Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 01.12.2018 01 Ran by Florenci (administrator) on FLORENCI-PC (08-12-2018 20:48:10) Running from C:\Users\Florenci\Desktop Loaded Profiles: Florenci (Available Profiles: Florenci) Platform: Windows 10 Home Version 1803 17134.407 (X64) Language: Espanyol (Espanya, alfabet internacional) Internet Explorer Version 11 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Arcai.com) C:\Program Files (x86)\arcai.com\aips.exe (SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1810.5-0\MsMpEng.exe (Windscribe Limited) C:\Program Files (x86)\Windscribe\WindscribeService.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe () C:\Program Files (x86)\arcai.com\netcut_windows.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe () C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.35.76.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe (Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler64.exe (Microsoft Corporation) C:\Program Files\rempl\sedsvc.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1810.5-0\MpCmdRun.exe (Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1810.5-0\MpCmdRun.exe (Microsoft Corporation) C:\Windows\SoftwareDistribution\Download\Install\AM_Delta_Patch_1.283.135.0.exe (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-12] (Microsoft Corporation) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11779176 2011-02-18] (Realtek Semiconductor) HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-19\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-12] (Microsoft Corporation) HKU\S-1-5-20\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-12] (Microsoft Corporation) HKU\S-1-5-21-549940460-2404856339-1566757125-1000\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [8907696 2018-12-06] (SUPERAntiSpyware) HKU\S-1-5-21-549940460-2404856339-1566757125-1000\...\Run: [Windscribe] => C:\Program Files (x86)\Windscribe\Windscribe.exe [10097840 2018-09-07] (Windscribe Limited) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 8.8.8.8 8.8.4.4 Tcpip\..\Interfaces\{421f5d7b-84f6-48c8-944c-f06057d9db72}: [DhcpNameServer] 8.8.8.8 8.8.4.4 Tcpip\..\Interfaces\{f8556924-b71e-458e-8333-de356950292b}: [DhcpNameServer] 8.8.8.8 8.8.4.4 Internet Explorer: ================== HKU\S-1-5-21-549940460-2404856339-1566757125-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/es-es/?ocid=iehp BHO: No Name -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> No File BHO-x32: No Name -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> No File Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - No File Edge: ====== Edge Extension: (Adblock Plus) -> 10_EyeoGmbHAdblockPlus_d55gg7py3s0m0 => C:\Program Files\WindowsApps\EyeoGmbH.AdblockPlus_0.9.11.0_neutral__d55gg7py3s0m0 [2018-06-01] FireFox: ======== FF DefaultProfile: dr0dfxpp.Florenci-1540316640948 FF ProfilePath: C:\Users\Florenci\AppData\Roaming\Mozilla\Firefox\Profiles\rebb3myb.default-1505571765827 [2018-12-08] FF Extension: (Avast Passwords) - C:\Users\Florenci\AppData\Roaming\Mozilla\Firefox\Profiles\rebb3myb.default-1505571765827\Extensions\jid1-r1tDuNiNb4SEww@jetpack.xpi [2018-09-03] FF Extension: (Malwarebytes Browser Extension) - C:\Users\Florenci\AppData\Roaming\Mozilla\Firefox\Profiles\rebb3myb.default-1505571765827\Extensions\{242af0bb-db11-4734-b7a0-61cb8a9b20fb}.xpi [2018-09-03] FF Extension: (Adblock Plus) - C:\Users\Florenci\AppData\Roaming\Mozilla\Firefox\Profiles\rebb3myb.default-1505571765827\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2018-09-03] FF ProfilePath: C:\Users\Florenci\AppData\Roaming\Mozilla\Firefox\Profiles\dr0dfxpp.Florenci-1540316640948 [2018-12-08] FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\e10ssaffplg.xpi => not found FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\e10ssaffplg.xpi => not found FF HKU\S-1-5-21-549940460-2404856339-1566757125-1000\...