Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 25-11-2019 01
Ran by Core 2 duo (administrator) on DESKTOP-62I3FUH (28-11-2019 18:37:26)
Running from C:\Users\Core 2 duo\Desktop
Loaded Profiles: Core 2 duo (Available Profiles: defaultuser0 & Core 2 duo)
Platform: Windows 10 Enterprise 2016 LTSB Version 1607 (X64) Language: Español (España, internacional)
Default browser: FF
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
() [File not signed] C:\Program Files (x86)\RocketDock\RocketDock.exe
(Adobe Systems, Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Advanced Micro Devices Inc.) [File not signed] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) [File not signed] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(ATI Technologies, Inc -> ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(ATI Technologies, Inc -> ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(Hewlett-Packard Company -> Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Ivaylo Beltchev -> IvoSoft) [File not signed] C:\Program Files\Classic Shell\ClassicStartMenu.exe
(Microsoft Corporation) [File not signed] C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Plex, Inc -> Plex, Inc.) C:\Program Files (x86)\Plex\Plex Media Server\Plex Update Service.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [163640 2017-08-13] (Ivaylo Beltchev -> IvoSoft) [File not signed]
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [18388928 2018-05-04] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [61440 2010-02-10] (Advanced Micro Devices, Inc.) [File not signed]
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard Company -> Hewlett-Packard)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [645648 2019-10-05] (Oracle America, Inc. -> Oracle Corporation)
HKLM-x32\...\Run: [Baidu Antivirus] => "C:\Program Files (x86)\Baidu Security\Baidu Antivirus\5.4.3.147185.0\BavTray.exe" -auto
HKLM\...\Policies\Explorer: [SettingsPageVisibility] hide:gaming-broadcasting;gaming-gamebar;gaming-gamedvr;gaming-gamemode;gaming-trueplay;gaming-xboxnetworking;maps;pen;recovery;speech;tabletmode;windowsdefender;windowsinsider
HKU\S-1-5-21-793460650-1082067395-1000565632-1001\...\Run: [RocketDock] => C:\Program Files (x86)\RocketDock\RocketDock.exe [495616 2007-09-02] () [File not signed]
HKU\S-1-5-18\...\Run: [Plex Media Server] => C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe [24869352 2019-06-28] (Plex, Inc -> Plex, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Welcome.lnk [2017-11-09]
ShortcutTarget: Welcome.lnk -> C:\Welcome\Welcome.exe () [File not signed]
Startup: C:\Users\Core 2 duo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sidebar662.lnk [2019-11-28]
ShortcutTarget: Sidebar662.lnk -> C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) [File not signed]
Startup: C:\Users\Core 2 duo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Supervisar alertas de tinta - HP ENVY 4500 series.lnk [2019-11-28]
ShortcutAndArgument: Supervisar alertas de tinta - HP ENVY 4500 series.lnk -> C:\Windows\system32\RunDll32.exe => "C:\Program Files\HP\HP ENVY 4500 series\bin\HPStatusBL.dll",RunDLLEntry SERIALNUMBER=CN53H221HJ060F;CONNECTION=USB;MONITOR=1;
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {01795000-5B9E-4D32-A575-159B4938508A} - System32\Tasks\HPCustParticipation HP ENVY 4500 series => C:\Program Files\HP\HP ENVY 4500 series\Bin\HPCustPartic.exe [5745672 2014-07-21] (Hewlett Packard -> Hewlett-Packard Development Company, LP)
