Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 25-11-2019 01 Ran by Marck (administrator) on MARCK-PC (ASUSTeK Computer Inc. K52F) (25-11-2019 17:53:10) Running from C:\Users\Marck\Downloads Loaded Profiles: Marck (Available Profiles: Marck) Platform: Windows 7 Home Basic (X64) Language: Español (España, internacional) Internet Explorer Version 8 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) () [File not signed] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe (ASUSTeK Computer Inc. -> ) C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe (ASUSTeK Computer Inc. -> ASUS) C:\Program Files (x86)\ASUS\ASUS CopyProtect\ASPG.exe (ASUSTeK Computer Inc. -> ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe (ASUSTeK Computer Inc. -> ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe (ASUSTeK Computer Inc. -> ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (ASUSTeK Computer Inc. -> ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (ASUSTeK Computer Inc. -> ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe (ASUSTeK Computer Inc. -> ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUSTeK Computer Inc. -> ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (ASUSTeK Computer Inc. -> ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUSTeK Computer Inc. -> asus) C:\Program Files (x86)\ASUS\ControlDeck\ControlDeck.exe (ASUSTeK Computer Inc. -> ASUS) C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe (ASUSTeK Computer Inc. -> ASUS) C:\Program Files (x86)\ASUS\SmartLogon\smartlogon.exe (ASUSTeK Computer Inc. -> ASUS) C:\Program Files\P4G\BatteryLife.exe (ASUSTeK Computer Inc. -> ASUS) C:\Windows\AsScrPro.exe (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) [File not signed] C:\Windows\System32\FBAgent.exe (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe (ASUSTek Computer Inc.) [File not signed] C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe (ASUSTeK) [File not signed] C:\Windows\SysWOW64\ACEngSvr.exe (ATK) [File not signed] C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Changzhou Jianzao 3D Technology Co., Ltd. -> Zbshareware Lab) C:\Program Files (x86)\USB Disk Security\USBGuard.exe (CyberLink -> ) [File not signed] C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe (CyberLink -> CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe (CyberLink -> CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (eCareme Technologies, Inc. -> ) C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe (ELAN Microelectronics Corporation -> ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronics Corporation -> ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.342\GoogleCrashHandler.exe (Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.342\GoogleCrashHandler64.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Intel Corporation -> Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation -> Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel Corporation -> Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) [File not signed] C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) [File not signed] C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation -> Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation -> Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (SRS Labs, Inc -> SRS Labs, Inc.) C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\SRSPremiumPanel_64.exe (SUPERAntiSpyware.com -> SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe (Support.com, Inc. -> SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe ==================== Registry (Whitelisted) =================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [ASUS WebStorage] => C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe [1754448 2010-03-15] (eCareme Technologies, Inc. -> ) HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SAIICpl.exe [307768 2009-11-19] (Conexant Systems, Inc. -> ) HKLM\...\Run: [ETDWare] => C:\Program Files\Elantech\ETDCtrl.exe [649608 2010-06-10] (ELAN Microelectronics Corporation -> ELAN Microelectronic Corp.) HKLM\...\Run: [Setwallpaper] => c:\programdata\SetWallpaper.cmd HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [268680 2019-11-22] (AVAST Software s.r.o. -> AVAST Software) HKLM-x32\...\Run: [UpdatePSTShortCut] => "C:\Program Files (x86)\Cyberlink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Cyberlink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter" HKLM-x32\...\Run: [UpdateLBPShortCut] => C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink -> CyberLink Corp.) HKLM-x32\...\Run: [UpdateP2GoShortCut] => C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink -> CyberLink Corp.) HKLM-x32\...\Run: [Microsoft Default Manager] => C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [439568 2010-05-10] (Microsoft Corporation -> Microsoft Corporation) HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-10-07] (ASUSTeK Computer Inc. -> ASUS) HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUSTeK Computer Inc. -> ASUS) HKLM-x32\...\Run: [Wireless Console 3] => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [1601536 2010-09-23] () [File not signed] HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\78.0.3904.108\Installer\chrmstp.exe [2019-11-22] (Google LLC -> Google LLC) HKLM\Software\...