\SeaMonkey\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi => not found FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-20] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-20] (Google Inc.) Chrome: ======= CHR DefaultProfile: Profile 6 CHR HomePage: Profile 6 -> hxxp://www.google.cat/ CHR StartupUrls: Profile 6 -> "hxxps://www.google.cat/" CHR Profile: C:\Users\Florenci\AppData\Local\Google\Chrome\User Data\Profile 6 [2018-12-08] CHR Extension: (Dr.Web Anti-Virus Link Checker) - C:\Users\Florenci\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\aleggpabliehgbeagmfhnodcijcmbonb [2018-09-07] CHR Extension: (Adblock Plus) - C:\Users\Florenci\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2018-12-06] CHR Extension: (Canal Partidazo Plus en directo onlin...) - C:\Users\Florenci\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\emhhkhofpmflafmpejplpbmnidicjjkl [2018-04-14] CHR Extension: (Malwarebytes Browser Extension) - C:\Users\Florenci\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\ihcjicgdanjaechkgeegckofjjedodee [2018-12-06] CHR Extension: (VER CANAL MOVISTAR PARTIDAZO ONLINE E...) - C:\Users\Florenci\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\ihobjaompgheafiigdjbablamjbhdggn [2018-05-20] CHR Extension: (ROJADIRECTA: Tarjeta Roja TV - Interg...) - C:\Users\Florenci\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\khcbmelncakfefpbioaneecjmidciecl [2017-11-07] CHR Extension: (Diresport) - C:\Users\Florenci\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\nhmklomilgafkfgfghfjfbblcmgonhbg [2018-03-04] CHR Extension: (Sistema de pagaments de Chrome Web Store) - C:\Users\Florenci\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-07] CHR Extension: (Chrome Media Router) - C:\Users\Florenci\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-12-06] CHR Profile: C:\Users\Florenci\AppData\Local\Google\Chrome\User Data\System Profile [2018-12-08] CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx ==================== Services (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [173472 2017-01-31] (SUPERAntiSpyware.com) R2 AIPS; C:\Program Files (x86)\arcai.com\aips.exe [2677760 2018-05-11] (Arcai.com) [File not signed] S3 GoogleChromeElevationService; C:\Program Files (x86)\Google\Chrome\Application\71.0.3578.80\elevation_service.exe [443872 2018-11-30] (Google Inc.) R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6347056 2018-09-19] (Malwarebytes) S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-03-01] (Riverbed Technology, Inc.) S4 ssh-agent; C:\WINDOWS\System32\OpenSSH\ssh-agent.exe [495616 2018-03-10] () R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [269400 2017-01-17] (Synaptics Incorporated) S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1810.5-0\NisSrv.exe [3917016 2018-10-23] (Microsoft Corporation) R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1810.5-0\MsMpEng.exe [114208 2018-10-23] (Microsoft Corporation) R2 WindscribeService; C:\Program Files (x86)\Windscribe\WindscribeService.exe [493232 2018-09-07] (Windscribe Limited) ===================== Drivers (Whitelisted) ====================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [260480 2018-12-08] (Malwarebytes) R2 NEWDRIVER; C:\WINDOWS\SysWow64\WinVDEdrv6.sys [197648 2016-03-22] () R2 NPF; C:\WINDOWS\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.) R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R3 tapwindscribe0901; C:\WINDOWS\System32\drivers\tapwindscribe0901.sys [54896 2018-06-19] (The OpenVPN Project) S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [46184 2018-10-23] (Microsoft Corporation) R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [328696 2018-10-23] (Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [60408 2018-10-23] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) Error(1) reading file: "C:\WINDOWS\System32\Tasks\Burbujas." 2018-12-08 20:48 - 2018-12-08 20:48 - 000011212 _____ C:\Users\Florenci\Desktop\FRST.txt 2018-12-08 20:47 - 2018-12-08 20:48 - 000000000 ____D C:\FRST 2018-12-08 20:45 - 2018-12-08 20:45 - 000000827 _____ C:\Users\Florenci\Desktop\JRT.txt 2018-12-08 20:41 - 2018-12-08 20:41 - 000001436 _____ C:\Users\Florenci\Desktop\AdwCleaner[C00].txt 2018-12-08 20:37 - 2018-12-08 20:37 - 000260480 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys 2018-12-08 20:35 - 2018-12-08 20:35 - 000001250 _____ C:\Users\Florenci\Desktop\AdwCleaner[S00].txt 2018-12-08 20:34 - 2018-12-08 20:34 - 000000000 ____D C:\AdwCleaner 2018-12-08 20:23 - 2018-12-08 20:23 - 000001552 _____ C:\Users\Florenci\Desktop\malwarebytes.txt 2018-12-08 19:15 - 2018-12-08 19:15 - 000000245 _____ C:\Users\Florenci\Desktop\Lo que tinc que dir a forospyware.txt 2018-12-08 14:44 - 2018-12-08 14:44 - 002417152 _____ (Farbar) C:\Users\Florenci\Desktop\FRST64.exe 2018-12-08 14:40 - 2018-12-08 14:40 - 007321808 _____ (Malwarebytes) C:\Users\Florenci\Desktop\adwcleaner_7.2.5.0.exe 2018-12-08 14:40 - 2018-12-08 14:40 - 001790024 _____ (Malwarebytes) C:\Users\Florenci\Desktop\JRT.exe 2018-12-06 21:16 - 2018-12-01 05:01 - 000835688 