Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 09-06-2021
Ran by gus (administrator) on DESKTOP-T99JRAI (Gigabyte Technology Co., Ltd. B450M DS3H) (09-06-2021 23:28:39)
Running from D:\instalaciones
Loaded Profiles: gus
Platform: Windows 10 Pro Version 1909 18363.418 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
() [File not signed] C:\Program Files\Sentey 7.1 GAMING HEADSET\CPL\FaceLift_x64.exe
(Adlice -> ) C:\Program Files\RogueKiller\RogueKiller64.exe
(Adlice -> ) C:\Program Files\RogueKiller\RogueKillerSvc.exe
(Adlice -> ) C:\Users\gus\AppData\Local\Temp\is-FQ6GU.tmp\RogueKiller_setup.tmp
(Adlice -> ) C:\Users\gus\AppData\Local\Temp\is-N71JF.tmp\RogueKiller_setup.tmp
(Adlice -> Adlice Software) D:\instalaciones\RogueKiller_setup.exe <2>
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\aswEngSrv.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\AvastSvc.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\AvastUI.exe <4>
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\wsc_proxy.exe
(Focusrite Audio Engineering, Ltd.) [File not signed] C:\Program Files\Focusriteusb\Focusrite Notifier.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.82\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.82\GoogleCrashHandler64.exe
(Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <16>
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_11811.1001.18.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeSH.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Native Instruments GmbH -> Native Instruments GmbH) C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareAccessibilityHelper.exe
(Native Instruments GmbH -> Native Instruments GmbH) C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe
(Native Instruments GmbH -> Native Instruments GmbH) C:\Program Files\Common Files\Native Instruments\Hardware\NIHostIntegrationAgent.exe
(Native Instruments GmbH -> Native Instruments GmbH) C:\Program Files\Common Files\Native Instruments\NTK\NTKDaemon.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9274304 2018-05-30] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\Avast Software\Avast\AvLaunch.exe [122592 2021-06-02] (Avast Software s.r.o. -> AVAST Software)
HKLM\...\Run: [Cm108BSound] => C:\Program Files\Sentey 7.1 GAMING HEADSET\CPL\FaceLift_x64.exe [2359296 2014-11-10] () [File not signed]
HKLM\...\Run: [Focusrite Notifier] => C:\Program Files\Focusriteusb\Focusrite Notifier.exe [5029376 2020-06-02] (Focusrite Audio Engineering, Ltd.) [File not signed]
HKU\S-1-5-21-2055302001-3795474816-1882738526-1002\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4109032 2021-06-08] (Valve -> Valve Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\91.0.4472.101\Installer\chrmstp.exe [2021-06-09] (Google LLC -> Google LLC)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> "C:\Program Files (x86)\Google\Chrome\Application\56.0.2924.87\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NIHardwareAccessibilityHelper.exe.lnk [2021-03-19] <==== ATTENTION
ShortcutTarget: NIHardwareAccessibilityHelper.exe.lnk -> C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareAccessibilityHelper.exe (Native Instruments GmbH -> Native Instruments GmbH) <==== ATTENTION
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NTKDaemon.lnk [2021-03-19]
ShortcutTarget: NTKDaemon.lnk -> C:\Program Files\Common Files\Native Instruments\NTK\NTKDaemon.exe (Native Instruments GmbH -> Native Instruments GmbH)
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {06A4F899-C317-4EC6-839A-7BD1C69879C4} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [155592 2021-01-14] (Google LLC -> Google LLC)
Task: {26D94133-B992-4540-A49F-2E0B0FCD1BA3} - System32\Tasks\Avast Emergency Update => C:\Program Files\Avast Software\Avast\AvEmUpdate.exe [4808928 2021-06-02] (Avast Software s.r.o. -> AVAST Software)
Task: {4B3612E8-B3A3-42D6-86CC-9014D65A92BC} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [1790184 2021-05-14] (Avast Software s.r.o. -> Avast Software)
Task: {4E8A2B7E-BAB9-4506-9434-5BE0710BBA6D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [155592 2021-01-14] (Google LLC -> Google LLC)
Task: {8D6EF556-85FC-4803-9724-98183C5C9EE3} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [690616 2021-06-06] (Mozilla Corporation -> Mozilla Foundation)
Task: {C497333D-BD9D-43A0-AEE8-FFD942F43F08} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1557200 2021-01-26] (Adobe Inc. -> Adobe Inc.)
