Addition.txt Parte 2 de 2
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
Shortcut: C:\Users\Usuario\Favorites\NCH Software Download Site.lnk -> hxxp://www.nchsoftware.com/index.htm
==================== Loaded Modules (Whitelisted) ==============
2013-12-06 16:06 - 2013-12-06 16:06 - 000214528 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.PerformanceTuning.dll
2013-07-26 05:59 - 2013-07-26 05:59 - 000814592 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Device.dll
2013-07-26 05:59 - 2013-07-26 05:59 - 003650560 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Platform.dll
2017-10-18 18:51 - 2017-10-18 18:51 - 000598528 _____ () C:\Users\Usuario\AppData\Local\MEGAsync\ShellExtX64.dll
2014-02-20 22:53 - 2018-09-10 12:38 - 000095168 _____ () C:\Program Files\CCleaner\lang\lang-1034.dll
2014-11-08 14:13 - 2016-03-09 16:18 - 000025088 _____ () C:\Program Files\SAMSUNG\Samsung Link\JniSys.dll
2014-11-08 14:13 - 2016-03-09 16:18 - 002513920 _____ () C:\Program Files\SAMSUNG\Samsung Link\scone_proxy.dll
2014-11-08 14:13 - 2016-03-09 16:18 - 002436096 _____ () C:\Program Files\SAMSUNG\Samsung Link\scone_stub.dll
2013-12-21 11:25 - 2013-12-21 11:25 - 000036864 _____ () C:\Program Files\SAMSUNG\AllShare Framework DMS\1.3.23\64bit\JNIInterface.dll
2013-12-21 11:26 - 2013-12-21 11:26 - 000144384 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\64bit\ASFAPI.dll
2013-12-21 11:27 - 2013-12-21 11:27 - 000018944 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\64bit\MediaDB_Manager.dll
2013-10-22 09:52 - 2013-10-22 09:52 - 000030720 _____ () C:\Windows\system32\MediaDB64.dll
2013-10-22 09:52 - 2013-10-22 09:52 - 000908800 _____ () C:\Windows\system32\ContentDirectoryPresenter64.dll
2013-12-21 11:27 - 2013-12-21 11:27 - 000521728 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\64bit\DMS_Manager.dll
2013-07-23 19:19 - 2013-07-23 19:19 - 000049152 _____ () C:\Windows\system32\boost_date_time-vc90-mt-1_47.dll
2013-07-23 19:19 - 2013-07-23 19:19 - 000016896 _____ () C:\Windows\system32\boost_system-vc90-mt-1_47.dll
2013-07-23 19:19 - 2013-07-23 19:19 - 000058880 _____ () C:\Windows\system32\boost_thread-vc90-mt-1_47.dll
2013-07-23 19:19 - 2013-07-23 19:19 - 000299520 _____ () C:\Windows\system32\boost_serialization-vc90-mt-1_47.dll
2016-04-25 13:18 - 2016-04-25 13:18 - 000669696 ____N () C:\Windows\Temp\sqlite-3.7.151-amd64-sqlitejdbc.dll
2013-12-11 16:46 - 2013-12-11 16:46 - 001114624 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\DMSManager.dll
2013-10-22 09:48 - 2013-10-22 09:48 - 000707072 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\ContentDirectoryPresenter.dll
2013-10-24 16:53 - 2013-10-24 16:53 - 000107008 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\DCMCDP.dll
2013-12-11 16:46 - 2013-12-11 16:46 - 000102400 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\FolderCDP.dll
2013-12-11 16:46 - 2013-12-11 16:46 - 000077312 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\MetadataFramework.dll
2013-02-14 19:42 - 2013-02-14 19:42 - 000520234 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\sqlite3.dll
2013-02-14 19:42 - 2013-02-14 19:42 - 000450560 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\MoodExtractor.dll
2013-02-14 19:42 - 2013-02-14 19:42 - 005717504 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\DCMImgExtractor.dll
2013-10-25 19:48 - 2013-10-25 19:48 - 000028672 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AutoChaptering.dll
2013-02-14 19:42 - 2013-02-14 19:42 - 000147456 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\libexpat.dll
2013-10-25 19:48 - 2013-10-25 19:48 - 000012288 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\VideoThumb.dll
2013-02-14 19:42 - 2013-02-14 19:42 - 004671488 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\avcodec-52.dll
2013-02-14 19:42 - 2013-02-14 19:42 - 000070656 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\avutil-50.dll
2013-02-14 19:42 - 2013-02-14 19:42 - 000686080 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\avformat-52.dll
2013-02-14 19:42 - 2013-02-14 19:42 - 000152064 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\swscale-0.dll
2013-10-25 19:49 - 2013-10-25 19:49 - 000028160 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AudioExtractor.dll
2013-10-25 19:48 - 2013-10-25 19:48 - 000064000 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\ID3Driver.dll
2013-02-14 19:42 - 2013-02-14 19:42 - 000366592 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\tag.dll
2013-10-25 19:48 - 2013-10-25 19:48 - 000289792 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\libThumbnail.dll
2013-10-25 19:48 - 2013-10-25 19:48 - 000023040 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\RichInfoDriver.dll
2013-12-11 16:45 - 2013-12-11 16:45 - 000017920 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\VideoExtractor.dll
2013-10-25 19:53 - 2013-10-25 19:53 - 000117248 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\ThumbnailMaker.dll
2013-10-25 19:53 - 2013-10-25 19:53 - 001033728 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\ImageMagickWrapper.dll
2013-12-11 16:45 - 2013-12-11 16:45 - 000134144 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\VideoMetadataDriver.dll
2013-10-25 19:48 - 2013-10-25 19:48 - 000290816 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\libKeyFrame.dll
2013-10-25 19:48 - 2013-10-25 19:48 - 000024064 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\SECMetaDriver.dll
2013-10-25 19:53 - 2013-10-25 19:53 - 000012288 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\ImageExtractor.dll
2013-10-25 19:48 - 2013-10-25 19:48 - 000024064 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\photoDriver.dll
2013-02-14 19:42 - 2013-02-14 19:42 - 000399826 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\libexif-12.dll.dll
2013-10-25 19:48 - 2013-10-25 19:48 - 000013824 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\TextExtractor.dll
2013-10-24 16:53 - 2013-10-24 16:53 - 000032768 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\Autobackup.dll
2013-04-19 16:38 - 2013-04-19 16:38 - 000055808 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\RosettaAllShare.dll