\Authentication\Credential Providers: [{06FE45A8-6D92-44ba-A0F1-9A9BCDC8F5A7}] -> C:\Program Files (x86)\ASUS\SmartLogon\system\FaceCredentialProvider64.dll [2009-06-19] (ASUSTeK Computer Inc. -> ASUS) HKLM\Software\...\Authentication\Credential Providers: [{2AD920F6-D745-4d8b-9526-619171C2CC4D}] -> C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x64\AdsmCredentialProvider.dll [2009-04-02] (ASUSTek Computer Inc.) [File not signed] HKLM\Software\...\Authentication\Credential Providers: [{455BD3EC-20A5-44c3-8D77-396909825B5E}] -> C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x64\AdsmCredentialProvider.dll [2009-04-02] (ASUSTek Computer Inc.) [File not signed] HKLM\Software\...\Authentication\Credential Providers: [{F8A0B131-5F68-486c-8040-7E8FC3C85BB6}] -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDCREDPROV.DLL [2010-09-21] (Microsoft Corporation -> Microsoft Corp.) HKLM\Software\...\Authentication\Credential Provider Filters: [{120495C2-9E38-48a2-A08B-C302F7487628}] -> C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x64\AdsmCredentialProvider.dll [2009-04-02] (ASUSTek Computer Inc.) [File not signed] Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FancyStart daemon.lnk [2011-01-06] ShortcutTarget: FancyStart daemon.lnk -> C:\Windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_C4A2FC3E3722966204FDD8.exe () [File not signed] Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SRS Premium Sound.lnk [2011-01-06] ShortcutTarget: SRS Premium Sound.lnk -> C:\Windows\Installer\{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}\NewShortcut5_21C7B668029A47458B27645FE6E4A715.exe (SRS Labs, Inc -> Acresso Software Inc.) FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION ==================== Scheduled Tasks (Whitelisted) ============ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {0570252F-B519-4580-BABC-1EA200084A60} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [1642672 2012-10-01] (Microsoft Corporation -> Microsoft Corporation) Task: {1D8F49A2-2360-4E5F-B529-43DB575ED90D} - System32\Tasks\ASPG => C:\Program Files (x86)\ASUS\ASUS CopyProtect\aspg.exe [163384 2009-06-29] (ASUSTeK Computer Inc. -> ASUS) Task: {2ED41BDE-FB59-4CF7-96DC-100A3372F7B8} - System32\Tasks\SUPERAntiSpyware Scheduled Task a136f9bc-3569-478d-b16e-6f4b3641250b => C:\Program Files\SUPERAntiSpyware\SASTask.exe [49944 2013-11-07] (SUPERAntiSpyware.com -> SUPERAdBlocker.com) Task: {31A9ED92-5669-4D9B-B414-C4446C6894A1} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [155432 2019-11-22] (Google Inc -> Google LLC) Task: {33DB99EA-05F7-4228-9BA3-15F8953A5EB5} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe [305720 2009-07-31] (ASUSTeK Computer Inc. -> ASUS) Task: {344C577F-CCCF-4D16-BB4B-5A93C755D082} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task => {3519154C-227E-47F3-9CC9-12C3F05817F1} Task: {5E9742DB-638A-46DC-B91B-3AD0DC01FE42} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [1873288 2019-11-22] (AVAST Software s.r.o. -> AVAST Software) Task: {61EC8B99-45D4-423C-9ED5-80A227BFFDDD} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [375416 2012-10-01] (Microsoft Corporation -> Microsoft Corporation) Task: {714BF0CD-2D03-486C-B9E6-2F0EDFF1AB21} - System32\Tasks\ASUS Live Update => C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe [51768 2007-11-30] (ASUSTeK Computer Inc. -> ) Task: {9557429A-5CC4-4A92-8DE4-927DDF224858} - System32\Tasks\ASUS P4G => C:\Program Files\P4G\BatteryLife.exe [976512 2010-11-10] (ASUSTeK Computer Inc. -> ASUS) Task: {A0A9D07A-DE12-4B15-929C-C430CA9DF297} - System32\Tasks\ASUSControlDeck => C:\Program Files (x86)\ASUS\ControlDeck\ControlDeck.exe [1078912 2010-09-30] (ASUSTeK Computer Inc. -> asus) Task: {BE14B1B0-FC95-4DA4-B6B4-A2567AF915B4} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [375416 2012-10-01] (Microsoft Corporation -> Microsoft Corporation) Task: {BF8FCD6C-9D17-4AFC-94D1-248F60E20F23} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [3933576 2019-11-22] (AVAST Software s.r.o. -> AVAST Software) Task: {C1181235-C472-416D-928E-67248D43D94A} - System32\Tasks\SUPERAntiSpyware Scheduled Task 30dd5486-d1d6-4865-8529-baf2e14004fc => C:\Program Files\SUPERAntiSpyware\SASTask.exe [49944 2013-11-07] (SUPERAntiSpyware.com -> SUPERAdBlocker.com) Task: {CC331870-A895-41F8-8C1A-2FE44C71E99C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [155432 2019-11-22] (Google Inc -> Google LLC) Task: {D1C4C6ED-F45B-4B90-9AF3-AE2DAB6D38C9} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS\AutoKMS.exe [3738624 2019-11-22] () [File not signed] Task: {D981A855-7D1F-4730-83E4-3A58B6F06449} - System32\Tasks\ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [684544 2009-07-23] (ATK) [File not signed] Task: {DF30248B-5E35-456F-9E65-AC4F0AFC8C9A} - System32\Tasks\ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [5732992 2010-08-17] (ASUSTeK Computer Inc. -> ASUS) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 30dd5486-d1d6-4865-8529-baf2e14004fc.job => C:\Program Files\SUPERAntiSpyware\SASTask.