Task: {FB49FFE9-5828-42BC-AB70-0524B8B897D0} - System32\Tasks\Microsoft\VisualStudio\Updates\BackgroundDownload => C:\Program Files (x86)\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\BackgroundDownload.exe [65448 2021-06-09] (Microsoft Corporation -> Microsoft)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{0d36b6cc-e798-45b9-9345-229d8cf6d643}: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF DefaultProfile: hx36lzds.default
FF ProfilePath: C:\Users\gus\AppData\Roaming\Mozilla\Firefox\Profiles\hx36lzds.default [2021-01-10]
FF ProfilePath: C:\Users\gus\AppData\Roaming\Mozilla\Firefox\Profiles\q5kke6d1.default-release [2021-06-09]
FF Extension: (AdBlock — best ad blocker) - C:\Users\gus\AppData\Roaming\Mozilla\Firefox\Profiles\q5kke6d1.default-release\Extensions\
jid1-NIfFY2CA8fy1tg@jetpack.xpi [2021-06-06]
FF Extension: (AdBlocker for YouTube™) - C:\Users\gus\AppData\Roaming\Mozilla\Firefox\Profiles\q5kke6d1.default-release\Extensions\
jid1-q4sG8pYhq8KGHs@jetpack.xpi [2021-06-06]
FF Extension: (Allow Right-Click) - C:\Users\gus\AppData\Roaming\Mozilla\Firefox\Profiles\q5kke6d1.default-release\Extensions\{278b0ae0-da9d-4cc6-be81-5aa7f3202672}.xpi [2021-06-06]
FF Extension: (Steamcito: Steam con impuestos Argentina 2021) - C:\Users\gus\AppData\Roaming\Mozilla\Firefox\Profiles\q5kke6d1.default-release\Extensions\{4ee0a760-13e0-4ee5-af22-03099a45936d}.xpi [2021-06-06]
FF Extension: (Close Tabs to the Right) - C:\Users\gus\AppData\Roaming\Mozilla\Firefox\Profiles\q5kke6d1.default-release\Extensions\{588c6fa6-14f9-4826-b769-71a305c80bbb}.xpi [2021-06-06]
FF Extension: (DownThemAll!) - C:\Users\gus\AppData\Roaming\Mozilla\Firefox\Profiles\q5kke6d1.default-release\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2021-06-06]
FF Plugin: @videolan.org/vlc,version=3.0.12 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2021-05-28] (Adobe Inc. -> Adobe Systems Inc.)
Chrome:
=======
CHR Profile: C:\Users\gus\AppData\Local\Google\Chrome\User Data\Default [2021-06-09]
CHR HomePage: Default -> hxxp://google.com.ar/
CHR StartupUrls: Default -> "hxxp://google.com.ar/"
CHR DefaultSearchURL: Default -> hxxp://www.google.com/search?q={searchTerms}&ie=utf-8&oe=utf-8&aq=t
CHR DefaultSearchKeyword: Default -> google.com_
CHR DefaultSuggestURL: Default -> hxxp://suggestqueries.google.com/complete/search?q={searchTerms}
CHR Extension: (Presentaciones) - C:\Users\gus\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2021-01-14]
CHR Extension: (Documentos) - C:\Users\gus\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2021-01-14]
CHR Extension: (Google Drive) - C:\Users\gus\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2021-01-14]
CHR Extension: (YouTube) - C:\Users\gus\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2021-01-14]
CHR Extension: (Adblock para Youtube™) - C:\Users\gus\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmedhionkhpnakcndndgjdbohmhepckk [2021-05-21]
CHR Extension: (Chrome Remote Desktop) - C:\Users\gus\AppData\Local\Google\Chrome\User Data\Default\Extensions\efmjfjelnicpmdcmfikempdhlmainjcb [2021-04-07]
CHR Extension: (Pixlr-o-matic) - C:\Users\gus\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehcibdjmpjlekgjhepbfmenfppliikcj [2021-01-14]
