Arranque elegir SO diferente, Avast

SystemLook 30.07.11 by jpshortstuff Log created at 07:00 on 20/04/2019 by Pequeñito Administrator - Elevation successful

========== filefind ==========

Searching for " Avast" No files found.

Searching for " " No files found.

========== regfind ==========

Searching for " Avast " pues eso es lo que sale, salidos

Hola

Sigue saliendo mal el reporte, así que lo he probado y copiandolo de la plantilla que te puse, se desajustan los parámetros, vas a escribirlo manualmente como está en la imagen.

Recuerda que tiene que estar el programa en el escritorio y tienes que ejecutarlo como administrador.

Captura%20de%20pantalla%20(59)

Trae el reporte.

Un saludo

Bueno parece que ya está, sería ese el problema.

SystemLook 30.07.11 by jpshortstuff
Log created at 18:35 on 20/04/2019 by Pequeñito
Administrator - Elevation successful

========== filefind ==========

Searching for "*Avast*"
C:\Program Files\LibreOffice\share\config\soffice.cfg\cui\ui\javastartparametersdialog.ui	--a---- 13451 bytes	[12:14 14/02/2019]	[12:14 14/02/2019] C99C3CF5A563338757A91B83EF9371F0
C:\Windows\Prefetch\AVASTBROWSERUNINSTALL.EXE_{FF-96B14E74.pf	--a---- 15142 bytes	[13:31 10/04/2019]	[13:31 10/04/2019] 764DD36EC637C64745971A784C2D5740
C:\Windows\Prefetch\AVASTTEMPINSTALLER_431915.EXE-7312F428.pf	--a---- 10831 bytes	[11:59 10/04/2019]	[11:59 10/04/2019] 7D3B33FB4C27C8E5309D3F12C80706D7
C:\Windows\Prefetch\AVAST_FREE_ANTIVIRUS_SETUP_ON-12036D95.pf	--a---- 12484 bytes	[11:14 10/04/2019]	[11:14 10/04/2019] F9B3958D5C915670DAB260FBEA8CC9DB
C:\Windows\Prefetch\AVAST_FREE_ANTIVIRUS_SETUP_ON-85DD10DA.pf	--a---- 27177 bytes	[11:14 10/04/2019]	[11:14 10/04/2019] BA39488DFA935EC138559B0C81BDBB33
C:\Windows\WinSxS\Manifests\amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_5ca6eb17137337f1.cat	--a---- 7456 bytes	[11:19 10/04/2019]	[11:19 10/04/2019] 22838361C44B34190435D79779E6A3A2
C:\Windows\WinSxS\Manifests\amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_5ca6eb17137337f1.manifest	------- 23612 bytes	[11:19 10/04/2019]	[11:19 10/04/2019] 024B03BE0701BBECBAD5621871107B9D
C:\Windows\WinSxS\Manifests\amd64_avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_6186ed0910476724.cat	--a---- 7456 bytes	[11:19 10/04/2019]	[11:19 10/04/2019] F62103490F4653E8E16D5A5E876E4A4C
C:\Windows\WinSxS\Manifests\amd64_avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_6186ed0910476724.manifest	------- 1231 bytes	[11:19 10/04/2019]	[11:19 10/04/2019] A70B55CE1170E9FECA60AF4E7A50327D
C:\Windows\WinSxS\Manifests\amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_4f95660acc611f2b.cat	--a---- 7456 bytes	[11:19 10/04/2019]	[11:19 10/04/2019] A1F45C3D0AFBCE2D76739B1478EB3A1C
C:\Windows\WinSxS\Manifests\amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_4f95660acc611f2b.manifest	------- 754 bytes	[11:19 10/04/2019]	[11:19 10/04/2019] BCC22FD7364713AF7FA8694E27D16F76
C:\Windows\WinSxS\Manifests\amd64_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_547567fcc9354e5e.cat	--a---- 7456 bytes	[11:20 10/04/2019]	[11:20 10/04/2019] F0780318E425DF6735528C87AF3D05E4
C:\Windows\WinSxS\Manifests\amd64_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_547567fcc9354e5e.manifest	------- 754 bytes	[11:20 10/04/2019]	[11:20 10/04/2019] E54700FC172E9364732F2318CB446BA3
C:\Windows\WinSxS\Manifests\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_a45421ee27ef60f7.cat	--a---- 7456 bytes	[11:19 10/04/2019]	[11:19 10/04/2019] C94F0E43B54FB342260F7841D482078D
C:\Windows\WinSxS\Manifests\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_a45421ee27ef60f7.manifest	------- 23610 bytes	[11:19 10/04/2019]	[11:19 10/04/2019] 4E85A9DD42F8019C0B22DB7584F4D376
C:\Windows\WinSxS\Manifests\x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_a93423e024c3902a.cat	--a---- 7456 bytes	[11:19 10/04/2019]	[11:19 10/04/2019] 7D8C282F03A573FAD6514A7988DD3FA1
C:\Windows\WinSxS\Manifests\x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_a93423e024c3902a.manifest	------- 1227 bytes	[11:19 10/04/2019]	[11:19 10/04/2019] 7EC9D3464746919457C60C42CCCE1E84
C:\Windows\WinSxS\Manifests\x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_97429ce1e0dd4831.cat	--a---- 7456 bytes	[11:19 10/04/2019]	[11:19 10/04/2019] FCFB0E251D26D4952442A1F096F14AFF
C:\Windows\WinSxS\Manifests\x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_97429ce1e0dd4831.manifest	------- 750 bytes	[11:19 10/04/2019]	[11:19 10/04/2019] 4E1FFBD4E5D8F29AD8E97D6568C20E35
C:\Windows\WinSxS\Manifests\x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_9c229ed3ddb17764.cat	--a---- 7456 bytes	[11:19 10/04/2019]	[11:19 10/04/2019] 5860B84542909D31019104CC7F4F63A7
C:\Windows\WinSxS\Manifests\x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_9c229ed3ddb17764.manifest	------- 750 bytes	[11:19 10/04/2019]	[11:19 10/04/2019] C208B77639E029D91E336BD22A0790CE

========== regfind ==========

Searching for "Avast"
[HKEY_CURRENT_USER\Software\Avast Software]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\4ab51afc_0]
@="{2}.\\?\hdaudio#func_01&ven_10ec&dev_0269&subsys_144dc0a8&rev_1001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\singlelineouttopo/00010001|\Device\HarddiskVolume3\Program Files\AVAST Software\Avast\AvastUI.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_CURRENT_USER\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\SafeZone 3.55.2393.609\Avast Pro Antivirus(1)]
[HKEY_CURRENT_USER\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\SafeZone 3.55.2393.609\Avast Pro Antivirus(1)]
"UninstallString"=""C:\Program Files\AVAST Software\SZBrowser\Launcher.exe" /uninstall"
[HKEY_LOCAL_MACHINE\BCD00000000\Objects\{43547433-5ba9-11e9-b8c2-90a4de9ee626}\Elements\12000004]
"Element"="Avast Antivirus Clear Uninstall"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_avast.vc140.crt_fcc99ee6193ebbca_none_020285fe6d6e0580]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_avast.vc140.mfc_fcc99ee6193ebbca_none_018be6966dc83925]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_none_ef17e13d91c55d96]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_none_eea141d5921f913b]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_avast.vc140.crt_fcc99ee6193ebbca_none_49afbcd581ea2e86]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_avast.vc140.mfc_fcc99ee6193ebbca_none_49391d6d8244622b]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_none_36c51814a641869c]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_none_364e78aca69bba41]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvastBrowserUpdate.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Avast Software]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsSelfHost\OneSettings]
"TargetingAttributes"="{
  "Version": 62,
  "SchemaVersion": 1,
  "PartA": [
    "App",
    "AppVer",
    "AttrDataVer"
  ],
  "Default": [
    "DeviceFamily",
    "f:FlightRing",
    "t:OSVersionFull"
  ],
  "PartB": {
    "CDM": [
      "ChassisTypeId",
      "r:CurrentBranch",
      "DeviceFamily",
      "f:FlightingBranchName",
      "f:FlightRing",
      "c:InstallLanguage",
      "c:IsDomainJoined",
      "t:IsTestLab",
      "OEMModel",
      "OSArchitecture",
      "OSVersion",
      "t:OSSkuId",
      "c:ProcessorIdentifier",
      "c:TelemetryLevel",
      "t:IsMsftOwned",
      "t:WCOSProductId"
    ],
    "CORTANA_GATEKEEPER": [
      "r:CurrentBranch",
      "f:FlightRing",
      "f:IsRetailOS"
    ],
    "CORTANAUWP": [
      "c:OSUILocale",
      "t:OSVersionFull",
      "v:CortanaAppVer"
    ],
    "CORTANAUWPTEST": [
      "+CORTANAUWP",
      "v:CortanaAppVerTest"
    ],
    "CTAC": [
      "+FSS"
    ],
    "DDC": [
      
[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\AVAST Software]
[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvastBrowserUpdate.exe]
[HKEY_USERS\.DEFAULT\Software\AVAST Software]
[HKEY_USERS\S-1-5-21-4285004602-114342504-2893149386-1001\Software\Avast Software]
[HKEY_USERS\S-1-5-21-4285004602-114342504-2893149386-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\4ab51afc_0]
@="{2}.\\?\hdaudio#func_01&ven_10ec&dev_0269&subsys_144dc0a8&rev_1001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\singlelineouttopo/00010001|\Device\HarddiskVolume3\Program Files\AVAST Software\Avast\AvastUI.exe%b{00000000-0000-0000-0000-000000000000}"
[HKEY_USERS\S-1-5-21-4285004602-114342504-2893149386-1001\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\SafeZone 3.55.2393.609\Avast Pro Antivirus(1)]
[HKEY_USERS\S-1-5-21-4285004602-114342504-2893149386-1001\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\SafeZone 3.55.2393.609\Avast Pro Antivirus(1)]
"UninstallString"=""C:\Program Files\AVAST Software\SZBrowser\Launcher.exe" /uninstall"
[HKEY_USERS\S-1-5-18\Software\AVAST Software]

-= EOF =-

buenas… y ahora…¿.

Hola

:arrow_forward: MUY Importante :arrow_backward: Realiza una copia de seguridad del registro :

  • Para hacerlo descarga :arrow_forward: DelFix.exe( en tu escritorio).

  • Doble clic para ejecutarlo.(Si usas Windows Vista/7/8 o 10 presiona clic derecho y selecciona -Ejecutar como Administrador-).

  • Atención, ahora marca/selecciona únicamente la casilla "Create registry backup", las demás NO.

  • Pulsar en Run.

Se abrirá el informe (DelFix.txt), guárdalo por si fuera necesario y cierra la herramienta.

A continuación inicia tu equipo desde el Modo Seguro de Windows sin función de red

:warning: Con los demás programas cerrados ve a :arrow_forward: Inicio :arrow_forward: Ejecutar :arrow_forward: y escribe Notepad.exe.

  • Ahora debes copiar y pegar los códigos/líneas que están en el interior del recuadro de más abajo, dentro del Notepad.
START
CREATERESTOREPOINT:
CLOSEPROCESSES:
C:\Windows\Prefetch\AVASTBROWSERUNINSTALL.EXE_{FF-96B14E74.pf
C:\Windows\Prefetch\AVASTTEMPINSTALLER_431915.EXE-7312F428.pf
C:\Windows\Prefetch\AVAST_FREE_ANTIVIRUS_SETUP_ON-12036D95.pf
C:\Windows\Prefetch\AVAST_FREE_ANTIVIRUS_SETUP_ON-85DD10DA.pf
C:\Windows\WinSxS\Manifests\amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_5ca6eb17137337f1.cat
C:\Windows\WinSxS\Manifests\amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_5ca6eb17137337f1.manifest
C:\Windows\WinSxS\Manifests\amd64_avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_6186ed0910476724.cat
C:\Windows\WinSxS\Manifests\amd64_avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_6186ed0910476724.manifest
C:\Windows\WinSxS\Manifests\amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_4f95660acc611f2b.cat
C:\Windows\WinSxS\Manifests\amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_4f95660acc611f2b.manifest
C:\Windows\WinSxS\Manifests\amd64_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_547567fcc9354e5e.cat
C:\Windows\WinSxS\Manifests\amd64_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_547567fcc9354e5e.manifest
C:\Windows\WinSxS\Manifests\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_a45421ee27ef60f7.cat
C:\Windows\WinSxS\Manifests\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_a45421ee27ef60f7.manifest
C:\Windows\WinSxS\Manifests\x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_a93423e024c3902a.cat
C:\Windows\WinSxS\Manifests\x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_a93423e024c3902a.manifest
C:\Windows\WinSxS\Manifests\x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_97429ce1e0dd4831.cat
C:\Windows\WinSxS\Manifests\x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_97429ce1e0dd4831.manifest
C:\Windows\WinSxS\Manifests\x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_9c229ed3ddb17764.cat
C:\Windows\WinSxS\Manifests\x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_9c229ed3ddb17764.manifest
DeleteKey: [HKEY_CURRENT_USER\Software\Avast Software]
DeleteKey: [HKEY_CURRENT_USER\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\SafeZone 3.55.2393.609\Avast Pro Antivirus(1)]
DeleteKey: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_avast.vc140.crt_fcc99ee6193ebbca_none_020285fe6d6e0580]
DeleteKey: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_avast.vc140.mfc_fcc99ee6193ebbca_none_018be6966dc83925]
DeleteKey: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_none_ef17e13d91c55d96]
DeleteKey: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_none_eea141d5921f913b]
DeleteKey: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_avast.vc140.crt_fcc99ee6193ebbca_none_49afbcd581ea2e86]
DeleteKey: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_avast.vc140.mfc_fcc99ee6193ebbca_none_49391d6d8244622b]
DeleteKey: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_none_36c51814a641869c]
DeleteKey: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_none_364e78aca69bba41]
DeleteKey: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvastBrowserUpdate.exe]
DeleteKey: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Avast Software]
DeleteKey: [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\AVAST Software]
DeleteKey: [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvastBrowserUpdate.exe]
DeleteKey: [HKEY_USERS\.DEFAULT\Software\AVAST Software]
DeleteKey: [HKEY_USERS\S-1-5-21-4285004602-114342504-2893149386-1001\Software\Avast Software]
DeleteKey: [HKEY_USERS\S-1-5-18\Software\AVAST Software]
DeleteKey: [HKEY_USERS\S-1-5-21-4285004602-114342504-2893149386-1001\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\SafeZone 3.55.2393.609\Avast Pro Antivirus(1)]
DeleteValue: [HKEY_USERS\S-1-5-21-4285004602-114342504-2893149386-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\4ab51afc_0]|@
DeleteValue: [HKEY_USERS\S-1-5-21-4285004602-114342504-2893149386-1001\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\SafeZone 3.55.2393.609\Avast Pro Antivirus(1)]|UninstallString
DeleteValue: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\4ab51afc_0]|@
DeleteValue: [HKEY_CURRENT_USER\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\SafeZone 3.55.2393.609\Avast Pro Antivirus(1)]|UninstallString
DeleteValue: [HKEY_LOCAL_MACHINE\BCD00000000\Objects\{43547433-5ba9-11e9-b8c2-90a4de9ee626}\Elements\12000004]|Element
DeleteValue: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsSelfHost\OneSettings]|TargetingAttributes

HOSTS:
REMOVEPROXY:
EMPTYTEMP:
CMD: netsh winsock reset
CMD: ipconfig /renew
CMD: ipconfig /flushdns
CMD: bitsadmin /reset /allusers
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
END

Guárdalo bajo el nombre de FIXLIST.TXT en el escritorio :arrow_backward: Esto es muy importante.