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe Task: C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task a136f9bc-3569-478d-b16e-6f4b3641250b.job => C:\Program Files\SUPERAntiSpyware\SASTask.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Winsock: Catalog5 07 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280 2010-09-21] (Microsoft Corporation -> Microsoft Corp.) Winsock: Catalog5 08 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280 2010-09-21] (Microsoft Corporation -> Microsoft Corp.) Winsock: Catalog5-x64 07 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [170880 2010-09-21] (Microsoft Corporation -> Microsoft Corp.) Winsock: Catalog5-x64 08 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [170880 2010-09-21] (Microsoft Corporation -> Microsoft Corp.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.254 Tcpip\..\Interfaces\{3BE8A351-B637-42EA-9EBB-1A7164B67EDD}: [DhcpNameServer] 13.5.0.10 Tcpip\..\Interfaces\{6CF744D2-0680-4731-9B7B-F8AE4A893C3A}: [DhcpNameServer] 192.168.1.254 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://asus.msn.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://asus.msn.com HKU\S-1-5-21-163947046-543606460-1708271080-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://linkzb.com HKU\S-1-5-21-163947046-543606460-1708271080-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus.msn.com SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=MAAU&src=IE-SearchBox SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=MAAU&src=IE-SearchBox SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=MAAU&src=IE-SearchBox SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=MAAU&src=IE-SearchBox SearchScopes: HKLM-x32 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUT SearchScopes: HKU\S-1-5-21-163947046-543606460-1708271080-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-163947046-543606460-1708271080-1000 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = SearchScopes: HKU\S-1-5-21-163947046-543606460-1708271080-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2012-10-01] (Microsoft Corporation -> Microsoft Corporation) BHO: Partner BHO Class -> {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} -> C:\ProgramData\Partner\Partner64.dll [2011-01-06] (Google Inc -> Google Inc.) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corporation -> Microsoft Corp.) BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2011-01-06] (Google Inc -> Google Inc.) BHO: Google Toolbar Notifier BHO -> {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -> C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg64.dll [2011-01-06] (Google Inc -> Google Inc.) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation -> Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation -> Microsoft Corporation) BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2012-10-01] (Microsoft Corporation -> Microsoft Corporation) BHO-x32: Search Helper -> {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} -> C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2010-07-27] (Microsoft Corporation -> Microsoft Corporation) BHO-x32: Partner BHO Class -> {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} -> C:\ProgramData\Partner\Partner.dll [2011-01-06] (Google Inc -> Google Inc.) BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corporation -> Microsoft Corp.) BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2010-09-23] (Microsoft Corporation -> Microsoft Corporation) BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2011-01-06] (Google Inc -> Google Inc.) BHO-x32: Google Toolbar Notifier BHO -> {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -> C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll [2011-01-06] (Google Inc -> Google Inc.) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation -> Microsoft Corporation) BHO-x32: Google Dictionary Compression sdch -> {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} -> C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll [2011-01-06] (Google Inc -> Google Inc.) BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation -> Microsoft Corporation) BHO-x32: Bing Bar BHO -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll [2010-08-13] (Microsoft Corporation -> Microsoft Corporation) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2011-01-06] (Google Inc -> Google Inc.) Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2011-01-06] (Google Inc -> Google Inc.) Toolbar: HKLM-x32 - @C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll [2010-08-13] (Microsoft Corporation -> Microsoft Corporation) Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2012-10-01] (Microsoft Corporation -> Microsoft Corporation) Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2011-01-06] (Microsoft Windows -> Microsoft Corporation) Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2011-01-06] (Microsoft Windows -> Microsoft Corporation) Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2011-01-06] (Microsoft Windows -> Microsoft Corporation) Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2011-01-06] (Microsoft Windows -> Microsoft Corporation) FireFox: ======== FF HKLM-x32\...