CHR Extension: (1clickVPN - VPN gratis para Chrome) - C:\Users\gus\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcfhplploccackoneaefokcmbjfbkenj [2021-04-23]
CHR Extension: (Hojas de cálculo) - C:\Users\gus\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2021-01-14]
CHR Extension: (Documentos de Google sin conexión) - C:\Users\gus\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-05-21]
CHR Extension: (AdBlock: el mejor bloqueador de anuncios) - C:\Users\gus\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2021-05-21]
CHR Extension: (Guardar en Google Drive) - C:\Users\gus\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmbmikajjgmnabiglmofipeabaddhgne [2021-03-15]
CHR Extension: (Google Keep: notas y listas) - C:\Users\gus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki [2021-06-03]
CHR Extension: (Chrome Remote Desktop) - C:\Users\gus\AppData\Local\Google\Chrome\User Data\Default\Extensions\inomeogfingihgjfjlpeplalcfajhgai [2021-04-07]
CHR Extension: (Captura de página completa - FireShot) - C:\Users\gus\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbpblocgmgfnpjjppndjkmgjaogfceg [2021-06-04]
CHR Extension: (DownThemAll!) - C:\Users\gus\AppData\Local\Google\Chrome\User Data\Default\Extensions\nljkibfhlpcnanjgbnlnbjecgicbjkge [2021-04-14]
CHR Extension: (Sistema de pagos de Chrome Web Store) - C:\Users\gus\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-03-11]
CHR Extension: (Gmail) - C:\Users\gus\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2021-01-14]
CHR Extension: (Chrome Media Router) - C:\Users\gus\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2021-06-04]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169672 2021-01-26] (Adobe Inc. -> Adobe Inc.)
R2 avast! Antivirus; C:\Program Files\Avast Software\Avast\AvastSvc.exe [622816 2021-06-02] (Avast Software s.r.o. -> AVAST Software)
R2 AvastWscReporter; C:\Program Files\Avast Software\Avast\wsc_proxy.exe [56912 2021-06-02] (Avast Software s.r.o. -> AVAST Software)
R2 NIHostIntegrationAgent; C:\Program Files\Common Files\Native Instruments\Hardware\NIHostIntegrationAgent.exe [18832256 2021-02-18] (Native Instruments GmbH -> Native Instruments GmbH)
R2 rkrtservice; C:\Program Files\RogueKiller\RogueKillerSvc.exe [13688656 2021-03-24] (Adlice -> )
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5796168 2019-10-06] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 VSStandardCollectorService150; C:\Program Files (x86)\Microsoft Visual Studio\Shared\Common\DiagnosticsHub.Collection.Service\StandardCollector.Service.exe [147392 2019-04-30] (Microsoft Corporation -> Microsoft Corporation)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2011.6-0\NisSrv.exe [2491880 2021-01-10] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2011.6-0\MsMpEng.exe [128376 2021-01-10] (Microsoft Windows Publisher -> Microsoft Corporation)
S4 NVDisplay.ContainerLocalSystem; C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_3621da861144492b\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_3621da861144492b\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem
S2 Registration for device management; C:\Windows\Logs\cmd.exe /c powershell.exe -windowstyle Hidden -noninteractive -executionpolicy bypass -file C:\Windows\Logs\Log\231546531\ssfr.ps1
S3 WaaSMedicSvc; %systemroot%\system32\WaasMedicSvc.dll [X]
