Reporte 2 de FRST:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 09.12.2018
Ran by Usuario (19-12-2018 12:33:47)
Running from F:\Descargas
Windows 10 Home Version 1803 17134.471 (X64) (2018-05-15 00:09:16)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrador (S-1-5-21-2880194073-616569380-2500398765-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2880194073-616569380-2500398765-503 - Limited - Disabled)
Invitado (S-1-5-21-2880194073-616569380-2500398765-501 - Limited - Disabled)
Usuario (S-1-5-21-2880194073-616569380-2500398765-1001 - Administrator - Enabled) => C:\Users\Usuario
WDAGUtilityAccount (S-1-5-21-2880194073-616569380-2500398765-504 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Avast Antivirus (Disabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Malwarebytes (Disabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AS: Malwarebytes (Disabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Disabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
µTorrent (HKU\S-1-5-21-2880194073-616569380-2500398765-1001\...\uTorrent) (Version: 3.5.4.44846 - BitTorrent Inc.)
64 Bit HP CIO Components Installer (HKLM\...\{FF21C3E6-97FD-474F-9518-8DCBE94C2854}) (Version: 7.2.8 - Hewlett-Packard) Hidden
Actualización de NVIDIA 2.5.14.5 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 2.5.14.5 - NVIDIA Corporation)
Adobe Acrobat Reader DC - Español (HKLM-x32\...\{AC76BA86-7AD7-1034-7B44-AC0F074E4100}) (Version: 19.008.20074 - Adobe Systems Incorporated)
Adobe Flash Player 31 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 31.0.0.122 - Adobe Systems Incorporated)
Adobe Flash Player 31 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 31.0.0.122 - Adobe Systems Incorporated)
AIO_CDA_ProductContext (HKLM-x32\...\{B5985100-D968-4B0D-B13C-B0362044612D}) (Version: 140.0.425.000 - Hewlett-Packard) Hidden
AIO_CDA_Software (HKLM-x32\...\{CBB55719-C875-4C5A-A0B6-2473F77DD164}) (Version: 140.0.428.000 - Hewlett-Packard) Hidden
AIO_Scan (HKLM-x32\...\{104066F4-5897-4067-85D3-4C88B67CCF75}) (Version: 130.0.421.000 - Hewlett-Packard) Hidden
Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 18.8.2356 - AVAST Software)
Backup and Sync from Google (HKLM\...\{608EBDC6-D18A-4CF6-AD54-EE6B71D29065}) (Version: 3.43.1584.4446 - Google, Inc.)
Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
BufferChm (HKLM-x32\...\{FA0FF682-CC70-4C57-93CD-E276F3E7537E}) (Version: 140.0.298.000 - Hewlett-Packard) Hidden
C3100 (HKLM-x32\...\{E601C028-B828-4CCC-BDC3-9678CEFC6965}) (Version: 140.0.425.000 - Hewlett-Packard) Hidden
c3100_Help (HKLM-x32\...\{1AE3E621-E0C0-4aa1-B10B-B3E353A8D110}) (Version: 82.0.256.000 - Hewlett-Packard) Hidden
calibre 64bit (HKLM\...\{F12B37DA-4B58-48B7-9557-F51E9D62C898}) (Version: 3.6.0 - Kovid Goyal)
CCleaner (HKLM\...\CCleaner) (Version: 5.51 - Piriform)
CLIP STUDIO 1.8.0 (HKLM-x32\...\{49274EB8-4598-47E6-8039-9BB7CE07627E}) (Version: 1.8.0 - CELSYS)
CLIP STUDIO PAINT 1.8.2 (HKLM-x32\...\{1E4572D2-28BC-4BC9-B743-13DC6CFD71DB}) (Version: 1.8.2 - CELSYS)
Copy (HKLM-x32\...\{9BE466FF-70B7-4DA8-807C-DB4C3610FDAA}) (Version: 140.0.298.000 - Hewlett-Packard) Hidden
Dawn of War - Dark Crusade (HKLM-x32\...\{FF39FC01-819B-42E4-AE49-1968AF12DDD4}) (Version: 1.00.0000 - THQ)
Dawn Of War - Winter Assault (HKLM-x32\...\{DD8408E9-9421-484F-979D-DB6361E3E828}) (Version: 1.4 - THQ)
DawnOfWar (HKLM-x32\...\{362D5167-9716-44BE-89FD-BF9EB6EF814B}) (Version: 1.00.00000 - THQ) Hidden
DawnOfWar (HKLM-x32\...\InstallShield_{362D5167-9716-44BE-89FD-BF9EB6EF814B}) (Version: 1.00.00000 - THQ)
Destinations (HKLM-x32\...\{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}) (Version: 140.0.253.000 - Hewlett-Packard) Hidden
DeviceDiscovery (HKLM-x32\...\{1458BB78-1DC5-4BC0-B9A3-2B644F5A8105}) (Version: 140.0.298.000 - Hewlett-Packard) Hidden
Diablo II (HKLM-x32\...\Diablo II) (Version: - Blizzard Entertainment)
Diablo III (HKLM-x32\...\Diablo III) (Version: - Blizzard Entertainment)
DocProc (HKLM-x32\...\{9B362566-EC1B-4700-BB9C-EC661BDE2175}) (Version: 140.0.185.000 - Hewlett-Packard) Hidden
Dropbox (HKLM-x32\...\Dropbox) (Version: 63.4.107 - Dropbox, Inc.)
Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.141.1 - Dropbox, Inc.) Hidden
EaseUS Data Recovery Wizard (HKLM\...\EaseUS Data Recovery Wizard_is1) (Version: - EaseUS)
Fax (HKLM-x32\...\{9294F169-72EE-4D74-AE92-CA25F64B4FF8}) (Version: 140.0.307.000 - Hewlett-Packard) Hidden
FS Water Configurator 3.15 (HKLM\...\FS Water Configurator) (Version: - )
Futuremark SystemInfo (HKLM-x32\...\{E540B871-3230-4C5B-AAD5-A30F64398275}) (Version: 4.48.599.0 - Futuremark)
Geeks3D FurMark 1.14.1 (HKLM-x32\...\{2397CAD4-2263-4CD0-96BE-E43A980B9C9A}_is1) (Version: - Geeks3D)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 71.0.3578.98 - Google Inc.)
