Archivo VBS de Mejortorrentt

Buenas noches, hoy estaba buscando una peli y vi que era “buena web” mejortorrentt y descargué un zip lo descomprimí pensando que iba a ver el torrent y vi un archivo ,vbs. Entonces lo ejecuté, inocente de mi pensando que iba a abrirse el torrent o que se iba a descomprimir y que apareciera el torrent. Entonces se apagó el ordenador aunque yo antes el corté la luz (la corriente). Lo encendí borre los archivos con el Clean my PC y luego vi una carpeta rara que llevaba un vbs, El disco ha estado al 100% hasta que ya dejé de usar el Malwarebytes, Dejo el informe:

malware.txt (4,3 KB)

Gracias de antemano.

Buenas @ImSurface Bienvenido al Foro.!!!

Para revisar tu máquina, sigue estos pasos, en el orden indicado y leyendo todo lo explicado, realiza TODOS aunque alguno YA lo hayas realizado… :+1:

:one: Desactiva temporalmente el Antivirus :arrow_forward: Cómo deshabilitar temporalmente su Antivirus, mientras estemos realizando TODOS los pasos.

Vamos a descargar en TU ESCRITORIO(y NO en otro lugar :face_with_monocle:) todas las herramientas que vamos a utilizar en este procedimiento (pero no las ejecutes todavía) :


:two: Ejecutas las herramientas de una en una y en el orden indicado :



CCleaner.-

  • Instalas y Ejecutas CCleaner siguiendo los pasos indicados en el manual.

  • Úsalo primero en su opción de Limpiador para borrar cookies, temporales de Internet y todos los archivos que te muestre como obsoletos.

  • Después usa su opción de Registro para limpiar todo el registro de Windows(haciendo copia de seguridad).

Malwarebytes.-

  • Instalas y Ejecutas MBAM siguiendo los pasos indicados en el manual.

  • Realiza un Análisis Personalizado. :white_check_mark:

  • Seleccionando TODOS a Cuarentena para enviarlo a la cuarentena y Reinicias el sistema.

  • En el apartado del programa :arrow_forward: Historial de detecciones :arrow_backward: encontrarás el informe de MBAM, que debes copiar y pegar en tu próxima respuesta, para poder analizarlo.

AdwCleaner.-

  • Ejecuta Adwcleaner.exe.

  • Pulsamos en el botón Analizar ahora, y espera a que se realice el proceso, inmediatamente pulsa siempre sobre el botón Iniciar Reparación.

  • Espera a que se complete y sigue las instrucciones, si te pidiera Reiniciar el sistema Aceptas.

  • El log/informe lo encontramos en la pestaña “Informes”, volviendo a abrir el programa si fuese necesario, para poder copiarlo y pegarlo en tu próxima respuesta.

  • El informe también se puede encontrar en C:\AdwCleaner\Logs\AdwCleaner[C00].txt

Junkware Removal Tool.-

  • Ejecuta JRT.exe.

  • Y pulsar cualquier tecla para continuar, esperar pacientemente a que termine el proceso.

  • Si en algún momento te pide Reiniciar hazlo.

  • Al finalizar, un registro/informe (JRT.txt) se guardara en el escritorio y se abrirá automáticamente.

  • Copia y pega el contenido de JRT.txt en tu próxima respuesta.

Farbar Recovery Scan Tool.-

  • Ejecuta FRST.exe.

  • En el mensaje de la ventana del Disclaimer/Responsabilidad, pulsamos Sí/Yes

  • En la ventana principal pulsamos en el botón Analizar/Scan y esperamos a que concluya el proceso.

  • Se abrirán dos(2) archivos(Logs), Frst.txt y Addition.txt, estos quedaran grabados en el escritorio.

:three: Poner los informes en tu próxima respuesta de :

  • Malwarebytes, AdwCleaner, JRT, FRST + Addition.txt, y en ese orden. :+1:

Debes copiarlos y pegarlos con todo su contenido y usaras varios mensajes si recibes un mensaje de error indicando que es muy largo(más de 64.000 caracteres aprox.).

Y nos cuentas como funciona tu equipo en relación al problema planteado. :face_with_monocle:

Saludos Javier.

# -------------------------------
# Malwarebytes AdwCleaner 8.0.2.0
# -------------------------------
# Build:    01-27-2020
# Database: 2020-01-24.1 (Local)
# Support:  https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start:    02-22-2020
# Duration: 00:00:04
# OS:       Windows 10 Home
# Cleaned:  10
# Failed:   1


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

Deleted       C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CleanMyPC
Not Deleted   C:\Program Files\CleanMyPC

***** [ Files ] *****

No malicious files cleaned.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

Deleted       C:\Windows\System32\Tasks\CMPCUAC

***** [ Registry ] *****

Deleted       HKCU\Software\CleanMyPC
Deleted       HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{227B8D62-0B06-4F01-9569-8A7C38A3B4A9} 
Deleted       HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{227B8D62-0B06-4F01-9569-8A7C38A3B4A9} 
Deleted       HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\CMPCUAC
Deleted       HKLM\Software\CleanMyPC
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{90385FF3-6721-4DCD-AD11-FEBA397F4FE9}_is1
Deleted       HKU\.DEFAULT\Software\CleanMyPC
Deleted       HKU\S-1-5-18\Software\CleanMyPC

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.

***** [ Hosts File Entries ] *****

No malicious hosts file entries cleaned.

***** [ Preinstalled Software ] *****

No Preinstalled Software cleaned.


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [6167 octets] - [22/02/2020 23:19:26]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.4 (07.09.2017)
Operating System: Windows 10 Home x64 
Ran by Usuario (Administrator) on 22/02/2020 at 23:29:13,02
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 1 

Successfully deleted: C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio (Folder) 



Registry: 0 





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 22/02/2020 at 23:34:02,38
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

1-

Resultado del análisis realizado por Farbar Recovery Scan Tool (FRST) (x64) Versión: 16-02-2020
Ejecutado por Usuario (administrador) sobre LAPTOP-CTGO9569 (HP HP Laptop 15-db0xxx) (22-02-2020 23:35:22)
Ejecutado desde C:\Users\Usuario\Desktop
Perfiles cargados: Usuario (Perfiles disponibles: Usuario)
Platform: Windows 10 Home Versión 1809 17763.1039 (X64) Idioma: Español (España, internacional)
Navegador predeterminado: Edge
Modo de Inicio: Normal
Tutorial para Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Procesos (Lista blanca) =================

(Si una entrada es incluida en el fixlist, el proceso será cerrado. El archivo no será movido.)

(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
(Adobe Inc. -> Adobe Systems) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe
(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\amdow.exe
(Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe
(Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\c0351505.inf_amd64_5938a70929a31401\B351435\atiesrxx.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.442\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.442\GoogleCrashHandler64.exe
(HP Inc. -> HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(HP Inc. -> HP Inc.) C:\Program Files (x86)\HP\HP JumpStart Bridge\HPJumpStartBridge.exe
(HP Inc. -> HP Inc.) C:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe
(HP Inc. -> HP Inc.) C:\Program Files\HPCommRecovery\HPCommRecovery.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm_service.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 4.0\ksde.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 4.0\ksdeui.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Cloud 20.0\avp.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Cloud 20.0\avpui.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor Corp.) C:\Windows\RtkBtManServ.exe
(Piriform Software Ltd -> Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Windows\System32\SynTPEnh.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Windows\System32\SynTPEnhService.exe
(WildTangent Inc -> ) C:\Program Files (x86)\WildTangent Games\Integration\WildTangentHelperService.exe

==================== Registro (Lista blanca) ===================

(Si una entrada es incluida en el fixlist, el elemento del registro será restaurado a su valor predeterminado o será eliminado. El archivo no será movido.)

HKLM\...\Run: [RtlS5Wake] => C:\Program Files (x86)\Realtek\PCIE Wireless LAN\RtlS5Wake\RtlS5Wake.exe [2097600 2018-04-18] (Realtek Semiconductor Corp. -> Realtek)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9270560 2019-03-14] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Session] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1506176 2019-03-14] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2872400 2019-10-08] (Adobe Inc. -> Adobe Systems, Incorporated)
HKLM\...\Run: [PentabletService] => C:\Program Files\Pentablet\PentabletService.exe [2236688 2019-11-25] (Guangzhou Ugee Computers Technology Co.,Ltd -> Ugee Technology Company Ltd)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-11] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM\...\Run: [WindowsDefender] => "%ProgramFiles%\Windows Defender\MSASCuiL.exe"
HKLM-x32\...\Run: [HPMessageService] => C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe [707624 2018-08-08] (HP Inc. -> HP Inc.)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2084920 2019-09-27] (Adobe Inc. -> Adobe Inc.)
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2137744 2016-10-08] (Wondershare software CO., LIMITED -> Wondershare)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc. -> Apple Inc.)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrotray.exe [5314096 2020-02-04] (Adobe Inc. -> Adobe Systems Inc.)
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-1019904135-823791453-1890871877-1001\...\Run: [CCXProcess] => C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe [597640 2020-02-07] (Adobe Inc. -> Adobe Systems Incorporated)
HKU\S-1-5-21-1019904135-823791453-1890871877-1001\...\Run: [Gyazo] => C:\Program Files (x86)\Gyazo\GyStation.exe [913800 2019-12-03] (Nota Inc. -> Nota Inc.)
HKU\S-1-5-21-1019904135-823791453-1890871877-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3289040 2019-11-29] (Valve -> Valve Corporation)
HKU\S-1-5-21-1019904135-823791453-1890871877-1001\...\Run: [EpicGamesLauncher] => C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [36060048 2019-12-30] (Epic Games Inc. -> Epic Games, Inc.)
HKU\S-1-5-21-1019904135-823791453-1890871877-1001\...\Run: [uTorrent] => C:\Users\Usuario\AppData\Roaming\uTorrent\uTorrent.exe [1883888 2020-01-06] (BitTorrent Inc -> BitTorrent Inc.)
HKU\S-1-5-21-1019904135-823791453-1890871877-1001\...\Run: [kpm.exe] => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm.exe [580048 2020-02-20] (Kaspersky Lab -> AO Kaspersky Lab)
HKU\S-1-5-21-1019904135-823791453-1890871877-1001\...\Run: [PicPick Start] => C:\Program Files (x86)\PicPick\picpick.exe [23999848 2019-11-19] (NGWIN Software Co. -> NGWIN)
HKU\S-1-5-21-1019904135-823791453-1890871877-1001\...\Run: [Movistar Cloud] => C:\Program Files (x86)\Movistar Cloud\Movistar Cloud.exe [5606400 2019-12-30] () [Archivo no firmado]
HKU\S-1-5-21-1019904135-823791453-1890871877-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [24552064 2019-10-14] (Piriform Software Ltd -> Piriform Ltd)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\79.0.3945.130\Installer\chrmstp.exe [2020-01-22] (Google LLC -> Google LLC)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{9459C573-B17A-45AE-9F64-1857B5D58CEE}] -> C:\Program Files (x86)\Microsoft\Edge\Application\80.0.361.57\Installer\setup.exe [2020-02-21] (Microsoft Corporation -> Microsoft Corporation)
Startup: C:\Users\Usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DqhgXm.lnk [2020-02-22]

==================== Tareas programadas (Lista blanca) ============

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)

Task: {11E763EA-FCDB-408E-89F6-2B6D0C8B646B} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [608384 2019-10-14] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {1319FFD2-E312-46BD-A148-D44BD2E67E9D} - System32\Tasks\MicrosoftEdgeUpdateTaskMachineCore => C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe [223112 2020-02-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {2A067FFB-10C6-4E4B-B464-F1D80DF0AF04} - System32\Tasks\AdobeGCInvoker-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2872400 2019-10-08] (Adobe Inc. -> Adobe Systems, Incorporated)
Task: {320412D6-A419-42F7-9CD3-67691AD35617} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [158760 2020-02-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {35F345C8-314E-4BC9-8170-675F2976A98F} - System32\Tasks\GyazoUpdateTaskMachineDaily => C:\Program Files (x86)\Gyazo\GyazoUpdate.exe [6785448 2019-12-03] (Nota Inc. -> Nota Inc.)
Task: {4574975A-25E9-44C7-86E9-9AD3F3CBDA4A} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1240656 2019-09-11] (Adobe Inc. -> Adobe Systems)
Task: {4AB08D66-D031-4697-8AFF-6FA256F4DC19} - System32\Tasks\HPAudioSwitch => C:\Program Files (x86)\HP\HPAudioSwitch\HPAudioSwitch.exe [1644984 2018-07-18] (HP Inc. -> HP Inc.)
Task: {4B7CCDAE-6005-4749-A4CC-875F6991CD19} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [155432 2019-11-22] (Google Inc -> Google LLC)
Task: {517377B4-E93B-4698-8ED0-D81F3D33F310} - System32\Tasks\MicrosoftEdgeUpdateTaskMachineUA => C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe [223112 2020-02-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {55B936AF-9A31-49B7-87B9-11C965599C82} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [6128024 2020-02-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {5AD00910-434C-4ABA-9623-C415BCCC9AE9} - System32\Tasks\GyazoUpdateTaskMachine => C:\Program Files (x86)\Gyazo\GyazoUpdate.exe [6785448 2019-12-03] (Nota Inc. -> Nota Inc.)
Task: {5B721CB3-B161-4520-854D-5E68B27C724A} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [1506680 2019-06-14] (HP Inc. -> HP Inc.)
Task: {64A00AE3-F141-4A31-B2B2-AD8F872CEFF1} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018616 2020-02-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {65FF911F-E472-44E9-B76C-60F812D0165E} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [198696 2018-05-04] (HP Inc. -> HP Inc.)
Task: {660A7E75-97F2-4FAA-AD3C-868B4ACBA5C6} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [1114488 2020-01-07] (HP Inc. -> HP Inc.)
Task: {730DA1B5-3108-43E4-81F5-98B69B981100} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [1114488 2020-01-07] (HP Inc. -> HP Inc.)
Task: {74B91CE5-E24A-47B6-A4A9-EBEADF805BD9} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [18458752 2019-10-14] (Piriform Software Ltd -> Piriform Ltd)
Task: {7D00467A-7D2B-410C-8249-A86B2C76677C} - System32\Tasks\HPCeeScheduleForUsuario => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [97656 2018-09-11] (HP Inc. -> HP Inc.)
Task: {879DD58C-CB48-41AA-B0B7-A78C1B00D099} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [655736 2019-07-31] (HP Inc. -> HP Inc.)
Task: {89732F72-957D-4C48-AB8F-CE84F300E5C0} - System32\Tasks\HPJumpStartLaunch => C:\Program Files (x86)\HP\HP JumpStart Launch\HPJumpStartLaunch.exe [462696 2018-06-01] (HP Inc. -> HP Inc.)
Task: {8E167F4E-A4B4-4B75-A8DE-96C40A682DB3} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [24568904 2020-02-09] (Microsoft Corporation -> Microsoft Corporation)
Task: {8F524B67-4363-4805-A131-7FA1BB59F59E} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [24568904 2020-02-09] (Microsoft Corporation -> Microsoft Corporation)
Task: {9363573E-8EAC-476C-B164-D7849A34773C} - System32\Tasks\AMDLinkUpdate => C:\Program Files\AMD\CIM\BIN64\InstallManagerApp.exe [1628672 2020-01-30] (Advanced Micro Devices, Inc.) [Archivo no firmado]
Task: {988629A2-DF0D-411E-A693-6A56B2FD27F0} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [155432 2019-11-22] (Google Inc -> Google LLC)
Task: {AB7966E2-53C0-4585-AE8C-1775BFA72D47} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [145272 2019-10-31] (HP Inc. -> HP Inc.)
Task: {AE4ACC42-907B-42AE-9359-4B725B685BFF} - System32\Tasks\ModifyLinkUpdate => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1628672 2020-01-30] (Advanced Micro Devices, Inc.) [Archivo no firmado]
Task: {C2AE9BC9-B32C-42D7-B92A-F22B7370F04B} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [158760 2020-02-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {C3F43D0E-B490-4F4A-AF52-DDB344AD4CDA} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Product Configurator => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\ProductConfig.exe [308088 2020-02-12] (HP Inc. -> HP Inc.)
Task: {CF1F94D4-AC52-4CE2-BB3F-4BE53F941BBA} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [1506680 2019-06-14] (HP Inc. -> HP Inc.)
Task: {CF242905-D4AA-476F-83A2-021394FCC9C1} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater - Resources => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [655736 2019-07-31] (HP Inc. -> HP Inc.)
Task: {DC62C76C-9821-4972-A5C5-BB0C371B99E2} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018616 2020-02-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {DC934428-D49C-411A-ADB2-5F62DA7ADEE0} - System32\Tasks\AMDInstallLauncher => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1628672 2020-01-30] (Advanced Micro Devices, Inc.) [Archivo no firmado]
Task: {DFA1BB83-A25E-451E-A7CB-19C2AAA26A20} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [60008 2020-01-30] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
Task: {E1162656-FBE4-4BA4-B4BA-6745AD2F1FD1} - System32\Tasks\StartDVR => C:\Program Files\AMD\CNext\CNext\RSServCmd.exe [67688 2020-01-30] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
Task: {E31DC788-4D5D-40B6-801C-75E252BCC33D} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\windows\explorer.exe /NOUACCHECK
Task: {E4E64703-7512-4135-9445-D53C1A65DB25} - System32\Tasks\Opera scheduled Autoupdate 1575232255 => C:\Users\Usuario\AppData\Local\Programs\Opera\launcher.exe [1532952 2020-02-18] (Opera Software AS -> Opera Software)
Task: {E81DCA5B-5F1B-440F-A6E9-CB40A352A0A2} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [6128024 2020-02-04] (Microsoft Corporation -> Microsoft Corporation)

(Si una entrada es incluida en el fixlist, el archivo de tarea (.job) será movido. El archivo que está siendo ejecutado por la tarea no será movido.)

Task: C:\windows\Tasks\HPCeeScheduleForUsuario.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe

==================== Internet (Lista blanca) ====================

(Si un elemento es incluido en el fixlist, y éste pertenece al registro, será eliminado o restaurado a su valor predeterminado.)