:o: Nota :o: Es importante que la herramienta FRST.exe (Farbar Recovery Scanner Tool) y FIXLIST.TXT se encuentren en la misma ubicación (escritorio) o si no, no trabajara.


  • Ejecuta FRST.exe.(Si usas Windows Vista/7/8 o 10, presiona clic derecho y seleccionas -Ejecutar como Administrador-).
  • Presionar el botón FIX y aguardar a que termine.
  • La Herramienta guardara el reporte de reparación en el escritorio (FIXLOG.TXT).

Pega el contenido de este fichero en tu próxima respuesta.

Reiniciar el equipo y comprobar su funcionamiento en relación al problema planteado y comentarlo.

Un saludo

Hola, he hecho todos y cada uno de los pasos, al terminar para reiniciar en modo normal … zass otra vez sale eso…, cuando a reiniciado solo cuando lo pedia después de usar farbar a reiniciado bien como quería. Pero al volver a modo normal otra vez a salido. Por otro lado , tengo que entrar en msconfig desde administrador de tareas por que desde botón de buscar de windows donde pone Escribe aquí para buscar. Escribo y no aparece nada. Además por otro. Tengo sólo 2GB de ram , se o supongo q será así pero me fastidia bastante la verdad. Sólo usar el escritorio tengo entre .0.9 a 1gb usado. Si abro chrome 1.3, si hago algo más como abrir la tv… empieza a temblar la cosa. Ah, corrijo de 1.3 a 1.4 con chrome . 70% de ram usado. En fin, mi pregunta es por que si windows usa 1gb no me deja ni hacer búsquedas con el mismo buscador o se ralentiza tanto al pulsar el botón inicio o el que seria cortana q lo uso de buscardor. Hay alguna manera de aliviar un poco el consumo de ram… por lo que veo desde el administrador de tareas es que consume mucha energía y creo que tengo que cargar la batería más veces de lo normal… gracias, un saludo.

Hola

Tienes muy poca RAM, es normal que vaya lento y te consuma prácticamente toda, además de tener instalado Windows 10, deberías ampliar la tarjeta, yo tengo 4 gigas de Ram y ahora mismo, con Chrome abierto y otro programa ya me consume el 76%.

Captura%20de%20pantalla%20(62)

Antes de continuar, por el reporte de FRST que te ha generado.

Un saludo

lo guarda en algún sitio?. no he visto ninguno. Sólo una ventana diciendo que había terminano .

Hola

En el escritorio se guarda el reporte con nombre Fixlog.txt.

Un saludo

cierto disculpa, pensaba que era el que he pegado para el fix, esto es lo que sale

Fix result of Farbar Recovery Scan Tool (x64) Version: 22.04.2019
Ran by Pequeñito (22-04-2019 17:50:09) Run:1
Running from C:\Users\Pequeñito\Desktop
Loaded Profiles: Pequeñito (Available Profiles: Pequeñito)
Boot Mode: Safe Mode (minimal)
==============================================

fixlist content:
*****************
START
CREATERESTOREPOINT:
CLOSEPROCESSES:
C:\Windows\Prefetch\AVASTBROWSERUNINSTALL.EXE_{FF-96B14E74.pf
C:\Windows\Prefetch\AVASTTEMPINSTALLER_431915.EXE-7312F428.pf
C:\Windows\Prefetch\AVAST_FREE_ANTIVIRUS_SETUP_ON-12036D95.pf
C:\Windows\Prefetch\AVAST_FREE_ANTIVIRUS_SETUP_ON-85DD10DA.pf
C:\Windows\WinSxS\Manifests\amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_5ca6eb17137337f1.cat
C:\Windows\WinSxS\Manifests\amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_5ca6eb17137337f1.manifest
C:\Windows\WinSxS\Manifests\amd64_avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_6186ed0910476724.cat
C:\Windows\WinSxS\Manifests\amd64_avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_6186ed0910476724.manifest
C:\Windows\WinSxS\Manifests\amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_4f95660acc611f2b.cat
C:\Windows\WinSxS\Manifests\amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_4f95660acc611f2b.manifest
C:\Windows\WinSxS\Manifests\amd64_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_547567fcc9354e5e.cat
C:\Windows\WinSxS\Manifests\amd64_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_547567fcc9354e5e.manifest
C:\Windows\WinSxS\Manifests\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_a45421ee27ef60f7.cat
C:\Windows\WinSxS\Manifests\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_a45421ee27ef60f7.manifest
C:\Windows\WinSxS\Manifests\x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_a93423e024c3902a.cat
C:\Windows\WinSxS\Manifests\x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_a93423e024c3902a.manifest
C:\Windows\WinSxS\Manifests\x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_97429ce1e0dd4831.cat
C:\Windows\WinSxS\Manifests\x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_97429ce1e0dd4831.manifest
C:\Windows\WinSxS\Manifests\x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_9c229ed3ddb17764.cat
C:\Windows\WinSxS\Manifests\x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_9c229ed3ddb17764.manifest
DeleteKey: [HKEY_CURRENT_USER\Software\Avast Software]
DeleteKey: [HKEY_CURRENT_USER\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\SafeZone 3.55.2393.609\Avast Pro Antivirus(1)]
DeleteKey: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_avast.vc140.crt_fcc99ee6193ebbca_none_020285fe6d6e0580]
DeleteKey: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_avast.vc140.mfc_fcc99ee6193ebbca_none_018be6966dc83925]
DeleteKey: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_none_ef17e13d91c55d96]
DeleteKey: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_none_eea141d5921f913b]
DeleteKey: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_avast.vc140.crt_fcc99ee6193ebbca_none_49afbcd581ea2e86]
DeleteKey: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_avast.vc140.mfc_fcc99ee6193ebbca_none_49391d6d8244622b]
DeleteKey: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_none_36c51814a641869c]
DeleteKey: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_none_364e78aca69bba41]
DeleteKey: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvastBrowserUpdate.exe]
DeleteKey: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Avast Software]
DeleteKey: [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\AVAST Software]
DeleteKey: [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvastBrowserUpdate.exe]
DeleteKey: [HKEY_USERS\.DEFAULT\Software\AVAST Software]
DeleteKey: [HKEY_USERS\S-1-5-21-4285004602-114342504-2893149386-1001\Software\Avast Software]
DeleteKey: [HKEY_USERS\S-1-5-18\Software\AVAST Software]
DeleteKey: [HKEY_USERS\S-1-5-21-4285004602-114342504-2893149386-1001\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\SafeZone 3.55.2393.609\Avast Pro Antivirus(1)]
DeleteValue: [HKEY_USERS\S-1-5-21-4285004602-114342504-2893149386-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\4ab51afc_0]|@
DeleteValue: [HKEY_USERS\S-1-5-21-4285004602-114342504-2893149386-1001\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\SafeZone 3.55.2393.609\Avast Pro Antivirus(1)]|UninstallString
DeleteValue: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\4ab51afc_0]|@
DeleteValue: [HKEY_CURRENT_USER\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\SafeZone 3.55.2393.609\Avast Pro Antivirus(1)]|UninstallString
DeleteValue: [HKEY_LOCAL_MACHINE\BCD00000000\Objects\{43547433-5ba9-11e9-b8c2-90a4de9ee626}\Elements\12000004]|Element
DeleteValue: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsSelfHost\OneSettings]|TargetingAttributes

HOSTS:
REMOVEPROXY:
EMPTYTEMP:
CMD: netsh winsock reset
CMD: ipconfig /renew
CMD: ipconfig /flushdns
CMD: bitsadmin /reset /allusers
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
END
*****************

Error: Restore point can only be created in normal mode.
Processes closed successfully.
C:\Windows\Prefetch\AVASTBROWSERUNINSTALL.EXE_{FF-96B14E74.pf => moved successfully
C:\Windows\Prefetch\AVASTTEMPINSTALLER_431915.EXE-7312F428.pf => moved successfully
C:\Windows\Prefetch\AVAST_FREE_ANTIVIRUS_SETUP_ON-12036D95.pf => moved successfully
C:\Windows\Prefetch\AVAST_FREE_ANTIVIRUS_SETUP_ON-85DD10DA.pf => moved successfully
C:\Windows\WinSxS\Manifests\amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_5ca6eb17137337f1.cat => moved successfully
C:\Windows\WinSxS\Manifests\amd64_avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_5ca6eb17137337f1.manifest => moved successfully
C:\Windows\WinSxS\Manifests\amd64_avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_6186ed0910476724.cat => moved successfully
C:\Windows\WinSxS\Manifests\amd64_avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_6186ed0910476724.manifest => moved successfully
C:\Windows\WinSxS\Manifests\amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_4f95660acc611f2b.cat => moved successfully
C:\Windows\WinSxS\Manifests\amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_4f95660acc611f2b.manifest => moved successfully
C:\Windows\WinSxS\Manifests\amd64_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_547567fcc9354e5e.cat => moved successfully
C:\Windows\WinSxS\Manifests\amd64_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_547567fcc9354e5e.manifest => moved successfully
C:\Windows\WinSxS\Manifests\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_a45421ee27ef60f7.cat => moved successfully
C:\Windows\WinSxS\Manifests\x86_avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_a45421ee27ef60f7.manifest => moved successfully
C:\Windows\WinSxS\Manifests\x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_a93423e024c3902a.cat => moved successfully
C:\Windows\WinSxS\Manifests\x86_avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_a93423e024c3902a.manifest => moved successfully
C:\Windows\WinSxS\Manifests\x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_97429ce1e0dd4831.cat => moved successfully
C:\Windows\WinSxS\Manifests\x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_14.0.27012.0_none_97429ce1e0dd4831.manifest => moved successfully
C:\Windows\WinSxS\Manifests\x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_9c229ed3ddb17764.cat => moved successfully
C:\Windows\WinSxS\Manifests\x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_14.0.27012.0_none_9c229ed3ddb17764.manifest => moved successfully
HKEY_CURRENT_USER\Software\Avast Software => removed successfully
HKEY_CURRENT_USER\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\SafeZone 3.55.2393.609\Avast Pro Antivirus(1) => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_avast.vc140.crt_fcc99ee6193ebbca_none_020285fe6d6e0580 => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_avast.vc140.mfc_fcc99ee6193ebbca_none_018be6966dc83925 => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_none_ef17e13d91c55d96 => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_none_eea141d5921f913b => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_avast.vc140.crt_fcc99ee6193ebbca_none_49afbcd581ea2e86 => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_avast.vc140.mfc_fcc99ee6193ebbca_none_49391d6d8244622b => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_policy.14.0.avast.vc140.crt_fcc99ee6193ebbca_none_36c51814a641869c => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\x86_policy.14.0.avast.vc140.mfc_fcc99ee6193ebbca_none_364e78aca69bba41 => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvastBrowserUpdate.exe => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Avast Software" => removed successfully
RegLink Found. Source: "" => Target: "HKLM\SOFTWARE\AVAST Software"
"HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\AVAST Software" => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvastBrowserUpdate.exe => not found
HKEY_USERS\.DEFAULT\Software\AVAST Software => removed successfully
HKEY_USERS\S-1-5-21-4285004602-114342504-2893149386-1001\Software\Avast Software => not found
HKEY_USERS\S-1-5-18\Software\AVAST Software => not found
HKEY_USERS\S-1-5-21-4285004602-114342504-2893149386-1001\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\SafeZone 3.55.2393.609\Avast Pro Antivirus(1) => not found
"HKEY_USERS\S-1-5-21-4285004602-114342504-2893149386-1001\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\4ab51afc_0\\@" => not found
"HKEY_USERS\S-1-5-21-4285004602-114342504-2893149386-1001\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\SafeZone 3.55.2393.609\Avast Pro Antivirus(1)\\UninstallString" => not found
"HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\4ab51afc_0\\@" => not found
"HKEY_CURRENT_USER\Software\VS Revo Group\Revo Uninstaller Pro\Uninstaller\Traced\LogsUSs\SafeZone 3.55.2393.609\Avast Pro Antivirus(1)\\UninstallString" => not found
"HKEY_LOCAL_MACHINE\BCD00000000\Objects\{43547433-5ba9-11e9-b8c2-90a4de9ee626}\Elements\12000004\\Element" => not found
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsSelfHost\OneSettings\\TargetingAttributes" => removed successfully
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.

========= RemoveProxy: =========

"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
"HKU\S-1-5-21-4285004602-114342504-2893149386-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
"HKU\S-1-5-21-4285004602-114342504-2893149386-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully


========= End of RemoveProxy: =========


========= netsh winsock reset =========


El cat logo Winsock se restableci¢ correctamente.
Debe reiniciar el equipo para completar el restablecimiento.


========= End of CMD: =========


========= ipconfig /renew =========


Configuraci¢n IP de Windows


========= End of CMD: =========


========= ipconfig /flushdns =========


Configuraci¢n IP de Windows

No se puede vaciar la cach‚ de resoluci¢n de DNS: Error de una funci¢n durante la ejecuci¢n.


========= End of CMD: =========


========= bitsadmin /reset /allusers =========


BITSADMIN version 3.0
BITS administration utility.
(C) Copyright Microsoft Corp.

Unable to connect to BITS - 0x8007043c
El servicio no puede iniciarse en modo a prueba de errores



========= End of CMD: =========


========= netsh advfirewall reset =========


Error al intentar ponerse en contacto con el servicio Firewall de Windows Defender. Aseg£rate de que el servicio se est  ejecutando e intenta la solicitud de nuevo.


========= End of CMD: =========


========= netsh advfirewall set allprofiles state ON =========


Error al intentar ponerse en contacto con el servicio Firewall de Windows Defender. Aseg£rate de que el servicio se est  ejecutando e intenta la solicitud de nuevo.