Google Earth Pro (HKLM-x32\...\{BF354C72-AC4C-4A87-8D42-B089862BAE58}) (Version: 7.3.2.5491 - Google)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.17 - Google Inc.) Hidden
GPBaseService2 (HKLM-x32\...\{BB3447F6-9553-4AA9-960E-0DB5310C5779}) (Version: 140.0.297.000 - Hewlett-Packard) Hidden
HP Customer Participation Program 14.0 (HKLM\...\HPExtendedCapabilities) (Version: 14.0 - HP)
HP Imaging Device Functions 14.0 (HKLM\...\HP Imaging Device Functions) (Version: 14.0 - HP)
HP Photosmart All-In-One Driver Software (HKLM\...\{4F6C1178-3FC0-44BB-8F9A-28D8516DFEE2}) (Version: 14.0 - HP)
HP Solution Center 14.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 14.0 - HP)
HP Support Solutions Framework (HKLM-x32\...\{E8FF0A82-0696-4347-B4AE-708DE306FFE9}) (Version: 12.10.49.21 - HP Inc.)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HPPhotoGadget (HKLM-x32\...\{CAE4213F-F797-439D-BD9E-79B71D115BE3}) (Version: 140.0.524.000 - Hewlett-Packard) Hidden
HPProductAssistant (HKLM-x32\...\{150B6201-E9E6-4DFB-960E-CCBD53FBDDED}) (Version: 140.0.298.000 - Hewlett-Packard) Hidden
HPSSupply (HKLM-x32\...\{AC35A885-0F8F-4857-B7DA-6E8DFB43E6B3}) (Version: 140.0.297.000 - Hewlett-Packard) Hidden
LibreOffice 6.0.5.2 (HKLM\...\{9645CDEF-085C-45F7-A3CD-B4B7046EF78C}) (Version: 6.0.5.2 - The Document Foundation)
Live! Cam Sync HD VF0770 Driver (1.00.07.00) (HKLM\...\Creative VF0770) (Version: - Creative Technology Ltd.)
Malwarebytes versión 3.6.1.2711 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.6.1.2711 - Malwarebytes)
MarketResearch (HKLM-x32\...\{D360FA88-17C8-4F14-B67F-13AAF9607B12}) (Version: 140.0.299.000 - Hewlett-Packard) Hidden
Microsoft Flight Simulator X Service Pack 2 (HKLM-x32\...\{8039B69D-FD7B-453D-9B63-836D949636FD}) (Version: 10.0.61472.0 - Microsoft Game Studios)
Microsoft OneDrive (HKU\S-1-5-21-2880194073-616569380-2500398765-1001\...\OneDriveSetup.exe) (Version: 18.091.0506.0007 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Mozilla Firefox 62.0.3 (x64 es-ES) (HKLM\...\Mozilla Firefox 62.0.3 (x64 es-ES)) (Version: 62.0.3 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 62.0.3 - Mozilla)
MSXML 4.0 SP2 Parser and SDK (HKLM-x32\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
Network64 (HKLM\...\{6BFAB6C1-6D46-46DB-A538-A269907C9F2F}) (Version: 140.0.306.000 - Hewlett-Packard) Hidden
Norton Security Scan (HKLM-x32\...\NSS) (Version: 4.7.0.181 - Symantec Corporation)
NVIDIA Controlador de 3D Vision 388.13 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 388.13 - NVIDIA Corporation)
NVIDIA Controlador de gráficos 388.13 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 388.13 - NVIDIA Corporation)
OCR Software by I.R.I.S. 14.0 (HKLM\...\HPOCR) (Version: 14.0 - HP)
Panda Cloud Cleaner (HKLM-x32\...\{92B2B132-C7F0-43DC-921A-4493C04F78A4}_is1) (Version: 1.1.10 - Panda Security)
Panel de control de NVIDIA 388.13 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 388.13 - NVIDIA Corporation) Hidden
PCMark 8 (HKLM\...\{1C105B2F-E38F-4CE4-97F7-D5F9381AC85F}) (Version: 2.7.613.0 - Futuremark) Hidden
PCMark 8 (HKLM-x32\...\{ffbe2963-bbe7-49f1-9c32-6fe7e17e5200}) (Version: 2.7.613.0 - Futuremark)
RealDownloader (HKLM-x32\...\{115CCDDD-8728-4789-983D-D041A8E02316}) (Version: 18.1.8.212 - RealNetworks, Inc.) Hidden
RealDownloader (HKLM-x32\...\{30f9b8e2-1723-49b3-a51a-6b1701314fd9}) (Version: 18.1.8.212 - RealNetworks) Hidden
RealDownloader (HKLM-x32\...\{4602B6EE-69EC-4548-B271-94D43CAA6C6F}) (Version: 18.1.8.212 - RealNetworks) Hidden
RealNetworks - Microsoft Visual C++ 2008 Runtime (HKLM-x32\...\{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}) (Version: 9.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (HKLM-x32\...\{AAECF7BA-E83B-4A10-87EA-DE0B333F8734}) (Version: 10.0 - RealNetworks, Inc) Hidden
RealPlayer (RealTimes) (HKLM-x32\...\RealPlayer 18.1) (Version: 18.1.8 - RealNetworks)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7836 - Realtek Semiconductor Corp.)
RealUpgrade 1.1 (HKLM-x32\...\{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}) (Version: 1.1.0 - RealNetworks, Inc.) Hidden
Scan (HKLM-x32\...\{06A1D88C-E102-4527-AF70-29FFD7AF215A}) (Version: 140.0.253.000 - Hewlett-Packard) Hidden
Shop for HP Supplies (HKLM\...\Shop for HP Supplies) (Version: 14.0 - HP)
SolutionCenter (HKLM-x32\...\{BC5DD87B-0143-4D14-AAE6-97109614DC6B}) (Version: 140.0.299.000 - Hewlett-Packard) Hidden
Status (HKLM-x32\...\{5B025634-7D5B-4B8D-BE2A-7943C1CF2D5D}) (Version: 140.0.342.000 - Hewlett-Packard) Hidden
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1224 - SUPERAntiSpyware.com)
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.19 - TeamSpeak Systems GmbH)
Toolbox (HKLM-x32\...\{292F0F52-B62D-4E71-921B-89A682402201}) (Version: 140.0.596.000 - Hewlett-Packard) Hidden
TrayApp (HKLM-x32\...\{CD31E63D-47FD-491C-8117-CF201D0AFAB5}) (Version: 140.0.297.000 - Hewlett-Packard) Hidden
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{9CBA860F-7437-4A75-941C-8EF559F2D145}) (Version: 2.52.0.0 - Microsoft Corporation)
UpdateService (HKLM-x32\...\{E3AE96D6-E196-45B4-AF62-2B41998B9E37}) (Version: 1.0.0 - RealNetworks, Inc.) Hidden
vc2012_redist (HKLM-x32\...\{9402AEF2-5981-4097-8BE2-6501DAC4DBFD}) (Version: 1.0.0.0 - Realnetworks) Hidden
Video Downloader (HKLM-x32\...\{CEF8613C-08DD-4092-9445-C3EBE9C81C37}) (Version: 18.1.8 - RealNetworks) Hidden
vs2015_redist x86 (HKLM-x32\...\{BD46163A-0331-4A61-B65A-7B66D7C93F8E}) (Version: 1.0.0.0 - Realnetworks) Hidden
Vulkan Run Time Libraries 1.0.61.0 (HKLM\...\VulkanRT1.0.61.0) (Version: 1.0.61.0 - LunarG, Inc.) Hidden
WebReg (HKLM-x32\...\{8EE94FD8-5F52-4463-A340-185D16328158}) (Version: 140.0.297.017 - Hewlett-Packard) Hidden
WinRAR 5.60 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.60.0 - win.rar GmbH)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
ShellIconOverlayIdentifiers: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-12-13] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-12-13] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-12-13] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-12-13] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-12-13] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-12-13] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-12-13] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-12-13] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-12-13] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-12-13] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync64.dll [2018-10-04] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync64.dll [2018-10-04] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync64.dll [2018-10-04] (Google)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-12-17] (AVAST Software)
ShellIconOverlayIdentifiers-x32: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-12-13] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-12-13] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-12-13] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-12-13] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-12-13] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-12-13] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-12-13] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-12-13] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-12-13] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-12-13] (Dropbox, Inc.)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => -> No File
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => -> No File
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-12-17] (AVAST Software)
ContextMenuHandlers1: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File
ContextMenuHandlers1: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-12-13] (Dropbox, Inc.)
