cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 23-02-2017
Ran by Joao (administrator) on DESKTOP-SKRPO5H (23-02-2017 00:35:45)
Running from C:\Users\Joao\Downloads
Loaded Profiles: Joao (Available Profiles: Joao)
Platform: Windows 10 Home Version 1607 (X64) Language: Português (Portugal)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

() C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(QIHU 360 SOFTWARE CO. LIMITED) C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe
(Kingsoft Corporation) C:\Program Files (x86)\cmcm\Clean Master\cmcore.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\Program Files (x86)\Realtek\REALTEK Bluetooth\BTDevMgr.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe
(Intel Corporation) C:\Windows\SysWOW64\esif_uf.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe
() C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Windows\System32\TieringEngineService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
() C:\Program Files\AVAST Software\SecureLine\VpnSvc.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Intel Corporation) C:\Windows\Temp\DPTF\esif_assist_64.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Windows\System32\LocationNotificationWindows.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(QIHU 360 SOFTWARE CO. LIMITED) C:\Program Files (x86)\360\Total Security\safemon\QHWatchdog.exe
(Kingsoft Corporation) C:\Program Files (x86)\cmcm\Clean Master\cmtray.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.110.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\REALTEK Bluetooth\BTServer.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
() C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam6\YouCamService6.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe
() C:\Program Files (x86)\AVG Web TuneUp\vprot.exe
() C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(AVAST Software) C:\Program Files\AVAST Software\SecureLine\SecureLine.exe
(HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\TXE Components\DAL\jhi_service.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8911872 2016-10-14] (Realtek Semiconductor)
HKLM\...\Run: [BtServer] => C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTServer.exe [229592 2015-07-09] (Realtek Semiconductor Corporation)
HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2016-09-27] (Microsoft Corporation)
HKLM\...\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [239672 2017-02-20] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [isa] => C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe [330240 2015-02-26] ()
HKLM-x32\...\Run: [HPMessageService] => C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe [654088 2015-02-17] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [PowerDVD14Agent] => C:\Program Files (x86)\CyberLink\PowerDVD14\PowerDVD14Agent.exe [795336 2015-06-22] (CyberLink Corp.)
HKLM-x32\...\Run: [vProt] => C:\Program Files (x86)\AVG Web TuneUp\vprot.exe [2180680 2017-01-26] ()
HKLM-x32\...\Run: [cmsc] => c:\program files (x86)\cmcm\Clean Master\cmtray.exe [771912 2016-11-15] (Kingsoft Corporation)
HKLM-x32\...\Run: [AVGUI.exe] => C:\Program Files (x86)\AVG\Antivirus\AVGUI.exe [9511480 2017-02-22] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [QHSafeTray] => C:\Program Files (x86)\360\Total Security\safemon\360Tray.exe [345000 2016-08-10] (QIHU 360 SOFTWARE CO. LIMITED)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-3387449138-3538770270-1031805266-1001\...\MountPoints2: {08604a51-da91-11e6-9c09-a8a7957499f2} - "E:\HiSuiteDownLoader.exe"
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
BootExecute: autocheck autochk * sdnclean64.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{cb52155f-c99f-449e-b5cd-2daf6abb17e9}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://hp15-comm.msn.com/?pc=HRTE
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp15-comm.msn.com/?pc=HRTE
HKU\S-1-5-21-3387449138-3538770270-1031805266-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/
SearchScopes: HKLM-x32 -> {6C0539AC-D9D9-424A-A135-41840C14313C} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKU\S-1-5-21-3387449138-3538770270-1031805266-1001 -> DefaultScope {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={DD2D3B00-7236-471E-BA15-A7236F1B1F08}&mid=98cc931cbadd47cf91a379eed3907001-21cc44e3cf1b46488f9c1667ee872826666517e2&lang=pt&ds=AVG&coid=avgtbavg&cmpid=1016tb&pr=fr&d=2016-09-28 21:33:56&v=4.3.6.255&pid=wtu&sg=&sap=dsp&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3387449138-3538770270-1031805266-1001 -> {6C0539AC-D9D9-424A-A135-41840C14313C} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKU\S-1-5-21-3387449138-3538770270-1031805266-1001 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={DD2D3B00-7236-471E-BA15-A7236F1B1F08}&mid=98cc931cbadd47cf91a379eed3907001-21cc44e3cf1b46488f9c1667ee872826666517e2&lang=pt&ds=AVG&coid=avgtbavg&cmpid=1016tb&pr=fr&d=2016-09-28 21:33:56&v=4.3.6.255&pid=wtu&sg=&sap=dsp&q={searchTerms}
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2016-12-13] (Microsoft Corporation)
BHO: AVG Web TuneUp -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files\AVG Web TuneUp\4.3.6.255\AVG Web TuneUp.dll [2017-01-26] (AVG)
BHO: SafeMon Class -> {B69F34DD-F0F9-42DC-9EDD-957187DA688D} -> C:\Program Files (x86)\360\Total Security\safemon\safemon64.dll [2016-08-10] (Qihu 360 Software Co., Ltd.)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2016-11-15] (Microsoft Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2016-12-13] (Microsoft Corporation)
BHO-x32: AVG Web TuneUp -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files (x86)\AVG Web TuneUp\4.3.6.255\AVG Web TuneUp.dll [2017-01-26] (AVG)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2016-11-15] (Microsoft Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2016-07-21] (HP Inc.)