Tcpip\Parameters: [DhcpNameServer] 80.58.61.250 80.58.61.254
Tcpip\..\Interfaces\{5a7f5856-17fa-4190-956e-5d8724554751}: [DhcpNameServer] 80.58.61.250 80.58.61.254

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp17win10.msn.com/?pc=HCTE
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp17win10.msn.com/?pc=HCTE
HKU\S-1-5-21-1019904135-823791453-1890871877-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp17win10.msn.com/?pc=HCTE
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll [2020-02-04] (Microsoft Corporation -> Microsoft Corporation)
BHO: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2020-02-04] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\root\Office16\GROOVEEX.DLL [2020-02-04] (Microsoft Corporation -> Microsoft Corporation)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2017-10-27] (HP Inc. -> HP Inc.)
BHO: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2020-02-04] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2020-02-04] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2020-02-04] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL [2020-02-04] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2017-10-27] (HP Inc. -> HP Inc.)
BHO-x32: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2020-02-04] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2020-02-04] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2020-02-04] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-02-04] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-02-04] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-02-04] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-02-04] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-02-04] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-02-04] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-02-04] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-02-04] (Microsoft Corporation -> Microsoft Corporation)

Edge: 
======
Edge DefaultProfile: Default
Edge Profile: C:\Users\Usuario\AppData\Local\Microsoft\Edge\User Data\Default [2020-02-22]
Edge Session Restore: Default -> está habilitado.
Edge Extension: (Fonts Ninja) - C:\Users\Usuario\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\eljapbgkmlngdpckoiiibecpemleclhh [2020-02-02]
Edge Extension: (Ver Imagen) - C:\Users\Usuario\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jpcmhcelnjdmblfmjabdeclccemkghjk [2020-02-04]
Edge Extension: (AdBlock: el mejor bloqueador de anuncios) - C:\Users\Usuario\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ndcileolkflehcjpmjnfbnaibdcgglog [2020-02-21]

FireFox:
========
FF DefaultProfile: vjpi4ld2.default
FF ProfilePath: C:\Users\Usuario\AppData\Roaming\Mozilla\Firefox\Profiles\vjpi4ld2.default [2020-01-10]
FF ProfilePath: C:\Users\Usuario\AppData\Roaming\Mozilla\Firefox\Profiles\n6y3u9ub.default-release [2020-02-22]
FF Extension: (Fontface Ninja) - C:\Users\Usuario\AppData\Roaming\Mozilla\Firefox\Profiles\n6y3u9ub.default-release\Extensions\@ffn.xpi [2020-01-10]
FF Extension: (uBlock Origin) - C:\Users\Usuario\AppData\Roaming\Mozilla\Firefox\Profiles\n6y3u9ub.default-release\Extensions\[email protected] [2020-01-10]
FF Extension: (Web Developer) - C:\Users\Usuario\AppData\Roaming\Mozilla\Firefox\Profiles\n6y3u9ub.default-release\Extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi [2020-01-18]
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi
FF Extension: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi [2020-02-04]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2020-02-04] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2019-09-27] (Adobe Inc. -> Adobe Systems)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2020-02-04] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2020-02-04] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2020-02-04] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2020-02-04] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2019-09-27] (Adobe Inc. -> Adobe Systems)
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\kl_prefs_62fbb8f7_c917_4cf7_957a_aad2b8fa768c.js [2020-01-10] <==== ATENCIÓN (Apunta a archivo *.cfg)
FF ExtraCheck: C:\Program Files\mozilla firefox\kl_config_62fbb8f7_c917_4cf7_957a_aad2b8fa768c.cfg [2020-01-10] <==== ATENCIÓN

Chrome: 
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default [2020-02-22]
CHR Session Restore: Default -> está habilitado.
CHR Extension: (Presentaciones) - C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-11-22]
CHR Extension: (Magic Actions for YouTube™) - C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\abjcfabbhafbcdfjoecdgepllmpfceif [2019-11-22]
CHR Extension: (Documentos) - C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-11-22]
CHR Extension: (Google Drive) - C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2019-11-22]
CHR Extension: (Web Developer) - C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfbameneiokkgbdmiekhjnmfkcnldhhm [2020-01-14]
CHR Extension: (YouTube) - C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-11-22]
CHR Extension: (uBlock Origin) - C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2020-02-09]
CHR Extension: (Telegram) - C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\clhhggbfdinjmjhajaheehoeibfljjno [2019-11-22]
CHR Extension: (Spotify - Music for every moment) - C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\cnkjkdjlofllcpbemipjbcpfnglbgieh [2019-11-22]
CHR Extension: (Calculator) - C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\decmldkknaaemlafplkkdmmmelbdnlja [2019-11-22]
CHR Extension: (PlayMax) - C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\dncmnmelaadhdoihlcbegdjfgkpaianf [2020-01-29]
CHR Extension: (Adobe Acrobat) - C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2019-12-10]
CHR Extension: (Fonts Ninja) - C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\eljapbgkmlngdpckoiiibecpemleclhh [2020-01-30]
CHR Extension: (Hojas de cálculo) - C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-11-22]
CHR Extension: (Caret) - C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\fljalecfjciodhpcledpamjachpmelml [2019-11-22]
CHR Extension: (EditThisCookie) - C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\fngmhnnpilhplaeedifhccceomclgfbg [2019-11-22]
CHR Extension: (OP.GG Extension) - C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbipjohhadjcagjjjhcooalfnkdlnfim [2020-01-30]
CHR Extension: (Documentos de Google sin conexión) - C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-01-07]
CHR Extension: (Google Keep: notas y listas) - C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki [2020-02-09]
CHR Extension: (Player para ver Movistar+) - C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\kenfcfndncbbggmafjjeihkdclggbojn [2020-01-21]
CHR Extension: (Screencastify - Screen Video Recorder) - C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmeijimgabbpbgpdklnllpncmdofkcpn [2020-02-09]
CHR Extension: (Sistema de pagos de Chrome Web Store) - C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-11-22]
CHR Extension: (System) - C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\ocjnemjmlhjkeilmaidemofakmpclcbi [2019-11-22]
CHR Extension: (Gravit Designer) - C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdagghjnpkeagmlbilmjmclfhjeaapaa [2020-01-23]
CHR Extension: (Modern Flat) - C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdcjjgefkpoemmlcjfcfkeminneboaob [2019-11-22]
CHR Extension: (Zed Code Editor) - C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfmjnmeipppmcebplngmhfkleiinphhp [2019-11-22]
CHR Extension: (Gmail) - C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-11-22]
CHR Extension: (Chrome Media Router) - C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-12-17]
CHR Extension: (Webflow Chrome Extension) - C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\poomgojobmjpninodpbopbeedkgcgiap [2019-11-22]
CHR HKLM\...\Chrome\Extension: [elhpdacimkjpccooodognopfhbdgnpbk] - hxxps://chrome.google.com/webstore/detail/elhpdacimkjpccooodognopfhbdgnpbk
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [elhpdacimkjpccooodognopfhbdgnpbk] - hxxps://chrome.google.com/webstore/detail/elhpdacimkjpccooodognopfhbdgnpbk

==================== Servicios (Lista blanca) ===================

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)

R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [823352 2019-09-27] (Adobe Inc. -> Adobe Inc.)
R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [3147344 2019-10-08] (Adobe Inc. -> Adobe Systems, Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2914896 2019-10-08] (Adobe Inc. -> Adobe Systems, Incorporated)
R2 AMD External Events Utility; C:\windows\System32\DriverStore\FileRepository\c0351505.inf_amd64_5938a70929a31401\B351435\atiesrxx.exe [522880 2020-02-03] (Advanced Micro Devices, Inc. -> AMD)
R2 AVP20.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Cloud 20.0\avp.exe [357416 2019-03-21] (Kaspersky Lab -> AO Kaspersky Lab)
S2 CleanMyPCService; C:\Program Files\CleanMyPC\CleanMyPCService.exe [498800 2019-12-20] (MacPaw INC -> MacPaw Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [11096432 2020-02-09] (Microsoft Corporation -> Microsoft Corporation)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [803440 2019-12-07] (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
S2 edgeupdate; C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe [223112 2020-02-01] (Microsoft Corporation -> Microsoft Corporation)
S3 edgeupdatem; C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe [223112 2020-02-01] (Microsoft Corporation -> Microsoft Corporation)
R2 HP Comm Recover; C:\Program Files\HPCommRecovery\HPCommRecovery.exe [1321096 2018-09-28] (HP Inc. -> HP Inc.)
R2 HPJumpStartBridge; c:\Program Files (x86)\HP\HP JumpStart Bridge\HPJumpStartBridge.exe [478056 2018-06-01] (HP Inc. -> HP Inc.)
S3 hpqcaslwmiex; C:\Program Files (x86)\HP\Shared\hpqwmiex.exe [1031704 2016-06-03] (Hewlett-Packard Company -> HP)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [361848 2019-12-06] (HP Inc. -> HP Inc.)
R2 HPWMISVC; c:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe [628768 2017-07-13] (HP Inc. -> HP Inc.)
S3 klvssbridge64_20.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Cloud 20.0\x64\vssbridge64.exe [438928 2019-03-21] (Kaspersky Lab -> AO Kaspersky Lab)
R2 kpm_launch_service; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm_service.exe [354152 2020-02-20] (Kaspersky Lab -> AO Kaspersky Lab)
R2 KSDE4.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 4.0\ksde.exe [619752 2019-03-21] (Kaspersky Lab -> AO Kaspersky Lab)
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [6960640 2020-02-22] (Malwarebytes Inc -> Malwarebytes)
S3 MicrosoftEdgeElevationService; C:\Program Files (x86)\Microsoft\Edge\Application\80.0.361.57\elevation_service.exe [1093512 2020-02-21] (Microsoft Corporation -> Microsoft Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2475312 2019-12-17] (Electronic Arts, Inc. -> Electronic Arts)
S2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3352376 2019-12-17] (Electronic Arts, Inc. -> Electronic Arts)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [267552 2019-03-14] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
R2 RtkBtManServ; C:\windows\RtkBtManServ.exe [738712 2020-01-11] (Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor Corp.)
R2 SynTPEnhService; C:\windows\System32\SynTPEnhService.exe [383240 2019-12-04] (Synaptics Incorporated -> Synaptics Incorporated)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [3831576 2019-11-23] (Microsoft Corporation -> Microsoft Corporation)
R2 WildTangentHelper; C:\Program Files (x86)\WildTangent Games\Integration\WildTangentHelperService.exe [1657136 2020-02-12] (WildTangent Inc -> )
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [110944 2018-09-15] (Microsoft Corporation -> Microsoft Corporation)

===================== Controladores (Lista blanca) ===================

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)

R3 amdacpbus; C:\windows\System32\drivers\amdacpbus.sys [1368720 2019-12-06] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices)
R3 amdgpio2; C:\windows\System32\drivers\amdgpio2.sys [34568 2018-10-29] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc)
R3 AMDHDAudBusService; C:\windows\System32\drivers\amdhdaudbus.sys [77800 2018-10-29] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices)
R3 amdkmdag; C:\windows\System32\DriverStore\FileRepository\c0351505.inf_amd64_5938a70929a31401\B351435\atikmdag.sys [65740416 2020-02-03] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
R3 amdkmdap; C:\windows\System32\DriverStore\FileRepository\c0351505.inf_amd64_5938a70929a31401\B351435\atikmpag.sys [590464 2020-02-03] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
R0 amdpsp; C:\windows\System32\drivers\amdpsp.sys [137688 2018-10-29] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc. )
S3 AmUStor; C:\windows\system32\drivers\AmUStor.SYS [108480 2018-09-07] (Alcorlink Corp. -> )
S3 AppleLowerFilter; C:\windows\System32\drivers\AppleLowerFilter.sys [35560 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
R3 AtiHDAudioService; C:\windows\system32\drivers\AtihdWT6.sys [108152 2019-07-24] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices)
R0 cm_km; C:\windows\System32\DRIVERS\cm_km.sys [246912 2019-02-16] (Kaspersky Lab -> AO Kaspersky Lab)
S3 HPCustomCapDriver; C:\windows\System32\DriverStore\FileRepository\hpcustomcapdriver.inf_amd64_1f5602eb8a12ac4c\x64\hpcustomcapdriver.sys [23960 2018-07-06] (HP Inc. -> HP Inc.)
R0 klbackupdisk; C:\windows\System32\DRIVERS\klbackupdisk.sys [79768 2020-02-12] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klbackupflt; C:\windows\System32\DRIVERS\klbackupflt.sys [145504 2020-02-12] (Kaspersky Lab -> AO Kaspersky Lab)
R1 kldisk; C:\windows\system32\DRIVERS\kldisk.sys [93312 2019-03-12] (Kaspersky Lab -> AO Kaspersky Lab)
S0 klelam; C:\windows\System32\DRIVERS\klelam.sys [37816 2019-01-24] (Microsoft Windows Early Launch Anti-malware Publisher -> AO Kaspersky Lab)
R3 klflt; C:\windows\system32\DRIVERS\klflt.sys [251512 2019-10-30] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klgse; C:\windows\System32\DRIVERS\klgse.sys [516216 2019-09-17] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klhk; C:\windows\system32\DRIVERS\klhk.sys [1123664 2019-10-17] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klids; C:\ProgramData\Kaspersky Lab\AVP20.0\Bases\klids.sys [201280 2019-12-16] (Kaspersky Lab -> AO Kaspersky Lab)
R1 KLIF; C:\windows\System32\DRIVERS\klif.sys [998296 2020-02-12] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klim6; C:\windows\system32\DRIVERS\klim6.sys [58192 2019-03-19] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klkbdflt; C:\windows\system32\DRIVERS\klkbdflt.sys [79184 2019-03-18] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klmouflt; C:\windows\system32\DRIVERS\klmouflt.sys [59512 2019-03-18] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klpd; C:\windows\System32\DRIVERS\klpd.sys [51328 2019-03-13] (Kaspersky Lab -> AO Kaspersky Lab)
S3 klpnpflt; C:\windows\system32\DRIVERS\klpnpflt.sys [45904 2019-03-10] (Kaspersky Lab -> AO Kaspersky Lab)
R3 kltap; C:\windows\System32\drivers\kltap.sys [48592 2018-03-16] (AnchorFree Inc -> The OpenVPN Project)
R0 klupd_klif_arkmon; C:\windows\System32\Drivers\klupd_klif_arkmon.sys [251256 2019-12-08] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klupd_klif_kimul; C:\windows\System32\Drivers\klupd_klif_kimul.sys [99152 2019-12-08] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klupd_klif_klark; C:\windows\System32\Drivers\klupd_klif_klark.sys [306248 2019-12-08] (Kaspersky Lab -> AO Kaspersky Lab)
R0 klupd_klif_klbg; C:\windows\System32\Drivers\klupd_klif_klbg.sys [119744 2019-12-08] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klupd_klif_mark; C:\windows\System32\Drivers\klupd_klif_mark.sys [204520 2019-12-08] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klwfp; C:\windows\system32\DRIVERS\klwfp.sys [105600 2019-03-05] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klwtp; C:\windows\system32\DRIVERS\klwtp.sys [211048 2019-12-19] (Kaspersky Lab -> AO Kaspersky Lab)
R1 kneps; C:\windows\system32\DRIVERS\kneps.sys [232272 2019-03-19] (Kaspersky Lab -> AO Kaspersky Lab)
S0 MbamElam; C:\windows\System32\DRIVERS\MbamElam.sys [20936 2020-02-22] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
S3 Netwtw04; C:\windows\System32\drivers\Netwtw04.sys [7708160 2018-09-15] (Microsoft Windows -> Intel Corporation)
R3 rt640x64; C:\windows\System32\drivers\rt640x64.sys [1118648 2018-10-04] (Realtek Semiconductor Corp. -> Realtek )
R3 RtkBtFilter; C:\windows\System32\drivers\RtkBtfilter.sys [787232 2020-01-11] (WDKTestCert VSAuto,131800073559665678 -> Realtek Semiconductor Corporation)
R3 RTWlanE; C:\windows\System32\drivers\rtwlane.sys [11722328 2019-12-04] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corporation )
R3 SmbDrv; C:\windows\System32\drivers\Smb_driver_AMDASF.sys [48904 2019-12-04] (Synaptics Incorporated -> Synaptics Incorporated)
S3 SmbDrvI; C:\windows\System32\drivers\Smb_driver_Intel.sys [48168 2018-10-26] (Synaptics Incorporated -> Synaptics Incorporated)
S3 SynRMIHID; C:\windows\System32\drivers\SynRMIHID.sys [63016 2018-10-26] (Synaptics Incorporated -> Synaptics Incorporated)
R3 vmulti; C:\windows\System32\drivers\vmulti.sys [10752 2018-12-11] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
S0 WdBoot; C:\windows\System32\drivers\WdBoot.sys [46584 2018-09-15] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\windows\System32\drivers\WdFilter.sys [340008 2018-09-15] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\windows\System32\Drivers\WdNisDrv.sys [61992 2018-09-15] (Microsoft Windows -> Microsoft Corporation)
R3 WirelessButtonDriver64; C:\windows\System32\drivers\WirelessButtonDriver64.sys [35392 2019-11-15] (HP Inc. -> HP)
S3 H2OFFT; \SystemRoot\System32\drivers\H2OFFT64.sys [X]

==================== NetSvcs (Lista blanca) ===================

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)


==================== Un mes (creado) ===================

(Si una entrada es incluida en el fixlist, el archivo/carpeta será eliminado/a.)

2020-02-22 23:35 - 2020-02-22 23:37 - 000042534 _____ C:\Users\Usuario\Desktop\FRST.txt
2020-02-22 23:34 - 2020-02-22 23:36 - 000000000 ____D C:\FRST
2020-02-22 23:34 - 2020-02-22 23:34 - 000000689 _____ C:\Users\Usuario\Desktop\JRT.txt
2020-02-22 23:19 - 2020-02-22 23:19 - 000002310 _____ C:\Users\Usuario\Desktop\AdwCleaner[C00].txt
2020-02-22 23:17 - 2020-02-22 23:19 - 000000000 ____D C:\AdwCleaner
2020-02-22 23:10 - 2020-02-22 23:10 - 000502984 _____ C:\Users\Usuario\Documents\cc_20200222_231037.reg
2020-02-22 23:06 - 2020-02-22 23:30 - 000004210 _____ C:\windows\system32\Tasks\CCleaner Update
2020-02-22 23:06 - 2020-02-22 23:06 - 000002892 _____ C:\windows\system32\Tasks\CCleanerSkipUAC
2020-02-22 23:06 - 2020-02-22 23:06 - 000000870 _____ C:\Users\Public\Desktop\CCleaner.lnk
2020-02-22 23:06 - 2020-02-22 23:06 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2020-02-22 23:06 - 2020-02-22 23:06 - 000000000 ____D C:\Program Files\CCleaner
2020-02-22 22:52 - 2020-02-22 22:52 - 024578944 _____ (Piriform Software Ltd) C:\Users\Usuario\Desktop\ccsetup563.exe
2020-02-22 22:51 - 2020-02-22 22:51 - 008356016 _____ (Malwarebytes) C:\Users\Usuario\Desktop\adwcleaner_8.0.2.exe
2020-02-22 22:50 - 2020-02-22 22:51 - 002279424 _____ (Farbar) C:\Users\Usuario\Desktop\FRST64.exe
2020-02-22 22:49 - 2020-02-22 22:49 - 024578944 _____ (Piriform Software Ltd) C:\Users\Usuario\Downloads\ccsetup563.exe
2020-02-22 22:49 - 2020-02-22 22:49 - 001790024 _____ (Malwarebytes) C:\Users\Usuario\Downloads\JRT.exe
2020-02-22 22:49 - 2020-02-22 22:49 - 001790024 _____ (Malwarebytes) C:\Users\Usuario\Desktop\JRT (1).exe
2020-02-22 21:58 - 2020-02-22 21:58 - 000000000 ____D C:\Users\Usuario\Downloads\Parasitos [720p][Castellano][wWw.EliteTorrent.BZ]
2020-02-22 21:55 - 2020-02-22 21:55 - 000020968 _____ C:\Users\Usuario\Downloads\1581885351-Parasitos [720p][Castellano][wWw.EliteTorrent.BZ].torrent
2020-02-22 21:17 - 2020-02-22 21:17 - 000004386 _____ C:\Users\Usuario\Desktop\malwarebytes.txt
2020-02-22 20:58 - 2020-02-22 20:58 - 000002028 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2020-02-22 20:58 - 2020-02-22 20:58 - 000000000 ____D C:\Users\Usuario\AppData\Local\mbamtray
2020-02-22 20:58 - 2020-02-22 20:58 - 000000000 ____D C:\Users\Usuario\AppData\Local\mbam
2020-02-22 20:58 - 2020-02-22 20:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2020-02-22 20:57 - 2020-02-22 20:57 - 000153312 _____ (Malwarebytes) C:\windows\system32\Drivers\mbae64.sys
2020-02-22 20:57 - 2020-02-22 20:57 - 000020936 _____ (Malwarebytes) C:\windows\system32\Drivers\MbamElam.sys
2020-02-22 20:57 - 2020-02-22 20:57 - 000000000 ____D C:\ProgramData\Malwarebytes
2020-02-22 20:56 - 2020-02-22 20:56 - 001883976 _____ (Malwarebytes) C:\Users\Usuario\Downloads\MBSetup-009996.009996-consumer.exe
2020-02-22 20:56 - 2020-02-22 20:56 - 000000000 ____D C:\Program Files\Malwarebytes
2020-02-22 20:46 - 2020-02-22 20:49 - 000000000 ___HD C:\$SysReset

