Professional Documents
Culture Documents
(If an entry is included in the fixlist, the process will be closed. The file will
not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Stardock Software, Inc) C:\Program Files (x86)\Stardock\Start8\Start8Srv.exe
(Stardock Software, Inc) C:\Program Files (x86)\Stardock\Start8\Start8_64.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files
(x86)\AVG\Framework\Common\avgsvca.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Razer Inc) C:\Program Files (x86)\Razer\Razer Services\GMS\GameManagerService.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Razer Services\Razer
Central\RazerCentralService.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG PC
TuneUp\TuneUpUtilitiesService64.exe
(Wondershare) C:\Program Files (x86)\Wondershare\WAF\2.4.2.223\WsAppService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG PC
TuneUp\TuneUpUtilitiesApp64.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Atheros Communications) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth
Suite\BtvStack.exe
() C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\ActivateDesktop.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\cnext.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files
(x86)\AVG\Framework\Common\avguix.exe
(If an entry is included in the fixlist, the registry item will be restored to
default or removed. The file will not be moved.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 200.30.192.14 190.160.0.13 190.160.0.15
Tcpip\..\Interfaces\{6D6B6A8F-96CC-4660-8E27-C74078D2E10C}: [NameServer]
8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{F61A634B-6971-4452-A6CC-3B54DB1F0505}: [DhcpNameServer]
200.30.192.14 190.160.0.13 190.160.0.15
Internet Explorer:
==================
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program
Files\Microsoft Office\Office15\OCHelper.dll [2014-01-21] (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program
Files\AVAST Software\Avast\aswWebRepIE64.dll [2017-06-28] (AVAST Software)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-
ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2014-01-
21] (Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} ->
C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2014-01-23]
(Microsoft Corporation)
BHO-x32: Wondershare Video Converter Ultimate 7.1.0 -> {451C804F-C205-4F03-B48E-
537EC94937BF} -> C:\ProgramData\Wondershare\Video Converter
Ultimate\WSBrowserAppMgr.dll [2017-06-01] (Wondershare)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} ->
C:\Program Files (x86)\Java\jre1.8.0_131\bin\ssv.dll [2017-06-14] (Oracle
Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} ->
C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-06-28] (AVAST Software)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-
ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL
[2014-01-23] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} ->
C:\Program Files (x86)\Java\jre1.8.0_131\bin\jp2ssv.dll [2017-06-14] (Oracle
Corporation)
Handler: WSWSVCUchrome - {1CA93FF0-A218-44F1 - No File
FireFox:
========
FF ProfilePath:
C:\Users\Administrador.JAVIER\AppData\Roaming\Mozilla\Firefox\Profiles\j8ag5082.def
ault [2017-06-28]
FF Extension: (anonymoX) -
C:\Users\Administrador.JAVIER\AppData\Roaming\Mozilla\Firefox\Profiles\j8ag5082.def
ault\Extensions\client@anonymox.net.xpi [2014-06-23] [not signed]
FF Extension: (YouTube Video and Audio Downloader) -
C:\Users\Administrador.JAVIER\AppData\Roaming\Mozilla\Firefox\Profiles\j8ag5082.def