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 aswArDisk; C:\Windows\System32\drivers\aswArDisk.sys [35664 2021-06-02] (Avast Software s.r.o. -> AVAST Software)
R1 aswArPot; C:\Windows\System32\drivers\aswArPot.sys [216360 2021-06-02] (Avast Software s.r.o. -> AVAST Software)
R0 aswbidsh; C:\Windows\System32\drivers\aswbidsh.sys [250336 2021-06-02] (Avast Software s.r.o. -> AVAST Software)
R0 aswbuniv; C:\Windows\System32\drivers\aswbuniv.sys [99296 2021-06-02] (Avast Software s.r.o. -> AVAST Software)
R0 aswElam; C:\Windows\System32\drivers\aswElam.sys [17328 2021-06-02] (Microsoft Windows Early Launch Anti-malware Publisher -> AVAST Software)
R1 aswKbd; C:\Windows\System32\drivers\aswKbd.sys [41296 2021-06-02] (Avast Software s.r.o. -> AVAST Software)
R1 aswMonFlt; C:\Windows\System32\drivers\aswMonFlt.sys [180944 2021-06-02] (Avast Software s.r.o. -> AVAST Software)
R0 aswRvrt; C:\Windows\System32\drivers\aswRvrt.sys [82856 2021-06-02] (Avast Software s.r.o. -> AVAST Software)
R1 aswSnx; C:\Windows\System32\drivers\aswSnx.sys [851144 2021-06-02] (Avast Software s.r.o. -> AVAST Software)
R1 aswSP; C:\Windows\System32\drivers\aswSP.sys [471352 2021-06-02] (Avast Software s.r.o. -> AVAST Software)
R0 aswVmm; C:\Windows\System32\drivers\aswVmm.sys [326976 2021-06-02] (Avast Software s.r.o. -> AVAST Software)
R3 bomebus; C:\Windows\System32\drivers\bomebus.sys [56376 2018-05-16] (Bome Software GmbH & Co.KG -> Bome Software GmbH & Co. KG)
S3 CMUAC; C:\Windows\System32\drivers\CMUAC.sys [613888 2014-10-09] (C-MEDIA ELECTRONICS INC. -> C-MEDIA)
S3 Focusriteusb; C:\Windows\System32\drivers\Focusriteusb.sys [123456 2020-06-02] (WDKTestCert builds,132265248139626354 -> Focusrite Audio Engineering Ltd.)
R3 FocusriteusbSwRoot; C:\Windows\System32\drivers\FocusriteusbSwRoot.sys [92568 2020-06-02] (WDKTestCert builds,132265248139626354 -> Focusrite Audio Engineering Ltd.)
S3 Focusriteusb_AUDIO; C:\Windows\system32\drivers\FocusriteusbAudio.sys [87912 2020-06-02] (WDKTestCert builds,132265248139626354 -> Focusrite Audio Engineering Ltd.)
S3 Focusriteusb_MIDI; C:\Windows\system32\drivers\FocusriteusbMidi.sys [49808 2020-06-02] (WDKTestCert builds,132265248139626354 -> Focusrite Audio Engineering Ltd.)
S3 gdrv; C:\Windows\gdrv.sys [26792 2021-01-10] (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGA-BYTE TECHNOLOGY CO., LTD.)
R0 pwdrvio; C:\Windows\System32\pwdrvio.sys [19152 2019-11-08] (MiniTool Solution Ltd -> )
S3 pwdspio; C:\Windows\system32\pwdspio.sys [12504 2019-11-08] (MiniTool Solution Ltd -> )
R3 RtlWlanu; C:\Windows\System32\drivers\rtwlanu.sys [1578128 2013-04-08] (Realtek Semiconductor Corp -> Realtek Semiconductor Corporation)
U3 TrueSight; C:\Windows\System32\drivers\truesight.sys [38032 2021-06-09] (Adlice -> )
S3 WdBoot; C:\Windows\system32\drivers\wd\WdBoot.sys [48536 2021-01-10] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\wd\WdFilter.sys [429296 2021-01-10] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [70896 2021-01-10] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-06-09 23:28 - 2021-06-09 23:28 - 000000000 ____D C:\FRST
2021-06-09 22:45 - 2021-06-09 22:50 - 000000000 ____D C:\ProgramData\RogueKiller
2021-06-09 22:45 - 2021-06-09 22:45 - 000038032 _____ C:\Windows\system32\Drivers\truesight.sys