2013-07-23 19:18 - 2013-07-23 19:18 - 000227840 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\boost_serialization-vc90-mt-1_47.dll
2013-07-23 19:18 - 2013-07-23 19:18 - 000038912 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\boost_date_time-vc90-mt-1_47.dll
2013-07-23 19:18 - 2013-07-23 19:18 - 000012800 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\boost_system-vc90-mt-1_47.dll
2013-07-23 19:18 - 2013-07-23 19:18 - 000046592 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\boost_thread-vc90-mt-1_47.dll
2013-02-14 19:42 - 2013-02-14 19:42 - 000044032 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\us.dll
2018-12-02 20:36 - 2018-12-02 20:36 - 000919256 _____ () C:\Program Files\AVAST Software\Avast\anen.dll
2018-12-02 20:36 - 2018-12-02 20:36 - 000596696 _____ () C:\Program Files\AVAST Software\Avast\streamback.dll
2018-12-12 20:31 - 2018-12-12 20:31 - 005786256 _____ () C:\Program Files\AVAST Software\Avast\defs\18121204\algo.dll
2018-12-02 20:36 - 2018-12-02 20:36 - 000496344 _____ () C:\Program Files\AVAST Software\Avast\gui_cache.dll
2018-12-02 20:36 - 2018-12-02 20:36 - 001112280 _____ () C:\Program Files\AVAST Software\Avast\shepherdsync.dll
2013-12-06 15:53 - 2013-12-06 15:53 - 000094208 _____ () C:\Program Files (x86)\ATI Technologies\HydraVision\HydraEsp.dll
2017-10-18 18:58 - 2017-10-18 18:58 - 000570368 _____ () C:\Users\Usuario\AppData\Local\MEGAsync\ShellExtX32.dll
2018-11-03 09:55 - 2018-11-03 09:55 - 067126928 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2018-12-12 18:23 - 2018-12-12 09:42 - 001140552 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_watchdog.dll
2018-12-12 18:23 - 2018-12-12 09:42 - 002103112 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_crashpad.dll
2018-12-12 18:23 - 2018-12-12 09:44 - 000023376 _____ () C:\Program Files (x86)\Dropbox\Client\tornado.speedups.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:43 - 000025456 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._constant_time.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:42 - 000148968 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_backend.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:43 - 001878888 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._openssl.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:43 - 000025960 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._padding.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:42 - 000118232 _____ () C:\Program Files (x86)\Dropbox\Client\pywintypes36.dll
2018-12-12 18:23 - 2018-12-12 09:42 - 000109024 _____ () C:\Program Files (x86)\Dropbox\Client\win32api.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:43 - 000082760 _____ () C:\Program Files (x86)\Dropbox\Client\fastpath.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:42 - 000418776 _____ () C:\Program Files (x86)\Dropbox\Client\pythoncom36.dll
2018-12-12 18:23 - 2018-12-12 09:43 - 000074072 _____ () C:\Program Files (x86)\Dropbox\Client\psutil._psutil_windows.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:42 - 000027616 _____ () C:\Program Files (x86)\Dropbox\Client\win32event.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:42 - 000049128 _____ () C:\Program Files (x86)\Dropbox\Client\win32process.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:42 - 000026600 _____ () C:\Program Files (x86)\Dropbox\Client\win32clipboard.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:42 - 000131552 _____ () C:\Program Files (x86)\Dropbox\Client\win32file.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:42 - 000182752 _____ () C:\Program Files (x86)\Dropbox\Client\win32gui.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:42 - 000027616 _____ () C:\Program Files (x86)\Dropbox\Client\win32pipe.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:42 - 000119272 _____ () C:\Program Files (x86)\Dropbox\Client\win32security.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:44 - 000401752 _____ () C:\Program Files (x86)\Dropbox\Client\win32com.shell.shell.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:42 - 000028640 _____ () C:\Program Files (x86)\Dropbox\Client\win32job.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:44 - 000034664 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.kernel32.compiled._winffi_kernel32.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:44 - 000062304 _____ () C:\Program Files (x86)\Dropbox\Client\winshell.compiled._winshell.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:42 - 000023520 _____ () C:\Program Files (x86)\Dropbox\Client\mmapfile.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:42 - 000053736 _____ () C:\Program Files (x86)\Dropbox\Client\win32service.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:42 - 000065504 _____ () C:\Program Files (x86)\Dropbox\Client\win32evtlog.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:43 - 000025944 _____ () C:\Program Files (x86)\Dropbox\Client\cpuid.compiled._cpuid.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:44 - 000068968 _____ () C:\Program Files (x86)\Dropbox\Client\winenumhandles.compiled._WinEnumHandles.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:44 - 000028520 _____ () C:\Program Files (x86)\Dropbox\Client\winscreenshot.compiled._CaptureScreenshot.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:43 - 000027488 _____ () C:\Program Files (x86)\Dropbox\Client\crashpad.compiled._Crashpad.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:42 - 000032224 _____ () C:\Program Files (x86)\Dropbox\Client\win32ts.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:43 - 000156504 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngineWidgets.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:43 - 000092496 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt562.sip.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:43 - 001778000 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtCore.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:43 - 000518992 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtNetwork.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:43 - 000052056 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngineCore.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:43 - 001929552 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtGui.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:43 - 003821392 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWidgets.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:43 - 000044888 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebChannel.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:43 - 000132944 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKit.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:43 - 000218456 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKitWidgets.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:43 - 000205656 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtPrintSupport.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:42 - 000061408 _____ () C:\Program Files (x86)\Dropbox\Client\win32print.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:44 - 000051552 _____ () C:\Program Files (x86)\Dropbox\Client\winrpcserver.compiled._RPCServer.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:42 - 000027624 _____ () C:\Program Files (x86)\Dropbox\Client\win32profile.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:44 - 000033632 _____ () C:\Program Files (x86)\Dropbox\Client\winreindex.compiled._winreindex.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:44 - 000028008 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.user32.compiled._winffi_user32.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:44 - 000025960 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.iphlpapi.compiled._winffi_iphlpapi.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:44 - 000025448 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winerror.compiled._winffi_winerror.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:44 - 000025960 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.wininet.compiled._winffi_wininet.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:43 - 000031600 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox.infinite.win.compiled._driverinstallation.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:42 - 000486880 _____ () C:\Program Files (x86)\Dropbox\Client\winxpgui.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:44 - 000029040 _____ () C:\Program Files (x86)\Dropbox\Client\winverifysignature.compiled._VerifySignature.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:43 - 011820368 _____ () C:\Program Files (x86)\Dropbox\Client\nucleus_python.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:43 - 000029024 _____ () C:\Program Files (x86)\Dropbox\Client\librsyncffi.compiled._librsyncffi.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:42 - 000036312 _____ () C:\Program Files (x86)\Dropbox\Client\librsync.dll
2018-12-12 18:23 - 2018-12-12 09:44 - 000025960 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.advapi32.compiled._winffi_advapi32.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:43 - 000433992 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_sqlite_ext.DLL
2018-12-12 18:23 - 2018-12-12 09:44 - 000038240 _____ () C:\Program Files (x86)\Dropbox\Client\wind3d11.compiled._wind3d11.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:43 - 000025920 _____ () C:\Program Files (x86)\Dropbox\Client\libEGL.DLL
2018-12-12 18:23 - 2018-12-12 09:43 - 001592128 _____ () C:\Program Files (x86)\Dropbox\Client\libGLESv2.dll
2018-12-12 18:23 - 2018-12-12 09:44 - 000029544 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.shell32.compiled._winffi_shell32.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:44 - 000241488 _____ () C:\Program Files (x86)\Dropbox\Client\windragdrop.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:43 - 000102736 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWinExtras.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:44 - 000025448 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.gdi32.compiled._winffi_gdi32.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:43 - 000037200 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngine.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:44 - 000029544 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winhttp.compiled._winffi_winhttp.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:43 - 000530768 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQuick.cp36-win32.pyd
2018-12-12 18:23 - 2018-12-12 09:43 - 000348496 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQml.cp36-win32.pyd
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\ProgramData\Temp:56E2E879 [118]
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
HKU\S-1-5-21-2385482525-178760063-3032261430-1000\Software\Classes\.scr: AutoCADScriptFile => C:\Windows\system32\notepad.exe "%1"
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
IE restricted site: HKU\.DEFAULT\...\007guard.com -> install.007guard.com
IE restricted site: HKU\.DEFAULT\...\008i.com -> 008i.com
IE restricted site: HKU\.DEFAULT\...\008k.com -> www.008k.com
IE restricted site: HKU\.DEFAULT\...\00hq.com -> www.00hq.com
IE restricted site: HKU\.DEFAULT\...\010402.com -> 010402.com
IE restricted site: HKU\.DEFAULT\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\.DEFAULT\...\0scan.com -> www.0scan.com
IE restricted site: HKU\.DEFAULT\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\.DEFAULT\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\.DEFAULT\...\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\.DEFAULT\...\1001namen.com -> www.1001namen.com
IE restricted site: HKU\.DEFAULT\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\.DEFAULT\...\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\.DEFAULT\...\10sek.com -> www.10sek.com
IE restricted site: HKU\.DEFAULT\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\.DEFAULT\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\.DEFAULT\...\123fporn.info -> www.123fporn.info
IE restricted site: HKU\.DEFAULT\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\.DEFAULT\...\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\.DEFAULT\...\123simsen.com -> www.123simsen.com
There are 7865 more sites.