\Firefox\Extensions: [msntoolbar@msn.com] - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\Firefox FF Extension: (Bing Bar) - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\Firefox [2011-01-06] [Legacy] [not signed] FF HKLM-x32\...\Firefox\Extensions: [{27182e60-b5f3-411c-b545-b44205977502}] - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension FF Extension: (Search Helper Extension) - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension [2011-01-06] [Legacy] [not signed] FF HKLM-x32\...\Firefox\Extensions: [{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}] - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension FF Extension: (Default Manager) - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension [2011-01-06] [Legacy] [not signed] FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32.dll [No File] FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2012-10-01] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll [2010-04-01] ( Microsoft Corporation) [File not signed] FF Plugin-x32: @Microsoft.com/NpWinExt,version=5.0 -> C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll [2010-08-13] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-09-23] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.35.342\npGoogleUpdate3.dll [2019-11-22] (Google Inc -> Google LLC) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.35.342\npGoogleUpdate3.dll [2019-11-22] (Google Inc -> Google LLC) Chrome: ======= CHR HomePage: Default -> hxxp://www.google.com/ig/redirectdomain?brand=ASUT&bmod=ASUT CHR Profile: C:\Users\Marck\AppData\Local\Google\Chrome\User Data\Default [2019-11-25] CHR Extension: (Presentaciones) - C:\Users\Marck\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-11-22] CHR Extension: (Earth and Moon) - C:\Users\Marck\AppData\Local\Google\Chrome\User Data\Default\Extensions\afmfhbdfjlfminjglfhcgcblgicnfcka [2019-11-22] CHR Extension: (Documentos) - C:\Users\Marck\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-11-22] CHR Extension: (Google Drive) - C:\Users\Marck\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2019-11-22] CHR Extension: (YouTube) - C:\Users\Marck\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-11-22] CHR Extension: (Avast SafePrice | Comparaciones, ofertas y cupones) - C:\Users\Marck\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2019-11-23] CHR Extension: (Hojas de cálculo) - C:\Users\Marck\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-11-22] CHR Extension: (Documentos de Google sin conexión) - C:\Users\Marck\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2019-11-22] CHR Extension: (Avast Online Security) - C:\Users\Marck\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2019-11-22] CHR Extension: (Sistema de pagos de Chrome Web Store) - C:\Users\Marck\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-11-22] CHR Extension: (Gmail) - C:\Users\Marck\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-11-22] CHR Extension: (Chrome Media Router) - C:\Users\Marck\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-11-22] CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] ==================== Services (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [173472 2017-01-30] (SUPERAntiSpyware.com -> SUPERAntiSpyware.com) R3 ADSMService; C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe [225280 2008-03-31] (ASUSTek Computer Inc.) [File not signed] R2 AFBAgent; C:\Windows\system32\FBAgent.exe [377264 2010-09-30] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) [File not signed] S3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [6085360 2019-11-22] (AVAST Software s.r.o. -> AVAST Software) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [996880 2019-11-22] (AVAST Software s.r.o. -> AVAST Software) R2 LMS; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [262144 2009-09-30] (Intel Corporation) [File not signed] R3 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2010-04-06] (CyberLink -> ) [File not signed] R2 UNS; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2314240 2009-09-30] (Intel Corporation) [File not signed] S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-13] (Microsoft Windows -> Microsoft Corporation) R2 wlidsvc; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2286976 2010-09-21] (Microsoft Corporation -> Microsoft Corp.) ===================== Drivers (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R0 aswArDisk; C:\Windows\System32\drivers\aswArDisk.sys [37616 2019-11-22] (AVAST Software s.r.o. -> AVAST Software) R1 aswArPot; C:\Windows\System32\drivers\aswArPot.sys [204824 2019-11-22] (AVAST Software s.r.o. -> AVAST Software) R1 aswbidsdriver; C:\Windows\System32\drivers\aswbidsdriver.sys [274456 2019-11-22] (AVAST Software s.r.o. -> AVAST Software) R0 aswbidsh; C:\Windows\System32\drivers\aswbidsh.sys [209552 2019-11-22] (AVAST Software s.r.o. -> AVAST Software) R0 aswbuniv; C:\Windows\System32\drivers\aswbuniv.sys [65120 2019-11-22] (AVAST Software s.r.o. -> AVAST Software) R1 aswHdsKe; C:\Windows\System32\drivers\aswHdsKe.sys [276952 2019-11-22] (AVAST Software s.r.o. -> AVAST Software) R1 aswKbd; C:\Windows\System32\drivers\aswKbd.sys [42736 2019-11-22] (AVAST Software