2021-06-09 22:45 - 2021-06-09 22:45 - 000000913 _____ C:\Users\Public\Desktop\RogueKiller.lnk
2021-06-09 22:45 - 2021-06-09 22:45 - 000000913 _____ C:\ProgramData\Desktop\RogueKiller.lnk
2021-06-09 22:45 - 2021-06-09 22:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2021-06-09 22:45 - 2021-06-09 22:45 - 000000000 ____D C:\Program Files\RogueKiller
2021-06-09 20:49 - 2021-06-09 20:49 - 000000000 ____D C:\Users\gus\AppData\Local\.IdentityService
2021-06-09 20:48 - 2021-06-09 20:48 - 000000000 ____D C:\Program Files (x86)\Xamarin
2021-06-09 20:48 - 2021-06-09 20:48 - 000000000 ____D C:\Program Files (x86)\Android
2021-06-09 19:18 - 2021-06-09 19:18 - 000000000 ____D C:\Program Files\Android
2021-06-09 19:12 - 2021-06-09 19:12 - 000001814 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blend for Visual Studio 2019.lnk
2021-06-09 19:10 - 2021-06-09 19:10 - 000000000 ____D C:\ProgramData\Windows App Certification Kit
2021-06-09 19:10 - 2021-06-09 19:10 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Kits
2021-06-09 19:10 - 2021-06-09 19:10 - 000000000 ____D C:\Program Files\Application Verifier
2021-06-09 19:10 - 2021-06-09 19:10 - 000000000 ____D C:\Program Files (x86)\Application Verifier
2021-06-09 18:16 - 2021-06-09 18:16 - 000000000 ____D C:\Users\gus\AppData\Local\Package Cache
2021-06-09 18:16 - 2021-06-09 18:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Python 3.7
2021-06-09 18:11 - 2021-06-09 18:11 - 000000000 ____D C:\Program Files (x86)\NuGet
2021-06-09 18:10 - 2021-06-09 18:10 - 000000000 ____D C:\Windows\SysWOW64\3082
2021-06-09 18:10 - 2021-06-09 18:10 - 000000000 ____D C:\Windows\SysWOW64\2052
2021-06-09 18:10 - 2021-06-09 18:10 - 000000000 ____D C:\Windows\SysWOW64\1055
2021-06-09 18:10 - 2021-06-09 18:10 - 000000000 ____D C:\Windows\SysWOW64\1049
2021-06-09 18:10 - 2021-06-09 18:10 - 000000000 ____D C:\Windows\SysWOW64\1046
2021-06-09 18:10 - 2021-06-09 18:10 - 000000000 ____D C:\Windows\SysWOW64\1045
2021-06-09 18:10 - 2021-06-09 18:10 - 000000000 ____D C:\Windows\SysWOW64\1042
2021-06-09 18:10 - 2021-06-09 18:10 - 000000000 ____D C:\Windows\SysWOW64\1041
2021-06-09 18:10 - 2021-06-09 18:10 - 000000000 ____D C:\Windows\SysWOW64\1040
2021-06-09 18:10 - 2021-06-09 18:10 - 000000000 ____D C:\Windows\SysWOW64\1036
2021-06-09 18:10 - 2021-06-09 18:10 - 000000000 ____D C:\Windows\SysWOW64\1031
2021-06-09 18:10 - 2021-06-09 18:10 - 000000000 ____D C:\Windows\SysWOW64\1029
2021-06-09 18:10 - 2021-06-09 18:10 - 000000000 ____D C:\Windows\SysWOW64\1028
2021-06-09 18:10 - 2021-06-09 18:10 - 000000000 ____D C:\Windows\system32\3082
2021-06-09 18:10 - 2021-06-09 18:10 - 000000000 ____D C:\Windows\system32\2052
2021-06-09 18:10 - 2021-06-09 18:10 - 000000000 ____D C:\Windows\system32\1055
2021-06-09 18:10 - 2021-06-09 18:10 - 000000000 ____D C:\Windows\system32\1049
2021-06-09 18:10 - 2021-06-09 18:10 - 000000000 ____D C:\Windows\system32\1046
2021-06-09 18:10 - 2021-06-09 18:10 - 000000000 ____D C:\Windows\system32\1045
2021-06-09 18:10 - 2021-06-09 18:10 - 000000000 ____D C:\Windows\system32\1042
2021-06-09 18:10 - 2021-06-09 18:10 - 000000000 ____D C:\Windows\system32\1041
2021-06-09 18:10 - 2021-06-09 18:10 - 000000000 ____D C:\Windows\system32\1040
2021-06-09 18:10 - 2021-06-09 18:10 - 000000000 ____D C:\Windows\system32\1036
2021-06-09 18:10 - 2021-06-09 18:10 - 000000000 ____D C:\Windows\system32\1031