========= End of CMD: =========


========= netsh int ipv4 reset =========

No hay valores configurados por el usuario para restablecer.


========= End of CMD: =========


========= netsh int ipv6 reset =========

No hay valores configurados por el usuario para restablecer.


========= End of CMD: =========


=========== EmptyTemp: ==========

BITS transfer queue => 7626752 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 22182086 B
Java, Flash, Steam htmlcache => 0 B
Windows/system/drivers => 42417170 B
Edge => 0 B
Chrome => 381352833 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 0 B
LocalService => 0 B
NetworkService => 46094 B
NetworkService => 0 B
Pequeñito => 72452260 B

RecycleBin => 0 B
EmptyTemp: => 501.7 MB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 17:51:55 ====

Hola

Vuelve a ejecutar Frst como te indiqué en este post:

En esta ocasión a parte de lo que está marcado por defecto, marca también la opción “List BCD”.

Captura%20de%20pantalla%20(63)

Un saludo

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 22.04.2019
Ran by Pequeñito (administrator) on PEQUEÑITO (SAMSUNG ELECTRONICS CO., LTD. NC210/NC110) (22-04-2019 19:14:11)
Running from C:\Users\Pequeñito\Desktop
Loaded Profiles: Pequeñito (Available Profiles: Pequeñito)
Platform: Windows 10 Pro Version 1809 17763.437 (X64) Language: Español (España, internacional)
Default browser: Chrome
Boot Mode: Safe Mode (minimal)
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1903.4-0\MsMpEng.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\HelpPane.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3251408 2015-09-23] (ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [14040296 2015-08-29] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [601928 2018-12-15] (Oracle America, Inc. -> Oracle Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\73.0.3683.103\Installer\chrmstp.exe [2019-04-07] (Google LLC -> Google Inc.)
Startup: C:\Users\Pequeñito\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MEGAsync.lnk [2019-03-29]
ShortcutTarget: MEGAsync.lnk -> C:\Users\Pequeñito\AppData\Local\MEGAsync\MEGAsync.exe (Mega Limited -> Mega Limited)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {161017CA-4780-489F-A50F-64C0C4D41FE5} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1903.4-0\MpCmdRun.exe [471472 2019-04-08] (Microsoft Corporation -> Microsoft Corporation)
Task: {19017404-B395-496B-A1D3-21810BF9020F} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1903.4-0\MpCmdRun.exe [471472 2019-04-08] (Microsoft Corporation -> Microsoft Corporation)
Task: {286F9C62-6A92-4D12-A35A-605B842DDCE9} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1903.4-0\MpCmdRun.exe [471472 2019-04-08] (Microsoft Corporation -> Microsoft Corporation)
Task: {60AF307E-3A4F-44FE-B0AE-9FD225FF8972} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1903.4-0\MpCmdRun.exe [471472 2019-04-08] (Microsoft Corporation -> Microsoft Corporation)
Task: {B2D505C4-9C5C-438D-A1AC-D3E59B81C410} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156968 2019-03-15] (Google Inc -> Google Inc.)
Task: {B392D498-D55F-4EF1-82D2-07C2E741DE49} - System32\Tasks\AVG\Overseer => C:\Program Files\Common Files\AVG\Overseer\overseer.exe [2408496 2019-04-03] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
Task: {B88FF234-F77C-4A4F-B53C-47C5526D1C88} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156968 2019-03-15] (Google Inc -> Google Inc.)
Task: {C4FEEECC-22D6-4B60-A388-77E9E24280FC} - System32\Tasks\RogueKiller Anti-Malware => C:\Program Files\RogueKiller\RogueKiller64.exe [33900088 2019-03-27] (Adlice -> )
Task: {CA67FEFA-AC8D-4328-B57E-28935D28CE97} - System32\Tasks\WpsUpdateTask_Pequeñito => C:\Users\Pequeñito\AppData\Local\Kingsoft\WPS Office\11.2.0.8310\office6\wps.exe
Task: {ECA82CCE-ACBB-45A9-A792-4965B566870E} - System32\Tasks\WpsExternal_Pequeñito_20190409101416 => C:\Users\Pequeñito\AppData\Local\Kingsoft\WPS Office\11.2.0.8310\office6\wps.exe
Task: {FE449ED6-F0F9-498E-8DB0-FD6D49D1A949} - System32\Tasks\AMHelper => C:\Program Files (x86)\Zemana\AntiMalware\AntiMalware.exe [630848 2019-03-12] (Zemana D.O.O. Sarajevo -> Zemana Ltd.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job => C:\Windows\explorer.exe
Task: C:\Windows\Tasks\Dr.Web Daily scan.job => C:\Program Files\DrWeb\dwscanner.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 80.58.61.250 80.58.61.254
Tcpip\..\Interfaces\{893aa8b1-fb9e-403e-9c47-cca511bdb55b}: [DhcpNameServer] 80.58.61.250 80.58.61.254

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = 
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = 
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = 
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = 
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = 
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = 
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = 
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page = 
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_201\bin\ssv.dll [2019-03-16] (Oracle America, Inc. -> Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_201\bin\jp2ssv.dll [2019-03-16] (Oracle America, Inc. -> Oracle Corporation)

FireFox:
========
FF Plugin: @java.com/DTPlugin,version=11.201.2 -> C:\Program Files\Java\jre1.8.0_201\bin\dtplugin\npDeployJava1.dll [2019-03-16] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.201.2 -> C:\Program Files\Java\jre1.8.0_201\bin\plugin2\npjp2.dll [2019-03-16] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2019-01-10] (VideoLAN -> VideoLAN)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.34.7\npGoogleUpdate3.dll [2019-03-28] (Google Inc -> Google LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.34.7\npGoogleUpdate3.dll [2019-03-28] (Google Inc -> Google LLC)