s.r.o. -> AVAST Software) R2 aswMonFlt; C:\Windows\System32\drivers\aswMonFlt.sys [171520 2019-11-22] (AVAST Software s.r.o. -> AVAST Software) R1 aswRdr; C:\Windows\System32\drivers\aswRdr2.sys [110320 2019-11-22] (AVAST Software s.r.o. -> AVAST Software) R0 aswRvrt; C:\Windows\System32\drivers\aswRvrt.sys [83792 2019-11-22] (AVAST Software s.r.o. -> AVAST Software) R1 aswSnx; C:\Windows\System32\drivers\aswSnx.sys [848432 2019-11-22] (AVAST Software s.r.o. -> AVAST Software) R1 aswSP; C:\Windows\System32\drivers\aswSP.sys [460448 2019-11-22] (AVAST Software s.r.o. -> AVAST Software) S2 aswStm; C:\Windows\System32\drivers\aswStm.sys [236024 2019-11-22] (AVAST Software s.r.o. -> AVAST Software) R0 aswVmm; C:\Windows\System32\drivers\aswVmm.sys [316528 2019-11-22] (AVAST Software s.r.o. -> AVAST Software) R3 athr; C:\Windows\System32\DRIVERS\athrx.sys [1594368 2010-03-02] (Microsoft Windows Hardware Compatibility Publisher -> Atheros Communications, Inc.) R3 ETD; C:\Windows\System32\DRIVERS\ETD.sys [129024 2010-09-08] (Microsoft Windows Hardware Compatibility Publisher -> ELAN Microelectronic Corp.) R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] (ASUSTeK Computer Inc. -> ) R0 lullaby; C:\Windows\System32\DRIVERS\lullaby.sys [15928 2009-06-18] (ASUSTeK Computer Inc. -> Windows (R) Win 7 DDK provider) R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (Support.com, Inc. -> SUPERAdBlocker.com and SUPERAntiSpyware.com) R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (Support.com, Inc. -> SUPERAdBlocker.com and SUPERAntiSpyware.com) S3 SiSGbeLH; C:\Windows\System32\DRIVERS\SiSG664.sys [56832 2009-06-10] (Microsoft Windows -> Silicon Integrated Systems Corp.) R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1800192 2009-08-19] (Microsoft Windows Hardware Compatibility Publisher -> ) U3 tmlwf; no ImagePath U3 tmwfp; no ImagePath ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One month (created) =================== (If an entry is included in the fixlist, the file/folder will be moved.) 2019-11-25 17:53 - 2019-11-25 17:54 - 000033203 _____ C:\Users\Marck\Downloads\FRST.txt 2019-11-25 17:51 - 2019-11-25 17:53 - 000000000 ____D C:\FRST 2019-11-25 17:48 - 2019-11-25 17:49 - 002262016 _____ (Farbar) C:\Users\Marck\Downloads\FRST64.exe 2019-11-24 12:09 - 2013-03-27 23:32 - 000177664 _____ (Xerox Corporation) C:\Windows\system32\xrhkazil.dll 2019-11-22 17:22 - 2019-11-22 17:22 - 000000000 ____D C:\Users\Marck\AppData\Roaming\Google 2019-11-22 17:17 - 2019-11-25 17:28 - 000003758 _____ C:\Windows\system32\Tasks\AutoKMS 2019-11-22 17:17 - 2019-11-24 12:06 - 000000000 ____D C:\Windows\AutoKMS 2019-11-22 17:16 - 2019-11-22 17:16 - 000000000 ____D C:\ProgramData\Microsoft Toolkit 2019-11-22 17:09 - 2019-11-22 17:10 - 005654538 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2019-11-22 17:07 - 2009-11-25 11:47 - 001942856 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll 2019-11-22 17:07 - 2009-11-25 11:47 - 001130824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dfshim.dll 2019-11-22 17:07 - 2009-11-25 11:47 - 000444752 _____ (Microsoft Corporation) C:\Windows\system32\mscoree.dll 2019-11-22 17:07 - 2009-11-25 11:47 - 000320352 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHost.exe 2019-11-22 17:07 - 2009-11-25 11:47 - 000297808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscoree.dll 2019-11-22 17:07 - 2009-11-25 11:47 - 000295264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationHost.exe 2019-11-22 17:07 - 2009-11-25 11:47 - 000109912 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHostProxy.dll 2019-11-22 17:07 - 2009-11-25 11:47 - 000099176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationHostProxy.dll 2019-11-22 17:07 - 2009-11-25 11:47 - 000049472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netfxperf.dll 2019-11-22 17:07 - 2009-11-25 11:47 - 000048960 _____ (Microsoft Corporation) C:\Windows\system32\netfxperf.dll 2019-11-22 17:05 - 2019-11-22 17:05 - 001005568 _____ (Microsoft Corporation) C:\Users\Marck\Downloads\dotNetFx45_Full_setup.exe 2019-11-22 16:56 - 2019-11-22 16:56 - 000000000 ____D C:\Windows\system32\Tasks\OfficeSoftwareProtectionPlatform 2019-11-22 16:55 - 2019-11-22 16:55 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013 2019-11-22 16:54 - 2019-11-22 16:54 - 000000000 ____D C:\Program Files\Common Files\DESIGNER 2019-11-22 16:53 - 2019-11-22 16:53 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2019-11-22 16:53 - 2019-11-22 16:53 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox 2019-11-22 16:53 - 2019-11-22 16:53 - 000000000 ____D C:\Program Files (x86)\Microsoft SQL Server 2019-11-22 16:52 - 2019-11-22 16:53 - 000000000 ____D C:\Program Files\Microsoft SQL Server 2019-11-22 16:50 - 2019-11-22 16:54 - 000000000 ____D C:\Windows\SHELLNEW 2019-11-22 16:50 - 2019-11-22 16:52 - 000000000 ____D C:\Program Files\Microsoft Office 2019-11-22 16:50 - 2019-11-22 16:50 - 000000000 ____D C:\Users\Marck\AppData\Local\Microsoft Help 2019-11-22 16:50 - 2019-11-22 16:50 - 000000000 ____D C:\Program Files\Microsoft Analysis Services 2019-11-22 16:50 - 2019-11-22 16:50 - 000000000 ____D C:\Program Files (x86)\Microsoft Analysis Services 