ContextMenuHandlers1: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files\Google\Drive\contextmenu64.dll [2018-10-04] (Google)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2018-06-24] (Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2018-06-24] (Alexander Roshal)
ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-12-17] (AVAST Software)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-09-19] (Malwarebytes)
ContextMenuHandlers3: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} => F:\RPDS\Bin64\rpcontextmenu.dll [2017-06-17] (RealNetworks, Inc.)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => -> No File
ContextMenuHandlers4: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-12-13] (Dropbox, Inc.)
ContextMenuHandlers4: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files\Google\Drive\contextmenu64.dll [2018-10-04] (Google)
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
ContextMenuHandlers5: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-12-13] (Dropbox, Inc.)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2017-10-27] (NVIDIA Corporation)
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-12-17] (AVAST Software)
ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-09-19] (Malwarebytes)
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2018-06-24] (Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2018-06-24] (Alexander Roshal)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {10C82761-B45E-43D1-B160-2E3887F211DA} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2018-08-30] (HP Inc.)
Task: {15162A4E-DA5A-4E0A-9C66-2EFA0F2F05B8} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2017-09-20] (HP Inc.)
Task: {2B2D1F4A-B9A6-4FE6-A330-6C4A7201C7CF} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [2018-10-28] (AVAST Software)
Task: {65B85F6F-35B3-4459-A179-28255D5B7B25} - System32\Tasks\Microsoft\Windows\HelloFace\FODCleanupTask => C:\WINDOWS\System32\WinBioPlugIns\FaceFodUninstaller.exe [2018-04-12] ()
Task: {7271104B-E80F-44B6-8CB8-8DF671CFFC79} - System32\Tasks\Norton Security Scan => C:\Program Files\Norton Security Scan\Engine32\4.7.0.181\NSS.exe [2017-12-26] (Symantec Corporation)
Task: {BB9CFA40-833E-41DD-A7BE-DE62046B243D} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
Task: C:\WINDOWS\Tasks\Norton Product Installer.job => C:\Users\Usuario\AppData\Local\Temp\7zSA38B.tmp\SymInstallStub.exeK/partnerid=symantec /productlist=nss /staging=false /delay=0 /launchedby=2 C:\Users\Usuario\AppData\Local\Temp\7zSA38B.tmp <==== ATTENTION
Task: C:\WINDOWS\Tasks\Norton Product InstallerIdle.job => C:\Users\Usuario\AppData\Local\Temp\7zSA38B.tmp\SymInstallStub.exeK/partnerid=symantec /productlist=nss /staging=false /delay=0 /launchedby=4 C:\Users\Usuario\AppData\Local\Temp\7zSA38B.tmp <==== ATTENTION
Task: C:\WINDOWS\Tasks\PTK-Scheduler-Norton Security Scan.job => C:\Program Files\Norton Security Scan\Engine32\4.7.0.181\NSS.exeÆaction=run fmui C:\Program Files\Norton Security Scan\Branding\Config.dll
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
==================== Loaded Modules (Whitelisted) ==============
2018-04-12 00:34 - 2018-04-12 00:34 - 000491744 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll
2018-04-12 00:34 - 2018-04-12 00:34 - 000472064 _____ () C:\Windows\ShellExperiences\TileControl.dll
2018-12-12 21:19 - 2018-11-09 03:17 - 002759680 _____ () C:\Windows\ShellComponents\TaskFlowUI.dll
2018-12-12 21:19 - 2018-12-08 08:33 - 002185728 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2018-10-04 20:45 - 2018-10-04 20:46 - 000009216 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.36.52.0_x64__kzf8qxf38zg5c\ImagePipelineNative.dll
2018-12-14 12:55 - 2018-12-14 12:56 - 000060416 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.36.52.0_x64__kzf8qxf38zg5c\ChakraBridge.dll
2018-12-14 12:55 - 2018-12-14 12:56 - 000182272 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.36.52.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe
2018-12-14 00:44 - 2018-12-12 06:11 - 005237216 _____ () C:\Program Files (x86)\Google\Chrome\Application\71.0.3578.98\libglesv2.dll
2018-12-14 00:44 - 2018-12-12 06:11 - 000117216 _____ () C:\Program Files (x86)\Google\Chrome\Application\71.0.3578.98\libegl.dll
2018-10-04 19:44 - 2018-10-04 19:44 - 046459080 _____ () C:\Program Files\Google\Drive\googledrivesync.exe
2018-12-19 12:23 - 2018-12-19 12:23 - 000113664 _____ () C:\Users\Usuario\AppData\Local\Temp\_MEI90122\_ctypes.pyd
2018-12-19 12:23 - 2018-12-19 12:23 - 000080896 _____ () C:\Users\Usuario\AppData\Local\Temp\_MEI90122\bz2.pyd
2018-12-19 12:23 - 2018-12-19 12:23 - 001792512 _____ () C:\Users\Usuario\AppData\Local\Temp\_MEI90122\_hashlib.pyd
2018-12-19 12:23 - 2018-12-19 12:23 - 000128512 _____ () C:\Users\Usuario\AppData\Local\Temp\_MEI90122\win32api.pyd
2018-12-19 12:23 - 2018-12-19 12:23 - 000137728 _____ () C:\Users\Usuario\AppData\Local\Temp\_MEI90122\pywintypes27.dll
2018-12-19 12:23 - 2018-12-19 12:23 - 000548864 _____ () C:\Users\Usuario\AppData\Local\Temp\_MEI90122\pythoncom27.dll
2018-12-19 12:23 - 2018-12-19 12:23 - 000689664 _____ () C:\Users\Usuario\AppData\Local\Temp\_MEI90122\unicodedata.pyd
2018-12-19 12:23 - 2018-12-19 12:23 - 000438784 _____ () C:\Users\Usuario\AppData\Local\Temp\_MEI90122\win32com.shell.shell.pyd
2018-12-19 12:23 - 2018-12-19 12:23 - 001489408 _____ () C:\Users\Usuario\AppData\Local\Temp\_MEI90122\wx._core_.pyd
2018-12-19 12:23 - 2018-12-19 12:23 - 001007104 _____ () C:\Users\Usuario\AppData\Local\Temp\_MEI90122\wx._gdi_.pyd
2018-12-19 12:23 - 2018-12-19 12:23 - 001039872 _____ () C:\Users\Usuario\AppData\Local\Temp\_MEI90122\wx._windows_.pyd