2-

2020-02-22 20:21 - 2020-02-22 20:22 - 000603136 _____ C:\windows\system32\FNTCACHE.DAT
2020-02-22 20:01 - 2020-02-22 20:05 - 000000000 ____D C:\Users\Usuario\AppData\Roaming\Telegram Desktop
2020-02-22 20:01 - 2020-02-22 20:01 - 021655176 _____ (Telegram FZ-LLC ) C:\Users\Usuario\Downloads\tsetup.1.9.14.exe
2020-02-22 20:01 - 2020-02-22 20:01 - 000000000 ____D C:\Users\Usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Telegram Desktop
2020-02-22 19:42 - 2020-02-22 19:42 - 000000000 ____D C:\ProgramData\Intel
2020-02-22 19:42 - 2020-02-22 19:42 - 000000000 ____D C:\ffbbg
2020-02-21 18:11 - 2020-02-21 18:11 - 000000000 ____D C:\Users\Usuario\AppData\Local\FelixDCXAppID
2020-02-20 19:25 - 2020-02-20 19:34 - 000000000 ____D C:\USB 32
2020-02-20 15:24 - 2020-02-22 20:50 - 000000000 ___RD C:\Users\Usuario\Movistar Cloud
2020-02-20 15:23 - 2020-02-20 15:23 - 000000000 ____D C:\Users\Usuario\AppData\Local\Movistar-Cloud
2020-02-20 15:23 - 2020-02-20 15:23 - 000000000 ____D C:\ProgramData\Movistar-Cloud
2020-02-20 15:21 - 2020-02-20 15:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movistar Cloud
2020-02-20 15:21 - 2020-02-20 15:21 - 000000000 ____D C:\Program Files (x86)\Movistar Cloud
2020-02-20 15:20 - 2020-02-20 15:21 - 081537808 _____ (Movistar-Cloud) C:\Users\Usuario\Downloads\windows-app-installer.exe
2020-02-19 14:41 - 2020-02-01 07:36 - 000801080 _____ (Microsoft Corporation) C:\windows\system32\sedplugins.dll
2020-02-18 18:46 - 2020-02-22 23:23 - 000003130 _____ C:\windows\system32\Tasks\AMDInstallLauncher
2020-02-18 18:45 - 2020-02-18 18:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Radeon Software
2020-02-18 18:44 - 2020-02-18 18:44 - 000000000 ____D C:\Program Files (x86)\AMD
2020-02-18 18:38 - 2020-02-03 18:38 - 001763968 _____ C:\windows\system32\vulkaninfo-1-999-0-0-0.exe
2020-02-18 18:38 - 2020-02-03 18:38 - 001763968 _____ C:\windows\system32\vulkaninfo.exe
2020-02-18 18:38 - 2020-02-03 18:38 - 001592448 _____ (AMD) C:\windows\system32\coinst_19.50.dll
2020-02-18 18:38 - 2020-02-03 18:38 - 001358464 _____ C:\windows\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2020-02-18 18:38 - 2020-02-03 18:38 - 001358464 _____ C:\windows\SysWOW64\vulkaninfo.exe
2020-02-18 18:38 - 2020-02-03 18:38 - 001083944 _____ C:\windows\system32\vulkan-1-999-0-0-0.dll
2020-02-18 18:38 - 2020-02-03 18:38 - 001083944 _____ C:\windows\system32\vulkan-1.dll
2020-02-18 18:38 - 2020-02-03 18:38 - 000942792 _____ C:\windows\SysWOW64\vulkan-1-999-0-0-0.dll
2020-02-18 18:38 - 2020-02-03 18:38 - 000942792 _____ C:\windows\SysWOW64\vulkan-1.dll
2020-02-18 18:38 - 2020-02-03 18:38 - 000483968 _____ (Advanced Micro Devices, Inc.) C:\windows\SysWOW64\Rapidfire.dll
2020-02-18 18:38 - 2020-02-03 18:38 - 000372864 _____ C:\windows\SysWOW64\GameManager32.dll
2020-02-18 18:38 - 2020-02-03 18:38 - 000151680 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\mantle32.dll
2020-02-18 18:38 - 2020-02-03 18:38 - 000136832 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\mantleaxl32.dll
2020-02-18 18:38 - 2020-02-03 18:38 - 000042624 _____ (Advanced Micro Devices, Inc.) C:\windows\SysWOW64\RapidFireServer.dll
2020-02-18 18:38 - 2020-02-03 18:38 - 000019384 _____ (Microsoft Corporation) C:\windows\SysWOW64\detoured.dll
2020-02-18 18:38 - 2020-02-03 18:38 - 000019384 _____ (Microsoft Corporation) C:\windows\system32\detoured.dll
2020-02-18 18:38 - 2020-01-30 17:25 - 003471376 _____ C:\windows\SysWOW64\atiumdva.cap
2020-02-18 18:38 - 2019-08-19 19:06 - 000125488 _____ C:\windows\system32\kapp_ci.sbin
2020-02-18 18:37 - 2020-02-03 18:38 - 000344192 _____ C:\windows\SysWOW64\atieah32.exe
2020-02-18 18:37 - 2020-02-03 18:38 - 000207488 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\atigktxx.dll
2020-02-18 18:37 - 2020-02-03 18:38 - 000134784 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\atisamu32.dll
2020-02-18 18:37 - 2020-02-03 18:37 - 062866048 _____ C:\windows\system32\amd_comgr.dll
2020-02-18 18:37 - 2020-02-03 18:37 - 052402032 _____ C:\windows\SysWOW64\amd_comgr32.dll
2020-02-18 18:37 - 2020-02-03 18:37 - 004092544 _____ (Advanced Micro Devices, Inc.) C:\windows\SysWOW64\amfrt32.dll
2020-02-18 18:37 - 2020-02-03 18:37 - 001241728 _____ (Advanced Micro Devices, Inc.) C:\windows\SysWOW64\atiadlxy.dll
2020-02-18 18:37 - 2020-02-03 18:37 - 001241728 _____ (Advanced Micro Devices, Inc.) C:\windows\SysWOW64\atiadlxx.dll
2020-02-18 18:37 - 2020-02-03 18:37 - 000767616 _____ (Advanced Micro Devices, Inc.) C:\windows\SysWOW64\amdlvr32.dll
2020-02-18 18:37 - 2020-02-03 18:37 - 000482944 _____ C:\windows\system32\amdgfxinfo64.dll
2020-02-18 18:37 - 2020-02-03 18:37 - 000467584 _____ (Advanced Micro Devices, Inc.) C:\windows\system32\atidemgy.dll
2020-02-18 18:37 - 2020-02-03 18:37 - 000382592 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\amdmcl32.dll
2020-02-18 18:37 - 2020-02-03 18:37 - 000372352 _____ C:\windows\SysWOW64\amdgfxinfo32.dll
2020-02-18 18:37 - 2020-02-03 18:37 - 000133760 _____ (Khronos Group) C:\windows\system32\OpenCL.dll
2020-02-18 18:37 - 2020-02-03 18:37 - 000119936 _____ (Khronos Group) C:\windows\SysWOW64\OpenCL.dll
2020-02-18 18:37 - 2020-02-03 18:37 - 000105600 _____ C:\windows\SysWOW64\atidxx32.dll
2020-02-18 18:37 - 2020-02-03 18:37 - 000104576 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\amdxc32.dll
2020-02-18 18:37 - 2020-02-03 18:37 - 000069248 _____ (Advanced Micro Devices, Inc.) C:\windows\system32\ati2erec.dll
2020-02-18 18:37 - 2020-02-03 18:35 - 000118848 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\amdave32.dll
2020-02-18 18:37 - 2020-02-03 18:35 - 000106832 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\atimpc32.dll
2020-02-18 18:37 - 2020-02-03 18:35 - 000106832 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\amdpcom32.dll
2020-02-18 18:37 - 2020-01-30 17:16 - 000542696 _____ C:\windows\SysWOW64\atiapfxx.blb
2020-02-18 18:37 - 2019-07-16 20:58 - 000069770 _____ C:\windows\system32\AMDKernelEvents.man
2020-02-18 18:36 - 2020-02-18 18:36 - 040545000 _____ (AMD Inc.) C:\Users\Usuario\Downloads\radeon-software-adrenalin-2020-20.2.1-minimalsetup-200203_64bit.exe
2020-02-18 15:04 - 2020-02-22 23:23 - 000003116 _____ C:\windows\system32\Tasks\AMDLinkUpdate
2020-02-13 15:08 - 2020-02-03 22:41 - 000835688 _____ (Adobe) C:\windows\SysWOW64\FlashPlayerApp.exe
2020-02-13 15:08 - 2020-02-03 22:41 - 000179608 _____ (Adobe) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2020-02-12 22:30 - 2020-02-12 22:30 - 000000000 ____D C:\ProgramData\ssh
2020-02-12 18:24 - 2020-02-12 18:24 - 024617472 _____ (Microsoft Corporation) C:\windows\system32\Hydrogen.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 020816384 _____ (Microsoft Corporation) C:\windows\SysWOW64\edgehtml.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 019020288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 013013504 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 012306432 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 008906752 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 007923712 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 006061056 _____ (Microsoft Corporation) C:\windows\SysWOW64\Chakra.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 005436936 _____ (Microsoft Corporation) C:\windows\system32\mfcore.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 004658688 _____ (Microsoft Corporation) C:\windows\system32\msi.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 004488192 _____ (Microsoft Corporation) C:\windows\system32\xpsrchvw.exe
2020-02-12 18:24 - 2020-02-12 18:24 - 003904000 _____ (Microsoft Corporation) C:\windows\SysWOW64\msi.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 003702784 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 003550592 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfcore.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 003442176 _____ (Microsoft Corporation) C:\windows\SysWOW64\xpsrchvw.exe
2020-02-12 18:24 - 2020-02-12 18:24 - 002942976 _____ (Microsoft Corporation) C:\windows\SysWOW64\mispace.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 002469432 _____ (Microsoft Corporation) C:\windows\system32\msmpeg2vdec.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 002323904 _____ (Microsoft Corporation) C:\windows\SysWOW64\msmpeg2vdec.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 002298880 _____ (Microsoft Corporation) C:\windows\system32\ResetEngine.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 002273080 _____ (Microsoft Corporation) C:\windows\system32\mfasfsrcsnk.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 001877168 _____ (Microsoft Corporation) C:\windows\system32\mfsrcsnk.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 001430672 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfsrcsnk.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 001292288 _____ (Microsoft Corporation) C:\windows\system32\werconcpl.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 001288856 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfasfsrcsnk.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 001267216 _____ (Microsoft Corporation) C:\windows\system32\SecConfig.efi
2020-02-12 18:24 - 2020-02-12 18:24 - 001229824 _____ (Microsoft Corporation) C:\windows\system32\HoloSI.PCShell.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 001224704 _____ (Microsoft Corporation) C:\windows\system32\reseteng.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 001182720 _____ (Microsoft Corporation) C:\windows\system32\wscui.cpl
2020-02-12 18:24 - 2020-02-12 18:24 - 001166336 _____ (Microsoft Corporation) C:\windows\SysWOW64\wscui.cpl
2020-02-12 18:24 - 2020-02-12 18:24 - 001071616 _____ (Microsoft Corporation) C:\windows\HelpPane.exe
2020-02-12 18:24 - 2020-02-12 18:24 - 001062400 _____ (Microsoft Corporation) C:\windows\system32\sysmain.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 000912384 _____ (Microsoft Corporation) C:\windows\system32\EdgeManager.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 000883200 _____ (Microsoft Corporation) C:\windows\system32\CPFilters.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 000833024 _____ (Microsoft Corporation) C:\windows\SysWOW64\webplatstorageserver.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 000796160 _____ (Microsoft Corporation) C:\windows\SysWOW64\clusapi.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 000690688 _____ (Microsoft Corporation) C:\windows\SysWOW64\CPFilters.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 000684544 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 000663040 _____ (Microsoft Corporation) C:\windows\SysWOW64\EdgeManager.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 000594432 _____ (Microsoft Corporation) C:\windows\system32\HolographicExtensions.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 000560640 _____ (Microsoft Corporation) C:\windows\SysWOW64\dfrgui.exe
2020-02-12 18:24 - 2020-02-12 18:24 - 000486912 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 000480256 _____ (Microsoft Corporation) C:\windows\SysWOW64\resutils.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 000430592 _____ (Microsoft Corporation) C:\windows\system32\rdpclip.exe
2020-02-12 18:24 - 2020-02-12 18:24 - 000428544 _____ (Microsoft Corporation) C:\windows\SysWOW64\werui.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 000370176 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieproxy.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 000310784 _____ (Microsoft Corporation) C:\windows\system32\tapisrv.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 000269312 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2020-02-12 18:24 - 2020-02-12 18:24 - 000263576 _____ (Microsoft Corporation) C:\windows\system32\mfps.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 000252928 _____ (Microsoft Corporation) C:\windows\SysWOW64\tapisrv.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 000249344 _____ (Microsoft Corporation) C:\windows\system32\srrstr.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 000218624 _____ (Microsoft Corporation) C:\windows\system32\wscinterop.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 000217088 _____ (Microsoft Corporation) C:\windows\system32\DWWIN.EXE
2020-02-12 18:24 - 2020-02-12 18:24 - 000212480 _____ (Microsoft Corporation) C:\windows\system32\DiagSvc.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 000194048 _____ (Microsoft Corporation) C:\windows\system32\recdisc.exe
2020-02-12 18:24 - 2020-02-12 18:24 - 000180736 _____ (Microsoft Corporation) C:\windows\SysWOW64\DWWIN.EXE
2020-02-12 18:24 - 2020-02-12 18:24 - 000180224 _____ (Microsoft Corporation) C:\windows\system32\rdsdwmdr.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 000165888 _____ (Microsoft Corporation) C:\windows\SysWOW64\wscinterop.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 000127488 _____ (Microsoft Corporation) C:\windows\SysWOW64\fdWSD.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 000122880 _____ (Microsoft Corporation) C:\windows\system32\wercplsupport.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 000096256 _____ (Microsoft Corporation) C:\windows\system32\msfeedsbs.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 000089088 _____ (Microsoft Corporation) C:\windows\SysWOW64\fdSSDP.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 000080384 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeedsbs.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 000069120 _____ (Microsoft Corporation) C:\windows\system32\fveskybackup.dll
2020-02-12 18:24 - 2020-02-12 18:24 - 000059904 _____ (Microsoft Corporation) C:\windows\system32\RDSPnf.exe
2020-02-12 18:24 - 2020-02-12 18:24 - 000057856 _____ (Microsoft Corporation) C:\windows\system32\SrTasks.exe
2020-02-12 18:23 - 2020-02-12 18:24 - 026806784 _____ (Microsoft Corporation) C:\windows\system32\edgehtml.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 023463424 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 007870976 _____ (Microsoft Corporation) C:\windows\system32\Chakra.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 006943232 _____ (Microsoft Corporation) C:\windows\system32\twinui.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 006546296 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Media.Protection.PlayReady.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 006445568 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Data.Pdf.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 006318544 _____ (Microsoft Corporation) C:\windows\SysWOW64\windows.storage.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 005777920 _____ (Microsoft Corporation) C:\windows\SysWOW64\twinui.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 005608328 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 005086208 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 004872704 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 004628992 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 003874936 _____ (Microsoft Corporation) C:\windows\SysWOW64\explorer.exe
2020-02-12 18:23 - 2020-02-12 18:23 - 003656704 _____ (Microsoft Corporation) C:\windows\system32\mispace.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 003430400 _____ (Microsoft Corporation) C:\windows\SysWOW64\cdp.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 002780296 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 002770944 _____ (Microsoft Corporation) C:\windows\SysWOW64\msftedit.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 002765312 _____ (Microsoft Corporation) C:\windows\SysWOW64\tquery.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 002699264 _____ (Microsoft Corporation) C:\windows\system32\WebRuntimeManager.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 002627600 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ntfs.sys
2020-02-12 18:23 - 2020-02-12 18:23 - 002348544 _____ (Microsoft Corporation) C:\windows\SysWOW64\mssrch.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 002280024 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 002086400 _____ (Microsoft Corporation) C:\windows\SysWOW64\xpsservices.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 001994976 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 001866240 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 001766400 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 001726480 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 001677088 _____ (Microsoft Corporation) C:\windows\SysWOW64\user32.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 001674688 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 001647104 _____ (Microsoft Corporation) C:\windows\SysWOW64\winmsipc.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 001590072 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdpserverbase.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 001486680 _____ (Microsoft Corporation) C:\windows\system32\msctf.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 001476096 _____ (Microsoft Corporation) C:\windows\SysWOW64\aadtb.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 001387520 _____ (Microsoft Corporation) C:\windows\system32\bcastdvruserservice.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 001360912 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ndis.sys
2020-02-12 18:23 - 2020-02-12 18:23 - 001309696 _____ (Microsoft Corporation) C:\windows\system32\webplatstorageserver.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 001247560 _____ (Microsoft Corporation) C:\windows\system32\ClipUp.exe
2020-02-12 18:23 - 2020-02-12 18:23 - 001222672 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdpbase.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 001219584 _____ (Microsoft Corporation) C:\windows\system32\sdclt.exe
2020-02-12 18:23 - 2020-02-12 18:23 - 001193984 _____ (Microsoft Corporation) C:\windows\system32\sdengin2.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 001076224 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdpcore.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 001051136 _____ (Microsoft Corporation) C:\windows\system32\clusapi.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 001012736 _____ (Microsoft Corporation) C:\windows\system32\refsutil.exe
2020-02-12 18:23 - 2020-02-12 18:23 - 000917816 _____ (Microsoft Corporation) C:\windows\SysWOW64\ReAgent.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 000879104 _____ (Microsoft Corporation) C:\windows\SysWOW64\SearchIndexer.exe
2020-02-12 18:23 - 2020-02-12 18:23 - 000876032 _____ (Microsoft Corporation) C:\windows\SysWOW64\rasapi32.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 000866304 _____ (Microsoft Corporation) C:\windows\SysWOW64\rasdlg.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 000852480 _____ (Microsoft Corporation) C:\windows\system32\ieproxy.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 000849920 _____ (Microsoft Corporation) C:\windows\SysWOW64\rasgcw.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 000840192 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 000801280 _____ (Microsoft Corporation) C:\windows\SysWOW64\winipcsecproc.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 000741376 _____ (Microsoft Corporation) C:\windows\SysWOW64\mssvp.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 000703488 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 000681472 _____ (Microsoft Corporation) C:\windows\SysWOW64\uReFS.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 000622080 _____ (Microsoft Corporation) C:\windows\system32\resutils.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 000615936 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.UI.Core.TextInput.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 000613376 _____ (Microsoft Corporation) C:\windows\system32\uxtheme.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 000590336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ActivationManager.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 000588600 _____ (Microsoft Corporation) C:\windows\system32\Drivers\netio.sys
2020-02-12 18:23 - 2020-02-12 18:23 - 000576512 _____ (Microsoft Corporation) C:\windows\system32\dfrgui.exe
2020-02-12 18:23 - 2020-02-12 18:23 - 000541472 _____ (Microsoft Corporation) C:\windows\SysWOW64\StructuredQuery.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 000501760 _____ (Microsoft Corporation) C:\windows\system32\msutb.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 000496128 _____ (Microsoft Corporation) C:\windows\system32\werui.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 000492032 _____ (Microsoft Corporation) C:\windows\system32\defragsvc.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 000481280 _____ (Microsoft Corporation) C:\windows\SysWOW64\uxtheme.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 000465424 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 000452608 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cldflt.sys
2020-02-12 18:23 - 2020-02-12 18:23 - 000449024 _____ (Microsoft Corporation) C:\windows\system32\edgeIso.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 000431416 _____ (Microsoft Corporation) C:\windows\system32\Drivers\Classpnp.sys
2020-02-12 18:23 - 2020-02-12 18:23 - 000403968 _____ (Microsoft Corporation) C:\windows\SysWOW64\PhotoMetadataHandler.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 000395776 _____ (Microsoft Corporation) C:\windows\SysWOW64\puiobj.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 000349184 _____ (Microsoft Corporation) C:\windows\SysWOW64\SearchProtocolHost.exe
2020-02-12 18:23 - 2020-02-12 18:23 - 000348672 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdpencom.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 000330752 _____ (Microsoft Corporation) C:\windows\SysWOW64\edgeIso.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 000296448 _____ (Microsoft Corporation) C:\windows\SysWOW64\Search.ProtocolHandler.MAPI2.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 000252024 _____ (Microsoft Corporation) C:\windows\SysWOW64\wscapi.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 000239616 _____ (Microsoft Corporation) C:\windows\system32\vdsbas.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 000224256 _____ (Microsoft Corporation) C:\windows\SysWOW64\SearchFilterHost.exe
2020-02-12 18:23 - 2020-02-12 18:23 - 000186880 _____ (Microsoft Corp.) C:\windows\system32\Defrag.exe
2020-02-12 18:23 - 2020-02-12 18:23 - 000156712 _____ (Microsoft Corporation) C:\windows\system32\omadmapi.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 000156160 _____ (Microsoft Corporation) C:\windows\SysWOW64\mssph.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 000152064 _____ (Microsoft Corporation) C:\windows\system32\fdWSD.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 000149504 _____ (Microsoft Corporation) C:\windows\system32\sdrsvc.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 000128616 _____ (Microsoft Corporation) C:\windows\SysWOW64\omadmapi.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 000108032 _____ (Microsoft Corporation) C:\windows\system32\fdSSDP.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 000092160 _____ (Microsoft Corporation) C:\windows\system32\wsqmcons.exe
2020-02-12 18:23 - 2020-02-12 18:23 - 000070656 _____ (Microsoft Corporation) C:\windows\SysWOW64\usoapi.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 000054784 _____ (Microsoft Corporation) C:\windows\SysWOW64\msscntrs.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 000052736 _____ (Microsoft Corporation) C:\windows\SysWOW64\rtutils.dll
2020-02-12 18:23 - 2020-02-12 18:23 - 000032256 _____ (Microsoft Corporation) C:\windows\SysWOW64\rasphone.exe
2020-02-12 18:23 - 2020-02-12 18:23 - 000027648 _____ (Microsoft Corporation) C:\windows\SysWOW64\mciwave.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 022137336 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 009669648 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2020-02-12 18:22 - 2020-02-12 18:22 - 007888896 _____ (Microsoft Corporation) C:\windows\system32\Windows.Data.Pdf.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 007645392 _____ (Microsoft Corporation) C:\windows\system32\Windows.Media.Protection.PlayReady.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 005577656 _____ (Microsoft Corporation) C:\windows\system32\StartTileData.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 005528576 _____ (Microsoft Corporation) C:\windows\system32\InputService.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 005300736 _____ (Microsoft Corporation) C:\windows\system32\cdp.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 004588776 _____ (Microsoft Corporation) C:\windows\system32\sppsvc.exe
2020-02-12 18:22 - 2020-02-12 18:22 - 004417552 _____ (Microsoft Corporation) C:\windows\explorer.exe
2020-02-12 18:22 - 2020-02-12 18:22 - 004050944 _____ (Microsoft Corporation) C:\windows\system32\EdgeContent.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 003636736 _____ (Microsoft Corporation) C:\windows\system32\win32kfull.sys
2020-02-12 18:22 - 2020-02-12 18:22 - 003387392 _____ (Microsoft Corporation) C:\windows\system32\AppXDeploymentServer.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 003363848 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dxgkrnl.sys
2020-02-12 18:22 - 2020-02-12 18:22 - 003334144 _____ (Microsoft Corporation) C:\windows\system32\tquery.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 003329536 _____ (Microsoft Corporation) C:\windows\system32\msftedit.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 002879488 _____ (Microsoft Corporation) C:\windows\system32\xpsservices.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 002848256 _____ (Microsoft Corporation) C:\windows\system32\mssrch.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 002634240 _____ (Microsoft Corporation) C:\windows\system32\wlansvc.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 002437344 _____ (Microsoft Corporation) C:\windows\system32\msxml6.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 002417664 _____ (Microsoft Corporation) C:\windows\system32\win32kbase.sys