IE trusted site: HKU\S-1-5-21-2385482525-178760063-3032261430-1000\...\localhost -> localhost
IE restricted site: HKU\S-1-5-21-2385482525-178760063-3032261430-1000\...\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-2385482525-178760063-3032261430-1000\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-2385482525-178760063-3032261430-1000\...\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-2385482525-178760063-3032261430-1000\...\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-2385482525-178760063-3032261430-1000\...\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-2385482525-178760063-3032261430-1000\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-2385482525-178760063-3032261430-1000\...\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-2385482525-178760063-3032261430-1000\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\S-1-5-21-2385482525-178760063-3032261430-1000\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-2385482525-178760063-3032261430-1000\...\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\S-1-5-21-2385482525-178760063-3032261430-1000\...\1001namen.com -> www.1001namen.com
IE restricted site: HKU\S-1-5-21-2385482525-178760063-3032261430-1000\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\S-1-5-21-2385482525-178760063-3032261430-1000\...\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\S-1-5-21-2385482525-178760063-3032261430-1000\...\10sek.com -> www.10sek.com
IE restricted site: HKU\S-1-5-21-2385482525-178760063-3032261430-1000\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\S-1-5-21-2385482525-178760063-3032261430-1000\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\S-1-5-21-2385482525-178760063-3032261430-1000\...\123fporn.info -> www.123fporn.info
IE restricted site: HKU\S-1-5-21-2385482525-178760063-3032261430-1000\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\S-1-5-21-2385482525-178760063-3032261430-1000\...\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\S-1-5-21-2385482525-178760063-3032261430-1000\...\123simsen.com -> www.123simsen.com
There are 7865 more sites.
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-13 23:34 - 2017-08-25 18:36 - 000450575 ____R C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 1000gratisproben.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1001namen.com
127.0.0.1 www.1001namen.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com
127.0.0.1 www.100sexlinks.com
127.0.0.1 100sexlinks.com
127.0.0.1 10sek.com
127.0.0.1 www.10sek.com
127.0.0.1 www.1-2005-search.com
127.0.0.1 1-2005-search.com
127.0.0.1 123fporn.info
127.0.0.1 www.123fporn.info
127.0.0.1 123haustiereundmehr.com
127.0.0.1 www.123haustiereundmehr.com
127.0.0.1 123moviedownload.com
127.0.0.1 www.123moviedownload.com
There are 15459 more lines.
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-2385482525-178760063-3032261430-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Usuario\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: Media is not connected to internet.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
If an entry is included in the fixlist, it will be removed.
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^BackupRemind.lnk => C:\Windows\pss\BackupRemind.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^Usuario^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup
MSCONFIG\startupfolder: C:^Users^Usuario^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Firemin.lnk => C:\Windows\pss\Firemin.lnk.Startup
MSCONFIG\startupfolder: C:^Users^Usuario^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MEGAsync.lnk => C:\Windows\pss\MEGAsync.lnk.Startup
MSCONFIG\startupfolder: C:^Users^Usuario^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Polaris Office Sync.lnk => C:\Windows\pss\Polaris Office Sync.lnk.Startup
MSCONFIG\startupfolder: C:^Users^Usuario^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Recorte de pantalla y Selector de OneNote 2010.lnk => C:\Windows\pss\Recorte de pantalla y Selector de OneNote 2010.lnk.Startup
MSCONFIG\startupreg: AdAwareTray =>
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: APSDaemon =>
MSCONFIG\startupreg: Autodesk Desktop App => "C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe" -tray
MSCONFIG\startupreg: Autodesk Sync => C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe
MSCONFIG\startupreg: Chromium => "c:\users\usuario\appdata\local\chromium\application\chrome.exe" --auto-launch-at-startup --profile-directory="Default" --restore-last-session
MSCONFIG\startupreg: Clip2Net => C:\Program Files (x86)\Clip2Net\clip2net.exe
MSCONFIG\startupreg: CorelDRAW Graphics Suite 11b =>
MSCONFIG\startupreg: Draughts => "C:\Users\Usuario\AppData\Roaming\Checkers\Draughts\Draughts.exe"
MSCONFIG\startupreg: Dropbox Update => "C:\Users\Usuario\AppData\Local\Dropbox\Update\DropboxUpdate.exe" /c