FireFox:
========
FF ProfilePath: C:\Users\Joao\AppData\Roaming\Mozilla\Firefox\Profiles\6vaElwr1.default [2017-01-26]
FF Extension: (Avira Browser Safety) - C:\Users\Joao\AppData\Roaming\Mozilla\Firefox\Profiles\6vaElwr1.default\Extensions\abs@avira.com [2016-09-17]
FF Extension: (Avira SafeSearch Plus) - C:\Users\Joao\AppData\Roaming\Mozilla\Firefox\Profiles\6vaElwr1.default\Extensions\safesearchplus2@avira.com [2016-09-17]
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw_1217157.dll [2015-02-05] (Adobe Systems, Inc.)
FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin -> C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\40.3.6\\npsitesafety.dll [No File]
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.56 -> C:\Program Files (x86)\Intel\TXE Components\IPT\npIntelWebAPIIPT.dll [2014-07-01] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\TXE Components\IPT\npIntelWebAPIUpdater.dll [2014-07-01] (Intel Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-08-27] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2017-01-05] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2017-01-05] (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2016-08-27] (Microsoft Corporation)

Chrome:
=======
CHR DefaultSearchURL: Default -> hxxps://search.avira.net/#web/result?source=omnibar&q={searchTerms}
CHR DefaultSearchKeyword: Default -> Avira
CHR DefaultSuggestURL: Default -> hxxps://search.avira.net/suggestions?q={searchTerms}&li=ff&hl=pt
CHR Profile: C:\Users\Joao\AppData\Local\Google\Chrome\User Data\Default [2017-02-23]
CHR Extension: (Google Apresentações) - C:\Users\Joao\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-09-17]
CHR Extension: (Google Docs) - C:\Users\Joao\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-09-17]
CHR Extension: (Google Drive) - C:\Users\Joao\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-09-17]
CHR Extension: (YouTube) - C:\Users\Joao\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-09-17]
CHR Extension: (Planilhas do Google) - C:\Users\Joao\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-09-17]
CHR Extension: (Documentos Google off-line) - C:\Users\Joao\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-09-17]
CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\Joao\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-01-20]
CHR Extension: (Gmail) - C:\Users\Joao\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-09-17]
CHR Extension: (Chrome Media Router) - C:\Users\Joao\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-01-06]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S2 AVG Antivirus; C:\Program Files (x86)\AVG\Antivirus\AVGSvc.exe [260080 2017-02-22] (AVG Technologies CZ, s.r.o.)
S3 AVG Firewall; C:\Program Files (x86)\AVG\Antivirus\afwServ.exe [275616 2017-02-22] (AVG Technologies CZ, s.r.o.)
S3 avgbIDSAgent; C:\Program Files (x86)\AVG\Antivirus\x64\aswidsagenta.exe [6183576 2017-02-22] (AVG Technologies CZ, s.r.o.)
R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1256872 2017-02-20] (AVG Technologies CZ, s.r.o.)
R2 BTDevManager; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe [121560 2015-07-20] ()
R2 cmcore; c:\program files (x86)\cmcm\Clean Master\cmcore.exe [315208 2016-11-15] (Kingsoft Corporation)
R2 esifsvc; C:\WINDOWS\SysWoW64\esif_uf.exe [1385640 2015-08-18] (Intel Corporation)
R2 HPSupportSolutionsFrameworkService; c:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [31776 2016-12-07] (HP Inc.)
R2 HPWMISVC; c:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe [608520 2015-02-17] (Hewlett-Packard Development Company, L.P.)
R2 igfxCUIService2.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [350312 2015-07-13] (Intel Corporation)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe [881152 2015-05-22] (Intel(R) Corporation)
S3 Intel(R) Security Assist; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe [330240 2015-02-26] () [File not signed]
R2 isaHelperSvc; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe [7680 2015-02-26] () [File not signed]
R2 jhi_service; C:\Program Files (x86)\Intel\TXE Components\DAL\jhi_service.exe [174368 2015-04-21] (Intel Corporation)
S2 Kingsoft_WPS_UpdateService; C:\Program Files (x86)\Kingsoft\WPS Office\9.1.0.5113\wtoolex\wpsupdatesvr.exe [133480 2015-12-17] (Zhuhai Kingsoft Office Software Co.,Ltd)
R2 QHActiveDefense; C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe [914344 2016-08-10] (QIHU 360 SOFTWARE CO. LIMITED)
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [389896 2014-04-14] ()
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [326656 2016-10-14] (Realtek Semiconductor)
S2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
R2 SecureLine; C:\Program Files\AVAST Software\SecureLine\VpnSvc.exe [445240 2015-04-29] ()
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [260704 2016-09-02] (Synaptics Incorporated)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)
R2 WtuSystemSupport; C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe [980552 2017-01-26] ()