2020-02-12 18:22 - 2020-02-12 18:22 - 002292224 _____ (Microsoft Corporation) C:\windows\system32\winmsipc.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 002192384 _____ (Microsoft Corporation) C:\windows\system32\AppXDeploymentExtensions.onecore.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 001963536 _____ (Microsoft Corporation) C:\windows\system32\Drivers\refs.sys
2020-02-12 18:22 - 2020-02-12 18:22 - 001830928 _____ (Microsoft Corporation) C:\windows\system32\rdpserverbase.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 001824768 _____ (Microsoft Corporation) C:\windows\system32\aadtb.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 001796920 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecs.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 001751432 _____ (Microsoft Corporation) C:\windows\system32\sppobjs.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 001702392 _____ (Microsoft Corporation) C:\windows\system32\winload.efi
2020-02-12 18:22 - 2020-02-12 18:22 - 001665720 _____ (Microsoft Corporation) C:\windows\system32\user32.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 001608192 _____ (Microsoft Corporation) C:\windows\system32\AppXDeploymentExtensions.desktop.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 001538560 _____ (Microsoft Corporation) C:\windows\system32\wbengine.exe
2020-02-12 18:22 - 2020-02-12 18:22 - 001479208 _____ (Microsoft Corporation) C:\windows\system32\rdpbase.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 001473088 _____ (Microsoft Corporation) C:\windows\system32\winload.exe
2020-02-12 18:22 - 2020-02-12 18:22 - 001345984 _____ (Microsoft Corporation) C:\windows\system32\winresume.efi
2020-02-12 18:22 - 2020-02-12 18:22 - 001319936 _____ (Microsoft Corporation) C:\windows\system32\NotificationController.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 001262592 _____ (Microsoft Corporation) C:\windows\system32\SystemSettings.Handlers.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 001260032 _____ (Microsoft Corporation) C:\windows\system32\rdpcore.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 001259832 _____ (Microsoft Corporation) C:\windows\system32\Drivers\http.sys
2020-02-12 18:22 - 2020-02-12 18:22 - 001183296 _____ (Microsoft Corporation) C:\windows\system32\winresume.exe
2020-02-12 18:22 - 2020-02-12 18:22 - 001114112 _____ (Microsoft Corporation) C:\windows\system32\wifinetworkmanager.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 001087800 _____ (Microsoft Corporation) C:\windows\system32\ReAgent.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 001056272 _____ (Microsoft Corporation) C:\windows\system32\pidgenx.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 001054952 _____ (Microsoft Corporation) C:\windows\system32\ApplyTrustOffline.exe
2020-02-12 18:22 - 2020-02-12 18:22 - 001051648 _____ (Microsoft Corporation) C:\windows\system32\SearchIndexer.exe
2020-02-12 18:22 - 2020-02-12 18:22 - 000954368 _____ (Microsoft Corporation) C:\windows\system32\rasapi32.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 000953344 _____ (Microsoft Corporation) C:\windows\system32\rasgcw.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 000950272 _____ (Microsoft Corporation) C:\windows\system32\rasdlg.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 000930816 _____ (Microsoft Corporation) C:\windows\system32\SecurityHealthSSO.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 000927232 _____ (Microsoft Corporation) C:\windows\system32\rasmans.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 000902344 _____ (Microsoft Corporation) C:\windows\system32\SecurityHealthService.exe
2020-02-12 18:22 - 2020-02-12 18:22 - 000898048 _____ (Microsoft Corporation) C:\windows\system32\winipcsecproc.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 000860160 _____ C:\windows\system32\MBR2GPT.EXE
2020-02-12 18:22 - 2020-02-12 18:22 - 000820736 _____ (Microsoft Corporation) C:\windows\system32\Windows.UI.Core.TextInput.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 000817664 _____ (Microsoft Corporation) C:\windows\system32\mssvp.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 000801280 _____ (Microsoft Corporation) C:\windows\system32\uReFS.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 000764216 _____ (Microsoft Corporation) C:\windows\system32\wimgapi.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 000741688 _____ (Microsoft Corporation) C:\windows\system32\SettingsHandlers_StorageSense.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 000690688 _____ (Microsoft Corporation) C:\windows\system32\ActivationManager.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 000657408 _____ (Microsoft Corporation) C:\windows\system32\BootMenuUX.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 000649728 _____ (Microsoft Corporation) C:\windows\system32\cdpsvc.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 000629760 _____ (Microsoft Corporation) C:\windows\system32\ipnathlp.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 000591376 _____ (Microsoft Corporation) C:\windows\system32\hal.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 000578560 _____ (Microsoft Corporation) C:\windows\system32\SppExtComObj.Exe
2020-02-12 18:22 - 2020-02-12 18:22 - 000520704 _____ (Microsoft Corporation) C:\windows\system32\SettingsHandlers_Notifications.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 000519992 _____ (Microsoft Corporation) C:\windows\system32\wimserv.exe
2020-02-12 18:22 - 2020-02-12 18:22 - 000519168 _____ (Microsoft Corporation) C:\windows\system32\sppcext.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 000515584 _____ (Microsoft Corporation) C:\windows\system32\cdpusersvc.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 000501248 _____ (Microsoft Corporation) C:\windows\system32\winipcfile.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 000494080 _____ (Microsoft Corporation) C:\windows\system32\puiobj.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 000485376 _____ (Microsoft Corporation) C:\windows\system32\cloudAP.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 000417280 _____ (Microsoft Corporation) C:\windows\system32\rdpencom.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 000415744 _____ (Microsoft Corporation) C:\windows\system32\SearchProtocolHost.exe
2020-02-12 18:22 - 2020-02-12 18:22 - 000410624 _____ (Microsoft Corporation) C:\windows\system32\Search.ProtocolHandler.MAPI2.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 000408064 _____ (Microsoft Corporation) C:\windows\system32\rascustom.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 000349696 _____ (Microsoft Corporation) C:\windows\system32\AppxAllUserStore.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 000333824 _____ (Microsoft Corporation) C:\windows\system32\RasMediaManager.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 000331104 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 000313000 _____ (Microsoft Corporation) C:\windows\system32\wscsvc.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 000305664 _____ (Microsoft Corporation) C:\windows\system32\DeviceDirectoryClient.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 000293856 _____ (Microsoft Corporation) C:\windows\system32\wscapi.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 000286520 _____ (Microsoft Corporation) C:\windows\system32\SecurityHealthAgent.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 000281088 _____ (Microsoft Corporation) C:\windows\system32\Windows.UI.AppDefaults.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 000256512 _____ (Microsoft Corporation) C:\windows\system32\SearchFilterHost.exe
2020-02-12 18:22 - 2020-02-12 18:22 - 000226816 _____ (Microsoft Corporation) C:\windows\system32\SettingsHandlers_CapabilityAccess.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 000222720 _____ (Microsoft Corporation) C:\windows\system32\SettingsHandlers_Geolocation.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 000198656 _____ (Microsoft Corporation) C:\windows\system32\policymanagerprecheck.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 000198656 _____ (Microsoft Corporation) C:\windows\system32\mssph.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 000164864 _____ (Microsoft Corporation) C:\windows\system32\dssvc.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 000154624 _____ (Microsoft Corporation) C:\windows\system32\SettingsHandlers_AppExecutionAlias.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 000151552 _____ (Microsoft Corporation) C:\windows\system32\SettingsHandlers_BackgroundApps.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 000146432 _____ (Microsoft Corporation) C:\windows\system32\mssprxy.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 000105784 _____ (Microsoft Corporation) C:\windows\system32\SecurityHealthProxyStub.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 000072704 _____ (Microsoft Corporation) C:\windows\system32\msscntrs.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 000066048 _____ (Microsoft Corporation) C:\windows\system32\rtutils.dll
2020-02-12 18:22 - 2020-02-12 18:22 - 000035328 _____ (Microsoft Corporation) C:\windows\system32\rasphone.exe
2020-02-12 18:22 - 2020-02-12 18:22 - 000034304 _____ (Microsoft Corporation) C:\windows\system32\mciwave.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 007701200 _____ (Microsoft Corporation) C:\windows\system32\windows.storage.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 003577856 _____ (Microsoft Corporation) C:\windows\system32\diagtrack.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 003334496 _____ (Microsoft Corporation) C:\windows\system32\combase.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 003269632 _____ (Microsoft Corporation) C:\windows\system32\esent.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 003006464 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 002928640 _____ (Microsoft Corporation) C:\windows\SysWOW64\esent.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 002707456 _____ (Microsoft Corporation) C:\windows\SysWOW64\win32kfull.sys
2020-02-12 18:21 - 2020-02-12 18:21 - 002590736 _____ (Microsoft Corporation) C:\windows\SysWOW64\combase.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 002015608 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 001677312 _____ (Microsoft Corporation) C:\windows\system32\rdpcorets.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 001674752 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 001566720 _____ (Microsoft Corporation) C:\windows\system32\dosvc.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 001520232 _____ (Microsoft Corporation) C:\windows\SysWOW64\WindowsCodecs.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 001387512 _____ (Microsoft Corporation) C:\windows\system32\WinTypes.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 001294488 _____ (Microsoft Corporation) C:\windows\SysWOW64\msctf.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 001258504 _____ (Microsoft Corporation) C:\windows\system32\hvix64.exe
2020-02-12 18:21 - 2020-02-12 18:21 - 001049400 _____ (Microsoft Corporation) C:\windows\system32\hvax64.exe
2020-02-12 18:21 - 2020-02-12 18:21 - 001005056 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 000985088 _____ (Microsoft Corporation) C:\windows\system32\MusUpdateHandlers.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 000902144 _____ (Microsoft Corporation) C:\windows\system32\usocore.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 000888864 _____ (Microsoft Corporation) C:\windows\system32\wer.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 000872000 _____ (Microsoft Corporation) C:\windows\system32\ClipSVC.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 000869888 _____ (Microsoft Corporation) C:\windows\system32\netlogon.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 000856432 _____ (Microsoft Corporation) C:\windows\system32\ci.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 000779776 _____ (Microsoft Corporation) C:\windows\system32\updatehandlers.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 000777728 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 000758928 _____ (Microsoft Corporation) C:\windows\system32\tcblaunch.exe
2020-02-12 18:21 - 2020-02-12 18:21 - 000751632 _____ (Microsoft Corporation) C:\windows\system32\Drivers\vhdmp.sys
2020-02-12 18:21 - 2020-02-12 18:21 - 000681416 _____ (Microsoft Corporation) C:\windows\SysWOW64\wer.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 000677144 _____ (Microsoft Corporation) C:\windows\system32\StructuredQuery.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 000664576 _____ (Microsoft Corporation) C:\windows\SysWOW64\netlogon.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 000662024 _____ (Microsoft Corporation) C:\windows\system32\computecore.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 000652088 _____ (Microsoft Corporation) C:\windows\system32\securekernel.exe
2020-02-12 18:21 - 2020-02-12 18:21 - 000613176 _____ (Microsoft Corporation) C:\windows\system32\Drivers\storport.sys
2020-02-12 18:21 - 2020-02-12 18:21 - 000611840 _____ (Microsoft Corporation) C:\windows\system32\CredProvDataModel.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 000606224 _____ (Microsoft Corporation) C:\windows\SysWOW64\wimgapi.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 000591872 _____ (Microsoft Corporation) C:\windows\system32\MusNotification.exe
2020-02-12 18:21 - 2020-02-12 18:21 - 000531976 _____ (Microsoft Corporation) C:\windows\SysWOW64\mf.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 000510264 _____ (Microsoft Corporation) C:\windows\system32\WerFault.exe
2020-02-12 18:21 - 2020-02-12 18:21 - 000506200 _____ (Microsoft Corporation) C:\windows\system32\mf.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 000476160 _____ (Microsoft Corporation) C:\windows\SysWOW64\CredProvDataModel.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 000476160 _____ (Microsoft Corporation) C:\windows\system32\wuuhext.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 000476160 _____ (Microsoft Corporation) C:\windows\system32\DscCore.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 000469504 _____ (Microsoft Corporation) C:\windows\system32\profsvc.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 000450912 _____ (Microsoft Corporation) C:\windows\system32\Faultrep.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 000446480 _____ (Microsoft Corporation) C:\windows\SysWOW64\WerFault.exe
2020-02-12 18:21 - 2020-02-12 18:21 - 000442880 _____ (Microsoft Corporation) C:\windows\system32\MusNotificationUx.exe
2020-02-12 18:21 - 2020-02-12 18:21 - 000438784 _____ (Microsoft Corporation) C:\windows\SysWOW64\msutb.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 000422712 _____ (Microsoft Corporation) C:\windows\system32\Drivers\pci.sys
2020-02-12 18:21 - 2020-02-12 18:21 - 000405520 _____ (Microsoft Corporation) C:\windows\system32\Drivers\clfs.sys
2020-02-12 18:21 - 2020-02-12 18:21 - 000402584 _____ (Microsoft Corporation) C:\windows\system32\SgrmEnclave.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 000398416 _____ (Microsoft Corporation) C:\windows\system32\SgrmEnclave_secure.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 000389920 _____ (Microsoft Corporation) C:\windows\SysWOW64\Faultrep.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 000376568 _____ (Microsoft Corporation) C:\windows\system32\MusNotifyIcon.exe
2020-02-12 18:21 - 2020-02-12 18:21 - 000277504 _____ (Microsoft Corporation) C:\windows\SysWOW64\AppxAllUserStore.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 000253256 _____ (Microsoft Corporation) C:\windows\system32\logoncli.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 000240640 _____ (Microsoft Corporation) C:\windows\system32\Drivers\winnat.sys
2020-02-12 18:21 - 2020-02-12 18:21 - 000215552 _____ (Microsoft Corporation) C:\windows\system32\wersvc.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 000213816 _____ (Microsoft Corporation) C:\windows\system32\wermgr.exe
2020-02-12 18:21 - 2020-02-12 18:21 - 000203064 _____ (Microsoft Corporation) C:\windows\system32\tcbloader.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 000197632 _____ (Microsoft Corporation) C:\windows\system32\updatepolicy.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 000193336 _____ (Microsoft Corporation) C:\windows\SysWOW64\wermgr.exe
2020-02-12 18:21 - 2020-02-12 18:21 - 000189496 _____ (Microsoft Corporation) C:\windows\SysWOW64\logoncli.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 000182272 _____ (Microsoft Corporation) C:\windows\system32\wuuhosdeployment.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 000169784 _____ (Microsoft Corporation) C:\windows\system32\Drivers\wcifs.sys
2020-02-12 18:21 - 2020-02-12 18:21 - 000163240 _____ (Microsoft Corporation) C:\windows\system32\WerFaultSecure.exe
2020-02-12 18:21 - 2020-02-12 18:21 - 000161792 _____ (Microsoft Corporation) C:\windows\SysWOW64\updatepolicy.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 000147944 _____ (Microsoft Corporation) C:\windows\SysWOW64\WerFaultSecure.exe
2020-02-12 18:21 - 2020-02-12 18:21 - 000145408 _____ (Microsoft Corporation) C:\windows\system32\musdialoghandlers.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 000118272 _____ (Microsoft Corporation) C:\windows\system32\Drivers\hidbth.sys
2020-02-12 18:21 - 2020-02-12 18:21 - 000109056 _____ (Microsoft Corporation) C:\windows\system32\usoapi.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 000103936 _____ (Microsoft Corporation) C:\windows\system32\utcutil.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 000103736 _____ (Microsoft Corporation) C:\windows\system32\Drivers\bindflt.sys
2020-02-12 18:21 - 2020-02-12 18:21 - 000095760 _____ (Microsoft Corporation) C:\windows\system32\rdpudd.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 000090624 _____ (Microsoft Corporation) C:\windows\system32\keyiso.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 000066560 _____ (Microsoft Corporation) C:\windows\SysWOW64\keyiso.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 000048128 _____ (Microsoft Corporation) C:\windows\system32\UsoClient.exe
2020-02-12 18:21 - 2020-02-12 18:21 - 000047104 _____ (Microsoft Corporation) C:\windows\system32\Websocket.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 000037376 _____ (Microsoft Corporation) C:\windows\SysWOW64\Websocket.dll
2020-02-12 18:21 - 2020-02-12 18:21 - 000000315 _____ C:\windows\system32\DrtmAuth8.bin
2020-02-12 18:21 - 2020-02-12 18:21 - 000000315 _____ C:\windows\system32\DrtmAuth7.bin
2020-02-12 18:21 - 2020-02-12 18:21 - 000000315 _____ C:\windows\system32\DrtmAuth6.bin
2020-02-12 18:21 - 2020-02-12 18:21 - 000000315 _____ C:\windows\system32\DrtmAuth5.bin
2020-02-12 18:21 - 2020-02-12 18:21 - 000000315 _____ C:\windows\system32\DrtmAuth4.bin
2020-02-12 18:21 - 2020-02-12 18:21 - 000000315 _____ C:\windows\system32\DrtmAuth3.bin
2020-02-12 18:21 - 2020-02-12 18:21 - 000000315 _____ C:\windows\system32\DrtmAuth2.bin
2020-02-12 18:21 - 2020-02-12 18:21 - 000000315 _____ C:\windows\system32\DrtmAuth1.bin
2020-02-11 19:48 - 2020-02-11 19:48 - 000148253 _____ C:\Users\Usuario\Downloads\PROMOCION LIBRO_RRSS.pdf
2020-02-11 15:47 - 2020-02-11 15:47 - 000000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2020-02-11 15:44 - 2020-02-11 15:44 - 000002469 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat DC.lnk
2020-02-11 15:44 - 2020-02-11 15:44 - 000002121 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller DC.lnk
2020-02-11 15:44 - 2020-02-11 15:44 - 000002098 _____ C:\Users\Public\Desktop\Adobe Acrobat DC.lnk
2020-02-11 15:42 - 2020-01-13 14:09 - 000000000 ____D C:\Users\Usuario\Downloads\4D0B3GEN2.4.WIN.AP.ZNT
2020-02-11 15:38 - 2020-02-11 15:38 - 019014952 _____ C:\Users\Usuario\Downloads\4D0B3GEN2.4.WIN.AP.ZNT.rar
2020-02-11 15:24 - 2019-12-04 10:17 - 000286240 _____ (Wondershare Software) C:\windows\system32\WSPDFelementMonitor.dll
2020-02-11 15:22 - 2020-02-11 15:22 - 000000000 ____D C:\Users\Public\Documents\Wondershare
2020-02-11 15:22 - 2020-02-11 15:22 - 000000000 ____D C:\ProgramData\PDFelement 7
2020-02-11 15:22 - 2020-02-11 15:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare
2020-02-11 15:22 - 2020-02-11 15:22 - 000000000 ____D C:\Program Files (x86)\Wondershare
2020-02-11 15:22 - 2019-12-04 10:15 - 011886624 _____ C:\windows\SysWOW64\WSPECRT.dll
2020-02-11 15:22 - 2019-11-21 15:37 - 000150736 _____ (TWAIN Working Group) C:\windows\SysWOW64\TWAINDSM.dll
2020-02-11 15:22 - 2019-11-21 15:37 - 000097280 _____ C:\windows\SysWOW64\TWAINDSM32.msm
2020-02-09 12:08 - 2020-02-09 12:08 - 000000000 ____D C:\Users\Usuario\AppData\Roaming\Font Previewer Lite
2020-02-09 12:07 - 2020-02-09 12:07 - 000000000 ____D C:\Users\Usuario\AppData\Roaming\Mt_Mograph
2020-02-09 11:44 - 2020-02-09 21:25 - 000000000 ____D C:\Users\Usuario\Documents\AEJuice
2020-02-09 11:44 - 2020-02-09 11:44 - 000000000 ____D C:\Users\Usuario\AppData\Roaming\AEJuice
2020-02-08 22:31 - 2020-02-08 22:31 - 000001149 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Media Encoder 2020.lnk
2020-02-08 16:40 - 2020-02-09 11:32 - 000000000 ____D C:\Users\Usuario\AppData\Roaming\Apple Computer
2020-02-08 16:29 - 2020-02-08 16:29 - 000000000 ____D C:\Users\Usuario\AppData\Local\Apple Computer
2020-02-08 16:28 - 2020-02-08 16:33 - 000000000 ____D C:\ProgramData\Apple Computer
2020-02-08 16:28 - 2020-02-08 16:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
2020-02-08 16:28 - 2020-02-08 16:28 - 000000000 ____D C:\Program Files (x86)\QuickTime
2020-02-08 16:27 - 2020-02-08 16:27 - 000000000 ____D C:\Users\Usuario\AppData\Local\Apple
2020-02-08 16:26 - 2020-02-08 16:26 - 000002535 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2020-02-08 16:26 - 2020-02-08 16:26 - 000000000 ____D C:\ProgramData\Apple
2020-02-08 16:26 - 2020-02-08 16:26 - 000000000 ____D C:\Program Files (x86)\Apple Software Update
2020-02-08 16:24 - 2020-02-08 16:24 - 000000000 ____D C:\Users\Usuario\AppData\LocalLow\Apple Computer
2020-02-08 14:58 - 2020-02-08 14:58 - 000000000 ____D C:\Users\Usuario\AppData\Local\MisterHorse
2020-02-08 14:53 - 2020-02-22 20:43 - 000000000 ____D C:\Users\Usuario\Downloads\Descargas
2020-02-08 12:49 - 2020-02-08 12:49 - 000000000 ____D C:\Program Files\Common Files\MacPaw
2020-02-08 12:45 - 2020-02-08 12:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maxon
2020-02-08 12:43 - 2020-02-08 12:48 - 000000000 ____D C:\Program Files\CleanMyPC
2020-02-08 12:43 - 2020-02-08 12:43 - 000000872 _____ C:\Users\Public\Desktop\CleanMyPC.lnk
2020-02-08 12:43 - 2020-02-08 12:43 - 000000000 ____D C:\ProgramData\MacPaw Inc
2020-02-08 12:42 - 2020-02-08 12:45 - 000000000 ____D C:\Program Files\Maxon Cinema 4D R21
2020-02-08 12:41 - 2020-02-08 12:41 - 000001257 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe After Effects 2020.lnk
2020-02-07 15:01 - 2020-02-07 15:02 - 000000000 ____D C:\ProgramData\Wondershare
2020-02-06 18:09 - 2020-02-06 18:09 - 000000000 ____D C:\Users\Usuario\AppData\Local\Wondershare
2020-02-06 18:08 - 2020-02-11 15:22 - 000000000 ____D C:\Users\Usuario\AppData\Roaming\Wondershare
2020-02-06 18:08 - 2020-02-06 18:13 - 000000000 ____D C:\Program Files (x86)\iSkysoft
2020-02-06 18:07 - 2020-02-06 18:09 - 000000000 ____D C:\Users\Public\Documents\iSkysoft
2020-02-06 18:06 - 2020-02-06 18:17 - 000000000 ____D C:\Users\Usuario\Documents\Francisco_Baja
2020-02-06 16:28 - 2020-02-06 16:28 - 000000000 ____D C:\Users\Usuario\AppData\Roaming\Ajar Productions
2020-02-04 23:21 - 2020-02-04 23:21 - 000065488 _____ (Adobe Systems Inc) C:\windows\system32\AdobePDF.dll
2020-02-04 23:21 - 2020-02-04 23:21 - 000036304 _____ (Adobe Systems Inc.) C:\windows\system32\AdobePDFUI.dll
2020-02-04 16:44 - 2020-02-04 16:44 - 000000000 ____D C:\Users\Usuario\Documents\Plantillas personalizadas de Office
2020-02-04 16:43 - 2020-02-04 16:43 - 000000000 ___SD C:\Users\Usuario\Documents\Mis formas
2020-02-04 16:33 - 2020-02-04 16:33 - 000002683 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive para la Empresa.lnk
2020-02-04 16:33 - 2020-02-04 16:33 - 000002545 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype Empresarial.lnk
2020-02-04 16:33 - 2020-02-04 16:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Herramientas de Microsoft Office
2020-02-04 15:43 - 2020-02-04 16:33 - 000002504 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Project.lnk
2020-02-04 15:43 - 2020-02-04 16:33 - 000002496 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk
2020-02-04 15:43 - 2020-02-04 16:33 - 000002477 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk
2020-02-04 15:43 - 2020-02-04 16:33 - 000002460 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visio.lnk
2020-02-04 15:43 - 2020-02-04 16:33 - 000002459 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk
2020-02-04 15:43 - 2020-02-04 16:33 - 000002452 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk
2020-02-04 15:43 - 2020-02-04 16:33 - 000002450 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk
2020-02-04 15:43 - 2020-02-04 16:33 - 000002408 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
2020-02-04 15:43 - 2020-02-04 16:33 - 000002404 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher.lnk
2020-02-04 15:38 - 2020-02-04 15:38 - 000000000 ____D C:\Program Files\Common Files\DESIGNER
2020-02-04 15:27 - 2020-02-15 16:19 - 000000000 ____D C:\Program Files\Microsoft Office
2020-02-04 15:27 - 2020-02-04 15:27 - 000000000 ____D C:\Program Files\Microsoft Office 15
2020-02-02 13:56 - 2020-02-02 13:56 - 000001347 _____ C:\Users\Usuario\Wi-Fi-MOVISTAR_PLUS_4AD8.xml
2020-02-01 19:10 - 2020-02-01 19:10 - 000000000 ____H C:\windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2020-02-01 12:45 - 2020-02-21 15:01 - 000002430 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2020-02-01 12:45 - 2020-02-21 15:01 - 000002268 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2020-02-01 12:44 - 2020-02-20 15:03 - 000003652 _____ C:\windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2020-02-01 12:44 - 2020-02-20 15:03 - 000003528 _____ C:\windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2020-01-27 17:33 - 2020-01-27 17:33 - 000000000 ____D C:\Users\Usuario\Documents\Inky