2019-11-22 16:49 - 2019-11-22 16:49 - 000000000 __RHD C:\MSOCache 2019-11-22 16:46 - 2019-11-22 16:46 - 000000000 ____D C:\Users\Marck\AppData\Roaming\WinRAR 2019-11-22 16:45 - 2019-11-22 16:45 - 000000000 ____D C:\Users\Marck\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2019-11-22 16:45 - 2019-11-22 16:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR 2019-11-22 16:45 - 2019-11-22 16:45 - 000000000 ____D C:\Program Files\WinRAR 2019-11-22 16:18 - 2019-11-22 16:18 - 000001072 _____ C:\Users\Public\Desktop\USB Disk Security.lnk 2019-11-22 16:18 - 2019-11-22 16:18 - 000001072 _____ C:\ProgramData\Desktop\USB Disk Security.lnk 2019-11-22 16:18 - 2019-11-22 16:18 - 000001060 _____ C:\Users\Public\Desktop\Web Navigation.lnk 2019-11-22 16:18 - 2019-11-22 16:18 - 000001060 _____ C:\ProgramData\Desktop\Web Navigation.lnk 2019-11-22 16:18 - 2019-11-22 16:18 - 000000000 ____D C:\Users\Marck\AppData\Roaming\Zbshareware Lab 2019-11-22 16:18 - 2019-11-22 16:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\USB Disk Security 2019-11-22 16:18 - 2019-11-22 16:18 - 000000000 ____D C:\Program Files (x86)\USB Disk Security 2019-11-22 16:17 - 2019-11-22 16:17 - 004050520 _____ (Zbshareware Lab ) C:\Users\Marck\Downloads\USBGuardSetup6.7.exe 2019-11-22 15:42 - 2006-05-13 10:22 - 000000005 _____ C:\Pass.txt 2019-11-22 14:39 - 2019-11-25 17:10 - 000000510 _____ C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task a136f9bc-3569-478d-b16e-6f4b3641250b.job 2019-11-22 14:39 - 2019-11-25 17:10 - 000000510 _____ C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 30dd5486-d1d6-4865-8529-baf2e14004fc.job 2019-11-22 14:39 - 2019-11-22 14:39 - 000003584 _____ C:\Windows\system32\Tasks\SUPERAntiSpyware Scheduled Task 30dd5486-d1d6-4865-8529-baf2e14004fc 2019-11-22 14:39 - 2019-11-22 14:39 - 000003510 _____ C:\Windows\system32\Tasks\SUPERAntiSpyware Scheduled Task a136f9bc-3569-478d-b16e-6f4b3641250b 2019-11-22 14:38 - 2019-11-22 14:38 - 000001810 _____ C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk 2019-11-22 14:38 - 2019-11-22 14:38 - 000001810 _____ C:\ProgramData\Desktop\SUPERAntiSpyware Free Edition.lnk 2019-11-22 14:38 - 2019-11-22 14:38 - 000000000 ____D C:\Users\Marck\AppData\Roaming\SUPERAntiSpyware.com 2019-11-22 14:38 - 2019-11-22 14:38 - 000000000 ____D C:\ProgramData\SUPERAntiSpyware.com 2019-11-22 14:38 - 2019-11-22 14:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware 2019-11-22 14:38 - 2019-11-22 14:38 - 000000000 ____D C:\Program Files\SUPERAntiSpyware 2019-11-22 14:35 - 2019-11-22 14:36 - 043201528 _____ (SUPERAntiSpyware) C:\Users\Marck\Downloads\SUPERAntiSpyware.exe 2019-11-22 14:10 - 2019-11-22 14:10 - 000002077 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk 2019-11-22 14:10 - 2019-11-22 14:10 - 000002077 _____ C:\ProgramData\Desktop\Avast Free Antivirus.lnk 2019-11-22 14:10 - 2019-11-22 14:10 - 000000000 ____D C:\Users\Marck\AppData\Roaming\AVAST Software 2019-11-22 14:10 - 2019-11-22 14:10 - 000000000 ____D C:\Users\Marck\AppData\Local\CEF 2019-11-22 14:10 - 2019-11-22 14:10 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software 2019-11-22 14:08 - 2019-11-22 14:08 - 000000000 ____D C:\Windows\system32\Tasks\Avast Software 2019-11-22 14:08 - 2019-11-22 14:08 - 000000000 _____ C:\Windows\SysWOW64\Drivers\1043_ASUSTeK_K52F.alu 2019-11-22 14:07 - 2019-11-24 12:08 - 000004168 _____ C:\Windows\system32\Tasks\Avast Emergency Update 2019-11-22 14:07 - 2019-11-22 14:07 - 000848432 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2019-11-22 14:07 - 2019-11-22 14:07 - 000460448 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2019-11-22 14:07 - 2019-11-22 14:07 - 000355720 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2019-11-22 14:07 - 2019-11-22 14:07 - 000316528 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys 2019-11-22 14:07 - 2019-11-22 14:07 - 000276952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHdsKe.sys 2019-11-22 14:07 - 2019-11-22 14:07 - 000274456 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbidsdriver.sys 2019-11-22 14:07 - 2019-11-22 14:07 - 000236024 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys 2019-11-22 14:07 - 2019-11-22 14:07 - 000209552 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbidsh.sys 2019-11-22 14:07 - 2019-11-22 14:07 - 000204824 _____ (AVAST Software) C:\Windows\system32\Drivers\aswArPot.sys 2019-11-22 14:07 - 2019-11-22 14:07 - 000171520 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2019-11-22 14:07 - 2019-11-22 14:07 - 000110320 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2019-11-22 14:07 - 2019-11-22 14:07 - 000083792 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys 2019-11-22 14:07 - 2019-11-22 14:07 - 000065120 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbuniv.sys 2019-11-22 14:07 - 2019-11-22 14:07 - 000042736 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys 2019-11-22 14:07 - 2019-11-22 14:07 - 000037616 _____ (AVAST Software) C:\Windows\system32\Drivers\aswArDisk.sys 2019-11-22 14:07 - 2019-11-22 14:07 - 000000000 ____D C:\Program Files\Common Files\AVAST Software 2019-11-22 14:05 - 2019-11-22 14:07 - 000000000 ____D C:\ProgramData\AVAST Software 2019-11-22 