Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 17.03.2019
Ran by Mavi (administrator) on MAVI-PC (07-04-2019 21:01:20)
Running from C:\Users\Mavi\Desktop
Loaded Profiles: Mavi (Available Profiles: Mavi & DefaultAppPool)
Platform: Windows 7 Professional Service Pack 1 (X64) Language: Español (España, internacional)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Adobe Systems, Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Adobe Systems Incorporated -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe
(Adobe Systems Incorporated -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Dropbox, Inc -> Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
(SEIKO EPSON Corporation -> Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Arvato Digital Services Canada Inc -> arvato digital services llc) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(Arvato Digital Services Canada Inc -> arvato digital services llc) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Intel Corporation - pGFX -> Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation - pGFX -> Intel Corporation) C:\Windows\System32\igfxpers.exe
(ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\eguiProxy.exe
(Adobe Systems, Incorporated -> Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\acrotray.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe
(AutoIt Team) [File not signed] C:\Users\Mavi\AppData\Local\Temp\systeminfo.exe
(Raúl Argente) [File not signed] C:\Program Files\Argente - Registry Cleaner\ArgenteRC.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\mspaint.exe
(Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Dropbox, Inc -> The Qt Company Ltd.) C:\Program Files (x86)\Dropbox\Client\QtWebEngineProcess.exe
(Adobe Systems, Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Acrobat.exe
(Adobe Systems, Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\AdobeCollabSync.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [18368512 2017-04-13] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET NOD32 Antivirus\ecmdS.exe [177928 2019-04-03] (ESET, spol. s r.o. -> ESET)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [1841496 2016-10-14] (Logitech -> Logitech, Inc.)
HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2675176 2018-12-13] (Adobe Systems Incorporated -> Adobe Systems, Incorporated)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-01-07] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [4426560 2019-04-03] (Dropbox, Inc -> Dropbox, Inc.)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Acrotray.exe [3500056 2017-11-01] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [601424 2018-10-06] (Oracle America, Inc. -> Oracle Corporation)
HKLM-x32\...\Run: [Opera Browser Assistant] => C:\Program Files\Opera\assistant\browser_assistant.exe [2480728 2019-03-22] (Opera Software AS -> Opera Software)
HKLM-x32\...\Run: [ArgenteRC] => C:\Program Files\Argente - Registry Cleaner\ArgenteRC.exe [2842112 2016-03-13] (Raúl Argente) [File not signed]
HKU\S-1-5-21-2590789392-3709184063-2437184007-1000\...\Run: [GUDelayStartup] => C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe [44016 2019-03-25] (Glarysoft LTD -> Glarysoft Ltd)
HKU\S-1-5-21-2590789392-3709184063-2437184007-1000\...\Run: [dc85d83f] => C:\ProgramData\dc85d83f\dc85d83f.exe [937776 2019-04-07] (AutoIt Consulting Ltd -> AutoIt Team)
HKU\S-1-5-21-2590789392-3709184063-2437184007-1000\...\RunOnce: [dc85d83f] => C:\ProgramData\dc85d83f\dc85d83f.exe [937776 2019-04-07] (AutoIt Consulting Ltd -> AutoIt Team)
HKU\S-1-5-21-2590789392-3709184063-2437184007-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\ssText3d.scr [333824 2010-11-20] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-18\...\RunOnce: [SPReview] => "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"hxxp://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
HKLM\...\Drivers32: [VIDC.FMVC] => C:\Windows\SysWOW64\fmcodec.dll [77824 2008-08-18] (Fox Magic Software) [File not signed]
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\73.0.3683.86\Installer\chrmstp.exe [2019-03-26] (Google LLC -> Google Inc.)