==================== Un mes (modificado) ==================

(Si una entrada es incluida en el fixlist, el archivo/carpeta será eliminado/a.)

2020-02-22 23:36 - 2019-12-08 10:05 - 000000000 ____D C:\ProgramData\Kaspersky Lab
2020-02-22 23:33 - 2018-09-15 08:33 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-02-22 23:21 - 2018-10-11 06:56 - 000000006 ____H C:\windows\Tasks\SA.DAT
2020-02-22 23:20 - 2018-09-15 07:09 - 000786432 _____ C:\windows\system32\config\BBI
2020-02-22 23:11 - 2019-11-08 10:32 - 000000000 ____D C:\Users\Usuario
2020-02-22 23:08 - 2019-12-07 16:06 - 000000000 ____D C:\Users\Usuario\AppData\Roaming\uTorrent
2020-02-22 23:08 - 2019-12-01 11:07 - 000000000 ____D C:\Program Files (x86)\Steam
2020-02-22 23:07 - 2019-11-23 13:12 - 000000000 ____D C:\Users\Usuario\AppData\Local\CrashDumps
2020-02-22 23:07 - 2018-10-11 07:54 - 000000000 ____D C:\windows\Panther
2020-02-22 23:07 - 2018-09-15 08:31 - 000000000 ____D C:\windows\INF
2020-02-22 21:56 - 2019-11-24 10:27 - 000000000 ____D C:\Users\Usuario\AppData\Local\BitTorrentHelper
2020-02-22 20:58 - 2019-11-22 17:27 - 000000000 ____D C:\Users\Usuario\AppData\Local\cache
2020-02-22 20:57 - 2018-09-15 08:33 - 000000000 ___HD C:\windows\ELAMBKUP
2020-02-22 20:21 - 2018-10-11 06:56 - 000000000 ____D C:\windows\system32\SleepStudy
2020-02-22 19:43 - 2019-11-23 12:29 - 000000372 _____ C:\windows\Tasks\HPCeeScheduleForUsuario.job
2020-02-22 11:49 - 2019-11-08 10:33 - 000000000 ____D C:\Users\Usuario\AppData\Local\D3DSCache
2020-02-22 11:11 - 2019-11-23 12:29 - 000003272 _____ C:\windows\system32\Tasks\HPCeeScheduleForUsuario
2020-02-22 10:31 - 2019-11-23 11:58 - 000000000 ___HD C:\Users\Public\Documents\AdobeGCData
2020-02-22 09:48 - 2018-09-15 08:33 - 000000000 ___HD C:\Program Files\WindowsApps
2020-02-22 09:48 - 2018-09-15 08:33 - 000000000 ____D C:\windows\AppReadiness
2020-02-22 09:45 - 2019-11-08 10:33 - 000000000 ____D C:\Users\Usuario\AppData\Local\AMD
2020-02-21 18:12 - 2019-11-22 22:43 - 000000000 ____D C:\Users\Usuario\AppData\Roaming\Dimension CC
2020-02-21 15:00 - 2019-12-01 21:31 - 000004230 _____ C:\windows\system32\Tasks\Opera scheduled Autoupdate 1575232255
2020-02-21 15:00 - 2019-12-01 21:30 - 000001412 _____ C:\Users\Usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Navegador Opera.lnk
2020-02-21 14:58 - 2019-11-22 21:57 - 000000000 ____D C:\Program Files\Adobe
2020-02-21 14:55 - 2019-11-23 12:00 - 000000000 ___RD C:\Users\Usuario\Creative Cloud Files
2020-02-21 14:55 - 2019-11-22 21:55 - 000000000 ____D C:\Users\Usuario\AppData\Local\Adobe
2020-02-19 19:00 - 2018-09-15 07:09 - 000032768 _____ C:\windows\system32\config\ELAM
2020-02-18 18:41 - 2019-11-08 09:08 - 000000000 ____D C:\Program Files\AMD
2020-02-18 18:37 - 2019-11-22 16:29 - 000000000 ____D C:\AMD
2020-02-18 16:37 - 2019-12-08 18:05 - 000000028 _____ C:\Users\Usuario\AppData\Roaming\kulerdata.json
2020-02-15 16:21 - 2018-09-15 08:33 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2020-02-15 15:35 - 2019-12-17 16:27 - 000000000 ____D C:\Users\Usuario\AppData\Roaming\Code
2020-02-13 18:57 - 2019-12-10 19:38 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2020-02-13 16:38 - 2020-01-17 20:27 - 000008272 _____ C:\windows\SysWOW64\antimalware.patch_management.product_registry.kvdb-wal
2020-02-13 15:14 - 2018-11-29 12:26 - 000824488 _____ C:\windows\system32\perfh00A.dat
2020-02-13 15:14 - 2018-11-29 12:26 - 000173234 _____ C:\windows\system32\perfc00A.dat
2020-02-13 15:14 - 2018-10-11 07:02 - 001920506 _____ C:\windows\system32\PerfStringBackup.INI
2020-02-13 15:10 - 2019-11-08 10:32 - 000000000 ___RD C:\Users\Usuario\3D Objects
2020-02-13 15:10 - 2018-10-11 06:58 - 000000000 __RHD C:\Users\Public\AccountPictures
2020-02-13 15:09 - 2020-01-17 20:27 - 000032768 _____ C:\windows\SysWOW64\antimalware.unwanted_products.browser_extension_registry.kvdb-shm
2020-02-13 15:09 - 2020-01-17 20:27 - 000032768 _____ C:\windows\SysWOW64\antimalware.patch_management.product_registry.kvdb-shm
2020-02-13 15:09 - 2018-09-15 08:33 - 000000000 ____D C:\windows\system32\SecureBootUpdates
2020-02-13 15:08 - 2020-01-17 20:27 - 000032768 _____ C:\windows\SysWOW64\antimalware.unwanted_products.product_registry.kvdb-shm
2020-02-12 22:30 - 2019-11-08 17:51 - 000000000 ____D C:\windows\holoshell
2020-02-12 22:30 - 2018-09-15 08:33 - 000000000 ___RD C:\windows\ImmersiveControlPanel
2020-02-12 22:30 - 2018-09-15 08:33 - 000000000 ____D C:\windows\SysWOW64\oobe
2020-02-12 22:30 - 2018-09-15 08:33 - 000000000 ____D C:\windows\SysWOW64\Dism
2020-02-12 22:30 - 2018-09-15 08:33 - 000000000 ____D C:\windows\system32\SystemResetPlatform
2020-02-12 22:30 - 2018-09-15 08:33 - 000000000 ____D C:\windows\system32\oobe
2020-02-12 22:30 - 2018-09-15 08:33 - 000000000 ____D C:\windows\ShellExperiences
2020-02-12 22:30 - 2018-09-15 08:33 - 000000000 ____D C:\windows\ShellComponents
2020-02-12 22:30 - 2018-09-15 08:33 - 000000000 ____D C:\windows\bcastdvr
2020-02-12 22:30 - 2018-09-15 07:09 - 000000000 ____D C:\windows\system32\Dism
2020-02-12 22:30 - 2018-09-15 07:09 - 000000000 ____D C:\windows\servicing
2020-02-12 18:46 - 2018-09-15 08:23 - 000000000 ____D C:\windows\CbsTemp
2020-02-12 18:41 - 2019-11-22 16:24 - 000000000 ____D C:\windows\system32\MRT
2020-02-12 18:31 - 2019-11-22 16:24 - 120407888 ____C (Microsoft Corporation) C:\windows\system32\MRT.exe
2020-02-12 16:37 - 2019-12-08 10:05 - 000998296 _____ (AO Kaspersky Lab) C:\windows\system32\Drivers\klif.sys
2020-02-12 16:37 - 2019-10-30 00:42 - 000145504 _____ (AO Kaspersky Lab) C:\windows\system32\Drivers\klbackupflt.sys
2020-02-12 16:37 - 2019-03-19 02:01 - 000079768 _____ (AO Kaspersky Lab) C:\windows\system32\Drivers\klbackupdisk.sys
2020-02-11 18:27 - 2019-11-28 20:34 - 000001456 _____ C:\Users\Usuario\AppData\Local\Adobe Guardar para Web 13.0 Prefs
2020-02-11 15:53 - 2019-11-08 10:32 - 000000000 ____D C:\Users\Usuario\AppData\Local\Packages
2020-02-11 15:53 - 2018-10-11 06:58 - 000000000 ____D C:\ProgramData\Packages
2020-02-11 15:48 - 2019-12-10 19:39 - 000004562 _____ C:\windows\system32\Tasks\Adobe Acrobat Update Task
2020-02-11 15:39 - 2019-11-22 21:57 - 000000000 ____D C:\Program Files (x86)\Adobe
2020-02-11 15:39 - 2019-11-22 21:55 - 000000000 ____D C:\ProgramData\Adobe
2020-02-10 19:39 - 2019-11-08 10:35 - 000003382 _____ C:\windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1019904135-823791453-1890871877-1001
2020-02-10 19:39 - 2019-11-08 10:35 - 000000000 ___RD C:\Users\Usuario\OneDrive
2020-02-10 19:39 - 2019-11-08 10:32 - 000002410 _____ C:\Users\Usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2020-02-08 22:34 - 2019-11-22 22:03 - 000000000 ____D C:\Users\Usuario\Documents\Adobe
2020-02-08 22:31 - 2019-11-08 10:32 - 000000000 ____D C:\Users\Usuario\AppData\Roaming\Adobe
2020-02-08 12:45 - 2019-11-22 21:57 - 000000000 ____D C:\Program Files\Common Files\Adobe
2020-02-08 12:41 - 2019-11-23 00:03 - 000000000 ____D C:\Users\Public\Documents\Adobe
2020-02-07 22:22 - 2019-11-22 16:14 - 000000000 ____D C:\Users\Usuario\AppData\Local\PlaceholderTileLogoFolder
2020-02-04 16:36 - 2019-12-05 15:43 - 000000000 ____D C:\Users\Usuario\AppData\Roaming\SoftMaker
2020-02-04 15:08 - 2019-11-22 16:15 - 000003622 _____ C:\windows\system32\Tasks\GoogleUpdateTaskMachineUA
2020-02-04 15:08 - 2019-11-22 16:15 - 000003498 _____ C:\windows\system32\Tasks\GoogleUpdateTaskMachineCore
2020-02-03 18:38 - 2019-11-14 13:57 - 000573056 _____ (Advanced Micro Devices, Inc.) C:\windows\system32\Rapidfire64.dll
2020-02-03 18:38 - 2019-11-14 13:57 - 000492160 _____ C:\windows\system32\dgtrayicon.exe
2020-02-03 18:38 - 2019-11-14 13:57 - 000490112 _____ C:\windows\system32\GameManager64.dll
2020-02-03 18:38 - 2019-11-14 13:57 - 000045696 _____ (Advanced Micro Devices, Inc.) C:\windows\system32\RapidFireServer64.dll
2020-02-03 18:38 - 2019-11-14 13:56 - 000450176 _____ C:\windows\system32\atieah64.exe
2020-02-03 18:38 - 2019-11-14 13:56 - 000157824 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\atisamu64.dll
2020-02-03 18:38 - 2019-11-14 13:56 - 000134784 _____ (AMD) C:\windows\system32\atimuixx.dll
2020-02-03 18:38 - 2019-11-08 09:08 - 000759424 _____ (AMD) C:\windows\system32\atieclxx.exe
2020-02-03 18:38 - 2019-11-08 09:08 - 000343168 _____ C:\windows\system32\clinfo.exe
2020-02-03 18:38 - 2019-11-08 09:08 - 000240256 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\atig6txx.dll
2020-02-03 18:38 - 2019-11-08 09:08 - 000182912 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\mantle64.dll
2020-02-03 18:38 - 2019-11-08 09:08 - 000161408 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\mantleaxl64.dll
2020-02-03 18:37 - 2019-11-14 13:56 - 004583040 _____ (Advanced Micro Devices, Inc.) C:\windows\system32\amfrt64.dll
2020-02-03 18:37 - 2019-11-14 13:56 - 000940160 _____ (Advanced Micro Devices, Inc.) C:\windows\system32\amdlvr64.dll
2020-02-03 18:37 - 2019-11-14 13:56 - 000552576 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\amdmcl64.dll
2020-02-03 18:37 - 2019-11-14 13:56 - 000177248 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\aticfx64.dll
2020-02-03 18:37 - 2019-11-14 13:56 - 000156600 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\aticfx32.dll
2020-02-03 18:37 - 2019-11-14 13:56 - 000123008 _____ C:\windows\system32\atidxx64.dll
2020-02-03 18:37 - 2019-11-14 13:56 - 000119424 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\amdxc64.dll
2020-02-03 18:37 - 2019-11-12 19:13 - 000165376 _____ (Advanced Micro Devices, Inc.) C:\windows\SysWOW64\amdihk32.dll
2020-02-03 18:37 - 2019-11-12 19:12 - 000195776 _____ (Advanced Micro Devices, Inc.) C:\windows\system32\amdihk64.dll
2020-02-03 18:37 - 2019-11-08 09:08 - 001729152 _____ (Advanced Micro Devices, Inc.) C:\windows\system32\atiadlxx.dll
2020-02-03 18:35 - 2019-11-14 13:56 - 000545320 _____ C:\windows\system32\amdmiracast.dll
2020-02-03 18:35 - 2019-11-14 13:56 - 000127728 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\atimpc64.dll
2020-02-03 18:35 - 2019-11-14 13:56 - 000127728 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\amdpcom64.dll
2020-02-03 18:35 - 2019-11-14 13:55 - 000133936 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\amdave64.dll
2020-02-02 10:26 - 2019-11-22 16:15 - 000000000 ____D C:\Users\Usuario\AppData\Local\Google
2020-01-30 17:25 - 2019-11-13 00:55 - 003437632 _____ C:\windows\system32\atiumd6a.cap
2020-01-30 17:16 - 2019-11-08 09:08 - 000542696 _____ C:\windows\system32\atiapfxx.blb
2020-01-27 16:39 - 2019-12-18 21:31 - 000000000 ____D C:\USB 64GB
2020-01-24 15:07 - 2019-11-08 10:50 - 000000000 ____D C:\Users\Usuario\AppData\Local\Publishers
2020-01-23 15:20 - 2018-09-15 08:33 - 000000000 ____D C:\windows\system32\NDF

==================== Archivos en la raíz de algunos directorios ========

2019-12-08 18:05 - 2020-02-18 16:37 - 000000028 _____ () C:\Users\Usuario\AppData\Roaming\kulerdata.json
2019-11-28 20:34 - 2020-02-11 18:27 - 000001456 _____ () C:\Users\Usuario\AppData\Local\Adobe Guardar para Web 13.0 Prefs
2019-11-23 12:09 - 2019-11-23 12:09 - 000000000 _____ () C:\Users\Usuario\AppData\Local\oobelibMkey.log

==================== SigCheck ============================

(No existe una corrección automática para los archivos que no pasan la verificación.)

==================== Final de FRST.txt ========================
Resultados del Análisis Adicional de Farbar Recovery Scan Tool (x64) Versión: 16-02-2020
Ejecutado por Usuario (22-02-2020 23:38:18)
Ejecutado desde C:\Users\Usuario\Desktop
Windows 10 Home Versión 1809 17763.1039 (X64) (2019-11-08 09:25:57)
Modo de Inicio: Normal
==========================================================


==================== Cuentas: =============================

Administrador (S-1-5-21-1019904135-823791453-1890871877-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1019904135-823791453-1890871877-503 - Limited - Disabled)
Invitado (S-1-5-21-1019904135-823791453-1890871877-501 - Limited - Disabled)
Usuario (S-1-5-21-1019904135-823791453-1890871877-1001 - Administrator - Enabled) => C:\Users\Usuario
WDAGUtilityAccount (S-1-5-21-1019904135-823791453-1890871877-504 - Limited - Disabled)

==================== Centro de Seguridad ========================

(Si una entrada es incluida en el fixlist, será eliminada.)

AV: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Kaspersky Security Cloud (Disabled - Up to date) {0AB30972-4BAC-7BEE-CBCA-B8F9E68797D8}
AS: Kaspersky Security Cloud (Disabled - Up to date) {B1D2E896-6D96-7460-F17A-838B9D00DD65}
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Security Cloud (Disabled) {32888857-01C3-7AB6-E095-11CC1854D0A3}

==================== Programas instalados ======================

(Solo los programas de adware con indicador "Oculto", pueden ser añadidos al fixlist para hacerlos visibles. Los programas adware deben ser desinstalados manualmente.)