MSCONFIG\startupreg: EPSON L800 Series => C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIG5P.EXE /FU "C:\Windows\TEMP\E_S55FD.tmp" /EF "HKCU"
MSCONFIG\startupreg: GoogleChromeAutoLaunch_CF0D12F859BF15DAB73FDD0B7E1E013D => "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
MSCONFIG\startupreg: HDAudDeck => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
MSCONFIG\startupreg: iTunesHelper =>
MSCONFIG\startupreg: KiesPDLR.exe => C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe Run
MSCONFIG\startupreg: KiesPreload => C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload
MSCONFIG\startupreg: KiesTrayAgent => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
MSCONFIG\startupreg: LanguageShortcut =>
MSCONFIG\startupreg: LifeCam => "C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe"
MSCONFIG\startupreg: MDS_Menu => "C:\Program Files (x86)\Olympus\ib\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Olympus\ib" UpdateWithCreateOnce "Software\OLYMPUS\ib\1.0"
MSCONFIG\startupreg: Olympus ib => "C:\Program Files (x86)\Olympus\ib\olycamdetect.exe" /Startup
MSCONFIG\startupreg: Polaris Office Sync => C:\Users\Usuario\AppData\Roaming\PolarisOfficeLink\POLinkLauncher.exe
MSCONFIG\startupreg: PowerDVD14Agent =>
MSCONFIG\startupreg: PSafeTray =>
MSCONFIG\startupreg: PSafeWDS =>
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: RemoteControl =>
MSCONFIG\startupreg: SDTray =>
MSCONFIG\startupreg: SideSync => C:\Program Files (x86)\Samsung\SideSync4\SideSync.exe
MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: Spotify => "C:\Users\Usuario\AppData\Roaming\Spotify\Spotify.exe" -autostart -minimized
MSCONFIG\startupreg: Spotify Web Helper => C:\Users\Usuario\AppData\Roaming\Spotify\SpotifyWebHelper.exe --autostart
MSCONFIG\startupreg: SSC Service Utility => C:\Program Files (x86)\SSC Service Utility\ssc_serv.exe /s
MSCONFIG\startupreg: StartCCC =>
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: TunnelBear => C:\Program Files (x86)\TunnelBear\TBear.Client.exe -autoconnect
MSCONFIG\startupreg: uTorrent => "C:\Users\Usuario\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
MSCONFIG\startupreg: VX1000 => C:\Windows\vVX1000.exe
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [TCP Query User{E722B8F5-AC8A-4D4A-90C8-7D4E4B534F84}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe
FirewallRules: [UDP Query User{0904E8C9-8D84-4D79-B57D-7EA2B88BC77C}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe
FirewallRules: [TCP Query User{81E39A98-9ABA-40DA-AD0B-289E6DA0A93D}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe
FirewallRules: [UDP Query User{C15FBE1A-AAA6-43A5-B2A5-389136F66929}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe
FirewallRules: [TCP Query User{2FD100E4-0A60-4F1F-B3D2-B90C6E06A6B4}C:\users\usuario\appdata\roaming\utorrent\utorrent.exe] => (Block) C:\users\usuario\appdata\roaming\utorrent\utorrent.exe
FirewallRules: [UDP Query User{7BC413A3-5337-446D-8F6A-22EC547F78E6}C:\users\usuario\appdata\roaming\utorrent\utorrent.exe] => (Block) C:\users\usuario\appdata\roaming\utorrent\utorrent.exe
FirewallRules: [{01D6D7D6-45A4-44F3-AAA2-520A034E139F}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{9D19973C-EF58-4E96-A4E3-B06F72452CE4}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{1AA4A925-DB3E-489B-B1E3-021B9B40DD79}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{9D4D61AD-C584-43E6-ABB4-8CEAFB1C6CB0}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe] => (Allow) C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe
FirewallRules: [UDP Query User{508F35E1-A721-4808-877F-DB8137C425CB}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe] => (Allow) C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe
FirewallRules: [TCP Query User{4F937B47-800A-4D67-BC23-DF35E42E7B93}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{2C07B46F-D9C6-4DC9-9106-3BD34DE2527A}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [TCP Query User{635F1155-8187-4A86-9444-FE08DFF17049}C:\users\usuario\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\usuario\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{3716DBD9-185F-4C4B-892E-6AF6A7D44E63}C:\users\usuario\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\usuario\appdata\roaming\spotify\spotify.exe
FirewallRules: [{39D4598A-26DD-41CB-94A2-46F3931C63D0}] => (Allow) C:\Users\Usuario\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{D3FA529B-58F6-4335-A3D8-2E4F48EC43A2}] => (Allow) C:\Users\Usuario\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [TCP Query User{88CC4BAD-5DF4-42DA-9AE3-383B556560CB}C:\program files (x86)\winamp\winamp.exe] => (Block) C:\program files (x86)\winamp\winamp.exe
FirewallRules: [UDP Query User{E861FB15-8623-4F4D-BA1D-CBF64B6F338E}C:\program files (x86)\winamp\winamp.exe] => (Block) C:\program files (x86)\winamp\winamp.exe