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 360AntiHacker; C:\WINDOWS\System32\Drivers\360AntiHacker64.sys [137808 2015-11-13] (360.cn)
S3 360AvFlt; C:\WINDOWS\System32\DRIVERS\360AvFlt.sys [95232 2016-08-10] (360.cn)
R1 360Box64; C:\WINDOWS\System32\DRIVERS\360Box64.sys [339456 2016-08-10] (360.cn)
R1 360Camera; C:\WINDOWS\System32\Drivers\360Camera64.sys [40520 2015-11-13] (360.cn)
R1 360FsFlt; C:\WINDOWS\System32\DRIVERS\360FsFlt.sys [367696 2015-11-13] (360.cn)
S3 avgbdisk; C:\WINDOWS\system32\drivers\avgbdiska.sys [165624 2017-02-22] (AVG Technologies CZ, s.r.o.)
S3 avgbidsdriver; C:\WINDOWS\system32\drivers\avgbidsdrivera.sys [311592 2017-02-22] (AVG Technologies CZ, s.r.o.)
S3 avgbidsh; C:\WINDOWS\system32\drivers\avgbidsha.sys [192096 2017-02-22] (AVG Technologies CZ, s.r.o.)
S3 avgblog; C:\WINDOWS\system32\drivers\avgbloga.sys [336920 2017-02-22] (AVG Technologies CZ, s.r.o.)
S3 avgbuniv; C:\WINDOWS\system32\drivers\avgbuniva.sys [50848 2017-02-22] (AVG Technologies CZ, s.r.o.)
S3 avgHwid; C:\WINDOWS\system32\drivers\avgHwid.sys [39288 2017-02-22] (AVG Technologies CZ, s.r.o.)
R2 avgMonFlt; C:\WINDOWS\system32\drivers\avgMonFlt.sys [127072 2017-02-22] (AVG Technologies CZ, s.r.o.)
S3 avgNetSec; C:\WINDOWS\system32\drivers\avgNetSec.sys [456936 2017-02-22] (AVG Technologies CZ, s.r.o.)
S3 avgRdr; C:\WINDOWS\system32\drivers\avgRdr2.sys [101624 2017-02-22] (AVG Technologies CZ, s.r.o.)
R0 avgRvrt; C:\WINDOWS\system32\drivers\avgRvrt.sys [75664 2017-02-22] (AVG Technologies CZ, s.r.o.)
S3 avgSnx; C:\WINDOWS\system32\drivers\avgSnx.sys [992488 2017-02-22] (AVG Technologies CZ, s.r.o.)
R1 avgSP; C:\WINDOWS\system32\drivers\avgSP.sys [555152 2017-02-22] (AVG Technologies CZ, s.r.o.)
S3 avgStm; C:\WINDOWS\system32\drivers\avgStm.sys [163512 2017-02-22] (AVG Technologies CZ, s.r.o.)
S3 avgVmm; C:\WINDOWS\system32\drivers\avgVmm.sys [311472 2017-02-22] (AVG Technologies CZ, s.r.o.)
R3 clwvd6; C:\WINDOWS\system32\DRIVERS\clwvd6.sys [41704 2013-10-29] (CyberLink Corporation)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.)
R3 dptf_acpi; C:\WINDOWS\System32\drivers\dptf_acpi.sys [55816 2015-08-18] (Intel Corporation)
R3 dptf_cpu; C:\WINDOWS\System32\drivers\dptf_cpu.sys [53752 2015-08-18] (Intel Corporation)
R3 esif_lf; C:\WINDOWS\system32\DRIVERS\esif_lf.sys [261624 2015-08-18] (Intel Corporation)
R3 igfxLP; C:\WINDOWS\system32\DRIVERS\igdkmd64lp.sys [5744568 2015-07-13] (Intel Corporation)
S3 ksapi64; C:\WINDOWS\system32\drivers\ksapi64.sys [56680 2016-11-14] (Kingsoft Corporation)
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [895256 2015-06-18] (Realtek )
R3 RtkBtFilter; C:\WINDOWS\system32\DRIVERS\RtkBtfilter.sys [600832 2015-07-16] (Realtek Semiconductor Corporation)
S3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [411712 2015-05-21] (Realsil Semiconductor Corporation)