BootExecute: autocheck autochk *
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\Parameters: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{0A623B7B-40EC-4CED-A5EF-D572E22320C8}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{0A623B7B-40EC-4CED-A5EF-D572E22320C8}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{0F7DEDFE-3D72-4082-94FA-E40E628BBCE4}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{140542A6-736D-470E-9844-81C7DFD47FDF}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{140542A6-736D-470E-9844-81C7DFD47FDF}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{F94776C7-D1F3-49BD-9988-CF03FD2A7A8E}: [NameServer] 8.8.8.8
Internet Explorer:
==================
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_191\bin\ssv.dll [2018-11-14] (Oracle America, Inc. -> Oracle Corporation)
BHO: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll [2017-11-01] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_191\bin\jp2ssv.dll [2018-11-14] (Oracle America, Inc. -> Oracle Corporation)
BHO: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll [2017-11-01] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
BHO-x32: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2017-11-01] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
BHO-x32: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2017-11-01] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll [2017-11-01] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2017-11-01] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
Toolbar: HKU\S-1-5-21-2590789392-3709184063-2437184007-1000 -> Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll [2017-11-01] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
FireFox:
========
FF DefaultProfile: nup6skaj.default
FF ProfilePath: C:\Users\Mavi\AppData\Roaming\TomTom\HOME\Profiles\qkyt918m.default [2018-04-22]
FF Extension: (No Name) - C:\Program Files (x86)\TomTom HOME 2\xul\extensions\[email protected] [not found]
FF ProfilePath: C:\Users\Mavi\AppData\Roaming\Mozilla\Firefox\Profiles\nup6skaj.default [2019-04-07]
FF Homepage: Mozilla\Firefox\Profiles\nup6skaj.default -> www.google.es/
FF Extension: (uBlock Origin) - C:\Users\Mavi\AppData\Roaming\Mozilla\Firefox\Profiles\nup6skaj.default\Extensions\[email protected] [2019-02-05]
FF Extension: (DownThemAll!) - C:\Users\Mavi\AppData\Roaming\Mozilla\Firefox\Profiles\nup6skaj.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2017-05-10] [Legacy]
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi
FF Extension: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi [2017-11-01]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi
FF HKLM-x32\...\Thunderbird\Extensions: [[email protected]] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird => not found
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_27_0_0_187.dll [2017-11-19] (Adobe Systems Incorporated -> )
FF Plugin: @java.com/DTPlugin,version=11.191.2 -> C:\Program Files\Java\jre1.8.0_191\bin\dtplugin\npDeployJava1.dll [2018-11-14] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.191.2 -> C:\Program Files\Java\jre1.8.0_191\bin\plugin2\npjp2.dll [2018-11-14] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.adobe.xfdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [No File]
FF Plugin: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [No File]
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2015-07-29] (Adobe Systems Incorporated -> Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_187.dll [2017-11-19] (Adobe Systems Incorporated -> )
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2015-10-13] (Google Inc -> Google, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.34.7\npGoogleUpdate3.dll [2019-03-28] (Google Inc -> Google LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.34.7\npGoogleUpdate3.dll [2019-03-28] (Google Inc -> Google LLC)
FF Plugin-x32: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.adobe.xfdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x86.dll [No File]
FF Plugin-x32: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x86.dll [No File]
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN -> VideoLAN)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Air\nppdf32.dll [2017-11-01] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2015-07-29] (Adobe Systems Incorporated -> Adobe Systems)
FF Plugin HKU\.DEFAULT: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [No File]
FF Plugin HKU\.DEFAULT: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.adobe.xfdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [No File]
FF Plugin HKU\.DEFAULT: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [No File]
FF Plugin HKU\S-1-5-21-2590789392-3709184063-2437184007-1000: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [No File]
FF Plugin HKU\S-1-5-21-2590789392-3709184063-2437184007-1000: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.adobe.xfdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [No File]
FF Plugin HKU\S-1-5-21-2590789392-3709184063-2437184007-1000: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [No File]
Chrome:
=======
CHR Profile: C:\Users\Mavi\AppData\Local\Google\Chrome\User Data\Default [2019-04-07]
CHR Extension: (Google Drive) - C:\Users\Mavi\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-11-11]
CHR Extension: (YouTube) - C:\Users\Mavi\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-11-11]
CHR Extension: (uBlock Origin) - C:\Users\Mavi\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2019-04-03]
CHR Extension: (Angels Heaven) - C:\Users\Mavi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ebggokncjhegpmpkjcjanmcmbegobpao [2018-05-04]
CHR Extension: (Adobe Acrobat) - C:\Users\Mavi\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2019-03-12]
CHR Extension: (MyJDownloader Browser Extension) - C:\Users\Mavi\AppData\Local\Google\Chrome\User Data\Default\Extensions\fbcohnmimjicjdomonkcbcpbpnhggkip [2018-11-11]
CHR Extension: (Documentos de Google sin conexión) - C:\Users\Mavi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-08-16]
CHR Extension: (Sistema de pagos de Chrome Web Store) - C:\Users\Mavi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-03-20]
CHR Extension: (Gmail) - C:\Users\Mavi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-11-11]
CHR Extension: (Chrome Media Router) - C:\Users\Mavi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-04-03]
CHR Profile: C:\Users\Mavi\AppData\Local\Google\Chrome\User Data\System Profile [2018-10-25]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCChromeExtn\WCChromeExtn.crx [2017-11-01]
Opera:
=======
OPR Extension: (Fast search) - C:\Users\Mavi\AppData\Roaming\Opera Software\Opera Stable\Extensions\pbdpajcdgknpendpmecafmopknefafha [2017-05-10]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [2917864 2018-12-13] (Adobe Systems Incorporated -> Adobe Systems, Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2709480 2018-12-13] (Adobe Systems Incorporated -> Adobe Systems, Incorporated)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-02-28] (Dropbox, Inc -> Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-02-28] (Dropbox, Inc -> Dropbox, Inc.)