Chrome: 
=======
CHR HomePage: Default -> hxxps://www.google.es/
CHR StartupUrls: Default -> "hxxp://www.google.es/","hxxps://www.google.com/","hxxps://www.google.com/","hxxps://www.google.com/","hxxps://www.google.com/"
CHR Profile: C:\Users\Pequeñito\AppData\Local\Google\Chrome\User Data\Default [2019-04-22]
CHR Extension: (Presentaciones) - C:\Users\Pequeñito\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-03-15]
CHR Extension: (Duolingo en la web) - C:\Users\Pequeñito\AppData\Local\Google\Chrome\User Data\Default\Extensions\aiahmijlpehemcpleichkcokhegllfjl [2019-03-15]
CHR Extension: (Documentos) - C:\Users\Pequeñito\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-03-15]
CHR Extension: (Google Drive) - C:\Users\Pequeñito\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2019-03-15]
CHR Extension: (Audiense) - C:\Users\Pequeñito\AppData\Local\Google\Chrome\User Data\Default\Extensions\bagknoiagpifjfbempgignagkejmkljm [2019-03-15]
CHR Extension: (Grupos de Google) - C:\Users\Pequeñito\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfmbadcfdhiklafcdohpfphhhakmiakk [2019-03-15]
CHR Extension: (Windows Defender Browser Protection) - C:\Users\Pequeñito\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkbeeeffjjeopflfhgeknacdieedcoml [2019-03-15]
CHR Extension: (YouTube) - C:\Users\Pequeñito\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-03-15]
CHR Extension: (Business Hangouts - Webinars for G Suite) - C:\Users\Pequeñito\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccbjchepdbjeemagnjpoihpkjghelnge [2019-03-15]
CHR Extension: (uBlock Origin) - C:\Users\Pequeñito\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2019-04-03]
CHR Extension: (Spotify - Music for every moment) - C:\Users\Pequeñito\AppData\Local\Google\Chrome\User Data\Default\Extensions\cnkjkdjlofllcpbemipjbcpfnglbgieh [2019-03-15]
CHR Extension: (Reto WGT de Golf) - C:\Users\Pequeñito\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcilimldmomiaihcfkmaldanopfejefg [2019-03-15]
CHR Extension: (Television) - C:\Users\Pequeñito\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhldnekicgefkglimkhjnldknpmljece [2019-03-15]
CHR Extension: (Google+) - C:\Users\Pequeñito\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlppkpafhbajpcmmoheippocdidnckmm [2019-03-15]
CHR Extension: (Hojas de cálculo) - C:\Users\Pequeñito\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-03-15]
CHR Extension: (Full Screen Weather) - C:\Users\Pequeñito\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkkaebihfmbofclegkcfkkemepfehibg [2019-03-15]
CHR Extension: (Documentos de Google sin conexión) - C:\Users\Pequeñito\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2019-03-15]
CHR Extension: (TweetDeck by Twitter) - C:\Users\Pequeñito\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbdpomandigafcibbmofojjchbcdagbl [2019-03-15]
CHR Extension: (PDF Mergy - Merge PDF files) - C:\Users\Pequeñito\AppData\Local\Google\Chrome\User Data\Default\Extensions\hgecghmkcdefnknohcimkoemhaofpoha [2019-03-15]
CHR Extension: (OSI: Servicio AntiBotnet) - C:\Users\Pequeñito\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhljghnmjahiaofikeljkjnhbeoiclbh [2019-03-15]
CHR Extension: (Google Play Music) - C:\Users\Pequeñito\AppData\Local\Google\Chrome\User Data\Default\Extensions\icppfcnhkcmnfdhfhphakoifcfokfdhg [2019-03-15]
CHR Extension: (The Weather Channel for Chrome) - C:\Users\Pequeñito\AppData\Local\Google\Chrome\User Data\Default\Extensions\iflpcokdamgefbghpdipcibmhlkdopop [2019-03-15]
CHR Extension: (Free SEO Deal of the Week) - C:\Users\Pequeñito\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgnekndlomccgljphjjcmhgmbbbeeklm [2019-03-15]
CHR Extension: (Hootsuite) - C:\Users\Pequeñito\AppData\Local\Google\Chrome\User Data\Default\Extensions\kneloppijbcidgidihgdjnooihjcdbij [2019-03-15]
CHR Extension: (Google Play) - C:\Users\Pequeñito\AppData\Local\Google\Chrome\User Data\Default\Extensions\komhbcfkdcgmcdoenjcjheifdiabikfi [2019-03-15]
CHR Extension: (AudioSauna) - C:\Users\Pequeñito\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkgfemnodkdnenmfkblebnkjpckkjcae [2019-03-15]
CHR Extension: (Cesta de aparcamiento del centro comercial) - C:\Users\Pequeñito\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjfoehokglnmbbnncflhhgapdfkhahle [2019-03-15]
CHR Extension: (SEO Webpage Analysis Tool) - C:\Users\Pequeñito\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfhheamcohgngngnmpckfgcfmdabmno [2019-03-15]
CHR Extension: (Sistema de pagos de Chrome Web Store) - C:\Users\Pequeñito\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-03-15]
CHR Extension: (Video Downloader) - C:\Users\Pequeñito\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbbjnobglkpbfmpabbgogbnlffkmgbii [2019-03-15]
CHR Extension: (Gmail) - C:\Users\Pequeñito\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-03-15]
CHR Extension: (Chrome Media Router) - C:\Users\Pequeñito\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-03-15]
CHR Extension: (SEO Competitor Analysis) - C:\Users\Pequeñito\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnpafbknegcefgoojplahellhohoklbj [2019-03-15]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 DrWebEngine; C:\Program Files\Common Files\Doctor Web\Scanning Engine\dwengine.exe [2224088 2019-03-20] (Doctor Web Ltd. -> Doctor Web, Ltd.)
S2 ETDService; C:\Program Files\Elantech\ETDService.exe [139984 2015-09-23] (ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5382448 2019-04-08] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1903.4-0\NisSrv.exe [3856504 2019-04-08] (Microsoft Corporation -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1903.4-0\MsMpEng.exe [113992 2019-04-08] (Microsoft Corporation -> Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 amsdk; C:\Windows\system32\drivers\amsdk.sys [232792 2019-03-23] (Zemana D.O.O. Sarajevo -> Copyright 2018.)
R0 DrWebLwf; C:\Windows\System32\drivers\drweblwf.sys [424168 2019-03-20] (Doctor Web Ltd. -> Doctor Web, Ltd.)
S3 igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [6192640 2012-03-23] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
S3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [605696 2018-09-15] (Microsoft Windows -> Realtek )
R0 SpiderG3; C:\Windows\System32\drivers\spiderg3.sys [323088 2019-03-20] (Doctor Web Ltd. -> Doctor Web, Ltd.)
S3 TKCtrl; C:\Windows\system32\TKCtrl2k64.sys [147240 2018-01-29] (INCA Internet Co.,Ltd. -> INCA Internet Co., Ltd.)
S3 TKFsAvM; C:\Windows\system32\TKFsAv64.sys [198808 2018-03-07] (INCA Internet Co.,Ltd. -> INCA Internet Co., Ltd.)
S3 TKFsFtM; C:\Windows\system32\TKFsFt64.sys [28824 2018-03-07] (INCA Internet Co.,Ltd. -> INCA Internet Co., Ltd.)
S3 TKPcFt; C:\Windows\system32\TKPcFtCb64.sys [54504 2018-01-30] (INCA Internet Co.,Ltd. -> INCA Internet Co., Ltd.)
S3 TKRgAc; C:\Windows\system32\TKRgAc2k64.sys [115760 2018-01-29] (INCA Internet Co.,Ltd. -> INCA Internet Co., Ltd.)
S3 TKRgFt; C:\Windows\system32\TKRgFtXp64.sys [68848 2018-02-04] (INCA Internet Co.,Ltd. -> INCA Internet Co., Ltd.)
S3 TKSP; C:\Windows\system32\TKSPxp64.sys [80824 2018-01-29] (INCA Internet Co.,Ltd. -> INCA Internet Co., Ltd.)
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [46472 2019-04-08] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [343520 2019-04-08] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [68576 2019-04-08] (Microsoft Windows -> Microsoft Corporation)
U3 TrueSight; \??\C:\Windows\System32\drivers\truesight.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-04-22 19:14 - 2019-04-22 19:18 - 000016383 _____ C:\Users\Pequeñito\Desktop\FRST.txt
2019-04-22 18:21 - 2019-04-22 18:26 - 000000000 ____D C:\Users\Pequeñito\Desktop\opositatest
2019-04-22 17:48 - 2019-04-22 19:14 - 000000000 ____D C:\FRST
2019-04-22 17:34 - 2019-04-22 17:35 - 002436096 _____ (Farbar) C:\Users\Pequeñito\Desktop\FRST64.exe
2019-04-22 17:30 - 2019-04-22 17:30 - 000797760 _____ C:\Users\Pequeñito\Desktop\delfix.exe
2019-04-20 18:35 - 2019-04-20 18:42 - 000017788 _____ C:\Users\Pequeñito\Desktop\SystemLook.txt
2019-04-19 18:55 - 2019-04-19 18:59 - 000000000 ____D C:\KVRT_Data
2019-04-19 18:53 - 2019-04-19 18:54 - 159635240 _____ (AO Kaspersky Lab) C:\Users\Pequeñito\Desktop\KVRT.exe
2019-04-19 18:32 - 2019-04-19 18:32 - 000000551 _____ C:\Users\Pequeñito\Desktop\JRT.txt
2019-04-19 17:34 - 2019-04-19 17:34 - 000005010 _____ C:\TDSSKiller.3.1.0.28_19.04.2019_17.34.08_log.txt
2019-04-19 12:35 - 2019-04-19 12:35 - 000000000 ____D C:\Users\Pequeñito\Desktop\tdsskiller
2019-04-19 12:33 - 2019-04-19 12:34 - 004962800 _____ C:\Users\Pequeñito\Desktop\tdsskiller.zip
2019-04-19 11:55 - 2019-04-19 12:00 - 000000000 ____D C:\AdwCleaner
2019-04-19 11:45 - 2019-04-21 18:35 - 000042904 _____ (Sysinternals - www.sysinternals.com) C:\Windows\system32\Drivers\PROCEXP152.SYS
2019-04-16 08:38 - 2019-04-16 08:38 - 000165376 _____ C:\Users\Pequeñito\Desktop\SystemLook_x64.exe
2019-04-15 16:10 - 2019-04-15 16:50 - 000000000 ____D C:\Users\Pequeñito\AppData\Local\NPE
2019-04-15 16:10 - 2019-04-15 16:10 - 000000000 ____D C:\ProgramData\Norton
2019-04-15 12:46 - 2019-04-15 12:46 - 000000000 ____D C:\ProgramData\GridinSoft
2019-04-14 18:01 - 2019-04-22 17:36 - 000000256 _____ C:\DelFix.txt
2019-04-14 18:01 - 2019-04-14 18:01 - 000000000 ____D C:\Windows\ERUNT
2019-04-12 15:40 - 2019-04-12 15:25 - 001453590 ____N C:\Users\Pequeñito\Desktop\ActTemario1TAI.pdf
2019-04-12 11:36 - 2019-04-12 19:26 - 000000000 ____D C:\Users\Pequeñito\Desktop\mp3audios
2019-04-12 11:33 - 2019-04-12 11:33 - 000001409 _____ C:\Users\Pequeñito\Desktop\MP3 Audio Converter.lnk
2019-04-12 11:33 - 2019-04-12 11:33 - 000000000 ____D C:\Users\Pequeñito\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MP3 Audio Converter
2019-04-12 11:33 - 2019-04-12 11:33 - 000000000 ____D C:\Users\Pequeñito\AppData\Local\EZSoftMagic
2019-04-12 11:33 - 2002-01-05 15:37 - 000344064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr70.dll
2019-04-12 11:28 - 2019-04-12 11:28 - 000000000 ____D C:\Users\Pequeñito\Documents\Audacity
2019-04-12 11:27 - 2019-04-12 17:55 - 000000000 ____D C:\Users\Pequeñito\AppData\Roaming\audacity
2019-04-12 11:27 - 2019-04-12 11:27 - 000001125 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
2019-04-12 11:27 - 2019-04-12 11:27 - 000001113 _____ C:\Users\Public\Desktop\Audacity.lnk
2019-04-12 11:27 - 2019-04-12 11:27 - 000000000 ____D C:\Users\Pequeñito\AppData\Local\Audacity
2019-04-12 11:26 - 2019-04-12 11:27 - 000000000 ____D C:\Program Files (x86)\Audacity
2019-04-11 12:32 - 2019-04-11 12:32 - 000000000 ____D C:\Users\Pequeñito\AppData\Local\VS Revo Group
2019-04-11 12:31 - 2019-04-11 12:31 - 000001159 _____ C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
2019-04-11 12:31 - 2019-04-11 12:31 - 000000000 ____D C:\ProgramData\VS Revo Group
2019-04-11 12:31 - 2019-04-11 12:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro
2019-04-11 12:31 - 2016-12-21 14:52 - 000040240 _____ (VS Revo Group) C:\Windows\system32\Drivers\revoflt.sys
2019-04-11 12:30 - 2019-04-11 12:30 - 000000000 ____D C:\Program Files\VS Revo Group
2019-04-10 17:42 - 2019-04-10 17:42 - 000000000 ____D C:\Users\Pequeñito\AppData\Roaming\LibreOffice
2019-04-10 17:15 - 2019-04-10 17:15 - 000001243 _____ C:\Users\Public\Desktop\LibreOffice 6.2.lnk
2019-04-10 17:15 - 2019-04-10 17:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 6.2
2019-04-10 17:12 - 2019-04-10 17:14 - 000000000 ____D C:\Program Files\LibreOffice
2019-04-10 13:02 - 2019-04-10 13:02 - 000007134 _____ C:\Windows\CleanMem Uninstall Log.txt
2019-04-10 02:39 - 2019-04-10 02:39 - 005436904 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll
2019-04-10 02:39 - 2019-04-10 02:39 - 003551112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll
2019-04-10 02:39 - 2019-04-10 02:39 - 000263600 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2019-04-10 02:38 - 2019-04-10 02:38 - 026810368 _____ (Microsoft Corporation) C:\Windows\system32\edgehtml.dll
2019-04-10 02:38 - 2019-04-10 02:38 - 023440896 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2019-04-10 02:38 - 2019-04-10 02:38 - 020815360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgehtml.dll
2019-04-10 02:38 - 2019-04-10 02:38 - 019025408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2019-04-10 02:38 - 2019-04-10 02:38 - 012843520 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2019-04-10 02:38 - 2019-04-10 02:38 - 012139008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2019-04-10 02:38 - 2019-04-10 02:38 - 007877120 _____ (Microsoft Corporation) C:\Windows\system32\Chakra.dll
2019-04-10 02:38 - 2019-04-10 02:38 - 006544824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Protection.PlayReady.dll
2019-04-10 02:38 - 2019-04-10 02:38 - 006071296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakra.dll
2019-04-10 02:38 - 2019-04-10 02:38 - 004660224 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2019-04-10 02:38 - 2019-04-10 02:38 - 003904512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2019-04-10 02:38 - 2019-04-10 02:38 - 001701888 _____ (Microsoft Corporation) C:\Windows\system32\GdiPlus.dll
2019-04-10 02:38 - 2019-04-10 02:38 - 001671352 _____ (Microsoft Corporation) C:\Windows\system32\gdi32full.dll
2019-04-10 02:38 - 2019-04-10 02:38 - 001590064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpserverbase.dll
2019-04-10 02:38 - 2019-04-10 02:38 - 001484800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GdiPlus.dll
2019-04-10 02:38 - 2019-04-10 02:38 - 001467344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32full.dll
2019-04-10 02:38 - 2019-04-10 02:38 - 001387520 _____ (Microsoft Corporation) C:\Windows\system32\bcastdvruserservice.dll
2019-04-10 02:38 - 2019-04-10 02:38 - 001311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjet40.dll
2019-04-10 02:38 - 2019-04-10 02:38 - 001309696 _____ (Microsoft Corporation) C:\Windows\system32\webplatstorageserver.dll
2019-04-10 02:38 - 2019-04-10 02:38 - 001221944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpbase.dll
2019-04-10 02:38 - 2019-04-10 02:38 - 001072640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll
2019-04-10 02:38 - 2019-04-10 02:38 - 001019392 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2019-04-10 02:38 - 2019-04-10 02:38 - 000912384 _____ (Microsoft Corporation) C:\Windows\system32\EdgeManager.dll
2019-04-10 02:38 - 2019-04-10 02:38 - 000833024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webplatstorageserver.dll
2019-04-10 02:38 - 2019-04-10 02:38 - 000663040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EdgeManager.dll
2019-04-10 02:38 - 2019-04-10 02:38 - 000653040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppXDeploymentClient.dll
2019-04-10 02:38 - 2019-04-10 02:38 - 000649064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2019-04-10 02:38 - 2019-04-10 02:38 - 000642048 _____ (Microsoft Corporation) C:\Windows\system32\SharedRealitySvc.dll
2019-04-10 02:38 - 2019-04-10 02:38 - 000532480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2019-04-10 02:38 - 2019-04-10 02:38 - 000475648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxbde40.dll
2019-04-10 02:38 - 2019-04-10 02:38 - 000474928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2019-04-10 02:38 - 2019-04-10 02:38 - 000375808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mspbde40.dll
2019-04-10 02:38 - 2019-04-10 02:38 - 000352768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrd3x40.dll
2019-04-10 02:38 - 2019-04-10 02:38 - 000340992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msexcl40.dll
2019-04-10 02:38 - 2019-04-10 02:38 - 000155136 _____ (Microsoft Corporation) C:\Windows\system32\Chakradiag.dll
2019-04-10 02:38 - 2019-04-10 02:38 - 000133120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Radios.dll
2019-04-10 02:38 - 2019-04-10 02:38 - 000115200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleprn.dll
2019-04-10 02:38 - 2019-04-10 02:38 - 000060928 _____ (Microsoft Corporation) C:\Windows\system32\mf3216.dll
2019-04-10 02:38 - 2019-04-10 02:38 - 000046080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf3216.dll
2019-04-10 02:37 - 2019-04-10 02:37 - 009682744 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2019-04-10 02:37 - 2019-04-10 02:37 - 007645608 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Protection.PlayReady.dll
2019-04-10 02:37 - 2019-04-10 02:37 - 004588536 _____ (Microsoft Corporation) C:\Windows\system32\sppsvc.exe
2019-04-10 02:37 - 2019-04-10 02:37 - 003657728 _____ (Microsoft Corporation) C:\Windows\system32\win32kfull.sys
2019-04-10 02:37 - 2019-04-10 02:37 - 003384832 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll
2019-04-10 02:37 - 2019-04-10 02:37 - 002925880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2019-04-10 02:37 - 2019-04-10 02:37 - 002720256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32kfull.sys
2019-04-10 02:37 - 2019-04-10 02:37 - 002469376 _____ (Microsoft Corporation) C:\Windows\system32\win32kbase.sys
2019-04-10 02:37 - 2019-04-10 02:37 - 002438368 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2019-04-10 02:37 - 2019-04-10 02:37 - 002189312 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.onecore.dll
2019-04-10 02:37 - 2019-04-10 02:37 - 002022304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2019-04-10 02:37 - 2019-04-10 02:37 - 001886208 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2019-04-10 02:37 - 2019-04-10 02:37 - 001830200 _____ (Microsoft Corporation) C:\Windows\system32\rdpserverbase.dll
2019-04-10 02:37 - 2019-04-10 02:37 - 001672704 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2019-04-10 02:37 - 2019-04-10 02:37 - 001605120 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.desktop.dll
2019-04-10 02:37 - 2019-04-10 02:37 - 001496576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2019-04-10 02:37 - 2019-04-10 02:37 - 001478968 _____ (Microsoft Corporation) C:\Windows\system32\rdpbase.dll
2019-04-10 02:37 - 2019-04-10 02:37 - 001256448 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
2019-04-10 02:37 - 2019-04-10 02:37 - 001253688 _____ (Microsoft Corporation) C:\Windows\system32\hvix64.exe
2019-04-10 02:37 - 2019-04-10 02:37 - 001054200 _____ (Microsoft Corporation) C:\Windows\system32\ApplyTrustOffline.exe
2019-04-10 02:37 - 2019-04-10 02:37 - 001044280 _____ (Microsoft Corporation) C:\Windows\system32\hvax64.exe
2019-04-10 02:37 - 2019-04-10 02:37 - 000865784 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentClient.dll
2019-04-10 02:37 - 2019-04-10 02:37 - 000793832 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2019-04-10 02:37 - 2019-04-10 02:37 - 000725928 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2019-04-10 02:37 - 2019-04-10 02:37 - 000604008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2019-04-10 02:37 - 2019-04-10 02:37 - 000593920 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2019-04-10 02:37 - 2019-04-10 02:37 - 000543744 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2019-04-10 02:37 - 2019-04-10 02:37 - 000531968 _____ (Microsoft Corporation) C:\Windows\system32\sppcext.dll
2019-04-10 02:37 - 2019-04-10 02:37 - 000346624 _____ (Microsoft Corporation) C:\Windows\system32\AppxAllUserStore.dll
2019-04-10 02:37 - 2019-04-10 02:37 - 000301568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netbt.sys
2019-04-10 02:37 - 2019-04-10 02:37 - 000273920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppxAllUserStore.dll
2019-04-10 02:37 - 2019-04-10 02:37 - 000183296 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Radios.dll
2019-04-10 02:37 - 2019-04-10 02:37 - 000143872 _____ (Microsoft Corporation) C:\Windows\system32\oleprn.dll
2019-04-10 02:37 - 2019-04-10 02:37 - 000138752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\luafv.sys
2019-04-10 02:37 - 2019-04-10 02:37 - 000095544 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2019-04-10 02:37 - 2019-04-10 02:37 - 000090424 _____ (Microsoft Corporation) C:\Windows\system32\hvloader.dll
2019-04-10 02:37 - 2019-04-10 02:37 - 000033792 _____ (Microsoft Corporation) C:\Windows\system32\sxssrv.dll
2019-04-10 02:37 - 2019-04-10 02:37 - 000000315 _____ C:\Windows\system32\DrtmAuth8.bin
2019-04-10 02:37 - 2019-04-10 02:37 - 000000315 _____ C:\Windows\system32\DrtmAuth7.bin
2019-04-10 02:37 - 2019-04-10 02:37 - 000000315 _____ C:\Windows\system32\DrtmAuth6.bin
2019-04-10 02:37 - 2019-04-10 02:37 - 000000315 _____ C:\Windows\system32\DrtmAuth5.bin
2019-04-10 02:37 - 2019-04-10 02:37 - 000000315 _____ C:\Windows\system32\DrtmAuth4.bin
2019-04-10 02:37 - 2019-04-10 02:37 - 000000315 _____ C:\Windows\system32\DrtmAuth3.bin
2019-04-10 02:37 - 2019-04-10 02:37 - 000000315 _____ C:\Windows\system32\DrtmAuth2.bin
2019-04-10 02:37 - 2019-04-10 02:37 - 000000315 _____ C:\Windows\system32\DrtmAuth1.bin
2019-04-09 17:58 - 2019-04-09 17:58 - 000179910 _____ C:\Users\Pequeñito\Desktop\leccion_7.pdf
2019-04-09 10:14 - 2019-04-09 10:14 - 000004078 _____ C:\Windows\System32\Tasks\WpsExternal_Pequeñito_20190409101416
2019-04-09 09:34 - 2019-04-09 09:34 - 000000000 ____D C:\Windows\Tasks\ImCleanDisabled
2019-04-08 14:30 - 2019-04-08 14:30 - 003602944 _____ (Microsoft Corporation) C:\Windows\system32\tellib.dll
2019-04-08 14:30 - 2019-04-08 14:30 - 001459080 _____ (Microsoft Corporation) C:\Windows\system32\msvproc.dll
2019-04-08 14:30 - 2019-04-08 14:30 - 001297120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvproc.dll
2019-04-08 14:30 - 2019-04-08 14:30 - 001294520 _____ (Microsoft Corporation) C:\Windows\system32\mfsvr.dll
2019-04-08 14:30 - 2019-04-08 14:30 - 001259320 _____ (Microsoft Corporation) C:\Windows\system32\SecConfig.efi
2019-04-08 14:30 - 2019-04-08 14:30 - 001072424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsvr.dll
2019-04-08 14:30 - 2019-04-08 14:30 - 000897536 _____ (Microsoft Corporation) C:\Windows\system32\fveapi.dll
2019-04-08 14:30 - 2019-04-08 14:30 - 000815616 _____ (Microsoft Corporation) C:\Windows\system32\fvewiz.dll
2019-04-08 14:30 - 2019-04-08 14:30 - 000740352 _____ (Microsoft Corporation) C:\Windows\system32\cscsvc.dll
2019-04-08 14:30 - 2019-04-08 14:30 - 000666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fveapi.dll
2019-04-08 14:30 - 2019-04-08 14:30 - 000464384 _____ (Microsoft Corporation) C:\Windows\system32\rdpshell.exe
2019-04-08 14:30 - 2019-04-08 14:30 - 000454144 _____ (Microsoft Corporation) C:\Windows\system32\bdesvc.dll
2019-04-08 14:30 - 2019-04-08 14:30 - 000372224 _____ (Microsoft Corporation) C:\Windows\system32\bdechangepin.exe
2019-04-08 14:30 - 2019-04-08 14:30 - 000370688 _____ (Microsoft Corporation) C:\Windows\system32\fveapibase.dll
2019-04-08 14:30 - 2019-04-08 14:30 - 000363520 _____ (Microsoft Corporation) C:\Windows\system32\rdpinit.exe
2019-04-08 14:30 - 2019-04-08 14:30 - 000331776 _____ (Microsoft Corporation) C:\Windows\system32\fvecpl.dll
2019-04-08 14:30 - 2019-04-08 14:30 - 000317240 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mssecflt.sys
2019-04-08 14:30 - 2019-04-08 14:30 - 000311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fveapibase.dll
2019-04-08 14:30 - 2019-04-08 14:30 - 000309760 _____ (Microsoft Corporation) C:\Windows\system32\fveui.dll
2019-04-08 14:30 - 2019-04-08 14:30 - 000087040 _____ (Microsoft Corporation) C:\Windows\system32\mssecuser.dll
2019-04-08 14:29 - 2019-04-08 14:29 - 008898048 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2019-04-08 14:29 - 2019-04-08 14:29 - 007919104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2019-04-08 14:29 - 2019-04-08 14:29 - 003690496 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2019-04-08 14:29 - 2019-04-08 14:29 - 003421696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2019-04-08 14:29 - 2019-04-08 14:29 - 002942464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mispace.dll
2019-04-08 14:29 - 2019-04-08 14:29 - 002127360 _____ (Microsoft Corporation) C:\Windows\system32\wsp_fs.dll
2019-04-08 14:29 - 2019-04-08 14:29 - 001521664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsp_fs.dll
2019-04-08 14:29 - 2019-04-08 14:29 - 001064448 _____ (Microsoft Corporation) C:\Windows\system32\sysmain.dll
2019-04-08 14:29 - 2019-04-08 14:29 - 000793600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\clusapi.dll
2019-04-08 14:29 - 2019-04-08 14:29 - 000772608 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2019-04-08 14:29 - 2019-04-08 14:29 - 000701440 _____ (Microsoft Corporation) C:\Windows\system32\FrameServer.dll
2019-04-08 14:29 - 2019-04-08 14:29 - 000684032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2019-04-08 14:29 - 2019-04-08 14:29 - 000617984 _____ (Microsoft Corporation) C:\Windows\system32\AssignedAccessManager.dll
2019-04-08 14:29 - 2019-04-08 14:29 - 000316416 _____ (Microsoft Corporation) C:\Windows\system32\FSClient.dll
2019-04-08 14:29 - 2019-04-08 14:29 - 000097280 _____ (Microsoft Corporation) C:\Windows\system32\EduPrintProv.exe
2019-04-08 14:29 - 2019-04-08 14:29 - 000067072 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe
2019-04-08 14:29 - 2019-04-08 14:29 - 000059904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe
2019-04-08 14:29 - 2019-04-08 14:29 - 000059904 _____ (Microsoft Corporation) C:\Windows\system32\RDSPnf.exe
2019-04-08 14:29 - 2019-04-08 14:29 - 000039936 _____ (Microsoft Corporation) C:\Windows\system32\perfts.dll
2019-04-08 14:29 - 2019-04-08 14:29 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshhttp.dll
2019-04-08 14:29 - 2019-04-08 14:29 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dataclen.dll
2019-04-08 14:29 - 2019-04-08 14:29 - 000032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\perfts.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 015223296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 006440960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Data.Pdf.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 006309040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\windows.storage.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 005765120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 005205448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.StateRepository.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 004527624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setupapi.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 003656192 _____ (Microsoft Corporation) C:\Windows\system32\mispace.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 003496448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.AI.MachineLearning.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 002777224 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 002765312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 002689024 _____ (Microsoft Corporation) C:\Windows\system32\WebRuntimeManager.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 002346496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 002275896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 001860096 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 001760768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 001711104 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Immersive.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 001687552 _____ (Microsoft Corporation) C:\Windows\system32\enterprisecsps.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 001674480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 001615872 ____R (The ICU Project) C:\Windows\SysWOW64\icuin.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 001506304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Immersive.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 001458056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3D12.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 001370624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AzureSettingSyncProvider.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 001249280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InstallService.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 001155072 ____R (The ICU Project) C:\Windows\SysWOW64\icuuc.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 001047552 _____ (Microsoft Corporation) C:\Windows\system32\clusapi.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 001026792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 001001472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wpnapps.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000982528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.Vpn.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000976896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000964096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncCore.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000949248 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.Management.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000909840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WWAHost.exe
2019-04-08 14:28 - 2019-04-08 14:28 - 000884224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MbaeApiPublic.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000882688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2019-04-08 14:28 - 2019-04-08 14:28 - 000845824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ShareHost.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000840192 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000828728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncHost.exe