µTorrent (HKU\S-1-5-21-1019904135-823791453-1890871877-1001\...\uTorrent) (Version: 3.5.5.45505 - BitTorrent Inc.)
Adobe Acrobat DC (HKLM-x32\...\{AC76BA86-1033-FFFF-7760-0C0F074E4100}) (Version: 20.006.20034 - Adobe Systems Incorporated)
Adobe Acrobat Reader DC - Español (HKLM-x32\...\{AC76BA86-7AD7-1034-7B44-AC0F074E4100}) (Version: 20.006.20034 - Adobe Systems Incorporated)
Adobe After Effects 2020 (HKLM-x32\...\AEFT_17_0_1) (Version: 17.0.1 - Adobe Systems Incorporated)
Adobe Audition 2020 (HKLM-x32\...\AUDT_13_0) (Version: 13.0 - Adobe Systems Incorporated)
Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 5.0.0.354 - Adobe Systems Incorporated)
Adobe Dimension (HKLM-x32\...\ESHR_3_0) (Version: 3.0 - Adobe Systems Incorporated)
Adobe Illustrator 2020 (HKLM-x32\...\ILST_24_0) (Version: 24.0 - Adobe Systems Incorporated)
Adobe InDesign 2020 (HKLM-x32\...\IDSN_15_0) (Version: 15.0 - Adobe Systems Incorporated)
Adobe Lightroom Classic (HKLM-x32\...\LTRM_9_0) (Version: 9.0 - Adobe Systems Incorporated)
Adobe Media Encoder 2020 (HKLM-x32\...\AME_14_0) (Version: 14.0 - Adobe Systems Incorporated)
Adobe Photoshop 2020 (HKLM-x32\...\PHSP_21_0_1) (Version: 21.0.1 - Adobe Systems Incorporated)
Adobe Premiere Pro 2020 (HKLM-x32\...\PPRO_14_0) (Version: 14.0 - Adobe Systems Incorporated)
Affinity Designer (HKLM\...\{3CA63F54-85C0-4077-8336-B795B90E9B7E}) (Version: 1.7.3.481 - Serif (Europe) Ltd)
Affinity Photo (HKLM\...\{6EE06075-1F8E-4737-B744-B2BB8E2BFE28}) (Version: 1.7.3.481 - Serif (Europe) Ltd)
Affinity Publisher (HKLM\...\{807C4485-85E7-48FC-AC19-6F5723F942C1}) (Version: 1.7.3.481 - Serif (Europe) Ltd)
AMD Software (HKLM\...\AMD Catalyst Install Manager) (Version: 20.2.1 - Advanced Micro Devices, Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Battlefield™ 1 (HKLM-x32\...\{335B50BC-6130-4BAF-9A6A-F1561270587B}) (Version: 1.0.57.44284 - Electronic Arts)
Branding64 (HKLM\...\{133E6274-9FD4-4ABD-80A8-2A954E89EAD6}) (Version: 1.00.0002 - Advanced Micro Devices, Inc.) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 5.63 - Piriform)
Compatibilidad con Aplicaciones de Apple (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.)
Epic Games Launcher (HKLM-x32\...\{385D03C4-767B-4B5F-A627-61319D136EF4}) (Version: 1.1.236.0 - Epic Games, Inc.)
Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 79.0.3945.130 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.441 - Google LLC) Hidden
Gyazo 4.1.0.0 (HKLM-x32\...\{6DB8C365-E719-4BA5-9594-10DFC244D3FD}_is1) (Version:  - Nota Inc.)
HP Audio Switch (HKLM-x32\...\{20A40E7C-E470-4E9F-9B5C-DDB2C205E856}) (Version: 1.0.154.0 - HP Inc.)
HP Connection Optimizer (HKLM-x32\...\{6468C4A5-E47E-405F-B675-A70A70983EA6}) (Version: 2.0.15.0 - HP Inc.)
HP Documentation (HKLM\...\HP_Documentation) (Version: 1.0.0.1 - HP Inc.)
HP JumpStart Bridge (HKLM-x32\...\{016FBF6D-AEDE-4D33-87B4-DF6815EF674A}) (Version: 1.4.0.485 - HP Inc.)
HP JumpStart Launch (HKLM-x32\...\{35556CCA-F14E-48F3-93F4-E29C4B3DBE30}) (Version: 1.4.485.0 - HP Inc.)
HP Support Assistant (HKLM-x32\...\{F322B446-B157-4257-B44F-4F22D41F8EDB}) (Version: 8.8.24.33 - HP Inc.)
HP Support Solutions Framework (HKLM-x32\...\{D13AEB56-7A17-43F1-9839-A30B6C50CC56}) (Version: 12.14.49.15 - HP Inc.)
HP System Event Utility (HKLM-x32\...\{57058272-92B0-4EFA-8FDD-ED3E5D689D37}) (Version: 1.4.32 - HP Inc.)
Intel(R) C++ Redistributables on Intel(R) 64 (HKLM-x32\...\{F70BCE36-25F2-4475-A918-6209B3D85BF3}) (Version: 15.0.179 - Intel Corporation)
Juegos WildTangent (HKLM-x32\...\WildTangent wildgames Master Uninstall) (Version: 1.1.1.47 - WildTangent)
Kaspersky Password Manager (HKLM-x32\...\{B2F7333E-6C8D-4994-AAC4-FEC8EBBF9611}) (Version: 9.0.2.767 - Kaspersky Lab) Hidden
Kaspersky Password Manager (HKLM-x32\...\InstallWIX_{B2F7333E-6C8D-4994-AAC4-FEC8EBBF9611}) (Version: 9.0.2.767 - Kaspersky Lab)
Kaspersky Secure Connection (HKLM-x32\...\{145AE349-477A-45E5-A57C-5F5BF2BB5775}) (Version: 20.0.14.1085 - Kaspersky) Hidden
Kaspersky Secure Connection (HKLM-x32\...\InstallWIX_{145AE349-477A-45E5-A57C-5F5BF2BB5775}) (Version: 20.0.14.1085 - Kaspersky)
Kaspersky Security Cloud (HKLM-x32\...\{D891550B-ACFE-4797-B368-BCFC434BBEB1}) (Version: 20.0.14.1085 - Kaspersky) Hidden
Kaspersky Security Cloud (HKLM-x32\...\InstallWIX_{D891550B-ACFE-4797-B368-BCFC434BBEB1}) (Version: 20.0.14.1085 - Kaspersky)
Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
League of Legends (HKU\S-1-5-21-1019904135-823791453-1890871877-1001\...\Riot Game league_of_legends.live) (Version:  - Riot Games, Inc)
Malwarebytes version 4.0.4.49 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.0.4.49 - Malwarebytes)
Maxon Cinema 4D R21 (HKLM\...\Maxon Cinema 4D R21) (Version: R21 - Maxon)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 80.0.361.57 - Microsoft Corporation)
Microsoft Edge Update (HKLM-x32\...\Microsoft Edge Update) (Version: 1.3.121.21 - )
Microsoft Office Profesional Plus 2019 - es-es (HKLM\...\ProPlus2019Retail - es-es) (Version: 16.0.12430.20264 - Microsoft Corporation)
Microsoft Office Professional Plus 2019 - en-us (HKLM\...\ProPlus2019Retail - en-us) (Version: 16.0.12430.20264 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1019904135-823791453-1890871877-1001\...\OneDriveSetup.exe) (Version: 19.232.1124.0005 - Microsoft Corporation)
Microsoft Project Professional 2019 - en-us (HKLM\...\ProjectPro2019Retail - en-us) (Version: 16.0.12430.20264 - Microsoft Corporation)
Microsoft Project Professional 2019 - es-es (HKLM\...\ProjectPro2019Retail - es-es) (Version: 16.0.12430.20264 - Microsoft Corporation)
Microsoft Visio Professional 2019 - en-us (HKLM\...\VisioPro2019Retail - en-us) (Version: 16.0.12430.20264 - Microsoft Corporation)
Microsoft Visio Professional 2019 - es-es (HKLM\...\VisioPro2019Retail - es-es) (Version: 16.0.12430.20264 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40660 (HKLM-x32\...\{ef6b00ec-13e1-4c25-9064-b2f383cb8412}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40660 (HKLM-x32\...\{61087a79-ac85-455c-934d-1fa22cc64f36}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x64) - 14.15.26706 (HKLM-x32\...\{95ac1cfa-f4fb-4d1b-8912-7f9d5fbb140d}) (Version: 14.15.26706.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (HKLM-x32\...\{7e9fae12-5bbf-47fb-b944-09c49e75c061}) (Version: 14.15.26706.0 - Microsoft Corporation)
Microsoft Visual Studio Code (User) (HKU\S-1-5-21-1019904135-823791453-1890871877-1001\...\{771FD6B0-FA20-440A-A002-3B3BAC16DC50}_is1) (Version: 1.41.1 - Microsoft Corporation)
Minecraft Launcher (HKLM-x32\...\{810F1419-7760-402E-8772-B4054FAA2B72}) (Version: 1.0.0.0 - Mojang)
Movistar Cloud (HKLM-x32\...\Movistar Cloud) (Version: 8.0.3 - Movistar-Cloud)
Mozilla Firefox 72.0.1 (x64 es-ES) (HKLM\...\Mozilla Firefox 72.0.1 (x64 es-ES)) (Version: 72.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 72.0.1 - Mozilla)
OEM Application Profile (HKLM-x32\...\{12C2AEB0-ED60-4CCF-DD83-C65BC7CCFB50}) (Version: 1.00.0000 - Advanced Micro Devices, Inc.)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.12430.20264 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.12430.20184 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0409-1000-0000000FF1CE}) (Version: 16.0.12430.20264 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0C0A-1000-0000000FF1CE}) (Version: 16.0.12430.20264 - Microsoft Corporation) Hidden
Opera Stable 66.0.3515.103 (HKU\S-1-5-21-1019904135-823791453-1890871877-1001\...\Opera 66.0.3515.103) (Version: 66.0.3515.103 - Opera Software)
Origin (HKLM-x32\...\Origin) (Version: 10.5.57.35162 - Electronic Arts, Inc.)
Pentablet versión 1.6.4.1948 (HKLM\...\{5DAB8C1A-6D8E-467D-BE62-AC13087AA950}_is1) (Version: 1.6.4.1948 - XPPEN Technology)
PicPick (HKLM-x32\...\PicPick) (Version: 5.0.7 - NGWIN)
PSD Codec by Ardfry Imaging, LLC (32 bit) (HKLM-x32\...\{830CBF47-6ED5-428C-82F3-4E05469D3BC7}) (Version: 1.0.7.0 - Ardfry Imaging, LLC) Hidden
PSD Codec by Ardfry Imaging, LLC (64 bit) (HKLM\...\{47DD3544-EA94-4B97-82EB-3693D7E4B442}) (Version: 1.0.7.0 - Ardfry Imaging, LLC) Hidden
PSD CODEC Version 1.4.0.0 (HKLM\...\Ardfry PSD CODEC_is1) (Version: 1.4.0.0 - Ardfry Imaging, LLC)
QuickTime 7 (HKLM-x32\...\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8652 - Realtek Semiconductor Corp.)
STAR WARS™ Battlefront™ (HKLM-x32\...\{E402D891-4E45-4ce9-B41F-DD35864EF170}) (Version: 1.0.7.64833 - Electronic Arts)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Telegram Desktop versión 1.9.14 (HKU\S-1-5-21-1019904135-823791453-1890871877-1001\...\{53F49750-6209-4FBF-9CA8-7A333C87D1ED}_is1) (Version: 1.9.14 - Telegram FZ-LLC)
Vulkan Run Time Libraries 1.1.70.0 (HKLM\...\VulkanRT1.1.70.0) (Version: 1.1.70.0 - LunarG, Inc.) Hidden
WildTangent Helper (HKLM-x32\...\{A39303AB-4898-4F12-BAA0-0B8630F86DB4}) (Version: 1.0.0.400 - WildTangent) Hidden
WildTangent ShortcutProvider (HKLM-x32\...\{80831F60-19D7-43B3-A60C-5CAF8C478DF6}) (Version: 6.0.0.43 - WildTangent) Hidden
WinRAR 5.71 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.71.0 - win.rar GmbH)
Wondershare Helper Compact 2.5.2 (HKLM-x32\...\{5363CE84-5F09-48A1-8B6C-6BB590FFEDF2}_is1) (Version: 2.5.2 - Wondershare)
Wondershare PDFelement(Build 7.3.4) (HKLM-x32\...\{77078E40-A92E-47FD-A0F6-168A4BF6CF3A}_is1) (Version: 7.3.4.4627 - Wondershare Software Co.,Ltd.)

Packages:
=========
¡Solitario! -> C:\Program Files\WindowsApps\26720RandomSaladGamesLLC.SimpleSolitaire_6.16.72.0_x64__kx24dqmazqk8j [2020-01-24] (Random Salad Games LLC) [MS Ad]
Acrobat Notification Client -> C:\Program Files\WindowsApps\AcrobatNotificationClient_1.0.4.0_x86__e1rzdqpraam7r [2020-02-11] (Adobe Systems Incorporated)
AdBlock -> C:\Program Files\WindowsApps\BetaFish.AdBlock_2.13.0.0_neutral__c1wakc4j0nefm [2020-02-01] (BetaFish)
Adobe Notification Client -> C:\Program Files\WindowsApps\AdobeNotificationClient_1.0.1.22_x86__enpm4xejd91yc [2019-11-23] (Adobe Systems Incorporated)
Adobe XD -> C:\Program Files\WindowsApps\Adobe.CC.XD_27.1.12.4_x64__adky2gkssdxte [2020-02-18] (Adobe Systems Incorporated)
Ajuste del suelo -> C:\windows\SystemApps\RoomAdjustment_cw5n1h2txyewy [2019-11-23] (Microsoft Corporation)
Autodesk SketchBook -> C:\Program Files\WindowsApps\89006A2E.AutodeskSketchBook_5.1.0.0_x64__tf1gferkr813w [2019-12-01] (Autodesk Inc.)
Booking.com EMEA: Big savings on hotels in 96,000 destinations worldwide -> C:\Program Files\WindowsApps\PricelinePartnerNetwork.Booking.comEMEABigsavingso_1.0.4.0_x64__mgae2k3ys4ra0 [2019-11-23] (Priceline Partner Network)
Descubrir la realidad mixta -> C:\windows\SystemApps\MixedRealityLearning_cw5n1h2txyewy [2019-11-23] (Microsoft Corporation)
Dropbox - promoción -> C:\Program Files\WindowsApps\C27EB4BA.DropboxOEM_20.4.3.0_x64__xbfy0k16fey96 [2020-01-14] (Dropbox Inc.)
Energy Star -> C:\Program Files\WindowsApps\AD2F1837.HPInc.EnergyStar_1.2.0.0_x64__v10z8vjag6ke6 [2019-11-08] (HP Inc.)
HP JumpStart -> C:\Program Files\WindowsApps\AD2F1837.HPJumpStart_1.4.481.0_x86__v10z8vjag6ke6 [2019-11-08] (HP Inc.)
HP PC Hardware Diagnostics Windows -> C:\Program Files\WindowsApps\AD2F1837.HPPCHardwareDiagnosticsWindows_1.6.3.0_x64__v10z8vjag6ke6 [2020-01-21] (HP Inc.)
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_110.1.671.0_x64__v10z8vjag6ke6 [2020-02-05] (HP Inc.)
Inky - PDF reader & ink annotation -> C:\Program Files\WindowsApps\30113AndreaDelBello.DInk-PDFreaderinkannotation_2.0.28.0_x64__2mj5svk4jk01m [2020-01-27] (Andrea Del Bello) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-11-23] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-11-23] (Microsoft Corporation) [MS Ad]
Microsoft Whiteboard -> C:\Program Files\WindowsApps\Microsoft.Whiteboard_20.10127.4764.0_x64__8wekyb3d8bbwe [2020-02-11] (Microsoft Corporation)
MSN El Tiempo -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.34.13393.0_x64__8wekyb3d8bbwe [2019-12-18] (Microsoft Corporation) [MS Ad]
Netflix -> C:\Program Files\WindowsApps\4DF9E0F8.Netflix_6.95.602.0_x64__mcm4njqhnhss8 [2019-11-23] (Netflix, Inc.)
Novedades para ti -> C:\windows\SystemApps\WhatsNew_cw5n1h2txyewy [2019-11-23] (Microsoft Corporation)
Passthrough -> C:\windows\SystemApps\passthrough_cw5n1h2txyewy [2019-11-08] (Microsoft Corporation)
PDF Ink -> C:\Program Files\WindowsApps\36376UserCamp.PDFInk_1.1.41.0_x64__t7afzrbtd67z0 [2020-01-28] (User Camp)
Sign In -> C:\windows\SystemApps\WebAuthBridgeInternet_cw5n1h2txyewy [2019-11-08] (ms-resource:PublisherDisplayName)
Sign In -> C:\windows\SystemApps\WebAuthBridgeInternetSso_cw5n1h2txyewy [2019-11-08] (ms-resource:PublisherDisplayName)
Sign In -> C:\windows\SystemApps\WebAuthBridgeIntranetSso_cw5n1h2txyewy [2019-11-08] (ms-resource:PublisherDisplayName)
Synaptics TouchPad -> C:\Program Files\WindowsApps\SynapticsIncorporated.SynHPConsumerDApp_19005.35042.0.0_x64__807d65c4rvak2 [2019-11-22] (Synaptics Incorporated)
Trello -> C:\Program Files\WindowsApps\45273LiamForsyth.PawsforTrello_2.11.3.0_x64__7pb5ddty8z1pa [2019-12-18] (Trello, Inc.)
uBlock Origin -> C:\Program Files\WindowsApps\37833NikRolls.uBlockOrigin_1.15.24.0_neutral__f8jsg5mm64m62 [2020-02-01] (Nik Rolls)
WildTangent Games -> C:\Program Files\WindowsApps\WildTangentGames.63435CFB65F55_2.0.82.0_x64__qt5r5pa5dyg8m [2019-12-23] (WildTangent Games)

==================== Personalizado CLSID (Lista blanca): ==============

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)

CustomCLSID: HKU\S-1-5-21-1019904135-823791453-1890871877-1001_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-584F653B76A1} -> [Creative Cloud Files] => C:\Users\Usuario\Creative Cloud Files [2019-11-23 12:00]
CustomCLSID: HKU\S-1-5-21-1019904135-823791453-1890871877-1001_Classes\CLSID\{60a9b097-020e-49da-acc9-f877308c59be} -> [Movistar Cloud] => C:\Users\Usuario\Movistar Cloud\ [0000-00-00 00:00]
CustomCLSID: HKU\S-1-5-21-1019904135-823791453-1890871877-1001_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Inc. -> Adobe Systems)
ShellIconOverlayIdentifiers: [   AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2020-01-07] (Adobe Inc. -> )
ShellIconOverlayIdentifiers: [   AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2020-01-07] (Adobe Inc. -> )
ShellIconOverlayIdentifiers: [   AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2020-01-07] (Adobe Inc. -> )
ShellIconOverlayIdentifiers: [  000_MovistarCloudSyncOverlayError] -> {2127DAAC-E24F-4D3C-88FF-6EE27182BDAA} => C:\Program Files (x86)\Movistar Cloud\x64\syncTagIconExt.dll [2019-12-30] (TODO: <Company name>) [Archivo no firmado]
ShellIconOverlayIdentifiers: [  001_MovistarCloudSyncOverlayInProgress] -> {3B641153-E46B-43B8-8B67-4DB875D2C1A2} => C:\Program Files (x86)\Movistar Cloud\x64\syncTagIconExt.dll [2019-12-30] (TODO: <Company name>) [Archivo no firmado]
ShellIconOverlayIdentifiers: [  002_MovistarCloudSyncOverlayInSync] -> {B4187CBF-F5A2-4E91-A6FA-D914C9600FC7} => C:\Program Files (x86)\Movistar Cloud\x64\syncTagIconExt.dll [2019-12-30] (TODO: <Company name>) [Archivo no firmado]
ShellIconOverlayIdentifiers: [  003_MovistarCloudSyncOverlayExcluded] -> {43619511-8A7D-4898-9E05-AFD0EC1B0BD5} => C:\Program Files (x86)\Movistar Cloud\x64\syncTagIconExt.dll [2019-12-30] (TODO: <Company name>) [Archivo no firmado]
ShellIconOverlayIdentifiers: [  004_MovistarCloudSyncOverlayInSyncShared] -> {FECEFC13-0472-407C-92F6-006D64B9B219} => C:\Program Files (x86)\Movistar Cloud\x64\syncTagIconExt.dll [2019-12-30] (TODO: <Company name>) [Archivo no firmado]
ShellIconOverlayIdentifiers: [  005_MovistarCloudSyncOverlayAvValidating] -> {2A08B4C0-AA9A-4619-9642-734F381B8ED1} => C:\Program Files (x86)\Movistar Cloud\x64\syncTagIconExt.dll [2019-12-30] (TODO: <Company name>) [Archivo no firmado]
ContextMenuHandlers1: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2020-01-07] (Adobe Inc. -> )
ContextMenuHandlers1: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat Elements\ContextMenuShim64.dll [2020-02-04] (Adobe Inc. -> Adobe Systems Inc.)
ContextMenuHandlers1: [CMPCContextMenu] -> {1650dc30-2343-498a-b49a-37b90918f611} => C:\Program Files\CleanMyPC\CleanMyPCShell.DLL [2019-12-20] (MacPaw INC -> MacPaw Inc.)
ContextMenuHandlers1: [Kaspersky Anti-Virus 20.0] -> {6E1B4453-548D-4C43-A4AB-DE8D1D3DE17B} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Cloud 20.0\x64\ShellEx.dll [2019-12-08] (Kaspersky Lab -> AO Kaspersky Lab)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers2: [Kaspersky Anti-Virus 20.0] -> {6E1B4453-548D-4C43-A4AB-DE8D1D3DE17B} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Cloud 20.0\x64\ShellEx.dll [2019-12-08] (Kaspersky Lab -> AO Kaspersky Lab)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-02-22] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers4: [CMPCContextMenu] -> {1650dc30-2343-498a-b49a-37b90918f611} => C:\Program Files\CleanMyPC\CleanMyPCShell.DLL [2019-12-20] (MacPaw INC -> MacPaw Inc.)
ContextMenuHandlers4: [Kaspersky Anti-Virus 20.0] -> {6E1B4453-548D-4C43-A4AB-DE8D1D3DE17B} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Cloud 20.0\x64\ShellEx.dll [2019-12-08] (Kaspersky Lab -> AO Kaspersky Lab)
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files\AMD\CNext\CNext\atiacm64.dll [2020-01-30] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
ContextMenuHandlers6: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2020-01-07] (Adobe Inc. -> )
ContextMenuHandlers6: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat Elements\ContextMenuShim64.dll [2020-02-04] (Adobe Inc. -> Adobe Systems Inc.)
ContextMenuHandlers6: [Kaspersky Anti-Virus 20.0] -> {6E1B4453-548D-4C43-A4AB-DE8D1D3DE17B} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Cloud 20.0\x64\ShellEx.dll [2019-12-08] (Kaspersky Lab -> AO Kaspersky Lab)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-02-22] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)

==================== Codecs (Lista blanca) ====================

==================== Accesos directos & WMI ========================

(Las entradas pueden ser listadas para ser restauradas o eliminadas.)