R2 DbxSvc; C:\Windows\system32\DbxSvc.exe [51024 2019-04-03] (Dropbox, Inc -> Dropbox, Inc.)
R2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2359312 2019-04-03] (ESET, spol. s r.o. -> ESET)
R3 ekrnEpfw; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2359312 2019-04-03] (ESET, spol. s r.o. -> ESET)
R2 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [144560 2012-05-17] (SEIKO EPSON Corporation -> Seiko Epson Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6562472 2019-02-01] (Malwarebytes Corporation -> Malwarebytes)
R2 PSI_SVC_2; C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe [277360 2014-04-30] (Arvato Digital Services Canada Inc -> arvato digital services llc)
R2 PSI_SVC_2_x64; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [337776 2014-04-30] (Arvato Digital Services Canada Inc -> arvato digital services llc)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Windows -> Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 asmthub3; C:\Windows\System32\DRIVERS\asmthub3.sys [128488 2011-06-02] (MCCI Internal Testing Software -> ASMedia Technology Inc)
R3 asmtxhci; C:\Windows\System32\DRIVERS\asmtxhci.sys [401896 2011-06-02] (MCCI Internal Testing Software -> ASMedia Technology Inc)
S3 athur; C:\Windows\System32\DRIVERS\athurx.sys [1847296 2010-01-05] (Microsoft Windows Hardware Compatibility Publisher -> Atheros Communications, Inc.)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [145600 2019-04-03] (ESET, spol. s r.o. -> ESET)
R0 edevmon; C:\Windows\System32\DRIVERS\edevmon.sys [107344 2017-05-04] (ESET, spol. s r.o. -> ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [188240 2019-04-03] (ESET, spol. s r.o. -> ESET)
R1 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [110000 2019-04-03] (ESET, spol. s r.o. -> ESET)
R1 GUBootStartup; C:\Windows\System32\drivers\GUBootStartup.sys [28936 2019-04-07] (Glarysoft LTD -> Glarysoft Ltd)
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28008 2013-07-10] (Intel Corporation - Intel® Rapid Storage Technology -> Intel Corporation)
R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [128200 2013-06-20] (Qualcomm Atheros -> Qualcomm Atheros Co., Ltd.)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [274416 2019-04-07] (Malwarebytes Corporation -> Malwarebytes)
S3 ptun0901; C:\Windows\System32\DRIVERS\ptun0901.sys [27136 2014-08-08] (OpenVPN Technologies, Inc. -> The OpenVPN Project)
R3 rtsuvc; C:\Windows\System32\DRIVERS\rtsuvc.sys [8244312 2013-06-19] (Realtek Semiconductor Corp -> Realtek Semiconductor Corp.)