2021-06-09 18:10 - 2021-06-09 18:10 - 000000000 ____D C:\Windows\system32\1029
2021-06-09 18:10 - 2021-06-09 18:10 - 000000000 ____D C:\Windows\system32\1028
2021-06-09 18:10 - 2021-06-09 18:10 - 000000000 ____D C:\Program Files\IIS
2021-06-09 18:10 - 2021-06-09 18:10 - 000000000 ____D C:\Program Files (x86)\IIS
2021-06-09 18:02 - 2021-06-09 18:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Azure
2021-06-09 18:02 - 2021-06-09 18:02 - 000000000 ____D C:\ProgramData\dftmp
2021-06-09 18:02 - 2021-06-09 18:02 - 000000000 ____D C:\Program Files\VS2012Schemas
2021-06-09 18:02 - 2021-06-09 18:02 - 000000000 ____D C:\Program Files\VS2010Schemas
2021-06-09 18:02 - 2021-06-09 18:02 - 000000000 ____D C:\Program Files\Microsoft SDKs
2021-06-09 18:00 - 2021-06-09 18:10 - 000000000 ____D C:\Windows\SysWOW64\1033
2021-06-09 18:00 - 2021-06-09 18:10 - 000000000 ____D C:\Windows\system32\1033
2021-06-09 18:00 - 2021-06-09 18:00 - 000000000 ____D C:\Users\gus\Documents\My Web Sites
2021-06-09 18:00 - 2021-06-09 18:00 - 000000000 ____D C:\Users\gus\Documents\IISExpress
2021-06-09 17:59 - 2021-06-09 18:00 - 000000000 ____D C:\Program Files\IIS Express
2021-06-09 17:59 - 2021-06-09 18:00 - 000000000 ____D C:\Program Files (x86)\IIS Express
2021-06-09 17:50 - 2021-06-09 17:50 - 000000000 ____D C:\Program Files (x86)\Microsoft Web Tools
2021-06-09 17:40 - 2021-06-09 19:15 - 000000000 ____D C:\Program Files (x86)\Microsoft SDKs
2021-06-09 17:40 - 2021-06-09 19:10 - 000000000 ____D C:\Program Files (x86)\Windows Kits
2021-06-09 17:40 - 2021-06-09 17:40 - 000000000 ____D C:\Users\gus\.dotnet
2021-06-09 17:37 - 2021-06-09 17:40 - 000000000 ____D C:\Program Files\dotnet
2021-06-09 17:37 - 2021-06-09 17:38 - 000000000 ____D C:\Program Files (x86)\dotnet
2021-06-09 17:37 - 2021-06-09 17:37 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visual Studio 2019
2021-06-09 17:37 - 2021-06-09 17:37 - 000000000 ____D C:\Program Files (x86)\MSBuild
2021-06-09 17:31 - 2021-06-09 17:31 - 000001813 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visual Studio 2019.lnk
2021-06-09 17:28 - 2021-06-09 17:28 - 000001447 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visual Studio Installer.lnk
2021-06-09 17:28 - 2021-06-09 17:28 - 000000000 ____D C:\Users\gus\AppData\Roaming\Visual Studio Setup
2021-06-09 17:27 - 2021-06-09 17:30 - 000000000 ____D C:\Program Files (x86)\Microsoft Visual Studio
2021-06-09 17:27 - 2021-06-09 17:27 - 000000000 ____D C:\ProgramData\Microsoft Visual Studio
2021-06-09 17:26 - 2021-06-09 17:27 - 000000000 ____D C:\Users\gus\Desktop\ARBA 2021
2021-06-07 01:05 - 2021-06-07 01:05 - 000000000 ____D C:\Users\gus\AppData\Roaming\Maize Sampler Player
2021-06-06 13:42 - 2021-06-06 13:46 - 000000000 ____D C:\Users\gus\Desktop\VST 2021 Guardar
2021-06-06 03:14 - 2021-06-06 03:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ReValver Mk III
2021-06-06 02:10 - 2021-06-06 02:17 - 000000000 __HDC C:\ProgramData\{0503F8F4-705A-448A-B340-94B42D7504BD}
2021-06-06 02:02 - 2021-06-06 02:02 - 000000000 ____D C:\Windows\system32\Tasks\Mozilla
2021-06-06 01:13 - 2021-06-06 13:29 - 000000000 ____D C:\Program Files\Mozilla Firefox
2021-06-05 21:25 - 2021-06-05 21:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Focusrite