Task: {0F9B572B-F328-407E-9BB1-BB723B05012E} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [375416 2012-10-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {16DEA092-FB0C-40D0-AE20-0536BECC21D9} - System32\Tasks\Microsoft\Windows\EDP\EDP App Launch Task => {35EF4182-F900-4632-B072-8639E4478A61}
Task: {1B65DD58-D16B-45E8-BEB4-94D7E4D64DF7} - System32\Tasks\Microsoft\Windows\EDP\EDP Auth Task => {35EF4182-F900-4632-B072-8639E4478A61}
Task: {1BCDB4BD-7AD3-4E67-85C0-61F100D7718D} - System32\Tasks\060184C3-9766-46a0-B258-F4518A0B2633 => C:\Windows\system32\CScript.exe "C:\ProgramData\Baidu Security\Duplicaterecord.js"
Task: {1E89733F-A4C0-47B9-83B4-8487BA5C6D55} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [608384 2019-10-14] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {4F65979C-3296-41F0-8163-FA972A47A276} - System32\Tasks\AutoPico Daily Restart => C:\Program Files\KMSpico\AutoPico.exe
Task: {676E0A73-BC47-4DE0-B9D4-85118816C2D5} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [1642672 2012-10-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {6B22DFE2-D005-4200-A225-C05BB5CB6FEA} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [375416 2012-10-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {81F8D840-9F75-4885-9880-AA638DB0D8BF} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\Windows\SysWoW64\Macromed\Flash\FlashUtil32_32_0_0_293_Plugin.exe [1457720 2019-11-13] (Adobe Inc. -> Adobe)
Task: {8A22C4BA-0816-4DF4-B67E-57E2B348A200} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [18458752 2019-10-14] (Piriform Software Ltd -> Piriform Ltd)
Task: {93BCA715-4DF2-4C17-9600-BB648A67FB88} - System32\Tasks\Microsoft\Windows\ErrorDetails\EnableErrorDetailsUpdate => {FE285C8C-5360-41C1-A700-045501C740DE} C:\Windows\System32\ErrorDetailsUpdate.dll [72704 2016-07-16] (Microsoft Windows -> Microsoft Corporation)
Task: {EB524607-9629-441C-A41E-D4F9B5262537} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWoW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2019-11-13] (Adobe Inc. -> Adobe)
Task: {EEA11AE2-2E36-401A-85A1-FBB532C73088} - System32\Tasks\Microsoft\Windows\ErrorDetails\ErrorDetailsUpdate => {9CDA66BE-3271-4723-8D35-DD834C58AD92} C:\Windows\System32\ErrorDetailsUpdate.dll [72704 2016-07-16] (Microsoft Windows -> Microsoft Corporation)
Task: {FABCE7CC-AE7E-418D-AC78-12EB16028359} - System32\Tasks\Microsoft Office 15 Sync Maintenance for DESKTOP-62I3FUH-Core 2 duo DESKTOP-62I3FUH => C:\Program Files\Microsoft Office\Office15\MsoSync.exe [469640 2012-10-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {FD05758A-94CC-47DE-8247-A4FA9B2908C4} - System32\Tasks\DriverEasy Scheduled Scan => C:\Program Files\Easeware\DriverEasy\DriverEasy.exe
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\DriverEasy Scheduled Scan.job => C:\Program Files\Easeware\DriverEasy\DriverEasy.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 80.58.61.250 80.58.61.254
Tcpip\..\Interfaces\{72d85931-d2c8-4899-a78a-7e0d319854c0}: [DhcpNameServer] 212.166.211.4 62.81.16.164
Tcpip\..\Interfaces\{a327b524-86ed-4b15-916e-5de61f12ff61}: [DhcpNameServer] 80.58.61.250 80.58.61.254
Tcpip\..\Interfaces\{bc6103c1-46b4-4381-8674-9cb3e4f607bc}: [DhcpNameServer] 212.166.211.4 62.81.16.164
Internet Explorer:
==================
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.facebook.com/groups/windowsminios
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.facebook.com/groups/windowsminios
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.facebook.com/groups/windowsminios