2019-04-08 14:28 - 2019-04-08 14:28 - 000762880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mprddm.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000731648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.BackgroundMediaPlayback.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000730112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Playback.BackgroundMediaPlayer.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000712192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Playback.MediaPlayer.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000711168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MbaeApi.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000672256 _____ (Microsoft Corporation) C:\Windows\system32\configmanager2.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000671232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntshrui.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Internal.Management.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000663552 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000617784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LicensingWinRT.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000551936 _____ (Microsoft Corporation) C:\Windows\system32\dmenrollengine.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000540448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StructuredQuery.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000528384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\OneDriveSettingSyncProvider.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000496128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sppcext.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000460800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dmenrollengine.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000424960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\daxexec.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000414720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winspool.drv
2019-04-08 14:28 - 2019-04-08 14:28 - 000408528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Enumeration.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000385536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.LowLevel.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LockAppBroker.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000358912 _____ (Microsoft Corporation) C:\Windows\system32\DeviceEnroller.exe
2019-04-08 14:28 - 2019-04-08 14:28 - 000349184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2019-04-08 14:28 - 2019-04-08 14:28 - 000312832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Graphics.Printing.Workflow.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000312632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\thumbcache.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000294912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RADCUI.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000224768 _____ (Microsoft Corporation) C:\Windows\system32\BitLockerCsp.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000201216 _____ (Microsoft Corporation) C:\Windows\system32\wincredui.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000188416 _____ (Microsoft Corporation) C:\Windows\system32\DMPushRouterCore.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000176640 _____ (Microsoft Corporation) C:\Windows\system32\spacebridge.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000159744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredui.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000143360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\BitLockerCsp.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000140288 _____ (Microsoft Corporation) C:\Windows\system32\mdmmigrator.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000107008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.SerialCommunication.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000101376 _____ (Microsoft Corporation) C:\Windows\system32\hlink.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000099840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\hlink.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000096256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserDataTimeUtil.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000089600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drvsetup.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000088576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\olepro32.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntlanman.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000049152 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000046592 _____ (Microsoft Corporation) C:\Windows\system32\dataclen.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000044544 _____ (Microsoft Corporation) C:\Windows\system32\nshhttp.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000040960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscapi.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000040960 _____ (Microsoft Corporation) C:\Windows\system32\perfproc.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\perfproc.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000035840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cmintegrator.dll
2019-04-08 14:28 - 2019-04-08 14:28 - 000026624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RpcPing.exe
2019-04-08 14:28 - 2019-04-08 14:28 - 000022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscdll.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 007883776 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Data.Pdf.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 006925824 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 004866560 _____ (Microsoft Corporation) C:\Windows\system32\Windows.AI.MachineLearning.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 004704272 _____ (Microsoft Corporation) C:\Windows\system32\setupapi.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 004304896 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_nt.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 003982848 _____ (Microsoft Corporation) C:\Windows\system32\EdgeContent.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 003377976 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2019-04-08 14:27 - 2019-04-08 14:27 - 003334144 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 002871304 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2019-04-08 14:27 - 2019-04-08 14:27 - 002842624 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 002701304 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 002627384 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2019-04-08 14:27 - 2019-04-08 14:27 - 002073960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 002042368 _____ (Microsoft Corporation) C:\Windows\system32\Windows.CloudStore.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 001994768 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 001969464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\refs.sys
2019-04-08 14:27 - 2019-04-08 14:27 - 001918464 _____ (Microsoft Corporation) C:\Windows\system32\AzureSettingSyncProvider.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 001844448 _____ (Microsoft Corporation) C:\Windows\system32\D3D12.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 001697752 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2019-04-08 14:27 - 2019-04-08 14:27 - 001671680 _____ (Microsoft Corporation) C:\Windows\system32\InstallService.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 001647632 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 001641400 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 001468952 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2019-04-08 14:27 - 2019-04-08 14:27 - 001395056 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 001360184 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2019-04-08 14:27 - 2019-04-08 14:27 - 001342400 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2019-04-08 14:27 - 2019-04-08 14:27 - 001315328 _____ (Microsoft Corporation) C:\Windows\system32\wpnapps.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 001311232 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.Vpn.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 001217024 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 001179680 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2019-04-08 14:27 - 2019-04-08 14:27 - 001145856 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncCore.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 001133568 _____ (Microsoft Corporation) C:\Windows\system32\MbaeApiPublic.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 001058304 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2019-04-08 14:27 - 2019-04-08 14:27 - 001057792 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2019-04-08 14:27 - 2019-04-08 14:27 - 001035776 _____ (Microsoft Corporation) C:\Windows\system32\ShareHost.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000998712 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncHost.exe
2019-04-08 14:27 - 2019-04-08 14:27 - 000981816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\refsv1.sys
2019-04-08 14:27 - 2019-04-08 14:27 - 000948224 _____ (Microsoft Corporation) C:\Windows\system32\uDWM.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000927232 _____ (Microsoft Corporation) C:\Windows\system32\rasmans.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000926208 _____ (Microsoft Corporation) C:\Windows\system32\MbaeApi.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000888320 _____ (Microsoft Corporation) C:\Windows\system32\mprddm.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000882176 _____ (Microsoft Corporation) C:\Windows\system32\BFE.DLL
2019-04-08 14:27 - 2019-04-08 14:27 - 000872448 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000865792 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000821048 _____ (Microsoft Corporation) C:\Windows\system32\NetSetupEngine.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000809784 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000776192 _____ (Microsoft Corporation) C:\Windows\system32\ntshrui.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000769536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2019-04-08 14:27 - 2019-04-08 14:27 - 000737080 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000730936 _____ (Microsoft Corporation) C:\Windows\system32\LicensingWinRT.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000699392 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_Language.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000663552 _____ (Microsoft Corporation) C:\Windows\system32\PsmServiceExtHost.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000660480 _____ (Microsoft Corporation) C:\Windows\system32\OneDriveSettingSyncProvider.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000620560 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000611840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.LowLevel.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000609792 _____ (Microsoft Corporation) C:\Windows\system32\daxexec.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000598544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NetSetupEngine.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000579072 _____ (Microsoft Corporation) C:\Windows\system32\netprofmsvc.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000568632 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000553784 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000552448 _____ (Microsoft Corporation) C:\Windows\system32\FirewallAPI.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000508208 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Enumeration.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000506880 _____ (Microsoft Corporation) C:\Windows\system32\EnterpriseAppMgmtSvc.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000505344 _____ (Microsoft Corporation) C:\Windows\system32\NetSetupShim.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000500224 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_PCDisplay.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000466432 _____ (Microsoft Corporation) C:\Windows\system32\slui.exe
2019-04-08 14:27 - 2019-04-08 14:27 - 000461112 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000450048 _____ (Microsoft Corporation) C:\Windows\system32\LockAppBroker.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000448000 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Graphics.Printing.Workflow.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000407552 _____ (Microsoft Corporation) C:\Windows\system32\rascustom.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000386360 _____ (Microsoft Corporation) C:\Windows\system32\thumbcache.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000343552 _____ (Microsoft Corporation) C:\Windows\system32\RADCUI.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000332800 _____ (Microsoft Corporation) C:\Windows\system32\NetSetupSvc.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000324096 _____ (Microsoft Corporation) C:\Windows\system32\sppcommdlg.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000322568 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000257696 _____ (Microsoft Corporation) C:\Windows\system32\sppwinob.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000246784 _____ (Microsoft Corporation) C:\Windows\system32\tetheringservice.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000241664 _____ (Microsoft Corporation) C:\Windows\system32\SharedPCCSP.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000182784 _____ (Microsoft Corporation) C:\Windows\system32\Windows.SharedPC.CredentialProvider.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000177152 _____ (Microsoft Corporation) C:\Windows\system32\LanguageComponentsInstaller.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000168448 _____ (Microsoft Corporation) C:\Windows\system32\drvinst.exe
2019-04-08 14:27 - 2019-04-08 14:27 - 000159272 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2019-04-08 14:27 - 2019-04-08 14:27 - 000149504 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.SerialCommunication.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000147496 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2019-04-08 14:27 - 2019-04-08 14:27 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000143880 _____ (Microsoft Corporation) C:\Windows\system32\NetSetupApi.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000134456 _____ (Microsoft Corporation) C:\Windows\system32\ImplatSetup.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000121344 _____ (Microsoft Corporation) C:\Windows\system32\UserDataTimeUtil.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000115360 _____ (Microsoft Corporation) C:\Windows\system32\phoneactivate.exe
2019-04-08 14:27 - 2019-04-08 14:27 - 000115200 _____ (Microsoft Corporation) C:\Windows\system32\negoexts.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000107832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NetSetupApi.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000079360 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mpsdrv.sys
2019-04-08 14:27 - 2019-04-08 14:27 - 000071208 _____ (Microsoft Corporation) C:\Windows\system32\win32appinventorycsp.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000066048 _____ (Microsoft Corporation) C:\Windows\system32\ntlanman.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000049664 _____ (Microsoft Corporation) C:\Windows\system32\cscapi.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000044544 _____ (Microsoft Corporation) C:\Windows\system32\cmintegrator.dll
2019-04-08 14:27 - 2019-04-08 14:27 - 000039736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WppRecorder.sys
2019-04-08 14:27 - 2019-04-08 14:27 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\RpcPing.exe
2019-04-08 14:27 - 2019-04-08 14:27 - 000030208 _____ (Microsoft Corporation) C:\Windows\system32\cscdll.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 017513472 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 007687576 _____ (Microsoft Corporation) C:\Windows\system32\windows.storage.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 004991112 _____ (Microsoft Corporation) C:\Windows\system32\Windows.StateRepository.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 003557888 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 003334496 _____ (Microsoft Corporation) C:\Windows\system32\combase.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 002995712 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 002592816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\combase.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 001892864 _____ (Microsoft Corporation) C:\Windows\system32\wevtsvc.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 001856000 ____R (The ICU Project) C:\Windows\system32\icuin.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 001616384 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 001567232 _____ (Microsoft Corporation) C:\Windows\system32\dosvc.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 001259320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2019-04-08 14:26 - 2019-04-08 14:26 - 001213752 _____ (Microsoft Corporation) C:\Windows\system32\drvstore.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 001191728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 001053192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ClipSp.sys
2019-04-08 14:26 - 2019-04-08 14:26 - 001022616 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 001007616 _____ (Microsoft Corporation) C:\Windows\system32\wcmsvc.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000984888 _____ (Microsoft Corporation) C:\Windows\system32\WWAHost.exe
2019-04-08 14:26 - 2019-04-08 14:26 - 000982880 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000974352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drvstore.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000877056 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.BackgroundMediaPlayback.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000874496 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Playback.BackgroundMediaPlayer.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000871792 _____ (Microsoft Corporation) C:\Windows\system32\ClipSVC.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000855040 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Playback.MediaPlayer.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000850760 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000822272 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2019-04-08 14:26 - 2019-04-08 14:26 - 000807424 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdiWiFi.sys
2019-04-08 14:26 - 2019-04-08 14:26 - 000799568 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000766480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000761280 _____ (Microsoft Corporation) C:\Windows\system32\pkeyhelper.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000757664 _____ (Microsoft Corporation) C:\Windows\system32\tcblaunch.exe
2019-04-08 14:26 - 2019-04-08 14:26 - 000756736 _____ (Microsoft Corporation) C:\Windows\system32\DolbyHrtfEnc.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000676352 _____ (Microsoft Corporation) C:\Windows\system32\AppReadiness.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000675096 _____ (Microsoft Corporation) C:\Windows\system32\StructuredQuery.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000651064 _____ (Microsoft Corporation) C:\Windows\system32\securekernel.exe
2019-04-08 14:26 - 2019-04-08 14:26 - 000580024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnsapi.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000551936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\nwifi.sys
2019-04-08 14:26 - 2019-04-08 14:26 - 000540672 _____ (Microsoft Corporation) C:\Windows\system32\winspool.drv
2019-04-08 14:26 - 2019-04-08 14:26 - 000522752 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000513040 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000506168 _____ (Microsoft Corporation) C:\Windows\system32\dcntel.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000485192 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase_enclave.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000475648 _____ (Microsoft Corporation) C:\Windows\system32\wuuhext.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000469504 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000463672 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000447488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000407504 _____ (Microsoft Corporation) C:\Windows\system32\wevtapi.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000404792 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\clfs.sys
2019-04-08 14:26 - 2019-04-08 14:26 - 000392704 _____ (Microsoft Corporation) C:\Windows\system32\domgmt.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000386872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000385024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FirewallAPI.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000384312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aepic.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000370688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NetSetupShim.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000368640 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000349184 _____ (Microsoft Corporation) C:\Windows\system32\dnsrslvr.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000343984 _____ (Microsoft Corporation) C:\Windows\system32\AudioSrvPolicyManager.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000325120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000306488 _____ (Microsoft Corporation) C:\Windows\system32\computestorage.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000300032 _____ (Microsoft Corporation) C:\Windows\system32\wc_storage.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000283032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wevtapi.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000281600 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore6.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000264704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore6.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000263680 _____ (Microsoft Corporation) C:\Windows\system32\WiFiCloudStore.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000255128 _____ (Microsoft Corporation) C:\Windows\system32\SgrmBroker.exe
2019-04-08 14:26 - 2019-04-08 14:26 - 000179712 _____ (Microsoft Corporation) C:\Windows\system32\wuuhosdeployment.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000169784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wcifs.sys
2019-04-08 14:26 - 2019-04-08 14:26 - 000165376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spacebridge.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000159112 _____ (Microsoft Corporation) C:\Windows\system32\winquic.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000157496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pdc.sys
2019-04-08 14:26 - 2019-04-08 14:26 - 000156984 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\winquic.sys
2019-04-08 14:26 - 2019-04-08 14:26 - 000119296 _____ (Microsoft Corporation) C:\Windows\system32\RjvMDMConfig.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000111104 _____ (Microsoft Corporation) C:\Windows\system32\MDMAgent.exe
2019-04-08 14:26 - 2019-04-08 14:26 - 000108032 _____ (Microsoft Corporation) C:\Windows\system32\drvsetup.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000100864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\negoexts.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000098664 _____ (Microsoft Corporation) C:\Windows\system32\mpr.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000097808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dam.sys
2019-04-08 14:26 - 2019-04-08 14:26 - 000089336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mpr.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000084480 _____ (Microsoft Corporation) C:\Windows\system32\KdsCli.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000079872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dtdump.exe
2019-04-08 14:26 - 2019-04-08 14:26 - 000048128 _____ (Microsoft Corporation) C:\Windows\system32\wcimage.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000035840 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000035640 _____ (Microsoft Corporation) C:\Windows\system32\DeviceCensus.exe
2019-04-08 14:26 - 2019-04-08 14:26 - 000002560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2019-04-08 14:26 - 2019-04-08 14:26 - 000002560 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2019-04-08 14:25 - 2019-04-08 14:25 - 002017792 _____ C:\Windows\system32\rdpnano.dll
2019-04-08 14:25 - 2019-04-08 14:25 - 000651792 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\spaceport.sys
2019-04-08 14:25 - 2019-04-08 14:25 - 000607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2019-04-08 14:25 - 2019-04-08 14:25 - 000556544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll
2019-04-08 14:25 - 2019-04-08 14:25 - 000421392 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pci.sys
2019-04-08 14:25 - 2019-04-08 14:25 - 000300344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbvideo.sys
2019-04-08 14:25 - 2019-04-08 14:25 - 000234808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netvsc.sys
2019-04-08 14:25 - 2019-04-08 14:25 - 000195896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\spacedump.sys
2019-04-08 14:25 - 2019-04-08 14:25 - 000131384 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\stornvme.sys
2019-04-08 00:21 - 2019-04-08 00:21 - 000003148 _____ C:\Windows\System32\Tasks\RogueKiller Anti-Malware
2019-04-08 00:20 - 2019-04-20 16:27 - 000000000 ____D C:\ProgramData\RogueKiller
2019-04-08 00:19 - 2019-04-08 00:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2019-04-08 00:19 - 2019-04-08 00:19 - 000000000 ____D C:\Program Files\RogueKiller
2019-04-05 16:39 - 2019-04-05 16:39 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2019-04-05 16:39 - 2019-04-05 16:39 - 000000000 ____D C:\Program Files\7-Zip
2019-04-04 21:31 - 2019-04-04 21:32 - 000017821 _____ C:\Windows\CleanMem Setup Log.txt
2019-04-04 20:38 - 2019-04-09 21:25 - 000003820 _____ C:\Windows\System32\Tasks\WpsUpdateTask_Pequeñito
2019-04-04 20:37 - 2019-04-04 20:37 - 000000000 ___HD C:\Users\Pequeñito\Documents\KingsoftData
2019-04-04 20:22 - 2019-04-04 20:26 - 000000000 ____D C:\Users\Pequeñito\AppData\Local\Kingsoft
2019-04-04 20:21 - 2019-04-05 16:45 - 000000000 ____D C:\Users\Pequeñito\AppData\Roaming\kingsoft
2019-04-04 20:21 - 2019-04-04 20:30 - 000000000 ____D C:\ProgramData\kingsoft
2019-04-03 20:31 - 2019-04-03 20:31 - 000000000 ___HD C:\Windows\msdownld.tmp
2019-04-03 20:31 - 2019-04-03 20:31 - 000000000 ____D C:\Windows\SysWOW64\directx
2019-04-03 20:30 - 2019-04-03 20:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
2019-04-03 20:29 - 2019-04-03 20:29 - 000000000 ____D C:\Program Files (x86)\K-Lite Codec Pack
2019-04-01 03:05 - 2019-04-01 03:05 - 000007602 _____ C:\Users\Pequeñito\AppData\Local\Resmon.ResmonCfg
2019-03-29 21:34 - 2019-03-29 21:34 - 000000000 ___RD C:\Users\Pequeñito\Documents\MEGAsync
2019-03-29 21:32 - 2019-03-29 21:32 - 000000000 ____D C:\Users\Pequeñito\AppData\Local\Mega Limited
2019-03-29 21:30 - 2019-03-29 21:31 - 000000000 ____D C:\Users\Pequeñito\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MEGAsync
2019-03-29 21:30 - 2019-03-29 21:31 - 000000000 ____D C:\Users\Pequeñito\AppData\Local\MEGAsync
2019-03-29 16:29 - 2019-04-11 17:52 - 000000000 ____D C:\Users\Pequeñito\Desktop\Adams 2019
2019-03-29 13:20 - 2019-03-31 19:49 - 000000000 ____D C:\Users\Pequeñito\AppData\Local\AVG
2019-03-29 13:20 - 2019-03-29 13:20 - 000000000 ____D C:\Users\Pequeñito\AppData\Local\CEF
2019-03-29 13:16 - 2019-03-29 13:16 - 000000000 ____D C:\Windows\System32\Tasks\AVG
2019-03-29 13:13 - 2019-03-29 13:13 - 000000000 ____D C:\Program Files\Common Files\AVG
2019-03-29 13:06 - 2019-03-31 19:49 - 000000000 ____D C:\ProgramData\AVG
2019-03-29 04:57 - 2019-04-14 18:51 - 000000008 __RSH C:\ProgramData\ntuser.pol
2019-03-29 04:45 - 2019-03-29 04:53 - 2377121792 _____ C:\Users\Pequeñito\Downloads\backbox-5.3-amd64.iso
2019-03-29 04:45 - 2019-03-29 04:45 - 000000000 ____D C:\Users\Pequeñito\AppData\Local\BitTorrentHelper
2019-03-27 00:40 - 2019-03-28 15:27 - 000000000 ____D C:\Users\Pequeñito\AppData\Roaming\vlc
2019-03-27 00:39 - 2019-03-27 00:39 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2019-03-27 00:37 - 2019-03-27 00:37 - 000000000 ____D C:\Program Files\VideoLAN
2019-03-23 04:38 - 2019-03-23 04:38 - 000003554 _____ C:\Windows\System32\Tasks\AMHelper
2019-03-23 04:38 - 2019-03-23 04:38 - 000000000 ____D C:\Users\Pequeñito\AppData\Local\Zemana
2019-03-23 04:38 - 2019-03-23 04:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zemana AntiMalware
2019-03-23 04:37 - 2019-04-22 19:18 - 000014999 _____ C:\Windows\ZAM.krnl.trace
2019-03-23 04:37 - 2019-04-10 19:51 - 000000000 ____D C:\Users\Pequeñito\AppData\Local\AMSDK
2019-03-23 04:37 - 2019-03-23 04:37 - 000232792 _____ (Copyright 2018.) C:\Windows\system32\Drivers\amsdk.sys
2019-03-23 04:37 - 2019-03-23 04:37 - 000000000 ____D C:\Program Files (x86)\Zemana