2021-06-05 21:25 - 2021-06-05 21:25 - 000000000 ____D C:\Program Files\Focusriteusb
2021-06-05 21:25 - 2020-06-02 15:35 - 000123456 _____ (Focusrite Audio Engineering Ltd.) C:\Windows\system32\Drivers\Focusriteusb.sys
2021-06-05 21:25 - 2020-06-02 15:35 - 000092568 _____ (Focusrite Audio Engineering Ltd.) C:\Windows\system32\Drivers\FocusriteusbSwRoot.sys
2021-06-05 21:25 - 2020-06-02 15:35 - 000087912 _____ (Focusrite Audio Engineering Ltd.) C:\Windows\system32\Drivers\FocusriteusbAudio.sys
2021-06-05 21:25 - 2020-06-02 15:35 - 000049808 _____ (Focusrite Audio Engineering Ltd.) C:\Windows\system32\Drivers\FocusriteusbMidi.sys
2021-06-05 02:12 - 2021-06-06 02:12 - 000000000 ____D C:\Users\gus\Desktop\Scarlett Drivers and Docs
2021-06-04 17:28 - 2021-06-09 23:14 - 000000000 ____D C:\Users\gus\AppData\Local\Avast Software
2021-06-02 22:34 - 2021-06-02 22:34 - 000339680 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2021-06-02 22:32 - 2021-06-02 22:32 - 000017328 _____ (AVAST Software) C:\Windows\system32\Drivers\aswElam.sys
2021-05-21 01:31 - 2021-05-21 01:31 - 000000000 ____D C:\Users\gus\AppData\Roaming\QtProject
2021-05-21 01:31 - 2019-11-08 10:15 - 003600896 _____ C:\Windows\system32\pwNative.exe
2021-05-21 01:31 - 2019-11-08 10:15 - 000019152 _____ C:\Windows\system32\pwdrvio.sys
2021-05-21 01:31 - 2019-11-08 10:15 - 000012504 _____ C:\Windows\system32\pwdspio.sys
2021-05-21 01:30 - 2021-05-21 01:41 - 000000000 ____D C:\Program Files\MiniTool Partition Wizard 12
2021-05-19 17:08 - 2021-05-19 17:08 - 001319288 _____ (LLVM) C:\Windows\SysWOW64\libomp140d.i386.dll
2021-05-19 17:08 - 2021-05-19 17:08 - 001319288 _____ (LLVM) C:\Windows\SysWOW64\libomp140.i386.dll
2021-05-19 17:06 - 2021-05-19 17:06 - 001664912 _____ (LLVM) C:\Windows\system32\libomp140d.x86_64.dll
2021-05-19 17:06 - 2021-05-19 17:06 - 001664912 _____ (LLVM) C:\Windows\system32\libomp140.x86_64.dll
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-06-09 23:24 - 2019-03-19 01:52 - 000000000 ____D C:\Windows\schemas
2021-06-09 23:22 - 2019-11-15 20:59 - 000000000 ____D C:\Windows\system32\SleepStudy
2021-06-09 23:13 - 2019-03-19 01:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2021-06-09 22:47 - 2021-01-10 05:48 - 000000000 ____D C:\ProgramData\Mozilla
2021-06-09 22:43 - 2021-01-10 06:35 - 000000000 ____D C:\ProgramData\Avast Software
2021-06-09 22:43 - 2019-11-15 20:59 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2021-06-09 22:40 - 2019-03-19 01:37 - 000524288 _____ C:\Windows\system32\config\BBI
2021-06-09 19:10 - 2021-01-10 02:18 - 000000000 ____D C:\ProgramData\Package Cache
2021-06-09 19:10 - 2019-03-19 01:37 - 000000000 ____D C:\Windows\CbsTemp
2021-06-09 18:10 - 2019-03-19 01:50 - 000000000 ____D C:\Windows\INF
2021-06-09 18:03 - 2021-03-11 17:57 - 000000000 ____D C:\Program Files (x86)\Steam
2021-06-09 18:00 - 2021-04-24 17:32 - 000000000 ____D C:\Program Files\Microsoft SQL Server
2021-06-09 18:00 - 2021-04-24 17:32 - 000000000 ____D C:\Program Files (x86)\Microsoft SQL Server
2021-06-09 17:49 - 2019-03-19 01:52 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2021-06-09 17:40 - 2021-01-09 23:22 - 000000000 ____D C:\Users\gus