S3 WDC_SAM; C:\Windows\System32\DRIVERS\wdcsam64.sys [23200 2015-04-30] (Microsoft Windows Hardware Compatibility Publisher -> Western Digital Technologies)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2019-04-07 21:01 - 2019-04-07 21:02 - 000024017 _____ C:\Users\Mavi\Desktop\FRST.txt
2019-04-07 21:01 - 2019-04-07 21:01 - 000000000 ____D C:\FRST
2019-04-07 20:07 - 2019-04-07 20:07 - 002434048 _____ (Farbar) C:\Users\Mavi\Desktop\FRST64 (1).exe
2019-04-07 14:53 - 2019-04-07 14:53 - 000274416 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2019-04-07 14:41 - 2019-04-07 14:41 - 000028936 _____ (Glarysoft Ltd) C:\Windows\system32\Drivers\GUBootStartup.sys
2019-04-07 14:41 - 2019-04-07 14:41 - 000001056 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5.lnk
2019-04-07 14:41 - 2019-04-07 14:41 - 000001044 _____ C:\Users\Public\Desktop\Glary Utilities 5.lnk
2019-04-07 14:41 - 2019-04-07 14:41 - 000000000 ____D C:\Users\Mavi\AppData\Roaming\GlarySoft
2019-04-07 14:41 - 2019-04-07 14:41 - 000000000 ____D C:\Users\Mavi\AppData\Roaming\DiskDefrag
2019-04-07 14:41 - 2019-04-07 14:41 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5
2019-04-07 14:40 - 2019-04-07 14:41 - 000000000 ____D C:\Program Files (x86)\Glary Utilities 5
2019-04-07 14:39 - 2019-04-07 14:39 - 017563064 _____ (Glarysoft Ltd) C:\Users\Mavi\Desktop\gu5setup.exe
2019-04-07 13:53 - 2019-04-07 14:38 - 000000000 ____D C:\Program Files\Argente - Registry Cleaner
2019-04-07 13:53 - 2019-04-07 13:53 - 000000943 _____ C:\Users\Public\Desktop\Argente - Registry Cleaner.lnk
2019-04-07 13:53 - 2019-04-07 13:53 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Argente - Registry Cleaner
2019-04-07 13:48 - 2019-04-07 13:48 - 000000822 _____ C:\Users\Public\Desktop\CCleaner.lnk
2019-04-06 19:42 - 2019-04-06 19:42 - 000000000 ____D C:\ProgramData\dc85d83f
2019-04-06 19:37 - 2019-04-06 19:37 - 000000000 ____D C:\ProgramData\bpsreS
2019-04-06 12:29 - 2019-04-06 12:29 - 000004035 _____ C:\Users\Mavi\Desktop\Informe de ZHPCleaner.txt
2019-04-06 12:26 - 2019-04-06 12:26 - 000004012 _____ C:\Users\Mavi\Desktop\ZHPCleaner (R).txt
2019-04-06 12:22 - 2019-04-06 12:22 - 000003997 _____ C:\Users\Mavi\Desktop\ZHPCleaner (S).txt
2019-04-06 12:14 - 2019-04-06 12:26 - 000000000 ____D C:\Users\Mavi\AppData\Roaming\ZHP
2019-04-06 12:14 - 2019-04-06 12:14 - 000000791 _____ C:\Users\Mavi\Desktop\ZHPCleaner.lnk
2019-04-06 12:14 - 2019-04-06 12:14 - 000000000 ____D C:\Users\Mavi\AppData\Local\ZHP
2019-04-06 12:13 - 2019-04-06 12:13 - 003126144 _____ C:\Users\Mavi\Desktop\ZHPCleaner.exe
2019-04-06 12:11 - 2019-04-06 12:11 - 000001257 _____ C:\Users\Mavi\Desktop\AdwCleaner[S00].txt
2019-04-06 12:08 - 2019-04-06 12:09 - 000000000 ____D C:\AdwCleaner
2019-04-06 12:07 - 2019-04-06 12:07 - 007025360 _____ (Malwarebytes) C:\Users\Mavi\Desktop\adwcleaner_7.3.exe
2019-04-06 11:59 - 2019-04-06 11:59 - 000000338 _____ C:\Users\Mavi\Desktop\eset online.txt
2019-04-06 05:57 - 2019-04-06 05:57 - 007665272 _____ (ESET spol. s r.o.) C:\Users\Mavi\Desktop\esetonlinescanner_esn.exe
2019-04-05 22:30 - 2019-04-05 22:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2019-04-05 18:38 - 2019-04-05 18:41 - 000001865 _____ C:\Users\Mavi\Desktop\Malwarebytes.txt
2019-04-05 18:21 - 2019-04-05 18:22 - 001599815 _____ C:\Users\Mavi\Desktop\IFS.exe
2019-04-04 20:31 - 2019-04-04 20:31 - 000000085 _____ C:\Windows\wininit.ini
2019-04-03 22:59 - 2019-04-03 22:59 - 000051024 _____ (Dropbox, Inc.) C:\Windows\system32\DbxSvc.exe
2019-04-03 22:59 - 2019-04-03 22:59 - 000047600 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-stable.sys