R3 RTWlanE; C:\WINDOWS\System32\drivers\rtwlane.sys [6294016 2017-02-01] (Realtek Semiconductor Corporation )
S3 SmbDrv; C:\WINDOWS\System32\drivers\Smb_driver_AMDASF.sys [33448 2015-07-13] (Synaptics Incorporated)
R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [71264 2016-09-02] (Synaptics Incorporated)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.)
R3 TXEIx64; C:\WINDOWS\System32\drivers\TXEIx64.sys [146232 2015-06-26] (Intel Corporation)
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
R3 WirelessButtonDriver64; C:\WINDOWS\System32\drivers\WirelessButtonDriver64.sys [30384 2015-06-23] (HP Inc.)
U3 aswbdisk; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-02-23 00:32 - 2017-02-23 00:35 - 00042895 _____ C:\Users\Joao\Downloads\Addition.txt
2017-02-23 00:28 - 2017-02-23 00:35 - 00022351 _____ C:\Users\Joao\Downloads\FRST.txt
2017-02-23 00:28 - 2017-02-23 00:35 - 00000000 ____D C:\FRST
2017-02-23 00:27 - 2017-02-23 00:28 - 02423296 _____ (Farbar) C:\Users\Joao\Downloads\FRST64.exe
2017-02-23 00:26 - 2017-02-23 00:26 - 01765376 _____ (Farbar) C:\Users\Joao\Downloads\FRST.exe
2017-02-23 00:07 - 2017-02-23 00:20 - 00000000 ____D C:\Users\Joao\Downloads\backups
2017-02-22 23:57 - 2017-02-22 23:58 - 00388608 _____ (Trend Micro Inc.) C:\Users\Joao\Downloads\HijackThis.exe
2017-02-22 23:55 - 2017-02-22 23:55 - 00000000 ____D C:\WINDOWS\System32\Tasks\Safer-Networking
2017-02-22 23:54 - 2017-02-22 23:54 - 00001471 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2017-02-22 23:54 - 2017-02-22 23:54 - 00001459 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2017-02-22 23:54 - 2017-02-22 23:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2017-02-22 23:53 - 2017-02-22 23:55 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2017-02-22 23:53 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\WINDOWS\system32\sdnclean64.exe
2017-02-22 23:52 - 2017-02-22 23:54 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2017-02-22 23:49 - 2017-02-22 23:51 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\Joao\Downloads\spybot-2.4.exe
2017-02-22 22:56 - 2017-02-22 22:56 - 00000000 ____D C:\Users\Joao\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\360 Security Center
2017-02-22 22:52 - 2017-02-22 22:52 - 32599984 _____ C:\Users\Joao\Downloads\360TSE_Setup.exe
2017-02-22 22:51 - 2017-02-22 23:04 - 00000000 ____D C:\Users\Joao\AppData\Roaming\360safe
2017-02-22 22:51 - 2017-02-22 23:01 - 00000000 ____D C:\ProgramData\360TotalSecurity
2017-02-22 22:51 - 2017-02-22 22:51 - 00000000 ____D C:\ProgramData\360safe
2017-02-22 22:51 - 2015-11-13 13:29 - 00367696 _____ (360.cn) C:\WINDOWS\system32\Drivers\360fsflt.sys
2017-02-22 22:50 - 2017-02-22 22:56 - 00001233 _____ C:\Users\Public\Desktop\360 Total Security.lnk
2017-02-22 22:50 - 2017-02-22 22:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\360 Security Center
2017-02-22 22:50 - 2017-02-22 22:50 - 00000000 _RSHD C:\360SANDBOX