ault\Extensions\feca4b87-3be4-43da-a1b1-137c24220968@jetpack.xpi [2014-06-23] [not
signed]
FF Extension: (Firebug) -
C:\Users\Administrador.JAVIER\AppData\Roaming\Mozilla\Firefox\Profiles\j8ag5082.def
ault\Extensions\firebug@software.joehewitt.com.xpi [2014-04-16] [not signed]
FF Extension: (MEGA EXTENSION) -
C:\Users\Administrador.JAVIER\AppData\Roaming\Mozilla\Firefox\Profiles\j8ag5082.def
ault\Extensions\firefox@mega.co.nz.xpi [2014-06-23] [not signed]
FF Extension: (Avast SafePrice) -
C:\Users\Administrador.JAVIER\AppData\Roaming\Mozilla\Firefox\Profiles\j8ag5082.def
ault\Extensions\sp@avast.com.xpi [2017-06-28]
FF Extension: (Thumbnail Zoom Plus) -
C:\Users\Administrador.JAVIER\AppData\Roaming\Mozilla\Firefox\Profiles\j8ag5082.def
ault\Extensions\thumbnailZoom@dadler.github.com.xpi [2014-06-23] [not signed]
FF Extension: (PDF Viewer) -
C:\Users\Administrador.JAVIER\AppData\Roaming\Mozilla\Firefox\Profiles\j8ag5082.def
ault\Extensions\uriloader@pdf.js.xpi [2014-06-23] [not signed]
FF Extension: (Avast Online Security) -
C:\Users\Administrador.JAVIER\AppData\Roaming\Mozilla\Firefox\Profiles\j8ag5082.def
ault\Extensions\wrc@avast.com.xpi [2017-06-28]
FF Extension: (YouTube to MP3) -
C:\Users\Administrador.JAVIER\AppData\Roaming\Mozilla\Firefox\Profiles\j8ag5082.def
ault\Extensions\youtube2mp3@mondayx.de.xpi [2014-06-23] [not signed]
FF Extension: (1-Click YouTube Video Downloader) -
C:\Users\Administrador.JAVIER\AppData\Roaming\Mozilla\Firefox\Profiles\j8ag5082.def
ault\Extensions\YoutubeDownloader@PeterOlayev.com.xpi [2014-06-23] [not signed]
FF Extension: (Image Zoom) -
C:\Users\Administrador.JAVIER\AppData\Roaming\Mozilla\Firefox\Profiles\j8ag5082.def
ault\Extensions\{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}.xpi [2014-06-23] [not
signed]
FF Extension: (IE Tab 2 (FF 3.6+)) -
C:\Users\Administrador.JAVIER\AppData\Roaming\Mozilla\Firefox\Profiles\j8ag5082.def
ault\Extensions\{1BC9BA34-1EED-42ca-A505-6D2F1A935BBB} [2014-06-23] [not signed]
FF Extension: (EPUBReader) -
C:\Users\Administrador.JAVIER\AppData\Roaming\Mozilla\Firefox\Profiles\j8ag5082.def
ault\Extensions\{5384767E-00D9-40E9-B72F-9CC39D655D6F} [2014-06-23] [not signed]
FF Extension: (Text Link) -
C:\Users\Administrador.JAVIER\AppData\Roaming\Mozilla\Firefox\Profiles\j8ag5082.def
ault\Extensions\{54BB9F3F-07E5-486c-9B39-C7398B99391C}.xpi [2014-06-23] [not
signed]
FF Extension: (Download Status Bar) -
C:\Users\Administrador.JAVIER\AppData\Roaming\Mozilla\Firefox\Profiles\j8ag5082.def
ault\Extensions\{6c28e999-e900-4635-a39d-b1ec90ba0c0f}.xpi [2014-06-23] [not
signed]
FF Extension: (Easy Youtube Video Downloader Express) -
C:\Users\Administrador.JAVIER\AppData\Roaming\Mozilla\Firefox\Profiles\j8ag5082.def
ault\Extensions\{b9acf540-acba-11e1-8ccb-001fd0e08bd4}.xpi [2014-06-23] [not
signed]
FF Extension: (Download YouTube Videos as MP4) -
C:\Users\Administrador.JAVIER\AppData\Roaming\Mozilla\Firefox\Profiles\j8ag5082.def
ault\Extensions\{b9bfaf1c-a63f-47cd-8b9a-29526ced9060}.xpi [2014-06-23] [not
signed]
FF Extension: (DownloadHelper) -
C:\Users\Administrador.JAVIER\AppData\Roaming\Mozilla\Firefox\Profiles\j8ag5082.def
ault\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-06-23] [not signed]
FF Extension: (RightToClick) -
C:\Users\Administrador.JAVIER\AppData\Roaming\Mozilla\Firefox\Profiles\j8ag5082.def
ault\Extensions\{cd617375-6743-4ee8-bac4-fbf10f35729e}.xpi [2014-06-23] [not
signed]
FF Extension: (CoolPreviews) -
C:\Users\Administrador.JAVIER\AppData\Roaming\Mozilla\Firefox\Profiles\j8ag5082.def