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2018-12-06 21:16 - 2018-12-01 05:01 - 000179808 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2018-12-06 20:56 - 2018-12-06 20:56 - 000000867 _____ C:\Users\Public\Desktop\CCleaner.lnk 2018-12-06 20:47 - 2018-12-07 09:56 - 000000000 ____D C:\Program Files\rempl 2018-12-06 20:28 - 2018-11-01 12:46 - 002394960 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVCORE.DLL 2018-12-06 20:28 - 2018-11-01 12:45 - 004527776 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe 2018-12-06 20:28 - 2018-11-01 12:45 - 001617320 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll 2018-12-06 20:28 - 2018-11-01 12:45 - 001376672 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll 2018-12-06 20:28 - 2018-11-01 12:31 - 006602240 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2018-12-06 20:28 - 2018-11-01 12:29 - 012710400 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2018-12-06 20:28 - 2018-11-01 12:28 - 004491264 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsrchvw.exe 2018-12-06 20:28 - 2018-11-01 12:28 - 003649024 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2018-12-06 20:28 - 2018-11-01 12:27 - 000878592 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll 2018-12-06 20:28 - 2018-11-01 12:26 - 000503296 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll 2018-12-06 20:28 - 2018-11-01 12:25 - 000577024 _____ (Microsoft Corporation) C:\WINDOWS\system32\SppExtComObj.Exe 2018-12-06 20:28 - 2018-11-01 11:09 - 001027000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll 2018-12-06 20:28 - 2018-11-01 10:59 - 005669888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2018-12-06 20:28 - 2018-11-01 10:56 - 011902464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2018-12-06 20:28 - 2018-11-01 10:54 - 003397632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsrchvw.exe 2018-12-06 20:28 - 2018-11-01 10:52 - 002892800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys 2018-12-06 20:28 - 2018-11-01 10:15 - 023861760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll 2018-12-06 20:28 - 2018-11-01 10:13 - 019525120 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll 2018-12-06 20:28 - 2018-11-01 08:39 - 001035256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe 2018-12-06 20:28 - 2018-11-01 08:27 - 000491200 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll 2018-12-06 20:28 - 2018-11-01 08:26 - 003291640 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll 2018-12-06 20:28 - 2018-11-01 08:26 - 003180080 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll 2018-12-06 20:28 - 2018-11-01 08:26 - 001363536 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll 2018-12-06 20:28 - 2018-11-01 08:25 - 009089848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2018-12-06 20:28 - 2018-11-01 08:25 - 007520088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll 2018-12-06 20:28 - 2018-11-01 08:25 - 004404912 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll 2018-12-06 20:28 - 2018-11-01 08:25 - 002571320 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll 2018-12-06 20:28 - 2018-11-01 08:25 - 002371296 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll 2018-12-06 20:28 - 2018-11-01 08:25 - 001934808 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll 2018-12-06 20:28 - 2018-11-01 08:25 - 001784680 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll 2018-12-06 20:28 - 2018-11-01 08:25 - 001288920 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll 2018-12-06 20:28 - 2018-11-01 08:25 - 001209888 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll 2018-12-06 20:28 - 2018-11-01 08:25 - 001190248 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll 2018-12-06 20:28 - 2018-11-01 08:25 - 000594224 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe 2018-12-06 20:28 - 2018-11-01 08:25 - 000413720 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll 2018-12-06 20:28 - 2018-11-01 08:25 - 000375824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msrpc.sys 2018-12-06 20:28 - 2018-11-01 08:25 - 000261000 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll 2018-12-06 20:28 - 2018-11-01 08:09 - 025855488 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2018-12-06 20:28 - 2018-11-01 08:03 - 003397120 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2018-12-06 20:28 - 2018-11-01 08:01 - 022716416 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2018-12-06 20:28 - 