FirewallRules: [TCP Query User{5AB421A8-CE57-4352-8946-D7F47D62A9F6}C:\program files (x86)\formatfactory\formatfactory.exe] => (Block) C:\program files (x86)\formatfactory\formatfactory.exe
FirewallRules: [UDP Query User{2E0848BB-F52D-4800-BBC5-B143CF4BC840}C:\program files (x86)\formatfactory\formatfactory.exe] => (Block) C:\program files (x86)\formatfactory\formatfactory.exe
FirewallRules: [TCP Query User{2104D34B-3CCE-44C9-958D-C49343952F21}C:\program files (x86)\microsoft office\office14\groove.exe] => (Block) C:\program files (x86)\microsoft office\office14\groove.exe
FirewallRules: [UDP Query User{3FB9A8E4-EDFB-4F9A-9E50-A09EFF42896B}C:\program files (x86)\microsoft office\office14\groove.exe] => (Block) C:\program files (x86)\microsoft office\office14\groove.exe
FirewallRules: [{35430691-6B12-4A25-A8E7-6035A1F1799A}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe
FirewallRules: [{59F66543-A68F-4E33-A199-D9DF894036BB}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe
FirewallRules: [TCP Query User{64BDAE3E-1EFC-45C5-ADD0-D772E3F5F0CA}C:\program files (x86)\reaper\reaper.exe] => (Block) C:\program files (x86)\reaper\reaper.exe
FirewallRules: [UDP Query User{27B0743F-BE5F-44CF-BF40-31B36FD928D2}C:\program files (x86)\reaper\reaper.exe] => (Block) C:\program files (x86)\reaper\reaper.exe
FirewallRules: [TCP Query User{1C54E26C-A3D0-43F1-B706-3CF1571219B3}C:\program files (x86)\reaper\reamote.exe] => (Block) C:\program files (x86)\reaper\reamote.exe
FirewallRules: [UDP Query User{D2783017-5547-4AAE-9E4C-91D2BE67BC3A}C:\program files (x86)\reaper\reamote.exe] => (Block) C:\program files (x86)\reaper\reamote.exe
FirewallRules: [{C837D156-D8D7-4DB4-B453-13AE16C134B7}] => (Allow) C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe
FirewallRules: [{9D4CA4CA-1FA5-4A6E-A1F9-977E075B659E}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{F97A3D26-F29A-488E-BF00-5A2DA6C29CF3}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe
FirewallRules: [{5DD7105D-3EEC-4576-B7F1-1D44EB136F65}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe
FirewallRules: [{5EBDF409-0101-4BB4-ACAD-724C11766B85}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
==================== Restore Points =========================
12-12-2018 19:58:43 Removed McAfee Safe Connect
12-12-2018 20:02:06 Windows Update
==================== Faulty Device Manager Devices =============
Name: VirtualBox Host-Only Ethernet Adapter
Description: VirtualBox Host-Only Ethernet Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Oracle Corporation
Service: VBoxNetAdp
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: =========================
Application errors:
==================
Error: (12/13/2018 01:42:07 AM) (Source: MsiInstaller) (EventID: 11316) (User: NT AUTHORITY)
Description: Product: Avast Update Helper -- Error 1316. La cuenta especificada ya existe.
Error: (12/13/2018 12:57:13 AM) (Source: DbxSvc) (EventID: 293) (User: )
Description: Failed to validate client process executable is signed: C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
Error: (12/13/2018 12:57:13 AM) (Source: DbxSvc) (EventID: 282) (User: )
Description: Certificate mismatch for file: C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
Error: (12/13/2018 12:46:02 AM) (Source: MsiInstaller) (EventID: 11316) (User: NT AUTHORITY)
Description: Product: Avast Update Helper -- Error 1316. La cuenta especificada ya existe.
Error: (12/12/2018 11:44:34 PM) (Source: MsiInstaller) (EventID: 11316) (User: NT AUTHORITY)
Description: Product: Avast Update Helper -- Error 1316. La cuenta especificada ya existe.
Error: (12/12/2018 10:44:57 PM) (Source: MsiInstaller) (EventID: 11316) (User: NT AUTHORITY)
Description: Product: Avast Update Helper -- Error 1316. La cuenta especificada ya existe.
Error: (12/12/2018 09:42:16 PM) (Source: MsiInstaller) (EventID: 11316) (User: NT AUTHORITY)
Description: Product: Avast Update Helper -- Error 1316. La cuenta especificada ya existe.
Error: (12/12/2018 08:42:43 PM) (Source: MsiInstaller) (EventID: 11316) (User: NT AUTHORITY)
Description: Product: Avast Update Helper -- Error 1316. La cuenta especificada ya existe.
System errors:
=============
Error: (12/13/2018 12:55:09 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: El servicio Wondershare Application Framework Service no pudo iniciarse debido al siguiente error:
El servicio no respondió a tiempo a la solicitud de inicio o de control.
Error: (12/13/2018 12:55:09 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Se agotó el tiempo de espera (30000 ms) para la conexión con el servicio Wondershare Application Framework Service.
Error: (12/13/2018 12:54:30 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: El servicio VBoxAsw Support Driver no pudo iniciarse debido al siguiente error:
El sistema no puede encontrar la ruta especificada.