ault\Extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}.xpi [2014-06-23] [not
signed]
FF Extension: (Adblock Plus) -
C:\Users\Administrador.JAVIER\AppData\Roaming\Mozilla\Firefox\Profiles\j8ag5082.def
ault\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-06-23] [not
signed]
FF Extension: (DownThemAll!) -
C:\Users\Administrador.JAVIER\AppData\Roaming\Mozilla\Firefox\Profiles\j8ag5082.def
ault\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2014-06-23] [not
signed]
FF Extension: (Greasemonkey) -
C:\Users\Administrador.JAVIER\AppData\Roaming\Mozilla\Firefox\Profiles\j8ag5082.def
ault\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2014-06-23] [not
signed]
FF Extension: (Greasemonkey) -
C:\Users\ELDI\AppData\Roaming\Mozilla\Firefox\Profiles\j8ag5082.default\extensions\
{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2014-06-23] [not signed]
FF Extension: (RightToClick) -
C:\Users\ELDI\AppData\Roaming\Mozilla\Firefox\Profiles\j8ag5082.default\extensions\
{cd617375-6743-4ee8-bac4-fbf10f35729e}.xpi [2014-06-23] [not signed]
FF Extension: (DownloadHelper) -
C:\Users\ELDI\AppData\Roaming\Mozilla\Firefox\Profiles\j8ag5082.default\extensions\
{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-06-23] [not signed]
FF Extension: (CoolPreviews) -
C:\Users\ELDI\AppData\Roaming\Mozilla\Firefox\Profiles\j8ag5082.default\extensions\
{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}.xpi [2014-06-23] [not signed]
FF Extension: (Text Link) -
C:\Users\ELDI\AppData\Roaming\Mozilla\Firefox\Profiles\j8ag5082.default\extensions\
{54BB9F3F-07E5-486c-9B39-C7398B99391C}.xpi [2014-06-23] [not signed]
FF Extension: (EPUBReader) -
C:\Users\ELDI\AppData\Roaming\Mozilla\Firefox\Profiles\j8ag5082.default\extensions\
{5384767E-00D9-40E9-B72F-9CC39D655D6F} [2014-06-23] [not signed]
FF Extension: (IE Tab 2 (FF 3.6+)) -
C:\Users\ELDI\AppData\Roaming\Mozilla\Firefox\Profiles\j8ag5082.default\extensions\
{1BC9BA34-1EED-42ca-A505-6D2F1A935BBB} [2014-06-23] [not signed]
FF Extension: (Image Zoom) -
C:\Users\ELDI\AppData\Roaming\Mozilla\Firefox\Profiles\j8ag5082.default\extensions\
{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}.xpi [2014-06-23] [not signed]
FF Extension: (YouTube to MP3) -
C:\Users\ELDI\AppData\Roaming\Mozilla\Firefox\Profiles\j8ag5082.default\extensions\
youtube2mp3@mondayx.de.xpi [2014-06-23] [not signed]
FF Extension: (Thumbnail Zoom Plus) -
C:\Users\ELDI\AppData\Roaming\Mozilla\Firefox\Profiles\j8ag5082.default\extensions\
thumbnailZoom@dadler.github.com.xpi [2014-06-23] [not signed]
FF Extension: (MEGA EXTENSION) -
C:\Users\ELDI\AppData\Roaming\Mozilla\Firefox\Profiles\j8ag5082.default\extensions\
firefox@mega.co.nz.xpi [2014-06-23] [not signed]
FF Extension: (DownThemAll!) -
C:\Users\ELDI\AppData\Roaming\Mozilla\Firefox\Profiles\j8ag5082.default\extensions\
{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2014-06-23] [not signed]
FF Extension: (1-Click YouTube Video Downloader) -
C:\Users\ELDI\AppData\Roaming\Mozilla\Firefox\Profiles\j8ag5082.default\extensions\
YoutubeDownloader@PeterOlayev.com.xpi [2014-06-23] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [WSVCU@Wondershare.com] -
C:\ProgramData\Wondershare\Video Converter Ultimate\WSVCU@Wondershare.com_xpi
FF Extension: (Wondershare Video Converter Ultimate) -
C:\ProgramData\Wondershare\Video Converter Ultimate\WSVCU@Wondershare.com_xpi
[2017-06-13]
FF Plugin: @adobe.com/FlashPlayer ->
C:\Windows\system32\Macromed\Flash\NPSWF64_26_0_0_131.dll [2017-06-28] ()