2019-04-03 22:59 - 2019-04-03 22:59 - 000047600 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-dev.sys
2019-04-03 22:59 - 2019-04-03 22:59 - 000047600 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-canary.sys
2019-04-03 11:35 - 2017-08-09 11:26 - 000004435 _____ C:\Users\Mavi\Desktop\license.lf
2019-03-28 19:42 - 2019-04-07 13:11 - 000003132 _____ C:\Windows\System32\Tasks\CorelUpdateHelperTask-CAAA1EF5E2B54BB10C8A531B38787585
2019-03-27 11:21 - 2019-03-27 11:21 - 000004024 _____ C:\Windows\System32\Tasks\Opera scheduled assistant Autoupdate 1553678500
2019-03-24 20:43 - 2019-03-24 20:44 - 000000000 ____D C:\tjwifroqnt__
2019-03-21 14:56 - 2019-03-21 14:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON Software
2019-03-16 20:27 - 2019-03-16 20:33 - 1779040256 _____ C:\Users\Mavi\Desktop\La Hora Señalada [BluRay Rip][AC3 2.0 Español Castellano][2018].avi
2019-03-16 11:31 - 2019-03-16 11:54 - 1769078784 _____ C:\Users\Mavi\Desktop\M4zeHDR.DIVXTOTAL.avi
2019-03-16 11:29 - 2019-03-16 11:53 - 1658259456 _____ C:\Users\Mavi\Desktop\10x10 [BluRay Rip][AC3 5.1 Castellano][2018][www.descargas2020.com].avi
2019-03-16 11:27 - 2019-03-16 11:47 - 2742261406 _____ C:\Users\Mavi\Desktop\Operacion Final [BluRay Rip][AC3 5.1 Castellano][2018][www.descargas2020.com].avi
2019-03-16 11:22 - 2019-03-16 11:55 - 1817987072 _____ C:\Users\Mavi\Desktop\The Keeping Hours [BluRay Rip][AC3 5.1 Castellano][2018][www.descargas2020.com].avi
2019-03-16 11:20 - 2019-03-16 11:28 - 1992132608 _____ C:\Users\Mavi\Desktop\Siberia [BluRayRIP][AC3 5.1 Castellano][2018][www.torrentrapid.com].avi
2019-03-13 13:20 - 2019-03-13 13:20 - 000096683 _____ C:\Users\Mavi\Desktop\Impuesto circulacion Francecs 2019.pdf
2019-03-12 13:13 - 2019-03-12 13:13 - 000095175 _____ C:\Users\Mavi\Desktop\Impuesto circulacion Mavi 2019.pdf
==================== One month (modified) ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2019-04-07 20:29 - 2017-01-02 22:07 - 000000000 ____D C:\Users\Mavi\AppData\LocalLow\Mozilla
2019-04-07 20:27 - 2017-02-28 00:59 - 000000988 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job
2019-04-07 17:46 - 2017-02-28 10:00 - 000000000 ___RD C:\Users\Mavi\Dropbox
2019-04-07 17:29 - 2017-01-11 15:39 - 000000000 ____D C:\Users\Mavi\AppData\Roaming\uTorrent
2019-04-07 17:28 - 2017-10-31 23:17 - 000000000 ____D C:\Users\Mavi\AppData\Local\CrashDumps
2019-04-07 17:26 - 2017-02-01 17:32 - 000000000 ___RD C:\Users\Mavi\Desktop\Descargas
2019-04-07 17:10 - 2017-02-28 00:59 - 000000984 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job
2019-04-07 15:28 - 2009-07-14 06:45 - 000035360 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2019-04-07 15:28 - 2009-07-14 06:45 - 000035360 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2019-04-07 14:53 - 2009-07-14 07:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2019-04-07 14:52 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\inf
2019-04-07 14:45 - 2017-08-23 21:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TNod User & Password Finder
2019-04-07 14:45 - 2017-01-08 17:48 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\aTube Catcher
2019-04-07 13:48 - 2017-11-02 13:00 - 000003870 _____ C:\Windows\System32\Tasks\CCleaner Update
2019-04-07 13:48 - 2017-01-11 16:05 - 000000000 ____D C:\Program Files\CCleaner
2019-04-07 13:28 - 2018-10-14 12:39 - 000000000 ____D C:\Users\Mavi\AppData\Roaming\1b56771ce39dab34de1448b88e12b38f
2019-04-06 19:44 - 2018-10-09 09:56 - 000000000 ____D C:\Users\Mavi\AppData\Local\Adobe
2019-04-06 19:44 - 2017-04-12 23:53 - 000004496 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