2018-11-01 08:01 - 009084928 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll 2018-12-06 20:28 - 2018-11-01 08:01 - 007057408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll 2018-12-06 20:28 - 2018-11-01 08:00 - 006031360 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll 2018-12-06 20:28 - 2018-11-01 08:00 - 000209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll 2018-12-06 20:28 - 2018-11-01 07:58 - 000530432 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll 2018-12-06 20:28 - 2018-11-01 07:58 - 000273408 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll 2018-12-06 20:28 - 2018-11-01 07:57 - 003381248 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapRouter.dll 2018-12-06 20:28 - 2018-11-01 07:57 - 002825728 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapGeocoder.dll 2018-12-06 20:28 - 2018-11-01 07:57 - 002364928 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpcServices.dll 2018-12-06 20:28 - 2018-11-01 07:57 - 000835584 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneService.dll 2018-12-06 20:28 - 2018-11-01 07:57 - 000265728 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll 2018-12-06 20:28 - 2018-11-01 07:56 - 002172928 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll 2018-12-06 20:28 - 2018-11-01 07:56 - 001768448 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2018-12-06 20:28 - 2018-11-01 07:56 - 001395200 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll 2018-12-06 20:28 - 2018-11-01 07:56 - 000506880 _____ (Microsoft Corporation) C:\WINDOWS\system32\netprofmsvc.dll 2018-12-06 20:28 - 2018-11-01 07:55 - 000684544 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll 2018-12-06 20:28 - 2018-11-01 07:54 - 001551360 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll 2018-12-06 20:28 - 2018-11-01 07:54 - 001264640 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll 2018-12-06 20:28 - 2018-11-01 07:54 - 001225216 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll 2018-12-06 20:28 - 2018-11-01 07:54 - 000943616 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingOnlineServices.dll 2018-12-06 20:28 - 2018-11-01 07:54 - 000916480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll 2018-12-06 20:28 - 2018-11-01 07:54 - 000884736 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll 2018-12-06 20:28 - 2018-11-01 07:53 - 002248192 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll 2018-12-06 20:28 - 2018-11-01 07:53 - 001159680 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll 2018-12-06 20:28 - 2018-11-01 07:53 - 000542208 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll 2018-12-06 20:28 - 2018-11-01 06:08 - 002417952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll 2018-12-06 20:28 - 2018-11-01 05:50 - 000786288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll 2018-12-06 20:28 - 2018-11-01 05:48 - 004790184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll 2018-12-06 20:28 - 2018-11-01 05:48 - 002478872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll 2018-12-06 20:28 - 2018-11-01 05:48 - 002331480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll 2018-12-06 20:28 - 2018-11-01 05:48 - 001805656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll 2018-12-06 20:28 - 2018-11-01 05:48 - 001011872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll 2018-12-06 20:28 - 2018-11-01 05:47 - 006570368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll 2018-12-06 20:28 - 2018-11-01 05:47 - 001980776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll 2018-12-06 20:28 - 2018-11-01 05:47 - 001379792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll 2018-12-06 20:28 - 2018-11-01 05:47 - 001020064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll 2018-12-06 20:28 - 2018-11-01 05:47 - 000129304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll 2018-12-06 20:28 - 2018-11-01 05:40 - 022015488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2018-12-06 20:28 - 2018-11-01 05:32 - 006647296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll 2018-12-06 20:28 - 2018-11-01 05:31 - 005307904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll 2018-12-06 20:28 - 2018-11-01 05:30 - 005883904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll 2018-12-06 20:28 - 2018-11-01 05:30 - 002449408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapRouter.dll 2018-12-06 20:28 - 2018-11-01 05:30 - 000392704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll 2018-12-06 