2021-06-09 17:12 - 2021-03-13 21:31 - 000002150 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2021-06-09 17:12 - 2021-01-14 12:34 - 000002259 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2021-06-09 17:12 - 2021-01-14 12:34 - 000002218 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2021-06-09 17:12 - 2021-01-14 12:34 - 000002218 _____ C:\ProgramData\Desktop\Google Chrome.lnk
2021-06-09 00:22 - 2020-12-20 07:26 - 000000000 ____D C:\Ubisoft F
2021-06-09 00:20 - 2020-03-17 13:12 - 000000000 ____D C:\Epic Games
2021-06-07 22:51 - 2020-11-24 20:48 - 000000000 ____D C:\Steam F
2021-06-07 22:42 - 2020-05-25 04:54 - 000000000 ____D C:\00-Varios Mover
2021-06-06 17:49 - 2021-01-14 12:52 - 000000000 ____D C:\Users\gus\Documents\REAPER Media
2021-06-06 13:29 - 2021-01-10 05:48 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2021-06-06 03:32 - 2021-01-10 05:23 - 000000000 ____D C:\Users\gus\AppData\Local\CrashDumps
2021-06-06 02:05 - 2021-03-11 02:12 - 000000000 ____D C:\ProgramData\boost_interprocess
2021-06-06 02:03 - 2021-01-10 05:48 - 000000000 ____D C:\Users\gus\AppData\LocalLow\Mozilla
2021-06-06 02:02 - 2021-01-10 05:48 - 000001019 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2021-06-05 22:22 - 2021-01-10 02:38 - 000000000 ____D C:\Users\gus\AppData\Local\PlaceholderTileLogoFolder
2021-06-05 21:19 - 2021-04-27 01:02 - 000000000 ____D C:\Users\gus\AppData\Roaming\discord
2021-06-05 20:42 - 2021-04-27 01:02 - 000000000 ____D C:\Users\gus\AppData\Local\Discord
2021-06-05 01:50 - 2021-01-14 12:50 - 000000000 ____D C:\Users\gus\AppData\Roaming\REAPER
2021-06-05 01:20 - 2021-03-11 05:32 - 000000000 ____D C:\Users\gus\AppData\Roaming\vlc
2021-06-04 22:18 - 2021-01-10 03:18 - 000000000 ____D C:\Users\gus\AppData\Local\D3DSCache
2021-06-04 22:14 - 2021-04-27 01:02 - 000002235 _____ C:\Users\gus\Desktop\Discord.lnk
2021-06-04 22:06 - 2021-03-11 01:38 - 000000000 ____D C:\Users\gus\AppData\Roaming\Telegram Desktop
2021-06-04 18:59 - 2021-03-12 03:28 - 000001324 _____ C:\Users\gus\Desktop\Fantasy Grounds Unity.lnk
2021-06-02 22:41 - 2021-04-06 01:10 - 000000000 ____D C:\Users\gus\AppData\Local\ElevatedDiagnostics
2021-06-02 22:35 - 2021-01-10 06:38 - 000003990 _____ C:\Windows\system32\Tasks\Avast Emergency Update
2021-06-02 22:34 - 2021-01-10 06:37 - 000851144 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2021-06-02 22:34 - 2021-01-10 06:37 - 000471352 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2021-06-02 22:34 - 2021-01-10 06:37 - 000326976 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2021-06-02 22:34 - 2021-01-10 06:37 - 000250336 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbidsh.sys
2021-06-02 22:34 - 2021-01-10 06:37 - 000216360 _____ (AVAST Software) C:\Windows\system32\Drivers\aswArPot.sys
2021-06-02 22:34 - 2021-01-10 06:37 - 000180944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2021-06-02 22:34 - 2021-01-10 06:37 - 000099296 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbuniv.sys
2021-06-02 22:34 - 2021-01-10 06:37 - 000082856 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2021-06-02 22:34 - 2021-01-10 06:37 - 000041296 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2021-06-02 22:34 - 2021-01-10 06:37 - 000035664 _____ (AVAST Software) C:\Windows\system32\Drivers\aswArDisk.sys
2021-06-02 22:34 - 2019-03-19 01:52 - 000000000 ___HD C:\Windows\ELAMBKUP
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================