FF Plugin: @videolan.org/vlc,version=2.1.4 -> C:\Program
Files\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.6 -> C:\Program
Files\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer ->
C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_26_0_0_131.dll [2017-06-28] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer ->
C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll [2014-03-10] (Adobe Systems, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=11.131.2 -> C:\Program Files
(x86)\Java\jre1.8.0_131\bin\dtplugin\npDeployJava1.dll [2017-06-14] (Oracle
Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.131.2 -> C:\Program Files
(x86)\Java\jre1.8.0_131\bin\plugin2\npjp2.dll [2017-06-14] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla
Firefox\plugins\npmeetingjoinpluginoc.dll [2014-01-23] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 ->
C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files
(x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-14] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files
(x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-14] (Google Inc.)
FF Plugin HKU\S-1-5-21-1939689530-1907219163-2975089833-500:
@talk.google.com/GoogleTalkPlugin ->
C:\Users\Administrador\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [No File]
FF Plugin HKU\S-1-5-21-1939689530-1907219163-2975089833-500:
@talk.google.com/O3DPlugin ->
C:\Users\Administrador\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll [No
File]
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla
firefox\plugins\npMeetingJoinPluginOC.dll [2014-01-23] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata:
C:\Users\Administrador.JAVIER\AppData\Roaming\mozilla\plugins\npgoogletalk.dll
[2012-09-10] (Google)
FF Plugin ProgramFiles/Appdata:
C:\Users\Administrador.JAVIER\AppData\Roaming\mozilla\plugins\npgtpo3dautoplugin.dl
l [2012-09-10] ()
Chrome:
=======
CHR DefaultProfile: Default
CHR DefaultSearchURL: Default -> hxxp://srch.bar/{searchTerms}
CHR DefaultSuggestURL: Default -> hxxp://srch.bar/?s={searchTerms}
CHR Profile: C:\Users\Administrador.JAVIER\AppData\Local\Google\Chrome\User
Data\Default [2017-06-28]
CHR Extension: (Avast SafePrice) -
C:\Users\Administrador.JAVIER\AppData\Local\Google\Chrome\User
Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2017-06-28]
CHR Extension: (Avast Online Security) -
C:\Users\Administrador.JAVIER\AppData\Local\Google\Chrome\User
Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2017-06-28]
CHR Extension: (Sistema de pagos de Chrome Web Store) -
C:\Users\Administrador.JAVIER\AppData\Local\Google\Chrome\User
Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-06-28]
CHR Extension: (Chrome Media Router) -
C:\Users\Administrador.JAVIER\AppData\Local\Google\Chrome\User
Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-06-28]
CHR HKLM\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej] -
hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] -
hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] -
hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej] -
hxxps://clients2.google.com/service/update2/crx
(If an entry is included in the fixlist, it will be removed from the registry. The
file will not be moved unless listed separately.)
(If an entry is included in the fixlist, it will be removed from the registry. The
file will not be moved unless listed separately.)
(If an entry is included in the fixlist, it will be removed from the registry. The
file will not be moved unless listed separately.)