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2012-10-01] (Microsoft Corporation -> Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation -> Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2012-10-01] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_231\bin\ssv.dll [2019-10-30] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_231\bin\jp2ssv.dll [2019-10-30] (Oracle America, Inc. -> Oracle Corporation)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2012-10-01] (Microsoft Corporation -> Microsoft Corporation)
FireFox:
========
FF DefaultProfile: azv8rvwh.default
FF ProfilePath: C:\Users\Core 2 duo\AppData\Roaming\Mozilla\Firefox\Profiles\azv8rvwh.default [2019-11-28]
FF Homepage: Mozilla\Firefox\Profiles\azv8rvwh.default -> hxxp://www.google.es/
FF Extension: (Avast SafePrice | Comparaciones, ofertas y cupones) - C:\Users\Core 2 duo\AppData\Roaming\Mozilla\Firefox\Profiles\azv8rvwh.default\Extensions\[email protected] [2019-11-27]
FF Extension: (Avast Online Security) - C:\Users\Core 2 duo\AppData\Roaming\Mozilla\Firefox\Profiles\azv8rvwh.default\Extensions\[email protected] [2019-11-27]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_32_0_0_293.dll [2019-11-13] (Adobe Inc. -> )
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\Microsoft Office\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2018-04-19] (VideoLAN -> VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWoW64\Macromed\Flash\NPSWF32_32_0_0_293.dll [2019-11-13] (Adobe Inc. -> )
FF Plugin-x32: @java.com/DTPlugin,version=11.231.2 -> C:\Program Files (x86)\Java\jre1.8.0_231\bin\dtplugin\npDeployJava1.dll [2019-10-30] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.231.2 -> C:\Program Files (x86)\Java\jre1.8.0_231\bin\plugin2\npjp2.dll [2019-10-30] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2012-10-01] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\Microsoft Office\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2013-05-11] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 PlexUpdateService; C:\Program Files (x86)\Plex\Plex Media Server\Plex Update Service.exe [2120680 2019-06-28] (Plex, Inc -> Plex, Inc.)
S2 BavSvc; "C:\Program Files (x86)\Baidu Security\Baidu Antivirus\5.4.3.147185.0\BavSvc.exe" [X]
S2 BHipsSvc; "C:\Program Files (x86)\Baidu Security\Baidu Antivirus\5.4.3.147185.0\BHipsSvc.exe" [X]
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 AtcL001; C:\Windows\System32\drivers\l160x64.sys [65024 2016-07-16] (Microsoft Windows -> Atheros Communications, Inc.)
S3 bcmfn; C:\Windows\System32\drivers\bcmfn.sys [9728 2016-07-16] (Microsoft Windows -> Windows (R) Win 7 DDK provider)
S3 bdark64; C:\Windows\system32\drivers\bdark64.sys [78792 2015-05-27] (Baidu Online Network Technology (Beijing) Co.,Ltd. -> )
R1 Bfilter; C:\Windows\System32\drivers\Bfilter.sys [62920 2018-12-06] (Baidu Online Network Technology (Beijing) Co.,Ltd. -> Baidu, Inc.)
R1 Bfmon; C:\Windows\System32\drivers\Bfmon.sys [38344 2018-12-06] (Baidu Online Network Technology (Beijing) Co.,Ltd. -> Baidu, Inc.)
R1 Bnbase; C:\Windows\System32\drivers\bnbasex64.sys [62792 2018-12-06] (Baidu Online Network Technology (Beijing) Co.,Ltd. -> Baidu, Inc.)
R1 Bndef; C:\Windows\System32\drivers\bndef64.sys [485672 2018-12-06] (Baidu Online Network Technology (Beijing) Co.,Ltd. -> Baidu, Inc.)
R1 Bprotect; C:\Windows\System32\drivers\Bprotect.sys [169416 2018-12-06] (Baidu Online Network Technology (Beijing) Co.,Ltd. -> Baidu, Inc.)
S3 L1C; C:\Windows\System32\drivers\L1C63x64.sys [121344 2016-07-16] (Microsoft Windows -> Qualcomm Atheros Co., Ltd.)
S3 L1E; C:\Windows\System32\drivers\L1E62x64.sys [59904 2016-07-16] (Microsoft Windows -> Atheros Communications, Inc.)