2017-02-22 22:50 - 2016-08-10 10:54 - 00339456 _____ (360.cn) C:\WINDOWS\system32\Drivers\360Box64.sys
2017-02-22 22:50 - 2016-08-10 10:54 - 00095232 _____ (360.cn) C:\WINDOWS\system32\Drivers\360AvFlt.sys
2017-02-22 22:50 - 2015-11-13 13:29 - 00137808 _____ (360.cn) C:\WINDOWS\system32\Drivers\360AntiHacker64.sys
2017-02-22 22:50 - 2015-11-13 13:29 - 00040520 _____ (360.cn) C:\WINDOWS\system32\Drivers\360Camera64.sys
2017-02-22 22:48 - 2017-02-22 22:48 - 00000000 ____D C:\Program Files (x86)\360
2017-02-22 22:47 - 2017-02-22 22:47 - 29502584 _____ C:\Users\Joao\Downloads\360TSE_Setup_7.2.0.1025.exe
2017-02-22 22:41 - 2017-02-22 22:41 - 00001691 _____ C:\ProgramData\1487803293.bdinstall.bin
2017-02-22 22:41 - 2017-02-22 22:41 - 00000000 ____D C:\Users\Joao\AppData\Roaming\QuickScan
2017-02-22 22:39 - 2017-02-22 22:40 - 10056744 _____ C:\Users\Joao\Downloads\Antivirus_Free_Edition_x86.exe
2017-02-22 22:36 - 2017-02-22 22:36 - 01369712 _____ C:\Users\Joao\Downloads\PandaCloudAntivirus.exe
2017-02-22 22:29 - 2017-02-22 22:29 - 00000000 ____D C:\KVRT_Data
2017-02-22 22:28 - 2017-02-22 22:29 - 109359448 _____ (Kaspersky Lab ZAO) C:\Users\Joao\Downloads\KVRT.exe
2017-02-22 21:59 - 2017-02-22 21:59 - 00000000 ____D C:\Users\Joao\AppData\Roaming\WildTangent
2017-02-22 21:55 - 2017-02-22 21:55 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-02-22 21:55 - 2017-02-22 21:55 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2017-02-22 21:54 - 2017-02-22 21:54 - 00000000 ____D C:\Users\Joao\Downloads\mbam-rules-2016.12.01
2017-02-22 21:53 - 2017-02-22 21:53 - 18877000 _____ C:\Users\Joao\Downloads\mbam-rules-2016.12.01.zip
2017-02-22 21:46 - 2017-02-22 21:43 - 00456936 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgNetSec.sys
2017-02-22 21:45 - 2017-02-22 10:51 - 00397800 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\avgBoot.exe
2017-02-22 10:52 - 2017-02-22 21:47 - 00992488 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgsnx.sys
2017-02-22 10:52 - 2017-02-22 21:46 - 00004008 _____ C:\WINDOWS\System32\Tasks\Antivirus Emergency Update
2017-02-22 10:52 - 2017-02-22 21:44 - 00992488 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgsnx.sys.148780002700001
2017-02-22 10:52 - 2017-02-22 10:51 - 00555152 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgSP.sys
2017-02-22 10:52 - 2017-02-22 10:51 - 00311472 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgVmm.sys
2017-02-22 10:52 - 2017-02-22 10:51 - 00163512 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgStm.sys
2017-02-22 10:52 - 2017-02-22 10:51 - 00127072 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgMonFlt.sys
2017-02-22 10:52 - 2017-02-22 10:51 - 00101624 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgRdr2.sys
2017-02-22 10:52 - 2017-02-22 10:51 - 00075664 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgRvrt.sys