14:05 - 2019-11-22 14:05 - 000000000 ____D C:\Program Files\AVAST Software 2019-11-22 14:04 - 2019-11-22 14:04 - 000228544 _____ (AVAST Software) C:\Users\Marck\Downloads\avast_free_antivirus_setup_online2.exe 2019-11-22 14:03 - 2019-11-22 15:28 - 000002255 _____ C:\Users\Marck\Desktop\Google Chrome.lnk 2019-11-22 14:00 - 2019-11-22 14:00 - 000000000 ____D C:\Users\Marck\AppData\Roaming\Adobe 2019-11-22 13:59 - 2019-11-22 13:59 - 000000000 ____D C:\Users\Marck\AppData\LocalLow\Google 2019-11-22 13:58 - 2019-11-22 13:59 - 000000000 ____D C:\Users\Marck\Desktop\Asus 2019-11-22 13:56 - 2019-11-22 14:24 - 000000000 ____D C:\Users\Marck\AppData\Local\Google 2019-11-22 13:53 - 2012-06-02 16:19 - 002428952 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2019-11-22 13:53 - 2012-06-02 16:19 - 000701976 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2019-11-22 13:53 - 2012-06-02 16:19 - 000057880 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2019-11-22 13:53 - 2012-06-02 16:19 - 000044056 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2019-11-22 13:53 - 2012-06-02 16:19 - 000038424 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2019-11-22 13:53 - 2012-06-02 16:15 - 002622464 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2019-11-22 13:53 - 2012-06-02 16:15 - 000099840 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2019-11-22 13:53 - 2012-06-02 15:19 - 000186752 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2019-11-22 13:53 - 2012-06-02 15:15 - 000036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2019-11-22 13:52 - 2019-11-22 13:52 - 000000000 ____D C:\Users\Marck\Documents\ASUS WebStorage 2019-11-22 13:52 - 2019-11-22 13:52 - 000000000 ____D C:\Users\Marck\AppData\Roaming\Asus WebStorage 2019-11-22 13:52 - 2019-11-22 13:52 - 000000000 ____D C:\Users\Marck\AppData\Local\SRS Labs 2019-11-22 13:51 - 2019-11-22 13:51 - 000001395 _____ C:\Users\Marck\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk 2019-11-22 13:50 - 2019-11-22 17:13 - 000116608 _____ C:\Users\Marck\AppData\Local\GDIPFONTCACHEV1.DAT 2019-11-22 13:50 - 2019-11-22 13:52 - 000000000 ___HD C:\ASUS.DAT 2019-11-22 13:50 - 2019-11-22 13:51 - 000001429 _____ C:\Users\Marck\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2019-11-22 13:49 - 2019-11-22 13:50 - 000000000 ____D C:\Users\Marck 2019-11-22 13:49 - 2019-11-22 13:49 - 000000020 ___SH C:\Users\Marck\ntuser.ini 2019-11-22 13:49 - 2019-11-22 13:49 - 000000000 _SHDL C:\Users\Marck\Reciente 2019-11-22 13:49 - 2019-11-22 13:49 - 000000000 _SHDL C:\Users\Marck\Plantillas 2019-11-22 13:49 - 2019-11-22 13:49 - 000000000 _SHDL C:\Users\Marck\Mis documentos 2019-11-22 13:49 - 2019-11-22 13:49 - 000000000 _SHDL C:\Users\Marck\Menú Inicio 2019-11-22 13:49 - 2019-11-22 13:49 - 000000000 _SHDL C:\Users\Marck\Impresoras 2019-11-22 13:49 - 2019-11-22 13:49 - 000000000 _SHDL C:\Users\Marck\Entorno de red 2019-11-22 13:49 - 2019-11-22 13:49 - 000000000 _SHDL C:\Users\Marck\Documents\Mis vídeos 2019-11-22 13:49 - 2019-11-22 13:49 - 000000000 _SHDL C:\Users\Marck\Documents\Mis imágenes 2019-11-22 13:49 - 2019-11-22 13:49 - 000000000 _SHDL C:\Users\Marck\Documents\Mi música 2019-11-22 13:49 - 2019-11-22 13:49 - 000000000 _SHDL C:\Users\Marck\Datos de programa 2019-11-22 13:49 - 2019-11-22 13:49 - 000000000 _SHDL C:\Users\Marck\Configuración local 2019-11-22 13:49 - 2019-11-22 13:49 - 000000000 _SHDL C:\Users\Marck\AppData\Roaming\Microsoft\Windows\Start Menu\Programas 2019-11-22 13:49 - 2019-11-22 13:49 - 000000000 _SHDL C:\Users\Marck\AppData\Local\Historial 2019-11-22 13:49 - 2019-11-22 13:49 - 000000000 _SHDL C:\Users\Marck\AppData\Local\Datos de programa 2019-11-22 13:49 - 2019-11-22 13:49 - 000000000 _SHDL C:\Users\Marck\AppData\Local\Archivos temporales de Internet 2019-11-22 13:49 - 2019-11-22 13:49 - 000000000 ____D C:\Users\Marck\AppData\Local\VirtualStore 2019-11-22 13:49 - 2019-11-22 13:49 - 000000000 ____D C:\Users\Marck\AppData\Local\Power2Go 2019-11-22 13:49 - 2011-01-06 04:25 - 000000000 ____D C:\Users\Marck\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink Blu-ray Disc Suite 2019-11-22 13:49 - 2011-01-06 04:23 - 000000000 ____D C:\Users\Marck\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASUS Video Magic ==================== One month (modified) ================== (If an entry is included in the fixlist, the file/folder will be moved.) 2019-11-25 17:32 - 2009-07-13 22:45 - 000010016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2019-11-25 17:32 - 2009-07-13 22:45 - 000010016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2019-11-24 12:09 - 2009-07-13 21:20 - 000000000 ____D C:\Windows\inf 2019-11-24 12:06 - 2009-07-13 23:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2019-11-22 19:07 - 2009-07-13 21:20 - 000000000 ____D C:\Windows\rescache 2019-11-22 19:00 - 2009-07-13 23:37 - 000000000 ____D C:\Windows\system32\WCN 2019-11-22 18:58 - 2009-08-03 22:28 - 000000000 ____D C:\Windows\SysWOW64\XPSViewer 2019-11-22 18:58 - 2009-07-13 23:37 - 000000000 ____D C:\Windows\SysWOW64\winrm 2019-11-22 18:58 - 2009-07-13 23:37 - 000000000 ____D C:\Windows\SysWOW64\WCN 2019-11-22 18:58 - 2009-07-13 23:37 - 000000000 ____D C:\Windows\SysWOW64\sysprep 