S3 NetAdapterCx; C:\Windows\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] (Microsoft Windows -> )
S3 netr28ux; C:\Windows\System32\drivers\netr28ux.sys [2224128 2016-07-16] (Microsoft Windows -> MediaTek Inc.)
S3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [589824 2016-07-16] (Microsoft Windows -> Realtek )
S3 RtlWlanu_OldIC; C:\Windows\System32\drivers\rtwlanu_oldIC.sys [3814400 2016-07-16] (Microsoft Windows -> Realtek Semiconductor Corporation )
S3 yukonw8; C:\Windows\System32\drivers\yk63x64.sys [288768 2016-07-16] (Microsoft Windows -> Marvell)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) ===================
(If an entry is included in the fixlist, the file/folder will be moved.)
2019-11-27 19:02 - 2019-11-27 19:03 - 000000000 ____D C:\Users\Core 2 duo\Desktop\Documentos Manoli
2019-11-27 18:57 - 2019-11-27 18:59 - 000052821 _____ C:\Users\Core 2 duo\Desktop\Addition.txt
2019-11-27 18:56 - 2019-11-28 18:38 - 000016887 _____ C:\Users\Core 2 duo\Desktop\FRST.txt
2019-11-27 18:50 - 2019-11-27 18:50 - 010823512 _____ (AVAST Software) C:\Users\Core 2 duo\Downloads\avastclear.exe
2019-11-27 09:06 - 2019-11-27 09:06 - 002066743 _____ C:\Users\Core 2 duo\Downloads\joinPdf_58da73a2188a062702c0956c57e89d2f.pdf
2019-11-26 21:39 - 2019-11-26 21:39 - 000000000 ____D C:\Users\Core 2 duo\AppData\Local\CEF
2019-11-26 21:38 - 2019-11-27 18:53 - 000000000 ____D C:\Program Files\Common Files\AVAST Software
2019-11-26 21:37 - 2019-11-27 18:53 - 000000000 ____D C:\ProgramData\AVAST Software
2019-11-26 21:36 - 2019-11-26 21:36 - 000233080 _____ (AVAST Software) C:\Users\Core 2 duo\Downloads\avast_free_antivirus_setup_online.exe
2019-11-26 21:32 - 2019-11-26 21:32 - 000066588 _____ C:\ProgramData\agent.uninstall.1574800366.bdinstall.v2.bin
2019-11-26 20:11 - 2019-11-26 20:11 - 000075164 _____ C:\ProgramData\agent.update.1574795472.bdinstall.v2.bin
2019-11-26 20:07 - 2019-11-26 20:07 - 000001219 _____ C:\Users\Core 2 duo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bitdefender Antivirus Free.lnk
2019-11-26 20:05 - 2019-11-26 20:05 - 000000000 ____D C:\ProgramData\Bitdefender
2019-11-26 20:04 - 2019-11-26 20:04 - 000103488 _____ C:\ProgramData\agent.1574795055.bdinstall.v2.bin
2019-11-26 20:04 - 2019-11-26 20:04 - 000000000 ____D C:\ProgramData\Bitdefender Agent
2019-11-26 20:03 - 2019-11-26 20:03 - 010527368 _____ C:\Users\Core 2 duo\Downloads\bitdefender_online.exe
2019-11-26 19:43 - 2019-11-26 19:43 - 000000008 __RSH C:\Users\Core 2 duo\ntuser.pol
2019-11-26 19:43 - 2019-11-26 19:43 - 000000008 __RSH C:\ProgramData\ntuser.pol
2019-11-26 19:41 - 2019-11-28 18:38 - 000000000 ____D C:\FRST
2019-11-26 19:40 - 2019-11-26 19:40 - 002262016 _____ (Farbar) C:\Users\Core 2 duo\Desktop\FRST64.exe
2019-11-26 19:35 - 2019-11-26 19:35 - 000797760 _____ C:\Users\Core 2 duo\Desktop\delfix.exe