20:28 - 2018-11-01 05:30 - 000310272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll 2018-12-06 20:28 - 2018-11-01 05:29 - 001986560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapGeocoder.dll 2018-12-06 20:28 - 2018-11-01 05:28 - 001348096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OpcServices.dll 2018-12-06 20:28 - 2018-11-01 05:28 - 001000448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll 2018-12-06 20:28 - 2018-11-01 05:28 - 000978944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll 2018-12-06 20:28 - 2018-11-01 05:27 - 000713216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingOnlineServices.dll 2018-12-06 20:28 - 2018-11-01 05:27 - 000678400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll 2018-12-06 20:27 - 2018-11-01 12:49 - 000348160 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe 2018-12-06 20:27 - 2018-11-01 12:32 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\iemigplugin.dll 2018-12-06 20:27 - 2018-11-01 12:30 - 000122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll 2018-12-06 20:27 - 2018-11-01 12:30 - 000029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\msisip.dll 2018-12-06 20:27 - 2018-11-01 12:29 - 000073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\SMSRouter.dll 2018-12-06 20:27 - 2018-11-01 12:28 - 000253952 _____ (Microsoft Corporation) C:\WINDOWS\system32\prnntfy.dll 2018-12-06 20:27 - 2018-11-01 12:27 - 001121792 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll 2018-12-06 20:27 - 2018-11-01 12:26 - 001364992 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvruserservice.dll 2018-12-06 20:27 - 2018-11-01 12:26 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll 2018-12-06 20:27 - 2018-11-01 10:56 - 000226304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\prnntfy.dll 2018-12-06 20:27 - 2018-11-01 10:56 - 000024576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msisip.dll 2018-12-06 20:27 - 2018-11-01 10:54 - 000344576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll 2018-12-06 20:27 - 2018-11-01 10:53 - 000908288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSWorkspace.dll 2018-12-06 20:27 - 2018-11-01 08:38 - 000269336 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave_secure.dll 2018-12-06 20:27 - 2018-11-01 08:37 - 000272408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave.dll 2018-12-06 20:27 - 2018-11-01 08:28 - 001221432 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe 2018-12-06 20:27 - 2018-11-01 08:28 - 001062712 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi 2018-12-06 20:27 - 2018-11-01 08:28 - 001029944 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe 2018-12-06 20:27 - 2018-11-01 08:28 - 000566568 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe 2018-12-06 20:27 - 2018-11-01 08:28 - 000134968 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll 2018-12-06 20:27 - 2018-11-01 08:28 - 000076088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys 2018-12-06 20:27 - 2018-11-01 08:27 - 001017152 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2adec.dll 2018-12-06 20:27 - 2018-11-01 08:26 - 007432120 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll 2018-12-06 20:27 - 2018-11-01 08:25 - 002822456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2018-12-06 20:27 - 2018-11-01 08:25 - 001456728 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi 2018-12-06 20:27 - 2018-11-01 08:25 - 001257880 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe 2018-12-06 20:27 - 2018-11-01 08:25 - 001140672 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi 2018-12-06 20:27 - 2018-11-01 08:25 - 000982592 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe 2018-12-06 20:27 - 2018-11-01 08:25 - 000885968 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll 2018-12-06 20:27 - 2018-11-01 08:25 - 000793080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys 2018-12-06 20:27 - 2018-11-01 08:25 - 000713472 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVideoDSP.dll 2018-12-06 20:27 - 2018-11-01 08:25 - 000463672 _____ (Microsoft Corporation) C:\WINDOWS\system32\coml2.dll 2018-12-06 20:27 - 2018-11-01 08:25 - 000412984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys 2018-12-06 20:27 - 2018-11-01 08:25 - 000268088 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll 2018-12-06 20:27 - 2018-11-01 08:03 - 000034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\dusmtask.exe 2018-12-06 20:27 - 2018-11-01 08:02 - 