2019-11-22 18:58 - 2009-07-13 23:37 - 000000000 ____D C:\Windows\SysWOW64\Printing_Admin_Scripts 2019-11-22 18:58 - 2009-07-13 23:37 - 000000000 ____D C:\Windows\system32\winrm 2019-11-22 18:58 - 2009-07-13 23:37 - 000000000 ____D C:\Windows\system32\Printing_Admin_Scripts 2019-11-22 18:58 - 2009-07-13 23:32 - 000000000 ____D C:\Program Files\Windows Sidebar 2019-11-22 18:58 - 2009-07-13 23:32 - 000000000 ____D C:\Program Files\Windows Photo Viewer 2019-11-22 18:58 - 2009-07-13 23:32 - 000000000 ____D C:\Program Files\Windows Defender 2019-11-22 18:58 - 2009-07-13 23:32 - 000000000 ____D C:\Program Files\DVD Maker 2019-11-22 18:58 - 2009-07-13 23:32 - 000000000 ____D C:\Program Files (x86)\Windows Sidebar 2019-11-22 18:58 - 2009-07-13 23:32 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer 2019-11-22 18:58 - 2009-07-13 23:32 - 000000000 ____D C:\Program Files (x86)\Windows Defender 2019-11-22 18:58 - 2009-07-13 21:20 - 000000000 ____D C:\Windows\SysWOW64\Setup 2019-11-22 18:58 - 2009-07-13 21:20 - 000000000 ____D C:\Windows\SysWOW64\oobe 2019-11-22 18:58 - 2009-07-13 21:20 - 000000000 ____D C:\Windows\SysWOW64\MUI 2019-11-22 18:58 - 2009-07-13 21:20 - 000000000 ____D C:\Windows\SysWOW64\migwiz 2019-11-22 18:58 - 2009-07-13 21:20 - 000000000 ____D C:\Windows\SysWOW64\Dism 2019-11-22 18:58 - 2009-07-13 21:20 - 000000000 ____D C:\Windows\SysWOW64\com 2019-11-22 18:58 - 2009-07-13 21:20 - 000000000 ____D C:\Windows\system32\sysprep 2019-11-22 18:58 - 2009-07-13 21:20 - 000000000 ____D C:\Windows\system32\Setup 2019-11-22 18:58 - 2009-07-13 21:20 - 000000000 ____D C:\Windows\system32\oobe 2019-11-22 18:58 - 2009-07-13 21:20 - 000000000 ____D C:\Windows\system32\MUI 2019-11-22 18:58 - 2009-07-13 21:20 - 000000000 ____D C:\Windows\system32\migwiz 2019-11-22 18:58 - 2009-07-13 21:20 - 000000000 ____D C:\Windows\system32\Dism 2019-11-22 18:58 - 2009-07-13 21:20 - 000000000 ____D C:\Windows\system32\com 2019-11-22 18:58 - 2009-07-13 21:20 - 000000000 ____D C:\Windows\servicing 2019-11-22 18:58 - 2009-07-13 21:20 - 000000000 ____D C:\Program Files\Common Files\System 2019-11-22 18:56 - 2009-07-13 23:37 - 000000000 ____D C:\Windows\SysWOW64\slmgr 2019-11-22 18:56 - 2009-07-13 23:37 - 000000000 ____D C:\Windows\system32\slmgr 2019-11-22 18:56 - 2009-07-13 21:20 - 000000000 ____D C:\Windows\PolicyDefinitions 2019-11-22 18:56 - 2009-07-13 21:20 - 000000000 ____D C:\Windows\IME 2019-11-22 17:12 - 2011-01-06 05:00 - 000001734 _____ C:\Windows\system32\AutoRunFilter.ini 2019-11-22 17:12 - 2009-07-13 22:45 - 000443504 _____ C:\Windows\system32\FNTCACHE.DAT 2019-11-22 17:10 - 2009-08-03 22:47 - 000648070 _____ C:\Windows\system32\perfh01F.dat 2019-11-22 17:10 - 2009-08-03 22:47 - 000139452 _____ C:\Windows\system32\perfc01F.dat 2019-11-22 17:10 - 2009-08-03 22:41 - 000705268 _____ C:\Windows\system32\prfh0416.dat 2019-11-22 17:10 - 2009-08-03 22:41 - 000147108 _____ C:\Windows\system32\prfc0416.dat 2019-11-22 17:10 - 2009-08-03 22:28 - 000747230 _____ C:\Windows\system32\perfh00A.dat 2019-11-22 17:10 - 2009-08-03 22:28 - 000158670 _____ C:\Windows\system32\perfc00A.dat 2019-11-22 17:10 - 2009-07-13 23:13 - 005654538 _____ C:\Windows\system32\PerfStringBackup.INI 2019-11-22 16:54 - 2009-07-13 21:20 - 000000000 ____D C:\Program Files\Common Files\Microsoft Shared 2019-11-22 16:52 - 2011-01-06 04:15 - 000000000 ____D C:\Program Files (x86)\Microsoft Office 2019-11-22 16:51 - 2009-07-13 20:34 - 000000478 _____ C:\Windows\win.ini 2019-11-22 15:29 - 2011-01-06 05:00 - 000001146 _____ C:\Windows\system32\ServiceFilter.ini 2019-11-22 15:29 - 2009-07-13 23:09 - 000000000 ____D C:\Windows\system32\Tasks\WPD 2019-11-22 14:03 - 2011-01-06 04:25 - 000002296 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2019-11-22 14:03 - 2011-01-06 04:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2019-11-22 13:55 - 2011-01-06 04:41 - 000000824 _____ C:\Windows\system32\Drivers\etc\tmvsthfud.bin 2019-11-22 13:55 - 2011-01-06 04:41 - 000000824 _____ C:\Windows\system32\Drivers\etc\tmvsthfss.bin 2019-11-22 13:53 - 2011-01-06 05:06 - 000000010 _____ C:\dpi.txt 2019-11-22 13:49 - 2011-01-06 04:25 - 000003472 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineUA 2019-11-22 13:49 - 2011-01-06 04:25 - 000003344 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineCore 2019-11-22 13:49 - 2011-01-06 04:25 - 000000000 ____D C:\Program Files (x86)\Google 2019-11-22 13:48 - 2011-01-06 05:00 - 000000080 _____ C:\Windows\system32\Defrag.ini ==================== Files in the root of some directories ======== 2007-06-12 11:34 - 2007-06-12 11:34 - 000035822 _____ () C:\Program Files (x86)\Common Files\ASPG_icon.ico 2008-05-22 10:35 - 2008-05-22 10:35 - 000051962 _____ () C:\Program Files (x86)\Common Files\banner.jpg 2009-04-08 12:31 - 2009-04-08 12:31 - 000106496 _____ () C:\Program Files (x86)\Common Files\CPInstallAction.dll 2008-08-11 23:45 - 2008-08-11 23:45 - 000155648 _____ (ASUS) C:\Program Files (x86)\Common Files\MSIactionall.dll ==================== SigCheck ============================ (There is no automatic fix for files that do not pass verification.) LastRegBack: 2019-11-22 18:42 ==================== End of FRST.txt ========================