ShortcutWithArgument: C:\Users\Usuario\AppData\Local\Microsoft\Edge\User Data\Default\Microsoft Edge.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe (Microsoft Corporation) -> --profile-directory=Default
ShortcutWithArgument: C:\Users\Usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplicaciones de Chrome\Calculator.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  --profile-directory=Default --app-id=decmldkknaaemlafplkkdmmmelbdnlja
ShortcutWithArgument: C:\Users\Usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplicaciones de Chrome\Caret.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  --profile-directory=Default --app-id=fljalecfjciodhpcledpamjachpmelml
ShortcutWithArgument: C:\Users\Usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplicaciones de Chrome\Google Keep_ notas y listas.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  --profile-directory=Default --app-id=hmjkmjkepdijhoojdojkdfohbdgmmhki
ShortcutWithArgument: C:\Users\Usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplicaciones de Chrome\Gravit Designer.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  --profile-directory=Default --app-id=pdagghjnpkeagmlbilmjmclfhjeaapaa
ShortcutWithArgument: C:\Users\Usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplicaciones de Chrome\System.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  --profile-directory=Default --app-id=ocjnemjmlhjkeilmaidemofakmpclcbi
ShortcutWithArgument: C:\Users\Usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplicaciones de Chrome\Telegram.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  --profile-directory=Default --app-id=clhhggbfdinjmjhajaheehoeibfljjno
ShortcutWithArgument: C:\Users\Usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplicaciones de Chrome\Zed Code Editor.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  --profile-directory=Default --app-id=pfmjnmeipppmcebplngmhfkleiinphhp
ShortcutWithArgument: C:\Users\Usuario\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Microsoft Edge.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe (Microsoft Corporation) -> --profile-directory=Default
ShortcutWithArgument: C:\Users\Usuario\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\d249d9ddd424b688\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory=Default

==================== Módulos cargados (Lista blanca) =============

2019-12-30 13:54 - 2019-12-30 13:54 - 000037888 _____ () [Archivo no firmado] C:\Program Files (x86)\Movistar Cloud\x64\libSyncTagIconExt.dll
2020-02-17 17:41 - 2020-02-17 17:41 - 000160768 _____ () [Archivo no firmado] C:\windows\assembly\NativeImages_v4.0.30319_32\BRIDGECommon\e6efbef310e99d946baffb1fa25131bf\BRIDGECommon.ni.dll
2020-02-18 19:38 - 2020-02-18 19:38 - 000125440 _____ () [Archivo no firmado] C:\windows\assembly\NativeImages_v4.0.30319_32\BridgeExtension\c655d42443428f15105d456a5724867c\BridgeExtension.ni.dll
2020-02-18 19:38 - 2020-02-18 19:38 - 000395264 _____ () [Archivo no firmado] C:\windows\assembly\NativeImages_v4.0.30319_32\CleanStartController\8838a27625be889c38c70ab6b640c8c1\CleanStartController.ni.dll
2020-02-18 19:38 - 2020-02-18 19:38 - 000145920 _____ () [Archivo no firmado] C:\windows\assembly\NativeImages_v4.0.30319_32\Registratio4eabc192#\628ec229af7290ef6960fbdc473891cc\RegistrationUtilities.ni.dll
2020-02-18 19:38 - 2020-02-18 19:38 - 000136192 _____ (HP Inc.) [Archivo no firmado] C:\windows\assembly\NativeImages_v4.0.30319_32\CommonPortable\bd0e151e26ae0cc1dec8976a53366433\CommonPortable.ni.dll
2020-02-17 17:42 - 2020-02-17 17:42 - 002306560 _____ (Newtonsoft) [Archivo no firmado] C:\windows\assembly\NativeImages_v4.0.30319_32\Newtonsoft.Json\67e96d905b0ee480dadec8739f7ed467\Newtonsoft.Json.ni.dll
2019-12-30 13:54 - 2019-12-30 13:54 - 005861376 _____ (The Qt Company Ltd.) [Archivo no firmado] C:\Program Files (x86)\Movistar Cloud\x64\Qt5Core.dll
2019-12-30 13:54 - 2019-12-30 13:54 - 001231872 _____ (The Qt Company Ltd.) [Archivo no firmado] C:\Program Files (x86)\Movistar Cloud\x64\Qt5Network.dll
2019-12-30 13:54 - 2019-12-30 13:54 - 000582144 _____ (TODO: <Company name>) [Archivo no firmado] C:\Program Files (x86)\Movistar Cloud\x64\syncTagIconExt.dll

==================== Alternate Data Streams (Lista blanca) ========

(Si una entrada es incluida en el fixlist, solamente los ADS serán eliminados.)

AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [476]
AlternateDataStreams: C:\Users\Usuario\ntuser.ini:NTV [12190]
AlternateDataStreams: C:\Users\Usuario\AppData\Local\Temp:com.affinity.designer.1 [240]
AlternateDataStreams: C:\Users\Usuario\AppData\Local\Temp:com.affinity.photo.1 [240]
AlternateDataStreams: C:\Users\Usuario\AppData\Local\Temp:com.affinity.publisher.1 [240]

==================== Modo Seguro (Lista blanca) ==================

(Si una entrada es incluida en el fixlist, será eliminada del registro. El "AlternateShell" será restaurado.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service"

==================== Asociación (Lista blanca) =================

==================== Internet Explorer sitios de confianza/restringidos ==========

==================== Hosts contenido: =========================

(Si es necesario, la directiva Hosts: puede ser incluida en el fixlist para restablecer Hosts.)

2018-09-15 08:31 - 2018-09-15 08:31 - 000000824 _____ C:\windows\system32\drivers\etc\hosts

==================== Otras Áreas ===========================

(Actualmente no existe una corrección automática para esta sección.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> %INTEL_DEV_REDIST%redist\intel64\compiler;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\;C:\Program Files (x86)\QuickTime\QTSystem\
HKU\S-1-5-21-1019904135-823791453-1890871877-1001\Control Panel\Desktop\\Wallpaper -> c:\users\usuario\downloads\wallhaven-3k387d.jpg
DNS Servers: El medio no está conectado a internet.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Firewall de Windows está habilitado.

==================== MSCONFIG/TASK MANAGER elementos deshabilitados ==

(Si una entrada es incluida en el fixlist, será eliminada.)

HKLM\...\StartupApproved\Run: => "PentabletService"
HKLM\...\StartupApproved\Run32: => "HPMessageService"
HKLM\...\StartupApproved\Run32: => "Wondershare Helper Compact.exe"
HKU\S-1-5-21-1019904135-823791453-1890871877-1001\...\StartupApproved\Run: => "utweb"
HKU\S-1-5-21-1019904135-823791453-1890871877-1001\...\StartupApproved\Run: => "Gyazo"
HKU\S-1-5-21-1019904135-823791453-1890871877-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-1019904135-823791453-1890871877-1001\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-1019904135-823791453-1890871877-1001\...\StartupApproved\Run: => "uTorrent"
HKU\S-1-5-21-1019904135-823791453-1890871877-1001\...\StartupApproved\Run: => "EpicGamesLauncher"
HKU\S-1-5-21-1019904135-823791453-1890871877-1001\...\StartupApproved\Run: => "PicPick Start"

==================== Reglas de firewall (Lista blanca) ================

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)

FirewallRules: [{5B79FD2C-7248-4DDD-B7B2-487B62BD311C}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [{DB10C356-EBA7-46E4-9D85-46CABE8AD134}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [{AB4B3462-08C6-4B9A-B663-2DB5F5DFB6C5}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{695AE260-D06E-4C50-AD88-2E64CF26EA7F}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{9A0830BD-4652-4BD9-AD7D-403E499445D9}] => (Allow) D:\SteamLibrary\steamapps\common\Counter-Strike Global Offensive\csgo.exe Ningún archivo
FirewallRules: [{612DB35F-E562-4B02-8109-0197B9F7F046}] => (Allow) D:\SteamLibrary\steamapps\common\Counter-Strike Global Offensive\csgo.exe Ningún archivo
FirewallRules: [{093E55F7-1AEA-4671-973D-5AF45E2E81C4}] => (Allow) C:\Users\Usuario\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{4CF75D6C-E17C-41F9-A830-B7618986D691}] => (Allow) C:\Users\Usuario\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{F4C3F58A-398A-4ADA-A573-EF4F4A343BE8}] => (Allow) D:\Battlefield 1 Campaña\bf1Trial.exe Ningún archivo
FirewallRules: [{5B50523D-99AB-41D7-A1F0-447631C36E0D}] => (Allow) D:\Battlefield 1 Campaña\bf1Trial.exe Ningún archivo
FirewallRules: [{A3F0EA36-637A-4061-B839-6A8DB25C9788}] => (Allow) D:\Battlefield 1 Campaña\bf1.exe Ningún archivo
FirewallRules: [{68C6CCB4-FAED-4C4C-8067-E4EE8F0CDFA2}] => (Allow) D:\Battlefield 1 Campaña\bf1.exe Ningún archivo
FirewallRules: [TCP Query User{DC0D882D-F964-41B3-9598-12C9DD045E10}D:\battlefield1\battlefield.1-cpy\setup\bf1.exe] => (Allow) D:\battlefield1\battlefield.1-cpy\setup\bf1.exe Ningún archivo
FirewallRules: [UDP Query User{07278328-596C-449D-9BB6-B1AD2AF3812C}D:\battlefield1\battlefield.1-cpy\setup\bf1.exe] => (Allow) D:\battlefield1\battlefield.1-cpy\setup\bf1.exe Ningún archivo
FirewallRules: [TCP Query User{4A47D3AC-EDAF-4926-9AB7-80A975342DFB}C:\riot games\league of legends\game\league of legends.exe] => (Allow) C:\riot games\league of legends\game\league of legends.exe (Riot Games, Inc. -> )
FirewallRules: [UDP Query User{E281646A-1512-4142-9BD5-562B1D906DBD}C:\riot games\league of legends\game\league of legends.exe] => (Allow) C:\riot games\league of legends\game\league of legends.exe (Riot Games, Inc. -> )
FirewallRules: [TCP Query User{C796A8C8-1873-4B2B-A7F8-473FBA999DEE}D:\battlefront\star wars battlefront\starwarsbattlefront.exe] => (Allow) D:\battlefront\star wars battlefront\starwarsbattlefront.exe Ningún archivo
FirewallRules: [UDP Query User{595BC6D1-F7A3-479B-9C19-D4691885001F}D:\battlefront\star wars battlefront\starwarsbattlefront.exe] => (Allow) D:\battlefront\star wars battlefront\starwarsbattlefront.exe Ningún archivo
FirewallRules: [{1ED03742-38A6-4BFD-B97D-4FA3520FF4F0}] => (Allow) D:\Battlefield 1 Origin\Battlefield 1\bf1Trial.exe Ningún archivo
FirewallRules: [{DA599FAA-5540-4F29-8737-F17E2586EF73}] => (Allow) D:\Battlefield 1 Origin\Battlefield 1\bf1Trial.exe Ningún archivo
FirewallRules: [{64BAD4CA-46E4-4E57-9A7C-A153A26E63C8}] => (Allow) D:\Battlefield 1 Origin\Battlefield 1\bf1.exe Ningún archivo
FirewallRules: [{45DA994D-E6E6-48F9-92BF-27D5E6864F8B}] => (Allow) D:\Battlefield 1 Origin\Battlefield 1\bf1.exe Ningún archivo
FirewallRules: [TCP Query User{8A692CE8-D84D-4DD8-BF92-D562B700B9FE}C:\program files (x86)\minecraft launcher\runtime\jre-x64\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft launcher\runtime\jre-x64\bin\javaw.exe
FirewallRules: [UDP Query User{B39AABBA-F0DF-4419-9483-E62B08DDE907}C:\program files (x86)\minecraft launcher\runtime\jre-x64\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft launcher\runtime\jre-x64\bin\javaw.exe
FirewallRules: [{985E6BA8-E10D-4031-8D64-029D53374463}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{12B5D9BA-737D-4147-8A62-CD0FE946F49C}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{69C35D10-AF8C-43A7-8CA6-806E5F2AA913}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{C8571728-500B-4AF4-AB4A-27371AF67002}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{C68029B9-61CF-4DB6-9F70-60EBA97055A7}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{1B96ED21-52B7-42F1-8243-7A0CE397E278}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{4B65E5CA-6FBA-4008-84EC-00F73BB91AF3}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{65140388-DE5D-4ED6-A3C2-70BC2AC12C55}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{54E101C5-1083-4890-8B80-EC9A157AC1EE}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{B2C0697B-4436-463F-B91C-C548AA58DDE5}] => (Allow) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe (Microsoft Corporation -> Microsoft Corporation)

==================== Puntos de Restauración =========================

18-02-2020 18:39:06 Radeon Installer
22-02-2020 23:29:15 JRT Pre-Junkware Removal

==================== Dispositivos defectuosos en el Administrador de dispositivos ============


==================== Errores del registro de eventos: ========================

Errores de aplicación:
==================
Error: (02/22/2020 11:28:00 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Error del Servicio de instantáneas de volumen: error inesperado al llamar a la rutina QueryFullProcessImageNameW. HR = 0x8007001f, Uno de los dispositivos conectados al sistema no funciona.
.


Operación:
   Ejecutando operación asincrónica

Contexto:
   Estado actual: DoSnapshotSet

Error: (02/22/2020 11:22:51 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Error en la inicialización de la inscripción de certificados de SCEP para WORKGROUP\LAPTOP-CTGO9569$ a través de https://AMD-KeyId-2e6bfdd2e20d739bec23f3ef706ddc952bb6a4bf.microsoftaik.azure.net/templates/Aik/scep:

GetCACaps

Método: GET(250ms)
Fase: GetCACaps
No se pudo resolver el nombre de servidor o su dirección 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED)

Error: (02/22/2020 11:19:53 PM) (Source: Application Error) (EventID: 1005) (User: )
Description: Windows no puede tener acceso al archivo  por alguna de las siguientes razones:
Hay un problema con la conexión de red, con el disco donde se almacena este archivo o con los controladores
de almacenamiento instalados en este equipo; o bien no se encuentra el disco.
Windows cerró el programa WildTangentHelperService.exe por este error.

Programa: WildTangentHelperService.exe
Archivo: 

El valor del error se muestra en la sección Datos adicionales.
Acción del usuario
1. Abra el archivo de nuevo.
Podría ser solo un problema temporal que se corrige al ejecutar el programa de nuevo.
2.
Si todavía no se puede tener acceso al archivo y 
	- Está en la red,
el administrador de red debe comprobar que no exista ningún problema con la red y que es posible ponerse en contacto con el servidor.
	- Está en un disco extraíble, como un disquete o un CD-ROM, compruebe que el disco esté insertado en el equipo.
3. Compruebe y repare el sistema de archivos ejecutando CHKDSK. Para ejecutar CHKDSK, haga clic en Inicio y después en Ejecutar; escriba CMD y después haga clic en Aceptar. En el símbolo del sistema, escriba CHKDSK /F y después presione Entrar.
4. Si el problema continúa, restaure el archivo a partir de una copia de seguridad.
5. Compruebe si se pueden abrir otros archivos en el mismo disco. Si no se pueden abrir, el disco podría estar dañado. Si se trata de un disco duro, póngase en contacto con el administrador o con el fabricante del hardware del equipo
para obtener ayuda adicional.

Datos adicionales
Valor del error:00000000
Tipo de disco: 0

Error: (02/22/2020 11:19:53 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nombre de la aplicación con errores: WildTangentHelperService.exe, versión: 1.0.0.400, marca de tiempo: 0x5e444a48
Nombre del módulo con errores: WildTangentHelperService.exe, versión: 1.0.0.400, marca de tiempo: 0x5e444a48
Código de excepción: 0xc0000096
Desplazamiento de errores: 0x000dec9c
Identificador del proceso con errores: 0x16dc
Hora de inicio de la aplicación con errores: 0x01d5e9ce33e047e4
Ruta de acceso de la aplicación con errores: C:\Program Files (x86)\WildTangent Games\Integration\WildTangentHelperService.exe
Ruta de acceso del módulo con errores: C:\Program Files (x86)\WildTangent Games\Integration\WildTangentHelperService.exe
Identificador del informe: cc486698-8b0b-4ce3-b5ef-cd30aa62c7cd
Nombre completo del paquete con errores: 
Identificador de aplicación relativa del paquete con errores:

Error: (02/22/2020 11:14:20 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Error en la inicialización de la inscripción de certificados de SCEP para WORKGROUP\LAPTOP-CTGO9569$ a través de https://AMD-KeyId-2e6bfdd2e20d739bec23f3ef706ddc952bb6a4bf.microsoftaik.azure.net/templates/Aik/scep:

GetCACaps

Método: GET(187ms)
Fase: GetCACaps
No se pudo resolver el nombre de servidor o su dirección 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED)

Error: (02/22/2020 10:13:52 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nombre de la aplicación con errores: RAVBg64.exe, versión: 1.0.0.295, marca de tiempo: 0x5bc04e16
Nombre del módulo con errores: ntdll.dll, versión: 10.0.17763.1039, marca de tiempo: 0x4dc06dfc
Código de excepción: 0xc0000005
Desplazamiento de errores: 0x000000000004df23
Identificador del proceso con errores: 0x1c7c
Hora de inicio de la aplicación con errores: 0x01d5e9b595952da5
Ruta de acceso de la aplicación con errores: C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
Ruta de acceso del módulo con errores: C:\windows\SYSTEM32\ntdll.dll
Identificador del informe: 6099bd99-a5ac-499b-9282-18dc9c753169
Nombre completo del paquete con errores: 
Identificador de aplicación relativa del paquete con errores:

Error: (02/22/2020 08:49:00 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nombre de la aplicación con errores: SystemSettingsAdminFlows.exe, versión: 10.0.17763.292, marca de tiempo: 0xda0f3371
Nombre del módulo con errores: wintypes.dll, versión: 10.0.17763.1007, marca de tiempo: 0x00063452
Código de excepción: 0xc0000005
Desplazamiento de errores: 0x0000000000015b5c
Identificador del proceso con errores: 0x644
Hora de inicio de la aplicación con errores: 0x01d5e9b8c474c3dd
Ruta de acceso de la aplicación con errores: C:\windows\system32\SystemSettingsAdminFlows.exe
Ruta de acceso del módulo con errores: C:\windows\SYSTEM32\wintypes.dll
Identificador del informe: 2d4246e4-271f-4f76-a0b1-6a16129856c8
Nombre completo del paquete con errores: 
Identificador de aplicación relativa del paquete con errores:

Error: (02/22/2020 08:27:34 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nombre de la aplicación con errores: OriginWebHelperService.exe, versión: 10.5.57.35162, marca de tiempo: 0x5df243e3
Nombre del módulo con errores: OriginWebHelperService.exe, versión: 10.5.57.35162, marca de tiempo: 0x5df243e3
Código de excepción: 0xc0000005
Desplazamiento de errores: 0x00099d50
Identificador del proceso con errores: 0xd48
Hora de inicio de la aplicación con errores: 0x01d5e9b55cf777cd
Ruta de acceso de la aplicación con errores: C:\Program Files (x86)\Origin\OriginWebHelperService.exe
Ruta de acceso del módulo con errores: C:\Program Files (x86)\Origin\OriginWebHelperService.exe
Identificador del informe: 7b0c22fc-1692-41ff-ae32-380c4d0d9cd9
Nombre completo del paquete con errores: 
Identificador de aplicación relativa del paquete con errores:


Errores del sistema:
=============
Error: (02/22/2020 11:26:56 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: El servicio Optimización de entrega no respondió después de iniciar.