==================== One month (modified) ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-04-22 19:13 - 2019-03-20 04:10 - 000000214 _____ C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job
2019-04-22 19:11 - 2019-03-14 22:42 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2019-04-22 19:11 - 2018-09-15 08:09 - 000524288 _____ C:\Windows\system32\config\BBI
2019-04-22 19:10 - 2019-03-20 04:07 - 000000000 ____D C:\Windows\pss
2019-04-22 19:08 - 2018-09-15 09:33 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2019-04-22 18:03 - 2019-03-14 23:00 - 001684176 _____ C:\Windows\system32\PerfStringBackup.INI
2019-04-22 18:03 - 2018-09-15 18:37 - 000753564 _____ C:\Windows\system32\perfh00A.dat
2019-04-22 18:03 - 2018-09-15 18:37 - 000148108 _____ C:\Windows\system32\perfc00A.dat
2019-04-22 18:03 - 2018-09-15 09:31 - 000000000 ____D C:\Windows\INF
2019-04-22 15:27 - 2019-03-14 22:41 - 000000000 ____D C:\Windows\system32\SleepStudy
2019-04-22 13:43 - 2019-03-15 01:06 - 000000000 ____D C:\Windows\Minidump
2019-04-22 13:43 - 2019-03-14 22:41 - 000111104 ____N C:\Windows\Minidump\042219-59781-01.dmp
2019-04-21 22:46 - 2019-03-14 22:41 - 000111616 ____N C:\Windows\Minidump\042119-78875-01.dmp
2019-04-21 18:29 - 2019-03-14 22:41 - 000111616 ____N C:\Windows\Minidump\042119-61203-01.dmp
2019-04-21 05:30 - 2019-03-14 22:41 - 000111616 ____N C:\Windows\Minidump\042119-46718-01.dmp
2019-04-20 16:10 - 2018-09-15 09:33 - 000000000 ____D C:\Windows\AppReadiness
2019-04-20 16:09 - 2019-03-14 23:21 - 000000000 ____D C:\Users\Pequeñito\AppData\Local\Packages
2019-04-20 16:09 - 2018-09-15 09:33 - 000000000 ___HD C:\Program Files\WindowsApps
2019-04-20 15:35 - 2019-03-14 22:41 - 000111616 ____N C:\Windows\Minidump\042019-66000-01.dmp
2019-04-19 17:31 - 2019-03-14 23:17 - 000000000 ____D C:\Users\Pequeñito
2019-04-19 13:22 - 2019-03-15 18:28 - 000000000 ____D C:\Users\Pequeñito\Desktop\ProcessExplorer
2019-04-19 11:37 - 2019-03-14 23:28 - 000003374 _____ C:\Windows\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-4285004602-114342504-2893149386-1001
2019-04-19 11:36 - 2019-03-14 23:28 - 000000000 ___RD C:\Users\Pequeñito\OneDrive
2019-04-19 11:36 - 2019-03-14 23:17 - 000002448 _____ C:\Users\Pequeñito\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2019-04-14 18:38 - 2018-09-15 09:33 - 000000000 ___HD C:\Windows\system32\GroupPolicy
2019-04-14 18:38 - 2018-09-15 09:33 - 000000000 ____D C:\Windows\SysWOW64\GroupPolicy
2019-04-14 15:11 - 2019-03-14 22:41 - 000111616 _____ C:\DUMPd88d.tmp
2019-04-10 17:32 - 2018-09-15 08:09 - 000032768 _____ C:\Windows\system32\config\ELAM
2019-04-10 17:29 - 2019-03-14 22:41 - 000459944 _____ C:\Windows\system32\FNTCACHE.DAT
2019-04-10 13:18 - 2018-09-15 09:33 - 000000000 ___HD C:\Windows\ELAMBKUP
2019-04-10 02:48 - 2018-09-15 09:33 - 000000000 ____D C:\Windows\bcastdvr
2019-04-10 02:46 - 2018-09-15 09:23 - 000000000 ____D C:\Windows\CbsTemp
2019-04-10 01:40 - 2019-03-14 23:55 - 000000000 ____D C:\Windows\system32\MRT
2019-04-10 01:40 - 2019-03-14 23:54 - 131129288 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2019-04-08 23:57 - 2019-03-14 22:42 - 000000000 ____D C:\Windows\system32\Drivers\wd
2019-04-08 15:25 - 2018-09-15 09:33 - 000000000 ____D C:\Windows\SysWOW64\Dism
2019-04-08 15:24 - 2018-09-15 18:40 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2019-04-08 15:24 - 2018-09-15 09:33 - 000000000 ___SD C:\Windows\system32\DiagSvcs
2019-04-08 15:24 - 2018-09-15 09:33 - 000000000 ____D C:\Windows\system32\oobe
2019-04-08 15:24 - 2018-09-15 09:33 - 000000000 ____D C:\Windows\PolicyDefinitions
2019-04-08 15:24 - 2018-09-15 08:09 - 000000000 ____D C:\Windows\system32\Dism
2019-04-08 02:08 - 2019-03-18 23:55 - 000000000 ____D C:\Update
2019-04-07 16:39 - 2019-03-15 01:35 - 000002336 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2019-04-03 17:43 - 2018-09-15 09:33 - 000000000 ____D C:\Windows\LiveKernelReports
2019-04-01 20:02 - 2018-09-15 09:36 - 000835480 _____ (Adobe) C:\Windows\SysWOW64\FlashPlayerApp.exe
2019-04-01 20:02 - 2018-09-15 09:36 - 000179608 _____ (Adobe) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2019-03-28 05:37 - 2019-03-15 01:34 - 000003618 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2019-03-28 05:37 - 2019-03-15 01:34 - 000003494 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore

==================== Files in the root of some directories =======

2019-04-01 03:05 - 2019-04-01 03:05 - 000007602 _____ () C:\Users\Pequeñito\AppData\Local\Resmon.ResmonCfg

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)



safeboot: Minimal => The system is configured to boot to Safe Mode <==== ATTENTION

==================== BCD ================================

Administrador de arranque de Windows
----------------------------------
Identificador           {bootmgr}
device                  partition=\Device\HarddiskVolume2
description             Windows Boot Manager
locale                  es-ES
inherit                 {globalsettings}
default                 {current}
resumeobject            {ffd110a9-4698-11e9-ba6e-a0b42e1249f7}
displayorder            {current}
                        {43547433-5ba9-11e9-b8c2-90a4de9ee626}
toolsdisplayorder       {memdiag}
timeout                 30

Cargador de arranque de Windows
-----------------------------
Identificador           {43547433-5ba9-11e9-b8c2-90a4de9ee626}
device                  partition=C:
path                    \Windows\system32\winload.exe
description             Avast Antivirus Clear Uninstall
locale                  es-ES
inherit                 {bootloadersettings}
recoverysequence        {ffd110ab-4698-11e9-ba6e-a0b42e1249f7}
displaymessageoverride  CommandPrompt
recoveryenabled         Yes
allowedinmemorysettings 0x15000075
osdevice                partition=C:
systemroot              \Windows
resumeobject            {ffd110a9-4698-11e9-ba6e-a0b42e1249f7}
nx                      OptIn
bootmenupolicy          Standard

Cargador de arranque de Windows
-----------------------------
Identificador           {current}
device                  partition=C:
path                    \Windows\system32\winload.exe
description             Windows 10
locale                  es-ES
inherit                 {bootloadersettings}
recoverysequence        {ffd110ab-4698-11e9-ba6e-a0b42e1249f7}
displaymessageoverride  CommandPrompt
recoveryenabled         Yes
allowedinmemorysettings 0x15000075
osdevice                partition=C:
systemroot              \Windows
resumeobject            {ffd110a9-4698-11e9-ba6e-a0b42e1249f7}
nx                      OptIn
safeboot                Minimal
bootmenupolicy          Standard

Cargador de arranque de Windows
-----------------------------
Identificador           {ffd110ab-4698-11e9-ba6e-a0b42e1249f7}
device                  ramdisk=[\Device\HarddiskVolume2]\Recovery\WindowsRE\Winre.wim,{ffd110ac-4698-11e9-ba6e-a0b42e1249f7}
path                    \windows\system32\winload.exe
description             Windows Recovery Environment
locale                  es-es
inherit                 {bootloadersettings}
displaymessage          Recovery
osdevice                ramdisk=[\Device\HarddiskVolume2]\Recovery\WindowsRE\Winre.wim,{ffd110ac-4698-11e9-ba6e-a0b42e1249f7}
systemroot              \windows
nx                      OptIn
bootmenupolicy          Standard
winpe                   Yes

Reanudar tras hibernaci�n
-------------------------
Identificador           {ffd110a9-4698-11e9-ba6e-a0b42e1249f7}
device                  partition=C:
path                    \Windows\system32\winresume.exe
description             Windows Resume Application
locale                  es-ES
inherit                 {resumeloadersettings}
recoverysequence        {ffd110ab-4698-11e9-ba6e-a0b42e1249f7}
recoveryenabled         Yes
allowedinmemorysettings 0x15000075
filedevice              partition=C:
filepath                \hiberfil.sys
bootmenupolicy          Standard
debugoptionenabled      No

Herramienta de comprobaci�n de memoria de Windows
-------------------------------------------------
Identificador           {memdiag}
device                  partition=\Device\HarddiskVolume2
path                    \boot\memtest.exe
description             Herramienta de diagn�stico de memoria de Windows
locale                  es-ES
inherit                 {globalsettings}
badmemoryaccess         Yes

Configuraci�n de EMS
--------------------
Identificador           {emssettings}
bootems                 No

Configuraci�n del depurador
---------------------------
Identificador           {dbgsettings}
debugtype               Local

Defectos de RAM
---------------
Identificador           {badmemory}

Configuraci�n global
--------------------
Identificador           {globalsettings}
inherit                 {dbgsettings}
                        {emssettings}
                        {badmemory}

Configuraci�n del cargador de arranque
------------------------------------
Identificador           {bootloadersettings}
inherit                 {globalsettings}
                        {hypervisorsettings}

Configuraci�n de hipervisor
-------------------
Identificador           {hypervisorsettings}
hypervisordebugtype     Serial
hypervisordebugport     1
hypervisorbaudrate      115200

Reanudar la configuraci�n del cargador
--------------------------------------
Identificador           {resumeloadersettings}
inherit                 {globalsettings}

Opciones de dispositivo
-----------------------
Identificador           {ffd110ac-4698-11e9-ba6e-a0b42e1249f7}
description             Windows Recovery
ramdisksdidevice        partition=\Device\HarddiskVolume2
ramdisksdipath          \Recovery\WindowsRE\boot.sdi

==================== End of FRST.txt ============================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 22.04.2019
Ran by Pequeñito (22-04-2019 19:20:49)
Running from C:\Users\Pequeñito\Desktop
Windows 10 Pro Version 1809 17763.437 (X64) (2019-03-14 20:57:41)
Boot Mode: Safe Mode (minimal)
==========================================================


==================== Accounts: =============================

Administrador (S-1-5-21-4285004602-114342504-2893149386-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-4285004602-114342504-2893149386-503 - Limited - Disabled)
Invitado (S-1-5-21-4285004602-114342504-2893149386-501 - Limited - Disabled)
Pequeñito (S-1-5-21-4285004602-114342504-2893149386-1001 - Administrator - Enabled) => C:\Users\Pequeñito
WDAGUtilityAccount (S-1-5-21-4285004602-114342504-2893149386-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 19.00 (x64) (HKLM\...\7-Zip) (Version: 19.00 - Igor Pavlov)
Audacity 2.2.2 (HKLM-x32\...\Audacity_is1) (Version: 2.2.2 - Audacity Team)
DVBViewer Pro (HKLM-x32\...\DVBViewer Pro_is1) (Version: 6.1.4 - CM&V)
ETDWare X64 15.7.0.1_WHQL (HKLM\...\Elantech) (Version: 15.7.0.1 - ELAN Microelectronic Corp.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 73.0.3683.103 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.34.7 - Google LLC) Hidden
Java 8 Update 201 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180201F0}) (Version: 8.0.2010.9 - Oracle Corporation)
K-Lite Codec Pack 14.8.8 Full (HKLM-x32\...\KLiteCodecPack_is1) (Version: 14.8.8 - KLCP)
LibreOffice 6.2.2.2 (HKLM\...\{7B486711-D8E3-41F4-A518-D709CD62C3D1}) (Version: 6.2.2.2 - The Document Foundation)
MEGAsync (HKLM-x32\...\MEGAsync) (Version:  - Mega Limited)
Microsoft OneDrive (HKU\S-1-5-21-4285004602-114342504-2893149386-1001\...\OneDriveSetup.exe) (Version: 19.043.0304.0007 - Microsoft Corporation)
MP3 Audio Converter 5.01 (HKLM-x32\...\MP3 Audio Converter_is1) (Version:  - EZ SoftMagic, Inc.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7543 - Realtek Semiconductor Corp.)
Revo Uninstaller Pro 4.0.5 (HKLM\...\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 4.0.5 - VS Revo Group, Ltd.)
RogueKiller versión 13.1.9.0 (HKLM\...\8B3D7924-ED89-486B-8322-E8594065D5CB_is1) (Version: 13.1.9.0 - Adlice Software)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.6 - VideoLAN)
Zemana AntiMalware versión 3.1.0 (HKLM-x32\...\{4E1F3677-C72E-4F7D-B66E-85467B1A289E}_is1) (Version: 3.1.0 - Zemana)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-4285004602-114342504-2893149386-1001_Classes\CLSID\{0B680B4D-1E6B-4C2D-ACFC-EDFF466201F7} -> [MEGAsync] => C:\Users\Pequeñito\Documents\MEGAsync [2019-03-29 21:34]
ShellIconOverlayIdentifiers: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Pequeñito\AppData\Local\MEGAsync\ShellExtX64.dll [2019-02-08] (Mega Limited -> )
ShellIconOverlayIdentifiers-x32: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Pequeñito\AppData\Local\MEGAsync\ShellExtX64.dll [2019-02-08] (Mega Limited -> )
ShellIconOverlayIdentifiers-x32: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Pequeñito\AppData\Local\MEGAsync\ShellExtX64.dll [2019-02-08] (Mega Limited -> )
ShellIconOverlayIdentifiers-x32: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Pequeñito\AppData\Local\MEGAsync\ShellExtX64.dll [2019-02-08] (Mega Limited -> )
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [File not signed]
ContextMenuHandlers1: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Pequeñito\AppData\Local\MEGAsync\ShellExtX64.dll [2019-02-08] (Mega Limited -> )
ContextMenuHandlers2: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Pequeñito\AppData\Local\MEGAsync\ShellExtX64.dll [2019-02-08] (Mega Limited -> )
ContextMenuHandlers3: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Pequeñito\AppData\Local\MEGAsync\ShellExtX64.dll [2019-02-08] (Mega Limited -> )
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [File not signed]
ContextMenuHandlers4: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Pequeñito\AppData\Local\MEGAsync\ShellExtX64.dll [2019-02-08] (Mega Limited -> )
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [File not signed]
ContextMenuHandlers6: [RUShellExt] -> {2C5515DC-2A7E-4BFD-B813-CACC2B685EB7} => C:\Program Files\VS Revo Group\Revo Uninstaller Pro\RUExt.dll [2018-09-06] (VS Revo Group Ltd. -> VS Revo Group)
ContextMenuHandlers1_.DEFAULT: [          qingshellext] -> {67F4D210-BFC2-4ADD-9A2A-C9B9E1F42C4F} =>  -> No File
ContextMenuHandlers4_.DEFAULT: [          qingshellext] -> {67F4D210-BFC2-4ADD-9A2A-C9B9E1F42C4F} =>  -> No File
ContextMenuHandlers5_.DEFAULT: [          qingshellext] -> {67F4D210-BFC2-4ADD-9A2A-C9B9E1F42C4F} =>  -> No File

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


==================== Loaded Modules (Whitelisted) ==============

2019-04-05 16:39 - 2019-02-21 18:00 - 000078336 _____ (Igor Pavlov) [File not signed] C:\Program Files\7-Zip\7-zip.dll
2019-03-15 01:21 - 2019-03-15 01:22 - 032393728 _____ (Dolby) [File not signed] C:\Program Files\WindowsApps\DolbyLaboratories.DolbyAccess_2.4.521.0_x64__rz1tebttyb220\DolbyUWP.dll
2019-03-15 01:21 - 2019-03-15 01:22 - 000948736 _____ () [File not signed] C:\Program Files\WindowsApps\DolbyLaboratories.DolbyAccess_2.4.521.0_x64__rz1tebttyb220\e_sqlite3.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\08732547.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\50131895.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\50551004.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\87063515.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\amsdk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DrWebEngine => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TKFsAvM => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TKFsFtM => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TKPcFt => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TKRgAc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TKRgFt => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\08732547.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\50131895.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\50551004.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\87063515.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\amsdk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DrWebEngine => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TKFsAvM => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TKFsFtM => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TKPcFt => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TKRgAc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TKRgFt => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="1"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2018-09-15 09:31 - 2019-04-22 17:50 - 000000027 _____ C:\Windows\system32\drivers\etc\hosts

127.0.0.1       localhost

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path: C:\Program Files (x86)\Common Files\Oracle\Java\javapath;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\
HKU\S-1-5-21-4285004602-114342504-2893149386-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Windows\img0.jpg
DNS Servers: Media is not connected to internet.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )

==================== MSCONFIG/TASK MANAGER disabled items ==

If an entry is included in the fixlist, it will be removed.