000047104 _____ (Microsoft Corporation) C:\WINDOWS\system32\dusmapi.dll 2018-12-06 20:27 - 2018-11-01 08:02 - 000023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\CSystemEventsBrokerClient.dll 2018-12-06 20:27 - 2018-11-01 08:00 - 008189440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll 2018-12-06 20:27 - 2018-11-01 08:00 - 003392000 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll 2018-12-06 20:27 - 2018-11-01 08:00 - 000433664 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe 2018-12-06 20:27 - 2018-11-01 07:59 - 000322048 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe 2018-12-06 20:27 - 2018-11-01 07:59 - 000241152 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll 2018-12-06 20:27 - 2018-11-01 07:59 - 000192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\scrrun.dll 2018-12-06 20:27 - 2018-11-01 07:59 - 000176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\WPTaskScheduler.dll 2018-12-06 20:27 - 2018-11-01 07:59 - 000107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\dab.dll 2018-12-06 20:27 - 2018-11-01 07:58 - 007573504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2018-12-06 20:27 - 2018-11-01 07:58 - 004867072 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2018-12-06 20:27 - 2018-11-01 07:58 - 004383744 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll 2018-12-06 20:27 - 2018-11-01 07:58 - 000154112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll 2018-12-06 20:27 - 2018-11-01 07:58 - 000149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll 2018-12-06 20:27 - 2018-11-01 07:57 - 001804288 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2018-12-06 20:27 - 2018-11-01 07:57 - 001708544 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSPhotography.dll 2018-12-06 20:27 - 2018-11-01 07:57 - 000898560 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll 2018-12-06 20:27 - 2018-11-01 07:57 - 000894464 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll 2018-12-06 20:27 - 2018-11-01 07:57 - 000808448 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll 2018-12-06 20:27 - 2018-11-01 07:57 - 000726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll 2018-12-06 20:27 - 2018-11-01 07:57 - 000356352 _____ (Microsoft Corporation) C:\WINDOWS\system32\dusmsvc.dll 2018-12-06 20:27 - 2018-11-01 07:57 - 000281600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll 2018-12-06 20:27 - 2018-11-01 07:56 - 002929664 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsservices.dll 2018-12-06 20:27 - 2018-11-01 07:55 - 002738688 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll 2018-12-06 20:27 - 2018-11-01 07:55 - 001058304 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe 2018-12-06 20:27 - 2018-11-01 07:54 - 001679360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll 2018-12-06 20:27 - 2018-11-01 07:54 - 001023488 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll 2018-12-06 20:27 - 2018-11-01 07:54 - 000895488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.OnlineId.dll 2018-12-06 20:27 - 2018-11-01 07:54 - 000796672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssvp.dll 2018-12-06 20:27 - 2018-11-01 07:54 - 000606208 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll 2018-12-06 20:27 - 2018-11-01 07:53 - 001373696 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll 2018-12-06 20:27 - 2018-11-01 07:53 - 000889344 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll 2018-12-06 20:27 - 2018-11-01 07:53 - 000406528 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe 2018-12-06 20:27 - 2018-11-01 06:39 - 000001310 _____ C:\WINDOWS\system32\tcbres.wim 2018-12-06 20:27 - 2018-11-01 05:50 - 000861712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2adec.dll 2018-12-06 20:27 - 2018-11-01 05:48 - 006039064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll 2018-12-06 20:27 - 2018-11-01 05:48 - 000880248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll 2018-12-06 20:27 - 2018-11-01 05:48 - 000384520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\coml2.dll 2018-12-06 20:27 - 2018-11-01 05:47 - 000581600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVideoDSP.dll 2018-12-06 20:27 - 2018-11-01 05:47 - 000567256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll 2018-12-06 20:27 - 2018-11-01 05:35 - 019403776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2018-12-06 20:27 - 2018-11-01 05:34 - 002700288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll 2018-12-06 