2019-11-26 19:35 - 2019-11-26 19:35 - 000000268 _____ C:\DelFix.txt
2019-11-26 19:35 - 2019-11-26 19:35 - 000000000 ____D C:\Windows\ERUNT
2019-11-26 19:26 - 2019-11-26 19:26 - 000001100 _____ C:\Users\Public\Desktop\Revo Uninstaller.lnk
2019-11-26 19:26 - 2019-11-26 19:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
2019-11-26 19:26 - 2019-11-26 19:26 - 000000000 ____D C:\Program Files\VS Revo Group
2019-11-26 19:24 - 2019-11-26 19:24 - 007411912 _____ (VS Revo Group ) C:\Users\Core 2 duo\Desktop\revosetup.exe
2019-11-25 12:32 - 2019-11-25 12:32 - 000006668 _____ C:\Users\Core 2 duo\Downloads\document.pdf
2019-11-23 21:06 - 2019-11-23 21:18 - 000000000 ____D C:\Users\Core 2 duo\AppData\Roaming\ZHP
2019-11-23 21:06 - 2019-11-23 21:06 - 000000000 ____D C:\Users\Core 2 duo\AppData\Local\ZHP
2019-11-23 20:43 - 2019-11-23 20:43 - 000320874 _____ C:\Users\Core 2 duo\Documents\Scan0009.pdf
2019-11-23 20:43 - 2019-11-23 20:43 - 000137659 _____ C:\Users\Core 2 duo\Documents\Scan0010.pdf
2019-11-23 20:42 - 2019-11-23 20:42 - 000536877 _____ C:\Users\Core 2 duo\Documents\Scan0008.pdf
2019-11-23 20:41 - 2019-11-23 20:41 - 000410788 _____ C:\Users\Core 2 duo\Documents\Scan0007.pdf
2019-11-23 20:40 - 2019-11-23 20:40 - 000346708 _____ C:\Users\Core 2 duo\Documents\Scan0005.pdf
2019-11-23 20:40 - 2019-11-23 20:40 - 000315055 _____ C:\Users\Core 2 duo\Documents\Scan0006.pdf
2019-11-23 20:39 - 2019-11-23 20:39 - 000173321 _____ C:\Users\Core 2 duo\Documents\Scan0004.pdf
2019-11-23 20:37 - 2019-11-23 20:37 - 000482263 _____ C:\Users\Core 2 duo\Documents\Scan0003.pdf
2019-11-22 10:11 - 2019-11-22 10:12 - 000703513 _____ C:\Users\Core 2 duo\Documents\Scan0002.pdf
2019-11-21 20:40 - 2019-11-21 20:40 - 000000000 ____D C:\Users\Core 2 duo\AppData\Local\mbamtray
2019-11-21 20:40 - 2019-11-21 20:39 - 000020936 _____ (Malwarebytes) C:\Windows\ELAMBKUP
2019-11-21 10:38 - 2019-11-21 10:38 - 000441117 _____ C:\Users\Core 2 duo\Documents\Scan0001.pdf
2019-11-06 15:19 - 2019-11-13 15:37 - 000004586 _____ C:\Windows\system32\Tasks\Adobe Flash Player NPAPI Notifier
2019-11-06 15:19 - 2019-11-13 15:37 - 000004388 _____ C:\Windows\system32\Tasks\Adobe Flash Player Updater
2019-11-06 15:19 - 2019-11-13 15:36 - 000000000 ____D C:\Windows\system32\Macromed
2019-11-06 15:19 - 2019-11-06 15:19 - 000000000 ____D C:\Users\Core 2 duo\AppData\Roaming\Macromedia
2019-11-03 21:08 - 2019-11-03 21:08 - 000000299 _____ C:\Users\Core 2 duo\Documents\Presupuesto Almussafes.txt
2019-10-31 16:13 - 2019-10-31 16:13 - 000000246 _____ C:\Users\Core 2 duo\Desktop\Prime Video.URL
2019-10-30 19:32 - 2019-10-30 19:31 - 000114232 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2019-11-28 18:33 - 2019-07-03 20:50 - 000000000 ____D C:\Users\Core 2 duo\AppData\LocalLow\Mozilla
2019-11-28 18:33 - 2018-12-06 16:07 - 000000000 ____D C:\Windows\system32\SleepStudy