2017-02-22 10:52 - 2017-02-22 10:51 - 00039288 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgHwid.sys
2017-02-22 10:52 - 2017-02-22 10:49 - 00336920 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbloga.sys
2017-02-22 10:52 - 2017-02-22 10:49 - 00311592 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbidsdrivera.sys
2017-02-22 10:52 - 2017-02-22 10:49 - 00192096 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbidsha.sys
2017-02-22 10:52 - 2017-02-22 10:49 - 00165624 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbdiska.sys
2017-02-22 10:52 - 2017-02-22 10:49 - 00050848 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbuniva.sys
2017-02-22 01:37 - 2017-02-22 01:37 - 00353304 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-02-22 01:33 - 2017-02-22 01:34 - 06654968 _____ (AVAST Software) C:\Users\Public\Desktop\avast_free_antivirus_setup_online (1).exe
2017-02-22 01:33 - 2017-02-22 01:34 - 06654968 _____ (AVAST Software) C:\Users\Joao\Downloads\avast_free_antivirus_setup_online (1).exe
2017-02-22 01:33 - 2017-02-22 01:33 - 00000000 ____D C:\ProgramData\Shared Space
2017-02-22 01:33 - 2017-02-22 01:33 - 00000000 ____D C:\ProgramData\Comodo Downloader
2017-02-22 01:33 - 2017-02-22 01:33 - 00000000 ____D C:\ProgramData\Comodo
2017-02-22 01:32 - 2017-02-22 01:32 - 05456584 _____ (COMODO) C:\Users\Joao\Downloads\cispremium_installer_6100_08.exe
2017-02-22 01:26 - 2017-02-22 01:26 - 00000943 _____ C:\Users\Public\Desktop\AVG.lnk
2017-02-22 01:26 - 2017-02-22 01:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG Zen
2017-02-22 01:23 - 2017-02-22 21:29 - 00003658 _____ C:\WINDOWS\System32\Tasks\AVG EUpdate Task
2017-02-22 01:23 - 2017-02-22 10:46 - 00000000 ____D C:\Program Files (x86)\AVG
2017-02-22 01:20 - 2017-02-22 01:22 - 03449440 _____ (AVG Technologies CZ, s.r.o.) C:\Users\Joao\Downloads\Antivirus_Free_1859.exe
2017-02-07 00:01 - 2017-02-07 14:54 - 235332223 _____ C:\Users\Joao\Downloads\PureSim4 (1).zip
2017-02-01 21:51 - 2017-02-01 21:51 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2017-02-01 01:37 - 2017-02-01 01:37 - 00021523 _____ C:\Users\Joao\Downloads\Pauta_TPG3.pdf
2017-02-01 01:36 - 2017-02-01 01:36 - 00030080 _____ C:\Users\Joao\Downloads\Classificacao_P3_TPG3.pdf
2017-02-01 00:38 - 2017-02-01 00:38 - 06294016 _____ (Realtek Semiconductor Corporation ) C:\WINDOWS\system32\Drivers\rtwlane.sys
2017-02-01 00:38 - 2017-02-01 00:38 - 01164800 _____ (Realtek Semiconductor Corp. ) C:\WINDOWS\system32\Rtlihvs.dll
2017-01-31 23:05 - 2017-01-31 18:37 - 00485032 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2017-01-28 15:13 - 2016-12-21 07:08 - 00142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe
2017-01-28 15:13 - 2016-12-21 04:44 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe
2017-01-27 15:29 - 2017-01-27 15:29 - 00000000 ____D C:\WINDOWS\System32\Tasks\AVAST Software