2018-12-19 12:23 - 2018-12-19 12:23 - 001325056 _____ () C:\Users\Usuario\AppData\Local\Temp\_MEI90122\wx._controls_.pyd
2018-12-19 12:23 - 2018-12-19 12:23 - 000916992 _____ () C:\Users\Usuario\AppData\Local\Temp\_MEI90122\wx._misc_.pyd
2018-12-19 12:23 - 2018-12-19 12:23 - 001084416 _____ () C:\Users\Usuario\AppData\Local\Temp\_MEI90122\pysqlite2._sqlite.pyd
2018-12-19 12:23 - 2018-12-19 12:23 - 000149504 _____ () C:\Users\Usuario\AppData\Local\Temp\_MEI90122\win32file.pyd
2018-12-19 12:23 - 2018-12-19 12:23 - 000136192 _____ () C:\Users\Usuario\AppData\Local\Temp\_MEI90122\win32security.pyd
2018-12-19 12:23 - 2018-12-19 12:23 - 000007680 _____ () C:\Users\Usuario\AppData\Local\Temp\_MEI90122\hashobjs_ext.pyd
2018-12-19 12:23 - 2018-12-19 12:23 - 000020992 _____ () C:\Users\Usuario\AppData\Local\Temp\_MEI90122\thumbnails_ext.pyd
2018-12-19 12:23 - 2018-12-19 12:23 - 000118784 _____ () C:\Users\Usuario\AppData\Local\Temp\_MEI90122\usb_ext.pyd
2018-12-19 12:23 - 2018-12-19 12:23 - 000047616 _____ () C:\Users\Usuario\AppData\Local\Temp\_MEI90122\_socket.pyd
2018-12-19 12:23 - 2018-12-19 12:23 - 002224640 _____ () C:\Users\Usuario\AppData\Local\Temp\_MEI90122\_ssl.pyd
2018-12-19 12:23 - 2018-12-19 12:23 - 000014848 _____ () C:\Users\Usuario\AppData\Local\Temp\_MEI90122\common.time34.pyd
2018-12-19 12:23 - 2018-12-19 12:23 - 000023040 _____ () C:\Users\Usuario\AppData\Local\Temp\_MEI90122\win32event.pyd
2018-12-19 12:23 - 2018-12-19 12:23 - 000034304 _____ () C:\Users\Usuario\AppData\Local\Temp\_MEI90122\windows.conditional.pyd
2018-12-19 12:23 - 2018-12-19 12:23 - 000020480 _____ () C:\Users\Usuario\AppData\Local\Temp\_MEI90122\windows.winwrap.pyd
2018-12-19 12:23 - 2018-12-19 12:23 - 000110080 _____ () C:\Users\Usuario\AppData\Local\Temp\_MEI90122\windows.volumes.pyd
2018-12-19 12:23 - 2018-12-19 12:23 - 000223232 _____ () C:\Users\Usuario\AppData\Local\Temp\_MEI90122\win32gui.pyd
2018-12-19 12:23 - 2018-12-19 12:23 - 000173568 _____ () C:\Users\Usuario\AppData\Local\Temp\_MEI90122\_elementtree.pyd
2018-12-19 12:23 - 2018-12-19 12:23 - 000169472 _____ () C:\Users\Usuario\AppData\Local\Temp\_MEI90122\pyexpat.pyd
2018-12-19 12:23 - 2018-12-19 12:23 - 000048128 _____ () C:\Users\Usuario\AppData\Local\Temp\_MEI90122\win32inet.pyd
2018-12-19 12:23 - 2018-12-19 12:23 - 000103424 _____ () C:\Users\Usuario\AppData\Local\Temp\_MEI90122\wx._html2.pyd
2018-12-19 12:23 - 2018-12-19 12:23 - 000046080 _____ () C:\Users\Usuario\AppData\Local\Temp\_MEI90122\_psutil_windows.pyd
2018-12-19 12:23 - 2018-12-19 12:23 - 000633272 _____ () C:\Users\Usuario\AppData\Local\Temp\_MEI90122\windows._cacheinvalidation.pyd
2018-12-19 12:23 - 2018-12-19 12:23 - 000011776 _____ () C:\Users\Usuario\AppData\Local\Temp\_MEI90122\win32crypt.pyd
2018-12-19 12:23 - 2018-12-19 12:23 - 000301568 _____ () C:\Users\Usuario\AppData\Local\Temp\_MEI90122\PIL._imaging.pyd
2018-12-19 12:23 - 2018-12-19 12:23 - 000032256 _____ () C:\Users\Usuario\AppData\Local\Temp\_MEI90122\_multiprocessing.pyd
2018-12-19 12:23 - 2018-12-19 12:23 - 005752320 _____ () C:\Users\Usuario\AppData\Local\Temp\_MEI90122\cello.pyd
2018-12-19 12:23 - 2018-12-19 12:23 - 000026112 _____ () C:\Users\Usuario\AppData\Local\Temp\_MEI90122\_yappi.pyd
2018-12-19 12:23 - 2018-12-19 12:23 - 000044032 _____ () C:\Users\Usuario\AppData\Local\Temp\_MEI90122\win32process.pyd
2018-12-19 12:23 - 2018-12-19 12:23 - 000027648 _____ () C:\Users\Usuario\AppData\Local\Temp\_MEI90122\win32pipe.pyd
2018-12-19 12:23 - 2018-12-19 12:23 - 000010752 _____ () C:\Users\Usuario\AppData\Local\Temp\_MEI90122\select.pyd
2018-12-19 12:23 - 2018-12-19 12:23 - 000029696 _____ () C:\Users\Usuario\AppData\Local\Temp\_MEI90122\win32pdh.pyd
2018-12-19 12:23 - 2018-12-19 12:23 - 000038400 _____ () C:\Users\Usuario\AppData\Local\Temp\_MEI90122\windows.connectivity.pyd
2018-12-19 12:23 - 2018-12-19 12:23 - 000073216 _____ () C:\Users\Usuario\AppData\Local\Temp\_MEI90122\windows.device_monitor.pyd
2018-12-19 12:23 - 2018-12-19 12:23 - 000020480 _____ () C:\Users\Usuario\AppData\Local\Temp\_MEI90122\win32profile.pyd
2018-12-19 12:23 - 2018-12-19 12:23 - 000026624 _____ () C:\Users\Usuario\AppData\Local\Temp\_MEI90122\win32ts.pyd
2017-06-02 15:53 - 2017-06-02 15:53 - 001297648 _____ () F:\RealDownloader\downloader2.exe
2018-12-17 23:45 - 2018-12-17 23:45 - 067126928 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2018-12-17 23:44 - 2018-12-17 23:44 - 000596696 _____ () C:\Program Files\AVAST Software\Avast\streamback.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\Users\Usuario\Desktop\Document:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Usuario\Desktop\EOI:com.dropbox.attributes [168]
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service"
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
IE trusted site: HKU\S-1-5-21-2880194073-616569380-2500398765-1001\...\localhost -> localhost
IE trusted site: HKU\S-1-5-21-2880194073-616569380-2500398765-1001\...\webcompanion.com -> hxxp://webcompanion.com
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2015-10-30 08:24 - 2015-10-30 08:21 - 000000824 _____ C:\WINDOWS\system32\Drivers\etc\hosts
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-2880194073-616569380-2500398765-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Usuario\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\PhotosAppBackground\{2ddc6bd5-62d5-48c1-b2b0-3efc6c8dc94a}.jpg
DNS Servers: 62.81.16.148 - 62.81.16.213
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
If an entry is included in the fixlist, it will be removed.
