2009-07-13 22:20 - 000000000 ____D C:\Windows\inf
2020-03-14 00:49 - 2017-11-28 21:46 - 000000000 ____D C:\Users\CamoVlog\AppData\Roaming\MPC-HC
2020-03-14 00:41 - 2009-07-13 22:20 - 000000000 ___HD C:\Windows\system32\GroupPolicy
2020-03-13 22:40 - 2017-11-23 17:39 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2020-03-13 01:06 - 2017-12-16 22:47 - 000000000 ____D C:\Users\CamoVlog\dwhelper
2020-03-12 09:59 - 2017-12-11 00:43 - 000000000 ____D C:\Windows\system32\MRT
2020-03-12 09:58 - 2018-06-29 15:24 - 000000033 _____ C:\Users\CamoVlog\AppData\Roaming\AdobeWLCMCache.dat
2020-03-12 09:42 - 2017-12-11 00:42 - 121542864 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2020-03-11 10:40 - 2018-06-29 14:46 - 000000000 ____D C:\ProgramData\Package Cache
2020-03-11 10:39 - 2018-08-06 22:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2020-03-10 18:11 - 2019-02-02 14:20 - 000000000 ____D C:\Users\CamoVlog\Desktop\Videos Twitter
2020-03-09 08:01 - 2009-07-14 00:08 - 000032630 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2020-03-05 15:23 - 2017-11-23 17:55 - 000002222 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-03-05 10:10 - 2018-08-06 22:40 - 000003292 _____ C:\Windows\system32\Tasks\Avira_Antivirus_Systray
2020-03-04 23:53 - 2019-12-31 13:52 - 014646237 _____ C:\Users\CamoVlog\Documents\Sin título.mp4
2020-03-04 14:37 - 2010-11-21 02:09 - 002935742 _____ C:\Windows\system32\perfh00A.dat
2020-03-04 14:37 - 2010-11-21 02:09 - 000876914 _____ C:\Windows\system32\perfc00A.dat
2020-03-04 14:37 - 2009-07-14 00:13 - 000006208 _____ C:\Windows\system32\PerfStringBackup.INI
2020-03-02 13:01 - 2019-07-14 22:43 - 000000000 ____D C:\Users\CamoVlog\AppData\Local\MEGAsync
2020-02-26 19:07 - 2019-03-13 22:57 - 000000132 _____ C:\Users\CamoVlog\AppData\Roaming\Prefs. de formato PNG de Adobe CS6
2020-02-24 01:46 - 2020-01-22 09:45 - 000000000 ____D C:\Users\CamoVlog\Desktop\Converse Negros
2020-02-18 16:17 - 2019-08-10 14:27 - 000000000 ____D C:\Users\CamoVlog\Documents\Archivos de Outlook
2020-02-18 15:50 - 2018-08-06 22:40 - 000222696 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
==================== Archivos en la raíz de algunos directorios ========
2018-06-29 15:24 - 2020-03-12 09:58 - 000000033 _____ () C:\Users\CamoVlog\AppData\Roaming\AdobeWLCMCache.dat
2019-03-13 22:57 - 2020-02-26 19:07 - 000000132 _____ () C:\Users\CamoVlog\AppData\Roaming\Prefs. de formato PNG de Adobe CS6
2018-09-27 11:04 - 2018-09-27 11:04 - 000000000 _____ () C:\Users\CamoVlog\AppData\Local\oobelibMkey.log
==================== SigCheck ============================
(No existe una corrección automática para los archivos que no pasan la verificación.)
LastRegBack: 2020-03-08 12:01
==================== Final de FRST.txt ========================