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-02-23 00:21 - 2016-09-14 19:10 - 00000000 ____D C:\Users\Joao\Documents\YouCam
2017-02-23 00:14 - 2016-09-27 11:19 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-02-23 00:14 - 2016-09-27 10:45 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2017-02-23 00:14 - 2016-09-14 19:05 - 00000000 __SHD C:\Users\Joao\IntelGraphicsProfiles
2017-02-23 00:14 - 2015-12-17 15:10 - 00000000 ____D C:\Program Files\AVAST Software
2017-02-23 00:12 - 2016-07-16 06:04 - 00524288 _____ C:\WINDOWS\system32\config\BBI
2017-02-23 00:11 - 2016-09-27 10:53 - 00000000 ____D C:\Users\Joao
2017-02-22 23:58 - 2016-09-14 19:05 - 00000000 ____D C:\Users\Joao\AppData\Local\VirtualStore
2017-02-22 23:08 - 2016-09-17 09:11 - 00000000 ____D C:\Users\Joao\AppData\Local\AvgSetupLog
2017-02-22 22:10 - 2016-07-16 11:47 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-02-22 22:02 - 2016-07-16 11:47 - 00000000 ___HD C:\Program Files\WindowsApps
2017-02-22 22:00 - 2015-12-17 15:20 - 00000000 ____D C:\Program Files (x86)\WildTangent Games
2017-02-22 21:59 - 2015-12-17 15:21 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2017-02-22 21:59 - 2015-12-17 15:20 - 00000000 ____D C:\ProgramData\WildTangent
2017-02-22 21:05 - 2015-12-17 15:10 - 00000000 ____D C:\ProgramData\AVAST Software
2017-02-22 21:02 - 2016-09-27 10:39 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-02-22 10:52 - 2016-09-17 09:11 - 00000000 ____D C:\ProgramData\Avg
2017-02-22 01:29 - 2015-12-17 14:38 - 00000000 ____D C:\ProgramData\Package Cache
2017-02-22 01:28 - 2016-09-17 08:21 - 00000000 ____D C:\ProgramData\Avira
2017-02-22 01:26 - 2016-09-28 21:34 - 00000000 ____D C:\Users\Joao\AppData\Local\AVG Web TuneUp
2017-02-22 01:14 - 2016-07-16 11:45 - 00000000 ____D C:\WINDOWS\INF
2017-02-20 22:57 - 2016-09-27 11:19 - 00004252 _____ C:\WINDOWS\System32\Tasks\avast! SL Update
2017-02-08 03:01 - 2016-07-16 11:47 - 00000000 ____D C:\WINDOWS\system32\NDF
2017-01-31 18:03 - 2016-10-08 13:19 - 00000360 _____ C:\WINDOWS\Tasks\HPCeeScheduleForJoao.job
2017-01-30 15:47 - 2016-07-16 11:36 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-01-28 15:10 - 2016-10-15 13:14 - 00003248 _____ C:\WINDOWS\System32\Tasks\HPCeeScheduleForJoao
2017-01-26 16:27 - 2016-09-28 21:33 - 00000000 ____D C:\ProgramData\AVG Web TuneUp
2017-01-26 16:27 - 2016-09-28 21:33 - 00000000 ____D C:\Program Files (x86)\AVG Web TuneUp

==================== Files in the root of some directories =======

2016-09-14 19:05 - 2017-02-23 00:15 - 0283096 _____ () C:\Users\Joao\AppData\Local\BTServer.log
2017-02-22 22:41 - 2017-02-22 22:41 - 0001691 _____ () C:\ProgramData\1487803293.bdinstall.bin

Some files in TEMP:
====================
2016-09-27 16:23 - 2016-09-27 16:23 - 0000000 ____D () C:\Users\Joao\AppData\Local\Temp\avgnt.exe
2016-11-25 21:28 - 2016-11-25 21:28 - 29648221 _____ (The Road to Success Games ) C:\Users\Joao\AppData\Local\Temp\Setup.exe
2016-11-14 19:02 - 2016-11-14 19:02 - 22972624 _____ (simplitec GmbH ) C:\Users\Joao\AppData\Local\Temp\simpliclean_2.4.6.195.exe

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2017-02-15 22:01

==================== End of FRST.txt ============================

Publicité


Signaler le contenu de ce document

Publicité