HKLM\...\StartupApproved\Run: => "SpIDerAgent"
HKU\S-1-5-21-4285004602-114342504-2893149386-1001\...\StartupApproved\StartupFolder: => "MEGAsync.lnk"
HKU\S-1-5-21-4285004602-114342504-2893149386-1001\...\StartupApproved\Run: => "OneDrive"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [TCP Query User{97A23619-32A3-46E4-B91D-911938BC0256}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe (Google LLC -> Google Inc.)
FirewallRules: [UDP Query User{17506993-50E4-456E-9D35-AF27904536B2}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe (Google LLC -> Google Inc.)
FirewallRules: [TCP Query User{3BD3A2AD-3A9C-4A58-B6B1-5802DF8104A7}C:\program files (x86)\google\chrome\application\chrome.exe] => (Block) C:\program files (x86)\google\chrome\application\chrome.exe (Google LLC -> Google Inc.)
FirewallRules: [UDP Query User{6EB21115-ECB1-4D27-BACE-A998DCB535C1}C:\program files (x86)\google\chrome\application\chrome.exe] => (Block) C:\program files (x86)\google\chrome\application\chrome.exe (Google LLC -> Google Inc.)
FirewallRules: [TCP Query User{D96F172C-2051-44DB-9058-68403AE30FEE}C:\program files (x86)\dvbviewer\dvbviewer.exe] => (Allow) C:\program files (x86)\dvbviewer\dvbviewer.exe (Christian Hackbart -> CM&V Hackbart)
FirewallRules: [UDP Query User{19C47124-FED9-4568-9FF8-A25A0C37B340}C:\program files (x86)\dvbviewer\dvbviewer.exe] => (Allow) C:\program files (x86)\dvbviewer\dvbviewer.exe (Christian Hackbart -> CM&V Hackbart)

==================== Restore Points =========================

10-04-2019 16:23:56 Removed Avast Driver Updater
10-04-2019 17:07:48 Installed LibreOffice 6.2.2.2
19-04-2019 12:06:49 JRT Pre-Junkware Removal

==================== Faulty Device Manager Devices =============

Name: Realtek High Definition Audio
Description: Realtek High Definition Audio
Class Guid: {4d36e96c-e325-11ce-bfc1-08002be10318}
Manufacturer: Realtek
Service: IntcAzAudAddService
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver

Name: Controlador de infraestructura de virtualización de Microsoft Hyper-V
Description: Controlador de infraestructura de virtualización de Microsoft Hyper-V
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: Vid
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver

Name: Realtek PCIe FE Family Controller
Description: Controladora Realtek PCIe FE Family
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Realtek
Service: rt640x64
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: =========================

Application errors:
==================
Error: (04/22/2019 06:14:59 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
hr=0x803F7001
Argumentos de línea de comandos:
RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=NetworkAvailable

Error: (04/22/2019 05:58:39 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
hr=0x803F7001
Argumentos de línea de comandos:
RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=UserLogon;SessionId=1

Error: (04/22/2019 01:44:49 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
hr=0x803F7001
Argumentos de línea de comandos:
RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=NetworkAvailable

Error: (04/22/2019 01:44:48 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
hr=0x803F7001
Argumentos de línea de comandos:
RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=UserLogon;SessionId=1

Error: (04/21/2019 10:47:58 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
hr=0x803F7001
Argumentos de línea de comandos:
RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=NetworkAvailable

Error: (04/21/2019 10:47:58 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
hr=0x803F7001
Argumentos de línea de comandos:
RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=UserLogon;SessionId=1

Error: (04/21/2019 07:58:07 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
hr=0x803F7001
Argumentos de línea de comandos:
RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=UserLogon;SessionId=2

Error: (04/21/2019 07:57:30 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
hr=0x8007139F
Argumentos de línea de comandos:
RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=NetworkAvailable
    System errors:
    =============
    Error: (04/22/2019 07:23:16 PM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY)
    Description: Error de DCOM "1084" al intentar iniciar el servicio EventSystem con argumentos "No disponible" para ejecutar el servidor:
    {1BE1F766-5536-11D1-B726-00C04FB926AF}

    Error: (04/22/2019 07:22:50 PM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY)
    Description: Error de DCOM "1084" al intentar iniciar el servicio netprofm con argumentos "No disponible" para ejecutar el servidor:
    {A47979D2-C419-11D9-A5B4-001185AD2B89}

    Error: (04/22/2019 07:22:49 PM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY)
    Description: Error de DCOM "1084" al intentar iniciar el servicio wuauserv con argumentos "No disponible" para ejecutar el servidor:
    {E60687F7-01A1-40AA-86AC-DB1CBF673334}

    Error: (04/22/2019 07:22:49 PM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY)
    Description: Error de DCOM "1084" al intentar iniciar el servicio wuauserv con argumentos "No disponible" para ejecutar el servidor:
    {E60687F7-01A1-40AA-86AC-DB1CBF673334}

    Error: (04/22/2019 07:22:49 PM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY)
    Description: Error de DCOM "1084" al intentar iniciar el servicio netprofm con argumentos "No disponible" para ejecutar el servidor:
    {A47979D2-C419-11D9-A5B4-001185AD2B89}

    Error: (04/22/2019 07:22:49 PM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY)
    Description: Error de DCOM "1084" al intentar iniciar el servicio netprofm con argumentos "No disponible" para ejecutar el servidor:
    {A47979D2-C419-11D9-A5B4-001185AD2B89}

    Error: (04/22/2019 07:22:48 PM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY)
    Description: Error de DCOM "1084" al intentar iniciar el servicio UsoSvc con argumentos "No disponible" para ejecutar el servidor:
    {B91D5831-B1BD-4608-8198-D72E155020F7}

    Error: (04/22/2019 07:22:48 PM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY)
    Description: Error de DCOM "1084" al intentar iniciar el servicio netprofm con argumentos "No disponible" para ejecutar el servidor:
    {A47979D2-C419-11D9-A5B4-001185AD2B89}


    Windows Defender:
    ===================================
    Date: 2019-04-22 19:08:25.110
    Description: 
    El examen de Antivirus de Windows Defender se detuvo antes de completarse.
    Id. de examen: {0D8312DF-B32F-45AD-BA8B-D41062B6B7A1}
    Tipo de examen: Antimalware
    Parámetros de examen: Examen rápido
    Usuario: NT AUTHORITY\SYSTEM

    Date: 2019-04-22 18:53:22.715
    Description: 
    El examen de Antivirus de Windows Defender se detuvo antes de completarse.
    Id. de examen: {489C92AD-40C0-42CB-8C7B-6EBD098DBC0F}
    Tipo de examen: Antimalware
    Parámetros de examen: Examen rápido
    Usuario: NT AUTHORITY\SYSTEM

    Date: 2019-04-19 17:29:33.733
    Description: 
    El examen de Antivirus de Windows Defender se detuvo antes de completarse.
    Id. de examen: {DE02DBC6-3DF1-424D-B408-2A32E5396D59}
    Tipo de examen: Antimalware
    Parámetros de examen: Examen rápido
    Usuario: NT AUTHORITY\SYSTEM

    Date: 2019-04-16 21:08:19.156
    Description: 
    El examen de Antivirus de Windows Defender se detuvo antes de completarse.
    Id. de examen: {CBF8AF8D-13D6-4685-9F47-DDA9700DF421}
    Tipo de examen: Antimalware
    Parámetros de examen: Examen rápido
    Usuario: NT AUTHORITY\SYSTEM

    Date: 2019-04-16 19:44:11.764
    Description: 
    El examen de Antivirus de Windows Defender se detuvo antes de completarse.
    Id. de examen: {766F555D-69EA-4778-A7E4-E6FDA29823BA}
    Tipo de examen: Antimalware
    Parámetros de examen: Examen rápido
    Usuario: NT AUTHORITY\SYSTEM

    Date: 2019-04-22 19:22:49.903
    Description: 
    Antivirus de Windows Defender encontró un error al intentar actualizar las firmas.
    Nueva versión de firma: 
    Versión de firma anterior: 1.291.2476.0
    Origen de actualización: Servidor de Microsoft Update
    Tipo de firma: AntiVirus
    Tipo de actualización: Completa
    Usuario: NT AUTHORITY\SYSTEM
    Versión de motor actual: 
    Versión de motor anterior: 1.1.15800.1
    Código de error: 0x8007043c
    Descripción del error: El servicio no puede iniciarse en modo a prueba de errores 

    Date: 2019-04-22 19:12:38.466
    Description: 
    La característica Protección en tiempo real de Antivirus de Windows Defender encontró un error:
    Característica: Durante el acceso
    Código de error: 0x8007043c
    Descripción del error: El servicio no puede iniciarse en modo a prueba de errores 
    Motivo: La protección antimalware dejó de funcionar por motivos desconocidos. En algunos casos, reiniciar el servicio puede que resuelva el problema.

    Date: 2019-04-22 17:53:08.466
    Description: 
    La característica Protección en tiempo real de Antivirus de Windows Defender encontró un error:
    Característica: Durante el acceso
    Código de error: 0x8007043c
    Descripción del error: El servicio no puede iniciarse en modo a prueba de errores 
    Motivo: La protección antimalware dejó de funcionar por motivos desconocidos. En algunos casos, reiniciar el servicio puede que resuelva el problema.

    Date: 2019-04-22 17:42:06.813
    Description: 
    La característica Protección en tiempo real de Antivirus de Windows Defender encontró un error:
    Característica: Durante el acceso
    Código de error: 0x8007043c
    Descripción del error: El servicio no puede iniciarse en modo a prueba de errores 
    Motivo: La protección antimalware dejó de funcionar por motivos desconocidos. En algunos casos, reiniciar el servicio puede que resuelva el problema.

    Date: 2019-04-19 19:08:53.456
    Description: 
    Antivirus de Windows Defender encontró un error al intentar actualizar las firmas.
    Nueva versión de firma: 
    Versión de firma anterior: 1.291.2272.0
    Origen de actualización: Servidor de Microsoft Update
    Tipo de firma: AntiVirus
    Tipo de actualización: Completa
    Usuario: NT AUTHORITY\SYSTEM
    Versión de motor actual: 
    Versión de motor anterior: 1.1.15800.1
    Código de error: 0x8007043c
    Descripción del error: El servicio no puede iniciarse en modo a prueba de errores 

    CodeIntegrity:
    ===================================

    Date: 2019-03-18 14:34:27.064
    Description: 
    Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\NANO Antivirus\bin\nanoav.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2019-03-18 14:34:25.287
    Description: 
    Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\NANO Antivirus\bin\nanoav.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2019-03-18 14:34:24.193
    Description: 
    Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\NANO Antivirus\bin\nanoav.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2019-03-18 14:34:23.348
    Description: 
    Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\NANO Antivirus\bin\nanoav.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    ==================== Memory info =========================== 

    BIOS: Phoenix Technologies Ltd. 01VG.M013.20110704.RHU 07/04/2011
    Motherboard: SAMSUNG ELECTRONICS CO., LTD. NC210/NC110
    Processor: Intel(R) Atom(TM) CPU N570 @ 1.66GHz
    Percentage of memory in use: 48%
    Total physical RAM: 2037.29 MB
    Available physical RAM: 1050.93 MB
    Total Virtual: 3125.29 MB
    Available Virtual: 2244.47 MB

    ==================== Drives ================================

    Drive c: () (Fixed) (Total:297.46 GB) (Free:255.13 GB) NTFS
    Drive d: (Reservado para el sistema) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[system with boot components (obtained from drive)]

    \\?\Volume{1797b1cb-0000-0000-0000-500600000000}\ (Reservado para el sistema) (Fixed) (Total:0.54 GB) (Free:0.11 GB) NTFS

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (MBR Code: Windows 7/8/10) (Size: 298.1 GB) (Disk ID: 1797B1CB)
    Partition 1: (Not Active) - (Size=100 MB) - (Type=07 NTFS)
    Partition 2: (Active) - (Size=549 MB) - (Type=07 NTFS)
    Partition 3: (Not Active) - (Size=297.5 GB) - (Type=07 NTFS)

    ==================== End of Addition.txt ============================

buenas, el siguiente paso a seguir… ?.

Hola

Antes de realizar el paso que te voy a indicar, guarda todos los archivos que tengas importantes en tu equipo, como tienes un Windows pirata no sabemos como puede reaccionar, es un paso que en un Windows legal no pasaría nada, pero en tu caso ante la duda mejor prevenir.

Ve a Inicio >> Sistema de Windows >> botón derecho sobre Símbolo de sistema >> (Ejecutar como Administrador) escribe:

bcdedit.exe /delete {43547433-5ba9-11e9-b8c2-90a4de9ee626}

Dale a Enter y esperas a que termine y compruebas si ya no da la opción de elegir en el arranque.

Comenta como ha ido.

Un saludo

Pues la acabo de liar parda, he enviado todo lo que tenía a un usb de más de 100gb bien, se ha copiado o eso me mostraba dentro del usb y cuando he abierto el usb solo tenía las carpetas vacías y luego me han desaparecido . no comprendo que copie archivos al usb y me haga una copia fantasma y no copie nada mostrando el transcurso de transferencia de datos, con la tontería ahora tengo que recuperarlo aún así sin tener los archivos en el usb. No me lo explico

confio en su ayuda para este nuevo reto, como para mi. Ya que acabo de perder o en teoría los archivos que necesito para estudiar mi oposición.

gracias, espero una pronta respuesta. Bueno, voy a reiniciar a ver si ha hecho algo eso o sigue encima igual.

la línea de códio parece que ha solucionado eso, ahora toca los archivos, y esperar que no vuelva a salir lo otro…