2019-04-06 19:44 - 2017-01-14 15:46 - 000842240 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2019-04-06 19:44 - 2017-01-14 15:46 - 000175104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2019-04-06 19:44 - 2017-01-10 20:06 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2019-04-06 19:44 - 2017-01-10 20:06 - 000000000 ____D C:\Windows\system32\Macromed
2019-04-06 19:39 - 2017-11-12 13:11 - 000000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2019-04-05 22:30 - 2017-02-28 00:59 - 000000000 ____D C:\Program Files (x86)\Dropbox
2019-04-05 18:29 - 2017-03-10 14:05 - 000000000 ____D C:\FSTool
2019-04-05 11:51 - 2017-07-07 13:06 - 000000310 _____ C:\Users\Mavi\Documents\Ctas.txt
2019-04-05 10:46 - 2009-07-14 05:20 - 000000000 ___HD C:\Windows\system32\GroupPolicy
2019-04-05 10:23 - 2009-07-14 11:31 - 000816658 _____ C:\Windows\system32\perfh00A.dat
2019-04-05 10:23 - 2009-07-14 11:31 - 000186528 _____ C:\Windows\system32\perfc00A.dat
2019-04-05 10:23 - 2009-07-14 07:13 - 001854082 _____ C:\Windows\system32\PerfStringBackup.INI
2019-04-04 20:31 - 2017-11-12 13:11 - 000000000 ____D C:\ProgramData\Spybot - Search & Destroy
2019-04-03 11:59 - 2018-04-12 16:26 - 000110000 _____ (ESET) C:\Windows\system32\Drivers\epfwwfp.sys
2019-04-03 11:59 - 2013-09-17 15:17 - 000188240 _____ (ESET) C:\Windows\system32\Drivers\ehdrv.sys
2019-04-03 11:59 - 2013-09-17 15:17 - 000145600 _____ (ESET) C:\Windows\system32\Drivers\eamonm.sys
2019-04-03 11:13 - 2019-02-11 00:04 - 000000000 ____D C:\Program Files (x86)\Origin
2019-04-02 20:07 - 2017-10-24 13:35 - 000000000 ____D C:\Users\Mavi\AppData\Roaming\vlc
2019-03-31 10:22 - 2017-04-08 14:57 - 000003840 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1491656257
2019-03-31 10:22 - 2017-04-08 14:56 - 000000000 ____D C:\Program Files\Opera
2019-03-28 00:04 - 2017-02-28 00:51 - 000003532 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2019-03-28 00:04 - 2017-02-28 00:51 - 000003404 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2019-03-27 18:09 - 2017-10-31 16:59 - 000000000 ____D C:\Program Files (x86)\Corel
2019-03-26 11:15 - 2017-11-11 14:54 - 000002182 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2019-03-22 20:19 - 2019-02-23 12:06 - 000153328 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae64.sys
2019-03-21 14:56 - 2017-01-20 14:52 - 000000000 ____D C:\Program Files (x86)\EPSON Software
2019-03-21 13:43 - 2017-09-13 21:21 - 000000000 ____D C:\Users\Mavi\AppData\Local\ElevatedDiagnostics
2019-03-12 13:11 - 2009-07-14 07:32 - 000000000 ____D C:\Windows\system32\FxsTmp
2019-03-09 19:14 - 2018-10-10 09:42 - 000000000 ____D C:\Users\Mavi\AppData\Roaming\Telegram Desktop
==================== Files in the root of some directories =======
2017-09-27 22:45 - 2017-09-27 22:45 - 000145382 _____ () C:\Users\Mavi\AppData\Roaming\throne_1200x437-1-534x437.ico
2017-11-04 21:49 - 2017-11-04 21:49 - 000140800 _____ () C:\Users\Mavi\AppData\Local\installer.dat
2018-10-07 11:25 - 2018-10-09 09:57 - 000001025 _____ () C:\Users\Mavi\AppData\Local\oobelibMkey.log
2017-11-04 21:52 - 2017-11-04 21:52 - 001900178 _____ () C:\Users\Mavi\AppData\Local\Reis.tst
2018-08-13 21:19 - 2018-08-13 22:05 - 000007607 _____ () C:\Users\Mavi\AppData\Local\Resmon.ResmonCfg
Some files in TEMP:
====================
2019-04-03 11:06 - 2019-04-07 17:10 - 001060864 _____ (AutoIt Team) C:\Users\Mavi\AppData\Local\Temp\systeminfo.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\dllhost.exe => File is digitally signed
C:\Windows\SysWOW64\dllhost.exe => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2019-04-03 15:47
==================== End of FRST.txt ============================