HKLM\...\StartupApproved\StartupFolder: => "HP Digital Imaging Monitor.lnk"
HKLM\...\StartupApproved\StartupFolder: => "RealTimes.lnk"
HKLM\...\StartupApproved\Run32: => "HP Software Update"
HKLM\...\StartupApproved\Run32: => "Dropbox"
HKU\S-1-5-21-2880194073-616569380-2500398765-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-2880194073-616569380-2500398765-1001\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-2880194073-616569380-2500398765-1001\...\StartupApproved\Run: => "Skype"
HKU\S-1-5-21-2880194073-616569380-2500398765-1001\...\StartupApproved\Run: => "SUPERAntiSpyware"
HKU\S-1-5-21-2880194073-616569380-2500398765-1001\...\StartupApproved\Run: => "Uninstall C:\Users\Usuario\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_2"
HKU\S-1-5-21-2880194073-616569380-2500398765-1001\...\StartupApproved\Run: => "Uninstall C:\Users\Usuario\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_2\amd64"
HKU\S-1-5-21-2880194073-616569380-2500398765-1001\...\StartupApproved\Run: => "uTorrent"
HKU\S-1-5-21-2880194073-616569380-2500398765-1001\...\StartupApproved\Run: => "Web Companion"
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{18867099-E709-48AA-AC54-02C371184E60}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{D7B880B5-52D3-44A6-A89B-79598E6E94A1}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{FA8514B3-3ACA-41C3-8ACF-25974E34DFC2}] => (Allow) C:\Program Files\Common Files\McAfee\MMSSHost\MMSSHost.exe
FirewallRules: [{1219F122-A74E-4FF6-B2A3-BE843ECFA486}] => (Allow) C:\Program Files (x86)\Common Files\Mcafee\MMSSHost\MMSSHost.exe
FirewallRules: [{BCA6AA61-C18E-447C-8CE5-12EFC5350C73}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Automation\Automation_Shipping_Steam.exe
FirewallRules: [{68A6272E-A03E-4BC0-9B38-7A2C63D07D88}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Automation\Automation_Shipping_Steam.exe
FirewallRules: [{B0AD2A13-D42B-4397-8146-DB3EA6EDB3D6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Automation\Automation Launcher Steam.exe
FirewallRules: [{9C738CA3-06AD-407E-B27D-348CE8F29A48}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Automation\Automation Launcher Steam.exe
FirewallRules: [{5A2969B2-98E3-42ED-B6E0-401CB0513BB6}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{42C991A8-9016-459E-98F2-F9D1752F91CE}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [UDP Query User{5EA25635-D061-44E2-BA4A-6163C429FB89}C:\program files (x86)\diablo iii\diablo iii.exe] => (Allow) C:\program files (x86)\diablo iii\diablo iii.exe
FirewallRules: [TCP Query User{51336A4C-C077-4FC1-A04B-12C98FEC119F}C:\program files (x86)\diablo iii\diablo iii.exe] => (Allow) C:\program files (x86)\diablo iii\diablo iii.exe
FirewallRules: [{FF917E3C-8363-49B4-9464-339D679A3356}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{90AD545E-CEE2-474D-BF66-B7D04256627C}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{766F459B-3CA6-4FD8-B595-16BA68F44A74}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{37CDD329-DD04-45F4-82B6-0335BC5C9CB2}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{068B254D-3D89-4255-8AED-C75985019E3C}] => (Allow) F:\HP\Digital Imaging\bin\hpqtra08.exe
FirewallRules: [{0ADF399D-1A77-4A6A-AD37-7F09FF307A42}] => (Allow) F:\HP\Digital Imaging\bin\hpqste08.exe
FirewallRules: [{3D383FDA-8BD1-468C-9BAB-2B7D1BB3D6A9}] => (Allow) F:\HP\Digital Imaging\bin\hpofxm08.exe
FirewallRules: [{FA092AB7-11F7-468C-AAD1-A08AFCDC8F5B}] => (Allow) F:\HP\Digital Imaging\bin\hposfx08.exe
FirewallRules: [{AEBD1179-0459-4B1F-9924-E7E8283A5600}] => (Allow) F:\HP\Digital Imaging\bin\hposid01.exe
FirewallRules: [{F6E23496-3625-423A-B9B9-F690A232EDC2}] => (Allow) F:\HP\Digital Imaging\bin\hpqkygrp.exe
FirewallRules: [{6FFB9D26-C529-4C13-B6E1-846EDBDDFB25}] => (Allow) F:\HP\Digital Imaging\bin\hpqcopy2.exe
FirewallRules: [{5A87127D-8F79-41D9-978F-965DAC6227FE}] => (Allow) F:\HP\Digital Imaging\bin\hpfccopy.exe
FirewallRules: [{A98C0870-1595-4B45-951C-6E14420AC5FC}] => (Allow) F:\HP\Digital Imaging\bin\hpzwiz01.exe
FirewallRules: [{55CBAD8E-A59D-493F-B377-E010669C9F2B}] => (Allow) F:\HP\Digital Imaging\bin\hpoews01.exe
FirewallRules: [{9536B054-7E3E-42FE-83C9-74F0643037DD}] => (Allow) F:\HP\Digital Imaging\bin\hpqnrs08.exe
FirewallRules: [{E0CCC91B-29EB-4C93-B6CD-49F46DDC5355}] => (Allow) F:\HP\Digital Imaging\bin\hpiscnapp.exe
FirewallRules: [{F3D30551-469F-42B0-B60B-7E0533C044CF}] => (Allow) F:\HP\Digital Imaging\bin\hpofxs08.exe
FirewallRules: [{6D8164C0-4640-4E7D-B2DD-310BA2F8BF51}] => (Allow) F:\HP\Digital Imaging\bin\hpqfxt08.exe
FirewallRules: [{A52B3AB2-1CE4-4025-B542-17A2C8AE5D0C}] => (Allow) F:\HP\Digital Imaging\bin\hpqgplgtupl.exe
FirewallRules: [{559066B4-7F17-486F-BB4E-3958380AC0EB}] => (Allow) F:\HP\Digital Imaging\bin\hpqgpc01.exe
FirewallRules: [{0168F81E-153C-4343-9658-F0CA9FBE43EA}] => (Allow) F:\HP\Digital Imaging\bin\hpqusgm.exe
FirewallRules: [{765E33B0-718C-4C8D-9AD1-CAB1AACBDF33}] => (Allow) F:\HP\Digital Imaging\bin\hpqusgh.exe
FirewallRules: [{E6E20B16-722E-4852-BFF6-62ACA39F29FB}] => (Allow) F:\HP\hp software update\hpwucli.exe
FirewallRules: [{4E426F27-A180-46A5-A3F8-81DF7BC387F2}] => (Allow) C:\Users\Usuario\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{183D5A00-D9A7-4764-9645-B7A8DF8492BB}] => (Allow) C:\Users\Usuario\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{72C69F1A-03E5-49A5-8E33-36AE43A38FCF}] => (Allow) F:\RPDS\Bin\rpdsvc.exe
FirewallRules: [TCP Query User{76779E7C-329A-47DE-B80A-669887B7EB39}F:\thq\dawn of war - dark crusade\darkcrusade.exe] => (Allow) F:\thq\dawn of war - dark crusade\darkcrusade.exe
FirewallRules: [UDP Query User{FFF50167-5C97-40BB-B12E-32885855E6C1}F:\thq\dawn of war - dark crusade\darkcrusade.exe] => (Allow) F:\thq\dawn of war - dark crusade\darkcrusade.exe
FirewallRules: [TCP Query User{E2C503EA-C98A-4841-99F6-22F0009D2F7A}F:\thq\dawn of war - dark crusade\darkcrusade.exe] => (Allow) F:\thq\dawn of war - dark crusade\darkcrusade.exe
FirewallRules: [UDP Query User{236C520E-F04D-479C-9AD9-F04AA3834DCA}F:\thq\dawn of war - dark crusade\darkcrusade.exe] => (Allow) F:\thq\dawn of war - dark crusade\darkcrusade.exe
FirewallRules: [TCP Query User{50FB8228-D84C-4E4D-A3E7-96A31D9C4669}C:\program files (x86)\diablo iii\x64\diablo iii64.exe] => (Allow) C:\program files (x86)\diablo iii\x64\diablo iii64.exe
FirewallRules: [UDP Query User{F996E2FF-D5E9-4C6D-A15D-14744CCD17D9}C:\program files (x86)\diablo iii\x64\diablo iii64.exe] => (Allow) C:\program files (x86)\diablo iii\x64\diablo iii64.exe