Error: (12/13/2018 12:54:30 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: El servicio TunnelBear Maintenance no pudo iniciarse debido al siguiente error:
El servicio no respondió a tiempo a la solicitud de inicio o de control.
Error: (12/13/2018 12:54:30 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Se agotó el tiempo de espera (30000 ms) para la conexión con el servicio TunnelBear Maintenance.
Error: (12/13/2018 12:53:25 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: El servicio Hddb Build Service no pudo iniciarse debido al siguiente error:
El sistema no puede encontrar el archivo especificado.
Error: (12/13/2018 12:51:24 AM) (Source: Service Control Manager) (EventID: 7043) (User: )
Description: El servicio Malwarebytes Service no se cerró correctamente después de recibir un control de aviso de apagado.
Error: (12/12/2018 08:40:53 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: El servicio Windows Search no respondió después de iniciar.
Windows Defender:
===================================
Date: 2014-11-24 23:51:11.428
Description:
Windows Defender detectó spyware u otro software potencialmente no deseado.
Para obtener más información, consulte lo siguiente:
http://go.microsoft.com/fwlink/?linkid=37020&name=Adware:Win32/NewDotNet&threatid=9108
Nombre:Adware:Win32/NewDotNet
Id.:9108
Gravedad:Alta
Categoría:Adware
Ruta de acceso encontrada:file:C:\Program Files (x86)\ProMp3Recorder\NNGLZA638.EXE;file:C:\Windows\NDNuninstall6_38.exe;regkey:HKCU@S-1-5-18\software\new.net
Tipo de detección:Concreto
Origen de detección:Sistema
Estado:Desconocido
Usuario:NT AUTHORITY\SYSTEM
Nombre de proceso:
Date: 2014-11-24 23:41:57.722
Description:
Windows Defender detectó spyware u otro software potencialmente no deseado.
Para obtener más información, consulte lo siguiente:
http://go.microsoft.com/fwlink/?linkid=37020&name=Adware:Win32/NewDotNet&threatid=9108
Nombre:Adware:Win32/NewDotNet
Id.:9108
Gravedad:Alta
Categoría:Adware
Ruta de acceso encontrada:file:C:\Program Files (x86)\NewDotNet\newdotnet6_38.dll;file:C:\Program Files (x86)\ProMp3Recorder\NNGLZA638.EXE;file:C:\Windows\NDNuninstall6_38.exe;process:pid:2976;process:pid:3128;process:pid:4128;process:pid:5304;process:pid:5572;process:pid:5704;process:pid:5932;process:pid:5952;process:pid:6648
Tipo de detección:Concreto
Origen de detección:Protección en tiempo real
Estado:Desconocido
Usuario:\
Nombre de proceso:
Date: 2014-11-24 23:41:31.280
Description:
Windows Defender detectó spyware u otro software potencialmente no deseado.
Para obtener más información, consulte lo siguiente:
http://go.microsoft.com/fwlink/?linkid=37020&name=Adware:Win32/NewDotNet&threatid=9108
Nombre:Adware:Win32/NewDotNet
Id.:9108
Gravedad:Alta
Categoría:Adware
Ruta de acceso encontrada:file:C:\Program Files (x86)\NewDotNet\newdotnet6_38.dll;file:C:\Program Files (x86)\ProMp3Recorder\NNGLZA638.EXE;file:C:\Windows\NDNuninstall6_38.exe;process:pid:2976;process:pid:3128;process:pid:4128;process:pid:5304;process:pid:5704;process:pid:5932;process:pid:5952;process:pid:6648
Tipo de detección:Concreto
Origen de detección:Protección en tiempo real
Estado:Desconocido
Usuario:\
Nombre de proceso:
Date: 2014-11-24 23:41:15.445
Description:
Windows Defender detectó spyware u otro software potencialmente no deseado.
Para obtener más información, consulte lo siguiente:
http://go.microsoft.com/fwlink/?linkid=37020&name=Adware:Win32/NewDotNet&threatid=9108
Nombre:Adware:Win32/NewDotNet
Id.:9108
Gravedad:Alta
Categoría:Adware
Ruta de acceso encontrada:file:C:\Program Files (x86)\NewDotNet\newdotnet6_38.dll;file:C:\Program Files (x86)\ProMp3Recorder\NNGLZA638.EXE;file:C:\Windows\NDNuninstall6_38.exe;process:pid:2976;process:pid:3128;process:pid:4128;process:pid:5304;process:pid:5704;process:pid:5932;process:pid:6648
Tipo de detección:Concreto
Origen de detección:Protección en tiempo real
Estado:Desconocido
Usuario:\
Nombre de proceso:
Date: 2014-11-24 23:40:25.116
Description:
Windows Defender detectó spyware u otro software potencialmente no deseado.