20:27 - 2018-11-01 05:33 - 006661632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll 2018-12-06 20:27 - 2018-11-01 05:33 - 003711488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2018-12-06 20:27 - 2018-11-01 05:31 - 000288768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Search.ProtocolHandler.MAPI2.dll 2018-12-06 20:27 - 2018-11-01 05:30 - 005775872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2018-12-06 20:27 - 2018-11-01 05:30 - 001361408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSPhotography.dll 2018-12-06 20:27 - 2018-11-01 05:30 - 000561152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll 2018-12-06 20:27 - 2018-11-01 05:29 - 002258944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll 2018-12-06 20:27 - 2018-11-01 05:29 - 001862656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsservices.dll 2018-12-06 20:27 - 2018-11-01 05:29 - 000848384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ShareHost.dll 2018-12-06 20:27 - 2018-11-01 05:29 - 000608768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll 2018-12-06 20:27 - 2018-11-01 05:29 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll 2018-12-06 20:27 - 2018-11-01 05:29 - 000165376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scrrun.dll 2018-12-06 20:27 - 2018-11-01 05:27 - 001627648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2018-12-06 20:27 - 2018-11-01 05:27 - 000856576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe 2018-12-06 20:27 - 2018-11-01 05:27 - 000534016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll 2018-12-06 20:27 - 2018-11-01 05:26 - 000795648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.OnlineId.dll 2018-12-06 20:27 - 2018-11-01 05:26 - 000735744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssvp.dll 2018-12-06 20:27 - 2018-11-01 05:26 - 000345088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2018-12-08 20:39 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\AppReadiness 2018-12-08 20:38 - 2018-04-12 00:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2018-12-08 20:36 - 2018-05-21 05:57 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2018-12-08 20:35 - 2018-04-11 22:04 - 000786432 _____ C:\WINDOWS\system32\config\BBI 2018-12-08 20:34 - 2018-04-12 00:38 - 000000000 ___HD C:\Program Files\WindowsApps 2018-12-08 20:22 - 2018-05-21 05:26 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2018-12-08 15:07 - 2014-03-04 17:11 - 000000000 ____D C:\Copias de seguridad echas por ccleaner 2018-12-08 15:06 - 2018-10-19 19:20 - 000002390 _____ C:\Users\Florenci\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2018-12-08 15:06 - 2018-05-21 05:57 - 000003374 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-549940460-2404856339-1566757125-1000 2018-12-08 15:06 - 2014-03-26 21:28 - 000000000 ___RD C:\Users\Florenci\OneDrive 2018-12-08 14:51 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\system32\Macromed 2018-12-08 14:51 - 2017-10-21 13:48 - 000000000 ___HD C:\Users\Florenci\MicrosoftEdgeBackups 2018-12-08 14:49 - 2016-03-21 21:09 - 000000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job 2018-12-08 14:46 - 2018-04-12 00:30 - 000000000 ____D C:\WINDOWS\CbsTemp 2018-12-08 14:23 - 2018-05-21 05:57 - 000004216 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{5C497AA6-8DA4-4F51-9231-255D2BE41896} 2018-12-08 14:22 - 2018-05-21 05:46 - 001768608 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2018-12-08 14:22 - 2018-04-12 17:18 - 000787744 _____ C:\WINDOWS\system32\perfh00A.dat 2018-12-08 14:22 - 2018-04-12 17:18 - 000155340 _____ C:\WINDOWS\system32\perfc00A.dat 2018-12-08 14:22 - 2018-04-12 00:36 - 000000000 ____D C:\WINDOWS\INF 2018-12-07 20:49 - 2016-06-11 18:43 - 000000000 ____D C:\Users\Florenci\AppData\Local\WiFi Guard 2018-12-07 20:42 - 2016-11-18 20:03 - 000000000 ____D C:\Users\Florenci\AppData\LocalLow\Mozilla 2018-12-07 09:56 - 2018-09-29 07:08 - 000001316 _____ C:\Users\Florenci\Desktop\CrystalDiskInfo Kurei Kei Edition.lnk 2018-12-06 21:43 - 2018-07-06 17:47 - 000000000 ____D C:\Program Files (x86)\arcai.com 2018-12-06 21:41 - 2017-11-16 21:35 - 000000000 ____D C:\Users\Florenci\AppData\Local\AVAST Software 2018-12-06 21:41 - 2017-11-16 21:07 - 000000000 ____D C:\ProgramData\AVAST Software 2018-12-06 21:40 - 2017-12-12 19:59 - 000000000 ____D C:\Program Files\Common Files\Avast Software 2018-12-06 21:15 - 2018-05-21 05:26 - 000234176 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2018-12-06 21:14 - 