FirewallRules: [{FF0FDA6A-67B4-423B-986C-D0349C991D4A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Automation\WindowsNoEditor\AutomationGame\Binaries\Win64\AutomationGame-Win64-Shipping.exe
FirewallRules: [{F5ADAE92-5AF2-415D-A64D-DAF3DAE520AF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Automation\WindowsNoEditor\AutomationGame\Binaries\Win64\AutomationGame-Win64-Shipping.exe
FirewallRules: [{7FA05ED8-8B8C-4994-87B3-7D80B734DB52}] => (Allow) C:\Program Files\Bitdefender Home Scanner\hvasrv.exe
FirewallRules: [{0BC3BA68-C589-4002-A29C-7E6E4BF3F244}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{A4ECB192-B343-421E-9173-8CA1B5220C3F}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
FirewallRules: [{72E6A93D-10FA-4D3C-94DA-0F0C0CD9B08E}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe
FirewallRules: [{5A0BDD8C-A8C8-41A2-B387-8A3FA289C6EF}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe
FirewallRules: [{959AF109-4FCD-4AFC-86B9-8495E3FDFDE6}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe
FirewallRules: [{F1844B4A-4BFB-44AC-AC49-02448465938F}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe
==================== Restore Points =========================
02-12-2018 17:35:36 Instalador de Módulos de Windows
04-12-2018 17:35:33 Instalador de Módulos de Windows
05-12-2018 19:35:33 Instalador de Módulos de Windows
06-12-2018 20:36:41 Instalador de Módulos de Windows
07-12-2018 20:59:21 Instalador de Módulos de Windows
08-12-2018 22:17:22 Instalador de Módulos de Windows
10-12-2018 13:05:40 Instalador de Módulos de Windows
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (12/19/2018 12:23:42 PM) (Source: Perflib) (EventID: 1023) (User: )
Description: Windows no puede cargar el archivo DLL del contador extensible rdyboost. Los primeros cuatro bytes (DWORD) de la sección de datos contienen el código de error de Windows.
Error: (12/19/2018 12:23:42 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: Error del procedimiento de apertura para el servicio "BITS" en el archivo DLL "C:\Windows\System32\bitsperf.dll". Los datos de rendimiento para este servicio no estarán disponibles. Los primeros cuatro bytes (DWORD) de la sección de datos contienen el código de error.
Error: (12/12/2018 11:33:42 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nombre de la aplicación con errores: RealPlayerUpdateSvc.exe, versión: 18.1.8.212, marca de tiempo: 0x5932053c
Nombre del módulo con errores: ntdll.dll, versión: 10.0.17134.471, marca de tiempo: 0xfe852bc4
Código de excepción: 0xc0000005
Desplazamiento de errores: 0x00094efd
Identificador del proceso con errores: 0xbc8
Hora de inicio de la aplicación con errores: 0x01d492668aef7e19
Ruta de acceso de la aplicación con errores: F:\UpdateService\RealPlayerUpdateSvc.exe
Ruta de acceso del módulo con errores: C:\WINDOWS\SYSTEM32\ntdll.dll
Identificador del informe: e91d38b2-5e6e-4f7f-8851-cc95657fadf5
Nombre completo del paquete con errores:
Identificador de aplicación relativa del paquete con errores:
Error: (12/12/2018 09:43:30 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nombre de la aplicación con errores: RealPlayerUpdateSvc.exe, versión: 18.1.8.212, marca de tiempo: 0x5932053c
Nombre del módulo con errores: ntdll.dll, versión: 10.0.17134.376, marca de tiempo: 0x4358e406
Código de excepción: 0xc0000005
Desplazamiento de errores: 0x00092bbb
Identificador del proceso con errores: 0xc88
Hora de inicio de la aplicación con errores: 0x01d4925725ced92d
Ruta de acceso de la aplicación con errores: F:\UpdateService\RealPlayerUpdateSvc.exe
Ruta de acceso del módulo con errores: C:\WINDOWS\SYSTEM32\ntdll.dll
Identificador del informe: b84d7ba9-caef-4332-b54d-3d93500cea8a
Nombre completo del paquete con errores:
Identificador de aplicación relativa del paquete con errores:
Error: (12/11/2018 02:33:32 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nombre de la aplicación con errores: RealPlayerUpdateSvc.exe, versión: 18.1.8.212, marca de tiempo: 0x5932053c
Nombre del módulo con errores: ntdll.dll, versión: 10.0.17134.376, marca de tiempo: 0x4358e406
Código de excepción: 0xc0000005
Desplazamiento de errores: 0x00092bbb
Identificador del proceso con errores: 0xc40
Hora de inicio de la aplicación con errores: 0x01d4914c545daac7
Ruta de acceso de la aplicación con errores: F:\UpdateService\RealPlayerUpdateSvc.exe
Ruta de acceso del módulo con errores: C:\WINDOWS\SYSTEM32\ntdll.dll
Identificador del informe: bd18f078-0b43-457e-946a-c70d1c3c4663
Nombre completo del paquete con errores:
Identificador de aplicación relativa del paquete con errores:
Error: (12/09/2018 01:06:55 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nombre de la aplicación con errores: RealPlayerUpdateSvc.exe, versión: 18.1.8.212, marca de tiempo: 0x5932053c
Nombre del módulo con errores: ntdll.dll, versión: 10.0.17134.376, marca de tiempo: 0x4358e406
Código de excepción: 0xc0000005
Desplazamiento de errores: 0x00092bbb
Identificador del proceso con errores: 0xc2c
Hora de inicio de la aplicación con errores: 0x01d48f4ee723372c
Ruta de acceso de la aplicación con errores: F:\UpdateService\RealPlayerUpdateSvc.exe
Ruta de acceso del módulo con errores: C:\WINDOWS\SYSTEM32\ntdll.dll
Identificador del informe: 88ef5768-60f5-4e53-8413-ded1ab1d2658
Nombre completo del paquete con errores:
Identificador de aplicación relativa del paquete con errores:
Error: (12/08/2018 10:47:12 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nombre de la aplicación con errores: RealPlayerUpdateSvc.exe, versión: 18.1.8.212, marca de tiempo: 0x5932053c
Nombre del módulo con errores: ntdll.dll, versión: 10.0.17134.376, marca de tiempo: 0x4358e406
Código de excepción: 0xc0000005
Desplazamiento de errores: 0x00092bbb
Identificador del proceso con errores: 0xd84
Hora de inicio de la aplicación con errores: 0x01d48f3b62362dce
Ruta de acceso de la aplicación con errores: F:\UpdateService\RealPlayerUpdateSvc.exe
Ruta de acceso del módulo con errores: C:\WINDOWS\SYSTEM32\ntdll.dll
Identificador del informe: ae51f878-3b88-4d44-b6e3-f4171f63b6f9
Nombre completo del paquete con errores:
Identificador de aplicación relativa del paquete con errores:
Error: (12/08/2018 02:56:38 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nombre de la aplicación con errores: MsiExec.exe, versión: 5.0.17134.228, marca de tiempo: 0xc71ce737
Nombre del módulo con errores: KERNELBASE.dll, versión: 10.0.17134.407, marca de tiempo: 0xade8d4fe