Error: (02/22/2020 11:25:01 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: La configuración de permisos específico de la aplicación no concede el permiso Iniciar Local para la aplicación de servidor COM con CLSID 
Windows.SecurityCenter.SecurityAppBroker
 y APPID 
No disponible
 al usuario NT AUTHORITY\SYSTEM con SID (S-1-5-18) en la dirección LocalHost (con LRPC) que se ejecuta en el contenedor de aplicaciones con SID No disponible (No disponible). Este permiso de seguridad se puede modificar mediante la herramienta administrativa Servicios de componentes.

Error: (02/22/2020 11:25:01 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: La configuración de permisos específico de la aplicación no concede el permiso Iniciar Local para la aplicación de servidor COM con CLSID 
Windows.SecurityCenter.WscBrokerManager
 y APPID 
No disponible
 al usuario NT AUTHORITY\SYSTEM con SID (S-1-5-18) en la dirección LocalHost (con LRPC) que se ejecuta en el contenedor de aplicaciones con SID No disponible (No disponible). Este permiso de seguridad se puede modificar mediante la herramienta administrativa Servicios de componentes.

Error: (02/22/2020 11:24:51 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: El servicio CleanMyPC Watcher no pudo iniciarse debido al siguiente error: 
El servicio no respondió a tiempo a la solicitud de inicio o de control.

Error: (02/22/2020 11:24:51 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Se agotó el tiempo de espera (30000 ms) para la conexión con el servicio CleanMyPCService.

Error: (02/22/2020 11:22:18 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: El servicio Origin Web Helper Service no pudo iniciarse debido al siguiente error: 
El servicio no respondió a tiempo a la solicitud de inicio o de control.

Error: (02/22/2020 11:22:18 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Se agotó el tiempo de espera (30000 ms) para la conexión con el servicio Origin Web Helper Service.

Error: (02/22/2020 11:20:12 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: El módulo de extensibilidad de WLAN se detuvo inesperadamente.

Ruta de acceso del módulo: C:\windows\system32\Rtlihvs.dll


Windows Defender:
===================================
Date: 2020-02-22 23:37:17.901
Description: 
Antivirus de Windows Defender encontró un error al intentar actualizar las firmas.
Nueva versión de firma: 
Versión de firma anterior: 0.0.0.0
Origen de actualización: Centro de protección contra malware de Microsoft
Tipo de firma: AntiVirus
Tipo de actualización: Completa
Usuario: NT AUTHORITY\Servicio de red
Versión de motor actual: 
Versión de motor anterior: 0.0.0.0
Código de error: 0x80072ee7
Descripción del error: No se pudo resolver el nombre de servidor o su dirección 

Date: 2020-02-22 23:37:17.900
Description: 
Antivirus de Windows Defender encontró un error al intentar actualizar las firmas.
Nueva versión de firma: 
Versión de firma anterior: 0.0.0.0
Origen de actualización: Centro de protección contra malware de Microsoft
Tipo de firma: AntiSpyware
Tipo de actualización: Completa
Usuario: NT AUTHORITY\Servicio de red
Versión de motor actual: 
Versión de motor anterior: 0.0.0.0
Código de error: 0x80072ee7
Descripción del error: No se pudo resolver el nombre de servidor o su dirección 

Date: 2020-02-22 23:37:17.900
Description: 
Antivirus de Windows Defender encontró un error al intentar actualizar las firmas.
Nueva versión de firma: 
Versión de firma anterior: 0.0.0.0
Origen de actualización: Centro de protección contra malware de Microsoft
Tipo de firma: AntiVirus
Tipo de actualización: Completa
Usuario: NT AUTHORITY\Servicio de red
Versión de motor actual: 
Versión de motor anterior: 0.0.0.0
Código de error: 0x80072ee7
Descripción del error: No se pudo resolver el nombre de servidor o su dirección 

Date: 2020-02-22 23:37:17.886
Description: 
Antivirus de Windows Defender encontró un error al intentar actualizar las firmas.
Nueva versión de firma: 
Versión de firma anterior: 0.0.0.0
Origen de actualización: Centro de protección contra malware de Microsoft
Tipo de firma: AntiVirus
Tipo de actualización: Completa
Usuario: NT AUTHORITY\Servicio de red
Versión de motor actual: 
Versión de motor anterior: 0.0.0.0
Código de error: 0x80072ee7
Descripción del error: No se pudo resolver el nombre de servidor o su dirección 

Date: 2020-02-22 23:37:17.885
Description: 
Antivirus de Windows Defender encontró un error al intentar actualizar las firmas.
Nueva versión de firma: 
Versión de firma anterior: 0.0.0.0
Origen de actualización: Centro de protección contra malware de Microsoft
Tipo de firma: AntiSpyware
Tipo de actualización: Completa
Usuario: NT AUTHORITY\Servicio de red
Versión de motor actual: 
Versión de motor anterior: 0.0.0.0
Código de error: 0x80072ee7
Descripción del error: No se pudo resolver el nombre de servidor o su dirección 

CodeIntegrity:
===================================

Date: 2020-02-22 23:23:27.631
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\spoolsv.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\AdobePDF.dll that did not meet the Unchecked signing level requirements.

Date: 2020-02-22 23:14:53.242
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\spoolsv.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\AdobePDF.dll that did not meet the Unchecked signing level requirements.

Date: 2020-02-22 20:23:38.045
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\spoolsv.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\AdobePDF.dll that did not meet the Unchecked signing level requirements.

Date: 2020-02-22 19:45:37.119
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\spoolsv.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\AdobePDF.dll that did not meet the Unchecked signing level requirements.

Date: 2020-02-22 09:39:56.985
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\spoolsv.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\AdobePDF.dll that did not meet the Unchecked signing level requirements.

Date: 2020-02-17 15:08:44.770
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\spoolsv.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\AdobePDF.dll that did not meet the Unchecked signing level requirements.

Date: 2020-02-15 09:03:17.630
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\spoolsv.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\AdobePDF.dll that did not meet the Unchecked signing level requirements.

Date: 2020-02-13 15:09:45.389
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\spoolsv.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\AdobePDF.dll that did not meet the Unchecked signing level requirements.

==================== Información de la memoria =========================== 

BIOS: Insyde F.10 05/31/2018
Placa base: HP 84AE
Procesador: AMD Ryzen 5 2500U with Radeon Vega Mobile Gfx 
Porcentaje de memoria en uso: 36%
RAM física total: 7843.27 MB
RAM física disponible: 4981.04 MB
Virtual total: 15267.27 MB
Virtual disponible: 11807.54 MB

==================== Unidades ================================

Drive c: (Windows) (Fixed) (Total:930.28 GB) (Free:768.21 GB) NTFS

\\?\Volume{c2c8dcd7-b28f-44c0-8941-ef334d67d164}\ (Windows RE tools) (Fixed) (Total:0.96 GB) (Free:0.57 GB) NTFS
\\?\Volume{f58a28f5-7243-424d-a132-219151029580}\ (SYSTEM) (Fixed) (Total:0.25 GB) (Free:0.19 GB) FAT32

==================== MBR & Tabla de particiones ====================

==========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: AF44C3DB)

Partition: GPT.

==================== Final de Addition.txt =======================

Mi pc va bien le pase el malwarebytes un par de veces, tengo un uso del disco muy bajo y de la cpu y gpu igual. No noto nada raro desde que use el malwarebytes

Bien… y ahora sigue estos pasos, :arrow_forward: MUY Importante :arrow_backward: Realiza una copia de seguridad del registro :

  • Para hacerlo descarga :arrow_forward: DelFix.exe(en tu escritorio).

  • Doble clic para ejecutarlo.(Si usas Windows Vista/7/8 o 10 presiona clic derecho y selecciona -Ejecutar como Administrador-).

  • Atención, ahora marca/selecciona únicamente la casilla :white_check_mark: Create registry backup, las demás casillas NO. :face_with_monocle:

  • Pulsar en Run.

Se abrirá el informe (DelFix.txt), guárdalo por si fuera necesario y cierra la herramienta.

:warning: Con los demás programas cerrados ve a :arrow_forward: Inicio :arrow_forward: Ejecutar :arrow_forward: y escribe Notepad.exe.

  • Ahora debes copiar y pegar los códigos/líneas que están en el interior del recuadro de más abajo, dentro del Notepad.
START
CREATERESTOREPOINT:
CLOSEPROCESSES:
AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [476]
AlternateDataStreams: C:\Users\Usuario\ntuser.ini:NTV [12190]
AlternateDataStreams: C:\Users\Usuario\AppData\Local\Temp:com.affinity.designer.1 [240]
AlternateDataStreams: C:\Users\Usuario\AppData\Local\Temp:com.affinity.photo.1 [240]
AlternateDataStreams: C:\Users\Usuario\AppData\Local\Temp:com.affinity.publisher.1 [240]
HKLM-x32\...\Run: [] => [X]
Startup: C:\Users\Usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DqhgXm.lnk [2020-02-22]
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\kl_prefs_62fbb8f7_c917_4cf7_957a_aad2b8fa768c.js [2020-01-10] <==== ATENCIÓN (Apunta a archivo *.cfg)
FF ExtraCheck: C:\Program Files\mozilla firefox\kl_config_62fbb8f7_c917_4cf7_957a_aad2b8fa768c.cfg [2020-01-10] <==== ATENCIÓN
CHR HKLM\...\Chrome\Extension: [elhpdacimkjpccooodognopfhbdgnpbk] - hxxps://chrome.google.com/webstore/detail/elhpdacimkjpccooodognopfhbdgnpbk
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [elhpdacimkjpccooodognopfhbdgnpbk] - hxxps://chrome.google.com/webstore/detail/elhpdacimkjpccooodognopfhbdgnpbk
S3 H2OFFT; \SystemRoot\System32\drivers\H2OFFT64.sys [X]
HOSTS:
REMOVEPROXY:
EMPTYTEMP:
CMD: netsh winsock reset
CMD: ipconfig /renew
CMD: ipconfig /flushdns
CMD: bitsadmin /reset /allusers
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
END

Guárdalo bajo el nombre de FIXLIST.TXT en el escritorio :arrow_backward: Esto es muy importante.

:o: Nota :o: Es importante que la herramienta FRST.exe(Farbar Recovery Scanner Tool) y FIXLIST.TXT se encuentren en la misma ubicación (escritorio) o si no, no trabajara.

Y ahora usa el 2º MÉTODO: de esta Faq de Windows 8(aplicable a Windows 10) :arrow_forward: ¿Cómo iniciar Windows 8/8.1 en Modo Seguro?, para trabajar desde ese modo de windows.

  • Ejecuta FRST.exe.(Si usas Windows Vista/7/8 o 10, presiona clic derecho y seleccionas -Ejecutar como Administrador-).

  • Presionar el botón FIX/Corregir y aguardar a que termine.

  • La Herramienta guardara el reporte de reparación en el escritorio (FIXLOG.TXT).

Pegar el contenido de este fichero en tu próxima respuesta. :+1:

Reiniciar el equipo y comprobar su funcionamiento en relación al problema planteado y comentarlo.

Saludos.

Gracias por responder te lo dejo aquí, mi PC todo esta bajo menos el disco que va al 80-100%. Aunque noto que va fluido y sin problemas Edito: Ha bajado el disco y ahora consume muy bajos recursos, supongo que sería del inicio.

Resultados de la corrección de Farbar Recovery Scan Tool (x64) Versión: 16-02-2020
Ejecutado por Usuario (23-02-2020 11:00:02) Run:1
Ejecutado desde C:\Users\Usuario\Desktop
Perfiles cargados: Usuario (Perfiles disponibles: Usuario)
Modo de Inicio: Normal
==============================================

fixlist contenido:
*****************
START
CREATERESTOREPOINT:
CLOSEPROCESSES:
AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [476]
AlternateDataStreams: C:\Users\Usuario\ntuser.ini:NTV [12190]
AlternateDataStreams: C:\Users\Usuario\AppData\Local\Temp:com.affinity.designer.1 [240]
AlternateDataStreams: C:\Users\Usuario\AppData\Local\Temp:com.affinity.photo.1 [240]
AlternateDataStreams: C:\Users\Usuario\AppData\Local\Temp:com.affinity.publisher.1 [240]
HKLM-x32\...\Run: [] => [X]
Startup: C:\Users\Usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DqhgXm.lnk [2020-02-22]
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\kl_prefs_62fbb8f7_c917_4cf7_957a_aad2b8fa768c.js [2020-01-10] <==== ATENCI�N (Apunta a archivo *.cfg)
FF ExtraCheck: C:\Program Files\mozilla firefox\kl_config_62fbb8f7_c917_4cf7_957a_aad2b8fa768c.cfg [2020-01-10] <==== ATENCI�N
CHR HKLM\...\Chrome\Extension: [elhpdacimkjpccooodognopfhbdgnpbk] - hxxps://chrome.google.com/webstore/detail/elhpdacimkjpccooodognopfhbdgnpbk
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [elhpdacimkjpccooodognopfhbdgnpbk] - hxxps://chrome.google.com/webstore/detail/elhpdacimkjpccooodognopfhbdgnpbk
S3 H2OFFT; \SystemRoot\System32\drivers\H2OFFT64.sys [X]
HOSTS:
REMOVEPROXY:
EMPTYTEMP:
CMD: netsh winsock reset
CMD: ipconfig /renew
CMD: ipconfig /flushdns
CMD: bitsadmin /reset /allusers
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
END
*****************

El punto de restauración fue creado correctamente.
Procesos cerrados correctamente.
C:\Users\Public\Shared Files => ":VersionCache" ADS eliminado correctamente
C:\Users\Usuario\ntuser.ini => ":NTV" ADS eliminado correctamente
C:\Users\Usuario\AppData\Local\Temp => ":com.affinity.designer.1" ADS eliminado correctamente
C:\Users\Usuario\AppData\Local\Temp => ":com.affinity.photo.1" ADS eliminado correctamente
C:\Users\Usuario\AppData\Local\Temp => ":com.affinity.publisher.1" ADS eliminado correctamente
"HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\" => eliminado correctamente
C:\Users\Usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DqhgXm.lnk => movido correctamente
C:\Program Files\mozilla firefox\defaults\pref\kl_prefs_62fbb8f7_c917_4cf7_957a_aad2b8fa768c.js => movido correctamente
C:\Program Files\mozilla firefox\kl_config_62fbb8f7_c917_4cf7_957a_aad2b8fa768c.cfg => movido correctamente
HKLM\SOFTWARE\Google\Chrome\Extensions\elhpdacimkjpccooodognopfhbdgnpbk => eliminado correctamente
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\efaidnbmnnnibpcajpcglclefindmkaj => eliminado correctamente
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\elhpdacimkjpccooodognopfhbdgnpbk => eliminado correctamente
HKLM\System\CurrentControlSet\Services\H2OFFT => eliminado correctamente
H2OFFT => servicio eliminado correctamente
C:\Windows\System32\Drivers\etc\hosts => movido correctamente
Hosts restaurado correctamente.

========= RemoveProxy: =========

"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => eliminado correctamente
"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => eliminado correctamente
"HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => eliminado correctamente
"HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => eliminado correctamente
"HKU\S-1-5-21-1019904135-823791453-1890871877-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => eliminado correctamente
"HKU\S-1-5-21-1019904135-823791453-1890871877-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => eliminado correctamente


========= Final de RemoveProxy: =========


========= netsh winsock reset =========


El cat logo Winsock se restableci¢ correctamente.
Debe reiniciar el equipo para completar el restablecimiento.


========= Final de CMD: =========


========= ipconfig /renew =========


Configuraci¢n IP de Windows

No se puede realizar ninguna operaci¢n en Ethernet mientras los medios
est‚n desconectados.
No se puede realizar ninguna operaci¢n en Conexi¢n de  rea local* 1 mientras los medios
est‚n desconectados.
No se puede realizar ninguna operaci¢n en Conexi¢n de  rea local* 2 mientras los medios
est‚n desconectados.
No se puede realizar ninguna operaci¢n en Ethernet 2 mientras los medios
est‚n desconectados.
No se puede realizar ninguna operaci¢n en Wi-Fi mientras los medios
est‚n desconectados.

========= Final de CMD: =========


========= ipconfig /flushdns =========


Configuraci¢n IP de Windows

Se vaci¢ correctamente la cach‚ de resoluci¢n de DNS.

========= Final de CMD: =========


========= bitsadmin /reset /allusers =========


BITSADMIN version 3.0
BITS administration utility.
(C) Copyright Microsoft Corp.

{7A2B008A-13E1-4F9F-B4C1-776940315593} canceled.
1 out of 1 jobs canceled.

========= Final de CMD: =========


========= netsh advfirewall reset =========

Aceptar


========= Final de CMD: =========


========= netsh advfirewall set allprofiles state ON =========

Aceptar


========= Final de CMD: =========


========= netsh int ipv4 reset =========

Reenv¡o de compartimiento se restableci¢ correctamente.
Compartimiento se restableci¢ correctamente.
Protocolo de control se restableci¢ correctamente.
Solicitud de secuencia eco se restableci¢ correctamente.
Global se restableci¢ correctamente.
Interfaz se restableci¢ correctamente.
Direcci¢n de difusi¢n por proximidad (a se restableci¢ correctamente.
Direcciones de multidifusi¢n se restableci¢ correctamente.
Direcci¢n de unidifusi¢n se restableci¢ correctamente.
Vecino se restableci¢ correctamente.
Ruta de acceso se restableci¢ correctamente.
Posible se restableci¢ correctamente.
Directiva de prefijo se restableci¢ correctamente.
Vecino de proxy se restableci¢ correctamente.
Ruta se restableci¢ correctamente.
Prefijo de sitio se restableci¢ correctamente.
Subinterfaz se restableci¢ correctamente.
Patr¢n de reactivaci¢n se restableci¢ correctamente.
Resolver vecino se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
Error al restablecer .
Acceso denegado.

 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
Reinicie el equipo para completar esta acci¢n.


========= Final de CMD: =========


========= netsh int ipv6 reset =========

Reenv¡o de compartimiento se restableci¢ correctamente.
Compartimiento se restableci¢ correctamente.
Protocolo de control se restableci¢ correctamente.
Solicitud de secuencia eco se restableci¢ correctamente.
Global se restableci¢ correctamente.
Interfaz se restableci¢ correctamente.
Direcci¢n de difusi¢n por proximidad (a se restableci¢ correctamente.
Direcciones de multidifusi¢n se restableci¢ correctamente.
Direcci¢n de unidifusi¢n se restableci¢ correctamente.
Vecino se restableci¢ correctamente.
Ruta de acceso se restableci¢ correctamente.
Posible se restableci¢ correctamente.
Directiva de prefijo se restableci¢ correctamente.
Vecino de proxy se restableci¢ correctamente.
Ruta se restableci¢ correctamente.
Prefijo de sitio se restableci¢ correctamente.
Subinterfaz se restableci¢ correctamente.
Patr¢n de reactivaci¢n se restableci¢ correctamente.
Resolver vecino se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
Error al restablecer .
Acceso denegado.

 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
Reinicie el equipo para completar esta acci¢n.


========= Final de CMD: =========


=========== EmptyTemp: ==========

BITS transfer queue => 11558912 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 225377472 B
Java, Flash, Steam htmlcache => 48579376 B
Windows/system/drivers => 5843397 B
Edge => 224508 B
Chrome => 6579197 B
Firefox => 8249082 B
Opera => 147456 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 306864 B
systemprofile32 => 306864 B
LocalService => 308626 B
NetworkService => 315442 B
Usuario => 21169892 B

RecycleBin => 0 B
EmptyTemp: => 313.7 MB datos temporales eliminados.

================================


El sistema necesita reiniciarse.

==== Final de Fixlog 11:02:08 ====

Hola.

Efectivamente… cuando se inicia el equipo puedes tener “picos” de consumo alto tanto en disco como en memoria o procesador y lo normal es que bajen al poco rato( a veces se mantienen algunos minutos) de encender el equipo.

También es normal que después de haber realizado los pasos con el FIX o con cualquiera de las otras herramientas que has usado y después de realizar un REINICIO el consumo del equipo sea mayor de lo habitual, ya que todavía se están realizando acciones por parte de las herramientas usadas.

Ahora APAGA totalmente tu equipo y vuelves a encenderlo, hazlo TRES veces seguidas y compruebas el funcionamiento del mismo.

Nos comenta resultados para darte los últimos pasos a realizar.

Saludos.

Ya lo hice varias veces y por ahora todo va bien, fluido como siempre. El disco al iniciar ha estado al 100% y luego ha bajado al mínimo.

Perfecto @ImSurface :+1: excelente, nos alegra ver que ya está el problema inicial completamente arreglado, ahora solo queda eliminar las herramientas usadas.

Para hacerlo descarga :arrow_forward: DelFix.exe en tu escritorio.

  • Doble clic para ejecutarlo. (Si usas Windows Vista/7/8 o 10 presiona clic derecho y selecciona - Ejecutar como Administrador -).

  • Marca todas las casillas, y pulsas en Run

Se abrirá el informe (DelFix.txt), puedes cerrarlo.


Para cualquier otro problema, no dudes en volver a postear., ya sabes dónde estamos. :+1:

Tema Solucionado.

Saludos, Javier.

1 me gusta