Para obtener más información, consulte lo siguiente:
http://go.microsoft.com/fwlink/?linkid=37020&name=Adware:Win32/NewDotNet&threatid=9108
Nombre:Adware:Win32/NewDotNet
Id.:9108
Gravedad:Alta
Categoría:Adware
Ruta de acceso encontrada:file:C:\Program Files (x86)\NewDotNet\newdotnet6_38.dll;file:C:\Program Files (x86)\ProMp3Recorder\NNGLZA638.EXE;file:C:\Windows\NDNuninstall6_38.exe;process:pid:2976;process:pid:3128;process:pid:4128;process:pid:5304;process:pid:5704;process:pid:5932
Tipo de detección:Concreto
Origen de detección:Protección en tiempo real
Estado:Desconocido
Usuario:\
Nombre de proceso:
Date: 2014-07-11 20:14:47.420
Description:
Windows Defender encontró un error al intentar cargar firmas e intentará restablecer un conjunto de firmas conocidas.
Firmas intentadas:Actual
Código de error:0x80070002
Descripción de error:El sistema no puede encontrar el archivo especificado.
Versión de firma:0.0.0.0
Versión de motor:0.0.0.0
Date: 2014-07-11 20:02:18.445
Description:
Windows Defender encontró un error al intentar cargar firmas e intentará restablecer un conjunto de firmas conocidas.
Firmas intentadas:Actual
Código de error:0x80070002
Descripción de error:El sistema no puede encontrar el archivo especificado.
Versión de firma:0.0.0.0
Versión de motor:0.0.0.0
Date: 2014-05-30 15:21:14.220
Description:
Windows Defender encontró un error al intentar cargar firmas e intentará restablecer un conjunto de firmas conocidas.
Firmas intentadas:Actual
Código de error:0x80070002
Descripción de error:El sistema no puede encontrar el archivo especificado.
Versión de firma:0.0.0.0
Versión de motor:0.0.0.0
Date: 2014-03-25 15:54:45.907
Description:
Windows Defender encontró un error al intentar cargar firmas e intentará restablecer un conjunto de firmas conocidas.
Firmas intentadas:Actual
Código de error:0x80070002
Descripción de error:El sistema no puede encontrar el archivo especificado.
Versión de firma:0.0.0.0
Versión de motor:0.0.0.0
CodeIntegrity:
===================================
Date: 2014-12-21 12:16:34.648
Description:
Windows no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume2\Users\Usuario\AppData\Local\Temp\EverestDriver.sys porque el hash del archivo no se encuentra en el sistema. Puede que un cambio reciente de hardware o software haya instalado un archivo dañado o con una firma incorrecta, o que exista un software malintencionado de origen desconocido.
Date: 2014-12-21 12:16:34.438
Description:
Windows no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume2\Users\Usuario\AppData\Local\Temp\EverestDriver.sys porque el hash del archivo no se encuentra en el sistema. Puede que un cambio reciente de hardware o software haya instalado un archivo dañado o con una firma incorrecta, o que exista un software malintencionado de origen desconocido.
Date: 2014-12-21 12:16:29.572
Description:
Windows no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume2\Program Files (x86)\Lavalys\EVEREST Home Edition\kerneld.amd64 porque el hash del archivo no se encuentra en el sistema. Puede que un cambio reciente de hardware o software haya instalado un archivo dañado o con una firma incorrecta, o que exista un software malintencionado de origen desconocido.
Date: 2014-12-21 12:16:29.360
Description:
Windows no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume2\Program Files (x86)\Lavalys\EVEREST Home Edition\kerneld.amd64 porque el hash del archivo no se encuentra en el sistema. Puede que un cambio reciente de hardware o software haya instalado un archivo dañado o con una firma incorrecta, o que exista un software malintencionado de origen desconocido.
==================== Memory info ===========================
Processor: AMD A6-3500 APU with Radeon(tm) HD Graphics
Percentage of memory in use: 73%
Total physical RAM: 4073.55 MB
Available physical RAM: 1085.72 MB
Total Virtual: 8145.25 MB
Available Virtual: 4717.78 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:475.74 GB) (Free:131.74 GB) NTFS
Drive e: (Nuevo vol) (Fixed) (Total:455.42 GB) (Free:179.3 GB) NTFS
Drive f: (Reservado para el sistema) (Fixed) (Total:0.1 GB) (Free:0.05 GB) NTFS
Drive h: (ANALIA AGUSTINA CAMILA) (Fixed) (Total:237.91 GB) (Free:83.79 GB) NTFS
Drive i: (Nuevo vol) (Fixed) (Total:227.75 GB) (Free:186.81 GB) NTFS
Drive j: (Nuevo vol) (Fixed) (Total:1863.01 GB) (Free:1485.25 GB) NTFS
\\?\Volume{bc87ece0-1996-11e3-a98f-806e6f6e6963}\ (Reservado para el sistema) (Fixed) (Total:0.35 GB) (Free:0.31 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: 2BD2C32A)
Partition 1: (Active) - (Size=356 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=475.7 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=455.4 GB) - (Type=07 NTFS)
========================================================
Disk: 1 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: D7D2BF09)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=237.9 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=227.7 GB) - (Type=07 NTFS)
========================================================
Disk: 2 (MBR Code: Windows 7/8/10) (Size: 1863 GB) (Disk ID: 0C699BCF)
Partition 1: (Not Active) - (Size=1863 GB) - (Type=07 NTFS)
==================== End of Addition.txt ============================