Código de excepción: 0xc06d007e
Desplazamiento de errores: 0x00111812
Identificador del proceso con errores: 0xe020
Hora de inicio de la aplicación con errores: 0x01d48efdd1f92a5a
Ruta de acceso de la aplicación con errores: C:\Windows\syswow64\MsiExec.exe
Ruta de acceso del módulo con errores: C:\WINDOWS\System32\KERNELBASE.dll
Identificador del informe: 0196d221-a5ed-4999-9a43-a0497dd6e042
Nombre completo del paquete con errores:
Identificador de aplicación relativa del paquete con errores:
System errors:
=============
Error: (12/19/2018 12:23:38 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: La configuración de permisos específico de la aplicación no concede el permiso Activación Local para la aplicación de servidor COM con CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
y APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
al usuario NT AUTHORITY\SERVICIO LOCAL con SID (S-1-5-19) en la dirección LocalHost (con LRPC) que se ejecuta en el contenedor de aplicaciones con SID No disponible (No disponible). Este permiso de seguridad se puede modificar mediante la herramienta administrativa Servicios de componentes.
Error: (12/19/2018 12:23:13 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-808CCCP)
Description: La configuración de permisos específico de la aplicación no concede el permiso Activación Local para la aplicación de servidor COM con CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
y APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
al usuario DESKTOP-808CCCP\Usuario con SID (S-1-5-21-2880194073-616569380-2500398765-1001) en la dirección LocalHost (con LRPC) que se ejecuta en el contenedor de aplicaciones con SID No disponible (No disponible). Este permiso de seguridad se puede modificar mediante la herramienta administrativa Servicios de componentes.
Error: (12/18/2018 11:52:37 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: La configuración de permisos específico de la aplicación no concede el permiso Activación Local para la aplicación de servidor COM con CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
y APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
al usuario NT AUTHORITY\SERVICIO LOCAL con SID (S-1-5-19) en la dirección LocalHost (con LRPC) que se ejecuta en el contenedor de aplicaciones con SID No disponible (No disponible). Este permiso de seguridad se puede modificar mediante la herramienta administrativa Servicios de componentes.
Error: (12/18/2018 12:13:16 AM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-808CCCP)
Description: La configuración de permisos específico de la aplicación no concede el permiso Activación Local para la aplicación de servidor COM con CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
y APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
al usuario DESKTOP-808CCCP\Usuario con SID (S-1-5-21-2880194073-616569380-2500398765-1001) en la dirección LocalHost (con LRPC) que se ejecuta en el contenedor de aplicaciones con SID No disponible (No disponible). Este permiso de seguridad se puede modificar mediante la herramienta administrativa Servicios de componentes.
Error: (12/16/2018 07:56:15 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: La configuración de permisos específico de la aplicación no concede el permiso Activación Local para la aplicación de servidor COM con CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
y APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
al usuario NT AUTHORITY\SERVICIO LOCAL con SID (S-1-5-19) en la dirección LocalHost (con LRPC) que se ejecuta en el contenedor de aplicaciones con SID No disponible (No disponible). Este permiso de seguridad se puede modificar mediante la herramienta administrativa Servicios de componentes.
Error: (12/16/2018 07:55:09 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-808CCCP)
Description: La configuración de permisos específico de la aplicación no concede el permiso Activación Local para la aplicación de servidor COM con CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
y APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
al usuario DESKTOP-808CCCP\Usuario con SID (S-1-5-21-2880194073-616569380-2500398765-1001) en la dirección LocalHost (con LRPC) que se ejecuta en el contenedor de aplicaciones con SID No disponible (No disponible). Este permiso de seguridad se puede modificar mediante la herramienta administrativa Servicios de componentes.
Error: (12/16/2018 05:26:12 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-808CCCP)
Description: La configuración de permisos específico de la aplicación no concede el permiso Activación Local para la aplicación de servidor COM con CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
y APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
al usuario DESKTOP-808CCCP\Usuario con SID (S-1-5-21-2880194073-616569380-2500398765-1001) en la dirección LocalHost (con LRPC) que se ejecuta en el contenedor de aplicaciones con SID No disponible (No disponible). Este permiso de seguridad se puede modificar mediante la herramienta administrativa Servicios de componentes.
Error: (12/16/2018 04:57:50 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: La configuración de permisos específico de la aplicación no concede el permiso Activación Local para la aplicación de servidor COM con CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
y APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
al usuario NT AUTHORITY\SERVICIO LOCAL con SID (S-1-5-19) en la dirección LocalHost (con LRPC) que se ejecuta en el contenedor de aplicaciones con SID No disponible (No disponible). Este permiso de seguridad se puede modificar mediante la herramienta administrativa Servicios de componentes.
Windows Defender:
===================================
Date: 2018-12-12 23:14:27.371
Description:
El examen de Antivirus de Windows Defender se detuvo antes de completarse.
Id. de examen: {A9601BEC-16AC-4304-99B6-B0B040280393}
Tipo de examen: Antimalware
Parámetros de examen: Examen rápido
Usuario: NT AUTHORITY\SYSTEM
Date: 2018-12-12 22:13:14.044
Description:
El examen de Antivirus de Windows Defender se detuvo antes de completarse.
Id. de examen: {120F1340-C226-4500-9B6B-00D8B9974681}
Tipo de examen: Antimalware
Parámetros de examen: Examen rápido
Usuario: NT AUTHORITY\SYSTEM
Date: 2018-12-06 16:37:38.972
Description:
Antivirus de Windows Defender detectó malware u otro software potencialmente no deseado.