2019-11-28 18:27 - 2019-06-28 19:20 - 000005338 _____ C:\Windows\system32\Tasks\Microsoft Office 15 Sync Maintenance for DESKTOP-62I3FUH-Core 2 duo DESKTOP-62I3FUH
2019-11-28 18:18 - 2018-12-06 16:08 - 006833880 _____ C:\Windows\system32\PerfStringBackup.INI
2019-11-28 18:18 - 2016-07-16 23:39 - 003332618 _____ C:\Windows\system32\perfh00A.dat
2019-11-28 18:18 - 2016-07-16 23:39 - 000951288 _____ C:\Windows\system32\perfc00A.dat
2019-11-28 18:13 - 2018-12-06 16:07 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2019-11-27 21:04 - 2018-12-06 19:42 - 000000000 ____D C:\Users\Core 2 duo\AppData\Local\ClassicShell
2019-11-27 20:57 - 2019-10-05 14:44 - 000000000 ____D C:\Users\Core 2 duo\AppData\Roaming\Kodi
2019-11-27 08:54 - 2018-12-06 21:08 - 000000000 ____D C:\Program Files\WinRAR
2019-11-26 21:43 - 2018-12-06 21:08 - 000000000 ____D C:\Users\Core 2 duo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2019-11-26 21:43 - 2018-12-06 21:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2019-11-26 21:32 - 2018-12-07 22:21 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2019-11-26 20:02 - 2018-12-07 22:46 - 000000000 ____D C:\Users\Core 2 duo\AppData\Roaming\MPC-HC
2019-11-26 20:02 - 2016-07-16 12:45 - 000000000 ____D C:\Windows\INF
2019-11-26 19:43 - 2018-12-06 19:40 - 000000000 ____D C:\Users\Core 2 duo
2019-11-26 19:42 - 2019-10-15 09:33 - 000000000 ____D C:\Users\Core 2 duo\AppData\LocalLow\Temp
2019-11-26 19:41 - 2016-07-16 12:47 - 000000000 ___HD C:\Windows\system32\GroupPolicy
2019-11-26 19:41 - 2016-07-16 12:47 - 000000000 ____D C:\Windows\SysWOW64\GroupPolicy
2019-11-26 13:11 - 2018-12-07 22:29 - 000000000 ____D C:\Users\Core 2 duo\AppData\Local\Microsoft Help
2019-11-25 15:06 - 2019-09-25 13:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
2019-11-22 10:06 - 2018-12-06 19:40 - 000000000 ____D C:\Users\Core 2 duo\AppData\Local\Packages
2019-11-21 20:40 - 2019-06-30 15:49 - 000000000 ____D C:\Users\Core 2 duo\AppData\Local\cache
2019-11-21 12:09 - 2016-07-16 07:04 - 000008192 _____ C:\Windows\system32\config\BBI
2019-11-19 09:49 - 2019-10-19 08:20 - 000000000 ____D C:\Users\Core 2 duo\Desktop\Ofimatica Pdf
2019-11-13 15:36 - 2016-07-16 12:47 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2019-11-06 15:19 - 2018-12-07 22:47 - 000000000 ____D C:\Users\Core 2 duo\AppData\Local\Adobe
2019-11-04 11:37 - 2019-10-10 11:25 - 000000000 ____D C:\Users\Core 2 duo\Desktop\correos
2019-11-03 20:21 - 2018-12-07 22:21 - 000001240 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2019-10-31 20:20 - 2019-10-28 20:47 - 000000000 ____D C:\Torrents
2019-10-30 19:32 - 2019-07-10 17:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2019-10-30 19:32 - 2019-07-10 17:56 - 000000000 ____D C:\Program Files (x86)\Java
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
LastRegBack: 2019-11-20 16:13
==================== End of FRST.txt ========================