2018-10-23 18:43 - 000000000 ____D C:\Program Files\Mozilla Firefox 2018-12-06 21:14 - 2018-10-23 18:43 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2018-12-06 21:14 - 2016-03-22 22:22 - 000000000 ____D C:\Program Files\WinRAR 2018-12-06 21:14 - 2016-03-22 10:12 - 000000000 ____D C:\Program Files\SUPERAntiSpyware 2018-12-06 21:12 - 2018-04-12 00:38 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12 2018-12-06 21:12 - 2018-04-12 00:38 - 000000000 ___SD C:\WINDOWS\system32\F12 2018-12-06 21:12 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\TextInput 2018-12-06 21:12 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences 2018-12-06 21:12 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\ShellExperiences 2018-12-06 21:12 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\bcastdvr 2018-12-06 21:08 - 2018-05-21 05:57 - 000003990 _____ C:\WINDOWS\System32\Tasks\Avast Emergency Update 2018-12-06 21:05 - 2017-11-13 07:50 - 000000000 ____D C:\Users\Florenci\AppData\Roaming\XnView 2018-12-06 21:05 - 2017-10-21 13:22 - 000000000 ____D C:\Users\Florenci\AppData\Local\Packages 2018-12-06 20:59 - 2018-04-12 00:38 - 000000000 ___HD C:\WINDOWS\ELAMBKUP 2018-12-06 20:56 - 2018-08-08 18:10 - 000003936 _____ C:\WINDOWS\System32\Tasks\CCleaner Update 2018-12-06 20:55 - 2018-09-29 07:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskInfo 2018-12-06 20:55 - 2018-09-29 07:08 - 000000000 ____D C:\Program Files (x86)\CrystalDiskInfo 2018-12-06 20:52 - 2017-10-29 21:10 - 000000983 _____ C:\Users\Florenci\Desktop\PerformanceTest.lnk 2018-12-06 20:52 - 2017-10-29 21:09 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PerformanceTest 2018-12-06 20:52 - 2017-10-29 20:37 - 000000000 ____D C:\Program Files\PerformanceTest 2018-12-06 20:46 - 2016-03-21 10:53 - 000000000 ____D C:\WINDOWS\system32\MRT 2018-12-06 20:45 - 2016-03-22 22:23 - 000001090 _____ C:\ProgramData\Microsoft\Windows\Start Menu\WinRAR.lnk 2018-12-06 20:45 - 2016-03-22 22:23 - 000001032 _____ C:\Users\Public\Desktop\WinRAR.lnk 2018-12-06 20:45 - 2016-03-22 22:23 - 000000000 ____D C:\Users\Florenci\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2018-12-06 20:45 - 2016-03-22 22:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR 2018-12-06 20:42 - 2016-03-21 10:53 - 137810048 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2018-12-06 20:17 - 2015-11-22 20:48 - 007194192 _____ (Stanislav Polshyn & Trend Micro Inc.) C:\Users\Florenci\Desktop\HiJackThis.exe 2018-12-06 20:03 - 2018-10-23 18:43 - 000001009 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk 2018-12-06 20:01 - 2018-10-19 19:59 - 000152688 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys 2018-12-06 20:00 - 2017-06-10 14:43 - 000002305 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2018-12-06 19:47 - 2016-03-21 10:55 - 000592416 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe ==================== Files in the root of some directories ======= 2017-11-22 18:59 - 2017-11-22 22:39 - 000000096 _____ () C:\Users\Florenci\AppData\Roaming\Camdata.ini 2017-11-22 18:59 - 2017-11-22 22:39 - 000000408 _____ () C:\Users\Florenci\AppData\Roaming\CamLayout.ini 2017-11-22 18:59 - 2017-11-22 22:39 - 000000408 _____ () C:\Users\Florenci\AppData\Roaming\CamShapes.ini 2017-11-22 18:59 - 2017-11-22 22:39 - 000004536 _____ () C:\Users\Florenci\AppData\Roaming\CamStudio.cfg 2017-11-22 18:56 - 2017-11-22 22:39 - 000000096 _____ () C:\Users\Florenci\AppData\Roaming\version2.xml ==================== Bamital & volsnap ====================== (There is no automatic fix for files that do not pass verification.) C:\WINDOWS\system32\winlogon.exe => File is digitally signed C:\WINDOWS\system32\wininit.exe => File is digitally signed C:\WINDOWS\explorer.exe => File is digitally signed C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed C:\WINDOWS\system32\svchost.exe => File is digitally signed C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed C:\WINDOWS\system32\services.exe => File is digitally signed C:\WINDOWS\system32\User32.dll => File is digitally signed C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed C:\WINDOWS\system32\userinit.exe => File is digitally signed C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed C:\WINDOWS\system32\rpcss.dll => File is digitally signed C:\WINDOWS\system32\dnsapi.dll => File is digitally signed C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2018-05-21 05:26 ==================== End of FRST.txt ============================