Para obtener más información consulte lo siguiente:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:VBS/Donvibs&threatid=2147717778&enterprise=0
Nombre: Trojan:VBS/Donvibs
Id.: 2147717778
Gravedad: Grave
Categoría: Caballo de Troya
Ruta de acceso: containerfile:_F:\Descargas\Warcraft_El_origen_MicroHD_1080p.torrent.zip; containerfile:_F:\Descargas\Warcraft_El_origen_MicroHD_1080p.torrent\Warcraft_El_origen_MicroHD_1080p.torrent.vbe; file:_C:\Users\Usuario\AppData\Roaming\Microsoft\Windows\Recent\Warcraft_El_origen_MicroHD_1080p.torrent.zip.lnk; file:_F:\Descargas\Warcraft_El_origen_MicroHD_1080p.torrent.zip->Warcraft_El_origen_MicroHD_1080p.torrent.vbe->(EncScript); file:_F:\Descargas\Warcraft_El_origen_MicroHD_1080p.torrent\Warcraft_El_origen_MicroHD_1080p.torrent.vbe->(EncScript)
Origen de detección: Equipo local
Tipo de detección: Concreto
Fuente de detección: Usuario
Usuario: DESKTOP-808CCCP\Usuario
Nombre de proceso: Unknown
Versión de firma: AV: 1.281.1491.0, AS: 1.281.1491.0, NIS: 1.281.1491.0
Versión de motor: AM: 1.1.15400.5, NIS: 1.1.15400.5
Date: 2018-12-02 18:05:12.989
Description:
El examen de Antivirus de Windows Defender se detuvo antes de completarse.
Id. de examen: {97AD097A-29F3-4D7D-AC92-BF263657C003}
Tipo de examen: Antimalware
Parámetros de examen: Examen rápido
Usuario: NT AUTHORITY\SYSTEM
Date: 2018-12-01 13:40:21.393
Description:
El examen de Antivirus de Windows Defender se detuvo antes de completarse.
Id. de examen: {D5F8131C-9921-4C51-9435-E5D6A1C0F036}
Tipo de examen: Antimalware
Parámetros de examen: Examen rápido
Usuario: NT AUTHORITY\SYSTEM
Date: 2018-12-11 20:03:54.805
Description:
Antivirus de Windows Defender encontró un error al intentar actualizar las firmas.
Nueva versión de firma:
Versión de firma anterior: 1.283.351.0
Origen de actualización: Servidor de Microsoft Update
Tipo de firma: AntiVirus
Tipo de actualización: Completa
Usuario: NT AUTHORITY\SYSTEM
Versión de motor actual:
Versión de motor anterior: 1.1.15500.2
Código de error: 0x8007043c
Descripción del error: El servicio no puede iniciarse en modo a prueba de errores
Date: 2018-12-11 19:53:52.971
Description:
La característica Protección en tiempo real de Antivirus de Windows Defender encontró un error:
Característica: Durante el acceso
Código de error: 0x8007043c
Descripción del error: El servicio no puede iniciarse en modo a prueba de errores
Motivo: La protección antimalware dejó de funcionar por motivos desconocidos. En algunos casos, reiniciar el servicio puede que resuelva el problema.
Date: 2018-12-11 12:12:32.666
Description:
Antivirus de Windows Defender encontró un error al intentar actualizar las firmas.
Nueva versión de firma:
Versión de firma anterior: 1.283.274.0
Origen de actualización: Servidor de Microsoft Update
Tipo de firma: AntiVirus
Tipo de actualización: Completa
Usuario: NT AUTHORITY\SYSTEM
Versión de motor actual:
Versión de motor anterior: 1.1.15500.2
Código de error: 0x8007043c
Descripción del error: El servicio no puede iniciarse en modo a prueba de errores
Date: 2018-12-11 12:02:30.996
Description:
La característica Protección en tiempo real de Antivirus de Windows Defender encontró un error:
Característica: Durante el acceso
Código de error: 0x8007043c
Descripción del error: El servicio no puede iniciarse en modo a prueba de errores
Motivo: La protección antimalware dejó de funcionar por motivos desconocidos. En algunos casos, reiniciar el servicio puede que resuelva el problema.
Date: 2018-12-11 10:27:47.963
Description:
Antivirus de Windows Defender encontró un error al intentar actualizar las firmas.
Nueva versión de firma:
Versión de firma anterior: 1.283.274.0
Origen de actualización: Servidor de Microsoft Update
Tipo de firma: AntiVirus
Tipo de actualización: Completa
Usuario: NT AUTHORITY\SYSTEM
Versión de motor actual:
Versión de motor anterior: 1.1.15500.2
Código de error: 0x8007043c
Descripción del error: El servicio no puede iniciarse en modo a prueba de errores
CodeIntegrity:
===================================
Date: 2018-12-08 22:17:16.981
Description:
Code Integrity determined that a process (\Device\HarddiskVolume6\ProgramData\Microsoft\Windows Defender\Scans\MsMpEngCP.exe) attempted to load \Device\HarddiskVolume6\Program Files\Emsisoft Anti-Malware\a2hooks64.dll that did not meet the Store signing level requirements.
Date: 2018-12-08 22:17:15.975
Description:
Code Integrity determined that a process (\Device\HarddiskVolume6\ProgramData\Microsoft\Windows Defender\Platform\4.18.1810.5-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume6\Program Files\Emsisoft Anti-Malware\a2hooks64.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2018-12-08 22:17:15.972
Description:
Code Integrity determined that a process (\Device\HarddiskVolume6\Windows\System32\SecurityHealthService.exe) attempted to load \Device\HarddiskVolume6\Program Files\Emsisoft Anti-Malware\a2hooks64.dll that did not meet the Windows signing level requirements.
Date: 2018-12-08 22:17:13.411
Description:
Code Integrity determined that a process (\Device\HarddiskVolume6\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume6\Program Files\Emsisoft Anti-Malware\a2hooks64.dll that did not meet the Windows signing level requirements.
Date: 2018-12-08 22:17:12.553
Description:
Code Integrity determined that a process (\Device\HarddiskVolume6\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume6\Program Files\Emsisoft Anti-Malware\a2hooks64.dll that did not meet the Windows signing level requirements.
Date: 2018-12-06 18:11:37.076
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume6\Windows\InfusedApps\Applications\Microsoft.HEVCVideoExtension_1.0.2512.0_x64__8wekyb3d8bbwe\x86\hevcdecoder_store.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2018-12-06 18:11:37.063
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume6\Windows\InfusedApps\Applications\Microsoft.HEVCVideoExtension_1.0.2512.0_x64__8wekyb3d8bbwe\x86\hevcdecoder_store.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2018-12-06 18:11:36.225
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume6\Windows\InfusedApps\Applications\Microsoft.HEVCVideoExtension_1.0.2512.0_x64__8wekyb3d8bbwe\x64\hevcdecoder_store.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i5-6600K CPU @ 3.50GHz
Percentage of memory in use: 23%
Total physical RAM: 16307.14 MB
Available physical RAM: 12535.54 MB
Total Virtual: 18739.14 MB
Available Virtual: 14159.74 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:232.33 GB) (Free:63.47 GB) NTFS
Drive f: () (Fixed) (Total:931.39 GB) (Free:225.28 GB) NTFS
\\?\Volume{2b8b9b3e-eea9-4c90-9ee6-6c08b496106e}\ (Recuperación) (Fixed) (Total:0.44 GB) (Free:0.05 GB) NTFS
\\?\Volume{4717b2dd-b333-470a-9082-baf0900153ea}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Protective MBR) (Size: 931.5 GB) (Disk ID: 00000000)
Partition: GPT.
========================================================
Disk: 1 (Protective MBR) (Size: 232.9 GB) (Disk ID: 00000000)
Partition: GPT.
==================== End of Addition.txt ============================